mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-09 10:42:54 +01:00
Fix yaml for idh,es,kib,esalert
This commit is contained in:
@@ -31,6 +31,9 @@
|
||||
|
||||
{# merge with the elasticsearch pillar #}
|
||||
{% set ESCONFIG = salt['pillar.get']('elasticsearch:config', default=ESCONFIG.elasticsearch.config, merge=True) %}
|
||||
{% do ESCONFIG.elasticsearch.config.node.update({'name': grains.host}) %}
|
||||
{% do ESCONFIG.elasticsearch.config.cluster.update({'name': grains.host}) %}
|
||||
{% do ESCONFIG.elasticsearch.config.transport.update({'publish_host': grains.host}) %}
|
||||
|
||||
{% if salt['pillar.get']('elasticsearch:config:path:repo', False) %}
|
||||
{% for repo in pillar.elasticsearch.config.path.repo %}
|
||||
|
||||
@@ -1,11 +1,9 @@
|
||||
elasticsearch:
|
||||
config:
|
||||
node:
|
||||
name: {{ grains.host }}
|
||||
attr:
|
||||
box_type: hot
|
||||
cluster:
|
||||
name: {{ grains.host }}
|
||||
routing:
|
||||
allocation:
|
||||
disk:
|
||||
@@ -22,7 +20,6 @@ elasticsearch:
|
||||
destructive_requires_name: true
|
||||
transport:
|
||||
bind_host: 0.0.0.0
|
||||
publish_host: {{ grains.host }}
|
||||
publish_port: 9300
|
||||
xpack:
|
||||
ml:
|
||||
@@ -60,380 +57,6 @@ elasticsearch:
|
||||
elasticsearch:
|
||||
deprecation: ERROR
|
||||
index_settings:
|
||||
so-logs-elastic_agent.apm_server:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.apm_server-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.apm_server@package"
|
||||
- "so-logs-elastic_agent.apm_server@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.auditbeat:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.auditbeat-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.auditbeat@package"
|
||||
- "so-logs-elastic_agent.auditbeat@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.cloudbeat:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.cloudbeat-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.cloudbeat@package"
|
||||
- "so-logs-elastic_agent.cloudbeat@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.endpoint_security:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.endpoint_security-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.endpoint_security@package"
|
||||
- "so-logs-elastic_agent.endpoint_security@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.filebeat:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.filebeat-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.filebeat@package"
|
||||
- "so-logs-elastic_agent.filebeat@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.fleet_server:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.fleet_server-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.fleet_server@package"
|
||||
- "so-logs-elastic_agent.fleet_server@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.heartbeat:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.heartbeat-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.heartbeat@package"
|
||||
- "so-logs-elastic_agent.heartbeat@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent@package"
|
||||
- "so-logs-elastic_agent@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.metricbeat:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.metricbeat-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.metricbeat@package"
|
||||
- "so-logs-elastic_agent.metricbeat@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.osquerybeat:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.osquerybeat-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.osquerybeat@package"
|
||||
- "so-logs-elastic_agent.osquerybeat@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-logs-elastic_agent.packetbeat:
|
||||
index_sorting: False
|
||||
index_template:
|
||||
index_patterns:
|
||||
- "logs-elastic_agent.packetbeat-*"
|
||||
template:
|
||||
settings:
|
||||
index:
|
||||
mapping:
|
||||
total_fields:
|
||||
limit: 5000
|
||||
sort:
|
||||
field: "@timestamp"
|
||||
order: desc
|
||||
mappings:
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
composed_of:
|
||||
- "so-logs-elastic_agent.packetbeat@package"
|
||||
- "so-logs-elastic_agent.packetbeat@custom"
|
||||
- ".fleet_globals-1"
|
||||
- ".fleet_agent_id_verification-1"
|
||||
priority: 500
|
||||
_meta:
|
||||
package:
|
||||
name: elastic_agent
|
||||
managed_by: fleet
|
||||
managed: true
|
||||
data_stream:
|
||||
hidden: false
|
||||
allow_custom_routing: false
|
||||
so-aws:
|
||||
warm: 7
|
||||
close: 30
|
||||
|
||||
Reference in New Issue
Block a user