From a9457d5f535a8a8af22e3ab02943c0626cb7c7e8 Mon Sep 17 00:00:00 2001 From: reyesj2 <94730068+reyesj2@users.noreply.github.com> Date: Tue, 17 Oct 2023 16:02:16 -0400 Subject: [PATCH] Remove external community-id replaced with Zeek 6 built in community-id. Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com> --- pillar/zeek/init.sls | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pillar/zeek/init.sls b/pillar/zeek/init.sls index 01023fb60..64316838f 100644 --- a/pillar/zeek/init.sls +++ b/pillar/zeek/init.sls @@ -42,12 +42,13 @@ zeek: - frameworks/files/hash-all-files - frameworks/files/detect-MHR - policy/frameworks/notice/extend-email/hostnames + - policy/frameworks/notice/community-id + - policy/protocols/conn/community-id-logging - ja3 - hassh - intel - cve-2020-0601 - securityonion/bpfconf - - securityonion/communityid - securityonion/file-extraction - oui-logging - icsnpp-modbus