Mike Reeves
bafb13fd6d
Merge pull request #1363 from Security-Onion-Solutions/dev
...
RC3
2020-09-17 15:05:33 -04:00
Mike Reeves
56e9f09c20
Update VERIFY_ISO.md
2020-09-17 11:02:16 -04:00
Mike Reeves
6cd30ce52f
Update Sig
2020-09-17 10:56:29 -04:00
Mike Reeves
3fb98bfd4d
Update VERIFY_ISO.md
2020-09-17 10:54:18 -04:00
Mike Reeves
4701091f76
Update VERIFY_ISO.md
2020-09-17 10:54:01 -04:00
Doug Burks
57e45308af
Fix pivot from TheHive to Kibana #1362
2020-09-17 08:05:55 -04:00
Doug Burks
c9c1245d1e
change from 2.1 RC2 to 2.2 RC3
2020-09-17 08:01:10 -04:00
Mike Reeves
7415c7fe81
Fix dashboard script
2020-09-16 14:55:32 -04:00
Mike Reeves
eac58f8f34
Merge pull request #1346 from Security-Onion-Solutions/rc3upgrade
...
Rc3upgrade
2020-09-16 14:29:53 -04:00
Mike Reeves
52072e0484
Update soup
2020-09-16 14:08:48 -04:00
doug
840b54d73c
make so-analyst executable
2020-09-16 13:11:49 -04:00
Mike Reeves
5910fe642c
Fix Update XML
2020-09-16 13:08:21 -04:00
Mike Reeves
a0f64440e0
Update changes.json
2020-09-16 13:06:26 -04:00
weslambert
74e4adda11
Merge pull request #1357 from Security-Onion-Solutions/feature/dashboard_updates_2
...
Add All Logs for Connections dashboard
2020-09-16 11:56:38 -04:00
Wes Lambert
44ef935d65
Add All Logs for Connections dashboard
2020-09-16 15:55:28 +00:00
Mike Reeves
3e0e41be32
Update changes.json
2020-09-16 11:41:21 -04:00
Mike Reeves
1801361cf8
Update changes.json
2020-09-16 11:40:05 -04:00
weslambert
6325b30a21
Merge pull request #1356 from Security-Onion-Solutions/feature/dashboard_updates
...
Kibana dashboard updates
2020-09-16 11:19:27 -04:00
Wes Lambert
bd8d2fc271
Kibana dashboard updates
2020-09-16 15:17:26 +00:00
Josh Patterson
6e0806a587
Merge pull request #1353 from Security-Onion-Solutions/fix/strelkaconfig
...
fix sensor mainip logic for strelka yaml files
2020-09-16 10:32:58 -04:00
m0duspwnens
4ee3e1ed01
fix sensor mainip logic for strelka yaml files
2020-09-16 10:29:23 -04:00
Josh Patterson
b7e41b53cb
Merge pull request #1352 from Security-Onion-Solutions/fix/es_templates
...
fix MYIP
2020-09-16 10:12:27 -04:00
m0duspwnens
3fe276dbb5
fix MYIP
2020-09-16 10:11:39 -04:00
Josh Patterson
66f21c4568
Merge pull request #1350 from Security-Onion-Solutions/fix/es_templates
...
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:54:16 -04:00
Josh Brower
d5fd15962c
Merge pull request #1351 from Security-Onion-Solutions/bugfix/tcpreplay
...
Fix so-test
2020-09-16 09:52:08 -04:00
Josh Brower
dd2d736bc1
Fix so-test
2020-09-16 09:51:38 -04:00
m0duspwnens
dd56d7d2d1
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:48:38 -04:00
weslambert
6806bd2461
Merge pull request #1348 from Security-Onion-Solutions/bugfix/es_template_load
...
Ensure templates are loaded for heavy nodes
2020-09-15 17:15:56 -04:00
weslambert
fbf037f460
Ensure templates are loaded for heavy nodes
2020-09-15 17:14:06 -04:00
Josh Brower
46a1369e81
Merge pull request #1347 from Security-Onion-Solutions/bugfix/tcpreplay
...
Add so-test
2020-09-15 13:20:56 -04:00
Josh Brower
2516429834
Add so-test
2020-09-15 13:14:00 -04:00
Mike Reeves
fc8ffd2080
Made the version update more reliable
2020-09-15 11:09:01 -04:00
Mike Reeves
ee4b35f2e4
Rename zeekversion.map.jinja to mdengine.map.jinja
2020-09-14 22:30:10 -04:00
Mike Reeves
c31d998061
Disk Space Check Final Final Final
2020-09-14 20:17:28 -04:00
Mike Reeves
62a8e676d9
Disk Space Check Final Final
2020-09-14 20:11:04 -04:00
Mike Reeves
9ef2b93586
Disk Space Check Final Final
2020-09-14 20:09:53 -04:00
Mike Reeves
eafb4e81a5
Disk Space Check Final Final
2020-09-14 20:01:53 -04:00
Mike Reeves
6eb3333af4
Disk Space Check Final
2020-09-14 19:46:16 -04:00
Mike Reeves
07e536df98
Disk Space Check
2020-09-14 19:42:58 -04:00
Mike Reeves
e8d2a6fdc2
Disk Space Check
2020-09-14 19:32:14 -04:00
Mike Reeves
1bc5e33007
Rotate Mysql Container Log
2020-09-14 16:27:32 -04:00
Mike Reeves
e2ecfca4c1
Merge pull request #1343 from Security-Onion-Solutions/rc3upgrade
...
Upgrade Fun
2020-09-14 14:54:37 -04:00
Mike Reeves
0a0e00866c
Upgrade Fun
2020-09-14 14:50:22 -04:00
Mike Reeves
38266f7db8
Merge pull request #1342 from Security-Onion-Solutions/experimental
...
Fix ruleupdate setting
2020-09-14 14:26:31 -04:00
Mike Reeves
9957fdec0f
Fix ruleupdate setting
2020-09-14 14:17:55 -04:00
Josh Patterson
32632864eb
Merge pull request #1341 from Security-Onion-Solutions/issue/1066
...
change how we determine how to run so-status
2020-09-14 12:43:05 -04:00
m0duspwnens
b559e5dd32
change how we determine how to run so-status
2020-09-14 12:40:39 -04:00
Jason Ertel
f86780a0db
Open PCAPs in same tab, but open external sites in new tabs
2020-09-14 10:41:39 -04:00
Mike Reeves
1958fef4ad
Merge pull request #1338 from Security-Onion-Solutions/experimental
...
Fix strelka rules
2020-09-14 09:58:34 -04:00
Mike Reeves
ee1317adf1
Merge branch 'experimental' of https://github.com/Security-Onion-Solutions/securityonion into experimental
2020-09-14 09:57:14 -04:00
Mike Reeves
d1836fb3a3
Fix Salt issue with script
2020-09-14 09:57:08 -04:00
Josh Patterson
67c1ece0bb
Merge pull request #1337 from Security-Onion-Solutions/issue/1066
...
Issue/1066
2020-09-14 09:38:15 -04:00
m0duspwnens
b93d149631
fix so-status
2020-09-14 09:36:26 -04:00
m0duspwnens
46cbcfa330
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1066
2020-09-14 08:45:54 -04:00
Mike Reeves
841db1b4b9
Merge pull request #1336 from Security-Onion-Solutions/experimental
...
Get Rules onto the install for airgap
2020-09-13 14:58:36 -04:00
Mike Reeves
112a0b426e
Merge branch 'dev' into experimental
2020-09-13 14:54:00 -04:00
Doug Burks
18dc7a915a
Hunt: Fix Tunnel query #1335
2020-09-13 08:26:33 -04:00
Jason Ertel
89c38541ee
Force all SOC quick actions to open in new tab
2020-09-13 02:52:25 -04:00
Mike Reeves
d6d22fb0e0
Fix Strelka
2020-09-12 23:07:35 -04:00
Mike Reeves
bb936c5bee
Fix Strelka
2020-09-12 23:07:15 -04:00
Mike Reeves
259df2ed6b
Fix Strelka
2020-09-12 23:06:06 -04:00
Doug Burks
311d67b934
Hunt: fix RFB groupby #1332
2020-09-12 06:14:58 -04:00
Josh Patterson
f03b128924
Merge pull request #1331 from Security-Onion-Solutions/fix/top
...
add redis to eval if playbook enabled
2020-09-11 18:31:19 -04:00
m0duspwnens
5f567368be
add redis to eval if playbook enabled
2020-09-11 18:30:21 -04:00
m0duspwnens
77911acfb4
so-status module
2020-09-11 18:28:53 -04:00
Mike Reeves
48d1d0c168
Strelkas Rules Update
2020-09-11 18:24:56 -04:00
Josh Patterson
2d508d9e57
Merge pull request #1328 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-11 15:02:30 -04:00
m0duspwnens
15563f2ee6
add nginx to top for sensor
2020-09-11 12:28:42 -04:00
m0duspwnens
bb0e686444
add elasticsearch to top for nodes missing it
2020-09-11 11:35:17 -04:00
Mike Reeves
46866f40b3
Merge pull request #1325 from Security-Onion-Solutions/experimental
...
Update Script
2020-09-11 11:02:57 -04:00
Mike Reeves
6e0cdf7be4
Update Script help
2020-09-11 11:01:56 -04:00
m0duspwnens
5f7c270984
only allow strelka to run on nodes that are sensors
2020-09-11 10:22:12 -04:00
Mike Reeves
af9a19b6e8
Merge pull request #1321 from Security-Onion-Solutions/experimental
...
IDS Tools now with Airgap support
2020-09-10 19:05:16 -04:00
Mike Reeves
53319738c4
Fix Nginx state
2020-09-10 16:56:48 -04:00
Mike Reeves
ef46094b0c
Update all nginx configs
2020-09-10 13:55:56 -04:00
Josh Patterson
53ff87b0ee
Merge pull request #1312 from Security-Onion-Solutions/issue/1281
...
add elasticsearch state to top for manager node
2020-09-10 12:47:05 -04:00
m0duspwnens
bc420d4a02
add
2020-09-10 11:57:15 -04:00
Josh Patterson
ca26548b2c
Merge pull request #1310 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-10 10:08:25 -04:00
m0duspwnens
0ed9c65646
remove logic from fleet state to only run if in top
2020-09-10 10:07:05 -04:00
Doug Burks
8c280221da
Hunt: Fix Intel groupby #1131
2020-09-10 07:00:54 -04:00
Doug Burks
24c325e9a1
Fix Elasticsearch parsing for Zeek Intel Indicator #1309
2020-09-10 06:41:19 -04:00
Josh Brower
56587f0df5
Merge pull request #1308 from Security-Onion-Solutions/feature/wel-ingest
...
Add event.category to WEL
2020-09-10 06:16:56 -04:00
Josh Brower
c3b2d98ffb
Add event.category to WEL
2020-09-10 06:15:30 -04:00
Doug Burks
7161a662aa
improve Wazuh support in Hunt
2020-09-10 06:03:33 -04:00
Mike Reeves
5d4e8925a3
Add Firewall Logic
2020-09-09 21:16:40 -04:00
Mike Reeves
45b11b2321
Fix Rulecat
2020-09-09 18:38:07 -04:00
Doug Burks
d18c498574
Update so-features-enable
2020-09-09 17:32:42 -04:00
m0duspwnens
09cc8ae1fb
fail the state if it isnt in top
2020-09-09 16:48:50 -04:00
m0duspwnens
01c9f7b2ae
merge with dev and resolve conflicts
2020-09-09 16:23:36 -04:00
Mike Reeves
7ebf93fcb5
IDSTools Overhaul
2020-09-09 15:53:32 -04:00
Josh Patterson
1e32b32659
Merge pull request #1302 from Security-Onion-Solutions/fix/sostatus
...
Fix/sostatus
2020-09-09 15:07:12 -04:00
m0duspwnens
39f200f565
fix whitespace
2020-09-09 14:59:21 -04:00
Mike Reeves
a77532c1d8
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 14:57:17 -04:00
Mike Reeves
04f4539385
Fix Airgap Repo Name
2020-09-09 14:57:10 -04:00
m0duspwnens
b0c526364f
handle strelka
2020-09-09 14:55:54 -04:00
m0duspwnens
921262b9a5
prevent duplicate containers for so-stauts
2020-09-09 14:07:38 -04:00
Jason Ertel
a5b87850df
Remove user sync between SOC and Cortex due to the unnecesary complexities involved with this style of integration
2020-09-09 14:07:36 -04:00
m0duspwnens
05d736d2df
handle strelka
2020-09-09 14:00:58 -04:00
m0duspwnens
918d9cf00f
handle strelka
2020-09-09 13:57:53 -04:00
m0duspwnens
3433b90029
fix so-status for strelka and wazuh
2020-09-09 13:53:10 -04:00
Doug Burks
82b582540e
Add period
2020-09-09 12:56:19 -04:00
Doug Burks
90ba1be978
Improve formatting of NIDS selection screen
2020-09-09 12:55:14 -04:00
m0duspwnens
e84507c386
Merge remote-tracking branch 'remotes/origin/dev' into fix/sostatus
2020-09-09 12:51:01 -04:00
m0duspwnens
9ee9a199b1
predefine each component as 0 to fix issues with it being unset
2020-09-09 12:50:22 -04:00
Jason Ertel
fc4ad1d556
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:22:38 -04:00
Jason Ertel
9babc445ce
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:07:23 -04:00
Mike Reeves
90feb503ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 10:54:53 -04:00
Mike Reeves
426257443a
Final airgap tweaks
2020-09-09 10:54:47 -04:00
Doug Burks
eaf3281ab7
Remove Suricata version numbers from Setup screens #1300
...
https://github.com/Security-Onion-Solutions/securityonion/issues/1300
2020-09-09 10:43:41 -04:00
Josh Patterson
c2398f966b
Merge pull request #1295 from Security-Onion-Solutions/fix/salt-ca-ssl
...
Fix/salt ca ssl
2020-09-09 10:36:54 -04:00
m0duspwnens
7facff2b7d
change from cmd.run to cp.get_file_str
2020-09-09 10:34:53 -04:00
Jason Ertel
ad05e75ce7
Add new quick actions to SOC config template
2020-09-09 00:46:23 -04:00
Mike Reeves
7d524a0723
Add Firewall Rule for yum and airgap
2020-09-08 18:51:14 -04:00
Josh Patterson
d7016b4557
Merge pull request #1298 from Security-Onion-Solutions/issue/1291
...
Issue/1291
2020-09-08 17:40:33 -04:00
m0duspwnens
da34222931
makedirs
2020-09-08 17:36:27 -04:00
m0duspwnens
eeb6c3128b
add salt.master state to manager nodes
2020-09-08 17:27:13 -04:00
m0duspwnens
da3d0948b4
creating engine to watch the health of the salt mine
2020-09-08 16:49:38 -04:00
Jason Ertel
710a2be422
Add new so-user-enable script and change so-user-disable to call 'so-user disable' instead of deleting the SOC user
2020-09-08 16:24:18 -04:00
Mike Reeves
7c41c31359
Fix airgap statement
2020-09-08 14:48:37 -04:00
Mike Reeves
7371f9236e
Update top.sls
2020-09-08 14:18:56 -04:00
Mike Reeves
1aea3f4f85
Merge pull request #1297 from Security-Onion-Solutions/experimental
...
Add Airgap code
2020-09-08 09:26:41 -04:00
Doug Burks
f8ebed43d7
fix spacing
2020-09-07 04:45:26 -04:00
Doug Burks
f5916e26a2
read ca.crt from filesystem when possible
2020-09-07 04:42:11 -04:00
weslambert
b6b52671e2
Merge pull request #1294 from Security-Onion-Solutions/fix/wazuh_agent_name
...
Fix typo
2020-09-05 08:17:09 -04:00
Wes Lambert
f9884606df
Fix typo
2020-09-05 12:15:55 +00:00
Jason Ertel
f27e5164d0
Update to latest kratos; add support for a custom status trait to represent whether a user is locked or not; refactor so-user to use new enable/disable capabilities in SOC; remove 'delete' option from so-user usage to avoid having user lists out of sync across SOC and external apps
2020-09-04 17:01:52 -04:00
Josh Brower
351e7761ef
Merge pull request #1292 from Security-Onion-Solutions/bugfix/playbook-rulesets
...
Update SOCtopus.conf
2020-09-04 14:15:18 -04:00
Josh Brower
39cc7151a5
Update SOCtopus.conf
2020-09-04 14:14:53 -04:00
Doug Burks
f8e68c82e4
downgrade to Mono 4.2.1.102 and NetworkMiner 2.4
2020-09-04 10:12:28 -04:00
Doug Burks
c050003b5a
Install file-roller for opening zip files
2020-09-04 07:14:01 -04:00
Doug Burks
a2265fac4f
NetworkMiner has a compatibility issue with Mono 6 right now
2020-09-04 06:50:22 -04:00
Doug Burks
1fc64d3eef
so-analyst should install gedit
2020-09-03 16:46:14 -04:00
Josh Patterson
c71a154e81
Merge pull request #1288 from Security-Onion-Solutions/quickfix/standalonetop
...
add elasticsearch to standalone top
2020-09-03 15:55:43 -04:00
m0duspwnens
05b8b71af2
add elasticsearch to standalone top
2020-09-03 15:54:24 -04:00
Mike Reeves
b2ee757db2
Airgap Time
2020-09-03 10:35:12 -04:00
weslambert
b10dd40376
Merge pull request #1287 from Security-Onion-Solutions/fix/suri_home_net
...
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:51 -04:00
weslambert
8db8dcb71a
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:14 -04:00
m0duspwnens
770cd6eafc
add endif
2020-09-02 16:19:58 -04:00
Mike Reeves
9745191f19
Add Airgap State
2020-09-02 16:17:44 -04:00
m0duspwnens
a229ae82ce
only allow state to run if it is in top for the node
2020-09-02 16:15:52 -04:00
weslambert
870e042c4c
Merge pull request #1285 from Security-Onion-Solutions/fix/so_stop_start_restart
...
Require at least one arg for start/stop/restart scripts
2020-09-02 14:58:19 -04:00
Wes Lambert
770aaf415c
Require at least on arg for start/stop/restart scripts
2020-09-02 18:55:59 +00:00
Jason Ertel
0142f43493
Add so-user-disable script which deletes the SOC user and disables the users in Fleet, TheHive, and Cortex
2020-09-02 13:54:50 -04:00
m0duspwnens
9d85b3223f
fix note about localrules
2020-09-02 11:46:48 -04:00
Josh Patterson
066c795e71
Merge pull request #1279 from Security-Onion-Solutions/fix/redhat
...
move redhat with centos
2020-09-02 09:12:44 -04:00
m0duspwnens
1f8f197066
move redhat with centos
2020-09-02 09:12:05 -04:00
weslambert
d35cca7fc5
Merge pull request #1278 from Security-Onion-Solutions/fix/elastalert_extra_hosts
...
Add manager to hosts file
2020-09-02 07:44:49 -04:00
weslambert
5d920885e0
Add manager to hosts file
2020-09-02 07:43:55 -04:00
Josh Patterson
7fa083069d
Merge pull request #1277 from Security-Onion-Solutions/issue/968
...
