reyesj2
|
911d6dcce1
|
update kafka output policy only on eligible grid types
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-18 12:09:59 -04:00 |
|
Doug Burks
|
de18bf06c3
|
FEATURE: Add new Process actions #13226
|
2024-06-18 10:36:41 -04:00 |
|
Jorge Reyes
|
73473d671d
|
Merge pull request #13222 from Security-Onion-Solutions/reyesj2-patch-3
update profile
|
2024-06-18 09:16:35 -04:00 |
|
DefensiveDepth
|
521cccaed6
|
Update defaults
|
2024-06-18 08:43:00 -04:00 |
|
reyesj2
|
35da3408dc
|
update profile
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-17 15:53:49 -04:00 |
|
reyesj2
|
2afc947d6c
|
suppress fleet policy update in soup
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-17 14:12:33 -04:00 |
|
m0duspwnens
|
55f8303dc2
|
remove manager and search pipelines from heavynode
|
2024-06-17 10:06:43 -04:00 |
|
Doug Burks
|
93ced0959c
|
FEATURE: Add more links and descriptions to SOC MOTD #13216
|
2024-06-17 09:25:01 -04:00 |
|
Doug Burks
|
6f13fa50bf
|
FEATURE: Add more links and descriptions to SOC MOTD #13216
|
2024-06-17 09:24:32 -04:00 |
|
Doug Burks
|
3bface12e0
|
FEATURE: Add more links and descriptions to SOC MOTD #13216
|
2024-06-17 09:23:14 -04:00 |
|
Doug Burks
|
b584c8e353
|
FEATURE: Add more links and descriptions to SOC MOTD #13216
|
2024-06-17 09:13:17 -04:00 |
|
reyesj2
|
4d1f2c2bc1
|
fix kafka elastic fleet output policy setup
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-14 23:04:08 -04:00 |
|
reyesj2
|
0b1175b46c
|
kafka logstash input plugin handle empty brokers list
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-14 23:03:36 -04:00 |
|
reyesj2
|
4e50dabc56
|
refix typos
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-14 23:03:06 -04:00 |
|
Jason Ertel
|
ce45a5926a
|
Merge pull request #13207 from Security-Onion-Solutions/kaffix
Standalone logstash error
|
2024-06-14 18:01:35 -04:00 |
|
DefensiveDepth
|
7af94c172f
|
Change spelling
|
2024-06-14 16:00:22 -04:00 |
|
DefensiveDepth
|
7556587e35
|
Update rule templates
|
2024-06-14 15:47:57 -04:00 |
|
reyesj2
|
a0030b27e2
|
add additional retries to elasticfleet scripts
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-14 15:34:40 -04:00 |
|
reyesj2
|
8080e05444
|
on fresh install kafka nodes pillar may not have populated. Avoiding this by only generating kafka input pipeline when kafka nodes pillar is not empty
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-14 14:17:26 -04:00 |
|
DefensiveDepth
|
c89f1c9d95
|
remove multiline
|
2024-06-14 13:48:55 -04:00 |
|
DefensiveDepth
|
b7ac599a42
|
set to empty
|
2024-06-14 13:21:36 -04:00 |
|
DefensiveDepth
|
8363877c66
|
move to custom rules
|
2024-06-14 12:41:44 -04:00 |
|
DefensiveDepth
|
4bcb4b5b9c
|
removed unneeded import
|
2024-06-14 09:32:34 -04:00 |
|
DefensiveDepth
|
68302e14b9
|
add to defaults and tweaks
|
2024-06-14 09:28:23 -04:00 |
|
DefensiveDepth
|
c1abc7a7f1
|
Update description
|
2024-06-14 08:51:34 -04:00 |
|
DefensiveDepth
|
484717d57d
|
initial support for custom suricata urls and local rulesets
|
2024-06-14 08:42:10 -04:00 |
|
reyesj2
|
8f8ece2b34
|
Only comment out so-kafka from so-status when it exists & only run ensure_default_pipeline when Kafka is configured
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-13 15:50:34 -04:00 |
|
reyesj2
|
816a1d446e
|
Generate kafka-logstash cert on standalone,manager,managersearch in addition to searchnodes.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-13 12:18:13 -04:00 |
