Jorge Reyes
|
6fbed2dd9f
|
Merge pull request #15264 from Security-Onion-Solutions/reyesj2-patch-2
add force & certs flag to update fleet certs as needed
|
2025-12-01 11:11:25 -06:00 |
|
Mike Reeves
|
875de88cb4
|
Merge pull request #15271 from Security-Onion-Solutions/TOoSmOotH-patch-2
Add JA4D option to config.zeek.ja4
|
2025-12-01 10:03:12 -05:00 |
|
Mike Reeves
|
63bb44886e
|
Add JA4D option to config.zeek.ja4
|
2025-12-01 10:00:42 -05:00 |
|
DefensiveDepth
|
bda83a47a2
|
Remove header
|
2025-11-29 17:45:22 -05:00 |
|
DefensiveDepth
|
e96cfd35f7
|
Refactor for simplicity
|
2025-11-29 17:00:51 -05:00 |
|
DefensiveDepth
|
65c96b2edf
|
Add error handling
|
2025-11-29 16:27:22 -05:00 |
|
DefensiveDepth
|
87477ae4f6
|
Removed uneeded bind
|
2025-11-29 15:40:10 -05:00 |
|
DefensiveDepth
|
89a9106d79
|
Add context
|
2025-11-29 15:17:28 -05:00 |
|
DefensiveDepth
|
1284150382
|
Move to manager init
|
2025-11-27 08:39:19 -05:00 |
|
reyesj2
|
edf3c9464f
|
add --certs flag to update certs. Used with --force, to ensure certs are updated even if hosts update isn't needed
|
2025-11-25 16:16:19 -06:00 |
|
DefensiveDepth
|
4bb0a7c9d9
|
Merge remote-tracking branch 'origin/2.4/dev' into idstools-refactor
|
2025-11-25 13:52:21 -05:00 |
|
DefensiveDepth
|
ced3af818c
|
Refactor for Airgap
|
2025-11-25 13:51:50 -05:00 |
|
reyesj2
|
cc8fb96047
|
valid config for number_of_replicas in allocate action includes 0
|
2025-11-24 11:12:09 -06:00 |
|
reyesj2
|
3339b50daf
|
drop forcemerge when max_num_segements doesn't exist or empty
|
2025-11-21 16:39:45 -06:00 |
|
reyesj2
|
415ea07a4f
|
clean up
|
2025-11-21 16:04:26 -06:00 |
|
reyesj2
|
b80ec95fa8
|
update regex, revert to default will allow setting value back to '' | None
|
2025-11-21 14:41:03 -06:00 |
|
reyesj2
|
99cb51482f
|
unneeded 'set'
|
2025-11-21 14:32:58 -06:00 |
|
reyesj2
|
90638f7a43
|
Merge branch 'reyesj2/advea' into reyesj2/advilm
|
2025-11-21 14:25:28 -06:00 |
|
reyesj2
|
1fb00c8eb6
|
update so-elastic-fleet-outputs-update to use advanced output options when set, else empty "". Also trigger update_logstash_outputs() when hash of config_yaml has changed
|
2025-11-21 14:22:42 -06:00 |
|
reyesj2
|
4490ea7635
|
format EA logstash output adv config items
|
2025-11-21 14:21:17 -06:00 |
|
reyesj2
|
bce7a20d8b
|
soc configurable EA logstash output adv settings
|
2025-11-21 14:19:51 -06:00 |
|
Josh Patterson
|
9c06713f32
|
Merge pull request #15251 from Security-Onion-Solutions/bravo
use timestamp in volume path to prevent duplicates
|
2025-11-21 14:54:30 -05:00 |
|
Josh Patterson
|
23da0d4ba0
|
use timestamp in filename to prevent duplicates
|
2025-11-21 14:49:03 -05:00 |
|
Josh Patterson
|
d5f2cfb354
|
Merge pull request #15248 from Security-Onion-Solutions/bravo
clarify hypervisor annotation
|
2025-11-20 17:28:32 -05:00 |
|
Josh Patterson
|
fb5ad4193d
