Hi Ralph,
I am not sure I understand the question 100%, to clarify a bit, are you wanting to parse log information related to a specific process from one of the logs on the management server and/or agent and relay this to elasticsearch directly?
Typically, as Gregg mentioned this would require writing a simple grok filter to prune what you want from the log(s) in question utilizing logstash and one of several input methods available(eg filebeat, file, etc), then output to elasticsearch.
Unfortunately, I am unaware of a method utilizing elasticsearch alone with any available action pack to accomplish this scenario. I have heard of using alternatives to logstash, such as rsyslog for example to accomplish this, but I cannot think of a way(or am just not aware of a way) utilizing elasticsearch or it's API without a 3rd party, or 'middleman' of sorts to convert and/or at minimum encapsulate the entire log message in json(elasticsearch native format for input).
If I am misunderstanding your question please let me know, nonetheless I do believe this is an excellent idea for an action pack to be created for the elk stack, and would definitely encourage everyone to vote this up.
Jeremy