Am using 5LK 5.6.4.
Beats => Logstash => ElasticSearch =>Kibana
I am collets server logs(using grok and mutate filter) and another one, I parse the whole XML in ELK(using multiline and XML filter plugin).
For Log: While beat collects data, It is not in proper order.
For XML: While too many events at the time it splits the XML