bump Elastic Stack to 7.16.3, change deprecated fields

This commit is contained in:
t3chn0m4g3 2022-01-20 10:32:10 +00:00
parent 3542ab728f
commit 602d1cc673
5 changed files with 23 additions and 23 deletions

View file

@ -1,7 +1,7 @@
FROM alpine:3.14 FROM alpine:3.15
# #
# VARS # VARS
ENV ES_VER=7.16.2 \ ENV ES_VER=7.16.3 \
ES_JAVA_HOME=/usr/lib/jvm/java-16-openjdk ES_JAVA_HOME=/usr/lib/jvm/java-16-openjdk
# Include dist # Include dist

View file

@ -1,7 +1,7 @@
FROM node:16.13.0-alpine3.14 FROM node:16.13.0-alpine3.14
# #
# VARS # VARS
ENV KB_VER=7.16.2 ENV KB_VER=7.16.3
# #
# Include dist # Include dist
ADD dist/ /root/dist/ ADD dist/ /root/dist/

View file

@ -1,7 +1,7 @@
FROM alpine:3.14 FROM alpine:3.15
# #
# VARS # VARS
ENV LS_VER=7.16.2 ENV LS_VER=7.16.3
# Include dist # Include dist
ADD dist/ /root/dist/ ADD dist/ /root/dist/
# #

View file

@ -221,8 +221,8 @@ filter {
} }
translate { translate {
refresh_interval => 86400 refresh_interval => 86400
field => "[alert][signature_id]" source => "[alert][signature_id]"
destination => "[alert][cve_id]" target => "[alert][cve_id]"
dictionary_path => "/etc/listbot/cve.yaml" dictionary_path => "/etc/listbot/cve.yaml"
# fallback => "-" # fallback => "-"
} }
@ -657,21 +657,21 @@ if "_jsonparsefailure" in [tags] { drop {} }
} }
# Add geo coordinates / ASN info / IP rep. # Add geo coordinates / ASN info / IP rep.
if [src_ip] { if [src_ip] {
geoip { geoip {
cache_size => 10000 cache_size => 10000
source => "src_ip" source => "src_ip"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-City.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-City.mmdb"
} }
geoip { geoip {
cache_size => 10000 cache_size => 10000
source => "src_ip" source => "src_ip"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-ASN.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-ASN.mmdb"
} }
translate { translate {
refresh_interval => 86400 refresh_interval => 86400
field => "src_ip" source => "src_ip"
destination => "ip_rep" target => "ip_rep"
dictionary_path => "/etc/listbot/iprep.yaml" dictionary_path => "/etc/listbot/iprep.yaml"
} }
} }
@ -680,13 +680,13 @@ if "_jsonparsefailure" in [tags] { drop {} }
cache_size => 10000 cache_size => 10000
source => "t-pot_ip_ext" source => "t-pot_ip_ext"
target => "geoip_ext" target => "geoip_ext"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-City.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-City.mmdb"
} }
geoip { geoip {
cache_size => 10000 cache_size => 10000
source => "t-pot_ip_ext" source => "t-pot_ip_ext"
target => "geoip_ext" target => "geoip_ext"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-ASN.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-ASN.mmdb"
} }
} }

View file

@ -221,8 +221,8 @@ filter {
} }
translate { translate {
refresh_interval => 86400 refresh_interval => 86400
field => "[alert][signature_id]" source => "[alert][signature_id]"
destination => "[alert][cve_id]" target => "[alert][cve_id]"
dictionary_path => "/etc/listbot/cve.yaml" dictionary_path => "/etc/listbot/cve.yaml"
# fallback => "-" # fallback => "-"
} }
@ -657,21 +657,21 @@ if "_jsonparsefailure" in [tags] { drop {} }
} }
# Add geo coordinates / ASN info / IP rep. # Add geo coordinates / ASN info / IP rep.
if [src_ip] { if [src_ip] {
geoip { geoip {
cache_size => 10000 cache_size => 10000
source => "src_ip" source => "src_ip"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-City.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-City.mmdb"
} }
geoip { geoip {
cache_size => 10000 cache_size => 10000
source => "src_ip" source => "src_ip"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-ASN.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-ASN.mmdb"
} }
translate { translate {
refresh_interval => 86400 refresh_interval => 86400
field => "src_ip" source => "src_ip"
destination => "ip_rep" target => "ip_rep"
dictionary_path => "/etc/listbot/iprep.yaml" dictionary_path => "/etc/listbot/iprep.yaml"
} }
} }
@ -680,13 +680,13 @@ if "_jsonparsefailure" in [tags] { drop {} }
cache_size => 10000 cache_size => 10000
source => "t-pot_ip_ext" source => "t-pot_ip_ext"
target => "geoip_ext" target => "geoip_ext"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-City.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-City.mmdb"
} }
geoip { geoip {
cache_size => 10000 cache_size => 10000
source => "t-pot_ip_ext" source => "t-pot_ip_ext"
target => "geoip_ext" target => "geoip_ext"
database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.8-java/vendor/GeoLite2-ASN.mmdb" database => "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-geoip-7.2.9-java/vendor/GeoLite2-ASN.mmdb"
} }
} }