Remove old modules

This commit is contained in:
Mike Reeves
2021-05-26 10:11:47 -04:00
parent 525d4325c7
commit 34d4eedf67
8 changed files with 12 additions and 37 deletions

View File

@@ -49,6 +49,12 @@ if [ "$ELASTICSEARCH_CONNECTED" == "no" ]; then
fi fi
echo "Setting up ingest pipeline(s)" echo "Setting up ingest pipeline(s)"
docker exec -it so-filebeat filebeat setup modules -pipelines -modules activemq,apache,auditd,aws,azure,barracuda,bluecoat,cef,checkpoint,cisco,coredns,crowdstrike,cyberark,cylance,elasticsearch,envoyproxy,f5,fortinet,gcp,google_workspace,googlecloud,gsuite,haproxy,ibmmq,icinga,iis,imperva,infoblox,iptables,juniper,kafka,kibana,logstash,microsoft,misp,mondogb,mssql,mysql,mysqlenterprise,nats,netflow,netscout,nginx,o365,okta,osquery,panw,pensando,postgresql,rabbitmq,radware,redis,santa,snort,snyk,sonicwall,sophos,squid,suricata,system,threatintel,tomcat,traefik,zeek,zoom,zscaler -c $FB_MODULE_YML
for MODULE in activemq apache auditd aws azure barracuda bluecoat cef checkpoint cisco coredns crowdstrike cyberark cylance elasticsearch envoyproxy f5 fortinet gcp google_workspace googlecloud gsuite haproxy ibmmq icinga iis imperva infoblox iptables juniper kafka kibana logstash microsoft misp mongodb mssql mysql nats netscout nginx o365 okta osquery panw postgresql rabbitmq radware redis santa snort snyk sonicwall sophos squid suricata system tomcat traefik zeek zscaler
do
echo "Loading $MODULE"
docker exec -it so-filebeat filebeat setup modules -pipelines -modules $MODULE -c $FB_MODULE_YML
sleep 2
done

View File

@@ -14,7 +14,6 @@ whiptail_manager_adv_service_zeeklogs() {
"conn" "Connection Logging" ON \ "conn" "Connection Logging" ON \
"dce_rpc" "RPC Logs" ON \ "dce_rpc" "RPC Logs" ON \
"dhcp" "DHCP Logs" ON \ "dhcp" "DHCP Logs" ON \
"dhcpv6" "DHCP IPv6 Logs" ON \
"dnp3" "DNP3 Logs" ON \ "dnp3" "DNP3 Logs" ON \
"dns" "DNS Logs" ON \ "dns" "DNS Logs" ON \
"dpd" "DPD Logs" ON \ "dpd" "DPD Logs" ON \
@@ -25,25 +24,20 @@ whiptail_manager_adv_service_zeeklogs() {
"irc" "IRC Chat Logs" ON \ "irc" "IRC Chat Logs" ON \
"kerberos" "Kerberos Logs" ON \ "kerberos" "Kerberos Logs" ON \
"modbus" "MODBUS Logs" ON \ "modbus" "MODBUS Logs" ON \
"mqtt" "MQTT Logs" ON \
"notice" "Zeek Notice Logs" ON \ "notice" "Zeek Notice Logs" ON \
"ntlm" "NTLM Logs" ON \ "ntlm" "NTLM Logs" ON \
"openvpn" "OPENVPN Logs" ON \
"pe" "PE Logs" ON \ "pe" "PE Logs" ON \
"radius" "Radius Logs" ON \ "radius" "Radius Logs" ON \
"rfb" "RFB Logs" ON \ "rfb" "RFB Logs" ON \
"rdp" "RDP Logs" ON \ "rdp" "RDP Logs" ON \
"signatures" "Signatures Logs" ON \
"sip" "SIP Logs" ON \ "sip" "SIP Logs" ON \
"smb_files" "SMB Files Logs" ON \ "smb_files" "SMB Files Logs" ON \
"smb_mapping" "SMB Mapping Logs" ON \ "smb_mapping" "SMB Mapping Logs" ON \
"smtp" "SMTP Logs" ON \ "smtp" "SMTP Logs" ON \
"snmp" "SNMP Logs" ON \ "snmp" "SNMP Logs" ON \
"software" "Software Logs" ON \
"ssh" "SSH Logs" ON \ "ssh" "SSH Logs" ON \
"ssl" "SSL Logs" ON \ "ssl" "SSL Logs" ON \
"syslog" "Syslog Logs" ON \ "syslog" "Syslog Logs" ON \
"telnet" "Telnet Logs" ON \
"tunnel" "Tunnel Logs" ON \ "tunnel" "Tunnel Logs" ON \
"weird" "Zeek Weird Logs" ON \ "weird" "Zeek Weird Logs" ON \
"mysql" "MySQL Logs" ON \ "mysql" "MySQL Logs" ON \

View File

@@ -3,7 +3,7 @@
- module: {{ module }} - module: {{ module }}
{%- for fileset in MODULES.modules[module] %} {%- for fileset in MODULES.modules[module] %}
{{ fileset }}: {{ fileset }}:
enabled: {{ MODULES.modules[module][fileset].enabled }} enabled: {{ MODULES.modules[module][fileset].enabled|string|lower }}
{#- only manage the settings if the fileset is enabled #} {#- only manage the settings if the fileset is enabled #}
{%- if MODULES.modules[module][fileset].enabled %} {%- if MODULES.modules[module][fileset].enabled %}
{%- for var, value in MODULES.modules[module][fileset].items() %} {%- for var, value in MODULES.modules[module][fileset].items() %}

View File

@@ -21,6 +21,8 @@ securityonion_filebeat:
log: log:
enabled: true enabled: true
var.paths: ["/logs/redis.log"] var.paths: ["/logs/redis.log"]
slowlog:
enabled: false
suricata: suricata:
eve: eve:
enabled: true enabled: true

