filebeat: prospectors: - type: log paths: - "/var/ossec/logs/alerts/alerts.json" document_type: json json.message_key: log json.keys_under_root: true json.overwrite_keys: true output: logstash: # The Logstash hosts hosts: ["YOUR_ELASTIC_SERVER_IP:5000"] # ssl: # certificate_authorities: ["/etc/filebeat/logstash.crt"]