From 5754c7908636ba75e2b485ce00606b67f3c3b542 Mon Sep 17 00:00:00 2001 From: t3chn0m4g3 Date: Tue, 13 Nov 2018 15:46:57 +0000 Subject: [PATCH] clean up log sources --- docker/elk/logstash/dist/logstash.conf | 16 ---------------- 1 file changed, 16 deletions(-) diff --git a/docker/elk/logstash/dist/logstash.conf b/docker/elk/logstash/dist/logstash.conf index 8d577415..48301ea3 100644 --- a/docker/elk/logstash/dist/logstash.conf +++ b/docker/elk/logstash/dist/logstash.conf @@ -50,12 +50,6 @@ input { type => "ElasticPot" } -# eMobility - file { - path => ["/data/emobility/log/centralsystemEWS.log"] - type => "eMobility" - } - # Glastopf file { path => ["/data/glastopf/log/glastopf.log"] @@ -231,16 +225,6 @@ filter { } } -# eMobility - if [type] == "eMobility" { - grok { - match => [ "message", "\A%{IP:src_ip}\.%{POSINT:src_port:integer}\|%{IP:dest_ip}\.%{POSINT:dest_port:integer}:%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424SD}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{URIPROTO:http_method}\|%{URIPATH:http_uri}\|%{TIMESTAMP_ISO8601:timestamp}" ] - } - date { - match => [ "timestamp", "ISO8601" ] - } - } - # Glastopf if [type] == "Glastopf" { grok {