Mike Reeves
66b087f12f
2.4.90
2024-07-25 11:49:57 -04:00
Jason Ertel
224c668c31
Merge pull request #13374 from Security-Onion-Solutions/jertel/rmtestparm
...
remove unused test parameters from setup
2024-07-22 11:08:34 -04:00
Jason Ertel
2e17e93cfe
remove unused test parameters from setup
2024-07-22 11:04:45 -04:00
Jason Ertel
7dfb75ba6b
remove unused test parameters from setup
2024-07-22 11:02:56 -04:00
Jorge Reyes
d97400e6f5
Merge pull request #13368 from Security-Onion-Solutions/reyesj2/kfps
...
fix kafka-logstash cert for searchnodes
2024-07-21 20:11:42 -04:00
reyesj2
cf1335dd84
searchnode logstash-kafka cert generation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-20 11:31:33 -04:00
coreyogburn
be74449fb9
Merge pull request #13365 from Security-Onion-Solutions/cogburn/suricata-regex-support
...
Cogburn/suricata regex support
2024-07-19 12:47:10 -06:00
Corey Ogburn
45b2413175
Removed Allow/Deny Regexes, Added Enable/Disable Regex
...
Update config and annotations for new regex support for suricata.
2024-07-19 12:45:24 -06:00
Corey Ogburn
022df966c7
Remove Allow/Deny Regex, Add Suricata Enable/Disable Regex
2024-07-19 12:28:04 -06:00
Jorge Reyes
92385d652e
Merge pull request #13363 from Security-Onion-Solutions/reyesj2/ksoup
...
kafka soup pillar
2024-07-19 10:50:48 -04:00
reyesj2
4478d7b55a
kafka soup pillar fix
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-19 09:32:47 -04:00
Josh Patterson
18df491f7e
Merge pull request #13355 from Security-Onion-Solutions/silsll
...
Exclude policy phases if not defined in defaults
2024-07-17 11:09:18 -04:00
m0duspwnens
cee6ee7a2a
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-17 10:16:36 -04:00
m0duspwnens
6d18177f98
only include global phases if defined in default for that index
2024-07-17 10:16:11 -04:00
m0duspwnens
72ad49ed12
add policy for so-lists and so-items
2024-07-16 14:36:06 -04:00
Jorge Reyes
d11f4ef9ba
Merge pull request #13350 from Security-Onion-Solutions/reyesj2/kflux
...
Kafka influxdb metrics & pillar update
2024-07-16 14:26:09 -04:00
reyesj2
03ca7977a0
quote variables
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-16 14:14:55 -04:00
m0duspwnens
91b2e7d400
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-16 14:06:56 -04:00
m0duspwnens
34c3a58efe
add cold policy
2024-07-16 14:03:48 -04:00
Josh Patterson
a867557f54
Merge pull request #13353 from Security-Onion-Solutions/fci
...
fix custom indices
2024-07-16 13:18:11 -04:00
m0duspwnens
b814f32e0a
fix custom indices
2024-07-16 12:39:30 -04:00
coreyogburn
2df44721d0
Merge pull request #13349 from Security-Onion-Solutions/cogburn/bulk-indexer
...
New Config Values for Detections Bulk Indexer
2024-07-15 15:34:01 -06:00
Corey Ogburn
d0565baaa3
New Config Values for Detections Bulk Indexer
...
`maxScrollSize` defines the "page size" of each scroll request.
`bulkIndexerWorkerCount` defines how many worker threads a bulk indexer should use. 0 or fewer indicates that 1 thread per CPU core should be used.
2024-07-15 14:43:47 -06:00
reyesj2
1b623c5c7a
Show Kafka EPS for nodes with broker role only
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:27:48 -04:00
reyesj2
542a116b8c
use so-yaml add for kafka pillar change
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:26:52 -04:00
Doug Burks
e7b6496f98
Merge pull request #13348 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346
2024-07-15 15:59:49 -04:00
Doug Burks
3991c7b5fe
FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346
2024-07-15 15:52:00 -04:00
weslambert
bf07d56da6
Merge pull request #13341 from Security-Onion-Solutions/revert-13323-fix/agent_pipeline
...
Revert "Change pipeline version for agent"
2024-07-15 11:38:56 -04:00
weslambert
cdbffa2323
Merge pull request #13342 from Security-Onion-Solutions/revert-13316-foxtrot
...
Revert "Elastic 8.14.2"
2024-07-15 11:38:48 -04:00
Josh Patterson
55469ebd24
Merge pull request #13340 from Security-Onion-Solutions/surianno
...
force var to be list of string
2024-07-15 11:34:00 -04:00
weslambert
4e81860a13
Revert "Change pipeline version for agent"
2024-07-15 11:33:52 -04:00
m0duspwnens
a23789287e
force var to be list of string
2024-07-15 11:29:47 -04:00
weslambert
fe1824aedd
Revert "Elastic 8.14.2"
2024-07-15 11:28:59 -04:00
Jorge Reyes
e58b2c45dd
Merge pull request #13335 from Security-Onion-Solutions/reyesj2/kgz
...
FIX: Kafka configuration updates
2024-07-12 15:55:43 -04:00
reyesj2
5d322ebc0b
Allow searchnodes to run kafka.ssl state for kafka-logstash cert generation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-12 14:45:11 -04:00
reyesj2
7ea8d5efd0
Remove redis input pipeline from searchnodes when global pipeline is Kafka
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-12 14:44:10 -04:00
reyesj2
4182ff66a0
rearrange kafka pillar, declutters SOC ui
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-11 16:37:16 -04:00
reyesj2
ff29d9ca51
Update log-check to ignore kafka data directories
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-11 10:23:51 -04:00
reyesj2
4a88dedcb8
Fixin kafka.ssl state and include name for kafka_user
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 16:18:46 -04:00
reyesj2
cfe5c1d76a
remove elasticsearch.ca from receiver allowed_states. Replaced by generated kafka trust
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 13:24:02 -04:00
weslambert
ebf5159c95
Merge pull request #13323 from Security-Onion-Solutions/fix/agent_pipeline
...
Change pipeline version for agent
2024-07-10 13:01:29 -04:00
weslambert
d432019ad9
Change version from 1.13.1 to 1.20.0
2024-07-10 12:48:08 -04:00
reyesj2
0d8fd42be3
update pillarwatch engine
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:37:07 -04:00
reyesj2
d5faf535c3
Only interact with logstash configuration when Kafka pipeline is enabled otherwise leave it default
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:36:44 -04:00
reyesj2
8e1edd1d91
split Kafka ssl from ssl/init. Certs won't be generated until Kafka is enabled. Also runs some clean up for old Kafka certs
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:32:43 -04:00
reyesj2
d791b23838
Generate new Kafka truststore
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:29:09 -04:00
weslambert
0db0754ee5
Merge pull request #13316 from Security-Onion-Solutions/foxtrot
...
Elastic 8.14.2
2024-07-10 08:53:03 -04:00
Wes
1f5a990b1e
Remove lines that aren't needed right now
2024-07-09 18:32:06 +00:00
weslambert
7a2f01be53
Update VERSION
2024-07-09 13:58:13 -04:00
Doug Burks
dadb0db8f3
Merge pull request #13321 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Update SOC MOTD #13320
2024-07-09 12:58:22 -04:00