I have been playing with ELK stack for a month or so and seem to have it working quite well at a single site, but I am running into issues of how to move forward.
I have several sites with logstash that I would like to feed into another logstash/elasticsearch at a central site. This would allow logs to be maintained at a site for maybe 30 days with no backups and then logs maintained at a central location for a longer period of time before they are archived.
I don't believe that a elasticsearch cluster is what I am looking for, so I am playing with logstash outputs. Currently, at each site, I have logstash configured to output to both the local elasticsearch and lumberjack. That lumberjack output is being received at my central site in what appears to be the proper format (took me a little bit to realize that I needed codec => "json" to get it to do that). The problem is that it is not appearing in elasticsearch at my central site, only the local beats inputs are showing up.
Has anybody set something up like this before and can they assist me?