Josh Brower
|
b8137214e4
|
Initial Support - Live Query to Hunt
|
2021-02-26 08:08:09 -05:00 |
|
Josh Patterson
|
dc673eef77
|
Merge pull request #3148 from Security-Onion-Solutions/salt-3002.5
Salt 3002.5
|
2021-02-25 23:00:35 -05:00 |
|
m0duspwnens
|
9fa625189f
|
upgrade to salt 3002.5 https://github.com/Security-Onion-Solutions/securityonion/issues/3147
|
2021-02-25 20:07:29 -05:00 |
|
Mike Reeves
|
e06ca75677
|
Merge pull request #3144 from Security-Onion-Solutions/interfaces
Don't disable NICs
|
2021-02-25 17:28:47 -05:00 |
|
Mike Reeves
|
a47a3d51c9
|
Merge pull request #3139 from Security-Onion-Solutions/feature/soup-log_size_limit
Show log_size_limit message at end of soup instead of during
|
2021-02-25 17:10:38 -05:00 |
|
William Wernert
|
b024dae72e
|
[fix] Don't call set_main_ip a second time
|
2021-02-25 15:19:28 -05:00 |
|
Josh Patterson
|
8a0e0e88e0
|
Merge pull request #3142 from Security-Onion-Solutions/issue/3130
stop zeek state.db from getting owned by root
|
2021-02-25 15:01:20 -05:00 |
|
Mike Reeves
|
2c8bc16c8f
|
Remove some nmcli business
|
2021-02-25 13:43:02 -05:00 |
|
Mike Reeves
|
37c13362df
|
Netowrk Manager needs to chill
|
2021-02-25 13:20:29 -05:00 |
|
Mike Reeves
|
51e8839daf
|
Inverse NIC offload
|
2021-02-25 11:46:00 -05:00 |
|
Josh Patterson
|
18365ed87d
|
Merge pull request #3140 from Security-Onion-Solutions/issue/3130
Issue/3130
|
2021-02-25 11:27:46 -05:00 |
|
m0duspwnens
|
fcd3f81400
|
fix quotes
|
2021-02-25 11:16:53 -05:00 |
|
m0duspwnens
|
c8213fa3d4
|
change docker exec
|
2021-02-25 11:07:54 -05:00 |
|
m0duspwnens
|
add66e750e
|
forgot to add -c
|
2021-02-25 10:49:09 -05:00 |
|
William Wernert
|
6a097beaff
|
Show log_size_limit message at end of soup instead of during
|
2021-02-25 10:47:29 -05:00 |
|
Doug Burks
|
79fefd83ef
|
Merge pull request #3134 from Security-Onion-Solutions/issue/3128
Improve Hunt queries for ssh and tunnel #3128
|
2021-02-25 07:11:20 -08:00 |
|
m0duspwnens
|
d52abcbcbd
|
ensure zeekctl is run as user zeek https://github.com/Security-Onion-Solutions/securityonion/issues/3130
|
2021-02-25 09:58:07 -05:00 |
|
Doug Burks
|
c18c865764
|
Improve Hunt queries for ssh and tunnel #3128
|
2021-02-25 09:23:19 -05:00 |
|
Doug Burks
|
ef1e296415
|
Improve Hunt queries for ssh and tunnel #3128
|
2021-02-25 08:52:34 -05:00 |
|
Mike Reeves
|
ae89260793
|
Merge pull request #3127 from Security-Onion-Solutions/foxtrot
Add automation files for Suricata metadata
|
2021-02-25 08:26:20 -05:00 |
|
Jason Ertel
|
34dab9009c
|
Ensure Zeek spool dir is owned by Zeek to allow Zeek to start correctly
|
2021-02-25 08:10:13 -05:00 |
|
Jason Ertel
|
ef7cdf27bf
|
Add automation files for Suricata metadata
|
2021-02-25 07:43:11 -05:00 |
|
Mike Reeves
|
c39b516f38
|
Merge pull request #3121 from Security-Onion-Solutions/strelkainstall
Fix Strelka Rule updates, repo fix
|
2021-02-24 17:13:41 -05:00 |
|
Mike Reeves
|
39860ea6bd
|
Merge pull request #3123 from Security-Onion-Solutions/kilo
Add function to soup to notify user of log_size_limit issues
|
2021-02-24 17:09:07 -05:00 |
|
Mike Reeves
|
701cfe7e9a
