From aa04ebad90e2e571d9389fd38adec3134b32b2df Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:04:21 -0300 Subject: [PATCH 01/12] roles/opendistro-elasticsearch: remove unused variables --- roles/opendistro/opendistro-elasticsearch/defaults/main.yml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/roles/opendistro/opendistro-elasticsearch/defaults/main.yml b/roles/opendistro/opendistro-elasticsearch/defaults/main.yml index 22709024..9d624025 100644 --- a/roles/opendistro/opendistro-elasticsearch/defaults/main.yml +++ b/roles/opendistro/opendistro-elasticsearch/defaults/main.yml @@ -1,8 +1,5 @@ --- # Cluster Settings -es_version: "7.9.1" -es_major_version: "7.x" - opendistro_version: 1.10.1 single_node: false @@ -44,7 +41,6 @@ es_nodes: |- {%- endfor %} # Security password -opendistro_security_password: admin opendistro_custom_user: "" opendistro_custom_user_role: "admin" From fad82ba7d171e609501c9d3e00d55de59a74fbfc Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:04:31 -0300 Subject: [PATCH 02/12] roles/opendistro-kibana: remove unused variables --- roles/opendistro/opendistro-kibana/defaults/main.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/roles/opendistro/opendistro-kibana/defaults/main.yml b/roles/opendistro/opendistro-kibana/defaults/main.yml index 2974bf3d..464302aa 100644 --- a/roles/opendistro/opendistro-kibana/defaults/main.yml +++ b/roles/opendistro/opendistro-kibana/defaults/main.yml @@ -44,7 +44,6 @@ kibana_newsfeed_enabled: "false" kibana_telemetry_optin: "false" kibana_telemetry_enabled: "false" -opendistro_security_user: elastic opendistro_admin_password: changeme opendistro_kibana_user: kibanaserver opendistro_kibana_password: changeme From e90ddb73e6d05a70a0570bf3761f0dc3d2740c59 Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:05:38 -0300 Subject: [PATCH 03/12] roles/filebeat-oss: remove unused variables --- roles/wazuh/ansible-filebeat-oss/README.md | 1 - roles/wazuh/ansible-filebeat-oss/defaults/main.yml | 3 --- 2 files changed, 4 deletions(-) diff --git a/roles/wazuh/ansible-filebeat-oss/README.md b/roles/wazuh/ansible-filebeat-oss/README.md index bed47531..02311817 100644 --- a/roles/wazuh/ansible-filebeat-oss/README.md +++ b/roles/wazuh/ansible-filebeat-oss/README.md @@ -19,7 +19,6 @@ Role Variables Available variables are listed below, along with default values (see `defaults/main.yml`): ``` - filebeat_output_elasticsearch_enabled: false filebeat_output_elasticsearch_hosts: - "localhost:9200" diff --git a/roles/wazuh/ansible-filebeat-oss/defaults/main.yml b/roles/wazuh/ansible-filebeat-oss/defaults/main.yml index ace9077f..44c8465e 100644 --- a/roles/wazuh/ansible-filebeat-oss/defaults/main.yml +++ b/roles/wazuh/ansible-filebeat-oss/defaults/main.yml @@ -3,9 +3,6 @@ filebeat_version: 7.9.1 wazuh_template_branch: v4.0.0 -filebeat_create_config: true - -filebeat_output_elasticsearch_enabled: false filebeat_output_elasticsearch_hosts: - "localhost:9200" From eb5e74bb0217e01003bb00d31a3cf342fa34d208 Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:06:42 -0300 Subject: [PATCH 04/12] roles/filebeat: remove unused variables --- roles/wazuh/ansible-filebeat/README.md | 1 - roles/wazuh/ansible-filebeat/defaults/main.yml | 18 +----------------- 2 files changed, 1 insertion(+), 18 deletions(-) diff --git a/roles/wazuh/ansible-filebeat/README.md b/roles/wazuh/ansible-filebeat/README.md index 416f7da0..3bbc2b32 100644 --- a/roles/wazuh/ansible-filebeat/README.md +++ b/roles/wazuh/ansible-filebeat/README.md @@ -19,7 +19,6 @@ Role Variables Available variables are listed below, along with default values (see `defaults/main.yml`): ``` - filebeat_output_elasticsearch_enabled: false filebeat_output_elasticsearch_hosts: - "localhost:9200" diff --git a/roles/wazuh/ansible-filebeat/defaults/main.yml b/roles/wazuh/ansible-filebeat/defaults/main.yml index f2c02a48..db70ffe1 100644 --- a/roles/wazuh/ansible-filebeat/defaults/main.yml +++ b/roles/wazuh/ansible-filebeat/defaults/main.yml @@ -5,28 +5,12 @@ wazuh_template_branch: v4.0.0 filebeat_create_config: true -filebeat_prospectors: - - input_type: log - paths: - - "/var/ossec/logs/alerts/alerts.json" - document_type: json - json.message_key: