Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- input {
- beats {
- port => "5050"
- }
- beats {
- port => "5051"
- }
- }
- filter {
- grok {
- match => {
- "message" => '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} \[%{HTTPDATE:timestamp}\] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{QS:agent}'
- }
- }
- date {
- match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
- target => "@timestamp"
- locale => en
- }
- geoip {
- source => "clientip"
- }
- useragent {
- source => "agent"
- target => "useragent"
- }
- }
- output {
- stdout {
- codec => dots
- }
- elasticsearch {
- hosts => ["10.0.2.4:9200"]
- index => "apache_example"
- template => "/home/ubuntu/Documents/apache_example/apache_template.json"
- template_name => "apache_template"
- template_overwrite => true
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement