Hello
Filebeats seems to have many modules available like system, apache, and others. Since modules are responsible for parsing the data, if I send data directly from Filebeats to ES, will those logs supported by modules be parsed?
I have been trying this setup however the system logs (/var/log/secure and others) do not seem to be parsed even though I have enabled the system module of filebeat within the Linux instance.
Wanted to know if this is the right setup or do we need to add an additional logstash to parse the logs?