Josh Patterson
|
03f9160fcc
|
Merge pull request #12860 from Security-Onion-Solutions/issue/12856
allow for enabled/disable of so-elasticsearch-indices-delete cronjob
|
2024-04-25 09:07:44 -04:00 |
|
m0duspwnens
|
d50de804a8
|
update annotation
|
2024-04-25 09:04:34 -04:00 |
|
weslambert
|
983ef362e9
|
Merge pull request #12858 from Security-Onion-Solutions/fix/index_sorting
Change index sorting to account for older so-prefixed indices
|
2024-04-25 08:54:22 -04:00 |
|
Josh Brower
|
d88c1a5e0a
|
Merge pull request #12861 from Security-Onion-Solutions/2.4/detectionlogs
Add runtime status logs
|
2024-04-24 20:07:32 -04:00 |
|
weslambert
|
44afa55274
|
Fix comments about deletion
|
2024-04-24 17:41:37 -04:00 |
|
weslambert
|
ab832e4bb2
|
Include logstash-prefixed indices
|
2024-04-24 17:17:53 -04:00 |
|
DefensiveDepth
|
3c3ed8b5c5
|
Add runtime status logs
|
2024-04-24 16:33:47 -04:00 |
|
m0duspwnens
|
c9d9979f22
|
allow for enabled/disable of so-elasticsearch-indices-delete cronjob
|
2024-04-24 16:18:45 -04:00 |
|
Josh Patterson
|
383420b554
|
Merge pull request #12859 from Security-Onion-Solutions/issue/12637
Issue/12637
|
2024-04-24 15:44:37 -04:00 |
|
m0duspwnens
|
73b5bb1a75
|
add memlock to so-suricata container
|
2024-04-24 15:35:17 -04:00 |
|
weslambert
|
59a02635ed
|
Change index sorting
|
2024-04-24 15:18:49 -04:00 |
|
m0duspwnens
|
13a6520a8c
|
mmap-locked default no
|
2024-04-24 13:50:12 -04:00 |
|
m0duspwnens
|
4b7f826a2a
|
quote is so true becomes yes
|
2024-04-24 13:29:55 -04:00 |
|
m0duspwnens
|
0bd0c7b1ec
|
allow for mmap-locked to be configured
|
2024-04-24 13:26:25 -04:00 |
|
weslambert
|
428fe787c4
|
Merge pull request #12852 from Security-Onion-Solutions/fix/elastic_max_age
Remove hot max_age
|
2024-04-24 10:15:06 -04:00 |
|
weslambert
|
1b3a0a3de8
|
Remove hot max_age
|
2024-04-24 10:11:02 -04:00 |
|
weslambert
|
96ec285241
|
Merge pull request #12848 from Security-Onion-Solutions/fix/elastic_annotation
Fix description, regex, and type for cold, warm, and hot
|
2024-04-24 09:22:05 -04:00 |
|
weslambert
|
75b5e16696
|
Update description, type, and regex
|
2024-04-24 09:14:39 -04:00 |
|
weslambert
|
8a0a435700
|
Fix warm description
|
2024-04-24 08:35:19 -04:00 |
|
weslambert
|
bef408b944
|
Merge pull request #12844 from Security-Onion-Solutions/fix/elastic_annotation
Fix warm description
|
2024-04-23 10:47:04 -04:00 |
|
weslambert
|
691b02a15e
|
Fix warm description
|
2024-04-23 10:40:09 -04:00 |
|
Josh Brower
|
fc1c41e5a4
|
Merge pull request #12841 from Security-Onion-Solutions/2.4/logfix
Temp exclude yara runtime status log
|
2024-04-23 07:36:02 -04:00 |
|
DefensiveDepth
|
58ddd55123
|
Exclude yara runtime log
|
2024-04-23 07:28:07 -04:00 |
|
Jorge Reyes
|
d402943403
|
Merge pull request #12773 from Security-Onion-Solutions/reyesj2/kismet
Kismet integration for WiFi devices
|
2024-04-22 15:59:22 -04:00 |
|
Josh Brower
|
64c43b1a55
|
Merge pull request #12805 from Security-Onion-Solutions/2.4/detectiondefaults
Strelka fixes and more
|
2024-04-19 16:53:07 -04:00 |
|
DefensiveDepth
|
a237ef5d96
|
Update default queries
|
2024-04-19 16:33:35 -04:00 |
|
Doug Burks
|
c48da45ac3
|
