mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-01-16 21:21:31 +01:00
Fix log rotate on Suricata
This commit is contained in:
@@ -123,7 +123,7 @@ filebeat.inputs:
|
||||
|
||||
- type: log
|
||||
paths:
|
||||
- /suricata/eve.json
|
||||
- /suricata/eve*.json
|
||||
fields:
|
||||
module: suricata
|
||||
dataset: common
|
||||
|
||||
@@ -95,8 +95,8 @@ outputs:
|
||||
- eve-log:
|
||||
enabled: yes
|
||||
filetype: regular #regular|syslog|unix_dgram|unix_stream|redis
|
||||
filename: /nsm/eve.json
|
||||
rotate-interval: day
|
||||
filename: /nsm/eve-%Y-%m-%d-%H:%M.json
|
||||
rotate-interval: hour
|
||||
|
||||
#prefix: "@cee: " # prefix to prepend to each log entry
|
||||
# the following are valid when type: syslog above
|
||||
|
||||
@@ -95,7 +95,7 @@ outputs:
|
||||
- eve-log:
|
||||
enabled: yes
|
||||
filetype: regular #regular|syslog|unix_dgram|unix_stream|redis
|
||||
filename: /nsm/eve.json
|
||||
filename: /nsm/eve-%Y-%m-%d-%H:%M.json
|
||||
rotate-interval: hour
|
||||
|
||||
#prefix: "@cee: " # prefix to prepend to each log entry
|
||||
|
||||
Reference in New Issue
Block a user