Files
securityonion/salt/logstash/defaults.yaml
2024-01-31 20:17:33 +00:00

73 lines
1.7 KiB
YAML

logstash:
enabled: False
assigned_pipelines:
roles:
standalone:
- manager
- search
receiver:
- receiver
heavynode:
- manager
- search
searchnode:
- search
manager:
- manager
managersearch:
- manager
- search
fleet:
- fleet
defined_pipelines:
fleet:
- so/0012_input_elastic_agent.conf.jinja
- so/9806_output_lumberjack_fleet.conf.jinja
manager:
- so/0011_input_endgame.conf
- so/0012_input_elastic_agent.conf.jinja
- so/0013_input_lumberjack_fleet.conf
- so/9999_output_redis.conf.jinja
receiver:
- so/0011_input_endgame.conf
- so/0012_input_elastic_agent.conf.jinja
- so/0013_input_lumberjack_fleet.conf
- so/9999_output_redis.conf.jinja
search:
- so/0900_input_redis.conf.jinja
- so/9805_output_elastic_agent.conf.jinja
- so/9900_output_endgame.conf.jinja
custom0: []
custom1: []
custom2: []
custom3: []
custom4: []
pipeline_config:
custom01: |-
filter {
if [event][module] =~ "zeek" {
mutate {
add_tag => ["network_stuff"]
}
}
}
custom02: PLACEHOLDER
custom03: PLACEHOLDER
custom04: PLACEHOLDER
custom05: PLACEHOLDER
custom06: PLACEHOLDER
custom07: PLACEHOLDER
custom08: PLACEHOLDER
custom09: PLACEHOLDER
custom10: PLACEHOLDER
settings:
lsheap: 500m
config:
http_x_host: 0.0.0.0
path_x_logs: /var/log/logstash
pipeline_x_workers: 1
pipeline_x_batch_x_size: 125
pipeline_x_ecs_compatibility: disabled
dmz_nodes: []