Issue/968
2020-09-01 15:43:22 -04:00
m0duspwnens
08ca2055dc
fix telegraf file input for zeek log
2020-09-01 15:34:06 -04:00
m0duspwnens
93f30a2064
fix telegraf config
2020-09-01 15:29:29 -04:00
m0duspwnens
b13b07eddf
add newline to end
2020-09-01 15:10:56 -04:00
m0duspwnens
01777c64d9
fix influxtime
2020-09-01 14:58:48 -04:00
m0duspwnens
b6d66bddfc
add redis to proper node types. grafana dahsboard changes. change zeek_restart to not use telegraf socket but read from file instead
2020-09-01 14:38:10 -04:00
Josh Brower
6cd0d16b91
Merge pull request #1276 from Security-Onion-Solutions/feature/import-wel
...
Initial support for evtx import
2020-09-01 13:48:12 -04:00
Josh Brower
a79d0319cd
Initial support for evtx import
2020-09-01 13:47:27 -04:00
Mike Reeves
951fe2ac69
Create repo
2020-09-01 11:26:33 -04:00
Mike Reeves
9cff7c1427
Enable airgap functions
2020-09-01 11:24:22 -04:00
Mike Reeves
643dab12d0
Enable airgap
2020-09-01 11:09:33 -04:00
Josh Patterson
67766745a4
Merge pull request #1275 from Security-Onion-Solutions/fix/redhat
...
resolve issue with salt state if os is redhat
2020-09-01 10:44:59 -04:00
m0duspwnens
2fee151bff
resolve issue with salt state if os is redhat
2020-09-01 10:43:21 -04:00
m0duspwnens
ada1c81ab7
manager and standalone dashboard changes
2020-09-01 10:40:20 -04:00
Jason Ertel
ff5d1cd815
Expand nginx body size limit to 2.5GB to handle 2G PCAPs from sensors
2020-09-01 10:07:28 -04:00
Doug Burks
45c0a7ac77
Kernel messages can overwrite whiptail screen #812
...
Kernel messages can overwrite whiptail screen #812
2020-09-01 08:55:34 -04:00
m0duspwnens
a1a7b36319
merge with dev and resolve conflict
2020-08-31 16:05:34 -04:00
m0duspwnens
31f25eca57
fix grafana related issues. add redis to standalone
2020-08-31 15:56:58 -04:00
weslambert
011958a2f3
Merge pull request #1274 from Security-Onion-Solutions/fix/zeek_syslog
...
Ensure Zeek syslog log is enabled for Import node
2020-08-31 13:08:44 -04:00
Wes Lambert
ae3fe9e892
Ensure Zeek syslog log is enabled for Import node
2020-08-31 17:07:16 +00:00
weslambert
96f25914db
Merge pull request #1273 from Security-Onion-Solutions/fix/zeek_syslog_default
...
Fix/zeek syslog default
2020-08-31 12:32:52 -04:00
Wes Lambert
5ed5e6603d
Fix space
2020-08-31 16:32:12 +00:00
Wes Lambert
26ffc44fd1
Only enable syslog log by default in Eval mode
2020-08-31 16:30:32 +00:00
Jason Ertel
dc3b065a41
Set exec bit on new user-add scripts
2020-08-31 10:57:23 -04:00
weslambert
6350c83e05
Merge pull request #1272 from Security-Onion-Solutions/feature/wazuh_mgmt_wrappers
...
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 10:55:25 -04:00
Wes Lambert
46e7e121e3
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 14:54:24 +00:00
weslambert
5db70cbd59
Merge pull request #1271 from Security-Onion-Solutions/fix/remove_minio
...
Remove minio for now
2020-08-31 10:29:30 -04:00
Wes Lambert
6d14f2af96
Remove minio for now
2020-08-31 14:07:47 +00:00
weslambert
42bd75a1cc
Merge pull request #1270 from Security-Onion-Solutions/fix/elastalert_startup
...
Wait for Elasticsearch indices to be queryable before starting Elasta…
2020-08-31 09:56:18 -04:00
Wes Lambert
9abbda8e04
Wait for Elasticsearch indices to be queryable before starting Elastalert container
2020-08-31 13:54:49 +00:00
Jason Ertel
189c02648d
Move container status check to so-common
2020-08-31 09:52:06 -04:00
Jason Ertel
8e06f0453e
Only add users to aux systems if those systems are currently running
2020-08-31 09:41:06 -04:00
Doug Burks
9680270b20
Set default monospace font to Liberation
2020-08-30 16:42:44 -04:00
Doug Burks
2f09156a02
quote filename when spawning NetworkMiner
2020-08-30 16:10:47 -04:00
Doug Burks
77b3ebdabe
Hunt Events table should show ssl.server_name when searching for ssl
...
Hunt Events table should show ssl.server_name when searching for ssl #1267
2020-08-30 06:56:15 -04:00
Doug Burks
13ce439678
Update README
2020-08-29 06:52:26 -04:00
Doug Burks
df5ef7c956
Update so-analyst
2020-08-29 06:07:58 -04:00
Doug Burks
1e1212bf41
Update so-analyst
2020-08-29 05:59:21 -04:00
Doug Burks
c20f47ffd6
make chaosreader executable
2020-08-29 04:52:21 -04:00
Doug Burks
c21b347549
Update README
2020-08-29 04:46:00 -04:00
Doug Burks
f6f990ca9f
Update README
2020-08-28 16:44:41 -04:00
Doug Burks
8344e38d91
Add files via upload
2020-08-28 16:43:28 -04:00
Josh Brower
764ba4a0e9
Merge pull request #1266 from Security-Onion-Solutions/bugfix/event.code-parsing
...
Set event.code to string for WEL
2020-08-28 13:49:01 -04:00
Josh Brower
b7dd14b8f0
Set event.code to string for WEL
2020-08-28 13:40:04 -04:00
Jason Ertel
3877706f20
Remove auto-start regardless of how setup was started
2020-08-28 09:10:35 -04:00
Jason Ertel
4e3e83820f
Correct pillar key for thehive
2020-08-28 08:17:42 -04:00
Josh Patterson
f4dc67e32a
Merge pull request #1264 from Security-Onion-Solutions/issue/1063
...
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:25:26 -04:00
m0duspwnens
b1e7ffc173
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:24:26 -04:00
Jason Ertel
a3e34bfaca
Add users to Fleet, TheHive, and Cortex when adding a user to SO via so-user-add command
2020-08-27 16:58:02 -04:00
Josh Patterson
9d30b58247
Merge pull request #1262 from Security-Onion-Solutions/issue/643
...
remove space
2020-08-27 15:09:05 -04:00
m0duspwnens
aa60ec8e5a
remove space
2020-08-27 15:07:45 -04:00
Josh Patterson
2559f740f1
Merge pull request #1260 from Security-Onion-Solutions/issue/643
...
Issue/643
2020-08-27 14:35:39 -04:00
m0duspwnens
dbb1390c42
move README to /
2020-08-27 14:32:51 -04:00
Mike Reeves
2b0b695ee4
Fix duplicate docker
2020-08-27 10:15:22 -04:00
Mike Reeves
dc6c0cc71c
Merge pull request #1259 from Security-Onion-Solutions/issue/286
...
Issue/286
2020-08-27 10:13:17 -04:00
m0duspwnens
e9b7538ee8
fix a couple things, add another package
2020-08-26 17:58:27 -04:00
m0duspwnens
16c3b9539b
fix a couple things, add another package
2020-08-26 17:51:04 -04:00
m0duspwnens
cc88c4c35f
adding so-analyst script to create analyst workstatin
2020-08-26 17:39:11 -04:00
weslambert
509985ed07
Merge pull request #1254 from Security-Onion-Solutions/fix/sensor_clean
...
Cron updates
2020-08-26 11:03:03 -04:00
weslambert
000c2abb33
Update timing for so-yara-update
2020-08-26 11:02:33 -04:00
Mike Reeves
19130b563d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/286
2020-08-26 11:01:01 -04:00
Mike Reeves
e1a52a4921
Update core counts if heavy node or SA
2020-08-26 11:00:23 -04:00
Mike Reeves
86584d90d7
Merge pull request #1253 from Security-Onion-Solutions/issue/1078
...
Issue/1078 Update Docker
2020-08-26 10:36:34 -04:00
Mike Reeves
e993397173
Update docker to latest version
2020-08-26 10:35:17 -04:00
Josh Brower
c38f4ad4ae
Merge pull request #1251 from Security-Onion-Solutions/feature/fleet3.1
...
Upgraded to Fleet 3.1
2020-08-26 06:14:34 -04:00
Josh Brower
67e0a219e6
Upgraded to Fleet 3.1
2020-08-26 06:13:45 -04:00
Josh Brower
b6ebcf6551
Merge pull request #1250 from Security-Onion-Solutions/feature/es-security-field
...
Adds new .security analyzed subfield
2020-08-26 05:12:23 -04:00
Josh Brower
1cf7301db4
Adds new .security analyzed subfield
2020-08-26 05:11:42 -04:00
Jason Ertel
3122280bd5
Update version to 2.2.0-rc.3
2020-08-25 15:16:09 -04:00
weslambert
ce49e050bc
Update timing for sensor clean cron
2020-08-25 12:14:43 -04:00
weslambert
61cc5b9712
Merge pull request #1246 from Security-Onion-Solutions/fix/sensor_clean_log
...
Fix/sensor clean log
2020-08-25 11:36:10 -04:00
Wes Lambert
c03812f7ab
Add rotation for sensor_clean log
2020-08-25 15:34:30 +00:00
weslambert
a8f727ad40
Don't write to log if not past CRIT_DISK_USAGE
2020-08-25 11:19:36 -04:00
Mike Reeves
6c5f8f7d53
Merge pull request #1240 from Security-Onion-Solutions/issue/1225
...
Remove duplicate IDSTools entries
2020-08-24 10:41:18 -04:00
Mike Reeves
52602f527e
Merge pull request #1238 from Security-Onion-Solutions/issue/796
...
Add /usr/sbin to the path
2020-08-24 10:39:29 -04:00
Mike Reeves
bc6eb74af2
Merge pull request #1230 from Security-Onion-Solutions/dev
...
2.1.0
2020-08-24 10:25:28 -04:00
Doug Burks
b627f565c9
Update VERIFY_ISO.md
2020-08-24 10:03:28 -04:00
Doug Burks
a0281830f8
Update VERIFY_ISO.md
2020-08-24 06:09:30 -04:00
Mike Reeves
aa3e3c3cec
Update Sig
2020-08-23 20:25:06 -04:00
Mike Reeves
e8568dbeb0
Update VERIFY_ISO.md
2020-08-23 20:23:49 -04:00
Mike Reeves
a97ca94354
Rotate suri stats log hourly
2020-08-23 16:08:17 -04:00
Mike Reeves
ebd8105cb5
Rotate suri stats log hourly
2020-08-23 16:03:37 -04:00
Mike Reeves
02712e7f46
Add /usr/sbin to the path
2020-08-22 11:07:00 -04:00
Mike Reeves
093819b0c7
Remove duplicate IDSTools entries
2020-08-22 10:32:11 -04:00
Doug Burks
daaa2d3579
Update README.md
2020-08-21 16:24:09 -04:00
Mike Reeves
3ea5bd0c53
Update MD5 and gpg info for new iso
2020-08-21 14:44:12 -04:00
Mike Reeves
64d34e46bf
Update ISO signature
2020-08-21 14:31:04 -04:00
Jason Ertel
9c6cc81f70
Remove improper suricata logging filter - this re-enables logging output for the suricata process itself
2020-08-21 12:44:28 -04:00
Mike Reeves
bdb8f616e4
Update VERIFY_ISO.md
2020-08-21 09:08:44 -04:00
Mike Reeves
60fbe357c5
Merge branch 'master' into dev
2020-08-20 21:10:59 -04:00
Mike Reeves
d0eae47047
Update ISO download details and signature
2020-08-20 21:08:17 -04:00
Mike Reeves
05d727e599
Final changes.json update
2020-08-20 19:18:39 -04:00
Mike Reeves
2b88f22eb2
Make HUP for rotate more reliable
2020-08-20 17:57:36 -04:00
Mike Reeves
69b3de43b9
Merge pull request #1229 from Security-Onion-Solutions/fix/statslog
...
add logrotate
2020-08-20 16:53:23 -04:00
Mike Reeves
b7da768dc7
add logrotate
2020-08-20 16:46:32 -04:00
Josh Patterson
44093e7484
Merge pull request #1228 from Security-Onion-Solutions/quickfix/importnode
...
remove bonding for import node
2020-08-20 14:23:21 -04:00
m0duspwnens
a7a0520cfe
remove bonding for import node
2020-08-20 14:20:09 -04:00
Jason Ertel
d1e5649a68
Corrected JSON typo and improved formatting
2020-08-20 13:46:20 -04:00
Mike Reeves
b7d1fd54c7
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-08-20 13:26:22 -04:00
Mike Reeves
3eea2c6b10
2.1.0 Release notes in changes.json
2020-08-20 13:26:14 -04:00
Jason Ertel
377c841c31
Switch back to direct command for removing setup from bash_profile due to how sed is interpreting the quoted expression
2020-08-20 13:11:57 -04:00
Mike Reeves
073a175939
Merge pull request #1224 from Security-Onion-Solutions/fix/mkrssl
...
Point logstash to use intca.crt
2020-08-20 10:52:28 -04:00
Mike Reeves
df95baa835
Point logstash to use intca.crt
2020-08-20 10:45:48 -04:00
weslambert
12a9d26231
Merge pull request #1223 from Security-Onion-Solutions/fix/aws_fwd_defaults
...
Add defaults file for fwdnode
2020-08-20 10:17:21 -04:00
Wes Lambert
3f04e566f2
Add defaults file for fwdnode
2020-08-20 14:16:05 +00:00
Jason Ertel
896bf6b78c
Update doc links to 2.1
2020-08-20 10:08:10 -04:00
Jason Ertel
22c9180386
Improve redirection of setup command output to log file, including stderr
2020-08-20 10:04:01 -04:00
Josh Patterson
014a0054c2
Merge pull request #1221 from Security-Onion-Solutions/quickfix/managersearch
...
remove monint from managersearch since they dont have a monint
2020-08-20 09:06:30 -04:00
m0duspwnens
43f4ebbcf1
remove monint from managersearch since they dont have a monint
2020-08-20 09:05:38 -04:00
Mike Reeves
2fce138d95
Change it to grains.host instead of grains.id
2020-08-19 21:26:27 -04:00
Mike Reeves
ccc2ed4478
don't create symlinks if a heavy node
2020-08-19 21:18:57 -04:00
Mike Reeves
f9e5ea8ba7
Fix SSL for filebeat
2020-08-19 21:12:41 -04:00
Mike Reeves
f7d3dca322
Fix duplicate state
2020-08-19 21:00:28 -04:00
Mike Reeves
d969b1e1b7
Update init.sls
2020-08-19 20:56:08 -04:00
Mike Reeves
507a3e852c
Update init.sls
2020-08-19 20:02:38 -04:00
Mike Reeves
5f41d9fc25
fix filebeat certs
2020-08-19 19:51:57 -04:00
Mike Reeves
8312221c82
Update soup
2020-08-19 18:51:32 -04:00
Mike Reeves
0439cf3205
Update soup
2020-08-19 18:47:36 -04:00
Jason Ertel
2325940789
Ensure strelka manager connects to local redis on heavy nodes
2020-08-19 16:24:28 -04:00
Josh Patterson
9fce1fc47d
Merge pull request #1220 from Security-Onion-Solutions/issue/1188
...
Issue/1188
2020-08-19 16:15:43 -04:00
Jason Ertel
5ff0058a65
Ensure strelka backend, frontend, and filestream are connecting to redis locally, on heavy node instances
2020-08-19 16:13:18 -04:00
m0duspwnens
961cc67e3f
add nginx state to heavynode
2020-08-19 16:05:40 -04:00
Mike Reeves
51a52228ac
Update init.sls
2020-08-19 16:01:58 -04:00
Mike Reeves
4527758e87
Update init.sls
2020-08-19 16:00:04 -04:00
m0duspwnens
826254bc3d
give redis key to heavy node too
2020-08-19 15:59:48 -04:00
Mike Reeves
ac2cf8c6d8
Merge pull request #1219 from Security-Onion-Solutions/feature/mkrsoup
...
Feature/mkrsoup
2020-08-19 15:47:53 -04:00
Mike Reeves
db2cc5f7a7
Update init.sls
2020-08-19 15:43:51 -04:00
weslambert
d80156505c
Merge pull request #1217 from Security-Onion-Solutions/fix/aws_automation
...
Add defaults file for search node
2020-08-19 15:09:00 -04:00
Wes Lambert
ed1e346789
Add defaults file for search node
2020-08-19 19:07:24 +00:00
Mike Reeves
4c246dc30d
remove airgap install option until rc3
2020-08-19 14:40:31 -04:00
weslambert
d25afe4aa5
Merge pull request #1216 from Security-Onion-Solutions/fix/logstash_hosts
...
Add manager IP to container hosts file
2020-08-19 14:39:04 -04:00
weslambert
b5dd868d1b
Add manager IP to container hosts file
2020-08-19 14:34:28 -04:00
Mike Reeves
6edf1c14f8
Fix filebeat certs
2020-08-19 13:35:58 -04:00
Mike Reeves
bf84822d36
fix if logic
2020-08-19 13:04:10 -04:00
Mike Reeves
3d48c1f99b
Add playbook updates
2020-08-19 12:14:11 -04:00
Mike Reeves
9280dbb9d9
Update soup
2020-08-19 12:00:25 -04:00
m0duspwnens
2f0ffffca4
lock and unlock master during soup
2020-08-19 11:46:29 -04:00
Mike Reeves
f57e0fbc56
Salt ACL
2020-08-19 10:33:26 -04:00
Mike Reeves
95f006db7d
Salt ACL
2020-08-19 10:08:11 -04:00
Mike Reeves
968e481ebe
Add cross cluster for SSL
2020-08-18 17:45:14 -04:00
Mike Reeves
348e802fb7
Add cross cluster for SSL
2020-08-18 17:38:35 -04:00
Mike Reeves
afa87374ad
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/mkrsoup
2020-08-18 17:33:25 -04:00
Mike Reeves
294a197cbf
Add cross cluster for SSL
2020-08-18 16:57:38 -04:00
Josh Brower
ad0f54fc40
Merge pull request #1209 from Security-Onion-Solutions/bugfix/osquery-parsing
...
Osquery Parsing fix
2020-08-18 15:54:47 -04:00
Josh Brower
d4f7a07f85
Osquery Parsing fix
2020-08-18 15:54:11 -04:00
weslambert
ca84ae43ef
Merge pull request #1208 from Security-Onion-Solutions/fix/remove_pillar_from_setup
...
