Some time ago type was declared to being depreciated in Logstash and that we should be using tags instead. Ever since then I have migrated everything to tags, and that is fine. I know that in Elasticsearch type has a meaning and after reading this blog about it https://www.elastic.co/blog/index-vs-type I'm even more confused when it comes to incoming logs.
Obviously logs should for the most part be stored in the same daily index, but then what about types or logs, do we gain anything when using type?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.