IMO I think adding a lowercase processor would make sense.
As a workaround, I think you might be able use an Ingest Node pipeline. I think an ingest node pipeline can modify the _index value so you could dynamically set the value in the pipeline after lowercasing the value. Once you have the pipeline setup and tested then set output.elasticsearch.pipeline to point Winlogbeat at the pipeline.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.