m0duspwnens
|
47ba4c0f57
|
add new annotation for soc autoEnabledSigmaRules
|
2024-05-01 12:55:29 -04:00 |
|
Mike Reeves
|
10c8e4203c
|
Update config.sls
|
2024-05-01 12:54:21 -04:00 |
|
Jason Ertel
|
05c69925c9
|
Merge pull request #12904 from Security-Onion-Solutions/jertel/wf
mark detections settings as read-only via the UI
|
2024-05-01 09:54:03 -07:00 |
|
Jason Ertel
|
252d9a5320
|
make rule settings advanced
|
2024-05-01 12:51:04 -04:00 |
|
m0duspwnens
|
7122709bbf
|
set Sigma rules based on role if defined and default if not
|
2024-05-01 12:25:34 -04:00 |
|
Mike Reeves
|
f7223f132a
|
Update config.sls
|
2024-05-01 12:00:39 -04:00 |
|
Mike Reeves
|
8cd75902f2
|
Update config.sls
|
2024-05-01 11:47:51 -04:00 |
|
Jason Ertel
|
c71af9127b
|
mark detections settings as read-only via the UI
|
2024-05-01 11:47:38 -04:00 |
|
weslambert
|
e6f45161c1
|
Merge pull request #12900 from Security-Onion-Solutions/fix/cold_min_age
Cold min_age to 60d
|
2024-05-01 11:24:48 -04:00 |
|
weslambert
|
fe2edeb2fb
|
30d to 60d
|
2024-05-01 11:01:59 -04:00 |
|
weslambert
|
6294f751ee
|
Cold min_age to 60d
|
2024-05-01 10:59:41 -04:00 |
|
reyesj2
|
de0af58cf8
|
Write out Kafka pillar path
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-01 10:45:46 -04:00 |
|
reyesj2
|
84abfa6881
|
Remove check for existing value since Kafka pillar is made empty on upgrade
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-01 10:45:05 -04:00 |
|
reyesj2
|
6b60e85a33
|
Make kafka configuration changes prior to 2.4.70 upgrade
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-01 10:15:26 -04:00 |
|
reyesj2
|
63f3e23e2b
|
soup typo
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-01 09:54:19 -04:00 |
|
Jason Ertel
|
66563a4da0
|
zeek networks will only ever have one HOME_NETWORKS setting
|
2024-05-01 09:31:11 -04:00 |
|
Jason Ertel
|
d0e140cf7b
|
zeek networks will only ever have one HOME_NETWORKS setting
|
2024-05-01 09:30:52 -04:00 |
|
Jason Ertel
|
87c6d0a820
|
zeek networks will only ever have one HOME_NETWORKS setting
|
2024-05-01 09:29:36 -04:00 |
|
reyesj2
|
eb1249618b
|
Update soup for Kafka
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-01 09:27:01 -04:00 |
|
reyesj2
|
cef9bb1487
|
Dynamically create Kafka topics based on event.module from elastic agent logs eg. zeek-topic. Depends on Kafka brokers having auto.create.topics.enable set to true
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-01 09:16:13 -04:00 |
|
reyesj2
|
bb49944b96
|
Setup elastic fleet rollover from logstash -> kafka output policy
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-30 16:47:40 -04:00 |
|
Jason Ertel
|
72db369fbb
|
Merge branch '2.4/dev' into jertel/wf
|
2024-04-30 15:16:41 -04:00 |
|
Jason Ertel
|
84db82852c
|
annotation updates for custom settings
|
2024-04-30 15:14:56 -04:00 |
|
reyesj2
|
fcc4050f86
|
Add id to grid-kafka fleet output policy
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-30 12:59:53 -04:00 |
|
reyesj2
|
9c83a52c6d
|
Add Kafka output to elastic-fleet setup. Includes separating topics by event.module with fallback to default-logs if no event.module is specified or doesn't match processors
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-30 12:01:31 -04:00 |
|
coreyogburn
|
ea4750d8ad
|
Merge pull request #12882 from Security-Onion-Solutions/cogburn/community-repos
Mark Repos as Community
|
2024-04-30 09:12:25 -06:00 |
|
Doug Burks
|
4d6124f982
|
FIX: Elasticsearch min_age regex #12885
|
2024-04-30 10:18:34 -04:00 |
|
Corey Ogburn
|
ddf662bdb4
|
Mark Repos as Community
Indicate that detection rules pulled from configured repos should be marked as Community rules.
