Merge pull request #431 from Security-Onion-Solutions/fix/elastic_changes

Fix/elastic changes
This commit is contained in:
weslambert
2020-03-17 17:32:05 -04:00
committed by GitHub
4 changed files with 8 additions and 8 deletions

View File

@@ -4,7 +4,7 @@
server.name: kibana server.name: kibana
server.host: "0" server.host: "0"
server.basePath: /kibana server.basePath: /kibana
elasticsearch.url: http://{{ ES }}:9200 elasticsearch.hosts: [ "http://{{ ES }}:9200" ]
#kibana.index: ".kibana" #kibana.index: ".kibana"
#elasticsearch.username: elastic #elasticsearch.username: elastic
#elasticsearch.password: changeme #elasticsearch.password: changeme

View File

@@ -21,9 +21,9 @@ output {
elasticsearch { elasticsearch {
pipeline => "%{event_type}" pipeline => "%{event_type}"
hosts => "{{ ES }}" hosts => "{{ ES }}"
index => "so-ossec-%{+YYYY.MM.dd}" index => "so-common-%{+YYYY.MM.dd}"
template_name => "so-ossec" template_name => "so-common"
template => "/so-ossec-template.json" template => "/so-common-template.json"
template_overwrite => true template_overwrite => true
} }
} }

View File

@@ -20,9 +20,9 @@ output {
if [event_type] =~ "strelka" { if [event_type] =~ "strelka" {
elasticsearch { elasticsearch {
hosts => "{{ ES }}" hosts => "{{ ES }}"
index => "so-strelka-%{+YYYY.MM.dd}" index => "so-common-%{+YYYY.MM.dd}"
template_name => "so-strelka" template_name => "so-common"
template => "/so-strelka-template.json" template => "/so-common-template.json"
template_overwrite => true template_overwrite => true
} }
} }

View File

@@ -743,7 +743,7 @@ master_static() {
touch /opt/so/saltstack/pillar/static.sls touch /opt/so/saltstack/pillar/static.sls
echo "static:" > /opt/so/saltstack/pillar/static.sls echo "static:" > /opt/so/saltstack/pillar/static.sls
echo " soversion: HH1.1.4" >> /opt/so/saltstack/pillar/static.sls echo " soversion: HH1.2.1" >> /opt/so/saltstack/pillar/static.sls
echo " hnmaster: $HNMASTER" >> /opt/so/saltstack/pillar/static.sls echo " hnmaster: $HNMASTER" >> /opt/so/saltstack/pillar/static.sls
echo " ntpserver: $NTPSERVER" >> /opt/so/saltstack/pillar/static.sls echo " ntpserver: $NTPSERVER" >> /opt/so/saltstack/pillar/static.sls
echo " proxy: $PROXY" >> /opt/so/saltstack/pillar/static.sls echo " proxy: $PROXY" >> /opt/so/saltstack/pillar/static.sls