Files
securityonion/salt/logstash/files/dynamic/0006_input_beats.conf
2019-11-19 15:02:35 -05:00

24 lines
493 B
Plaintext

input {
beats {
port => "5044"
ssl => false
ssl_certificate_authorities => ["/usr/share/filebeat/ca.crt"]
ssl_certificate => "/usr/share/logstash/filebeat.crt"
ssl_key => "/usr/share/logstash/filebeat.key"
tags => [ "beat" ]
}
}
filter {
if [type] == "osquery" {
mutate {
rename => { "host" => "beat_host" }
remove_tag => ["beat"]
add_tag => ["osquery"]
}
json {
source => "message"
target => "osquery"
}
}
}