m0duspwnens
|
f9b04ab96a
|
add node's own ip to FILEBEAT_EXTRA_HOSTS
|
2021-12-15 16:53:22 -05:00 |
|
m0duspwnens
|
024860d0ae
|
rename EXTRA_NODES to LOGSTASH_NODES AND REDIS_NODES
|
2021-12-14 23:43:06 -05:00 |
|
m0duspwnens
|
c490a3be36
|
move node_data pillar to logstash:nodes, set extra hosts for filebeat docker
|
2021-12-14 13:32:42 -05:00 |
|
m0duspwnens
|
6bf4d5a576
|
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
|
2021-11-12 11:37:55 -05:00 |
|
m0duspwnens
|
283f7296bc
|
fix require
|
2021-10-22 14:45:22 -04:00 |
|
m0duspwnens
|
9f6407fcb0
|
fix dupe ids
|
2021-10-22 14:26:04 -04:00 |
|
m0duspwnens
|
f61400680d
|
fix dupe ids
|
2021-10-22 14:22:15 -04:00 |
|
m0duspwnens
|
fed8bfac67
|
more requires on docker containers
|
2021-10-22 14:10:59 -04:00 |
|
Mike Reeves
|
ea50023ca5
|
Fix filebeat modules
|
2021-06-24 15:53:14 -04:00 |
|
m0duspwnens
|
8cd2bc7c13
|
adding so-eval to ES_INCLUDED_NODES
|
2021-06-17 09:37:21 -04:00 |
|
m0duspwnens
|
2a5198cae4
|
change perms to resolve error about module-setup.yml being 660
|
2021-06-17 08:49:21 -04:00 |
|
Jason Ertel
|
dd8eb29a18
|
Continue merge of ECS into Elastic Auth
|
2021-06-15 09:11:58 -04:00 |
|
m0duspwnens
|
fd5d540c78
|
update roles that include es state
|
2021-06-14 10:00:19 -04:00 |
|
m0duspwnens
|
d2069dc5f2
|
update roles that include es state
|
2021-06-14 09:58:50 -04:00 |
|
m0duspwnens
|
5941332d49
|
fix two bugs
|
2021-06-14 08:51:29 -04:00 |
|
Mike Reeves
|
264080546c
|
Add log path
|
2021-06-09 11:37:27 -04:00 |
|
m0duspwnens
|
b23ce7462e
|
add depenency
|
2021-05-27 11:26:25 -04:00 |
|
m0duspwnens
|
842aa97f7e
|
load filebeat modules when es container starts and if fb container is running
|
2021-05-26 11:00:18 -04:00 |
|
m0duspwnens
|
ecf7e25a51
|
fix merge conflict
|
2021-05-25 17:16:44 -04:00 |
|
m0duspwnens
|
dfaf40f583
|
add zeekloglookup to translate zeeklogs to filebeat filesets
|
2021-05-25 17:14:26 -04:00 |
|
Mike Reeves
|
543154f037
|
Remove old modules
|
2021-05-25 16:58:18 -04:00 |
|
m0duspwnens
|
2aacd5b9b6
|
so defaults filebeat modules
|
2021-05-25 16:40:50 -04:00 |
|
m0duspwnens
|
4012a8276c
|
add template for module .yml file
|
2021-05-11 12:22:25 -04:00 |
|
m0duspwnens
|
efc028d0a5
|
handle the docker port bindings for filebeat modules
|
2021-05-10 18:08:47 -04:00 |
|
Wes Lambert
|
37929dbd7d
|
Add additional config for Filebeat modules
|
2021-05-06 13:54:28 +00:00 |
|
Mike Reeves
|
7153f58a03
|
Add Firewall for Beats port
|
2021-04-13 20:17:26 -04:00 |
|
Mike Reeves
|
621e5c1cf8
|
Enable Filebeat Stats
|
2021-04-13 19:18:10 -04:00 |
|
Mike Reeves
|
1ecb079066
|
Fix Kibana Script for loading dashboards
|
2021-03-08 17:36:07 -05:00 |
|
Mike Reeves
|
a0a8d12526
|
Enable SSL and Features
|
2021-03-04 10:08:28 -05:00 |
|
Mike Reeves
|
4212afe0c9
|
Add features option back
|
2021-01-30 19:57:18 -05:00 |
|
Mike Reeves
|
4ef38f8d04
|
Add EPS and RAID status collection for telegraf
|
2021-01-25 19:14:46 -05:00 |
|
Mike Reeves
|
636687ac59
|
Merge pull request #2702 from Security-Onion-Solutions/essecurity
SSL with Elastic Basic license. Remove features option.
|
2021-01-21 13:57:28 -05:00 |
|
Mike Reeves
|
9408d62c65
|
Remove features
|
2021-01-21 13:55:53 -05:00 |
|
m0duspwnens
|
b693373d8d
|
change how we allow or disallow states to be run https://github.com/Security-Onion-Solutions/securityonion/issues/2679
|
2021-01-20 15:09:53 -05:00 |
|
m0duspwnens
|
1fca5e65df
|
redo how containers get added to so-status https://github.com/Security-Onion-Solutions/securityonion/issues/1681
|
2020-11-10 15:31:47 -05:00 |
|
William Wernert
|
6169758f4e
|
[fix] 0 -> root so file owner is set correctly
|
2020-11-03 16:47:59 -05:00 |
|
m0duspwnens
|
79854f111e
|
add 514 tcp listener to filebeat docker and add syslog listener to fb config for manager and manager search - https://github.com/Security-Onion-Solutions/securityonion/issues/1551
|
2020-10-19 10:27:40 -04:00 |
|
Doug Burks
|
a106913d1a
|
Heavy node filebeat needs extra_hosts for the heavy node itself #1521
|
2020-10-14 09:51:59 -04:00 |
|
Wes Lambert
|
1970d95d5f
|
Make Filebeat registry persistent to avoid re-reading old data
|
2020-10-05 13:30:04 +00:00 |
|
m0duspwnens
|
09cc8ae1fb
|
fail the state if it isnt in top
|
2020-09-09 16:48:50 -04:00 |
|
m0duspwnens
|
a229ae82ce
|
only allow state to run if it is in top for the node
|
2020-09-02 16:15:52 -04:00 |
|
Mike Reeves
|
92cc176b6d
|
Fix features logic in all states that use it
|
2020-08-10 20:59:41 -04:00 |
|
Mike Reeves
|
24ed92c9dc
|
minio and change to global
|
2020-08-04 15:54:03 -04:00 |
|
Wes Lambert
|
958ee25f6d
|
Move Wazuh from /opt/so/ to /nsm/wazuh
|
2020-07-27 11:58:12 +00:00 |
|
Jason Ertel
|
8f66a27f07
|
Refactor image repository to a single variable
|
2020-07-13 18:26:43 -04:00 |
|
m0duspwnens
|
5ca3ecf4bd
|
fix reference to master grain
|
2020-07-09 15:42:39 -04:00 |
|
m0duspwnens
|
3cf31e2460
|
https://github.com/Security-Onion-Solutions/securityonion/issues/404
|
2020-07-09 11:27:06 -04:00 |
|
m0duspwnens
|
fff713db85
|
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/825
|
2020-07-07 15:48:47 -04:00 |
|
Jason Ertel
|
96e93b012d
|
Adjust imports for filebeat configuration to ensure import data is placed into ES
|
2020-07-01 17:18:01 -04:00 |
|
Jason Ertel
|
930f15eea5
|
Introduce so-import-pcap tool - WIP
|
2020-06-30 14:56:08 -04:00 |
|