Wes Lambert
|
42d6c3a956
|
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
|
2022-03-15 14:55:04 +00:00 |
|
Wes Lambert
|
5f56c7a261
|
Replace ELASTICCURL with so-elasticsearch-query
|
2022-03-15 14:32:00 +00:00 |
|
Wes Lambert
|
d12ff503c2
|
Chage role loading verbiage
|
2022-03-11 16:23:19 +00:00 |
|
Wes Lambert
|
dc258cf043
|
Load custom component templates in so-elasticsearch-templates-load
|
2022-03-11 16:22:55 +00:00 |
|
Wes Lambert
|
8e43a6e571
|
Don't generate index template if index_template definition is not present in pillar
|
2022-03-11 16:22:06 +00:00 |
|
m0duspwnens
|
e1e8a20e11
|
make sure values exist in data structure
|
2022-03-10 17:09:00 -05:00 |
|
weslambert
|
406267a892
|
Add process.name.keyword
|
2022-03-08 12:42:34 -05:00 |
|
Mike Reeves
|
4eb37fd5a9
|
Update init.sls
|
2022-03-07 15:09:36 -05:00 |
|
Mike Reeves
|
d33db6fb23
|
Only load pipelines on change
|
2022-03-07 14:25:46 -05:00 |
|
Wes Lambert
|
c549b20221
|
Add DTC client mappings
|
2022-03-07 18:36:26 +00:00 |
|
Mike Reeves
|
c67604590d
|
Only load templates on change
|
2022-03-07 09:52:18 -05:00 |
|
weslambert
|
fc3273fa49
|
Change to label fields to comply with what's defined in Filebeat template
|
2022-03-04 16:29:01 -05:00 |
|
weslambert
|
254cf53c2f
|
Increase clause count to 3500
|
2022-03-04 10:36:37 -05:00 |
|
Wes Lambert
|
ffae22beef
|
Add DTC syslog mappings for .keyword and add refs to defaults.yml
|
2022-03-04 13:04:11 +00:00 |
|
Wes Lambert
|
1f71816ad7
|
Add keyword subfield for DTC winlog mappings
|
2022-03-03 14:54:30 +00:00 |
|
Wes Lambert
|
1c086e36da
|
Add missing comma for file mappings
|
2022-03-03 13:49:54 +00:00 |
|
Wes Lambert
|
aa8d24b6cd
|
Add DTC destination, source, and winlog mapping references to templates in defaults file
|
2022-03-03 13:42:20 +00:00 |
|
Wes Lambert
|
85979cbce8
|
Add file, process, and winlog mapping changes
|
2022-03-03 13:37:27 +00:00 |
|
Wes Lambert
|
8f97f09c9c
|
Additional .keyword changes for host.hostname client.address, and event.action
|
2022-03-02 21:54:46 +00:00 |
|
Wes Lambert
|
3ee46e4c29
|
Add .keyword for destination/source geo.country_name
|
2022-03-02 21:50:03 +00:00 |
|
Wes Lambert
|
c5b16fdf3b
|
Adjust field limit for now
|
2022-03-02 16:33:39 +00:00 |
|
Wes Lambert
|
ab9b81ea39
|
Change match_only_text to text for mac in host mappings
|
2022-03-02 15:01:05 +00:00 |
|
Wes Lambert
|
ed620b93b7
|
Add custom analyzer definition to all SO/DTC mappings
|
2022-03-02 14:43:19 +00:00 |
|
Wes Lambert
|
27c8eaa630
|
Update all other mappings for .security where applicable
|
2022-03-02 14:39:23 +00:00 |
|
Wes Lambert
|
e925d435ff
|
Update event, file, and host mappings to include .security
|
2022-03-02 14:33:52 +00:00 |
|
Wes Lambert
|
496b161253
|
Update ECS mappings to include .security
|
2022-03-02 14:27:36 +00:00 |
|
Wes Lambert
|
aae2fd1fbb
|
Update DNS mappings to include .security
|
2022-03-02 14:27:15 +00:00 |
|
Wes Lambert
|
0b45cf7ae1
|
Update base mappings to include .security
|
2022-03-02 14:25:57 +00:00 |
|
Wes Lambert
|
d89af5f04f
|
Update agent mappings to include .security
|
2022-03-02 14:25:14 +00:00 |
|
Wes Lambert
|
2d2ec45029
|
Modify base ECS mappings to include .security where possible, as well as custom analyzer definition
|
2022-03-02 14:19:36 +00:00 |
|
Wes Lambert
|
5489b8559d
|
Revert "Switch from .security to match_only_text"
This reverts commit f7862af934.
