Doug Burks
e83afa3e30
Merge pull request #10660 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md
2023-06-26 08:33:22 -04:00
Doug Burks
70fb28a8b3
Update README.md
2023-06-26 08:31:41 -04:00
Josh Brower
8355432356
Merge pull request #10657 from Security-Onion-Solutions/2.4/policy-name-fix
...
2.4/policy name fix
2023-06-24 19:00:00 -04:00
Josh Brower
2247cafe5f
Change policy name
2023-06-24 17:13:28 -04:00
Josh Brower
85a8da6331
Change policy name
2023-06-24 16:58:36 -04:00
Josh Brower
ddabab253c
Merge pull request #10653 from Security-Onion-Solutions/2.4/heavynode
...
2.4/heavynode
2023-06-23 19:55:24 -04:00
Jason Ertel
2e42eddbc2
Merge pull request #10656 from Security-Onion-Solutions/jertel/fix-import
...
fix agent extract error during install; simplify logic
2023-06-23 17:21:39 -04:00
Jason Ertel
07a590dda8
fix agent extract error during install; simplify logic
2023-06-23 17:17:59 -04:00
Josh Brower
336a40d646
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-06-23 15:50:14 -04:00
Josh Brower
bb0cfc5253
Create & assign Heavy Node Fleet Policy
2023-06-23 15:49:03 -04:00
coreyogburn
106aaa9c3e
Merge pull request #10652 from Security-Onion-Solutions/cogburn/10122
...
FIX: Exclude System logs from Hunt/Dashboard Queries.
2023-06-23 13:48:17 -06:00
Corey Ogburn
fb27e7c479
Also add to dashboard
...
Duplicate new queryToggleFilter from hunt to dashboard.
2023-06-23 11:30:26 -06:00
Corey Ogburn
261acee8a0
New Hunt queryToggleFilter
...
New filter to exclude soc logs from hunt results.
2023-06-23 11:30:26 -06:00
Josh Brower
a9585b2a7f
Fix Elastic Agent for Heavy
2023-06-23 10:45:58 -04:00
Jason Ertel
d247c9d704
Merge pull request #10648 from Security-Onion-Solutions/jertel/fix-import
...
use cluster-unique password for import encryption
2023-06-23 09:40:26 -04:00
Jason Ertel
b21b545756
use cluster-unique password for import encryption
2023-06-23 09:37:41 -04:00
Jason Ertel
7623dd20b9
Merge pull request #10644 from Security-Onion-Solutions/cogburn/salt-relay-fix
...
WIP: Fix `salt cmd.run` commands for importing
2023-06-22 20:31:19 -04:00
Corey Ogburn
2b323ab661
Fix salt cmd.run commands for importing
...
Functional and easy to read.
2023-06-22 17:30:56 -06:00
Josh Brower
8de01625a8
Add Elastic Agent container for Heavy Nodes
2023-06-22 16:02:42 -04:00
Josh Brower
d0d7ab57ca
Add Elastic Agent container for Heavy Nodes
2023-06-22 16:02:17 -04:00
Jason Ertel
f4cbe20ddf
Merge pull request #10641 from Security-Onion-Solutions/jertel/fix-import
...
fix quotations
2023-06-22 14:46:41 -04:00
Jason Ertel
0d92a1594a
fix quotations
2023-06-22 14:41:39 -04:00
m0duspwnens
daaead618e
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/heavynode
2023-06-22 13:26:56 -04:00
m0duspwnens
19469205e1
include eval and import in so-elasticsearch-cluster-settings
2023-06-22 13:12:47 -04:00
Jason Ertel
cae9e6230f
Merge pull request #10638 from Security-Onion-Solutions/cogburn/import-fix
...
Change upload path
2023-06-22 13:04:22 -04:00
m0duspwnens
6c4c815683
change so-elasticsearch-cluster settings to include heavynode, and only run on managers
2023-06-22 13:04:20 -04:00
Corey Ogburn
6769386c86
Change upload path
2023-06-22 10:59:24 -06:00
m0duspwnens
36272efda7
create ES_LOGSTASH_NODES which removes heavynodes
2023-06-22 09:46:42 -04:00
weslambert
6b97d07a89
Merge pull request #10629 from Security-Onion-Solutions/fix/elasticsearch_ingest_suricata_xff_ip
...
