Files
securityonion/salt/strelka/filecheck/filecheck.yaml
2022-10-31 13:41:45 -04:00

12 lines
379 B
YAML

{%- set ENGINE = salt['pillar.get']('global:mdengine', '') -%}
filecheck:
{%- if ENGINE == "SURICATA" -%}
extract_path = '/nsm/suricata/extracted'
{%- else -%}
extract_path = '/nsm/zeek/extracted/complete'
{%- endif -%}
historypath = '/nsm/strelka/history/'
strelkapath = '/nsm/strelka/unprocessed/'
logfile = '/opt/so/log/strelka/filecheck.log'