Jason Ertel
a35bfc4822
Merge pull request #12747 from Security-Onion-Solutions/jertel/ana
...
do not prompt about telemetry on airgap installs
2024-04-03 21:50:38 -04:00
Jason Ertel
7c64fc8c05
do not prompt about telemetry on airgap installs
2024-04-03 18:08:42 -04:00
coreyogburn
fb5eea8284
Merge pull request #12744 from Security-Onion-Solutions/cogburn/detection-state
...
Update SOC Config with State File Paths
2024-04-03 13:19:26 -06:00
Corey Ogburn
0f50a265cf
Update SOC Config with State File Paths
...
Each detection engine is getting a state file to help manage the timer over restarts. By default, the files will go in soc's config folder inside a fingerprints folder.
2024-04-03 13:12:18 -06:00
Jason Ertel
3e05c04aa1
Merge pull request #12731 from Security-Onion-Solutions/jertel/ana
...
SOC Telemetry
2024-04-03 14:51:41 -04:00
Jason Ertel
8f8896c505
fix link
2024-04-03 14:45:39 -04:00
Jason Ertel
941a841da0
fix link
2024-04-03 14:41:57 -04:00
Jason Ertel
2b8a051525
fix link
2024-04-03 14:30:09 -04:00
Mike Reeves
1c7cc8dd3b
Merge pull request #12741 from Security-Onion-Solutions/metrics
...
Change code to allow for non root
2024-04-03 12:56:17 -04:00
Doug Burks
58d081eed1
Merge pull request #12742 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module kratos #12740
2024-04-03 12:48:24 -04:00
Doug Burks
9078b2bad2
FEATURE: Add Events table columns for event.module kratos #12740
2024-04-03 12:46:29 -04:00
Mike Reeves
8889c974b8
Change code to allow for non root
2024-04-03 12:38:59 -04:00
Doug Burks
f615a73120
Merge pull request #12739 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add dashboard for SOC Login Failures #12738
2024-04-03 12:01:08 -04:00
Doug Burks
66844af1c2
FEATURE: Add dashboard for SOC Login Failures #12738
2024-04-03 11:54:53 -04:00
Mike Reeves
a0b7d89eb6
Merge pull request #12734 from Security-Onion-Solutions/metrics
...
Add Elastic Agent Status Metrics
2024-04-03 11:12:53 -04:00
Mike Reeves
c31e459c2b
Change metrics reporting order
2024-04-03 11:06:00 -04:00
weslambert
d96d696c35
Merge pull request #12735 from Security-Onion-Solutions/feature/cef
...
Add cef
2024-04-03 10:49:44 -04:00
Wes
105eadf111
Add cef
2024-04-03 14:40:41 +00:00
Jason Ertel
ca57c20691
suppress soup update output for cleaner console
2024-04-03 10:31:24 -04:00
Jason Ertel
c4767bfdc8
suppress soup update output for cleaner console
2024-04-03 10:28:43 -04:00
Mike Reeves
0de1f76139
add agent count to reposync
2024-04-03 10:26:59 -04:00
Jason Ertel
5f4a0fdfad
suppress soup update output for cleaner console
2024-04-03 10:26:48 -04:00
Jason Ertel
c712529cf6
suppress soup update output for cleaner console
2024-04-03 10:21:35 -04:00
Mike Reeves
976ddd3982
add agentstatus to telegraf
2024-04-03 10:06:08 -04:00
Mike Reeves
64748b98ad
add agentstatus to telegraf
2024-04-03 09:56:12 -04:00
Mike Reeves
3335612365
add agentstatus to telegraf
2024-04-03 09:54:16 -04:00
Mike Reeves
513273c8c3
add agentstatus to telegraf
2024-04-03 09:43:55 -04:00
Mike Reeves
0dfde3c9f2
add agentstatus to telegraf
2024-04-03 09:40:14 -04:00
Mike Reeves
0efdcfcb52
add agentstatus to telegraf
2024-04-03 09:36:02 -04:00
Josh Brower
fbdcc53fe0
Merge pull request #12732 from Security-Onion-Solutions/2.4/detections-defaults
...
Feature - auto-enabled Sigma rules
2024-04-03 09:01:09 -04:00
Jason Ertel
c1b5ef0891
ensure so-yaml.py is updated during soup
2024-04-03 08:44:40 -04:00
DefensiveDepth
a8f25150f6
Feature - auto-enabled Sigma rules
2024-04-03 08:21:50 -04:00
Jason Ertel
1ee2a6d37b
Improve wording for Airgap annotation
2024-04-03 08:21:30 -04:00
Mike Reeves
f64d9224fb
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into metrics
2024-04-02 17:22:20 -04:00
Jason Ertel
b6187ab769
Improve wording for Airgap annotation
2024-04-02 15:54:39 -04:00
Mike Reeves
283939b18a
Gather metrics from elastic agent to influx
2024-04-02 15:36:01 -04:00
Jason Ertel
3b112e20e3
fix syntax error
2024-04-02 12:32:33 -04:00
Doug Burks
23a6c4adb6
Merge pull request #12725 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:54:15 -04:00
Doug Burks
2f03cbf115
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:42:20 -04:00
Doug Burks
a678a5a416
Merge pull request #12724 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:15:20 -04:00
Doug Burks
b2b54ccf60
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:11:16 -04:00
Doug Burks
55e71c867c
Merge pull request #12723 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module playbook #12703
2024-04-02 10:04:21 -04:00
Doug Burks
6c2437f8ef
FEATURE: Add Events table columns for event.module playbook #12703
2024-04-02 09:55:56 -04:00
Doug Burks
261f2cbaf7
Merge pull request #12722 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 09:43:15 -04:00
Jason Ertel
f083558666
break out into sep func
2024-04-02 09:42:43 -04:00
Doug Burks
505eeea66a
Update defaults.yaml
2024-04-02 09:39:54 -04:00
Josh Brower
1001aa665d
Merge pull request #12720 from Security-Onion-Solutions/2.4/detections-defaults
...
Add default columns
2024-04-02 09:21:06 -04:00
DefensiveDepth
7f488422b0
Add default columns
2024-04-02 09:13:27 -04:00
Jason Ertel
f17d8d3369
analytics
2024-04-01 10:59:44 -04:00
Jason Ertel
ff777560ac
limit col size
2024-04-01 10:35:15 -04:00