Files
securityonion/salt/logstash/pipelines/config/so/9100_output_osquery.conf.jinja
2022-10-11 11:57:15 -04:00

14 lines
339 B
Django/Jinja

output {
if [module] =~ "osquery" and "live_query" not in [dataset] {
elasticsearch {
pipeline => "%{module}.%{dataset}"
hosts => "{{ GLOBALS.manager }}"
user => "{{ ES_USER }}"
password => "{{ ES_PASS }}"
index => "so-osquery"
ssl => true
ssl_certificate_verification => false
}
}
}