Jason Ertel
8f9081618f
Add role to sensoroni.json file
2020-11-25 11:11:46 -05:00
Jason Ertel
7fb264b4fe
Use double quotes around agent key to ensure interpolation
2020-11-24 17:17:50 -05:00
Jason Ertel
d20560385f
Remove /nsm/wazuh/etc subdir state since confirmed the Wazuh docker container itself
2020-11-24 16:50:46 -05:00
Jason Ertel
e1147398cc
Ensure /nsm/wazuh is owned by ossec
2020-11-24 15:48:46 -05:00
Jason Ertel
8864428a00
Ensure setup output is redirected to logfile
2020-11-24 15:45:40 -05:00
Jason Ertel
ea9bbfd1aa
Improve wazuh agent registration with retry logic to wait for manager to become ready
2020-11-24 13:53:20 -05:00
weslambert
0c4ee94472
Merge pull request #2077 from Security-Onion-Solutions/fix/thehive_upgrade_conf
...
Fix/thehive upgrade conf
2020-11-24 11:52:51 -05:00
weslambert
39bf60feb7
Add digit
2020-11-24 11:52:20 -05:00
weslambert
35653d2e66
Changes for ES7
2020-11-24 11:51:19 -05:00
weslambert
eb2364b926
Changes for ES7
2020-11-24 11:49:08 -05:00
Josh Patterson
9bb485cdc9
Merge pull request #2074 from Security-Onion-Solutions/issue/2040
...
Issue/2040
2020-11-24 11:45:08 -05:00
m0duspwnens
fe2662cab8
dont enable steno pillar on import node https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 11:42:03 -05:00
m0duspwnens
995a377432
squigly comma if steno enabled https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 11:31:41 -05:00
weslambert
e3a41c2a94
Changes for ES7 elasticsearch.yml
2020-11-24 11:20:09 -05:00
Mike Reeves
ddca9563e5
Merge branch 'mkrmerge' into escluster
2020-11-24 10:29:57 -05:00
OmerTirosh
e2ee0db727
Ignore failure for rename processor
...
Ignore failure for winlog.event_data.SubjectUserName rename processor.
For some event ids (for example 4688), this field already been added in winlogbeat JS processor.
Therefor, elastic throw [user.name] already exists error.
2020-11-24 17:21:47 +02:00
m0duspwnens
4dfd49ef39
add vars https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 10:11:28 -05:00
m0duspwnens
65334d15ea
https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 09:33:38 -05:00
Jason Ertel
1e32a01657
Create symlink before registration otherwise registration script can't save it's state (.log) file into the conf subdir; add more logging output to track down registration failures
2020-11-23 18:36:19 -05:00
Jason Ertel
bafefb980b
Update so-elastalert-test script for compatibility with SO 2.3
2020-11-23 10:45:56 -05:00
Mike Reeves
426769588a
Merge pull request #1739 from jtgreen-cse/patch-2
...
fix for Windows events via osquery
2020-11-21 13:27:05 -05:00
Josh Patterson
a183be489c
Merge pull request #2030 from Security-Onion-Solutions/master
...
Merge master to dev
2020-11-20 17:00:31 -05:00
Josh Patterson
b29ffcac92
Merge pull request #2029 from Security-Onion-Solutions/soup-ubuntu-salt
...
fix issue with proper salt.minion state execution for ubuntu
2020-11-20 16:55:45 -05:00
Jason Ertel
78f5727f6f
Improve so-ip-update prompts
2020-11-20 15:16:07 -05:00
m0duspwnens
0d3754200f
fix issue with proper salt.minion state execution for ubuntu
2020-11-20 14:27:07 -05:00
Jason Ertel
bc40a2bfc5
Correct so-import-pcap wrapping; add so-pcap-import alias for so-import-pcap; prompt to reboot after changing IP address on manager; ensure all tools have exec bit set
2020-11-20 14:14:03 -05:00
Jason Ertel
f074179656
Correct so-import-pcap wrapping; add so-pcap-import alias for so-import-pcap; prompt to reboot after changing IP address on manager; ensure all tools have exec bit set
2020-11-20 14:14:03 -05:00
William Wernert
b6e36d4d06
Merge pull request #2023 from Security-Onion-Solutions/bugfix/bug-hunt
...
Bugfix/bug hunt
2020-11-20 13:04:33 -05:00
William Wernert
2e6be747d9
[fix] Fixes for quiet flag in so-ssh-harden
2020-11-20 11:18:40 -05:00
William Wernert
1a11c24f03
[fix] Add newline escapes to so-ssh-harden
2020-11-20 11:13:40 -05:00
William Wernert
d15064b294
Merge branch 'dev' into bugfix/bug-hunt
2020-11-20 10:15:52 -05:00
William Wernert
d3ef46a5f6
Merge pull request #2020 from Security-Onion-Solutions/bugfix/pre-whiptail-message
...
[fix] Remove echo redirect at beginning of install
2020-11-20 10:15:24 -05:00
William Wernert
9d837f7b45
[fix] Reload sshd if config changes are made
...
Fixes #1976
2020-11-20 10:09:14 -05:00
William Wernert
e62b52da1b
[fix] Add condition to zeek state during setup for ZEEKVERSION
...
Fixes #1990
2020-11-20 09:58:07 -05:00
William Wernert
79ec1de83a
[fix] Add exit check for static ip whiptail menus
...
Fixes #1992
2020-11-20 09:56:48 -05:00
Jason Ertel
9fb8a6d482
Increment version to 2.3.20
2020-11-19 16:53:34 -05:00
Mike Reeves
5344d30d56
Merge pull request #2003 from Security-Onion-Solutions/dev
...
2.3.10
2.3.10
2020-11-19 16:48:53 -05:00
Mike Reeves
4051111999
Update hashes and keys
2020-11-19 16:00:40 -05:00
Mike Reeves
316a1c02f1
Update soup to display what its doing
2020-11-19 15:19:50 -05:00
Josh Patterson
c07f62f8d1
Merge pull request #2007 from Security-Onion-Solutions/fix/minon
...
kill salt process with soup and dont restart salt-minion service when…
2020-11-19 15:17:58 -05:00
m0duspwnens
cdc7a5cc7c
kill salt process with soup and dont restart salt-minion service when salt upgrade
2020-11-19 15:17:11 -05:00
Josh Patterson
10a3e6f414
Merge pull request #2006 from Security-Onion-Solutions/fix/minon
...
change typo on minon to minion
2020-11-19 15:11:16 -05:00
m0duspwnens
2a3951ab36
change typo on minon to minion
2020-11-19 15:08:08 -05:00
Mike Reeves
67a8c4e8cb
Update Readme
2020-11-19 11:27:15 -05:00
Mike Reeves
177819447b
Update Sigs and Hashes
2020-11-19 11:26:08 -05:00
Mike Reeves
3be1c9ae32
Clean up 2.3.1 dockers
2020-11-19 09:58:08 -05:00
William Wernert
ac3b5e4f1b
[fix] Remove echo redirect at beginning of install
2020-11-19 09:48:56 -05:00
Josh Brower
b79e1c3225
Merge pull request #1987 from Security-Onion-Solutions/bugfix/playbookdb-user
...
playbook mysqluser
2020-11-18 20:48:49 -05:00
Josh Brower
d3065005ca
playbook mysqluser
2020-11-18 20:48:02 -05:00
Josh Patterson
26e97d5875
Merge pull request #1984 from Security-Onion-Solutions/salt/3002.2
...
upgrade from salt 3002.1 to salt 3002.2
2020-11-18 18:26:11 -05:00