Josh Brower
|
6081c46d7f
|
Merge pull request #14362 from Security-Onion-Solutions/reyesj2-patch-2
fix osquery action_data mapping conflict
|
2025-03-08 10:18:12 -05:00 |
|
reyesj2
|
4dd72ad15c
|
fix osquery action_data mapping conflict
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-07 17:05:13 -06:00 |
|
Jason Ertel
|
4893eda4fe
|
Merge pull request #14359 from Security-Onion-Solutions/jertel/wip
Improve label
|
2025-03-07 08:44:12 -05:00 |
|
Jason Ertel
|
2af05b9a23
|
switch back to colon for better clarity
|
2025-03-07 08:24:19 -05:00 |
|
Jason Ertel
|
0bb76aecb3
|
Merge branch '2.4/dev' into jertel/wip
|
2025-03-07 08:23:18 -05:00 |
|
Mike Reeves
|
53ab7a223d
|
Merge pull request #14358 from Security-Onion-Solutions/dougburks-patch-1
|
2025-03-07 07:21:14 -05:00 |
|
Doug Burks
|
3037dc7c38
|
Update soc_soc.yaml to fix previous change
|
2025-03-07 07:13:27 -05:00 |
|
Mike Reeves
|
bde8a965f3
|
Merge pull request #14357 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update soc_soc.yaml
|
2025-03-06 21:12:24 -05:00 |
|
Mike Reeves
|
14e95f4898
|
Update soc_soc.yaml
|
2025-03-06 21:01:45 -05:00 |
|
Mike Reeves
|
bad0031829
|
Update soc_soc.yaml
|
2025-03-06 20:58:23 -05:00 |
|
Josh Patterson
|
f30938ed59
|
hypervisor annotation show if base domain is initialized or not
|
2025-03-06 15:26:08 -05:00 |
|
Doug Burks
|
630140b979
|
Merge pull request #14354 from Security-Onion-Solutions/dougburks-patch-1
Update soc_elasticsearch.yaml to include note about ILM rollover
|
2025-03-06 12:11:58 -05:00 |
|
Doug Burks
|
cce94d96d1
|
Update soc_elasticsearch.yaml to include note about ILM rollover
|
2025-03-06 11:14:48 -05:00 |
|
Mike Reeves
|
bcea02b059
|
Merge pull request #14301 from Security-Onion-Solutions/truefalse
Update annotations for new features
|
2025-03-05 16:23:00 -05:00 |
|
Mike Reeves
|
03ebc2d86e
|
Add Actions
|
2025-03-05 15:58:10 -05:00 |
|
Mike Reeves
|
3021ed5d36
|
Add Actions
|
2025-03-05 15:56:26 -05:00 |
|
Jorge Reyes
|
e59ebc89f8
|
Merge pull request #14346 from Security-Onion-Solutions/reyesj2-patch-2
bump version
|
2025-03-05 14:40:36 -06:00 |
|
reyesj2
|
6a5377ceac
|
bump version
|
2025-03-05 14:39:01 -06:00 |
|
Jorge Reyes
|
515cb3aea8
|
Merge pull request #14345 from Security-Onion-Solutions/reyesj2-patch-2
osquery templates
|
2025-03-05 14:28:08 -06:00 |
|
Mike Reeves
|
b51aa56e86
|
Some things I thought were bools are not bools
|
2025-03-05 15:15:26 -05:00 |
|
reyesj2
|
d2884ef00b
|
typo
|
2025-03-05 14:02:45 -06:00 |
|
reyesj2
|
0f16b00563
|
osquery templates
|
2025-03-05 13:57:47 -06:00 |
|
Mike Reeves
|
b01fb733a9
|
Some things I thought were bools are not bools
|
2025-03-05 14:56:26 -05:00 |
|
Mike Reeves
|
945a467ec8
|
Some things I thought were bools are not bools
|
2025-03-05 14:54:17 -05:00 |
|
Mike Reeves
|
67f9cd39db
|
Some things I thought were bools are not bools
|
2025-03-05 14:53:29 -05:00 |
|
Mike Reeves
|
72ffef9433
|
Some things I thought were bools are not bools
|
2025-03-05 14:52:54 -05:00 |
|
Mike Reeves
|
cf536469e6
|
Some things I thought were bools are not bools
|
2025-03-05 14:51:56 -05:00 |
|
Mike Reeves
|
c7c6d3e556
|
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into truefalse
|
2025-03-05 13:21:21 -05:00 |
|
coreyogburn
|
3a465c2e69
|
Merge pull request #14343 from Security-Onion-Solutions/cogburn/detections-group-items
Add Client Parameter
|
2025-03-05 09:57:31 -07:00 |
|
Corey Ogburn
|
21a64b6c1d
|
Add Client Parameter
Add groupItemsPerPage so detections groupby tables have proper default value for page size.
