<global>
  <jsonout_output>yes</jsonout_output>
</global>
- input_type: log
paths:
  - /var/ossec/logs/alerts/alerts.json
json.keys_under_root: true
fields: {log_type: osseclogs}
input {
  beats {
    id => "beats_test"
    port => 9001
    type => "ossec"
  }
}
filter {
  if([fields][log_type] == "osseclogs") {
    mutate {
      replace => {
        "[type]" => "osseclogs"
      }
    }
  }
}
output {
  if([type] == "osseclogs") {
    elasticsearch {
      index => "ossec-%{+YYYY.MM.dd}"
    }
  }
}