reyesj2
|
4618256442
|
include okta-mappings in so-logs-okta.system index template
|
2025-01-13 11:32:27 -06:00 |
|
reyesj2
|
323ef1d5d6
|
add missing lifecycle name to trend_micro_vision_one indices
|
2025-01-13 09:29:22 -06:00 |
|
reyesj2
|
a5b1648b68
|
add missing lifecycle name to crowdstrike indices
|
2025-01-13 09:26:16 -06:00 |
|
reyesj2
|
4f92b7ced1
|
add support for cloudflare_logpush integration
|
2025-01-13 09:23:05 -06:00 |
|
reyesj2
|
157185c370
|
add ti_opencti integration support
|
2024-12-18 11:33:49 -06:00 |
|
reyesj2
|
993d56cb58
|
ti_rapid7*
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-25 15:51:49 -06:00 |
|
reyesj2
|
efa6a533c3
|
add missing ilm to index template
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-25 15:47:47 -06:00 |
|
reyesj2
|
44ec237447
|
additional integration support - cisco secure email gateway - rapid7 threat command
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-15 11:39:01 -06:00 |
|
Jorge Reyes
|
4e0b5569dc
|
Merge pull request #13933 from Security-Onion-Solutions/ilm-detection
add ilm and update managed index settings
|
2024-11-12 15:22:05 -06:00 |
|
reyesj2
|
6dbe0645e5
|
use auto_expand_replica, configure ilm for so-case* & so-detection*
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-11 13:51:48 -06:00 |
|
Jason Ertel
|
57a9992a3d
|
Merge branch '2.4/dev' into jertel/wip
|
2024-11-11 10:06:44 -05:00 |
|
reyesj2
|
80b82b0bd6
|
missing replica 0
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-06 15:24:13 -06:00 |
|
reyesj2
|
039d5c22ac
|
fix: crowdstrike integration
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-06 14:35:41 -06:00 |
|
reyesj2
|
36fc3bbd6d
|
add so-ip-mappings index
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-10-30 10:24:11 -04:00 |
|
Jorge Reyes
|
cf95af66c6
|
Revert "Add support for cybereason integration"
|
2024-10-21 15:23:05 -04:00 |
|
reyesj2
|
8b11019712
|
Add support for cybereason integration
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-10-18 11:56:47 -04:00 |
|
reyesj2
|
322199358d
|
add support for trendmicro integration
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-10-16 16:45:46 -04:00 |
|
Jason Ertel
|
523ff66389
|
connect work
|
2024-10-16 13:44:01 -04:00 |
|
Wes
|
f2bb54d993
|
Add barracuda and imperva integrations
|
2024-09-11 19:41:38 +00:00 |
|
Josh Patterson
|
71f6b44c0c
|
Merge pull request #13607 from Security-Onion-Solutions/esver
use Elasticsearch version for some containers
|
2024-09-04 13:30:07 -04:00 |
|
weslambert
|
a7de6993f9
|
Add so-system-mappings
|
2024-08-30 16:11:41 -04:00 |
|
m0duspwnens
|
3d61897522
|
ref es version from defaults for kibana
|
2024-08-21 08:51:35 -04:00 |
|
weslambert
|
61ab1f1ef2
|
Add tenable_io templates
|
2024-08-15 23:03:07 -04:00 |
|
weslambert
|
49d2ac2b13
|
Change name for system component
|
2024-07-31 16:17:57 -04:00 |
|
Wes
|
fb2a42a9af
|
Use custom system component
|
2024-07-31 17:02:45 +00:00 |
|
weslambert
|
0453f51e64
|
Actually ignore missing templates
|
2024-07-30 12:54:07 -04:00 |
|
Corey Ogburn
|
20f915f649
|
so-detection refresh_interval => 1s
Speeds up the refresh_interval so bulk indexing a single rule does not wait 30s.
|
2024-07-25 12:53:04 -06:00 |
|
weslambert
|
fe1824aedd
|
Revert "Elastic 8.14.2"
|
2024-07-15 11:28:59 -04:00 |
|
weslambert
|
8615e5d5ea
|
Move enabled and index_clean back to the top
|
2024-07-08 16:50:06 -04:00 |
|
weslambert
|
745b6775f1
|
Change name for ILM
|
2024-07-02 09:05:35 -04:00 |
|
Wes
|
32d7927a49
|
Template changes for Elastic 8.14.1
|
2024-07-01 15:16:06 +00:00 |
|
Wes
|
f396247838
|
Add index templates and lifecycle policies
|
2024-05-31 17:46:19 +00:00 |
|
Wes
|
55c5ea5c4c
|
Add template for Suricata alerts
|
2024-05-30 16:58:56 +00:00 |
|
weslambert
|
c8870eae65
|
Add detection alerts template
|
2024-05-13 14:23:47 -04:00 |
|
weslambert
|
6294f751ee
|
Cold min_age to 60d
|
2024-05-01 10:59:41 -04:00 |
|
m0duspwnens
|
c9d9979f22
|
allow for enabled/disable of so-elasticsearch-indices-delete cronjob
|
2024-04-24 16:18:45 -04:00 |
|
reyesj2
|
55cf90f477
|
merge 2.4/dev
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-11 14:44:59 -04:00 |
|
reyesj2
|
4097e1d81a
|
Create mappings for Kismet integration
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-04-10 16:10:27 -04:00 |
|
Wes
|
105eadf111
|
Add cef
|
2024-04-03 14:40:41 +00:00 |
|
reyesj2
|
000d15a53c
|
Kismet integration: TODO Elasticsearch mappings
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-03-29 13:56:01 -04:00 |
|
Wes
|
c6df805556
|
Add SOC template
|
2024-03-18 14:53:36 +00:00 |
|
weslambert
|
d8e8933ea0
|
Add AWS Security Hub template
|
2024-03-05 09:25:41 -05:00 |
|
weslambert
|
d85ac39e28
|
Add AWS Inspector template
|
2024-03-05 09:23:17 -05:00 |
|
weslambert
|
1514f1291e
|
Add AWS GuardDuty template
|
2024-03-05 09:21:48 -05:00 |
|
weslambert
|
b64d61065a
|
Add AWS Cloudfront template
|
2024-03-05 09:19:43 -05:00 |
|
weslambert
|
df3943b465
|
Daily rollover
|
2024-02-27 17:24:27 -05:00 |
|
weslambert
|
1d099f97d2
|
Update pattern for endpoint diagnostic template
|
2024-02-26 11:27:56 -05:00 |
|
Josh Brower
|
686304f24a
|
Merge remote-tracking branch 'origin/2.4/dev' into kilo
|
2024-02-15 09:47:51 -05:00 |
|
Wes
|
182667bafb
|
Change numbers for Elasticsearch
|
2024-02-01 13:59:23 +00:00 |
|
Wes
|
cd4bd6460a
|
Custom pipelines
|
2024-01-31 20:16:18 +00:00 |
|