# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one # or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at # https://securityonion.net/license; you may not use this file except in compliance with the # Elastic License 2.0. {%- set cur_close_days = CURATORMERGED['logs-windows-powershell-default'].close %} actions: 1: action: close description: >- Close Elastic Agent Windows Powershell indices older than {{cur_close_days}} days. options: delete_aliases: False timeout_override: ignore_empty_list: True disable_action: False filters: - filtertype: pattern kind: regex value: '^(.ds-logs-windows.powershell-default.*)$' - filtertype: age source: name direction: older timestring: '%Y.%m.%d' unit: days unit_count: {{cur_close_days}} exclude: