Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #! this request accesses system indices: [.fleet-policies-7], but in a future major version, direct access to system indices will be prevented by default
- {
- "took": 97,
- "timed_out": false,
- "_shards": {
- "total": 1,
- "successful": 1,
- "skipped": 0,
- "failed": 0
- },
- "hits": {
- "total": {
- "value": 19,
- "relation": "eq"
- },
- "max_score": 0.7907857,
- "hits": [
- {
- "_index": ".fleet-policies-7",
- "_id": "812474c4-8530-4af6-bf84-5dc154308a8e",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:58:55.260Z",
- "revision_idx": 4,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "https://****:9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "fleet-server-fleet_server-13bcfd99-a40a-4b46-9bd9-395f76a0f0fa",
- "revision": 1,
- "name": "fleet_server-1",
- "type": "fleet-server",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "server": {
- "port": 8220,
- "host": "172.24.54.23"
- },
- "meta": {
- "package": {
- "name": "fleet_server",
- "version": "1.2.0"
- }
- }
- }
- ],
- "revision": 4,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "9d934285-27c2-42af-9938-904f294f47af",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:57:54.791Z",
- "revision_idx": 3,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "https://****:9200"
- ]
- }
- },
- "inputs": [],
- "revision": 3,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "06769482-d075-4a88-bbe3-f0baf2df2adb",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:57:32.374Z",
- "revision_idx": 2,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "https://****9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "fleet-server-fleet_server-7baac62d-e019-4ea3-b23f-7b741cb6fd7f",
- "revision": 1,
- "name": "fleet_server-1",
- "type": "fleet-server",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "server": {
- "port": 8220,
- "host": "0.0.0.0"
- },
- "meta": {
- "package": {
- "name": "fleet_server",
- "version": "1.2.0"
- }
- }
- }
- ],
- "revision": 2,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "55792ad3-36f3-4592-b1dc-a311fde2a1df",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-15T12:41:14.552Z",
- "revision_idx": 1,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "http://localhost:9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "fleet-server-fleet_server-ea8e9eb8-234c-475b-b8ea-08335ab5057e",
- "revision": 1,
- "name": "fleet_server-2",
- "type": "fleet-server",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "server": {
- "port": 8220,
- "host": "0.0.0.0"
- },
- "meta": {
- "package": {
- "name": "fleet_server",
- "version": "1.2.0"
- }
- }
- },
- {
- "id": "logfile-system-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "revision": 1,
- "name": "system-2",
- "type": "logfile",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "logfile-system.auth-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "logs",
- "dataset": "system.auth"
- },
- "paths": [
- "/var/log/auth.log*",
- "/var/log/secure*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- },
- {
- "id": "logfile-system.syslog-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "logs",
- "dataset": "system.syslog"
- },
- "paths": [
- "/var/log/messages*",
- "/var/log/syslog*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "winlog-system-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "revision": 1,
- "name": "system-2",
- "type": "winlog",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "winlog-system.application-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "logs",
- "dataset": "system.application"
- },
- "name": "Application",
- "condition": "${host.platform} == 'windows'",
- "ignore_older": "72h",
- "tags": null
- },
- {
- "id": "winlog-system.security-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "logs",
- "dataset": "system.security"
- },
- "name": "Security",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- },
- {
- "id": "winlog-system.system-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "logs",
- "dataset": "system.system"
- },
- "name": "System",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "system/metrics-system-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "revision": 1,
- "name": "system-2",
- "type": "system/metrics",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "system/metrics-system.filesystem-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.filesystem"
- },
- "metricsets": [
- "filesystem"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.filesystem.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.cpu-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.cpu"
- },
- "metricsets": [
- "cpu"
- ],
- "cpu.metrics": [
- "percentages",
- "normalized_percentages"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.process-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process"
- },
- "metricsets": [
- "process"
- ],
- "period": "10s",
- "process.include_top_n.by_cpu": 5,
- "process.include_top_n.by_memory": 5,
- "process.cmdline.cache.enabled": true,
- "process.cgroups.enabled": false,
- "process.include_cpu_ticks": false,
- "processes": [
- ".*"
- ]
- },
- {
- "id": "system/metrics-system.fsstat-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.fsstat"
- },
- "metricsets": [
- "fsstat"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.fsstat.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.socket_summary-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.socket_summary"
- },
- "metricsets": [
- "socket_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.network-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.network"
- },
- "metricsets": [
- "network"
- ],
- "period": "10s",
- "network.interfaces": null
- },
- {
- "id": "system/metrics-system.memory-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.memory"
- },
- "metricsets": [
- "memory"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.load-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.load"
- },
- "metricsets": [
- "load"
- ],
- "condition": "${host.platform} != 'windows'",
- "period": "10s"
- },
- {
- "id": "system/metrics-system.process.summary-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process.summary"
