I havent looked at Elastic Search in a long time, so I really do want to know. Not trying to pick a fight. ;)
I havent looked at Elastic Search in a long time, so I really do want to know. Not trying to pick a fight. ;)
* Much more approachable config.
* Its clustering is easier to setup.
* Eventhough logstash is a bit heavy for my taste, the whole ELK stack is really nice for aggregating server logs.
As things are, one can always direct an app sever's syslog to a logging fleet running logstash (or elasticsearch running embedded logstash): http://cookbook.logstash.net/recipes/rsyslog-agent/
It looks pretty promising, but I have yet to meet anyone who uses it.
https://blog.mozilla.org/services/2013/04/30/introducing-hek...
That's what logstash-forwarder[1] (formerly lumberjack) is for. It's in Go, not Java.
If you want to know more details, vote for my talk in November, I'll be digging into much more technical comparison: http://lucenerevolution.uservoice.com/forums/254257-open-sou...
Elasticsearch has easier config, especially for clustering. It is designed to be schemaless so you can push almost any JSON data into it.
Performance is adequate in both.
It's not a big advantage either way, unless you need clustering.