reyesj2
382cd24a57
Small changes needed for using new Kafka docker image + added Kafka logging output to /opt/so/log/kafka/
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:39:21 -04:00
reyesj2
b1beb617b3
Logstash should be disabled when Kafka is enabled except when a minion override exists OR node is a standalone
...
- Standalone subscribes to Kafka topics via logstash for ingest
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:38:09 -04:00
reyesj2
91f8b1fef7
Set default replication factor back to Kafka default
...
If replication factor is > 1 Kafka will fail to start until another broker is added
- For internal automated testing purposes a Standalone will be utilized
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:35:09 -04:00
Jason Ertel
ca6e2b8e22
Merge pull request #13054 from Security-Onion-Solutions/jertel/eaconfig
...
fix elastalert settings
2024-05-21 18:38:03 -04:00
Jason Ertel
8af3158ea7
fix elastalert settings
2024-05-21 18:28:21 -04:00
Josh Brower
8b011b8d7e
Merge pull request #13053 from Security-Onion-Solutions/2.4/alertsefaults
...
Add rule.uuid to default groupbys
2024-05-21 17:54:27 -04:00
DefensiveDepth
f9e9b825cf
Removed unneeded groupby
2024-05-21 17:53:20 -04:00
DefensiveDepth
3992ef1082
Add rule.uuid to default groupbys
2024-05-21 17:45:56 -04:00
weslambert
556fdfdcf9
Merge pull request #13052 from Security-Onion-Solutions/fix/add_rule_uuid
...
Add rule.uuid for YARA matches
2024-05-21 17:09:49 -04:00
weslambert
f4490fab58
Add rule.uuid for YARA matches
2024-05-21 17:05:39 -04:00
weslambert
5aaf44ebb2
Merge pull request #13049 from Security-Onion-Solutions/fix/detections_alerts_component_template
...
Exclude detections from template name matching
2024-05-21 13:45:19 -04:00
weslambert
deb140e38e
Exclude detections from template name matching
2024-05-21 13:38:52 -04:00
Jason Ertel
3de6454d4f
Merge pull request #13047 from Security-Onion-Solutions/jertel/eaconfig
...
Jertel/eaconfig
2024-05-21 13:34:20 -04:00
Jason Ertel
d57cc9627f
exclude false positives related to detections
2024-05-21 13:31:50 -04:00
Jason Ertel
8ce19a93b9
exclude false positives related to detections
2024-05-21 13:29:20 -04:00
Jason Ertel
d315b95d77
elastalert settings
2024-05-21 07:15:19 -04:00
Doug Burks
6172816f61
Merge pull request #13044 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md with new Detections screenshot number
2024-05-21 06:49:35 -04:00
Doug Burks
03826dd32c
Update README.md with new Detections screenshot number
2024-05-21 06:43:07 -04:00
Jason Ertel
b7a4f20c61
elastalert settings
2024-05-20 20:11:30 -04:00
Jason Ertel
02b4d37c11
elastalert settings
2024-05-20 20:00:31 -04:00
Jason Ertel
f8ce039065
elastalert settings
2024-05-20 19:58:12 -04:00
Jason Ertel
e2d0b8f4c7
elastalert settings
2024-05-20 19:38:36 -04:00
Jason Ertel
8a3061fe3e
elastalert settings
2024-05-20 19:36:06 -04:00
Jason Ertel
c594168b65
elastalert settings
2024-05-20 19:05:43 -04:00
Jason Ertel
31fdf15ce1
Merge branch '2.4/dev' into jertel/eaconfig
2024-05-20 18:59:35 -04:00
Jason Ertel
6b2219b7f2
elastalert settings
2024-05-20 18:52:37 -04:00
coreyogburn
64144b4759
Merge pull request #13041 from Security-Onion-Solutions/cogburn/integrity-checker-annotations
...
Annotate integrityCheckFrequencySeconds per det engine
2024-05-20 14:52:38 -06:00
Corey Ogburn
6e97c39f58
Marked as Advanced
2024-05-20 14:52:05 -06:00
Corey Ogburn
026023fd0a
Annotate integrityCheckFrequencySeconds per det engine
2024-05-20 14:35:11 -06:00
Jorge Reyes
d7ee89542a
Merge pull request #13040 from Security-Onion-Solutions/lkscript
...
Create helper script for tpm enrollment
2024-05-20 15:25:50 -04:00
reyesj2
6fac6eebce
Helper script for enrolling tpm into luks
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-20 14:37:54 -04:00
coreyogburn
3c3497c2fd
Merge pull request #13039 from Security-Onion-Solutions/cogburn/integrity-check
...
Add Default IntegrityCheck Frequency Values
2024-05-20 11:26:30 -06:00
Corey Ogburn
fcc72a4f4e
Add Default IntegrityCheck Frequency Values
2024-05-20 11:23:25 -06:00
coreyogburn
28dea9be58
Merge pull request #13037 from Security-Onion-Solutions/cogburn/comp-report-path-change
...
Change Compilation Report Path
2024-05-17 15:48:52 -06:00
Corey Ogburn
0cc57fc240
Change Compilation Report Path
...
Move compilation report path to /opt/so/state and mount that foulder in SOC
2024-05-17 15:47:23 -06:00
weslambert
17518b90ca
Merge pull request #13036 from Security-Onion-Solutions/fix/yara_compile_report
...
Create YARA compile report for SOC integrity check
2024-05-17 16:15:21 -04:00
weslambert
d9edff38df
Create compile report for SOC integrity check
2024-05-17 16:10:10 -04:00
Jason Ertel
300d8436a8
Merge pull request #13035 from Security-Onion-Solutions/jertel/eaconfig
...
add support for custom alerters
2024-05-17 15:01:54 -04:00
Jason Ertel
1c4d36760a
add support for custom alerters
2024-05-17 14:49:39 -04:00
reyesj2
34a5985311
Create tpm enrollment script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-16 21:14:57 -04:00
Josh Patterson
aa0163349b
Merge pull request #13031 from Security-Onion-Solutions/issue/13021
...
Issue/13021
2024-05-16 16:40:17 -04:00
Josh Patterson
572b8d08d9
Merge branch '2.4/dev' into issue/13021
2024-05-16 16:39:17 -04:00
m0duspwnens
cc6cb346e7
fix issue/13030
2024-05-16 16:31:45 -04:00
m0duspwnens
b54632080e
check if exists in override before popping
2024-05-16 16:04:17 -04:00
Josh Patterson
44d3468f65
Merge pull request #13029 from Security-Onion-Solutions/revert-13028-issue/13021
...
Revert "dont merge policy from global_overrides if not defined in default index_settings"
2024-05-16 15:48:05 -04:00
Josh Patterson
9d4668f4d3
Revert "dont merge policy from global_overrides if not defined in default index_settings"
2024-05-16 15:45:55 -04:00
Josh Patterson
da2ac4776e
Merge pull request #13028 from Security-Onion-Solutions/issue/13021
...
dont merge policy from global_overrides if not defined in default index_settings
2024-05-16 14:33:51 -04:00
m0duspwnens
9796354b48
dont merge policy from global_overrides if not defined in default index_settings
2024-05-16 14:27:32 -04:00
Jason Ertel
aa32eb9c0e
Merge pull request #13025 from Security-Onion-Solutions/jertel/suridp
...
exclude detect-parse errors
2024-05-15 19:21:30 -04:00
Jason Ertel
4771810361
exclude detect-parse errors
2024-05-15 19:10:50 -04:00