mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Fix zeek logs in filebeat
This commit is contained in:
@@ -1,6 +1,5 @@
|
||||
filebeat:
|
||||
config:
|
||||
|
||||
zeek_logs_enabled:
|
||||
- conn
|
||||
- dce_rpc
|
||||
|
||||
@@ -131,7 +131,11 @@ filebeat.inputs:
|
||||
|
||||
{%- if grains['role'] in ['so-eval', 'so-standalone', 'so-sensor', 'so-helix', 'so-heavynode', 'so-import'] %}
|
||||
{%- if ZEEKVER != 'SURICATA' %}
|
||||
{%- for LOGNAME in salt['pillar.get']('filebeat:zeek_logs_enabled', '') %}
|
||||
{% import_yaml 'filebeat/defaults.yaml' as FBD with context %}
|
||||
|
||||
{% set FBCONFIG = salt['pillar.get']('filebeat:zeek_logs_enabled', default=FBD.filebeat, merge=True) %}
|
||||
|
||||
{%- for LOGNAME in FBCONFIG.zeek_logs_enabled %}
|
||||
- type: filestream
|
||||
id: zeek-{{ LOGNAME }}
|
||||
paths:
|
||||
|
||||
Reference in New Issue
Block a user