--- /dev/null
+-----BEGIN CERTIFICATE-----
+MIIDoTCCAomgAwIBAgIJAOWS1wQ8fa1RMA0GCSqGSIb3DQEBCwUAMGcxCzAJBgNV
+BAYTAkdCMRUwEwYDVQQHDAxEZWZhdWx0IENpdHkxHDAaBgNVBAoME0RlZmF1bHQg
+Q29tcGFueSBMdGQxIzAhBgNVBAMMGmxvZ3N0YXNoLm9wZW5zdHJlZXRtYXAub3Jn
+MB4XDTE1MDgyODA3NDYzNloXDTI1MDgyNTA3NDYzNlowZzELMAkGA1UEBhMCR0Ix
+FTATBgNVBAcMDERlZmF1bHQgQ2l0eTEcMBoGA1UECgwTRGVmYXVsdCBDb21wYW55
+IEx0ZDEjMCEGA1UEAwwabG9nc3Rhc2gub3BlbnN0cmVldG1hcC5vcmcwggEiMA0G
+CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCxU5CoykubpFaYdJMJOGFmq8a3bMLx
+KG9wlkDfYH65fxh8W+XAHR0oyi3kwqy9P1OmicdMJkFRpFsIDmg0EuirZCX2A4nw
+ADJxXa/mqbFTNCHmVjhFqMdAaMW/O0WkcXxLc/9D/WLFEqTNMkZwZ1wo6JwAo26f
+Dxn75TggFy0rTBYsOp87nK3fYEp8cY43tGWkqMbTdU2GB511+FeUbm7NTyQakHq8
+9/LtmJPzmsO30wJzF++NOJkis/xNTvPPybkljwSshoo53ed/kmxy/KiVgPqD/fR7
+8bkOfqknycyqV5zskMUtrN9PsWQx3bzY7dhYo1nNMd8oNLVKpSluvga5AgMBAAGj
+UDBOMB0GA1UdDgQWBBS5qcKaMediosEUc6SHDGgTfGnpRzAfBgNVHSMEGDAWgBS5
+qcKaMediosEUc6SHDGgTfGnpRzAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUA
+A4IBAQA1G0BJ6rxyyuvY4iLtyah0p7hawt7jkQ35Y6gNoGGwHgMGslQ8URhx29zr
+HpJPtCdrHagC58FmL74/SS8czNdt+V3xcYAAZxm3ZwlJr/GyxSlCD/3zpD/eWHTV
+lMFqvGqLGxJfo9Q1iuyV35jEfi84toXT+zps/4voX6fYutNaouQDk5V/up9lPPCp
+x2xq0vVDV+BhZ3Y7QxsZHEcAqPg9wGMT4UiJFSsatwnmSwSv429tdZeETEb3yCZv
+kautRvtRRMB2QqNQRFGXmJLt4sMFuAjo5jcz4GvBWZTjPOoFrgnhlmWkCvqWrxJU
+/CA3EQf+gGw2loeKZrxbKXdSuIPs
+-----END CERTIFICATE-----
notifies :restart, "service[logstash]"
end
+cookbook_file "/var/lib/logstash/beats.crt" do
+ source "beats.crt"
+ user "root"
+ group "logstash"
+ mode 0o644
+ notifies :restart, "service[logstash]"
+end
+
+file "/var/lib/logstash/beats.key" do
+ content keys["beats"].join("\n")
+ user "root"
+ group "logstash"
+ mode 0o640
+ notifies :restart, "service[logstash]"
+end
+
template "/etc/logstash/conf.d/chef.conf" do
source "logstash.conf.erb"
user "root"
dest_ports "5043"
source_ports "1024:"
end
+
+ firewall_rule "accept-beats-#{forwarder}" do
+ action :accept
+ family interface[:family]
+ source "#{interface[:zone]}:#{interface[:address]}"
+ dest "fw"
+ proto "tcp:syn"
+ dest_ports "5044"
+ source_ports "1024:"
+ end
end
end
dest_ports "5043"
source_ports "1024:"
end
+
+ firewall_rule "accept-beats-#{gateway}" do
+ action :accept
+ family interface[:family]
+ source "#{interface[:zone]}:#{interface[:address]}"
+ dest "fw"
+ proto "tcp:syn"
+ dest_ports "5044"
+ source_ports "1024:"
+ end
end
end