Mike Reeves
|
ae89260793
|
Merge pull request #3127 from Security-Onion-Solutions/foxtrot
Add automation files for Suricata metadata
|
2021-02-25 08:26:20 -05:00 |
|
Jason Ertel
|
34dab9009c
|
Ensure Zeek spool dir is owned by Zeek to allow Zeek to start correctly
|
2021-02-25 08:10:13 -05:00 |
|
Jason Ertel
|
ef7cdf27bf
|
Add automation files for Suricata metadata
|
2021-02-25 07:43:11 -05:00 |
|
Mike Reeves
|
c39b516f38
|
Merge pull request #3121 from Security-Onion-Solutions/strelkainstall
Fix Strelka Rule updates, repo fix
|
2021-02-24 17:13:41 -05:00 |
|
Mike Reeves
|
39860ea6bd
|
Merge pull request #3123 from Security-Onion-Solutions/kilo
Add function to soup to notify user of log_size_limit issues
|
2021-02-24 17:09:07 -05:00 |
|
Mike Reeves
|
701cfe7e9a
|
Merge branch 'dev' into strelkainstall
|
2021-02-24 17:07:26 -05:00 |
|
William Wernert
|
4ae34f928c
|
Merge branch 'dev' into kilo
# Conflicts:
# setup/so-functions
|
2021-02-24 17:05:53 -05:00 |
|
Mike Reeves
|
ff577cdf41
|
Merge pull request #3079 from petiepooo/feature/eslogsize
calculate log_size_limit based on /nsm/elasticsearch
|
2021-02-24 17:03:35 -05:00 |
|
William Wernert
|
4a6ad7c87e
|
Set MAINIP to MNIC_IP when using a VPN
|
2021-02-24 16:31:45 -05:00 |
|
Mike Reeves
|
b30f964974
|
Moving the wildcard
|
2021-02-24 16:09:37 -05:00 |
|
Mike Reeves
|
262bf03595
|
Testing capitals
|
2021-02-24 16:04:53 -05:00 |
|
Mike Reeves
|
ae17a3aeb8
|
Fix Syntax try 3
|
2021-02-24 16:02:36 -05:00 |
|
Mike Reeves
|
ab66f175c5
|
Fix Syntax
|
2021-02-24 16:01:18 -05:00 |
|
Mike Reeves
|
8f3ba7633c
|
Fix Syntax
|
2021-02-24 15:57:18 -05:00 |
|
Mike Reeves
|
5949119cb5
|
Bypass route check
|
2021-02-24 15:53:55 -05:00 |
|
Mike Reeves
|
6058400aad
|
Bypass route check
|
2021-02-24 15:52:50 -05:00 |
|
William Wernert
|
f042312aac
|
Merge branch 'dev' into kilo
# Conflicts:
# salt/common/tools/sbin/soup
|
2021-02-24 15:42:10 -05:00 |
|
Mike Reeves
|
52fd3c0470
|
Merge pull request #3122 from Security-Onion-Solutions/strelka_repo_update
Modify soup to add Strelka rule repo in pillar
|
2021-02-24 15:35:35 -05:00 |
|
Wes Lambert
|
6ea8eab9af
|
Modify soup to add Strelka rule repo in pillar
|
2021-02-24 20:32:47 +00:00 |
|
William Wernert
|
775f274962
|
Also check /nsm/elasticsearch in soup log_size_limit check
Reflect changes from PR#3079
|
2021-02-24 14:36:41 -05:00 |
|
William Wernert
|
e500e24802
|
Only show log_size_limit warning on dist if heavynode pillars exist
|
2021-02-24 13:56:59 -05:00 |
|
William Wernert
|
298f7da90b
|
Fix indent in set_default_log_size
|
2021-02-24 13:56:33 -05:00 |
|
Mike Reeves
|
38d60752b7
|
Merge pull request #3110 from Security-Onion-Solutions/dockerclean
Docker Cleanup
|
2021-02-24 13:44:06 -05:00 |
|
Josh Patterson
|
25ca70efd8
|
Merge pull request #3120 from Security-Onion-Solutions/issue/3115
ensure log_level and log_level_logfile are set to info in /etc/salt/minion
|
2021-02-24 13:36:34 -05:00 |
|
Mike Reeves
|
bdfec5176d
|
Dont disable unused interfaces during setup
|
2021-02-24 13:22:06 -05:00 |
|
William Wernert
|
ece79379a5
|
