Merge pull request #9315 from Security-Onion-Solutions/jertel/surifilecheck

Suricata support for filecheck; reduce cron noise
This commit is contained in:
Jason Ertel
2022-12-07 08:17:19 -05:00
committed by GitHub

View File

@@ -173,12 +173,19 @@ filecheck_script:
filecheck_restart: filecheck_restart:
cmd.run: cmd.run:
- name: pkill -f "python3 /opt/so/conf/strelka/filecheck" - name: pkill -f "python3 /opt/so/conf/strelka/filecheck"
- hide_output: True
- success_retcodes: [0,1]
- onchanges: - onchanges:
- file: filecheck_script - file: filecheck_script
filecheck_oldcronremoval:
cron.absent:
- name: 'ps -ef | grep filecheck | grep -v grep || python3 /opt/so/conf/strelka/filecheck >> /opt/so/log/strelka/filecheck_stdout.log 2>&1 &'
- user: {{ filecheck_runas }}
filecheck_run: filecheck_run:
cron.present: cron.present:
- name: 'ps -ef | grep filecheck | grep -v grep || python3 /opt/so/conf/strelka/filecheck >> /opt/so/log/strelka/filecheck_stdout.log 2>&1 &' - name: 'pgrep -f "python3 /opt/so/conf/strelka/filecheck" &> /dev/null || python3 /opt/so/conf/strelka/filecheck >> /opt/so/log/strelka/filecheck_stdout.log 2>&1 &'
- user: {{ filecheck_runas }} - user: {{ filecheck_runas }}
filcheck_history_clean: filcheck_history_clean: