Dear all, I have an ELK 7.8.1 server with syslog and cisco module enabled from Filebeat.
At the moment I'm receiving data from:
- Linux servers (syslog)
- Cisco ASA (cisco module, asa data set)
- Cisco IOS (cisco module, ios data set)
All of these data point to filebeat-* index pattern, and filebeat is the default index with 50 GB of capacity.
Please, I have two questions:
Should I have to create a new index to store data coming from Linux servers, another for Cisco ASA and the last one for Cisco IOS ??? Or it's the same to point all of them to filebeat-* indices ???
In case I create new indexes defining index templates, do I have to define every field name and type from each source log??? I think this is hard to do taking into account that Cisco ASA, Cisco IOS and Linux servers have several type of logs.