|
Merge branch 'dev' into strelkainstall
|
2021-02-24 17:07:26 -05:00 |
|
William Wernert
|
4ae34f928c
|
Merge branch 'dev' into kilo
# Conflicts:
# setup/so-functions
|
2021-02-24 17:05:53 -05:00 |
|
Mike Reeves
|
ff577cdf41
|
Merge pull request #3079 from petiepooo/feature/eslogsize
calculate log_size_limit based on /nsm/elasticsearch
|
2021-02-24 17:03:35 -05:00 |
|
William Wernert
|
4a6ad7c87e
|
Set MAINIP to MNIC_IP when using a VPN
|
2021-02-24 16:31:45 -05:00 |
|
Mike Reeves
|
b30f964974
|
Moving the wildcard
|
2021-02-24 16:09:37 -05:00 |
|
Mike Reeves
|
262bf03595
|
Testing capitals
|
2021-02-24 16:04:53 -05:00 |
|
Mike Reeves
|
ae17a3aeb8
|
Fix Syntax try 3
|
2021-02-24 16:02:36 -05:00 |
|
Mike Reeves
|
ab66f175c5
|
Fix Syntax
|
2021-02-24 16:01:18 -05:00 |
|
Mike Reeves
|
8f3ba7633c
|
Fix Syntax
|
2021-02-24 15:57:18 -05:00 |
|
Mike Reeves
|
5949119cb5
|
Bypass route check
|
2021-02-24 15:53:55 -05:00 |
|
Mike Reeves
|
6058400aad
|
Bypass route check
|
2021-02-24 15:52:50 -05:00 |
|
William Wernert
|
f042312aac
|
Merge branch 'dev' into kilo
# Conflicts:
# salt/common/tools/sbin/soup
|
2021-02-24 15:42:10 -05:00 |
|
Mike Reeves
|
52fd3c0470
|
Merge pull request #3122 from Security-Onion-Solutions/strelka_repo_update
Modify soup to add Strelka rule repo in pillar
|
2021-02-24 15:35:35 -05:00 |
|
Wes Lambert
|
6ea8eab9af
|
Modify soup to add Strelka rule repo in pillar
|
2021-02-24 20:32:47 +00:00 |
|
William Wernert
|
775f274962
|
Also check /nsm/elasticsearch in soup log_size_limit check
Reflect changes from PR#3079
|
2021-02-24 14:36:41 -05:00 |
|
William Wernert
|
e500e24802
|
Only show log_size_limit warning on dist if heavynode pillars exist
|
2021-02-24 13:56:59 -05:00 |
|
William Wernert
|
298f7da90b
|
Fix indent in set_default_log_size
|
2021-02-24 13:56:33 -05:00 |
|
Mike Reeves
|
38d60752b7
|
Merge pull request #3110 from Security-Onion-Solutions/dockerclean
Docker Cleanup
|
2021-02-24 13:44:06 -05:00 |
|
Josh Patterson
|
25ca70efd8
|
Merge pull request #3120 from Security-Onion-Solutions/issue/3115
ensure log_level and log_level_logfile are set to info in /etc/salt/minion
|
2021-02-24 13:36:34 -05:00 |
|
Mike Reeves
|
bdfec5176d
|
Dont disable unused interfaces during setup
|
2021-02-24 13:22:06 -05:00 |
|
William Wernert
|
ece79379a5
|
Add file name/path to log_size_limit message
|
2021-02-24 12:54:14 -05:00 |
|
William Wernert
|
ac6f1df86f
|
[fix] Only check log_size_limit on .2X -> .30
* Since we're showing a message in the middle of soup, wait for keypress if it's shown
|
2021-02-24 12:35:17 -05:00 |
|
William Wernert
|
4507a89d95
|
tar arg fix (-x -> -z)
|
2021-02-24 12:24:54 -05:00 |
|
William Wernert
|
2be7ccac33
|
Add function to notify user that log_size_limit may be incorrect
|
2021-02-24 12:24:32 -05:00 |
|
Josh Patterson
|
81331264e7
|
Merge pull request #3117 from Security-Onion-Solutions/issue/3115
logfile is 1 word
|
2021-02-24 11:57:33 -05:00 |
|
m0duspwnens
|
eba5d271aa
|
logfile is 1 word https://github.com/Security-Onion-Solutions/securityonion/issues/3115
|
2021-02-24 11:56:43 -05:00 |
|