Josh Brower
|
8faf80a03b
|
Revert "Playbook db updates"
This reverts commit 35be785f7a.
|
2020-12-12 10:07:23 -05:00 |
|
Mike Reeves
|
b5ed973abd
|
Merge pull request #2138 from OmerTirosh/OmerTirosh-fix-win.eventlog
Fix Error: SO elasticsearch ingest failed to convert 'winlog.event_data.SubjectUserName' to 'user.name'
|
2020-12-12 10:00:27 -05:00 |
|
Doug Burks
|
85aac4ad75
|
Prevent Wazuh "last -n 20" logs from going to Alerts queue #2321
|
2020-12-12 09:22:08 -05:00 |
|
Jason Ertel
|
fd7fe72b2a
|
Correct default address pool base value
|
2020-12-11 23:29:59 -05:00 |
|
Jason Ertel
|
c5a3597564
|
Swap AWS interfaces
|
2020-12-11 21:57:56 -05:00 |
|
Josh Brower
|
66495e6bae
|
Swap localhost for 127.0.0.1
|
2020-12-11 17:38:42 -05:00 |
|
Jason Ertel
|
42c8f1e325
|
Use eth0/eth1 instead of ens5/ens6 in AWS
|
2020-12-11 15:34:16 -05:00 |
|
Jason Ertel
|
bb61c1f745
|
Cleanup bash imports/sources, function definitions, and variables
|
2020-12-11 15:33:31 -05:00 |
|
Josh Patterson
|
e4eea6a616
|
Merge pull request #2320 from Security-Onion-Solutions/issue/2319
zeek file extraction can now be manipulated with zeek pillar
|
2020-12-11 14:38:10 -05:00 |
|
m0duspwnens
|
09b3a4a0dd
|
merge pillar with the defaults https://github.com/Security-Onion-Solutions/securityonion/issues/2319
|
2020-12-11 14:35:06 -05:00 |
|
m0duspwnens
|
b8e8510dd2
|
merge pillar with the defaults https://github.com/Security-Onion-Solutions/securityonion/issues/2319
|
2020-12-11 14:26:32 -05:00 |
|
Jason Ertel
|
eb735c7289
|
Replace duplicate random generator with common function
|
2020-12-11 13:22:13 -05:00 |
|
Josh Patterson
|
2f2867804a
|
Merge pull request #2318 from Security-Onion-Solutions/issue/1175
pillarize grafana and allow for grafana alerts to be created
|
2020-12-11 12:36:06 -05:00 |
|
m0duspwnens
|
d877fac786
|
add null for max graph value https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 12:28:43 -05:00 |
|
m0duspwnens
|
c88a1a943d
|
update search and sensor node dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 12:21:16 -05:00 |
|
m0duspwnens
|
e3335a3106
|
update managersearch dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 12:00:02 -05:00 |
|
m0duspwnens
|
0a77a28e06
|
guage to graph cor cpu on manager and eval https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 11:51:42 -05:00 |
|
m0duspwnens
|
6eb64227ae
|
update manager dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 11:44:21 -05:00 |
|
m0duspwnens
|
5a95181b2b
|
update eval version 1 https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 11:36:19 -05:00 |
|
m0duspwnens
|
2fc151d923
|
update eval dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 11:34:08 -05:00 |
|
William Wernert
|
db276d9020
|
[fix] Always set hostname
|
2020-12-11 11:02:27 -05:00 |
|
m0duspwnens
|
33fde42dbc
|
dont show legend on pcap retention panel
|
2020-12-11 10:42:30 -05:00 |
|
m0duspwnens
|
e0e38ac37f
|
update standlone dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-11 10:39:25 -05:00 |
|
William Wernert
|
75c5abef30
|
[fix] Add all selected options to install_opts
|
2020-12-11 10:16:00 -05:00 |
|
Jason Ertel
|
0915ae30e4
|
