reyesj2
|
7c73b4713f
|
update analyzer pipeline
|
2025-11-14 15:47:29 -06:00 |
|
reyesj2
|
45b4b1d963
|
ingest zeek analyzer.log + update dpd dashboard with analyzer tag
|
2025-11-14 15:47:29 -06:00 |
|
reyesj2
|
fcfd74ec1e
|
zeek.analyzer format json
|
2025-11-14 15:47:29 -06:00 |
|
reyesj2
|
68b0cd7549
|
rename zeek.dpd zeek.analyzer
|
2025-11-14 15:47:29 -06:00 |
|
reyesj2
|
715d801ce8
|
format json zeek.dns
|
2025-11-14 15:47:19 -06:00 |
|
Jorge Reyes
|
4a810696e7
|
Merge pull request #15231 from Security-Onion-Solutions/reyesj2/bond0
fix so-setup error duplicate bond0
|
2025-11-14 12:12:46 -06:00 |
|
reyesj2
|
6b525a2c21
|
fix so-setup error duplicate bond0
|
2025-11-14 11:19:32 -06:00 |
|
Jorge Reyes
|
a5d8385f07
|
Merge pull request #15230 from Security-Onion-Solutions/reyesj2/pipeline-upd
suricata pipeline updates
|
2025-11-14 10:43:33 -06:00 |
|
reyesj2
|
211bf7e77b
|
ignore errors on tld script
|
2025-11-14 09:25:19 -06:00 |
|
reyesj2
|
1542b74133
|
move dns tld fields to its own pipeline
|
2025-11-14 09:24:58 -06:00 |
|
reyesj2
|
4314c79f85
|
bump suricata dns logging version
|
2025-11-14 08:24:31 -06:00 |
|
reyesj2
|
da9717bc79
|
don't attempt rename if field doesn't exist -- reducing pipeline stat errors
|
2025-11-14 08:15:40 -06:00 |
|
Jason Ertel
|
045cf7866c
|
Merge pull request #15225 from Security-Onion-Solutions/jertel/wip
pcap annotations
|
2025-11-14 08:37:37 -05:00 |
|
reyesj2
|
431e0b0780
|
format suricata.alert json
|
2025-11-13 19:29:50 -06:00 |
|
reyesj2
|
e782266caa
|
suricata 8 dns v3
|
2025-11-13 19:21:31 -06:00 |
|
coreyogburn
|
a4666b2c08
|
Merge pull request #15229 from Security-Onion-Solutions/cogburn/toggle-models
Add Enabled Flag to Models
|
2025-11-13 16:13:24 -07:00 |
|
Corey Ogburn
|
dcc3206e51
|
Add Enabled Flag to Models
|
2025-11-13 15:32:28 -07:00 |
|
Josh Patterson
|
8358b6ea6f
|
Merge pull request #15228 from Security-Onion-Solutions/bravo
wait for 200 from registry before proceeding
|
2025-11-13 16:34:43 -05:00 |
|
coreyogburn
|
d1a66a91c6
|
Merge pull request #15221 from Security-Onion-Solutions/cogburn/compress-context
CompressContextPrompt
|
2025-11-13 14:33:56 -07:00 |
|
Josh Patterson
|
7fdcb92614
|
wait for 200 from registry before proceeding
|
2025-11-13 16:30:58 -05:00 |
|
Jason Ertel
|
cec1890b6b
|
pcap annotations
|
2025-11-13 16:15:47 -05:00 |
|
Corey Ogburn
|
b1b66045ea
|
Change in prompt wording
|
2025-11-13 12:08:47 -07:00 |
|
Corey Ogburn
|
33b22bf2e4
|
Shorten Prompt
|
2025-11-13 11:09:09 -07:00 |
|
Corey Ogburn
|
3a38886345
|
CompressContextPrompt
|
2025-11-13 11:09:08 -07:00 |
|
reyesj2
|
7be70faab6
|
format json
|
2025-11-13 10:49:37 -06:00 |
|
Josh Patterson
|
2729fdbea6
|
Merge pull request #15223 from Security-Onion-Solutions/bravo
configure salt, then install. update bootstrap-salt. reduce salt install fail timeout
|
2025-11-13 11:35:43 -05:00 |
|
Jorge Reyes
|
bfd08d1d2e
|
Merge pull request #15204 from Security-Onion-Solutions/reyesj2/retention
update so-elasticsearch-retention-estimate
|
2025-11-13 10:05:49 -06:00 |
|
Josh Patterson
|
fed75c7b39
|
use -r with bootstrap to disable script repo
|
2025-11-12 19:47:25 -05:00 |
|
Josh Patterson
|
3427df2a54
|
update bootstrap-salt to latest
|
2025-11-12 18:07:14 -05:00 |
|
Josh Patterson
|
be11c718f6
|
configure salt then install it
|
2025-11-12 18:06:55 -05:00 |
|
Josh Patterson
|
235dfd78f1
|
Revert "salt-minion service KillMode to control-group"
This reverts commit 7c8b9b4374.
