I'm super noob with ELK, after 1 month I finally created beautifuls dashboard with useful information to my company. But I have an issue, I tried to find something about this , but didn't find anything.
Logstash-server Conf Files:
- Cisco Asa A
- Cisco Asa B
- Cisco Asa C
These 3 config files have differents Output Indexes and Differents Input UDP ports, but the information sent to " Cisco Asa A " is replicated in the indexes of Cisco ASa B & C .
Also the physical device " B " & " C" doesn't have syslogs/netflows configured yet.
Doing a Curl to elasticsearch Im saw the index of " B " " C" growing like " Cisco Asa A " , also when I added the " Asa B " & " Asa C" indexes into Kibana I saw the same info than " Cisco Asa A"
I really don't know what is going on here. Im pretty sure that i'm misunderstood something.
can anyone guide me with this situation ?
Thanks in advance