mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Merge pull request #481 from Security-Onion-Solutions/fix/strelka_stuff
Fix/strelka stuff
This commit is contained in:
@@ -162,9 +162,10 @@ filebeat.inputs:
|
|||||||
|
|
||||||
- type: log
|
- type: log
|
||||||
paths:
|
paths:
|
||||||
- /opt/so/log/strelka/strelka.log
|
- /nsm/strelka/log/strelka.log
|
||||||
fields:
|
fields:
|
||||||
module: strelka
|
module: strelka
|
||||||
|
category: file
|
||||||
dataset: file
|
dataset: file
|
||||||
|
|
||||||
processors:
|
processors:
|
||||||
|
|||||||
@@ -23,14 +23,6 @@ strelkaconfdir:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
|
|
||||||
# Strelka logs
|
|
||||||
strelkalogdir:
|
|
||||||
file.directory:
|
|
||||||
- name: /opt/so/log/strelka
|
|
||||||
- user: 939
|
|
||||||
- group: 939
|
|
||||||
- makedirs: True
|
|
||||||
|
|
||||||
# Sync dynamic config to conf dir
|
# Sync dynamic config to conf dir
|
||||||
strelkasync:
|
strelkasync:
|
||||||
file.recurse:
|
file.recurse:
|
||||||
@@ -47,6 +39,13 @@ strelkadatadir:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
|
|
||||||
|
strelkalogdir:
|
||||||
|
file.directory:
|
||||||
|
- name: /nsm/strelka/log
|
||||||
|
- user: 939
|
||||||
|
- group: 939
|
||||||
|
- makedirs: True
|
||||||
|
|
||||||
strelkastagedir:
|
strelkastagedir:
|
||||||
file.directory:
|
file.directory:
|
||||||
- name: /nsm/strelka/processed
|
- name: /nsm/strelka/processed
|
||||||
@@ -75,7 +74,7 @@ strelka_frontend:
|
|||||||
- image: soshybridhunter/so-strelka-frontend:HH1.2.1
|
- image: soshybridhunter/so-strelka-frontend:HH1.2.1
|
||||||
- binds:
|
- binds:
|
||||||
- /opt/so/conf/strelka/frontend/:/etc/strelka/:ro
|
- /opt/so/conf/strelka/frontend/:/etc/strelka/:ro
|
||||||
- /opt/so/log/strelka/:/var/log/strelka/:rw
|
- /nsm/strelka/log/:/var/log/strelka/:rw
|
||||||
- privileged: True
|
- privileged: True
|
||||||
- name: so-strelka-frontend
|
- name: so-strelka-frontend
|
||||||
- command: strelka-frontend
|
- command: strelka-frontend
|
||||||
|
|||||||
Reference in New Issue
Block a user