|
2025-11-12 14:20:28 -05:00 |
|
Josh Patterson
|
7c8b9b4374
|
salt-minion service KillMode to control-group
|
2025-11-12 12:30:29 -05:00 |
|
Jason Ertel
|
7762faf075
|
Merge pull request #15219 from Security-Onion-Solutions/jertel/wip
add support to so-yaml for using yaml file content for values
|
2025-11-12 08:12:23 -05:00 |
|
Jason Ertel
|
80fbb31372
|
fix test
|
2025-11-11 17:04:19 -05:00 |
|
Jason Ertel
|
7c45db2295
|
add support to so-yaml for using yaml file content for values
|
2025-11-11 16:57:54 -05:00 |
|
Jason Ertel
|
0545e1d33b
|
add support to so-yaml for using yaml file content for values
|
2025-11-11 16:55:00 -05:00 |
|
Jason Ertel
|
08147e27b0
|
Merge pull request #15213 from Security-Onion-Solutions/jertel/wip
reduce pcapMaxCount to fit better with max upload size
|
2025-11-10 19:08:58 -05:00 |
|
Josh Patterson
|
c9153617be
|
Merge pull request #15211 from Security-Onion-Solutions/bravo
Suricata 8.0.2
|
2025-11-10 17:09:43 -05:00 |
|
Josh Patterson
|
245ceb2d49
|
suricata defaults and annotation
|
2025-11-10 16:40:11 -05:00 |
|
Jason Ertel
|
4c65975907
|
reduce pcapMaxCount to fit better with max upload size
|
2025-11-10 15:44:05 -05:00 |
|
Mike Reeves
|
dfef7036ce
|
Merge pull request #15209 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update defaults.yaml
|
2025-11-10 14:53:00 -05:00 |
|
Mike Reeves
|
44594ba726
|
Update defaults.yaml
|
2025-11-10 14:24:27 -05:00 |
|
Josh Patterson
|
1876c4d9df
|
fix var name
|
2025-11-10 14:16:16 -05:00 |
|
Josh Patterson
|
a2ff66b5d0
|
update annotation
|
2025-11-10 14:12:20 -05:00 |
|
Josh Patterson
|
e3972dc5af
|
Merge remote-tracking branch 'origin/2.4/dev' into bravo
|
2025-11-10 13:28:42 -05:00 |
|
Josh Patterson
|
18c0f197b2
|
suricata bpf
|
2025-11-10 13:28:19 -05:00 |
|
Jorge Reyes
|
5b371c220c
|
Merge pull request #15207 from Security-Onion-Solutions/reyesj2/forwardnode-sensor
|
2025-11-10 08:46:12 -06:00 |
|
Josh Patterson
|
78c193f0a2
|
handle bpf for suricata 8 pcap
|
2025-11-07 17:40:24 -05:00 |
|
Josh Patterson
|
274295bc97
|
return exit codes
|
2025-11-07 17:39:13 -05:00 |
|
Josh Patterson
|
6c7ef622c1
|
spaces removed from expected output
|
2025-11-07 17:08:33 -05:00 |
|