Dear people, I have an ELK server 7.8.0.
I'm using the SIEM in order to see and monitor netflow and beats data.
But now I want to add every syslog messages from Linux, Windows and Network Devices (Cisco and much more). All these logs will be sent to an independent index, and I want to add it to the SIEM default indices in order to let the SIEM search for data there.
Is it possible to receive syslog data from different platforms so SIEM can loook for events on them?
Is it better to use filebeat with syslog module or logstash with syslog input to reach my objectve? Please send me a howto URL if you can.
Thanking in advance !!!