mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Merge pull request #2393 from Security-Onion-Solutions/fix/strelka_filestream
Fix/strelka filestream
This commit is contained in:
@@ -16,7 +16,7 @@ throughput:
|
|||||||
delay: 0s
|
delay: 0s
|
||||||
files:
|
files:
|
||||||
patterns:
|
patterns:
|
||||||
- '/nsm/strelka/*'
|
- '/nsm/strelka/unprocessed/*'
|
||||||
delete: false
|
delete: false
|
||||||
gatekeeper: true
|
gatekeeper: true
|
||||||
response:
|
response:
|
||||||
|
|||||||
@@ -72,13 +72,20 @@ strelkalogdir:
|
|||||||
- group: 939
|
- group: 939
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
|
|
||||||
strelkastagedir:
|
strelkaprocessed:
|
||||||
file.directory:
|
file.directory:
|
||||||
- name: /nsm/strelka/processed
|
- name: /nsm/strelka/processed
|
||||||
- user: 939
|
- user: 939
|
||||||
- group: 939
|
- group: 939
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
|
|
||||||
|
strelkaunprocessed:
|
||||||
|
file.directory:
|
||||||
|
- name: /nsm/strelka/unprocessed
|
||||||
|
- user: 939
|
||||||
|
- group: 939
|
||||||
|
- makedirs: True
|
||||||
|
|
||||||
strelka_coordinator:
|
strelka_coordinator:
|
||||||
docker_container.running:
|
docker_container.running:
|
||||||
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-redis:{{ VERSION }}
|
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-redis:{{ VERSION }}
|
||||||
@@ -163,11 +170,18 @@ append_so-strelka-filestream_so-status.conf:
|
|||||||
file.append:
|
file.append:
|
||||||
- name: /opt/so/conf/so-status/so-status.conf
|
- name: /opt/so/conf/so-status/so-status.conf
|
||||||
- text: so-strelka-filestream
|
- text: so-strelka-filestream
|
||||||
|
|
||||||
|
strelka_zeek_extracted_sync_old:
|
||||||
|
cron.absent:
|
||||||
|
- user: root
|
||||||
|
- name: '[ -d /nsm/zeek/extracted/complete/ ] && mv /nsm/zeek/extracted/complete/* /nsm/strelka/ > /dev/null 2>&1'
|
||||||
|
- minute: '*'
|
||||||
|
|
||||||
strelka_zeek_extracted_sync:
|
strelka_zeek_extracted_sync:
|
||||||
cron.present:
|
cron.present:
|
||||||
- user: root
|
- user: root
|
||||||
- name: '[ -d /nsm/zeek/extracted/complete/ ] && mv /nsm/zeek/extracted/complete/* /nsm/strelka/ > /dev/null 2>&1'
|
- identifier: zeek-extracted-strelka-sync
|
||||||
|
- name: '[ -d /nsm/zeek/extracted/complete/ ] && mv /nsm/zeek/extracted/complete/* /nsm/strelka/unprocessed/ > /dev/null 2>&1'
|
||||||
- minute: '*'
|
- minute: '*'
|
||||||
|
|
||||||
{% else %}
|
{% else %}
|
||||||
@@ -176,4 +190,4 @@ strelka_state_not_allowed:
|
|||||||
test.fail_without_changes:
|
test.fail_without_changes:
|
||||||
- name: strelka_state_not_allowed
|
- name: strelka_state_not_allowed
|
||||||
|
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
Reference in New Issue
Block a user