Josh Brower
|
31cd5b1365
|
Add support for dns.resolved_ip
|
2025-06-20 15:02:59 -04:00 |
|
reyesj2
|
fcdacc3b0d
|
fix system integration time overwrite and delete unused ingest pipeline
|
2025-05-29 12:21:28 -05:00 |
|
Jorge Reyes
|
d3ee5ed7b8
|
use zeek network.community_id when available
|
2025-05-28 09:20:41 -05:00 |
|
Josh Brower
|
b753d40861
|
Tighten parsing
|
2025-05-20 17:06:11 -04:00 |
|
Josh Brower
|
b55cb257b6
|
Add parsing for Playbook
|
2025-05-19 13:25:27 -04:00 |
|
Josh Brower
|
df103b3dca
|
Spacing
|
2025-05-14 16:36:59 -04:00 |
|
Josh Brower
|
0542c77137
|
Remove wip config
|
2025-05-14 16:35:09 -04:00 |
|
Josh Brower
|
9022dc24fb
|
Add Parsing for Playbooks
|
2025-05-14 13:19:50 -06:00 |
|
reyesj2
|
e1d31c895e
|
add null check
|
2025-05-07 21:25:30 -05:00 |
|
reyesj2
|
4d7fdd390c
|
ldap_search include observer.name
|
2025-03-18 08:52:43 -05:00 |
|
reyesj2
|
4bd83f8983
|
zeek traceroute & ntp
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-03 10:48:06 -06:00 |
|
reyesj2
|
69b559fb26
|
ES 8.17.2 pipeline version updates
|
2025-02-20 17:11:28 -06:00 |
|
Jorge Reyes
|
a3dba9b566
|
Merge pull request #14255 from Security-Onion-Solutions/foxtrot
ES 8.17.1
|
2025-02-18 14:58:46 -06:00 |
|
reyesj2
|
1be8de7acb
|
must use null check
|
2025-02-18 11:16:57 -06:00 |
|
reyesj2
|
c1c72ddd9b
|
update global@custom pipeline ignore null/empty string values
|
2025-02-18 10:39:54 -06:00 |
|
reyesj2
|
12f0195f29
|
pfsense integration - keep suricata events
|
2025-02-17 12:28:23 -06:00 |
|
reyesj2
|
c711ffe6c5
|
keep pipeline "managed" metadata
|
2025-02-13 08:44:56 -06:00 |
|
reyesj2
|
09c7b31918
|
update pfsense pipeline version. Remove unused component templates
|
2025-02-12 16:33:56 -06:00 |
|
reyesj2
|
33f145a40b
|
ensure network packet capture integration data has event.module:network_traffic
|
2025-02-10 13:16:39 -06:00 |
|
reyesj2
|
9bde70a8e2
|
zeek.software typo
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-02-07 15:19:40 -06:00 |
|
reyesj2
|
1396083b7d
|
use so-elasticsearch-query where possible; simplify suricata.alerts index reroute
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 13:29:46 -06:00 |
|
reyesj2
|
9032d7d7bc
|
any suricata.alert with event.imported: true remains in logs-import-so
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 18:48:31 -06:00 |
|
reyesj2
|
45d3438d18
|
update ingest pipeline for imported logs
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 17:33:14 -06:00 |
|
reyesj2
|
b3b7fb8f29
|
add null check and move tag lookup to .contains() in global@custom
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-15 12:16:11 -06:00 |
|
reyesj2
|
e60a1e4357
|
zeek ldap & ldap_search parsing
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-09 16:06:10 -06:00 |
|
reyesj2
|
9f83853922
|
Zeek QUIC support
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-12-31 13:44:20 -06:00 |
|
reyesj2
|
ad8b339a3b
|
fix error due to null reference
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-12-06 09:07:16 -06:00 |
|
reyesj2
|
754d28e95d
|
add openvpn & ipsec support to Zeek
|
2024-12-05 09:52:55 -06:00 |
|
reyesj2
|
1113c3924f
|
zeek http2
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-14 09:09:23 -06:00 |
|
Jason Ertel
|
523ff66389
|
connect work
|
2024-10-16 13:44:01 -04:00 |
|
Wes
|
cf0d56eee7
|
Fix suricata alerts for opnsense and pfsense
|
2024-09-17 19:24:31 +00:00 |
|
weslambert
|
e96a0108c3
|
Add global@custom
|
2024-08-23 13:05:34 -04:00 |
|
reyesj2
|
1ec5e3bf2a
|
add kafka.id to common ingest pipeline
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-08-23 09:47:21 -04:00 |
|
Wes
|
e789c17bc3
|
Add global@custom pipeline file
|
2024-07-23 16:37:37 +00:00 |
|
Wes
|
6f44d39b18
|
Remove Fleet final pipeline file
|
2024-07-23 16:37:03 +00:00 |
|
reyesj2
|
a81e4c3362
|
remove dash(-) from kafka.id
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-11 11:55:17 -04:00 |
|
reyesj2
|
08557ae287
|
kafka.id field should only be present when metadata for kafka exists
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-11 11:01:34 -04:00 |
|
reyesj2
|
3b0339a9b3
|
create kafka.id from kafka {partition}-{offset}-{timestamp} for tracking event
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-04 14:27:52 -04:00 |
|
Wes
|
2c635bce62
|
Set index for Suricata alerts
|
2024-05-30 17:02:31 +00:00 |
|
DefensiveDepth
|
8e7c487cb0
|
Fix strelka rule.uuid
|
2024-05-23 05:59:31 -04:00 |
|
weslambert
|
f4490fab58
|
Add rule.uuid for YARA matches
|
2024-05-21 17:05:39 -04:00 |
|
reyesj2
|
fadb6e2aa9
|
Re-add original timestamp format + ignore failures with this processor
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 16:57:48 -04:00 |
|
reyesj2
|
192d91565d
|
Update final pipeline timestamp format for event.module system events
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 16:34:29 -04:00 |
|
reyesj2
|
55cf90f477
|
merge 2.4/dev
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-11 14:44:59 -04:00 |
|
reyesj2
|
fd689a4607
|
Fix typo in ingest pipeline
Test to fix duplicate events in SOC, by removing conflicting field event.created
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-11 11:18:04 -04:00 |
|
reyesj2
|
7124f04138
|
Update ingest pipelines to match updated mappings
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-10 16:13:06 -04:00 |
|
DefensiveDepth
|
376efab40c
|
Ship Defender logs
|
2024-04-08 14:01:38 -04:00 |
|
reyesj2
|
000d15a53c
|
Kismet integration: TODO Elasticsearch mappings
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-03-29 13:56:01 -04:00 |
|
weslambert
|
df058b3f4a
|
Merge branch '2.4/dev' into feature/pfsense_suricata
|
2024-03-25 10:08:03 -04:00 |
|
Wes
|
5e21da443f
|
Minor verbiage updates
|
2024-03-25 13:58:32 +00:00 |
|