I am monitoring /var/log/* in my linux box through Filebeat. Every log file have it's own style. I am getting the event like below (sample log file)
"message:b8tTpts/0��3T(:a� pts/0ts/0SAHISD+jocktramen10.33.111.11f>Te @version:1 @timestamp:January 19th 2016, 16:38:32.732 beat.hostname:NSAH-PC1169-1 beat.name:NSAH-PC1169-1 count:1 fields: - input_type:log offset:109,405 ** source:/var/log/wtmp** type:syslog host:NHCLT-PC1169-1 _id:AVJZkgL5augbAVuIOsWM _type:syslog _index:filebeat-2016.01.19 _score:"
From above event I couldn't able to make a meaningful dashboard in Kibana. I cannot Extract new fields as every log file have it's own style of logging. Can I write code in Logstash , that extract from multiple log files?
In Elasticsearch document there i found /var/log/syslog. But I didn't found in my Linux box.
Is Syslog is a software? will it take all the logfiles, and convert it into Single format i.e., Syslog format?