Corey Ogburn
d0fa6eaf83
New Limit on Bulk Creating Related Events
...
Used by the UI and API to hint at a user that not every event will be attached to a case. Supports values up to 10,000 (the default limit on the number of documents returned by a single ES search).
2025-02-03 14:20:33 -07:00
Josh Brower
7a0309cdf4
Merge pull request #14179 from Security-Onion-Solutions/2.4/fixilmpolicy
...
Fix ip-mappings ILM
2025-02-03 09:35:55 -05:00
Joshua Brower
b874619f0d
Fix ip-mappings ILM
2025-02-03 09:31:08 -05:00
Jason Ertel
028c73fd3a
Merge pull request #14162 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-functions
2025-01-29 10:12:20 -05:00
Mike Reeves
27e9773782
Update so-functions
2025-01-29 10:07:52 -05:00
Josh Patterson
7ae128dec6
Merge pull request #14161 from Security-Onion-Solutions/esdtsn
...
env discovery.type single-node change
2025-01-29 09:29:04 -05:00
Josh Patterson
fe4129c8e0
env discovery.type single-node change
...
only managers and heavynodes are eligible for discovery.type=single-node
2025-01-29 09:11:52 -05:00
Jorge Reyes
8828a3049d
Merge pull request #14155 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
add additional weird_integration
2025-01-27 16:36:17 -06:00
reyesj2
d74b69d84d
add additional weird_integration
2025-01-27 16:34:33 -06:00
Jorge Reyes
abcfe638c9
Merge pull request #14153 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
Reyesj2/es integ tmp
2025-01-27 14:07:32 -06:00
Joshua Brower
49ab0751c0
Remove uneeded import
2025-01-27 15:01:21 -05:00
Joshua Brower
e994f3a220
Fix commits
2025-01-27 14:48:50 -05:00
reyesj2
38b0276458
remove reference to deleted file
2025-01-27 13:45:18 -06:00
reyesj2
a373d96c3c
run managed_soc_annotations.sls from manager state
2025-01-27 13:45:03 -06:00
Josh Brower
97a3f130c8
Update Elastic
2025-01-23 15:32:39 -05:00
reyesj2
5b8f8fb62f
add/remove es annotations/defaults automagically
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-23 12:47:22 -06:00
Josh Brower
9738ef382c
Upgrade Elastic to 8.17.1
2025-01-23 08:12:02 -05:00
Jason Ertel
ca0c1170ab
Merge pull request #14140 from Security-Onion-Solutions/jertel/wip
...
fix issue with first-time api client permission toggling
2025-01-22 17:43:54 -05:00
Jason Ertel
db9387764d
fix issue with first-time api client permission toggling
2025-01-22 17:41:04 -05:00
reyesj2
e0039a08ef
fix forcedType typo
2025-01-22 13:57:26 -06:00
Jorge Reyes
09df4a5771
Merge pull request #14139 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
fixes merging local pillar /global overrides for generated index temp…
2025-01-22 13:12:53 -06:00
reyesj2
81ac1ebc08
fixes merging local pillar /global overrides for generated index templates
2025-01-22 13:12:09 -06:00
Jorge Reyes
c2f5c2226f
Merge pull request #14138 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
add back missing component for http_endpoint_x_generic & winlog_x_win…
2025-01-22 10:16:30 -06:00
reyesj2
d779f7ae7f
add back missing component for http_endpoint_x_generic & winlog_x_winglog
2025-01-22 10:15:16 -06:00
Jorge Reyes
d26c7e6f9b
Merge pull request #14134 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
remove individual <integration>@custom mappings. Moved over to so-fle…
2025-01-21 11:00:18 -06:00
reyesj2
6331298eac
remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1
2025-01-21 10:49:54 -06:00
reyesj2
76abf37351
Merge remote-tracking branch 'origin/2.4/dev' into foxtrot
2025-01-21 09:03:04 -06:00
Jorge Reyes
704e30219a
Merge pull request #14124 from Security-Onion-Solutions/reyesj2-patch-8
...
keep imported data in logs-import-so index
2025-01-17 13:33:26 -06:00
reyesj2
1396083b7d
use so-elasticsearch-query where possible; simplify suricata.alerts index reroute
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-17 13:29:46 -06:00
Jason Ertel
7017024ba7
Merge pull request #14123 from Security-Onion-Solutions/jertel/wip
...
Additional web security measures
2025-01-17 12:31:42 -05:00
Jorge Reyes
942c1aa3a6
Merge pull request #14126 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
merge dev
2025-01-17 11:24:31 -06:00
reyesj2
d35ffef503
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-17 11:23:54 -06:00
Jason Ertel
7705f45d78
Revert "subgrid config annotations"
...
This reverts commit 3ab1b907e4 .
2025-01-17 12:16:12 -05:00
Jason Ertel
964bbe6aa5
additional web server security measures
2025-01-17 12:14:30 -05:00
reyesj2
01a2e4cd4f
check for index existence before attemping rollover
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-17 09:27:28 -06:00
reyesj2
9032d7d7bc
any suricata.alert with event.imported: true remains in logs-import-so
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-16 18:48:31 -06:00
reyesj2
d573c0922d
add 2.4.111 -> postupgrade check
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-16 18:25:06 -06:00
reyesj2
45d3438d18
update ingest pipeline for imported logs
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-16 17:33:14 -06:00
Jorge Reyes
6c80fd0e18
Merge pull request #14116 from Security-Onion-Solutions/reyesj2-patch-8
...
update global@custom
2025-01-15 14:23:40 -06:00
reyesj2
b3b7fb8f29
add null check and move tag lookup to .contains() in global@custom
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-15 12:16:11 -06:00
Jason Ertel
d101fda423
Merge branch '2.4/dev' into jertel/wip
2025-01-15 11:06:05 -05:00
Jorge Reyes
b1d523a4e6
Merge pull request #14113 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
update fleet-optional-integrations-load
2025-01-14 15:26:33 -06:00
reyesj2
dab56f0882
update fleet-optional-integrations-load
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-14 15:24:59 -06:00
Jorge Reyes
846f2485db
Merge pull request #14111 from Security-Onion-Solutions/reyesj2-patch-1
...
update http query
2025-01-14 08:26:43 -06:00
Jorge Reyes
107ca38268
fix http query for "includes" function
2025-01-14 08:24:07 -06:00
Jorge Reyes
35547b476f
update http query
2025-01-14 08:13:27 -06:00
Jorge Reyes
ad765200c3
Merge pull request #14105 from Security-Onion-Solutions/reyesj2/moarzeekparse
...
Additional Zeek parsing & cloudflare_logpush integration
2025-01-13 11:37:21 -06:00
reyesj2
4618256442
include okta-mappings in so-logs-okta.system index template
2025-01-13 11:32:27 -06:00
reyesj2
323ef1d5d6
add missing lifecycle name to trend_micro_vision_one indices
2025-01-13 09:29:22 -06:00
reyesj2
a5b1648b68
add missing lifecycle name to crowdstrike indices
2025-01-13 09:26:16 -06:00