I'm a compleet n00b concerning the ELK stack. I'm a network engineer and doing some research about logging and analytics.
I wanna do 3 things.
Grab log out of /var/log on the local machine. Grab log via filebeat on remote machines. Collect syslog thats being send to the ELK stack.
Second: Pull data in via vendors API (represented in json).
Now my question is what to use. I red alot about the ELK stack so basic knowledge (informational) is available. Only thing i'm not sure of is should i use the logstash or inject data from filebeat directly in elasticsearch.
To put data from vendor API in ELK do i need the logstash ?