logstash-plugins/logstash-input-elasticsearch

Add a "sincedb" type of mecanism

Closed this issue · 1 comments

Hi,

Would it be possible to add a "sincedb" type of functionality to this plugin ?

You can schedule a query to pull logs from Elastic at regular intervals for example 1 minute and configure the query to return 1 minute's worth of logs. The issue is that if a crash occurs or if the logstash is restarted, logs will be missing. The issue arises only when trying to "stream" events from elastic into logstash continuously. Other plugins such as the JDBC plugin let you configure a sincedb to avoid these issues.

Is there another way to reliably stream logs from elastic to logstash ?

Thanks

jsvd commented

closing as dup of #93 please follow that issue instead.