Cisco Switch logs

?? syslog==>logstash==> elasticsearch ?
I want a clear way to collect, normalize the cisco switch logs with ELK