Send CADF audit events to Elasticsearch
Change-Id: I0c359bf7eccd8c401348880359d0f189fd9bd42b
diff --git a/heka/meta/heka.yml b/heka/meta/heka.yml
index 1d6c76f..3cd50d8 100644
--- a/heka/meta/heka.yml
+++ b/heka/meta/heka.yml
@@ -267,7 +267,7 @@
engine: elasticsearch
server: "http://{{ remote_collector.elasticsearch_host }}:{{ remote_collector.elasticsearch_port }}"
encoder: elasticsearch_encoder
- message_matcher: "Type == 'notification'"
+ message_matcher: "Type == 'notification' || Type == 'audit'"
{%- endif %}
{%- endif %}
aggregator: