Advertisement
Guest User

Untitled

a guest
Jul 19th, 2020
493
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.35 KB | None | 0 0
  1. input{
  2. beats{
  3. port => 5044
  4. }
  5. }
  6. filter {
  7. if [log][file][path] =~ "/var/log/commands.log" {
  8. grok{
  9. match => { "message" => "\[(%{TIMESTAMP_ISO8601:sys_timestamp})\]\s(?<field1>[0-9a-zA-Z_-]+)\s(?<field2>[0-9a-zA-Z_-]+)\:USER=(?<fi$
  10. }
  11. }
  12. }
  13. }
  14. output{
  15. elasticsearch {
  16. # manage_template => false
  17. hosts => ["localhost:9200"]
  18. index => "cleandata"
  19. }
  20. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement