Mike Reeves
|
126d1598ee
|
SNMP for suricata
|
2020-06-03 11:03:23 -04:00 |
|
Jason Ertel
|
970368c74e
|
Avoid logs leaking to stdout/stderr during cron jobs
|
2020-06-03 09:42:44 -04:00 |
|
Josh Brower
|
eaacb7b71e
|
Fleet cleanup
|
2020-06-03 05:54:35 -04:00 |
|
Jason Ertel
|
e6fcf75181
|
Re-ordered wazuh setup to avoid agent-service failures due to missing client.keys file; Prepare for user profile settings screen support in reverse proxy
|
2020-06-02 17:31:51 -04:00 |
|
weslambert
|
c91bc0e681
|
Clean up some stuff
|
2020-06-02 15:31:48 -04:00 |
|
Mike Reeves
|
25aae21cf6
|
Trying to get decoded packet
|
2020-06-02 15:06:39 -04:00 |
|
Mike Reeves
|
b507b87871
|
Trying to get decoded packet
|
2020-06-02 14:49:07 -04:00 |
|
Mike Reeves
|
fb68506418
|
Add mor suricata ingest parser types
|
2020-06-02 14:42:15 -04:00 |
|
Mike Reeves
|
3096d8d988
|
Add mor suricata ingest parser types
|
2020-06-02 14:34:38 -04:00 |
|
Mike Reeves
|
0ea2252b5b
|
Add Suricata Flow pipeline
|
2020-06-02 13:40:46 -04:00 |
|
Wes Lambert
|
8cac30728b
|
update Logstash config
|
2020-06-02 17:36:36 +00:00 |
|
Wes Lambert
|
91673a5d70
|
Update FB config
|
2020-06-02 17:33:42 +00:00 |
|
Mike Reeves
|
617f60d472
|
Fix Syntax
|
2020-06-02 12:01:26 -04:00 |
|
Mike Reeves
|
e63f39a9c4
|
Rename dataset
|
2020-06-02 11:58:14 -04:00 |
|
Mike Reeves
|
d47acd1d80
|
Change suricata to hit suricata.common
|
2020-06-02 11:41:13 -04:00 |
|
Josh Brower
|
b5cc653179
|
Fleet standalone fixes - mainip
|
2020-06-02 09:39:42 -04:00 |
|
Jason Ertel
|
42683ddb67
|
always restart acng and registry containers when docker restarts
|
2020-06-02 09:12:25 -04:00 |
|
Jason Ertel
|
07c0075fc0
|
Upgrade containerd.io and docker-ce to match ISO rpms
|
2020-06-02 08:43:06 -04:00 |
|
Josh Brower
|
b695b7f245
|
Fleet standalone fixes - firewall
|
2020-06-02 08:05:48 -04:00 |
|
Jason Ertel
|
9d5f4049b5
|
Avoid filtering NIC when it's an empty string
|
2020-06-02 05:52:03 -04:00 |
|
Mike Reeves
|
307cbe4b77
|
Couple of QOL scripts
|
2020-06-01 20:48:25 -04:00 |
|
Josh Brower
|
4b14ecf1d9
|
Fleet standalone fixes
|
2020-06-01 16:36:32 -04:00 |
|
Mike Reeves
|
45d17c5148
|
Pillarize Suricata Round 1
|
2020-06-01 14:53:04 -04:00 |
|
m0duspwnens
|
1737b46abb
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-06-01 12:15:00 -04:00 |
|
Doug Burks
|
80d1814f10
|
remove event.module:zeek to make queries more generic
|
2020-06-01 12:00:33 -04:00 |
|
Mike Reeves
|
03f34404b1
|
Suricata 5 Meta Data
|
2020-06-01 11:03:43 -04:00 |
|
Wes Lambert
|
51f5d64ef6
|
Rename tunnel_parents
|
2020-06-01 13:51:32 +00:00 |
|
Wes Lambert
|
d7ce3d4719
|
fix naming of uid field for tunnel
|
2020-06-01 12:52:57 +00:00 |
|
Doug Burks
|
f559621f00
|
add x509 issuer and subject groupby queries
|
2020-06-01 07:48:50 -04:00 |
|
Doug Burks
|
46dc5f42e9
|
combine two http queries into one with multiple groupby
|
2020-06-01 07:30:08 -04:00 |
|
m0duspwnens
|
5ddfb7ccce
|
fix merge conflicts
|
2020-05-29 17:31:07 -04:00 |
|
m0duspwnens
|
4dfb58a98c
|
change how whitelist script determines if wazuh is enabled
|
2020-05-29 17:22:39 -04:00 |
|
m0duspwnens
|
17879ad88c
|
add nginx state to searchnode in salt/top
|
2020-05-29 17:01:43 -04:00 |
|
m0duspwnens
|
15fc97e516
|
adding suricata.master state to mastersearch - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-29 13:11:55 -04:00 |
|
m0duspwnens
|
6db8470de7
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-05-29 13:09:49 -04:00 |
|
m0duspwnens
|
3143643692
|
add navigator to master if enabled
|
2020-05-29 13:05:26 -04:00 |
|
m0duspwnens
|
2db2054cce
|
update instructions in logstash customer pipelines and templates - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-29 10:58:53 -04:00 |
|
Wes Lambert
|
4059121dd6
|
fix framed_addr field
|
2020-05-29 11:55:18 +00:00 |
|
m0duspwnens
|
40fa5293bf
|
move fileserve update to suricata.master
|
2020-05-28 15:54:11 -04:00 |
|
Wes Lambert
|
7f75050682
|
Add basic Zeek stats script
|
2020-05-28 17:54:15 +00:00 |
|
Josh Brower
|
aeb71bb8f0
|
Simplified setup script
|
2020-05-28 13:21:25 -04:00 |
|
weslambert
|
b835c2e27e
|
Update for exact match (ex. thehive, thehive-es, thehive-cortex)
|
2020-05-28 13:17:31 -04:00 |
|
weslambert
|
12f426d4f4
|
Move eve.json to /nsm
|
2020-05-28 12:59:41 -04:00 |
|
Wes Lambert
|
869bfb947d
|
add master to SOCtopus hosts file
|
2020-05-28 16:45:48 +00:00 |
|
weslambert
|
d2263db0ff
|
Update init.sls
|
2020-05-28 12:11:08 -04:00 |
|
m0duspwnens
|
4f15de8b77
|
refresh salt fileserver if suricata rule symlink is created
|
2020-05-28 12:00:22 -04:00 |
|
Josh Brower
|
e53e891bd6
|
Fleet reactor - Typo fix
|
2020-05-28 11:36:38 -04:00 |
|
Wes Lambert
|
b7d7747f65
|
allow syslog
|
2020-05-28 13:56:02 +00:00 |
|
Mike Reeves
|
8304d91b0b
|
Merge branch 'dev' into feature/suri5
|
2020-05-28 09:41:28 -04:00 |
|
Wes Lambert
|
d2b93d531e
|
Basic syslog config
|
2020-05-28 12:36:29 +00:00 |
|