input {
tcp {
port => "9900"
type => "syslog"
}
}
input {
udp {
port => "9900"
type => "syslog"
}
}
output {
elasticsearch {
hosts => ["192.168.10.10:9200"]
index => "logstash-tcplog-test-%{+YYYY.MM.dd}"
}
}
geoip {
source => "SrcIp"
target => "SrcGeo"
}
geoip {
source => "DstIp"
target => "DstGeo"
}