If i want to centralized the logs in my application Environment. I have installed ELK (Eleasticsearch, Logstash and Kibana) and using Grok file input filter which is working fine on my local machine.
When i want to use it as centralized Solution, i can install it on a VM and on all my applictaion servers Filebeat service which can pick up the data from logfiles and send to Elasticsearch. Kibana is based on Elasticsearch and can show me logs on the basis of Indexes created in Elasticsearch.
Now question is, if its working between Filebeat, Elasticsearch and Kibana , do i still need Logstash? if yes what will be the job of Logstash?