I am planning our migration from our ageing rsyslog(RELP) > logtash > elasticsearch with a new set of infrastructure.
I have been experimenting with filebeat > logstash > elasticsearch but I'm not getting the message granularity that I was hoping for.
Using filebeat > elasticsearch I get lots of wonderful exported fields with loads of useful information. However, if I set filebeat with logstash output all this appears to be lost, and I just get everything lumped into the message field.
Is this expected behaviour? I know I can grok the output, but I was hoping save that for just additional insights or filtering
You don't mention if you were using Filebeat modules when sending Filebeat -> Elasticsearch, but I suspect that you were based on the experience you describe.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.