| # Licensed to the Apache Software Foundation (ASF) under one |
| # or more contributor license agreements. See the NOTICE file |
| # distributed with this work for additional information |
| # regarding copyright ownership. The ASF licenses this file |
| # to you under the Apache License, Version 2.0 (the |
| # "License"); you may not use this file except in compliance |
| # with the License. You may obtain a copy of the License at |
| # |
| # http://www.apache.org/licenses/LICENSE-2.0 |
| # |
| # Unless required by applicable law or agreed to in writing, software |
| # distributed under the License is distributed on an "AS IS" BASIS, |
| # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| # See the License for the specific language governing permissions and |
| # limitations under the License. |
| |
| ##### Storm ##### |
| enrichment.workers=1 |
| enrichment.acker.executors=0 |
| topology.worker.childopts= |
| topology.auto-credentials= |
| topology.max.spout.pending=500 |
| |
| ##### Kafka ##### |
| kafka.zk=node1:2181 |
| kafka.broker=node1:6667 |
| kafka.security.protocol=PLAINTEXT |
| |
| # One of EARLIEST, LATEST, UNCOMMITTED_EARLIEST, UNCOMMITTED_LATEST |
| kafka.start=UNCOMMITTED_EARLIEST |
| |
| enrichment.input.topic=enrichments |
| enrichment.output.topic=indexing |
| enrichment.error.topic=indexing |
| threat.intel.error.topic=indexing |
| |
| ##### JoinBolt ##### |
| enrichment.join.cache.size=100000 |
| threat.intel.join.cache.size=100000 |
| |
| ##### Enrichment ##### |
| hbase.provider.impl=org.apache.metron.hbase.HTableProvider |
| enrichment.simple.hbase.table=enrichment |
| enrichment.simple.hbase.cf=t |
| enrichment.host.known_hosts=[{"ip":"10.1.128.236", "local":"YES", "type":"webserver", "asset_value" : "important"},\ |
| {"ip":"10.1.128.237", "local":"UNKNOWN", "type":"unknown", "asset_value" : "important"},\ |
| {"ip":"10.60.10.254", "local":"YES", "type":"printer", "asset_value" : "important"}] |
| |
| ##### Threat Intel ##### |
| threat.intel.tracker.table=access_tracker |
| threat.intel.tracker.cf=t |
| threat.intel.simple.hbase.table=threatintel |
| threat.intel.simple.hbase.cf=t |
| |
| ##### Parallelism ##### |
| kafka.spout.parallelism=1 |
| enrichment.split.parallelism=1 |
| enrichment.stellar.parallelism=1 |
| enrichment.join.parallelism=1 |
| threat.intel.split.parallelism=1 |
| threat.intel.stellar.parallelism=1 |
| threat.intel.join.parallelism=1 |
| kafka.writer.parallelism=1 |