defensivedepth
3567dfc0dc
Move Airgap later in setup
2024-09-26 15:48:50 -04:00
defensivedepth
fe860481c5
Fix location for airgap
2024-09-26 08:52:53 -04:00
defensivedepth
778d5be407
Change summaries branch
2024-09-25 15:35:08 -04:00
defensivedepth
445a9679bd
Add so repo back in
2024-09-25 10:18:57 -04:00
defensivedepth
48aff374a3
Use temp summaries branch
2024-09-24 15:37:43 -04:00
defensivedepth
01f87218de
Airgap support
2024-09-24 12:04:24 -04:00
Mike Reeves
da5e91ee03
Update so-functions
2024-09-10 15:24:44 -04:00
m0duspwnens
576d218cd9
dont restart suricata during setup. retry rule reload for 3 minutes
2024-09-06 08:10:59 -04:00
Jason Ertel
56ef2a4e1c
Merge pull request #13430 from Security-Onion-Solutions/jertel/retryreposync
...
retry up to 5 times if reposync fails
2024-08-02 14:59:27 -04:00
Jason Ertel
c36e8abc19
retry up to 5 times if reposync fails
2024-08-02 14:52:08 -04:00
Jason Ertel
e76293acdb
Merge pull request #13429 from Security-Onion-Solutions/jertel/retryreposync
...
retry up to 5 times if reposync fails
2024-08-02 14:19:30 -04:00
Jason Ertel
5bdb4ed51b
retry up to 5 times if reposync fails
2024-08-02 14:17:14 -04:00
m0duspwnens
d9a696a411
run state from local
2024-08-01 14:02:21 -04:00
m0duspwnens
76ab4c92f0
use salt to install py modules during setup
2024-08-01 13:37:22 -04:00
m0duspwnens
1a363790a0
upgrade docker python module
2024-08-01 11:20:08 -04:00
Jason Ertel
2e17e93cfe
remove unused test parameters from setup
2024-07-22 11:04:45 -04:00
Jason Ertel
7dfb75ba6b
remove unused test parameters from setup
2024-07-22 11:02:56 -04:00
reyesj2
4182ff66a0
rearrange kafka pillar, declutters SOC ui
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-11 16:37:16 -04:00
reyesj2
d791b23838
Generate new Kafka truststore
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:29:09 -04:00
reyesj2
4e50dabc56
refix typos
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-14 23:03:06 -04:00
reyesj2
83412b813f
Renamed Kafka pillar
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 11:19:25 -04:00
reyesj2
b56d497543
Revert a so-setup change. Kafka is not an installable option
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 11:17:06 -04:00
reyesj2
dd40962288
Revert a whiptail menu change. Kafka is not an install option
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 11:07:23 -04:00
reyesj2
1fd5165079
Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/kafka
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-29 23:37:40 -04:00
m0duspwnens
ea7715f729
use waitforstate var instead.
2024-05-23 10:41:10 -04:00
m0duspwnens
0b9ebefdb6
only show telem status in final whiptail if new deployment
2024-05-23 10:08:23 -04:00
weslambert
3cfd710756
Change tab casing to be consistent with other whiptail prompts
2024-05-22 13:41:32 -04:00
weslambert
6dec9b4cf7
Merge pull request #12986 from Security-Onion-Solutions/fix/old_strelka
...
Remove old Strelka configuration for YARA
2024-05-14 09:27:19 -04:00
m0duspwnens
649f52dac7
create_local_directories in soup too
2024-05-13 10:37:56 -04:00
Jason Ertel
074d063fee
tests will retry on any rule import failure
2024-05-09 14:52:58 -04:00
Wes
6ed82d7b29
Remove YARA download in setup
2024-05-09 17:27:46 +00:00
reyesj2
2ad87bf1fe
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-08 16:30:45 -04:00
Jason Ertel
8364b2a730
update for testing
2024-05-07 14:30:52 -04:00
Jason Ertel
4ebe070cd8
test regexes for detections
2024-05-06 19:03:12 -04:00
DefensiveDepth
7f12d4c815
Exclude new sigma rules
2024-05-03 15:22:53 -04:00
Josh Patterson
b50789a77c
Merge pull request #12928 from Security-Onion-Solutions/orchit
...
Orchit
2024-05-03 15:17:34 -04:00
Doug Burks
6cbbb81cad
FEATURE: Add hyperlink to airgap screen in setup #12925
2024-05-03 12:59:41 -04:00
m0duspwnens
442a717d75
orchit
2024-05-03 12:08:57 -04:00
Doug Burks
5fe8c6a95f
Update so-whiptail to make installation screen more consistent
2024-05-03 09:38:34 -04:00
reyesj2
e960ae66a3
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka
2024-05-02 15:12:27 -04:00
Doug Burks
9a4a85e3ae
FEATURE: Lower EVAL memory requirement to 8GB RAM #12896
2024-05-01 07:54:38 -04:00
m0duspwnens
a663bf63c6
set Suricata as default pcap engine for eval
2024-04-29 14:22:04 -04:00
Mike Reeves
b5c5c7857b
Merge pull request #12846 from petiepooo/fix/check-srvc-status
...
check status before stopping service
2024-04-25 15:10:42 -04:00
Pete
e53e7768a0
check status before stopping service
...
resolves #12811 so-verify detects rare false error
If salt is uninstalled during call to so-setup where it detects a previous install, the "Failed" keyword from "systemctl stop $service" causes so-verify to falsely detect an installation error. This might happen if the user removes the salt packages between calls to so-setup, or if upgrading from Ubuntu 20.04 to 22.04 then installing 2.4.xx on top of a 2.3.xx installation.
The fix is to wrap the call to stop the service in a check if the service is running.
This ignores the setting of pid var, as the next use of pid is within a while loop that will not execute for the same reason the systemctl stop call was not launched in the background.
2024-04-23 21:24:39 +00:00
reyesj2
a6ff92b099
Note to remove so-kafka-clusterid. Update soup and setup to generate needed kafka pillar values
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 12:11:18 -04:00
reyesj2
af29ae1968
Merge kaffytaffy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 11:43:46 -04:00
m0duspwnens
0ed9894b7e
create kratos local pillar dirs during setup
2024-04-12 11:19:46 -04:00
reyesj2
3955587372
Use global.pipeline for redis / kafka states
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 16:20:09 -04:00
reyesj2
ca7253a589
Run kafka-clusterid script when pillar values are missing
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:38:03 -04:00
reyesj2
af53dcda1b
Remove references to kafkanode
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:32:00 -04:00