|
2025-03-05 09:43:21 -07:00 |
|
Josh Patterson
|
6c472dd383
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-03-05 08:58:03 -05:00 |
|
Josh Patterson
|
2c5861a0c2
|
ensure local hypervisor dir when new hypervisor key accepted. apply soc.dyanno.hypervisor when hypervisor key accepted
|
2025-03-05 08:51:10 -05:00 |
|
Doug Burks
|
2f6c7d2643
|
Merge pull request #14340 from Security-Onion-Solutions/dougburks-patch-1
FEATURE: Add sankey chart to Elastic Agent API dashboard to show relationship between process.name and process.Ext.api.name #14339
|
2025-03-05 08:02:39 -05:00 |
|
Doug Burks
|
c6c67f4d06
|
FEATURE: Add sankey chart to Elastic Agent API dashboard to show relationship between process.name and process.Ext.api.name #14339
|
2025-03-05 06:31:16 -05:00 |
|
Jorge Reyes
|
f35930317b
|
Merge pull request #14336 from Security-Onion-Solutions/reyesj2-patch-2
ES 8.17.3
|
2025-03-04 15:36:59 -06:00 |
|
reyesj2
|
11dc004811
|
ES 8.17.3
|
2025-03-04 14:24:38 -06:00 |
|
Jorge Reyes
|
966503d875
|
Merge pull request #14331 from Security-Onion-Solutions/reyesj2-patch-2
osquery v1.15.0 index templates updates
|
2025-03-04 13:17:28 -06:00 |
|
reyesj2
|
124bf266b5
|
osquery v1.15.0 index templates updates
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-04 12:27:04 -06:00 |
|
Jason Ertel
|
75e3bba9f5
|
reduce stdout
|
2025-03-04 11:35:22 -05:00 |
|
Jason Ertel
|
0ff4fc101b
|
Merge pull request #14329 from Security-Onion-Solutions/jertel/wip
reduce stdout verbosity
|
2025-03-04 11:23:14 -05:00 |
|
Jason Ertel
|
85450693a2
|
Merge branch '2.4/dev' into jertel/wip
|
2025-03-04 10:55:29 -05:00 |
|
Jason Ertel
|
0047246cf2
|
reduce stdout verbosity
|
2025-03-04 10:55:12 -05:00 |
|
Jorge Reyes
|
95d3a2d834
|
Merge pull request #14328 from Security-Onion-Solutions/reyesj2-patch-2
install bc package
|
2025-03-04 09:03:02 -06:00 |
|
reyesj2
|
e1c8bee71a
|
install bc package
|
2025-03-04 08:58:41 -06:00 |
|
Doug Burks
|
1c96449ad9
|
Merge pull request #14327 from Security-Onion-Solutions/dougburks-patch-1
FIX: Elastic Agent Security Events dashboard should reference user.effective.name #14325
|
2025-03-04 07:10:41 -05:00 |
|
Doug Burks
|
44535cba8c
|
FIX: Elastic Agent Security Events dashboard should reference user.effective.name #14325
|
2025-03-04 06:46:56 -05:00 |
|
Jorge Reyes
|
3f4a5a1b28
|
Merge pull request #14320 from Security-Onion-Solutions/reyesj2/zeekparslin
zeek traceroute & ntp
|
2025-03-03 10:56:15 -06:00 |
|
reyesj2
|
4bd83f8983
|
zeek traceroute & ntp
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-03 10:48:06 -06:00 |
|
Doug Burks
|
206acbe618
|
Merge pull request #14312 from Security-Onion-Solutions/dougburks-patch-1
FIX: SOC Actions for process.entity_id value must be quoted #14311
|
2025-03-03 07:09:45 -05:00 |
|
Doug Burks
|
e53f4fd1f1
|
Update defaults.yaml to quote the process.entity_id value
|
2025-03-02 05:54:30 -05:00 |
|