reyesj2
8675193d1f
elasticsearch upgrade 8.18.8
2025-10-06 12:56:31 -05:00
Jorge Reyes
4d24c57903
Merge pull request #15028 from Security-Onion-Solutions/reyesj2/ea-alerter
...
agent monitor template & dataset name update
2025-09-12 14:45:20 -05:00
reyesj2
0606c0a454
agent monitor template & dataset name update
2025-09-12 14:26:22 -05:00
reyesj2
588a1b86d1
suricata metadata index rollover 1d -> 30d
2025-09-11 15:46:45 -05:00
Corey Ogburn
2535ae953d
Fix Index Patterns
...
so-assistant-chat and so-assistant-session both had templates with a trailing dash that prevented the pattern from applying to the name of the indices.
2025-09-09 14:00:01 -06:00
reyesj2
855b489c4b
datastream
2025-09-08 09:13:24 -06:00
Corey Ogburn
673f9cb544
Responding to Feedback
2025-09-08 09:13:24 -06:00
Corey Ogburn
73776f8d11
Cleaning up New ES Indexes
2025-09-08 09:13:23 -06:00
reyesj2
1a32a0897c
Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/ea-alerter
2025-09-02 17:11:21 -05:00
reyesj2
e26310d172
elastic agent offline alerter
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-09-02 17:00:03 -05:00
reyesj2
1ea7b3c09f
es 8.18.6
2025-08-28 18:27:56 -05:00
reyesj2
3fc244ee85
8.18.4
2025-07-22 16:56:51 -05:00
reyesj2
b3eb06f53e
ja4
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-07-16 15:56:34 -05:00
reyesj2
d8be6e42e1
es 8.18.3
2025-07-07 12:58:00 -05:00
Josh Patterson
07ef3d632c
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
2025-04-15 08:08:12 -04:00
reyesj2
58df566c79
add mapping for metadata.kafka.timestamp
2025-04-14 14:30:40 -05:00
Josh Patterson
21bb325157
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
2025-04-14 08:22:42 -04:00
Josh Brower
4c3518385b
Change timeout to 1s
2025-04-11 07:37:09 -04:00
Josh Patterson
44a5b3b1e5
MANAGERHYPE setup is now complete!
2025-03-12 21:05:04 -04:00
reyesj2
4dd72ad15c
fix osquery action_data mapping conflict
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-03-07 17:05:13 -06:00
reyesj2
d2884ef00b
typo
2025-03-05 14:02:45 -06:00
reyesj2
0f16b00563
osquery templates
2025-03-05 13:57:47 -06:00
reyesj2
11dc004811
ES 8.17.3
2025-03-04 14:24:38 -06:00
reyesj2
124bf266b5
osquery v1.15.0 index templates updates
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-03-04 12:27:04 -06:00
reyesj2
df350b5a56
ES 8.17.2
2025-02-20 14:20:09 -06:00
reyesj2
3b6344e7f0
add back settings previously defined when overwritting logs-elastic_agent@package and logs-endpoint.diagnostics.collection@package
2025-02-20 12:42:30 -06:00
Jorge Reyes
a3dba9b566
Merge pull request #14255 from Security-Onion-Solutions/foxtrot
...
ES 8.17.1
2025-02-18 14:58:46 -06:00
reyesj2
235a8e3934
update index templates for endpoint integration
2025-02-17 18:30:51 -06:00
reyesj2
40cb3a53ae
Revert ES 8.17.2 upgrade -> 8.17.1
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-02-12 13:18:08 -06:00
reyesj2
fb0cd436d3
ES 8.17.2 TODO: Check import-evtx-logs.json for updated pipeline versions
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-02-11 11:23:04 -06:00
Joshua Brower
b874619f0d
Fix ip-mappings ILM
2025-02-03 09:31:08 -05:00
Josh Brower
9738ef382c
Upgrade Elastic to 8.17.1
2025-01-23 08:12:02 -05:00
reyesj2
d779f7ae7f
add back missing component for http_endpoint_x_generic & winlog_x_winglog
2025-01-22 10:15:16 -06:00
reyesj2
6331298eac
remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1
2025-01-21 10:49:54 -06:00
reyesj2
4618256442
include okta-mappings in so-logs-okta.system index template
2025-01-13 11:32:27 -06:00
reyesj2
323ef1d5d6
add missing lifecycle name to trend_micro_vision_one indices
2025-01-13 09:29:22 -06:00
reyesj2
a5b1648b68
add missing lifecycle name to crowdstrike indices
2025-01-13 09:26:16 -06:00
reyesj2
4f92b7ced1
add support for cloudflare_logpush integration
2025-01-13 09:23:05 -06:00
reyesj2
cdd4a1ff1f
fixes addon integration map file
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-03 16:06:22 -06:00
reyesj2
157185c370
add ti_opencti integration support
2024-12-18 11:33:49 -06:00
reyesj2
888145a2ed
remove optional integrations from defaults.yaml & soc_elasticsearch.yaml
2024-12-03 08:55:43 -06:00
reyesj2
993d56cb58
ti_rapid7*
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-25 15:51:49 -06:00
reyesj2
efa6a533c3
add missing ilm to index template
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-25 15:47:47 -06:00
reyesj2
44ec237447
additional integration support - cisco secure email gateway - rapid7 threat command
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-15 11:39:01 -06:00
Jorge Reyes
4e0b5569dc
Merge pull request #13933 from Security-Onion-Solutions/ilm-detection
...
add ilm and update managed index settings
2024-11-12 15:22:05 -06:00
reyesj2
6dbe0645e5
use auto_expand_replica, configure ilm for so-case* & so-detection*
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-11 13:51:48 -06:00
Jason Ertel
57a9992a3d
Merge branch '2.4/dev' into jertel/wip
2024-11-11 10:06:44 -05:00
reyesj2
80b82b0bd6
missing replica 0
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-06 15:24:13 -06:00
reyesj2
039d5c22ac
fix: crowdstrike integration
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-06 14:35:41 -06:00
reyesj2
36fc3bbd6d
add so-ip-mappings index
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-10-30 10:24:11 -04:00