View File

@@ -199,12 +199,6 @@ third_party_filebeat:
okta: okta:
system: system:
enabled: false enabled: false
pesando:
dfw:
enabled: false
var.input: udp
var.syslog_host: 0.0.0.0
var.syslog_port: 9001
proofpoint: proofpoint:
emailsecurity: emailsecurity:
enabled: false enabled: false
@@ -251,17 +245,6 @@ third_party_filebeat:
var.input: udp var.input: udp
var.syslog_host: 0.0.0.0 var.syslog_host: 0.0.0.0
var.syslog_port: 9520 var.syslog_port: 9520
threatintel:
abuseurl:
enabled: false
abusemalware:
enabled: false
misp:
enabled: false
otx:
enabled: false
anomali:
enabled: false
tomcat: tomcat:
log: log:
enabled: false enabled: false

View File

@@ -183,6 +183,8 @@ so-zeek:
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-zeek:{{ VERSION }} - image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-zeek:{{ VERSION }}
- start: {{ START }} - start: {{ START }}
- privileged: True - privileged: True
- ulimits:
- core=0
- binds: - binds:
- /nsm/zeek/logs:/nsm/zeek/logs:rw - /nsm/zeek/logs:/nsm/zeek/logs:rw
- /nsm/zeek/spool:/nsm/zeek/spool:rw - /nsm/zeek/spool:/nsm/zeek/spool:rw

View File

@@ -2827,7 +2827,6 @@ zeek_logs_enabled() {
" - conn"\ " - conn"\
" - dce_rpc"\ " - dce_rpc"\
" - dhcp"\ " - dhcp"\
" - dhcpv6"\
" - dnp3"\ " - dnp3"\
" - dns"\ " - dns"\
" - dpd"\ " - dpd"\
@@ -2838,25 +2837,20 @@ zeek_logs_enabled() {
" - irc"\ " - irc"\
" - kerberos"\ " - kerberos"\
" - modbus"\ " - modbus"\
" - mqtt"\
" - notice"\ " - notice"\
" - ntlm"\ " - ntlm"\
" - openvpn"\
" - pe"\ " - pe"\
" - radius"\ " - radius"\
" - rfb"\ " - rfb"\
" - rdp"\ " - rdp"\
" - signatures"\
" - sip"\ " - sip"\
" - smb_files"\ " - smb_files"\
" - smb_mapping"\ " - smb_mapping"\
" - smtp"\ " - smtp"\
" - snmp"\ " - snmp"\
" - software"\
" - ssh"\ " - ssh"\
" - ssl"\ " - ssl"\
" - syslog"\ " - syslog"\
" - telnet"\
" - tunnel"\ " - tunnel"\
" - weird"\ " - weird"\
" - mysql"\ " - mysql"\

View File

@@ -1154,7 +1154,6 @@ whiptail_manager_adv_service_zeeklogs() {
"conn" "Connection Logging" ON \ "conn" "Connection Logging" ON \
"dce_rpc" "RPC Logs" ON \ "dce_rpc" "RPC Logs" ON \
"dhcp" "DHCP Logs" ON \ "dhcp" "DHCP Logs" ON \
"dhcpv6" "DHCP IPv6 Logs" ON \
"dnp3" "DNP3 Logs" ON \ "dnp3" "DNP3 Logs" ON \
"dns" "DNS Logs" ON \ "dns" "DNS Logs" ON \
"dpd" "DPD Logs" ON \ "dpd" "DPD Logs" ON \
@@ -1165,25 +1164,20 @@ whiptail_manager_adv_service_zeeklogs() {
"irc" "IRC Chat Logs" ON \ "irc" "IRC Chat Logs" ON \
"kerberos" "Kerberos Logs" ON \ "kerberos" "Kerberos Logs" ON \
"modbus" "MODBUS Logs" ON \ "modbus" "MODBUS Logs" ON \
"mqtt" "MQTT Logs" ON \
"notice" "Zeek Notice Logs" ON \ "notice" "Zeek Notice Logs" ON \
"ntlm" "NTLM Logs" ON \ "ntlm" "NTLM Logs" ON \
"openvpn" "OPENVPN Logs" ON \
"pe" "PE Logs" ON \ "pe" "PE Logs" ON \
"radius" "Radius Logs" ON \ "radius" "Radius Logs" ON \
"rfb" "RFB Logs" ON \ "rfb" "RFB Logs" ON \
"rdp" "RDP Logs" ON \ "rdp" "RDP Logs" ON \
"signatures" "Signatures Logs" ON \
"sip" "SIP Logs" ON \ "sip" "SIP Logs" ON \
"smb_files" "SMB Files Logs" ON \ "smb_files" "SMB Files Logs" ON \
"smb_mapping" "SMB Mapping Logs" ON \ "smb_mapping" "SMB Mapping Logs" ON \
"smtp" "SMTP Logs" ON \ "smtp" "SMTP Logs" ON \
"snmp" "SNMP Logs" ON \ "snmp" "SNMP Logs" ON \
"software" "Software Logs" ON \
"ssh" "SSH Logs" ON \ "ssh" "SSH Logs" ON \
"ssl" "SSL Logs" ON \ "ssl" "SSL Logs" ON \
"syslog" "Syslog Logs" ON \ "syslog" "Syslog Logs" ON \
"telnet" "Telnet Logs" ON \
"tunnel" "Tunnel Logs" ON \ "tunnel" "Tunnel Logs" ON \
"weird" "Zeek Weird Logs" ON \ "weird" "Zeek Weird Logs" ON \
"mysql" "MySQL Logs" ON \ "mysql" "MySQL Logs" ON \