Ship filtered logs to logstash server from remote server

Hi all,

I have ELK framework setup on my system.
I am interested collecting logs from remote server and forward them to ELK
I see there are logstash shipper and logstash forwarder approaches to do
My remote servers have huge logs which I can't just forward without
filtering as it choke the network.

  1. can I do filtering on remote servers, and then forward only the
    filtered logs to ELK server for indexing?
  2. What could be the performance impact to have logstash filtering on
    each remote servers?
  3. What architecture is suggested for scenarios with large logs on
    remote servers?

Your help would be appreciated.


You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
To view this discussion on the web visit
For more options, visit