Commit Graph

253 Commits

Author SHA1 Message Date
Mike Reeves 329a030585 Merge remote-tracking branch 'remotes/origin/dev' into issue/140 2020-05-17 09:38:30 -04:00
Wes Lambert f0662eed48 remark Beat tag for now 2020-05-16 14:59:41 +00:00
m0duspwnens 74290eca2a change = to in - https://github.com/Security-Onion-Solutions/securityonion-saltstack.git 2020-05-15 11:20:06 -04:00
m0duspwnens 509188092c adding so-standalone state logic, add zeek pillar to so-standalone - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/140 2020-05-15 10:02:25 -04:00
m0duspwnens 766b56a944 update dockers to 1.2.2 2020-04-23 10:11:26 -04:00
Mike Reeves d9e27a5444 Update Versions 2020-04-15 15:37:59 -04:00
m0duspwnens 749935339b removing path.config 2020-04-08 15:31:11 -04:00
Wes Lambert 7765d9a038 update common template 2020-04-05 20:40:30 +00:00
Josh Brower 513419ce2f template + nginx config 2020-04-02 20:16:21 -04:00
Wes Lambert 09022ad752 Update Zeek and Strelka 2020-04-01 19:11:10 +00:00
Wes Lambert 1df2302287 Update Zeek and Strelka 2020-04-01 19:09:38 +00:00
weslambert 82c99edbfc Update Suricata output 2020-04-01 15:02:52 -04:00
weslambert e1008269ce Update OSSEC output 2020-04-01 15:00:52 -04:00
Josh Brower 5ca9a643a8 Merge branch 'dev' into feature/osquery-ingest 2020-04-01 10:19:35 -04:00
Josh Brower 0e76447d11 osquery ingest - initial support 2020-04-01 10:17:36 -04:00
Wes Lambert 33512eca2a template and kibana config updates 2020-04-01 13:14:13 +00:00
weslambert ece7e139f2 Add message 2020-03-23 23:39:15 -04:00
Wes Lambert 7a71a2c459 removing mapping types 2020-03-18 20:17:57 +00:00
Wes Lambert 5072095eeb removing mapping types 2020-03-18 20:15:10 +00:00
Wes Lambert fcc5c306ea fix index names 2020-03-18 16:42:06 +00:00
m0duspwnens 504d22de83 fix issue lsetcsync if node doesnt have templates defined 2020-03-18 10:49:51 -04:00
Wes Lambert 29a4932785 fix strelka pattern 2020-03-18 13:47:22 +00:00
Wes Lambert 70f109af86 elastic changes 2020-03-17 21:29:28 +00:00
Wes Lambert 5ed3dbff39 Fix template name 2020-03-17 15:15:01 +00:00
Wes Lambert d48c2723ba modify default templates 2020-03-14 12:02:52 +00:00
Wes Lambert 9fb3a47358 modify default templates 2020-03-14 12:02:42 +00:00
Wes Lambert f9e4d218ec update config 2020-03-11 12:13:11 +00:00
Wes Lambert 70e78a0642 add renamed templates 2020-03-11 12:12:32 +00:00
weslambert 14dfec5365 Change to bro template 2020-03-09 09:18:57 -04:00
Josh Patterson 79210a07da Merge pull request #396 from Security-Onion-Solutions/issue/326
fix issue with salt not removing pipeline configs or templates if removed from pillar
2020-03-04 10:14:57 -05:00
m0duspwnens 28c4bb4b22 fix issue with salt not removing pipeline configs or templates if removed from pillar 2020-03-04 10:12:28 -05:00
Wes Lambert bbebc4fc9b Add src/dst objects and Bro template 2020-03-02 20:02:39 +00:00
Wes Lambert 9eb5a9be3a Begin switch to ECS for Suricata 2020-03-02 19:07:40 +00:00
m0duspwnens 847e6d2d13 create pipelines directory 2020-02-26 16:38:47 -05:00
m0duspwnens a3e48f0315 logstash cleanup and conflict resolution - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/326 2020-02-26 10:58:39 -05:00
m0duspwnens 54e4c40c2a logstash cleanup and conflict resolution - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/326 2020-02-26 10:26:50 -05:00
m0duspwnens 0c4973ad77 pillarize logstash config,parsers,templates and docker port bindings 2020-02-25 17:44:32 -05:00
Wes Lambert 5d81bf3204 remove source 2020-02-25 12:36:35 +00:00
m0duspwnens e2ccebd2fa resolve conflicts 2020-02-20 17:00:15 -05:00
m0duspwnens 2b34bdece9 logstash cleanup - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/326 2020-02-20 16:47:40 -05:00
weslambert fc9786e541 Change template name 2020-02-20 11:46:15 -05:00
weslambert 6945cbb843 Change template name 2020-02-20 11:45:50 -05:00
weslambert 30a1197b44 Rename template to avoid duplication under different name 2020-02-20 11:20:06 -05:00
m0duspwnens 7604853c59 fix logic for logstash pipelines 2020-02-19 16:02:24 -05:00
m0duspwnens 54e94676fe fix pipelines variable 2020-02-19 14:59:39 -05:00
m0duspwnens 408b3695e0 add back deleted states to logstash state 2020-02-19 14:12:18 -05:00
m0duspwnens c396342aea fix syntax error with new ls pipeline config 2020-02-19 13:46:52 -05:00
m0duspwnens 6a7580404d directory cleanup - logstash pipeline rework 2020-02-19 13:08:14 -05:00
Wes Lambert 50fcf8307f Add initia/basic Strelka config 2020-02-18 02:46:31 +00:00
Wes Lambert 64166f96a1 Ensure correct template is used 2020-02-17 21:15:11 +00:00