Skip to content

Commit eb34bc3

Browse files
author
Jose M
committed
Update filebeat.yml
1 parent 6d393f9 commit eb34bc3

1 file changed

Lines changed: 12 additions & 49 deletions

File tree

wazuh/config/filebeat.yml

Lines changed: 12 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -1,53 +1,16 @@
1-
# Wazuh Docker Copyright (C) 2019 Wazuh Inc. (License GPLv2)
2-
filebeat.inputs:
3-
- type: log
4-
paths:
5-
- '/var/ossec/logs/alerts/alerts.json'
1+
2+
# Wazuh - Filebeat configuration file
3+
filebeat.modules:
4+
- module: wazuh
5+
alerts:
6+
enabled: true
7+
archives:
8+
enabled: false
69

710
setup.template.json.enabled: true
8-
setup.template.json.path: "/etc/filebeat/wazuh-template.json"
9-
setup.template.json.name: "wazuh"
11+
setup.template.json.path: '/etc/filebeat/wazuh-template.json'
12+
setup.template.json.name: 'wazuh'
1013
setup.template.overwrite: true
14+
setup.ilm.enabled: false
1115

12-
processors:
13-
- decode_json_fields:
14-
fields: ['message']
15-
process_array: true
16-
max_depth: 200
17-
target: ''
18-
overwrite_keys: true
19-
- drop_fields:
20-
fields: ['message', 'ecs', 'beat', 'input_type', 'tags', 'count', '@version', 'log', 'offset', 'type', 'host']
21-
- rename:
22-
fields:
23-
- from: "data.aws.sourceIPAddress"
24-
to: "@src_ip"
25-
ignore_missing: true
26-
fail_on_error: false
27-
when:
28-
regexp:
29-
data.aws.sourceIPAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
30-
- rename:
31-
fields:
32-
- from: "data.srcip"
33-
to: "@src_ip"
34-
ignore_missing: true
35-
fail_on_error: false
36-
when:
37-
regexp:
38-
data.srcip: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
39-
- rename:
40-
fields:
41-
- from: "data.win.eventdata.ipAddress"
42-
to: "@src_ip"
43-
ignore_missing: true
44-
fail_on_error: false
45-
when:
46-
regexp:
47-
data.win.eventdata.ipAddress: \b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b
48-
49-
output.elasticsearch:
50-
hosts: ['http://elasticsearch:9200']
51-
#pipeline: geoip
52-
indices:
53-
- index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}'
16+
output.elasticsearch.hosts: ['http://elasticsearch:9200']

0 commit comments

Comments
 (0)