Simplify the HTTP log pipeline
Now we have NGINX write traditional common-log-style logs, and then use mmlognorm in the log-collector to parse them into structured data. There is actually no need for this, we could have NGINX generate lumberjack-style logs (with the @cee
tag) directly, since the log_format directive supports JSON escaping of variables. An example here: https://ahelpme.com/software/rsyslog/send-access-logs-in-json-to-elasticsearch-using-rsyslog/