mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Playbook & SOCtopus init edits
This commit is contained in:
@@ -15,11 +15,6 @@
|
|||||||
"viewMode": 0,
|
"viewMode": 0,
|
||||||
"hideDisabled": "false",
|
"hideDisabled": "false",
|
||||||
"techniques": [{
|
"techniques": [{
|
||||||
"techniqueID": "T1003",
|
|
||||||
"color": "#5AADFF",
|
|
||||||
"comment": "",
|
|
||||||
"enabled": "true",
|
|
||||||
"metadata": []
|
|
||||||
}],
|
}],
|
||||||
"gradient": {
|
"gradient": {
|
||||||
"colors": ["#ff6666", "#ffe766", "#8ec843"],
|
"colors": ["#ff6666", "#ffe766", "#8ec843"],
|
||||||
|
|||||||
@@ -1,15 +1,5 @@
|
|||||||
navigatordefaultlayer:
|
|
||||||
file.manage:
|
|
||||||
- name: /opt/so/conf/playbook/nav_layer_playbook.json
|
|
||||||
- source: salt://playbook/files/nav_layer_playbook.json
|
|
||||||
- user: 939
|
|
||||||
- group: 939
|
|
||||||
- makedirs: True
|
|
||||||
- replace: False
|
|
||||||
- template: jinja
|
|
||||||
|
|
||||||
navigatorconfig:
|
navigatorconfig:
|
||||||
file.manage:
|
file.managed:
|
||||||
- name: /opt/so/conf/playbook/navigator_config.json
|
- name: /opt/so/conf/playbook/navigator_config.json
|
||||||
- source: salt://playbook/files/navigator_config.json
|
- source: salt://playbook/files/navigator_config.json
|
||||||
- user: 939
|
- user: 939
|
||||||
|
|||||||
@@ -28,19 +28,30 @@ playbookrulessync:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- template: jinja
|
- template: jinja
|
||||||
|
|
||||||
|
navigatordefaultlayer:
|
||||||
|
file.managed:
|
||||||
|
- name: /opt/so/conf/playbook/nav_layer_playbook.json
|
||||||
|
- source: salt://playbook/files/nav_layer_playbook.json
|
||||||
|
- user: 939
|
||||||
|
- group: 939
|
||||||
|
- makedirs: True
|
||||||
|
- replace: False
|
||||||
|
- template: jinja
|
||||||
|
|
||||||
so-soctopusimage:
|
so-soctopusimage:
|
||||||
cmd.run:
|
cmd.run:
|
||||||
- name: docker pull --disable-content-trust=false soshybridhunter/so-soctopus:HH1.1.0
|
- name: docker pull --disable-content-trust=false soshybridhunter/so-soctopus:HH1.1.1
|
||||||
|
|
||||||
so-soctopus:
|
so-soctopus:
|
||||||
docker_container.running:
|
docker_container.running:
|
||||||
- require:
|
- require:
|
||||||
- so-soctopusimage
|
- so-soctopusimage
|
||||||
- image: soshybridhunter/so-soctopus:HH1.1.0
|
- image: soshybridhunter/so-soctopus:HH1.1.1
|
||||||
- hostname: soctopus
|
- hostname: soctopus
|
||||||
- name: so-soctopus
|
- name: so-soctopus
|
||||||
- binds:
|
- binds:
|
||||||
- /opt/so/conf/soctopus/SOCtopus.conf:/SOCtopus/SOCtopus.conf:ro
|
- /opt/so/conf/soctopus/SOCtopus.conf:/SOCtopus/SOCtopus.conf:ro
|
||||||
- /opt/so/rules/elastalert/playbook:/etc/playbook-rules:rw
|
- /opt/so/rules/elastalert/playbook:/etc/playbook-rules:rw
|
||||||
|
- /opt/so/conf/playbook/nav_layer_playbook.json:/etc/playbook/nav_layer_playbook.json:rw
|
||||||
- port_bindings:
|
- port_bindings:
|
||||||
- 0.0.0.0:7000:7000
|
- 0.0.0.0:7000:7000
|
||||||
|
|||||||
Reference in New Issue
Block a user