/
githubmirror
/
charts
Обзор
Документация
Войти
/
githubmirror
/
charts
Код
Запросы
0
Пакеты
0
Релизы
0
Аналитика
Безопасность
master
stable/auditbeat/values.yaml
131 строка
4 KB
Carlos Tadeu Panato Junior
bump auditbeat to 6.7.0 (#12594)
28 мар 2019, 15:44
28 мар 2019, 15:44
bfea6d7
Код
Авторство
О чём код?
image: repository: docker.elastic.co/beats/auditbeat tag: 6.7.0 pullPolicy: IfNotPresent config: auditbeat.modules: - module: auditd # keep this 0 and be more selective in auditd rules to rate-limit without dropping audit events rate_limit: 0 # maximum number of audit messages that will be buffered by the kernel backlog_limit: 8196 # See https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-auditd.html for more info audit_rules: | # Things that affect identity. -w /etc/group -p wa -k identity -w /etc/passwd -p wa -k identity -w /etc/gshadow -p wa -k identity -w /etc/shadow -p wa -k identity # Unauthorized access attempts to files (unsuccessful). -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -F key=access -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -F key=access -a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -F key=access -a always,exit -F arch=b64 -S open,truncate,ftruncate,creat,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -F key=access ## for development # failure_mode: log # include_raw_message: true # include_warnings: true - module: file_integrity paths: - /bin - /usr/bin - /sbin - /usr/sbin - /etc processors: - add_cloud_metadata: queue: {} ## Queue type by name (default 'mem') ## The memory queue will present all available events (up to the outputs ## bulk_max_size) to the output, the moment the output is ready to server ## another batch of events. # mem: ## Max number of events the queue can buffer. # events: 4096 ## Hints the minimum number of events stored in the queue, ## before providing a batch of events to the outputs. ## A value of 0 (the default) ensures events are immediately available ## to be sent to the outputs. # flush.min_events: 2048 ## Maximum duration after which events are available to the outputs, ## if the number of events stored in the queue is < min_flush_events. # flush.timeout: 1s # When a key contains a period, use this format for setting values on the command line: # --set config."output\.file".enabled=false output.file: path: "/usr/share/auditbeat/data" filename: auditbeat rotate_every_kb: 10000 number_of_files: 5 # output.elasticsearch: # hosts: ["elasticsearch:9200"] # protocol: "https" # username: "elastic" # password: "changeme" # List of beat plugins plugins: [] # - kinesis.so # Additional container arguments extraArgs: [] # - -d # - * # A map of additional environment variables extraVars: {} # test1: "test2" # Add additional volumes and mounts, for example to read other log files on the host extraVolumes: [] # - hostPath: # path: /var/log # name: varlog extraVolumeMounts: [] # - name: varlog # mountPath: /host/var/log # readOnly: true ## Labels to be added to pods podLabels: {} ## Annotations to be added to pods podAnnotations: {} resources: {} ## We usually recommend not to specify default resources and to leave this as a conscious ## choice for the user. This also increases chances charts run on environments with little ## resources, such as Minikube. If you do want to specify resources, uncomment the following ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. # limits: # cpu: 100m # memory: 200Mi # requests: # cpu: 100m # memory: 100Mi ## Node labels for pod assignment ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ nodeSelector: {} ## Affinity configuration for pod assignment ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ affinity: {} rbac: # Specifies whether RBAC resources should be created create: true serviceAccount: # Specifies whether a ServiceAccount should be created create: true # The name of the ServiceAccount to use. # If not set and create is true, a name is generated using the fullname template name: