From 89f8bcd19f291705569f3206595a8ec1adfc5e21 Mon Sep 17 00:00:00 2001 From: defensivedepth Date: Thu, 1 Oct 2026 10:28:10 -0400 Subject: [PATCH 1/6] evtx-import fixup --- .../grid-nodes_general/import-evtx-logs.json | 2 +- salt/elasticsearch/files/ingest/global@custom | 4 +-- salt/elasticsearch/files/ingest/import.evtx | 31 +++++++++++++++++++ 3 files changed, 34 insertions(+), 3 deletions(-) create mode 100644 salt/elasticsearch/files/ingest/import.evtx diff --git a/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json b/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json index 723370ba6..6f6bb8628 100644 --- a/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json +++ b/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json @@ -29,7 +29,7 @@ "\\.gz$" ], "include_files": [], - "processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- drop_fields:\n fields: [\"host\"]\n ignore_missing: true\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: system.security\n- add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.security-2.22.3\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: windows.sysmon_operational\n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-windows.sysmon_operational-3.9.0\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: system.application\n - add_fields:\n target: event\n fields:\n dataset: system.application\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.application-2.22.3\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: system.system\n - add_fields:\n target: event\n fields:\n dataset: system.system\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.system-2.22.3\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: windows.powershell_operational\n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-windows.powershell_operational-3.9.0\n- add_fields:\n target: data_stream\n fields:\n dataset: import", + "processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- add_fields:\n target: event\n fields:\n dataset: windows.forwarded\n module: windows\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: import.evtx\n- if:\n equals:\n winlog.channel: 'Security'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n- if:\n equals:\n winlog.channel: 'Windows PowerShell'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell\n module: windows\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.application\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.system\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: import", "tags": [ "import" ], diff --git a/salt/elasticsearch/files/ingest/global@custom b/salt/elasticsearch/files/ingest/global@custom index 979c5c1b8..ab1418cd2 100644 --- a/salt/elasticsearch/files/ingest/global@custom +++ b/salt/elasticsearch/files/ingest/global@custom @@ -99,7 +99,7 @@ }, { "set": { - "if": "ctx.tags != null && ctx.tags.contains('import')", + "if": "ctx.tags != null && ctx.tags.contains('import') && ctx._index != null && ctx._index.startsWith('logs-import-')", "override": true, "field": "data_stream.dataset", "value": "import" @@ -107,7 +107,7 @@ }, { "set": { - "if": "ctx.tags != null && ctx.tags.contains('import')", + "if": "ctx.tags != null && ctx.tags.contains('import') && ctx._index != null && ctx._index.startsWith('logs-import-')", "override": true, "field": "data_stream.namespace", "value": "so" diff --git a/salt/elasticsearch/files/ingest/import.evtx b/salt/elasticsearch/files/ingest/import.evtx new file mode 100644 index 000000000..99189130c --- /dev/null +++ b/salt/elasticsearch/files/ingest/import.evtx @@ -0,0 +1,31 @@ +{ + "description" : "import.evtx: normalize imported EVTX and reroute to logs--import", + "processors" : [ + { "script": { + "description": "Host from the event, not the importing node", + "lang": "painless", + "source": "Map host = ['os': ['type': 'windows', 'family': 'windows', 'platform': 'windows']]; def cn = ctx.winlog?.computer_name; if (cn != null && cn.toString().length() > 0) { String name = cn.toString(); int dot = name.indexOf('.'); if (dot > 0) { name = name.substring(0, dot); } host.put('hostname', name); host.put('name', name.toLowerCase()); } ctx.host = host;" + } }, + { "script": { + "description": "String event IDs, as Winlogbeat sends", + "lang": "painless", + "source": "if (ctx.winlog?.event_id != null) { ctx.winlog.event_id = ctx.winlog.event_id.toString(); } if (ctx.event?.code != null) { ctx.event.code = ctx.event.code.toString(); }" + } }, + { "script": { + "description": "Unnamed to param1..N, as Winlogbeat", + "lang": "painless", + "if": "ctx.winlog?.event_data?.Data instanceof Map && ctx.winlog.event_data.Data['#text'] != null", + "source": "def t = ctx.winlog.event_data.Data['#text']; List vals = t instanceof List ? t : [t]; for (int i = 0; i < vals.size(); i++) { ctx.winlog.event_data['param' + (i + 1)] = vals.get(i); } ctx.winlog.event_data.remove('Data');" + } }, + { "script": { + "description": "String values and LF line endings, as Winlogbeat", + "lang": "painless", + "if": "ctx.winlog?.event_data instanceof Map || ctx.winlog?.user_data instanceof Map", + "source": "String lf = String.valueOf((char) 10); String crlf = String.valueOf((char) 13) + lf; for (def key : ['event_data', 'user_data']) { def m = ctx.winlog[key]; if (!