MozDef/examples/heka-lua-bro-notice/heka.toml

29 строки
655 B
TOML

[bronotice]
type = "LogstreamerInput"
log_directory = "/nsm/bro/spool/manager"
file_match = 'notice\.log'
decoder = "bronotice_transform_decoder"
[bronotice_transform_decoder]
type = "SandboxDecoder"
script_type = "lua"
filename = "bronotice.lua"
# Start commenting here if you don't want any stdout
[stdout]
type = "LogOutput"
message_matcher = "TRUE"
#payload_only = true
# Finish commenting here
[ESJsonEncoder]
index = "events"
es_index_from_timestamp = false
type_name = "event"
[ElasticSearchOutput]
message_matcher = "Type =='bronotice'"
encoder = "ESJsonEncoder"
server = "http://mozdef.example.com:8080"
flush_interval = 1000
flush_count = 10