Commit Graph

1536 Commits

Author SHA1 Message Date
Wes Lambert 81da44b85d fix Logstash Eval SLS 2020-03-15 00:32:29 +00:00
Wes Lambert 26c4d453d3 Add ES templates script 2020-03-15 00:30:59 +00:00
Wes Lambert 85c1873f4d switch logging to error 2020-03-14 12:10:06 +00:00
Wes Lambert b6ba8e483d update ES init 2020-03-14 12:06:32 +00:00
Wes Lambert d2016d3ff2 modify Filebeat config 2020-03-14 12:05:16 +00:00
Wes Lambert c52220330b modify pipelines 2020-03-14 12:03:32 +00:00
Wes Lambert d48c2723ba modify default templates 2020-03-14 12:02:52 +00:00
Wes Lambert 9fb3a47358 modify default templates 2020-03-14 12:02:42 +00:00
Wes Lambert ffc33b15e5 switch to Filebeat 2020-03-14 12:00:17 +00:00
m0duspwnens 2bda1f4beb remove whitespace 2020-03-13 16:12:16 -04:00
m0duspwnens 1db9692c6b allow all zeekctl configuration options to be defined - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/97 2020-03-13 16:10:42 -04:00
m0duspwnens a21ffaecc8 add option to compress archived logs for zeekctl - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/97 2020-03-13 15:05:25 -04:00
m0duspwnens da8811bc87 restart zeek docker if zeekctl.cfg changes 2020-03-13 14:44:56 -04:00
m0duspwnens 1b7e22d5bd fix couple minor issue - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/97 2020-03-13 14:41:16 -04:00
m0duspwnens 8e82633772 fix missing : in playbook state 2020-03-13 13:45:29 -04:00
m0duspwnens f9cf04e14e fix couple minor issue - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/97 2020-03-13 13:42:28 -04:00
m0duspwnens bc6aab5b22 add zeekctl.cfg docker file bind 2020-03-13 13:23:27 -04:00
m0duspwnens 3aa48b1a23 first go at managing zeekctl.cfg - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/97 2020-03-13 13:20:48 -04:00
m0duspwnens 7ea0b2c284 add salt cron identifiers - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/134 2020-03-13 08:38:45 -04:00
m0duspwnens 2d91851c34 fix spacing for titles in grafana dashboard - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/362 2020-03-13 08:08:51 -04:00
Josh Patterson 8b0509aa4a Merge pull request #415 from Security-Onion-Solutions/issue/136
Issue/136
2020-03-12 17:46:38 -04:00
m0duspwnens 804a87eb21 append role to minion id and use it to target in top - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/136 2020-03-12 17:42:32 -04:00
Wes Lambert 648b0ba790 remove old config 2020-03-11 12:14:22 +00:00
Wes Lambert 9ad16e8c71 upadte ingest config 2020-03-11 12:13:53 +00:00
Wes Lambert f9e4d218ec update config 2020-03-11 12:13:11 +00:00
Wes Lambert 70e78a0642 add renamed templates 2020-03-11 12:12:32 +00:00
weslambert 14dfec5365 Change to bro template 2020-03-09 09:18:57 -04:00
Josh Brower e3916e5de2 Merge pull request #406 from Security-Onion-Solutions/feature/playbook-alerting
Playbook - Schedule Playbook rule updates
2020-03-09 08:58:39 -04:00
Josh Brower a96465383f Schedule Playbook rule updates 2020-03-09 08:57:31 -04:00
Wes Lambert aeb298a818 fix typo 2020-03-06 18:49:29 +00:00
Wes Lambert 84df1db201 fix repo name 2020-03-06 17:45:16 +00:00
Wes Lambert ed8adcae5a add files back 2020-03-06 17:28:05 +00:00
Wes Lambert 6af6d7f5b6 fix typo 2020-03-06 16:17:04 +00:00
Wes Lambert 627d89c481 fix webhook 2020-03-06 16:16:02 +00:00
Wes Lambert 0bf125e88e add Node scripts 2020-03-06 13:47:21 +00:00
Wes Lambert 19cff23a2b restructure files 2020-03-06 13:14:52 +00:00
Wes Lambert 8bac9118fb add flows 2020-03-06 13:13:34 +00:00
Wes Lambert 32f8d7c793 update init 2020-03-06 13:11:00 +00:00
Wes Lambert 73cbadfe5c add complete directory to extracted 2020-03-05 15:49:22 +00:00
Wes Lambert ee611d44cf update file extraction script 2020-03-05 15:48:28 +00:00
Josh Patterson 79210a07da Merge pull request #396 from Security-Onion-Solutions/issue/326
fix issue with salt not removing pipeline configs or templates if removed from pillar
2020-03-04 10:14:57 -05:00
m0duspwnens 28c4bb4b22 fix issue with salt not removing pipeline configs or templates if removed from pillar 2020-03-04 10:12:28 -05:00
Wes Lambert a0522943f7 fix path 2020-03-03 22:40:46 +00:00
Wes Lambert a8a93260a9 add file extraction 2020-03-03 22:40:06 +00:00
Wes Lambert b1203cfb9f add initial Strelka ingest config 2020-03-03 21:20:45 +00:00
Wes Lambert 4939884d93 Update Strelka init 2020-03-02 22:15:55 +00:00
Wes Lambert bbebc4fc9b Add src/dst objects and Bro template 2020-03-02 20:02:39 +00:00
Wes Lambert ec6638a276 src/dst ip/port fields to ECS 2020-03-02 19:10:18 +00:00
Wes Lambert e4fee51ed6 Change Bro Files source to file_source 2020-03-02 19:09:24 +00:00
Wes Lambert 9eb5a9be3a Begin switch to ECS for Suricata 2020-03-02 19:07:40 +00:00