|
@@ -5,6 +5,33 @@ locals {
|
|
|
account_alias = "afs-mdr-test-c2-gov"
|
|
|
aws_account_id = "738800754746"
|
|
|
instance_termination_protection = false # set to true for production!
|
|
|
+ splunk_prefix = "moose2"
|
|
|
+
|
|
|
+ # Additional sources that are allowed to send data, such as Customer LCPs, Azure, etc.
|
|
|
+ splunk_data_sources = [
|
|
|
+ "170.248.172.0/23", # ?
|
|
|
+ "20.190.250.137/32", # ?
|
|
|
+ "52.232.227.197/32", # ?
|
|
|
+ "52.185.64.173/32", # ?
|
|
|
+ "52.242.225.98/32", # ?
|
|
|
+ "52.177.84.83/32", # ?
|
|
|
+ "199.16.64.3/32", #?
|
|
|
+ "99.56.213.129/32", # Fred Damstra's Home IP - For testing
|
|
|
+ ]
|
|
|
+ splunk_legacy_cidr = [ # Allow splunk ports to/from here, too
|
|
|
+ "10.80.100.0/22",
|
|
|
+ ]
|
|
|
+ splunk_asg_sizes = [ 1, 1, 1 ] # How many?
|
|
|
+ splunk_volume_sizes = {
|
|
|
+ "swap": 8, # minimum: 8
|
|
|
+ "/": 10, # minimum: 10
|
|
|
+ "/home": 4, # minimum: 4
|
|
|
+ "/var": 15, # minimum: 15
|
|
|
+ "/var/tmp": 4, # minimum: 4
|
|
|
+ "/var/log": 8, # minimum: 8
|
|
|
+ "/var/log/audit": 8, # minimum: 8
|
|
|
+ "/tmp": 4 # minimum: 4
|
|
|
+ }
|
|
|
|
|
|
account_tags = { }
|
|
|
c2_account_standards_path = "../../mdr-test-c2/005-account-standards-c2"
|
|
@@ -61,6 +88,14 @@ locals {
|
|
|
},
|
|
|
}
|
|
|
|
|
|
+ instance_types = {
|
|
|
+ "splunk-cm" = "t3a.small", # legacy: t2.small
|
|
|
+ "splunk-indexer" = "i3en.large", # legacy: t2.small, but whats the point if we don't have instance storage.
|
|
|
+ "splunk-hf" = "t3a.small", # legacy: t2.medium
|
|
|
+ "splunk-sh" = "t3a.small", # legacy: ? not sure
|
|
|
+ }
|
|
|
+
|
|
|
+ # TODO: The instance types below should be moved to the instance_type map above
|
|
|
# DNS Resolver
|
|
|
resolver_instance_type = "t3a.micro"
|
|
|
resolver_instance_key_name = "fdamstra"
|