This commit is contained in:
m0duspwnens
2022-09-20 15:25:50 -04:00
parent 75aa121b2d
commit 1685e0e6db
2 changed files with 13 additions and 11 deletions

View File

@@ -1,9 +1,10 @@
zeek: zeek:
config: config:
node: node:
lb_procs: 1 lb_procs: 0
zeek_pins_enabled: False pins_enabled: False
zeek_pins: [] pins: []
buffer: 128*1024*1024
zeekctl: zeekctl:
MailTo: root@localhost MailTo: root@localhost
MailConnectionSummary: 1 MailConnectionSummary: 1
@@ -21,7 +22,7 @@ zeek:
CfgDir: /opt/zeek/etc CfgDir: /opt/zeek/etc
CompressLogs: 1 CompressLogs: 1
local: local:
load: '@load':
- misc/loaded-scripts - misc/loaded-scripts
- tuning/defaults - tuning/defaults
- misc/capture-loss - misc/capture-loss
@@ -53,7 +54,7 @@ zeek:
- securityonion/bpfconf - securityonion/bpfconf
- securityonion/communityid - securityonion/communityid
- securityonion/file-extraction - securityonion/file-extraction
load-sigs: '@load-sigs':
- frameworks/signatures/detect-windows-shells - frameworks/signatures/detect-windows-shells
redef: redef:
- LogAscii::use_json = T; - LogAscii::use_json = T;

View File

@@ -1,3 +1,4 @@
{%- if NODE.pins or NODE.lb_procs %}
[manager] [manager]
type=manager type=manager
host=localhost host=localhost
@@ -15,17 +16,17 @@ type=worker
host=localhost host=localhost
interface=af_packet::{{ NODE.interface }} interface=af_packet::{{ NODE.interface }}
lb_method=custom lb_method=custom
{%- if NODE.lbprocs %} {%- if NODE.lb_procs %}
lb_procs={{ NODE.lbprocs }} lb_procs={{ NODE.lb_procs }}
{%- else %} {%- else %}
lb_procs={{ NODE.zeek_pins | length }} lb_procs={{ NODE.pins | length }}
{%- endif %} {%- endif %}
{%- if NODE.zeek_pins %} {%- if NODE.pins %}
pin_cpus={{ NODE.zeek_pins | join(", ") }} pin_cpus={{ NODE.pins | join(", ") }}
{%- endif %} {%- endif %}
af_packet_fanout_id=23 af_packet_fanout_id=23
af_packet_fanout_mode=AF_Packet::FANOUT_HASH af_packet_fanout_mode=AF_Packet::FANOUT_HASH
af_packet_buffer_size={{ NODE.zeek_buffer }} af_packet_buffer_size={{ NODE.buffer }}
{%- else %} {%- else %}
[zeeksa] [zeeksa]
type=standalone type=standalone