mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Update template settings to use data streams
This commit is contained in:
@@ -1152,8 +1152,9 @@ elasticsearch:
|
|||||||
delete: 365
|
delete: 365
|
||||||
index_sorting: False
|
index_sorting: False
|
||||||
index_template:
|
index_template:
|
||||||
|
data_stream: {}
|
||||||
index_patterns:
|
index_patterns:
|
||||||
- so-*
|
- logs-*_so
|
||||||
template:
|
template:
|
||||||
mappings:
|
mappings:
|
||||||
dynamic_templates:
|
dynamic_templates:
|
||||||
@@ -2154,11 +2155,12 @@ elasticsearch:
|
|||||||
- common-settings
|
- common-settings
|
||||||
- common-dynamic-mappings
|
- common-dynamic-mappings
|
||||||
priority: 500
|
priority: 500
|
||||||
so-ids:
|
so-suricata:
|
||||||
index_sorting: False
|
index_sorting: False
|
||||||
index_template:
|
index_template:
|
||||||
|
data_stream: {}
|
||||||
index_patterns:
|
index_patterns:
|
||||||
- so-ids*
|
- logs-*-suricata_so
|
||||||
template:
|
template:
|
||||||
mappings:
|
mappings:
|
||||||
dynamic_templates:
|
dynamic_templates:
|
||||||
@@ -2324,8 +2326,9 @@ elasticsearch:
|
|||||||
so-import:
|
so-import:
|
||||||
index_sorting: False
|
index_sorting: False
|
||||||
index_template:
|
index_template:
|
||||||
|
data_stream: {}
|
||||||
index_patterns:
|
index_patterns:
|
||||||
- so-import*
|
- logs-*-import_so
|
||||||
template:
|
template:
|
||||||
mappings:
|
mappings:
|
||||||
dynamic_templates:
|
dynamic_templates:
|
||||||
@@ -4162,8 +4165,9 @@ elasticsearch:
|
|||||||
so-strelka:
|
so-strelka:
|
||||||
index_sorting: False
|
index_sorting: False
|
||||||
index_template:
|
index_template:
|
||||||
|
data_stream: {}
|
||||||
index_patterns:
|
index_patterns:
|
||||||
- so-strelka*
|
- logs-*-strelka_so
|
||||||
template:
|
template:
|
||||||
mappings:
|
mappings:
|
||||||
dynamic_templates:
|
dynamic_templates:
|
||||||
@@ -4415,8 +4419,9 @@ elasticsearch:
|
|||||||
so-zeek:
|
so-zeek:
|
||||||
index_sorting: False
|
index_sorting: False
|
||||||
index_template:
|
index_template:
|
||||||
|
data_stream: {}
|
||||||
index_patterns:
|
index_patterns:
|
||||||
- so-zeek*
|
- logs-*-zeek_so
|
||||||
template:
|
template:
|
||||||
mappings:
|
mappings:
|
||||||
dynamic_templates:
|
dynamic_templates:
|
||||||
|
|||||||
Reference in New Issue
Block a user