reyesj2
|
58df566c79
|
add mapping for metadata.kafka.timestamp
|
2025-04-14 14:30:40 -05:00 |
|
Josh Brower
|
4c3518385b
|
Change timeout to 1s
|
2025-04-11 07:37:09 -04:00 |
|
reyesj2
|
4dd72ad15c
|
fix osquery action_data mapping conflict
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-07 17:05:13 -06:00 |
|
reyesj2
|
d2884ef00b
|
typo
|
2025-03-05 14:02:45 -06:00 |
|
reyesj2
|
0f16b00563
|
osquery templates
|
2025-03-05 13:57:47 -06:00 |
|
reyesj2
|
11dc004811
|
ES 8.17.3
|
2025-03-04 14:24:38 -06:00 |
|
reyesj2
|
124bf266b5
|
osquery v1.15.0 index templates updates
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-04 12:27:04 -06:00 |
|
reyesj2
|
df350b5a56
|
ES 8.17.2
|
2025-02-20 14:20:09 -06:00 |
|
reyesj2
|
3b6344e7f0
|
add back settings previously defined when overwritting logs-elastic_agent@package and logs-endpoint.diagnostics.collection@package
|
2025-02-20 12:42:30 -06:00 |
|
Jorge Reyes
|
a3dba9b566
|
Merge pull request #14255 from Security-Onion-Solutions/foxtrot
ES 8.17.1
|
2025-02-18 14:58:46 -06:00 |
|
reyesj2
|
235a8e3934
|
update index templates for endpoint integration
|
2025-02-17 18:30:51 -06:00 |
|
reyesj2
|
40cb3a53ae
|
Revert ES 8.17.2 upgrade -> 8.17.1
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-02-12 13:18:08 -06:00 |
|
reyesj2
|
fb0cd436d3
|
ES 8.17.2 TODO: Check import-evtx-logs.json for updated pipeline versions
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-02-11 11:23:04 -06:00 |
|
Joshua Brower
|
b874619f0d
|
Fix ip-mappings ILM
|
2025-02-03 09:31:08 -05:00 |
|
Josh Brower
|
9738ef382c
|
Upgrade Elastic to 8.17.1
|
2025-01-23 08:12:02 -05:00 |
|
reyesj2
|
d779f7ae7f
|
add back missing component for http_endpoint_x_generic & winlog_x_winglog
|
2025-01-22 10:15:16 -06:00 |
|
reyesj2
|
6331298eac
|
remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1
|
2025-01-21 10:49:54 -06:00 |
|
reyesj2
|
4618256442
|
include okta-mappings in so-logs-okta.system index template
|
2025-01-13 11:32:27 -06:00 |
|
reyesj2
|
323ef1d5d6
|
add missing lifecycle name to trend_micro_vision_one indices
|
2025-01-13 09:29:22 -06:00 |
|
reyesj2
|
a5b1648b68
|
add missing lifecycle name to crowdstrike indices
|
2025-01-13 09:26:16 -06:00 |
|
reyesj2
|
4f92b7ced1
|
add support for cloudflare_logpush integration
|
2025-01-13 09:23:05 -06:00 |
|
reyesj2
|
cdd4a1ff1f
|
fixes addon integration map file
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-01-03 16:06:22 -06:00 |
|
reyesj2
|
157185c370
|
add ti_opencti integration support
|
2024-12-18 11:33:49 -06:00 |
|
reyesj2
|
888145a2ed
|
remove optional integrations from defaults.yaml & soc_elasticsearch.yaml
|
2024-12-03 08:55:43 -06:00 |
|
reyesj2
|
993d56cb58
|
ti_rapid7*
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-25 15:51:49 -06:00 |
|
reyesj2
|
efa6a533c3
|
add missing ilm to index template
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-25 15:47:47 -06:00 |
|
reyesj2
|
44ec237447
|
additional integration support - cisco secure email gateway - rapid7 threat command
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-15 11:39:01 -06:00 |
|
Jorge Reyes
|
4e0b5569dc
|
Merge pull request #13933 from Security-Onion-Solutions/ilm-detection
add ilm and update managed index settings
|
2024-11-12 15:22:05 -06:00 |
|
reyesj2
|
6dbe0645e5
|
use auto_expand_replica, configure ilm for so-case* & so-detection*
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-11 13:51:48 -06:00 |
|
Jason Ertel
|
57a9992a3d
|
Merge branch '2.4/dev' into jertel/wip
|
2024-11-11 10:06:44 -05:00 |
|
reyesj2
|
80b82b0bd6
|
missing replica 0
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-06 15:24:13 -06:00 |
|
reyesj2
|
039d5c22ac
|
fix: crowdstrike integration
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-06 14:35:41 -06:00 |
|
reyesj2
|
36fc3bbd6d
|
add so-ip-mappings index
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-10-30 10:24:11 -04:00 |
|
Jorge Reyes
|
cf95af66c6
|
Revert "Add support for cybereason integration"
|
2024-10-21 15:23:05 -04:00 |
|
reyesj2
|
8b11019712
|
Add support for cybereason integration
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-10-18 11:56:47 -04:00 |
|
reyesj2
|
322199358d
|
add support for trendmicro integration
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-10-16 16:45:46 -04:00 |
|
Jason Ertel
|
523ff66389
|
connect work
|
2024-10-16 13:44:01 -04:00 |
|
Wes
|
f2bb54d993
|
Add barracuda and imperva integrations
|
2024-09-11 19:41:38 +00:00 |
|
Josh Patterson
|
71f6b44c0c
|
Merge pull request #13607 from Security-Onion-Solutions/esver
use Elasticsearch version for some containers
|
2024-09-04 13:30:07 -04:00 |
|
weslambert
|
a7de6993f9
|
Add so-system-mappings
|
2024-08-30 16:11:41 -04:00 |
|
m0duspwnens
|
3d61897522
|
ref es version from defaults for kibana
|
2024-08-21 08:51:35 -04:00 |
|
weslambert
|
61ab1f1ef2
|
Add tenable_io templates
|
2024-08-15 23:03:07 -04:00 |
|
weslambert
|
49d2ac2b13
|
Change name for system component
|
2024-07-31 16:17:57 -04:00 |
|
Wes
|
fb2a42a9af
|
Use custom system component
|
2024-07-31 17:02:45 +00:00 |
|
weslambert
|
0453f51e64
|
Actually ignore missing templates
|
2024-07-30 12:54:07 -04:00 |
|
Corey Ogburn
|
20f915f649
|
so-detection refresh_interval => 1s
Speeds up the refresh_interval so bulk indexing a single rule does not wait 30s.
|
2024-07-25 12:53:04 -06:00 |
|
weslambert
|
fe1824aedd
|
Revert "Elastic 8.14.2"
|
2024-07-15 11:28:59 -04:00 |
|
weslambert
|
8615e5d5ea
|
Move enabled and index_clean back to the top
|
2024-07-08 16:50:06 -04:00 |
|
weslambert
|
745b6775f1
|
Change name for ILM
|
2024-07-02 09:05:35 -04:00 |
|
Wes
|
32d7927a49
|
Template changes for Elastic 8.14.1
|
2024-07-01 15:16:06 +00:00 |
|