Due to the wildly different syslog formats (And my not understanding how to grok/mutate/etc properly yet) I'm trying to split my syslog inputs by IP address so there's a different index for each. It seems to mostly be working but I created a catchall entry at the end that is seeing data too sometimes.
Want to make sure there's not a "better" way....I vaguely remember someone telling me that 'host' wasn't a good idea to use, so I am wondering what the "correct" way is. Sorry, just a beginner trying to do things right rather than hack it together!
I'm doing that with beats too, as you can see in the config below. I'm using [host][name].
Syslog data seems to come in with [host] == IP Address.
Here's a trimmed/somewhat sanitized version of the current config. Am I making this too hard for myself?
Running 7.6.2 on CentOS7