Syslog input to elastic using logstah

Use a kv filter.