Configure the output for Elastic Cloud Hosted
Auditbeat comes with two settings that simplify the output configuration when used together with Elastic Cloud Hosted. When defined, these setting overwrite settings from other parts in the configuration.
Example:
cloud.id: "staging:dXMtZWFzdC0xLmF3cy5mb3VuZC5pbyRjZWM2ZjI2MWE3NGJmMjRjZTMzYmI4ODExYjg0Mjk0ZiRjNmMyY2E2ZDA0MjI0OWFmMGNjN2Q3YTllOTYyNTc0Mw=="
cloud.auth: "elastic:YOUR_PASSWORD"
These settings can be also specified at the command line, like this:
auditbeat -e -E cloud.id="<cloud-id>" -E cloud.auth="<cloud.auth>"
If an Elastic Cloud Hosted deployment is protected by an AWS PrivateLink VPC filter, you can't use cloud.id. The Cloud ID encodes the public Elasticsearch endpoint, which is not available after the filter is associated. Find the private Elasticsearch URL, then connect using that URL and an API key:
output.elasticsearch:
hosts: ["ELASTICSEARCH_ENDPOINT_URL"]
api_key: "YOUR_API_KEY"
The Cloud ID, which can be found in the Elastic Cloud console, is used by Auditbeat to resolve the Elasticsearch and Kibana URLs. This setting overwrites the output.elasticsearch.hosts and setup.kibana.host settings. For more on locating and configuring the Cloud ID, see Find your Cloud ID.
cloud.auth should not be confused with API keys generated in Elastic Cloud stack management. Although these values look similar, they are unrelated.
When specified, the cloud.auth overwrites the output.elasticsearch.username and output.elasticsearch.password settings. Because the Kibana settings inherit the username and password from the Elasticsearch output, this can also be used to set the setup.kibana.username and setup.kibana.password options.