As we work on migrating to SO2 we're currently trying to get logs / functions up and running ASAP and then working on Elasticsearch pipeline ingestion.
We'd like for the meantime to use the logstash confs we had in place.
Following:
1. I updated the minion for the heavy forwarder adding
logstash:
pipelines:
search:
config:
- custom/custom_logstash_conf.jinja
2. Placed the conf in /opt/so/saltstack/local/salt/logstash/pipelines/config/custom/
3. Did an so-elastic-restart
4. Not sure if of interest, but the "local" dir on the heavy forwarder is empty.
Logs are not being parsed. I don't think I'm missing anything additional in the docs. Thanks in advance!