I am new to ELK, and have been tasked with implementing the Beats side of the deployment. Sadly, I find that I cannot find any reference materials online that address working with Beats. Yes, I have seen the documentation on the ES site, but I find it inadequate for my needs. I cannot find any commercial reference material at this time either.
I am trying to do stuff the rest of you may find basic but is puzzling me. For example, I set me up a prospector, and I am trying to filter out all the lines in the Chef-Client log that say "INFO: Processing". Seems like it should be easy, but it aint working. The example is rather sparse, does not cover multiple entries well.
I was hoping to find more examples of people posting a filebeat.yml that shows some more complex configurations, perhaps some that are already set up for files like that. There dont seem to be many out there for me to dissect and learn from.
Does anybody know of any reference books available besides the sparse online docs?