I am using Filebeat to send logs to logstash and then to elasticsearch.
But now, I am thinking of sending the logs to a single rsyslog-server(over UDP/TCP) and then to logstash to elasticsearch. By this way, I will not need to install filebeat on my servers.
Moreover, I can send data in JSON format, which is pretty easy to filter.
I want to ask which will be better, rsyslog OR filebeat for this purpose, in terms of performance, overhead and reliability ?
Please guide me in the right direction.