Commit Graph

6989 Commits

Author SHA1 Message Date
Wes
df94e830c5 Remove unnecessary Curator action files 2023-03-07 16:15:41 +00:00
Wes
086b3bf528 Add Curator to so-status output 2023-03-07 15:14:53 +00:00
Josh Brower
a6db2d4502 Fleet - setup ES output for all Managers 2023-03-06 15:50:09 -05:00
Josh Brower
8fae826a3a Merge pull request #9890 from Security-Onion-Solutions/2.4/fixosquerylink
Fixup osquery SO Hunt link
2023-03-06 07:25:00 -05:00
Doug Burks
a2bda07820 add VLAN dashboard 2023-03-05 15:24:11 -05:00
Doug Burks
19ab2a5a46 rename suricata vlan field to network.vlan.id 2023-03-05 05:57:52 -05:00
Josh Brower
f0db5cf657 Fixup osquery SO Hunt link 2023-03-04 11:50:01 -05:00
Doug Burks
4a2e75dd8c fix formatting 2023-03-03 17:16:45 -05:00
Doug Burks
e24296d536 add SOC Dashboards groupby for Zeek conn vlan field 2023-03-03 15:23:43 -05:00
Doug Burks
9940a36722 update Elasticsearch ingest for Zeek conn vlan field 2023-03-03 15:22:43 -05:00
Doug Burks
adb925b4d6 enable zeek vlan script 2023-03-03 12:48:42 -05:00
weslambert
06d1f0f913 Update Curator configuration to align with requirements for Curator 8.0.x 2023-03-02 08:46:52 -05:00
Mike Reeves
af284b9aae Update init.sls 2023-03-01 16:38:48 -05:00
Mike Reeves
2091806f1f Merge pull request #9864 from Security-Onion-Solutions/setuperrors
Fix some errors in setup
2023-03-01 09:48:20 -05:00
m0duspwnens
704365c6eb only stdout redirect 2023-03-01 09:44:48 -05:00
m0duspwnens
a79c380e2b use cmd.run to populate metrics_link 2023-03-01 09:18:58 -05:00
weslambert
134caa7f58 Various adjustments to descriptions 2023-02-28 16:31:16 -05:00
m0duspwnens
8772dcaa10 ensure influxdb is running 2023-02-28 15:57:54 -05:00
Josh Brower
96467f0bd8 Merge pull request #9865 from Security-Onion-Solutions/2.4/fleet-esoutput
Move Output to ES
2023-02-28 15:20:46 -05:00
m0duspwnens
052e0dea2e create and manage metrics_link in a file for soc 2023-02-28 14:47:44 -05:00
Josh Patterson
cbcd3c9dd9 Update defaults.map.jinja 2023-02-27 15:39:03 -05:00
Josh Patterson
8632606a24 Update defaults.map.jinja 2023-02-27 15:37:35 -05:00
Josh Patterson
8d33f01936 Update defaults.map.jinja 2023-02-27 15:01:31 -05:00
Mike Reeves
aa7b05d639 small cleanup 2023-02-27 14:12:26 -05:00
Mike Reeves
9967e91825 remove mysql check 2023-02-27 13:42:11 -05:00
Josh Patterson
fb5aad34e0 Merge pull request #9861 from Security-Onion-Solutions/somefixes2
Somefixes2
2023-02-27 13:14:08 -05:00
m0duspwnens
44ed48033c move requirement 2023-02-27 13:04:23 -05:00
m0duspwnens
068d383442 change to service.running 2023-02-27 12:44:46 -05:00
m0duspwnens
b4015ac73e add sensor to node_containers 2023-02-27 10:05:08 -05:00
Josh Brower
f7176f9989 Move Output to ES 2023-02-27 09:58:43 -05:00
Josh Patterson
dd8f6a460b Merge pull request #9853 from Security-Onion-Solutions/somefixes2
custom hostgroups in soc ui
2023-02-24 16:25:48 -05:00
m0duspwnens
d12ea041bf capitalize 2023-02-24 16:20:16 -05:00
m0duspwnens
6b486d9604 move to default 2023-02-24 15:55:27 -05:00
m0duspwnens
fa5b9799f5 add firewall.soc to top for managers 2023-02-24 15:26:39 -05:00
m0duspwnens
d502d95dba changes for soc firewall 2023-02-24 15:24:02 -05:00
m0duspwnens
29c68c1273 fix bracket, add output to template 2023-02-24 14:32:35 -05:00
m0duspwnens
3e2e68fbd0 custom hostgroups in soc 2023-02-24 14:24:47 -05:00
Jason Ertel
aed41404fc Merge pull request #9852 from Security-Onion-Solutions/kilo
Remove FleetDM tool from SOC instead of deactivating it; generate SRV key during setup
2023-02-24 13:05:58 -05:00
Mike Reeves
afccd3f820 comment out minion installs for now 2023-02-24 12:21:14 -05:00
Mike Reeves
a0eb505db0 Add fireall custom groups 2023-02-24 11:12:17 -05:00
Mike Reeves
99105c7563 Add fireall custom groups 2023-02-24 10:43:41 -05:00
Jason Ertel
316db85584 Generate SOC SRVKey during setup 2023-02-24 10:20:23 -05:00
Jason Ertel
d3c5d0569a Remove FleetDM tool instead of deactivating it 2023-02-24 10:20:02 -05:00
Mike Reeves
29cf95d6eb remove yum versionlock 2023-02-24 10:06:43 -05:00
Mike Reeves
39361c2ab0 unfix playbook fix 2023-02-24 10:01:27 -05:00
Mike Reeves
1289500e03 unfix playbook fix 2023-02-24 09:55:49 -05:00
Mike Reeves
cd56d3a799 unfix playbook fix 2023-02-23 16:18:22 -05:00
Mike Reeves
bf512d56ec unfix playbook fix 2023-02-23 16:12:57 -05:00
Mike Reeves
b206b23fe1 unfix playbook fix 2023-02-23 16:09:54 -05:00
m0duspwnens
8f46e4aa30 set docker extra_hosts for soc 2023-02-23 12:26:58 -05:00