Hi! Is it possible to specify multiple inputs in Graylog 2.4.6 but using only 1 IP and PORT?
Let’s say I have a logstash that has 20 inputs from different systems, this logstash’s adress is: logstash.example and port 5044. Every log has a field called “tags” where the systems (source) name is stored.
Would it be possible to create 20 inputs in graylog, all on logstash.example:5044 but all ingesting different logs depending on field: tags? Reasoning behind it would be : every system needs it’s own specific extractors so having everything piled up in a single INPUT can lead to a disaster.