Filebeat - Modify config for Wazuh alerts

This commit is contained in:
Wes Lambert
2018-12-10 19:50:55 +00:00
parent cb68f502ee
commit e70db05a0f

View File

@@ -1,6 +1,7 @@
{%- set MASTER = grains['master'] %} {%- set MASTER = grains['master'] %}
{%- set HOSTNAME = salt['grains.get']('host', '') %} {%- set HOSTNAME = salt['grains.get']('host', '') %}
{%- set BROVER = salt['pillar.get']('static:broversion', 'COMMUNITY') %} {%- set BROVER = salt['pillar.get']('static:broversion', 'COMMUNITY') %}
{%- set WAZUHENABLED = salt['pillar.get']('static:wazuh_enabled', '1') %}
name: {{ HOSTNAME }} name: {{ HOSTNAME }}
@@ -36,16 +37,16 @@ filebeat.prospectors:
clean_removed: false clean_removed: false
close_removed: false close_removed: false
{%- if WAZUHENABLED != '1' %}
- type: log - type: log
paths: paths:
- /alerts/alerts.json - /wazuh/alerts/alerts.json
fields: fields:
type: ossec type: ossec
fields_under_root: true fields_under_root: true
clean_removed: false clean_removed: false
close_removed: false close_removed: false
{%- endif %}
#----------------------------- Logstash output --------------------------------- #----------------------------- Logstash output ---------------------------------
output.logstash: output.logstash: