I'm trying to send both classic nginx logs (access/error) using filebeat. Which works great.
Now, my application, also spawns logs which are json encoded. Which also works great if I send only these.
It is when I try to combine both of these input to the same logstash, things get complicated. When parsing the application logs, I simply add a
codec => json to the input field. However, since the nginx logs are plain text, json parsing fails.
How can I solve this problem? Sending both logs to the same logstash instance?
Can I filter in the input section?