Mike Reeves
|
2419cf86ee
|
Fix some files
|
2023-05-02 12:41:49 -04:00 |
|
Mike Reeves
|
7595072e85
|
Fix some files
|
2023-05-02 12:15:05 -04:00 |
|
Mike Reeves
|
e60e21d9ff
|
Move files out of common
|
2023-05-02 09:40:02 -04:00 |
|
Mike Reeves
|
2d4f4791e0
|
Move files out of common
|
2023-05-01 15:21:31 -04:00 |
|
Mike Reeves
|
3d7f2bc691
|
Fix annotations and file locations
|
2023-04-27 13:23:53 -04:00 |
|
Doug Burks
|
a67cbb3276
|
FIX: Suricata DNS A and CNAME parsing #10117
|
2023-04-13 10:56:17 -04:00 |
|
Wes
|
8d0074c712
|
Only load pipelines and tempaltes if the node role is not 'so-searchnode'
|
2023-04-11 14:15:21 +00:00 |
|
Doug Burks
|
a8b6470a14
|
Update limited-auditor.json
|
2023-03-31 09:22:42 -04:00 |
|
Doug Burks
|
e945f1c38f
|
Update limited-analyst.json
|
2023-03-31 09:22:28 -04:00 |
|
Doug Burks
|
d0dff9572d
|
Update auditor.json
|
2023-03-31 09:22:15 -04:00 |
|
Doug Burks
|
68e8c159ce
|
Update analyst.json
|
2023-03-31 09:21:59 -04:00 |
|
weslambert
|
de902ebd02
|
Merge pull request #10024 from Security-Onion-Solutions/esspace
Manage disk-based index deletion via so-curator-cluster-delete
|
2023-03-28 12:25:19 -04:00 |
|
Jason Ertel
|
44c696a495
|
Merge pull request #10036 from Security-Onion-Solutions/commonprofile
ensure scripts are run as root, have copyright, and path is correct
|
2023-03-28 11:59:10 -04:00 |
|
Jason Ertel
|
4efe22efb3
|
Update so-elasticsearch-cluster-settings
|
2023-03-28 11:57:41 -04:00 |
|
Jason Ertel
|
591129b98c
|
Update so-elasticsearch-pipelines
|
2023-03-28 11:57:22 -04:00 |
|
Jason Ertel
|
60d770411a
|
Update so-elasticsearch-roles-load
|
2023-03-28 11:57:07 -04:00 |
|
Jason Ertel
|
5f49a120de
|
Update so-elasticsearch-templates-load
|
2023-03-28 11:56:51 -04:00 |
|
m0duspwnens
|
64446f585c
|
change #/bin/bash to #!/bin/bash
|
2023-03-28 11:55:47 -04:00 |
|
Mike Reeves
|
636505ef98
|
Add license and common
|
2023-03-28 11:18:56 -04:00 |
|
Wes
|
f854d92cab
|
Remove the cluster space configuration script reference from the Elasticsearch state
|
2023-03-28 12:27:45 +00:00 |
|
Wes
|
a38aa903ac
|
Configure cluster space settings
|
2023-03-28 01:36:52 +00:00 |
|
Mike Reeves
|
2cb6f0f1e6
|
Add curator settings
|
2023-03-27 12:30:39 -04:00 |
|
Mike Reeves
|
e38b0313c7
|
Merge pull request #9994 from Security-Onion-Solutions/hotones
Switch up elastic roles
|
2023-03-23 16:59:49 -04:00 |
|
Josh Brower
|
bad905f54c
|
SOC Logs & Hunt Query
|
2023-03-23 16:22:59 -04:00 |
|
Mike Reeves
|
90159f4bcd
|
Switch up elastic roles
|
2023-03-23 15:09:40 -04:00 |
|
weslambert
|
0a9a064648
|
Remove node attrs configuration since node roles will be used
|
2023-03-23 13:45:51 -04:00 |
|
Wes
|
84360aa9bf
|
Set replicas for Osquery manager indices to 0
|
2023-03-22 21:47:49 +00:00 |
|
Wes
|
3fba27a0d4
|
Ensure component template files are in the correct directory
|
2023-03-22 20:45:33 +00:00 |
|
Wes
|
28f5dcd43b
|
Add managed generic Elastic Agent log component templates
|
2023-03-22 19:57:46 +00:00 |
|
Wes
|
eaaa028999
|
Update Elastic Agent template settings
|
2023-03-22 19:52:13 +00:00 |
|
Mike Reeves
|
d2bc5e4af2
|
Update config.map.jinja
|
2023-03-22 15:45:51 -04:00 |
|
weslambert
|
6d87620c6a
|
Explicitly set 'event.dataset' as 'file'
|
2023-03-22 11:04:18 -04:00 |
|
Mike Reeves
|
5fc297b8c1
|
Change Elastic Logic
|
2023-03-21 16:52:08 -04:00 |
|
Jason Ertel
|
ca363053e6
|
Merge pull request #9975 from Security-Onion-Solutions/kilo
catch errors and exit with proper exit code
|
2023-03-21 10:51:36 -04:00 |
|
Jason Ertel
|
efd5f7b8a2
|
catch errors and exit with proper exit code
|
2023-03-21 10:44:21 -04:00 |
|
Mike Reeves
|
41554e8311
|
Merge pull request #9969 from Security-Onion-Solutions/guifixes
Add several annotations
|
2023-03-21 08:51:53 -04:00 |
|
Mike Reeves
|
444988f287
|
Adjust annotations
|
2023-03-21 08:48:02 -04:00 |
|
Josh Brower
|
df036206a8
|
Fix Kratos parsing
|
2023-03-20 16:53:25 -04:00 |
|
Mike Reeves
|
22c3a4d398
|
Adjust elasticsearch annotations
|
2023-03-20 16:08:26 -04:00 |
|
Josh Brower
|
f7be4ba31c
|
Remove host field from NIDS logs
|
2023-03-13 14:07:17 -04:00 |
|
Wes
|
e105e56fac
|
Move data stream configuration outside of ILM policy definition
|
2023-03-13 13:27:02 +00:00 |
|
weslambert
|
16d9478196
|
Add index lifecycle management policy definitions for default Elastic Agent data streams
|
2023-03-10 16:54:47 -05:00 |
|
Doug Burks
|
19ab2a5a46
|
rename suricata vlan field to network.vlan.id
|
2023-03-05 05:57:52 -05:00 |
|
Doug Burks
|
9940a36722
|
update Elasticsearch ingest for Zeek conn vlan field
|
2023-03-03 15:22:43 -05:00 |
|
weslambert
|
134caa7f58
|
Various adjustments to descriptions
|
2023-02-28 16:31:16 -05:00 |
|
weslambert
|
acda03ce40
|
Add annotation settings for Elasticsearch's ILM feature, and remove various index keys
|
2023-02-10 14:57:11 -05:00 |
|
Wes
|
1255c60317
|
Move policy load script into Elasticsearch state script directory
|
2023-02-10 18:59:45 +00:00 |
|
Wes
|
994eabae1b
|
Manage policy loading in Elasticsearch state
|
2023-02-10 18:57:19 +00:00 |
|
Wes
|
c9118699a9
|
Add index management lifecycle policy defintion and reference in index template
|
2023-02-10 15:10:30 +00:00 |
|
m0duspwnens
|
a37f0fd0c0
|
rename sosbridge to sobridge
|
2023-02-03 10:07:07 -05:00 |
|