mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-04-26 22:47:49 +02:00
merge with dev and resolv conflicts
This commit is contained in:
@@ -1,6 +1,12 @@
|
||||
<<<<<<< HEAD
|
||||
{% set es = salt['pillar.get']('static:managerip', '') %}
|
||||
{% set hivehost = salt['pillar.get']('static:managerip', '') %}
|
||||
{% set hivekey = salt['pillar.get']('static:hivekey', '') %}
|
||||
=======
|
||||
{%- set es = salt['pillar.get']('static:masterip', '') %}
|
||||
{%- set hivehost = salt['pillar.get']('static:masterip', '') %}
|
||||
{%- set hivekey = salt['pillar.get']('static:hivekey', '') %}
|
||||
>>>>>>> remotes/origin/dev
|
||||
alert: hivealerter
|
||||
|
||||
hive_connection:
|
||||
@@ -23,3 +29,15 @@ hive_alert_config:
|
||||
status: 'New'
|
||||
follow: True
|
||||
caseTemplate: '5000'
|
||||
|
||||
alert: modules.so.playbook-es.PlaybookESAlerter
|
||||
elasticsearch_host: "{{ es }}:9200"
|
||||
play_title: ""
|
||||
event.module: "playbook"
|
||||
event.dataset: "alert"
|
||||
event.severity:
|
||||
rule.category:
|
||||
play_url: "https://{{ es }}/playbook/issues/6000"
|
||||
kibana_pivot: "https://{{es}}/kibana/app/kibana#/discover?_g=()&_a=(columns:!(_source),interval:auto,query:(language:lucene,query:'_id:{[_id]}'),sort:!('@timestamp',desc))"
|
||||
soc_pivot: "https://{{es}}/#/hunt"
|
||||
sigma_level: ""
|
||||
@@ -31,3 +31,14 @@ hive_alert_config:
|
||||
caseTemplate: '5000'
|
||||
|
||||
|
||||
alert: modules.so.playbook-es.PlaybookESAlerter
|
||||
elasticsearch_host: "{{ es }}:9200"
|
||||
play_title: ""
|
||||
event.module: "playbook"
|
||||
event.dataset: "alert"
|
||||
event.severity:
|
||||
rule.category:
|
||||
play_url: "https://{{ es }}/playbook/issues/6000"
|
||||
kibana_pivot: "https://{{es}}/kibana/app/kibana#/discover?_g=()&_a=(columns:!(_source),interval:auto,query:(language:lucene,query:'_id:{[_id]}'),sort:!('@timestamp',desc))"
|
||||
soc_pivot: "https://{{es}}/#/hunt"
|
||||
sigma_level: ""
|
||||
Reference in New Issue
Block a user