TheHive 3.4.0 (Includes ES 6.8.3 for TheHive only).
-
Fixed Bro/Zeek packet loss calculation for Grafana.
-
Updated to latest Sensoroni for websockets to enable job status updates without refreshing.
-
NIDS and HIDS dashboard updates.
-
Playbook and ATT&CK Navigator features are now included.
-
Filebeat now logs to a file, instead of stdout.
-
Elastalert has been updated to use Python 3 and allow for use of custom alerters.
-
Elasticsearch Ingest is now used to consume Zeek logs and Suricata alerts (instead of the traditional Logstash pipeline). This reduces the memory footprint of Logstash dramatically!
-
Several changes to the setup script have been made to improve stability of the setup process:
-
-
Setup now modifies your hosts file so that the install works better in environments without DNS.
-
You are now prompted for setting a password for the socore user.
-
The install now forces a reboot at the end of the install. This fixes an issue with some of the Docker containers being in the wrong state from a manual reboot. Manual reboots are fine after the initial reboot.