|
2024-04-29 16:22:30 -06:00 |
|
reyesj2
|
fadb6e2aa9
|
Re-add original timestamp format + ignore failures with this processor
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 16:57:48 -04:00 |
|
reyesj2
|
192d91565d
|
Update final pipeline timestamp format for event.module system events
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 16:34:29 -04:00 |
|
reyesj2
|
a6e8b25969
|
Add Kafka connectivity between manager - > receiver nodes.
Add connectivity to Kafka between other node types that may need to publish to Kafka.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 15:48:57 -04:00 |
|
reyesj2
|
529bc01d69
|
Add missing configuration for nodes running Kafka broker role only
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 14:53:52 -04:00 |
|
reyesj2
|
11055b1d32
|
Rename kafkapass -> kafka_pass
Run so-kafka-clusterid within nodes.sls state so switchover is consistent
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 14:09:09 -04:00 |
|
reyesj2
|
fd9a91420d
|
Use SOC UI to configure list of KRaft (Kafka) controllers for cluster
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 11:37:24 -04:00 |
|
reyesj2
|
529c8d7cf2
|
Remove salt reactor for Kafka
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 11:35:46 -04:00 |
|
reyesj2
|
086ebe1a7c
|
Split kafka defaults between broker / controller
Setup config.map.jinja to update broker / controller / combined node types
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 09:08:14 -04:00 |
|
reyesj2
|
29c964cca1
|
Set kafka.nodes state to run first to populate kafka.nodes pillar
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-29 09:04:52 -04:00 |
|
DefensiveDepth
|
f2c3c928fc
|
Sigma pivot fix and cleanup
|
2024-04-29 08:49:05 -04:00 |
|
m0duspwnens
|
2c7eb3c755
|
only apply ulimits to suricata container if user enable mmap-locked
|
2024-04-25 10:05:59 -04:00 |
|
weslambert
|
b424426298
|
Exclude suricata
|
2024-04-25 09:14:18 -04:00 |
|
Josh Patterson
|
03f9160fcc
|
Merge pull request #12860 from Security-Onion-Solutions/issue/12856
allow for enabled/disable of so-elasticsearch-indices-delete cronjob
|
2024-04-25 09:07:44 -04:00 |
|
m0duspwnens
|
d50de804a8
|
update annotation
|
2024-04-25 09:04:34 -04:00 |
|
weslambert
|
983ef362e9
|
Merge pull request #12858 from Security-Onion-Solutions/fix/index_sorting
Change index sorting to account for older so-prefixed indices
|
2024-04-25 08:54:22 -04:00 |
|
Josh Brower
|
d88c1a5e0a
|
Merge pull request #12861 from Security-Onion-Solutions/2.4/detectionlogs
Add runtime status logs
|
2024-04-24 20:07:32 -04:00 |
|
weslambert
|
44afa55274
|
Fix comments about deletion
|
2024-04-24 17:41:37 -04:00 |
|
weslambert
|
ab832e4bb2
|
Include logstash-prefixed indices
|
2024-04-24 17:17:53 -04:00 |
|
DefensiveDepth
|
3c3ed8b5c5
|
Add runtime status logs
|
2024-04-24 16:33:47 -04:00 |
|
m0duspwnens
|
c9d9979f22
|
allow for enabled/disable of so-elasticsearch-indices-delete cronjob
|
2024-04-24 16:18:45 -04:00 |
|
m0duspwnens
|
73b5bb1a75
|
add memlock to so-suricata container
|
2024-04-24 15:35:17 -04:00 |
|
weslambert
|
59a02635ed
|
Change index sorting
|
2024-04-24 15:18:49 -04:00 |
|