Mike Reeves
3e248da14d
2.4.90
2024-07-29 11:37:42 -04:00
coreyogburn
ed7f8dbf1d
Merge pull request #13392 from Security-Onion-Solutions/cogburn/sodet-refresh-interval
...
so-detection refresh_interval => 1s
2024-07-25 14:10:39 -06:00
Corey Ogburn
d6af3aab6d
Use a wildcard instead of making 2 requests
2024-07-25 14:05:09 -06:00
Corey Ogburn
0cb067f6f2
Don't forget history
...
Also update so-detectionhistory to have a refresh_interval of 1s.
2024-07-25 14:01:10 -06:00
Corey Ogburn
ccf88fa62b
Add step to soup to set refresh_interval during upgrade
...
The so-detection index needs it's refresh_interval reset during an upgrade. If the index doesn't exist, the config change will set it correctly when it is created.
2024-07-25 13:44:22 -06:00
Corey Ogburn
20f915f649
so-detection refresh_interval => 1s
...
Speeds up the refresh_interval so bulk indexing a single rule does not wait 30s.
2024-07-25 12:53:04 -06:00
Mike Reeves
f447b6b698
Merge pull request #13390 from Security-Onion-Solutions/2.4.90
...
2.4.90
2024-07-25 11:55:59 -04:00
Mike Reeves
66b087f12f
2.4.90
2024-07-25 11:49:57 -04:00
weslambert
f2ad4c40e6
Fix update for 2.4.90
2024-07-24 10:38:05 -04:00
weslambert
8538f2eca2
Elastic Agent update
2024-07-24 09:40:30 -04:00
Wes
c55fa6dc6a
Fix pattern for pipelines
2024-07-23 17:48:32 +00:00
Wes
17f37750e5
Remove onchanges condition
2024-07-23 16:46:18 +00:00
Wes
e789c17bc3
Add global@custom pipeline file
2024-07-23 16:37:37 +00:00
Wes
6f44d39b18
Remove Fleet final pipeline file
2024-07-23 16:37:03 +00:00
Wes
dd85249781
Remove Fleet final pipeline
2024-07-23 16:36:41 +00:00
Wes
bdba621442
Remove soup changes
2024-07-23 16:32:28 +00:00
Mike Reeves
034315ed85
Turn off console messages
2024-07-23 09:46:51 -04:00
Jason Ertel
224c668c31
Merge pull request #13374 from Security-Onion-Solutions/jertel/rmtestparm
...
remove unused test parameters from setup
2024-07-22 11:08:34 -04:00
Jason Ertel
2e17e93cfe
remove unused test parameters from setup
2024-07-22 11:04:45 -04:00
Jason Ertel
7dfb75ba6b
remove unused test parameters from setup
2024-07-22 11:02:56 -04:00
Mike Reeves
af0425b8f1
Update rulecat.conf
2024-07-22 10:20:30 -04:00
Mike Reeves
6cf0a0bb42
Update so-rule-update
2024-07-22 10:19:34 -04:00
Jorge Reyes
d97400e6f5
Merge pull request #13368 from Security-Onion-Solutions/reyesj2/kfps
...
fix kafka-logstash cert for searchnodes
2024-07-21 20:11:42 -04:00
reyesj2
cf1335dd84
searchnode logstash-kafka cert generation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-20 11:31:33 -04:00
coreyogburn
be74449fb9
Merge pull request #13365 from Security-Onion-Solutions/cogburn/suricata-regex-support
...
Cogburn/suricata regex support
2024-07-19 12:47:10 -06:00
Corey Ogburn
45b2413175
Removed Allow/Deny Regexes, Added Enable/Disable Regex
...
Update config and annotations for new regex support for suricata.
2024-07-19 12:45:24 -06:00
Corey Ogburn
022df966c7
Remove Allow/Deny Regex, Add Suricata Enable/Disable Regex
2024-07-19 12:28:04 -06:00
Jorge Reyes
92385d652e
Merge pull request #13363 from Security-Onion-Solutions/reyesj2/ksoup
...
kafka soup pillar
2024-07-19 10:50:48 -04:00
reyesj2
4478d7b55a
kafka soup pillar fix
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-19 09:32:47 -04:00
Wes
612716ee69
Apply ES to load pipelines
2024-07-17 17:35:41 +00:00
Wes
f78a5d1a78
Remove pipeline file
2024-07-17 15:42:40 +00:00
Wes
2d0de87530
Add component templates for Fleet metrics
2024-07-17 15:19:46 +00:00
Josh Patterson
18df491f7e
Merge pull request #13355 from Security-Onion-Solutions/silsll
...
Exclude policy phases if not defined in defaults
2024-07-17 11:09:18 -04:00
m0duspwnens
cee6ee7a2a
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-17 10:16:36 -04:00
m0duspwnens
6d18177f98
only include global phases if defined in default for that index
2024-07-17 10:16:11 -04:00
weslambert
c0bb395571
Remove pipeline file removal
2024-07-17 09:51:51 -04:00
weslambert
f051ddc7f0
Remove pipelines
2024-07-17 09:50:26 -04:00
m0duspwnens
72ad49ed12
add policy for so-lists and so-items
2024-07-16 14:36:06 -04:00
Jorge Reyes
d11f4ef9ba
Merge pull request #13350 from Security-Onion-Solutions/reyesj2/kflux
...
Kafka influxdb metrics & pillar update
2024-07-16 14:26:09 -04:00
reyesj2
03ca7977a0
quote variables
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-16 14:14:55 -04:00
m0duspwnens
91b2e7d400
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-16 14:06:56 -04:00
m0duspwnens
34c3a58efe
add cold policy
2024-07-16 14:03:48 -04:00
Josh Patterson
a867557f54
Merge pull request #13353 from Security-Onion-Solutions/fci
...
fix custom indices
2024-07-16 13:18:11 -04:00
m0duspwnens
b814f32e0a
fix custom indices
2024-07-16 12:39:30 -04:00
coreyogburn
2df44721d0
Merge pull request #13349 from Security-Onion-Solutions/cogburn/bulk-indexer
...
New Config Values for Detections Bulk Indexer
2024-07-15 15:34:01 -06:00
Corey Ogburn
d0565baaa3
New Config Values for Detections Bulk Indexer
...
`maxScrollSize` defines the "page size" of each scroll request.
`bulkIndexerWorkerCount` defines how many worker threads a bulk indexer should use. 0 or fewer indicates that 1 thread per CPU core should be used.
2024-07-15 14:43:47 -06:00
weslambert
38e7da1334
Merge pull request #13347 from Security-Onion-Solutions/upgrade/elastic_8_14_3
...
Elastic 8.14.3
2024-07-15 16:29:24 -04:00
reyesj2
1b623c5c7a
Show Kafka EPS for nodes with broker role only
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:27:48 -04:00
reyesj2
542a116b8c
use so-yaml add for kafka pillar change
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:26:52 -04:00
Doug Burks
e7b6496f98
Merge pull request #13348 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346
2024-07-15 15:59:49 -04:00