Allow rule exclusions #44

This commit is contained in:
Bob Vincent 2018-07-25 11:35:12 -04:00
parent 956b56b82b
commit 09620d3af6
2 changed files with 7 additions and 1 deletions

View File

@ -167,6 +167,8 @@ wazuh_manager_config:
executable: 'route-null.cmd'
expect: 'srcip'
timeout_allowed: 'yes'
rule_exclude:
- '0215-policy_rules.xml'
active_responses:
- command: 'restart-ossec'
location: 'local'

View File

@ -307,7 +307,11 @@
<!-- Default ruleset -->
<decoder_dir>ruleset/decoders</decoder_dir>
<rule_dir>ruleset/rules</rule_dir>
<rule_exclude>0215-policy_rules.xml</rule_exclude>
{% if wazuh_manager_config.rule_exclude is defined %}
{% for rule in wazuh_manager_config.rule_exclude %}
<rule_exclude>{{ rule }}</rule_exclude>
{% endfor %}
{% endif %}
{% if cdb_lists is defined %}
{% for list in cdb_lists %}
<list>etc/lists/{{ list.name }}</list>