If you need to analyze different log formats (eventlog, syslog, etc.), support different transports (UDP, TCP, etc.), and log outputs use Logstash. If http is right for you and you only collect logs from one application, use ES directly. Logstash is an optional tool. Details here .
source
share