Files
securityonion/salt/curator/files/action/delete.yml
2018-12-05 13:09:07 +00:00

27 lines
815 B
YAML

{% if grains['role'] == 'so-node' or grains['role'] == 'so-eval' %}
{%- set log_size_limit = salt['pillar.get']('node:log_size_limit', '') -%}
{%- endif %}
---
# Remember, leave a key empty if there is no value. None will be a string,
# not a Python "NoneType"
#
# Also remember that all examples have 'disable_action' set to True. If you
# want to use this action as a template, be sure to set this to False after
# copying it.
actions:
1:
action: delete_indices
description: >-
Delete indices when {{log_size_limit}}(GB) is exceeded.
options:
ignore_empty_list: True
disable_action: False
filters:
- filtertype: pattern
kind: prefix
value: logstash-
- filtertype: space
source: creation_date
use_age: True
disk_space: {{log_size_limit}}