<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<template encoding-version="1.3">
    <description></description>
    <groupId>b9e35746-0172-1000-cfb1-78b6822503c3</groupId>
    <name>Elasticsearch to Syslog</name>
    <snippet>
        <connections>
            <id>9f08ebad-32af-3cc7-0000-000000000000</id>
            <parentGroupId>5a65bd8d-b8cf-3a00-0000-000000000000</parentGroupId>
            <backPressureDataSizeThreshold>1 GB</backPressureDataSizeThreshold>
            <backPressureObjectThreshold>10000</backPressureObjectThreshold>
            <destination>
                <groupId>5a65bd8d-b8cf-3a00-0000-000000000000</groupId>
                <id>dd01c414-919a-3bbc-0000-000000000000</id>
                <type>PROCESSOR</type>
            </destination>
            <flowFileExpiration>0 sec</flowFileExpiration>
            <labelIndex>1</labelIndex>
            <loadBalanceCompression>DO_NOT_COMPRESS</loadBalanceCompression>
            <loadBalancePartitionAttribute></loadBalancePartitionAttribute>
            <loadBalanceStatus>LOAD_BALANCE_NOT_CONFIGURED</loadBalanceStatus>
            <loadBalanceStrategy>DO_NOT_LOAD_BALANCE</loadBalanceStrategy>
            <name></name>
            <selectedRelationships>success</selectedRelationships>
            <source>
                <groupId>5a65bd8d-b8cf-3a00-0000-000000000000</groupId>
                <id>e6d4d6a2-45f9-3a57-0000-000000000000</id>
                <type>PROCESSOR</type>
            </source>
            <zIndex>0</zIndex>
        </connections>
        <connections>
            <id>f873593c-f7e4-308b-0000-000000000000</id>
            <parentGroupId>5a65bd8d-b8cf-3a00-0000-000000000000</parentGroupId>
            <backPressureDataSizeThreshold>1 GB</backPressureDataSizeThreshold>
            <backPressureObjectThreshold>10000</backPressureObjectThreshold>
            <destination>
                <groupId>5a65bd8d-b8cf-3a00-0000-000000000000</groupId>
                <id>d88fed39-4aa3-35ad-0000-000000000000</id>
                <type>PROCESSOR</type>
            </destination>
            <flowFileExpiration>0 sec</flowFileExpiration>
            <labelIndex>1</labelIndex>
            <loadBalanceCompression>DO_NOT_COMPRESS</loadBalanceCompression>
            <loadBalancePartitionAttribute></loadBalancePartitionAttribute>
            <loadBalanceStatus>LOAD_BALANCE_NOT_CONFIGURED</loadBalanceStatus>
            <loadBalanceStrategy>DO_NOT_LOAD_BALANCE</loadBalanceStrategy>
            <name></name>
            <selectedRelationships>matched</selectedRelationships>
            <source>
                <groupId>5a65bd8d-b8cf-3a00-0000-000000000000</groupId>
                <id>dd01c414-919a-3bbc-0000-000000000000</id>
                <type>PROCESSOR</type>
            </source>
            <zIndex>0</zIndex>
        </connections>
        <processors>
            <id>d88fed39-4aa3-35ad-0000-000000000000</id>
            <parentGroupId>5a65bd8d-b8cf-3a00-0000-000000000000</parentGroupId>
            <position>
                <x>0.0</x>
                <y>448.0</y>
            </position>
            <bundle>
                <artifact>nifi-standard-nar</artifact>
                <group>org.apache.nifi</group>
                <version>1.11.4</version>
            </bundle>
            <config>
                <bulletinLevel>WARN</bulletinLevel>
                <comments></comments>
                <concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
                <descriptors>
                    <entry>
                        <key>Hostname</key>
                        <value>
                            <name>Hostname</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Port</key>
                        <value>
                            <name>Port</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Max Size of Socket Send Buffer</key>
                        <value>
                            <name>Max Size of Socket Send Buffer</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Idle Connection Expiration</key>
                        <value>
                            <name>Idle Connection Expiration</name>
                        </value>
                    </entry>
                </descriptors>
                <executionNode>ALL</executionNode>
                <lossTolerant>false</lossTolerant>
                <penaltyDuration>30 sec</penaltyDuration>
                <properties>
                    <entry>
                        <key>Hostname</key>
                        <value>yoursyslogserver</value>
                    </entry>
                    <entry>
                        <key>Port</key>
                        <value>514</value>
                    </entry>
                    <entry>
                        <key>Max Size of Socket Send Buffer</key>
                        <value>1 MB</value>
                    </entry>
                    <entry>
                        <key>Idle Connection Expiration</key>
                        <value>5 seconds</value>
                    </entry>
                </properties>
                <runDurationMillis>0</runDurationMillis>
                <schedulingPeriod>0 sec</schedulingPeriod>
                <schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
                <yieldDuration>1 sec</yieldDuration>
            </config>
            <executionNodeRestricted>false</executionNodeRestricted>
            <name>PutUDP</name>
            <relationships>
                <autoTerminate>true</autoTerminate>
                <name>failure</name>
            </relationships>
            <relationships>
                <autoTerminate>true</autoTerminate>
                <name>success</name>
            </relationships>
            <state>STOPPED</state>
            <style/>
            <type>org.apache.nifi.processors.standard.PutUDP</type>
        </processors>
        <processors>
            <id>dd01c414-919a-3bbc-0000-000000000000</id>
            <parentGroupId>5a65bd8d-b8cf-3a00-0000-000000000000</parentGroupId>
            <position>
                <x>0.0</x>
                <y>232.0</y>
            </position>
