Josh Patterson
|
c66cd3b2f3
|
ensure image is readded if removed
|
2025-03-10 11:23:26 -04:00 |
|
Josh Patterson
|
f30938ed59
|
hypervisor annotation show if base domain is initialized or not
|
2025-03-06 15:26:08 -05:00 |
|
Josh Patterson
|
6c472dd383
|
Merge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-03-05 08:58:03 -05:00 |
|
Josh Patterson
|
2c5861a0c2
|
ensure local hypervisor dir when new hypervisor key accepted. apply soc.dyanno.hypervisor when hypervisor key accepted
|
2025-03-05 08:51:10 -05:00 |
|
Doug Burks
|
2f6c7d2643
|
Merge pull request #14340 from Security-Onion-Solutions/dougburks-patch-1
FEATURE: Add sankey chart to Elastic Agent API dashboard to show relationship between process.name and process.Ext.api.name #14339
|
2025-03-05 08:02:39 -05:00 |
|
Doug Burks
|
c6c67f4d06
|
FEATURE: Add sankey chart to Elastic Agent API dashboard to show relationship between process.name and process.Ext.api.name #14339
|
2025-03-05 06:31:16 -05:00 |
|
Jorge Reyes
|
f35930317b
|
Merge pull request #14336 from Security-Onion-Solutions/reyesj2-patch-2
ES 8.17.3
|
2025-03-04 15:36:59 -06:00 |
|
reyesj2
|
11dc004811
|
ES 8.17.3
|
2025-03-04 14:24:38 -06:00 |
|
Jorge Reyes
|
966503d875
|
Merge pull request #14331 from Security-Onion-Solutions/reyesj2-patch-2
osquery v1.15.0 index templates updates
|
2025-03-04 13:17:28 -06:00 |
|
reyesj2
|
124bf266b5
|
osquery v1.15.0 index templates updates
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-04 12:27:04 -06:00 |
|
Jason Ertel
|
0ff4fc101b
|
Merge pull request #14329 from Security-Onion-Solutions/jertel/wip
reduce stdout verbosity
|
2025-03-04 11:23:14 -05:00 |
|
Jason Ertel
|
85450693a2
|
Merge branch '2.4/dev' into jertel/wip
|
2025-03-04 10:55:29 -05:00 |
|
Jason Ertel
|
0047246cf2
|
reduce stdout verbosity
|
2025-03-04 10:55:12 -05:00 |
|
Jorge Reyes
|
95d3a2d834
|
Merge pull request #14328 from Security-Onion-Solutions/reyesj2-patch-2
install bc package
|
2025-03-04 09:03:02 -06:00 |
|
reyesj2
|
e1c8bee71a
|
install bc package
|
2025-03-04 08:58:41 -06:00 |
|
Doug Burks
|
1c96449ad9
|
Merge pull request #14327 from Security-Onion-Solutions/dougburks-patch-1
FIX: Elastic Agent Security Events dashboard should reference user.effective.name #14325
|
2025-03-04 07:10:41 -05:00 |
|
Doug Burks
|
44535cba8c
|
FIX: Elastic Agent Security Events dashboard should reference user.effective.name #14325
|
2025-03-04 06:46:56 -05:00 |
|
Jorge Reyes
|
3f4a5a1b28
|
Merge pull request #14320 from Security-Onion-Solutions/reyesj2/zeekparslin
zeek traceroute & ntp
|
2025-03-03 10:56:15 -06:00 |
|
reyesj2
|
4bd83f8983
|
zeek traceroute & ntp
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2025-03-03 10:48:06 -06:00 |
|
Doug Burks
|
206acbe618
|
Merge pull request #14312 from Security-Onion-Solutions/dougburks-patch-1
FIX: SOC Actions for process.entity_id value must be quoted #14311
|
2025-03-03 07:09:45 -05:00 |
|
Doug Burks
|
e53f4fd1f1
|
Update defaults.yaml to quote the process.entity_id value
|
2025-03-02 05:54:30 -05:00 |
|
Josh Patterson
|
8047e196fe
|
fix pipeline workers, zeek/suricata lbprocs, CPUCORES and CORECOUNT
|
2025-02-28 17:21:06 -05:00 |
|
Josh Patterson
|
c6c979dc19
|
properly set memory and CPUCORES for minion pillars during vm setup
|
2025-02-28 16:12:28 -05:00 |
|
Jorge Reyes
|
573a2a5595
|
Merge pull request #14307 from Security-Onion-Solutions/reyesj2/esmngdint
|
2025-02-27 17:13:26 -06:00 |
|
reyesj2
|
9bc64bf453
|
managed int multiline input
|
2025-02-27 16:48:07 -06:00 |
|
Josh Patterson
|
c8a1c8377a
|
vm power operations
|
2025-02-27 16:04:44 -05:00 |
|
Jason Ertel
|
bc969c1ca2
|
Merge pull request #14302 from Security-Onion-Solutions/jertel/wip
more false positives
|
2025-02-27 08:00:49 -05:00 |
|
Jason Ertel
|
772aa7379f
|
more false positives
|
2025-02-27 07:55:22 -05:00 |
|
Josh Patterson
|
4e954c24f7
|
handle cpu, copper and sfp as options
|
2025-02-26 17:58:09 -05:00 |
|
Josh Patterson
|
52839e2a7d
|
implement regex for cpu and mem
|
2025-02-26 15:22:36 -05:00 |
|
Josh Patterson
|
1a9d5f151f
|
change description formatting. include full vm name in HYPERVISORS
|
2025-02-26 14:28:31 -05:00 |
|
Jorge Reyes
|
f8d19301be
|
Merge pull request #14300 from Security-Onion-Solutions/betrfix
default capinfos to use start/end time arg
|
2025-02-26 08:32:46 -06:00 |
|
Josh Patterson
|
d6f527881a
|
allow for destroyed vms to be displayed in ui. VNM cleanup destroyed status files after 48h
|
2025-02-26 09:06:45 -05:00 |
|
reyesj2
|
80fed1e045
|
default capinfos to use start/end time arg
|
2025-02-25 21:47:56 -06:00 |
|
Jason Ertel
|
a94d657251
|
Merge pull request #14296 from Security-Onion-Solutions/jertel/wip
annotation/config updates
|
2025-02-25 17:04:13 -05:00 |
|
Jason Ertel
|
9dafa062f8
|
annotation/config updates
|
2025-02-25 17:00:41 -05:00 |
|
Josh Patterson
|
5811b184be
|
enhance annotations. account for line separation instead of comma for hardware
|
2025-02-25 11:13:35 -05:00 |
|
Josh Patterson
|
e0a3b51ca2
|
md in description
|
2025-02-25 08:54:04 -05:00 |
|
Josh Patterson
|
b5276a6a1d
|
add hypervisor to firewall annotation
|
2025-02-25 04:41:59 -05:00 |
|
Jorge Reyes
|
c8a6aa42fb
|
Merge pull request #14290 from Security-Onion-Solutions/reyesj2-patch-41
allow installing integrations that require an elastic license
|
2025-02-24 15:24:38 -06:00 |
|
reyesj2
|
17edc06987
|
allow installing integrations that require an elastic license
|
2025-02-24 14:45:43 -06:00 |
|
Josh Patterson
|
cc1b030c00
|
q
xMerge remote-tracking branch 'origin/2.4/dev' into vlb2
|
2025-02-24 15:32:54 -05:00 |
|
Josh Patterson
|
c896785480
|
fix vm deletion
|
2025-02-24 14:20:09 -05:00 |
|
Josh Patterson
|
0006948c29
|
get hypervisor from dir name
|
2025-02-24 12:26:28 -05:00 |
|
Josh Patterson
|
6ac14f832e
|
only allow first process step to overwrite last
|
2025-02-24 12:22:52 -05:00 |
|
Jorge Reyes
|
a60afdbaa5
|
Merge pull request #14288 from Security-Onion-Solutions/reyesj2-patch-41
missing metadata field
|
2025-02-24 10:31:42 -06:00 |
|
reyesj2
|
e2772e899e
|
component template missing metadata field
|
2025-02-24 10:24:11 -06:00 |
|
Jorge Reyes
|
43f86e5e37
|
Merge pull request #14287 from Security-Onion-Solutions/reyesj2-patch-41
elasticsearch templates load
|
2025-02-24 09:11:58 -06:00 |
|
reyesj2
|
d7c06e5ff4
|
run elasticsearch state, right before completing soup to ensure templates for optional integrations are loaded
|
2025-02-24 09:02:56 -06:00 |
|
reyesj2
|
3f2b0973af
|
manually create unused logs-soc@package for successful elasticsearch templates load
|
2025-02-24 08:59:59 -06:00 |
|