mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-09 02:32:46 +01:00
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
This commit is contained in:
@@ -79,7 +79,7 @@ if DEFAULTPOLICY=$(fleet_api "outputs/fleet-default-output"); then
|
|||||||
fleet_default=$(echo "$DEFAULTPOLICY" | jq -er '.item.is_default')
|
fleet_default=$(echo "$DEFAULTPOLICY" | jq -er '.item.is_default')
|
||||||
fleet_default_monitoring=$(echo "$DEFAULTPOLICY" | jq -er '.item.is_default_monitoring')
|
fleet_default_monitoring=$(echo "$DEFAULTPOLICY" | jq -er '.item.is_default_monitoring')
|
||||||
# Check that fleet-default-output isn't configured as a default for anything ( both variables return false )
|
# Check that fleet-default-output isn't configured as a default for anything ( both variables return false )
|
||||||
if [[ $fleet_default ]] && [[ $fleet_default_monitoring ]]; then
|
if [[ ! $fleet_default ]] && [[ ! $fleet_default_monitoring ]]; then
|
||||||
echo -e "\nso-manager_elasticsearch is configured as the current default policy..."
|
echo -e "\nso-manager_elasticsearch is configured as the current default policy..."
|
||||||
else
|
else
|
||||||
echo -e "\nVerification of so-manager_elasticsearch policy failed... The default 'fleet-default-output' output is still active..."
|
echo -e "\nVerification of so-manager_elasticsearch policy failed... The default 'fleet-default-output' output is still active..."
|
||||||
|
|||||||
@@ -54,6 +54,9 @@ so-kratos:
|
|||||||
- file: kratosconfig
|
- file: kratosconfig
|
||||||
- file: kratoslogdir
|
- file: kratoslogdir
|
||||||
- file: kratosdir
|
- file: kratosdir
|
||||||
|
- retry:
|
||||||
|
attempts: 10
|
||||||
|
interval: 10
|
||||||
|
|
||||||
delete_so-kratos_so-status.disabled:
|
delete_so-kratos_so-status.disabled:
|
||||||
file.uncomment:
|
file.uncomment:
|
||||||
|
|||||||
@@ -2545,7 +2545,7 @@ soc:
|
|||||||
level: 'high' # info | low | medium | high | critical
|
level: 'high' # info | low | medium | high | critical
|
||||||
assistant:
|
assistant:
|
||||||
enabled: false
|
enabled: false
|
||||||
investigationPrompt: Investigate Alert ID {socid}
|
investigationPrompt: Investigate Alert ID {socId}
|
||||||
contextLimitSmall: 200000
|
contextLimitSmall: 200000
|
||||||
contextLimitLarge: 1000000
|
contextLimitLarge: 1000000
|
||||||
thresholdColorRatioLow: 0.5
|
thresholdColorRatioLow: 0.5
|
||||||
|
|||||||
Reference in New Issue
Block a user