I've more than once read that logstash is far too heavy for a simple shipper, and I've also heard that rsyslog is also sometimes a bit heavy (albeit much lighter) for the purpose. I think with reasonable effort we could create a tool that
- monitors text files (much like imfile does) and pulls new entries from them
- does NOT further process or transform these logs
- sends the resulting file to a very limited number of destionations (for starters, I'd say syslog protocol only)
- with the focus on being very lightweight, intentionnally not implementing anything complex.
Would this be useful for you? What would be the minimal feature set you need in order to make it useful? Does something like this already exist? Is it really needed or is a stripped-down rsyslog config sufficient?
I'd be grateful for any thoughts in this direction.