vault-es-audit/filebeat.yml

30 lines
516 B
YAML
Raw Normal View History

---
filebeat.prospectors:
- type: log
enabled: true
paths:
- /var/log/vault/*.log
json.keys_under_root: true
json.overwrite_keys: true
output.elasticsearch:
hosts:
- ${HOST}
protocol: ${PROTOCOL:http}
username: ${USERNAME:}
password: ${PASSWORD:}
index: "vault-audit-%{+yyyy.MM.dd}"
path.home: /opt/filebeat
path.data: /var/log/vault/es-audit
setup.template.enabled: true
setup.template.name: "vault-audit"
setup.template.pattern: "vault-audit-*"
setup.template.overwrite: true
...