log - json.keys_under_root: true - json.overwrite_keys: true - filebeat_node_name: node-1 -filebeat_output_elasticsearch_enabled: false filebeat_output_elasticsearch_hosts: - "localhost:9200" -filebeat_enable_logging: true -filebeat_log_level: debug -filebeat_log_dir: /var/log/mybeat -filebeat_log_filename: mybeat.log filebeat_ssl_dir: /etc/pki/filebeat -filebeat_ssl_certificate_file: "" -filebeat_ssl_insecure: "false" filebeat_module_package_url: https://packages.wazuh.com/4.x/filebeat filebeat_module_package_name: wazuh-filebeat-0.1.tar.gz @@ -40,7 +24,7 @@ filebeat_xpack_security: false elasticsearch_xpack_security_user: elastic elasticsearch_xpack_security_password: elastic_pass -node_certs_generator : false +node_certs_generator: false node_certs_source: /usr/share/elasticsearch node_certs_destination: /etc/filebeat/certs From b928bc81fe324eb29e1c5ed90312987f1d1d8e4c Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:23:39 -0300 Subject: [PATCH 05/12] roles/opendistro-elasticsearch: remove unused variable elasticrepo --- roles/opendistro/opendistro-elasticsearch/defaults/main.yml | 5 ----- 1 file changed, 5 deletions(-) diff --git a/roles/opendistro/opendistro-elasticsearch/defaults/main.yml b/roles/opendistro/opendistro-elasticsearch/defaults/main.yml index 9d624025..7476410d 100644 --- a/roles/opendistro/opendistro-elasticsearch/defaults/main.yml +++ b/roles/opendistro/opendistro-elasticsearch/defaults/main.yml @@ -54,11 +54,6 @@ certs_gen_tool_version: 1.8 # Url of Search Guard certificates generator tool certs_gen_tool_url: "https://search.maven.org/remotecontent?filepath=com/floragunn/search-guard-tlstool/{{ certs_gen_tool_version }}/search-guard-tlstool-{{ certs_gen_tool_version }}.zip" -elasticrepo: - apt: 'https://artifacts.elastic.co/packages/7.x/apt' - yum: 'https://artifacts.elastic.co/packages/7.x/yum' - gpg: 'https://artifacts.elastic.co/GPG-KEY-opendistro' - key_id: '46095ACC8548582C1A2699A9D27D666CD88E42B4' opendistro_admin_password: changeme opendistro_kibana_password: changeme From 200efb981c66b5d9399cbb15e917c8f908896a8f Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:24:11 -0300 Subject: [PATCH 06/12] roles/opendistro-kibana: remove unused variable elasticsearch_nodes --- roles/opendistro/opendistro-kibana/defaults/main.yml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/roles/opendistro/opendistro-kibana/defaults/main.yml b/roles/opendistro/opendistro-kibana/defaults/main.yml index 464302aa..170e72b5 100644 --- a/roles/opendistro/opendistro-kibana/defaults/main.yml +++ b/roles/opendistro/opendistro-kibana/defaults/main.yml @@ -2,10 +2,6 @@ # Kibana configuration elasticsearch_http_port: 9200 -elasticsearch_nodes: |- - {% for item in groups['es_cluster'] -%} - {{ hostvars[item]['ip'] }}{% if not loop.last %}","{% endif %} - {%- endfor %} elastic_api_protocol: https kibana_conf_path: /etc/kibana kibana_node_name: node-1 From 04e242e2071c303cf083966140a64ab2f1beb647 Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:24:52 -0300 Subject: [PATCH 07/12] roles/filebeat-oss: remove unused variables filebeat_security_user and filebeat_security_password --- roles/wazuh/ansible-filebeat-oss/defaults/main.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/roles/wazuh/ansible-filebeat-oss/defaults/main.yml b/roles/wazuh/ansible-filebeat-oss/defaults/main.yml index 44c8465e..e77112c8 100644 --- a/roles/wazuh/ansible-filebeat-oss/defaults/main.yml +++ b/roles/wazuh/ansible-filebeat-oss/defaults/main.yml @@ -15,8 +15,6 @@ elasticsearch_security_user: admin elasticsearch_security_password: changeme # Security plugin filebeat_security: true -filebeat_security_user: admin -filebeat_security_password: changeme filebeat_ssl_dir: /etc/pki/filebeat # Local path to store the generated certificates (OpenDistro security plugin) From 1d93181625a2bb80b7b74491d32003aeb7c00326 Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:25:41 -0300 Subject: [PATCH 08/12] roles/filebeat: remove unused variables node_certs_generator and node_certs_source --- roles/wazuh/ansible-filebeat/defaults/main.yml | 3 --- 1 file changed, 3 deletions(-) diff --git a/roles/wazuh/ansible-filebeat/defaults/main.yml