Jason Ertel
|
567d80bb01
|
Update sed to disable sudo password prompt for automated testing
|
2021-01-07 11:33:59 -05:00 |
|
Josh Patterson
|
d2848b9985
|
Merge pull request #2561 from Security-Onion-Solutions/automation/so-status
add description for exit code 99
|
2021-01-07 11:24:14 -05:00 |
|
m0duspwnens
|
83e7493691
|
add description for exit code 99
|
2021-01-07 11:23:39 -05:00 |
|
William Wernert
|
1ec45fb4ae
|
[fix] Only show Zeek prompts if Zeek was selected as the MD tool
Resolves #900
|
2021-01-07 10:37:25 -05:00 |
|
William Wernert
|
c1e32ed680
|
[refactor] Rename MD tool function to be more clear
|
2021-01-07 10:36:32 -05:00 |
|
William Wernert
|
fa06a38a3b
|
[refactor] Remove duplicate function
|
2021-01-07 10:36:01 -05:00 |
|
Josh Patterson
|
d287dd2412
|
Merge pull request #2557 from Security-Onion-Solutions/automation/so-status
Automation/so status
|
2021-01-07 09:07:12 -05:00 |
|
Josh Patterson
|
8fa2b14c98
|
Merge pull request #2539 from Security-Onion-Solutions/automation/ssh_prompts
Automation/ssh prompts
|
2021-01-07 09:06:10 -05:00 |
|
Jason Ertel
|
948f900673
|
Drop password requirement for sudo access during automated tests
|
2021-01-06 20:39:44 -05:00 |
|
m0duspwnens
|
a5735e6654
|
return 99 if setup is running
|
2021-01-06 20:14:42 -05:00 |
|
m0duspwnens
|
ae7c0a26be
|
add a quiet mode to so-status for automation testing
|
2021-01-06 18:46:21 -05:00 |
|
Jason Ertel
|
bbdb47703d
|
Rename automation files to match environment names for consistency
|
2021-01-06 17:21:46 -05:00 |
|
Wes Lambert
|
7f64d57111
|
Reserve port for Wazuh API and check if port is already in use
|
2021-01-06 14:37:28 -05:00 |
|
Wes Lambert
|
e7db1a99bd
|
Set @timestamp to winlog.systemTime
|
2021-01-06 14:37:28 -05:00 |
|
Mike Reeves
|
7d25e8a08b
|
Remove ERSPAN so log doesn't show a warning
|
2021-01-06 14:37:28 -05:00 |
|
Masaya-A
|
d37023e0f5
|
Make yum removing unneeded packages
Reference: https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2020-09-03/finding/V-204452
|
2021-01-06 14:37:28 -05:00 |
|
William Wernert
|
9d8fb79d9f
|
[feat] Reorder network-only prompt
|
2021-01-06 14:37:27 -05:00 |
|
weslambert
|
c864cc607f
|
Remove multiple old so-yara-update cron jobs, if needed
|
2021-01-06 14:37:27 -05:00 |
|
William Wernert
|
80a3d8dcf8
|
[fix] Fix automation compatibility
|
2021-01-06 14:37:27 -05:00 |
|
William Wernert
|
ac35a345ff
|
[fix] Don't prompt to only set up network and then skip if network was previously configured
|
2021-01-06 14:37:27 -05:00 |
|
weslambert
|
958635b012
|
Remove old Strelka cron job
|
2021-01-06 14:37:27 -05:00 |
|
William Wernert
|
6ba11f835d
|
[fix] Remove condition for stopping SOC, since the parent condition covers what's tested
|
2021-01-06 14:37:27 -05:00 |
|
Jason Ertel
|
1cc8a78aa5
|
Only stop SOC if is_manager or is_import
|
2021-01-06 14:37:27 -05:00 |
|
Jason Ertel
|
7dcd934269
|
so-fleet-setup doesn't need an interactive terminal to run, remove 'it'
|
2021-01-06 14:37:27 -05:00 |
|
Jason Ertel
|
bedbd39b82
|
tcpreplay doesn't need an interactive terminal to run, remove 'it'
