Files
securityonion/salt/elasticfleet/files/integrations/endpoints-initial/system-endpoints.json
2023-05-16 12:50:40 -04:00

58 lines
1.1 KiB
JSON

{
"policy_id": "endpoints-initial",
"package": {
"name": "system",
"version": ""
},
"name": "system-endpoints",
"namespace": "default",
"inputs": {
"system-logfile": {
"enabled": true,
"streams": {
"system.auth": {
"enabled": true,
"vars": {
"paths": [
"/var/log/auth.log*",
"/var/log/secure*"
]
}
},
"system.syslog": {
"enabled": true,
"vars": {
"paths": [
"/var/log/messages*",
"/var/log/syslog*"
]
}
}
}
},
"system-winlog": {
"enabled": true,
"vars": {
"preserve_original_event": false
},
"streams": {
"system.application": {
"enabled": true,
"vars": {
"tags": []
}
},
"system.security": {
"enabled": true,
"vars": {
"tags": []
}
}
}
},
"system-system/metrics": {
"enabled": false
}
}
}