i have a syslog server with my asa's log, and i installed filebeat agent on it, then i can see asa's log on my logstash. now i don't create any filter on my logstash . on elk. picture as below
and who can tell me how to create filter rules on logstash? i want to see the firewall session count timely