Thanks for the reply.
I will display the results first.
stdout:
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "timestamp" => "Feb 6 16:20:24",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "agent" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "version" => "7.12.1",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "name" => "MY-SERVER",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "hostname" => "MY-SERVER",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "ephemeral_id" => "d4d40b29-a2d6-477d-b275-ce3c6bb2be1a",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "id" => "87215304-c7a1-4914-b057-ef6a368959eb",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "type" => "filebeat"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "@timestamp" => 2024-02-06T07:20:30.758Z,
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "ecs" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "version" => "1.8.0"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "@version" => "1",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "event" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "original" => "Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "message" => "Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "host" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "mac" => [
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: [0] "00:50:56:89:24:4a",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: [1] "00:50:56:89:d8:32"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: ],
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "os" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "version" => "8.6 (Green Obsidian)",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "name" => "Rocky Linux",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "family" => "",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "kernel" => "4.18.0-372.9.1.el8.x86_64",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "platform" => "rocky",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "type" => "linux"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "ip" => [
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: [0] "202.32.104.72",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: [1] "192.168.49.12"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: ],
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "containerized" => false,
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "name" => "MY-SERVER",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "architecture" => "x86_64",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "hostname" => "MY-SERVER",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "id" => "b4a712b2cebb41268aa683d962977dde"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "tags" => [
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: [0] "kin",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: [1] "mail",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: [2] "beats_input_codec_plain_applied"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: ],
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "fields" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "index_name" => "MY-MAIL"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "log" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "file" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "path" => "/var/log/maillog"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "offset" => 3624292
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "logsource" => "MY-SERVER",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "pid" => "2989787",
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "input" => {
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "type" => "log"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: },
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: "process" => "smtp"
Feb 06 16:20:31 ITS-ELST-01 logstash[689501]: }
Elasticsearch(By Kibana)
{
"_index": "MY-MAIL-2024.02.06",
"_id": "fcJKfY0BX2moE9zJNd6f",
"_version": 1,
"_score": 0,
