This repository was archived by the owner on Apr 16, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 522
This repository was archived by the owner on Apr 16, 2021. It is now read-only.
securityonion-elastic: RC4 #1219
Copy link
Copy link
Closed
Description
-
Elasticsearch
-
Logstash
- Logstash 6.2.3
- don't automatically install
redis
files so we can avoid overwriting on package upgrades - allow users to disable individual files in
/etc/logstash/conf.d/
without them being re-enabled - remove NIDS rule lookup to avoid performance hit
- some outputs have template references like
./logstash-template.json
(remove the dot) - heap size should be 25% of RAM up to 4GB
- comment out
pipeline.workers: 1
so that logstash can set workers automatically - use default logstash.yml and set path.config, http.host, and path.logs
- move to
jvm.options
for setting heap size - fix kerberos client_cert_subject
- fix RADIUS parser
- fix OSSEC sysmon parser
- fix pfsense parser
-
Kibana
-
CapMe
-
ElastAlert
-
elasticdownload.conf
-
so-*
-
so-elastic-status
-
so-import-pcap
-
sosetup-elastic
-
so-crossclustercheck
Metadata
Metadata
Assignees
Labels
No labels