|
indicate base image download start
|
2025-11-20 17:13:36 -05:00 |
|
Josh Patterson
|
1f5f283c06
|
update hypervisor annotaion. preinit instead of initialized
|
2025-11-20 16:53:55 -05:00 |
|
Josh Patterson
|
cf048030c4
|
Merge pull request #15247 from Security-Onion-Solutions/bravo
Notify user of hypervisor environment setup failures
|
2025-11-20 16:04:49 -05:00 |
|
Josh Patterson
|
2d716b44a8
|
update comment
|
2025-11-20 15:52:21 -05:00 |
|
Jorge Reyes
|
d70d652310
|
Merge pull request #15244 from Security-Onion-Solutions/reyesj2/suricapfile
suricata capture file
|
2025-11-20 14:31:43 -06:00 |
|
reyesj2
|
c5db7c8752
|
suricata.capture_file keyword
|
2025-11-20 14:26:12 -06:00 |
|
reyesj2
|
6f42ff3442
|
suricata capture_file
|
2025-11-20 14:16:49 -06:00 |
|
reyesj2
|
433dab7376
|
format json
|
2025-11-20 14:16:10 -06:00 |
|
Josh Patterson
|
97c1a46013
|
update annotation for general failure
|
2025-11-20 15:08:04 -05:00 |
|
Josh Patterson
|
fbe97221bb
|
set initialized status
|
2025-11-20 14:43:09 -05:00 |
|
Josh Patterson
|
841ce6b6ec
|
update hypervisor annotation for image download or ssh key creation failure
|
2025-11-20 13:55:22 -05:00 |
|
Josh Patterson
|
dd0b4c3820
|
fix failed or hung qcow2 image download
|
2025-11-19 15:48:53 -05:00 |
|
reyesj2
|
b52dd53e29
|
advanced ilm actions
|
2025-11-19 13:24:55 -06:00 |
|
reyesj2
|
a155f45036
|
always update annotation / defaults for managed integrations
|
2025-11-19 13:24:29 -06:00 |
|
Josh Patterson
|
b407c68d88
|
Merge remote-tracking branch 'origin/2.4/dev' into bravo
|
2025-11-19 10:23:11 -05:00 |
|
Josh Patterson
|
5b6a7035af
|
need python_shell for pipes
|
2025-11-19 10:22:58 -05:00 |
|
Jason Ertel
|
12d490ad4a
|
Merge pull request #15240 from Security-Onion-Solutions/jertel/wip
communicate to the viewer that OS patches may take some time
|
2025-11-19 10:01:03 -05:00 |
|
Jason Ertel
|
76cbd18d2c
|
communicate to the viewer that OS patches may take some time
|
2025-11-19 09:56:42 -05:00 |
|
DefensiveDepth
|
148ef7ef21
|
add default ruleset
|
2025-11-18 11:57:30 -05:00 |
|
DefensiveDepth
|
1b55642c86
|
Refactor rules location
|
2025-11-18 09:58:14 -05:00 |
|
DefensiveDepth
|
af7f7d0728
|
Fix file paths
|
2025-11-17 12:00:08 -05:00 |
|
Jorge Reyes
|
a7337c95e1
|
Merge pull request #15234 from Security-Onion-Solutions/reyesj2/pipeline-upd
update zeek pipelines
|
2025-11-17 10:36:10 -06:00 |
|
Josh Patterson
|
3f7c3326ea
|
Merge pull request #15237 from Security-Onion-Solutions/bravo
rm salt keyring and repo file for deb
|
2025-11-17 09:27:53 -05:00 |
|
Josh Patterson
|
bf41de8c14
|
rm salt keyring and repo file for deb
|
2025-11-17 08:56:02 -05:00 |
|
reyesj2
|
de4424fab0
|
remove typos
|
2025-11-14 19:15:51 -06:00 |
|
reyesj2
|
136a829509
|
detect-sqli deprecated in favor of detect-sql-injection
|
2025-11-14 16:51:00 -06:00 |
|