"_source": {
"timestamp": "Feb 6 16:20:24",
"agent": {
"version": "7.12.1",
"name": "MY-SERVER",
"hostname": "MY-SERVER",
"ephemeral_id": "d4d40b29-a2d6-477d-b275-ce3c6bb2be1a",
"id": "87215304-c7a1-4914-b057-ef6a368959eb",
"type": "filebeat"
},
"@timestamp": "2024-02-06T07:20:30.758Z",
"ecs": {
"version": "1.8.0"
},
"@version": "1",
"event": {
"original": "Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)"
},
"message": "Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)",
"host": {
"mac": [
"00:50:56:89:24:4a",
"00:50:56:89:d8:32"
],
"os": {
"version": "8.6 (Green Obsidian)",
"name": "Rocky Linux",
"family": "",
"kernel": "4.18.0-372.9.1.el8.x86_64",
"platform": "rocky",
"type": "linux"
},
"ip": [
"202.32.104.72",
"XXX.XXX.XXX.XXX"
],
"containerized": false,
"name": "MY-SERVER",
"architecture": "x86_64",
"hostname": "MY-SERVER",
"id": "b4a712b2cebb41268aa683d962977dde"
},
"tags": [
"kin",
"mail",
"beats_input_codec_plain_applied"
],
"fields": {
"index_name": "MY-MAIL"
},
"log": {
"file": {
"path": "/var/log/maillog"
},
"offset": 3624292
},
"logsource": "MY-SERVER",
"pid": "2989787",
"input": {
"type": "log"
},
"process": "smtp"
},
"fields": {
"agent.version.keyword": [
"7.12.1"
],
"host.architecture.keyword": [
"x86_64"
],
"host.name.keyword": [
"MY-SERVER"
],
"pid": [
"2989787"
],
"host.hostname": [
"MY-SERVER"
],
"host.mac": [
"00:50:56:89:24:4a",
"00:50:56:89:d8:32"
],
"agent.hostname.keyword": [
"MY-SERVER"
],
"ecs.version.keyword": [
"1.8.0"
],
"host.ip.keyword": [
"202.32.104.72",
"XXX.XXX.XXX.XXX"
],
"fields.index_name": [
"MY-MAIL"
],
"host.os.version": [
"8.6 (Green Obsidian)"
],
"host.os.name": [
"Rocky Linux"
],
"agent.name": [
"MY-SERVER"
],
"host.id.keyword": [
"b4a712b2cebb41268aa683d962977dde"
],
"host.name": [
"MY-SERVER"
],
"host.os.version.keyword": [
"8.6 (Green Obsidian)"
],
"logsource.keyword": [
"MY-SERVER"
],
"event.original": [
"Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)"
],
"host.os.type": [
"linux"
],
"agent.id.keyword": [
"87215304-c7a1-4914-b057-ef6a368959eb"
],
"@version.keyword": [
"1"
],
"input.type": [
"log"
],
"log.offset": [
3624292
],
"agent.hostname": [
"MY-SERVER"
],
"tags": [
"kin",
"mail",
"beats_input_codec_plain_applied"
],
"host.architecture": [
"x86_64"
],
"agent.id": [
"87215304-c7a1-4914-b057-ef6a368959eb"
],
"ecs.version": [
"1.8.0"
],
"host.containerized": [
false
],
"message.keyword": [
"Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)"
],
"fields.index_name.keyword": [
"MY-MAIL"
],
"host.hostname.keyword": [
"MY-SERVER"
],
"agent.version": [
"7.12.1"
],
"host.os.family": [
""
],
"input.type.keyword": [
"log"
],
"tags.keyword": [
"kin",
"mail",
"beats_input_codec_plain_applied"
],
"process.keyword": [
"smtp"
],
"timestamp.keyword": [
"Feb 6 16:20:24"
],
"host.ip": [
"202.32.104.72",
"XXX.XXX.XXX.XXX"
],
"pid.keyword": [
"2989787"
],
"agent.type": [
"filebeat"
],
"host.os.kernel.keyword": [
"4.18.0-372.9.1.el8.x86_64"
],
"host.os.kernel": [
"4.18.0-372.9.1.el8.x86_64"
],
"@version": [
"1"
],
"host.os.name.keyword": [
"Rocky Linux"
],
"host.id": [
"b4a712b2cebb41268aa683d962977dde"
],
"log.file.path.keyword": [
"/var/log/maillog"
],
"agent.type.keyword": [
"filebeat"
],
"timestamp": [
"Feb 6 16:20:24"
],
"agent.ephemeral_id.keyword": [
"d4d40b29-a2d6-477d-b275-ce3c6bb2be1a"
],
"process": [
"smtp"
],
"host.mac.keyword": [
"00:50:56:89:24:4a",
"00:50:56:89:d8:32"
],
"agent.name.keyword": [
"MY-SERVER"
],
"logsource": [
"MY-SERVER"
],
"message": [
"Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)"
],
"host.os.family.keyword": [
""
],
"@timestamp": [
"2024-02-06T07:20:30.758Z"
],
"host.os.type.keyword": [
"linux"
],
"host.os.platform": [
"rocky"
],
"host.os.platform.keyword": [
"rocky"
],
"event.original.keyword": [
"Feb 6 16:20:24 MY-SERVER postfix/smtp[2989787]: B90FEC014ADE: to=<XXXXXX@XXX.XXX.XXX>, relay=mx02.au.com[27.86.106.196]:25, delay=0.22, delays=0.06/0.01/0.07/0.07, dsn=2.0.0, status=sent (250 Ok: queued as DB6471600A3)"
],
"log.file.path": [
"/var/log/maillog"
],
"agent.ephemeral_id": [
"d4d40b29-a2d6-477d-b275-ce3c6bb2be1a"
]
}
}