change defaults for testing, remove measurements list since cq uses wildcard now - https://github.com/Security-Onion-Solutions/securityonion/issues/3264

This commit is contained in:
m0duspwnens
2021-04-01 10:18:01 -04:00
parent 8e55e0b994
commit 4f3b3a787c

View File

@@ -2,34 +2,12 @@ influxdb:
retention_policies: retention_policies:
autogen: autogen:
default: True default: True
duration: 1h duration: 2d
shard_duration: 1h shard_duration: 1h
so_long_term: so_long_term:
default: False default: False
duration: 2d duration: 7d
shard_duration: 1d shard_duration: 1d
downsample: downsample:
so_long_term: so_long_term:
resolution: 5m resolution: 5m
measurements:
- cpu
- disk
- diskio
- docker_container_cpu
- docker_container_mem
- docker_container_net
- elasticsearch_indices
- elasticsearch_jvm
- esteps
- healthcheck
- influxsize
- mem
- net
- pcapage
- processes
- redisqueue
- stenodrop
- suridrop
- system
- zeekcaptureloss
- zeekdrop