mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-08-23 16:08:19 +02:00
LogExpireInterval, StatsLogExpireInterval and CrashExpireInterval are only acted on by "zeekctl cron", which nothing in the grid ran, so setting them in SOC did nothing. Add so-zeek-cron and run it every 5 minutes, the interval upstream recommends. This also restarts a node that died unexpectedly and marks it crashed so a crash report is written, which is what CrashExpireInterval then reaps. The crontab runs as root because the script needs the docker socket; it drops to the zeek user inside the container so the stats logs and zeekctl-config.sh it writes stay owned by uid 937. Annotate the five zeekctl settings that were previously undocumented. The regex on LogExpireInterval matters: a bare number means days, and a value shorter than LogRotationInterval raises ConfigurationError, which fails the zeekctl deploy in the container entrypoint. Zeek then never starts while Salt still reports success and the container still reports healthy. Excluding the min unit keeps that unreachable at the default 3600 second rotation interval. MinDiskSpace and MailHostUpDown only send mail and the image has no sendmail, so their descriptions say they currently have no effect.
112 lines
3.9 KiB
YAML+Jinja
112 lines
3.9 KiB
YAML+Jinja
# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one
|
|
# or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
|
|
# https://securityonion.net/license; you may not use this file except in compliance with the
|
|
# Elastic License 2.0.
|
|
|
|
{% from 'allowed_states.map.jinja' import allowed_states %}
|
|
{% if sls.split('.')[0] in allowed_states %}
|
|
{% from 'vars/globals.map.jinja' import GLOBALS %}
|
|
{% from 'docker/docker.map.jinja' import DOCKERMERGED %}
|
|
|
|
|
|
include:
|
|
- zeek.config
|
|
- zeek.sostatus
|
|
|
|
so-zeek:
|
|
docker_container.running:
|
|
- image: {{ GLOBALS.registry_host }}:5000/{{ GLOBALS.image_repo }}/so-zeek:{{ GLOBALS.so_version }}
|
|
- restart_policy: unless-stopped
|
|
- start: True
|
|
- privileged: True
|
|
{% if DOCKERMERGED.containers['so-zeek'].ulimits %}
|
|
- ulimits:
|
|
{% for ULIMIT in DOCKERMERGED.containers['so-zeek'].ulimits %}
|
|
- {{ ULIMIT.name }}={{ ULIMIT.soft }}:{{ ULIMIT.hard }}
|
|
{% endfor %}
|
|
{% endif %}
|
|
- binds:
|
|
- /nsm/zeek/logs:/nsm/zeek/logs:rw
|
|
- /nsm/zeek/spool:/nsm/zeek/spool:rw
|
|
- /nsm/zeek/extracted:/nsm/zeek/extracted:rw
|
|
- /opt/so/conf/zeek/local.zeek:/opt/zeek/share/zeek/site/local.zeek:ro
|
|
- /opt/so/conf/zeek/node.cfg:/opt/zeek/etc/node.cfg:ro
|
|
- /opt/so/conf/zeek/networks.cfg:/opt/zeek/etc/networks.cfg:ro
|
|
- /opt/so/conf/zeek/zeekctl.cfg:/opt/zeek/etc/zeekctl.cfg:ro
|
|
- /opt/so/conf/zeek/policy/securityonion:/opt/zeek/share/zeek/policy/securityonion:ro
|
|
- /opt/so/conf/zeek/policy/custom:/opt/zeek/share/zeek/policy/custom:ro
|
|
- /opt/so/conf/zeek/policy/cve-2020-0601:/opt/zeek/share/zeek/policy/cve-2020-0601:ro
|
|
- /opt/so/conf/zeek/policy/intel:/opt/zeek/share/zeek/policy/intel:rw
|
|
- /opt/so/conf/zeek/bpf:/opt/zeek/etc/bpf:ro
|
|
- /opt/so/conf/zeek/config.zeek:/opt/zeek/share/zeek/site/packages/ja4/config.zeek:ro
|
|
- /opt/so/conf/zeek/zkg:/opt/so/conf/zeek/zkg:ro
|
|
{% if DOCKERMERGED.containers['so-zeek'].custom_bind_mounts %}
|
|
{% for BIND in DOCKERMERGED.containers['so-zeek'].custom_bind_mounts %}
|
|
- {{ BIND }}
|
|
{% endfor %}
|
|
{% endif %}
|
|
- network_mode: host
|
|
{% if DOCKERMERGED.containers['so-zeek'].extra_hosts %}
|
|
- extra_hosts:
|
|
{% for XTRAHOST in DOCKERMERGED.containers['so-zeek'].extra_hosts %}
|
|
- {{ XTRAHOST }}
|
|
{% endfor %}
|
|
{% endif %}
|
|
{% if DOCKERMERGED.containers['so-zeek'].extra_env %}
|
|
- environment:
|
|
{% for XTRAENV in DOCKERMERGED.containers['so-zeek'].extra_env %}
|
|
- {{ XTRAENV }}
|
|
{% endfor %}
|
|
{% endif %}
|
|
- watch:
|
|
- file: /opt/so/conf/zeek/local.zeek
|
|
- file: /opt/so/conf/zeek/node.cfg
|
|
- file: /opt/so/conf/zeek/networks.cfg
|
|
- file: /opt/so/conf/zeek/zeekctl.cfg
|
|
- file: /opt/so/conf/zeek/policy
|
|
- file: /opt/so/conf/zeek/bpf
|
|
- require:
|
|
- file: localzeek
|
|
- file: nodecfg
|
|
- file: zeekctlcfg
|
|
- file: zeekbpf
|
|
|
|
delete_so-zeek_so-status.disabled:
|
|
file.uncomment:
|
|
- name: /opt/so/conf/so-status/so-status.conf
|
|
- regex: ^so-zeek$
|
|
|
|
zeekpacketlosscron:
|
|
cron.present:
|
|
- name: /usr/local/bin/packetloss.sh
|
|
- identifier: zeekpacketlosscron
|
|
- user: root
|
|
- minute: '*/10'
|
|
- hour: '*'
|
|
- daymonth: '*'
|
|
- month: '*'
|
|
- dayweek: '*'
|
|
|
|
# LogExpireInterval, StatsLogExpireInterval and CrashExpireInterval are only acted on by
|
|
# 'zeekctl cron', so run it on the interval upstream recommends. This also restarts any
|
|
# node that died unexpectedly. Runs as root because the script needs the docker socket;
|
|
# it drops to the zeek user inside the container.
|
|
zeekctlcron:
|
|
cron.present:
|
|
- name: /usr/sbin/so-zeek-cron > /dev/null 2>&1
|
|
- identifier: zeekctlcron
|
|
- user: root
|
|
- minute: '*/5'
|
|
- hour: '*'
|
|
- daymonth: '*'
|
|
- month: '*'
|
|
- dayweek: '*'
|
|
|
|
{% else %}
|
|
|
|
{{sls}}_state_not_allowed:
|
|
test.fail_without_changes:
|
|
- name: {{sls}}_state_not_allowed
|
|
|
|
{% endif %}
|