I have quick query and I really would appreaciate if someone can answer it?
What is the better way to accept messages from server to elastic stack if installed on same server?
I mean lets say I have apache, nginx, Windows server and couple of Linux mail servers what would you recommend to injest message in es?
through logstash to ES or through filebeat on end computers into logstash on ELK and then to ES?
Since I am not so familiar with logstash and grok patterns; I am finding bit difficult to normalize the logs hence wanted to understand the best practise? Will filebeat suffice my need?