Vector.dev might be a good replacement for filebeat. Built on Rust and very efficient
I don’t really mean to discourage the author of the post, I just realize this can be done with two simple vector configs.
I respect the simplicity of Redis here, but personally I would consider Kafka if I wanted to scale this setup further, maybe one of:
Vector -> Kafka -> Clickhouse (using Clickhouse's built-in Kafka support)
Vector -> Kafka -> Vector -> Clickhouse
This also lets you stream the logs live if you want to.