--- packetbeat/packetbeat.yml.orig 2019-10-15 21:08:29 UTC +++ packetbeat/packetbeat.yml @@ -10,8 +10,10 @@ #============================== Network device ================================ # Select the network interface to sniff the data. On Linux, you can use the -# "any" keyword to sniff on all connected interfaces. -packetbeat.interfaces.device: any +# "any" keyword to sniff on all connected interfaces. FreeBSD is a bit different +# and the beats programmers did not bother to implement it, so you must set this +# to your preferred device +packetbeat.interfaces.device: em0 #================================== Flows ===================================== @@ -217,6 +219,8 @@ processors: # To enable all selectors use ["*"]. Examples of other selectors are "beat", # "publish", "service". #logging.selectors: ["*"] +logging.to_syslog: true +logging.to_files: false #============================== Xpack Monitoring =============================== # packetbeat can export internal metrics to a central Elasticsearch monitoring