I have Centralized SYSLOG-NG Installed in my network.
I have few hundred devices in the network, including Cisco Switch, Routers, FW and other kind of devices.
All the devices send logs to centralized Logging server that is SYSLOG-NG.
Each Device store in separate folder with the respective IP address as folder name.
Now installed Filebeat on the same server to ship the logs to Logstash.
Problem i have here is i have mentioned filebeat to ship all the logs from source folder /var/log/syslog-ng///*.logs
I am able to see the logs in LogStash and inturn the logs can visulaise in Elasticsearch and Kibana.
But what i was looking here is to configure is filebeat config, how to tag each device information with respective IP before shipping to Logstash, so i can search based on the tag name in Kibana and make alerts.
appreciate guidance and help.