forked from wazuh/wazuh-docker
Removed Logstash
This commit is contained in:
@@ -1,12 +0,0 @@
|
|||||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
|
||||||
FROM docker.elastic.co/logstash/logstash:6.7.2
|
|
||||||
|
|
||||||
COPY --chown=logstash:logstash config/entrypoint.sh /entrypoint.sh
|
|
||||||
|
|
||||||
RUN chmod 755 /entrypoint.sh
|
|
||||||
|
|
||||||
RUN rm -f /usr/share/logstash/pipeline/logstash.conf
|
|
||||||
|
|
||||||
COPY config/01-wazuh.conf /usr/share/logstash/pipeline/01-wazuh.conf
|
|
||||||
|
|
||||||
ENTRYPOINT /entrypoint.sh
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
|
||||||
# Wazuh - Logstash configuration file
|
|
||||||
## Remote Wazuh Manager - Filebeat input
|
|
||||||
input {
|
|
||||||
beats {
|
|
||||||
port => 5000
|
|
||||||
codec => "json_lines"
|
|
||||||
# ssl => true
|
|
||||||
# ssl_certificate => "/etc/logstash/logstash.crt"
|
|
||||||
# ssl_key => "/etc/logstash/logstash.key"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
filter {
|
|
||||||
if [data][srcip] {
|
|
||||||
mutate {
|
|
||||||
add_field => [ "@src_ip", "%{[data][srcip]}" ]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if [data][aws][sourceIPAddress] {
|
|
||||||
mutate {
|
|
||||||
add_field => [ "@src_ip", "%{[data][aws][sourceIPAddress]}" ]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
filter {
|
|
||||||
geoip {
|
|
||||||
source => "@src_ip"
|
|
||||||
target => "GeoLocation"
|
|
||||||
fields => ["city_name", "country_name", "region_name", "location"]
|
|
||||||
}
|
|
||||||
date {
|
|
||||||
match => ["timestamp", "ISO8601"]
|
|
||||||
target => "@timestamp"
|
|
||||||
}
|
|
||||||
mutate {
|
|
||||||
remove_field => [ "timestamp", "beat", "input_type", "tags", "count", "@version", "log", "offset", "type", "@src_ip", "host"]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
output {
|
|
||||||
elasticsearch {
|
|
||||||
hosts => ["elasticsearch:9200"]
|
|
||||||
index => "wazuh-alerts-3.x-%{+YYYY.MM.dd}"
|
|
||||||
document_type => "wazuh"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,72 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2)
|
|
||||||
#
|
|
||||||
# OSSEC container bootstrap. See the README for information of the environment
|
|
||||||
# variables expected by this script.
|
|
||||||
#
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
##############################################################################
|
|
||||||
# Waiting for elasticsearch
|
|
||||||
##############################################################################
|
|
||||||
|
|
||||||
if [ "x${ELASTICSEARCH_URL}" = "x" ]; then
|
|
||||||
el_url="http://elasticsearch:9200"
|
|
||||||
else
|
|
||||||
el_url="${ELASTICSEARCH_URL}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
##############################################################################
|
|
||||||
# Customize logstash output ip
|
|
||||||
##############################################################################
|
|
||||||
|
|
||||||
if [ "$LOGSTASH_OUTPUT" != "" ]; then
|
|
||||||
>&2 echo "Customize Logstash ouput ip."
|
|
||||||
sed -i 's|elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/pipeline/01-wazuh.conf
|
|
||||||
sed -i 's|http://elasticsearch:9200|'$LOGSTASH_OUTPUT'|g' /usr/share/logstash/config/logstash.yml
|
|
||||||
fi
|
|
||||||
|
|
||||||
until curl -XGET $el_url; do
|
|
||||||
>&2 echo "Elastic is unavailable - sleeping."
|
|
||||||
sleep 5
|
|
||||||
done
|
|
||||||
|
|
||||||
sleep 2
|
|
||||||
|
|
||||||
>&2 echo "Elasticsearch is up."
|
|
||||||
|
|
||||||
##############################################################################
|
|
||||||
# Waiting for wazuh alerts template
|
|
||||||
##############################################################################
|
|
||||||
|
|
||||||
strlen=0
|
|
||||||
|
|
||||||
while [[ $strlen -eq 0 ]]
|
|
||||||
do
|
|
||||||
template=$(curl $el_url/_cat/templates/wazuh -s)
|
|
||||||
strlen=${#template}
|
|
||||||
>&2 echo "Wazuh alerts template not loaded - sleeping."
|
|
||||||
sleep 2
|
|
||||||
done
|
|
||||||
|
|
||||||
sleep 2
|
|
||||||
|
|
||||||
>&2 echo "Wazuh alerts template is loaded."
|
|
||||||
|
|
||||||
##############################################################################
|
|
||||||
# Map environment variables to entries in logstash.yml.
|
|
||||||
# Note that this will mutate logstash.yml in place if any such settings are found.
|
|
||||||
# This may be undesirable, especially if logstash.yml is bind-mounted from the
|
|
||||||
# host system.
|
|
||||||
##############################################################################
|
|
||||||
|
|
||||||
env2yaml /usr/share/logstash/config/logstash.yml
|
|
||||||
|
|
||||||
export LS_JAVA_OPTS="-Dls.cgroup.cpuacct.path.override=/ -Dls.cgroup.cpu.path.override=/ $LS_JAVA_OPTS"
|
|
||||||
|
|
||||||
if [[ -z $1 ]] || [[ ${1:0:1} == '-' ]] ; then
|
|
||||||
exec logstash "$@"
|
|
||||||
else
|
|
||||||
exec "$@"
|
|
||||||
fi
|
|
||||||
Reference in New Issue
Block a user