Merge pull request #3448 from Security-Onion-Solutions/kilo

Allow for moving Strelka files to processed directory after scanning
This commit is contained in:
Mike Reeves
2021-03-15 14:51:04 -04:00
committed by GitHub
2 changed files with 10 additions and 2 deletions

View File

@@ -19,7 +19,8 @@ files:
- '/nsm/strelka/unprocessed/*' - '/nsm/strelka/unprocessed/*'
delete: false delete: false
gatekeeper: true gatekeeper: true
processed: '/nsm/strelka/processed'
response: response:
report: 5s report: 5s
delta: 5s delta: 5s
staging: '/nsm/strelka/processed' staging: '/nsm/strelka/staging'

View File

@@ -86,6 +86,13 @@ strelkaprocessed:
- group: 939 - group: 939
- makedirs: True - makedirs: True
strelkastaging:
file.directory:
- name: /nsm/strelka/staging
- user: 939
- group: 939
- makedirs: True
strelkaunprocessed: strelkaunprocessed:
file.directory: file.directory:
- name: /nsm/strelka/unprocessed - name: /nsm/strelka/unprocessed