m0duspwnens
|
ada1c81ab7
|
manager and standalone dashboard changes
|
2020-09-01 10:40:20 -04:00 |
|
m0duspwnens
|
a1a7b36319
|
merge with dev and resolve conflict
|
2020-08-31 16:05:34 -04:00 |
|
m0duspwnens
|
31f25eca57
|
fix grafana related issues. add redis to standalone
|
2020-08-31 15:56:58 -04:00 |
|
Jason Ertel
|
dc3b065a41
|
Set exec bit on new user-add scripts
|
2020-08-31 10:57:23 -04:00 |
|
Wes Lambert
|
46e7e121e3
|
Add Wazuh mgmt wrappers for manage_agents and upgrade
|
2020-08-31 14:54:24 +00:00 |
|
Wes Lambert
|
6d14f2af96
|
Remove minio for now
|
2020-08-31 14:07:47 +00:00 |
|
weslambert
|
42bd75a1cc
|
Merge pull request #1270 from Security-Onion-Solutions/fix/elastalert_startup
Wait for Elasticsearch indices to be queryable before starting Elasta…
|
2020-08-31 09:56:18 -04:00 |
|
Wes Lambert
|
9abbda8e04
|
Wait for Elasticsearch indices to be queryable before starting Elastalert container
|
2020-08-31 13:54:49 +00:00 |
|
Jason Ertel
|
189c02648d
|
Move container status check to so-common
|
2020-08-31 09:52:06 -04:00 |
|
Jason Ertel
|
8e06f0453e
|
Only add users to aux systems if those systems are currently running
|
2020-08-31 09:41:06 -04:00 |
|
Doug Burks
|
77b3ebdabe
|
Hunt Events table should show ssl.server_name when searching for ssl
Hunt Events table should show ssl.server_name when searching for ssl #1267
|
2020-08-30 06:56:15 -04:00 |
|
Josh Brower
|
b7dd14b8f0
|
Set event.code to string for WEL
|
2020-08-28 13:40:04 -04:00 |
|
Jason Ertel
|
4e3e83820f
|
Correct pillar key for thehive
|
2020-08-28 08:17:42 -04:00 |
|
m0duspwnens
|
b1e7ffc173
|
fix inbound for monitor traffic on standalone graphana dashboard
|
2020-08-27 18:24:26 -04:00 |
|
Jason Ertel
|
a3e34bfaca
|
Add users to Fleet, TheHive, and Cortex when adding a user to SO via so-user-add command
|
2020-08-27 16:58:02 -04:00 |
|
Mike Reeves
|
2b0b695ee4
|
Fix duplicate docker
|
2020-08-27 10:15:22 -04:00 |
|
weslambert
|
509985ed07
|
Merge pull request #1254 from Security-Onion-Solutions/fix/sensor_clean
Cron updates
|
2020-08-26 11:03:03 -04:00 |
|
weslambert
|
000c2abb33
|
Update timing for so-yara-update
|
2020-08-26 11:02:33 -04:00 |
|
Mike Reeves
|
e993397173
|
Update docker to latest version
|
2020-08-26 10:35:17 -04:00 |
|
Josh Brower
|
67e0a219e6
|
Upgraded to Fleet 3.1
|
2020-08-26 06:13:45 -04:00 |
|
Josh Brower
|
b6ebcf6551
|
Merge pull request #1250 from Security-Onion-Solutions/feature/es-security-field
Adds new .security analyzed subfield
|
2020-08-26 05:12:23 -04:00 |
|
Josh Brower
|
1cf7301db4
|
Adds new .security analyzed subfield
|
2020-08-26 05:11:42 -04:00 |
|
Jason Ertel
|
3122280bd5
|
Update version to 2.2.0-rc.3
|
2020-08-25 15:16:09 -04:00 |
|
weslambert
|
