filebeat: output: elasticsearch: hosts: - localhost:9200 prospectors: - paths: - /var/log/daemon.log - input_type: log paths: - /var/log/auth.log