(m instanceof Map)) { continue; } for (def e : m.entrySet()) { def v = e.getValue(); if (v instanceof String) { e.setValue(v.replace(crlf, lf)); } else if (v instanceof Number || v instanceof Boolean) { e.setValue(v.toString()); } } }" + } }, + { "set": { "description": "event.kind, as Winlogbeat", "field": "event.kind", "value": "event", "override": false } }, + { "set": { "field": "data_stream.dataset", "copy_from": "event.dataset", "override": true, "ignore_empty_value": true } }, + { "set": { "field": "data_stream.namespace", "value": "import", "override": true } }, + { "reroute": { "dataset": "{{data_stream.dataset}}", "namespace": "{{data_stream.namespace}}" } } + ] +} From 2a4611df45e17b3ba98b376bddeaccf9f8a232b2 Mon Sep 17 00:00:00 2001 From: defensivedepth Date: Thu, 1 Oct 2026 10:48:55 -0400 Subject: [PATCH 2/6] Add caseless mappings --- salt/elasticsearch/defaults.yaml | 5 + .../so-fleet_process_caseless-1.json | 123 ++++++++++++++++++ .../so-fleet_system.security_caseless-1.json | 80 ++++++++++++ .../files/soc/sigma_playbook_pipeline.yaml | 1 - salt/soc/files/soc/sigma_so_pipeline.yaml | 10 ++ 5 files changed, 218 insertions(+), 1 deletion(-) create mode 100644 salt/elasticsearch/templates/component/elastic-agent/so-fleet_process_caseless-1.json create mode 100644 salt/elasticsearch/templates/component/elastic-agent/so-fleet_system.security_caseless-1.json diff --git a/salt/elasticsearch/defaults.yaml b/salt/elasticsearch/defaults.yaml index f67a01df9..c8ceab34d 100644 --- a/salt/elasticsearch/defaults.yaml +++ b/salt/elasticsearch/defaults.yaml @@ -3309,6 +3309,7 @@ elasticsearch: composed_of: - event-mappings - logs-system.security@package + - so-fleet_system.security_caseless-1 - logs-system.security@custom - so-fleet_integrations.ip_mappings-1 - so-fleet_globals-1 @@ -4175,6 +4176,7 @@ elasticsearch: index_template: composed_of: - logs-windows.forwarded@package + - so-fleet_process_caseless-1 - logs-windows.forwarded@custom - so-fleet_integrations.ip_mappings-1 - so-fleet_globals-1 @@ -4224,6 +4226,7 @@ elasticsearch: index_template: composed_of: - logs-windows.powershell@package + - so-fleet_process_caseless-1 - logs-windows.powershell@custom - so-fleet_integrations.ip_mappings-1 - so-fleet_globals-1 @@ -4273,6 +4276,7 @@ elasticsearch: index_template: composed_of: - logs-windows.powershell_operational@package + - so-fleet_process_caseless-1 - logs-windows.powershell_operational@custom - so-fleet_integrations.ip_mappings-1 - so-fleet_globals-1 @@ -4322,6 +4326,7 @@ elasticsearch: index_template: composed_of: - logs-windows.sysmon_operational@package + - so-fleet_process_caseless-1 - logs-windows.sysmon_operational@custom - so-fleet_integrations.ip_mappings-1 - so-fleet_globals-1 diff --git a/salt/elasticsearch/templates/component/elastic-agent/so-fleet_process_caseless-1.json b/salt/elasticsearch/templates/component/elastic-agent/so-fleet_process_caseless-1.json new file mode 100644 index 000000000..37b6413e9 --- /dev/null +++ b/salt/elasticsearch/templates/component/elastic-agent/so-fleet_process_caseless-1.json @@ -0,0 +1,123 @@ +{ + "_meta": { + "managed_by": "security_onion", + "managed": true, + "description": "Adds .caseless for Lucene queries. Restates each field's package type and .text." + }, + "template": { + "mappings": { + "properties": { + "process": { + "properties": { + "executable": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + }, + "text": { + "type": "match_only_text" + } + } + }, + "name": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + }, + "text": { + "type": "match_only_text" + } + } + }, + "command_line": { + "type": "wildcard", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + }, + "text": { + "type": "match_only_text" + } + } + }, + "parent": { + "properties": { + "executable": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + }, + "text": { + "type": "match_only_text" + } + } + }, + "name": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + }, + "text": { + "type": "match_only_text" + } + } + }, + "command_line": { + "type": "wildcard", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + }, + "text": { + "type": "match_only_text" + } + } + } + } + } + } + }, + "file": { + "properties": { + "path": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + }, + "text": { + "type": "match_only_text" + } + } + } + } + } + } + } + } +} diff --git a/salt/elasticsearch/templates/component/elastic-agent/so-fleet_system.security_caseless-1.json b/salt/elasticsearch/templates/component/elastic-agent/so-fleet_system.security_caseless-1.json new file mode 100644 index 000000000..d320364fb --- /dev/null +++ b/salt/elasticsearch/templates/component/elastic-agent/so-fleet_system.security_caseless-1.json @@ -0,0 +1,80 @@ +{ + "_meta": { + "managed_by": "security_onion", + "managed": true, + "description": "Adds .caseless for Lucene queries. Keeps each field's existing keyword type." + }, + "template": { + "mappings": { + "properties": { + "process": { + "properties": { + "command_line": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + } + } + }, + "parent": { + "properties": { + "executable": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + } + } + }, + "name": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + } + } + }, + "command_line": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + } + } + } + } + } + } + }, + "file": { + "properties": { + "path": { + "type": "keyword", + "ignore_above": 1024, + "fields": { + "caseless": { + "type": "keyword", + "ignore_above": 1024, + "normalizer": "lowercase" + } + } + } + } + } + } + } + } +} diff --git a/salt/soc/files/soc/sigma_playbook_pipeline.yaml b/salt/soc/files/soc/sigma_playbook_pipeline.yaml index a779c4dec..6d428d2a8 100644 --- a/salt/soc/files/soc/sigma_playbook_pipeline.yaml +++ b/salt/soc/files/soc/sigma_playbook_pipeline.yaml @@ -2,7 +2,6 @@ name: Security Onion - Playbook Pipeline priority: 97 transformations: # Route to lowercase-normalized .caseless subfields for case-insensitive matching. - # file.path.caseless exists on Defend only (Sysmon file events lack it); # registry.path / dll.path / file.name have no .caseless on any source. - id: case_insensitive_string_fields type: field_name_mapping diff --git a/salt/soc/files/soc/sigma_so_pipeline.yaml b/salt/soc/files/soc/sigma_so_pipeline.yaml index ae867be49..23348860d 100644 --- a/salt/soc/files/soc/sigma_so_pipeline.yaml +++ b/salt/soc/files/soc/sigma_so_pipeline.yaml @@ -26,6 +26,16 @@ transformations: type: set_state key: keep val: "_id, _index, _source" + # Not every source maps .caseless; EQL/ES|QL already match case-insensitively. + - id: caseless_to_parent_fields + type: field_name_mapping + mapping: + process.executable.caseless: process.executable + process.name.caseless: process.name + process.parent.executable.caseless: process.parent.executable + process.parent.name.caseless: process.parent.name + target.process.executable.caseless: target.process.executable + target.process.name.caseless: target.process.name - id: baseline_field_name_mapping type: field_name_mapping mapping: From 99322cf26a731d182aeef0aa41c860d2b9912085 Mon Sep 17 00:00:00 2001 From: defensivedepth Date: Thu, 1 Oct 2026 15:24:52 -0400 Subject: [PATCH 3/6] Add additional mapping --- salt/soc/files/soc/sigma_playbook_pipeline.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/salt/soc/files/soc/sigma_playbook_pipeline.yaml b/salt/soc/files/soc/sigma_playbook_pipeline.yaml index 6d428d2a8..b31f8ba5d 100644 --- a/salt/soc/files/soc/sigma_playbook_pipeline.yaml +++ b/salt/soc/files/soc/sigma_playbook_pipeline.yaml @@ -8,6 +8,7 @@ transformations: mapping: process.executable: process.executable.caseless process.parent.executable: process.parent.executable.caseless + process.parent.name: process.parent.name.caseless process.command_line: process.command_line.caseless process.parent.command_line: process.parent.command_line.caseless file.path: file.path.caseless From 43475452b31d2b48a3e38f395191458421052376 Mon Sep 17 00:00:00 2001 From: defensivedepth Date: Thu, 1 Oct 2026 19:17:52 -0400 Subject: [PATCH 4/6] set module --- .../files/integrations/grid-nodes_general/import-evtx-logs.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json b/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json index 6f6bb8628..2a3f80431 100644 --- a/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json +++ b/salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json @@ -29,7 +29,7 @@ "\\.gz$" ], "include_files": [], - "processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- add_fields:\n target: event\n fields:\n dataset: windows.forwarded\n module: windows\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: import.evtx\n- if:\n equals:\n winlog.channel: 'Security'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n- if:\n equals:\n winlog.channel: 'Windows PowerShell'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell\n module: