mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-07-02 01:27:27 -04:00
tweaking
This commit is contained in:
19
docker/elk/logstash/dist/http_input.conf
vendored
Normal file
19
docker/elk/logstash/dist/http_input.conf
vendored
Normal file
@ -0,0 +1,19 @@
|
||||
# Input section
|
||||
input {
|
||||
http {
|
||||
id => "tpot"
|
||||
host => "0.0.0.0"
|
||||
port => "80"
|
||||
}
|
||||
}
|
||||
|
||||
# Output section
|
||||
output {
|
||||
elasticsearch {
|
||||
hosts => ["elasticsearch:9200"]
|
||||
# With templates now being legacy and ILM in place we need to set the daily index with its template manually. Otherwise a new index might be created with differents settings configured through Kibana.
|
||||
index => "logstash-%{+YYYY.MM.dd}"
|
||||
template => "/etc/logstash/tpot_es_template.json"
|
||||
}
|
||||
|
||||
}
|
Reference in New Issue
Block a user