I am implementing an ELK Stack and have got the server up and running with all the services and applications. Everything is working fine as I can see all the syslogs from routers and switches in Kibana.
I have a question. We also need to capture NETFlow, but I am wondering whether it will get mixed up into the syslogs.
Do I need to create a seperate index? Right now I have two, "logstash_syslogs*" and "logstash_netflow*". The default one on Kibana is "logstash_syslogs*" and can see them all coming in.
Anyone who can assist me in visualizing NETFlow as well? Do I need to switch between indexes to do so and will I have to create a filter for my NETFlow config file?
Here are my configurations: