mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-04-29 19:58:52 +00:00
20 lines
481 B
Text
20 lines
481 B
Text
![]() |
# Input section
|
||
|
input {
|
||
|
http {
|
||
|
id => "tpot"
|
||
|
host => "0.0.0.0"
|
||
|
port => "80"
|
||
|
}
|
||
|
}
|
||
|
|
||
|
# Output section
|
||
|
output {
|
||
|
elasticsearch {
|
||
|
hosts => ["elasticsearch:9200"]
|
||
|
# With templates now being legacy and ILM in place we need to set the daily index with its template manually. Otherwise a new index might be created with differents settings configured through Kibana.
|
||
|
index => "logstash-%{+YYYY.MM.dd}"
|
||
|
template => "/etc/logstash/tpot_es_template.json"
|
||
|
}
|
||
|
|
||
|
}
|