- },
- "metricsets": [
- "process_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.diskio-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.diskio"
- },
- "metricsets": [
- "diskio"
- ],
- "diskio.include_devices": null,
- "period": "10s"
- },
- {
- "id": "system/metrics-system.uptime-a45c03f4-aac3-4314-941a-5d61bba5e610",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.uptime"
- },
- "metricsets": [
- "uptime"
- ],
- "period": "10s"
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- }
- ],
- "revision": 1,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- },
- "a45c03f4-aac3-4314-941a-5d61bba5e610": {
- "indices": [
- {
- "names": [
- "logs-system.auth-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.syslog-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.application-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.system-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.filesystem-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.cpu-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.fsstat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.socket_summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.network-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.memory-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.load-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process.summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.diskio-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.uptime-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- }
- }
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "8ccc109b-a0a8-4bef-882e-5e278f3ea500",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-15T12:41:07.771Z",
- "revision_idx": 1,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "http://localhost:9200"
- ]
- }
- },
- "inputs": [],
- "revision": 1,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- }
- }
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "d2356447-f51f-4817-83fb-d56f5a00dd67",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:38:45.894Z",
- "revision_idx": 2,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "http://****:9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "fleet-server-fleet_server-fa8e0d60-8e68-4dab-84f1-faff3f2a12c5",
- "revision": 1,
- "name": "fleet_server-1",
- "type": "fleet-server",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "server": {
- "port": 8220,
- "host": "0.0.0.0"
- },
- "meta": {
- "package": {
- "name": "fleet_server",
- "version": "1.2.0"
- }
- }
- },
- {
- "id": "logfile-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "logfile",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "logfile-system.auth-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.auth"
- },
- "paths": [
- "/var/log/auth.log*",
- "/var/log/secure*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- },
- {
- "id": "logfile-system.syslog-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.syslog"
- },
- "paths": [
- "/var/log/messages*",
- "/var/log/syslog*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "winlog-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "winlog",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "winlog-system.security-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.security"
- },
- "name": "Security",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- },
- {
- "id": "winlog-system.application-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.application"
- },
- "name": "Application",
- "condition": "${host.platform} == 'windows'",
- "ignore_older": "72h",
- "tags": null
- },
- {
- "id": "winlog-system.system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.system"
- },
- "name": "System",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "system/metrics-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "system/metrics",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "system/metrics-system.cpu-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.cpu"
- },
- "metricsets": [
- "cpu"
- ],
- "cpu.metrics": [
- "percentages",
- "normalized_percentages"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.network-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.network"
- },
- "metricsets": [
- "network"
- ],
- "period": "10s",
- "network.interfaces": null
- },
- {
- "id": "system/metrics-system.socket_summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.socket_summary"
- },
- "metricsets": [
- "socket_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.uptime-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.uptime"
- },
- "metricsets": [
- "uptime"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.diskio-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.diskio"
- },
- "metricsets": [
- "diskio"
- ],
- "diskio.include_devices": null,
- "period": "10s"
- },
- {
- "id": "system/metrics-system.memory-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.memory"
- },
- "metricsets": [
- "memory"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.fsstat-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.fsstat"
- },
- "metricsets": [
- "fsstat"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.fsstat.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.filesystem-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.filesystem"
- },
- "metricsets": [
- "filesystem"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.filesystem.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.process.summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process.summary"
- },
- "metricsets": [
- "process_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.process-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process"
- },
- "metricsets": [
- "process"
- ],
- "period": "10s",
- "process.include_top_n.by_cpu": 5,
- "process.include_top_n.by_memory": 5,
- "process.cmdline.cache.enabled": true,
- "process.cgroups.enabled": false,
- "process.include_cpu_ticks": false,
- "processes": [
- ".*"
- ]
- },
- {
- "id": "system/metrics-system.load-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.load"
- },
- "metricsets": [
- "load"
- ],
