Hi all, I'm setting up Winlogbeat for collecting windows event logs and use ES and Kibana for analysis.
In my log pipeline I have Logstash in the middle as that seems to be the best current practice and allows for a central configuration and filtering, normalization etc of logs passing through. However, it seems to me like Beats is optimized to talk to directly to ES and that using Logstash (even though it is supported and not discouraged) in the pipeline will complicate things. Apart from the documentation taking for granted that Beats is talking to ES directly there is the fact that the downloadable Beats dashboard package for Kibana ships with "beats-*" indexes hardcoded (and I cannot find anywhere to change this in the Kibana UI afterwards) and hence is not really intended to support Beats transmitted through Logstash. Ofc there are ways of hacking it together either by manually editing the dashboard-files before uploading them, and manhandling stuff in Logstash into the correct indexes, but that hardly seems worth it if the logstash support will be half-ass and needing continous hacks to work.
TL;DR; Should I use Beats to ES directly since logstash support seems half-assed?