133 lines
3.1 KiB
YAML
133 lines
3.1 KiB
YAML
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: netflow-ilm-policy
|
|
namespace: elastic
|
|
labels:
|
|
app.kubernetes.io/name: netflow
|
|
app.kubernetes.io/part-of: elastic-stack
|
|
data:
|
|
policy.json: |
|
|
{
|
|
"policy": {
|
|
"phases": {
|
|
"hot": {
|
|
"actions": {
|
|
"rollover": {
|
|
"max_age": "1d",
|
|
"max_primary_shard_size": "30gb"
|
|
}
|
|
}
|
|
},
|
|
"delete": {
|
|
"min_age": "30d",
|
|
"actions": {
|
|
"delete": {}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
---
|
|
apiVersion: beat.k8s.elastic.co/v1beta1
|
|
kind: Beat
|
|
metadata:
|
|
name: netflow
|
|
namespace: elastic
|
|
labels:
|
|
app.kubernetes.io/name: netflow
|
|
app.kubernetes.io/part-of: elastic-stack
|
|
spec:
|
|
type: filebeat
|
|
version: 9.5.2
|
|
image: docker.elastic.co/beats/filebeat-wolfi:9.5.2
|
|
elasticsearchRef:
|
|
name: elasticsearch
|
|
kibanaRef:
|
|
name: kibana
|
|
config:
|
|
filebeat.modules:
|
|
- module: netflow
|
|
log:
|
|
enabled: true
|
|
var:
|
|
netflow_host: 0.0.0.0
|
|
netflow_port: 2055
|
|
expiration_timeout: 30m
|
|
queue_size: 32768
|
|
internal_networks:
|
|
- private
|
|
processors:
|
|
- add_fields:
|
|
target: observer
|
|
fields:
|
|
name: newgw
|
|
vendor: MikroTik
|
|
product: RouterOS
|
|
type: firewall
|
|
setup.dashboards.enabled: true
|
|
setup.dashboards.retry.enabled: true
|
|
setup.dashboards.retry.interval: 10s
|
|
setup.dashboards.retry.maximum: 0
|
|
setup.ilm.enabled: true
|
|
setup.ilm.policy_name: netflow-30d
|
|
setup.ilm.policy_file: /usr/share/filebeat/ilm/policy.json
|
|
setup.ilm.overwrite: true
|
|
queue.mem.events: 16384
|
|
queue.mem.flush.min_events: 1024
|
|
queue.mem.flush.timeout: 1s
|
|
max_procs: 2
|
|
logging.level: info
|
|
deployment:
|
|
podTemplate:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: netflow
|
|
app.kubernetes.io/part-of: elastic-stack
|
|
spec:
|
|
terminationGracePeriodSeconds: 60
|
|
containers:
|
|
- name: filebeat
|
|
securityContext:
|
|
runAsUser: 0
|
|
ports:
|
|
- name: netflow
|
|
containerPort: 2055
|
|
protocol: UDP
|
|
resources:
|
|
requests:
|
|
cpu: 500m
|
|
memory: 1Gi
|
|
limits:
|
|
cpu: "2"
|
|
memory: 2Gi
|
|
volumeMounts:
|
|
- name: ilm-policy
|
|
mountPath: /usr/share/filebeat/ilm
|
|
readOnly: true
|
|
volumes:
|
|
- name: ilm-policy
|
|
configMap:
|
|
name: netflow-ilm-policy
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: netflow
|
|
namespace: elastic
|
|
labels:
|
|
app.kubernetes.io/name: netflow
|
|
app.kubernetes.io/part-of: elastic-stack
|
|
annotations:
|
|
metallb.io/loadBalancerIPs: "192.168.0.20"
|
|
spec:
|
|
type: LoadBalancer
|
|
externalTrafficPolicy: Local
|
|
selector:
|
|
beat.k8s.elastic.co/name: netflow
|
|
ports:
|
|
- name: netflow
|
|
port: 2055
|
|
targetPort: netflow
|
|
protocol: UDP
|