add osquery logs if fleet is enabled

This commit is contained in:
Josh Brower
2018-12-28 13:49:53 -05:00
committed by GitHub
parent 94d25d96e9
commit 44eed120cb

View File

@@ -2,6 +2,7 @@
{%- set HOSTNAME = salt['grains.get']('host', '') %} {%- set HOSTNAME = salt['grains.get']('host', '') %}
{%- set BROVER = salt['pillar.get']('static:broversion', 'COMMUNITY') %} {%- set BROVER = salt['pillar.get']('static:broversion', 'COMMUNITY') %}
{%- set WAZUHENABLED = salt['pillar.get']('static:wazuh_enabled', '1') %} {%- set WAZUHENABLED = salt['pillar.get']('static:wazuh_enabled', '1') %}
{%- set FLEETENABLED = salt['pillar.get']('static:fleet_enabled', '1') %}
name: {{ HOSTNAME }} name: {{ HOSTNAME }}
@@ -61,6 +62,18 @@ filebeat.prospectors:
{%- endif %} {%- endif %}
{%- if FLEETENABLED == '1' %}
- type: log
paths:
- /osquery/logs/result.log
fields:
type: osquery
fields_under_root: true
clean_removed: false
close_removed: false
{%- endif %}
#----------------------------- Logstash output --------------------------------- #----------------------------- Logstash output ---------------------------------
output.logstash: output.logstash:
# Boolean flag to enable or disable the output module. # Boolean flag to enable or disable the output module.