Josh Patterson
f5095b273d
Merge pull request #7665 from Security-Onion-Solutions/workstation_state
...
Workstation state
2022-03-29 10:27:07 -04:00
m0duspwnens
e3f3af52e1
fix spacing
2022-03-29 10:19:29 -04:00
m0duspwnens
2f489895ef
top match and remove_gui state
2022-03-29 10:17:21 -04:00
weslambert
6004dde54a
Add strelka_frontend to heavynode, sensor, and standalone role FW portgroups
2022-03-28 16:05:07 -04:00
m0duspwnens
0ddfaf8d74
changes for workstation
2022-03-28 15:34:15 -04:00
weslambert
e6599cd10e
Update with changes from Abe's PR and other fixes
2022-03-25 13:57:44 -04:00
weslambert
c02d7fab50
Merge pull request #7636 from Security-Onion-Solutions/feature/rita
...
Parsing of RITA Logs
2022-03-24 13:05:22 -04:00
weslambert
fbc86f43ec
Add exclude filter for logs for when there are no results from analysis
2022-03-24 13:03:03 -04:00
Wes Lambert
fe1b72655b
Additional .keyword shims for process mappings
2022-03-24 16:45:06 +00:00
m0duspwnens
293de159db
fix package names
2022-03-24 11:33:16 -04:00
m0duspwnens
7cfc52da8a
fix include
2022-03-24 10:02:25 -04:00
m0duspwnens
a0841ee7a7
workstation state
2022-03-24 09:57:58 -04:00
weslambert
1f2bca599f
Check cluster health before trying to load roles for ES
2022-03-23 11:00:26 -04:00
Wes Lambert
8a56c88773
Adjust log file paths
2022-03-22 17:51:17 +00:00
Wes Lambert
57f01c70ec
Remove extra forward slash in log path
2022-03-22 17:45:23 +00:00
Wes Lambert
2487d468ab
Add RITA Elasticsearch ingest pipeline config
2022-03-22 17:38:22 +00:00
Wes Lambert
f613d8ad86
Add RITA Logstash config
2022-03-22 17:36:18 +00:00
Doug Burks
eda7a8d7ea
FIX: Update telegraf influxdbsize.sh to collect influxdb size from influxdb_size.log #7468
2022-03-18 13:15:43 -04:00
Doug Burks
f7dc5588ae
FIX: Update common init.sls to create cron job to write influxdb size for telegraf #7468
2022-03-18 13:13:46 -04:00
Doug Burks
c13994994b
FIX: Update telegraf init.sls to run telegraf as non-root #7468
2022-03-18 13:11:56 -04:00
Doug Burks
e65f2a5513
FIX: Prevent multiple instances of so-sensor-clean #6622
2022-03-16 13:28:39 -04:00
Doug Burks
e56f90d83c
FIX: Prevent multiple instances of so-playbook-sync #6622
2022-03-16 13:27:37 -04:00
weslambert
aaded58131
Merge pull request #7565 from Security-Onion-Solutions/fix/es_template_fix
...
Custom ES template fixes
2022-03-15 11:09:46 -04:00
Doug Burks
9bf0265cea
Merge pull request #7566 from Security-Onion-Solutions/feature/hunt-soc-auth
...
FEATURE: Add new Hunt query for SOC logins #7327
2022-03-15 10:58:40 -04:00
Mike Reeves
e01c1398d5
Merge pull request #7564 from Security-Onion-Solutions/removethehive
...
Removethehive
2022-03-15 10:56:08 -04:00
Wes Lambert
42d6c3a956
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
2022-03-15 14:55:04 +00:00
Doug Burks
eec44a6b02
Add a SOC Auth query to hunt.queries.json
2022-03-15 10:38:46 -04:00
Doug Burks
d1e1887e36
Add support for Kratos audit logs in hunt.eventfields.json
2022-03-15 10:37:58 -04:00
Wes Lambert
5f56c7a261
Replace ELASTICCURL with so-elasticsearch-query
2022-03-15 14:32:00 +00:00
weslambert
d46620ea2a
Merge pull request #7561 from Security-Onion-Solutions/es_template_map_fix
...
Custom ES Template Fixes
2022-03-15 10:01:42 -04:00
Mike Reeves
9c80ff4f65
Remove hive from more files
2022-03-15 09:37:58 -04:00
Mike Reeves
81f0aa58b8
Remove hive from more files
2022-03-15 08:28:03 -04:00
Doug Burks
db4f138a78
FIX: surilogcompress cron job not running
...
The suricata user was originally created with `/opt/so/conf/suricata` as its home directory. I think at some point we changed permissions on `/opt/so/conf` and at that point the `surilogcompress` cron job stopped working. Changing the home directory to `/nsm/suricata` works on all of my PROD systems (including Ubuntu and CentOS).
For more information, please see:
https://github.com/Security-Onion-Solutions/securityonion/issues/7133
2022-03-15 07:10:02 -04:00
Mike Reeves
b5b60af16f
Remove hive from so-user
2022-03-14 15:06:07 -04:00
Mike Reeves
b83fec6fd2
More hive remova
2022-03-14 14:51:39 -04:00
Mike Reeves
ff30f572d7
Remove thehive from image common
2022-03-14 10:40:41 -04:00
Jason Ertel
5a28725def
Add assignee to case list
2022-03-14 08:45:28 -04:00
Wes Lambert
d12ff503c2
Chage role loading verbiage
2022-03-11 16:23:19 +00:00
Wes Lambert
dc258cf043
Load custom component templates in so-elasticsearch-templates-load
2022-03-11 16:22:55 +00:00
Wes Lambert
8e43a6e571
Don't generate index template if index_template definition is not present in pillar
2022-03-11 16:22:06 +00:00
m0duspwnens
e1e8a20e11
make sure values exist in data structure
2022-03-10 17:09:00 -05:00
weslambert
c83b63d0d8
Add .template extension to load template file
2022-03-08 20:53:16 -05:00
weslambert
8d9ddf5f1b
Add .template extension to load template
2022-03-08 20:52:13 -05:00
weslambert
8115da358f
Add .template extension to load template file
2022-03-08 20:51:50 -05:00
Doug Burks
b76c01ef53
Revert security_opt addition in telegraf init.sls
2022-03-08 18:27:15 -05:00
weslambert
65f998d6f7
Remove process.name.keyword for future-proofing
2022-03-08 12:44:51 -05:00
weslambert
406267a892
Add process.name.keyword
2022-03-08 12:42:34 -05:00
weslambert
d9c3160fbf
Merge pull request #7465 from Security-Onion-Solutions/fix/kibana_saved_objects_load
...
Kibana dashboard/saved objects loading improvements
2022-03-08 12:22:55 -05:00
Wes Lambert
d392cb258c
Switch Kibana state to kibana.so_savedobjects_defaults in top file
2022-03-08 16:59:48 +00:00
Wes Lambert
86e228b200
Add .template extension for future-proofing config files
2022-03-08 16:58:37 +00:00