I am planning our migration from our ageing rsyslog(RELP) > logtash > elasticsearch with a new set of infrastructure.
I have been experimenting with filebeat > logstash > elasticsearch but I'm not getting the message granularity that I was hoping for.
Using filebeat > elasticsearch I get lots of wonderful exported fields with loads of useful information. However, if I set filebeat with logstash output all this appears to be lost, and I just get everything lumped into the message field.
Is this expected behaviour? I know I can grok the output, but I was hoping save that for just additional insights or filtering