Jason Ertel
1236c8c1f2
support pcap imports for sensors in distributed grids
2025-03-21 10:34:55 -04:00
Jason Ertel
ad8f3dfde7
use specified role on new user add
2025-03-17 14:55:40 -04:00
Jason Ertel
2af05b9a23
switch back to colon for better clarity
2025-03-07 08:24:19 -05:00
Doug Burks
3037dc7c38
Update soc_soc.yaml to fix previous change
2025-03-07 07:13:27 -05:00
Mike Reeves
14e95f4898
Update soc_soc.yaml
2025-03-06 21:01:45 -05:00
Mike Reeves
bad0031829
Update soc_soc.yaml
2025-03-06 20:58:23 -05:00
Mike Reeves
03ebc2d86e
Add Actions
2025-03-05 15:58:10 -05:00
Mike Reeves
3021ed5d36
Add Actions
2025-03-05 15:56:26 -05:00
Mike Reeves
b51aa56e86
Some things I thought were bools are not bools
2025-03-05 15:15:26 -05:00
Mike Reeves
b01fb733a9
Some things I thought were bools are not bools
2025-03-05 14:56:26 -05:00
Mike Reeves
c7c6d3e556
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into truefalse
2025-03-05 13:21:21 -05:00
Corey Ogburn
21a64b6c1d
Add Client Parameter
...
Add groupItemsPerPage so detections groupby tables have proper default value for page size.
2025-03-05 09:43:21 -07:00
Doug Burks
c6c67f4d06
FEATURE: Add sankey chart to Elastic Agent API dashboard to show relationship between process.name and process.Ext.api.name #14339
2025-03-05 06:31:16 -05:00
Jason Ertel
85450693a2
Merge branch '2.4/dev' into jertel/wip
2025-03-04 10:55:29 -05:00
Jason Ertel
0047246cf2
reduce stdout verbosity
2025-03-04 10:55:12 -05:00
Doug Burks
44535cba8c
FIX: Elastic Agent Security Events dashboard should reference user.effective.name #14325
2025-03-04 06:46:56 -05:00
Doug Burks
e53f4fd1f1
Update defaults.yaml to quote the process.entity_id value
2025-03-02 05:54:30 -05:00
Mike Reeves
2ffaf2f601
Add hunt queries
2025-02-27 12:42:03 -05:00
Mike Reeves
4696152f78
Add hunt queries
2025-02-27 12:31:51 -05:00
Mike Reeves
a0944f8359
Add hunt queries
2025-02-27 12:17:57 -05:00
Mike Reeves
1fdbe987b8
Add hunt queries
2025-02-27 12:15:37 -05:00
Mike Reeves
40303c2d78
Add hunt queries
2025-02-27 12:10:59 -05:00
Mike Reeves
4b5048bd80
Add hunt queries
2025-02-27 11:57:57 -05:00
Mike Reeves
9d31050907
roll back SOC changes
2025-02-27 11:32:59 -05:00
Mike Reeves
e930d1dec6
roll back SOC changes
2025-02-27 11:28:06 -05:00
Mike Reeves
1d3bae4a7a
Add additional entries for actions
2025-02-27 11:15:51 -05:00
Mike Reeves
d950e4ebb3
Add additional entries for actions
2025-02-27 11:11:56 -05:00
Mike Reeves
3ba82bd5a4
Fix actions
2025-02-27 11:04:47 -05:00
Mike Reeves
6c00cdd726
Fix healthlink
2025-02-26 16:15:00 -05:00
Mike Reeves
8bc500e4da
soc
2025-02-26 14:16:42 -05:00
Mike Reeves
25217c3262
soc
2025-02-26 14:14:25 -05:00
Mike Reeves
0c2797ecdc
soc
2025-02-26 13:49:30 -05:00
Mike Reeves
101f6e744a
sensoroni
2025-02-26 13:44:35 -05:00
Mike Reeves
c5e0b8a42e
sensoroni
2025-02-26 13:40:24 -05:00
Mike Reeves
2bc2e86b01
actions
2025-02-26 13:36:16 -05:00
Mike Reeves
6fec217068
actions
2025-02-26 13:34:32 -05:00
Jason Ertel
9dafa062f8
annotation/config updates
2025-02-25 17:00:41 -05:00
Jason Ertel
bf19c6e730
ca download; ignore shard errors on startup; clarify oidc id
2025-02-05 15:04:04 -05:00
Corey Ogburn
23ebe966e0
Added Large Values Warning
...
maxBulkEscalateEvents now has a warning that large values may run into other limits.
2025-02-04 10:33:04 -07:00
Corey Ogburn
d0fa6eaf83
New Limit on Bulk Creating Related Events
...
Used by the UI and API to hint at a user that not every event will be attached to a case. Supports values up to 10,000 (the default limit on the number of documents returned by a single ES search).
2025-02-03 14:20:33 -07:00
Jorge Reyes
107ca38268
fix http query for "includes" function
2025-01-14 08:24:07 -06:00
Jorge Reyes
35547b476f
update http query
2025-01-14 08:13:27 -06:00
Jorge Reyes
ad765200c3
Merge pull request #14105 from Security-Onion-Solutions/reyesj2/moarzeekparse
...
Additional Zeek parsing & cloudflare_logpush integration
2025-01-13 11:37:21 -06:00
reyesj2
14c920a258
fix hidden ldap menu subtitle
2025-01-13 09:23:32 -06:00
Joshua Brower
dcdf31eee8
Fix folder perm
2025-01-10 16:15:17 -05:00
reyesj2
e60a1e4357
zeek ldap & ldap_search parsing
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-09 16:06:10 -06:00
Joshua Brower
a2caf7425d
Add config options
2025-01-07 13:22:14 -05:00
Joshua Brower
6fa11a38ef
Update defaults
2025-01-07 13:14:50 -05:00
Josh Brower
8408a53b82
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/navigator
2025-01-02 16:13:34 -05:00
Doug Burks
927b618ec9
Update Zeek QUIC dashboard, add Hunt query, add quic.server.name as column in Events table
2025-01-02 06:57:56 -05:00