Don't echo pillar to setup log
2020-08-18 15:44:20 -04:00
weslambert
a4e986ea37
Don't echo pillar to setup log
2020-08-18 15:43:43 -04:00
Josh Patterson
be8483c580
Merge pull request #1207 from Security-Onion-Solutions/issue/1188
...
remove monint from nodestab grafana dashboard since search nodes dont…
2020-08-18 15:37:56 -04:00
m0duspwnens
65d9afd8d5
remove monint from nodestab grafana dashboard since search nodes dont have monint
2020-08-18 15:37:17 -04:00
Mike Reeves
59aa55f9bc
Add playsecrets
2020-08-18 15:29:41 -04:00
Jason Ertel
47ad3f65ef
Only fail setup when the root mailbox is not empty for ISO installations, since network installations can't be sure if the error came from setup or something unrelated
2020-08-18 15:26:30 -04:00
Josh Patterson
1bf4b86d07
Merge pull request #1206 from Security-Onion-Solutions/issue/1188
...
remove monint from manager since it doesnt have a monint
2020-08-18 15:10:40 -04:00
m0duspwnens
5a3d95d9a1
remove monint from manager since it doesnt have a monint
2020-08-18 15:09:21 -04:00
Mike Reeves
44fcd999fd
Address #1205
2020-08-18 15:08:24 -04:00
weslambert
82bfa567d0
Merge pull request #1204 from Security-Onion-Solutions/fix/enable_strelka_default
...
Enable YARA rules by default
2020-08-18 14:54:46 -04:00
weslambert
eaad0487b5
Enable YARA rules by default
2020-08-18 14:54:11 -04:00
Josh Patterson
54c43634a3
Merge pull request #1203 from Security-Onion-Solutions/issue/1188
...
add strelka to heavynode if strelka is enabled
2020-08-18 14:29:07 -04:00
m0duspwnens
c8dfc2495c
add strelka to heavynode if strelka is enabled - https://github.com/Security-Onion-Solutions/securityonion/issues/1188
2020-08-18 14:21:23 -04:00
Jason Ertel
45d957566d
Only show 'Waiting for TheHive to start up' status if setup is actually installing thehive
2020-08-18 11:36:29 -04:00
Josh Patterson
b214b20e58
Merge pull request #1201 from Security-Onion-Solutions/issue/1063
...
fix monint for several node types for grafana
2020-08-18 10:53:30 -04:00
m0duspwnens
9f8f59f4df
fix monint for several node types for grafana
2020-08-18 10:48:52 -04:00
Mike Reeves
ba192d6c32
Update addtotab.sh
2020-08-17 17:23:25 -04:00
Josh Brower
9c1c4b1a98
Merge pull request #1198 from Security-Onion-Solutions/feature/playbook-tweaks
...
Playbook schema update - RC2
2020-08-17 14:10:26 -04:00
Josh Brower
a8aa97edd2
Playbook schema update - RC2
2020-08-17 14:09:17 -04:00
Josh Patterson
1d02fbdd0b
Merge pull request #1197 from Security-Onion-Solutions/feature/soup
...
add sls extension
2020-08-17 12:27:34 -04:00
m0duspwnens
eb1272c127
add sls extension
2020-08-17 12:26:44 -04:00
Josh Patterson
5581cf6721
Merge pull request #1196 from Security-Onion-Solutions/feature/soup
...
Feature/soup
2020-08-17 10:57:32 -04:00
m0duspwnens
a82c4c24fb
move url_base from manager to global in when running soup
2020-08-17 10:55:07 -04:00
Mike Reeves
dcb110b31f
Add rc1 conditional logic
2020-08-17 09:57:00 -04:00
Jason Ertel
d8833abf73
Use load instead of import on the registry image itself
2020-08-15 09:42:56 -04:00
Josh Patterson
2c9c328a40
Merge pull request #1193 from Security-Onion-Solutions/issue/1039
...
Issue/1039
2020-08-14 18:45:12 -04:00
m0duspwnens
e6da423dc3
change reference from manager:url_base to global:url_base - https://github.com/Security-Onion-Solutions/securityonion/issues/1039
2020-08-14 17:55:30 -04:00
m0duspwnens
4946bb54d8
Merge remote-tracking branch 'remotes/origin/dev' into issue/1039
2020-08-14 17:25:13 -04:00
Josh Patterson
5663edfaee
Merge pull request #1192 from Security-Onion-Solutions/quickfix/importnoderonicheckin
...
set checking interval for sensoroni on import node
2020-08-14 17:11:35 -04:00
m0duspwnens
387c26f052
set checking interval for sensoroni on import node
2020-08-14 17:10:36 -04:00
Josh Patterson
e4b80ff183
Merge pull request #1190 from Security-Onion-Solutions/quickfix/setuplogging
...
send service status to /dev/null to prevent FP on install failure
2020-08-14 16:47:55 -04:00
m0duspwnens
43f6f5c27a
send service status to /dev/null to prevent FP on install failure
2020-08-14 16:45:28 -04:00
Josh Patterson
51cbccad09
Merge pull request #1189 from Security-Onion-Solutions/quickfix/modulerun
...
use new module.run style
2020-08-14 16:39:17 -04:00
m0duspwnens
5220b5ae0c
use new module.run style
2020-08-14 16:37:45 -04:00
Josh Patterson
6b6f39edde
Merge pull request #1187 from Security-Onion-Solutions/quickfix/heavyfw
...
heavynode firewall rules
2020-08-14 16:01:56 -04:00
m0duspwnens
47faee48a6
heavynode firewall rules
2020-08-14 15:58:59 -04:00
Mike Reeves
eb6b2f6ca0
Merge pull request #1186 from Security-Onion-Solutions/feature/airgap
...
Airgap round 1
2020-08-14 15:41:36 -04:00
Mike Reeves
bac58abf3e
Airgap round 1
2020-08-14 15:32:33 -04:00
m0duspwnens
d963222f31
provide proper url for so-import-pcap based on redirect strategy chosen during setup - https://github.com/Security-Onion-Solutions/securityonion/issues/1039
2020-08-14 15:28:47 -04:00
Jason Ertel
11ebc6b8b2
Do not cancel setup if user choose not to run so-allow during setup
2020-08-14 15:28:42 -04:00
Josh Patterson
0ba0c16c38
Merge pull request #1185 from Security-Onion-Solutions/issue/1049
...
Issue/1049
2020-08-14 14:55:14 -04:00
m0duspwnens
35027e32b3
dont constantly run steno or suricata containers for import node
2020-08-14 14:43:37 -04:00
weslambert
945bc5c6de
Merge pull request #1184 from Security-Onion-Solutions/fix/automate_ssh
...
Don't copy SSH key if automated install
2020-08-14 14:42:44 -04:00
weslambert
c9d6293f8f
Don't copy SSH key if automated install
2020-08-14 14:41:35 -04:00
Jason Ertel
7fa5e17935
Correct if logic for determining when to show web interface URL
2020-08-14 14:40:12 -04:00
m0duspwnens
f9a6b8d231
remove zeek and suricata from so-status for import node
2020-08-14 14:39:02 -04:00
m0duspwnens
3836f00309
allow sensori port for import node
2020-08-14 14:32:34 -04:00
Jason Ertel
04340728ff
Improve title spacing among standard log lines
2020-08-14 14:28:52 -04:00
m0duspwnens
ff84640aad
add pcap to import node, test not starting zeek docker by default
2020-08-14 13:59:23 -04:00
Josh Patterson
fbbec71165
Merge pull request #1183 from Security-Onion-Solutions/issue/1170
...
Issue/1170
2020-08-14 12:56:57 -04:00
m0duspwnens
b7bfa6f9a9
move functions up
2020-08-14 12:55:54 -04:00
m0duspwnens
6602ad3286
sleep for 5 seconds
2020-08-14 12:53:24 -04:00
m0duspwnens
4bb23a089e
add some parens
2020-08-14 12:48:52 -04:00
m0duspwnens
4b21c1b492
logic change
2020-08-14 12:45:50 -04:00
Mike Reeves
2a8e4e4eb2
Merge pull request #1182 from Security-Onion-Solutions/feature/airgap
...
Feature/airgap
2020-08-14 12:32:26 -04:00
m0duspwnens
9d59fc23dd
logic changes
2020-08-14 12:24:15 -04:00
Mike Reeves
c64faacdbc
Install registry if the image is local
2020-08-14 12:15:56 -04:00
Mike Reeves
18f37e3ef8
Install registry if the image is local
2020-08-14 11:49:18 -04:00
m0duspwnens
e229cb49bc
logic changes
2020-08-14 11:40:21 -04:00
Wes Lambert
7686a05f42
Set Strelka rules enabled by default for Eval Mode
2020-08-14 15:33:38 +00:00
m0duspwnens
69fd803759
change while
2020-08-14 11:30:10 -04:00
m0duspwnens
683e8a2a39
remove quotes
2020-08-14 11:24:46 -04:00
weslambert
b662f9354f
Merge pull request #1180 from Security-Onion-Solutions/fix/thehive_global
...
Only copy TheHive details to global pillar if enabled
2020-08-14 11:23:16 -04:00
Wes Lambert
ab4285aaaf
Only copy TheHive details to global pillar if enabled
2020-08-14 15:21:56 +00:00
m0duspwnens
aa2b0699d5
move parens
2020-08-14 11:20:18 -04:00
m0duspwnens
876c6c7cb0
logic changes
2020-08-14 11:16:56 -04:00
m0duspwnens
ea5116700d
stop both service then start both
2020-08-14 11:01:26 -04:00
m0duspwnens
cd1169b68d
logging changes
2020-08-14 10:53:42 -04:00
m0duspwnens
e2fbe59b7c
additional logging
2020-08-14 10:30:01 -04:00
m0duspwnens
0eb0551b68
add check if salt minion is returning jobs
2020-08-14 10:15:54 -04:00
Mike Reeves
283f91459a
Fix rule update cron
2020-08-14 10:05:56 -04:00
Mike Reeves
7309767829
Merge pull request #1178 from Security-Onion-Solutions/fix/elasticwatch
...
Add watch statements
2020-08-14 09:58:40 -04:00
Mike Reeves
a3d8b7d0d3
Add watch statements
2020-08-14 09:40:38 -04:00
Jason Ertel
78bceeb9e5
Only show the web interface link when the redirect URL is available, such as on manager nodes
2020-08-14 09:17:25 -04:00
Jason Ertel
ee62faae72
Only show the web interface link when the redirect URL is available, such as on manager nodes
2020-08-14 09:10:28 -04:00
Jason Ertel
e6830e9cba
Avoid reusing header function from so-common
2020-08-14 01:09:47 -04:00
m0duspwnens
42c1e817fe
more logging and debugging
2020-08-13 18:09:57 -04:00
m0duspwnens
f9f2744d3f
logic changes
2020-08-13 17:49:05 -04:00
Jason Ertel
3c113a7a89
Add system information at beginning of installation; provide logging functions to be used instead of echo commands
2020-08-13 17:29:50 -04:00
Josh Brower
34d8261669
Merge pull request #1176 from Security-Onion-Solutions/feature/playbook
...
Elastalert/Playbook Stability updates
2020-08-13 17:19:01 -04:00
Josh Brower
7400bbd6c1
Elastalert Stability Fixes
2020-08-13 17:14:53 -04:00
m0duspwnens
829490da19
fix errors
2020-08-13 17:05:50 -04:00
m0duspwnens
6cf623e133
some logic changes
2020-08-13 16:52:39 -04:00
Doug Burks
ed4bee0d0b
so-allow has no usage function #1133
2020-08-13 16:42:50 -04:00
m0duspwnens
3d20cc0341
some debugging
2020-08-13 16:34:18 -04:00
m0duspwnens
1b4029f74b
fix syntax errors
2020-08-13 16:18:02 -04:00
m0duspwnens
07ef464375
https://github.com/Security-Onion-Solutions/securityonion/issues/1170
2020-08-13 16:01:53 -04:00
Jason Ertel
40b5b96e17
Respond with 403 status code to unauthorized sensor requests
2020-08-13 15:00:49 -04:00
Josh Patterson
078f87d6c7
Merge pull request #1169 from Security-Onion-Solutions/issue/1049
...
remove so-registry from docker see for import node as it doesnt even …
2020-08-13 10:49:14 -04:00
m0duspwnens
8ab1cd32f0
remove so-registry from docker see for import node as it doesnt even exist
2020-08-13 10:47:57 -04:00
Josh Patterson
ae66ec5f43
Merge pull request #1168 from Security-Onion-Solutions/issue/1049
...
Issue/1049
2020-08-13 10:12:47 -04:00
m0duspwnens
9fafd5f721
update trusted containers for soup to minimize downloaded containers
2020-08-13 08:32:51 -04:00
m0duspwnens
3387114389
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-13 08:21:43 -04:00
Mike Reeves
5a53194313
Update sotls.yml
2020-08-12 21:12:48 -04:00
Mike Reeves
59ddac57bf
Rename sotls.yaml to sotls.yml
2020-08-12 17:48:37 -04:00
m0duspwnens
a746d597bb
rename to .yml
2020-08-12 17:42:45 -04:00
m0duspwnens
dbe14fcbdb
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-12 16:46:03 -04:00
Doug Burks
5640faef13
Kernel consoleblank is causing whiptail progress screen to appear to hang #1084
2020-08-12 16:34:59 -04:00
m0duspwnens
f59b8683ae
allow soup to run on import node
2020-08-12 15:48:34 -04:00
m0duspwnens
5d5fcecdca
set the cluster for import node
2020-08-12 15:46:34 -04:00
Mike Reeves
0129519d0c
Merge pull request #1165 from Security-Onion-Solutions/feature/esssl
...
TLS Transport Encryption
2020-08-12 15:39:17 -04:00
Mike Reeves
9980d02844
Elastic Transport TLSgit add .
2020-08-12 15:38:19 -04:00
Mike Reeves
7e3e4d0f54
Convert ES cert to p12
2020-08-12 15:16:12 -04:00
Mike Reeves
82821fbb25
Convert ES cert to p12
2020-08-12 15:09:52 -04:00
Mike Reeves
daaffd5185
Convert ES cert to p12
2020-08-12 15:05:33 -04:00
Mike Reeves
683799d077
Convert ES cert to p12
2020-08-12 15:02:54 -04:00
m0duspwnens
ddf3e6f943
remove logstash from docker registry seed
2020-08-12 14:05:28 -04:00
Mike Reeves
c02a363e92
Merge pull request #1163 from Security-Onion-Solutions/feature/esssl
...
Feature/esssl
2020-08-12 14:02:27 -04:00
Mike Reeves
69e7285e30
Fix a bug where minio passwrods cause issues
2020-08-12 12:44:55 -04:00
m0duspwnens
68f5c1c3c5
create web user during setup for import node
2020-08-12 12:01:25 -04:00
m0duspwnens
dcd5e95b38
add so-pcaptools to registry for import node
2020-08-12 11:57:13 -04:00
m0duspwnens
c166bc84f3
add zeek to import node top
2020-08-12 11:48:22 -04:00
m0duspwnens
41afe0ab2e
remove tab
2020-08-12 11:33:10 -04:00
m0duspwnens
b5c9d44d91
nginx config for import node
2020-08-12 11:15:14 -04:00
Mike Reeves
32083132e5
Back out some ES settings
2020-08-12 11:10:36 -04:00
m0duspwnens
dfd3a1de6a
set monitor interface to bond0 for import node
2020-08-12 10:42:07 -04:00
m0duspwnens
0f53b4d703
set esheapsize and filebeat config for import node
2020-08-12 10:39:31 -04:00
m0duspwnens
5a0df27193
rename importpcap node to import
2020-08-12 10:27:15 -04:00
m0duspwnens
6260a0aeaa
add idstools to docker registry for importpcap node
2020-08-11 16:29:35 -04:00
m0duspwnens
53b4a73bb9
add idstools to importpcap node
2020-08-11 15:59:08 -04:00
m0duspwnens
de05403237
ensure nids rules dir exists
2020-08-11 15:52:15 -04:00
Mike Reeves
0f7074a499
SSL intraca
2020-08-11 15:49:04 -04:00
Mike Reeves
65d535d893
SSL intraca
2020-08-11 15:45:17 -04:00
Mike Reeves
f862133323
SSL intraca
2020-08-11 15:37:55 -04:00
Mike Reeves
5a0aae5fe7
SSL intraca
2020-08-11 15:34:07 -04:00
Mike Reeves
a817465318
SSL intraca
2020-08-11 15:25:09 -04:00
Mike Reeves
e8b61a3828
SSL intraca
2020-08-11 15:14:29 -04:00
Mike Reeves
5f30c947c9
SSL intraca
2020-08-11 15:12:23 -04:00
Josh Brower
b724d40376
Playbook Stability Fixes
2020-08-11 15:07:16 -04:00
m0duspwnens
a81d14463c
add logstash to registry for importpcap, change PATCHSCHEDULENAME=auto
2020-08-11 15:01:20 -04:00
Mike Reeves
42c9653669
anon user hack
2020-08-11 14:45:55 -04:00
Mike Reeves
f553a8e27a
anon user hack
2020-08-11 14:40:34 -04:00
Mike Reeves
8daf11f085
Fix logstash outputs
2020-08-11 13:58:28 -04:00
m0duspwnens
40006752a1
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-11 13:30:48 -04:00
m0duspwnens
ee91450424
fix patch schedule name for importpcap node
2020-08-11 13:30:41 -04:00
weslambert
796551d71b
Merge pull request #1161 from Security-Onion-Solutions/fix/redisconf
...
Update Redis maxmemory settings
2020-08-11 13:27:28 -04:00
Mike Reeves
362749ca85
Make hostnames default in cross cluster
2020-08-11 13:00:42 -04:00
weslambert
b95f8a9314
Update Redis maxmemory settings
2020-08-11 12:57:57 -04:00
m0duspwnens
ec62668eb7
firewall rules for importpcap node
2020-08-11 12:31:37 -04:00
m0duspwnens
f6a85ac852
top and seed registry for importpcap node
2020-08-11 12:27:21 -04:00
Mike Reeves
94bb9e0d6c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-11 12:20:00 -04:00
Mike Reeves
95367f8d23
Fix cross cluster
2020-08-11 12:00:58 -04:00
Mike Reeves
348f7f39cc
strip node suffix
2020-08-11 11:37:53 -04:00
Mike Reeves
05a05b5e9b
use hostname for cross cluster
2020-08-11 11:15:57 -04:00
Mike Reeves
cbba473c2d
fix ssl certs for SN
2020-08-11 11:10:27 -04:00
Mike Reeves
32c407231f
fix ssl certs for SN
2020-08-11 11:08:49 -04:00
Mike Reeves
a5131da5c9
fix ssl certs for SN
2020-08-11 11:07:34 -04:00
Mike Reeves
7e0249c377
ES cleanup
2020-08-11 10:28:21 -04:00
Mike Reeves
b84d7d818f
Fix for loop
2020-08-11 10:20:02 -04:00
Mike Reeves
d941209479
Walk nodes tab
2020-08-11 10:17:28 -04:00
Mike Reeves
32f8ea3158
Removes https from rest port
2020-08-11 10:02:00 -04:00
Jason Ertel
854cc487f7
Always disable screen blanking, to simplify logic
2020-08-11 09:21:06 -04:00
Mike Reeves
59292425c0
Add transport hostname
2020-08-10 23:03:54 -04:00
Mike Reeves
ac3f490299
Add transport hostname
2020-08-10 23:02:03 -04:00
Mike Reeves
730e389aae
Add transport hostname
2020-08-10 22:57:49 -04:00
Mike Reeves
52cc56bebb
Add transport hostname
2020-08-10 22:56:15 -04:00
Mike Reeves
c3d8c599cc
Turn off user auth
2020-08-10 22:13:17 -04:00
Mike Reeves
6007a6c4d8
Things like this are why I hate Java
2020-08-10 22:10:03 -04:00
Mike Reeves
d00231af06
Things like this are why I hate Java
2020-08-10 22:05:46 -04:00
Mike Reeves
31ab1e8ed8
Things like this are why I hate Java
2020-08-10 22:03:24 -04:00
Mike Reeves
6d2be9af7e
Things like this are why I hate Java
2020-08-10 21:58:44 -04:00
Mike Reeves
cdda46ce58
ca typeo
2020-08-10 21:54:36 -04:00
Mike Reeves
811da5732a
Elastic logic fix
2020-08-10 21:51:29 -04:00
Mike Reeves
08d544e527
Fix SSL perms
2020-08-10 21:44:45 -04:00
Mike Reeves
cf5c29d01c
Change certs path on elstic
2020-08-10 21:30:53 -04:00
Mike Reeves
e28619604c
Change certs path on elstic
2020-08-10 21:26:00 -04:00
Mike Reeves
e7cd527d49
Enable SSL in elastic
2020-08-10 21:18:03 -04:00
Mike Reeves
92cc176b6d
Fix features logic in all states that use it
2020-08-10 20:59:41 -04:00
Mike Reeves
28806513d9
Logstash logic fix
2020-08-10 20:53:56 -04:00
m0duspwnens
11433b87e6
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-10 16:36:49 -04:00
Mike Reeves
788864310c
Fix ssl state
2020-08-10 14:52:20 -04:00
Mike Reeves
523e42bec8
Fix ssl state
2020-08-10 14:40:11 -04:00
Mike Reeves
9d2d8d372f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-10 14:27:08 -04:00
Mike Reeves
e659af3466
ES basic SSL
2020-08-10 14:26:56 -04:00
Josh Patterson
6bb84f8513
Merge pull request #1160 from Security-Onion-Solutions/quickfix/saltinstall
...
add replace: False to get rid of warning, eventhough it doesntt. bug …
2020-08-10 13:06:15 -04:00
m0duspwnens
1f3ceb50da
add replace: False to get rid of warning, eventhough it doesntt. bug report submitted on saltstack gh.
