I'm using Elasticsearch to collect and categorise logs from network devices. These are being sent to Logstash before being forwarded to Elasticsearch.
I want to forward some Linux server Fail2Ban logs via Filebeat but have a few questions;
Is is best to forward these to Logstash or direct to Elasticsearch?
In either case, how would I ensure logs are matched? I found the following for logstash, but the file is for local input, so i'm unsure what this what need to look like for filebeat input?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.