--- filebeat.prospectors: - type: log enabled: true paths: - /var/log/vault/*.log json.keys_under_root: true json.overwrite_keys: true output.elasticsearch: hosts: - ${HOST} protocol: ${PROTOCOL:http} username: ${USERNAME:} password: ${PASSWORD:} index: "vault-audit-%{+yyyy.MM.dd}" path.home: /opt/filebeat path.data: /var/log/vault/es-audit setup.template.enabled: true setup.template.name: "vault-audit" setup.template.pattern: "vault-audit-*" setup.template.overwrite: true ...