update airgapEnabled in map file

This commit is contained in:
m0duspwnens
2024-05-06 12:59:45 -04:00
parent 38f74d2e9e
commit 554a203541
3 changed files with 2 additions and 6 deletions

View File

@@ -1246,7 +1246,6 @@ soc:
maxPacketCount: 5000
htmlDir: html
importUploadDir: /nsm/soc/uploads
airgapEnabled: false
modules:
cases: soc
filedatastore:

View File

@@ -41,9 +41,11 @@
{% if GLOBALS.airgap %}
{% do SOCMERGED.config.server.modules.elastalertengine.update({'rulesRepos': SOCMERGED.config.server.modules.elastalertengine.rulesRepos.airgap}) %}
{% do SOCMERGED.config.server.modules.strelkaengine.update({'rulesRepos': SOCMERGED.config.server.modules.strelkaengine.rulesRepos.airgap}) %}
{% do SOCMERGED.config.server.update({'airgapEnabled': true}) %}
{% else %}
{% do SOCMERGED.config.server.modules.elastalertengine.update({'rulesRepos': SOCMERGED.config.server.modules.elastalertengine.rulesRepos.default}) %}
{% do SOCMERGED.config.server.modules.strelkaengine.update({'rulesRepos': SOCMERGED.config.server.modules.strelkaengine.rulesRepos.default}) %}
{% do SOCMERGED.config.server.update({'airgapEnabled': false}) %}
{% endif %}
{# remove these modules if detections is disabled #}

View File

@@ -119,11 +119,6 @@ soc:
global: True
advanced: False
helpLink: sigma.html
airgapEnabled:
description: 'This setting dynamically changes to the current status of Airgap on this system and is used during the Sigma ruleset update process.'
global: True
advanced: True
helpLink: sigma.html
elastic:
index:
description: Comma-separated list of indices or index patterns (wildcard "*" supported) that SOC will search for records.