Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- output {
- #Ciso ASA
- if [type] == "cisco-fw" {
- elasticsearch {
- hosts => ["***.***.***.***"]
- index => "asa-%{+YYYY.MM.dd}"
- }
- }
- #filebeat syslog, web-server, and authlog
- if [type] == "syslog" or "web-server" or "authlog" {
- elasticsearch {
- hosts => ["***.***.***.***"]
- sniffing => true
- manage_template => false
- index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
- document_type => "%{[@metadata][type]}"
- }
- }
- } #end
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement