Mike Reeves
|
1d45472b48
|
Fix Strelka Rule updates, repo fix
|
2021-02-24 11:30:43 -05:00 |
|
Mike Reeves
|
54367db99b
|
Merge pull request #3108 from Security-Onion-Solutions/issue/3056
add estimated EPS graphs to Grafana for manager, mastersearch and standalone nodes
|
2021-02-24 08:49:36 -05:00 |
|
Mike Reeves
|
56daae64be
|
Merge pull request #3097 from Security-Onion-Solutions/sometacleanup
Clean up on sid numbers
|
2021-02-24 08:24:48 -05:00 |
|
Mike Reeves
|
00deab9305
|
Merge pull request #3100 from Security-Onion-Solutions/kilo
Add so-preflight + usage to so-monitor-add, fix managersearch missing from so-rule
|
2021-02-23 17:32:41 -05:00 |
|
Mike Reeves
|
fa6fd20ff9
|
Merge pull request #3088 from Security-Onion-Solutions/soupairgap
Syn the latest rules on an airgap install
|
2021-02-23 17:31:29 -05:00 |
|
Mike Reeves
|
d195efa8e5
|
Merge pull request #3098 from Security-Onion-Solutions/feature/update-soup
Update SOUP with so-playbook-sigma-refresh
|
2021-02-23 15:46:48 -05:00 |
|
Josh Brower
|
a7eb3cd38d
|
Add so-playbook-sigma-refresh
|
2021-02-23 15:43:09 -05:00 |
|
Mike Reeves
|
5baa4cb6a5
|
Clean up on sid numbers
|
2021-02-23 15:42:58 -05:00 |
|
William Wernert
|
a361ca0e19
|
[fix] Add managersearch node type to so-rule pillar search
|
2021-02-23 14:15:17 -05:00 |
|
William Wernert
|
9cf15cdae5
|
[fix] Reword so-monitor-add help message
|
2021-02-23 13:55:18 -05:00 |
|
William Wernert
|
d5477b4721
|
Add usage/help message to so-monitor-add
|
2021-02-23 13:48:54 -05:00 |
|
William Wernert
|
5a2fa26d72
|
Add ET OPEN/PRO URLs
|
2021-02-23 13:47:52 -05:00 |
|
William Wernert
|
61a23509a1
|
[fix] grep -q doesn't give output to parse, so remove the flag
|
2021-02-23 13:43:10 -05:00 |
|
William Wernert
|
25698dafe3
|
Add initial pre-flight check script
|
2021-02-23 13:25:54 -05:00 |
|
Mike Reeves
|
186710964b
|
Fix Airgap Rule Path
|
2021-02-23 13:07:23 -05:00 |
|
Mike Reeves
|
3b32eb539f
|
Copy latest rules when using airgaps
|
2021-02-23 11:21:23 -05:00 |
|
m0duspwnens
|
6ee69ff21b
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/3056
|
2021-02-23 11:11:50 -05:00 |
|
m0duspwnens
|
00cc640224
|
add EPS to managersearch dashboard
|
2021-02-23 11:08:08 -05:00 |
|
Mike Reeves
|
40721d7dec
|
Merge pull request #3084 from Security-Onion-Solutions/feature/log-rotate
Configure fleet result.log to rotate
|
2021-02-23 10:20:53 -05:00 |
|
m0duspwnens
|
e76ee07932
|
add CPUS for cpu count
|
2021-02-23 10:10:58 -05:00 |
|
Josh Brower
|
122e34b69c
|
Configure fleet result.log to rotate
|
2021-02-23 10:06:24 -05:00 |
|
m0duspwnens
|
1f2475c1c5
|
add eps graph to manager
|
2021-02-23 10:06:11 -05:00 |
|
m0duspwnens
|
141fbaced1
|
add eps graph to standalone
|
2021-02-23 09:40:21 -05:00 |
|
William Wernert
|
fa9fe82046
|
Merge pull request #3082 from Security-Onion-Solutions/kilo
Add so-rule script + soup pillar changes
|
2021-02-23 08:56:49 -05:00 |
|
William Wernert
|
fad87a8789
|
Fix function name (.20 -> .2X)
|
2021-02-23 08:51:44 -05:00 |
