Josh Brower
|
97a3f130c8
|
Update Elastic
|
2025-01-23 15:32:39 -05:00 |
|
reyesj2
|
5b8f8fb62f
|
add/remove es annotations/defaults automagically
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-23 12:47:22 -06:00 |
|
m0duspwnens
|
213df68d04
|
merge with 120 dev and fix conflicts
|
2025-01-23 10:56:48 -05:00 |
|
Josh Brower
|
9738ef382c
|
Upgrade Elastic to 8.17.1
|
2025-01-23 08:12:02 -05:00 |
|
Jason Ertel
|
ca0c1170ab
|
Merge pull request #14140 from Security-Onion-Solutions/jertel/wip
fix issue with first-time api client permission toggling
|
2025-01-22 17:43:54 -05:00 |
|
Jason Ertel
|
db9387764d
|
fix issue with first-time api client permission toggling
|
2025-01-22 17:41:04 -05:00 |
|
reyesj2
|
e0039a08ef
|
fix forcedType typo
|
2025-01-22 13:57:26 -06:00 |
|
Jorge Reyes
|
09df4a5771
|
Merge pull request #14139 from Security-Onion-Solutions/reyesj2/es-integ-tmp
fixes merging local pillar /global overrides for generated index temp…
|
2025-01-22 13:12:53 -06:00 |
|
reyesj2
|
81ac1ebc08
|
fixes merging local pillar /global overrides for generated index templates
|
2025-01-22 13:12:09 -06:00 |
|
Jorge Reyes
|
c2f5c2226f
|
Merge pull request #14138 from Security-Onion-Solutions/reyesj2/es-integ-tmp
add back missing component for http_endpoint_x_generic & winlog_x_win…
|
2025-01-22 10:16:30 -06:00 |
|
reyesj2
|
d779f7ae7f
|
add back missing component for http_endpoint_x_generic & winlog_x_winglog
|
2025-01-22 10:15:16 -06:00 |
|
Jorge Reyes
|
d26c7e6f9b
|
Merge pull request #14134 from Security-Onion-Solutions/reyesj2/es-integ-tmp
remove individual <integration>@custom mappings. Moved over to so-fle…
|
2025-01-21 11:00:18 -06:00 |
|
reyesj2
|
6331298eac
|
remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1
|
2025-01-21 10:49:54 -06:00 |
|
reyesj2
|
76abf37351
|
Merge remote-tracking branch 'origin/2.4/dev' into foxtrot
|
2025-01-21 09:03:04 -06:00 |
|
m0duspwnens
|
9db3cd901c
|
update documentation of core functionality
|
2025-01-18 10:45:10 -05:00 |
|
m0duspwnens
|
64c9230423
|
prevent conflicts with network manager in base vm
|
2025-01-18 10:44:44 -05:00 |
|
m0duspwnens
|
17943ef0db
|
add hypervisor state to hypervisor node
|
2025-01-18 08:24:50 -05:00 |
|
m0duspwnens
|
8ed3f0b1cc
|
change base image path for so-salt-cloud
|
2025-01-18 07:30:36 -05:00 |
|
m0duspwnens
|
7c50a5e17b
|
cloud-init needs to import repo gpg keys so packags can install
|
2025-01-17 23:16:18 -05:00 |
|
m0duspwnens
|
c13c85bd2d
|
manager needs ssh config. need -r to ignore bootstrap provided repos
|
2025-01-17 22:54:46 -05:00 |
|
m0duspwnens
|
ae01dc9639
|
manager needs more packages for salt-cloud. change location of priv key for salt-cloud config
|
2025-01-17 22:26:39 -05:00 |
|
m0duspwnens
|
a74ed0daf0
|
fix disabling cloud-init and system shutdown. increase ram/cpu of base vm. shrink disk_size to 6G for testing
|
2025-01-17 21:25:40 -05:00 |
|
m0duspwnens
|
60387651d2
|
recreate the base vm if any of the cloud init files change
|
2025-01-17 20:13:42 -05:00 |
|
m0duspwnens
|
3a78be68d6
|
ensure cloud-init is removed
|
2025-01-17 20:05:35 -05:00 |
|
m0duspwnens
|
a896332db3
|
fix deprecation
|
