Files
siem-backend/.env
2026-05-02 21:37:21 +02:00

77 lines
1.6 KiB
Bash

TZ=UTC
LISTEN_ADDR=:8080
DB_DSN=eventuser:DEINPASSWORT@tcp(mariadb:3306)/eventcollector?parseTime=true&charset=utf8mb4,utf8&collation=utf8mb4_unicode_ci&loc=UTC
DB_MAX_OPEN_CONNS=50
DB_MAX_IDLE_CONNS=25
DB_CONN_MAX_LIFETIME=3m
DB_CONN_MAX_IDLE_TIME=1m
MAX_BODY_BYTES=10485760
HTTP_READ_TIMEOUT=15s
HTTP_WRITE_TIMEOUT=30s
HTTP_IDLE_TIMEOUT=60s
DETECTION_INTERVAL=1m
OFFLINE_AFTER=10m
OFFLINE_ALERT_MAX=120m
FAILED_LOGON_WINDOW=5m
FAILED_LOGON_THRESHOLD=25
REBOOT_WINDOW=15m
REBOOT_THRESHOLD=3
PASSWORD_SPRAY_WINDOW=5m
PASSWORD_SPRAY_MIN_USERS=5
PASSWORD_SPRAY_MIN_ATTEMPTS=15
SUCCESS_AFTER_FAILURE_WINDOW=10m
NEW_SOURCE_IP_LOOKBACK=720h
NEW_SOURCE_IP_WINDOW=10m
DETECTIONS_LIMIT=100
MARIADB_DATABASE=eventcollector
MARIADB_USER=eventuser
MARIADB_PASSWORD=DEINPASSWORT
MARIADB_ROOT_PASSWORD=ROOTPASSWORT
GRAFANA_ADMIN_USER=admin
GRAFANA_ADMIN_PASSWORD=admin
ENROLLMENT_KEY=BITTE_SEHR_LANG_UND_ZUFAELLIG
#Woche 1
BASELINE_WINDOW=15m
BASELINE_MIN_SAMPLES=72
BASELINE_MIN_COUNT=30
BASELINE_MEDIUM_Z=3.5
BASELINE_HIGH_Z=6.0
BASELINE_SUPPRESS_FOR=6h
#Woche 2-4
#BASELINE_WINDOW=15m
#BASELINE_MIN_SAMPLES=48
#BASELINE_MIN_COUNT=20
#BASELINE_MEDIUM_Z=3.0
#BASELINE_HIGH_Z=5.0
#BASELINE_SUPPRESS_FOR=4h
#Dauerlauf Aggressiv
#BASELINE_WINDOW=10m
#BASELINE_MIN_SAMPLES=36
#BASELINE_MIN_COUNT=15
#BASELINE_MEDIUM_Z=2.8
#BASELINE_HIGH_Z=4.5
#BASELINE_SUPPRESS_FOR=2h
#Dauerlauf Passiv
#BASELINE_WINDOW=15m
#BASELINE_MIN_SAMPLES=48
#BASELINE_MIN_COUNT=20
#BASELINE_MEDIUM_Z=3.0
#BASELINE_HIGH_Z=5.0
#BASELINE_SUPPRESS_FOR=4h
PARTITION_MAINTENANCE_ENABLED=true
PARTITION_MAINTENANCE_INTERVAL=15m
PARTITION_INTERVAL=3h
PARTITION_AHEAD=24h
PARTITION_BEHIND=6h