mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-08-27 18:08:39 +02:00
Auto State Apply fires on SOC config saves and on suricata/strelka rule updates. Files a user creates or edits by hand under /opt/so/saltstack/local/salt/ change no pillar, so nothing fired and the change waited for the next scheduled highstate, now 120 minutes by default. That gap is the 3.2 Known Issue in the docs. Watch the directories the docs tell users to edit, and route them through the push pipeline that already exists: zeek/policy -> zeek (covers intel/ and custom/) zeek/zkg -> zeek elasticsearch/files/ingest -> elasticsearch elasticsearch/roles -> elasticsearch logstash/pipelines/config/custom -> logstash Tags are pillar_push_map.yaml app names, so the existing entries already carry the right state and compound target, and no map entry changes. Rename the beacon rules_beacon -> local_files_beacon. Rules are now one of five kinds of file it watches, and the new name matches how its sibling postgres_pillar_beacon is named: source, then what it watches. Replace push_suricata.sls and push_strelka.sls with one push_files.sls bound to salt/beacon/*/local_files_beacon/*, which looks the tag up in pillar_push_map.yaml the same way push_pillar.sls does. The map's suricata and strelka targets match the compounds those two reactors hardcoded, so rule pushes are unchanged. The app comes from the event tag rather than the payload because salt's beacon loop pops the beacon's tag key off the data. Key watermarks by watched directory instead of by tag. zeek/policy and zeek/zkg both emit the tag zeek, and a shared watermark would make them overwrite each other's digest and emit on every poll. Prune .git from the fingerprint walk. zkg packages must be git clones with a clean working tree, so the watched tree carries full git metadata; walking it every 15s is wasted work and git's own index and ref mtime churn would fire a grid-wide zeek apply on its own. Placing or updating a package always touches working-tree files too, so detection is unaffected. The watch is an allowlist rather than the whole local salt tree because salt writes into that tree itself: hypervisor/hosts/ is rewritten continuously by virtual_node_manager.py and virtual_power_manager.py, libvirt/images/ holds multi-GB qcow2 files, and elasticfleet/files/so_agent-installers/, elasticsearch/files/users, ca/files/ and filebeat/files/ are all state-written. Watching any of them would either self-retrigger or make the 15s poll walk gigabytes.
19 lines
922 B
Django/Jinja
19 lines
922 B
Django/Jinja
{% from 'salt/auto_apply.map.jinja' import AUTOAPPLY %}
|
|
beacons:
|
|
postgres_pillar_beacon:
|
|
- interval: {{ AUTOAPPLY.drain_interval }}
|
|
- disable_during_state_run: False
|
|
local_files_beacon:
|
|
- interval: {{ AUTOAPPLY.drain_interval }}
|
|
- disable_during_state_run: False
|
|
# Tags are app names in salt/reactor/pillar_push_map.yaml.
|
|
# Allowlist on purpose: salt writes elsewhere under local/salt/ and would self-retrigger.
|
|
- paths:
|
|
/opt/so/saltstack/local/salt/suricata/rules: suricata
|
|
/opt/so/saltstack/local/salt/strelka/rules/compiled: strelka
|
|
/opt/so/saltstack/local/salt/zeek/policy: zeek
|
|
/opt/so/saltstack/local/salt/zeek/zkg: zeek
|
|
/opt/so/saltstack/local/salt/elasticsearch/files/ingest: elasticsearch
|
|
/opt/so/saltstack/local/salt/elasticsearch/roles: elasticsearch
|
|
/opt/so/saltstack/local/salt/logstash/pipelines/config/custom: logstash
|