- "condition": "${host.platform} != 'windows'",
- "period": "10s"
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- }
- ],
- "revision": 2,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- },
- "c7c94db7-48d8-4ccb-935c-e13f6d166860": {
- "indices": [
- {
- "names": [
- "logs-system.auth-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.syslog-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.application-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.system-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.cpu-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.network-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.socket_summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.uptime-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.diskio-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.memory-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.fsstat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.filesystem-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process.summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.load-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "3fb600c8-e541-411e-af61-fe2032360ba8",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:51:48.767Z",
- "revision_idx": 1,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "https://****:9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "fleet-server-fleet_server-7baac62d-e019-4ea3-b23f-7b741cb6fd7f",
- "revision": 1,
- "name": "fleet_server-1",
- "type": "fleet-server",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "server": {
- "port": 8220,
- "host": "0.0.0.0"
- },
- "meta": {
- "package": {
- "name": "fleet_server",
- "version": "1.2.0"
- }
- }
- },
- {
- "id": "logfile-system-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "revision": 1,
- "name": "system-1",
- "type": "logfile",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "logfile-system.auth-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "logs",
- "dataset": "system.auth"
- },
- "paths": [
- "/var/log/auth.log*",
- "/var/log/secure*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- },
- {
- "id": "logfile-system.syslog-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "logs",
- "dataset": "system.syslog"
- },
- "paths": [
- "/var/log/messages*",
- "/var/log/syslog*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "winlog-system-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "revision": 1,
- "name": "system-1",
- "type": "winlog",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "winlog-system.security-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "logs",
- "dataset": "system.security"
- },
- "name": "Security",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- },
- {
- "id": "winlog-system.application-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "logs",
- "dataset": "system.application"
- },
- "name": "Application",
- "condition": "${host.platform} == 'windows'",
- "ignore_older": "72h",
- "tags": null
- },
- {
- "id": "winlog-system.system-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "logs",
- "dataset": "system.system"
- },
- "name": "System",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "system/metrics-system-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "revision": 1,
- "name": "system-1",
- "type": "system/metrics",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "system/metrics-system.cpu-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.cpu"
- },
- "metricsets": [
- "cpu"
- ],
- "cpu.metrics": [
- "percentages",
- "normalized_percentages"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.network-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.network"
- },
- "metricsets": [
- "network"
- ],
- "period": "10s",
- "network.interfaces": null
- },
- {
- "id": "system/metrics-system.socket_summary-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.socket_summary"
- },
- "metricsets": [
- "socket_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.uptime-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.uptime"
- },
- "metricsets": [
- "uptime"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.diskio-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.diskio"
- },
- "metricsets": [
- "diskio"
- ],
- "diskio.include_devices": null,
- "period": "10s"
- },
- {
- "id": "system/metrics-system.memory-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.memory"
- },
- "metricsets": [
- "memory"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.fsstat-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.fsstat"
- },
- "metricsets": [
- "fsstat"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.fsstat.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.filesystem-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.filesystem"
- },
- "metricsets": [
- "filesystem"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.filesystem.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.process.summary-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process.summary"
- },
- "metricsets": [
- "process_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.process-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process"
- },
- "metricsets": [
- "process"
- ],
- "period": "10s",
- "process.include_top_n.by_cpu": 5,
- "process.include_top_n.by_memory": 5,
- "process.cmdline.cache.enabled": true,
- "process.cgroups.enabled": false,
- "process.include_cpu_ticks": false,
- "processes": [
- ".*"
- ]
- },
- {
- "id": "system/metrics-system.load-c75cb103-8b4a-453c-9a57-ca351fa69141",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.load"
- },
- "metricsets": [
- "load"
- ],
- "condition": "${host.platform} != 'windows'",
- "period": "10s"
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- }
- ],
- "revision": 1,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- },
- "c75cb103-8b4a-453c-9a57-ca351fa69141": {
- "indices": [
- {
- "names": [
