Ships T-Pot honeypot logs with
Filebeat. Use it alongside
honeynet/ansible-role-tpotce,
which starts the Filebeat container; add filebeat to that role's
tpot_services so the container is generated.
This role writes configuration only. It does not install or run Filebeat.
{{ filebeat_path }}/filebeat.yml— the main configuration, including the output transport.{{ filebeat_path }}/conf.d/<honeypot>.yml— one input per entry inhoneypot_list. Files for honeypots no longer selected are removed, because Filebeat globs the directory rather than readinghoneypot_list.
The inputs mirror the input section of upstream's
docker/elk/logstash/dist/logstash.conf for T-Pot 24.04, so every log file
upstream reads directly is shipped here instead. Each input sets:
tags: ["<honeypot>"]— what the Logstash filters key on.type: <Type>— the same capitalised type name upstream uses, carried as a root field so downstream configuration can match upstream's[type]tests.t-pot_ip_ext,t-pot_ip_int,t-pot_hostnamefrom the container environment, replacing the${MY_EXTIP}interpolation upstream does inside Logstash.
Filebeat 9.x. The inputs use the filestream type; the log input they
previously used was deprecated in 7.16 and removed in 9.0. The companion
image honeynet/filebeat tracks
the Elasticsearch version pinned by upstream T-Pot.
Exactly one output transport is active, selected by filebeat_output:
| Variable | Default | Description |
|---|---|---|
filebeat_output |
logstash |
logstash or kafka. |
| Variable | Default | Description |
|---|---|---|
logstash_servers |
127.0.0.1:5044 |
A host:port string or a list of them. |
filebeat_logstash_loadbalance |
true |
Spread events across all hosts. |
filebeat_logstash_compression_level |
3 |
gzip level, 0–9. |
Events are routed to one topic per honeypot, named
<filebeat_kafka_topic_prefix><honeypot> — cowrie lands in tpot-cowrie.
Routing keys off the tag each input sets, so it stays in step with
honeypot_list automatically.
| Variable | Default | Description |
|---|---|---|
filebeat_kafka_hosts |
[] |
Broker list. Required for this transport. |
filebeat_kafka_topic_prefix |
tpot- |
Prefix for the per-honeypot topics. |
filebeat_kafka_topic_fallback |
tpot-unrouted |
Catches events matching no honeypot tag, which would otherwise be dropped silently. |
filebeat_kafka_version |
2.6.0 |
Oldest broker in the cluster. |
filebeat_kafka_required_acks |
1 |
0 none, 1 leader, -1 all replicas. |
filebeat_kafka_compression |
gzip |
none, snappy, lz4 or gzip. |
filebeat_kafka_partition_strategy |
hash |
random, round_robin or hash. |
filebeat_kafka_max_message_bytes |
1000000 |
Must not exceed the broker's message.max.bytes. |
filebeat_kafka_username / _password |
"" |
Set the username to enable SASL. |
filebeat_kafka_sasl_mechanism |
SCRAM-SHA-512 |
Ignored unless a username is set. |
filebeat_kafka_ssl_enabled |
false |
TLS to the brokers. |
filebeat_kafka_ssl_certificate_authorities |
[] |
CA bundles for the above. |
| Variable | Default | Description |
|---|---|---|
filebeat_path |
/opt/filebeat/etc |
Where the configuration is written. Must match what the container mounts. |
honeypot_list |
all 34 upstream sources | Honeypots to ship. Each entry needs a matching files/conf.d/<name>.yml; the role fails early if one is missing. |
Shipping a subset to a pair of Logstash hosts:
- hosts: sensors
roles:
- role: ansible-role-tpotce-filebeat
vars:
logstash_servers:
- "logstash1.example.org:5044"
- "logstash2.example.org:5044"
honeypot_list: [cowrie, dionaea, heralding, suricata]Shipping everything to Kafka over TLS:
- hosts: sensors
roles:
- role: ansible-role-tpotce-filebeat
vars:
filebeat_output: kafka
filebeat_kafka_hosts: ["kafka1.example.org:9093", "kafka2.example.org:9093"]
filebeat_kafka_ssl_enabled: true
filebeat_kafka_ssl_certificate_authorities: [/etc/pki/tls/certs/kafka-ca.crt]
filebeat_kafka_username: honeynet
filebeat_kafka_password: "{{ vault_kafka_password }}"pip3 install -r requirements.txt
ansible-galaxy collection install -r requirements.yml
molecule test # logstash transport
molecule test -s kafka # kafka transportBoth scenarios render the configuration into a container and assert on the result; neither starts Filebeat.
To test another platform from the CI matrix, set all three variables together -- the image is a full reference, not a distribution slug:
MOLECULE_IMAGE=almalinux:10 MOLECULE_DISTRO_TAG=almalinux10 \
MOLECULE_DOCKER_COMMAND=/usr/lib/systemd/systemd molecule testCI runs both scenarios against the current release of each distribution honeynet/ansible-role-tpotce supports: debian13, ubuntu2604, almalinux10, rockylinux10, fedora44 and tumbleweed.
This project is supported by: