I'm trying to get all my logs into 1 index - I have DNS logs currently going into logstash (lumberjack), now when I want to sen windows eventlogs, I'd like them to be index in the logstash-* index. I this possible, as far as I see using winlogbeat you need to create a new index called winlogbeat-*.
The use case is being able to interrogate all data (network/machine) created by sysmon, eventlogs, dns logs, proxy logs). Having a separate index for the wineventlogs makes the correlation impossible.
Any help would be greatly appreciated!