-
Notifications
You must be signed in to change notification settings - Fork 415
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Improvements to Kibana settings added (#91)
- Loading branch information
1 parent
f3cc91f
commit ffe3dde
Showing
5 changed files
with
60 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -21,4 +21,6 @@ done | |
|
||
sleep 5 | ||
|
||
./kibana_settings.sh & | ||
|
||
/usr/local/bin/kibana-docker |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,50 @@ | ||
#!/bin/bash | ||
# Wazuh App Copyright (C) 2019 Wazuh Inc. (License GPLv2) | ||
|
||
|
||
WAZUH_MAJOR=3 | ||
|
||
############################################################################## | ||
# Wait for the Kibana API to start. It is necessary to do it in this container | ||
# because the others are running Elastic Stack and we can not interrupt them. | ||
# | ||
# The following actions are performed: | ||
# | ||
# Add the wazuh alerts index as default. | ||
# Set the Discover time interval to 24 hours instead of 15 minutes. | ||
# Do not ask user to help providing usage statistics to Elastic. | ||
############################################################################## | ||
|
||
while [[ "$(curl -XGET -I -s -o /dev/null -w ''%{http_code}'' kibana:5601/status)" != "200" ]]; do | ||
echo "Waiting for Kibana API. Sleeping 5 seconds" | ||
sleep 5 | ||
done | ||
|
||
# Prepare index selection. | ||
echo "Kibana API is running" | ||
|
||
default_index="/tmp/default_index.json" | ||
|
||
cat > ${default_index} << EOF | ||
{ | ||
"changes": { | ||
"defaultIndex": "wazuh-alerts-${WAZUH_MAJOR}.x-*" | ||
} | ||
} | ||
EOF | ||
|
||
sleep 5 | ||
# Add the wazuh alerts index as default. | ||
curl -POST "http://kibana:5601/api/kibana/settings" -H "Content-Type: application/json" -H "kbn-xsrf: true" -d@${default_index} | ||
rm -f ${default_index} | ||
|
||
sleep 5 | ||
# Configuring Kibana TimePicker. | ||
curl -POST "http://kibana:5601/api/kibana/settings" -H "Content-Type: application/json" -H "kbn-xsrf: true" -d \ | ||
'{"changes":{"timepicker:timeDefaults":"{\n \"from\": \"now-24h\",\n \"to\": \"now\",\n \"mode\": \"quick\"}"}}' | ||
|
||
sleep 5 | ||
# Do not ask user to help providing usage statistics to Elastic | ||
curl -POST "http://kibana:5601/api/telemetry/v1/optIn" -H "Content-Type: application/json" -H "kbn-xsrf: true" -d '{"enabled":false}' | ||
|
||
echo "End settings" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters