m0duspwnens
|
b38d5df684
|
set default mime_db
|
2023-03-14 13:25:51 -04:00 |
|
m0duspwnens
|
9d4e1cc149
|
jinja for strelka
|
2023-03-13 16:48:21 -04:00 |
|
m0duspwnens
|
58343e39fa
|
2.4 strelka
|
2023-03-10 17:32:14 -05:00 |
|
m0duspwnens
|
61879a8d33
|
merge with dev and resolve conflicts in salt/top
|
2023-03-08 09:04:09 -05:00 |
|
weslambert
|
2d7ce41a70
|
Remove reference to 'so-curator-cluster-warm' script since it has been removed
|
2023-03-07 16:16:55 -05:00 |
|
weslambert
|
a738c7c36d
|
Merge pull request #9907 from Security-Onion-Solutions/fix/curator_global_delete_action
Add the new Security Onion index format to the global delete action file for Curator
|
2023-03-07 16:03:28 -05:00 |
|
weslambert
|
e93c052d34
|
Add the new index format to the global delete action file for Curator
|
2023-03-07 15:21:53 -05:00 |
|
Josh Brower
|
fd2312a2ac
|
Remove EA install from manager highstates
|
2023-03-07 15:13:35 -05:00 |
|
Wes
|
f50639d2d2
|
Fix import and syslog actions
|
2023-03-07 17:41:48 +00:00 |
|
Wes
|
26c9813276
|
Add keys for new Curator actions to defaults.yaml
|
2023-03-07 17:29:07 +00:00 |
|
Wes
|
88d98af243
|
Add new Curator action files to Curator close and delete scripts
|
2023-03-07 17:21:03 +00:00 |
|
Wes
|
d636546871
|
Add new Curator action files
|
2023-03-07 17:15:25 +00:00 |
|
Wes
|
073054b447
|
Remove 'so-curator-cluster-warm' and remove unncessary Curator default values
|
2023-03-07 16:21:55 +00:00 |
|
Wes
|
df94e830c5
|
Remove unnecessary Curator action files
|
2023-03-07 16:15:41 +00:00 |
|
m0duspwnens
|
2767d4bee3
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
|
2023-03-07 10:36:12 -05:00 |
|
m0duspwnens
|
14aa9ac5c9
|
apply elastic-fleet state to managers
|
2023-03-07 10:35:49 -05:00 |
|
Wes
|
086b3bf528
|
Add Curator to so-status output
|
2023-03-07 15:14:53 +00:00 |
|
m0duspwnens
|
691080de88
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
|
2023-03-06 16:04:14 -05:00 |
|
Josh Brower
|
a6db2d4502
|
Fleet - setup ES output for all Managers
|
2023-03-06 15:50:09 -05:00 |
|
m0duspwnens
|
0f9803120e
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
|
2023-03-06 13:55:09 -05:00 |
|
m0duspwnens
|
b6d55bedc8
|
make influxdb token accessible to all nodes
|
2023-03-06 13:50:17 -05:00 |
|
Josh Brower
|
8fae826a3a
|
Merge pull request #9890 from Security-Onion-Solutions/2.4/fixosquerylink
Fixup osquery SO Hunt link
|
2023-03-06 07:25:00 -05:00 |
|
Doug Burks
|
a2bda07820
|
add VLAN dashboard
|
2023-03-05 15:24:11 -05:00 |
|
Doug Burks
|
19ab2a5a46
|
rename suricata vlan field to network.vlan.id
|
2023-03-05 05:57:52 -05:00 |
|
Josh Brower
|
f0db5cf657
|
Fixup osquery SO Hunt link
|
2023-03-04 11:50:01 -05:00 |
|
Doug Burks
|
4a2e75dd8c
|
fix formatting
|
2023-03-03 17:16:45 -05:00 |
|
Doug Burks
|
e24296d536
|
add SOC Dashboards groupby for Zeek conn vlan field
|
2023-03-03 15:23:43 -05:00 |
|
Doug Burks
|
9940a36722
|
update Elasticsearch ingest for Zeek conn vlan field
|
2023-03-03 15:22:43 -05:00 |
|
Doug Burks
|
adb925b4d6
|
enable zeek vlan script
|
2023-03-03 12:48:42 -05:00 |
|
m0duspwnens
|
e3f9b5297a
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
|
2023-03-02 16:58:56 -05:00 |
|
m0duspwnens
|
e6167dc34a
|
heavynode changes
|
2023-03-02 15:09:59 -05:00 |
|
weslambert
|
06d1f0f913
|
Update Curator configuration to align with requirements for Curator 8.0.x
|
2023-03-02 08:46:52 -05:00 |
|
Mike Reeves
|
af284b9aae
|
Update init.sls
|
2023-03-01 16:38:48 -05:00 |
|
Mike Reeves
|
2091806f1f
|
Merge pull request #9864 from Security-Onion-Solutions/setuperrors
Fix some errors in setup
|
2023-03-01 09:48:20 -05:00 |
|
m0duspwnens
|
704365c6eb
|
only stdout redirect
|
2023-03-01 09:44:48 -05:00 |
|
m0duspwnens
|
a79c380e2b
|
use cmd.run to populate metrics_link
|
2023-03-01 09:18:58 -05:00 |
|
weslambert
|
134caa7f58
|
Various adjustments to descriptions
|
2023-02-28 16:31:16 -05:00 |
|
m0duspwnens
|
8772dcaa10
|
ensure influxdb is running
|
2023-02-28 15:57:54 -05:00 |
|
Josh Brower
|
96467f0bd8
|
Merge pull request #9865 from Security-Onion-Solutions/2.4/fleet-esoutput
Move Output to ES
|
2023-02-28 15:20:46 -05:00 |
|
m0duspwnens
|
052e0dea2e
|
create and manage metrics_link in a file for soc
|
2023-02-28 14:47:44 -05:00 |
|
Josh Patterson
|
cbcd3c9dd9
|
Update defaults.map.jinja
|
2023-02-27 15:39:03 -05:00 |
|
Josh Patterson
|
8632606a24
|
Update defaults.map.jinja
|
2023-02-27 15:37:35 -05:00 |
|
Josh Patterson
|
8d33f01936
|
Update defaults.map.jinja
|
2023-02-27 15:01:31 -05:00 |
|
Mike Reeves
|
aa7b05d639
|
small cleanup
|
2023-02-27 14:12:26 -05:00 |
|
Mike Reeves
|
9967e91825
|
remove mysql check
|
2023-02-27 13:42:11 -05:00 |
|
Josh Patterson
|
fb5aad34e0
|
Merge pull request #9861 from Security-Onion-Solutions/somefixes2
Somefixes2
|
2023-02-27 13:14:08 -05:00 |
|
m0duspwnens
|
44ed48033c
|
move requirement
|
2023-02-27 13:04:23 -05:00 |
|
m0duspwnens
|
068d383442
|
change to service.running
|
2023-02-27 12:44:46 -05:00 |
|
m0duspwnens
|
b4015ac73e
|
add sensor to node_containers
|
2023-02-27 10:05:08 -05:00 |
|
Josh Brower
|
f7176f9989
|
Move Output to ES
|
2023-02-27 09:58:43 -05:00 |
|