I'm pretty new to ELK and I was hoping to get some help with a use case I have.
From our network we collect data in elasticsearch with netflow and we have a openvpn server from which we collect the logging with beats.
Now we have the users connected with the VPN in the log files from OpenVPN and we want to now what is doing in the network, e.g. we want to enrich our netflow data with the user from openvpn.
What will be the best way to achieve this?
In the future I'm expecting lots more of these use cases.