Filebeat ingest

Hi Team,

I want to use the below ingest directly in the Filebeat.yml file.

I have made changes for few processor. need to know -> how to use grok, Geoip, user-agent and scripts.
Please help me on the same.

Because, am using Filebeat.yml with Cloudtrail module for pushing the Cloudtrail log event to the elk using docker.
The logs in elk is not parsed as expected.
Note: I want to push it to Elasticsearch via Logstash only.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.