I have a syslog-ng server which gathers data from Cisco Router, switches, netflow data and firewall related data .
The data is stored as flat files. Now, i am looking to send those to ELK SIEM .
I see that i can use filebeat and but no idea how can i set it up to fetch from a particular location and how to parse the data to make it SIEM compatible.
Also, do i need logstash to make the data SIEM compatible.