Files
securityonion/salt/logstash/pipelines/config/so/9600_output_ossec.conf.jinja
T
Mike Reeves 2bd9dd80e2 Move In Day
2022-09-07 09:06:25 -04:00

17 lines
508 B
Django/Jinja

{%- set ES = salt['grains.get']('master') -%}
{%- set ES_USER = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:user', '') %}
{%- set ES_PASS = salt['pillar.get']('elasticsearch:auth:users:so_elastic_user:pass', '') %}
output {
if [module] =~ "ossec" {
elasticsearch {
pipeline => "%{module}"
hosts => "{{ ES }}"
user => "{{ ES_USER }}"
password => "{{ ES_PASS }}"
index => "so-ossec"
ssl => true
ssl_certificate_verification => false
}
}
}