2020-08-10 13:04:19 -04:00
Josh Patterson
b0aa40737b
Merge pull request #1159 from Security-Onion-Solutions/quickfix/saltinstall
...
fix --exclude, add salt-minion-3001.1 where missed
2020-08-10 12:23:48 -04:00
m0duspwnens
8146930b80
fix --exclude, add salt-minion-3001.1 where missed
2020-08-10 12:22:42 -04:00
Josh Patterson
b6740ef360
Merge pull request #1158 from Security-Onion-Solutions/quickfix/saltinstall
...
upgrading to salt 3001.1
2020-08-10 10:21:55 -04:00
m0duspwnens
ab7014d70a
upgrading to salt 3001.1
2020-08-10 10:19:25 -04:00
Mike Reeves
29aaa84a6f
Merge pull request #1157 from Security-Onion-Solutions/feature/esssl
...
Feature/esssl
2020-08-08 22:20:55 -04:00
Mike Reeves
32fe3ed961
fix ports
2020-08-08 20:59:13 -04:00
Mike Reeves
63031a965a
fix ports
2020-08-08 20:48:46 -04:00
Mike Reeves
bc09a89a01
output plugin to normal port
2020-08-08 20:36:28 -04:00
Mike Reeves
9248896a20
fix redis ports
2020-08-08 20:24:30 -04:00
Mike Reeves
112dba4549
Upodate SSL
2020-08-08 20:12:17 -04:00
Mike Reeves
f154d2fa78
Upodate SSL
2020-08-08 20:04:19 -04:00
Mike Reeves
9708b02387
update pipeline
2020-08-08 18:32:36 -04:00
Mike Reeves
86fd38a347
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-08 17:32:29 -04:00
Mike Reeves
f840c85a46
make script run
2020-08-08 17:31:59 -04:00
Mike Reeves
26a095a89c
redis binds
2020-08-08 00:20:46 -04:00
Mike Reeves
8a50768e16
redis binds
2020-08-08 00:19:55 -04:00
Mike Reeves
dc12cacee0
generate redis key
2020-08-08 00:16:38 -04:00
Mike Reeves
d1c4e3d021
generate redis key
2020-08-08 00:15:36 -04:00
Mike Reeves
20dba6eaac
jruby ssl fun
2020-08-07 23:56:09 -04:00
Mike Reeves
ec1065462c
jruby ssl fun
2020-08-07 23:50:26 -04:00
Jason Ertel
5e3d21c43c
Wrap minio keys with quotes to ensure YAML parsing
2020-08-07 23:50:18 -04:00
Mike Reeves
d171adb9c9
jruby ssl fun
2020-08-07 23:39:13 -04:00
Mike Reeves
64af6f99e9
jruby ssl fun
2020-08-07 23:34:55 -04:00
Mike Reeves
2705cbbf45
jruby ssl fun
2020-08-07 23:33:02 -04:00
Mike Reeves
5525e235d1
jruby ssl fun
2020-08-07 23:28:58 -04:00
Mike Reeves
62a6f29c96
bucket stuff
2020-08-07 22:51:52 -04:00
Mike Reeves
321122cc87
update logstash
2020-08-07 22:43:34 -04:00
Mike Reeves
0d66e32305
sync cacerts
2020-08-07 22:39:29 -04:00
Mike Reeves
952234446f
fix logic
2020-08-07 22:18:58 -04:00
Mike Reeves
cca0dd9344
enable jinja
2020-08-07 22:14:33 -04:00
Mike Reeves
1b0f90b7e4
sync script
2020-08-07 22:12:47 -04:00
Mike Reeves
d15d53bcdc
Add script to extract cacerts
2020-08-07 22:04:30 -04:00
Josh Brower
4b99f55e0a
Merge pull request #1155 from Security-Onion-Solutions/feature/playbook-fixes2
...
Playbook/Nav Fixes - Issue #1064
2020-08-07 17:03:32 -04:00
Josh Brower
928e5ed832
Playbook/Nav Fixes - Issue #1064
2020-08-07 17:02:48 -04:00
m0duspwnens
30e0abf326
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-07 16:43:02 -04:00
m0duspwnens
0c2ea53f25
revert back to local_salt_dir
2020-08-07 16:42:46 -04:00
m0duspwnens
b02332d84a
fix global pillar location for setup
2020-08-07 16:18:11 -04:00
m0duspwnens
7933bafd55
more fixes for importpcap node
2020-08-07 15:46:45 -04:00
m0duspwnens
d7b55c1109
add so-status map for importpcap
2020-08-07 15:21:07 -04:00
m0duspwnens
86b118ba1a
add importpcap to local assigned hostgroups yaml
2020-08-07 15:00:32 -04:00
m0duspwnens
9649994f73
add importpcap to pillar/top
2020-08-07 14:40:02 -04:00
m0duspwnens
a8147d7d3b
add importpcap to salt_checkin for setup ssl/ca
2020-08-07 14:19:58 -04:00
Jason Ertel
847939e9b2
Fixed extra space that causes global.sls file to be empty
2020-08-07 14:11:28 -04:00
m0duspwnens
fadd81c9f3
so-importpcap to ssl state
2020-08-07 13:58:29 -04:00
m0duspwnens
7c3070655b
copy_minion_tmp_files for IMPORTPCAP too
2020-08-07 13:39:17 -04:00
Josh Brower
ff209cfd65
Merge pull request #1149 from Security-Onion-Solutions/feature/wlb-parsing
...
Ingest Parsing Update for Sysmon/WEL
2020-08-07 13:37:22 -04:00
Josh Brower
3ec1b1db71
Merge pull request #1154 from Security-Onion-Solutions/feature/playbook-fixes
...
More Playbook Fixes - Issue #1064
2020-08-07 13:36:38 -04:00
Josh Brower
a8b980b6a7
More Playbook Fixes - Issue #1064
2020-08-07 13:35:43 -04:00
m0duspwnens
2d7aefed0d
add IMPORTPCAP node to set_hostname
2020-08-07 11:42:48 -04:00
m0duspwnens
7d11fc345f
dont ask for patch schedule for importpcap node
2020-08-07 11:19:31 -04:00
m0duspwnens
24b77fa855
enlarge whiptail for install type selection
2020-08-07 11:16:52 -04:00
m0duspwnens
2c6a20fee9
enlarge whiptail for install type selection
2020-08-07 11:11:21 -04:00
m0duspwnens
d668b85033
copy_ssh_key for is_importpcap also
2020-08-07 11:09:12 -04:00
m0duspwnens
fce22c1cc4
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-07 10:27:11 -04:00
Mike Reeves
b534d2b975
Update so-functions
2020-08-07 10:05:47 -04:00
Mike Reeves
d3e6657b45
Fix Spacing
2020-08-07 10:01:40 -04:00
Mike Reeves
80550b0d76
Merge pull request #1151 from Security-Onion-Solutions/feature/minio
...
Feature/minio
2020-08-06 15:45:27 -04:00
Josh Brower
c3da302353
Merge pull request #1150 from Security-Onion-Solutions/feature/playbook-fixes
...
Simplify elastalert rules
2020-08-06 15:45:06 -04:00
Josh Brower
ddd099233a
Playbook Fixes - Issue #1064
2020-08-06 15:43:45 -04:00
Mike Reeves
bbdaee28ed
Add upload queue thread
2020-08-06 15:41:10 -04:00
Mike Reeves
16d0c02113
Fix cert dev null
2020-08-06 15:39:02 -04:00
Mike Reeves
63e31bd6b9
Add upload queue thread
2020-08-06 15:33:48 -04:00
Jason Ertel
31fd0b6407
Update the Hunt event fields lookups to reflect the latest ingest configs
2020-08-06 14:59:39 -04:00
Josh Brower
4f9ef89098
Simplify elastalert rules
2020-08-06 14:30:44 -04:00
Josh Brower
15efe77e06
Ingest Parsing Update for Sysmon/WEL
2020-08-06 13:11:47 -04:00
Mike Reeves
4936da9b5d
Merge pull request #1146 from Security-Onion-Solutions/feature/minio
...
Feature/minio
2020-08-05 23:01:58 -04:00
Mike Reeves
e7225349a6
Ability to toggle between redis and minio
2020-08-05 22:56:41 -04:00
Mike Reeves
4e40615e51
Add tuneable to the global pillar
2020-08-05 22:47:12 -04:00
Mike Reeves
d9b1127308
Switch to gzip encoding
2020-08-05 22:36:23 -04:00
m0duspwnens
d7801acea5
add mode 1
2020-08-05 17:09:41 -04:00
Mike Reeves
633c100ace
final logstash tweaks
2020-08-05 16:40:21 -04:00
Jason Ertel
30ff6d2b93
Update event fields to reflect new ECS terms - WIP
2020-08-05 16:28:36 -04:00
William Wernert
64c366971f
[fix] Redirect ca state apply in setup to /dev/null
...
Redirect ca state apply line in accept_salt_key_remote to /dev/null to avoid generating error in setup log
2020-08-05 16:13:25 -04:00
m0duspwnens
8079dc54fc
add stuff for /etc/salt/minion to get populated for importpcap node
2020-08-05 15:42:22 -04:00
m0duspwnens
83dc35c720
add importpcap mode to whiptail
2020-08-05 15:24:11 -04:00
m0duspwnens
66ca7b266c
first commit of importpcap node mode code, kek
2020-08-05 14:44:23 -04:00
Mike Reeves
cd766753eb
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/minio
2020-08-05 14:34:22 -04:00
Mike Reeves
95cae2f17a
SSL path for logstash
2020-08-05 14:14:35 -04:00
Mike Reeves
e30746c5ca
Final minio fix
2020-08-05 14:12:06 -04:00
Mike Reeves
734f2979d2
add ca.crt to lgostash docker bind
2020-08-04 23:20:51 -04:00
Mike Reeves
1855eeaa13
fix cert name
2020-08-04 23:09:08 -04:00
Mike Reeves
970ee195a1
use hostname so TLS will work
2020-08-04 23:08:33 -04:00
Mike Reeves
58872c9b48
enable ssl logstash
2020-08-04 22:40:59 -04:00
Mike Reeves
a765790d6c
fix minio container name
2020-08-04 22:37:04 -04:00
Mike Reeves
a733dceb18
enable ssl minio
2020-08-04 22:33:40 -04:00
Mike Reeves
5d4a0c53b5
add ssl cert for minio
2020-08-04 21:29:07 -04:00
Mike Reeves
61ff944087
add tmp to survive restarts
2020-08-04 18:18:06 -04:00
Mike Reeves
a2e5dca065
Fix output pillar for minio
2020-08-04 18:02:54 -04:00
Mike Reeves
38d0f519ce
Fix output pillar for minio
2020-08-04 18:00:05 -04:00
Mike Reeves
9c5a969c2e
Fix minio init
2020-08-04 17:18:09 -04:00
Mike Reeves
fd039b3008
Fix top file for minio
2020-08-04 17:11:20 -04:00
Mike Reeves
c56ead08e9
add so minio docker
2020-08-04 16:28:50 -04:00
Mike Reeves
407160b729
Update changes.json
2020-08-04 16:23:03 -04:00
Mike Reeves
24ed92c9dc
minio and change to global
2020-08-04 15:54:03 -04:00
Mike Reeves
549bf7ba19
Activate minio
2020-08-04 10:17:43 -04:00
weslambert
e9af032c28
Merge pull request #1143 from Security-Onion-Solutions/feature/aws_mgr_defaults
...
Add AWS defaults file for manager
2020-08-04 10:13:07 -04:00
Wes Lambert
46f70c254c
Add AWS defaults file for manager
2020-08-04 14:11:50 +00:00
weslambert
f7425b14e3
Merge pull request #1142 from Security-Onion-Solutions/feature/aws_eval_defaults
...
AWS defaults modifications
2020-08-03 23:51:32 -04:00
Wes Lambert
2290c28a07
AWS defaults modifications
2020-08-04 03:49:59 +00:00
Mike Reeves
7c1120e47d
Fix grafana monitor interface.
2020-08-03 18:48:01 -04:00
Jason Ertel
d1641aa0d8
chown /var/ossec dir to match the needful user/group ownership for ossec-agentd
2020-08-03 15:49:21 -04:00
Josh Patterson
51934d6e5f
Merge pull request #1137 from Security-Onion-Solutions/issue/1091
...
iunstall saltstack 3001 during setup
2020-08-03 11:39:44 -04:00
m0duspwnens
fb887f7d9e
iunstall saltstack 3001 during setup
2020-08-03 10:47:24 -04:00
weslambert
12f53ce9d9
Merge pull request #1134 from Security-Onion-Solutions/fix/aws_auto_reboot
...
Reboot after finished with setup
2020-08-03 10:31:24 -04:00
weslambert
7e2917fc99
Reboot after finished with setup
2020-08-03 10:31:03 -04:00
Jason Ertel
f47128824e
Before finishing setup, rescan the log file and root mailbox for errors
2020-08-02 09:04:29 -04:00
weslambert
9255e77263
Merge pull request #1129 from Security-Onion-Solutions/feature/aws_standalone_defaults
...
Add AWS Standalone Defaults
2020-07-31 16:15:12 -04:00
Wes Lambert
ecafbc6014
Add AWS Standalone Defaults
2020-07-31 20:12:25 +00:00
Josh Brower
f99413c84d
Merge pull request #1128 from Security-Onion-Solutions/feature/launcher-update
...
Osquery & WLB Parsing Update for WEL & Sysmon
2020-07-31 16:07:41 -04:00
Josh Brower
4d66d37ac5
Merge branch 'dev' into feature/launcher-update
2020-07-31 16:07:33 -04:00
Josh Brower
d971d07720
Osquery & WLB Parsing Update for WEL & Sysmon
2020-07-31 16:06:15 -04:00
Josh Patterson
40272b2ed0
Merge pull request #1126 from Security-Onion-Solutions/issue/1091
...
Issue/1091
2020-07-31 13:53:28 -04:00
m0duspwnens
b3b67ff2a5
Merge remote-tracking branch 'remotes/origin/dev' into issue/1091
2020-07-31 13:50:11 -04:00
m0duspwnens
d16d2b6551
full path to salt bootstrap
2020-07-31 13:42:06 -04:00
m0duspwnens
e3581bb76e
change to salt-common
2020-07-31 13:36:21 -04:00
m0duspwnens
13c9fa3089
test minion upgrade at end
2020-07-31 13:32:12 -04:00
m0duspwnens
1e1d6a395d
cant get grains.filter_by to work for some reason
2020-07-31 13:25:37 -04:00
m0duspwnens
d7ad2fbfd7
move include
2020-07-31 13:17:56 -04:00
m0duspwnens
dd865f6a68
change map
2020-07-31 13:10:37 -04:00
m0duspwnens
173f945fc0
remove comma
2020-07-31 13:01:37 -04:00
m0duspwnens
d6f89cb09a
fix ubuntu salt-common package name
2020-07-31 12:37:19 -04:00
m0duspwnens
7287f5f935
wordsmithing
2020-07-30 17:01:17 -04:00
m0duspwnens
da9dc42a47
more logging
2020-07-30 16:47:40 -04:00
m0duspwnens
2ad17dfd06
dont append
2020-07-30 16:42:59 -04:00
m0duspwnens
8d044084e1
try to log soup
2020-07-30 16:41:21 -04:00
Josh Brower
ed8d443fe5
Merge pull request #1125 from Security-Onion-Solutions/feature/launcher-update
...
Fleet - Update osquery config for 4.4 windows_events
2020-07-30 16:35:42 -04:00
Josh Brower
4e01ef2795
Fleet - Update osquery config for 4.4 windows_events
2020-07-30 16:34:48 -04:00
m0duspwnens
de7f67ff2f
fix UPGRADECOMMAND
2020-07-30 16:31:37 -04:00
m0duspwnens
f209deac98
call detect_os function
2020-07-30 16:25:45 -04:00
m0duspwnens
914d890a51
fix UPGRADECOMMAND
2020-07-30 16:21:01 -04:00
m0duspwnens
8180f2cd93
remove quotes
2020-07-30 16:13:38 -04:00
m0duspwnens
cc48b55acf
change state name
2020-07-30 16:06:01 -04:00
m0duspwnens
1492d132ca
add ability to upgrade salt minion and master for ubuntu
2020-07-30 16:00:50 -04:00
m0duspwnens
a4fc2cbd42
caps
2020-07-30 13:50:22 -04:00
m0duspwnens
4bf4634762
ensure yum versionlock with a state rather than cmd.run state
2020-07-30 13:47:21 -04:00
m0duspwnens
6812d3f5c5
change output wording, add periods
2020-07-30 13:35:09 -04:00
m0duspwnens
a562d70fe2
stop salt minion first then salt master
2020-07-30 13:18:59 -04:00
m0duspwnens
8a8705f469
move when we check for salt minion update in setup
2020-07-30 12:41:09 -04:00
m0duspwnens
9570efbf8e
fix opt check
2020-07-30 12:15:09 -04:00
m0duspwnens
c099f3c5ec
change if for optargs
2020-07-30 11:49:34 -04:00
m0duspwnens
de0b34a66b
change if for optargs
2020-07-30 11:43:18 -04:00
m0duspwnens
1c5e6fa10f
change if for optargs
2020-07-30 11:39:58 -04:00
m0duspwnens
e9d889f719
fix regex
2020-07-30 11:33:19 -04:00
m0duspwnens
2222bce77b
update regex
2020-07-30 11:22:12 -04:00
m0duspwnens
728afdcaaf
exit soup if batch size invalid
2020-07-30 11:18:27 -04:00
m0duspwnens
3d4a96fae0
update ssl state unless , check and upgrade salt minion if needed during install
2020-07-30 11:16:37 -04:00
weslambert
00ba4ca6c0
Merge pull request #1121 from Security-Onion-Solutions/fix/thehive_static
...
