We are currently setting some hosts to forward their logs via rsyslog
and omelasticsearch
to an elasticsearch
cluster. The manual for omelasticsearch seems to allow only one server name of the ES cluster to be configured, which would be a single point of failure.
How can one configure the logging to log to any node of the ES cluster and not only to one so it is resistant to failures of one node?
Currently we have configured a shared ip for the ES cluster and use that as server name (and this works). Can omelasticsearch
use multiple hosts?