I need some help. I read a lot about kibana, elasticsearch and logstash, but I'm get stucked.
We've 2 vm's with ubuntu 18.04. on of them is the kibana with elasticsearch (1st) the other is a rsyslog collector (2nd). The windows servers send the log via winlogbeat to the 1st it is working properly. The linux servers connected to the 2nd and the log sendings working fine as well. We collect the warning logs to separated log files like servername_syslog.log. I tried to transfer this log files via filebat from 2nd to 1st. It is working but when I try to browes the logs the host name is 2nd, how can I change taht field? Can I?
I read another option it is the logstash, where I have to make a logstah server and the rsyslog push it to the logstash and the logstash send it to the elasticsearch and maybe the fields will be good for me.
My question is which is the easiest way?