Wes Lambert
|
b06c16f750
|
Add ingest node pipeline for Kratos
|
2022-07-08 15:53:00 +00:00 |
|
Mike Reeves
|
8b3d5e808e
|
Fix repo location
|
2022-06-30 13:30:56 -04:00 |
|
Mike Reeves
|
e86b7bff84
|
Fix repo location
|
2022-06-30 13:29:21 -04:00 |
|
weslambert
|
44595cb333
|
Merge pull request #8123 from Security-Onion-Solutions/foxtrot
Merge foxtrot into dev
|
2022-06-14 15:44:13 -04:00 |
|
doug
|
025993407e
|
FIX: Add event.category field to pfsense firewall logs #8112
|
2022-06-13 08:03:44 -04:00 |
|
Josh Brower
|
8e368bdebe
|
Merge in upstream dev
|
2022-05-06 20:01:07 -04:00 |
|
weslambert
|
542db5b7f5
|
Update defaults.yaml
|
2022-04-21 17:24:24 -04:00 |
|
Josh Brower
|
2b39570b08
|
Fix matching logic
|
2022-04-18 10:37:38 -04:00 |
|
Josh Brower
|
886d69fb38
|
Compress + Clean ES & Logstash App Logs
|
2022-04-11 16:09:24 -04:00 |
|
weslambert
|
e6599cd10e
|
Update with changes from Abe's PR and other fixes
|
2022-03-25 13:57:44 -04:00 |
|
weslambert
|
c02d7fab50
|
Merge pull request #7636 from Security-Onion-Solutions/feature/rita
Parsing of RITA Logs
|
2022-03-24 13:05:22 -04:00 |
|
Wes Lambert
|
fe1b72655b
|
Additional .keyword shims for process mappings
|
2022-03-24 16:45:06 +00:00 |
|
weslambert
|
1f2bca599f
|
Check cluster health before trying to load roles for ES
|
2022-03-23 11:00:26 -04:00 |
|
Wes Lambert
|
2487d468ab
|
Add RITA Elasticsearch ingest pipeline config
|
2022-03-22 17:38:22 +00:00 |
|
weslambert
|
7128b04636
|
Remove indices.query.bool.max_clause_count because it is dynamically allocated in Elastic 8
|
2022-03-17 21:20:41 -04:00 |
|
Wes Lambert
|
42d6c3a956
|
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
|
2022-03-15 14:55:04 +00:00 |
|
Wes Lambert
|
5f56c7a261
|
Replace ELASTICCURL with so-elasticsearch-query
|
2022-03-15 14:32:00 +00:00 |
|
Wes Lambert
|
d12ff503c2
|
Chage role loading verbiage
|
2022-03-11 16:23:19 +00:00 |
|
Wes Lambert
|
dc258cf043
|
Load custom component templates in so-elasticsearch-templates-load
|
2022-03-11 16:22:55 +00:00 |
|
Wes Lambert
|
8e43a6e571
|
Don't generate index template if index_template definition is not present in pillar
|
2022-03-11 16:22:06 +00:00 |
|
m0duspwnens
|
e1e8a20e11
|
make sure values exist in data structure
|
2022-03-10 17:09:00 -05:00 |
|
weslambert
|
406267a892
|
Add process.name.keyword
|
2022-03-08 12:42:34 -05:00 |
|
Mike Reeves
|
4eb37fd5a9
|
Update init.sls
|
2022-03-07 15:09:36 -05:00 |
|
Mike Reeves
|
d33db6fb23
|
Only load pipelines on change
|
2022-03-07 14:25:46 -05:00 |
|
Wes Lambert
|
c549b20221
|
Add DTC client mappings
|
2022-03-07 18:36:26 +00:00 |
|
Mike Reeves
|
c67604590d
|
Only load templates on change
|
2022-03-07 09:52:18 -05:00 |
|
weslambert
|
fc3273fa49
|
Change to label fields to comply with what's defined in Filebeat template
|
2022-03-04 16:29:01 -05:00 |
|
weslambert
|
254cf53c2f
|
Increase clause count to 3500
|
2022-03-04 10:36:37 -05:00 |
|
Wes Lambert
|
ffae22beef
|
Add DTC syslog mappings for .keyword and add refs to defaults.yml
|
2022-03-04 13:04:11 +00:00 |
|
Wes Lambert
|
1f71816ad7
|
Add keyword subfield for DTC winlog mappings
|
2022-03-03 14:54:30 +00:00 |
|
Wes Lambert
|
1c086e36da
|
Add missing comma for file mappings
|
2022-03-03 13:49:54 +00:00 |
|
Wes Lambert
|
aa8d24b6cd
|
Add DTC destination, source, and winlog mapping references to templates in defaults file
|
2022-03-03 13:42:20 +00:00 |
|
Wes Lambert
|
85979cbce8
|
Add file, process, and winlog mapping changes
|
2022-03-03 13:37:27 +00:00 |
|
Wes Lambert
|
8f97f09c9c
|
Additional .keyword changes for host.hostname client.address, and event.action
|
2022-03-02 21:54:46 +00:00 |
|
Wes Lambert
|
3ee46e4c29
|
Add .keyword for destination/source geo.country_name
|
2022-03-02 21:50:03 +00:00 |
|
Wes Lambert
|
c5b16fdf3b
|
Adjust field limit for now
|
2022-03-02 16:33:39 +00:00 |
|
Wes Lambert
|
ab9b81ea39
|
Change match_only_text to text for mac in host mappings
|
2022-03-02 15:01:05 +00:00 |
|
Wes Lambert
|
ed620b93b7
|
Add custom analyzer definition to all SO/DTC mappings
|
2022-03-02 14:43:19 +00:00 |
|
Wes Lambert
|
27c8eaa630
|
Update all other mappings for .security where applicable
|
2022-03-02 14:39:23 +00:00 |
|
Wes Lambert
|
e925d435ff
|
Update event, file, and host mappings to include .security
|
2022-03-02 14:33:52 +00:00 |
|
Wes Lambert
|
496b161253
|
Update ECS mappings to include .security
|
2022-03-02 14:27:36 +00:00 |
|
Wes Lambert
|
aae2fd1fbb
|
Update DNS mappings to include .security
|
2022-03-02 14:27:15 +00:00 |
|
Wes Lambert
|
0b45cf7ae1
|
Update base mappings to include .security
|
2022-03-02 14:25:57 +00:00 |
|
Wes Lambert
|
d89af5f04f
|
Update agent mappings to include .security
|
2022-03-02 14:25:14 +00:00 |
|
Wes Lambert
|
2d2ec45029
|
Modify base ECS mappings to include .security where possible, as well as custom analyzer definition
|
2022-03-02 14:19:36 +00:00 |
|
Wes Lambert
|
5489b8559d
|
Revert "Switch from .security to match_only_text"
This reverts commit f7862af934.
|
2022-03-01 18:44:00 +00:00 |
|
Wes Lambert
|
2a9caccc7c
|
Revert "Add additional .text subfield mappings"
This reverts commit 61dadc6249.
|
2022-03-01 18:43:24 +00:00 |
|
Wes Lambert
|
a290602a70
|
Revert syslog pipeline updates from Abe' PR for now
|
2022-03-01 15:31:07 +00:00 |
|
Wes Lambert
|
038dc49098
|
Temporarily increase field limit before trimming efforts
|
2022-03-01 15:06:28 +00:00 |
|
Wes Lambert
|
dc07adca63
|
Rename ingest.timestamp to event.ingested
|
2022-03-01 15:05:08 +00:00 |
|