Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?
Logstash config for receiving OSSIM logs
input {
tcp {
port => 5142
type => "ossim-events"
codec => json {
charset => "CP1252"
}
}
syslog {
type => "syslog"
}
}
filter {
mutate {
add_field => { "Agent_IP" => "%{host}" }
}
######## ALIENVAULT OSSIM Logs ########################################
if [type] == "ossim-events" {
kv {
value_split => "='"
field_split => "' "
}
}
}
output {
stdout { }
elasticsearch {
host => "localhost"
template => "/elk/logstash/templates/elasticsearch-template.json"
template_overwrite => true
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment