Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.

securityonion-elastic: avoid duplicating logs into multiple indices #1359

Closed
dougburks opened this issue Oct 30, 2018 · 3 comments
Closed

securityonion-elastic: avoid duplicating logs into multiple indices #1359

dougburks opened this issue Oct 30, 2018 · 3 comments

Comments

@dougburks
Copy link
Contributor

OSSEC, firewall, and IDS logs are being duplicated into logstash-syslog indices.

Need to update /etc/logstash/conf.d/1001_preprocess_syslogng.conf to adjust tagging appropriately.

@dougburks
Copy link
Contributor Author

@dougburks
Copy link
Contributor Author

@dougburks
Copy link
Contributor Author

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant