reyesj2
|
6331298eac
|
remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1
|
2025-01-21 10:49:54 -06:00 |
|
reyesj2
|
76abf37351
|
Merge remote-tracking branch 'origin/2.4/dev' into foxtrot
|
2025-01-21 09:03:04 -06:00 |
|
Jorge Reyes
|
704e30219a
|
Merge pull request #14124 from Security-Onion-Solutions/reyesj2-patch-8
keep imported data in logs-import-so index
|
2025-01-17 13:33:26 -06:00 |
|
reyesj2
|
1396083b7d
|
use so-elasticsearch-query where possible; simplify suricata.alerts index reroute
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 13:29:46 -06:00 |
|
Jason Ertel
|
7017024ba7
|
Merge pull request #14123 from Security-Onion-Solutions/jertel/wip
Additional web security measures
|
2025-01-17 12:31:42 -05:00 |
|
Jorge Reyes
|
942c1aa3a6
|
Merge pull request #14126 from Security-Onion-Solutions/reyesj2/es-integ-tmp
merge dev
|
2025-01-17 11:24:31 -06:00 |
|
reyesj2
|
d35ffef503
|
merge 2.4/dev
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 11:23:54 -06:00 |
|
Jason Ertel
|
7705f45d78
|
Revert "subgrid config annotations"
This reverts commit 3ab1b907e4.
|
2025-01-17 12:16:12 -05:00 |
|
Jason Ertel
|
964bbe6aa5
|
additional web server security measures
|
2025-01-17 12:14:30 -05:00 |
|
reyesj2
|
01a2e4cd4f
|
check for index existence before attemping rollover
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-17 09:27:28 -06:00 |
|
reyesj2
|
9032d7d7bc
|
any suricata.alert with event.imported: true remains in logs-import-so
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 18:48:31 -06:00 |
|
reyesj2
|
d573c0922d
|
add 2.4.111 -> postupgrade check
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 18:25:06 -06:00 |
|
reyesj2
|
45d3438d18
|
update ingest pipeline for imported logs
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-16 17:33:14 -06:00 |
|
Jorge Reyes
|
6c80fd0e18
|
Merge pull request #14116 from Security-Onion-Solutions/reyesj2-patch-8
update global@custom
|
2025-01-15 14:23:40 -06:00 |
|
reyesj2
|
b3b7fb8f29
|
add null check and move tag lookup to .contains() in global@custom
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-15 12:16:11 -06:00 |
|
Jason Ertel
|
d101fda423
|
Merge branch '2.4/dev' into jertel/wip
|
2025-01-15 11:06:05 -05:00 |
|
Jorge Reyes
|
b1d523a4e6
|
Merge pull request #14113 from Security-Onion-Solutions/reyesj2/es-integ-tmp
update fleet-optional-integrations-load
|
2025-01-14 15:26:33 -06:00 |
|
reyesj2
|
dab56f0882
|
update fleet-optional-integrations-load
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-14 15:24:59 -06:00 |
|
Jorge Reyes
|
846f2485db
|
Merge pull request #14111 from Security-Onion-Solutions/reyesj2-patch-1
update http query
|
2025-01-14 08:26:43 -06:00 |
|
Jorge Reyes
|
107ca38268
|
fix http query for "includes" function
|
2025-01-14 08:24:07 -06:00 |
|
Jorge Reyes
|
35547b476f
|
update http query
|
2025-01-14 08:13:27 -06:00 |
|
Jorge Reyes
|
ad765200c3
|
Merge pull request #14105 from Security-Onion-Solutions/reyesj2/moarzeekparse
Additional Zeek parsing & cloudflare_logpush integration
|
2025-01-13 11:37:21 -06:00 |
|
reyesj2
|
4618256442
|
include okta-mappings in so-logs-okta.system index template
|
2025-01-13 11:32:27 -06:00 |
|
reyesj2
|
323ef1d5d6
|
add missing lifecycle name to trend_micro_vision_one indices
|
2025-01-13 09:29:22 -06:00 |
|
reyesj2
|
a5b1648b68
|
add missing lifecycle name to crowdstrike indices
|
2025-01-13 09:26:16 -06:00 |
|
reyesj2
|
14c920a258
|
fix hidden ldap menu subtitle
|
2025-01-13 09:23:32 -06:00 |
|
reyesj2
|
4f92b7ced1
|
add support for cloudflare_logpush integration
|
2025-01-13 09:23:05 -06:00 |
|
Josh Brower
|
5ec2006c9e
|
Merge pull request #14102 from Security-Onion-Solutions/2.4/nav-airgap
Fix folder perm
|
2025-01-10 16:20:18 -05:00 |
|
Joshua Brower
|
dcdf31eee8
|
Fix folder perm
|
2025-01-10 16:15:17 -05:00 |
|
Jason Ertel
|
3ab1b907e4
|
subgrid config annotations
|
2025-01-10 13:45:42 -05:00 |
|
reyesj2
|
e60a1e4357
|
zeek ldap & ldap_search parsing
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-09 16:06:10 -06:00 |
|
Josh Brower
|
2de1f0464f
|
Merge pull request #14091 from Security-Onion-Solutions/2.4/nav-airgap
Refactor Navigator Airgap
|
2025-01-09 11:59:50 -05:00 |
|
Joshua Brower
|
bcb92b63e3
|
Move json files to container image
|
2025-01-09 10:58:40 -05:00 |
|
Jorge Reyes
|
412397fa7b
|
Merge pull request #14089 from Security-Onion-Solutions/reyesj2/moarzeekparse
|
2025-01-08 17:45:14 -06:00 |
|
reyesj2
|
0e87351a9c
|
add zeek.quic mappings
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-08 16:18:53 -06:00 |
|
Josh Brower
|
71f4150c27
|
Merge pull request #14013 from Security-Onion-Solutions/2.4/navigator
Refactor Navigator for Detections
|
2025-01-07 13:34:19 -05:00 |
|
Joshua Brower
|
a2caf7425d
|
Add config options
|
2025-01-07 13:22:14 -05:00 |
|
Joshua Brower
|
6fa11a38ef
|
Update defaults
|
2025-01-07 13:14:50 -05:00 |
|
Joshua Brower
|
e3f75215b6
|
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/navigator
|
2025-01-07 13:06:49 -05:00 |
|
Jorge Reyes
|
06983948b0
|
Merge pull request #14078 from Security-Onion-Solutions/reyesj2/es-integ-tmp
run elasticsearch state to sync templates
|
2025-01-06 21:34:07 -06:00 |
|
reyesj2
|
a21535b0a2
|
run elasticsearch state to sync templates
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-06 21:33:07 -06:00 |
|
Jason Ertel
|
d14b6e6d7d
|
Merge pull request #14077 from Security-Onion-Solutions/jertel/wip
invalidate user sessions when an admin changes the user's password
|
2025-01-06 17:26:56 -05:00 |
|
Jason Ertel
|
bd96b5d722
|
invalidate user sessions when an admin changes the user's password
|
2025-01-06 17:23:10 -05:00 |
|
Jorge Reyes
|
b431fb1e49
|
Merge pull request #14075 from Security-Onion-Solutions/reyesj2/es-integ-tmp
merge dev
|
2025-01-06 15:18:05 -06:00 |
|
reyesj2
|
b97619b8f9
|
Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/es-integ-tmp
|
2025-01-06 14:44:35 -06:00 |
|
reyesj2
|
3d3f0460fa
|
move addon integration script run to elasticfleet state
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-06 14:42:16 -06:00 |
|
Jorge Reyes
|
37d67ee9d0
|
Merge pull request #14073 from Security-Onion-Solutions/reyesj2/es-integ-tmp
update version to foxtrot
|
2025-01-06 11:23:27 -06:00 |
|
reyesj2
|
0d49dee46e
|
update version to foxtrot
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-06 11:22:51 -06:00 |
|
reyesj2
|
9fe3f6042f
|
Remove individual integrations ip mappings component template. Replaced with global mappings
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-06 10:44:22 -06:00 |
|
reyesj2
|
cdd4a1ff1f
|
fixes addon integration map file
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-03 16:06:22 -06:00 |
|