# Which architecture is better? Should I collect the logs on the server side using rsyslog?

**URL:** <https://discuss.elastic.co/t/which-architecture-is-better-should-i-collect-the-logs-on-the-server-side-using-rsyslog/286589>\
**Category:** Logstash\
**Created:** [October 13, 2021, 8:11am UTC](https://discuss.elastic.co/t/which-architecture-is-better-should-i-collect-the-logs-on-the-server-side-using-rsyslog/286589 "2021-10-13T08:11:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sagimb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagimb/32/78403_2.png) [@Sagimb](https://discuss.elastic.co/u/Sagimb)\
**Post date:** [October 13, 2021, 8:11am UTC](https://discuss.elastic.co/t/which-architecture-is-better-should-i-collect-the-logs-on-the-server-side-using-rsyslog/286589/1 "2021-10-13T08:11:34Z")

</div>

![A or B](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e7603958e5a5c5fd6df654e55ca06b7822e72690.png)

I am trying to understand which architecture is better for me. I have a few hundreds of instances that I want to send their logs to one central server.  
Should I got with A (run rsyslog on the central server to collect the logs and pass them into logstash) OR should I go with B (all logs will go directly into logstash from the rsyslog clients)?

If you have any other tips about my architecture, I would love to hear.

Thanks.

BTW- I rather not use Beats, because I already have rsyslog installed

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 13, 2021, 8:35am UTC](https://discuss.elastic.co/t/which-architecture-is-better-should-i-collect-the-logs-on-the-server-side-using-rsyslog/286589/2 "2021-10-13T08:35:27Z")

</div>

@Sagimb

Topology B reduces the number of integration points therefore reducing the overall number of failure points.

The less moving parts the better, so if Logstash Input can reduce your need for extra hardware, network hops and bandwidth and skill set required, the better!

Sticking with something because it is familiar is the road to disaster if newer better ways of solving something is present.

I also think many user cases will present themselves with Beats and Fleet Managed agents that Topology B will be the basis to future proof your solution

---

<div class="post-metadata">

**Author:** ![Sagimb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagimb/32/78403_2.png) [@Sagimb](https://discuss.elastic.co/u/Sagimb)\
**Post date:** [October 13, 2021, 9:11am UTC](https://discuss.elastic.co/t/which-architecture-is-better-should-i-collect-the-logs-on-the-server-side-using-rsyslog/286589/3 "2021-10-13T09:11:43Z")

</div>

Thank you.

I'll stick with topology B, but i'll want to change the communication port between the rsyslog clients and the logstash to be 514.  
Can I do that without running logstash as root? Will it be able to listen to port 514?

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 13, 2021, 9:34am UTC](https://discuss.elastic.co/t/which-architecture-is-better-should-i-collect-the-logs-on-the-server-side-using-rsyslog/286589/4 "2021-10-13T09:34:35Z")

</div>

@Sagimb

> [@Sagimb](#):
>
> Can I do that without running logstash as root? Will it be able to listen to port 514?

You can change the tcp port in the Input settings. The port configuration is configured via the logstash input module, so you shouldn't have problems with running it under the current account you are using.

> **[Tcp input plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html#plugins-inputs-tcp-port)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2021, 9:35am UTC](https://discuss.elastic.co/t/which-architecture-is-better-should-i-collect-the-logs-on-the-server-side-using-rsyslog/286589/5 "2021-11-10T09:35:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
