Commit Graph

1271 Commits

Author SHA1 Message Date
Wes Lambert ec11b9ea25 Remove Redis config from eval PL 2020-02-05 20:34:32 +00:00
Josh Patterson 3fff89e538 Merge pull request #308 from Security-Onion-Solutions/quickfix/helix
Quickfix/helix
2020-02-05 15:10:45 -05:00
m0duspwnens 799cf32265 fix logstash for so-helix role 2020-02-05 14:45:07 -05:00
William Wernert 981dfa1cb2 chmod +x script changes 2020-02-05 11:39:37 -05:00
Mike Reeves b69dfd9b25 Helix fix dockers 2020-02-05 11:27:19 -05:00
William Wernert 3e97930506 Merge branch 'dev' into feature/script-fixes
# Conflicts:
#	salt/auth/init.sls
#	salt/common/tools/sbin/so-bro-restart
#	salt/common/tools/sbin/so-bro-start
#	salt/common/tools/sbin/so-bro-stop
#	salt/wazuh/files/wazuh-manager-whitelist
2020-02-05 10:58:51 -05:00
Josh Brower c1dd26d97e Logstash EVAL pipeline fix - osquery 2020-02-05 08:12:08 -05:00
m0duspwnens ad651dbea4 fix grafana for zeek 2020-02-04 17:21:13 -05:00
Josh Patterson 8148be6ec8 Merge pull request #301 from Security-Onion-Solutions/quickfix/zeek
fix zeek state
2020-02-03 11:17:39 -05:00
m0duspwnens 820462e45a fix zeek state 2020-02-03 11:15:44 -05:00
Josh Brower a6a999af95 tcpreplay fix 2020-02-03 09:59:41 -05:00
Josh Brower b5bf12f8c8 Zeek - bpf fixup 2020-01-31 15:06:57 -05:00
Josh Brower f5efc68825 Merge pull request #289 from Security-Onion-Solutions/feature/so-status
feature/so-status
2020-01-31 14:02:15 -05:00
Josh Brower c96a95e526 SO Scripts - fixes 2020-01-31 12:41:01 -05:00
m0duspwnens 6b580eaba9 evalmode fix 2020-01-30 17:54:24 -05:00
m0duspwnens 68e7dcfba0 evalfix 2020-01-30 17:38:48 -05:00
m0duspwnens 88967c2512 evalfix 2020-01-30 17:36:38 -05:00
m0duspwnens d94065fa00 evalfix 2020-01-30 17:09:06 -05:00
William Wernert 025c1972cd Merge pull request #288 from Security-Onion-Solutions/hotfix/auth-init
hotfix/auth-init
2020-01-30 16:34:24 -05:00
Mike Reeves 1e0d0d74e1 Fix Eval Event Pickup x2 2020-01-30 16:16:21 -05:00
Mike Reeves c32b2726fa Fix Eval Event Pickup 2020-01-30 16:10:59 -05:00
Mike Reeves 59d6b7cb8a Add log paths 2020-01-30 16:00:57 -05:00
Mike Reeves 048c77695d Fix Filebeat 2020-01-30 15:47:51 -05:00
William Wernert 746bd99f99 Merge branch 'dev' into feature/so-status 2020-01-30 12:41:41 -05:00
William Wernert f839f38553 Fix for jinja error 2020-01-30 12:40:39 -05:00
William Wernert 5dec2b1c87 Move auth init.sls to docker registry 2020-01-30 12:39:09 -05:00
Mike Reeves 21e374c82e Fix SSL State 2020-01-30 11:10:52 -05:00
Josh Brower 3fdc5fbef4 Dep Bro and enabled Zeek BPF 2020-01-30 09:45:02 -05:00
Wes Lambert 3277ca185e Update Zeek config 2020-01-29 22:09:32 +00:00
weslambert eba02ef3b4 Merge pull request #279 from Security-Onion-Solutions/features/heavynode
Features/heavynode
2020-01-29 17:07:00 -05:00
m0duspwnens 07df8bff7e add filebeat features back 2020-01-29 17:00:39 -05:00
m0duspwnens 0d22502072 changes to filebeat for heavynode 2020-01-29 16:45:04 -05:00
Josh Brower a75949e062 Merge pull request #274 from Security-Onion-Solutions/fix/elastic_clear
so-elastic-clear: Set IP in script
2020-01-29 15:49:16 -05:00
Wes Lambert aa3fc72565 Change bro to zeek 2020-01-29 18:56:21 +00:00
m0duspwnens bd5b597aed heavynode 2020-01-29 12:56:25 -05:00
m0duspwnens 306cc1127b heavynode 2020-01-29 12:56:25 -05:00
Wes Lambert ef83d812d2 Set IP 2020-01-29 17:41:56 +00:00
Josh Brower 5213c19e44 Suricata - logfile fix 2020-01-29 09:30:03 -05:00
Mike Reeves bd395b8356 Update filebeat.yml 2020-01-28 22:20:21 -05:00
weslambert 101c2a93d1 Merge pull request #269 from Security-Onion-Solutions/feature/so-status
feature/so-status
2020-01-28 22:13:47 -05:00
Josh Brower 3925ed52c7 Suricata - BPF hotfix 2020-01-28 22:02:18 -05:00
Mike Reeves bf1187ad60 Merge pull request #270 from Security-Onion-Solutions/feature/bpf-zeek
Zeek - Initial BPF Support
2020-01-28 21:49:03 -05:00
Mike Reeves 357cfcbe78 Merge pull request #266 from Security-Onion-Solutions/fix/elastalert_indices
Update config.yaml for Elastalert shard/replica changes
2020-01-28 21:47:07 -05:00
Josh Brower aa2fbc2d53 Zeek - Initial BPF support 2020-01-28 21:44:42 -05:00
Mike Reeves 745a92f217 Merge pull request #259 from Security-Onion-Solutions/fix/wazuh_whitelist
Don't restart when running whitelist script
2020-01-28 21:44:06 -05:00
William Wernert 5bd037e88c Initial so-status script 2020-01-28 21:42:47 -05:00
William Wernert 50d4693a09 Merge branch 'dev' into feature/script-fixes 2020-01-28 21:39:41 -05:00
Josh Brower 492ad7035b Merge pull request #268 from Security-Onion-Solutions/feature/nsm_clear
Feature/nsm clear
2020-01-28 21:01:04 -05:00
Wes Lambert 48ebc5e2e3 Fix data checks 2020-01-29 01:13:40 +00:00
Wes Lambert 5e0299e7bb Add PCAP stop|start|restart scripts 2020-01-29 01:11:22 +00:00