mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-08 18:22:47 +01:00
Merge remote-tracking branch 'remotes/origin/dev' into soup2340
This commit is contained in:
@@ -19,7 +19,8 @@ files:
|
|||||||
- '/nsm/strelka/unprocessed/*'
|
- '/nsm/strelka/unprocessed/*'
|
||||||
delete: false
|
delete: false
|
||||||
gatekeeper: true
|
gatekeeper: true
|
||||||
|
processed: '/nsm/strelka/processed'
|
||||||
response:
|
response:
|
||||||
report: 5s
|
report: 5s
|
||||||
delta: 5s
|
delta: 5s
|
||||||
staging: '/nsm/strelka/processed'
|
staging: '/nsm/strelka/staging'
|
||||||
|
|||||||
@@ -86,6 +86,13 @@ strelkaprocessed:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
|
|
||||||
|
strelkastaging:
|
||||||
|
file.directory:
|
||||||
|
- name: /nsm/strelka/staging
|
||||||
|
- user: 939
|
||||||
|
- group: 939
|
||||||
|
- makedirs: True
|
||||||
|
|
||||||
strelkaunprocessed:
|
strelkaunprocessed:
|
||||||
file.directory:
|
file.directory:
|
||||||
- name: /nsm/strelka/unprocessed
|
- name: /nsm/strelka/unprocessed
|
||||||
@@ -213,4 +220,4 @@ strelka_zeek_extracted_sync:
|
|||||||
test.fail_without_changes:
|
test.fail_without_changes:
|
||||||
- name: {{sls}}_state_not_allowed
|
- name: {{sls}}_state_not_allowed
|
||||||
|
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
@@ -618,11 +618,8 @@
|
|||||||
# # Read stats from one or more Elasticsearch servers or clusters
|
# # Read stats from one or more Elasticsearch servers or clusters
|
||||||
{% if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone'] %}
|
{% if grains['role'] in ['so-manager', 'so-eval', 'so-managersearch', 'so-standalone'] %}
|
||||||
[[inputs.elasticsearch]]
|
[[inputs.elasticsearch]]
|
||||||
|
|
||||||
# ## specify a list of one or more Elasticsearch servers
|
|
||||||
# # you can add username and password to your url to use basic authentication:
|
|
||||||
# # servers = ["http://user:pass@localhost:9200"]
|
|
||||||
servers = ["https://{{ MANAGER }}:9200"]
|
servers = ["https://{{ MANAGER }}:9200"]
|
||||||
|
insecure_skip_verify = true
|
||||||
{% elif grains['role'] in ['so-node', 'so-hotnode', 'so-warmnode', 'so-heavynode'] %}
|
{% elif grains['role'] in ['so-node', 'so-hotnode', 'so-warmnode', 'so-heavynode'] %}
|
||||||
[[inputs.elasticsearch]]
|
[[inputs.elasticsearch]]
|
||||||
servers = ["https://{{ NODEIP }}:9200"]
|
servers = ["https://{{ NODEIP }}:9200"]
|
||||||
|
|||||||
Reference in New Issue
Block a user