Add Templates for all filebeat modules

This commit is contained in:
Mike Reeves
2021-08-27 14:41:04 -04:00
parent f8cdf5bca3
commit a27263435a
3 changed files with 9 additions and 9 deletions

View File

@@ -1,8 +1,8 @@
{%- set SHARDS = salt['pillar.get']('elasticsearch:index_settings:so-zeek:shards', 1) %} {%- set SHARDS = salt['pillar.get']('elasticsearch:index_settings:so-snyk:shards', 1) %}
{%- set REPLICAS = salt['pillar.get']('elasticsearch:replicas', 0) %} {%- set REPLICAS = salt['pillar.get']('elasticsearch:replicas', 0) %}
{%- set REFRESH = salt['pillar.get']('elasticsearch:index_settings:so-zeek:refresh', '30s') %} {%- set REFRESH = salt['pillar.get']('elasticsearch:index_settings:so-snyk:refresh', '30s') %}
{ {
"index_patterns": ["so-zeek-*"], "index_patterns": ["so-snyk-*"],
"version":50001, "version":50001,
"order":11, "order":11,
"settings":{ "settings":{

View File

@@ -1,8 +1,8 @@
{%- set SHARDS = salt['pillar.get']('elasticsearch:index_settings:so-zeek:shards', 1) %} {%- set SHARDS = salt['pillar.get']('elasticsearch:index_settings:so-sophos:shards', 1) %}
{%- set REPLICAS = salt['pillar.get']('elasticsearch:replicas', 0) %} {%- set REPLICAS = salt['pillar.get']('elasticsearch:replicas', 0) %}
{%- set REFRESH = salt['pillar.get']('elasticsearch:index_settings:so-zeek:refresh', '30s') %} {%- set REFRESH = salt['pillar.get']('elasticsearch:index_settings:so-sophos:refresh', '30s') %}
{ {
"index_patterns": ["so-zeek-*"], "index_patterns": ["so-sophos-*"],
"version":50001, "version":50001,
"order":11, "order":11,
"settings":{ "settings":{

View File

@@ -1,8 +1,8 @@
{%- set SHARDS = salt['pillar.get']('elasticsearch:index_settings:so-zeek:shards', 1) %} {%- set SHARDS = salt['pillar.get']('elasticsearch:index_settings:so-squid:shards', 1) %}
{%- set REPLICAS = salt['pillar.get']('elasticsearch:replicas', 0) %} {%- set REPLICAS = salt['pillar.get']('elasticsearch:replicas', 0) %}
{%- set REFRESH = salt['pillar.get']('elasticsearch:index_settings:so-zeek:refresh', '30s') %} {%- set REFRESH = salt['pillar.get']('elasticsearch:index_settings:so-squid:refresh', '30s') %}
{ {
"index_patterns": ["so-zeek-*"], "index_patterns": ["so-squid-*"],
"version":50001, "version":50001,
"order":11, "order":11,
"settings":{ "settings":{