William Wernert
|
056b3a0629
|
Merge branch 'dev' into feature/setup
# Conflicts:
# setup/so-setup
|
2020-07-10 18:41:24 -04:00 |
|
William Wernert
|
f9c8f8cdca
|
[fix] Set SKIP_REBOOT on any failure during setup
|
2020-07-10 18:40:39 -04:00 |
|
William Wernert
|
aee304e5d5
|
[fix] master -> manager
|
2020-07-10 18:13:20 -04:00 |
|
William Wernert
|
4cfecae3b2
|
[ix] Remove grafanapassword pillar key
|
2020-07-10 17:59:51 -04:00 |
|
William Wernert
|
ce7373501b
|
[fix] Add fallback for hive + cortex users
|
2020-07-10 17:58:47 -04:00 |
|
William Wernert
|
571e97cdf7
|
Merge branch 'dev' into feature/setup
# Conflicts:
# salt/thehive/scripts/cortex_init
# salt/thehive/scripts/hive_init
# setup/so-functions
# setup/so-whiptail
|
2020-07-10 17:42:56 -04:00 |
|
William Wernert
|
547298fce0
|
[refactor] Hide output for cortex and thehive init scripts
|
2020-07-10 17:34:33 -04:00 |
|
weslambert
|
ef64048fc6
|
Merge pull request #978 from Security-Onion-Solutions/fix/sensor-clean
Fix value
|
2020-07-10 17:17:57 -04:00 |
|
weslambert
|
eb2dc0be4c
|
Fix value
|
2020-07-10 17:17:33 -04:00 |
|
Josh Patterson
|
69023cdb31
|
Merge pull request #976 from Security-Onion-Solutions/issue/404
Issue/404
|
2020-07-10 16:28:28 -04:00 |
|
m0duspwnens
|
13af4cacb0
|
merge with dev and resolve conflicts
|
2020-07-10 16:27:10 -04:00 |
|
Mike Reeves
|
755f47da2d
|
Merge pull request #975 from Security-Onion-Solutions/fix/lstemplate
Fix/lstemplate
|
2020-07-10 15:55:50 -04:00 |
|
Mike Reeves
|
46d572fa8c
|
Fix Filebeat spacing
|
2020-07-10 15:51:12 -04:00 |
|
weslambert
|
9b079df9f5
|
Merge pull request #974 from Security-Onion-Solutions/fix/sensor_clean
Fix/sensor clean
|
2020-07-10 15:35:57 -04:00 |
|
Wes Lambert
|
d7f7fb801c
|
Set role
|
2020-07-10 19:35:27 +00:00 |
|
Wes Lambert
|
37ab252e01
|
Add sensor proc eval
|
2020-07-10 19:30:08 +00:00 |
|
William Wernert
|
f56811e745
|
[feat] Use setup user+pass for TheHive, Cortex, and Fleet as well
|
2020-07-10 14:40:04 -04:00 |
|
William Wernert
|
67c8836cd6
|
[fix] Use 100GB min space for standalone also
|
2020-07-10 14:39:02 -04:00 |
|
William Wernert
|
72aa91b763
|
[feat] Add message in setup and motd on where to access SOC
|
2020-07-10 14:38:21 -04:00 |
|
m0duspwnens
|
9730c4561d
|
add elasticsearch pillar to manager
|
2020-07-10 14:08:39 -04:00 |
|
Jason Ertel
|
358ef78cd9
|
Do not stop curator since imported data will now be placed into a longer term so-import index
|
2020-07-10 13:58:52 -04:00 |
|
Jason Ertel
|
811bbb4cb0
|
Require sudo to run an import
|
2020-07-10 13:58:52 -04:00 |
|
weslambert
|
33375a0809
|
Merge pull request #973 from Security-Onion-Solutions/fix/curator_logsizelimit
Move zeek_clean to so-sensor-clean
