Ok, I can do that. I thought that logstash is the low-level part of the stack that picks up the logs.
Therefore, I suspected that the logstash filter didn't pick up the rsyslog messages. Hence, I put it in this section.
The latter error of the Elasticsearch output filter of course might suggest a different cause now.
Should reopen a new topic or can this entry be moved by the moderators?