            <bundle>
                <artifact>nifi-standard-nar</artifact>
                <group>org.apache.nifi</group>
                <version>1.11.4</version>
            </bundle>
            <config>
                <bulletinLevel>WARN</bulletinLevel>
                <comments></comments>
                <concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
                <descriptors>
                    <entry>
                        <key>Destination</key>
                        <value>
                            <name>Destination</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Return Type</key>
                        <value>
                            <name>Return Type</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Path Not Found Behavior</key>
                        <value>
                            <name>Path Not Found Behavior</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Null Value Representation</key>
                        <value>
                            <name>Null Value Representation</name>
                        </value>
                    </entry>
                    <entry>
                        <key>message</key>
                        <value>
                            <name>message</name>
                        </value>
                    </entry>
                </descriptors>
                <executionNode>ALL</executionNode>
                <lossTolerant>false</lossTolerant>
                <penaltyDuration>30 sec</penaltyDuration>
                <properties>
                    <entry>
                        <key>Destination</key>
                        <value>flowfile-content</value>
                    </entry>
                    <entry>
                        <key>Return Type</key>
                        <value>auto-detect</value>
                    </entry>
                    <entry>
                        <key>Path Not Found Behavior</key>
                        <value>ignore</value>
                    </entry>
                    <entry>
                        <key>Null Value Representation</key>
                        <value>empty string</value>
                    </entry>
                    <entry>
                        <key>message</key>
                        <value>$.message</value>
                    </entry>
                </properties>
                <runDurationMillis>0</runDurationMillis>
                <schedulingPeriod>0 sec</schedulingPeriod>
                <schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
                <yieldDuration>1 sec</yieldDuration>
            </config>
            <executionNodeRestricted>false</executionNodeRestricted>
            <name>EvaluateJsonPath</name>
            <relationships>
                <autoTerminate>true</autoTerminate>
                <name>failure</name>
            </relationships>
            <relationships>
                <autoTerminate>false</autoTerminate>
                <name>matched</name>
            </relationships>
            <relationships>
                <autoTerminate>true</autoTerminate>
                <name>unmatched</name>
            </relationships>
            <state>STOPPED</state>
            <style/>
            <type>org.apache.nifi.processors.standard.EvaluateJsonPath</type>
        </processors>
        <processors>
            <id>e6d4d6a2-45f9-3a57-0000-000000000000</id>
            <parentGroupId>5a65bd8d-b8cf-3a00-0000-000000000000</parentGroupId>
            <position>
                <x>8.0</x>
                <y>0.0</y>
            </position>
            <bundle>
                <artifact>nifi-elasticsearch-nar</artifact>
                <group>org.apache.nifi</group>
                <version>1.11.4</version>
            </bundle>
            <config>
                <bulletinLevel>WARN</bulletinLevel>
                <comments></comments>
                <concurrentlySchedulableTaskCount>1</concurrentlySchedulableTaskCount>
                <descriptors>
                    <entry>
                        <key>elasticsearch-http-url</key>
                        <value>
                            <name>elasticsearch-http-url</name>
                        </value>
                    </entry>
                    <entry>
                        <key>SSL Context Service</key>
                        <value>
                            <identifiesControllerService>org.apache.nifi.ssl.SSLContextService</identifiesControllerService>
                            <name>SSL Context Service</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Character Set</key>
                        <value>
                            <name>Character Set</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Username</key>
                        <value>
                            <name>Username</name>
                        </value>
                    </entry>
                    <entry>
                        <key>Password</key>
                        <value>
                            <name>Password</name>
                        </value>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-connect-timeout</key>
                        <value>
                            <name>elasticsearch-http-connect-timeout</name>
                        </value>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-response-timeout</key>
                        <value>
                            <name>elasticsearch-http-response-timeout</name>
                        </value>
                    </entry>
                    <entry>
                        <key>proxy-configuration-service</key>
                        <value>
                            <identifiesControllerService>org.apache.nifi.proxy.ProxyConfigurationService</identifiesControllerService>
                            <name>proxy-configuration-service</name>
                        </value>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-proxy-host</key>
                        <value>
                            <name>elasticsearch-http-proxy-host</name>
