Merge pull request #2393 from Security-Onion-Solutions/fix/strelka_filestream

Fix/strelka filestream
This commit is contained in:
weslambert
2020-12-18 15:48:54 -05:00
committed by GitHub
2 changed files with 19 additions and 5 deletions

View File

@@ -16,7 +16,7 @@ throughput:
delay: 0s delay: 0s
files: files:
patterns: patterns:
- '/nsm/strelka/*' - '/nsm/strelka/unprocessed/*'
delete: false delete: false
gatekeeper: true gatekeeper: true
response: response:

View File

@@ -72,13 +72,20 @@ strelkalogdir:
- group: 939 - group: 939
- makedirs: True - makedirs: True
strelkastagedir: strelkaprocessed:
file.directory: file.directory:
- name: /nsm/strelka/processed - name: /nsm/strelka/processed
- user: 939 - user: 939
- group: 939 - group: 939
- makedirs: True - makedirs: True
strelkaunprocessed:
file.directory:
- name: /nsm/strelka/unprocessed
- user: 939
- group: 939
- makedirs: True
strelka_coordinator: strelka_coordinator:
docker_container.running: docker_container.running:
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-redis:{{ VERSION }} - image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-redis:{{ VERSION }}
@@ -163,11 +170,18 @@ append_so-strelka-filestream_so-status.conf:
file.append: file.append:
- name: /opt/so/conf/so-status/so-status.conf - name: /opt/so/conf/so-status/so-status.conf
- text: so-strelka-filestream - text: so-strelka-filestream
strelka_zeek_extracted_sync_old:
cron.absent:
- user: root
- name: '[ -d /nsm/zeek/extracted/complete/ ] && mv /nsm/zeek/extracted/complete/* /nsm/strelka/ > /dev/null 2>&1'
- minute: '*'
strelka_zeek_extracted_sync: strelka_zeek_extracted_sync:
cron.present: cron.present:
- user: root - user: root
- name: '[ -d /nsm/zeek/extracted/complete/ ] && mv /nsm/zeek/extracted/complete/* /nsm/strelka/ > /dev/null 2>&1' - identifier: zeek-extracted-strelka-sync
- name: '[ -d /nsm/zeek/extracted/complete/ ] && mv /nsm/zeek/extracted/complete/* /nsm/strelka/unprocessed/ > /dev/null 2>&1'
- minute: '*' - minute: '*'
{% else %} {% else %}
@@ -176,4 +190,4 @@ strelka_state_not_allowed:
test.fail_without_changes: test.fail_without_changes:
- name: strelka_state_not_allowed - name: strelka_state_not_allowed
{% endif %} {% endif %}