add line space

This commit is contained in:
m0duspwnens
2022-10-21 11:49:01 -04:00
parent 8b5c79fb39
commit 8c5197c2ea
136 changed files with 136 additions and 136 deletions

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set log_size_limit = salt['pillar.get']('elasticsearch:log_size_limit') -%} {%- set log_size_limit = salt['pillar.get']('elasticsearch:log_size_limit') %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-aws'].close -%} {%- set cur_close_days = CURATORMERGED['so-aws'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-aws'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-aws'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-aws'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-aws'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-azure'].close -%} {%- set cur_close_days = CURATORMERGED['so-azure'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-azure'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-azure'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-azure'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-azure'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-barracuda'].close -%} {%- set cur_close_days = CURATORMERGED['so-barracuda'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-barracuda'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-barracuda'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-barracuda'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-barracuda'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-beats'].close -%} {%- set cur_close_days = CURATORMERGED['so-beats'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-beats'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-beats'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-beats'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-beats'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-bluecoat'].close -%} {%- set cur_close_days = CURATORMERGED['so-bluecoat'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-bluecoat'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-bluecoat'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-bluecoat'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-bluecoat'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-cef'].close -%} {%- set cur_close_days = CURATORMERGED['so-cef'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-cef'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-cef'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-cef'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-cef'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-checkpoint'].close -%} {%- set cur_close_days = CURATORMERGED['so-checkpoint'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-checkpoint'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-checkpoint'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-checkpoint'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-checkpoint'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-cisco'].close -%} {%- set cur_close_days = CURATORMERGED['so-cisco'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-cisco'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-cisco'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-cisco'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-cisco'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-cyberark'].close -%} {%- set cur_close_days = CURATORMERGED['so-cyberark'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-cyberark'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-cyberark'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-cyberark'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-cyberark'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-cylance'].close -%} {%- set cur_close_days = CURATORMERGED['so-cylance'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-cylance'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-cylance'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-cylance'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-cylance'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-elasticsearch'].close -%} {%- set cur_close_days = CURATORMERGED['so-elasticsearch'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-elasticsearch'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-elasticsearch'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-elasticsearch'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-elasticsearch'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-endgame'].close -%} {%- set cur_close_days = CURATORMERGED['so-endgame'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-endgame'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-endgame'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-endgame'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-endgame'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-f5'].close -%} {%- set cur_close_days = CURATORMERGED['so-f5'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-f5'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-f5'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-f5'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-f5'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-firewall'].close -%} {%- set cur_close_days = CURATORMERGED['so-firewall'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-firewall'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-firewall'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-firewall'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-firewall'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-fortinet'].close -%} {%- set cur_close_days = CURATORMERGED['so-fortinet'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-fortinet'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-fortinet'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-fortinet'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-fortinet'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-gcp'].close -%} {%- set cur_close_days = CURATORMERGED['so-gcp'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-gcp'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-gcp'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-gcp'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-gcp'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-google_workspace'].close -%} {%- set cur_close_days = CURATORMERGED['so-google_workspace'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-google_workspace'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-google_workspace'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-google_workspace'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-google_workspace'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-ids'].close -%} {%- set cur_close_days = CURATORMERGED['so-ids'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-ids'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-ids'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-ids'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-ids'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -4,7 +4,7 @@
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-imperva'].close -%} {%- set cur_close_days = CURATORMERGED['so-imperva'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-imperva'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-imperva'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-imperva'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-imperva'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-import'].close -%} {%- set cur_close_days = CURATORMERGED['so-import'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-import'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-import'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-import'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-import'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-infoblox'].close -%} {%- set cur_close_days = CURATORMERGED['so-infoblox'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-infoblox'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-infoblox'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-infoblox'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-infoblox'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-juniper'].close -%} {%- set cur_close_days = CURATORMERGED['so-juniper'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-juniper'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-juniper'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-aws'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-aws'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-kibana'].close -%} {%- set cur_close_days = CURATORMERGED['so-kibana'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-kibana'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-kibana'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-kibana'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-kibana'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-kratos'].close -%} {%- set cur_close_days = CURATORMERGED['so-kratos'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-kratos'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-kratos'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-kratos'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-kratos'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-logstash'].close -%} {%- set cur_close_days = CURATORMERGED['so-logstash'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-logstash'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-logstash'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-logstash'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-logstash'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-microsoft'].close -%} {%- set cur_close_days = CURATORMERGED['so-microsoft'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-microsoft'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-microsoft'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-microsoft'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-microsoft'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-misp'].close -%} {%- set cur_close_days = CURATORMERGED['so-misp'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-misp'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-misp'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-misp'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-misp'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-netflow'].close -%} {%- set cur_close_days = CURATORMERGED['so-netflow'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-netflow'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-netflow'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-netflow'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-netflow'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-netscout'].close -%} {%- set cur_close_days = CURATORMERGED['so-netscout'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-netscout'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-netscout'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-netscout'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-netscout'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-o365'].close -%} {%- set cur_close_days = CURATORMERGED['so-o365'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-o365'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-o365'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-o365'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-o365'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-okta'].close -%} {%- set cur_close_days = CURATORMERGED['so-okta'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-okta'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-okta'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-okta'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-okta'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-osquery'].close -%} {%- set cur_close_days = CURATORMERGED['so-osquery'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-osquery'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-osquery'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-osquery'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-osquery'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set cur_close_days = CURATORMERGED['so-ossec'].close -%} {%- set cur_close_days = CURATORMERGED['so-ossec'].close %}
actions: actions:
1: 1:
action: close action: close

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set DELETE_DAYS = CURATORMERGED['so-ossec'].delete -%} {%- set DELETE_DAYS = CURATORMERGED['so-ossec'].delete %}
actions: actions:
1: 1:
action: delete_indices action: delete_indices

View File

@@ -3,7 +3,7 @@
# https://securityonion.net/license; you may not use this file except in compliance with the # https://securityonion.net/license; you may not use this file except in compliance with the
# Elastic License 2.0. # Elastic License 2.0.
{%- set WARM_DAYS = CURATORMERGED['so-ossec'].warm -%} {%- set WARM_DAYS = CURATORMERGED['so-ossec'].warm %}
actions: actions:
1: 1:
action: allocation action: allocation

Some files were not shown because too many files have changed in this diff Show More