|
2020-07-10 13:57:58 -04:00 |
|
Wes Lambert
|
6e99ca600f
|
Move zeek_clean to so-sensor-clean
|
2020-07-10 17:56:40 +00:00 |
|
Mike Reeves
|
5eb33d5ac7
|
Logstash Import and Template Assignment
|
2020-07-10 13:53:55 -04:00 |
|
m0duspwnens
|
24b8f81e38
|
merge with dev and resolve conflicts
|
2020-07-10 12:20:14 -04:00 |
|
Mike Reeves
|
bbef7955b2
|
Update eval.sls
|
2020-07-10 11:36:46 -04:00 |
|
Mike Reeves
|
9da4dd0ac9
|
Merge pull request #971 from Security-Onion-Solutions/feature/espillarz
Feature/espillarz
|
2020-07-10 11:35:24 -04:00 |
|
Mike Reeves
|
c656bec9c0
|
Merge branch 'dev' into feature/espillarz
|
2020-07-10 11:35:12 -04:00 |
|
m0duspwnens
|
0a1b5f29eb
|
merge with dev and resolv conflicts
|
2020-07-10 10:48:49 -04:00 |
|
m0duspwnens
|
1f48dc765e
|
merge with dev and resolv conflicts
|
2020-07-10 10:36:48 -04:00 |
|
Mike Reeves
|
3706aa76d8
|
Add jinja extension
|
2020-07-10 10:35:31 -04:00 |
|
Doug Burks
|
2ce254dfb0
|
add new DPD query to Hunt
|
2020-07-10 06:00:36 -04:00 |
|
Doug Burks
|
f5114c034d
|
change Log Type query in Hunt to include event.dataset in the groupby
|
2020-07-10 05:52:10 -04:00 |
|
Mike Reeves
|
1a6c4c12b4
|
Fix elasticsearch yaml
|
2020-07-09 21:56:32 -04:00 |
|
Jason Ertel
|
6bfd777d25
|
Enabled elastalert log
|
2020-07-09 21:34:35 -04:00 |
|
Mike Reeves
|
8ef18f9044
|
Fiz pillar
|
2020-07-09 18:51:59 -04:00 |
|
m0duspwnens
|
b2e7a4221c
|
master to manager for ssl signing policy
|
2020-07-09 17:19:17 -04:00 |
|
Mike Reeves
|
9a7035326d
|
Update Logstash pillar
|
2020-07-09 17:09:20 -04:00 |
|
m0duspwnens
|
9c2dcd2318
|
fix reference to master grain
|
2020-07-09 17:06:44 -04:00 |
|
Mike Reeves
|
ad6c9e7fe9
|
recurse actions for curator
|
2020-07-09 16:58:35 -04:00 |
|
Mike Reeves
|
6094d19b0b
|
Make hot default
|
2020-07-09 16:54:31 -04:00 |
|
Mike Reeves
|
3c6465bb7f
|
ES Jinja the config
|
2020-07-09 16:42:39 -04:00 |
|
Jason Ertel
|
33179141a1
|
Enable PCAP pivots from imports
|
2020-07-09 16:11:38 -04:00 |
|
m0duspwnens
|
5ca3ecf4bd
|
fix reference to master grain
|
2020-07-09 15:42:39 -04:00 |
|
Josh Brower
|
7b91704894
|
Merge pull request #970 from Security-Onion-Solutions/defensivedepth-patch-2-host-pillar
Update so-setup
|
2020-07-09 15:32:38 -04:00 |
|
Josh Brower
|
58d290aa57
|
Update so-setup
|
2020-07-09 15:32:19 -04:00 |
|
William Wernert
|
c5eff1d89e
|
[feat][WIP] Add option to run so-allow -a <ip/cidr> during setup
|
2020-07-09 14:47:55 -04:00 |
|
Josh Brower
|
206bdc60f3
|
Merge pull request #967 from Security-Onion-Solutions/feature/low-level-alerts
Feature - low level alerts
|
2020-07-09 13:56:31 -04:00 |
|
m0duspwnens
|
bdd0f64462
|
add period
|
2020-07-09 13:54:48 -04:00 |
|