There may be better options than filebeat anyway…
Snort has a binary output which (as I understand it) can ship out to logstash without needing filebeat.
Suricata can output EVE data directly to a remote location via the 'redis' configuration.
dnsmasq and unbound support dnstap which gives the whole request & response in a single entry.
I'd expect more packages will have similar abilities if configured for it... I'm going to set up an ELK VM to play with at some point soon (I wanted to set it up on an RPi2 but MongoDB won't build for FreeBSD/ARM unfortunately).