Filebeat input in Logstash is losing fields

To do this, filebeat needs to have a elasticsearch output in its configuration. You will have to:

  1. Stop Filebeat.
  2. Comment out logstash output, uncomment and configure the elasticsearch output.
  3. Load the ingest pipeline as mentioned in the link.
  4. Restore the logstash output in the config file and comment out the elasticsearch output. Start filebeat again.