cat /etc/filebeat/filebeat.yml
filebeat.config.modules:
path: /etc/filebeat/modules.d/*.yml
reload.enabled: false
filebeat.inputs:
- type: log
enabled: false
paths:
- /var/log/*.log
- /home/local/example/example.log
filebeat.registry_file: /var/lib/filebeat/registry
output.elasticsearch:
hosts: ["192.168.100.100:9200"]
ssl.certificate_authorities: ["/etc/pki/tls/certs/beats.crt"]
setup.template.settings:
index:
number_of_shards: 3
setup.kibana:
host: "192.168.100.100:5601"
logging.to_files: true
logging.files:
rotateeverybytes: 10485760 # = 10MB
keepfiles: 7
cat /etc/filebeat/modules.d/system.yml
- module: system
syslog:
enabled: true
var.paths: ["/var/log/syslog*"]
var.convert_timezone: true
auth:
enabled: true
var.paths: ["/var/log/auth.log*"]
var.convert_timezone: true
filebeat modules list
Enabled:
system
Disabled:
apache2
auditd
elasticsearch
icinga
iis
kafka
kibana
logstash
mongodb
mysql
nginx
osquery
postgresql
redis
traefik
Elk server show only
source: /var/log/syslog* and /var/log/auth.log*
Don't show:
source: /home/local/example/example.log
I need also /home/local/example/example.log source logs and syslog both.
What is my wrong?