m0duspwnens
ea7715f729
use waitforstate var instead.
2024-05-23 10:41:10 -04:00
m0duspwnens
0b9ebefdb6
only show telem status in final whiptail if new deployment
2024-05-23 10:08:23 -04:00
Mike Reeves
19e66604d0
Merge pull request #13069 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update defaults.yaml
2024-05-23 08:22:05 -04:00
Mike Reeves
1e6161f89c
Update defaults.yaml
2024-05-23 08:19:43 -04:00
Josh Brower
a8c287c491
Merge pull request #13067 from Security-Onion-Solutions/2.4/fixpipeline
...
Fix strelka rule.uuid
2024-05-23 07:53:14 -04:00
Doug Burks
2c4f5f0a91
Merge pull request #13066 from Security-Onion-Solutions/dougburks-patch-1
...
Update defaults.yaml to fix order of groupby tables and eliminate dup…
2024-05-23 06:02:49 -04:00
DefensiveDepth
8e7c487cb0
Fix strelka rule.uuid
2024-05-23 05:59:31 -04:00
Doug Burks
3d4f3a04a3
Update defaults.yaml to fix order of groupby tables and eliminate duplicate
2024-05-23 05:56:18 -04:00
Josh Brower
ce063cf435
Merge pull request #13063 from Security-Onion-Solutions/2.4/yarafix
...
Fix casing issue
2024-05-22 18:51:54 -04:00
DefensiveDepth
a072e34cfe
Fix casing issue
2024-05-22 17:12:41 -04:00
DefensiveDepth
d19c1a514b
Detections backup script
2024-05-22 15:12:23 -04:00
weslambert
b415810485
Merge pull request #13061 from Security-Onion-Solutions/fix/tab_casing
...
Change tab casing to be consistent with other whiptail prompts
2024-05-22 13:44:09 -04:00
weslambert
3cfd710756
Change tab casing to be consistent with other whiptail prompts
2024-05-22 13:41:32 -04:00
reyesj2
382cd24a57
Small changes needed for using new Kafka docker image + added Kafka logging output to /opt/so/log/kafka/
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:39:21 -04:00
reyesj2
b1beb617b3
Logstash should be disabled when Kafka is enabled except when a minion override exists OR node is a standalone
...
- Standalone subscribes to Kafka topics via logstash for ingest
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:38:09 -04:00
reyesj2
91f8b1fef7
Set default replication factor back to Kafka default
...
If replication factor is > 1 Kafka will fail to start until another broker is added
- For internal automated testing purposes a Standalone will be utilized
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:35:09 -04:00
Jason Ertel
ca6e2b8e22
Merge pull request #13054 from Security-Onion-Solutions/jertel/eaconfig
...
fix elastalert settings
2024-05-21 18:38:03 -04:00
Jason Ertel
8af3158ea7
fix elastalert settings
2024-05-21 18:28:21 -04:00
Josh Brower
8b011b8d7e
Merge pull request #13053 from Security-Onion-Solutions/2.4/alertsefaults
...
Add rule.uuid to default groupbys
2024-05-21 17:54:27 -04:00
DefensiveDepth
f9e9b825cf
Removed unneeded groupby
2024-05-21 17:53:20 -04:00
DefensiveDepth
3992ef1082
Add rule.uuid to default groupbys
2024-05-21 17:45:56 -04:00
weslambert
556fdfdcf9
Merge pull request #13052 from Security-Onion-Solutions/fix/add_rule_uuid
...
Add rule.uuid for YARA matches
2024-05-21 17:09:49 -04:00
weslambert
f4490fab58
Add rule.uuid for YARA matches
2024-05-21 17:05:39 -04:00
weslambert
5aaf44ebb2
Merge pull request #13049 from Security-Onion-Solutions/fix/detections_alerts_component_template
...
Exclude detections from template name matching
2024-05-21 13:45:19 -04:00
weslambert
deb140e38e
Exclude detections from template name matching
2024-05-21 13:38:52 -04:00
Jason Ertel
3de6454d4f
Merge pull request #13047 from Security-Onion-Solutions/jertel/eaconfig
...
Jertel/eaconfig
2024-05-21 13:34:20 -04:00
Jason Ertel
d57cc9627f
exclude false positives related to detections
2024-05-21 13:31:50 -04:00
Jason Ertel
8ce19a93b9
exclude false positives related to detections
2024-05-21 13:29:20 -04:00
Jason Ertel
d315b95d77
elastalert settings
2024-05-21 07:15:19 -04:00
Doug Burks
6172816f61
Merge pull request #13044 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md with new Detections screenshot number
2024-05-21 06:49:35 -04:00
Doug Burks
03826dd32c
Update README.md with new Detections screenshot number
2024-05-21 06:43:07 -04:00
Jason Ertel
b7a4f20c61
elastalert settings
2024-05-20 20:11:30 -04:00
Jason Ertel
02b4d37c11
elastalert settings
2024-05-20 20:00:31 -04:00
Jason Ertel
f8ce039065
elastalert settings
2024-05-20 19:58:12 -04:00
Jason Ertel
e2d0b8f4c7
elastalert settings
2024-05-20 19:38:36 -04:00
Jason Ertel
8a3061fe3e
elastalert settings
2024-05-20 19:36:06 -04:00
Jason Ertel
c594168b65
elastalert settings
2024-05-20 19:05:43 -04:00
Jason Ertel
31fdf15ce1
Merge branch '2.4/dev' into jertel/eaconfig
2024-05-20 18:59:35 -04:00
Jason Ertel
6b2219b7f2
elastalert settings
2024-05-20 18:52:37 -04:00
coreyogburn
64144b4759
Merge pull request #13041 from Security-Onion-Solutions/cogburn/integrity-checker-annotations
...
Annotate integrityCheckFrequencySeconds per det engine
2024-05-20 14:52:38 -06:00
Corey Ogburn
6e97c39f58
Marked as Advanced
2024-05-20 14:52:05 -06:00
Corey Ogburn
026023fd0a
Annotate integrityCheckFrequencySeconds per det engine
2024-05-20 14:35:11 -06:00
Jorge Reyes
d7ee89542a
Merge pull request #13040 from Security-Onion-Solutions/lkscript
...
Create helper script for tpm enrollment
2024-05-20 15:25:50 -04:00
reyesj2
6fac6eebce
Helper script for enrolling tpm into luks
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-20 14:37:54 -04:00
coreyogburn
3c3497c2fd
Merge pull request #13039 from Security-Onion-Solutions/cogburn/integrity-check
...
Add Default IntegrityCheck Frequency Values
2024-05-20 11:26:30 -06:00
Corey Ogburn
fcc72a4f4e
Add Default IntegrityCheck Frequency Values
2024-05-20 11:23:25 -06:00
coreyogburn
28dea9be58
Merge pull request #13037 from Security-Onion-Solutions/cogburn/comp-report-path-change
...
Change Compilation Report Path
2024-05-17 15:48:52 -06:00
Corey Ogburn
0cc57fc240
Change Compilation Report Path
...
Move compilation report path to /opt/so/state and mount that foulder in SOC
2024-05-17 15:47:23 -06:00
weslambert
17518b90ca
Merge pull request #13036 from Security-Onion-Solutions/fix/yara_compile_report
...
Create YARA compile report for SOC integrity check
2024-05-17 16:15:21 -04:00
weslambert
d9edff38df
Create compile report for SOC integrity check
2024-05-17 16:10:10 -04:00