Files
securityonion/salt/elasticfleet/files/integrations/grid-nodes_general/syslog-udp-514.json
2025-02-18 10:40:18 -06:00

37 lines
932 B
JSON

{
"package": {
"name": "udp",
"version": ""
},
"name": "syslog-udp-514",
"namespace": "so",
"description": "Syslog over UDP Port 514",
"policy_id": "so-grid-nodes_general",
"inputs": {
"udp-udp": {
"enabled": true,
"streams": {
"udp.udp": {
"enabled": true,
"vars": {
"listen_address": "0.0.0.0",
"listen_port": "514",
"data_stream.dataset": "syslog",
"pipeline": "syslog",
"max_message_size": "10KiB",
"keep_null": false,
"processors": "- add_fields:\n target: event\n fields: \n module: syslog",
"tags": [
"syslog"
],
"syslog_options": "field: message\n#format: auto\n#timezone: Local\n",
"preserve_original_event": false,
"custom": ""
}
}
}
}
},
"force": true
}