mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Add SOC Config for Detections
This commit is contained in:
@@ -1002,6 +1002,11 @@ soc:
|
|||||||
jobDir: jobs
|
jobDir: jobs
|
||||||
kratos:
|
kratos:
|
||||||
hostUrl:
|
hostUrl:
|
||||||
|
elastalertengine:
|
||||||
|
communityRulesImportFrequencySeconds: 180
|
||||||
|
elastAlertRulesFolder: /opt/so/rules/elastalert
|
||||||
|
rulesFingerprintFile: /opt/so/conf/soc/sigma.fingerprint
|
||||||
|
sigmaRulePackages: all
|
||||||
elastic:
|
elastic:
|
||||||
hostUrl:
|
hostUrl:
|
||||||
remoteHostUrls: []
|
remoteHostUrls: []
|
||||||
@@ -1043,6 +1048,15 @@ soc:
|
|||||||
- rbac/custom_roles
|
- rbac/custom_roles
|
||||||
userFiles:
|
userFiles:
|
||||||
- rbac/users_roles
|
- rbac/users_roles
|
||||||
|
strelkaengine:
|
||||||
|
compileYaraPythonScriptPath: /opt/so/conf/strelka/compile_yara.py
|
||||||
|
reposFolder: /nsm/rules/strelka/repos
|
||||||
|
rulesRepos:
|
||||||
|
- https://github.com/Security-Onion-Solutions/securityonion-yara
|
||||||
|
yaraRulesFolder: /opt/so/conf/strelka/rules
|
||||||
|
suricataengine:
|
||||||
|
communityRulesFile: /nsm/rules/suricata/emerging-all.rules
|
||||||
|
rulesFingerprintFile: /opt/so/conf/soc/emerging-all.fingerprint
|
||||||
client:
|
client:
|
||||||
enableReverseLookup: false
|
enableReverseLookup: false
|
||||||
docsUrl: /docs/
|
docsUrl: /docs/
|
||||||
|
|||||||
Reference in New Issue
Block a user