Wes
6f44d39b18
Remove Fleet final pipeline file
2024-07-23 16:37:03 +00:00
Wes
dd85249781
Remove Fleet final pipeline
2024-07-23 16:36:41 +00:00
Wes
bdba621442
Remove soup changes
2024-07-23 16:32:28 +00:00
Mike Reeves
034315ed85
Turn off console messages
2024-07-23 09:46:51 -04:00
Jason Ertel
224c668c31
Merge pull request #13374 from Security-Onion-Solutions/jertel/rmtestparm
...
remove unused test parameters from setup
2024-07-22 11:08:34 -04:00
Jason Ertel
2e17e93cfe
remove unused test parameters from setup
2024-07-22 11:04:45 -04:00
Jason Ertel
7dfb75ba6b
remove unused test parameters from setup
2024-07-22 11:02:56 -04:00
Mike Reeves
af0425b8f1
Update rulecat.conf
2024-07-22 10:20:30 -04:00
Mike Reeves
6cf0a0bb42
Update so-rule-update
2024-07-22 10:19:34 -04:00
Jorge Reyes
d97400e6f5
Merge pull request #13368 from Security-Onion-Solutions/reyesj2/kfps
...
fix kafka-logstash cert for searchnodes
2024-07-21 20:11:42 -04:00
reyesj2
cf1335dd84
searchnode logstash-kafka cert generation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-20 11:31:33 -04:00
coreyogburn
be74449fb9
Merge pull request #13365 from Security-Onion-Solutions/cogburn/suricata-regex-support
...
Cogburn/suricata regex support
2024-07-19 12:47:10 -06:00
Corey Ogburn
45b2413175
Removed Allow/Deny Regexes, Added Enable/Disable Regex
...
Update config and annotations for new regex support for suricata.
2024-07-19 12:45:24 -06:00
Corey Ogburn
022df966c7
Remove Allow/Deny Regex, Add Suricata Enable/Disable Regex
2024-07-19 12:28:04 -06:00
Jorge Reyes
92385d652e
Merge pull request #13363 from Security-Onion-Solutions/reyesj2/ksoup
...
kafka soup pillar
2024-07-19 10:50:48 -04:00
reyesj2
4478d7b55a
kafka soup pillar fix
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-19 09:32:47 -04:00
Wes
612716ee69
Apply ES to load pipelines
2024-07-17 17:35:41 +00:00
Wes
f78a5d1a78
Remove pipeline file
2024-07-17 15:42:40 +00:00
Wes
2d0de87530
Add component templates for Fleet metrics
2024-07-17 15:19:46 +00:00
Josh Patterson
18df491f7e
Merge pull request #13355 from Security-Onion-Solutions/silsll
...
Exclude policy phases if not defined in defaults
2024-07-17 11:09:18 -04:00
m0duspwnens
cee6ee7a2a
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-17 10:16:36 -04:00
m0duspwnens
6d18177f98
only include global phases if defined in default for that index
2024-07-17 10:16:11 -04:00
weslambert
c0bb395571
Remove pipeline file removal
2024-07-17 09:51:51 -04:00
weslambert
f051ddc7f0
Remove pipelines
2024-07-17 09:50:26 -04:00
m0duspwnens
72ad49ed12
add policy for so-lists and so-items
2024-07-16 14:36:06 -04:00
Jorge Reyes
d11f4ef9ba
Merge pull request #13350 from Security-Onion-Solutions/reyesj2/kflux
...
Kafka influxdb metrics & pillar update
2024-07-16 14:26:09 -04:00
reyesj2
03ca7977a0
quote variables
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-16 14:14:55 -04:00
m0duspwnens
91b2e7d400
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-16 14:06:56 -04:00
m0duspwnens
34c3a58efe
add cold policy
2024-07-16 14:03:48 -04:00
Josh Patterson
a867557f54
Merge pull request #13353 from Security-Onion-Solutions/fci
...
fix custom indices
2024-07-16 13:18:11 -04:00
m0duspwnens
b814f32e0a
fix custom indices
2024-07-16 12:39:30 -04:00
coreyogburn
2df44721d0
Merge pull request #13349 from Security-Onion-Solutions/cogburn/bulk-indexer
...
New Config Values for Detections Bulk Indexer
2024-07-15 15:34:01 -06:00
Corey Ogburn
d0565baaa3
New Config Values for Detections Bulk Indexer
...
`maxScrollSize` defines the "page size" of each scroll request.
`bulkIndexerWorkerCount` defines how many worker threads a bulk indexer should use. 0 or fewer indicates that 1 thread per CPU core should be used.
2024-07-15 14:43:47 -06:00
weslambert
38e7da1334
Merge pull request #13347 from Security-Onion-Solutions/upgrade/elastic_8_14_3
...
Elastic 8.14.3
2024-07-15 16:29:24 -04:00
reyesj2
1b623c5c7a
Show Kafka EPS for nodes with broker role only
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:27:48 -04:00
reyesj2
542a116b8c
use so-yaml add for kafka pillar change
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:26:52 -04:00
Doug Burks
e7b6496f98
Merge pull request #13348 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346
2024-07-15 15:59:49 -04:00
Doug Burks
3991c7b5fe
FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346
2024-07-15 15:52:00 -04:00
weslambert
678b232c24
Elastic 8.14.3
2024-07-15 15:48:01 -04:00
weslambert
fbd0dbd048
Elastic 8.14.3
2024-07-15 15:46:55 -04:00
weslambert
1df19faf5c
Elastic 8.14.3
2024-07-15 15:44:50 -04:00
weslambert
8ec5794833
Update VERSION
2024-07-15 15:42:40 -04:00
weslambert
bf07d56da6
Merge pull request #13341 from Security-Onion-Solutions/revert-13323-fix/agent_pipeline
...
Revert "Change pipeline version for agent"
2024-07-15 11:38:56 -04:00
weslambert
cdbffa2323
Merge pull request #13342 from Security-Onion-Solutions/revert-13316-foxtrot
...
Revert "Elastic 8.14.2"
2024-07-15 11:38:48 -04:00
Josh Patterson
55469ebd24
Merge pull request #13340 from Security-Onion-Solutions/surianno
...
force var to be list of string
2024-07-15 11:34:00 -04:00
weslambert
4e81860a13
Revert "Change pipeline version for agent"
2024-07-15 11:33:52 -04:00
m0duspwnens
a23789287e
force var to be list of string
2024-07-15 11:29:47 -04:00
weslambert
fe1824aedd
Revert "Elastic 8.14.2"
2024-07-15 11:28:59 -04:00
Jorge Reyes
e58b2c45dd
Merge pull request #13335 from Security-Onion-Solutions/reyesj2/kgz
...
FIX: Kafka configuration updates
2024-07-12 15:55:43 -04:00
reyesj2
5d322ebc0b
Allow searchnodes to run kafka.ssl state for kafka-logstash cert generation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-12 14:45:11 -04:00