weslambert
|
ac28f90af3
|
Remove override
|
2023-08-02 13:15:11 -04:00 |
|
Josh Brower
|
9437a47946
|
Fix formatting
|
2023-07-26 10:54:24 -04:00 |
|
Josh Brower
|
4f94d953c9
|
Merge remote-tracking branch 'origin/2.4/dev' into fix/elasticsearch_endpoint
|
2023-07-25 07:42:59 -04:00 |
|
Wes
|
5553be02ac
|
Change how tags are added
|
2023-07-24 21:31:28 +00:00 |
|
Wes
|
4efc951eaf
|
Add tags
|
2023-07-24 20:57:39 +00:00 |
|
Wes
|
d84dbf9535
|
Add fleet
|
2023-07-24 18:53:52 +00:00 |
|
Wes
|
de7b7ff989
|
Add endpoint
|
2023-07-24 18:35:02 +00:00 |
|
Josh Brower
|
eead0c42d4
|
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/SigmaMappings
|
2023-07-24 09:27:14 -04:00 |
|
Josh Brower
|
741e6039c1
|
Cleanup for Sigma Rules
|
2023-07-24 09:25:58 -04:00 |
|
weslambert
|
83e1e3efdc
|
Merge pull request #10788 from Security-Onion-Solutions/fix/elastic_mappings
Fix user name mapping and remove security subfield
|
2023-07-20 15:51:42 -04:00 |
|
Wes
|
4b7e7978ef
|
Add final pipeline
|
2023-07-19 19:56:54 +00:00 |
|
Wes
|
6a8737e9a2
|
Set delete for interactive
|
2023-07-19 12:21:47 +00:00 |
|
Wes
|
a59eda319e
|
Remove security subfield
|
2023-07-18 19:00:50 +00:00 |
|
Wes
|
8a76975d8c
|
Use new agent scripts
|
2023-07-18 18:43:57 +00:00 |
|
Wes
|
1d3e39b6bd
|
Map user name to keyword and remove security subfield generation
|
2023-07-18 14:46:47 +00:00 |
|
Wes
|
e3249c8e4c
|
Wrap values in quotes for proper conversion
|
2023-07-13 14:18:57 +00:00 |
|
weslambert
|
85bb5a327c
|
Fix long vs float for pe version
|
2023-07-13 09:38:09 -04:00 |
|
Wes
|
577bfac886
|
Update logic for YARA matches
|
2023-07-11 17:00:13 +00:00 |
|
Josh Brower
|
ce1f363424
|
Allow base_url
|
2023-07-08 13:30:19 -04:00 |
|
Wes
|
0b5ee49873
|
Fix inverted logic for component template
|
2023-07-06 20:46:35 +00:00 |
|
Wes
|
910125f13a
|
Restructure logic
|
2023-07-06 17:49:06 +00:00 |
|
Wes
|
d551faeb16
|
Heavy node template considerations
|
2023-07-06 17:19:28 +00:00 |
|
weslambert
|
c2efd7ef64
|
Merge pull request #10655 from Security-Onion-Solutions/feature/supported_integrations
Restructure Elasticsearch templates for supported integrations
|
2023-06-26 09:43:10 -04:00 |
|
weslambert
|
e02bdffe34
|
Fix typos
|
2023-06-23 16:10:22 -04:00 |
|
weslambert
|
e2ff48164b
|
Only load if so-elastic-fleet-common exists
|
2023-06-23 16:03:58 -04:00 |
|
Wes
|
b96d3473f2
|
Fix indentation
|
2023-06-23 18:38:04 +00:00 |
|
Wes
|
62fa15c63e
|
Add more templates
|
2023-06-23 14:43:15 +00:00 |
|
weslambert
|
e995576b1d
|
Remove extra templates
|
2023-06-23 09:41:49 -04:00 |
|
Wes
|
d8700137d2
|
Add updated so-elasticsearch-templates-load
|
2023-06-23 13:23:29 +00:00 |
|
Wes
|
2c42d4b19e
|
Add package check to so-elasticsearch-templates-load
|
2023-06-23 13:22:51 +00:00 |
|
m0duspwnens
|
daaead618e
|
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/heavynode
|
2023-06-22 13:26:56 -04:00 |
|
m0duspwnens
|
19469205e1
|
include eval and import in so-elasticsearch-cluster-settings
|
2023-06-22 13:12:47 -04:00 |
|
m0duspwnens
|
6c4c815683
|
change so-elasticsearch-cluster settings to include heavynode, and only run on managers
|
2023-06-22 13:04:20 -04:00 |
|
m0duspwnens
|
36272efda7
|
create ES_LOGSTASH_NODES which removes heavynodes
|
2023-06-22 09:46:42 -04:00 |
|
weslambert
|
7e37cd0f05
|
Parse xff
|
2023-06-21 14:29:54 -04:00 |
|
Wes
|
3a34da354f
|
Use append instead of set
|
2023-06-15 16:35:43 +00:00 |
|
Wes
|
58a63e0765
|
Remove extra comma
|
2023-06-15 14:22:37 +00:00 |
|
Wes
|
b5bccc5e05
|
Use module in dataset name and add dataset tag
|
2023-06-15 13:06:57 +00:00 |
|
m0duspwnens
|
8f6226b531
|
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/heavynode
|
2023-06-14 10:40:22 -04:00 |
|
m0duspwnens
|
2c4eccd7e0
|
2.4 heavynode changes
|
2023-06-14 10:40:05 -04:00 |
|
Wes
|
48331ce35b
|
Add system.system component templates
|
2023-06-14 13:29:11 +00:00 |
|
Wes
|
c2ac60b82e
|
Add system.system template and add event-mappings
|
2023-06-14 13:28:00 +00:00 |
|
Wes
|
8cde05807c
|
Remove elastic-agent dir
|
2023-06-13 21:33:04 +00:00 |
|
Wes
|
2ac0aba916
|
Add osquery files
|
2023-06-13 21:32:02 +00:00 |
|
Wes
|
af003cc2a1
|
Add osquery templates
|
2023-06-13 20:43:39 +00:00 |
|
Wes
|
bd7644a557
|
Add another template
|
2023-06-13 19:13:20 +00:00 |
|
Wes
|
5547a1b7ab
|
Add event mappings
|
2023-06-13 18:23:50 +00:00 |
|
Wes
|
1b90fd8581
|
Add custom component templates
|
2023-06-13 18:21:45 +00:00 |
|
Wes
|
e43b7607bb
|
Add more component templates
|
2023-06-13 17:04:03 +00:00 |
|
Wes
|
a265c06e31
|
Add other component templates
|
2023-06-13 15:47:25 +00:00 |
|