mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Filebeat - Update for Wazuh logs
This commit is contained in:
@@ -36,6 +36,16 @@ filebeat.prospectors:
|
|||||||
clean_removed: false
|
clean_removed: false
|
||||||
close_removed: false
|
close_removed: false
|
||||||
|
|
||||||
|
- type: log
|
||||||
|
paths:
|
||||||
|
- /alerts/alerts.json
|
||||||
|
fields:
|
||||||
|
type: ossec
|
||||||
|
fields_under_root: true
|
||||||
|
clean_removed: false
|
||||||
|
close_removed: false
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
#----------------------------- Logstash output ---------------------------------
|
#----------------------------- Logstash output ---------------------------------
|
||||||
output.logstash:
|
output.logstash:
|
||||||
@@ -152,7 +162,7 @@ output.logstash:
|
|||||||
|
|
||||||
# Sets log level. The default log level is info.
|
# Sets log level. The default log level is info.
|
||||||
# Available log levels are: error, warning, info, debug
|
# Available log levels are: error, warning, info, debug
|
||||||
#logging.level: info
|
logging.level: debug
|
||||||
|
|
||||||
# Enable debug output for selected components. To enable all selectors use ["*"]
|
# Enable debug output for selected components. To enable all selectors use ["*"]
|
||||||
# Other available selectors are "beat", "publish", "service"
|
# Other available selectors are "beat", "publish", "service"
|
||||||
|
|||||||
Reference in New Issue
Block a user