File: //usr/share/filebeat/module/elasticsearch/audit/manifest.yml
module_version: 1.0
var:
- name: paths
default:
- /var/log/elasticsearch/*_access.log
- /var/log/elasticsearch/*_audit.log
- /var/log/elasticsearch/*_audit.json
os.darwin:
- /usr/local/var/lib/elasticsearch/*_access.log
- /usr/local/var/lib/elasticsearch/*_audit.log
- /usr/local/var/lib/elasticsearch/*_audit.json
os.windows:
- c:/ProgramData/Elastic/Elasticsearch/logs/*_access.log
- c:/ProgramData/Elastic/Elasticsearch/logs/*_audit.log
- c:/ProgramData/Elastic/Elasticsearch/logs/*_audit.json
ingest_pipeline:
- ingest/pipeline.yml
- ingest/pipeline-json.yml
- ingest/pipeline-plaintext.yml
input: config/audit.yml