Doug Burks
|
19ab2a5a46
|
rename suricata vlan field to network.vlan.id
|
2023-03-05 05:57:52 -05:00 |
|
Doug Burks
|
9940a36722
|
update Elasticsearch ingest for Zeek conn vlan field
|
2023-03-03 15:22:43 -05:00 |
|
weslambert
|
134caa7f58
|
Various adjustments to descriptions
|
2023-02-28 16:31:16 -05:00 |
|
weslambert
|
acda03ce40
|
Add annotation settings for Elasticsearch's ILM feature, and remove various index keys
|
2023-02-10 14:57:11 -05:00 |
|
Wes
|
1255c60317
|
Move policy load script into Elasticsearch state script directory
|
2023-02-10 18:59:45 +00:00 |
|
Wes
|
994eabae1b
|
Manage policy loading in Elasticsearch state
|
2023-02-10 18:57:19 +00:00 |
|
Wes
|
c9118699a9
|
Add index management lifecycle policy defintion and reference in index template
|
2023-02-10 15:10:30 +00:00 |
|
m0duspwnens
|
a37f0fd0c0
|
rename sosbridge to sobridge
|
2023-02-03 10:07:07 -05:00 |
|
m0duspwnens
|
8cbafb52d8
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
|
2023-01-31 13:32:51 -05:00 |
|
m0duspwnens
|
e09a86dc30
|
2.4 searchnode es config
|
2023-01-31 10:54:40 -05:00 |
|
Doug Burks
|
a44d83d69b
|
Improve Suricata DHCP parsing and dashboard
|
2023-01-31 08:33:38 -05:00 |
|
weslambert
|
0436f885b8
|
Set values for '@timestamp' and 'event.ingested'
|
2023-01-31 08:04:49 -05:00 |
|
weslambert
|
2772b03dca
|
Change event.dataset value from 'tunnels' to 'tunnel'
|
2023-01-27 11:03:49 -05:00 |
|
weslambert
|
716ec7f936
|
Change event.dataset value from 'files' to 'file'
|
2023-01-27 11:02:44 -05:00 |
|
Wes
|
f1db1bc273
|
Ensure Kratos events are sent to a data stream instead of an index
|
2023-01-26 16:12:06 +00:00 |
|
weslambert
|
c9f458e1e2
|
Set event.dataset for all Kratos logs to 'access' for now
|
2023-01-25 08:19:50 -05:00 |
|
Wes
|
4b9c92c53d
|
Set RITA event.dataset value explicitly
|
2023-01-24 18:00:34 +00:00 |
|
Wes
|
f19cf75311
|
Change how event.dataset is determined for Suricata events
|
2023-01-24 14:45:00 +00:00 |
|
Wes
|
51692ac66c
|
Update index pattern in various template definitions to match new data stream naming convention
|
2023-01-23 21:52:44 +00:00 |
|
Wes
|
40c6b380df
|
Update Import and Zeek integration policies; also update Zeek ingest node pipelines to set event.dataset.
|
2023-01-23 21:44:46 +00:00 |
|
weslambert
|
7d3f6121eb
|
Remove default "logs-*" template settings for now
|
2023-01-19 10:29:10 -05:00 |
|
weslambert
|
7a499c9051
|
Modify default 'logs-*' template priority
|
2023-01-18 17:24:07 -05:00 |
|
weslambert
|
73a4dae28e
|
Make sure Elastic Agent data streams do not use replicas
|
2023-01-13 16:10:44 -05:00 |
|
Josh Patterson
|
3efca0010a
|
Merge pull request #9573 from Security-Onion-Solutions/2.4/firewall
2.4/firewall
|
2023-01-13 12:41:58 -05:00 |
|
m0duspwnens
|
6033e9a0de
|
use port_bindings from docker defaults in docker states
|
2023-01-13 10:15:10 -05:00 |
|
weslambert
|
7cba5626b7
|
Merge pull request #9570 from Security-Onion-Solutions/fix/elasticsearch_templates_elastic_agent
Change priority for Elastic Agent Elasticsearch index templates
|
2023-01-12 16:48:12 -05:00 |
|
weslambert
|
654d869e3e
|
Change priority from 500 to 200 for Elastic Agent index templates to avoid collisions with other templates
|
2023-01-12 16:46:08 -05:00 |
|
weslambert
|
fb8d8ea972
|
Update Elasticsearch index template for Kratos
|
2023-01-12 15:31:41 -05:00 |
|
weslambert
|
9416552338
|
Don't set the Kratos index explicitly
|
2023-01-12 15:25:35 -05:00 |
|
Wes
|
c3b83f1fc8
|
Update template settings to use data streams
|
2023-01-11 14:03:11 +00:00 |
|
Wes
|
5062dd2873
|
Suricata Elasticsearch ingest node pipeline changes - set 'alert' dataset
|
2023-01-11 14:02:09 +00:00 |
|
Wes
|
2e886d0c55
|
Remove data_index_name processor since we are using data streams
|
2023-01-11 13:58:38 +00:00 |
|
m0duspwnens
|
d4c6834cd0
|
merge with 2.4/dev
|
2023-01-06 14:01:58 -05:00 |
|
Wes
|
c8ff2c7a06
|
Update RITA beacon parsing
|
2023-01-03 16:03:49 +00:00 |
|
doug
|
4e5d1d587e
|
update sysmon ingest parser and Sysmon File dashboard
|
2023-01-03 09:02:17 -05:00 |
|
m0duspwnens
|
24876eecd9
|
change refs from sosnet to sosbridge
|
2022-12-22 14:02:40 -05:00 |
|
m0duspwnens
|
accc293c8a
|
2.4 firewall changes
|
2022-12-21 15:03:45 -05:00 |
|
weslambert
|
fd1be0ab2c
|
Remove 'so-' prefix for Elastic Agent/Fleet component templates
|
2022-12-19 10:11:26 -05:00 |
|
doug
|
07a4919cd3
|
remove old opcua files
|
2022-12-08 16:43:11 -05:00 |
|
Wes
|
14af1d36cb
|
Ensure ICS/SCADA pipelines are present
|
2022-12-06 15:58:47 +00:00 |
|
Wes
|
7f324bc47e
|
Remove extra space used during testing
|
2022-11-22 20:52:08 +00:00 |
|
Wes
|
a6bc5b108f
|
Add missing OPCUA 'activate_session' pipelines
|
2022-11-22 20:51:44 +00:00 |
|
m0duspwnens
|
b95a83b016
|
Merge remote-tracking branch 'remotes/origin/2.4/dev' into dockerips
|
2022-11-22 14:17:19 -05:00 |
|
weslambert
|
356904f751
|
Fix spelling of 'wireguard.responses' field name
|
2022-11-22 13:03:04 -05:00 |
|
weslambert
|
6b77843e52
|
Fix format/speliing for 'enip.status_code' field name
|
2022-11-22 12:07:55 -05:00 |
|
weslambert
|
13faf63770
|
Fix spelling for 'stun.class' field name
|
2022-11-22 12:07:15 -05:00 |
|
Wes
|
a38e312df4
|
Add COTP and TDS ingest pipelines
|
2022-11-22 13:36:27 +00:00 |
|
Wes
|
05b9a067fd
|
Add additional ICS/SCADA ingest node pipelines
|
2022-11-17 16:03:21 +00:00 |
|
Wes
|
638a3568b0
|
Update ingest node pipelines for ICS/SCADA protocols
|
2022-11-16 21:11:21 +00:00 |
|
Mike Reeves
|
6016b0e38a
|
Add dynamic ability for IP range for sosnet
|
2022-11-14 20:20:38 -05:00 |
|