Commit Graph

185 Commits

Author SHA1 Message Date
Wes Lambert
fbb9f099f9 Update Elastic state files 2020-01-28 14:49:58 +00:00
Mike Reeves
e038a8b731 Merge branch 'dev' into feature/issue124 2020-01-21 16:48:26 -05:00
m0duspwnens
a39edad3f6 changes for multipipelines / mastersearch node - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/124 2020-01-21 16:39:42 -05:00
William Wernert
54fb2ad244 Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into feature/registry
# Conflicts:
#	salt/common/init.sls
#	salt/elasticsearch/init.sls
#	salt/filebeat/init.sls
#	salt/hive/init.sls
#	salt/kibana/init.sls
#	salt/logstash/init.sls
#	salt/suricata/init.sls
#	salt/tcpreplay/init.sls
#	salt/wazuh/init.sls
2020-01-14 15:48:56 -05:00
Mike Reeves
e141443238 Fix some contianer links 2020-01-14 11:05:36 -05:00
Mike Reeves
ae55b59048 Switch to using images in registry 2020-01-14 10:11:26 -05:00
Wes Lambert
7e1870e9d0 update image versions 2020-01-13 13:52:30 +00:00
m0duspwnens
ed28be4ba9 rename logstash config for storage to search - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/176 2019-12-20 11:32:55 -05:00
Mike Reeves
e49de63460 Helix - Final Parser Fixes 2019-12-13 13:59:29 -05:00
Mike Reeves
fdbb223155 Helix - Add geo 2019-12-13 11:52:43 -05:00
Mike Reeves
e263d72813 Setup - Add sensor pillar to Helix 2019-12-13 11:46:30 -05:00
Mike Reeves
79d48f9e77 Logstash - Fix helix output typeo 2019-12-12 15:17:19 -05:00
Mike Reeves
bd9b1957ba Logstash - Fix helix output 2019-12-12 14:12:51 -05:00
Mike Reeves
989641eb5a Setup - Fix prompts and disable onion user if iso 2019-12-11 13:44:40 -05:00
Mike Reeves
e134071295 Helix - Change Parsers for Helix 2019-12-10 13:50:27 -05:00
Mike Reeves
ae3c428941 Helix Logstash Changes 2019-12-10 10:02:41 -05:00
Mike Reeves
4c4cdb7189 Helix changes and Wazuh 2019-12-09 16:27:03 -05:00
Mike Reeves
3904c19333 Change Variables to UperCase 2019-12-09 10:04:14 -05:00
m0duspwnens
599341483e adding api key for Helix 2019-12-09 09:59:28 -05:00
Mike Reeves
362cd0487f Additional Helix Support 2019-12-09 09:52:52 -05:00
Mike Reeves
5140a17fe3 Merge pull request #140 from defensivedepth/logstash-fix
Fix dup events
2019-11-19 15:25:46 -05:00
Josh Brower
7373473b3f Fix dup events 2019-11-19 15:02:35 -05:00
Mike Reeves
f3c204c790 Disable Beats input - Update sensoroni version 2019-11-06 13:37:42 -05:00
Mike Reeves
9d9b3c18f3 Merge pull request #115 from defensivedepth/logstash-tweaks
Logstash tweaks
2019-10-28 10:38:51 -04:00
Josh Brower
4dbc5f07b2 Enable 0006_input_beats.conf by default on EVAL 2019-10-25 10:19:05 -04:00
Josh Brower
504dd6559d Default ssl to false 2019-10-24 16:44:33 -04:00
Mike Reeves
ca4cd782a1 Docker URL Fix - Issue #68 2019-10-16 10:39:18 -04:00
Dustin Lee
699371a4d7 logstash: add beats template used in latest SO 2019-10-11 08:36:44 -04:00
Mike Reeves
b1f582d218 Logstash Module - 1.1.1 2019-09-24 11:22:07 -04:00
doug
8472b24a67 parse Bro logs using Elasticsearch ingest node 2019-09-23 16:04:23 -04:00
Mike Reeves
6d14a94765 Logstash Module - Fix watch 2019-09-20 16:31:23 -04:00
Mike Reeves
50c074bb4e Logstash Module - Add more watches 2019-09-19 15:46:46 -04:00
Josh Brower
9a4eadc967 Add rule_signature mapping 2019-09-19 08:30:33 -04:00
Mike Reeves
b6fd6fa2cc PCAP module - fix dir 2019-06-19 22:10:09 -04:00
Mike Reeves
f8b6b752b6 Logstash - Fix filebeat 2019-06-18 10:30:00 -04:00
Mike Reeves
feefc07235 HH Alpha Initial Push 2019-06-17 18:09:46 -04:00
Mike Reeves
9c1e128ca0 Logstash Module - Add new input conf 2019-06-10 18:44:10 -04:00
Mike Reeves
d9b1caf044 Logstash Module - Add new input conf 2019-06-10 18:33:09 -04:00
Mike Reeves
0876566317 Filebeat Module - Change port for internal filebeat traffic 2019-06-10 18:27:03 -04:00
Mike Reeves
f1e015edcf Add content trust to all modules 2019-05-02 16:53:19 -04:00
Mike Reeves
8663da0330 Logstash Module - Disable stuff that isn't used in eval 2019-03-18 10:23:43 -04:00
Mike Reeves
c8102fe7b5 Logstash Module - Disable stuff that isn't used in eval 2019-03-18 10:17:33 -04:00
Mike Reeves
70e8db5991 Logstash Module - Add the osquery configs 2019-01-24 20:27:57 -05:00
Wes Lambert
cdfc3a15ad osquery: fix host field conflict 2019-01-16 19:25:06 +00:00
Mike Reeves
05a4c6410f LogStash and Kibana modules - Clean up for new Zeek Version 2019-01-15 10:51:30 -05:00
Mike Reeves
341297bbaa Update For 1.0.6 2019-01-08 13:29:24 -05:00
Josh Brower
ce43fd7cd4 Moved to dynamic 2019-01-01 11:20:09 -05:00
Josh Brower
b9f6269925 Moved to dynamic 2019-01-01 11:20:01 -05:00
Josh Brower
bc7bf5774a Enable osquery parsers for EVAL role 2019-01-01 11:14:38 -05:00
Josh Brower
15bfce07e8 Move osquery parsers from custom to dynamic 2019-01-01 11:13:05 -05:00