|
2021-01-06 14:37:27 -05:00 |
|
Jason Ertel
|
7d97e3590c
|
Redirect tcpreplay init output to file
|
2021-01-06 14:37:27 -05:00 |
|
Jason Ertel
|
bdbc637852
|
Stop SOC prior to opening the firewall for analysts, this ensures no outside requests can be processed prior to the server rebooting
|
2021-01-06 14:37:27 -05:00 |
|
Jason Ertel
|
10d04f760d
|
Use manager internal IP for intra-service comms
|
2021-01-06 14:37:26 -05:00 |
|
Jason Ertel
|
ebb0e615b9
|
Fix script typo to correctly run the so-test
|
2021-01-06 14:37:26 -05:00 |
|
Jason Ertel
|
f20feabda2
|
Reboot to ensure thehive falls in line before kicking off the test
|
2021-01-06 14:37:26 -05:00 |
|
Jason Ertel
|
9b40318bfe
|
Ensure so-test is logged
|
2021-01-06 14:37:26 -05:00 |
|
Jason Ertel
|
fc44474519
|
Add eval automation
|
2021-01-06 14:37:26 -05:00 |
|
Jason Ertel
|
229657f7d2
|
Use AMI's public IP for external access
|
2021-01-06 14:37:26 -05:00 |
|
Jason Ertel
|
fb28faa4e3
|
Monitor interface will not always be bond0 - pull correct value from pillar; Replay test data after automated test installations complete.
|
2021-01-06 14:37:26 -05:00 |
|
weslambert
|
36ae09ac4a
|
Merge pull request #2545 from Security-Onion-Solutions/fix/wazuh_port_reservation
Reserve port for Wazuh API and check if port is already in use
|
2021-01-06 11:49:23 -05:00 |
|
weslambert
|
55344725e7
|
Merge pull request #2544 from Security-Onion-Solutions/fix/winlog_timestamp
Set @timestamp to winlog.systemTime
|
2021-01-06 11:49:01 -05:00 |
|
Wes Lambert
|
875908dc90
|
Set @timestamp to winlog.systemTime
|
2021-01-06 16:47:35 +00:00 |
|
Wes Lambert
|
f2b677bfcb
|
Reserve port for Wazuh API and check if port is already in use
|
2021-01-06 15:52:10 +00:00 |
|
m0duspwnens
|
48f81d9ac6
|
reduce setting ssh commands down to 1 function and 1 function call
|
2021-01-06 08:58:33 -05:00 |
|
m0duspwnens
|
94fd79cd28
|
originally had sshpass package install reveresed, fixed it here
|
2021-01-06 08:51:33 -05:00 |
|
m0duspwnens
|
aecc0c025e
|
fix comment
|
2021-01-06 08:49:08 -05:00 |
|
m0duspwnens
|
91ad7f26bf
|
no longer need to pass $automated to compare_versions
|
2021-01-06 08:45:33 -05:00 |
|
m0duspwnens
|
c65e722164
|
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
|
2021-01-06 08:39:56 -05:00 |
|
m0duspwnens
|
749b21e684
|
make sure ssh commands get set whether automated install or not
|
2021-01-05 14:12:43 -05:00 |
|
Mike Reeves
|
1154b533d6
|
Remove ERSPAN so log doesn't show a warning
|
2021-01-05 13:56:56 -05:00 |
|
m0duspwnens
|
0f9bf9deb6
|
make sshcmd, scpcmd, ssh_copy_id_cmd global to so-functions;
|
2021-01-05 13:49:51 -05:00 |
|
m0duspwnens
|
c93dfa7b33
|
hardcode automation pw
|
2021-01-05 11:47:22 -05:00 |
|
m0duspwnens
|
81c4d879eb
|
first round of testing for automated testing ssh/scp
|
2021-01-05 10:26:19 -05:00 |
|
Mike Reeves
|
dc429494ac
|
Merge pull request #2370 from Masaya-A/improve/yum
Make yum removing unneeded packages
|
2021-01-05 09:26:04 -05:00 |
|
William Wernert
|
294601ff64
|
[feat] Reorder network-only prompt
|
2021-01-04 16:40:16 -05:00 |
|