Hello,
I'm trying to see how to configure elasticstack to receive logs from cisco devices. I see in the Integrations for 'Cisco Logs' and says to configure the output.elasticsearch section of the filebeat.yml file then enable the Cisco module.
I have setup a fleet-server to manage the elastic-agents centrally and I'm receiving logs currently from the agents. So do I configure the filebeat.yml inside the elastic-agent directory (in my case it's /var/lib/elastic-agent/data/elastic-agent-de80b0/components/filebeat.yml)? And then have the cisco switch send the logs to that host IP? T.I.A.