Commit Graph

6590 Commits

Author SHA1 Message Date
Wes
c8ff2c7a06 Update RITA beacon parsing 2023-01-03 16:03:49 +00:00
doug
4e5d1d587e update sysmon ingest parser and Sysmon File dashboard 2023-01-03 09:02:17 -05:00
Jason Ertel
a89976779d Ensure create/update dates are both reset when an admin sets a user's password 2022-12-30 11:30:09 -05:00
Mike Reeves
058b4013aa Merge pull request #9470 from Security-Onion-Solutions/kilo
Kilo
2022-12-23 10:37:22 -05:00
Jason Ertel
136867c96a ensure zombie pipe is destroyed before SOC restarts 2022-12-23 10:27:49 -05:00
Mike Reeves
75ffd1f56b Update soc_global.yaml 2022-12-23 08:55:19 -05:00
Mike Reeves
3f0ded0638 Merge pull request #9464 from Security-Onion-Solutions/mkr24
Add global annotation and influx support
2022-12-22 13:57:56 -05:00
Mike Reeves
cd77e71d8d Create annotation file for global settings 2022-12-22 13:37:41 -05:00
Mike Reeves
78f851e6c2 Create annotation file for global settings 2022-12-22 13:35:37 -05:00
Mike Reeves
a924d48408 Specify Influxdb host 2022-12-22 13:12:19 -05:00
Mike Reeves
308228620a Specify Influxdb host 2022-12-22 13:05:33 -05:00
Doug Burks
2df4755fef Enable Grafana in EVAL mode 2022-12-22 12:54:57 -05:00
Jason Ertel
a077645bb4 Merge branch '2.4/dev' into kilo 2022-12-22 10:27:13 -05:00
Jason Ertel
b6f37f8499 Correct indentation of client section 2022-12-22 10:26:51 -05:00
Doug Burks
e95034886e add influxdb and telegraf to import mode 2022-12-22 09:49:57 -05:00
Doug Burks
9352854fe4 enable influxdb for eval and import modes 2022-12-22 09:48:38 -05:00
Doug Burks
75e16963c8 add influxdb and telegraf to import mode 2022-12-22 09:47:47 -05:00
Doug Burks
dfd5947051 add influxdb and telegraf to import mode 2022-12-22 09:46:27 -05:00
Jason Ertel
38634fde17 fix redis defaults to force string keys instead of numeric 2022-12-21 18:15:17 -05:00
Jason Ertel
8b6006e9c3 fix redis defaults to force string keys instead of numeric 2022-12-21 18:14:18 -05:00
Jason Ertel
3fd210463e fix redis defaults to force string keys instead of numeric 2022-12-21 18:11:39 -05:00
Doug Burks
f99279ca24 Merge pull request #9453 from Security-Onion-Solutions/feature/improve-dashboards-2.4
FEATURE: Improve SOC Dashboards #9450 2.4
2022-12-21 15:46:11 -05:00
Doug Burks
69415a0d8d Improve Strelka dashboard 2022-12-21 15:34:35 -05:00
Doug Burks
506556f0d2 Improve Firewall dashboard 2022-12-21 15:29:09 -05:00
Doug Burks
d7b2c88201 Improve Software dashboard 2022-12-21 15:24:58 -05:00
Doug Burks
4519c533a2 Improve Intel dashboard 2022-12-21 15:20:27 -05:00
Josh Patterson
8d35e0120e Merge pull request #9451 from Security-Onion-Solutions/2.4/so-kibana-config-load
need space between curl.config and -X
2022-12-21 15:11:54 -05:00
m0duspwnens
6d6fa4c1e3 need space between curl.config and -X 2022-12-21 15:06:56 -05:00
Doug Burks
3a367d69f4 Improve FTP dashboard 2022-12-21 14:37:17 -05:00
Doug Burks
a4f1f75306 Improve NIDS Alerts dashboard 2022-12-21 14:33:01 -05:00
Jason Ertel
5a5c565fae Merge pull request #9449 from Security-Onion-Solutions/kilo
Ensure user/pass values are quoted due to symbol chars appearing in values
2022-12-21 14:02:38 -05:00
Jason Ertel
0889d49025 Ensure user/pass values are quoted due to symbol chars appearing in the values 2022-12-21 14:00:10 -05:00
Doug Burks
3d1ce4ef10 Improve SOC dashboards 2022-12-21 13:26:04 -05:00
Jason Ertel
33a1aea729 Merge pull request #9448 from Security-Onion-Solutions/kilo
improve so-status rendering on terminals that only support 8 colors
2022-12-21 10:14:47 -05:00
Jason Ertel
8e63909edf improve so-status rendering on terminals that only support 8 colors 2022-12-21 10:11:38 -05:00
Mike Reeves
ab9edd4e6b Merge pull request #9421 from Security-Onion-Solutions/mkr24
Redis defaults.yaml
2022-12-21 09:15:49 -05:00
Mike Reeves
e1d0f99a14 Modify redis config defaults 2022-12-20 22:00:10 -05:00
Mike Reeves
38e23a0110 Modify Kratos config defaults 2022-12-20 21:21:18 -05:00
Mike Reeves
3768c0fee2 Fix Redis 2022-12-20 21:16:53 -05:00
Mike Reeves
8c6a2ce83a Fix Kratos mode 2022-12-20 21:00:06 -05:00
m0duspwnens
318aac880e file.managed for kratos schema 2022-12-20 17:40:29 -05:00
m0duspwnens
16b882a10e new states for kratos config and schema 2022-12-20 15:34:58 -05:00
Jason Ertel
2edc3cac11 Clarify Kratos annotations 2022-12-20 14:08:49 -05:00
Mike Reeves
13e5fa7544 SOC files for Kratos 2022-12-20 13:30:51 -05:00
m0duspwnens
a2d0de7e49 kratos config jinja 2022-12-20 12:15:33 -05:00
Josh Brower
73a9c3bb38 Make Fleet setup less fragile 2022-12-20 11:52:56 -05:00
Mike Reeves
c0c2d28d19 SOC files for Redis 2022-12-20 11:09:49 -05:00
Doug Burks
894434715b so-status should ignore commented entries in so-status.conf
Import mode comments out so-steno, so-suricata, and so-zeek in so-status.conf, so so-status should ignore these lines.
2022-12-20 09:05:07 -05:00
doug
9d8951ceb8 fix import 2022-12-19 16:55:16 -05:00
Mike Reeves
aea91cc776 Merge branch 'mkr24' of https://github.com/Security-Onion-Solutions/securityonion into mkr24 2022-12-19 16:21:47 -05:00