I have 2 machines , on first machine i have logstash conf file that points to the 2nd machine and PacketBeat services running on both machines. On 1st machine i have ElasticSearch engine and do i realy need it ? I assume that only PacketBeat service is enough for transfer data between two machines?
I don't understand. Is your setup like:
packetbeat  --| |-- > logstash  -> elasticsearch  packetbeat  --|
 being machine 1 and
 being machine 2? packetbeat can directly send to elasticsearch (See docs).
Hi, tnx for response
I already configured it by your way and it works.