mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
strelka ui things
This commit is contained in:
@@ -531,10 +531,9 @@ strelka:
|
|||||||
response:
|
response:
|
||||||
log: "/var/log/strelka/strelka.log"
|
log: "/var/log/strelka/strelka.log"
|
||||||
manager:
|
manager:
|
||||||
coordinator:
|
coordinator:
|
||||||
addr: 'HOST:6380'
|
addr: 'HOST:6380'
|
||||||
db: 0
|
db: 0
|
||||||
|
|
||||||
rules:
|
rules:
|
||||||
enabled: True
|
enabled: True
|
||||||
repos:
|
repos:
|
||||||
@@ -557,3 +556,7 @@ strelka:
|
|||||||
- gen_susp_xor.yar
|
- gen_susp_xor.yar
|
||||||
- gen_webshells_ext_vars.yar
|
- gen_webshells_ext_vars.yar
|
||||||
- configured_vulns_ext_vars.yar
|
- configured_vulns_ext_vars.yar
|
||||||
|
filecheck:
|
||||||
|
historypath: '/nsm/strelka/history/'
|
||||||
|
strelkapath: '/nsm/strelka/unprocessed/'
|
||||||
|
logfile: '/opt/so/log/strelka/filecheck.log'
|
||||||
|
|||||||
@@ -1 +1,2 @@
|
|||||||
{{ FILECHECKCONFIG | yaml(false) }}
|
filecheck:
|
||||||
|
{{ FILECHECKCONFIG | yaml(false) | indent(width=2) }}
|
||||||
|
|||||||
@@ -1,12 +0,0 @@
|
|||||||
{% from 'vars/globals.map.jinja' import GLOBALS %}
|
|
||||||
{% import_yaml 'strelka/filecheck/defaults.yaml' as FILECHECKDEFAULTS %}
|
|
||||||
|
|
||||||
{% if GLOBALS.md_engine == "SURICATA" %}
|
|
||||||
{% set extract_path = '/nsm/suricata/extracted' %}
|
|
||||||
{% set filecheck_runas = 'suricata' %}
|
|
||||||
{% else %}
|
|
||||||
{% set extract_path = '/nsm/zeek/extracted/complete' %}
|
|
||||||
{% set filecheck_runas = 'socore' %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% do FILECHECKDEFAULTS.filecheck.update({'extract_path': extract_path}) %}
|
|
||||||
@@ -99,7 +99,7 @@ manager_config:
|
|||||||
- defaults:
|
- defaults:
|
||||||
MANAGERCONFIG: {{ STRELKAMERGED.config.manager }}
|
MANAGERCONFIG: {{ STRELKAMERGED.config.manager }}
|
||||||
|
|
||||||
{% if STRELKAMERGED.rules.enabled %}
|
{% if STRELKAMERGED.rules.enabled %}
|
||||||
|
|
||||||
strelkarules:
|
strelkarules:
|
||||||
file.recurse:
|
file.recurse:
|
||||||
@@ -109,7 +109,7 @@ strelkarules:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- clean: True
|
- clean: True
|
||||||
|
|
||||||
{% if grains['role'] in GLOBALS.manager_roles %}
|
{% if grains['role'] in GLOBALS.manager_roles %}
|
||||||
strelkarepos:
|
strelkarepos:
|
||||||
file.managed:
|
file.managed:
|
||||||
- name: /opt/so/conf/strelka/repos.txt
|
- name: /opt/so/conf/strelka/repos.txt
|
||||||
@@ -118,8 +118,8 @@ strelkarepos:
|
|||||||
- defaults:
|
- defaults:
|
||||||
STRELKAREPOS: {{ STRELKAMERGED.rules.repos }}
|
STRELKAREPOS: {{ STRELKAMERGED.rules.repos }}
|
||||||
|
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
strelkadatadir:
|
strelkadatadir:
|
||||||
file.directory:
|
file.directory:
|
||||||
@@ -185,7 +185,7 @@ filecheck_conf:
|
|||||||
- source: salt://strelka/filecheck/filecheck.yaml.jinja
|
- source: salt://strelka/filecheck/filecheck.yaml.jinja
|
||||||
- template: jinja
|
- template: jinja
|
||||||
- defaults:
|
- defaults:
|
||||||
FILECHECKCONFIG: {{ FILECHECKDEFAULTS }}
|
FILECHECKCONFIG: {{ STRELKAMERGED.filecheck }}
|
||||||
|
|
||||||
filecheck_script:
|
filecheck_script:
|
||||||
file.managed:
|
file.managed:
|
||||||
|
|||||||
@@ -17,4 +17,14 @@
|
|||||||
{% set manager_coordinator_port = STRELKADEFAULTS.strelka.config.manager.coordinator.addr.split(':')[1] %}
|
{% set manager_coordinator_port = STRELKADEFAULTS.strelka.config.manager.coordinator.addr.split(':')[1] %}
|
||||||
{% do STRELKADEFAULTS.strelka.config.manager.coordinator.update({'addr': HOST ~ ':' ~ manager_coordinator_port}) %}
|
{% do STRELKADEFAULTS.strelka.config.manager.coordinator.update({'addr': HOST ~ ':' ~ manager_coordinator_port}) %}
|
||||||
|
|
||||||
|
{% if GLOBALS.md_engine == "SURICATA" %}
|
||||||
|
{% set extract_path = '/nsm/suricata/extracted' %}
|
||||||
|
{% set filecheck_runas = 'suricata' %}
|
||||||
|
{% else %}
|
||||||
|
{% set extract_path = '/nsm/zeek/extracted/complete' %}
|
||||||
|
{% set filecheck_runas = 'socore' %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
{% do STRELKADEFAULTS.strelka.filecheck.update({'extract_path': extract_path}) %}
|
||||||
|
|
||||||
{% set STRELKAMERGED = salt['pillar.get']('strelka', STRELKADEFAULTS.strelka, merge=True) %}
|
{% set STRELKAMERGED = salt['pillar.get']('strelka', STRELKADEFAULTS.strelka, merge=True) %}
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user