Skip to content
This repository was archived by the owner on Jan 10, 2025. It is now read-only.

Commit 0ffc0af

Browse files
authored
Merge pull request #276 from elastic/rwaight-patch-1
SIEM-at-Home example updates
2 parents d579207 + 3f3cdf4 commit 0ffc0af

File tree

2 files changed

+46
-5
lines changed

2 files changed

+46
-5
lines changed

Security Analytics/SIEM-at-Home/beats-configs/beats-general-config.yml

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,14 @@ name: myHostName
44
tags: ["myTag", "myHostName"]
55
fields:
66
env: myEnv
7-
version: 11-13-2019
7+
version: 11-26-2019
88

99
#========================== Top Level Processor ===============================
1010
processors:
1111
- add_host_metadata:
12-
# netinfo.enabled should be set to `false` in packetbeat until GitHub
13-
# issue https://github.com/elastic/elasticsearch/issues/46193 is closed
14-
netinfo.enabled: true
12+
# netinfo.enabled should be set to `false` until GitHub issue
13+
# https://github.com/elastic/elasticsearch/issues/46193 is resolved
14+
netinfo.enabled: false
1515
Geo: # These Geo configurations are optional
1616
location: 40.7128, -74.0060
1717
continent_name: North America
@@ -58,7 +58,9 @@ cloud.auth: "data_shipper:0987654321abcDEF"
5858

5959
# The geoip-info pipeline is used to enrich GeoIP information in Elasticsearch
6060
# You must configure the pipeline in Elasticsearch before enabling the pipeline in Beats.
61-
output.elasticsearch.pipeline: geoip-info
61+
# The `output.elasticsearch.pipeline: geoip-info` setting should be commented out until
62+
# until GitHub issue https://github.com/elastic/elasticsearch/issues/46193 is resolved
63+
#output.elasticsearch.pipeline: geoip-info
6264

6365
# The `max_retries` setting is the number of times to retry publishing an event after
6466
# a publishing failure. After the specified number of retries, the events are typically dropped.
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
# Example for the Beats on Windows blog
2+
# Configuration version: 11-25-2019
3+
#=== Winlogbeat specific options ===
4+
winlogbeat.event_logs:
5+
- name: Application
6+
ignore_older: 72h
7+
8+
- name: System
9+
10+
- name: Security
11+
ignore_older: 24h
12+
processors:
13+
- drop_event.when.and: # drop local service login events
14+
- equals.event.code: '4672'
15+
- equals.winlog.event_data.SubjectUserName: 'LOCAL SERVICE'
16+
- script:
17+
lang: javascript
18+
id: security
19+
file: ${path.home}/module/security/config/winlogbeat-security.js
20+
21+
- name: Windows PowerShell
22+
ignore_older: 72h
23+
24+
- name: Microsoft-Windows-PowerShell/Operational
25+
ignore_older: 72h
26+
event_id: 4103, 4104
27+
28+
- name: Microsoft-Windows-Sysmon/Operational
29+
ignore_older: 24h
30+
processors:
31+
- script:
32+
lang: javascript
33+
id: sysmon
34+
file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js
35+
36+
#=== Beats Common Configs Here ===
37+
# Add the settings from the Beats General Config file (beats-general-config.yml)
38+
# to the end of this configuration file. The Beats General Config file example can be found at this link:
39+
# https://github.com/elastic/examples/blob/master/Security%20Analytics/SIEM-at-Home/beats-configs/beats-general-config.yml

0 commit comments

Comments
 (0)