mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-07 09:42:46 +01:00
Enable index sorting by default but allow it to be disabled
This commit is contained in:
@@ -1,3 +1,4 @@
|
|||||||
|
{%- set INDEX_SORTING = salt['pillar.get']('elasticsearch:index_sorting', True) %}
|
||||||
{
|
{
|
||||||
"index_patterns": ["so-*"],
|
"index_patterns": ["so-*"],
|
||||||
"version":50001,
|
"version":50001,
|
||||||
@@ -8,8 +9,10 @@
|
|||||||
"index.refresh_interval":"30s",
|
"index.refresh_interval":"30s",
|
||||||
"index.routing.allocation.require.box_type":"hot",
|
"index.routing.allocation.require.box_type":"hot",
|
||||||
"index.mapping.total_fields.limit": "1500",
|
"index.mapping.total_fields.limit": "1500",
|
||||||
|
{%- if INDEX_SORTING is sameas true %}
|
||||||
"index.sort.field": "@timestamp",
|
"index.sort.field": "@timestamp",
|
||||||
"index.sort.order": "desc",
|
"index.sort.order": "desc",
|
||||||
|
{%- endif %}
|
||||||
"analysis": {
|
"analysis": {
|
||||||
"analyzer": {
|
"analyzer": {
|
||||||
"es_security_analyzer": {
|
"es_security_analyzer": {
|
||||||
|
|||||||
Reference in New Issue
Block a user