Wes Lambert
3b50ce032a
Add fields for exiftool keys
2020-07-07 20:02:09 +00:00
Josh Patterson
07cc89e4d6
Merge pull request #943 from Security-Onion-Solutions/issue/825
...
Pillarize filebeat inputs and output
2020-07-07 15:51:08 -04:00
m0duspwnens
fff713db85
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/825
2020-07-07 15:48:47 -04:00
Mike Reeves
eccfaf94fb
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/937
2020-07-07 15:10:12 -04:00
Jason Ertel
f4f189cc50
correct capitalization of true
2020-07-07 14:28:11 -04:00
William Wernert
640cfee3e1
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-07 13:13:28 -04:00
William Wernert
3815f7e58e
[refactor] Edit logic around setup failure/completion
...
* Always run `install_cleanup` and `so-allow`
* Change if statement to check whether `$success != 0` or if `$SO_ERROR` was set
* Set `$IP` only for `so-allow` instead of exporting it
2020-07-07 13:12:46 -04:00
William Wernert
1d47cec928
[refactor] Move install_cleanup outside of whiptail functions
2020-07-07 13:02:58 -04:00
William Wernert
0b995533ea
[refactor] Only notify user of error found during setup
2020-07-07 13:01:29 -04:00
Mike Reeves
ec89ab39ac
Update 9999_output_redis.conf.jinja
2020-07-07 11:56:45 -04:00
weslambert
34e06ecde1
Merge pull request #940 from Security-Onion-Solutions/feature/strelka_fuid
...
Add Zeek FUID for Strelka records
2020-07-07 11:01:09 -04:00
Wes Lambert
e0570e1db7
Add Zeek FUID for Strelka records
2020-07-07 15:00:01 +00:00
Mike Reeves
c59096d9bd
rename node pillar to elasticsearch
2020-07-07 10:42:12 -04:00
Jason Ertel
62cc02301e
Do not attempt to install a plugin or bc command if already exists
2020-07-07 10:28:15 -04:00
weslambert
d334d5ab83
Merge pull request #938 from Security-Onion-Solutions/fix/strelka_filebeat
...
Fix pillar reference for Strelka/FB
2020-07-07 09:48:19 -04:00
Wes Lambert
2fdd5fd77b
Fix pillar reference for Strelka/FB
2020-07-07 13:46:57 +00:00
William Wernert
e2c9184b29
[fix][refactor] Don't use relative path in so-setup-network
2020-07-07 08:45:28 -04:00
Mike Reeves
291ac3c597
Fix SSL Perms
2020-07-06 17:24:04 -04:00
Mike Reeves
be5f4b04c6
Fix SSL Perms
2020-07-06 17:21:23 -04:00
Mike Reeves
cc6d0c1cb5
Merge pull request #935 from Security-Onion-Solutions/issue/929
...
Change grafana to use anon auth
2020-07-06 16:45:19 -04:00
Mike Reeves
3b452ab597
Change grafana to use anon auth
2020-07-06 16:39:43 -04:00
Mike Reeves
cc2f023840
Merge pull request #934 from Security-Onion-Solutions/issue/142
...
Issue/142
2020-07-06 16:12:48 -04:00
Mike Reeves
f05e366d49
Fix salt upgrade script
2020-07-06 15:56:55 -04:00
Mike Reeves
be3390a796
Fix Logstash state
2020-07-06 15:53:21 -04:00
Josh Patterson
da0a0ae6ae
Merge pull request #933 from Security-Onion-Solutions/quickfix/firewall
...
add elasticsearch_rest to assigned hostgroups where missing
2020-07-06 15:20:00 -04:00
m0duspwnens
b4e556496b
add elasticsearch_rest to assigned hostgroups where missing
2020-07-06 15:18:47 -04:00
Mike Reeves
623c37f1f5
Merge remote-tracking branch 'remotes/origin/dev' into issue/142
2020-07-06 14:35:46 -04:00
Mike Reeves
1016315196
Change Logic for logstash
2020-07-06 13:58:38 -04:00
Mike Reeves
087080d583
Add logix for logstash_settings
2020-07-06 13:16:40 -04:00
William Wernert
57bbb02c65
[refactor][fix] Move nmcli status list gen to a function
...
nmcli is only assured to be installed after detect_os is run so move this command to a function so it can run after detect_os
2020-07-02 17:18:56 -04:00
William Wernert
99d490bc06
[fix][refactor] Move detect_ec2 and add echo statement
2020-07-02 17:15:46 -04:00
bryant-treacle
cfeb95a718
Merge pull request #924 from Security-Onion-Solutions/feature/so-container-scripts
...
Additional so-container scripts Issue # 701
2020-07-02 14:42:49 -04:00
William Wernert
b9a176201f
Merge pull request #913 from Security-Onion-Solutions/feature/setup-changes
...
Feature/setup changes
2020-07-02 14:01:46 -04:00
William Wernert
d2ba25e784
Merge branch 'dev' into feature/setup-changes
...
# Conflicts:
# setup/so-setup
2020-07-02 14:00:10 -04:00
weslambert
0bfa3d486e
Merge pull request #923 from Security-Onion-Solutions/fix/es-allow
...
Fix my typo
2020-07-02 13:32:45 -04:00
weslambert
bbc752b6d9
Fix my typo
2020-07-02 13:32:19 -04:00
Josh Brower
518c8db3de
Merge pull request #922 from Security-Onion-Solutions/feature/low-level-alerts
...
Initial commit - Low Level Alerts
2020-07-02 12:18:03 -04:00
Josh Brower
69ace6fbfa
Initial commit - Low Level Alerts
2020-07-02 12:16:56 -04:00
Jason Ertel
cf6a229f51
Import now requires execution on a sensor node due to the need for zeek and suricata; Automatically stop curator if curator is installed
2020-07-02 12:07:30 -04:00
William Wernert
c7a3cc9c17
[fix][revert] Change source in so-allow to correct path
2020-07-02 08:58:14 -04:00
Jason Ertel
4cedacf8fd
Improve curator verbiage in so-import-pcap
2020-07-02 06:01:17 -04:00
Josh Brower
07d13b7ad0
Merge pull request #916 from Security-Onion-Solutions/defensivedepth-patch-1
...
Delete playbook_db_init.sql.backup
2020-07-02 05:32:45 -04:00
Josh Brower
7811ea5d4c
Delete playbook_db_init.sql.backup
2020-07-02 05:32:35 -04:00
Josh Brower
0f915ec85e
Merge pull request #915 from Security-Onion-Solutions/feature/playbook-updates
...
Feature/playbook updates
2020-07-02 05:31:30 -04:00
Josh Brower
3c93f9fd45
Playbook setup fix
2020-07-02 05:30:30 -04:00
bryant-treacle
0b10b775c5
Additional so-container scripts
2020-07-02 07:02:35 +00:00
Jason Ertel
ac01b8de4b
Stop curator when directed on PCAP imports
2020-07-01 22:04:07 -04:00
Doug Burks
98cfba18e9
fix zeek.ftp description
2020-07-01 20:27:40 -04:00
Doug Burks
f6adf4ed56
fix zeek.smb_mapping description
2020-07-01 20:26:51 -04:00
Doug Burks
2cbd5ffe61
fix zeek.ssh description
2020-07-01 20:26:06 -04:00