diff --git a/salt/manager/tools/sbin_jinja/so-elastic-fleet-reset b/salt/manager/tools/sbin_jinja/so-elastic-fleet-reset index 558590601..068b3ce8f 100644 --- a/salt/manager/tools/sbin_jinja/so-elastic-fleet-reset +++ b/salt/manager/tools/sbin_jinja/so-elastic-fleet-reset @@ -59,6 +59,15 @@ do done done +status "Deleting Fleet-related Data Streams..." +DATASTREAMS="logs-suricata-so","logs-kratos-so","logs-soc-so","logs-zeek-so" +JSON_STRING=$( jq -n \ + --arg DATASTREAMLIST "$DATASTREAMS" \ + '{"dataStreams":[$DATASTREAMLIST]}' + ) +curl -K /opt/so/conf/elasticsearch/curl.config -L -X POST "localhost:5601/api/index_management/delete_data_streams" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d "$JSON_STRING" + + status "Restarting Kibana..." so-kibana-restart --force