windows\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.application\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.system\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: import", + "processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- add_fields:\n target: event\n fields:\n dataset: windows.forwarded\n module: windows\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: import.evtx\n- if:\n equals:\n winlog.channel: 'Security'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n- if:\n equals:\n winlog.channel: 'Windows PowerShell'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell\n module: windows\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.application\n module: system\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.system\n module: system\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: import", "tags": [ "import" ], From 4ce7a06abee374b4f8aec2f70421f02887c273c2 Mon Sep 17 00:00:00 2001 From: Josh Patterson Date: Tue, 29 Sep 2026 17:39:05 -0400 Subject: [PATCH 5/6] upgrade docker to 29.8.1 and containerd.io to 2.3.6 Latest upstream stable for el9. All four NVRs are already carried by the SO prod repo, so no repo change is needed -- a so-repo-sync refresh is enough. Tested on a managersearch and a heavynode (OL 9.8, 3.4.0), upgrading from 29.2.1/2.2.1 both by hand and through the state itself: - The 29.8.1 RPM ships a byte-identical docker.service, so the full ExecStart override in files/iptables-disabled.conf still resolves correctly and the hand-written DOCKER/DOCKER-ISOLATION/DOCKER-USER chains came back byte-identical on both nodes across upgrade, restart and reboot. - update_holds re-pinned the versionlock from the old NVRs to the new ones without intervention, so soup's path needs no change. - docker-py 7.1.0 still creates sobridge and soauth (forced by removing both); bridges keep their configured kernel names rather than br-. - 29.6 changed how dynamic port allocation treats net.ipv4.ip_local_reserved_ports; Strelka's 57314 is both published and reserved, and docker-proxy still owns it with no bind errors. - docker ps --format json gained a HealthStatus key. Additive, so so-status, so-log-check and so-docker-prune all still parse it. - containerd 2.3.6 ships the same config.toml, and it is %config(noreplace) and unmodified on disk, so no .rpmnew and disabled_plugins=["cri"] survives. - Zeek/Suricata/Strelka pipeline verified end-to-end with so-test: 111k packets replayed, 0 capture loss, file extraction and ES ingest all landed. The manifest unknown exclusion in so-log-check still fires on 29.8.1 -- it comes from a tag lookup during the registry-to-registry image copy, not from the 29.2.1 upgrade the old comment blamed -- so only the comment changes. --- salt/common/tools/sbin/so-log-check | 2 +- salt/docker/init.sls | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/salt/common/tools/sbin/so-log-check b/salt/common/tools/sbin/so-log-check index 211a3f58d..852592a10 100755 --- a/salt/common/tools/sbin/so-log-check +++ b/salt/common/tools/sbin/so-log-check @@ -241,7 +241,7 @@ if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459 EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user - EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # appears in so-dockerregistry log for so-tcpreplay following docker upgrade to 29.2.1-1 + EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # so-dockerregistry logs a tag lookup miss during image copy; not tied to one docker version EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Could not index event to Elasticsearch.*\"version\" => \"9.0.8\"" # Expected during Elastic upgrade temporarily, as policies referencing older pipelines are updated fi diff --git a/salt/docker/init.sls b/salt/docker/init.sls index 9945a8096..4917cc163 100644 --- a/salt/docker/init.sls +++ b/salt/docker/init.sls @@ -18,10 +18,10 @@ dockergroup: dockerheldpackages: pkg.installed: - pkgs: - - containerd.io: 2.2.1-1.el9 - - docker-ce: 3:29.2.1-1.el9 - - docker-ce-cli: 1:29.2.1-1.el9 - - docker-ce-rootless-extras: 29.2.1-1.el9 + - containerd.io: 2.3.6-1.el9 + - docker-ce: 3:29.8.1-1.el9 + - docker-ce-cli: 1:29.8.1-1.el9 + - docker-ce-rootless-extras: 29.8.1-1.el9 - hold: True - update_holds: True From 31c5190a1fab2a41229fd8e8709e75f47c837789 Mon Sep 17 00:00:00 2001 From: Josh Patterson Date: Wed, 30 Sep 2026 09:58:31 -0400 Subject: [PATCH 6/6] add missing comma --- salt/repo/client/map.jinja | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/salt/repo/client/map.jinja b/salt/repo/client/map.jinja index 21f52a5e7..3a44d8431 100644 --- a/salt/repo/client/map.jinja +++ b/salt/repo/client/map.jinja @@ -9,7 +9,7 @@ 'epel-testing.repo', 'saltstack.repo', 'salt-latest.repo', - 'wazuh.repo' + 'wazuh.repo', 'Rocky-Base.repo', 'Rocky-CR.repo', 'Rocky-Debuginfo.repo',