Parse xff
2023-06-22 08:45:58 -04:00
coreyogburn
da82395dcf
Merge pull request #10633 from Security-Onion-Solutions/cogburn/10413
...
Cogburn/10413
2023-06-21 15:48:53 -06:00
Corey Ogburn
b5e5bd57ad
Fix for Upload Import
...
Needed to mount /nsm/soc/uploads into soc container.
Made the upload route configurable.
Added gpg logging to salt-relay.
2023-06-21 15:41:16 -06:00
Josh Patterson
ad4fb52b81
Merge pull request #10631 from Security-Onion-Solutions/2.4/repos
...
2.4/repos
2023-06-21 16:06:30 -04:00
m0duspwnens
4e849ecc90
issues with exclude rocky-repos
2023-06-21 15:14:53 -04:00
weslambert
7e37cd0f05
Parse xff
2023-06-21 14:29:54 -04:00
m0duspwnens
1675b787bf
exclude rocky-repos and remove files
2023-06-21 13:27:34 -04:00
Josh Brower
139b36b189
Merge pull request #10627 from Security-Onion-Solutions/2.4/import-evtx
...
Refactor EVTX Import
2023-06-21 11:42:10 -04:00
Josh Brower
6ddf887342
Refactor EVTX Import
2023-06-21 09:32:42 -04:00
Josh Brower
6ba9e057a9
Merge pull request #10600 from Security-Onion-Solutions/fix/dataset_tags
...
Change format of event dataset and assign dataset to tags
2023-06-21 09:22:40 -04:00
Mike Reeves
b02c38175c
Merge pull request #10624 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Salt Defunct Workaround
2023-06-20 17:44:53 -04:00
Mike Reeves
4497f6561f
Salt Defunct Workaround
...
This can be removed once they patch salt
2023-06-20 17:27:02 -04:00
coreyogburn
fb81c6e2e3
Merge pull request #10601 from Security-Onion-Solutions/cogburn/10413
...
Cogburn/10413
2023-06-20 11:08:53 -06:00
Corey Ogburn
ad28ea275f
Better state management
...
When salt-cp runs it's course and finds it can't send a file, it outputs a report saying as much but the exit code will be zero. Now we remove the filename and node from the response and look for `True` to know if it succeeded. Also, respect the cleanup flag on success or failure.
Check the status of the decryption process before importing.
No longer decrypt locally, issue salt command for the remote client to do the decrypting.
2023-06-20 09:41:14 -06:00
Corey Ogburn
41951659ec
Use importer's new --json flag.
...
Using the new --json flag is not only more reliable than using a regex, the way the import script was written even re-imports will provide a url. This means that in more cases we can provide the results to the users (even if nothing changed).
2023-06-20 09:41:14 -06:00
Corey Ogburn
451a4784a1
send-file and import-file security
...
Encrypt the file with a passphrase before sending and decrypt the file with the same passphrase before importing.
2023-06-20 09:41:14 -06:00
Corey Ogburn
1b7095fa81
Improved import-file url regex
...
sed doesn't remove ALL whitespace, only newlines. It's better to stop at the first whitespace than to stop at a particular, maybe-not-last query string parameter.
2023-06-20 09:41:14 -06:00
Corey Ogburn
89d789fe0f
New folder for salt to maintain
...
This folder is where a manager will initially store uploaded PCAP/EVTX files before sending to sensors. Sensors will store uploads in this folder on their own system.
2023-06-20 09:41:14 -06:00
Corey Ogburn
49055e260f
salt-relay import-file reporting
...
On successful import, return dashboard URL
2023-06-20 09:41:14 -06:00
Corey Ogburn
a465039887
2 new capabilities: send-file and import-file
2023-06-20 09:41:14 -06:00
Doug Burks
b60cf29598
Merge pull request #10618 from Security-Onion-Solutions/dougburks-patch-1
...
Resolve conflicts with dataset PR
2023-06-20 07:42:30 -04:00
Doug Burks
0e09d73aa0
Resolve conflicts with dataset PR
2023-06-20 07:40:10 -04:00