|
reyesj2
|
19bfd5beca
|
fix kafka nodeid assignment to increment correctly
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-13 12:16:39 -04:00 |
|
Jorge Reyes
|
9ac7e051b3
|
Merge pull request #13190 from Security-Onion-Solutions/reyesj2/kafka
Initial Kafka support
|
2024-06-13 09:42:59 -04:00 |
|
reyesj2
|
80b1d51f76
|
wrong location for global.pipeline check
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-13 08:50:53 -04:00 |
|
reyesj2
|
9c31622598
|
telegraft should only include jolokia config when Kafka is set as the global.pipeline
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-12 15:42:00 -04:00 |
|
reyesj2
|
f372b0907b
|
Use kafka:password for kafka certs
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-12 15:41:10 -04:00 |
|
coreyogburn
|
fac96e0b08
|
Merge pull request #13183 from Security-Onion-Solutions/cogburn/cleanup-config
Fix unnecessary escaping
|
2024-06-12 11:57:31 -06:00 |
|
reyesj2
|
2bc53f9868
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka
|
2024-06-12 12:36:58 -04:00 |
|
reyesj2
|
e8106befe9
|
Append '-securityonion' to all Security Onion related Kafka topics. Adjust logstash to ingest all topics ending in '-securityonion' to avoid having to manually list topic names
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-12 12:05:16 -04:00 |
|
reyesj2
|
b7eebad2a5
|
Update Kafka self reset & add initial Kafka wrapper scripts to build out
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-12 11:01:40 -04:00 |
|
m0duspwnens
|
8f8698fd02
|
Merge remote-tracking branch 'origin/2.4/dev' into issue/13073
|
2024-06-12 10:50:18 -04:00 |
|
Josh Patterson
|
092f716f12
|
Merge pull request #13189 from Security-Onion-Solutions/soupmsgq
remove this \n
|
2024-06-12 10:41:49 -04:00 |
|
m0duspwnens
|
c38f48c7f2
|
remove this \n
|
2024-06-12 10:34:32 -04:00 |
|
m0duspwnens
|
98837bc379
|
this method does not cause soup to fail
|
2024-06-12 09:11:02 -04:00 |
|
m0duspwnens
|
0f243bb6ec
|
Merge remote-tracking branch 'origin/2.4/dev' into issue/13073
|
2024-06-11 16:33:23 -04:00 |
|
m0duspwnens
|
88fc1bbe32
|
quotes on vars
|
2024-06-11 16:32:57 -04:00 |
|
Corey Ogburn
|
d5ef0e5744
|
Fix unnecessary escaping
|
2024-06-11 12:34:32 -06:00 |
|
m0duspwnens
|
2ecac38f6d
|
disable logstash on heavynodes
|
2024-06-11 13:50:29 -04:00 |
|
Josh Brower
|
e90557d7dc
|
Merge pull request #13179 from Security-Onion-Solutions/2.4/fixintegritycheck
Add new bind - suricata all.rules
|
2024-06-11 13:08:40 -04:00 |
|
reyesj2
|
628893fd5b
|
remove redundant 'kafka_' from annotations & defaults
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-11 11:56:21 -04:00 |
|
reyesj2
|
a81e4c3362
|
remove dash(-) from kafka.id
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-11 11:55:17 -04:00 |
|
reyesj2
|
ca7b89c308
|
Added Kafka reset to SOC UI. Incase of changing an active broker to a controller topics may become unavailable. Resolving this would require manual intervention. This option allows running a reset to start from a clean slate to then configure cluster to desired state before reenabling Kafka as global pipeline.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-11 11:21:13 -04:00 |
|
reyesj2
|
08557ae287
|
kafka.id field should only be present when metadata for kafka exists
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-06-11 11:01:34 -04:00 |
|