So with some help from multiple sources. On Elastic 7.6.2 and Unifi Controller 5.12.66
https://redmine.openinfosecfoundation.org/projects/suricata/wiki/_Logstash_Kibana_and_Suricata_JSON_output
https://pastebin.com/xASkU5dm
Here is how you install Filebeat on the USG with the Suricata module and what you need to edit in the suricata*.yaml files in order to send your events/alerts to ES.
Unifi has been dragging their feet on getting the logs outside these devices.
Items left to do here is see if the suricata*.yaml files get overwritten and find a way to get Filebeat to run as a service. You couldn't just install filebeat as you see in the youtube because you recompile it for mips64