Fix/thehive static
2020-07-30 10:27:43 -04:00
weslambert
4282930f08
Update cortex-application.conf
2020-07-30 10:26:49 -04:00
weslambert
c58ee8a37d
Add Cortex play secret
2020-07-30 10:25:53 -04:00
weslambert
b6a053070f
Change TheHive play secret
2020-07-30 10:25:07 -04:00
weslambert
2fab00458b
Add randomized play secrets for Cortex + TheHive
2020-07-30 10:23:00 -04:00
Mike Reeves
55053748df
Merge pull request #1119 from Security-Onion-Solutions/fix/2.0.3
...
2.0.3
2020-07-30 09:52:04 -04:00
m0duspwnens
14584b28e1
include salt state in salt.minion, manager salt-minion service in salt.minion state;
2020-07-29 16:04:47 -04:00
m0duspwnens
3e78c88114
update salt top to run salt.minion state if defined version not installed. only apply other states if proper version installed
2020-07-29 15:52:48 -04:00
Mike Reeves
1e15786430
Update VERIFY_ISO.md
2020-07-29 15:48:37 -04:00
Mike Reeves
c73d4aa690
Update sig file for 2.0.3
2020-07-29 15:40:02 -04:00
m0duspwnens
22b757f112
dont install new minion if already installed
2020-07-29 15:36:35 -04:00
m0duspwnens
03144446c8
revert branch to original code
2020-07-29 14:59:00 -04:00
m0duspwnens
5a814f8312
change condidtional statement
2020-07-29 14:41:58 -04:00
m0duspwnens
8c466f548b
update wording
2020-07-29 14:38:42 -04:00
m0duspwnens
171aa1178a
fix vars and if statement
2020-07-29 14:36:42 -04:00
m0duspwnens
8a44d4752b
fix var def
2020-07-29 14:26:57 -04:00
m0duspwnens
c949845218
only try to upgrade salt on grid if salt upgraded on manager
2020-07-29 14:20:17 -04:00
m0duspwnens
b8c0653818
soup upgrade salt on minions - add batch size option
2020-07-29 14:18:11 -04:00
weslambert
646bf1cb4d
Merge pull request #1118 from Security-Onion-Solutions/fix/wazuh_register_to
...
Fix/wazuh registration timeout
2020-07-29 13:53:45 -04:00
weslambert
c48ba8abaf
Re-arrange config
2020-07-29 13:52:12 -04:00
weslambert
9db390023b
Increase timeout from 10s to 30s
2020-07-29 13:51:46 -04:00
m0duspwnens
0de6e86cdb
dont run booststrap-salt if the proper version is installed
2020-07-29 13:39:55 -04:00
m0duspwnens
b9d0bd86ca
fbkeylink and fbcertlink owned by socore:socore
2020-07-29 13:27:06 -04:00
m0duspwnens
9b29dff04f
only generate p8 files if the key used for genetation changes
2020-07-29 11:40:45 -04:00
m0duspwnens
dca3855f81
remove always update if branch specified
2020-07-29 10:50:11 -04:00
m0duspwnens
b67e3507d3
always update and clean dockers
2020-07-29 10:13:30 -04:00
Mike Reeves
e3da326fcb
Remove non used pillar items
2020-07-29 09:27:18 -04:00
weslambert
4b36c4a809
Merge pull request #1115 from Security-Onion-Solutions/fix/remove_ls_syslog
...
Remove LS syslog port binding
2020-07-29 08:35:41 -04:00
weslambert
7d432091e2
Remove LS syslog port binding
2020-07-29 08:35:07 -04:00
Josh Brower
e7b9e001e1
mysql init.sls - change startup time from 2 min to 15min
...
Closes https://github.com/Security-Onion-Solutions/securityonion/issues/1106
2020-07-28 22:08:00 -04:00
m0duspwnens
f056a0a17b
use import_yaml
2020-07-28 17:09:53 -04:00
m0duspwnens
8905869db2
move salt pillars to defaults
2020-07-28 16:58:44 -04:00
m0duspwnens
bfae439c90
salt state distribute bootstrap script
2020-07-28 16:37:14 -04:00
Doug Burks
cf63e891b5
Update changes.json
2020-07-28 16:29:03 -04:00
m0duspwnens
4d5c8e5c2b
add salt minion state to install/upgrade salt-minion
2020-07-28 16:22:42 -04:00
Mike Reeves
b46b7ae1a0
Update changes.json
2020-07-28 16:19:16 -04:00
Mike Reeves
db89089291
Update README.md
2020-07-28 16:15:59 -04:00
Mike Reeves
1ff440b7b0
Update VERSION
2020-07-28 16:15:23 -04:00
Josh Brower
b1c09a9b72
Typo fix - ingest parser - win.eventlogs
2020-07-28 15:23:17 -04:00
m0duspwnens
c00b452f8d
change module.run for ca state
2020-07-28 15:10:16 -04:00
m0duspwnens
73830123b6
Merge remote-tracking branch 'remotes/origin/dev' into issue/1091
2020-07-28 14:32:07 -04:00
m0duspwnens
307945e260
dont state salt-minion service, allow salt state to start it during highstate
2020-07-28 13:51:28 -04:00
m0duspwnens
2067cc118f
remove broken logging
2020-07-28 13:25:43 -04:00
m0duspwnens
77acb8f348
change ot /opt/so/log
2020-07-28 13:20:01 -04:00
m0duspwnens
d8375cce14
touch soup log
2020-07-28 13:15:47 -04:00
m0duspwnens
73a1a05404
change back sed delimiters, last highstate log level to info
2020-07-28 13:11:38 -04:00
Josh Brower
fe76f1c87c
Merge pull request #1111 from Security-Onion-Solutions/feature/refactor-sysmon-parsing
...
initial refactor - beats/sysmon parsing
2020-07-28 11:04:13 -04:00
Josh Brower
55e60cb749
initial refactor - beats/sysmon parsing
2020-07-28 11:03:33 -04:00
m0duspwnens
fb453a0d9c
change sed delimiters in soup
2020-07-28 08:13:03 -04:00
m0duspwnens
254dcdb2f0
prevent dockers from redownloading if we are updating soup to a branch
2020-07-27 18:19:26 -04:00
m0duspwnens
f42a39ca69
allow soup to continue update if branch is specified
2020-07-27 18:08:27 -04:00
m0duspwnens
e811718ebc
change to salt 3001.1, fix dupe state name, add git branch option to soup
2020-07-27 17:53:02 -04:00
m0duspwnens
7606cc0ad0
changes to ssl state for salt 3001
2020-07-27 15:51:31 -04:00
weslambert
0f6ecdf38a
Merge pull request #1104 from Security-Onion-Solutions/feature/cortex_orguser
...
Create default orguser if empty
2020-07-27 09:50:23 -04:00
Wes Lambert
e81fd7464b
Create default orguser if empty
2020-07-27 13:49:17 +00:00
weslambert
ced51761fa
Merge pull request #1103 from Security-Onion-Solutions/feature/wazuh_version
...
Bump Wazuh version
2020-07-27 09:46:27 -04:00
Wes Lambert
ac5aeb4801
Bump Wazuh version
2020-07-27 13:45:34 +00:00
weslambert
88ffd0c17c
Merge pull request #1101 from Security-Onion-Solutions/feature/wazuh_symlinks
...
Add Wazuh Wazuh symlinks for config/rules
2020-07-27 08:15:58 -04:00
Wes Lambert
51e27cadc8
Add Wazuh Wazuh symlinks for cpnfig/rules
2020-07-27 12:14:43 +00:00
weslambert
2d2bebdd9c
Merge pull request #1100 from Security-Onion-Solutions/feature/wazuh_nsm
...
Move Wazuh from /opt/so/ to /nsm/wazuh
2020-07-27 07:59:39 -04:00
Wes Lambert
958ee25f6d
Move Wazuh from /opt/so/ to /nsm/wazuh
2020-07-27 11:58:12 +00:00
weslambert
2d096ddd66
Merge pull request #1096 from Security-Onion-Solutions/fix/elastalert_thehive
...
Make sure we are searching all clusters when running rules
2020-07-24 18:05:46 -04:00
Wes Lambert
3ac9f1800b
Make sure we are searching all clusters when running rules
2020-07-24 22:04:30 +00:00
m0duspwnens
78491e1fc5
soup update salt on manager for centos - https://github.com/Security-Onion-Solutions/securityonion/issues/1091
2020-07-24 15:06:06 -04:00
William Wernert
6c9c60b8dd
Merge branch 'master' into dev
...
# Conflicts:
# VERSION
2020-07-24 11:50:34 -04:00
Doug Burks
25f6ec861a
Merge pull request #1090 from Security-Onion-Solutions/fix/2.0.2
...
Fix/2.0.2
2020-07-24 11:47:19 -04:00
Mike Reeves
2cabcd4239
Update sig file and hashes
2020-07-24 10:19:38 -04:00
Mike Reeves
91e7a474d5
Update VERIFY_ISO.md
2020-07-24 10:18:09 -04:00
Mike Reeves
79c45156c2
Update changes.json
2020-07-23 22:13:02 -04:00
Mike Reeves
31daad1e5b
Update VERIFY_ISO.md
...
still needs MD5s etc
2020-07-23 22:11:22 -04:00
Mike Reeves
650c983a2e
Update README.md
2020-07-23 22:09:05 -04:00
Mike Reeves
95bb1147ca
Update VERSION
2020-07-23 22:08:23 -04:00
Jason Ertel
ec09c064d0
If SENSOR_CHECKIN_INTERVAL_MS is still not set when using in a template, fallback to 10s
2020-07-23 21:19:45 -04:00
Jason Ertel
39426afffd
Ensure SENSOR_CHECKIN_INTERVAL_MS var is non-null before saving static pillar
2020-07-23 21:00:10 -04:00
Jason Ertel
9eeb527ea7
Include UTC parameter when providing a hyperlink to Hunt from so-import-pcap output
2020-07-23 17:18:42 -04:00
Mike Reeves
bb6871a54a
Merge pull request #1087 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERIFY_ISO.md
2020-07-23 15:29:32 -04:00
Mike Reeves
261310ce92
Update VERIFY_ISO.md
2020-07-23 15:28:37 -04:00
Mike Reeves
5417b31a10
Merge pull request #1086 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERIFY_ISO.md
2020-07-23 15:27:27 -04:00
Mike Reeves
11932366cd
Update VERIFY_ISO.md
2020-07-23 15:25:53 -04:00
Doug Burks
2f73dcc6f6
Merge pull request #1085 from Security-Onion-Solutions/fix/2.0.1sig
...
Update Signature and hashes
2020-07-23 15:23:58 -04:00
Mike Reeves
acf20bf2e8
Update Signature and hashes
2020-07-23 15:20:22 -04:00
Mike Reeves
4d84b840e4
Update Signature and hashes
2020-07-23 15:16:39 -04:00
Mike Reeves
c112dfa098
Merge pull request #1074 from Security-Onion-Solutions/fix/2.0.1sig
...
Update Signature and Download Links
2020-07-23 13:36:30 -04:00
Mike Reeves
3dd8e1998d
Update Signature and Download Links
2020-07-23 13:33:12 -04:00
Mike Reeves
d66f424e5e
Merge pull request #1072 from Security-Onion-Solutions/fix/2.0.1-pcap-interval
...
Fix/2.0.1 Update Readme and changes.json
2020-07-23 12:12:13 -04:00
Mike Reeves
4b127010ee
Update changes.json
2020-07-23 11:59:20 -04:00
Mike Reeves
75477fe9bf
Update changes.json
2020-07-23 11:56:14 -04:00
Mike Reeves
30fa9872f9
Update README.md
2020-07-23 10:38:26 -04:00
Jason Ertel
1e993da31d
Merge master into dev to pull in 2.0.1-rc.1 patch
2020-07-23 09:56:42 -04:00
Mike Reeves
42390eb8a2
Merge pull request #1069 from Security-Onion-Solutions/fix/2.0.1-pcap-interval
...
Fix/2.0.1 pcap interval and security fixes
2020-07-23 09:53:56 -04:00
Mike Reeves
ff77abfdc8
Update soup
...
Remove strelka that isn't an image. Fix formatting
2020-07-23 09:51:52 -04:00
Mike Reeves
74faab92ab
Remove variables.txt
2020-07-23 09:21:05 -04:00
Mike Reeves
201efd285a
Fix passwords from conflicting with yaml
2020-07-22 16:34:50 -04:00
Mike Reeves
6d6ba04dcd
Fix version replace
2020-07-22 16:15:32 -04:00
Mike Reeves
b24c82d49c
Fix Docker List
2020-07-22 16:09:28 -04:00
Mike Reeves
b9e6ddf7df
Clean up static.sls passwords
2020-07-22 15:50:56 -04:00
Jason Ertel
46e7d29f12
Add support for custom branches in soup
2020-07-22 14:35:50 -04:00
Jason Ertel
cb46ca4832
Ensure distributed installations have the check-in interval correctly set
2020-07-22 14:26:55 -04:00
William Wernert
f3c24f1f01
[fix] Add check for $TESTING
2020-07-21 16:43:21 -04:00
William Wernert
c70bb9e58f
Merge pull request #1053 from Security-Onion-Solutions/feature/storage-calculation
...
Feature/storage calculation
2020-07-21 16:41:12 -04:00
William Wernert
752d1bceb4
[fix] Remove old storage space check
2020-07-21 16:36:37 -04:00
William Wernert
ddf0a5055e
[fix] Exit on NO
2020-07-21 16:34:08 -04:00
William Wernert
003271127a
[feat] Only check storage during setup on a network install
2020-07-21 16:32:28 -04:00
William Wernert
c531395452
Merge branch 'dev' into feature/storage-calculation
2020-07-21 16:24:28 -04:00
William Wernert
e43829b22c
[fix] Add then to if statement
2020-07-21 16:24:13 -04:00
William Wernert
d6f7dcb630
[refactor] Changes to storage requirements
...
See #1047
2020-07-21 15:35:13 -04:00
Jason Ertel
d2df405cf0
so-import-pcap improvements: Ensure PCAP filenames with spaces are handled properly; Provide link directly to the imported logs, filtered by import ID; Require sudo access to run so-import-pcap
2020-07-21 11:07:09 -04:00
Mike Reeves
abc68c2efb
Update VERIFY_ISO.md
2020-07-21 08:51:46 -04:00
Mike Reeves
f5665ad700
Merge pull request #1045 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERIFY_ISO.md
2020-07-21 08:49:53 -04:00
Mike Reeves
3141e2eca1
Update VERIFY_ISO.md
2020-07-21 08:46:38 -04:00
Jason Ertel
3281467994
When running in automated mode, cat all piped in input to setup log
2020-07-20 20:26:35 -04:00
Jason Ertel
e881f4c92b
Increment VERSION for dev to 2.1.0-rc.2; Add more logging to troubleshoot automated setup not initiating post-installation steps
2020-07-20 17:37:53 -04:00
Mike Reeves
6c49addbec
Merge pull request #1040 from Security-Onion-Solutions/dev
...
Update ISO Signature
2020-07-20 17:01:02 -04:00
Mike Reeves
a891fed1be
Create VERIFY_ISO.md
2020-07-20 16:58:32 -04:00
Mike Reeves
bbd1e9ba74
Create KEYS
2020-07-20 16:36:23 -04:00
Doug Burks
da3b055428
Update README.md
2020-07-20 16:33:39 -04:00
Doug Burks
a7fdd21284
Update README.md
2020-07-20 16:30:25 -04:00
Mike Reeves
1b02ad0d46
Upload ISO sig
2020-07-20 16:13:07 -04:00
Josh Brower
6d1ad3f2e0
Merge pull request #1038 from Security-Onion-Solutions/dev
...
Fix for telegraf
2020-07-20 14:38:12 -04:00
Josh Patterson
666464c7f2
Merge pull request #1037 from Security-Onion-Solutions/quickfix/grafana
...
ensure telegraf hostname is lowercase
2020-07-20 14:36:49 -04:00
m0duspwnens
fc14f4d8d8
ensure telegraf hostname is lowercase
2020-07-20 14:35:47 -04:00
Doug Burks
095e637dfa
Merge pull request #1036 from Security-Onion-Solutions/dev
...
2.0.0.rc.1
2020-07-20 14:35:16 -04:00
William Wernert
edcf834635
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
...
# Conflicts:
# salt/common/tools/sbin/so-elastic-clear
2020-07-20 14:23:23 -04:00
William Wernert
9be4756a90
[fix] Resolve merge commits
2020-07-20 14:22:55 -04:00
bryant-treacle
9ff3ffc401
Issue #885 : so-elastic-clear not removing so-* indices
2020-07-20 14:21:17 -04:00
Mike Reeves
a642ea0e98
Merge branch 'master' into dev
2020-07-20 13:27:44 -04:00
Mike Reeves
0b0543045b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-07-20 10:15:53 -04:00
Mike Reeves
9565050b82
Fix Features script
2020-07-20 10:15:47 -04:00
Jason Ertel
beda859207
Update changes.json sub-bullets to improve communication of the content
2020-07-20 08:47:39 -04:00
Jason Ertel
bd70fdbb33
Corrected JSON syntax to avoid a blank Overview screen in SOC; Applied HTML formatting of changes.json summaries for better markup handling.
2020-07-19 08:11:57 -04:00
Jason Ertel
053f27eb35
Run setterm, to blank terminal, only for non-automated installations
2020-07-19 06:58:28 -04:00
Mike Reeves
514df1211e
Soup Update
2020-07-18 23:34:45 -04:00
Mike Reeves
28a954db82
Soup Update
2020-07-18 23:24:22 -04:00
Mike Reeves
0302d2b6ac
Soup Update
2020-07-18 23:19:52 -04:00
Mike Reeves
74e6846e84
Soup Update
2020-07-18 23:19:14 -04:00
Mike Reeves
954c12acfb
Soup Update
2020-07-18 23:16:39 -04:00
Mike Reeves
872f849204
Soup Update
2020-07-18 23:12:53 -04:00
Mike Reeves
5bab5ae7d1
Soup Update
2020-07-18 23:10:37 -04:00
Mike Reeves
27568f0047
Soup Update
2020-07-18 23:09:18 -04:00
Mike Reeves
095a87dc46
Soup Update
2020-07-18 23:06:31 -04:00
Mike Reeves
847a9d76e0
Soup Update
2020-07-18 23:02:28 -04:00
Mike Reeves
fbc8a90083
Soup Update
2020-07-18 22:58:15 -04:00
Mike Reeves
7b1ca5f361
Fix common tools permissions
2020-07-18 22:50:08 -04:00
Mike Reeves
1bcbcb1f98
Fix idstools jinja
2020-07-18 22:46:57 -04:00
Mike Reeves
517edf1938
Update Release Notes
2020-07-18 17:55:35 -04:00
Mike Reeves
64bd70bb48
Update Release Notes
2020-07-18 17:50:25 -04:00
Mike Reeves
f4c23fcc2e
Merge pull request #1033 from Security-Onion-Solutions/fix/idstools
...
