Filebeat doesn't parse log files. With the exception of being able to merge multiline events it ships logs as-is. Look into Logstash for such operations.
Because some date I need to use XML filter to get the right data (Logstash) and other data can be send directly to ElasticSearch
I do not have the possibility to use Filebeat.yml config file to filter out the needed data from the XML it seems..
OK, thanks for the information. I will have a look on what's going to be best for me, but I guess forwarding the data to Logstash will provide me more possibilities then doing it via the filebeat.yml config file.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.