add elasticsearch template manager pillar and assign to manager node

This commit is contained in:
m0duspwnens
2020-10-13 16:08:15 -04:00
parent f6296c095f
commit 1afa12e607
2 changed files with 31 additions and 17 deletions

View File

@@ -0,0 +1,13 @@
elasticsearch:
templates:
- so/so-beats-template.json.jinja
- so/so-common-template.json
- so/so-firewall-template.json.jinja
- so/so-flow-template.json.jinja
- so/so-ids-template.json.jinja
- so/so-import-template.json.jinja
- so/so-osquery-template.json.jinja
- so/so-ossec-template.json.jinja
- so/so-strelka-template.json.jinja
- so/so-syslog-template.json.jinja
- so/so-zeek-template.json.jinja

View File

@@ -14,22 +14,23 @@ base:
- logstash.search - logstash.search
- elasticsearch.search - elasticsearch.search
'*_sensor':
- global
- zeeklogs
- healthcheck.sensor
- minions.{{ grains.id }}
'*_manager or *_managersearch':
- match: compound
- global
- data.*
- secrets
- minions.{{ grains.id }}
'*_manager': '*_manager':
- logstash - logstash
- logstash.manager - logstash.manager
- elasticsearch.manager
'*_manager or *_managersearch':
- match: compound
- data.*
- secrets
- global
- minions.{{ grains.id }}
'*_sensor':
- zeeklogs
- healthcheck.sensor
- global
- minions.{{ grains.id }}
'*_eval': '*_eval':
- data.* - data.*
@@ -57,29 +58,29 @@ base:
- minions.{{ grains.id }} - minions.{{ grains.id }}
'*_heavynode': '*_heavynode':
- global
- zeeklogs - zeeklogs
- global
- minions.{{ grains.id }} - minions.{{ grains.id }}
'*_helix': '*_helix':
- global
- fireeye - fireeye
- zeeklogs - zeeklogs
- logstash - logstash
- logstash.helix - logstash.helix
- global
- minions.{{ grains.id }} - minions.{{ grains.id }}
'*_fleet': '*_fleet':
- global
- data.* - data.*
- secrets - secrets
- global
- minions.{{ grains.id }} - minions.{{ grains.id }}
'*_searchnode': '*_searchnode':
- global
- logstash - logstash
- logstash.search - logstash.search
- elasticsearch.search - elasticsearch.search
- global
- minions.{{ grains.id }} - minions.{{ grains.id }}
'*_import': '*_import':