I wrote a custom parser with dissect processor for collecting fail2ban-logs. Those are working fine for the servers where logs are being collected using filebeat however I am not sure how do I add those with where I have Elastic-Agent installed?
Nope I am ingesting the logs with filebeat and parsing with processor. I used dissect processor and wondering how do I replicate with servers using elatic-agent?
Since Elastic-Agent is using filebeat in the background wondering if I could modifty that config and pickup and parse the logs using my processor? My logs are being dumped in /var/log/fail2ban.log and here are my dissec_processor