As of now, there is Filebeat s3 input that doesn't support AWS WAF logs. AWS WAF logs use Kinesis Firehose to get to S3 and the "Content-type" is set to "application/octet-stream". Due to this, the logs didn't get expanded in the Elasticsearch.
If that support can be added it will resolve a big problem and many users looking forward to getting AWS WAF logs to the ELK stack for the analysis.
Thanks in Advance