mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-07-02 01:27:27 -04:00
prepare for elk 5.x and improvements
This commit is contained in:
21
installer/bin/dump_elk.sh
Executable file
21
installer/bin/dump_elk.sh
Executable file
@ -0,0 +1,21 @@
|
||||
#/bin/bash
|
||||
myDATE=$(date +%Y%m%d%H%M)
|
||||
myINDICES=$(curl -s -XGET 'http://127.0.0.1:64298/_cat/indices/' | grep logstash | awk '{ print $3 }' | sort | grep -v 1970)
|
||||
myES="http://127.0.0.1:64298/"
|
||||
myCOL1="[0;34m"
|
||||
myCOL0="[0;0m"
|
||||
mkdir $myDATE
|
||||
for i in $myINDICES;
|
||||
do
|
||||
echo $myCOL1"### Now dumping: "$i $myCOL0
|
||||
elasticdump --input=$myES$i --output=$myDATE"/"$i --limit 7500
|
||||
echo $myCOL1"### Now compressing: $myDATE/$i" $myCOL0
|
||||
gzip -f $myDATE"/"$i
|
||||
done;
|
||||
echo $myCOL1"### Now building tar archive: es_dump_"$myDATE".tgz" $myCOL0
|
||||
cd $myDATE
|
||||
tar cvfz es_dump_$myDATE.tgz *
|
||||
mv es_dump_$myDATE.tgz ..
|
||||
cd ..
|
||||
rm -rf $myDATE
|
||||
echo $myCOL1"### Done."$myCOL0
|
45
installer/bin/restore_elk.sh
Executable file
45
installer/bin/restore_elk.sh
Executable file
@ -0,0 +1,45 @@
|
||||
#/bin/bash
|
||||
myDUMP=$1
|
||||
myES="http://127.0.0.1:64298/"
|
||||
myCOL1="[0;34m"
|
||||
myCOL0="[0;0m"
|
||||
|
||||
# Check if parameter is given and file exists
|
||||
if [ "$myDUMP" = "" ];
|
||||
then
|
||||
echo $myCOL1"### Please proive a backup file name."$myCOL0
|
||||
echo $myCOL1"### restore-elk.sh <es_dump.tgz>"$myCOL0
|
||||
echo
|
||||
exit
|
||||
fi
|
||||
if ! [ -a $myDUMP ];
|
||||
then
|
||||
echo $myCOL1"### File not found."$myCOL0
|
||||
exit
|
||||
fi
|
||||
|
||||
# Unpack tar archive
|
||||
echo $myCOL1"### Now unpacking tar archive: "$myDUMP $myCOL0
|
||||
mkdir tmp
|
||||
tar xvfz $myDUMP -C tmp
|
||||
cd tmp
|
||||
# Build indices list
|
||||
myINDICES=$(ls | cut -c 1-19)
|
||||
echo $myCOL1"### The following indices will be restored: "$myCOL0
|
||||
echo $myINDICES
|
||||
echo
|
||||
|
||||
for i in $myINDICES;
|
||||
do
|
||||
# Delete index if it already exists
|
||||
curl -s -XDELETE $myES$i > /dev/null
|
||||
echo $myCOL1"### Now uncompressing: "$i".gz" $myCOL0
|
||||
gunzip $i.gz
|
||||
# Restore index to ES
|
||||
echo $myCOL1"### Now restoring: "$i $myCOL0
|
||||
elasticdump --input=$i --output=$myES$i --limit 7500
|
||||
rm $i
|
||||
done;
|
||||
cd ..
|
||||
rm -rf tmp
|
||||
echo $myCOL1"### Done."$myCOL0
|
Reference in New Issue
Block a user