I've just started using filebeat and the apache2 and system module. The apache2 module parses all messages and exporting a nice number of fields. Is there any news if the system module will do the same? I'm mostly interesting in parsing the auth.log file. Of is there any other way to accomplish this?
Our filebeat module sends the logs directly to elasticsearch