Hello,
The live stream feature seems really nice! But I'm a little bit confused about this functionality: It looks like the same as the "Discover" view...isn't it?
We are already using the Elastic stack as a "big" farm to parse, store, and analyse the logs (10TB/month). Beat is not an option because it doesn't work on closed systems like appliances, network devices... so I really hope you will not focus only on beat
The data used for Discovery and the Log UI is the same. By default the Log UI looks for the indices of Filebeat but you can configure it to any index you want, so it should also work with your data. What does your index pattern look like?
Thanks for the answer, we use multiple index patterns (around 20 patterns using 20 different templates in ES).
We parse system/event logs from linux/windows/switch/router.
And also antispam appliances, radius appliances...
In the doc you highlighted me in an other post it does not seems to be possible to use multiple "log templates/patterns".
But I may not understand correctly and maybe it is possible to change the "default" value in "xpack.infra.sources.default.someparameter" to use multiple templates.
e.g.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.