System is Ubuntu
Logstash version 7.17
The current idea is to collect logs (via syslog-514Port) from different servers or network devices
Logstash will then send the log cut to Elasticsearch
I have successfully received logs and sent them to Elasticsearch
But I want to use conf to separate devices from different sources
For example, DHCP log will create a DHCP.conf which is the name of his Log representation and output index
I tried forwarding with ufw first
Convert 2 different source host 514 ports to specific ports
then separate conf
Also successfully delivered to Elasticsearch to build 2 indexes
But the content is not separated
Is there any other way to solve it?
Because the sources are different devices. Therefore, the log segmentation method is also different.