diff --git a/salt/logstash/pipelines/config/so/9101_output_osquery_livequery.conf.jinja b/salt/logstash/pipelines/config/so/9101_output_osquery_livequery.conf.jinja deleted file mode 100644 index 8d661b8cc..000000000 --- a/salt/logstash/pipelines/config/so/9101_output_osquery_livequery.conf.jinja +++ /dev/null @@ -1,37 +0,0 @@ -{%- set ES = salt['grains.get']('master') -%} -{%- set ES_USER = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:user', '') %} -{%- set ES_PASS = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:pass', '') %} - -filter { - if [type] =~ "live_query" { - - mutate { - rename => { - "[host][hostname]" => "computer_name" - } - } - - prune { - blacklist_names => ["host"] - } - - split { - field => "rows" - } - } -} - - -output { - if [type] =~ "live_query" { - elasticsearch { - pipeline => "osquery.live_query" - hosts => "{{ ES }}" - user => "{{ ES_USER }}" - password => "{{ ES_PASS }}" - index => "so-osquery" - ssl => true - ssl_certificate_verification => false - } - } -}