reyesj2
|
a9457d5f53
|
Remove external community-id replaced with Zeek 6 built in community-id.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2023-10-17 16:02:16 -04:00 |
|
Mike Reeves
|
46fc62b8dc
|
Update init.sls
|
2023-04-12 10:29:54 -04:00 |
|
weslambert
|
2b2d39c869
|
Don't load BZAR script(s) by default
|
2022-12-02 10:46:45 -05:00 |
|
Peter Di Giorgio
|
2e30cefd91
|
Add remaining protocol parsers
- icsnpp-bsap
- icsnpp-s7comm
- zeek-plugin-tds
- zeek-plugin-profinet
- zeek-spicy-wireguard
- zeek-spicy-stun
|
2022-11-17 10:47:00 -06:00 |
|
Peter Di Giorgio
|
13b6b43324
|
Update init.sls
|
2022-11-17 10:42:21 -06:00 |
|
weslambert
|
78bc2a95e5
|
Add icsnpp-bsap to enabled plugins
|
2022-11-17 11:20:24 -05:00 |
|
lock-wire
|
1b8e546045
|
Add s7comm,tds,stun,profinet,wireguard
|
2022-11-16 21:41:02 -06:00 |
|
Peter Di Giorgio
|
d890f75cca
|
Correct typo
|
2022-11-11 13:59:20 -08:00 |
|
lock-wire
|
73b1e5949b
|
Add ecat, enip, cip, and opcua
|
2022-11-11 12:15:54 -08:00 |
|
Peter Di Giorgio
|
1ea6feca37
|
Add icsnpp-bacnet
|
2022-10-27 15:31:38 -07:00 |
|
Peter Di Giorgio
|
61d36d584f
|
Add Modbus, DNP3, BZAR, and oui-logging
|
2022-10-25 07:10:52 -07:00 |
|
Peter Di Giorgio
|
beb67847f9
|
Remove modbus,bzar,dnp3,oui-logging
|
2022-10-24 23:14:32 -07:00 |
|
Peter Di Giorgio
|
01d177366d
|
Fix Zeek Pillar
|
2022-10-24 12:00:43 -07:00 |
|
Peter Di Giorgio
|
4a60310dc8
|
Add Modbus, DNP3, BZAR, and oui-logging
This is an initial proof of concept. Need to migrate these entries behind a flag.
|
2022-10-21 14:04:40 -07:00 |
|
Wes Lambert
|
37929dbd7d
|
Add additional config for Filebeat modules
|
2021-05-06 13:54:28 +00:00 |
|
m0duspwnens
|
f38519247b
|
change capture loss to every 5 minutes and default grafana dashboard to 1h
|
2020-10-08 17:52:02 -04:00 |
|
m0duspwnens
|
fdf5450a2e
|
remove stuff.sls
|
2020-04-28 14:29:44 -04:00 |
|
m0duspwnens
|
8d2ca003fb
|
change how we populate local.zeek - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/585
|
2020-04-28 14:10:57 -04:00 |
|
m0duspwnens
|
b6741daca6
|
pillarize local.zeek and move zeekctl from defaults.yml to zeek pillar - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/585
|
2020-04-28 09:44:37 -04:00 |
|