Newbie here, can someone help me out please?
2 log servers producing:
connection logs (user ip etc) (generated every 10 mins)
http logs (user actions) (generated on the fly)
the connection logs have username and ip (sent via filebeat to logstash)
the http logs are missing the username (sent via syslog, then loaded from syslog file to logstash)
(i cannot change this, i dont think)
how is best to fuse these two? can i add something in the logstash, or is there something I can do to merge the logs in a search in kibana?