Generic HTTP
The Generic HTTP output can be used to send records to an HTTP endpoint such as the http_endpoint input of Elastic's Filebeat, or the http input of Elastic's Logstash.
The following is an example configuration for Elastic Filebeat:
filebeat.inputs:
- type: http_endpoint
enabled: true
listen_address: 0.0.0.0
listen_port: 8888
processors:
- convert:
fields:
- {from: "json", type: "string"}
ignore_missing: true
fail_on_error: false
- decode_json_fields:
fields: ["json"]
process_array: true
target: ""
overwrite_keys: true
add_error_key: false
- drop_fields:
fields: ["json"]
ignore_missing: false
processors:
- drop_fields:
fields:
- agent
- ecs
- host
- inputThe following is an example pipeline for Elastic Logstash:
EF_OUTPUT_GENERIC_HTTP_ENABLE
Specifies whether the Generic HTTP output is enabled.
Valid Values
true,false
Default
false
EF_OUTPUT_GENERIC_HTTP_ECS_ENABLE
Specifies whether the data will be sent using Elastic Common Schema (ECS).
Valid Values
true,false
Default
false
EF_OUTPUT_GENERIC_HTTP_BATCH_DEADLINE
The maximum time, in milliseconds, to wait for a batch of records to fill before being sent to the HTTP Endpoint.
Default
2000
EF_OUTPUT_GENERIC_HTTP_BATCH_MAX_BYTES
The maximum size, in bytes, for a batch of records being sent to the HTTP Endpoint.
Default
8388608
EF_OUTPUT_GENERIC_HTTP_TIMESTAMP_SOURCE
Determines the timestamp source to be used to set the @timestamp field. Usually end would be the best setting. However, in the case of poorly behaving or misconfigured devices, collect may be the better option. For this reason the default value is collect as it best handles a variety of scenarios.
Valid Values
start- Use the timestamp fromflow.start.timestamp. The flow start time indicated in the flow.end- Use the timestamp fromflow.end.timestamp. The flow end time (or last reported time).export- Use the timestamp fromflow.export.timestamp. The time from the flow record header.collect- Use the timestamp fromflow.collect.timestamp. The time that the collector processed the flow record.
Default
collect
EF_OUTPUT_GENERIC_HTTP_ADDRESSES
This setting specifies the HTTP servers to which the output should connect. It is a comma-separated list of HTTP servers, including port number.
Do NOT include http:// or https:// in the provided value. TLS communications is enabled/disabled using EF_OUTPUT_GENERIC_HTTP_TLS_ENABLE.
Default
127.0.0.1:8888
EF_OUTPUT_GENERIC_HTTP_USERNAME
The username to use when connecting to the HTTP endpoint.
Default
``
EF_OUTPUT_GENERIC_HTTP_PASSWORD
The password to use when connecting to the HTTP endpoint.
Default
``
EF_OUTPUT_GENERIC_HTTP_TLS_ENABLE
This setting is used to enable/disable TLS connections to the HTTP server.
Valid Values
true,false
Default
false
EF_OUTPUT_GENERIC_HTTP_TLS_SKIP_VERIFICATION
This setting is used to enable/disable TLS verification of the HTTP server to which the output is attempting to connect.
Valid Values
true,false
Default
false
EF_OUTPUT_GENERIC_HTTP_TLS_CA_CERT_FILEPATH
The path to the Certificate Authority (CA) certificate to use for verification of the HTTP server to which the output is attempting to connect.
Default
''
EF_OUTPUT_GENERIC_HTTP_DROP_FIELDS
This setting allows for a comma-separated list of fields that are to be removed from all records.
Valid Values
any field names related to the enabled schema, comma-separated
Example
flow.export.sysuptime,flow.export.version.ver,flow.start.sysuptime,flow.end.sysuptime,flow.seq_num
Default
''
EF_OUTPUT_GENERIC_HTTP_ALLOWED_RECORD_TYPES
This setting allows for a comma-separated list of record types that the output will send will emit. If left empty, all types will be allowed by default.
Valid Values
as_path_hop,flow_option,flow,ifa_hop,telemetry,metric,log
Default
'as_path_hop,flow_option,flow,ifa_hop,telemetry,metric,log'
Last updated
Was this helpful?
