I want to use the below ingest directly in the Filebeat.yml file.
I have made changes for few processor. need to know -> how to use grok, Geoip, user-agent and scripts.
Please help me on the same.
Because, am using Filebeat.yml with Cloudtrail module for pushing the Cloudtrail log event to the elk using docker.
The logs in elk is not parsed as expected.
Note: I want to push it to Elasticsearch via Logstash only.