mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-15 21:52:47 +01:00
33 lines
963 B
YAML
33 lines
963 B
YAML
{%- set ZEEKVER = salt['pillar.get']('global:mdengine', '') %}
|
|
securityonion_filebeat:
|
|
modules:
|
|
elasticsearch:
|
|
server:
|
|
enabled: true
|
|
var.paths: ["/logs/elasticsearch/*.log"]
|
|
kibana:
|
|
log:
|
|
enabled: true
|
|
var.paths: ["/logs/kibana/kibana.log"]
|
|
logstash:
|
|
log:
|
|
enabled: true
|
|
var.paths: ["/logs/logstash.log"]
|
|
redis:
|
|
log:
|
|
enabled: true
|
|
var.paths: ["/logs/redis.log"]
|
|
suricata:
|
|
eve:
|
|
enabled: true
|
|
var.paths: ["/nsm/suricata/eve*.json"]
|
|
{%- if grains['role'] in ['so-eval', 'so-standalone', 'so-sensor', 'so-helix', 'so-heavynode', 'so-import'] %}
|
|
{%- if ZEEKVER != 'SURICATA' %}
|
|
zeek:
|
|
{%- for LOGNAME in salt['pillar.get']('zeeklogs:enabled', '') %}
|
|
{{ LOGNAME }}:
|
|
enabled: false
|
|
var.paths: ["/nsm/zeek/logs/current/{{ LOGNAME }}.log"]
|
|
{%- endfor %}
|
|
{%- endif %}
|
|
{%- endif %} |