Josh Brower
|
55e60cb749
|
initial refactor - beats/sysmon parsing
|
2020-07-28 11:03:33 -04:00 |
|
Jason Ertel
|
d2df405cf0
|
so-import-pcap improvements: Ensure PCAP filenames with spaces are handled properly; Provide link directly to the imported logs, filtered by import ID; Require sudo access to run so-import-pcap
|
2020-07-21 11:07:09 -04:00 |
|
Josh Patterson
|
f1d8548913
|
Merge pull request #1017 from Security-Onion-Solutions/quickfix/lstoes
dont run templates script if there arent templates
|
2020-07-16 13:37:15 -04:00 |
|
m0duspwnens
|
9606d86e84
|
dont run templates script if there arent templates
|
2020-07-16 13:36:44 -04:00 |
|
Josh Patterson
|
549916306c
|
Merge pull request #1008 from Security-Onion-Solutions/quickfix/lstoes
Quickfix/lstoes
|
2020-07-14 17:37:19 -04:00 |
|
m0duspwnens
|
5cf71596b2
|
add curlys
|
2020-07-14 17:36:52 -04:00 |
|
m0duspwnens
|
acaec6c125
|
remove recurse causing issues
|
2020-07-14 17:12:29 -04:00 |
|
Josh Brower
|
8647944ae6
|
Parsing & Hunt query updates
|
2020-07-14 16:59:06 -04:00 |
|
m0duspwnens
|
57bf23d83c
|
move templates from logstash to elasticsearch
|
2020-07-14 16:07:46 -04:00 |
|
Doug Burks
|
a1e6a85a68
|
explicitly set Suricata timestamp timezone to UTC
|
2020-07-14 15:49:46 -04:00 |
|
Wes Lambert
|
f9df39977b
|
Add observer name for Strelka events
|
2020-07-14 17:38:43 +00:00 |
|
Wes Lambert
|
d6afde90b0
|
Convert message timestamp to @timestamp
|
2020-07-14 13:37:00 +00:00 |
|
Jason Ertel
|
8f66a27f07
|
Refactor image repository to a single variable
|
2020-07-13 18:26:43 -04:00 |
|
Josh Brower
|
e62381e998
|
Merge pull request #982 from Security-Onion-Solutions/bugfix/alerting
Misc fixes
|
2020-07-10 19:50:27 -04:00 |
|
Josh Brower
|
65062d93f4
|
Misc fixes
|
2020-07-10 19:43:43 -04:00 |
|
m0duspwnens
|
24b8f81e38
|
merge with dev and resolve conflicts
|
2020-07-10 12:20:14 -04:00 |
|
Mike Reeves
|
c656bec9c0
|
Merge branch 'dev' into feature/espillarz
|
2020-07-10 11:35:12 -04:00 |
|
m0duspwnens
|
1f48dc765e
|
merge with dev and resolv conflicts
|
2020-07-10 10:36:48 -04:00 |
|
Mike Reeves
|
1a6c4c12b4
|
Fix elasticsearch yaml
|
2020-07-09 21:56:32 -04:00 |
|
Mike Reeves
|
6094d19b0b
|
Make hot default
|
2020-07-09 16:54:31 -04:00 |
|
Mike Reeves
|
3c6465bb7f
|
ES Jinja the config
|
2020-07-09 16:42:39 -04:00 |
|
m0duspwnens
|
5ca3ecf4bd
|
fix reference to master grain
|
2020-07-09 15:42:39 -04:00 |
|
Josh Brower
|
206bdc60f3
|
Merge pull request #967 from Security-Onion-Solutions/feature/low-level-alerts
Feature - low level alerts
|
2020-07-09 13:56:31 -04:00 |
|
Josh Brower
|
52f7111e1d
|
Feature - low level alerts
|
2020-07-09 13:53:55 -04:00 |
