Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 521 forks source link

securityonion-elastic: migrate script.* settings from elasticsearch.yml.bak to elasticsearch.yml #1676

Closed dougburks closed 4 years ago

dougburks commented 4 years ago

Jim Hranicky asked about retaining the following setting in /etc/elasticsearch/elasticsearch.yml when updating via soup:

script.painless.regex.enabled: true

We currently migrate other common settings from elasticsearch.yml.bak to elasticsearch.yml here: https://github.com/Security-Onion-Solutions/securityonion-elastic/blob/master/usr/sbin/so-elastic-configure-stack#L73-L98

So we should be able to do something similar for script.*:

grep "^script.*:" $ES_YAML_BAK >> $ES_YAML
dougburks commented 4 years ago

https://github.com/Security-Onion-Solutions/securityonion-elastic/commit/6f2384f223b32d39721f8fec84dcfda74e44425b

weslambert commented 4 years ago

Confirmed setting gets migrated from backed up file to new file. 👍

dougburks commented 4 years ago

Published: https://blog.securityonion.net/2020/02/zeek-301-elastic-686-and-cyberchef-9120.html