Mike Reeves
|
02d013c0cc
|
Re-Work IDSTOOLS
|
2023-03-15 16:47:43 -04:00 |
|
Mike Reeves
|
b56baf900c
|
Re-Work IDSTOOLS
|
2023-03-15 16:44:53 -04:00 |
|
Mike Reeves
|
0d30c14561
|
Re-Work IDSTOOLS
|
2023-03-15 16:33:33 -04:00 |
|
Josh Patterson
|
b809b22566
|
Merge pull request #9931 from Security-Onion-Solutions/2.4/strelka
2.4/strelka
|
2023-03-14 16:16:53 -04:00 |
|
m0duspwnens
|
f9b8c78d74
|
move repos to rules dir
|
2023-03-14 14:43:13 -04:00 |
|
m0duspwnens
|
7cf4e6b03b
|
add rules dir, change so-yar-update to save to local/salt/strelka/rules
|
2023-03-14 13:59:31 -04:00 |
|
m0duspwnens
|
5f7256c826
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/strelka
|
2023-03-14 13:26:15 -04:00 |
|
m0duspwnens
|
b38d5df684
|
set default mime_db
|
2023-03-14 13:25:51 -04:00 |
|
weslambert
|
4e0390963b
|
Merge pull request #9928 from Security-Onion-Solutions/fix/curator_elastic_agent_filebeat_actions_close
Fix Curator Action Files
|
2023-03-14 10:58:53 -04:00 |
|
weslambert
|
8eba3426be
|
Remove extra dash for 'logs-elastic_agent-metricbeat-default' key
|
2023-03-14 10:51:50 -04:00 |
|
weslambert
|
7c39938e14
|
Change 'elastic_agent.filebeat' to 'elastic_agent-filebeat'
|
2023-03-14 10:48:50 -04:00 |
|
weslambert
|
123275ca35
|
Merge pull request #9926 from Security-Onion-Solutions/fix/curator_additional_elastic_agent_indices
Add more Elastic Agent Curator actions
|
2023-03-14 09:59:47 -04:00 |
|
Wes
|
766e6a7974
|
Add 'logs-windows-sysmon_operational-delete' for Windows Sysmon operational indices
|
2023-03-14 13:51:49 +00:00 |
|
Wes
|
f0d4c16b2b
|
Add more Elastic Agent index keys for Curator
|
2023-03-14 13:49:13 +00:00 |
|
Wes
|
412e5c0402
|
Add more Elastic Agent Curator action files
|
2023-03-14 13:46:08 +00:00 |
|
Josh Brower
|
fbac23c28d
|
Merge pull request #9925 from Security-Onion-Solutions/2.4/fiedfix
Removes Suricata host.* fields
|
2023-03-14 07:38:05 -04:00 |
|
weslambert
|
ebc943fcab
|
Merge pull request #9924 from Security-Onion-Solutions/fix/curator_action_file_system_syslog_delete
Fix Elastic Agent system syslog default delete file configuration
|
2023-03-13 17:28:38 -04:00 |
|
weslambert
|
486de12ca5
|
Delete logs-system-auth-syslog-close.yaml
|
2023-03-13 17:27:52 -04:00 |
|
weslambert
|
f4112b30c0
|
Fix index reference for system auth default
|
2023-03-13 17:27:06 -04:00 |
|
weslambert
|
bab40de58d
|
Fix system auth default key value
|
2023-03-13 17:26:05 -04:00 |
|
weslambert
|
785f100132
|
Fix system auth default key value
|
2023-03-13 17:25:33 -04:00 |
|
weslambert
|
8ade7b85fc
|
Fix system syslog default key value
|
2023-03-13 17:24:40 -04:00 |
|
weslambert
|
c2701f1835
|
Fix system syslog default key value
|
2023-03-13 17:24:12 -04:00 |
|
weslambert
|
d5bb223235
|
Fix system syslog delete file configuration
|
2023-03-13 17:10:52 -04:00 |
|
weslambert
|
bb711a2a15
|
Merge pull request #9923 from Security-Onion-Solutions/fix/curator_default_elastic_agent_logs
Add Elastic Agent default indices to be managed by Curator
|
2023-03-13 16:59:40 -04:00 |
|
Wes
|
efc5832499
|
Add Elastic Agent default log action files
|
2023-03-13 20:54:38 +00:00 |
|
Wes
|
8d395dc465
|
Add Elastic Agent default data stream backing indices for management by Curator