ce49e050bc
|
Update timing for sensor clean cron
|
2020-08-25 12:14:43 -04:00 |
|
Wes Lambert
|
c03812f7ab
|
Add rotation for sensor_clean log
|
2020-08-25 15:34:30 +00:00 |
|
weslambert
|
a8f727ad40
|
Don't write to log if not past CRIT_DISK_USAGE
|
2020-08-25 11:19:36 -04:00 |
|
Mike Reeves
|
a97ca94354
|
Rotate suri stats log hourly
|
2020-08-23 16:08:17 -04:00 |
|
Mike Reeves
|
ebd8105cb5
|
Rotate suri stats log hourly
|
2020-08-23 16:03:37 -04:00 |
|
Jason Ertel
|
9c6cc81f70
|
Remove improper suricata logging filter - this re-enables logging output for the suricata process itself
|
2020-08-21 12:44:28 -04:00 |
|
Mike Reeves
|
05d727e599
|
Final changes.json update
|
2020-08-20 19:18:39 -04:00 |
|
Mike Reeves
|
2b88f22eb2
|
Make HUP for rotate more reliable
|
2020-08-20 17:57:36 -04:00 |
|
Mike Reeves
|
b7da768dc7
|
add logrotate
|
2020-08-20 16:46:32 -04:00 |
|
Josh Patterson
|
44093e7484
|
Merge pull request #1228 from Security-Onion-Solutions/quickfix/importnode
remove bonding for import node
|
2020-08-20 14:23:21 -04:00 |
|
m0duspwnens
|
a7a0520cfe
|
remove bonding for import node
|
2020-08-20 14:20:09 -04:00 |
|
Jason Ertel
|
d1e5649a68
|
Corrected JSON typo and improved formatting
|
2020-08-20 13:46:20 -04:00 |
|
Mike Reeves
|
3eea2c6b10
|
2.1.0 Release notes in changes.json
|
2020-08-20 13:26:14 -04:00 |
|
Mike Reeves
|
df95baa835
|
Point logstash to use intca.crt
|
2020-08-20 10:45:48 -04:00 |
|
m0duspwnens
|
43f4ebbcf1
|
remove monint from managersearch since they dont have a monint
|
2020-08-20 09:05:38 -04:00 |
|
Mike Reeves
|
2fce138d95
|
Change it to grains.host instead of grains.id
|
2020-08-19 21:26:27 -04:00 |
|
Mike Reeves
|
ccc2ed4478
|
don't create symlinks if a heavy node
|
2020-08-19 21:18:57 -04:00 |
|
Mike Reeves
|
f9e5ea8ba7
|
Fix SSL for filebeat
|
2020-08-19 21:12:41 -04:00 |
|
Mike Reeves
|
f7d3dca322
|
Fix duplicate state
|
2020-08-19 21:00:28 -04:00 |
|
Mike Reeves
|
d969b1e1b7
|
Update init.sls
|
2020-08-19 20:56:08 -04:00 |
|
Mike Reeves
|
507a3e852c
|
Update init.sls
|
2020-08-19 20:02:38 -04:00 |
|
Mike Reeves
|
5f41d9fc25
|
fix filebeat certs
|
2020-08-19 19:51:57 -04:00 |
|
Mike Reeves
|
8312221c82
|
Update soup
|
2020-08-19 18:51:32 -04:00 |
|
Mike Reeves
|
0439cf3205
|
Update soup
|
2020-08-19 18:47:36 -04:00 |
|
Jason Ertel
|
2325940789
|
Ensure strelka manager connects to local redis on heavy nodes
|
2020-08-19 16:24:28 -04:00 |
|
Josh Patterson
|
9fce1fc47d
|
Merge pull request #1220 from Security-Onion-Solutions/issue/1188
Issue/1188
|
2020-08-19 16:15:43 -04:00 |
|
Jason Ertel
|
5ff0058a65
|
Ensure strelka backend, frontend, and filestream are connecting to redis locally, on heavy node instances
|
2020-08-19 16:13:18 -04:00 |
|