I was using Logstash for parsing logs. I am using Rsyslog + One Logstash instance + ES and Kibana.
Now I am also doing throttling, that if particular types of request comes more than 10 per minute than generate an Alarm. Everything is working fine as config.
I am not sure now that how to scale Logstash part to handle more load ?
If i run logstash on multiple instances then throttling can not be proper. Any help to handle more load ?