Closed dougburks closed 6 years ago
[x] Elasticsearch
jvm.options
dynamic mapping
false
[x] Logstash
redis
/etc/logstash/conf.d/
./logstash-template.json
pipeline.workers: 1
[x] Kibana
so-elastic-configure-kibana-config
hostname
Sysmon - Event Type Visualization
Event ID
[x] CapMe
uid
[x] ElastAlert
flatline
new_term
change
[x] elasticdownload.conf
[x] so-*
so-COMPONENT-VERB
so-logstash-restart
[x] so-elastic-status
[x] so-import-pcap
[x] sosetup-elastic
skip_unavailable: true
[x] so-crossclustercheck
_cluster/settings
submitted for testing: https://groups.google.com/d/topic/security-onion-testing/WU5Sj88nF6s/discussion
Published: https://blog.securityonion.net/2018/03/elastic-623-and-securityonion-elastic.html
[x] Elasticsearch
jvm.options
for setting heap sizedynamic mapping
tofalse
- commit[x] Logstash
redis
files so we can avoid overwriting on package upgrades/etc/logstash/conf.d/
without them being re-enabled./logstash-template.json
(remove the dot)pipeline.workers: 1
so that logstash can set workers automaticallyjvm.options
for setting heap size[x] Kibana
so-elastic-configure-kibana-config
should lower casehostname
when setting seedsSysmon - Event Type Visualization
should be changed toEvent ID
[x] CapMe
uid
is an array[x] ElastAlert
flatline
rulenew_term
rulechange
rule[x] elasticdownload.conf
[x] so-*
so-COMPONENT-VERB
control scripts (example:so-logstash-restart
)[x] so-elastic-status
[x] so-import-pcap
[x] sosetup-elastic
skip_unavailable: true
[x] so-crossclustercheck
_cluster/settings
since we're now usingskip_unavailable: true