b/roles/wazuh/ansible-filebeat/defaults/main.yml index db70ffe1..9369e7b7 100644 --- a/roles/wazuh/ansible-filebeat/defaults/main.yml +++ b/roles/wazuh/ansible-filebeat/defaults/main.yml @@ -24,11 +24,8 @@ filebeat_xpack_security: false elasticsearch_xpack_security_user: elastic elasticsearch_xpack_security_password: elastic_pass -node_certs_generator: false -node_certs_source: /usr/share/elasticsearch node_certs_destination: /etc/filebeat/certs - # CA Generation master_certs_path: "{{ playbook_dir }}/es_certs" generate_CA: true From 1511649944a95b930f414ec20a1b9d6f7746ab49 Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:52:29 -0300 Subject: [PATCH 09/12] roles/elasticsearch: remove unused variable elasticsearch_xpack_security_user --- roles/elastic-stack/ansible-elasticsearch/defaults/main.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/roles/elastic-stack/ansible-elasticsearch/defaults/main.yml b/roles/elastic-stack/ansible-elasticsearch/defaults/main.yml index 5a638104..3556489d 100644 --- a/roles/elastic-stack/ansible-elasticsearch/defaults/main.yml +++ b/roles/elastic-stack/ansible-elasticsearch/defaults/main.yml @@ -27,9 +27,8 @@ elasticsearch_discovery_nodes: elasticsearch_node_data: true elasticsearch_node_ingest: true -# X-Pack Security +# X-Pack Security elasticsearch_xpack_security: false -elasticsearch_xpack_security_user: elastic elasticsearch_xpack_security_password: elastic_pass node_certs_generator: false From e466b3c35e3f1ce328adeca5d467b6f57766e8db Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:52:58 -0300 Subject: [PATCH 10/12] roles/kibana: remove unused variables node_certs_generator and node_certs_source --- roles/elastic-stack/ansible-kibana/defaults/main.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/roles/elastic-stack/ansible-kibana/defaults/main.yml b/roles/elastic-stack/ansible-kibana/defaults/main.yml index 35bae043..014910d7 100644 --- a/roles/elastic-stack/ansible-kibana/defaults/main.yml +++ b/roles/elastic-stack/ansible-kibana/defaults/main.yml @@ -31,8 +31,6 @@ kibana_ssl_verification_mode: "full" elasticsearch_xpack_security_user: elastic elasticsearch_xpack_security_password: elastic_pass -node_certs_generator: false -node_certs_source: /usr/share/elasticsearch node_certs_destination: /etc/kibana/certs # CA Generation From f5f80aa588b206781bd3fb927f85b96ea8fd7b6a Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:53:21 -0300 Subject: [PATCH 11/12] roles/opendistro-elasticsearch: remove unused variable es_nodes --- roles/opendistro/opendistro-elasticsearch/defaults/main.yml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/roles/opendistro/opendistro-elasticsearch/defaults/main.yml b/roles/opendistro/opendistro-elasticsearch/defaults/main.yml index 7476410d..cfe22df8 100644 --- a/roles/opendistro/opendistro-elasticsearch/defaults/main.yml +++ b/roles/opendistro/opendistro-elasticsearch/defaults/main.yml @@ -35,10 +35,6 @@ package_repos: opendistro_sec_plugin_conf_path: /usr/share/elasticsearch/plugins/opendistro_security/securityconfig opendistro_sec_plugin_tools_path: /usr/share/elasticsearch/plugins/opendistro_security/tools opendistro_conf_path: /etc/elasticsearch/ -es_nodes: |- - {% for item in groups['es_cluster'] -%} - {{ hostvars[item]['ip'] }}{% if not loop.last %}","{% endif %} - {%- endfor %} # Security password opendistro_custom_user: "" From 36e235c877f5b3551b7d3489c418c8e7de7526a0 Mon Sep 17 00:00:00 2001 From: neonmei Date: Tue, 10 Nov 2020 15:53:43 -0300 Subject: [PATCH 12/12] roles/filebeat: remove unused variable filebeat_ssl_dir --- roles/wazuh/ansible-filebeat/defaults/main.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/roles/wazuh/ansible-filebeat/defaults/main.yml b/roles/wazuh/ansible-filebeat/defaults/main.yml index 9369e7b7..99dd3358 100644 --- a/roles/wazuh/ansible-filebeat/defaults/main.yml +++ b/roles/wazuh/ansible-filebeat/defaults/main.yml @@ -10,8 +10,6 @@ filebeat_node_name: node-1 filebeat_output_elasticsearch_hosts: - "localhost:9200" -filebeat_ssl_dir: /etc/pki/filebeat - filebeat_module_package_url: https://packages.wazuh.com/4.x/filebeat filebeat_module_package_name: wazuh-filebeat-0.1.tar.gz filebeat_module_package_path: /tmp/