mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-08 10:12:53 +01:00
Add ES settings to pillar
This commit is contained in:
10
salt/logstash/pipelines/templates/so/so-beats-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-beats-template.json
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-beats-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-zeek-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
10
salt/logstash/pipelines/templates/so/so-ids-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-ids-template.json
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-zeek-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
10
salt/logstash/pipelines/templates/so/so-import-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-import-template.json
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-zeek-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-zeek-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
10
salt/logstash/pipelines/templates/so/so-ossec-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-ossec-template.json
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-zeek-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-zeek-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
10
salt/logstash/pipelines/templates/so/so-syslog-template.json
Normal file
10
salt/logstash/pipelines/templates/so/so-syslog-template.json
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"index_patterns": ["so-zeek-*"],
|
||||||
|
"version":50001,
|
||||||
|
"order" : 11,
|
||||||
|
"settings":{
|
||||||
|
"number_of_replicas":0,
|
||||||
|
"number_of_shards":1,
|
||||||
|
"index.refresh_interval":"30s"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1068,10 +1068,28 @@ elasticsearch_pillar() {
|
|||||||
" log_size_limit: $log_size_limit"\
|
" log_size_limit: $log_size_limit"\
|
||||||
" cur_close_days: $CURCLOSEDAYS"\
|
" cur_close_days: $CURCLOSEDAYS"\
|
||||||
" route_type: hot"\
|
" route_type: hot"\
|
||||||
|
" replicas: 0"\
|
||||||
|
" true_cluster: False"
|
||||||
|
" true_cluster_name: so"
|
||||||
" index_settings:"\
|
" index_settings:"\
|
||||||
|
" so-beats:"\
|
||||||
|
" shards: 1"\
|
||||||
|
" so-firewall:"\
|
||||||
|
" shards: 1"\
|
||||||
|
" so-ids:"\
|
||||||
|
" shards: 1"\
|
||||||
|
" so-import:"\
|
||||||
|
" shards: 1"\
|
||||||
|
" so-osquery:"\
|
||||||
|
" shards: 1"\
|
||||||
|
" so-ossec:"\
|
||||||
|
" shards: 1"\
|
||||||
|
" so-strelka:"\
|
||||||
|
" shards: 1"\
|
||||||
|
" so-syslog:"\
|
||||||
|
" shards: 1"\
|
||||||
" so-zeek:"\
|
" so-zeek:"\
|
||||||
" shards: 5"\
|
" shards: 5"\
|
||||||
" replicas: 0"\
|
|
||||||
"" >> "$pillar_file"
|
"" >> "$pillar_file"
|
||||||
|
|
||||||
if [ "$install_type" != 'EVAL' ] && [ "$install_type" != 'HELIXSENSOR' ] && [ "$install_type" != 'MASTERSEARCH' ] && [ "$install_type" != 'STANDALONE' ]; then
|
if [ "$install_type" != 'EVAL' ] && [ "$install_type" != 'HELIXSENSOR' ] && [ "$install_type" != 'MASTERSEARCH' ] && [ "$install_type" != 'STANDALONE' ]; then
|
||||||
|
|||||||
Reference in New Issue
Block a user