|
2023-03-13 20:54:13 +00:00 |
|
m0duspwnens
|
9d4e1cc149
|
jinja for strelka
|
2023-03-13 16:48:21 -04:00 |
|
Josh Brower
|
f7be4ba31c
|
Remove host field from NIDS logs
|
2023-03-13 14:07:17 -04:00 |
|
Josh Brower
|
126add7ddd
|
Merge pull request #9922 from Security-Onion-Solutions/2.4/fieldfixes
auto-apply firewall rules
|
2023-03-13 12:00:28 -04:00 |
|
Josh Brower
|
b3a2680847
|
auto-apply firewall rules
|
2023-03-13 11:41:36 -04:00 |
|
weslambert
|
1774d16d9a
|
Merge pull request #9921 from Security-Onion-Solutions/fix/elasticsearch_template_data_stream_configuration
Move data stream configuration outside of ILM policy definition
|
2023-03-13 09:29:42 -04:00 |
|
Wes
|
e105e56fac
|
Move data stream configuration outside of ILM policy definition
|
2023-03-13 13:27:02 +00:00 |
|
m0duspwnens
|
58343e39fa
|
2.4 strelka
|
2023-03-10 17:32:14 -05:00 |
|
weslambert
|
a844819261
|
Merge pull request #9919 from Security-Onion-Solutions/fix/elasticsearch_ilm_policy_elastic_agent_default
Add index lifecycle management policy definitions for default Elastic Agent data streams
|
2023-03-10 17:02:27 -05:00 |
|
weslambert
|
16d9478196
|
Add index lifecycle management policy definitions for default Elastic Agent data streams
|
2023-03-10 16:54:47 -05:00 |
|
Josh Brower
|
2fe8668f1b
|
Merge pull request #9891 from Security-Onion-Solutions/2.4/huntqueries
Initial updates for 2.4 fieldnames
|
2023-03-09 14:37:50 -05:00 |
|
Josh Brower
|
73abf8dbfd
|
Generic host dashboard
|
2023-03-09 14:32:52 -05:00 |
|
Josh Brower
|
1493806040
|
Change host dashboard titles
|
2023-03-08 17:03:02 -05:00 |
|
Josh Brower
|
a5c89bfaa1
|
update sysmon dashboards
|
2023-03-08 16:49:34 -05:00 |
|
Josh Patterson
|
d75866caec
|
Merge pull request #9912 from Security-Onion-Solutions/2.4/heavynode
2.4/heavynode
|
2023-03-08 14:11:43 -05:00 |
|
m0duspwnens
|
61879a8d33
|
merge with dev and resolve conflicts in salt/top
|
2023-03-08 09:04:09 -05:00 |
|
weslambert
|
7ad34ee8d7
|
Merge pull request #9910 from Security-Onion-Solutions/fix/curator_so_curator_cluster_warm
Remove reference to 'so-curator-cluster-warm' script since it has been removed
|
2023-03-07 16:18:05 -05:00 |
|
weslambert
|
2d7ce41a70
|
Remove reference to 'so-curator-cluster-warm' script since it has been removed
|
2023-03-07 16:16:55 -05:00 |
|
weslambert
|
a738c7c36d
|
Merge pull request #9907 from Security-Onion-Solutions/fix/curator_global_delete_action
Add the new Security Onion index format to the global delete action file for Curator
|
2023-03-07 16:03:28 -05:00 |
|
Josh Brower
|
6f82cf3807
|
Merge pull request #9906 from Security-Onion-Solutions/2.4/setupfix
Remove EA install from manager highstates
|
2023-03-07 15:33:34 -05:00 |
|
weslambert
|
e93c052d34
|
Add the new index format to the global delete action file for Curator
|
2023-03-07 15:21:53 -05:00 |
|
Josh Brower
|
fd2312a2ac
|
Remove EA install from manager highstates
|
2023-03-07 15:13:35 -05:00 |
|
weslambert
|
8c79d7e40d
|
Merge pull request #9905 from Security-Onion-Solutions/fix/curator_new_action_files
Add New Curator Action Files
|
2023-03-07 12:44:25 -05:00 |
|
Wes
|
f50639d2d2
|
Fix import and syslog actions
|
2023-03-07 17:41:48 +00:00 |
|