mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Bro - Add cron for checking PL
This commit is contained in:
@@ -0,0 +1 @@
|
|||||||
|
docker exec -it so-bro /opt/bro/bin/broctl netstats | awk -F '[ =]' '{RCVD += $5;DRP += $7;TTL += $9} END { print "rcvd: " RCVD, "dropped: " DRP, "total: " TTL}' >> /nsm/bro/logs/packetloss.log
|
||||||
|
|||||||
@@ -65,9 +65,14 @@ nodecfgsync:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- template: jinja
|
- template: jinja
|
||||||
|
|
||||||
brocron:
|
plcronscript:
|
||||||
|
file.managed:
|
||||||
|
- name: /usr/local/bin/packetloss.sh
|
||||||
|
- source: salt://bro/cron/packetloss.sh
|
||||||
|
- mode: 755
|
||||||
|
|
||||||
|
/usr/local/bin/packetloss.sh:
|
||||||
cron.present:
|
cron.present:
|
||||||
- name: docker exec -it so-bro /opt/bro/bin/broctl netstats | awk -F '[ =]' '{RCVD += $5;DRP += $7;TTL += $9} END { print "rcvd: " RCVD, "dropped: " DRP, "total: " TTL}' >> /nsm/bro/logs/packetloss.log;
|
|
||||||
- user: root
|
- user: root
|
||||||
- minute: '*/10'
|
- minute: '*/10'
|
||||||
- hour: '*'
|
- hour: '*'
|
||||||
|
|||||||
Reference in New Issue
Block a user