Wes Lambert
|
d2b93d531e
|
Basic syslog config
|
2020-05-28 12:36:29 +00:00 |
|
Wes Lambert
|
5afc05feb2
|
Update FB init for syslog
|
2020-05-28 12:35:22 +00:00 |
|
Wes Lambert
|
b9bdca509e
|
update Filebeat config for syslog
|
2020-05-28 12:33:41 +00:00 |
|
Doug Burks
|
f3efafc9ca
|
combine two notice queries into one query with multiple groupby
|
2020-05-28 08:01:33 -04:00 |
|
Doug Burks
|
60cc3e9675
|
remove address from DHCP leases query
|
2020-05-28 07:50:52 -04:00 |
|
weslambert
|
6a935b5452
|
Hive to TheHive
|
2020-05-27 15:43:41 -04:00 |
|
Wes Lambert
|
b80eb5f73b
|
Add Hive/ES/Cortex scripts
|
2020-05-27 17:43:17 +00:00 |
|
Wes Lambert
|
b26f6826dd
|
Rename Hive to TheHive in several places
|
2020-05-27 17:17:55 +00:00 |
|
Wes Lambert
|
d56bc4c167
|
fix path
|
2020-05-27 17:01:05 +00:00 |
|
Wes Lambert
|
3684cdf1c6
|
Update FB and LS
|
2020-05-27 17:00:09 +00:00 |
|
Wes Lambert
|
e78a3f3278
|
update Suricata config
|
2020-05-27 16:59:26 +00:00 |
|
Wes Lambert
|
b7a0f79038
|
Update Suricata init
|
2020-05-27 16:58:31 +00:00 |
|
weslambert
|
f3809cb93d
|
Wrap with quotes
|
2020-05-27 08:31:14 -04:00 |
|
Mike Reeves
|
4049df8cb4
|
Merge pull request #774 from Security-Onion-Solutions/feature/packages
Feature/packages
|
2020-05-26 15:40:30 -04:00 |
|
Mike Reeves
|
21cd66d109
|
add ntpdate/ntp
|
2020-05-26 14:05:47 -04:00 |
|
Mike Reeves
|
41935996d4
|
add ntpdate/ntp
|
2020-05-26 13:48:36 -04:00 |
|
Josh Brower
|
894bfd47f4
|
Merge pull request #771 from Security-Onion-Solutions/feature/communityid-hive-pivot
Elasticsearch Ingest fixes
|
2020-05-26 13:08:40 -04:00 |
|
Josh Brower
|
8723f8785e
|
osquery pipeline fix and fail state if errors
|
2020-05-26 13:05:56 -04:00 |
|
Doug Burks
|
7a657d1229
|
add Community ID to default fields in bottom data table in Hunt
|
2020-05-26 12:58:01 -04:00 |
|
Josh Brower
|
2cb7464086
|
Add TheHive communityid link
|
2020-05-26 12:01:58 -04:00 |
|
Mike Reeves
|
87407c9ace
|
rework common init.sls
|
2020-05-26 11:21:59 -04:00 |
|
Wes Lambert
|
0e51ab41cf
|
Update ES watermark settings
|
2020-05-26 14:18:58 +00:00 |
|
Wes Lambert
|
97306d3acd
|
rename indices
|
2020-05-26 14:05:33 +00:00 |
|
Wes Lambert
|
3eb62287ac
|
update Curator config for index transition
|
2020-05-26 14:00:16 +00:00 |
|
Wes Lambert
|
330de46249
|
update SOCtopus config for hostname/ip
|
2020-05-26 13:19:15 +00:00 |
|
Wes Lambert
|
e09027e795
|
update Strelka cron
|
2020-05-26 13:00:03 +00:00 |
|
Mike Reeves
|
31b3563fb3
|
Fix package versions
|
2020-05-24 10:56:30 -04:00 |
|
Mike Reeves
|
1c207afb31
|
Define packages in the common state
|
2020-05-23 12:00:24 -04:00 |
|
Josh Brower
|
35f3498ffa
|
Merge pull request #760 from Security-Onion-Solutions/feature/ingest-communityid
Ingest pipeline commid fix for conn logs
|
2020-05-22 17:11:38 -04:00 |
|
Josh Brower
|
56f5fbdf6b
|
Ingest pipeline commid fix for conn logs
|
2020-05-22 17:11:08 -04:00 |
|
Josh Brower
|
767eda6d60
|
Merge pull request #754 from Security-Onion-Solutions/feature/ingest-communityid
Feature/ingest communityid
|
2020-05-21 14:36:08 -04:00 |
|
Josh Brower
|
bff86ea802
|
zeek.common ingest parser fix
|
2020-05-21 14:35:25 -04:00 |
|
Josh Brower
|
c74ace89ba
|
Initial support - Ingest community_id
|
2020-05-21 14:34:00 -04:00 |
|
m0duspwnens
|
0a6f0efdc5
|
Sort so-status output alphabetically - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/747
|
2020-05-21 09:21:28 -04:00 |
|
m0duspwnens
|
9f5a38c26f
|
add so-filebeat to so-status for eval - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/706
|
2020-05-21 09:19:24 -04:00 |
|
m0duspwnens
|
d4840d203c
|
fix version lock for wazuh
|
2020-05-20 11:23:55 -04:00 |
|
m0duspwnens
|
92c2222879
|
ensure wazuh-agent service is enabled and running
|
2020-05-19 16:59:43 -04:00 |
|
Mike Reeves
|
0f2369b5cb
|
Fix permissions due to umask issues in Ubuntu 18
|
2020-05-19 16:31:39 -04:00 |
|
Mike Reeves
|
c045e3f936
|
remove replicas
|
2020-05-19 13:57:31 -04:00 |
|
Mike Reeves
|
46762e5ad9
|
change cortex to 0 replicas
|
2020-05-19 13:56:59 -04:00 |
|
Josh Patterson
|
07560463de
|
Merge pull request #737 from Security-Onion-Solutions/quickfix/wazuh
https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/695
|
2020-05-19 13:27:52 -04:00 |
|
Doug Burks
|
064768d07d
|
Fix dce_rpc hunt query #736
https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/736
|
2020-05-19 11:27:01 -04:00 |
|
Josh Brower
|
10691036e0
|
Update hive_init
|
2020-05-19 10:27:46 -04:00 |
|
m0duspwnens
|
4f65d17690
|
https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/695
|
2020-05-19 10:14:40 -04:00 |
|
Doug Burks
|
29420da565
|
Only process zeek.dns.tld if dns.query.name contains a dot #734
https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/734
|
2020-05-19 10:08:30 -04:00 |
|
Mike Reeves
|
fc4afe6767
|
Fix Curl statement
|
2020-05-19 09:58:16 -04:00 |
|
Mike Reeves
|
1d677bb529
|
Update known issues list
|
2020-05-19 09:36:36 -04:00 |
|
Josh Patterson
|
8957af0a4d
|
Merge pull request #733 from Security-Onion-Solutions/quickfix/sostatus
removing strelka-backend from strelka so-status map
|
2020-05-18 17:53:32 -04:00 |
|
m0duspwnens
|
411389b68e
|
removing strelka-backend from strelka so-status map
|
2020-05-18 17:52:47 -04:00 |
|
Josh Patterson
|
341c70de9e
|
Merge pull request #732 from Security-Onion-Solutions/quickfix/sostatus
add strelka container list for so-status
|
2020-05-18 17:46:55 -04:00 |
|