mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
disable stenographer if suricata is pcap engine
This commit is contained in:
@@ -2,6 +2,12 @@
|
|||||||
or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
|
or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
|
||||||
https://securityonion.net/license; you may not use this file except in compliance with the
|
https://securityonion.net/license; you may not use this file except in compliance with the
|
||||||
Elastic License 2.0. #}
|
Elastic License 2.0. #}
|
||||||
|
|
||||||
|
{% from 'vars/globals.map.jinja' import GLOBALS %}
|
||||||
{% import_yaml 'pcap/defaults.yaml' as PCAPDEFAULTS %}
|
{% import_yaml 'pcap/defaults.yaml' as PCAPDEFAULTS %}
|
||||||
{% set PCAPMERGED = salt['pillar.get']('pcap', PCAPDEFAULTS.pcap, merge=True) %}
|
{% set PCAPMERGED = salt['pillar.get']('pcap', PCAPDEFAULTS.pcap, merge=True) %}
|
||||||
|
|
||||||
|
{# disable stenographer if the pcap engine is set to SURICATA #}
|
||||||
|
{% if GLOBALS.pcap_engine == "SURICATA" %}
|
||||||
|
{% do PCAPMERGED.update({'enabled': False}) %}
|
||||||
|
{% endif %}
|
||||||
|
|||||||
Reference in New Issue
Block a user