Tighten & Document Pipelines

This commit is contained in:
Josh Brower
2023-07-10 14:17:42 -04:00
parent 7805ca8beb
commit 31edf2e8ea
2 changed files with 12 additions and 8 deletions

View File

@@ -21,21 +21,21 @@ logstash:
- fleet - fleet
defined_pipelines: defined_pipelines:
fleet: fleet:
- so/0012_input_elastic_agent.conf - so/0012_input_elastic_agent.conf # Logs from agents
- so/9806_output_lumberjack_fleet.conf.jinja - so/9806_output_lumberjack_fleet.conf.jinja # Logstash to Logstash Output
manager: manager:
- so/0011_input_endgame.conf - so/0011_input_endgame.conf
- so/0012_input_elastic_agent.conf - so/0012_input_elastic_agent.conf # Logs from agents
- so/0013_input_lumberjack_fleet.conf - so/0013_input_lumberjack_fleet.conf # Logstash to Logstash Input
- so/9999_output_redis.conf.jinja - so/9999_output_redis.conf.jinja
receiver: receiver:
- so/0011_input_endgame.conf - so/0011_input_endgame.conf
- so/0012_input_elastic_agent.conf - so/0012_input_elastic_agent.conf # Logs from agents
- so/0013_input_lumberjack_fleet.conf - so/0013_input_lumberjack_fleet.conf # Logstash to Logstash Input
- so/9999_output_redis.conf.jinja - so/9999_output_redis.conf.jinja
search: search:
- so/0900_input_redis.conf.jinja - so/0900_input_redis.conf.jinja
- so/9805_output_elastic_agent.conf.jinja - so/9805_output_elastic_agent.conf.jinja # Elastic Agent data Output to ES (Final)
- so/9900_output_endgame.conf.jinja - so/9900_output_endgame.conf.jinja
custom0: [] custom0: []
custom1: [] custom1: []

View File

@@ -1,7 +1,7 @@
input { input {
elastic_agent { elastic_agent {
port => 5056 port => 5056
tags => [ "elastic-agent" ] tags => [ "elastic-agent", "fleet-lumberjack-input" ]
ssl => true ssl => true
ssl_certificate => "/usr/share/logstash/elasticfleet-lumberjack.crt" ssl_certificate => "/usr/share/logstash/elasticfleet-lumberjack.crt"
ssl_key => "/usr/share/logstash/elasticfleet-lumberjack.key" ssl_key => "/usr/share/logstash/elasticfleet-lumberjack.key"
@@ -10,9 +10,13 @@ input {
codec => "json" codec => "json"
} }
} }
filter { filter {
if "fleet-lumberjack-input" in [tags] {
mutate { mutate {
rename => {"@metadata" => "metadata"} rename => {"@metadata" => "metadata"}
} }
} }
}