mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
strelka ui things
This commit is contained in:
@@ -534,7 +534,6 @@ strelka:
|
|||||||
coordinator:
|
coordinator:
|
||||||
addr: 'HOST:6380'
|
addr: 'HOST:6380'
|
||||||
db: 0
|
db: 0
|
||||||
|
|
||||||
rules:
|
rules:
|
||||||
enabled: True
|
enabled: True
|
||||||
repos:
|
repos:
|
||||||
@@ -557,3 +556,7 @@ strelka:
|
|||||||
- gen_susp_xor.yar
|
- gen_susp_xor.yar
|
||||||
- gen_webshells_ext_vars.yar
|
- gen_webshells_ext_vars.yar
|
||||||
- configured_vulns_ext_vars.yar
|
- configured_vulns_ext_vars.yar
|
||||||
|
filecheck:
|
||||||
|
historypath: '/nsm/strelka/history/'
|
||||||
|
strelkapath: '/nsm/strelka/unprocessed/'
|
||||||
|
logfile: '/opt/so/log/strelka/filecheck.log'
|
||||||
|
|||||||
@@ -1 +1,2 @@
|
|||||||
{{ FILECHECKCONFIG | yaml(false) }}
|
filecheck:
|
||||||
|
{{ FILECHECKCONFIG | yaml(false) | indent(width=2) }}
|
||||||
|
|||||||
@@ -1,12 +0,0 @@
|
|||||||
{% from 'vars/globals.map.jinja' import GLOBALS %}
|
|
||||||
{% import_yaml 'strelka/filecheck/defaults.yaml' as FILECHECKDEFAULTS %}
|
|
||||||
|
|
||||||
{% if GLOBALS.md_engine == "SURICATA" %}
|
|
||||||
{% set extract_path = '/nsm/suricata/extracted' %}
|
|
||||||
{% set filecheck_runas = 'suricata' %}
|
|
||||||
{% else %}
|
|
||||||
{% set extract_path = '/nsm/zeek/extracted/complete' %}
|
|
||||||
{% set filecheck_runas = 'socore' %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% do FILECHECKDEFAULTS.filecheck.update({'extract_path': extract_path}) %}
|
|
||||||
@@ -185,7 +185,7 @@ filecheck_conf:
|
|||||||
- source: salt://strelka/filecheck/filecheck.yaml.jinja
|
- source: salt://strelka/filecheck/filecheck.yaml.jinja
|
||||||
- template: jinja
|
- template: jinja
|
||||||
- defaults:
|
- defaults:
|
||||||
FILECHECKCONFIG: {{ FILECHECKDEFAULTS }}
|
FILECHECKCONFIG: {{ STRELKAMERGED.filecheck }}
|
||||||
|
|
||||||
filecheck_script:
|
filecheck_script:
|
||||||
file.managed:
|
file.managed:
|
||||||
|
|||||||
@@ -17,4 +17,14 @@
|
|||||||
{% set manager_coordinator_port = STRELKADEFAULTS.strelka.config.manager.coordinator.addr.split(':')[1] %}
|
{% set manager_coordinator_port = STRELKADEFAULTS.strelka.config.manager.coordinator.addr.split(':')[1] %}
|
||||||
{% do STRELKADEFAULTS.strelka.config.manager.coordinator.update({'addr': HOST ~ ':' ~ manager_coordinator_port}) %}
|
{% do STRELKADEFAULTS.strelka.config.manager.coordinator.update({'addr': HOST ~ ':' ~ manager_coordinator_port}) %}
|
||||||
|
|
||||||
|
{% if GLOBALS.md_engine == "SURICATA" %}
|
||||||
|
{% set extract_path = '/nsm/suricata/extracted' %}
|
||||||
|
{% set filecheck_runas = 'suricata' %}
|
||||||
|
{% else %}
|
||||||
|
{% set extract_path = '/nsm/zeek/extracted/complete' %}
|
||||||
|
{% set filecheck_runas = 'socore' %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% do STRELKADEFAULTS.strelka.filecheck.update({'extract_path': extract_path}) %}
|
||||||
|
|
||||||
{% set STRELKAMERGED = salt['pillar.get']('strelka', STRELKADEFAULTS.strelka, merge=True) %}
|
{% set STRELKAMERGED = salt['pillar.get']('strelka', STRELKADEFAULTS.strelka, merge=True) %}
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user