Fix/idstools
2020-07-18 17:33:54 -04:00
Mike Reeves
16906b8361
Merge branch 'dev' into fix/idstools
2020-07-18 17:32:54 -04:00
Mike Reeves
3de2afe618
Fix final bugs
2020-07-18 17:29:11 -04:00
Jason Ertel
23420ace56
Prevent nmcli, setterm, and echo output from leaking to console and crontab output
2020-07-18 08:38:09 -04:00
Mike Reeves
1d24d7bc7f
Misc pillars
2020-07-17 17:38:10 -04:00
Mike Reeves
b75487dc74
Update so-functions
2020-07-17 17:36:13 -04:00
Mike Reeves
aaca5c7ff2
Update rulecat.conf
2020-07-17 17:35:16 -04:00
Mike Reeves
2e2bcfb3b7
Fix functions so pillars are correct
2020-07-17 17:33:36 -04:00
Mike Reeves
e78a14e2c7
Merge pull request #1032 from Security-Onion-Solutions/fix/idstools
...
IDSTOOLS Pillar Items
2020-07-17 16:00:59 -04:00
Mike Reeves
693a101d34
IDSTOOLS Pillar Items
2020-07-17 15:59:58 -04:00
William Wernert
3c855ed793
[fix] Set $percentage since it only exists in previous subshell
2020-07-17 15:38:14 -04:00
Mike Reeves
d3529686cc
Merge pull request #1031 from Security-Onion-Solutions/quickfix/bro2zeeklogs
...
change reference from bro to zeek
2020-07-17 14:53:47 -04:00
m0duspwnens
7176fdf7a1
rename from bro to zeek
2020-07-17 14:53:01 -04:00
m0duspwnens
e3efaee864
change reference from bro to zeek
2020-07-17 14:41:44 -04:00
Mike Reeves
74f6f2abee
Update soup
2020-07-17 13:38:55 -04:00
Josh Patterson
0d737b8f41
Merge pull request #1030 from Security-Onion-Solutions/quickfix/schedulesetup
...
remove quotes
2020-07-17 13:30:43 -04:00
William Wernert
5570c778ad
[feat] Add hostname formatting check for manager hostname
2020-07-17 13:30:08 -04:00
m0duspwnens
6ba342c084
remove quotes
2020-07-17 13:30:05 -04:00
William Wernert
1309e0c7ad
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-17 13:09:21 -04:00
William Wernert
446817353d
[refactor] | tee ... >> to > ... 2>> to show errors in log
2020-07-17 13:09:18 -04:00
Josh Brower
3c6ae08d4d
Merge pull request #1029 from Security-Onion-Solutions/bugfix/fleet-eval
...
Kibana Fleet Pivot Fix
2020-07-17 13:01:08 -04:00
Josh Brower
da155b5dea
Kibana Fleet Pivot Fix
2020-07-17 13:00:03 -04:00
William Wernert
1abf324654
[fix] Set py_ver_url_path for all install types
2020-07-17 12:59:17 -04:00
William Wernert
d88e15ecb4
[fix] Use | tee instead of redirect when already redirecting to setup log
2020-07-17 12:33:25 -04:00
William Wernert
9cbc7ad8f5
[fix] guage -> gauge
2020-07-17 12:08:16 -04:00
William Wernert
1bd154760d
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-17 11:09:11 -04:00
William Wernert
ede250d9e4
[feat] Merge access method dialogs together
2020-07-17 11:09:08 -04:00
William Wernert
d97271cca3
[fix] Don't drop to shell while running so-allow
2020-07-17 11:08:31 -04:00
Mike Reeves
17e3bde2f8
Create home dir for adduser function
2020-07-17 10:55:30 -04:00
Josh Brower
083e43b26b
Merge pull request #1028 from Security-Onion-Solutions/bugfix/fleet-eval
...
Eval Ubuntu Fleet fix
2020-07-17 10:27:51 -04:00
Josh Brower
6e4eb76393
Eval Ubuntu Fleet fix
2020-07-17 10:25:48 -04:00
Josh Patterson
5633eed6a4
Merge pull request #1027 from Security-Onion-Solutions/quickfix/schedulesetup
...
dont try to copy schedules if the directory is empty
2020-07-17 10:24:50 -04:00
m0duspwnens
2541f4d8e8
dont try to copy schedules if the directory is empty
2020-07-17 10:23:51 -04:00
Josh Patterson
e6b795e8b3
Merge pull request #1026 from Security-Onion-Solutions/quickfix/schedulesetup
...
dont try to copy schedules if the directory is empty
2020-07-17 10:07:17 -04:00
m0duspwnens
6f077e66e6
dont try to copy schedules if the directory is empty
2020-07-17 10:05:54 -04:00
weslambert
2341d9592e
Merge pull request #1025 from Security-Onion-Solutions/fix/wazuh_cleanup
...
Change verbiage
2020-07-17 09:39:21 -04:00
weslambert
e91aa751a7
Change verbiage
2020-07-17 09:38:43 -04:00
William Wernert
958d614bef
[fix] Only show motd ip message on manager node
2020-07-17 09:21:47 -04:00
Josh Brower
442e870c16
Merge pull request #1024 from Security-Onion-Solutions/bugfix/kibana-dashboard-updates
...
Kibana dashboard updates
2020-07-17 08:15:33 -04:00
Josh Brower
32a6f825c2
Kibana dashboard updates
2020-07-17 08:14:37 -04:00
Josh Patterson
06c4924b70
Merge pull request #1023 from Security-Onion-Solutions/quickfix/yum
...
change from manager to master for salt config.get
2020-07-16 21:06:35 -04:00
m0duspwnens
cc77a50d8d
change from manager to master for salt config.get
2020-07-16 21:05:44 -04:00
Mike Reeves
2d68d5419b
fix adtotab perms
2020-07-16 19:47:15 -04:00
Mike Reeves
258d9d3bfc
change salt perms
2020-07-16 17:07:04 -04:00
Mike Reeves
03ff592aa4
Merge pull request #1022 from Security-Onion-Solutions/fix/telegrafperms
...
Fix salt refresh script
2020-07-16 16:38:40 -04:00
Mike Reeves
21f09a9cd5
Fix salt refresh script
2020-07-16 16:37:48 -04:00
Josh Brower
4fd1daeca1
Merge pull request #1021 from Security-Onion-Solutions/bugfix/fleet-packages-urlbase
...
Osquery packages hostname fix
2020-07-16 16:36:30 -04:00
Josh Brower
51beb52bb8
Osquery packages hostname fix
2020-07-16 16:35:51 -04:00
Mike Reeves
20446ed3aa
Merge pull request #1020 from Security-Onion-Solutions/fix/telegrafperms
...
Fix/telegrafperms
2020-07-16 16:34:04 -04:00
Mike Reeves
d31ce4aa48
Fix soup issues
2020-07-16 16:32:38 -04:00
Mike Reeves
07626905c5
Fix telegraf script perms
2020-07-16 15:20:11 -04:00
Josh Patterson
5634446fcb
Merge pull request #1019 from Security-Onion-Solutions/quickfix/lstoes
...
fix the container watch for logstash container state
2020-07-16 15:06:29 -04:00
m0duspwnens
c61a52cc5e
fix the container watch for logstash container state
2020-07-16 15:05:54 -04:00
William Wernert
25dbcfaebe
[refactor] Add check for "Result: False" in setup
2020-07-16 14:08:56 -04:00
Josh Patterson
f1d8548913
Merge pull request #1017 from Security-Onion-Solutions/quickfix/lstoes
...
dont run templates script if there arent templates
2020-07-16 13:37:15 -04:00
m0duspwnens
9606d86e84
dont run templates script if there arent templates
2020-07-16 13:36:44 -04:00
William Wernert
8f62cd8f82
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-16 11:33:20 -04:00
William Wernert
a041be5c21
[fix] Don't force YARA Strelka rules during setup
2020-07-16 11:33:11 -04:00
phil1090
5d2c6d330f
Update README.md
2020-07-16 10:15:40 -04:00
Josh Patterson
582edd7aac
Merge pull request #1016 from Security-Onion-Solutions/quickfix/lstoes
...
including elasticsearch in logstash state
2020-07-16 10:13:18 -04:00
m0duspwnens
f10f47ad4e
including elasticsearch in logstash state
2020-07-16 10:12:10 -04:00
weslambert
f8bb094546
Merge pull request #1014 from Security-Onion-Solutions/fix/strelka_standalone
...
Fix module eval
2020-07-16 09:32:06 -04:00
Wes Lambert
8275f458a1
Fix module eval
2020-07-16 13:30:38 +00:00
William Wernert
5190e5d434
Update README.md
2020-07-16 09:20:20 -04:00
weslambert
7fecfdab32
Update README.md
2020-07-16 08:14:47 -04:00
weslambert
f7d527bb90
Update README.md
2020-07-16 08:14:23 -04:00
Josh Brower
350d2fbeda
Update README.md
2020-07-15 19:07:25 -04:00
Josh Brower
29c28fcb5e
Update README.md
2020-07-15 19:06:36 -04:00
Josh Brower
48c9244a81
Update README.md
2020-07-15 19:05:49 -04:00
Mike Reeves
a4672dedee
Update README.md
2020-07-15 18:17:05 -04:00
Mike Reeves
473606371a
Fix Features Download
2020-07-15 17:49:13 -04:00
Mike Reeves
d71dc89b13
New SOUP
2020-07-15 17:46:33 -04:00
Jason Ertel
9781d8d0e7
Ensure permissions are consistently applied to all imported PCAP files
2020-07-15 13:53:28 -04:00
Jason Ertel
0a976861f3
Dynamically set sensor checkin interval; allow overrides if var is preset
2020-07-15 13:22:14 -04:00
Josh Brower
80e081e828
Merge pull request #1010 from Security-Onion-Solutions/bugfix/playbook-anonymous-perms
...
Playbook anonymous perms fix
2020-07-15 12:40:47 -04:00
Josh Brower
d11ef08961
Playbook anonymous perms fix
2020-07-15 12:37:04 -04:00
Jason Ertel
3c42f50e99
Ensure whiptail success/summary screen is final step before reboot
2020-07-15 11:12:48 -04:00
Josh Patterson
83428d4785
Merge pull request #1009 from Security-Onion-Solutions/quickfix/lstoes
...
load templates for es for eval
2020-07-15 08:32:50 -04:00
m0duspwnens
e4fff05dbc
load templates for es for eval
2020-07-15 08:30:43 -04:00
Jason Ertel
9dc1151347
Imported logs are sent to so-import index on eval installations
2020-07-14 22:59:42 -04:00
Jason Ertel
b53ce392ef
Improve grammer of summary screen in whiptail
2020-07-14 22:45:38 -04:00
Jason Ertel
c0960e58e8
Improve grammer of so-allow input prompt
2020-07-14 19:42:53 -04:00
Josh Patterson
549916306c
Merge pull request #1008 from Security-Onion-Solutions/quickfix/lstoes
...
Quickfix/lstoes
2020-07-14 17:37:19 -04:00
m0duspwnens
5cf71596b2
add curlys
2020-07-14 17:36:52 -04:00
Jason Ertel
acb800d1c9
Using static UID for Grafana overview dashboard to allow SOC to directly link to those dashboards
2020-07-14 17:36:30 -04:00
Jason Ertel
9bbbaa485c
Switch PM to AM since we want to span midnight to midnight
2020-07-14 17:36:30 -04:00
m0duspwnens
acaec6c125
remove recurse causing issues
2020-07-14 17:12:29 -04:00
Josh Brower
e7e1982862
Merge pull request #1007 from Security-Onion-Solutions/bugfix/ingest-parsing
...
Parsing & Hunt query updates
2020-07-14 17:00:04 -04:00
Josh Brower
8647944ae6
Parsing & Hunt query updates
2020-07-14 16:59:06 -04:00
Mike Reeves
55056f3193
Merge pull request #1006 from Security-Onion-Solutions/fix/perms
...
Change opt/so perms
2020-07-14 16:19:02 -04:00
m0duspwnens
57bf23d83c
move templates from logstash to elasticsearch
2020-07-14 16:07:46 -04:00
Doug Burks
a1e6a85a68
explicitly set Suricata timestamp timezone to UTC
2020-07-14 15:49:46 -04:00
weslambert
7a36803e2c
Merge pull request #1002 from Security-Onion-Solutions/fix/strelka_observer
...
Add observer name for Strelka events
2020-07-14 13:39:52 -04:00
Wes Lambert
f9df39977b
Add observer name for Strelka events
2020-07-14 17:38:43 +00:00
weslambert
7ed902c0ae
Merge pull request #1001 from Security-Onion-Solutions/fix/suricata_timestamp
...
Convert message timestamp to @timestamp
2020-07-14 13:34:58 -04:00
Josh Brower
47388fa98d
Merge pull request #998 from Security-Onion-Solutions/bugfix/fleet-soimage-fix
...
Fleet reactor fix
2020-07-14 13:06:52 -04:00
Josh Brower
ba8395fc11
Fleet reactor fix
2020-07-14 13:04:29 -04:00
William Wernert
3df5904269
Merge pull request #979 from Security-Onion-Solutions/feature/setup
...
Feature/setup
2020-07-14 11:17:03 -04:00
William Wernert
caf9e3f75a
[fix] Redirect hive_init output to log
2020-07-14 11:13:50 -04:00
William Wernert
ad3c4c4950
[fix] master -> manager
2020-07-14 11:09:12 -04:00
Mike Reeves
57cd2cdbeb
Change opt/so perms
2020-07-14 10:37:49 -04:00
William Wernert
4ab90a9a30
[fix] Move redirect var to function after $MAINIP has been set
2020-07-14 10:12:51 -04:00
Mike Reeves
f2d9abf1a5
Merge pull request #996 from Security-Onion-Solutions/fix/curator
...
Add all actions to cron
2020-07-14 10:05:27 -04:00
Mike Reeves
e404a41d8a
Add all actions to cron
2020-07-14 10:04:15 -04:00
Mike Reeves
15be31af6d
Merge pull request #995 from Security-Onion-Solutions/fix/curator
...
Fix spelling error in actions
2020-07-14 09:43:41 -04:00
Jason Ertel
67f2edce28
Resolve merge conflict that reverted import URL back to Kibana
2020-07-14 09:40:16 -04:00
Mike Reeves
d4e6189f6e
Fix spelling error in actions
2020-07-14 09:39:56 -04:00
Wes Lambert
d6afde90b0
Convert message timestamp to @timestamp
2020-07-14 13:37:00 +00:00
Josh Brower
0c9c66f6e1
Merge pull request #993 from Security-Onion-Solutions/bugfix/playbook-init
...
Bugfix/playbook init
2020-07-14 09:14:56 -04:00
Josh Brower
2c72940010
Playbook db init fix
2020-07-14 09:09:55 -04:00
Josh Brower
b884e09e7a
Playbook db init fix
2020-07-14 09:09:47 -04:00
William Wernert
178ac79da8
[refactor] Set $REDIRECTIT outside of subshell
2020-07-14 09:05:09 -04:00
Jason Ertel
09c460dbe9
Switch to final image repository prefix 'securityonion' for RC1
2020-07-14 00:45:20 -04:00
Jason Ertel
d75d64c8ed
Mount imported pcap dirs into sensoroni container for imported PCAP pivots
2020-07-13 21:03:47 -04:00
Jason Ertel
8f66a27f07
Refactor image repository to a single variable
2020-07-13 18:26:43 -04:00
Jason Ertel
f67f0679ae
Add new so-pcaptools image to docker list for network install
2020-07-13 16:02:22 -04:00
William Wernert
aa4d435020
[fix] Don't run so-allow before setup complete menu
2020-07-13 15:21:05 -04:00
William Wernert
81c8185cb5
[refactor] Delete check for network install since we check /nsm now
2020-07-13 14:53:47 -04:00
William Wernert
1cf0732991
Merge branch 'dev' into feature/setup
...
# Conflicts:
# setup/so-setup
2020-07-13 14:35:24 -04:00
William Wernert
00f178197c
[fix] Evaluate $success early to avoid checking against other output
2020-07-13 14:34:11 -04:00
Mike Reeves
98811c147d
Merge pull request #989 from Security-Onion-Solutions/feature/isosetup
...
Fix username so install works properly from ISO
2020-07-13 14:27:20 -04:00
Mike Reeves
55869c4f81
Fix username so install works properly from ISO
2020-07-13 14:25:10 -04:00
William Wernert
c585713122
[style] Change SO_ERROR check to non-empty check
2020-07-13 13:28:54 -04:00
Josh Patterson
8dc63a1f52
Merge pull request #987 from Security-Onion-Solutions/quickfix/patchschedule
...
Quickfix/patchschedule
2020-07-13 11:35:00 -04:00
m0duspwnens
59c00057b1
fix patch pillar, select patch hours on 1 screen
2020-07-13 11:34:30 -04:00
m0duspwnens
ef3c5d1fe0
fix patch pillar, select patch hours on 1 screen
2020-07-13 11:31:37 -04:00
William Wernert
06aa63dd14
Merge branch 'dev' into feature/setup
2020-07-13 11:24:04 -04:00
Mike Reeves
3bc492ebde
Merge pull request #986 from Security-Onion-Solutions/feature/isosetup
...
Removes create admin user from setup
2020-07-13 11:13:10 -04:00
Mike Reeves
dc0aa270d9
Fix ISO rsync
2020-07-13 11:12:11 -04:00
Mike Reeves
14faa3b898
Clean up bash profile
2020-07-13 11:08:04 -04:00
Mike Reeves
a6cceef986
Removes create admin user from setup
2020-07-13 10:55:55 -04:00
Josh Patterson
db80675609
Merge pull request #985 from Security-Onion-Solutions/quickfix/elasticpillar
...
prevent elasticsearch pillar being added twice for managers and helix
2020-07-13 09:48:44 -04:00
m0duspwnens
242e17b329
prevent elasticsearch pillar being added twice for managers and helix
2020-07-13 09:45:11 -04:00
William Wernert
c31c24ccd8
[fix] Check /nsm instead of / for free space
2020-07-13 09:12:24 -04:00
Josh Brower
e62381e998
Merge pull request #982 from Security-Onion-Solutions/bugfix/alerting
...
Misc fixes
2020-07-10 19:50:27 -04:00
Josh Brower
65062d93f4
Misc fixes
2020-07-10 19:43:43 -04:00
William Wernert
99dc16d644
Merge pull request #981 from Security-Onion-Solutions/bugfix/disk-space-network-only
...
[fix] Only check for disk space on a network install
2020-07-10 18:52:48 -04:00
William Wernert
605daaf66b
[fix] Only check for disk space on a network install
2020-07-10 18:45:34 -04:00
William Wernert
056b3a0629
Merge branch 'dev' into feature/setup
...
