mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
remove optional integrations from defaults.yaml & soc_elasticsearch.yaml
This commit is contained in:
File diff suppressed because it is too large
Load Diff
@@ -358,160 +358,9 @@ elasticsearch:
|
|||||||
so-logs-windows_x_powershell_operational: *indexSettings
|
so-logs-windows_x_powershell_operational: *indexSettings
|
||||||
so-logs-windows_x_sysmon_operational: *indexSettings
|
so-logs-windows_x_sysmon_operational: *indexSettings
|
||||||
so-logs-winlog_x_winlog: *indexSettings
|
so-logs-winlog_x_winlog: *indexSettings
|
||||||
so-logs-apache_x_access: *indexSettings
|
|
||||||
so-logs-apache_x_error: *indexSettings
|
|
||||||
so-logs-auditd_x_log: *indexSettings
|
|
||||||
so-logs-aws_x_cloudtrail: *indexSettings
|
|
||||||
so-logs-aws_x_cloudwatch_logs: *indexSettings
|
|
||||||
so-logs-aws_x_ec2_logs: *indexSettings
|
|
||||||
so-logs-aws_x_elb_logs: *indexSettings
|
|
||||||
so-logs-aws_x_firewall_logs: *indexSettings
|
|
||||||
so-logs-aws_x_route53_public_logs: *indexSettings
|
|
||||||
so-logs-aws_x_route53_resolver_logs: *indexSettings
|
|
||||||
so-logs-aws_x_s3access: *indexSettings
|
|
||||||
so-logs-aws_x_vpcflow: *indexSettings
|
|
||||||
so-logs-aws_x_waf: *indexSettings
|
|
||||||
so-logs-azure_x_activitylogs: *indexSettings
|
|
||||||
so-logs-azure_x_application_gateway: *indexSettings
|
|
||||||
so-logs-azure_x_auditlogs: *indexSettings
|
|
||||||
so-logs-azure_x_eventhub: *indexSettings
|
|
||||||
so-logs-azure_x_firewall_logs: *indexSettings
|
|
||||||
so-logs-azure_x_identity_protection: *indexSettings
|
|
||||||
so-logs-azure_x_platformlogs: *indexSettings
|
|
||||||
so-logs-azure_x_provisioning: *indexSettings
|
|
||||||
so-logs-azure_x_signinlogs: *indexSettings
|
|
||||||
so-logs-azure_x_springcloudlogs: *indexSettings
|
|
||||||
so-logs-barracuda_x_waf: *indexSettings
|
|
||||||
so-logs-barracuda_cloudgen_firewall_x_log: *indexSettings
|
|
||||||
so-logs-cef_x_log: *indexSettings
|
|
||||||
so-logs-cisco_asa_x_log: *indexSettings
|
|
||||||
so-logs-cisco_ftd_x_log: *indexSettings
|
|
||||||
so-logs-cisco_ios_x_log: *indexSettings
|
|
||||||
so-logs-cisco_ise_x_log: *indexSettings
|
|
||||||
so-logs-citrix_adc_x_interface: *indexSettings
|
|
||||||
so-logs-citrix_adc_x_lbvserver: *indexSettings
|
|
||||||
so-logs-citrix_adc_x_service: *indexSettings
|
|
||||||
so-logs-citrix_adc_x_system: *indexSettings
|
|
||||||
so-logs-citrix_adc_x_vpn: *indexSettings
|
|
||||||
so-logs-citrix_waf_x_log: *indexSettings
|
|
||||||
so-logs-cloudflare_x_audit: *indexSettings
|
|
||||||
so-logs-cloudflare_x_logpull: *indexSettings
|
|
||||||
so-logs-crowdstrike_x_alert: *indexSettings
|
|
||||||
so-logs-crowdstrike_x_falcon: *indexSettings
|
|
||||||
so-logs-crowdstrike_x_fdr: *indexSettings
|
|
||||||
so-logs-crowdstrike_x_host: *indexSettings
|
|
||||||
so-logs-darktrace_x_ai_analyst_alert: *indexSettings
|
|
||||||
so-logs-darktrace_x_model_breach_alert: *indexSettings
|
|
||||||
so-logs-darktrace_x_system_status_alert: *indexSettings
|
|
||||||
so-logs-detections_x_alerts: *indexSettings
|
so-logs-detections_x_alerts: *indexSettings
|
||||||
so-logs-f5_bigip_x_log: *indexSettings
|
|
||||||
so-logs-fim_x_event: *indexSettings
|
|
||||||
so-logs-fortinet_x_clientendpoint: *indexSettings
|
|
||||||
so-logs-fortinet_x_firewall: *indexSettings
|
|
||||||
so-logs-fortinet_x_fortimail: *indexSettings
|
|
||||||
so-logs-fortinet_x_fortimanager: *indexSettings
|
|
||||||
so-logs-fortinet_x_fortigate: *indexSettings
|
|
||||||
so-logs-gcp_x_audit: *indexSettings
|
|
||||||
so-logs-gcp_x_dns: *indexSettings
|
|
||||||
so-logs-gcp_x_firewall: *indexSettings
|
|
||||||
so-logs-gcp_x_loadbalancing_logs: *indexSettings
|
|
||||||
so-logs-gcp_x_vpcflow: *indexSettings
|
|
||||||
so-logs-github_x_audit: *indexSettings
|
|
||||||
so-logs-github_x_code_scanning: *indexSettings
|
|
||||||
so-logs-github_x_dependabot: *indexSettings
|
|
||||||
so-logs-github_x_issues: *indexSettings
|
|
||||||
so-logs-github_x_secret_scanning: *indexSettings
|
|
||||||
so-logs-google_workspace_x_access_transparency: *indexSettings
|
|
||||||
so-logs-google_workspace_x_admin: *indexSettings
|
|
||||||
so-logs-google_workspace_x_alert: *indexSettings
|
|
||||||
so-logs-google_workspace_x_context_aware_access: *indexSettings
|
|
||||||
so-logs-google_workspace_x_device: *indexSettings
|
|
||||||
so-logs-google_workspace_x_drive: *indexSettings
|
|
||||||
so-logs-google_workspace_x_gcp: *indexSettings
|
|
||||||
so-logs-google_workspace_x_group_enterprise: *indexSettings
|
|
||||||
so-logs-google_workspace_x_groups: *indexSettings
|
|
||||||
so-logs-google_workspace_x_login: *indexSettings
|
|
||||||
so-logs-google_workspace_x_rules: *indexSettings
|
|
||||||
so-logs-google_workspace_x_saml: *indexSettings
|
|
||||||
so-logs-google_workspace_x_token: *indexSettings
|
|
||||||
so-logs-google_workspace_x_user_accounts: *indexSettings
|
|
||||||
so-logs-http_endpoint_x_generic: *indexSettings
|
so-logs-http_endpoint_x_generic: *indexSettings
|
||||||
so-logs-httpjson_x_generic: *indexSettings
|
so-logs-httpjson_x_generic: *indexSettings
|
||||||
so-logs-iis_x_access: *indexSettings
|
|
||||||
so-logs-iis_x_error: *indexSettings
|
|
||||||
so-logs-imperva_cloud_waf_x_event: *indexSettings
|
|
||||||
so-logs-juniper_x_junos: *indexSettings
|
|
||||||
so-logs-juniper_x_netscreen: *indexSettings
|
|
||||||
so-logs-juniper_x_srx: *indexSettings
|
|
||||||
so-logs-juniper_srx_x_log: *indexSettings
|
|
||||||
so-logs-kafka_log_x_generic: *indexSettings
|
|
||||||
so-logs-lastpass_x_detailed_shared_folder: *indexSettings
|
|
||||||
so-logs-lastpass_x_event_report: *indexSettings
|
|
||||||
so-logs-lastpass_x_user: *indexSettings
|
|
||||||
so-logs-m365_defender_x_event: *indexSettings
|
|
||||||
so-logs-m365_defender_x_incident: *indexSettings
|
|
||||||
so-logs-m365_defender_x_log: *indexSettings
|
|
||||||
so-logs-microsoft_defender_endpoint_x_log: *indexSettings
|
|
||||||
so-logs-microsoft_dhcp_x_log: *indexSettings
|
|
||||||
so-logs-microsoft_sqlserver_x_audit: *indexSettings
|
|
||||||
so-logs-microsoft_sqlserver_x_log: *indexSettings
|
|
||||||
so-logs-mysql_x_error: *indexSettings
|
|
||||||
so-logs-mysql_x_slowlog: *indexSettings
|
|
||||||
so-logs-netflow_x_log: *indexSettings
|
|
||||||
so-logs-nginx_x_access: *indexSettings
|
|
||||||
so-logs-nginx_x_error: *indexSettings
|
|
||||||
so-logs-o365_x_audit: *indexSettings
|
|
||||||
so-logs-okta_x_system: *indexSettings
|
|
||||||
so-logs-panw_x_panos: *indexSettings
|
|
||||||
so-logs-pfsense_x_log: *indexSettings
|
|
||||||
so-logs-proofpoint_tap_x_clicks_blocked: *indexSettings
|
|
||||||
so-logs-proofpoint_tap_x_clicks_permitted: *indexSettings
|
|
||||||
so-logs-proofpoint_tap_x_message_blocked: *indexSettings
|
|
||||||
so-logs-proofpoint_tap_x_message_delivered: *indexSettings
|
|
||||||
so-logs-sentinel_one_x_activity: *indexSettings
|
|
||||||
so-logs-sentinel_one_x_agent: *indexSettings
|
|
||||||
so-logs-sentinel_one_x_alert: *indexSettings
|
|
