Yeah, so logstash has similar functionalities as an HF since it can group forwarded TCP events together... simce your UF is simply sending out TCP with no line breaking indication youll most probably need to do that with Logstash.. and Im sure Splunk wouldnt invest in interoperability for multiline forwarding with logstash since data going to ELK means less license cost..so yes that plugin is your solution.
You could also use a syslog server, have it write the logs to files and just use a file beats on it... It could be easier to maintain and configure
... View more