# Conflicts:
# setup/so-setup
2020-07-10 18:41:24 -04:00
William Wernert
f9c8f8cdca
[fix] Set SKIP_REBOOT on any failure during setup
2020-07-10 18:40:39 -04:00
William Wernert
aee304e5d5
[fix] master -> manager
2020-07-10 18:13:20 -04:00
William Wernert
4cfecae3b2
[ix] Remove grafanapassword pillar key
2020-07-10 17:59:51 -04:00
William Wernert
ce7373501b
[fix] Add fallback for hive + cortex users
2020-07-10 17:58:47 -04:00
William Wernert
571e97cdf7
Merge branch 'dev' into feature/setup
...
# Conflicts:
# salt/thehive/scripts/cortex_init
# salt/thehive/scripts/hive_init
# setup/so-functions
# setup/so-whiptail
2020-07-10 17:42:56 -04:00
William Wernert
547298fce0
[refactor] Hide output for cortex and thehive init scripts
2020-07-10 17:34:33 -04:00
weslambert
ef64048fc6
Merge pull request #978 from Security-Onion-Solutions/fix/sensor-clean
...
Fix value
2020-07-10 17:17:57 -04:00
weslambert
eb2dc0be4c
Fix value
2020-07-10 17:17:33 -04:00
Josh Patterson
69023cdb31
Merge pull request #976 from Security-Onion-Solutions/issue/404
...
Issue/404
2020-07-10 16:28:28 -04:00
m0duspwnens
13af4cacb0
merge with dev and resolve conflicts
2020-07-10 16:27:10 -04:00
Mike Reeves
755f47da2d
Merge pull request #975 from Security-Onion-Solutions/fix/lstemplate
...
Fix/lstemplate
2020-07-10 15:55:50 -04:00
Mike Reeves
46d572fa8c
Fix Filebeat spacing
2020-07-10 15:51:12 -04:00
weslambert
9b079df9f5
Merge pull request #974 from Security-Onion-Solutions/fix/sensor_clean
...
Fix/sensor clean
2020-07-10 15:35:57 -04:00
Wes Lambert
d7f7fb801c
Set role
2020-07-10 19:35:27 +00:00
Wes Lambert
37ab252e01
Add sensor proc eval
2020-07-10 19:30:08 +00:00
William Wernert
f56811e745
[feat] Use setup user+pass for TheHive, Cortex, and Fleet as well
2020-07-10 14:40:04 -04:00
William Wernert
67c8836cd6
[fix] Use 100GB min space for standalone also
2020-07-10 14:39:02 -04:00
William Wernert
72aa91b763
[feat] Add message in setup and motd on where to access SOC
2020-07-10 14:38:21 -04:00
m0duspwnens
9730c4561d
add elasticsearch pillar to manager
2020-07-10 14:08:39 -04:00
Jason Ertel
358ef78cd9
Do not stop curator since imported data will now be placed into a longer term so-import index
2020-07-10 13:58:52 -04:00
Jason Ertel
811bbb4cb0
Require sudo to run an import
2020-07-10 13:58:52 -04:00
weslambert
33375a0809
Merge pull request #973 from Security-Onion-Solutions/fix/curator_logsizelimit
...
Move zeek_clean to so-sensor-clean
2020-07-10 13:57:58 -04:00
Wes Lambert
6e99ca600f
Move zeek_clean to so-sensor-clean
2020-07-10 17:56:40 +00:00
Mike Reeves
5eb33d5ac7
Logstash Import and Template Assignment
2020-07-10 13:53:55 -04:00
m0duspwnens
24b8f81e38
merge with dev and resolve conflicts
2020-07-10 12:20:14 -04:00
Mike Reeves
bbef7955b2
Update eval.sls
2020-07-10 11:36:46 -04:00
Mike Reeves
9da4dd0ac9
Merge pull request #971 from Security-Onion-Solutions/feature/espillarz
...
Feature/espillarz
2020-07-10 11:35:24 -04:00
Mike Reeves
c656bec9c0
Merge branch 'dev' into feature/espillarz
2020-07-10 11:35:12 -04:00
m0duspwnens
0a1b5f29eb
merge with dev and resolv conflicts
2020-07-10 10:48:49 -04:00
m0duspwnens
1f48dc765e
merge with dev and resolv conflicts
2020-07-10 10:36:48 -04:00
Mike Reeves
3706aa76d8
Add jinja extension
2020-07-10 10:35:31 -04:00
Doug Burks
2ce254dfb0
add new DPD query to Hunt
2020-07-10 06:00:36 -04:00
Doug Burks
f5114c034d
change Log Type query in Hunt to include event.dataset in the groupby
2020-07-10 05:52:10 -04:00
Mike Reeves
1a6c4c12b4
Fix elasticsearch yaml
2020-07-09 21:56:32 -04:00
Jason Ertel
6bfd777d25
Enabled elastalert log
2020-07-09 21:34:35 -04:00
Mike Reeves
8ef18f9044
Fiz pillar
2020-07-09 18:51:59 -04:00
m0duspwnens
b2e7a4221c
master to manager for ssl signing policy
2020-07-09 17:19:17 -04:00
Mike Reeves
9a7035326d
Update Logstash pillar
2020-07-09 17:09:20 -04:00
m0duspwnens
9c2dcd2318
fix reference to master grain
2020-07-09 17:06:44 -04:00
Mike Reeves
ad6c9e7fe9
recurse actions for curator
2020-07-09 16:58:35 -04:00
Mike Reeves
6094d19b0b
Make hot default
2020-07-09 16:54:31 -04:00
Mike Reeves
3c6465bb7f
ES Jinja the config
2020-07-09 16:42:39 -04:00
Jason Ertel
33179141a1
Enable PCAP pivots from imports
2020-07-09 16:11:38 -04:00
m0duspwnens
5ca3ecf4bd
fix reference to master grain
2020-07-09 15:42:39 -04:00
Josh Brower
7b91704894
Merge pull request #970 from Security-Onion-Solutions/defensivedepth-patch-2-host-pillar
...
Update so-setup
2020-07-09 15:32:38 -04:00
Josh Brower
58d290aa57
Update so-setup
2020-07-09 15:32:19 -04:00
William Wernert
c5eff1d89e
[feat][WIP] Add option to run so-allow -a <ip/cidr> during setup
2020-07-09 14:47:55 -04:00
Josh Brower
206bdc60f3
Merge pull request #967 from Security-Onion-Solutions/feature/low-level-alerts
...
Feature - low level alerts
2020-07-09 13:56:31 -04:00
m0duspwnens
bdd0f64462
add period
2020-07-09 13:54:48 -04:00
Josh Brower
52f7111e1d
Feature - low level alerts
2020-07-09 13:53:55 -04:00
m0duspwnens
aea3099df6
change wording
2020-07-09 13:52:31 -04:00
m0duspwnens
823ee42120
https://github.com/Security-Onion-Solutions/securityonion/issues/404
2020-07-09 13:45:24 -04:00
Mike Reeves
7c6677916a
Curator actions
2020-07-09 12:56:29 -04:00
Mike Reeves
357efac873
Add index specific curator settings
2020-07-09 12:10:53 -04:00
Mike Reeves
ca20279a09
Add curator to static pillar
2020-07-09 12:00:07 -04:00
Mike Reeves
96bcf9d9f3
Add temaplte files per index
2020-07-09 11:51:55 -04:00
m0duspwnens
3cf31e2460
https://github.com/Security-Onion-Solutions/securityonion/issues/404
2020-07-09 11:27:06 -04:00
Mike Reeves
9c2f7d574d
Add ES settings to pillar
2020-07-09 11:19:02 -04:00
Mike Reeves
2c32c24bf0
Fix logstash logic
2020-07-09 09:16:48 -04:00
Josh Patterson
2bfdb09674
Merge pull request #966 from Security-Onion-Solutions/issue/959
...
fix typo
2020-07-09 08:52:30 -04:00
m0duspwnens
d539f1ddf8
fix typo
2020-07-09 08:51:53 -04:00
Doug Burks
8dfafffef0
remove duplicate line for message2.conn_uids
2020-07-09 06:44:08 -04:00
weslambert
818f7f56b2
Merge pull request #965 from Security-Onion-Solutions/feature/add_gcp_check
...
Add GCP and make cloud check more generic
2020-07-08 23:31:37 -04:00
weslambert
c01047fad2
Add /dev/null
2020-07-08 23:30:50 -04:00
weslambert
889ba67d85
Move EC2 to more generic cloud verbiage
2020-07-08 23:27:46 -04:00
weslambert
ce00d829e1
Move EC2 to more generic cloud verbiage and check for GCP
2020-07-08 23:26:48 -04:00
weslambert
67fb46f519
Merge pull request #963 from Security-Onion-Solutions/fix/curator_logsizelimit
...
Add standalone evaluation for log_size_limit
2020-07-08 15:40:54 -04:00
Josh Patterson
99ce77e9bd
Merge pull request #962 from Security-Onion-Solutions/issue/959
...
pillarize yum.conf installonly_limit and proxy
2020-07-08 15:39:22 -04:00
Wes Lambert
f2cea273b6
Add standalone evaluation for log_size_limit
2020-07-08 19:39:14 +00:00
m0duspwnens
59061926f0
pillarize yum.conf installonly_limit and proxy
2020-07-08 15:37:20 -04:00
weslambert
beda67d2a9
Merge pull request #955 from Security-Onion-Solutions/fix/strelka_message_drop
...
Drop message field and original exiftool keys
2020-07-08 10:56:06 -04:00
weslambert
4cf31e1ee7
Drop message field and original exiftool keys
2020-07-08 10:55:40 -04:00
Doug Burks
fef803a86c
Add ignore_failure to geoip processor calls #942
2020-07-08 10:41:14 -04:00
Josh Patterson
3352eb77e9
Merge pull request #954 from Security-Onion-Solutions/issue/825
...
add pillar example for filebeat inputs/output
2020-07-08 09:53:18 -04:00
m0duspwnens
5f68542241
add pillar example for filebeat inputs/output
2020-07-08 09:52:25 -04:00
weslambert
9c11de5455
Merge pull request #953 from Security-Onion-Solutions/fix/zeek_files_uid
...
Rename uids to uid
2020-07-08 09:40:04 -04:00
weslambert
b25a3b6986
Rename uids to uid
2020-07-08 09:39:37 -04:00
weslambert
88b7a31195
Merge pull request #952 from Security-Onion-Solutions/fix/wazuh_authdport
...
Add Wazuh Authd Port
2020-07-08 09:26:28 -04:00
weslambert
987acaeb7b
Add Wazuh Authd Port
2020-07-08 09:26:04 -04:00
Josh Brower
10cbc96f48
Merge pull request #948 from Security-Onion-Solutions/fix/fleet
...
Fleet setup bugfix
2020-07-07 20:56:43 -04:00
Josh Brower
b4b122dbd9
Fleet setup bugfix
2020-07-07 20:55:47 -04:00
William Wernert
4231fb1d1a
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-07 17:38:30 -04:00
William Wernert
72a98b33a7
[fix] Change test to check value of $SO_ERROR
2020-07-07 17:38:23 -04:00
Mike Reeves
cdce804c9f
Update 9700_output_strelka.conf.jinja
2020-07-07 17:36:49 -04:00
weslambert
2992938596
Merge pull request #947 from Security-Onion-Solutions/fix/strelka_exiftool
...
Add fields for exiftool keys
2020-07-07 17:13:57 -04:00
Mike Reeves
fc377cd3c1
Merge pull request #945 from Security-Onion-Solutions/issue/929
...
SSL Lockdown
2020-07-07 16:31:33 -04:00
Mike Reeves
1954a389b0
Update so-functions
2020-07-07 16:12:07 -04:00
Mike Reeves
9576151993
Merge pull request #944 from Security-Onion-Solutions/issue/937
...
Issue/937
2020-07-07 16:07:47 -04:00
Wes Lambert
3b50ce032a
Add fields for exiftool keys
2020-07-07 20:02:09 +00:00
Josh Patterson
07cc89e4d6
Merge pull request #943 from Security-Onion-Solutions/issue/825
...
Pillarize filebeat inputs and output
2020-07-07 15:51:08 -04:00
m0duspwnens
fff713db85
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/825
2020-07-07 15:48:47 -04:00
Mike Reeves
eccfaf94fb
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/937
2020-07-07 15:10:12 -04:00
Jason Ertel
f4f189cc50
correct capitalization of true
2020-07-07 14:28:11 -04:00
William Wernert
640cfee3e1
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-07 13:13:28 -04:00
William Wernert
3815f7e58e
[refactor] Edit logic around setup failure/completion
...
* Always run `install_cleanup` and `so-allow`
* Change if statement to check whether `$success != 0` or if `$SO_ERROR` was set
* Set `$IP` only for `so-allow` instead of exporting it
2020-07-07 13:12:46 -04:00
William Wernert
1d47cec928
[refactor] Move install_cleanup outside of whiptail functions
2020-07-07 13:02:58 -04:00
William Wernert
0b995533ea
[refactor] Only notify user of error found during setup
2020-07-07 13:01:29 -04:00
Mike Reeves
ec89ab39ac
Update 9999_output_redis.conf.jinja
2020-07-07 11:56:45 -04:00
weslambert
34e06ecde1
Merge pull request #940 from Security-Onion-Solutions/feature/strelka_fuid
...
Add Zeek FUID for Strelka records
2020-07-07 11:01:09 -04:00
Wes Lambert
e0570e1db7
Add Zeek FUID for Strelka records
2020-07-07 15:00:01 +00:00
Mike Reeves
c59096d9bd
rename node pillar to elasticsearch
2020-07-07 10:42:12 -04:00
Jason Ertel
62cc02301e
Do not attempt to install a plugin or bc command if already exists
2020-07-07 10:28:15 -04:00
weslambert
d334d5ab83
Merge pull request #938 from Security-Onion-Solutions/fix/strelka_filebeat
...
Fix pillar reference for Strelka/FB
2020-07-07 09:48:19 -04:00
Wes Lambert
2fdd5fd77b
Fix pillar reference for Strelka/FB
2020-07-07 13:46:57 +00:00
William Wernert
e2c9184b29
[fix][refactor] Don't use relative path in so-setup-network
2020-07-07 08:45:28 -04:00
Mike Reeves
291ac3c597
Fix SSL Perms
2020-07-06 17:24:04 -04:00
Mike Reeves
be5f4b04c6
Fix SSL Perms
2020-07-06 17:21:23 -04:00
Mike Reeves
cc6d0c1cb5
Merge pull request #935 from Security-Onion-Solutions/issue/929
...
Change grafana to use anon auth
2020-07-06 16:45:19 -04:00
Mike Reeves
3b452ab597
Change grafana to use anon auth
2020-07-06 16:39:43 -04:00
Mike Reeves
cc2f023840
Merge pull request #934 from Security-Onion-Solutions/issue/142
...
Issue/142
2020-07-06 16:12:48 -04:00
Mike Reeves
f05e366d49
Fix salt upgrade script
2020-07-06 15:56:55 -04:00
Mike Reeves
be3390a796
Fix Logstash state
2020-07-06 15:53:21 -04:00
Josh Patterson
da0a0ae6ae
Merge pull request #933 from Security-Onion-Solutions/quickfix/firewall
...
add elasticsearch_rest to assigned hostgroups where missing
2020-07-06 15:20:00 -04:00
m0duspwnens
b4e556496b
add elasticsearch_rest to assigned hostgroups where missing
2020-07-06 15:18:47 -04:00
Mike Reeves
623c37f1f5
Merge remote-tracking branch 'remotes/origin/dev' into issue/142
2020-07-06 14:35:46 -04:00
Mike Reeves
1016315196
Change Logic for logstash
2020-07-06 13:58:38 -04:00
Mike Reeves
087080d583
Add logix for logstash_settings
2020-07-06 13:16:40 -04:00
William Wernert
57bbb02c65
[refactor][fix] Move nmcli status list gen to a function
...
nmcli is only assured to be installed after detect_os is run so move this command to a function so it can run after detect_os
2020-07-02 17:18:56 -04:00
William Wernert
99d490bc06
[fix][refactor] Move detect_ec2 and add echo statement
2020-07-02 17:15:46 -04:00
bryant-treacle
cfeb95a718
Merge pull request #924 from Security-Onion-Solutions/feature/so-container-scripts
...
Additional so-container scripts Issue # 701
2020-07-02 14:42:49 -04:00
William Wernert
b9a176201f
Merge pull request #913 from Security-Onion-Solutions/feature/setup-changes
...
Feature/setup changes
2020-07-02 14:01:46 -04:00
William Wernert
d2ba25e784
Merge branch 'dev' into feature/setup-changes
...
# Conflicts:
# setup/so-setup
2020-07-02 14:00:10 -04:00
weslambert
0bfa3d486e
Merge pull request #923 from Security-Onion-Solutions/fix/es-allow
...
Fix my typo
2020-07-02 13:32:45 -04:00
weslambert
bbc752b6d9
Fix my typo
2020-07-02 13:32:19 -04:00
Josh Brower
518c8db3de
Merge pull request #922 from Security-Onion-Solutions/feature/low-level-alerts
...
Initial commit - Low Level Alerts
2020-07-02 12:18:03 -04:00
Josh Brower
69ace6fbfa
Initial commit - Low Level Alerts
2020-07-02 12:16:56 -04:00
Jason Ertel
cf6a229f51
Import now requires execution on a sensor node due to the need for zeek and suricata; Automatically stop curator if curator is installed
2020-07-02 12:07:30 -04:00
Mike Reeves
541de278c9
Merge pull request #918 from Security-Onion-Solutions/versionfix
...
Versionfix
2020-07-02 10:39:15 -04:00
Mike Reeves
5df88f6f2d
Update so-functions
2020-07-02 10:36:28 -04:00
Mike Reeves
86a2650fbf
Update VERSION
2020-07-02 10:34:50 -04:00
Mike Reeves
c895503fe6
Merge pull request #917 from Security-Onion-Solutions/updateversion
...
Update VERSION
2020-07-02 10:06:23 -04:00
Mike Reeves
63ef3a1e07
Update VERSION
2020-07-02 10:05:12 -04:00
William Wernert
c7a3cc9c17
[fix][revert] Change source in so-allow to correct path
2020-07-02 08:58:14 -04:00
Jason Ertel
4cedacf8fd
Improve curator verbiage in so-import-pcap
2020-07-02 06:01:17 -04:00
Josh Brower
07d13b7ad0
Merge pull request #916 from Security-Onion-Solutions/defensivedepth-patch-1
...
Delete playbook_db_init.sql.backup
2020-07-02 05:32:45 -04:00
Josh Brower
7811ea5d4c
Delete playbook_db_init.sql.backup
2020-07-02 05:32:35 -04:00
Josh Brower
0f915ec85e
Merge pull request #915 from Security-Onion-Solutions/feature/playbook-updates
...
