Hi - I can't seem to get Filebeat to collect syslog from ONLY my network devices. It seems to collect everything from /var/log/messages (Filebeat installed on Centos 7) and from my network devices.
Here are the input/output parts of my filebeat.yml:
filebeat.inputs: - type: syslog protocol.udp: host: "0.0.0.0:10514" output.logstash: hosts: ["localhost:5044"]
The end result is that in Elasticsearch I am seeing all logs from /var/log/messages and from the network devices, instead of only from the network devices.
module.d/system.yml looks like this:
- module: system syslog: enabled: true