diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 763768d72..64a734032 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1496,7 +1496,7 @@ soc: verifyCert: false notification: dismissedPruneDays: 30 - enabled: false + enabled: true playbook: autoUpdateEnabled: true playbookImportFrequencySeconds: 86400 @@ -1634,6 +1634,13 @@ soc: database: securityonion user: "" password: "" + postgresmetrics: + host: "" + port: 5432 + sslMode: "require" + database: telegraf + user: "" + password: "" salt: queueDir: /opt/sensoroni/queue timeoutMs: 45000 diff --git a/salt/soc/soc_soc.yaml b/salt/soc/soc_soc.yaml index 365775259..adb19833e 100644 --- a/salt/soc/soc_soc.yaml +++ b/salt/soc/soc_soc.yaml @@ -160,6 +160,7 @@ soc: description: Schedules that are shared across the Security Onion product. Modify via one of the SOC Schedules view. readonlyUi: True global: True + advanced: True forcedType: string syntax: json storage: db @@ -495,6 +496,7 @@ soc: description: JSON list of notifications. Modify via the SOC Notifications view. readonlyUi: True global: True + advanced: True forcedType: string syntax: json storage: db @@ -503,6 +505,10 @@ soc: description: The number of days to retain dismissed notifications. When a notification is dismissed, it will be pruned after this many days. Only one user need dismiss a notification for it to be pruned. forcedType: int global: True + maxListLimit: + description: Maximum number of notifications to display. + forcedType: int + global: True enabled: description: Enables or disables the SOC notification module. forcedType: bool @@ -533,6 +539,48 @@ soc: global: True sensitive: True advanced: True + postgresmetrics: + host: + description: Hostname or IP address of the PostgreSQL server used by Telegraf. Defaults to the manager hostname. + global: True + advanced: True + port: + description: Port of the PostgreSQL server used by Telegraf. + global: True + advanced: True + sslMode: + description: "Use encrypted connections to the PostgreSQL server used by Telegraf. Must be one of the following values: disable, allow, prefer, require, verify-ca, verify-full." + global: True + advanced: True + database: + description: Database to authenticate to on the PostgreSQL server. + global: True + advanced: True + user: + description: Username to authenticate to the PostgreSQL server used by Telegraf. + global: True + advanced: True + password: + description: Password used to authenticate to the PostgreSQL server used by Telegraf. + global: True + sensitive: True + advanced: True + cacheExpirationMs: + description: The interval (in milliseconds) to wait before querying the DB for updated metrics. + global: True + advanced: True + maxMetricAgeSeconds: + description: The maximum age (in seconds) of metrics to display in the SOC Grid Metrics view. Metrics older than this value will not be displayed. + global: True + advanced: True + alarms: + description: JSON list of metric alarms. Modify via the SOC Grid Alarms view. + readonlyUi: True + advanced: True + global: True + forcedType: string + syntax: json + storage: db salt: longRelayTimeoutMs: description: Duration (in milliseconds) to wait for a response from the Salt API when executing tasks known for being long running before giving up and showing an error on the SOC UI.