I've tested lately filebeat 7.0.0. but coudn't get it to work with my elasticsearch-cluster (also version 7.0.0). Whenever I used the appropiate way to change the index name:
First I had to disable ILM which isn't stated anywhere and after this data is incoming into ES under my newly created Index. Unfortunatly the data isn't complete, because all fields are missing...
FYI: I use the system-module to collect syslog and auth logs.
I would like to hear If anyone use this type of configuration and can help out with some configuration snippets, or help troubleshooting.