mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
91 lines
1.5 KiB
Plaintext
91 lines
1.5 KiB
Plaintext
base:
|
|
'*':
|
|
- patch.needs_restarting
|
|
- logrotate
|
|
|
|
'*_eval or *_helix or *_heavynode or *_sensor or *_standalone or *_import':
|
|
- match: compound
|
|
- zeek
|
|
|
|
'*_managersearch or *_heavynode':
|
|
- match: compound
|
|
- logstash
|
|
- logstash.manager
|
|
- logstash.search
|
|
- elasticsearch.search
|
|
|
|
'*_manager':
|
|
- logstash
|
|
- logstash.manager
|
|
- elasticsearch.manager
|
|
|
|
'*_manager or *_managersearch':
|
|
- match: compound
|
|
- data.*
|
|
- secrets
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_sensor':
|
|
- zeeklogs
|
|
- healthcheck.sensor
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_eval':
|
|
- data.*
|
|
- zeeklogs
|
|
- secrets
|
|
- healthcheck.eval
|
|
- elasticsearch.eval
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_standalone':
|
|
- logstash
|
|
- logstash.manager
|
|
- logstash.search
|
|
- elasticsearch.search
|
|
- data.*
|
|
- zeeklogs
|
|
- secrets
|
|
- healthcheck.standalone
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_node':
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_heavynode':
|
|
- zeeklogs
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_helix':
|
|
- fireeye
|
|
- zeeklogs
|
|
- logstash
|
|
- logstash.helix
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_fleet':
|
|
- data.*
|
|
- secrets
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_searchnode':
|
|
- logstash
|
|
- logstash.search
|
|
- elasticsearch.search
|
|
- global
|
|
- minions.{{ grains.id }}
|
|
|
|
'*_import':
|
|
- zeeklogs
|
|
- secrets
|
|
- elasticsearch.eval
|
|
- global
|
|
- minions.{{ grains.id }} |