weslambert
|
c73cd78f08
|
Merge pull request #9643 from Security-Onion-Solutions/2.4/dev
Merge Dev
|
2023-01-25 16:59:47 -05:00 |
|
Wes
|
5c58cda872
|
Move certificate configuration outside of conditional logic
|
2023-01-25 19:29:50 +00:00 |
|
Mike Reeves
|
31f591a098
|
Merge pull request #9635 from Security-Onion-Solutions/mkr24
Ubuntu support changes
|
2023-01-25 13:34:44 -05:00 |
|
Mike Reeves
|
704d99e757
|
Salt for Ubuntu
|
2023-01-25 11:50:19 -05:00 |
|
Mike Reeves
|
9243b01cbb
|
Salt for Ubuntu
|
2023-01-25 11:44:22 -05:00 |
|
Wes
|
86a925e1c7
|
Download Elastic Agent images for Import Mode
|
2023-01-25 16:09:12 +00:00 |
|
Wes
|
838beabae5
|
Add missing single quote for Elastic Agent Elasticsearch output
|
2023-01-25 15:58:06 +00:00 |
|
Wes
|
506baa854d
|
Configure Elasticsearch output if running Import Mode
|
2023-01-25 13:52:54 +00:00 |
|
weslambert
|
7bf9d77962
|
Rename Kratos data stream
|
2023-01-25 08:18:21 -05:00 |
|
Wes
|
38ead7cb82
|
Remove import tag for now
|
2023-01-24 17:58:19 +00:00 |
|
Wes
|
1e5377c78a
|
Condense RITA integration policies, add ICS tags, and improve output readability
|
2023-01-24 16:56:20 +00:00 |
|
weslambert
|
7e0e5071d9
|
Merge pull request #9627 from Security-Onion-Solutions/fix/elastic_agent_integration_improvements
Elastic Agent Integration Improvements
|
2023-01-24 10:10:01 -05:00 |
|
Wes
|
7b4d8a47f0
|
Add copyright header to 'so-elastic-fleet-*' scripts
|
2023-01-24 15:07:00 +00:00 |
|
m0duspwnens
|
ee98e0684e
|
change MASTER to MANAGER
|
2023-01-24 09:44:01 -05:00 |
|
Wes
|
40c6b380df
|
Update Import and Zeek integration policies; also update Zeek ingest node pipelines to set event.dataset.
|
2023-01-23 21:44:46 +00:00 |
|
Wes
|
d342f3c4b8
|
Add 'so-elastic-fleet-integration-policy-bulk-delete' to perform bulk deletion of integration policies
|
2023-01-23 21:38:13 +00:00 |
|
m0duspwnens
|
90a224793e
|
merge with 2.4dev and fix conflict
|
2023-01-23 14:49:32 -05:00 |
|
m0duspwnens
|
22fbb953ea
|
create cronjob to run highstate after setup
|
2023-01-23 14:46:26 -05:00 |
|
Josh Brower
|
d3cb57bba2
|
Rerun the playbook state
|
2023-01-23 08:16:28 -05:00 |
|
Wes
|
739c174898
|
Add scripts for starting, stopping, and restarting Sensoroni
|
2023-01-19 21:50:10 +00:00 |
|
Jason Ertel
|
79fb5dc525
|
prevent false success occurring when deleting the grafana dashboard
|
2023-01-19 14:19:55 -05:00 |
|
Jason Ertel
|
05c7999df3
|
merge
|
2023-01-19 10:06:58 -05:00 |
|
Jason Ertel
|
05a6d702b0
|
Add logic to determine if setup succeeded and provide relevant output
|
2023-01-19 10:03:03 -05:00 |
|
Josh Brower
|
e83e54936e
|
Temp disable Elastic Registry Repo
|
2023-01-19 07:25:25 -05:00 |
|
Wes
|
0e437f84e7
|
Add back echo statement to print the import policy being loaded
|
2023-01-11 21:13:30 +00:00 |
|
Wes
|
ea01e68846
|
Fix Zeek import policies and remove unnecessary dash in RITAENABLED statement
|
2023-01-11 21:01:31 +00:00 |
|
weslambert
|
4391c22335
|
Move Suricata import policy definition so that it does not get caught in the for loop for Zeek policies
|
2023-01-11 12:23:50 -05:00 |
|
Wes
|
33e2affb1d
|
Remove newlines from end of Syslog processor definitions
|
2023-01-11 14:08:28 +00:00 |
|
Wes
|
caf0ea6b53
|
Add Elastic Agent policy view script
|
2023-01-11 13:56:21 +00:00 |
|
Wes
|
a146f1134e
|
Add Elastic Agent utility scripts
|
2023-01-11 13:54:42 +00:00 |
|
m0duspwnens
|
dbbcea0009
|
look for True
|
2023-01-09 11:53:32 -05:00 |
|
m0duspwnens
|
c313b19b50
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-01-09 11:18:08 -05:00 |
|
Mike Reeves
|
73ae48d28e
|
Merge pull request #9539 from Security-Onion-Solutions/mkr24
Changes to accept minion
|
2023-01-09 11:17:45 -05:00 |
|
Mike Reeves
|
0e1e9ff343
|
Changes to accept minion
|
2023-01-09 11:15:29 -05:00 |
|
Doug Burks
|
10e82c5f1c
|
Remove line numbers from vi
|
2023-01-06 14:23:54 -05:00 |
|
m0duspwnens
|
d4c6834cd0
|
merge with 2.4/dev
|
2023-01-06 14:01:58 -05:00 |
|
m0duspwnens
|
4aacc6d1db
|
change role names in so-firewall-minion
|
2023-01-06 11:09:09 -05:00 |
|
Mike Reeves
|
2e53476a06
|
Merge pull request #9516 from Security-Onion-Solutions/mkr24
Add PW auth for Redis
|
2023-01-04 14:50:27 -05:00 |
|
Mike Reeves
|
e52b54720a
|
Allow auth for redis check for tgraf
|
2023-01-04 14:26:24 -05:00 |
|
Mike Reeves
|
5afad52b3f
|
Allow auth for redis check for tgraf
|
2023-01-04 14:18:08 -05:00 |
|
Mike Reeves
|
9bc08661c5
|
Allow auth for redis check for tgraf
|
2023-01-04 14:15:53 -05:00 |
|
doug
|
7ba4bdd87b
|
fix jinja whitespace
|
2023-01-04 13:50:25 -05:00 |
|
Jason Ertel
|
a89976779d
|
Ensure create/update dates are both reset when an admin sets a user's password
|
2022-12-30 11:30:09 -05:00 |
|
Jason Ertel
|
136867c96a
|
ensure zombie pipe is destroyed before SOC restarts
|
2022-12-23 10:27:49 -05:00 |
|
Doug Burks
|
e95034886e
|
add influxdb and telegraf to import mode
|
2022-12-22 09:49:57 -05:00 |
|
m0duspwnens
|
accc293c8a
|
2.4 firewall changes
|
2022-12-21 15:03:45 -05:00 |
|
Jason Ertel
|
33a1aea729
|
Merge pull request #9448 from Security-Onion-Solutions/kilo
improve so-status rendering on terminals that only support 8 colors
|
2022-12-21 10:14:47 -05:00 |
|
Jason Ertel
|
8e63909edf
|
improve so-status rendering on terminals that only support 8 colors
|
2022-12-21 10:11:38 -05:00 |
|
Josh Brower
|
73a9c3bb38
|
Make Fleet setup less fragile
|
2022-12-20 11:52:56 -05:00 |
|
Doug Burks
|
894434715b
|
so-status should ignore commented entries in so-status.conf
Import mode comments out so-steno, so-suricata, and so-zeek in so-status.conf, so so-status should ignore these lines.
|
2022-12-20 09:05:07 -05:00 |
|