mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
few more
This commit is contained in:
@@ -1,9 +1,10 @@
|
|||||||
zeek:
|
zeek:
|
||||||
config:
|
config:
|
||||||
node:
|
node:
|
||||||
lb_procs: 1
|
lb_procs: 0
|
||||||
zeek_pins_enabled: False
|
pins_enabled: False
|
||||||
zeek_pins: []
|
pins: []
|
||||||
|
buffer: 128*1024*1024
|
||||||
zeekctl:
|
zeekctl:
|
||||||
MailTo: root@localhost
|
MailTo: root@localhost
|
||||||
MailConnectionSummary: 1
|
MailConnectionSummary: 1
|
||||||
@@ -21,7 +22,7 @@ zeek:
|
|||||||
CfgDir: /opt/zeek/etc
|
CfgDir: /opt/zeek/etc
|
||||||
CompressLogs: 1
|
CompressLogs: 1
|
||||||
local:
|
local:
|
||||||
load:
|
'@load':
|
||||||
- misc/loaded-scripts
|
- misc/loaded-scripts
|
||||||
- tuning/defaults
|
- tuning/defaults
|
||||||
- misc/capture-loss
|
- misc/capture-loss
|
||||||
@@ -53,7 +54,7 @@ zeek:
|
|||||||
- securityonion/bpfconf
|
- securityonion/bpfconf
|
||||||
- securityonion/communityid
|
- securityonion/communityid
|
||||||
- securityonion/file-extraction
|
- securityonion/file-extraction
|
||||||
load-sigs:
|
'@load-sigs':
|
||||||
- frameworks/signatures/detect-windows-shells
|
- frameworks/signatures/detect-windows-shells
|
||||||
redef:
|
redef:
|
||||||
- LogAscii::use_json = T;
|
- LogAscii::use_json = T;
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
{%- if NODE.pins or NODE.lb_procs %}
|
||||||
[manager]
|
[manager]
|
||||||
type=manager
|
type=manager
|
||||||
host=localhost
|
host=localhost
|
||||||
@@ -15,17 +16,17 @@ type=worker
|
|||||||
host=localhost
|
host=localhost
|
||||||
interface=af_packet::{{ NODE.interface }}
|
interface=af_packet::{{ NODE.interface }}
|
||||||
lb_method=custom
|
lb_method=custom
|
||||||
{%- if NODE.lbprocs %}
|
{%- if NODE.lb_procs %}
|
||||||
lb_procs={{ NODE.lbprocs }}
|
lb_procs={{ NODE.lb_procs }}
|
||||||
{%- else %}
|
{%- else %}
|
||||||
lb_procs={{ NODE.zeek_pins | length }}
|
lb_procs={{ NODE.pins | length }}
|
||||||
{%- endif %}
|
{%- endif %}
|
||||||
{%- if NODE.zeek_pins %}
|
{%- if NODE.pins %}
|
||||||
pin_cpus={{ NODE.zeek_pins | join(", ") }}
|
pin_cpus={{ NODE.pins | join(", ") }}
|
||||||
{%- endif %}
|
{%- endif %}
|
||||||
af_packet_fanout_id=23
|
af_packet_fanout_id=23
|
||||||
af_packet_fanout_mode=AF_Packet::FANOUT_HASH
|
af_packet_fanout_mode=AF_Packet::FANOUT_HASH
|
||||||
af_packet_buffer_size={{ NODE.zeek_buffer }}
|
af_packet_buffer_size={{ NODE.buffer }}
|
||||||
{%- else %}
|
{%- else %}
|
||||||
[zeeksa]
|
[zeeksa]
|
||||||
type=standalone
|
type=standalone
|
||||||
|
|||||||
Reference in New Issue
Block a user