Am using the filebeat for Suricata & ES server. Now my colleague have decided to use filebeat as well. But they are using a completely different setup. I have been attempting to set different configurations in conf.d. However it won't accept multiple output servers as far as i can see.
My question:
What would be the best way to configure filebeat to read two different logs and output to two different servers?
Thanks for you response but perhaps I wasn't clear enough.
Server1 has apache and suricata logs.
Apache logs need to end up on logstash_server_1 and there after ES_server 1
Suricata logs need to end up on logstash_server_2 and there after ES_server 2
The options for multiple servers is for cluster servers. But in this case the servers are not in a cluster. And data needs to remain separate.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.