SigmaHQ/tools/config/elk-linux.yml
2020-06-25 13:59:51 +02:00

17 lines
383 B
YAML

title: ELK Linux Indices and Mappings
logsources:
apache:
category: webserver
index: logstash-apache-*
webapp-error:
category: application
index: logstash-apache_error-*
linux-auth:
product: linux
service: auth
index: logstash-auth-*
fieldmappings:
client_ip: clientip
url: request
defaultindex: logstash-*