Wes Lambert
33512eca2a
template and kibana config updates
2020-04-01 13:14:13 +00:00
weslambert
d8f30a0240
Merge pull request #481 from Security-Onion-Solutions/fix/strelka_stuff
...
Fix/strelka stuff
2020-04-01 09:00:07 -04:00
Wes Lambert
70422809ec
add category
2020-04-01 12:59:10 +00:00
Wes Lambert
9bbcc185aa
change Strelka log location
2020-04-01 12:57:51 +00:00
Jason Ertel
8767f17325
Removed obsolete osquery-packages.html since it's now in soc
2020-03-31 17:43:03 -04:00
Josh Brower
2bfacecb4b
Merge pull request #478 from Security-Onion-Solutions/bugfix/osquery
...
fleet init fix
2020-03-31 09:54:45 -04:00
Josh Brower
131fd1f322
fleet init fix
2020-03-31 09:53:59 -04:00
Jason Ertel
14c44e0f6e
Merge pull request #476 from Security-Onion-Solutions/feature/auth
...
Integrate new auth system and SOC interface
2020-03-31 08:57:19 -04:00
Jason Ertel
f7e9e99eae
Added new soc-related saltstack files.
2020-03-30 22:15:49 -04:00
weslambert
fd00cdf8f3
Merge pull request #473 from Security-Onion-Solutions/more_elastic_stuff
...
More elastic stuff
2020-03-30 20:41:56 -04:00
Wes Lambert
68138e009a
update FB config
2020-03-31 00:37:58 +00:00
Wes Lambert
5226ec1560
update Kibana config/dashboards/etc
2020-03-31 00:37:17 +00:00
Wes Lambert
eacd3c9bfd
update zeek.common
2020-03-31 00:36:42 +00:00
Jason Ertel
cbd710bcf2
Replaced auth system with new identity management system.
2020-03-30 19:27:56 -04:00
weslambert
9758563967
Merge pull request #470 from Security-Onion-Solutions/ecs_community_id
...
add community_id parsing for ingest
2020-03-30 11:51:05 -04:00
Wes Lambert
ad50093315
add community_id parsing for ingest
2020-03-30 15:49:36 +00:00
weslambert
ee4e3c0659
Merge pull request #469 from Security-Onion-Solutions/fix/ingest_stuff
...
update wazuh fields and category
2020-03-30 10:24:43 -04:00
Wes Lambert
93c3c86e2f
update wazuh fields and category
2020-03-30 14:24:01 +00:00
weslambert
b6db36723d
Merge pull request #467 from Security-Onion-Solutions/fix/kibana_config_update
...
update Kibana json config
2020-03-30 10:21:18 -04:00
Wes Lambert
70bc35eb7e
update Kibana json config
2020-03-30 14:20:06 +00:00
William Wernert
d7478bbcb7
[fix] Revert checksum script change
2020-03-27 09:05:21 -04:00
William Wernert
c105732976
Merge pull request #466 from Security-Onion-Solutions/bugfix/ubuntu-xenial-fixes
...
Bugfix/ubuntu xenial fixes
2020-03-26 18:55:41 -04:00
William Wernert
04cbda356f
Merge pull request #465 from Security-Onion-Solutions/hotfix/so-status-docker-api
...
[fix] Use v2 of Docker http api
2020-03-26 18:48:11 -04:00
William Wernert
7709bfd28e
[fix] Use v2 of Docker http api
...
Docker no longer exposes the default api path, so we need to use /v2 in our api call
2020-03-26 18:47:37 -04:00
William Wernert
f02808aaa7
[fix] Networking config fixes + 18.04 changes
...
* Add code to allow 18.04 to use Network Manager
* Disable ipv6 on all interfaces to prevent multicast traffic on sniffing interface (revisit later)
* Rename and modify checksum disable script for 18.04 compatibility
Fixes #387
Fixes #413
2020-03-26 18:45:56 -04:00
Josh Brower
e44157aa7d
Merge pull request #464 from Security-Onion-Solutions/feature/zeek-communityid
...
Zeek - enable Community ID policy
2020-03-26 16:34:46 -04:00
Josh Brower
31ae8a2c26
Zeek - enable Community ID policy
2020-03-26 16:33:47 -04:00
Josh Patterson
3918b697e4
Merge pull request #463 from Security-Onion-Solutions/issue/90
...
Issue/90
2020-03-26 15:54:25 -04:00
m0duspwnens
c14f32fcc9
more changes for healthcheck - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/90
2020-03-26 15:45:19 -04:00
Josh Brower
11907dc4ad
Merge pull request #462 from Security-Onion-Solutions/bugfix/fleet
...
Bugfix/fleet
2020-03-26 11:23:28 -04:00
Josh Brower
1c9dd40b02
Fleet webpage fix
2020-03-26 11:20:20 -04:00
m0duspwnens
22127a3d58
Merge remote-tracking branch 'remotes/origin/dev' into issue/90
2020-03-26 11:01:10 -04:00
m0duspwnens
cfdaedb89c
changes to healthcheck. specify mount points for telegraf
2020-03-26 11:00:46 -04:00
William Wernert
83c2edb0d9
[fix] Set all indents to tabs
2020-03-25 15:59:04 -04:00
Josh Brower
e5ecf0f4cb
Fleet dedicated node - various fixes
2020-03-25 13:03:40 -04:00
m0duspwnens
e6f91264fb
send proper format data to telegraf module from healtheck module - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/90
2020-03-25 12:48:47 -04:00
m0duspwnens
566a26e3b7
fix dashboards to use right node name
2020-03-25 12:47:01 -04:00
Josh Brower
05690691f5
Merge pull request #459 from Security-Onion-Solutions/feature/communityid-suricata
...
Suricata - enable community id
2020-03-25 09:28:02 -04:00
Josh Brower
51b9af7ac4
Suricata - enable community id
2020-03-25 09:24:45 -04:00
m0duspwnens
77a48b1d66
Merge remote-tracking branch 'remotes/origin/dev' into issue/90
2020-03-25 09:03:16 -04:00
Josh Brower
9bcba41882
Feature/Fleet-Standalone
2020-03-24 20:57:24 -04:00
m0duspwnens
b96579f6d3
Merge remote-tracking branch 'remotes/origin/dev' into issue/90
2020-03-24 17:28:46 -04:00
m0duspwnens
7e6c70aff2
add modules to be used in monitoring - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/90
2020-03-24 17:27:55 -04:00
Josh Brower
e4e598f0be
Merge pull request #458 from Security-Onion-Solutions/bugfix/so-functions
...
so-functions --- conditional-fix
2020-03-24 16:01:12 -04:00
Josh Brower
166a21c1d1
conditional-fix
2020-03-24 15:59:50 -04:00
weslambert
b59fc5b77e
Merge pull request #457 from Security-Onion-Solutions/fix/more_ossec_fields
...
fix ossec fields
2020-03-24 11:44:45 -04:00
Wes Lambert
ef808875f4
fix ossec fields
2020-03-24 15:42:31 +00:00
weslambert
239e0a0cb6
Merge pull request #456 from Security-Onion-Solutions/kibana_disable_telem
...
Disable telemetry
2020-03-24 10:20:51 -04:00
weslambert
fef0185e90
Disable telemetry
2020-03-24 10:18:39 -04:00
weslambert
81a481022c
Merge pull request #455 from Security-Onion-Solutions/fix/zeek_weird_ingest
...
add some more fields
2020-03-23 23:44:47 -04:00