Adjust portgroup yaml

This commit is contained in:
Mike Reeves
2022-09-20 13:45:29 -04:00
parent b622940f3f
commit 0ade4d7847

View File

@@ -1,23 +1,65 @@
firewall: role:
portgroups:
role:
eval: eval:
ports: chain:
DOCKER-USER:
hostgroups:
manager:
portgroups:
- playbook - playbook
- mysql - mysql
- kibana - kibana
- redis - redis
- minio
- influxdb - influxdb
- cortex
- elasticsearch_rest - elasticsearch_rest
- elasticsearch_node - elasticsearch_node
- cortex_es_rest
- cortex_es_node
minion:
portgroups:
- acng
- docker_registry - docker_registry
- influxdb - influxdb
- sensoroni - sensoroni
sensor:
portgroups:
- beats_5044 - beats_5044
- beats_5644 - beats_5644
search_node:
portgroups:
- redis - redis
- minio
- elasticsearch_node
heavy_node:
portgroups:
- redis
- minio
- elasticsearch_node
self:
portgroups:
- syslog - syslog
beats_endpoint:
portgroups:
- beats_5044
beats_endpoint_ssl:
portgroups:
- beats_5644
elasticsearch_rest:
portgroups:
- elasticsearch_rest
elastic_agent_endpoint:
portgroups:
- elastic_agent_control
- elastic_agent_data
strelka_frontend:
portgroups:
- strelka_frontend - strelka_frontend
syslog:
portgroups:
- syslog
analyst:
portgroups:
- nginx - nginx
INPUT: INPUT:
hostgroups: hostgroups:
@@ -39,16 +81,12 @@ firewall:
hostgroups: hostgroups:
manager: manager:
portgroups: portgroups:
- wazuh_agent
- wazuh_api
- wazuh_authd
- playbook - playbook
- mysql - mysql
- kibana - kibana
- redis - redis
- minio - minio
- influxdb - influxdb
- fleet_api
- cortex - cortex
- elasticsearch_rest - elasticsearch_rest
- elasticsearch_node - elasticsearch_node
@@ -58,10 +96,7 @@ firewall:
portgroups: portgroups:
- acng - acng
- docker_registry - docker_registry
- osquery_8080
- influxdb - influxdb
- wazuh_api
- fleet_api
- sensoroni - sensoroni
- yum - yum
sensor: sensor:
@@ -82,7 +117,7 @@ firewall:
- beats_5644 - beats_5644
self: self:
portgroups: portgroups:
- syslog}} - syslog
syslog: syslog:
portgroups: portgroups:
- syslog - syslog
@@ -98,18 +133,6 @@ firewall:
endgame: endgame:
portgroups: portgroups:
- endgame - endgame
osquery_endpoint:
portgroups:
- fleet_api
wazuh_agent:
portgroups:
- wazuh_agent
wazuh_api:
portgroups:
- wazuh_api
wazuh_authd:
portgroups:
- wazuh_authd
analyst: analyst:
portgroups: portgroups:
- nginx - nginx
@@ -133,16 +156,12 @@ firewall:
hostgroups: hostgroups:
manager: manager:
portgroups: portgroups:
- wazuh_agent
- wazuh_api
- wazuh_authd
- playbook - playbook
- mysql - mysql
- kibana - kibana
- redis - redis
- minio - minio
- influxdb - influxdb
- fleet_api
- cortex - cortex
- elasticsearch_rest - elasticsearch_rest
- elasticsearch_node - elasticsearch_node
@@ -152,10 +171,7 @@ firewall:
portgroups: portgroups:
- acng - acng
- docker_registry - docker_registry
- osquery_8080
- influxdb - influxdb
- wazuh_api
- fleet_api
- sensoroni - sensoroni
- yum - yum
sensor: sensor:
@@ -184,24 +200,16 @@ firewall:
elasticsearch_rest: elasticsearch_rest:
portgroups: portgroups:
- elasticsearch_rest - elasticsearch_rest
elastic_agent_endpoint:
portgroups:
- elastic_agent_control
- elastic_agent_data
endgame: endgame:
portgroups: portgroups:
- endgame - endgame
osquery_endpoint:
portgroups:
- fleet_api
syslog: syslog:
portgroups: portgroups:
- syslog - syslog
wazuh_agent:
portgroups:
- wazuh_agent
wazuh_api:
portgroups:
- wazuh_api
wazuh_authd:
portgroups:
- wazuh_authd
analyst: analyst:
portgroups: portgroups:
- nginx - nginx
@@ -225,16 +233,12 @@ firewall:
hostgroups: hostgroups:
