Corey Ogburn
|
ba601c39b3
|
Rough Go at New Mappings/Settings
|
2025-09-08 09:13:21 -06:00 |
|
reyesj2
|
dfec29d18e
|
custom kquery
|
2025-09-04 15:37:28 -05:00 |
|
reyesj2
|
1a32a0897c
|
Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/ea-alerter
|
2025-09-02 17:11:21 -05:00 |
|
reyesj2
|
e26310d172
|
elastic agent offline alerter
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-09-02 17:00:03 -05:00 |
|
reyesj2
|
a5675a79fe
|
es 8.18.6 pipeline upd
|
2025-08-28 19:45:17 -05:00 |
|
reyesj2
|
1ea7b3c09f
|
es 8.18.6
|
2025-08-28 18:27:56 -05:00 |
|
Jorge Reyes
|
cdb7f0602c
|
Merge pull request #14889 from Security-Onion-Solutions/reyesj2-es-helper
only show data nodes in disk usage output
|
2025-07-29 14:45:30 -05:00 |
|
reyesj2
|
07305d8799
|
only show data nodes in disk usage output
|
2025-07-29 14:15:43 -05:00 |
|
reyesj2
|
fbf5bafae7
|
set 2m timeout
|
2025-07-28 15:17:04 -05:00 |
|
reyesj2
|
d49cd3cb85
|
increased timeout for so-elasticsearch-roles-load from default of 30s
|
2025-07-28 15:14:12 -05:00 |
|
reyesj2
|
84b38daf62
|
name destination_geo & source_geo to destination.as and source.as better aligning with ECS and linking other log sources already using .as for ASN geo data.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-07-25 16:17:22 -05:00 |
|
reyesj2
|
3fc244ee85
|
8.18.4
|
2025-07-22 16:56:51 -05:00 |
|
Jorge Reyes
|
47831eb300
|
Merge pull request #14856 from Security-Onion-Solutions/reyesj2-es-ts
elasticsearch troubleshoot script
|
2025-07-17 15:56:40 -05:00 |
|
reyesj2
|
0b1f2252ee
|
elasticsearch troubleshoot script
|
2025-07-17 13:27:54 -05:00 |
|
reyesj2
|
c29f11863e
|
ja4 ignore empty strings
|
2025-07-17 10:47:00 -05:00 |
|
reyesj2
|
b3eb06f53e
|
ja4
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-07-16 15:56:34 -05:00 |
|
reyesj2
|
317d7dea7d
|
check required files exist before loading map file
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-07-09 17:25:36 -05:00 |
|
reyesj2
|
b9d813cef2
|
typo
|
2025-07-08 18:26:46 -05:00 |
|
reyesj2
|
bef2fa9e8d
|
8.18.3 pipeline updates
|
2025-07-08 16:09:16 -05:00 |
|
reyesj2
|
d4f0cbcb67
|
changes for 'generic' integrations with no compoent templates assigned. Default to using the logs-filestream.generic@package componet template
|
2025-07-08 15:23:46 -05:00 |
|
reyesj2
|
d8be6e42e1
|
es 8.18.3
|
2025-07-07 12:58:00 -05:00 |
|
Josh Patterson
|
0602601655
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-06-20 16:25:16 -04:00 |
|
Josh Brower
|
31cd5b1365
|
Add support for dns.resolved_ip
|
2025-06-20 15:02:59 -04:00 |
|
Josh Patterson
|
2ef89be67d
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-06-05 09:40:44 -04:00 |
|
Jorge Reyes
|
d9790b04f6
|
Merge pull request #14676 from Security-Onion-Solutions/reyesj2/fixsystemtime
fix system integration time overwrite and delete unused ingest pipeline
|
2025-06-03 14:01:42 -05:00 |
|
reyesj2
|
d240fca721
|
remove usage of temp file
|
2025-06-03 08:45:04 -05:00 |
|
reyesj2
|
4d6171bde6
|
rename script
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-06-03 07:32:12 -05:00 |
|
reyesj2
|
6238a5b3ed
|
tighten up search timeframe
|
2025-06-02 16:31:26 -05:00 |
|
reyesj2
|
061600fa7a
|
shebang line
|
2025-06-02 15:55:46 -05:00 |
|
reyesj2
|
1b89cc6818
|
so-elasticsearch-index-growth script
|
2025-06-02 15:41:03 -05:00 |
|
Josh Patterson
|
6e1e617124
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-06-02 14:06:00 -04:00 |
|
Doug Burks
|
bf38055a6c
|
add echo to end of so-elasticsearch-ilm-stop
|
2025-05-30 11:41:50 -04:00 |
|
Doug Burks
|
90b8d6b2f7
|
add echo to end of so-elasticsearch-ilm-start
|
2025-05-30 11:41:11 -04:00 |
|
Doug Burks
|
45d541d4f2
|
FIX: so-elasticsearch-ilm-start needs shebang #14688
|
2025-05-30 09:55:53 -04:00 |
|
Josh Patterson
|
b3c48674c5
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-05-30 09:52:14 -04:00 |
|
Doug Burks
|
58936b31d5
|
FIX: Improve annotation for Elasticsearch index deletion #14682
|
2025-05-29 15:19:21 -04:00 |
|
reyesj2
|
fcdacc3b0d
|
fix system integration time overwrite and delete unused ingest pipeline
|
2025-05-29 12:21:28 -05:00 |
|
Jorge Reyes
|
d3ee5ed7b8
|
use zeek network.community_id when available
|
2025-05-28 09:20:41 -05:00 |
|
Josh Patterson
|
b2650da057
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-05-22 09:10:20 -04:00 |
|
Josh Brower
|
b753d40861
|
Tighten parsing
|
2025-05-20 17:06:11 -04:00 |
|
Josh Brower
|
b55cb257b6
|
Add parsing for Playbook
|
2025-05-19 13:25:27 -04:00 |
|
Josh Patterson
|
b0a8191f59
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-05-19 10:02:26 -04:00 |
|
Josh Brower
|
df103b3dca
|
Spacing
|
2025-05-14 16:36:59 -04:00 |
|
Josh Brower
|
0542c77137
|
Remove wip config
|
2025-05-14 16:35:09 -04:00 |
|
Josh Brower
|
9022dc24fb
|
Add Parsing for Playbooks
|
2025-05-14 13:19:50 -06:00 |
|
reyesj2
|
e1d31c895e
|
add null check
|
2025-05-07 21:25:30 -05:00 |
|
Josh Patterson
|
8c37a4454c
|
merge and fix conflicts
|
2025-05-06 11:55:42 -04:00 |
|
Mike Reeves
|
92d8985f3c
|
enable the delete on heavynodes
|
2025-05-02 08:52:57 -04:00 |
|
Josh Patterson
|
ed80c4e13b
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-04-23 15:42:04 -04:00 |
|
Josh Patterson
|
272410ecae
|
Merge pull request #14568 from Security-Onion-Solutions/fixem
Fixem
|
2025-04-23 13:28:29 -04:00 |
|