Handle YARA rules for distributed deployments

This commit is contained in:
Wes
2024-05-06 19:08:01 +00:00
parent a67f0d93a0
commit 5aa611302a
3 changed files with 15 additions and 0 deletions

View File

@@ -65,6 +65,7 @@
'registry', 'registry',
'manager', 'manager',
'nginx', 'nginx',
'strelka.manager',
'soc', 'soc',
'kratos', 'kratos',
'influxdb', 'influxdb',
@@ -91,6 +92,7 @@
'nginx', 'nginx',
'telegraf', 'telegraf',
'influxdb', 'influxdb',
'strelka.manager',
'soc', 'soc',
'kratos', 'kratos',
'elasticfleet', 'elasticfleet',
@@ -111,6 +113,7 @@
'nginx', 'nginx',
'telegraf', 'telegraf',
'influxdb', 'influxdb',
'strelka.manager',
'soc', 'soc',
'kratos', 'kratos',
'elastic-fleet-package-registry', 'elastic-fleet-package-registry',

View File

@@ -29,6 +29,15 @@ strelkarulesdir:
- group: 939 - group: 939
- makedirs: True - makedirs: True
{%- if grains.role in ['so-sensor', 'so-heavynode'] %}
strelkasensorrules:
file.managed:
- name: /opt/so/conf/strelka/rules/compiled/rules.compiled
- source: salt://strelka/rules/compiled/rules.compiled
- user: 939
- group: 939
{%- endif %}
strelkareposdir: strelkareposdir:
file.directory: file.directory:
- name: /opt/so/conf/strelka/repos - name: /opt/so/conf/strelka/repos

View File

@@ -87,6 +87,7 @@ base:
- registry - registry
- nginx - nginx
- influxdb - influxdb
- strelka.manager
- soc - soc
- kratos - kratos
- firewall - firewall
@@ -161,6 +162,7 @@ base:
- registry - registry
- nginx - nginx
- influxdb - influxdb
- strelka.manager
- soc - soc
- kratos - kratos
- firewall - firewall
@@ -210,6 +212,7 @@ base:
- manager - manager
- nginx - nginx
- influxdb - influxdb
- strelka.manager
- soc - soc
- kratos - kratos
- sensoroni - sensoroni