diff --git a/salt/filebeat/etc/filebeat.yml b/salt/filebeat/etc/filebeat.yml index 61c5a7b7c..01febed92 100644 --- a/salt/filebeat/etc/filebeat.yml +++ b/salt/filebeat/etc/filebeat.yml @@ -203,15 +203,14 @@ filebeat.inputs: - type: log paths: - - /wazuh/alerts/alerts.json + - /wazuh/archives/archives.json fields: module: ossec - dataset: alert category: host processors: - drop_fields: fields: ["source", "prospector", "input", "offset", "beat"] - + pipeline: "ossec" fields_under_root: true clean_removed: false close_removed: false