This repository was archived by the owner on Apr 16, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 522
This repository was archived by the owner on Apr 16, 2021. It is now read-only.
Elastic Stack Release Candidate 2 #1198
Copy link
Copy link
Closed
Description
-
Elasticsearch
-
Kibana
-
Logstash
-
Curator
- add new option to
/etc/nsm/securityonion.conf
calledCURATOR_CLOSE_DAYS
and default to30
- modify
so-elastic-configure-curator
to update/etc/curator/action/close.yml
withCURATOR_CLOSE_DAYS
- remove
--dry-run
from/etc/cron.d/curator-close
- update
/etc/cron.d/curator-close
to copyCURATOR_CLOSE_DAYS
into config before runningcurator
- update
/etc/cron.d/curator-delete
to copyLOG_SIZE_LIMIT
into config before runningcurator
- update https://github.com/Security-Onion-Solutions/security-onion/wiki/Curator
- add new option to
-
ElastAlert
-
Docker
- when suspending/resuming a VM with VMware Tools installed, Docker interfaces drop and Elastic components no longer able to communicate - workaround is to remove
/etc/vmware-tools/scripts/vmware/network
- include Docker
--memory
and--memory-swap
options so that Docker enforces the limits we've already placed on Elastic - cancelled since this requires changes to grub boot loader and "Memory and swap accounting incur an overhead of about 1% of the total available memory and a 10% overall performance degradation, even if Docker is not running" - recommend disabling swap altogether in host
- when suspending/resuming a VM with VMware Tools installed, Docker interfaces drop and Elastic components no longer able to communicate - workaround is to remove
-
so-autossh-*
-
so-elastic-configure-apache
-
sosetup-elastic
- avoid configuring and starting Kibana and ElastAlert when configuring sensor-only
- avoid configuring and starting Elasticsearch and Logstash when running forward-only sensor
- avoid configuring cross cluster search when running forward-only
- remove disclaimers and warnings
- add support for storage node consuming from redis on master server
- improve user experience - start a new deployment or join an existing deployment
-
so-user-*
-
ELSA
-
update Wiki
- document data fields (including fields that are renamed and fields whose value we modify)
- add more Hardware requirements to Hardware page including SSD recommendation
Metadata
Metadata
Assignees
Labels
No labels