I am using logstash in a mode where it reads log files from disk and puts in ElasticSearch.
What is the best way to deploy logstash for high availability (especially failover)? I'm ok with both active/active mode where two logstash instances are always active, and with active/passive mode where one instance is working and the other one will start only if the first one is down.
I'm specifically asking about logstash and not ElasticSearch.
It seems, that Logstash does not have built in HA options, where we remain with Linux classic - Virtual IP. I was thinking on the same topick, and currently decided to try the following option (hot/cold version):
Here are issues, that need to be solved out, yet:
As far as I know, Active/Active Logstash is available only with the following options taken in mind:
You could use a queue that will act as a buffer between input and indexing process.
It's always a good thing to separate tier with a queue, so if elasticsearch crashs, your application will not suffer.
在这种情况下,最好的方法是使用某种硬件平衡器,例如F5(如果有的话)池,因此您要定义具有相应端口的VIP,然后将该VIP与主机的N个IP地址相关联。 N个logstash主机,因此您可以从logstash中获得任意数量的节点或需要运行的任何服务,然后应用循环算法并平衡连接。
The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.