diff --git a/salt/zeek/config.sls b/salt/zeek/config.sls index 42ea74fc9..2797c6fa2 100644 --- a/salt/zeek/config.sls +++ b/salt/zeek/config.sls @@ -32,6 +32,20 @@ zeekpolicydir: - group: 939 - makedirs: True +zeekzkgdir: + file.directory: + - name: /opt/so/conf/zeek/zkg + - user: 937 + - group: 939 + - makedirs: True + +zeekzkgsync: + file.recurse: + - name: /opt/so/conf/zeek/zkg + - source: salt://zeek/zkg + - user: 937 + - group: 939 + # Zeek Log Directory zeeklogdir: file.directory: diff --git a/salt/zeek/enabled.sls b/salt/zeek/enabled.sls index ff090428f..cf87946af 100644 --- a/salt/zeek/enabled.sls +++ b/salt/zeek/enabled.sls @@ -35,6 +35,7 @@ so-zeek: - /opt/so/conf/zeek/policy/intel:/opt/zeek/share/zeek/policy/intel:rw - /opt/so/conf/zeek/bpf:/opt/zeek/etc/bpf:ro - /opt/so/conf/zeek/config.zeek:/opt/zeek/share/zeek/site/packages/ja4/config.zeek:ro + - /opt/so/conf/zeek/zkg:/opt/so/conf/zeek/zkg:ro {% if DOCKER.containers['so-zeek'].custom_bind_mounts %} {% for BIND in DOCKER.containers['so-zeek'].custom_bind_mounts %} - {{ BIND }} diff --git a/salt/zeek/zkg/README b/salt/zeek/zkg/README new file mode 100644 index 000000000..6c3b65ae7 --- /dev/null +++ b/salt/zeek/zkg/README @@ -0,0 +1 @@ +# Place custom Zeek packages in /opt/so/saltstack/local/salt/zeek/zkg/