Add timestamps to so-yara-update output
|
2020-12-11 10:08:10 -05:00 |
|
Jason Ertel
|
14f28e38be
|
Ensure so-yara-updata script is logging to a file during cron job execution
|
2020-12-11 10:04:43 -05:00 |
|
William Wernert
|
870cc6b79b
|
[fix][typo] readaraay -> readarray
|
2020-12-11 09:39:22 -05:00 |
|
William Wernert
|
3c7a8fe92f
|
[fix] Don't cd in so-variables
|
2020-12-11 09:39:00 -05:00 |
|
William Wernert
|
b6a0e692c6
|
[refactor] Use command -v for netplan check
|
2020-12-11 09:38:44 -05:00 |
|
m0duspwnens
|
fbcc62d5c5
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/1175
|
2020-12-10 15:17:45 -05:00 |
|
m0duspwnens
|
733f5a5021
|
allowUiUpdates to dashboards to allow for alert creation on stock dashboards issue/1175
|
2020-12-10 15:17:22 -05:00 |
|
William Wernert
|
25f2075e22
|
[fix] Revert bad change to whiptail_basic_zeek
|
2020-12-10 15:01:10 -05:00 |
|
William Wernert
|
5c4103681c
|
[fix] Save original argument array to use later
|
2020-12-10 14:45:24 -05:00 |
|
William Wernert
|
ab856532e6
|
[fix] Show airgap option on import install
|
2020-12-10 14:20:48 -05:00 |
|
William Wernert
|
58bcc79c54
|
[fix] Create full dir structure, rm /root/install_opt on failure
|
2020-12-10 14:17:47 -05:00 |
|
William Wernert
|
1f1cfde3ac
|
[fix] Make directory for new setup download
|
2020-12-10 14:03:54 -05:00 |
|
William Wernert
|
bc6a0c1e6f
|
[fix] Add missing append flags to tee
|
2020-12-10 13:54:41 -05:00 |
|
William Wernert
|
8302119756
|
[fix] Don't redirect entire download function to setup log
|
2020-12-10 13:26:19 -05:00 |
|
William Wernert
|
21e107f2e8
|
[fix] Remove sudo from version check, only remove known_hosts entry if exists
|
2020-12-10 13:13:45 -05:00 |
|
Mike Reeves
|
cd6a945a24
|
Merge pull request #2298 from Security-Onion-Solutions/escluster
Traditional ES Clustering Support
|
2020-12-10 12:07:17 -05:00 |
|
m0duspwnens
|
4ee944448f
|
remove $Interval template var since alerts cant be crated when it is used https://github.com/Security-Onion-Solutions/securityonion/issues/1175
|
2020-12-10 12:05:57 -05:00 |
|
TOoSmOotH
|
42833b2086
|
Make non clustered node attributes
|
2020-12-10 11:14:32 -05:00 |
|
TOoSmOotH
|
d9d7f49b96
|
Adjust elasticsearch.yml
|
2020-12-10 11:09:38 -05:00 |
|
William Wernert
|
86313796a5
|
[fix] Set manager_ver in download function
|
2020-12-10 11:00:52 -05:00 |
|
weslambert
|
24fce27e62
|
Merge pull request #2297 from Security-Onion-Solutions/feature/idstools_arg
Add ability to supply an arg, for example overriding 15 min limit
|
2020-12-10 09:31:50 -05:00 |
|
Wes Lambert
|
45faa7fda4
|
Add ability to supply an arg, for example overriding 15 min limit
|
2020-12-10 14:30:29 +00:00 |
|
weslambert
|
c2cf2c4987
|
Merge pull request #2296 from Security-Onion-Solutions/fix/suricata_ftp_data
Add initial suricata.ftp_data pipeline
|
2020-12-10 09:17:01 -05:00 |
|
TOoSmOotH
|
379f1d98d8
|
fix addtotab
|
2020-12-10 09:15:17 -05:00 |
|
Wes Lambert
|
f689722559
|
Add initial suricata.ftp_data pipeline
|
2020-12-10 14:14:50 +00:00 |
|
weslambert
|
d09daef094
|
Merge pull request #2288 from Security-Onion-Solutions/fix/strelka_rules
Expand STRELKARULES
|
2020-12-09 17:05:44 -05:00 |
|