I have setup losgstash and graylog on a machine and filebeat on another 16 machines to send logs to graylog server via logstash.
I can see logs on graylog server for 6 of the machines but not for rest of them as log size is large(1gb each for 10 machines). Filebeat is still processing logs for these machines after running for continuously 3 days.
I have following queries regarding this scenario:
- Can i interrupt the process of sending the logs from filebeat to logstash for a while so that logstash send the logs accumulated till now to graylog?
- What should be the ideal speed of filebeat logs sending to logstash assuming machine which has filebeat has 16gb ram and 5gb free space and graylog server has 32gb ram and 8gb free space?
- How can i be sure that logstash cache does not fill out in case of 16 machines sending logs to it continuously?
Kindly reply asap as i am working on a real project implementation.
Thanks and Regards