mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-19 23:43:07 +01:00
Update Strelka init for rules
This commit is contained in:
@@ -25,6 +25,13 @@ strelkaconfdir:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
|
|
||||||
|
strelkarulesdir:
|
||||||
|
file.directory:
|
||||||
|
- name: /opt/so/conf/strelka/rules
|
||||||
|
- user: 939
|
||||||
|
- group: 939
|
||||||
|
- makedirs: True
|
||||||
|
|
||||||
# Sync dynamic config to conf dir
|
# Sync dynamic config to conf dir
|
||||||
strelkasync:
|
strelkasync:
|
||||||
file.recurse:
|
file.recurse:
|
||||||
@@ -33,9 +40,21 @@ strelkasync:
|
|||||||
- user: 939
|
- user: 939
|
||||||
- group: 939
|
- group: 939
|
||||||
- template: jinja
|
- template: jinja
|
||||||
{%- if STRELKA_RULES != 1 %}
|
|
||||||
- exclude_pat: rules/
|
{%- if STRELKA_RULES == 1 %}
|
||||||
{%- endif %}
|
strelka_yara_update:
|
||||||
|
cron.present:
|
||||||
|
- user: root
|
||||||
|
- name: '[ -d /opt/so/saltstack/default/salt/strelka/rules/ ] && /usr/sbin/so-yara-update > /dev/null 2>&1'
|
||||||
|
- hour: '7'
|
||||||
|
|
||||||
|
strelkarules:
|
||||||
|
file.recurse:
|
||||||
|
- name: /opt/so/conf/strelka/rules
|
||||||
|
- source: salt://strelka/rules
|
||||||
|
- user: 939
|
||||||
|
- group: 939
|
||||||
|
{%- endif %}
|
||||||
|
|
||||||
strelkadatadir:
|
strelkadatadir:
|
||||||
file.directory:
|
file.directory:
|
||||||
|
|||||||
Reference in New Issue
Block a user