mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-08-30 19:29:19 +02:00
The Logstash log level was hardcoded to info in log4j2.properties, and logstash.yml carried no log.level key, so the only way to raise verbosity for troubleshooting was to hand-edit a file that the next highstate overwrites. Add log_x_level and log_x_format to logstash:config so both render into logstash.yml, annotated as advanced per-node settings with the value sets Logstash 9.3.7 accepts. log4j2.properties gains jinja, so it moves to log4j2.properties.jinja and is rendered by a discrete lslog4j2 state rather than the lsetcsync recurse, which cannot rename. The recurse exclude_pat now matches both names so it neither copies the template verbatim nor lets clean: True delete the rendered file, matching how pipelines.yml is already handled. The appender layout is selected at render time so log.format actually changes the log output instead of being a dead setting, keeping the existing file name so nothing downstream moves. rootLogger.level now follows ls.log.level rather than claiming info regardless of the configured level.