|
m0duspwnens
|
3cf31e2460
|
https://github.com/Security-Onion-Solutions/securityonion/issues/404
|
2020-07-09 11:27:06 -04:00 |
|
Doug Burks
|
8dfafffef0
|
remove duplicate line for message2.conn_uids
|
2020-07-09 06:44:08 -04:00 |
|
weslambert
|
4cf31e1ee7
|
Drop message field and original exiftool keys
|
2020-07-08 10:55:40 -04:00 |
|
Doug Burks
|
fef803a86c
|
Add ignore_failure to geoip processor calls #942
|
2020-07-08 10:41:14 -04:00 |
|
weslambert
|
b25a3b6986
|
Rename uids to uid
|
2020-07-08 09:39:37 -04:00 |
|
weslambert
|
2992938596
|
Merge pull request #947 from Security-Onion-Solutions/fix/strelka_exiftool
Add fields for exiftool keys
|
2020-07-07 17:13:57 -04:00 |
|
Wes Lambert
|
3b50ce032a
|
Add fields for exiftool keys
|
2020-07-07 20:02:09 +00:00 |
|
Mike Reeves
|
eccfaf94fb
|
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/937
|
2020-07-07 15:10:12 -04:00 |
|
Wes Lambert
|
e0570e1db7
|
Add Zeek FUID for Strelka records
|
2020-07-07 15:00:01 +00:00 |
|
Mike Reeves
|
c59096d9bd
|
rename node pillar to elasticsearch
|
2020-07-07 10:42:12 -04:00 |
|
Doug Burks
|
98cfba18e9
|
fix zeek.ftp description
|
2020-07-01 20:27:40 -04:00 |
|
Doug Burks
|
f6adf4ed56
|
fix zeek.smb_mapping description
|
2020-07-01 20:26:51 -04:00 |
|
Doug Burks
|
2cbd5ffe61
|
fix zeek.ssh description
|
2020-07-01 20:26:06 -04:00 |
|
Wes Lambert
|
84e2965fef
|
Addl krb fix
|
2020-06-30 03:06:01 +00:00 |
|
Wes Lambert
|
bf8798f1d1
|
Fix krb client/server cert subject parsing
|
2020-06-30 03:04:01 +00:00 |
|
Wes Lambert
|
8f5da66335
|
Add null safe operator for query name
|
2020-06-30 03:02:38 +00:00 |
|
William Wernert
|
a45fbb6f5c
|
Revert "[fix] discovery.zen.minimum_master_nodes is deprecated, update the key"
This reverts commit 8bd6c067aa.
|
2020-06-25 10:53:26 -04:00 |
|
William Wernert
|
8bd6c067aa
|
[fix] discovery.zen.minimum_master_nodes is deprecated, update the key
|
2020-06-24 13:10:18 -04:00 |
|
Wes Lambert
|
af451573eb
|
Move dataset from files to file
|
2020-06-23 17:43:28 +00:00 |
|
Mike Reeves
|
3681f91c37
|
Suricata Conn
|
2020-06-15 21:46:04 -04:00 |
|
Wes Lambert
|
206261fbe6
|
rename id to log.id.fuid for X509
|
2020-06-15 16:55:14 +00:00 |
|
Wes Lambert
|
18547e8ea8
|
enforce field types
|
2020-06-15 16:54:33 +00:00 |
|
Mike Reeves
|
6058d438bf
|
Fix Protocol
|
2020-06-12 12:28:29 -04:00 |
|
Mike Reeves
|
42938a4e67
|
Add the makor Suricata parsers
|
2020-06-12 12:14:48 -04:00 |
|
Mike Reeves
|
c0d24d942c
|
Merge remote-tracking branch 'remotes/origin/dev' into feature/metasuri
|
2020-06-09 13:31:31 -04:00 |
|
Mike Reeves
|
4b6af0cd81
|
Suricata DHCP
|
2020-06-08 08:58:35 -04:00 |
|