- "logs-system.auth-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.syslog-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.application-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.system-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.cpu-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.network-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.socket_summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.uptime-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.diskio-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.memory-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.fsstat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.filesystem-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process.summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.load-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "bf8b4145-ee98-415e-8579-7afdb1fa37f0",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:17:29.142Z",
- "revision_idx": 1,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "http://localhost:9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "fleet-server-fleet_server-fa8e0d60-8e68-4dab-84f1-faff3f2a12c5",
- "revision": 1,
- "name": "fleet_server-1",
- "type": "fleet-server",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "server": {
- "port": 8220,
- "host": "0.0.0.0"
- },
- "meta": {
- "package": {
- "name": "fleet_server",
- "version": "1.2.0"
- }
- }
- },
- {
- "id": "logfile-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "logfile",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "logfile-system.auth-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.auth"
- },
- "paths": [
- "/var/log/auth.log*",
- "/var/log/secure*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- },
- {
- "id": "logfile-system.syslog-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.syslog"
- },
- "paths": [
- "/var/log/messages*",
- "/var/log/syslog*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "winlog-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "winlog",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "winlog-system.security-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.security"
- },
- "name": "Security",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- },
- {
- "id": "winlog-system.application-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.application"
- },
- "name": "Application",
- "condition": "${host.platform} == 'windows'",
- "ignore_older": "72h",
- "tags": null
- },
- {
- "id": "winlog-system.system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.system"
- },
- "name": "System",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "system/metrics-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "system/metrics",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "system/metrics-system.cpu-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.cpu"
- },
- "metricsets": [
- "cpu"
- ],
- "cpu.metrics": [
- "percentages",
- "normalized_percentages"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.network-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.network"
- },
- "metricsets": [
- "network"
- ],
- "period": "10s",
- "network.interfaces": null
- },
- {
- "id": "system/metrics-system.socket_summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.socket_summary"
- },
- "metricsets": [
- "socket_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.uptime-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.uptime"
- },
- "metricsets": [
- "uptime"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.diskio-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.diskio"
- },
- "metricsets": [
- "diskio"
- ],
- "diskio.include_devices": null,
- "period": "10s"
- },
- {
- "id": "system/metrics-system.memory-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.memory"
- },
- "metricsets": [
- "memory"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.fsstat-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.fsstat"
- },
- "metricsets": [
- "fsstat"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.fsstat.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.filesystem-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.filesystem"
- },
- "metricsets": [
- "filesystem"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.filesystem.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.process.summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process.summary"
- },
- "metricsets": [
- "process_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.process-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process"
- },
- "metricsets": [
- "process"
- ],
- "period": "10s",
- "process.include_top_n.by_cpu": 5,
- "process.include_top_n.by_memory": 5,
- "process.cmdline.cache.enabled": true,
- "process.cgroups.enabled": false,
- "process.include_cpu_ticks": false,
- "processes": [
- ".*"
- ]
- },
- {
- "id": "system/metrics-system.load-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.load"
- },
- "metricsets": [
- "load"
- ],
- "condition": "${host.platform} != 'windows'",
- "period": "10s"
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- }
- ],
- "revision": 1,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- },
- "c7c94db7-48d8-4ccb-935c-e13f6d166860": {
- "indices": [
- {
- "names": [
- "logs-system.auth-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.syslog-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.application-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.system-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.cpu-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.network-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.socket_summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.uptime-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.diskio-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.memory-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.fsstat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.filesystem-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process.summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.load-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "e3c8381d-077a-4bb3-9365-30c78f2d375c",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:42:55.092Z",
