filebeat.inputs:
- type: log
enabled: true
paths: /path/to/your/radius_logs
multiline.pattern: '^[[:space:]]'
multiline.negate: false
multiline.match: after
output.logstash:
hosts: [ "WASHOSTNAME-elastic.WASSUFFIX:5044" ]
ssl.certificate_authorities: [ "/etc/filebeatssl/certs/ca-certificates.crt" ]
processors:
- add_fields:
target: ''
fields:
logtype: radius
- drop_fields:
fields: [ 'input' , 'host' , 'agent' , 'acs' , 'log' , 'ecs' ]
|