mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-07 17:52:46 +01:00
Add ES settings to pillar
This commit is contained in:
10
salt/logstash/pipelines/templates/so/so-beats-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-beats-template.json
Normal file
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-beats-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-zeek-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
10
salt/logstash/pipelines/templates/so/so-ids-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-ids-template.json
Normal file
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-zeek-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
10
salt/logstash/pipelines/templates/so/so-import-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-import-template.json
Normal file
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-zeek-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-zeek-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
10
salt/logstash/pipelines/templates/so/so-ossec-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-ossec-template.json
Normal file
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-zeek-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-zeek-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
10
salt/logstash/pipelines/templates/so/so-syslog-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-syslog-template.json
Normal file
@@ -0,0 +1,10 @@
|
||||
{
|
||||
"index_patterns": ["so-zeek-*"],
|
||||
"version":50001,
|
||||
"order" : 11,
|
||||
"settings":{
|
||||
"number_of_replicas":0,
|
||||
"number_of_shards":1,
|
||||
"index.refresh_interval":"30s"
|
||||
}
|
||||
}
|
||||
@@ -1068,10 +1068,28 @@ elasticsearch_pillar() {
|
||||
" log_size_limit: $log_size_limit"\
|
||||
" cur_close_days: $CURCLOSEDAYS"\
|
||||
" route_type: hot"\
|
||||
" replicas: 0"\
|
||||
" true_cluster: False"
|
||||
" true_cluster_name: so"
|
||||
" index_settings:"\
|
||||
" so-beats:"\
|
||||
" shards: 1"\
|
||||
" so-firewall:"\
|
||||
" shards: 1"\
|
||||
" so-ids:"\
|
||||
" shards: 1"\
|
||||
" so-import:"\
|
||||
" shards: 1"\
|
||||
" so-osquery:"\
|
||||
" shards: 1"\
|
||||
" so-ossec:"\
|
||||
" shards: 1"\
|
||||
" so-strelka:"\
|
||||
" shards: 1"\
|
||||
" so-syslog:"\
|
||||
" shards: 1"\
|
||||
" so-zeek:"\
|
||||
" shards: 5"\
|
||||
" replicas: 0"\
|
||||
"" >> "$pillar_file"
|
||||
|
||||
if [ "$install_type" != 'EVAL' ] && [ "$install_type" != 'HELIXSENSOR' ] && [ "$install_type" != 'MASTERSEARCH' ] && [ "$install_type" != 'STANDALONE' ]; then
|
||||
|
||||
Reference in New Issue
Block a user