Merge branch 'dev' into foxtrot

This commit is contained in:
William Wernert
2021-10-25 10:50:25 -04:00
2 changed files with 162 additions and 23 deletions

View File

@@ -26,23 +26,48 @@
"properties": {
"ephemeral_id": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"id": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"name": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"type": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"version": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
}
}
},
@@ -597,7 +622,12 @@
"properties": {
"version": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
}
}
},
@@ -683,18 +713,33 @@
},
"category": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"code": {
"ignore_above": 1024,
"type": "keyword"
},
"created": {
"type": "date"
"type": "date",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"dataset": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"duration": {
"type": "long"
@@ -711,7 +756,12 @@
"type": "keyword"
},
"ingested": {
"type": "date"
"type": "date",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"kind": {
"ignore_above": 1024,
@@ -719,7 +769,12 @@
},
"module": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"original": {
"doc_values": false,
@@ -729,7 +784,12 @@
},
"outcome": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"provider": {
"ignore_above": 1024,
@@ -756,11 +816,21 @@
},
"timezone": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"type": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"url": {
"ignore_above": 1024,
@@ -1006,7 +1076,12 @@
},
"name": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"os": {
"properties": {
@@ -1139,11 +1214,21 @@
},
"method": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"referrer": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
}
}
},
@@ -1187,7 +1272,12 @@
"properties": {
"level": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"logger": {
"ignore_above": 1024,
@@ -2149,7 +2239,12 @@
},
"name": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"node": {
"properties": {
@@ -2165,7 +2260,12 @@
},
"type": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"version": {
"ignore_above": 1024,
@@ -2177,7 +2277,12 @@
"properties": {
"address": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"as": {
"properties": {
@@ -2333,7 +2438,12 @@
},
"tags": {
"ignore_above": 1024,
"type": "keyword"
"type": "keyword",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"threat": {
"properties": {
@@ -2684,6 +2794,9 @@
},
"original": {
"fields": {
"keyword": {
"type": "keyword"
},
"text": {
"norms": false,
"type": "text"

View File

@@ -80,6 +80,10 @@ soccustomroles:
- mode: 600
- template: jinja
socusersroles:
file.exists:
- name: /opt/so/conf/soc/soc_users_roles
# we dont want this added too early in setup, so we add the onlyif to verify 'startup_states: highstate'
# is in the minion config. That line is added before the final highstate during setup
sosyncusers:
@@ -95,13 +99,13 @@ so-soc:
- name: so-soc
- binds:
- /nsm/soc/jobs:/opt/sensoroni/jobs:rw
- /opt/so/log/soc/:/opt/sensoroni/logs/:rw
- /opt/so/conf/soc/soc.json:/opt/sensoroni/sensoroni.json:ro
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
- /opt/so/conf/soc/custom_roles:/opt/sensoroni/rbac/custom_roles:ro
- /opt/so/conf/soc/soc_users_roles:/opt/sensoroni/rbac/users_roles:rw
- /opt/so/log/soc/:/opt/sensoroni/logs/:rw
{%- if salt['pillar.get']('nodestab', {}) %}
- extra_hosts:
{%- for SN, SNDATA in salt['pillar.get']('nodestab', {}).items() %}
@@ -112,6 +116,15 @@ so-soc:
- 0.0.0.0:9822:9822
- watch:
- file: /opt/so/conf/soc/*
- require:
- file: socdatadir
- file: soclogdir
- file: socconfig
- file: socmotd
- file: socbanner
- file: soccustom
- file: soccustomroles
- file: socusersroles
append_so-soc_so-status.conf:
file.append:
@@ -154,6 +167,14 @@ kratossync:
- file_mode: 600
- template: jinja
kratos_schema:
file.exists:
- name: /opt/so/conf/kratos/schema.json
kratos_yaml:
file.exists:
- name: /opt/so/conf/kratos/kratos.yaml
so-kratos:
docker_container.running:
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-kratos:{{ VERSION }}
@@ -169,6 +190,11 @@ so-kratos:
- 0.0.0.0:4434:4434
- watch:
- file: /opt/so/conf/kratos
- require:
- file: kratos_schema
- file: kratos_yaml
- file: kratoslogdir
- file: kratosdir
append_so-kratos_so-status.conf:
file.append: