Logstash can be installed on the server where you are comfortable sending your network log to. The installation steps are available at https://www.elastic.co/guide/en/logstash/current/installing-logstash.html. By default, you can put the Logstash configuration file under /etc/logstash/conf.d/. The file is in the input-filter-output format (https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html). In the following example, we specified the input as a network log file, with a placeholder for filtering the input, and the output as both printing out messages to the console as well as having the output exported toward our AWS Elasticsearch Service instance:
input { file { type => "network_log" path => "path ...