mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Dynamix Pipelines take 2
This commit is contained in:
@@ -1,5 +1,5 @@
|
|||||||
{
|
{
|
||||||
"index_patterns": ["so-grid-*","so-ids-*", "so-firewall-*", "so-syslog-*", "so-zeek-*", "so-import-*", "so-ossec-*", "so-strelka-*", "so-beats-*", "so-osquery-*","so-playbook-*"],
|
"index_patterns": ["so-*"],
|
||||||
"version":50001,
|
"version":50001,
|
||||||
"order":10,
|
"order":10,
|
||||||
"settings":{
|
"settings":{
|
||||||
|
|||||||
@@ -2,25 +2,30 @@
|
|||||||
{% set ZEEKLOGLOOKUP = {
|
{% set ZEEKLOGLOOKUP = {
|
||||||
'conn': 'connection',
|
'conn': 'connection',
|
||||||
} %}
|
} %}
|
||||||
|
|
||||||
securityonion_filebeat:
|
securityonion_filebeat:
|
||||||
modules:
|
modules:
|
||||||
|
{%- if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone','so-node', 'so-hotnode', 'so-warmnode', 'so-heavynode'] %}
|
||||||
elasticsearch:
|
elasticsearch:
|
||||||
server:
|
server:
|
||||||
enabled: true
|
enabled: true
|
||||||
var.paths: ["/logs/elasticsearch/*.log"]
|
var.paths: ["/logs/elasticsearch/*.log"]
|
||||||
kibana:
|
|
||||||
log:
|
|
||||||
enabled: true
|
|
||||||
var.paths: ["/logs/kibana/kibana.log"]
|
|
||||||
logstash:
|
logstash:
|
||||||
log:
|
log:
|
||||||
enabled: true
|
enabled: true
|
||||||
var.paths: ["/logs/logstash.log"]
|
var.paths: ["/logs/logstash.log"]
|
||||||
|
{%- endif %}
|
||||||
|
{%- if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone'] %}
|
||||||
|
kibana:
|
||||||
|
log:
|
||||||
|
enabled: true
|
||||||
|
var.paths: ["/logs/kibana/kibana.log"]
|
||||||
|
{%- endif %}
|
||||||
|
{%- if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone', 'so-heavynode'] %}
|
||||||
redis:
|
redis:
|
||||||
log:
|
log:
|
||||||
enabled: true
|
enabled: true
|
||||||
var.paths: ["/logs/redis.log"]
|
var.paths: ["/logs/redis.log"]
|
||||||
slowlog:
|
slowlog:
|
||||||
enabled: false
|
enabled: false
|
||||||
|
{%- endif %}
|
||||||
|
|
||||||
@@ -6,6 +6,6 @@ input {
|
|||||||
}
|
}
|
||||||
filter {
|
filter {
|
||||||
mutate {
|
mutate {
|
||||||
rename => {“@metadata” => “metadata”}
|
rename => {"@metadata" => "metadata"}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user