What is the best way to monitor my hosts? Should I stand up a rsyslog server, and then have clients send logs there, then forward to logstash, or should the clients just send them right to logstash?
Up to you, your requirements and your environment.
Filebeat direct to Elasticsearch removes a lot of complexity.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.