Merge pull request #12820 from Security-Onion-Solutions/dougburks-patch-1
FIX: Elastic retention setting not being honored when manager hostname is a subset of search node hostname #12819
|
2024-04-18 11:59:57 -04:00 |
|
Doug Burks
|
406dda6051
|
Update so-elasticsearch-cluster-space-used
|
2024-04-18 11:48:15 -04:00 |
|
Doug Burks
|
229a989914
|
Update so-elasticsearch-cluster-space-total
|
2024-04-18 11:47:01 -04:00 |
|
DefensiveDepth
|
6c6647629c
|
Refactor yara for compilation
|
2024-04-18 11:32:17 -04:00 |
|
Doug Burks
|
7f9bc1fc0f
|
Merge pull request #12817 from Security-Onion-Solutions/dougburks-patch-1
FEATURE: Add queue=True to so-checkin so that it will wait for any ru…
|
2024-04-18 09:30:55 -04:00 |
|
Doug Burks
|
8d9aae1983
|
FEATURE: Add queue=True to so-checkin so that it will wait for any running states #12815
|
2024-04-18 09:28:30 -04:00 |
|
Mike Reeves
|
3854620bcd
|
Merge pull request #12810 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update limited-analyst.json
|
2024-04-17 13:21:04 -04:00 |
|
Mike Reeves
|
67a57e9df7
|
Update limited-analyst.json
|
2024-04-17 13:14:45 -04:00 |
|
DefensiveDepth
|
ff28476191
|
Fix compile_yara path
|
2024-04-16 13:10:17 -04:00 |
|
DefensiveDepth
|
8cc4d2668e
|
Move compile_yara
|
2024-04-16 12:52:14 -04:00 |
|
DefensiveDepth
|
dbfb178556
|
Add test
|
2024-04-16 12:22:53 -04:00 |
|
Josh Brower
|
5e8b16569f
|
Merge pull request #12793 from Security-Onion-Solutions/2.4/detectiondefaults
Add docs for ruleset change
|
2024-04-12 13:54:06 -04:00 |
|
DefensiveDepth
|
f5e42e73af
|
Add docs for ruleset change
|
2024-04-12 13:30:20 -04:00 |
|
Josh Brower
|
5b81a73e58
|
Merge pull request #12791 from Security-Onion-Solutions/2.4/detectiondefaults
Fix fingerprint paths
|
2024-04-12 09:01:38 -04:00 |
|
DefensiveDepth
|
49ccd86c39
|
Fix fingerprint paths
|
2024-04-12 08:35:44 -04:00 |
|
reyesj2
|
55cf90f477
|
merge 2.4/dev
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-11 14:44:59 -04:00 |
|
reyesj2
|
c269fb90ac
|
Added a Kismet Wifi devices dashboard for an overview of kismet data
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-11 14:41:54 -04:00 |
|
Mike Reeves
|
1250a728ac
|
Merge pull request #12769 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update analyst.json
|
2024-04-11 14:30:17 -04:00 |
|
reyesj2
|
68e016090b
|
Fix network.wireless.ssid not parsing
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-11 13:21:54 -04:00 |
|
reyesj2
|
fd689a4607
|
Fix typo in ingest pipeline
Test to fix duplicate events in SOC, by removing conflicting field event.created
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-11 11:18:04 -04:00 |
|
Josh Brower
|
ae09869417
|
Merge pull request #12780 from Security-Onion-Solutions/2.4/detectiondefaults
Enable Detections Adv by default
|
2024-04-11 09:32:34 -04:00 |
|
DefensiveDepth
|
1c5f02ade2
|
Update annotations
|
2024-04-11 09:21:08 -04:00 |
|
DefensiveDepth
|
ed97aa4e78
|
Enable Detections Adv by default
|
2024-04-11 08:21:20 -04:00 |
|
reyesj2
|
7124f04138
|
Update ingest pipelines to match updated mappings
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-10 16:13:06 -04:00 |
|