I would love to try out filebeat as a replacement for my current use of LogStash.
I like the idea of running a Go program instead of a JVM.
Replacing my use of the "file" input plugin to use filebeat would be easy for "tailing" the access logs.
However, I actually read a fair number of other inputs and use grok to filter out the noise as close to the data source as possible.
Further, I plan to have my LogStash output go over Kafka instead of going directly into ES.
On the face of it, Go should be able to do "grok" and "kafka" just as easily as Java (LogStash) , but apparently that is not (currently) the case.
I guess the question is what is the correct place to draw the line between LogStash and Filebeat?