diff --git a/salt/filebeat/etc/filebeat.yml b/salt/filebeat/etc/filebeat.yml index 826073856..3be56233e 100644 --- a/salt/filebeat/etc/filebeat.yml +++ b/salt/filebeat/etc/filebeat.yml @@ -164,9 +164,10 @@ filebeat.inputs: - type: log paths: - - /opt/so/log/strelka/strelka.log + - /nsm/strelka/log/strelka.log fields: module: strelka + category: file dataset: file processors: @@ -197,6 +198,9 @@ output.elasticsearch: - index: "so-osquery-%{+yyyy.MM.dd}" when.contains: module: "osquery" + - index: "so-strelka-%{+yyyy.MM.dd}" + when.contains: + module: "strelka" #output.logstash: # Boolean flag to enable or disable the output module. diff --git a/salt/fleet/files/osquery-packages.html b/salt/fleet/files/osquery-packages.html deleted file mode 100644 index a64e6a2df..000000000 --- a/salt/fleet/files/osquery-packages.html +++ /dev/null @@ -1,133 +0,0 @@ -{%- set PACKAGESTS = salt['pillar.get']('static:fleet_packages-timestamp:', 'N/A') -%} - - -
--