William Wernert
387d4d6ad5
Add so-deny script + rewrite so-allow to match so-deny
2021-10-20 16:44:57 -04:00
William Wernert
adf6cb4b3c
Merge branch 'dev' into foxtrot
2021-10-20 16:44:50 -04:00
William Wernert
b5cb47e066
Fix sbin perms
2021-10-20 16:43:55 -04:00
Josh Patterson
8061508330
Merge pull request #5961 from Security-Onion-Solutions/issue/5960
...
Issue/5960
2021-10-20 16:08:50 -04:00
m0duspwnens
adffb11800
fix redis port
2021-10-20 15:39:21 -04:00
m0duspwnens
8619af59cc
servers to list format
2021-10-20 15:02:33 -04:00
m0duspwnens
7ecfb55b70
fix pillar call
2021-10-20 14:50:50 -04:00
m0duspwnens
b496810b63
add redis and logstash input plugins to telegraf
2021-10-20 14:46:47 -04:00
Mike Reeves
e1ad02c28d
Merge pull request #5949 from Security-Onion-Solutions/kilo
...
Fix Docker-created corruption of SOC user roles file
2021-10-19 18:37:37 -04:00
Jason Ertel
2f8bb5a2a6
Fix Docker-created corruption of SOC user roles file
2021-10-19 16:04:10 -04:00
Mike Reeves
7f1585dcc0
Merge pull request #5942 from Security-Onion-Solutions/tunesteno
...
Fix Steno Math for PL
2021-10-19 13:03:50 -04:00
Mike Reeves
64f25961b0
Fix Steno Math for PL
2021-10-19 11:15:58 -04:00
Mike Reeves
b9a3d3a6a9
Fix Steno Math for PL
2021-10-19 11:14:02 -04:00
m0duspwnens
1b2268dfe5
load kibana configs during setup
2021-10-18 14:30:47 -04:00
Mike Reeves
00e5b54dda
Merge pull request #5911 from Security-Onion-Solutions/tunesteno
...
Add Steno Tuning Options
2021-10-18 09:01:14 -04:00
Mike Reeves
4016b416ec
Merge pull request #5923 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.1
2021-10-16 09:15:06 -04:00
weslambert
bb36fc1ed8
Add TI module defaults
2021-10-15 17:16:38 -04:00
weslambert
d0a6dafc8b
Add TI module
2021-10-15 17:09:59 -04:00
m0duspwnens
76097476d3
remove includes
2021-10-15 16:57:38 -04:00
m0duspwnens
8b3b0bf160
fix opts
2021-10-15 16:51:11 -04:00
m0duspwnens
f19680b3e6
fix opts
2021-10-15 16:50:03 -04:00
m0duspwnens
7e1bbe3cc2
define MAANGER
2021-10-15 16:14:14 -04:00
m0duspwnens
947285e932
update cmd.run amd s_o files
2021-10-15 16:06:25 -04:00
m0duspwnens
1741f5068a
update config-load to do an update or import
2021-10-15 15:35:30 -04:00
Mike Reeves
a9f6c84d7c
Add Steno Tuning Options
2021-10-15 14:17:54 -04:00
weslambert
59852841ff
Add keyword subfield for event.module
2021-10-15 13:29:50 -04:00
Jason Ertel
8de8d58155
Upgrade to ES 7.15.1
2021-10-15 13:27:08 -04:00
Wes Lambert
032373187c
Allow setting ES index patterns for SOC in pillar
2021-10-15 16:02:53 +00:00
William Wernert
db2b70f655
Merge pull request #5900 from Security-Onion-Solutions/foxtrot
...
Replace rather than append to Kibana misc log
2021-10-15 10:27:25 -04:00
Jason Ertel
1800ec4570
Upgrade to Elastalert 2 v2.2.2
2021-10-15 09:25:44 -04:00
Mike Reeves
8a5960c220
Merge pull request #5896 from Security-Onion-Solutions/kilo
2021-10-14 18:05:33 -04:00
Jason Ertel
9797a15218
Fix issue with 'so-user delete' resetting all user roles - note that this function is not technically supported or published since it's not intended for production use
2021-10-14 17:23:18 -04:00
William Wernert
c7b15a9b1f
Replace rather than append to Kibana misc log
2021-10-14 15:13:55 -04:00
m0duspwnens
6a2bf11a75
change format of file
2021-10-14 13:43:39 -04:00
m0duspwnens
78d30285b1
seperate securitySolutions load
2021-10-14 13:24:51 -04:00
Wes Lambert
15049f44b9
Add EG pivot
2021-10-14 15:15:23 +00:00
Doug Burks
42a642b85c
Merge pull request #5873 from petiepooo/enh-rediscount-tty
...
featreq: remove tty flag in redis-count script
2021-10-14 10:07:07 -04:00
Wes Lambert
5ee0ea3fe7
Allow SOC actions to use Jinja
2021-10-14 13:59:55 +00:00
Wes Lambert
a9b250c0f4
Add EG firewall config
2021-10-13 21:37:59 +00:00
m0duspwnens
ae9753326a
fix var, quote vars
2021-10-13 16:38:01 -04:00
m0duspwnens
c8fb504ee0
Revert "Merge remote-tracking branch 'remotes/origin/dev' into issue/3933"
...
This reverts commit 54eec92621 , reversing
changes made to 7832e59629 .
2021-10-13 15:22:46 -04:00
m0duspwnens
54eec92621
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 15:19:33 -04:00
m0duspwnens
7832e59629
only load default kibana saved_objects during setup
2021-10-13 15:19:20 -04:00
Wes Lambert
2a504a061b
Add Curator action files for EG indices
2021-10-13 18:40:34 +00:00
Pete
e7581036f7
remove tty/interactive flags
...
This call to docker exec simply returns a number. No interaction (stdin) or tty is required. Specifically, having the -t option prevents running via salt using a command such as:
> salt '*' cmd.run 'so-redis-count'
2021-10-13 13:51:05 -04:00
Wes Lambert
e1629d7ec4
Initial EG stuff
2021-10-13 17:13:07 +00:00
m0duspwnens
23ea53248d
single line format
2021-10-12 14:15:37 -04:00
m0duspwnens
f1a5991699
add securitySolution.defaultIndex to defaults
2021-10-12 12:35:13 -04:00
m0duspwnens
c69ad091f7
update saved_objects config
2021-10-12 12:02:30 -04:00
m0duspwnens
498e385484
change name to SAVED_OBJECTS
2021-10-12 10:15:39 -04:00