diff --git a/elk_metrics_6x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 b/elk_metrics_6x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 index c0c164e2..c8954ad5 100644 --- a/elk_metrics_6x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 +++ b/elk_metrics_6x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 @@ -33,7 +33,7 @@ auditbeat.modules: # The auditd module collects events from the audit framework in the Linux # kernel. You need to specify audit rules for the events that you want to audit. - module: auditd -{% if ansible_kernel is version_compare('4.4', '>=') %} +{% if ansible_kernel is version('4.4', '>=') %} socket_type: {{ (apply_security_hardening | default(true) | bool) | ternary('multicast', 'unicast') }} {% endif %} resolve_ids: true diff --git a/elk_metrics_7x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 b/elk_metrics_7x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 index c0c164e2..c8954ad5 100644 --- a/elk_metrics_7x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 +++ b/elk_metrics_7x/roles/elastic_auditbeat/templates/auditbeat.yml.j2 @@ -33,7 +33,7 @@ auditbeat.modules: # The auditd module collects events from the audit framework in the Linux # kernel. You need to specify audit rules for the events that you want to audit. - module: auditd -{% if ansible_kernel is version_compare('4.4', '>=') %} +{% if ansible_kernel is version('4.4', '>=') %} socket_type: {{ (apply_security_hardening | default(true) | bool) | ternary('multicast', 'unicast') }} {% endif %} resolve_ids: true