Hi,
I have a centralised logstash server and configured beats for sending data to elasticsearch through logstash.
i have filebeat apache and iis module and auditbeat installed.
Data is parsed properly and reflecting in dashbaord and siem but i am not able to get geo ip related data.
Using the below link
Geoip for auditbeat
When i try the link it works fine and getting geo ip data if output is elasticsearch but in my case its logstash so how do i add the same in logstash output.
I have used this link for filebeat and works fine but need geo ip data as well.
Ingest pipeline for filebeat modules
Kindly help for the same.
Regards,
Bryce Fernandes.