Mike Reeves
|
2fb73cd516
|
Update defaults.yaml
|
2023-09-27 16:07:38 -04:00 |
|
Mike Reeves
|
62cb661bab
|
Merge pull request #11408 from Security-Onion-Solutions/TOoSmOotH-patch-4
Fix sendmail errors in zeek
|
2023-09-27 15:53:50 -04:00 |
|
Jason Ertel
|
1e04199ea6
|
Merge pull request #11406 from Security-Onion-Solutions/jertel/lc
ignore generic python stack trace log lines of code, rely on actual e…
|
2023-09-27 15:52:48 -04:00 |
|
Jason Ertel
|
4666916077
|
ignore generic python stack trace log lines of code, rely on actual error messages
|
2023-09-27 15:48:52 -04:00 |
|
Mike Reeves
|
f094b1162d
|
Update defaults.yaml
|
2023-09-27 15:48:05 -04:00 |
|
Jason Ertel
|
ae9619f0c3
|
Merge pull request #11405 from Security-Onion-Solutions/jertel/lc
deb OS doesn't use /var/log/cron, skip
|
2023-09-27 15:42:10 -04:00 |
|
Jason Ertel
|
87cc389088
|
deb OS doesn't use /var/log/cron, skip
|
2023-09-27 15:36:13 -04:00 |
|
Josh Patterson
|
ec046a6943
|
Merge pull request #11404 from Security-Onion-Solutions/fix/filecheckcron
Fix/filecheckcron
|
2023-09-27 12:51:25 -04:00 |
|
Mike Reeves
|
7eefe7b79c
|
Merge pull request #11403 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update nginx.conf to use user nobody
|
2023-09-27 12:38:58 -04:00 |
|
Mike Reeves
|
c4fea9cb9d
|
Update nginx.conf
|
2023-09-27 11:03:58 -04:00 |
|
m0duspwnens
|
3fded86aa1
|
Merge remote-tracking branch 'origin/2.4/dev' into fix/filecheckcron
|
2023-09-27 10:08:17 -04:00 |
|
m0duspwnens
|
05e7c32cf9
|
remove duplicate filecheck_run cron
|
2023-09-27 10:08:08 -04:00 |
|
Jason Ertel
|
af2ff2b07c
|
Merge pull request #11399 from Security-Onion-Solutions/jertel/lc
don't inspect imported zeek output
|
2023-09-27 09:45:39 -04:00 |
|
Jason Ertel
|
b47d915cb6
|
don't inspect imported zeek output
|
2023-09-27 09:30:19 -04:00 |
|
Jason Ertel
|
376d525ad7
|
Merge pull request #11398 from Security-Onion-Solutions/jertel/lc
skip zeek spool logs due to test data false positives
|
2023-09-26 22:01:50 -04:00 |
|
Jason Ertel
|
9c854a13cc
|
skip zeek spool logs due to test data false positives
|
2023-09-26 21:41:44 -04:00 |
|
Jason Ertel
|
ff780738fd
|
Merge pull request #11397 from Security-Onion-Solutions/jertel/lc
log check tool initial
|
2023-09-26 18:23:41 -04:00 |
|
Jason Ertel
|
2c8d413f16
|
log check tool initial
|
2023-09-26 18:14:37 -04:00 |
|
Jason Ertel
|
48801da44e
|
log check tool initial
|
2023-09-26 18:12:20 -04:00 |
|
Josh Patterson
|
641b8ef0b6
|
Merge pull request #11393 from Security-Onion-Solutions/issue/11390
Issue/11390
|
2023-09-26 13:26:42 -04:00 |
|
m0duspwnens
|
036a21ff17
|
Merge remote-tracking branch 'origin/2.4/dev' into issue/11390
|
2023-09-26 11:01:44 -04:00 |
|
m0duspwnens
|
2abf434ebe
|
create snapshots of default, local salt and pillars during soup. rsync soup with --delete
|
2023-09-26 10:56:20 -04:00 |
|
weslambert
|
4dc477cc1d
|
Merge pull request #11391 from Security-Onion-Solutions/fix/elasticsearch_strelka_image_version
Make scan.pe.image_version type of 'float'
|
2023-09-26 10:21:17 -04:00 |
|
Wes
|
0bba68769b
|
Make scan.pe.image_version type of 'float'
|
2023-09-26 14:05:12 +00:00 |
|
m0duspwnens
|
e25d1c0ff3
|
