Doug Burks
|
3f62cddc3b
|
change . to _
|
2022-11-23 12:21:12 -05:00 |
|
Doug Burks
|
085420997c
|
move status_code before status_code.link_id
|
2022-11-23 12:11:04 -05:00 |
|
Doug Burks
|
0a1d0d35c8
|
fix description
|
2022-11-23 11:33:31 -05:00 |
|
Doug Burks
|
9ee96f2280
|
fix description
|
2022-11-23 11:32:09 -05:00 |
|
doug
|
bc620b7def
|
fix zeek opcua pipelines
|
2022-11-23 10:56:32 -05:00 |
|
weslambert
|
3a64362887
|
Remove extra space used during testing
|
2022-11-22 15:47:16 -05:00 |
|
Wes
|
e77a60bcbf
|
Add missing OPCUA 'activate_session' pipelines
|
2022-11-22 20:44:48 +00:00 |
|
weslambert
|
3c054fd133
|
Fix spelling of 'wireguard.responses' field name
|
2022-11-22 13:02:43 -05:00 |
|
weslambert
|
8e17c23659
|
Fix format/speliing for 'enip.status_code' field name
|
2022-11-22 12:05:03 -05:00 |
|
weslambert
|
92170941f0
|
Fix spelling for 'stun.class' field name
|
2022-11-22 12:04:07 -05:00 |
|
Wes
|
95a6f9aa7d
|
Add COTP and TDS ingest pipelines
|
2022-11-22 13:35:19 +00:00 |
|
Peter Di Giorgio
|
33bf0c6902
|
Merge pull request #9163 from Security-Onion-Solutions/dev
Update Foxtrot from Dev
|
2022-11-17 10:44:24 -06:00 |
|
Wes
|
a278194037
|
Add additional ICS/SCADA ingest node pipelines
|
2022-11-17 16:16:33 +00:00 |
|
Wes
|
35e131b888
|
Update ingest node pipelines for ICS/SCADA protocols
|
2022-11-16 21:09:30 +00:00 |
|
lock-wire
|
73b1e5949b
|
Add ecat, enip, cip, and opcua
|
2022-11-11 12:15:54 -08:00 |
|
lock-wire
|
85d30520ce
|
Add BSAP protocol
|
2022-11-11 07:22:55 -08:00 |
|
Peter Di Giorgio
|
5ebf470a86
|
Update zeek.bacnet_discovery
|
2022-11-03 22:27:04 -07:00 |
|
Peter Di Giorgio
|
4b39ccec6d
|
Update zeek.bacnet_property
|
2022-11-03 15:30:20 -07:00 |
|
Peter Di Giorgio
|
b97c822800
|
Add zeek.bacnet_discovery and zeek.bacnet_property
|
2022-10-27 15:40:52 -07:00 |
|
Peter Di Giorgio
|
71e3b2d1fb
|
Create zeek.bacnet
|
2022-10-27 15:40:07 -07:00 |
|
Peter Di Giorgio
|
2b51d72585
|
Rename zeek.read_write_multiple_registers to zeek.modbus_read_write_multiple_registers
|
2022-10-25 17:20:01 -07:00 |
|
Peter Di Giorgio
|
7a60d0987c
|
Update zeek.conn to include client.oui
|
2022-10-21 13:02:01 -07:00 |
|
Peter Di Giorgio
|
9ac06057c1
|
Create zeek.read_write_multiple_registers
|
2022-10-21 13:00:12 -07:00 |
|
Peter Di Giorgio
|
e5c69c3236
|
Create zeek.modbus_mask_write_register
|
2022-10-21 12:58:36 -07:00 |
|
Peter Di Giorgio
|
39f050c6e4
|
Rename modbus_detailed to zeek.modbus_detailed
|
2022-10-21 12:56:59 -07:00 |
|
Peter Di Giorgio
|
4ee083759c
|
Rename dnp3_objects to zeek.dnp3_objects
|
2022-10-21 12:56:35 -07:00 |
|
Peter Di Giorgio
|
072bfd87b7
|
Create Ingest for Modbus Detailed
|
2022-10-21 12:53:30 -07:00 |
|
Peter Di Giorgio
|
b7aaaa80bb
|
Create Ingest for DNP3 Objects extension
|
2022-10-21 12:51:13 -07:00 |
|
bryant-treacle
|
82dff3e9da
|
Fix issues: 8591-8953
|
2022-08-30 13:48:53 +00:00 |
|
weslambert
|
8c694a7ca3
|
Disable ingest.geoip.downloader by default
|
2022-08-03 09:21:40 -04:00 |
|
weslambert
|
9ac640fa67
|
Remove airgap-specific logic for ingest.geoip.downloader
|
2022-08-03 09:21:03 -04:00 |
|
Wes Lambert
|
839cfcaefa
|
Update Elasticsearch defaults file and config.map.jinja to allow for local GeoIP database use when airgap is enabled
|
2022-08-02 14:32:17 +00:00 |
|
weslambert
|
2914007393
|
Add forward slash to fix issue with missing query path
|
2022-07-18 09:07:34 -04:00 |
|
Wes Lambert
|
b06c16f750
|
Add ingest node pipeline for Kratos
|
2022-07-08 15:53:00 +00:00 |
|
Mike Reeves
|
8b3d5e808e
|
Fix repo location
|
2022-06-30 13:30:56 -04:00 |
|
Mike Reeves
|
e86b7bff84
|
Fix repo location
|
2022-06-30 13:29:21 -04:00 |
|
weslambert
|
44595cb333
|
Merge pull request #8123 from Security-Onion-Solutions/foxtrot
Merge foxtrot into dev
|
2022-06-14 15:44:13 -04:00 |
|
doug
|
025993407e
|
FIX: Add event.category field to pfsense firewall logs #8112
|
2022-06-13 08:03:44 -04:00 |
|
Josh Brower
|
8e368bdebe
|
Merge in upstream dev
|
2022-05-06 20:01:07 -04:00 |
|
weslambert
|
542db5b7f5
|
Update defaults.yaml
|
2022-04-21 17:24:24 -04:00 |
|
Josh Brower
|
2b39570b08
|
Fix matching logic
|
2022-04-18 10:37:38 -04:00 |
|
Josh Brower
|
886d69fb38
|
Compress + Clean ES & Logstash App Logs
|
2022-04-11 16:09:24 -04:00 |
|
weslambert
|
e6599cd10e
|
Update with changes from Abe's PR and other fixes
|
2022-03-25 13:57:44 -04:00 |
|
weslambert
|
c02d7fab50
|
Merge pull request #7636 from Security-Onion-Solutions/feature/rita
Parsing of RITA Logs
|
2022-03-24 13:05:22 -04:00 |
|
Wes Lambert
|
fe1b72655b
|
Additional .keyword shims for process mappings
|
2022-03-24 16:45:06 +00:00 |
|
weslambert
|
1f2bca599f
|
Check cluster health before trying to load roles for ES
|
2022-03-23 11:00:26 -04:00 |
|
Wes Lambert
|
2487d468ab
|
Add RITA Elasticsearch ingest pipeline config
|
2022-03-22 17:38:22 +00:00 |
|
weslambert
|
7128b04636
|
Remove indices.query.bool.max_clause_count because it is dynamically allocated in Elastic 8
|
2022-03-17 21:20:41 -04:00 |
|
Wes Lambert
|
42d6c3a956
|
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
|
2022-03-15 14:55:04 +00:00 |
|
Wes Lambert
|
5f56c7a261
|
Replace ELASTICCURL with so-elasticsearch-query
|
2022-03-15 14:32:00 +00:00 |
|