Skip to content

Fix/auto state apply local salt files - #41

Merged
dougburks merged 2 commits into
3/devfrom
fix/auto-state-apply-local-salt-files
Sep 8, 2026
Merged

dougburks merged 2 commits into
3/devfrom
fix/auto-state-apply-local-salt-files

Conversation

@m0duspwnens

Copy link
Copy Markdown
Contributor

securityonion now watches the directories under /opt/so/saltstack/local/salt/ that these pages tell users to edit, so hand-placed files are applied within a few minutes instead of waiting for the next scheduled highstate.

Drop the Known Issues entry and turn the "not detected, so this step is required" caveats on the zeek, elasticsearch, and rbac pages back into an optional "if you don't want to wait" step.

Document the watched directories under Auto State Apply in salt.md, and say plainly that anything else under local/salt/ still waits for the highstate.

securityonion now watches the directories under /opt/so/saltstack/local/salt/
that these pages tell users to edit, so hand-placed files are applied within
a few minutes instead of waiting for the next scheduled highstate.

Drop the Known Issues entry and turn the "not detected, so this step is
required" caveats on the zeek, elasticsearch, and rbac pages back into an
optional "if you don't want to wait" step.

Document the watched directories under Auto State Apply in salt.md, and say
plainly that anything else under local/salt/ still waits for the highstate.

Also correct two stale claims:
  - zeek.md said intel and zkg packages reach separate sensor nodes only at
    their next highstate. Auto State Apply targets every node running Zeek.
  - logstash.md said a defined_pipelines change waits for the next highstate.
    That is a SOC config save, which Auto State Apply has always detected.
@dougburks
dougburks merged commit 1398d9e into 3/dev Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants