I have a doubt with the module for IIS logs. I configured the output of filebeat to connect directly with the elasticsearch and then I've have done the command ".\filebeat.exe setup to make the index in elasticsearch and the dashboards in kibana. But i have a problem...
With the index created automatically, the index doesn't have a field for the IP that comes from "X Forwarded for". Now, my question is:
Can i update the pipeline that parses the IIS logs to add the field for this IP?
Thanks for advance