Files
log_collection_docker/data/syslog-logstash/config/logstash.conf
2022-12-27 21:59:06 +01:00

29 lines
652 B
Plaintext

input {
beats {
port => 5044
}
}
filter {
grok {
match => ["message", "<%{DATA:event_priority}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_process}\[%{NUMBER:syslog_uid}\]: %{DATA:SYSLOGMESSAGE}"]
add_tag => [ "syslog" ]
}
}
output {
#stdout {}
#file {
# path => "/tmp/output.json"
#}
opensearch {
hosts => ["${OPENSEARCH_HOST}"]
index => "${OPENSEARCH_INDEX}-%{+YYYY-MM-dd}"
user => "${LOGSTASH_USER}"
password => "${LOGSTASH_PASSWORD}"
ssl => true
ssl_certificate_verification => false
}
}