Skip to content

Instantly share code, notes, and snippets.

Created November 7, 2014 14:12
Show Gist options
  • Save anonymous/d1373af062b9cc85d0ae to your computer and use it in GitHub Desktop.
Save anonymous/d1373af062b9cc85d0ae to your computer and use it in GitHub Desktop.
logstash input windows eventlog ssl
input {
tcp{
type => eventlog
port => 1515
ssl_enable => true
ssl_cert => "/etc/nginx/ssl/server.crt"
ssl_key => "/etc/nginx/ssl/server.key"
ssl_key_passphrase => "password"
ssl_cacert => "/etc/nginx/ssl/server.csr"
codec => "json"
}
}
filter{
if [type] == "eventlog" {
json{
source => "message"
}
if [SourceModuleName] == "eventlog" {
mutate {
replace => [ "message", "%{Message}" ]
}
mutate {
remove_field => [ "Message" ]
}
}
}
}
output {
redis {
host => "127.0.0.1"
data_type => "list"
key => "logstash"
port => 6379
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment