I new to the ELK, just learning the basics.
Logstash (multiline implemented) => elasticsearch => kibana. This is working for me.
However i want to start using filebeat => logstash => elastichsearch => kibana.
Now i run into trouble using the multiline feature of filebeat.
As far as i understand it doesn't support grok (which i used in logstash).
Is this planned to be supported in the near future?
I hope really soon, now just doing the log level multline, I also got multiple time format to be implemented
So i replaced the the complete pattern (LOGLEVEL in this case) to the filebeat configuration.
I copied the the pattern from:
This is not resulting in any hit on my log files.
So short question what am i doing wrong?
If more information needed pls ask.