Merge pull request #1014 from Security-Onion-Solutions/fix/strelka_standalone

Fix module eval
This commit is contained in:
weslambert
2020-07-16 09:32:06 -04:00
committed by GitHub

View File

@@ -4,7 +4,7 @@
{%- set ES = salt['pillar.get']('elasticsearch:mainip', '') -%}
{%- endif %}
output {
if [event_type] =~ "strelka" {
if [module] =~ "strelka" {
elasticsearch {
pipeline => "%{module}.%{dataset}"
hosts => "{{ ES }}"