||||||
so-logs-sentinel_one_x_group: *indexSettings
|
|
||||||
so-logs-sentinel_one_x_threat: *indexSettings
|
|
||||||
so-logs-sonicwall_firewall_x_log: *indexSettings
|
|
||||||
so-logs-snort_x_log: *indexSettings
|
|
||||||
so-logs-symantec_endpoint_x_log: *indexSettings
|
|
||||||
so-logs-tenable_io_x_asset: *indexSettings
|
|
||||||
so-logs-tenable_io_x_plugin: *indexSettings
|
|
||||||
so-logs-tenable_io_x_scan: *indexSettings
|
|
||||||
so-logs-tenable_io_x_vulnerability: *indexSettings
|
|
||||||
so-logs-tenable_sc_x_asset: *indexSettings
|
|
||||||
so-logs-tenable_sc_x_plugin: *indexSettings
|
|
||||||
so-logs-tenable_sc_x_vulnerability: *indexSettings
|
|
||||||
so-logs-ti_abusech_x_malware: *indexSettings
|
|
||||||
so-logs-ti_abusech_x_malwarebazaar: *indexSettings
|
|
||||||
so-logs-ti_abusech_x_threatfox: *indexSettings
|
|
||||||
so-logs-ti_abusech_x_url: *indexSettings
|
|
||||||
so-logs-ti_anomali_x_threatstream: *indexSettings
|
|
||||||
so-logs-ti_cybersixgill_x_threat: *indexSettings
|
|
||||||
so-logs-ti_misp_x_threat: *indexSettings
|
|
||||||
so-logs-ti_misp_x_threat_attributes: *indexSettings
|
|
||||||
so-logs-ti_otx_x_pulses_subscribed: *indexSettings
|
|
||||||
so-logs-ti_otx_x_threat: *indexSettings
|
|
||||||
so-logs-ti_recordedfuture_x_latest_ioc-template: *indexSettings
|
|
||||||
so-logs-ti_recordedfuture_x_threat: *indexSettings
|
|
||||||
so-logs-ti_threatq_x_threat: *indexSettings
|
|
||||||
so-logs-trend_micro_vision_one_x_alert: *indexSettings
|
|
||||||
so-logs-trend_micro_vision_one_x_audit: *indexSettings
|
|
||||||
so-logs-trend_micro_vision_one_x_detection: *indexSettings
|
|
||||||
so-logs-trendmicro_x_deep_security: *indexSettings
|
|
||||||
so-logs-zscaler_zia_x_alerts: *indexSettings
|
|
||||||
so-logs-zscaler_zia_x_dns: *indexSettings
|
|
||||||
so-logs-zscaler_zia_x_firewall: *indexSettings
|
|
||||||
so-logs-zscaler_zia_x_tunnel: *indexSettings
|
|
||||||
so-logs-zscaler_zia_x_web: *indexSettings
|
|
||||||
so-logs-zscaler_zpa_x_app_connector_status: *indexSettings
|
|
||||||
so-logs-zscaler_zpa_x_audit: *indexSettings
|
|
||||||
so-logs-zscaler_zpa_x_browser_access: *indexSettings
|
|
||||||
so-logs-zscaler_zpa_x_user_activity: *indexSettings
|
|
||||||
so-logs-zscaler_zpa_x_user_status: *indexSettings
|
|
||||||
so-logs-1password_x_item_usages: *indexSettings
|
|
||||||
so-logs-1password_x_signin_attempts: *indexSettings
|
|
||||||
so-logs-osquery-manager-actions: *indexSettings
|
so-logs-osquery-manager-actions: *indexSettings
|
||||||
so-logs-osquery-manager-action_x_responses: *indexSettings
|
so-logs-osquery-manager-action_x_responses: *indexSettings
|
||||||
so-logs-elastic_agent_x_apm_server: *indexSettings
|
so-logs-elastic_agent_x_apm_server: *indexSettings
|
||||||
@@ -537,6 +386,9 @@ elasticsearch:
|
|||||||
so-metrics-endpoint_x_metrics: *indexSettings
|
so-metrics-endpoint_x_metrics: *indexSettings
|
||||||
so-metrics-endpoint_x_policy: *indexSettings
|
so-metrics-endpoint_x_policy: *indexSettings
|
||||||
so-metrics-nginx_x_stubstatus: *indexSettings
|
so-metrics-nginx_x_stubstatus: *indexSettings
|
||||||
|
so-metrics-vsphere_x_datastore: *indexSettings
|
||||||
|
so-metrics-vsphere_x_host: *indexSettings
|
||||||
|
so-metrics-vsphere_x_virtualmachine: *indexSettings
|
||||||
so-case: *indexSettings
|
so-case: *indexSettings
|
||||||
so-common: *indexSettings
|
so-common: *indexSettings
|
||||||
so-endgame: *indexSettings
|
so-endgame: *indexSettings
|
||||||
|
|||||||
Reference in New Issue
Block a user