                        </value>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-proxy-port</key>
                        <value>
                            <name>elasticsearch-http-proxy-port</name>
                        </value>
                    </entry>
                    <entry>
                        <key>proxy-username</key>
                        <value>
                            <name>proxy-username</name>
                        </value>
                    </entry>
                    <entry>
                        <key>proxy-password</key>
                        <value>
                            <name>proxy-password</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-query</key>
                        <value>
                            <name>query-es-query</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-size</key>
                        <value>
                            <name>query-es-size</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-index</key>
                        <value>
                            <name>query-es-index</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-type</key>
                        <value>
                            <name>query-es-type</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-fields</key>
                        <value>
                            <name>query-es-fields</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-sort</key>
                        <value>
                            <name>query-es-sort</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-limit</key>
                        <value>
                            <name>query-es-limit</name>
                        </value>
                    </entry>
                    <entry>
                        <key>query-es-target</key>
                        <value>
                            <name>query-es-target</name>
                        </value>
                    </entry>
                    <entry>
                        <key>routing-query-info-strategy</key>
                        <value>
                            <name>routing-query-info-strategy</name>
                        </value>
                    </entry>
                </descriptors>
                <executionNode>ALL</executionNode>
                <lossTolerant>false</lossTolerant>
                <penaltyDuration>30 sec</penaltyDuration>
                <properties>
                    <entry>
                        <key>elasticsearch-http-url</key>
                        <value>http://yourelasticserver:9200</value>
                    </entry>
                    <entry>
                        <key>SSL Context Service</key>
                    </entry>
                    <entry>
                        <key>Character Set</key>
                        <value>UTF-8</value>
                    </entry>
                    <entry>
                        <key>Username</key>
                    </entry>
                    <entry>
                        <key>Password</key>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-connect-timeout</key>
                        <value>5 secs</value>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-response-timeout</key>
                        <value>15 secs</value>
                    </entry>
                    <entry>
                        <key>proxy-configuration-service</key>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-proxy-host</key>
                    </entry>
                    <entry>
                        <key>elasticsearch-http-proxy-port</key>
                    </entry>
                    <entry>
                        <key>proxy-username</key>
                    </entry>
                    <entry>
                        <key>proxy-password</key>
                    </entry>
                    <entry>
                        <key>query-es-query</key>
                        <value>tags:geoip AND tags:pihole AND @timestamp:[now-1m TO *]</value>
                    </entry>
                    <entry>
                        <key>query-es-size</key>
                        <value>20</value>
                    </entry>
                    <entry>
                        <key>query-es-index</key>
                        <value>logstash</value>
                    </entry>
                    <entry>
                        <key>query-es-type</key>
                    </entry>
                    <entry>
                        <key>query-es-fields</key>
                    </entry>
                    <entry>
                        <key>query-es-sort</key>
                    </entry>
                    <entry>
                        <key>query-es-limit</key>
                    </entry>
                    <entry>
                        <key>query-es-target</key>
                        <value>Flow file content</value>
                    </entry>
                    <entry>
                        <key>routing-query-info-strategy</key>
                        <value>NEVER</value>
                    </entry>
                </properties>
                <runDurationMillis>0</runDurationMillis>
                <schedulingPeriod>1 min</schedulingPeriod>
                <schedulingStrategy>TIMER_DRIVEN</schedulingStrategy>
                <yieldDuration>1 sec</yieldDuration>
            </config>
            <executionNodeRestricted>false</executionNodeRestricted>
            <name>QueryElasticsearchHttp</name>
            <relationships>
                <autoTerminate>true</autoTerminate>
                <name>failure</name>
            </relationships>
            <relationships>
                <autoTerminate>true</autoTerminate>
                <name>retry</name>
            </relationships>
            <relationships>
                <autoTerminate>false</autoTerminate>
                <name>success</name>
            </relationships>
            <state>STOPPED</state>
            <style/>
            <type>org.apache.nifi.processors.elasticsearch.QueryElasticsearchHttp</type>
        </processors>
    </snippet>
    <timestamp>06/16/2020 11:29:53 EDT</timestamp>
</template>
