Josh Patterson
c92aedfff3
ensure bool sliders for elastalert config options
2026-03-19 13:06:32 -04:00
Josh Patterson
c2c5aea244
ensure bool sliders for each state:enabled annotation
2026-03-19 12:35:38 -04:00
Josh Patterson
cceaebe350
remove restriction of mmap locked on suricata ulimits
2026-03-19 09:42:39 -04:00
Josh Patterson
a982056363
Merge remote-tracking branch 'origin/3/dev' into delta
2026-03-18 15:45:15 -04:00
Josh Patterson
db81834e06
fix indentation to match prior indentation
2026-03-18 15:44:49 -04:00
Jason Ertel
318e4ec54b
Merge pull request #15643 from Security-Onion-Solutions/jertel/wip
...
fix casing to match annotation docs
2026-03-18 15:36:47 -04:00
Josh Patterson
4254769e68
Merge remote-tracking branch 'origin/3/dev' into delta
2026-03-18 15:32:52 -04:00
reyesj2
c16ff2bd99
so-idh and so-redis datastream config
2026-03-18 14:31:23 -05:00
Jason Ertel
0c88b32fc2
fix casing to match annotation docs
2026-03-18 15:31:19 -04:00
Josh Patterson
0814f34f0e
don't define zeek nofile, already uses docker default
2026-03-18 13:13:06 -04:00
Jason Ertel
b6366e52ba
Merge pull request #15642 from Security-Onion-Solutions/jertel/wip
...
more doc updates
2026-03-18 13:09:36 -04:00
Jason Ertel
825f377d2d
more doc updates
2026-03-18 13:05:36 -04:00
Josh Patterson
74ad2990a7
Merge remote-tracking branch 'origin/3/dev' into delta
2026-03-18 13:05:02 -04:00
Josh Patterson
057ec6f0f1
ensure valid ulimit names
2026-03-18 12:49:46 -04:00
Jorge Reyes
20c4da50b1
Merge pull request #15632 from Security-Onion-Solutions/reyesj2-15601
...
fix global override settings affecting non-data stream indices
2026-03-18 10:51:17 -05:00
Josh Patterson
cacae12ba3
remove .jinja from daemon.json
2026-03-18 11:08:33 -04:00
Jason Ertel
83bd8a025c
ignore redis restart warning in logstash log
2026-03-18 10:59:20 -04:00
Josh Patterson
e19e83bebb
allow user defined ulimits
2026-03-18 10:38:15 -04:00
Doug Burks
930985b770
update helpLink references for new documentation
2026-03-18 09:46:45 -04:00
Jorge Reyes
346dc446de
Merge pull request #15630 from Security-Onion-Solutions/reyesj2-449
...
use elasticsearch recommended vm.max_map_count
2026-03-17 15:36:06 -05:00
reyesj2
7e7b8dc8a8
vm.max_map_count allow for minion specific values
2026-03-17 15:23:46 -05:00
Josh Patterson
341471d38e
DOCKER to DOCKERMERGED
2026-03-17 16:19:36 -04:00
Josh Patterson
2349750e13
DOCKER to DOCKERMERGED
2026-03-17 16:19:02 -04:00
reyesj2
2c6c502067
use elasticsearch recommended vm.max_map_count
2026-03-17 15:12:29 -05:00
Josh Patterson
00986dc2fd
Merge remote-tracking branch 'origin/delta' into customulimit
2026-03-17 16:04:09 -04:00
Josh Patterson
d60bef1371
add spft/hard ulimits
2026-03-17 16:00:09 -04:00
Mike Reeves
2d97dfc8a1
Add customizable ulimit settings for all Docker containers
...
Add ulimits as a configurable advanced setting for every container,
allowing customization through the web UI. Move hardcoded ulimits
from elasticsearch and zeek into defaults.yaml and fix elasticsearch
ulimits that were incorrectly nested under the environment key.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-17 15:10:42 -04:00
Josh Patterson
d6263812a6
move daemon.json to docker/files
2026-03-17 15:09:09 -04:00
Josh Patterson
ef7d1771ab
DOCKER TO DOCKERMERGED
2026-03-17 15:08:10 -04:00
Josh Patterson
4dc377c99f
DOCKER to DOCKERMERGED
2026-03-17 15:06:06 -04:00
reyesj2
a52e5d0474
update index template priorities + explicity add datastream config options
2026-03-17 13:50:15 -05:00
reyesj2
1a943aefc5
rollover datastreams to get latest index templates + remove existing ilm policies from so-case / so-detection indices
2026-03-17 13:49:20 -05:00
Mike Reeves
4bb61d999d
Merge pull request #15628 from Security-Onion-Solutions/zeekload
...
Add salt states for custom Zeek package loading
2026-03-17 13:40:14 -04:00
Mike Reeves
e0e0e3e97b
Exclude README from zkg sync
2026-03-17 13:36:56 -04:00
Mike Reeves
6b039b3f94
Consolidate zkg directory creation into file.recurse with makedirs
2026-03-17 13:36:03 -04:00
Mike Reeves
e6ee7dac7c
Add salt states for custom Zeek package loading
...
Create /opt/so/conf/zeek/zkg directory and sync custom packages
from the manager via file.recurse. Bind mount the directory into
the so-zeek container so the entrypoint can install packages on
startup.
2026-03-17 13:22:59 -04:00
Josh Patterson
7bf63b822d
replace placeholder files with .gitkeep to keep empty directories
2026-03-17 11:40:49 -04:00
Josh Patterson
1a7d72c630
ensure empty directory tracked by git
2026-03-17 11:11:02 -04:00
Josh Patterson
4224713cc6
Merge pull request #15624 from Security-Onion-Solutions/moreja
...
Add SOC UI toggle for JA4+ fingerprinting
2026-03-17 09:44:04 -04:00
Mike Reeves
b452e70419
Keep JA4S_raw and JA4H_raw hardcoded to disabled
2026-03-17 09:37:37 -04:00
Mike Reeves
6809497730
Add SOC UI toggle for JA4+ fingerprinting in Zeek
...
JA4 (BSD licensed) remains always enabled, but JA4+ variants (JA4S,
JA4D, JA4H, JA4L, JA4SSH, JA4T, JA4TS, JA4X) require a FoxIO license
and are now toggleable via the SOC UI. The toggle includes a license
agreement warning and defaults to disabled.
2026-03-17 09:35:31 -04:00
Jason Ertel
70597a77ab
Merge pull request #15623 from Security-Onion-Solutions/jertel/wip
...
fix hydra health check
2026-03-17 07:53:00 -04:00
Jason Ertel
f5faf86cb3
fix hydra health check
2026-03-17 07:50:40 -04:00
Mike Reeves
ebc1152376
Rebuild all analyzer source-packages for Python 3.14
...
Full rebuild of all analyzer source-packages via pip download targeting
cp314/manylinux_2_17_x86_64 to match the so-soc Dockerfile base image
(python:3.14.3-slim).
Replaces cp313 wheels with cp314 for pyyaml and charset_normalizer,
and picks up certifi 2026.2.25 (from 2026.1.4).
2026-03-16 18:58:24 -04:00
Mike Reeves
625bfb3ba7
Rebuild analyzer source-packages wheels for Python 3.14
...
The so-soc Dockerfile base image moved to python:3.14.3-slim but
analyzer source-packages still contained cp313 wheels for pyyaml and
charset_normalizer, causing pip install failures at container startup.
Replace all cp313 wheels with cp314 builds (pyyaml 6.0.3,
charset_normalizer 3.4.6) across all 14 analyzers and update the
CI python-test workflow to match.
2026-03-16 18:58:23 -04:00
Jason Ertel
a3b471c1d1
fix health check for new hydra version
2026-03-16 18:43:36 -04:00
reyesj2
eaf3f10adc
remove unused close/delete configs on datastream index templates
2026-03-16 17:26:45 -05:00
reyesj2
84f4e460f6
update index patterns
2026-03-16 16:53:22 -05:00
reyesj2
88841c9814
remove ilm configs from non-datastream indices
2026-03-16 16:52:42 -05:00
Mike Reeves
64bb0dfb5b
Merge pull request #15610 from Security-Onion-Solutions/moresoup
...
Add -r flag to so-yaml get and migrate pcap pillar to suricata
2026-03-16 17:36:32 -04:00