mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-07 17:52:46 +01:00
Merge pull request #8752 from Security-Onion-Solutions/fix/logstash_remove_osquery_livequery_output_configuration
Remove Osquery live query Logstash output configuration
This commit is contained in:
@@ -1,37 +0,0 @@
|
|||||||
{%- set ES = salt['grains.get']('master') -%}
|
|
||||||
{%- set ES_USER = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:user', '') %}
|
|
||||||
{%- set ES_PASS = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:pass', '') %}
|
|
||||||
|
|
||||||
filter {
|
|
||||||
if [type] =~ "live_query" {
|
|
||||||
|
|
||||||
mutate {
|
|
||||||
rename => {
|
|
||||||
"[host][hostname]" => "computer_name"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
prune {
|
|
||||||
blacklist_names => ["host"]
|
|
||||||
}
|
|
||||||
|
|
||||||
split {
|
|
||||||
field => "rows"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
output {
|
|
||||||
if [type] =~ "live_query" {
|
|
||||||
elasticsearch {
|
|
||||||
pipeline => "osquery.live_query"
|
|
||||||
hosts => "{{ ES }}"
|
|
||||||
user => "{{ ES_USER }}"
|
|
||||||
password => "{{ ES_PASS }}"
|
|
||||||
index => "so-osquery"
|
|
||||||
ssl => true
|
|
||||||
ssl_certificate_verification => false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user