mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-07 09:42:46 +01:00
Merge branch 'quickfix/helix' into dev
This commit is contained in:
4
pillar/logstash/helix.sls
Normal file
4
pillar/logstash/helix.sls
Normal file
@@ -0,0 +1,4 @@
|
||||
logstash:
|
||||
pipelines:
|
||||
helix:
|
||||
config: "/usr/share/logstash/pipelines/helix/*.conf"
|
||||
@@ -48,6 +48,7 @@ base:
|
||||
- static
|
||||
- firewall.*
|
||||
- fireeye
|
||||
- static
|
||||
- brologs
|
||||
- logstash.helix
|
||||
- static
|
||||
- minions.{{ grains.id }}
|
||||
|
||||
@@ -1395,7 +1395,7 @@
|
||||
"condition": "AND",
|
||||
"key": "container_name",
|
||||
"operator": "=",
|
||||
"value": "so-bro"
|
||||
"value": "so-zeek"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1913,7 +1913,7 @@
|
||||
"condition": "AND",
|
||||
"key": "container_name",
|
||||
"operator": "=",
|
||||
"value": "so-bro"
|
||||
"value": "so-zeek"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -1396,7 +1396,7 @@
|
||||
"condition": "AND",
|
||||
"key": "container_name",
|
||||
"operator": "=",
|
||||
"value": "so-bro"
|
||||
"value": "so-zeek"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1901,7 +1901,7 @@
|
||||
"condition": "AND",
|
||||
"key": "container_name",
|
||||
"operator": "=",
|
||||
"value": "so-bro"
|
||||
"value": "so-zeek"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#!/bin/bash
|
||||
|
||||
BROLOG=$(tac /host/nsm/bro/logs/packetloss.log | head -2)
|
||||
declare RESULT=($BROLOG)
|
||||
ZEEKLOG=$(tac /host/nsm/zeek/logs/packetloss.log | head -2)
|
||||
declare RESULT=($ZEEKLOG)
|
||||
CURRENTDROP=${RESULT[3]}
|
||||
PASTDROP=${RESULT[9]}
|
||||
DROPPED=$(($CURRENTDROP - $PASTDROP))
|
||||
|
||||
@@ -197,7 +197,6 @@ if (whiptail_you_sure) ; then
|
||||
patch_pillar >> $SETUPLOG 2>&1
|
||||
echo "** Generating the FireEye pillar **" >> $SETUPLOG
|
||||
fireeye_pillar >> $SETUPLOG 2>&1
|
||||
sensor_pillar >> $SETUPLOG 2>&1
|
||||
echo -e "XXX\n24\nCopying Minion Pillars to Master... \nXXX"
|
||||
copy_minion_tmp_files >> $SETUPLOG 2>&1
|
||||
# Do a checkin to push the key up
|
||||
|
||||
Reference in New Issue
Block a user