so-salt-minion-check is jinja template
|
2023-09-26 10:01:21 -04:00 |
|
weslambert
|
f9ace4791f
|
Merge pull request #11384 from Security-Onion-Solutions/fix/analyzers_testing
Add a note about testing analyzers outside of the Sensoroni Docker container
|
2023-09-25 14:48:45 -04:00 |
|
weslambert
|
7cb9b5f257
|
Add the blank line that was removed from the previous commit
|
2023-09-25 14:41:20 -04:00 |
|
weslambert
|
c95af6b992
|
Add a note about testing analyzers outside of the Sensoroni Docker container
|
2023-09-25 14:39:33 -04:00 |
|
weslambert
|
2fc4d2923d
|
Merge pull request #11289 from Security-Onion-Solutions/fix/elastic_agent_404
/app/dashboards to /kibana/app/dashboards
|
2023-09-25 09:11:50 -04:00 |
|
Wes
|
eeeae08ec8
|
/app/ to /app/dashboards/
|
2023-09-21 18:39:06 +00:00 |
|
Jason Ertel
|
220f25e206
|
Merge pull request #11369 from Security-Onion-Solutions/jertel-patch-1
Update soup to prune in background
|
2023-09-21 09:42:28 -04:00 |
|
Jason Ertel
|
fa3a79a787
|
Update soup to prune in background
|
2023-09-21 09:41:44 -04:00 |
|
Doug Burks
|
ca71add51b
|
Merge pull request #11363 from Security-Onion-Solutions/dougburks-patch-1
FIX: SOC Config sensoroni doc links should point to correct docs #11362
|
2023-09-20 08:29:30 -04:00 |
|
Doug Burks
|
3fa3f83007
|
Update soc_sensoroni.yaml
|
2023-09-20 08:22:52 -04:00 |
|
weslambert
|
377802410e
|
Merge pull request #11352 from Security-Onion-Solutions/fix/import_evtx_exists
Fix EVTX Imports
|
2023-09-19 16:11:22 -04:00 |
|
Wes
|
2e0ea3f374
|
Set final pipeline
|
2023-09-19 13:33:12 +00:00 |
|
Wes
|
508260bd46
|
Use event.created for timestamp
|
2023-09-19 13:32:03 +00:00 |
|
Wes
|
a1e963f834
|
Reverse timestamps where necessary
|
2023-09-19 13:28:20 +00:00 |
|
Jason Ertel
|
8a98040008
|
Merge pull request #11351 from Security-Onion-Solutions/jertel/auto
ignore debian apt update output
|
2023-09-19 09:26:31 -04:00 |
|
Jason Ertel
|
47e611682a
|
ignore debian apt update output
|
2023-09-19 09:24:12 -04:00 |
|
Wes
|
5bac1e4d15
|
Show correct dates and Kibana URL for already processed EVTX files
|
2023-09-18 21:31:15 +00:00 |
|
Jason Ertel
|
ad025b9683
|
Merge pull request #11345 from Security-Onion-Solutions/jertel/auto
ensure all binds are present to avoid volume sprawl
|
2023-09-18 15:34:57 -04:00 |
|
Josh Patterson
|
3e97ddc22d
|
Merge pull request #11344 from Security-Onion-Solutions/fix/idstoolextra_env
fix idstool extra_env for container
|
2023-09-18 15:29:33 -04:00 |
|
m0duspwnens
|
151e8bfc4e
|
fix idstool extra_env for container
|
2023-09-18 15:21:45 -04:00 |
|
Jason Ertel
|
a914a02273
|
prune unused volumes during upgrade
|
2023-09-18 14:43:02 -04:00 |
|
Jason Ertel
|
bb3632d1b2
|
fix bind if statement
|
2023-09-18 14:38:15 -04:00 |
|
Jason Ertel
|
66bb1272ae
|
avoid volume sprawl
|
2023-09-18 13:39:56 -04:00 |
|
Jason Ertel
|
bbef96ac25
|
use unique name
|
2023-09-18 12:12:57 -04:00 |
|
Jason Ertel
|
f9cbde10a6
|
avoid volume sprawl
|
2023-09-18 11:19:21 -04:00 |
|
weslambert
|
fe1bae96ed
|
Merge pull request #11297 from Security-Onion-Solutions/fix/soc_idh
Change description to indicate that opencanary modules only apply to IDH nodes
|
2023-09-15 11:16:06 -04:00 |
|