Hello Team,
Currently we are using ELK 6.4.0 but now we want to upgrade on ELK 7.4.0 to use SIEM feature. So we are setting up our testing environment first before making change in prod environment.
In ELK version 6.4.0 i have used logstash pipeline for parsing to use the filebeat dashboard because we are using Logstash. I have followed the below link at that time:
Earlier we have no need to enable filebeat module to use logstash pipeline and its working fine.
In version ELK 7.4.0 i used same approach but it didn't work. Then i search the documentation
Logstash pipeline for parsing
Form this document i understand that we need to enable the filebeat module also e.g system, nginx etc and then we can use logstash pipeline for parsing but it was not required in earlier version like 6.4.0.
I am going in right way or not?
Please help me.
Thanks.