Doubt about System Module [Filebeat]

Hi, everyone

I would like to know over which logs Module System is able to parse.

In Filebeat Doc, it shows an example with auth.log and syslog. Is it possible to do it with logs as secure, messages, etc?

From my point of view, it would be better to mention which kind of logs can be used with this module.

Thanks in advance,

Rodrigo :vulcan_salute:


You can configure filebeat to collect and process all possible log files. In this case, you may need to provide your custom processing pipeline.

Hi, @mtojek

My doubt is which logs Module Sytem is able to parse ? only auth.log and syslog ?

Thanks in advance,


Correct. See:

