Might seem like a dumb question.
I've been trying to learn the ELK stack, and keep shifting focus between each component.
At work, I'm "playing" with a small cluster in attempt to ingest and analyze BRO data. Outside of work, I'm running a single instance that's ingesting from an Apache VPS.
I have never created any templates, either is Logstash or Elasticsearch, yet my data always seems to arrive, and be accessible in Kibana.
It might seem silly, but can anyone tell me if I should be doing something different?
ALSO: I've posted in other forums, but if anyone has any recommendations for a printed book about the whole stack (Elasticsearch, Kibana, Logstash), I would very much appreciate it. I'd rather a printed guide I can carry with me for instances when its' not practical to have two displays open (coffeeshop, etc). But that's an aside