|
William Wernert
|
9287209750
|
Merge branch 'soup2.3.30' into feature/so-rules
# Conflicts:
# salt/common/tools/sbin/soup
|
2021-02-22 16:07:15 -05:00 |
|
William Wernert
|
982967fdde
|
Merge branch 'dev' into feature/so-rules
|
2021-02-22 16:01:48 -05:00 |
|
William Wernert
|
fb3af255d9
|
Add more info to apply messaging
|
2021-02-22 15:50:07 -05:00 |
|
William Wernert
|
3e3c923ab9
|
Arrange missing pillar error message better
|
2021-02-22 15:44:29 -05:00 |
|
William Wernert
|
b00cc88801
|
[fix] Unreverse apply prompt actions
|
2021-02-22 15:43:56 -05:00 |
|
William Wernert
|
e9b85337ff
|
[fix] Only prompt if entry doesn't exist, deep compare arrays
|
2021-02-22 15:41:09 -05:00 |
|
William Wernert
|
fd33a6cebe
|
Rename script, prompt user to apply if they didn't pass --apply
|
2021-02-22 15:32:18 -05:00 |
|
William Wernert
|
cdf766eeae
|
explicitely -> explicitly
|
2021-02-22 14:30:26 -05:00 |
|
William Wernert
|
8fc82fa3ef
|
Fix minion pillar directory
|
2021-02-22 14:27:22 -05:00 |
|
Mike Reeves
|
6ed1cc3875
|
Add Soup Functions
|
2021-02-22 14:02:37 -05:00 |
|
Doug Burks
|
84f138772f
|
Merge pull request #3072 from Security-Onion-Solutions/kilo
Additional fine tuning of Suricata metadata support
|
2021-02-22 10:57:02 -08:00 |
|
doug
|
71c7ffae3e
|
Improve support for Suricata metadata #2200
|
2021-02-22 13:49:29 -05:00 |
|
doug
|
bcce205430
|
Improve support for Suricata metadata #2200
|
2021-02-22 13:00:14 -05:00 |
|
Jason Ertel
|
943cbdbf1f
|
Merge pull request #3073 from Security-Onion-Solutions/delta
Apply action on PR only now that PRs are mandatory
|
2021-02-22 12:50:38 -05:00 |
|
Jason Ertel
|
43e0c3a60b
|
Apply action on PR only now that PRs are mandatory
|
2021-02-22 12:35:17 -05:00 |
|
Mike Reeves
|
d5069d12cf
|
Merge pull request #3071 from Security-Onion-Solutions/delta
Add acng to import installs for consistency
|
2021-02-22 11:34:23 -05:00 |
|
William Wernert
|
e65c9e5c7c
|
Don't expect apply arg at beginning of command
|
2021-02-22 11:29:30 -05:00 |
|
William Wernert
|
4bcb7403a9
|
Add apply option to end of command
|
2021-02-22 11:27:03 -05:00 |
|
William Wernert
|
bef3a6921c
|
[fix] SID wildcards are not parsed by idstools, remove
|
2021-02-22 11:12:02 -05:00 |
|
William Wernert
|
f7bef9200b
|
[fix] Only look for manager-type pillars
* SID disabling is only managed globally for now, so don't give the option to edit a different pillar
|
2021-02-22 10:38:53 -05:00 |
|
William Wernert
|
bb6f3107bc
|
[fix] idstools can run on an import node as well
|
2021-02-22 10:29:40 -05:00 |
|
doug
|
3467f30603
|
Improve support for Suricata metadata #2200
|
2021-02-22 10:27:24 -05:00 |
|
Doug Burks
|
d4ee2b86e6
|
Merge pull request #3070 from Security-Onion-Solutions/dev
Dev to Kilo
|
2021-02-22 07:22:49 -08:00 |
|
William Wernert
|
f2a1e89633
|
Merge branch 'dev' into feature/so-rules
|
2021-02-22 10:03:14 -05:00 |
|
William Wernert
|
abae673568
|
Update help text to reflect arg requirement changes
|
2021-02-22 10:00:29 -05:00 |
|