m0duspwnens
|
867613669d
|
changes for syncing users
|
2021-06-01 17:01:03 -04:00 |
|
Mike Reeves
|
fd1de624c8
|
Disable TTY for filebeat script
|
2021-06-01 14:50:21 -04:00 |
|
Jason Ertel
|
2a2247e1da
|
Additional so-user sync adjustments
|
2021-06-01 14:45:01 -04:00 |
|
Jason Ertel
|
7a59bee315
|
Add so-elastic-auth script
|
2021-06-01 12:48:53 -04:00 |
|
William Wernert
|
91c8a7c65b
|
Use correct syntax for tar to drop directory structure
|
2021-06-01 12:16:56 -04:00 |
|
Mike Reeves
|
73a0b31380
|
elastic pipeline enable
|
2021-06-01 12:12:20 -04:00 |
|
m0duspwnens
|
ef00695b07
|
fix typo
|
2021-06-01 11:31:50 -04:00 |
|
m0duspwnens
|
bfaffbc87e
|
add reactor and beacon for sqlite db
|
2021-06-01 11:15:28 -04:00 |
|
William Wernert
|
e800d62df4
|
Merge branch 'dev' into fix/update-iso-soup-wording
|
2021-06-01 11:12:17 -04:00 |
|
m0duspwnens
|
7e48740ea7
|
fix merge conflict
|
2021-06-01 10:56:02 -04:00 |
|
m0duspwnens
|
d25a439bd4
|
more changes
|
2021-06-01 10:53:58 -04:00 |
|
Jason Ertel
|
ed8c85df2b
|
Only sync web users if teh sqlite db exists
|
2021-06-01 10:26:33 -04:00 |
|
Josh Patterson
|
c4ae8c3418
|
Merge pull request #4359 from Security-Onion-Solutions/pipeline_userpass
generate pillar file if auth enabled or not
|
2021-06-01 09:38:34 -04:00 |
|
m0duspwnens
|
f87dce8ec1
|
generate pillar file if auth enabled or not
|
2021-06-01 09:38:07 -04:00 |
|
Josh Patterson
|
5d2f1c8e11
|
Merge pull request #4357 from Security-Onion-Solutions/pipeline_userpass
fix logic
|
2021-06-01 08:36:48 -04:00 |
|
m0duspwnens
|
1aa2852ed6
|
fix logic
|
2021-06-01 08:35:43 -04:00 |
|
Jason Ertel
|
a42a406f53
|
Remove extra users file mounts; disable elastic anon access when auth enabled
|
2021-05-29 07:52:08 -04:00 |
|
Jason Ertel
|
47b56e78b3
|
Fix missing endif
|
2021-05-28 20:07:51 -04:00 |
|
Josh Patterson
|
52db7b32ef
|
Merge pull request #4335 from Security-Onion-Solutions/pipeline_userpass
fix logic on password created in pillar and fix how me manage
|
2021-05-28 18:29:59 -04:00 |
|
m0duspwnens
|
3aad5a30e9
|
fix logic on password created in pillar and fix how me manage
|
2021-05-28 18:28:53 -04:00 |
|
Jason Ertel
|
b8a10f2e86
|
Support multiple elastic system users
|
2021-05-28 15:59:51 -04:00 |
|
m0duspwnens
|
edf60f80f7
|
manager and common states now require elasticsearch.auth state
|
2021-05-28 15:26:26 -04:00 |
|
m0duspwnens
|
68abaa5e3c
|
update auth.map and curl.config to use new elasticsearch:auth pillar format
|
2021-05-28 14:03:21 -04:00 |
|
m0duspwnens
|
63b31de2b8
|
add additional users - manage file if user name isnt returned from grepping the file
|
2021-05-28 13:58:03 -04:00 |
|
Mike Reeves
|
eac5c604bd
|
Update packetloss.sh
|
2021-05-28 12:57:35 -04:00 |
|
m0duspwnens
|
18926009d3
|
remove unneeded curl.config template
|
2021-05-28 10:38:06 -04:00 |
|
doug
|
ada8255af0
|
bump version to 7.13.0
|
2021-05-28 08:59:40 -04:00 |
|
m0duspwnens
|
423793ecf9
|
remove vault pg from testing
|
2021-05-27 13:50:22 -04:00 |
|
m0duspwnens
|
0134ceef16
|
merge and resolve conflict in elasticsearch state
|
2021-05-27 11:33:44 -04:00 |
|
m0duspwnens
|
b23ce7462e
|
add depenency
|
2021-05-27 11:26:25 -04:00 |
|
m0duspwnens
|
dc8520df42
|
user curl.config for curl and elasticscripts
|
2021-05-26 18:04:30 -04:00 |
|
doug
|
aeea5701e4
|
completely disable both alerts.actions.json and hunt.actions.json
|
2021-05-26 16:34:05 -04:00 |
|
m0duspwnens
|
7263e35a89
|
happy little comment
|
2021-05-26 14:52:59 -04:00 |
|
m0duspwnens
|
4d991d3773
|
propogate users and users_roles
|
2021-05-26 14:52:10 -04:00 |
|
Mike Reeves
|
bfcde15a24
|
elastic pipeline test
|
2021-05-26 14:22:14 -04:00 |
|
doug
|
ee675546ac
|
add menu.actions.json and update soc.json
|
2021-05-26 14:09:00 -04:00 |
|
Jason Ertel
|
b43e6c5d6b
|
Salt will handle auto-sync
|
2021-05-26 13:51:24 -04:00 |
|
Jason Ertel
|
c531ef0773
|
Move user sync'd files to saltstack for grid propagation
|
2021-05-26 13:44:30 -04:00 |
|
Jason Ertel
|
a6a4c03029
|
Improve error scenarios for user sync; Ensure user sync runs before Elastic container starts
|
2021-05-26 12:08:10 -04:00 |
|
m0duspwnens
|
842aa97f7e
|
load filebeat modules when es container starts and if fb container is running
|
2021-05-26 11:00:18 -04:00 |
|
Mike Reeves
|
34d4eedf67
|
Remove old modules
|
2021-05-26 10:11:47 -04:00 |
|
Josh Brower
|
ed249600d3
|
Merge remote-tracking branch 'remotes/origin/dev' into feature/so-pcap-pull
|
2021-05-26 09:52:58 -04:00 |
|
Josh Brower
|
0187c9d6df
|
Adds so-pcap-export
|
2021-05-26 09:51:37 -04:00 |
|
William Wernert
|
6da37966d9
|
Update wording for iso location prompt in soup
|
2021-05-26 09:32:25 -04:00 |
|
m0duspwnens
|
525d4325c7
|
define ZEEKLOGLOOKUP in the yaml
|
2021-05-25 17:18:58 -04:00 |
|
m0duspwnens
|
ecf7e25a51
|
fix merge conflict
|
2021-05-25 17:16:44 -04:00 |
|
Jason Ertel
|
ec2f8fe6c8
|
Synchronize SOC passwords with Elastic
|
2021-05-25 17:16:05 -04:00 |
|
m0duspwnens
|
dfaf40f583
|
add zeekloglookup to translate zeeklogs to filebeat filesets
|
2021-05-25 17:14:26 -04:00 |
|
Mike Reeves
|
543154f037
|
Remove old modules
|
2021-05-25 16:58:18 -04:00 |
|
Mike Reeves
|
cd3e355f84
|
Fix zeek depth
|
2021-05-25 16:54:20 -04:00 |
|