Josh Brower
|
31cd5b1365
|
Add support for dns.resolved_ip
|
2025-06-20 15:02:59 -04:00 |
|
Jorge Reyes
|
d9790b04f6
|
Merge pull request #14676 from Security-Onion-Solutions/reyesj2/fixsystemtime
fix system integration time overwrite and delete unused ingest pipeline
|
2025-06-03 14:01:42 -05:00 |
|
reyesj2
|
d240fca721
|
remove usage of temp file
|
2025-06-03 08:45:04 -05:00 |
|
reyesj2
|
4d6171bde6
|
rename script
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-06-03 07:32:12 -05:00 |
|
reyesj2
|
6238a5b3ed
|
tighten up search timeframe
|
2025-06-02 16:31:26 -05:00 |
|
reyesj2
|
061600fa7a
|
shebang line
|
2025-06-02 15:55:46 -05:00 |
|
reyesj2
|
1b89cc6818
|
so-elasticsearch-index-growth script
|
2025-06-02 15:41:03 -05:00 |
|
Doug Burks
|
bf38055a6c
|
add echo to end of so-elasticsearch-ilm-stop
|
2025-05-30 11:41:50 -04:00 |
|
Doug Burks
|
90b8d6b2f7
|
add echo to end of so-elasticsearch-ilm-start
|
2025-05-30 11:41:11 -04:00 |
|
Doug Burks
|
45d541d4f2
|
FIX: so-elasticsearch-ilm-start needs shebang #14688
|
2025-05-30 09:55:53 -04:00 |
|
Doug Burks
|
58936b31d5
|
FIX: Improve annotation for Elasticsearch index deletion #14682
|
2025-05-29 15:19:21 -04:00 |
|
reyesj2
|
fcdacc3b0d
|
fix system integration time overwrite and delete unused ingest pipeline
|
2025-05-29 12:21:28 -05:00 |
|
Jorge Reyes
|
d3ee5ed7b8
|
use zeek network.community_id when available
|
2025-05-28 09:20:41 -05:00 |
|
Josh Brower
|
b753d40861
|
Tighten parsing
|
2025-05-20 17:06:11 -04:00 |
|
Josh Brower
|
b55cb257b6
|
Add parsing for Playbook
|
2025-05-19 13:25:27 -04:00 |
|
Josh Brower
|
df103b3dca
|
Spacing
|
2025-05-14 16:36:59 -04:00 |
|
Josh Brower
|
0542c77137
|
Remove wip config
|
2025-05-14 16:35:09 -04:00 |
|
Josh Brower
|
9022dc24fb
|
Add Parsing for Playbooks
|
2025-05-14 13:19:50 -06:00 |
|
reyesj2
|
e1d31c895e
|
add null check
|
2025-05-07 21:25:30 -05:00 |
|
Mike Reeves
|
92d8985f3c
|
enable the delete on heavynodes
|
2025-05-02 08:52:57 -04:00 |
|
Josh Patterson
|
272410ecae
|
Merge pull request #14568 from Security-Onion-Solutions/fixem
Fixem
|
2025-04-23 13:28:29 -04:00 |
|
Josh Patterson
|
77f88371b8
|
manage default and local in separate states
|
2025-04-23 08:30:37 -04:00 |
|
Mike Reeves
|
e3c8d22cac
|
Update enabled.sls
|
2025-04-18 16:43:17 -04:00 |
|
reyesj2
|
58df566c79
|
add mapping for metadata.kafka.timestamp
|
2025-04-14 14:30:40 -05:00 |
|
reyesj2
|
395b81ffc6
|
FIX: Add log.origin.file.line to base templates #14417
|
2025-04-14 14:30:00 -05:00 |
|
Josh Brower
|
4c3518385b
|
Change timeout to 1s
|
2025-04-11 07:37:09 -04:00 |
|
reyesj2
|
4d7fdd390c
|
ldap_search include observer.name
|
2025-03-18 08:52:43 -05:00 |
|
Josh Brower
|
6081c46d7f
|
Merge pull request #14362 from Security-Onion-Solutions/reyesj2-patch-2
fix osquery action_data mapping conflict
|
2025-03-08 10:18:12 -05:00 |
|
reyesj2
|
4dd72ad15c
|
fix osquery action_data mapping conflict
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-07 17:05:13 -06:00 |
|
Doug Burks
|
cce94d96d1
|
Update soc_elasticsearch.yaml to include note about ILM rollover
|
2025-03-06 11:14:48 -05:00 |
|
Jorge Reyes
|
515cb3aea8
|
Merge pull request #14345 from Security-Onion-Solutions/reyesj2-patch-2
osquery templates
|
2025-03-05 14:28:08 -06:00 |
|
reyesj2
|
d2884ef00b
|
typo
|
2025-03-05 14:02:45 -06:00 |
|
reyesj2
|
0f16b00563
|
osquery templates
|
2025-03-05 13:57:47 -06:00 |
|
Jorge Reyes
|
f35930317b
|
Merge pull request #14336 from Security-Onion-Solutions/reyesj2-patch-2
ES 8.17.3
|
2025-03-04 15:36:59 -06:00 |
|
reyesj2
|
11dc004811
|
ES 8.17.3
|
2025-03-04 14:24:38 -06:00 |
|
Jorge Reyes
|
966503d875
|
Merge pull request #14331 from Security-Onion-Solutions/reyesj2-patch-2
osquery v1.15.0 index templates updates
|
2025-03-04 13:17:28 -06:00 |
|
reyesj2
|
124bf266b5
|
osquery v1.15.0 index templates updates
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-04 12:27:04 -06:00 |
|
Jason Ertel
|
85450693a2
|
Merge branch '2.4/dev' into jertel/wip
|
2025-03-04 10:55:29 -05:00 |
|
Jason Ertel
|
0047246cf2
|
reduce stdout verbosity
|
2025-03-04 10:55:12 -05:00 |
|
reyesj2
|
4bd83f8983
|
zeek traceroute & ntp
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-03 10:48:06 -06:00 |
|
reyesj2
|
9bc64bf453
|
managed int multiline input
|
2025-02-27 16:48:07 -06:00 |
|
reyesj2
|
e2772e899e
|
component template missing metadata field
|
2025-02-24 10:24:11 -06:00 |
|
reyesj2
|
3f2b0973af
|
manually create unused logs-soc@package for successful elasticsearch templates load
|
2025-02-24 08:59:59 -06:00 |
|
reyesj2
|
69b559fb26
|
ES 8.17.2 pipeline version updates
|
2025-02-20 17:11:28 -06:00 |
|
reyesj2
|
df350b5a56
|
ES 8.17.2
|
2025-02-20 14:20:09 -06:00 |
|
reyesj2
|
3b6344e7f0
|
add back settings previously defined when overwritting logs-elastic_agent@package and logs-endpoint.diagnostics.collection@package
|
2025-02-20 12:42:30 -06:00 |
|
reyesj2
|
c9b41e2eb1
|
formatting
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-02-20 10:11:34 -06:00 |
|
reyesj2
|
499d473b9d
|
set metrics indices to 0 replicas
|
2025-02-20 10:06:59 -06:00 |
|
reyesj2
|
45c66b93d7
|
make sure only a non-empty file is loaded
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-02-19 09:23:48 -06:00 |
|
Jorge Reyes
|
a3dba9b566
|
Merge pull request #14255 from Security-Onion-Solutions/foxtrot
ES 8.17.1
|
2025-02-18 14:58:46 -06:00 |
|