diff --git a/salt/soc/config.sls b/salt/soc/config.sls index 95135566b..549bf94cf 100644 --- a/salt/soc/config.sls +++ b/salt/soc/config.sls @@ -57,6 +57,22 @@ socmotd: - mode: 600 - template: jinja +socsigmafinalpipeline: + file.managed: + - name: /opt/so/conf/soc/sigma_final_pipeline.yaml + - source: salt://soc/files/soc/sigma_final_pipeline.yaml + - user: 939 + - group: 939 + - mode: 600 + +socsigmasopipeline: + file.managed: + - name: /opt/so/conf/soc/sigma_so_pipeline.yaml + - source: salt://soc/files/soc/sigma_so_pipeline.yaml + - user: 939 + - group: 939 + - mode: 600 + socbanner: file.managed: - name: /opt/so/conf/soc/banner.md diff --git a/salt/soc/enabled.sls b/salt/soc/enabled.sls index 11f73e761..535423179 100644 --- a/salt/soc/enabled.sls +++ b/salt/soc/enabled.sls @@ -32,6 +32,8 @@ so-soc: - /opt/so/conf/soc/soc.json:/opt/sensoroni/sensoroni.json:ro - /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro - /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro + - /opt/so/conf/soc/sigma_so_pipeline.yaml:/opt/sensoroni/sigma_so_pipeline.yaml:ro + - /opt/so/conf/soc/sigma_final_pipeline.yaml:/opt/sensoroni/sigma_final_pipeline.yaml:rw - /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro - /opt/so/conf/soc/custom_roles:/opt/sensoroni/rbac/custom_roles:ro - /opt/so/conf/soc/soc_users_roles:/opt/sensoroni/rbac/users_roles:rw diff --git a/salt/soc/final_sigma_pipeline.yaml b/salt/soc/files/soc/final_sigma_pipeline.yaml similarity index 100% rename from salt/soc/final_sigma_pipeline.yaml rename to salt/soc/files/soc/final_sigma_pipeline.yaml diff --git a/salt/soc/so_sigma_pipeline.yaml b/salt/soc/files/soc/so_sigma_pipeline.yaml similarity index 100% rename from salt/soc/so_sigma_pipeline.yaml rename to salt/soc/files/soc/so_sigma_pipeline.yaml diff --git a/salt/soc/soc_soc.yaml b/salt/soc/soc_soc.yaml index fe672fe3e..f413b5c73 100644 --- a/salt/soc/soc_soc.yaml +++ b/salt/soc/soc_soc.yaml @@ -32,7 +32,7 @@ soc: global: True advanced: True helpLink: soc-customization.html - final_sigma_pipeline__yaml: + sigma_final_pipeline__yaml: title: Final Sigma Pipeline description: Final Processing Pipeline for Sigma Rules syntax: yaml