I don't know much about the ingest converter, but in principle it should be possible to use the ingest pipeline you are getting with curl. You cannot find the json pipeline in the filebeat repository because some pipelines, including the Cisco ones are developed in YAML format, for readability and improved maintainability.
I've also tried to test the filebeat IIS module and almost every single log was not being parsed correctly, so I've decided to go with logstash again and create my own patterns.
I was hoping it would just work since it's a Windows server 2012 but things are never simple
There are some issues reported for the IIS module for Filebeat, including one (#13799) about supporting more log formats. It'd be great if you could provide there some of example lines of the logs you see that are not being correctly parsed. Thanks!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.