Add file name/path to log_size_limit message
|
2021-02-24 12:54:14 -05:00 |
|
William Wernert
|
ac6f1df86f
|
[fix] Only check log_size_limit on .2X -> .30
* Since we're showing a message in the middle of soup, wait for keypress if it's shown
|
2021-02-24 12:35:17 -05:00 |
|
William Wernert
|
4507a89d95
|
tar arg fix (-x -> -z)
|
2021-02-24 12:24:54 -05:00 |
|
William Wernert
|
2be7ccac33
|
Add function to notify user that log_size_limit may be incorrect
|
2021-02-24 12:24:32 -05:00 |
|
m0duspwnens
|
eba5d271aa
|
logfile is 1 word https://github.com/Security-Onion-Solutions/securityonion/issues/3115
|
2021-02-24 11:56:43 -05:00 |
|
m0duspwnens
|
3552abfca1
|
ensure info log level -
|
2021-02-24 11:50:08 -05:00 |
|
Mike Reeves
|
1d45472b48
|
Fix Strelka Rule updates, repo fix
|
2021-02-24 11:30:43 -05:00 |
|
Mike Reeves
|
68c683e3bf
|
Merge pull request #3114 from Security-Onion-Solutions/foxtrot
Add retry support for 'docker pull' command
|
2021-02-24 11:25:14 -05:00 |
|
Jason Ertel
|
050058a959
|
Add retry support for 'docker pull' command
|
2021-02-24 09:34:14 -05:00 |
|
Mike Reeves
|
09c94ddf95
|
Docker Cleanup
|
2021-02-24 08:57:25 -05:00 |
|
Mike Reeves
|
54367db99b
|
Merge pull request #3108 from Security-Onion-Solutions/issue/3056
add estimated EPS graphs to Grafana for manager, mastersearch and standalone nodes
|
2021-02-24 08:49:36 -05:00 |
|
Mike Reeves
|
56daae64be
|
Merge pull request #3097 from Security-Onion-Solutions/sometacleanup
Clean up on sid numbers
|
2021-02-24 08:24:48 -05:00 |
|
Mike Reeves
|
00deab9305
|
Merge pull request #3100 from Security-Onion-Solutions/kilo
Add so-preflight + usage to so-monitor-add, fix managersearch missing from so-rule
|
2021-02-23 17:32:41 -05:00 |
|
Mike Reeves
|
fa6fd20ff9
|
Merge pull request #3088 from Security-Onion-Solutions/soupairgap
Syn the latest rules on an airgap install
|
2021-02-23 17:31:29 -05:00 |
|
Mike Reeves
|
d195efa8e5
|
Merge pull request #3098 from Security-Onion-Solutions/feature/update-soup
Update SOUP with so-playbook-sigma-refresh
|
2021-02-23 15:46:48 -05:00 |
|
Josh Brower
|
a7eb3cd38d
|
Add so-playbook-sigma-refresh
|
2021-02-23 15:43:09 -05:00 |
|
Mike Reeves
|
5baa4cb6a5
|
Clean up on sid numbers
|
2021-02-23 15:42:58 -05:00 |
|
William Wernert
|
a361ca0e19
|
[fix] Add managersearch node type to so-rule pillar search
|
2021-02-23 14:15:17 -05:00 |
|
William Wernert
|
9cf15cdae5
|
[fix] Reword so-monitor-add help message
|
2021-02-23 13:55:18 -05:00 |
|
William Wernert
|
d5477b4721
|
Add usage/help message to so-monitor-add
|
2021-02-23 13:48:54 -05:00 |
|
William Wernert
|
5a2fa26d72
|
Add ET OPEN/PRO URLs
|
2021-02-23 13:47:52 -05:00 |
|
William Wernert
|
61a23509a1
|
[fix] grep -q doesn't give output to parse, so remove the flag
|
2021-02-23 13:43:10 -05:00 |
|
William Wernert
|
25698dafe3
|
Add initial pre-flight check script
|
2021-02-23 13:25:54 -05:00 |
|
Mike Reeves
|
186710964b
|
Fix Airgap Rule Path
|
2021-02-23 13:07:23 -05:00 |
|
Mike Reeves
|
3b32eb539f
|
Copy latest rules when using airgaps
|
2021-02-23 11:21:23 -05:00 |
|