vault-es-audit/filebeat.yml
Knut Ahlers 74daa8feb9
Store data on log volume
Signed-off-by: Knut Ahlers <knut@ahlers.me>
2018-01-13 19:47:45 +01:00

30 lines
516 B
YAML

---
filebeat.prospectors:
- type: log
enabled: true
paths:
- /var/log/vault/*.log
json.keys_under_root: true
json.overwrite_keys: true
output.elasticsearch:
hosts:
- ${HOST}
protocol: ${PROTOCOL:http}
username: ${USERNAME:}
password: ${PASSWORD:}
index: "vault-audit-%{+yyyy.MM.dd}"
path.home: /opt/filebeat
path.data: /var/log/vault/es-audit
setup.template.enabled: true
setup.template.name: "vault-audit"
setup.template.pattern: "vault-audit-*"
setup.template.overwrite: true
...