Dynamix Pipelines take 2

This commit is contained in:
Mike Reeves
2021-06-10 09:19:15 -04:00
parent 7fba904f75
commit 12d4d4a4f7
3 changed files with 12 additions and 7 deletions

View File

@@ -1,5 +1,5 @@
{ {
"index_patterns": ["so-grid-*","so-ids-*", "so-firewall-*", "so-syslog-*", "so-zeek-*", "so-import-*", "so-ossec-*", "so-strelka-*", "so-beats-*", "so-osquery-*","so-playbook-*"], "index_patterns": ["so-*"],
"version":50001, "version":50001,
"order":10, "order":10,
"settings":{ "settings":{

View File

@@ -2,25 +2,30 @@
{% set ZEEKLOGLOOKUP = { {% set ZEEKLOGLOOKUP = {
'conn': 'connection', 'conn': 'connection',
} %} } %}
securityonion_filebeat: securityonion_filebeat:
modules: modules:
{%- if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone','so-node', 'so-hotnode', 'so-warmnode', 'so-heavynode'] %}
elasticsearch: elasticsearch:
server: server:
enabled: true enabled: true
var.paths: ["/logs/elasticsearch/*.log"] var.paths: ["/logs/elasticsearch/*.log"]
kibana:
log:
enabled: true
var.paths: ["/logs/kibana/kibana.log"]
logstash: logstash:
log: log:
enabled: true enabled: true
var.paths: ["/logs/logstash.log"] var.paths: ["/logs/logstash.log"]
{%- endif %}
{%- if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone'] %}
kibana:
log:
enabled: true
var.paths: ["/logs/kibana/kibana.log"]
{%- endif %}
{%- if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone', 'so-heavynode'] %}
redis: redis:
log: log:
enabled: true enabled: true
var.paths: ["/logs/redis.log"] var.paths: ["/logs/redis.log"]
slowlog: slowlog:
enabled: false enabled: false
{%- endif %}

View File

@@ -6,6 +6,6 @@ input {
} }
filter { filter {
mutate { mutate {
rename => {@metadata => metadata} rename => {"@metadata" => "metadata"}
} }
} }