Merge pull request #481 from Security-Onion-Solutions/fix/strelka_stuff

Fix/strelka stuff
This commit is contained in:
weslambert
2020-04-01 09:00:07 -04:00
committed by GitHub
2 changed files with 10 additions and 10 deletions

View File

@@ -162,9 +162,10 @@ filebeat.inputs:
- type: log - type: log
paths: paths:
- /opt/so/log/strelka/strelka.log - /nsm/strelka/log/strelka.log
fields: fields:
module: strelka module: strelka
category: file
dataset: file dataset: file
processors: processors:

View File

@@ -23,14 +23,6 @@ strelkaconfdir:
- group: 939 - group: 939
- makedirs: True - makedirs: True
# Strelka logs
strelkalogdir:
file.directory:
- name: /opt/so/log/strelka
- user: 939
- group: 939
- makedirs: True
# Sync dynamic config to conf dir # Sync dynamic config to conf dir
strelkasync: strelkasync:
file.recurse: file.recurse:
@@ -47,6 +39,13 @@ strelkadatadir:
- group: 939 - group: 939
- makedirs: True - makedirs: True
strelkalogdir:
file.directory:
- name: /nsm/strelka/log
- user: 939
- group: 939
- makedirs: True
strelkastagedir: strelkastagedir:
file.directory: file.directory:
- name: /nsm/strelka/processed - name: /nsm/strelka/processed
@@ -75,7 +74,7 @@ strelka_frontend:
- image: soshybridhunter/so-strelka-frontend:HH1.2.1 - image: soshybridhunter/so-strelka-frontend:HH1.2.1
- binds: - binds:
- /opt/so/conf/strelka/frontend/:/etc/strelka/:ro - /opt/so/conf/strelka/frontend/:/etc/strelka/:ro
- /opt/so/log/strelka/:/var/log/strelka/:rw - /nsm/strelka/log/:/var/log/strelka/:rw
- privileged: True - privileged: True
- name: so-strelka-frontend - name: so-strelka-frontend
- command: strelka-frontend - command: strelka-frontend