add ELK support (#331)

* add support to forward logs to ELK stack.
* from docker elk customize image with
* https://github.com/whyscream/postfix-grok-patterns
* custom imput
* override syslog filter.
* fix typo.
* Explicit forwarder vars and messages.
* add amavis grok
* add dovecot grok
* add geoip db
* add logstash geoip plugin
* add custom amavis grok from @tomav.
* switch to filebeats input
* refactor syslog filter
* add filebeat
* add template config
* replace rsyslog with filebeat.
This commit is contained in:
Pablo Castorino 2016-09-29 22:52:05 +02:00 committed by Thomas VIAL
parent c2eb975ace
commit e4bab5b996
8 changed files with 124 additions and 1 deletions

6
elk/02-beats-input.conf Normal file
View file

@ -0,0 +1,6 @@
input {
beats {
port => 5044
ssl => false
}
}