|
2022-03-01 18:44:00 +00:00 |
|
Wes Lambert
|
2a9caccc7c
|
Revert "Add additional .text subfield mappings"
This reverts commit 61dadc6249.
|
2022-03-01 18:43:24 +00:00 |
|
Wes Lambert
|
a290602a70
|
Revert syslog pipeline updates from Abe' PR for now
|
2022-03-01 15:31:07 +00:00 |
|
Wes Lambert
|
038dc49098
|
Temporarily increase field limit before trimming efforts
|
2022-03-01 15:06:28 +00:00 |
|
Wes Lambert
|
dc07adca63
|
Rename ingest.timestamp to event.ingested
|
2022-03-01 15:05:08 +00:00 |
|
weslambert
|
414b9dcd59
|
Run template load first to prevent issues with pipeline changes that generate new indices
|
2022-02-28 12:33:18 -05:00 |
|
Doug Burks
|
32b71fdcac
|
Avoid changing _index for imported logs
|
2022-02-26 10:36:09 -05:00 |
|
weslambert
|
e942d81433
|
Ensure correct formatting for source override
|
2022-02-25 19:14:58 -05:00 |
|
weslambert
|
a511fd33e9
|
Ensure correct formatting for destination override
|
2022-02-25 19:14:21 -05:00 |
|
Wes Lambert
|
a8bdff89ae
|
Move files into SO component template directory
|
2022-02-25 18:00:16 +00:00 |
|
Wes Lambert
|
08097fe9ec
|
Add Playbook override mappings
|
2022-02-25 17:58:51 +00:00 |
|
Wes Lambert
|
61dadc6249
|
Add additional .text subfield mappings
|
2022-02-25 16:27:37 +00:00 |
|
Wes Lambert
|
0f8a39002f
|
Add .text subfield mappings for DTC where fields are defined
|
2022-02-24 19:39:52 +00:00 |
|
weslambert
|
23fb62c0d6
|
Split Zeek DNS records into a separate index
|
2022-02-24 12:52:25 -05:00 |
|
weslambert
|
bc2c1b4ccc
|
Merge pull request #6935 from abesinger/issue/6912
Updated syslog pipeline, resolves #6912.
|
2022-02-24 08:33:55 -05:00 |
|
weslambert
|
6a0ecb9e9c
|
Add IDH and Kratos index templates
|
2022-02-23 12:13:46 -05:00 |
|
Wes Lambert
|
f7862af934
|
Switch from .security to match_only_text
|
2022-02-22 20:33:49 +00:00 |
|
Wes Lambert
|
4d1533537b
|
Remove old index templates
|
2022-02-18 20:08:13 +00:00 |
|
m0duspwnens
|
cb55af4c1c
|
dont allow $ to be used for elasticsearch:auth or kibana:secrets - https://github.com/Security-Onion-Solutions/securityonion/issues/7233
|
2022-02-18 13:13:56 -05:00 |
|
weslambert
|
87a5e64f12
|
Merge pull request #7249 from Security-Onion-Solutions/fix/component_index_association
Update component -> index association for file/scan mappings for Strelka
|
2022-02-18 12:19:41 -05:00 |
|