manager: manager:
portgroups: portgroups:
- wazuh_agent
- wazuh_api
- wazuh_authd
- playbook - playbook
- mysql - mysql
- kibana - kibana
- redis - redis
- minio - minio
- influxdb - influxdb
- fleet_api
- cortex - cortex
- elasticsearch_rest - elasticsearch_rest
- elasticsearch_node - elasticsearch_node
@@ -244,10 +248,7 @@ firewall:
portgroups: portgroups:
- acng - acng
- docker_registry - docker_registry
- osquery_8080
- influxdb - influxdb
- wazuh_api
- fleet_api
- sensoroni - sensoroni
- yum - yum
sensor: sensor:
@@ -276,27 +277,19 @@ firewall:
elasticsearch_rest: elasticsearch_rest:
portgroups: portgroups:
- elasticsearch_rest - elasticsearch_rest
elastic_agent_endpoint:
portgroups:
- elastic_agent_control
- elastic_agent_data
endgame: endgame:
portgroups: portgroups:
- endgame - endgame
osquery_endpoint:
portgroups:
- fleet_api
strelka_frontend: strelka_frontend:
portgroups: portgroups:
- strelka_frontend - strelka_frontend
syslog: syslog:
portgroups: portgroups:
- syslog - syslog
wazuh_agent:
portgroups:
- wazuh_agent
wazuh_api:
portgroups:
- wazuh_api
wazuh_authd:
portgroups:
- wazuh_authd
analyst: analyst:
portgroups: portgroups:
- nginx - nginx
@@ -320,13 +313,11 @@ firewall:
hostgroups: hostgroups:
manager: manager:
portgroups: portgroups:
- wazuh_agent
- playbook - playbook
- mysql - mysql
- kibana - kibana
- redis - redis
- influxdb - influxdb
- fleet_api
- cortex - cortex
- elasticsearch_rest - elasticsearch_rest
- elasticsearch_node - elasticsearch_node
@@ -336,9 +327,7 @@ firewall:
portgroups: portgroups:
- acng - acng
- docker_registry - docker_registry
- osquery_8080
- influxdb - influxdb
- wazuh_api
- sensoroni - sensoroni
sensor: sensor:
portgroups: portgroups:
@@ -354,12 +343,6 @@ firewall:
beats_endpoint: beats_endpoint:
portgroups: portgroups:
- beats_5044 - beats_5044
osquery_endpoint:
portgroups:
- fleet_api
wazuh_agent:
portgroups:
- wazuh_agent
analyst: analyst:
portgroups: portgroups:
- nginx - nginx
@@ -397,7 +380,7 @@ firewall:
- elasticsearch_node - elasticsearch_node
self: self:
portgroups: portgroups:
- syslog}} - syslog
INPUT: INPUT:
hostgroups: hostgroups:
anywhere: anywhere:
@@ -447,7 +430,7 @@ firewall:
- elasticsearch_rest - elasticsearch_rest
self: self:
portgroups: portgroups:
- syslog}} - syslog
strelka_frontend: strelka_frontend:
portgroups: portgroups:
- strelka_frontend - strelka_frontend
@@ -462,39 +445,6 @@ firewall:
localhost: localhost:
portgroups: portgroups:
- all - all
fleet:
chain:
DOCKER-USER:
hostgroups:
self:
portgroups:
- redis
- mysql
- osquery_8080
localhost:
portgroups:
- mysql
- osquery_8080
analyst:
portgroups:
- fleet_webui
minion:
portgroups:
- fleet_api
osquery_endpoint:
portgroups:
- fleet_api}}
INPUT:
hostgroups:
anywhere:
portgroups:
- ssh
dockernet:
portgroups:
- all
localhost:
portgroups:
- all
import: import:
chain: chain:
DOCKER-USER: DOCKER-USER:
@@ -559,7 +509,7 @@ firewall:
self: self:
portgroups: portgroups:
- redis - redis
- syslog}} - syslog
- beats_5644 - beats_5644
syslog: syslog:
portgroups: portgroups:
@@ -573,15 +523,6 @@ firewall:
endgame: endgame:
portgroups: portgroups:
- endgame - endgame
wazuh_agent:
portgroups:
- wazuh_agent
wazuh_api:
portgroups:
- wazuh_api
wazuh_authd:
portgroups:
- wazuh_authd
INPUT: INPUT:
hostgroups: hostgroups:
anywhere: anywhere:
@@ -599,7 +540,7 @@ firewall:
hostgroups: hostgroups:
anywhere: anywhere:
portgroups: portgroups:
- idh - ssh
dockernet: dockernet:
portgroups: portgroups:
- all - all