2019-10-22 11:06:06 -04:00
|
|
|
elasticsearch:
|
|
|
|
enabled: true
|
|
|
|
cluster:
|
|
|
|
env:
|
|
|
|
MINIMUM_MASTER_NODES: "1"
|
|
|
|
master:
|
|
|
|
replicas: 2
|
|
|
|
client:
|
|
|
|
replicas: 1
|
|
|
|
data:
|
2020-02-12 01:09:05 -05:00
|
|
|
replicas: 2
|
2019-10-22 11:06:06 -04:00
|
|
|
|
|
|
|
kibana:
|
2020-01-13 19:08:14 -05:00
|
|
|
enabled: false
|
2019-10-22 11:06:06 -04:00
|
|
|
|
|
|
|
logstash:
|
|
|
|
enabled: false
|
|
|
|
|
|
|
|
filebeat:
|
|
|
|
enabled: true
|
|
|
|
config:
|
|
|
|
output.file.enabled: false
|
|
|
|
output.elasticsearch:
|
|
|
|
enabled: true
|
|
|
|
hosts: ["http://elastic-stack-elasticsearch-client:9200"]
|
2020-02-17 13:09:00 -05:00
|
|
|
filebeat.prospectors:
|
|
|
|
- type: log
|
|
|
|
enabled: true
|
|
|
|
paths:
|
|
|
|
- /var/log/*.log
|
|
|
|
- /var/log/messages
|
|
|
|
- /var/log/syslog
|
|
|
|
- type: docker
|
|
|
|
containers.ids:
|
|
|
|
- "*"
|
|
|
|
json.keys_under_root: true
|
|
|
|
json.ignore_decoding_error: true
|
|
|
|
processors:
|
|
|
|
- add_kubernetes_metadata:
|
|
|
|
- drop_event:
|
|
|
|
when:
|
|
|
|
equals:
|
|
|
|
kubernetes.container.name: "filebeat"
|
|
|
|
- decode_json_fields:
|
|
|
|
fields: ["message"]
|
|
|
|
when:
|
|
|
|
equals:
|
|
|
|
kubernetes.container.name: "modsecurity-log"
|
2019-10-22 11:06:06 -04:00
|
|
|
|
|
|
|
fluentd:
|
|
|
|
enabled: false
|
|
|
|
|
|
|
|
fluent-bit:
|
|
|
|
enabled: false
|
|
|
|
|
|
|
|
nginx-ldapauth-proxy:
|
|
|
|
enabled: false
|
|
|
|
|
|
|
|
elasticsearch-curator:
|
2020-01-16 13:08:46 -05:00
|
|
|
enabled: true
|
|
|
|
configMaps:
|
|
|
|
config_yml: |-
|
|
|
|
---
|
|
|
|
client:
|
|
|
|
hosts:
|
|
|
|
- elastic-stack-elasticsearch-client
|
|
|
|
port: 9200
|
|
|
|
action_file_yml: |-
|
|
|
|
---
|
|
|
|
actions:
|
|
|
|
1:
|
|
|
|
action: delete_indices
|
|
|
|
description: >-
|
2020-02-06 19:09:12 -05:00
|
|
|
Delete indices older than 30 days (based on index name), for filebeat-
|
2020-01-16 13:08:46 -05:00
|
|
|
prefixed indices. Ignore the error if the filter does not result in an
|
|
|
|
actionable list of indices (ignore_empty_list) and exit cleanly.
|
|
|
|
options:
|
|
|
|
ignore_empty_list: True
|
|
|
|
filters:
|
|
|
|
- filtertype: pattern
|
|
|
|
kind: prefix
|
|
|
|
value: filebeat-
|
|
|
|
- filtertype: age
|
|
|
|
source: name
|
|
|
|
direction: older
|
|
|
|
timestring: '%Y.%m.%d'
|
|
|
|
unit: days
|
2020-02-06 19:09:12 -05:00
|
|
|
unit_count: 30
|
2019-10-22 11:06:06 -04:00
|
|
|
|
|
|
|
elasticsearch-exporter:
|
|
|
|
enabled: false
|