Here is one sanitized event from the file output:
{"@timestamp":"2021-03-29T16:16:18.558Z","@metadata":{"beat":"filebeat","type":"_doc","version":"7.12.0","pipeline":"filebeat-7.12.0-cisco-amp-pipeline","_id":"bc92555d02c032dad9f8fcb565275eb2c6e9fda56590bed750e84693688b720b"},"message":"{\"data\":{\"computer\":{\"active\":true,\"connector_guid\":\"REDACTED\",\"external_ip\":\"REDACTED\",\"hostname\":\"REDACTED.contoso.com\",\"links\":{\"computer\":\"https://api.amp.cisco.com/v1/computers/REDACTED\",\"group\":\"https://api.amp.cisco.com/v1/groups/REDACTED\",\"trajectory\":\"https://api.amp.cisco.com/v1/computers/REDACTED/trajectory\"},\"network_addresses\":[{\"ip\":\"REDACTED\",\"mac\":\"REDACTED\"}]},\"connector_guid\":\"REDACTED\",\"date\":\"2021-03-28T14:01:04+00:00\",\"event_type\":\"Scan Started\",\"event_type_id\":554696714,\"group_guids\":[\"REDACTED\"],\"id\":6944704694472147000,\"scan\":{\"description\":\"Flash Scan\"},\"timestamp\":1616940064,\"timestamp_nanoseconds\":486000000},\"metadata\":{\"links\":{\"next\":\"https://api.amp.cisco.com/v1/events?limit=100\\u0026start_date=2021-03-25T16%3A14%3A53%2B00%3A00\\u0026offset=9000\",\"prev\":\"https://api.amp.cisco.com/v1/events?limit=100\\u0026start_date=2021-03-25T16%3A14%3A53%2B00%3A00\\u0026offset=8800\",\"self\":\"https://api.amp.cisco.com/v1/events?limit=100\\u0026start_date=2021-03-25T16%3A14%3A53%2B00%3A00\\u0026offset=8900\"},\"results\":{\"current_item_count\":100,\"index\":8900,\"items_per_page\":100,\"total\":31347}},\"version\":\"v1.2.0\"}","ecs":{"version":"1.7.0"},"event":{"dataset":"cisco.amp","timezone":"PDT","created":"2021-03-29T16:16:18.558Z","module":"cisco"},"fileset":{"name":"amp"},"service":{"type":"cisco"},"input":{"type":"httpjson"},"json":{"metadata":{"links":{"self":"https://api.amp.cisco.com/v1/events?limit=100&start_date=2021-03-25T16%3A14%3A53%2B00%3A00&offset=8900","next":"https://api.amp.cisco.com/v1/events?limit=100&start_date=2021-03-25T16%3A14%3A53%2B00%3A00&offset=9000","prev":"https://api.amp.cisco.com/v1/events?limit=100&start_date=2021-03-25T16%3A14%3A53%2B00%3A00&offset=8800"},"results":{"current_item_count":100,"index":8900,"items_per_page":100,"total":31347}},"version":"v1.2.0","data":{"connector_guid":"REDACTED","date":"2021-03-28T14:01:04+00:00","id":6944704694472147000,"timestamp":1616940064,"timestamp_nanoseconds":486000000,"computer":{"active":true,"connector_guid":"REDACTED","external_ip":"REDACTED","hostname":"REDACTED.contoso.com","links":{"group":"https://api.amp.cisco.com/v1/groups/REDACTED","trajectory":"https://api.amp.cisco.com/v1/computers/REDACTED/trajectory","computer":"https://api.amp.cisco.com/v1/computers/REDACTED"},"network_addresses":[{"ip":"REDACTED","mac":"REDACTED"}]},"event_type":"Scan Started","event_type_id":554696714,"group_guids":["REDACTED"],"scan":{"description":"Flash Scan"}}},"agent":{"name":"REDACTED","type":"filebeat","version":"7.12.0","hostname":"REDACTED","ephemeral_id":"REDACTED","id":"REDACTED"},"host":{"hostname":"REDACTED","architecture":"x86_64","os":{"family":"debian","name":"Ubuntu","kernel":"5.4.0-70-generic","codename":"focal","type":"linux","platform":"ubuntu","version":"20.04.2 LTS (Focal Fossa)"},"id":"b78fd072ff7d4ab48cd30bbf3951b041","containerized":false,"ip":["REDACTED","REDACTED"],"mac":["REDACTED"]},"tags":["cisco-amp","forwarded"]}
Let me know if you would like me to grab more.