filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
- /var/log/*messages*
- /var/log/secure
- /var/apache-tomcat-8.5.23/logs/catalina*
- /var/apache-tomcat-8.5.23/logs/*.log
### Multiline options
# Mutiline can be used for log messages spanning multiple lines. This is common
# for Java Stack Traces or C-Line Continuation
# The regexp Pattern that has to be matched. The example pattern matches all lines starting with [
# multiline.pattern: ^[0-9]{2}-(?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)?|May|Jun(?:e)?|Jul(?:y)?|Aug(?:ust)?|Sep(?:tember)?|Sept|Oct(?:ober)?|Nov(?:ember)?|Dec(?:ember)?)-[0-9]{4}
# multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
#multiline.pattern: ^[0-9]{2}-(?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)?|May|Jun(?:e)?|Jul(?:y)?|Aug(?:ust)?|Sep(?:tember)?|Sept|Oct(?:ober)?|Nov(?:ember)?|Dec(?:ember)?)-[0-9]{4}
#multiline.negate: true
#multiline.match: after
multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
multiline.negate: false
multiline.match: after
filebeat.config.modules:
path: ${path.config}/modules.d/*.yml
reload.enabled: true
setup.template.settings:
index.number_of_shards: 3
setup.kibana:
host: "xxxxx"
output.logstash:
hosts: ["xxxxxx"]
processors:
- add_host_metadata: ~
- add_cloud_metadata: ~
xpack.monitoring.elasticsearch.hosts: ["https://xxxxxx"]