Feature/playbook updates
2020-07-02 05:31:30 -04:00
Josh Brower
3c93f9fd45
Playbook setup fix
2020-07-02 05:30:30 -04:00
bryant-treacle
0b10b775c5
Additional so-container scripts
2020-07-02 07:02:35 +00:00
Jason Ertel
ac01b8de4b
Stop curator when directed on PCAP imports
2020-07-01 22:04:07 -04:00
Doug Burks
98cfba18e9
fix zeek.ftp description
2020-07-01 20:27:40 -04:00
Doug Burks
f6adf4ed56
fix zeek.smb_mapping description
2020-07-01 20:26:51 -04:00
Doug Burks
2cbd5ffe61
fix zeek.ssh description
2020-07-01 20:26:06 -04:00
Jason Ertel
e3126064e8
Improve usage instructions for so-import-pcap
2020-07-01 17:58:02 -04:00
William Wernert
aeda3fde74
[revert] Remove regex from setup log grep
2020-07-01 17:39:04 -04:00
William Wernert
408b5ee32d
[ix] Fix if conditions
2020-07-01 17:25:26 -04:00
Jason Ertel
96e93b012d
Adjust imports for filebeat configuration to ensure import data is placed into ES
2020-07-01 17:18:01 -04:00
Josh Brower
d893aa0032
Playbook Updates
2020-07-01 16:48:07 -04:00
William Wernert
b671f28562
[fix] Rename function whiptail_bond_nics to whiptail_sensor_nics
2020-07-01 16:32:33 -04:00
William Wernert
85a3f3c277
Merge branch 'dev' into feature/setup-changes
2020-07-01 16:24:55 -04:00
William Wernert
b4f9fe5f54
[fix] Remove quotes
2020-07-01 16:24:41 -04:00
William Wernert
b75cb36058
Merge branch 'feature/ec2_setup' into feature/setup-changes
2020-07-01 16:23:48 -04:00
William Wernert
54c3327240
[refactor] Simplify ec2 detection + handling
2020-07-01 16:23:38 -04:00
Jason Ertel
d6feafb12a
Correct indentation in filebeat.yaml
2020-07-01 15:39:23 -04:00
Mike Reeves
ab42126d8e
Add logstash_settings pillar
2020-07-01 15:25:35 -04:00
Mike Reeves
5580f05daf
Add logstash pillar
2020-07-01 15:07:00 -04:00
Mike Reeves
f580da5d56
Update 9999_output_redis.conf.jinja
2020-07-01 14:45:54 -04:00
Mike Reeves
70e4ce3e98
Add batch to output
2020-07-01 14:38:51 -04:00
William Wernert
4b5571a8d6
[refactor][fix] Remove unnecessary variable
2020-07-01 13:56:15 -04:00
William Wernert
44890edc79
[refactor] Use regex in error check for setup log
2020-07-01 13:51:54 -04:00
Josh Patterson
549fd93cba
Merge pull request #912 from Security-Onion-Solutions/issue/642
...
Issue/642
2020-07-01 13:44:49 -04:00
m0duspwnens
f98c497d79
change setup and whiptail back to bro
2020-07-01 13:43:37 -04:00
Wes Lambert
26b0daf2da
Add other setup-related items for EC2 interface
2020-07-01 17:42:51 +00:00
m0duspwnens
fd939a06b9
whitespace cleanup
2020-07-01 13:40:40 -04:00
Wes Lambert
3cf79995a2
Modify Whiptail menu for EC2 NIC
2020-07-01 17:32:43 +00:00
m0duspwnens
38db512eda
fix spacing
2020-07-01 13:29:19 -04:00
m0duspwnens
4e7e19af54
pillarize zeek node.cfg. change reference from bro to zeek.
2020-07-01 13:26:27 -04:00
William Wernert
db764902c7
[fix] Change if condition when checking nmcli status
2020-07-01 13:05:11 -04:00
William Wernert
19b997ece0
Merge branch 'dev' into feature/setup-changes
2020-07-01 12:56:57 -04:00
William Wernert
7bb97f2b2d
[fix] Remove "Panel Title" from Kibana CPU graph
...
Resolves #874
2020-07-01 11:12:21 -04:00
William Wernert
90f4b8e043
[feat] Add welcome/instruction wording to initial menu
2020-07-01 11:03:18 -04:00
William Wernert
c97798b57d
[feat] Add check to see if bond nics are managed by Network Manager
2020-07-01 09:43:39 -04:00
William Wernert
3a9d252af3
[fix] Correct indent in create_local_directories()
2020-07-01 09:42:07 -04:00
William Wernert
de620c88a1
Merge pull request #910 from Security-Onion-Solutions/version-correction
...
Remove HH prefix to ensure compatibility with updated build system
2020-06-30 15:57:30 -04:00
Jason Ertel
a49532d15c
Remove HH prefix to ensure compatibility with updated build system
2020-06-30 15:54:56 -04:00
Jason Ertel
a3deb868ad
Improve filebeat config indentation
2020-06-30 14:57:34 -04:00
Jason Ertel
930f15eea5
Introduce so-import-pcap tool - WIP
2020-06-30 14:56:08 -04:00
William Wernert
8dedd60da8
Merge branch 'feature/fast-fail' into feature/setup-changes
2020-06-30 14:27:04 -04:00
William Wernert
ce8a59243c
[feat] Add grep for "Error" to fail if nmcli fails
2020-06-30 14:26:48 -04:00
William Wernert
8d624e6ade
[fix] Move navigatordefaultlayer file.managed state to nginx sls
2020-06-30 10:53:10 -04:00
William Wernert
cab232ae9f
[feat] Add check for disk space during setup
2020-06-30 10:11:02 -04:00
Mike Reeves
ba81b7275a
Merge pull request #909 from Security-Onion-Solutions/fix/1.4.1
...
Update to 1.4.1
2020-06-30 09:55:10 -04:00
Mike Reeves
a1791f1e2e
Update to 1.4.1
2020-06-30 09:47:20 -04:00
Mike Reeves
a74d52a986
Merge pull request #908 from Security-Onion-Solutions/bugfix/hostname-regex
...
[fix] Apply regex filter to hostname input
2020-06-30 09:14:20 -04:00
William Wernert
1022bf5b99
[fix] Apply regex filter to hostname input
2020-06-30 09:08:55 -04:00
William Wernert
9f39875192
[fix] Apply regex filter to hostname input
2020-06-30 09:01:19 -04:00
Josh Brower
376a6e5fd5
Merge pull request #907 from Security-Onion-Solutions/feature/spacing-so-allow
...
so-allow spacing fix
2020-06-30 08:13:38 -04:00
Josh Brower
1c0443458c
so-allow spacing fix
2020-06-30 08:13:00 -04:00
weslambert
0b7026a11e
Merge pull request #906 from Security-Onion-Solutions/fix/ingest_parsing
...
Fix/ingest parsing
2020-06-29 23:07:22 -04:00
Wes Lambert
84e2965fef
Addl krb fix
2020-06-30 03:06:01 +00:00
Wes Lambert
bf8798f1d1
Fix krb client/server cert subject parsing
2020-06-30 03:04:01 +00:00
Wes Lambert
8f5da66335
Add null safe operator for query name
2020-06-30 03:02:38 +00:00
Josh Patterson
46d58acdd9
Merge pull request #905 from Security-Onion-Solutions/issue/878
...
add sensoroni to so-status output for sensors
2020-06-29 16:24:41 -04:00
m0duspwnens
0f9d8024f8
add sensoroni to so-status output for sensors - https://github.com/Security-Onion-Solutions/securityonion/issues/878
2020-06-29 16:23:04 -04:00
Josh Patterson
c73071c95e
Merge pull request #904 from Security-Onion-Solutions/issue/583
...
Issue/583
2020-06-29 16:17:22 -04:00
m0duspwnens
efaf41107c
update description in localrules/local.rules for idstools
2020-06-29 16:14:36 -04:00
m0duspwnens
67f2eedad1
cleanup whitespace in idstools enable/disable.conf
2020-06-29 16:11:30 -04:00
m0duspwnens
fe8df22063
cleanup whitespace in idstools enable/disable.conf
2020-06-29 16:03:14 -04:00
William Wernert
fdaab8da9f
Merge branch 'dev' into feature/setup-changes
2020-06-29 15:54:36 -04:00
William Wernert
23c0363899
[fix] Reference correct directory in nginx sls and remove navigator sls
2020-06-29 15:54:17 -04:00
William Wernert
b97ecd2d7a
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-06-29 15:53:29 -04:00
William Wernert
0a97328acc
[fix] Apply regex filter to hostname input
2020-06-29 15:53:21 -04:00
Josh Patterson
6bc7f023ff
Merge pull request #903 from Security-Onion-Solutions/quickfix/suricata
...
fix suricata state if suripins or suri procs arent set
2020-06-29 15:39:40 -04:00
m0duspwnens
d7580fe6a0
fix suricata state if suripins or suri procs arent set
2020-06-29 15:38:05 -04:00
William Wernert
53c3b1579b
[feat] Reformat install type menu
2020-06-29 15:20:17 -04:00
William Wernert
8e15f858dd
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
...
# Conflicts:
# salt/common/tools/sbin/so-allow
2020-06-29 15:14:12 -04:00
Mike Reeves
abe063602b
Update whiptail snort
...
Update the user to let them know Snort 3.x won't work.
2020-06-29 14:57:42 -04:00
weslambert
b398d58dc9
Merge pull request #902 from Security-Onion-Solutions/feature/es_allow
...
Add ES REST API option for so-allow
2020-06-29 14:51:09 -04:00
Wes Lambert
ed60d48c81
Add ES REST API option for so-allow
2020-06-29 18:49:16 +00:00
William Wernert
8cbccb656d
[fix] Apply shellcheck fixes
2020-06-29 11:32:25 -04:00
William Wernert
b01bdf35f9
[fix] Remove port binding from telegraf docker state
2020-06-29 11:31:44 -04:00
m0duspwnens
8ee2142de4
pillarize idstools - https://github.com/Security-Onion-Solutions/securityonion/issues/583
2020-06-29 11:21:47 -04:00
Mike Reeves
378ad97e7b
Disabled socket listener
2020-06-29 11:16:19 -04:00
weslambert
b99b19ce58
Merge pull request #898 from Security-Onion-Solutions/feature/strelka_scripts
...
Add Strelka mgmt scripts
2020-06-29 09:11:16 -04:00
Wes Lambert
9ac85cf674
Add Stelka mgmt scripts
2020-06-29 13:09:14 +00:00
weslambert
6f6e8a8853
Merge pull request #897 from Security-Onion-Solutions/fix/strelka_rules
...
Fix/strelka rules
2020-06-26 16:43:21 -04:00
weslambert
c421bd464a
Remove Strelka function (in favor of direct script execution in so-setup)
2020-06-26 16:42:44 -04:00
William Wernert
22eb81128a
Merge pull request #891 from Security-Onion-Solutions/feature/navigator-to-nginx
...
Feature/navigator to nginx
2020-06-26 15:48:46 -04:00
weslambert
8c47723bc9
Run YARA update script after applying state
2020-06-26 15:45:52 -04:00
Josh Patterson
9c388cd6aa
Merge pull request #896 from Security-Onion-Solutions/feature/suripillar
...
Feature/suripillar
2020-06-26 14:44:36 -04:00
m0duspwnens
0b1a258a4b
change sensor homenet map
2020-06-26 14:43:27 -04:00
weslambert
813c243d3d
Update so-yara-update
2020-06-26 13:26:08 -04:00
m0duspwnens
2079eba0ad
Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar
2020-06-26 13:09:15 -04:00
m0duspwnens
052c65c05e
add the things to pillarize suricata - https://github.com/Security-Onion-Solutions/securityonion/issues/584
2020-06-26 13:07:41 -04:00
William Wernert
cf7e5f1b6f
[fix] Change permissions on so-yara-update + fix indents
2020-06-26 09:59:44 -04:00
Josh Brower
b895d6fa4f
Merge pull request #894 from Security-Onion-Solutions/feature/playbook-unit-testing
...
Playbook - Initial Support for Unit Testing
2020-06-26 06:33:05 -04:00
Josh Brower
7f0eacd342
Playbook - Initial Support for Unit Testing
2020-06-26 06:24:09 -04:00
Mike Reeves
1e4c967afc
Fix math for suri loss calulcations
2020-06-25 14:02:02 -04:00
Mike Reeves
1e6fab4e6e
Fix math for suri loss calulcations
2020-06-25 13:54:01 -04:00
Mike Reeves
65687fd28e
Update saltstack update to point to correct github
2020-06-25 13:02:17 -04:00
Mike Reeves
57d0603e4c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into dev
2020-06-25 12:56:38 -04:00
Mike Reeves
30ac5f9764
ADding Suricata log compression
2020-06-25 12:56:26 -04:00
weslambert
5e41bba6db
Merge pull request #892 from Security-Onion-Solutions/feature/more_strelka_rules
...
Feature/more strelka rules
2020-06-25 12:33:36 -04:00
Wes Lambert
a24402de99
More Strelka rule config
2020-06-25 16:31:04 +00:00
Wes Lambert
63c45be388
Update Strelka init for rules
2020-06-25 15:49:58 +00:00
Wes Lambert
6487fdf5e6
Add Strelka YARA function
2020-06-25 15:46:37 +00:00
William Wernert
a45fbb6f5c
Revert "[fix] discovery.zen.minimum_master_nodes is deprecated, update the key"
...
This reverts commit 8bd6c067aa .
2020-06-25 10:53:26 -04:00
bryant-treacle
00713312c6
Merge pull request #890 from Security-Onion-Solutions/fix/so-elastic-clear
...
updated so-elastic-clear with new so-* indices - #885
2020-06-24 15:09:37 -04:00
bryant-treacle
443332d584
Update so-elastic-clear
2020-06-24 15:03:25 -04:00
bryant-treacle
ffc9567278
Delete test.test
2020-06-24 15:01:30 -04:00
bryant-treacle
08220e3330
Issue #885 : so-elastic-clear not removing so-* indices
2020-06-24 18:40:11 +00:00
weslambert
83ed21314a
Merge pull request #888 from Security-Onion-Solutions/feature/strelka_rules
...
Feature/strelka rules
2020-06-24 13:28:52 -04:00
Wes Lambert
f5bb831edf
Fix comment
2020-06-24 17:27:59 +00:00
Wes Lambert
a01339039a
Update Setup for Strelka rules
2020-06-24 17:22:55 +00:00
bryant-treacle
0849014b24
Issue #885 : so-elastic-clear not removing so-* indices
2020-06-24 17:21:58 +00:00
Wes Lambert
8bfbd77367
Update whiptail for Strelka
2020-06-24 17:18:05 +00:00
William Wernert
8bd6c067aa
[fix] discovery.zen.minimum_master_nodes is deprecated, update the key
2020-06-24 13:10:18 -04:00
Wes Lambert
52a0ace1b8
Use Strelka rules if enabled
2020-06-24 17:08:58 +00:00
William Wernert
bd36749959
[feat] Remove navigator container references
2020-06-24 12:38:32 -04:00
William Wernert
4404a4f312
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-06-23 17:57:19 -04:00
William Wernert
0a0fe5914a
[fix][feat] Move navigator entries to static files + fix indent
2020-06-23 17:57:14 -04:00
weslambert
c3651f1b45
Merge pull request #884 from Security-Onion-Solutions/feature/strelka_client
...
Add FW config for Strelka frontend
2020-06-23 14:57:06 -04:00
Wes Lambert
f7eacc2b05
Add FW config for Strelka frontend
2020-06-23 18:47:23 +00:00
weslambert
685e3048ac
Merge pull request #883 from Security-Onion-Solutions/fix/hunt_files_rename
...
Update file dataset name for hunt queries
2020-06-23 13:49:52 -04:00
Wes Lambert
c0428ce79d
Update file dataset name for hunt queries
2020-06-23 17:48:12 +00:00
weslambert
13df2e6312
Merge pull request #882 from Security-Onion-Solutions/fix/files_rename
...
Move dataset from files to file
2020-06-23 13:44:26 -04:00
Wes Lambert
af451573eb
Move dataset from files to file
2020-06-23 17:43:28 +00:00
m0duspwnens
36a329214a
merge eve-log in outputs for suricata meta data generation or zeek/default - https://github.com/Security-Onion-Solutions/securityonion/issues/584
2020-06-22 16:56:03 -04:00
m0duspwnens
f1bcd35734
Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar
2020-06-22 09:13:29 -04:00
Jason Ertel
d7693f9b55
Expose pcap dir to sensoroni for epoch discovery
2020-06-22 08:27:43 -04:00
Jason Ertel
1ee3625f61
Ensure certs dir is group readable by socore since Sensoroni process will need to read the client key
2020-06-21 15:46:36 -04:00
Jason Ertel
81ed656ba0
Bind both steno and sensoroni processes to host network
2020-06-21 10:50:10 -04:00
Jason Ertel
76e3118bd3
Split Sensoroni and Stenographer executables into separate images
2020-06-21 08:33:09 -04:00
m0duspwnens
57fa2c5abe
Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar
2020-06-18 13:49:07 -04:00
Mike Reeves
6dbe83a77f
Update so-docker-refresh
2020-06-18 12:38:07 -04:00
Jason Ertel
2f3a99cfb0
fix: indentation is incorrect
2020-06-17 17:46:49 -04:00
weslambert
fb9ac58ed6
Merge pull request #869 from Security-Onion-Solutions/feature/elastic_indices_rw
...
Basic index read-only attr removal script
2020-06-17 15:00:23 -04:00
Wes Lambert
6d25151ab8
Basic index read-only attr removal script
2020-06-17 18:59:13 +00:00
Josh Brower
6794cabf9c
Merge pull request #868 from Security-Onion-Solutions/bugfix/fleet-custom-hostname
...
Fleet custom hostname regex fix
2020-06-17 14:46:07 -04:00
weslambert
569fc4ac4d
Merge pull request #867 from Security-Onion-Solutions/feature/zeek_custom_policy
...
Feature/zeek custom policy
2020-06-17 13:12:38 -04:00
Wes Lambert
90c278096c
Add custom Zeek script dir
2020-06-17 17:11:27 +00:00
Josh Brower
3418f5748c
Fleet custom hostname regex fix
2020-06-17 13:08:47 -04:00
Jason Ertel
6bf8f0af08
Eliminate multiple version definitions in this repo
2020-06-17 10:46:07 -04:00
Jason Ertel
3451f74b63
Update version to 2.0.0-rc.1
2020-06-17 10:32:39 -04:00
weslambert
b489420002
Merge pull request #865 from Security-Onion-Solutions/feature/cortex_custom
...
Feature/cortex custom
2020-06-17 09:22:42 -04:00
Wes Lambert
1beff65cc9
fix typo
2020-06-17 13:20:32 +00:00
Wes Lambert
cbfe375407
Custom analyzer and responder dirs
2020-06-17 13:16:52 +00:00
William Wernert
ce86dbfac0
[feat] Add message about root mail spool growing
2020-06-11 09:24:23 -04:00
William Wernert
07b2f2885c
[fix] Always exit on early failure
2020-06-10 15:32:46 -04:00
William Wernert
7de02752e5
[fix] Reboot on early failure too, better if statements
2020-06-10 15:29:54 -04:00
William Wernert
379a5445e8
[feat] Also exit with non-zero status for automated installs
2020-06-10 14:27:18 -04:00
William Wernert
9695b9326b
Merge branch 'dev' into feature/fast-fail
2020-06-10 14:19:44 -04:00
William Wernert
03dfece9af
[feat] Fail setup early if "ERROR" is found in setup log
2020-06-10 14:18:25 -04:00
m0duspwnens
f8193cb914
beginning to pillarize suricata
2020-06-04 09:40:38 -04:00
Mike Reeves
45d17c5148
Pillarize Suricata Round 1
2020-06-01 14:53:04 -04:00