Files
securityonion/salt/soctopus/files/templates/es-generic.template
2021-06-14 14:08:14 -04:00

12 lines
482 B
Plaintext

{% set ES = salt['pillar.get']('global:managerip', '') %}
{%- set ES_USER = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:user', '') %}
{%- set ES_PASS = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:pass', '') %}
alert: modules.so.playbook-es.PlaybookESAlerter
elasticsearch_host: "{{ ES }}:9200"
elasticsearch_user: "{{ ES_USER }}"
elasticsearch_pass: "{{ ES_PASS }}"
play_title: ""
play_url: "https://{{ ES }}/playbook/issues/6000"
sigma_level: ""