mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
28 lines
878 B
YAML
28 lines
878 B
YAML
# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one
|
|
# or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
|
|
# https://securityonion.net/license; you may not use this file except in compliance with the
|
|
# Elastic License 2.0.
|
|
|
|
{%- set cur_close_days = CURATORMERGED['so-syslog'].close %}
|
|
actions:
|
|
1:
|
|
action: close
|
|
description: >-
|
|
Close syslog indices older than {{cur_close_days}} days.
|
|
options:
|
|
delete_aliases: False
|
|
timeout_override:
|
|
ignore_empty_list: True
|
|
disable_action: False
|
|
filters:
|
|
- filtertype: pattern
|
|
kind: regex
|
|
value: '^(logstash-syslog.*|so-syslog.*)$'
|
|
- filtertype: age
|
|
source: name
|
|
direction: older
|
|
timestring: '%Y.%m.%d'
|
|
unit: days
|
|
unit_count: {{cur_close_days}}
|
|
exclude:
|