mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Rename Fleet pipelines
This commit is contained in:
@@ -22,15 +22,16 @@ logstash:
|
|||||||
defined_pipelines:
|
defined_pipelines:
|
||||||
fleet:
|
fleet:
|
||||||
- so/0012_input_elastic_agent.conf
|
- so/0012_input_elastic_agent.conf
|
||||||
- so/9806_output_http_fleet.conf.jinja
|
- so/9806_output_lumberjack_fleet.conf.jinja
|
||||||
manager:
|
manager:
|
||||||
- so/0011_input_endgame.conf
|
- so/0011_input_endgame.conf
|
||||||
- so/0012_input_elastic_agent.conf
|
- so/0012_input_elastic_agent.conf
|
||||||
- so/0013_input_http_fleet.conf
|
- so/0013_input_lumberjack_fleet.conf
|
||||||
- so/9999_output_redis.conf.jinja
|
- so/9999_output_redis.conf.jinja
|
||||||
receiver:
|
receiver:
|
||||||
- so/0011_input_endgame.conf
|
- so/0011_input_endgame.conf
|
||||||
- so/0012_input_elastic_agent.conf
|
- so/0012_input_elastic_agent.conf
|
||||||
|
- so/0013_input_lumberjack_fleet.conf
|
||||||
- so/9999_output_redis.conf.jinja
|
- so/9999_output_redis.conf.jinja
|
||||||
search:
|
search:
|
||||||
- so/0900_input_redis.conf.jinja
|
- so/0900_input_redis.conf.jinja
|
||||||
|
|||||||
@@ -62,7 +62,7 @@ so-logstash:
|
|||||||
- /etc/pki/elasticfleet-logstash.crt:/usr/share/logstash/elasticfleet-logstash.crt:ro
|
- /etc/pki/elasticfleet-logstash.crt:/usr/share/logstash/elasticfleet-logstash.crt:ro
|
||||||
- /etc/pki/elasticfleet-logstash.key:/usr/share/logstash/elasticfleet-logstash.key:ro
|
- /etc/pki/elasticfleet-logstash.key:/usr/share/logstash/elasticfleet-logstash.key:ro
|
||||||
- /etc/pki/elasticfleet-lumberjack.crt:/usr/share/logstash/elasticfleet-lumberjack.crt:ro
|
- /etc/pki/elasticfleet-lumberjack.crt:/usr/share/logstash/elasticfleet-lumberjack.crt:ro
|
||||||
- /etc/pki/elasticfleet-lumberjack.p8:/usr/share/logstash/elasticfleet-lumberjack.key:ro
|
- /etc/pki/elasticfleet-lumberjack.key:/usr/share/logstash/elasticfleet-lumberjack.key:ro
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% if GLOBALS.role in ['so-manager', 'so-managersearch', 'so-standalone', 'so-import'] %}
|
{% if GLOBALS.role in ['so-manager', 'so-managersearch', 'so-standalone', 'so-import'] %}
|
||||||
- /etc/pki/ca.crt:/usr/share/filebeat/ca.crt:ro
|
- /etc/pki/ca.crt:/usr/share/filebeat/ca.crt:ro
|
||||||
|
|||||||
@@ -186,7 +186,9 @@ chownelasticfleetkey:
|
|||||||
- user: 947
|
- user: 947
|
||||||
- group: 939
|
- group: 939
|
||||||
# End -- Elastic Fleet Host Cert
|
# End -- Elastic Fleet Host Cert
|
||||||
|
{% endif %} # endif is for not including HeavyNodes & Receivers
|
||||||
|
|
||||||
|
{% if grains['role'] not in [ 'so-heavynode'] %}
|
||||||
# Start -- Elastic Fleet Logstash Input Cert
|
# Start -- Elastic Fleet Logstash Input Cert
|
||||||
etc_elasticfleet_logstash_key:
|
etc_elasticfleet_logstash_key:
|
||||||
x509.private_key_managed:
|
x509.private_key_managed:
|
||||||
@@ -220,7 +222,7 @@ etc_elasticfleet_logstash_crt:
|
|||||||
cmd.run:
|
cmd.run:
|
||||||
- name: "/usr/bin/openssl pkcs8 -in /etc/pki/elasticfleet-logstash.key -topk8 -out /etc/pki/elasticfleet-logstash.p8 -nocrypt"
|
- name: "/usr/bin/openssl pkcs8 -in /etc/pki/elasticfleet-logstash.key -topk8 -out /etc/pki/elasticfleet-logstash.p8 -nocrypt"
|
||||||
- onchanges:
|
- onchanges:
|
||||||
- x509: etc_elasticfleet_key
|
- x509: etc_elasticfleet_logstash_key
|
||||||
|
|
||||||
eflogstashperms:
|
eflogstashperms:
|
||||||
file.managed:
|
file.managed:
|
||||||
@@ -245,7 +247,7 @@ chownelasticfleetlogstashkey:
|
|||||||
- user: 931
|
- user: 931
|
||||||
- group: 939
|
- group: 939
|
||||||
# End -- Elastic Fleet Logstash Input Cert
|
# End -- Elastic Fleet Logstash Input Cert
|
||||||
{% endif %} # endif is for not including HeavyNodes & Receivers
|
{% endif %} # endif is for not including HeavyNodes
|
||||||
|
|
||||||
# Start -- Elastic Fleet Node - Logstash Lumberjack Input / Output
|
# Start -- Elastic Fleet Node - Logstash Lumberjack Input / Output
|
||||||
# Cert needed on: Managers, Receivers
|
# Cert needed on: Managers, Receivers
|
||||||
|
|||||||
Reference in New Issue
Block a user