diff --git a/wazuh/config/filebeat.yml b/wazuh/config/filebeat.yml index 0f2ea6ce..fcb32e1e 100644 --- a/wazuh/config/filebeat.yml +++ b/wazuh/config/filebeat.yml @@ -1,11 +1,10 @@ # Wazuh App Copyright (C) 2018 Wazuh Inc. (License GPLv2) filebeat: - inputs: + prospectors: - type: log paths: - - "/var/ossec/data/logs/alerts/alerts.json" - fields: - document_type: wazuh-alerts + - "/var/ossec/logs/alerts/alerts.json" + document_type: json json.message_key: log json.keys_under_root: true json.overwrite_keys: true