My setup is:
elasticsearch cluster < logstash_host < ( filebeat_host, filebeat_host2)
Is there a need / benefit to defining log types in elastic 6?
What's the advantage of using the defined module e.g. apache2 module over the standard log module with paths: defined?
Since I'm using logstash, is there an easy way to install all indexes required at point of use e.g. if no apache hosts are configured, don't install the apache indexes, or is this not possible? Is there a downside to installing these generic indexes, even if they're not used?