Wes
|
bb6fc8da19
|
Add policy templates for other logs
|
2023-02-09 15:51:58 +00:00 |
|
weslambert
|
364799dcc5
|
Merge pull request #9751 from Security-Onion-Solutions/fix/elastic_fleet_output_temp_change
Temporarily use Elasticsearch output for standalone installations
|
2023-02-09 09:37:14 -05:00 |
|
weslambert
|
b744dc0641
|
Add so-eval to list of modes using the Elasticsearch output for Elastic Agent and Fleet
|
2023-02-09 09:35:29 -05:00 |
|
weslambert
|
613793ad9b
|
Temporarily use Elasticsearch output for Standalone installations
|
2023-02-09 09:32:04 -05:00 |
|
Josh Patterson
|
131d9b5898
|
Merge pull request #9747 from Security-Onion-Solutions/2.4/firewall
ensure node_data is populated with self
|
2023-02-08 17:29:07 -05:00 |
|
m0duspwnens
|
8a00521092
|
ensure node_data is populated with self if logstash:nodes data doesnt exist, ie import node
|
2023-02-08 17:19:20 -05:00 |
|
weslambert
|
32823ef640
|
Merge pull request #9746 from Security-Onion-Solutions/feature/elasticsearch_ilm_utility_scripts
Add Elasticsearch ILM utility scripts
|
2023-02-08 16:43:44 -05:00 |
|
Wes
|
b319b50fa1
|
Add initial ILM status script
|
2023-02-08 21:39:33 +00:00 |
|
Wes
|
1d6c03feb1
|
Rename initial ILM lifecycle status explanation script
|
2023-02-08 21:34:39 +00:00 |
|
Wes
|
91d24d36f9
|
Add initial ILM lifecycle status explanation script
|
2023-02-08 21:34:15 +00:00 |
|
Wes
|
3e31bda285
|
Fix typo in Elasticsearch portion of script names
|
2023-02-08 21:32:17 +00:00 |
|
Wes
|
1de3871ee9
|
Add initial ILM service restart script
|
2023-02-08 21:30:25 +00:00 |
|
Wes
|
03849b0659
|
Add initial ILM service start script
|
2023-02-08 21:29:38 +00:00 |
|
Wes
|
b38f4ca766
|
Add initial ILM service stop script
|
2023-02-08 21:29:16 +00:00 |
|
Wes
|
8027055086
|
Add initial ILM policy delete script
|
2023-02-08 21:09:42 +00:00 |
|
Wes
|
d6d01f8542
|
Add initial ILM policy view script
|
2023-02-08 21:01:02 +00:00 |
|
Wes
|
713e9ee215
|
Create initial template for ILM policy load script
|
2023-02-08 20:10:41 +00:00 |
|
Josh Patterson
|
3b9bdecab8
|
Merge pull request #9745 from Security-Onion-Solutions/2.4/firewall
2.4/firewall
|
2023-02-08 13:26:40 -05:00 |
|
m0duspwnens
|
3d34a49e44
|
change to new local ports file
|
2023-02-08 13:21:48 -05:00 |
|
m0duspwnens
|
19f49dde75
|
recusivly copy the firewall files for setup
|
2023-02-08 13:14:08 -05:00 |
|
Josh Patterson
|
d6fb0598df
|
Merge pull request #9743 from Security-Onion-Solutions/2.4/firewall
2.4/firewall
|
2023-02-08 11:37:05 -05:00 |
|
m0duspwnens
|
31daeef30d
|
2.4 fw changes
|
2023-02-08 11:01:26 -05:00 |
|
m0duspwnens
|
342b9619b0
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-02-08 09:18:21 -05:00 |
|
m0duspwnens
|
fb7ebcac7e
|
2.4 fw changes
|
2023-02-08 09:18:05 -05:00 |
|
Doug Burks
|
291bdc0d82
|
Merge pull request #9726 from Security-Onion-Solutions/2.4/change-radio-to-menu
FIX: Minimize keystrokes and errors in Setup by changing radio lists to menus where appropriate #9725
|
2023-02-06 12:11:21 -05:00 |
|
Doug Burks
|
cd38ecb300
|
change whiptail selections from radiolist to menu where appropriate
