I was mentioned in previous statements that we have two instances so I need to filebeat on both the instances right
How to do message field to un-analyzed so that searching can be done.
With the default mappings configured by the index template that ships with Logstash, all string fields have a .raw subfield containing an unanalyzed copy of the field. You can confirm that you can perform the searches you want using those fields. To skip the .raw subfield and make the field itself unanalyzed, make a copy of the index template, modify it, and configure Logstash to use it. This was discussed in a thread in the Logstash group just a few days ago.