fluent-bit.yaml
fluent-bit
[INPUT]
name tail
path /var/lib/docker/containers/**/*.log
path_key path
multiline.parser docker, cri
Parser docker
Docker_Mode On
[INPUT]
Name syslog
Listen 0.0.0.0
Port 5140
Parser syslog-rfc3164
Mode tcp
[SERVICE]
Flush 1
Parsers_File parsers.conf
HTTP_Server On
HTTP_Listen 0.0.0.0
HTTP_PORT 2020
## https://zincsearch-docs.zinc.dev/ingestion/fluent-bit/
[OUTPUT]
Name es
Match *
Path /api
Index syslog
Type journal
Host local.org
Port 4080
Generate_ID On
HTTP_User admin
HTTP_Passwd cs#123
[FILTER]
Name parser
Match *
Key_Name data
Parser syslog-rfc3164