reyesj2
|
85dcfbf368
|
update kibana default space
|
2025-02-17 12:27:36 -06:00 |
|
reyesj2
|
8568c372f6
|
disable fleet apm
|
2025-02-17 12:21:31 -06:00 |
|
Jorge Reyes
|
810abba83e
|
Merge pull request #14229 from Security-Onion-Solutions/reyesj2/rel
force es pipeline sync
|
2025-02-13 08:54:06 -06:00 |
|
reyesj2
|
03b76cbcf5
|
remove state files
|
2025-02-13 08:51:50 -06:00 |
|
reyesj2
|
c711ffe6c5
|
keep pipeline "managed" metadata
|
2025-02-13 08:44:56 -06:00 |
|
Jorge Reyes
|
8094bf9c7c
|
Merge pull request #14225 from Security-Onion-Solutions/reyesj2/rel
update pfsense pipeline version. Remove unused component templates
|
2025-02-12 16:37:25 -06:00 |
|
reyesj2
|
09c7b31918
|
update pfsense pipeline version. Remove unused component templates
|
2025-02-12 16:33:56 -06:00 |
|
Jorge Reyes
|
d1e98d0849
|
Merge pull request #14224 from Security-Onion-Solutions/reyesj2/rel
Revert ES 8.17.2 upgrade -> 8.17.1
|
2025-02-12 13:18:39 -06:00 |
|
reyesj2
|
40cb3a53ae
|
Revert ES 8.17.2 upgrade -> 8.17.1
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-02-12 13:18:08 -06:00 |
|
Jorge Reyes
|
cdf8943f24
|
Merge pull request #14214 from Security-Onion-Solutions/reyesj2/rel
ES 8.17.2
|
2025-02-11 11:24:18 -06:00 |
|
reyesj2
|
fb0cd436d3
|
ES 8.17.2 TODO: Check import-evtx-logs.json for updated pipeline versions
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-02-11 11:23:04 -06:00 |
|
reyesj2
|
33f145a40b
|
ensure network packet capture integration data has event.module:network_traffic
|
2025-02-10 13:16:39 -06:00 |
|
reyesj2
|
3b69ff9fc9
|
integration policy update
|
2025-02-10 13:16:25 -06:00 |
|
Jorge Reyes
|
8828a3049d
|
Merge pull request #14155 from Security-Onion-Solutions/reyesj2/es-integ-tmp
add additional weird_integration
|
2025-01-27 16:36:17 -06:00 |
|
reyesj2
|
d74b69d84d
|
add additional weird_integration
|
2025-01-27 16:34:33 -06:00 |
|
Jorge Reyes
|
abcfe638c9
|
Merge pull request #14153 from Security-Onion-Solutions/reyesj2/es-integ-tmp
Reyesj2/es integ tmp
|
2025-01-27 14:07:32 -06:00 |
|
Joshua Brower
|
49ab0751c0
|
Remove uneeded import
|
2025-01-27 15:01:21 -05:00 |
|
Joshua Brower
|
e994f3a220
|
Fix commits
|
2025-01-27 14:48:50 -05:00 |
|
reyesj2
|
38b0276458
|
remove reference to deleted file
|
2025-01-27 13:45:18 -06:00 |
|
reyesj2
|
a373d96c3c
|
run managed_soc_annotations.sls from manager state
|
2025-01-27 13:45:03 -06:00 |
|
Josh Brower
|
97a3f130c8
|
Update Elastic
|
2025-01-23 15:32:39 -05:00 |
|
reyesj2
|
5b8f8fb62f
|
add/remove es annotations/defaults automagically
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-23 12:47:22 -06:00 |
|
Josh Brower
|
9738ef382c
|
Upgrade Elastic to 8.17.1
|
2025-01-23 08:12:02 -05:00 |
|
reyesj2
|
e0039a08ef
|
fix forcedType typo
|
2025-01-22 13:57:26 -06:00 |
|
Jorge Reyes
|
09df4a5771
|
Merge pull request #14139 from Security-Onion-Solutions/reyesj2/es-integ-tmp
fixes merging local pillar /global overrides for generated index temp…
|
2025-01-22 13:12:53 -06:00 |
|
reyesj2
|
81ac1ebc08
|
fixes merging local pillar /global overrides for generated index templates
|
2025-01-22 13:12:09 -06:00 |
|
Jorge Reyes
|
c2f5c2226f
|
Merge pull request #14138 from Security-Onion-Solutions/reyesj2/es-integ-tmp
add back missing component for http_endpoint_x_generic & winlog_x_win…