- "revision_idx": 3,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "https://****:9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "fleet-server-fleet_server-fa8e0d60-8e68-4dab-84f1-faff3f2a12c5",
- "revision": 1,
- "name": "fleet_server-1",
- "type": "fleet-server",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "server": {
- "port": 8220,
- "host": "0.0.0.0"
- },
- "meta": {
- "package": {
- "name": "fleet_server",
- "version": "1.2.0"
- }
- }
- },
- {
- "id": "logfile-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "logfile",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "logfile-system.auth-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.auth"
- },
- "paths": [
- "/var/log/auth.log*",
- "/var/log/secure*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- },
- {
- "id": "logfile-system.syslog-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.syslog"
- },
- "paths": [
- "/var/log/messages*",
- "/var/log/syslog*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "winlog-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "winlog",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "winlog-system.security-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.security"
- },
- "name": "Security",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- },
- {
- "id": "winlog-system.application-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.application"
- },
- "name": "Application",
- "condition": "${host.platform} == 'windows'",
- "ignore_older": "72h",
- "tags": null
- },
- {
- "id": "winlog-system.system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.system"
- },
- "name": "System",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "system/metrics-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "system/metrics",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "system/metrics-system.cpu-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.cpu"
- },
- "metricsets": [
- "cpu"
- ],
- "cpu.metrics": [
- "percentages",
- "normalized_percentages"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.network-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.network"
- },
- "metricsets": [
- "network"
- ],
- "period": "10s",
- "network.interfaces": null
- },
- {
- "id": "system/metrics-system.socket_summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.socket_summary"
- },
- "metricsets": [
- "socket_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.uptime-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.uptime"
- },
- "metricsets": [
- "uptime"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.diskio-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.diskio"
- },
- "metricsets": [
- "diskio"
- ],
- "diskio.include_devices": null,
- "period": "10s"
- },
- {
- "id": "system/metrics-system.memory-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.memory"
- },
- "metricsets": [
- "memory"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.fsstat-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.fsstat"
- },
- "metricsets": [
- "fsstat"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.fsstat.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.filesystem-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.filesystem"
- },
- "metricsets": [
- "filesystem"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.filesystem.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.process.summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process.summary"
- },
- "metricsets": [
- "process_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.process-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process"
- },
- "metricsets": [
- "process"
- ],
- "period": "10s",
- "process.include_top_n.by_cpu": 5,
- "process.include_top_n.by_memory": 5,
- "process.cmdline.cache.enabled": true,
- "process.cgroups.enabled": false,
- "process.include_cpu_ticks": false,
- "processes": [
- ".*"
- ]
- },
- {
- "id": "system/metrics-system.load-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.load"
- },
- "metricsets": [
- "load"
- ],
- "condition": "${host.platform} != 'windows'",
- "period": "10s"
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- }
- ],
- "revision": 3,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- },
- "c7c94db7-48d8-4ccb-935c-e13f6d166860": {
- "indices": [
- {
- "names": [
- "logs-system.auth-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.syslog-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.application-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.system-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.cpu-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.network-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.socket_summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.uptime-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.diskio-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.memory-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.fsstat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.filesystem-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process.summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.load-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- },
- {
- "_index": ".fleet-policies-7",
- "_id": "816ae16c-939e-4bf2-80d2-f927231d09ff",
- "_score": 0.7907857,
- "_source": {
- "@timestamp": "2022-11-16T15:49:11.678Z",
- "revision_idx": 4,
- "coordinator_idx": 0,
- "data": {
- "id": "fleet-server-policy",
- "outputs": {
- "default": {
- "type": "elasticsearch",
- "hosts": [
- "https://****:9200"
- ]
- }
- },
- "inputs": [
- {
- "id": "logfile-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "logfile",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "logfile-system.auth-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.auth"
- },
- "paths": [
- "/var/log/auth.log*",
- "/var/log/secure*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- },
- {
- "id": "logfile-system.syslog-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.syslog"
- },
- "paths": [
- "/var/log/messages*",
- "/var/log/syslog*"
- ],
- "exclude_files": [
- ".gz$"
- ],
- "multiline": {
- "pattern": """^\s""",
- "match": "after"
- },
- "processors": [
- {
- "add_locale": null
- }
- ]
