Corey Ogburn
1b7095fa81
Improved import-file url regex
...
sed doesn't remove ALL whitespace, only newlines. It's better to stop at the first whitespace than to stop at a particular, maybe-not-last query string parameter.
2023-06-20 09:41:14 -06:00
Corey Ogburn
89d789fe0f
New folder for salt to maintain
...
This folder is where a manager will initially store uploaded PCAP/EVTX files before sending to sensors. Sensors will store uploads in this folder on their own system.
2023-06-20 09:41:14 -06:00
Corey Ogburn
49055e260f
salt-relay import-file reporting
...
On successful import, return dashboard URL
2023-06-20 09:41:14 -06:00
Corey Ogburn
a465039887
2 new capabilities: send-file and import-file
2023-06-20 09:41:14 -06:00
Doug Burks
b60cf29598
Merge pull request #10618 from Security-Onion-Solutions/dougburks-patch-1
...
Resolve conflicts with dataset PR
2023-06-20 07:42:30 -04:00
Doug Burks
0e09d73aa0
Resolve conflicts with dataset PR
2023-06-20 07:40:10 -04:00
Doug Burks
520a5671ca
Merge pull request #10617 from Security-Onion-Solutions/dougburks-patch-1
...
Fix SOC Auth queries in Dashboards and Hunt
2023-06-20 07:32:46 -04:00
Doug Burks
fc824359ed
Update default fields for kratos.audit
2023-06-20 07:30:56 -04:00
Doug Burks
7caa7cec6b
Fix SOC Auth queries in Dashboards and Hunt
...
Change `event.dataset:audit` to `event.dataset:kratos.audit`.
2023-06-20 07:13:33 -04:00
Josh Patterson
0695140f83
Merge pull request #10611 from Security-Onion-Solutions/2.4/ubuntu
...
2.4/ubuntu
2023-06-16 14:00:52 -04:00
m0duspwnens
ed1e2c8908
ignore failure notification for Ubuntu Failed to restart snapd
2023-06-16 13:58:45 -04:00
Jason Ertel
594900a8d4
Merge pull request #10609 from Security-Onion-Solutions/kilo
...
webauthn for SOC
2023-06-16 13:15:25 -04:00
Jason Ertel
6894fa4e4d
Update VERSION
2023-06-16 13:09:01 -04:00
m0duspwnens
2334d82d36
fix salt install for ubuntu
2023-06-16 11:13:34 -04:00
Doug Burks
251bc6f45e
Merge pull request #10597 from Security-Onion-Solutions/dougburks-patch-1
...
Update so_motd.jinja
2023-06-15 09:59:25 -04:00
Doug Burks
b84d997f87
Update so_motd.jinja
2023-06-15 09:54:23 -04:00
Jason Ertel
b4e5ac9796
Add note to advise against changing settings
2023-06-14 16:11:50 -04:00
Jason Ertel
a88227d13f
Merge branch '2.4/dev' into kilo
2023-06-14 13:34:15 -04:00
Jason Ertel
21a7b76352
webauthn
2023-06-14 13:33:31 -04:00
weslambert
03082339ca
Merge pull request #10592 from Security-Onion-Solutions/fix/analyzer_dependencies
...
Update analyzer dependencies
2023-06-14 12:22:06 -04:00
Josh Brower
fa57494694
Merge pull request #10584 from Security-Onion-Solutions/2.4/elasticagent-renaming
...
Change Elastic Fleet Tarball naming
2023-06-14 09:42:57 -04:00
weslambert
3f1741e75a
Merge pull request #10585 from Security-Onion-Solutions/fix/elasticsearch_templates
...
Update Elasticsearch templates for Fleet
2023-06-14 09:33:23 -04:00
Wes
48331ce35b
Add system.system component templates
2023-06-14 13:29:11 +00:00
Wes
c2ac60b82e
Add system.system template and add event-mappings
2023-06-14 13:28:00 +00:00
Josh Brower
fedfbe9fec
Fix tarball output name
2023-06-14 08:52:56 -04:00
Josh Brower
9947f9def4
Rework tarball naming schema
2023-06-14 07:38:03 -04:00
Wes
c205438771
Update dependencies
2023-06-14 02:35:29 +00:00
Wes
8cde05807c
Remove elastic-agent dir
2023-06-13 21:33:04 +00:00
Wes
2ac0aba916
Add osquery files
2023-06-13 21:32:02 +00:00
Wes
af003cc2a1
Add osquery templates
2023-06-13 20:43:39 +00:00
Josh Brower
0d4f6b4fe6
Change Elastic Fleet Tarball naming
2023-06-13 16:32:19 -04:00
Jason Ertel
7093254439
Merge pull request #10582 from Security-Onion-Solutions/jertel/pcap
...
ensure status line shows dates for new and existing imports
2023-06-13 15:16:43 -04:00
Wes
bd7644a557
Add another template
2023-06-13 19:13:20 +00:00
Jason Ertel
90b740a997
ensure status line shows dates for new and existing imports
2023-06-13 15:11:13 -04:00
Wes
5547a1b7ab
Add event mappings
2023-06-13 18:23:50 +00:00
Wes
1b90fd8581
Add custom component templates
2023-06-13 18:21:45 +00:00
Doug Burks
bbdf7bb5a7
Merge pull request #10580 from Security-Onion-Solutions/dougburks-patch-1
...
Set START and END variables earlier in so-import-pcap
2023-06-13 13:31:16 -04:00
Doug Burks
fb8ad71b27
Set START and END variables earlier in so-import-pcap
2023-06-13 13:19:18 -04:00
Wes
e43b7607bb
Add more component templates
2023-06-13 17:04:03 +00:00
Wes
a265c06e31
Add other component templates
2023-06-13 15:47:25 +00:00
Wes
2aa954cb0a
Add component templates
2023-06-13 15:25:23 +00:00
Wes
73812b11a3
Allow ingest node pipelines that start with a period
2023-06-13 13:37:56 +00:00
Wes
38ab426470
Add final Fleet pipeline
2023-06-13 13:36:26 +00:00
Wes
d0a6881c2c
Add event mappings and remove meta information for now
2023-06-13 13:35:46 +00:00
Wes
57268ba934
Change priority of templates
2023-06-12 14:29:45 +00:00
Wes
1208915896
Remove Elastic Agent package templates
2023-06-12 14:24:59 +00:00
Wes
42f5ad9939
Add templates for system.auth and systen.syslog
2023-06-12 14:23:24 +00:00
Doug Burks
8e0d895afb
Merge pull request #10572 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Add more Zeek logs to excluded list #10569
2023-06-12 09:33:13 -04:00
Doug Burks
998c85e3f8
Update defaults.yaml
2023-06-12 09:31:19 -04:00
weslambert
32f3ee0b01
Merge pull request #10564 from Security-Onion-Solutions/fix/elasticsearch_templates
...
Update templates for integrations
2023-06-12 09:05:31 -04:00