|
2025-01-22 10:16:30 -06:00 |
|
reyesj2
|
d779f7ae7f
|
add back missing component for http_endpoint_x_generic & winlog_x_winglog
|
2025-01-22 10:15:16 -06:00 |
|
Jorge Reyes
|
d26c7e6f9b
|
Merge pull request #14134 from Security-Onion-Solutions/reyesj2/es-integ-tmp
remove individual <integration>@custom mappings. Moved over to so-fle…
|
2025-01-21 11:00:18 -06:00 |
|
reyesj2
|
6331298eac
|
remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1
|
2025-01-21 10:49:54 -06:00 |
|
reyesj2
|
76abf37351
|
Merge remote-tracking branch 'origin/2.4/dev' into foxtrot
|
2025-01-21 09:03:04 -06:00 |
|
Jorge Reyes
|
704e30219a
|
Merge pull request #14124 from Security-Onion-Solutions/reyesj2-patch-8
keep imported data in logs-import-so index
|
2025-01-17 13:33:26 -06:00 |
|
reyesj2
|
1396083b7d
|
use so-elasticsearch-query where possible; simplify suricata.alerts index reroute
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 13:29:46 -06:00 |
|
Jason Ertel
|
7017024ba7
|
Merge pull request #14123 from Security-Onion-Solutions/jertel/wip
Additional web security measures
|
2025-01-17 12:31:42 -05:00 |
|
Jorge Reyes
|
942c1aa3a6
|
Merge pull request #14126 from Security-Onion-Solutions/reyesj2/es-integ-tmp
merge dev
|
2025-01-17 11:24:31 -06:00 |
|
reyesj2
|
d35ffef503
|
merge 2.4/dev
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 11:23:54 -06:00 |
|
Jason Ertel
|
7705f45d78
|
Revert "subgrid config annotations"
This reverts commit 3ab1b907e4.
|
2025-01-17 12:16:12 -05:00 |
|
Jason Ertel
|
964bbe6aa5
|
additional web server security measures
|
2025-01-17 12:14:30 -05:00 |
|
reyesj2
|
01a2e4cd4f
|
check for index existence before attemping rollover
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 09:27:28 -06:00 |
|
reyesj2
|
9032d7d7bc
|
any suricata.alert with event.imported: true remains in logs-import-so
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 18:48:31 -06:00 |
|
reyesj2
|
d573c0922d
|
add 2.4.111 -> postupgrade check
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 18:25:06 -06:00 |
|
reyesj2
|
45d3438d18
|
update ingest pipeline for imported logs
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 17:33:14 -06:00 |
|
Jorge Reyes
|
6c80fd0e18
|
Merge pull request #14116 from Security-Onion-Solutions/reyesj2-patch-8
update global@custom
|
2025-01-15 14:23:40 -06:00 |
|
reyesj2
|
b3b7fb8f29
|
add null check and move tag lookup to .contains() in global@custom
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-15 12:16:11 -06:00 |
|
Jason Ertel
|
d101fda423
|
Merge branch '2.4/dev' into jertel/wip
|
2025-01-15 11:06:05 -05:00 |
|
Jorge Reyes
|
b1d523a4e6
|
Merge pull request #14113 from Security-Onion-Solutions/reyesj2/es-integ-tmp
update fleet-optional-integrations-load
|
2025-01-14 15:26:33 -06:00 |
|
reyesj2
|
dab56f0882
|
update fleet-optional-integrations-load
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-14 15:24:59 -06:00 |
|
Jorge Reyes
|
846f2485db
|
Merge pull request #14111 from Security-Onion-Solutions/reyesj2-patch-1
update http query
|
2025-01-14 08:26:43 -06:00 |
|
Jorge Reyes
|
107ca38268
|
fix http query for "includes" function
|
2025-01-14 08:24:07 -06:00 |
|
Jorge Reyes
|
35547b476f
|
update http query
|
2025-01-14 08:13:27 -06:00 |
|