Commit Graph

776 Commits

Author SHA1 Message Date
Mike Reeves e38b0313c7 Merge pull request #9994 from Security-Onion-Solutions/hotones
Switch up elastic roles
2023-03-23 16:59:49 -04:00
Josh Brower bad905f54c SOC Logs & Hunt Query 2023-03-23 16:22:59 -04:00
Mike Reeves 90159f4bcd Switch up elastic roles 2023-03-23 15:09:40 -04:00
weslambert 0a9a064648 Remove node attrs configuration since node roles will be used 2023-03-23 13:45:51 -04:00
Wes 84360aa9bf Set replicas for Osquery manager indices to 0 2023-03-22 21:47:49 +00:00
Wes 3fba27a0d4 Ensure component template files are in the correct directory 2023-03-22 20:45:33 +00:00
Wes 28f5dcd43b Add managed generic Elastic Agent log component templates 2023-03-22 19:57:46 +00:00
Wes eaaa028999 Update Elastic Agent template settings 2023-03-22 19:52:13 +00:00
Mike Reeves d2bc5e4af2 Update config.map.jinja 2023-03-22 15:45:51 -04:00
weslambert 6d87620c6a Explicitly set 'event.dataset' as 'file' 2023-03-22 11:04:18 -04:00
Mike Reeves 5fc297b8c1 Change Elastic Logic 2023-03-21 16:52:08 -04:00
Jason Ertel ca363053e6 Merge pull request #9975 from Security-Onion-Solutions/kilo
catch errors and exit with proper exit code
2023-03-21 10:51:36 -04:00
Jason Ertel efd5f7b8a2 catch errors and exit with proper exit code 2023-03-21 10:44:21 -04:00
Mike Reeves 41554e8311 Merge pull request #9969 from Security-Onion-Solutions/guifixes
Add several annotations
2023-03-21 08:51:53 -04:00
Mike Reeves 444988f287 Adjust annotations 2023-03-21 08:48:02 -04:00
Josh Brower df036206a8 Fix Kratos parsing 2023-03-20 16:53:25 -04:00
Mike Reeves 22c3a4d398 Adjust elasticsearch annotations 2023-03-20 16:08:26 -04:00
Josh Brower f7be4ba31c Remove host field from NIDS logs 2023-03-13 14:07:17 -04:00
Wes e105e56fac Move data stream configuration outside of ILM policy definition 2023-03-13 13:27:02 +00:00
weslambert 16d9478196 Add index lifecycle management policy definitions for default Elastic Agent data streams 2023-03-10 16:54:47 -05:00
Doug Burks 19ab2a5a46 rename suricata vlan field to network.vlan.id 2023-03-05 05:57:52 -05:00
Doug Burks 9940a36722 update Elasticsearch ingest for Zeek conn vlan field 2023-03-03 15:22:43 -05:00
weslambert 134caa7f58 Various adjustments to descriptions 2023-02-28 16:31:16 -05:00
weslambert acda03ce40 Add annotation settings for Elasticsearch's ILM feature, and remove various index keys 2023-02-10 14:57:11 -05:00
Wes 1255c60317 Move policy load script into Elasticsearch state script directory 2023-02-10 18:59:45 +00:00
Wes 994eabae1b Manage policy loading in Elasticsearch state 2023-02-10 18:57:19 +00:00
Wes c9118699a9 Add index management lifecycle policy defintion and reference in index template 2023-02-10 15:10:30 +00:00
m0duspwnens a37f0fd0c0 rename sosbridge to sobridge 2023-02-03 10:07:07 -05:00
m0duspwnens 8cbafb52d8 Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall 2023-01-31 13:32:51 -05:00
m0duspwnens e09a86dc30 2.4 searchnode es config 2023-01-31 10:54:40 -05:00
Doug Burks a44d83d69b Improve Suricata DHCP parsing and dashboard 2023-01-31 08:33:38 -05:00
weslambert 0436f885b8 Set values for '@timestamp' and 'event.ingested' 2023-01-31 08:04:49 -05:00
weslambert 2772b03dca Change event.dataset value from 'tunnels' to 'tunnel' 2023-01-27 11:03:49 -05:00
weslambert 716ec7f936 Change event.dataset value from 'files' to 'file' 2023-01-27 11:02:44 -05:00
Wes f1db1bc273 Ensure Kratos events are sent to a data stream instead of an index 2023-01-26 16:12:06 +00:00
weslambert c9f458e1e2 Set event.dataset for all Kratos logs to 'access' for now 2023-01-25 08:19:50 -05:00
Wes 4b9c92c53d Set RITA event.dataset value explicitly 2023-01-24 18:00:34 +00:00
Wes f19cf75311 Change how event.dataset is determined for Suricata events 2023-01-24 14:45:00 +00:00
Wes 51692ac66c Update index pattern in various template definitions to match new data stream naming convention 2023-01-23 21:52:44 +00:00
Wes 40c6b380df Update Import and Zeek integration policies; also update Zeek ingest node pipelines to set event.dataset. 2023-01-23 21:44:46 +00:00
weslambert 7d3f6121eb Remove default "logs-*" template settings for now 2023-01-19 10:29:10 -05:00
weslambert 7a499c9051 Modify default 'logs-*' template priority 2023-01-18 17:24:07 -05:00
weslambert 73a4dae28e Make sure Elastic Agent data streams do not use replicas 2023-01-13 16:10:44 -05:00
Josh Patterson 3efca0010a Merge pull request #9573 from Security-Onion-Solutions/2.4/firewall
2.4/firewall
2023-01-13 12:41:58 -05:00
m0duspwnens 6033e9a0de use port_bindings from docker defaults in docker states 2023-01-13 10:15:10 -05:00
weslambert 7cba5626b7 Merge pull request #9570 from Security-Onion-Solutions/fix/elasticsearch_templates_elastic_agent
Change priority for Elastic Agent Elasticsearch index templates
2023-01-12 16:48:12 -05:00
weslambert 654d869e3e Change priority from 500 to 200 for Elastic Agent index templates to avoid collisions with other templates 2023-01-12 16:46:08 -05:00
weslambert fb8d8ea972 Update Elasticsearch index template for Kratos 2023-01-12 15:31:41 -05:00
weslambert 9416552338 Don't set the Kratos index explicitly 2023-01-12 15:25:35 -05:00
Wes c3b83f1fc8 Update template settings to use data streams 2023-01-11 14:03:11 +00:00