Wes
|
4b9c92c53d
|
Set RITA event.dataset value explicitly
|
2023-01-24 18:00:34 +00:00 |
|
Wes
|
f19cf75311
|
Change how event.dataset is determined for Suricata events
|
2023-01-24 14:45:00 +00:00 |
|
Wes
|
51692ac66c
|
Update index pattern in various template definitions to match new data stream naming convention
|
2023-01-23 21:52:44 +00:00 |
|
Wes
|
40c6b380df
|
Update Import and Zeek integration policies; also update Zeek ingest node pipelines to set event.dataset.
|
2023-01-23 21:44:46 +00:00 |
|
weslambert
|
7d3f6121eb
|
Remove default "logs-*" template settings for now
|
2023-01-19 10:29:10 -05:00 |
|
weslambert
|
7a499c9051
|
Modify default 'logs-*' template priority
|
2023-01-18 17:24:07 -05:00 |
|
weslambert
|
73a4dae28e
|
Make sure Elastic Agent data streams do not use replicas
|
2023-01-13 16:10:44 -05:00 |
|
Josh Patterson
|
3efca0010a
|
Merge pull request #9573 from Security-Onion-Solutions/2.4/firewall
2.4/firewall
|
2023-01-13 12:41:58 -05:00 |
|
m0duspwnens
|
6033e9a0de
|
use port_bindings from docker defaults in docker states
|
2023-01-13 10:15:10 -05:00 |
|
weslambert
|
7cba5626b7
|
Merge pull request #9570 from Security-Onion-Solutions/fix/elasticsearch_templates_elastic_agent
Change priority for Elastic Agent Elasticsearch index templates
|
2023-01-12 16:48:12 -05:00 |
|
weslambert
|
654d869e3e
|
Change priority from 500 to 200 for Elastic Agent index templates to avoid collisions with other templates
|
2023-01-12 16:46:08 -05:00 |
|
weslambert
|
fb8d8ea972
|
Update Elasticsearch index template for Kratos
|
2023-01-12 15:31:41 -05:00 |
|
weslambert
|
9416552338
|
Don't set the Kratos index explicitly
|
2023-01-12 15:25:35 -05:00 |
|
Wes
|
c3b83f1fc8
|
Update template settings to use data streams
|
2023-01-11 14:03:11 +00:00 |
|
Wes
|
5062dd2873
|
Suricata Elasticsearch ingest node pipeline changes - set 'alert' dataset
|
2023-01-11 14:02:09 +00:00 |
|
Wes
|
2e886d0c55
|
Remove data_index_name processor since we are using data streams
|
2023-01-11 13:58:38 +00:00 |
|
m0duspwnens
|
d4c6834cd0
|
merge with 2.4/dev
|
2023-01-06 14:01:58 -05:00 |
|
Wes
|
c8ff2c7a06
|
Update RITA beacon parsing
|
2023-01-03 16:03:49 +00:00 |
|
doug
|
4e5d1d587e
|
update sysmon ingest parser and Sysmon File dashboard
|
2023-01-03 09:02:17 -05:00 |
|
m0duspwnens
|
24876eecd9
|
change refs from sosnet to sosbridge
|
2022-12-22 14:02:40 -05:00 |
|
m0duspwnens
|
accc293c8a
|
2.4 firewall changes
|
2022-12-21 15:03:45 -05:00 |
|
weslambert
|
fd1be0ab2c
|
Remove 'so-' prefix for Elastic Agent/Fleet component templates
|
2022-12-19 10:11:26 -05:00 |
|
doug
|
07a4919cd3
|
remove old opcua files
|
2022-12-08 16:43:11 -05:00 |
|
Wes
|
14af1d36cb
|
Ensure ICS/SCADA pipelines are present
|
2022-12-06 15:58:47 +00:00 |
|
Wes
|
7f324bc47e
|
Remove extra space used during testing
|
2022-11-22 20:52:08 +00:00 |
|
Wes
|
a6bc5b108f
|
Add missing OPCUA 'activate_session' pipelines
|
2022-11-22 20:51:44 +00:00 |
|
m0duspwnens
|
b95a83b016
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into dockerips
|
2022-11-22 14:17:19 -05:00 |
|
weslambert
|
356904f751
|
Fix spelling of 'wireguard.responses' field name
|
2022-11-22 13:03:04 -05:00 |
|
weslambert
|
6b77843e52
|
Fix format/speliing for 'enip.status_code' field name
|
2022-11-22 12:07:55 -05:00 |
|
weslambert
|
13faf63770
|
Fix spelling for 'stun.class' field name
|
2022-11-22 12:07:15 -05:00 |
|
Wes
|
a38e312df4
|
Add COTP and TDS ingest pipelines
|
2022-11-22 13:36:27 +00:00 |
|
Wes
|
05b9a067fd
|
Add additional ICS/SCADA ingest node pipelines
|
2022-11-17 16:03:21 +00:00 |
|
Wes
|
638a3568b0
|
Update ingest node pipelines for ICS/SCADA protocols
|
2022-11-16 21:11:21 +00:00 |
|
Mike Reeves
|
6016b0e38a
|
Add dynamic ability for IP range for sosnet
|
2022-11-14 20:20:38 -05:00 |
|
Mike Reeves
|
e41361e127
|
Add Docker IP Skeleton
|
2022-11-14 17:43:14 -05:00 |
|
Mike Reeves
|
3378f58300
|
Add Docker IP Skeleton
|
2022-11-14 17:07:42 -05:00 |
|
Mike Reeves
|
a2d3b95e92
|
Add Docker IP Skeleton
|
2022-11-14 13:04:31 -05:00 |
|
Mike Reeves
|
5c50fdb74c
|
Add Docker IP Skeleton
|
2022-11-14 13:00:56 -05:00 |
|
m0duspwnens
|
c880be8d45
|
use curator defaults.yaml merged with pillar for actions
|
2022-10-21 10:38:32 -04:00 |
|
m0duspwnens
|
eed3746ebc
|
fix some globals
|
2022-10-12 13:39:37 -04:00 |
|
m0duspwnens
|
b526532ab6
|
use global vars in states
|
2022-10-11 11:57:15 -04:00 |
|
doug
|
fee5a7bea9
|
initial quick OCD pass
|
2022-09-23 16:29:55 -04:00 |
|
Mike Reeves
|
e3f4a58989
|
Merge pull request #8804 from Security-Onion-Solutions/funstuff
Firewall and More
|
2022-09-23 14:00:51 -04:00 |
|
Wes
|
0fd5fee868
|
Fix syntax for Fleet component templates
|
2022-09-22 15:07:43 +00:00 |
|
m0duspwnens
|
c77fcc74c1
|
merge in 2.4./firewall changes
|
2022-09-22 10:55:39 -04:00 |
|
Wes
|
46dd4c2749
|
Rename component mappings and references for Security Onion
|
2022-09-20 20:33:06 +00:00 |
|
Wes
|
7f2c5bc757
|
Add component templates for Fleet
|
2022-09-20 20:27:26 +00:00 |
|
Mike Reeves
|
85339d7cb1
|
Add helpLinks to everything
|
2022-09-20 15:43:34 -04:00 |
|
Doug Burks
|
df18f8f886
|
Merge pull request #8779 from Security-Onion-Solutions/2.4/dev
2.4/dev
|
2022-09-20 13:32:54 +00:00 |
|
weslambert
|
509c32482f
|
Update so-elasticsearch-templates-load to allow for proper loading of differently formatted Elastic Agent index templates
|
2022-09-19 16:39:49 -04:00 |
|