|
2023-02-06 11:52:42 -05:00 |
|
Josh Patterson
|
22a18d8855
|
Merge pull request #9717 from Security-Onion-Solutions/2.4/firewall
2.4/firewall
|
2023-02-03 11:04:36 -05:00 |
|
m0duspwnens
|
e8a1e164aa
|
add so.version module
|
2023-02-03 10:58:08 -05:00 |
|
m0duspwnens
|
e0e094cd95
|
rename sosbip and sosrange to sobip and sorange
|
2023-02-03 10:10:51 -05:00 |
|
m0duspwnens
|
a37f0fd0c0
|
rename sosbridge to sobridge
|
2023-02-03 10:07:07 -05:00 |
|
m0duspwnens
|
6e45f1b6e1
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-02-03 09:55:50 -05:00 |
|
m0duspwnens
|
df9ef9ffc7
|
add managersearch
|
2023-02-03 09:55:33 -05:00 |
|
weslambert
|
bee5a1e9e8
|
Merge pull request #9711 from Security-Onion-Solutions/fix/so_import_pcap_suricata_metadata_disable_zeek
Only run Zeek if it is defined as the metadata engine
|
2023-02-02 13:27:35 -05:00 |
|
m0duspwnens
|
3e808a70fa
|
allow managersearch. comment out localhost allow in setup
|
2023-02-02 12:11:03 -05:00 |
|
Wes
|
bc082dff99
|
Only run Zeek if it is defined as 'mdengine'
|
2023-02-02 16:22:42 +00:00 |
|
m0duspwnens
|
33787d345b
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-02-02 10:04:01 -05:00 |
|
m0duspwnens
|
9eae31e488
|
add managersearch to allowed roles for so-firewall. fix setup error from so-firewall "Please specify a role with --role="
|
2023-02-02 10:03:22 -05:00 |
|
weslambert
|
395cbf330a
|
Merge pull request #9706 from Security-Onion-Solutions/fix/suricata_metadata
Add Suricata metadata configuration
|
2023-02-02 09:54:49 -05:00 |
|
Wes
|
5fba3c5872
|
Add Suricata metadata configuration
|
2023-02-02 14:48:01 +00:00 |
|
m0duspwnens
|
3ba64f7545
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-02-02 09:31:40 -05:00 |
|
weslambert
|
eb7b6e78b9
|
Merge pull request #9702 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_disable
Disable loading of Kibana and Logstash integration policies
|
2023-02-01 16:02:56 -05:00 |
|
weslambert
|
d242050627
|
Disable loading of Kibana and Logstash logs for now since there are issues with the packages from the registry
|
2023-02-01 15:59:35 -05:00 |
|
weslambert
|
3dfa7959b3
|
Merge pull request #9698 from Security-Onion-Solutions/fix/strelka_yara_exclusion_2_4
Add 'configured_vulns_ext_vars.yar' to exclusion list
|
2023-02-01 14:38:38 -05:00 |
|
weslambert
|
2101ca60e9
|
Add 'configured_vulns_ext_vars.yar' to exclusion list
|
2023-02-01 14:25:46 -05:00 |
|
m0duspwnens
|
33668105a5
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-02-01 11:32:02 -05:00 |
|
m0duspwnens
|
d2dd68eb44
|
add global vars for managersearch
|
2023-02-01 11:31:36 -05:00 |
|
Josh Patterson
|
77749adc8f
|
Merge pull request #9691 from Security-Onion-Solutions/2.4/firewall
2.4/firewall
|
2023-01-31 17:11:57 -05:00 |
|
m0duspwnens
|
6ec086e24a
|
add influxdb as extra_hosts for grafana container
|
2023-01-31 17:10:11 -05:00 |
|
m0duspwnens
|
6f1438148f
|
allow elastic agent access
|
2023-01-31 16:54:46 -05:00 |
|
m0duspwnens
|
12bede5e77
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-01-31 16:10:50 -05:00 |
|