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "winlog-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "winlog",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "winlog-system.security-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.security"
- },
- "name": "Security",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- },
- {
- "id": "winlog-system.application-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.application"
- },
- "name": "Application",
- "condition": "${host.platform} == 'windows'",
- "ignore_older": "72h",
- "tags": null
- },
- {
- "id": "winlog-system.system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "logs",
- "dataset": "system.system"
- },
- "name": "System",
- "condition": "${host.platform} == 'windows'",
- "tags": null
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- },
- {
- "id": "system/metrics-system-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "revision": 1,
- "name": "system-1",
- "type": "system/metrics",
- "data_stream": {
- "namespace": "default"
- },
- "use_output": "default",
- "streams": [
- {
- "id": "system/metrics-system.cpu-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.cpu"
- },
- "metricsets": [
- "cpu"
- ],
- "cpu.metrics": [
- "percentages",
- "normalized_percentages"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.network-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.network"
- },
- "metricsets": [
- "network"
- ],
- "period": "10s",
- "network.interfaces": null
- },
- {
- "id": "system/metrics-system.socket_summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.socket_summary"
- },
- "metricsets": [
- "socket_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.uptime-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.uptime"
- },
- "metricsets": [
- "uptime"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.diskio-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.diskio"
- },
- "metricsets": [
- "diskio"
- ],
- "diskio.include_devices": null,
- "period": "10s"
- },
- {
- "id": "system/metrics-system.memory-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.memory"
- },
- "metricsets": [
- "memory"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.fsstat-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.fsstat"
- },
- "metricsets": [
- "fsstat"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.fsstat.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.filesystem-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.filesystem"
- },
- "metricsets": [
- "filesystem"
- ],
- "period": "1m",
- "processors": [
- {
- "drop_event.when.regexp": {
- "system.filesystem.mount_point": "^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)"
- }
- }
- ]
- },
- {
- "id": "system/metrics-system.process.summary-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process.summary"
- },
- "metricsets": [
- "process_summary"
- ],
- "period": "10s"
- },
- {
- "id": "system/metrics-system.process-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.process"
- },
- "metricsets": [
- "process"
- ],
- "period": "10s",
- "process.include_top_n.by_cpu": 5,
- "process.include_top_n.by_memory": 5,
- "process.cmdline.cache.enabled": true,
- "process.cgroups.enabled": false,
- "process.include_cpu_ticks": false,
- "processes": [
- ".*"
- ]
- },
- {
- "id": "system/metrics-system.load-c7c94db7-48d8-4ccb-935c-e13f6d166860",
- "data_stream": {
- "type": "metrics",
- "dataset": "system.load"
- },
- "metricsets": [
- "load"
- ],
- "condition": "${host.platform} != 'windows'",
- "period": "10s"
- }
- ],
- "meta": {
- "package": {
- "name": "system",
- "version": "1.6.4"
- }
- }
- }
- ],
- "revision": 4,
- "agent": {
- "download": {
- "source_uri": "https://artifacts.elastic.co/downloads/"
- },
- "monitoring": {
- "namespace": "default",
- "use_output": "default",
- "enabled": true,
- "logs": true,
- "metrics": true
- }
- },
- "output_permissions": {
- "default": {
- "_elastic_agent_monitoring": {
- "indices": [
- {
- "names": [
- "metrics-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.apm_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.auditbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.filebeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.cloudbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.metricbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.packetbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.fleet_server-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.heartbeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.osquerybeat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.elastic_agent-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-elastic_agent.endpoint_security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- },
- "_elastic_agent_checks": {
- "cluster": [
- "monitor"
- ]
- },
- "c7c94db7-48d8-4ccb-935c-e13f6d166860": {
- "indices": [
- {
- "names": [
- "logs-system.auth-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.syslog-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.security-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.application-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "logs-system.system-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.cpu-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.network-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.socket_summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.uptime-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.diskio-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.memory-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.fsstat-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.filesystem-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process.summary-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.process-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- },
- {
- "names": [
- "metrics-system.load-default"
- ],
- "privileges": [
- "auto_configure",
- "create_doc"
- ]
- }
- ]
- }
- }
- },
- "fleet": {
- "hosts": [
- "https://172.24.54.23:8220"
- ]
- }
- },
- "policy_id": "fleet-server-policy",
- "default_fleet_server": true
- }
- }
- ]
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement