reyesj2
|
9532f21c7b
|
check zeek reporter.log
|
2024-12-05 13:49:44 -06:00 |
|
Jason Ertel
|
918f26962a
|
ignore fp from hydra
|
2024-11-17 12:21:06 -05:00 |
|
Jason Ertel
|
523ff66389
|
connect work
|
2024-10-16 13:44:01 -04:00 |
|
Jason Ertel
|
f0e4e52364
|
es sig pulled from es dir
|
2024-09-11 11:12:20 -04:00 |
|
Josh Patterson
|
e7a7a8609a
|
Merge pull request #13640 from Security-Onion-Solutions/esver
only elasticsearch image uses es version
|
2024-09-09 16:45:14 -04:00 |
|
m0duspwnens
|
8702d95434
|
only elasticsearch image uses es version
|
2024-09-09 16:38:38 -04:00 |
|
Josh Patterson
|
ba0779ea1e
|
Merge pull request #13624 from Security-Onion-Solutions/esver
fix es agent update for soup
|
2024-09-06 10:46:18 -04:00 |
|
m0duspwnens
|
fc25bfe0df
|
grab es version from defaults during soup
|
2024-09-06 09:04:43 -04:00 |
|
Jason Ertel
|
5625771ffb
|
es version shift
|
2024-09-05 13:16:28 -04:00 |
|
Jason Ertel
|
c85e5643db
|
es version shift
|
2024-09-05 13:14:45 -04:00 |
|
m0duspwnens
|
7d9b3b1f28
|
use correct sig
|
2024-09-04 15:36:17 -04:00 |
|
Josh Patterson
|
71f6b44c0c
|
Merge pull request #13607 from Security-Onion-Solutions/esver
use Elasticsearch version for some containers
|
2024-09-04 13:30:07 -04:00 |
|
m0duspwnens
|
2b807c2409
|
update comment
|
2024-09-04 10:33:14 -04:00 |
|
m0duspwnens
|
0af2e85f91
|
update annotation.
|
2024-09-04 10:32:11 -04:00 |
|
m0duspwnens
|
cfdc8ede90
|
fix es version logic
|
2024-09-03 16:49:39 -04:00 |
|
m0duspwnens
|
83aa4c9a53
|
fix awk
|
2024-09-03 15:22:25 -04:00 |
|
m0duspwnens
|
c20ac6c2d8
|
fix if and awk
|
2024-09-03 15:20:49 -04:00 |
|
m0duspwnens
|
6d7b76115f
|
use the version that is longest for the loop
|
2024-09-03 13:00:37 -04:00 |
|
m0duspwnens
|
a920adcf7f
|
handle ver1 missing segment
|
2024-09-03 12:53:53 -04:00 |
|
m0duspwnens
|
529844eb36
|
update so-image-common to use es version for es containers
|
2024-09-03 12:38:21 -04:00 |
|
DefensiveDepth
|
89a1e2500e
|
Exclude logstash startup errors
|
2024-08-28 16:50:11 -04:00 |
|
Jason Ertel
|
394ce29ea3
|
Merge pull request #13565 from Security-Onion-Solutions/jertel/an2
move custom alerters to subgroup; avoid false positives on log check
|
2024-08-28 09:39:44 -04:00 |
|
Jason Ertel
|
f19a35ff06
|
move custom alerters to subgroup; avoid false positives on log check
|
2024-08-28 09:32:25 -04:00 |
|
Jason Ertel
|
d29727c869
|
Merge pull request #13540 from Security-Onion-Solutions/jertel/an2
exclude all logstash errors related to license manager init log line
|
2024-08-22 18:17:23 -04:00 |
|
Jason Ertel
|
eabb894580
|
exclude all logstash errors related to license manager init log line
|
2024-08-22 17:52:37 -04:00 |
|
Mike Reeves
|
04577a48be
|
Merge pull request #13530 from Security-Onion-Solutions/raidtools
|
2024-08-21 14:33:40 -04:00 |
|
Mike Reeves
|
ff479de7bd
|
Add support for new appliance raid controllers
|
2024-08-21 14:10:24 -04:00 |
|
m0duspwnens
|
7fbf448b22
|
fail if no defaults file
|
2024-08-21 11:36:06 -04:00 |
|
m0duspwnens
|
da1671fdf1
|
add get_elastic_agent_vars function
|
2024-08-21 11:25:33 -04:00 |
|
weslambert
|
205bbd9c61
|
Use more specific match
|
2024-08-16 14:31:11 -04:00 |
|
weslambert
|
224bc6b429
|
Ignore old SOC logs before licenseStatus
|
2024-08-16 14:15:10 -04:00 |
|
DefensiveDepth
|
b860bf753a
|
Add influxdb known error
|
2024-08-15 11:50:34 -04:00 |
|
weslambert
|
c60b14e2e7
|
Merge branch '2.4/dev' into foxtrot
|
2024-07-30 08:52:48 -04:00 |
|
weslambert
|
1df19faf5c
|
Elastic 8.14.3
|
2024-07-15 15:44:50 -04:00 |
|
weslambert
|
fe1824aedd
|
Revert "Elastic 8.14.2"
|
2024-07-15 11:28:59 -04:00 |
|
Jorge Reyes
|
e58b2c45dd
|
Merge pull request #13335 from Security-Onion-Solutions/reyesj2/kgz
FIX: Kafka configuration updates
|
2024-07-12 15:55:43 -04:00 |
|
reyesj2
|
ff29d9ca51
|
Update log-check to ignore kafka data directories
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-07-11 10:23:51 -04:00 |
|
weslambert
|
c6f6811f47
|
Elastic 8.14.2
|
2024-07-08 09:47:34 -04:00 |
|
weslambert
|
5743189eef
|
Elastic 8.14.1
|
2024-06-27 10:47:46 -04:00 |
|
weslambert
|
222ebbdec1
|
Revert back to 8.10.4
|
2024-06-27 09:05:29 -04:00 |
|
weslambert
|
0f226cc08e
|
Elastic 8.14.1
|
2024-06-26 13:59:23 -04:00 |
|
Mike Reeves
|
9577c3f59d
|
Make soup use reposync from the repo
|
2024-06-21 15:24:54 -04:00 |
|
reyesj2
|
4581a46529
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka
|
2024-06-05 20:47:41 -04:00 |
|
m0duspwnens
|
ff5773c837
|
move so-tcpreplay back to common. return empty string if no sensor.interface pillar
|
2024-06-05 08:56:32 -04:00 |
|
m0duspwnens
|
a2467d0418
|
move so-tcpreplay to sensor state
|
2024-06-05 08:24:57 -04:00 |
|
m0duspwnens
|
c0b2cf7388
|
add the curlys
|
2024-06-04 10:28:21 -04:00 |
|
reyesj2
|
1fd5165079
|
Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/kafka
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-29 23:37:40 -04:00 |
|
m0duspwnens
|
b5f656ae58
|
dont render pillar each time so-tcpreplay runs
|
2024-05-23 13:22:22 -04:00 |
|
Jason Ertel
|
8ce19a93b9
|
exclude false positives related to detections
|
2024-05-21 13:29:20 -04:00 |
|
reyesj2
|
6fac6eebce
|
Helper script for enrolling tpm into luks
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-20 14:37:54 -04:00 |
|