2025-01-17 19:49:41 -05:00 |
|
m0duspwnens
|
54eeb0e327
|
handle refreshing base image and reinstalling the vm if the source qcow2 image changes
|
2025-01-17 19:27:04 -05:00 |
|
Jorge Reyes
|
704e30219a
|
Merge pull request #14124 from Security-Onion-Solutions/reyesj2-patch-8
keep imported data in logs-import-so index
|
2025-01-17 13:33:26 -06:00 |
|
reyesj2
|
1396083b7d
|
use so-elasticsearch-query where possible; simplify suricata.alerts index reroute
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 13:29:46 -06:00 |
|
Jason Ertel
|
7017024ba7
|
Merge pull request #14123 from Security-Onion-Solutions/jertel/wip
Additional web security measures
|
2025-01-17 12:31:42 -05:00 |
|
Jorge Reyes
|
942c1aa3a6
|
Merge pull request #14126 from Security-Onion-Solutions/reyesj2/es-integ-tmp
merge dev
|
2025-01-17 11:24:31 -06:00 |
|
reyesj2
|
d35ffef503
|
merge 2.4/dev
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 11:23:54 -06:00 |
|
Jason Ertel
|
7705f45d78
|
Revert "subgrid config annotations"
This reverts commit 3ab1b907e4.
|
2025-01-17 12:16:12 -05:00 |
|
Jason Ertel
|
964bbe6aa5
|
additional web server security measures
|
2025-01-17 12:14:30 -05:00 |
|
reyesj2
|
01a2e4cd4f
|
check for index existence before attemping rollover
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 09:27:28 -06:00 |
|
m0duspwnens
|
1f13554bd9
|
move add virt install and pool creation to images/init. start moving to /nsm/libvirt/
|
2025-01-17 09:43:39 -05:00 |
|
reyesj2
|
9032d7d7bc
|
any suricata.alert with event.imported: true remains in logs-import-so
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 18:48:31 -06:00 |
|
reyesj2
|
d573c0922d
|
add 2.4.111 -> postupgrade check
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 18:25:06 -06:00 |
|
reyesj2
|
45d3438d18
|
update ingest pipeline for imported logs
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 17:33:14 -06:00 |
|
m0duspwnens
|
4cc3691489
|
give all nodes access to soc license pillar file
|
2025-01-16 17:51:39 -05:00 |
|
m0duspwnens
|
24eadf2507
|
add libvirt state to highstate for hypervisor. update allowed_states for libvirt
|
2025-01-16 17:46:20 -05:00 |
|
m0duspwnens
|
a274bfb744
|
license note
|
2025-01-16 17:45:07 -05:00 |
|
m0duspwnens
|
2277c792b9
|
update feature error logging in so-minion
|
2025-01-16 17:13:36 -05:00 |
|
m0duspwnens
|
61f5614ac9
|
added logging and error handling so-minion
|
2025-01-16 16:57:36 -05:00 |
|
m0duspwnens
|
6367aed62a
|
reactor needs to match runner function parameter structure
|
2025-01-16 14:59:11 -05:00 |
|
m0duspwnens
|
739f592061
|
remove old line of code
|
2025-01-16 14:06:01 -05:00 |
|
m0duspwnens
|
116c2b73c1
|
update gitignore
|
2025-01-16 11:16:34 -05:00 |
|
m0duspwnens
|
58be7ae5db
|
rename from coreol9 or coreol9Small to sool9
|
2025-01-16 11:16:20 -05:00 |
|
m0duspwnens
|
0e0fb885d2
|
hypervisor highstate after image creation, not when key accepted
|
2025-01-16 11:13:36 -05:00 |
|
m0duspwnens
|
e8546b82f8
|
default image: sool9. cloud-init add local repo
|
2025-01-16 08:43:46 -05:00 |
|
m0duspwnens
|
837fbab96d
|
minimize packages installed on manager for hyper
|
2025-01-15 17:00:06 -05:00 |
|