Lets say I pipe a few Beats (in a remote DC) through Logstash, and a few beats direct to ES, can I send them to the same index? Wondering if Logstash would change the events significantly, that I have to use different indexes.
I would also like to use the canned dashboards... hopefully as they are.
Thanks @andrewkroh! Almost there... but for these 2 issues:
Few fields, like beat.name show up in Kibana as beat.name.keyword.
Ended up with more than 1000 fields for Winlogbeat.
I fixed for both by updating the visualization and changing the template. But I'd like to understand what I could have done wrong. I'm not doing any filtering - just in/out.
What I'm actually doing is: Beats --> Logstash --> Logstash --> Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.