I am building an environment as follows:
server1 = logstash & filebeat (with Cisco module enabled)
server2 = kibana
server3 = elasticsearch
I want to use this to monitor Cisco ASA firewalls. The ASA's will send logs to Filebeat on UDP/10514. Filebeat will output to Logstash (localhost) on TCP/5044. Logstash will then send to Elasticsearch.
I have installed the Filebeat dashboards and index templates to Elasticsearch. My question is:
Will the Filebeat dashboards be functional (useful) in Elasticsearch, without loading any ingest pipelines? I understand that ingest pipelines will give additional parsing/modification capability, much like grok filtering in Logstash ... but what I'm trying to understand is whether the ingest pipelines have to be used in order for the Filebeat dashboards to work.
I understand that I could 'convert' the ingest pipelines into Logstash filtering, but this is not what I'm asking about. I want to know if the Filebeat dashboards will function without either ES ingest pipelines or equivalent Logstash filtering in place?