Mike Reeves
ba7b34a8ce
Merge pull request #1529 from Security-Onion-Solutions/dev
...
2.3.0 GA!
2020-10-16 10:53:53 -04:00
Mike Reeves
e2f16d51a6
Update VERIFY_ISO.md
2020-10-15 20:54:11 -04:00
Mike Reeves
42a6693101
Sig File for ISO
2020-10-15 20:36:08 -04:00
Jason Ertel
2326701cc0
Moved known issues underneath new changes
2020-10-15 19:29:33 -04:00
Jason Ertel
6ee37977c3
Fixed quotes and href targets
2020-10-15 19:25:26 -04:00
Mike Reeves
1ae35a39c3
Update changes.json
2020-10-15 19:11:55 -04:00
Mike Reeves
943aa82ce4
Update changes.json
2020-10-15 19:09:46 -04:00
Mike Reeves
131e105106
Update changes.json
2020-10-15 19:07:37 -04:00
Mike Reeves
cc56dc5a7f
Update changes.json
2020-10-15 19:05:47 -04:00
weslambert
657e251f51
Merge pull request #1528 from Security-Onion-Solutions/fix/kibana_ack
...
Update Kibana mappings for event ack/eslacation
2020-10-15 14:48:00 -04:00
Wes Lambert
d863f26f9d
Update Kibana mappings for event ack/eslacation
2020-10-15 18:46:37 +00:00
Mike Reeves
a7e0df84bb
Update README.md
2020-10-15 14:46:13 -04:00
William Wernert
1fdf431c12
[fix] so-user spelling+syntax fixes
...
* Consistent ending punctuation
* Consistent capitalization
* Correct comparison operators
2020-10-15 13:44:23 -04:00
Mike Reeves
35b10b1f91
Sensors should clean up their dockers as well
2020-10-15 10:31:51 -04:00
weslambert
36b9450a39
Merge pull request #1526 from Security-Onion-Solutions/fix/kibana_things
...
Intel mapping enforcement and winlog.verion
2020-10-15 08:43:34 -04:00
Wes Lambert
af9daa4d71
Intel mapping enforcement and winlog.verion
2020-10-15 12:42:33 +00:00
weslambert
c81ee9621d
Merge pull request #1525 from Security-Onion-Solutions/fix/kibana_discover_default
...
Fix default discover query
2020-10-14 17:44:55 -04:00
Wes Lambert
e7401b3e0c
Fix default discover query
2020-10-14 21:43:19 +00:00
weslambert
f2125242f9
Merge pull request #1523 from Security-Onion-Solutions/fix/strelka_file_mime_type
...
Rename file.flavors.mime to file.mime_type
2020-10-14 14:58:15 -04:00
Wes Lambert
54c4ee796f
Rename file.flavors.mime to file.mime_type
2020-10-14 18:56:44 +00:00
weslambert
8d4fd6c18d
Merge pull request #1522 from Security-Onion-Solutions/fix/pipeline_commmon_remove_ignore_missing
...
Fix common pipeline field removal so won't fail for missing fields
2020-10-14 09:56:34 -04:00
Wes Lambert
3c820365ab
Fix common pipeline field removal so won't fail for missing fields
2020-10-14 13:55:24 +00:00
Doug Burks
a106913d1a
Heavy node filebeat needs extra_hosts for the heavy node itself #1521
2020-10-14 09:51:59 -04:00
Josh Patterson
493c9a11df
Merge pull request #1520 from Security-Onion-Solutions/issue/1519
...
disable strelka by default for sensor nodes during setup
2020-10-14 09:38:50 -04:00
m0duspwnens
1283708186
disable strelka by default for sensor nodes during setup
2020-10-14 09:36:59 -04:00
Josh Patterson
2e62494793
Merge pull request #1518 from Security-Onion-Solutions/issue/1153
...
fix issue with schedule being placed in wrong location
2020-10-14 09:26:31 -04:00
Doug Burks
f88403e83e
use ssl on nodes that support it
2020-10-14 05:50:29 -04:00
m0duspwnens
a08d0c8b6f
fix issue with schedule being placed in wrong location
2020-10-13 18:24:44 -04:00
Josh Patterson
9f6fcb3763
Merge pull request #1516 from Security-Onion-Solutions/quickfix/managerestempalte
...
add elasticsearch template manager pillar and assign to manager node
2020-10-13 16:09:24 -04:00
m0duspwnens
1afa12e607
add elasticsearch template manager pillar and assign to manager node
2020-10-13 16:08:15 -04:00
Doug Burks
190869a1f2
enable https on elasticsearch nodes that support it
2020-10-13 16:04:55 -04:00
William Wernert
f6296c095f
[fix] Redirect stderr to stdout for crontab -l
2020-10-13 15:00:00 -04:00
Josh Patterson
15ea152b84
Merge pull request #1515 from Security-Onion-Solutions/issue/1511
...
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/1511
2020-10-13 14:17:28 -04:00
weslambert
4fff105986
Merge pull request #1514 from Security-Onion-Solutions/fix/replay_verbiage
...
Replay verbiage -- let users know when preparing to replay
2020-10-13 14:14:41 -04:00
Wes Lambert
3f8f0da468
Replay verbiage -- let users know when preparing to replay
2020-10-13 18:13:36 +00:00
m0duspwnens
2456605a54
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/1511
2020-10-13 14:10:24 -04:00
William Wernert
675db1da1b
[fix] Remove tab from string in whiptail menu
2020-10-13 13:44:51 -04:00
Doug Burks
0f68a53af4
Update so-curator-closed-delete-delete
2020-10-13 13:22:35 -04:00
Doug Burks
b004a9149e
Update so-index-list
2020-10-13 12:40:45 -04:00
Doug Burks
e5ece6cd50
Update so-index-list
2020-10-13 12:34:49 -04:00
Jason Ertel
2ad6ab7dfc
Dynamically alter docs URL based on airgap setting
2020-10-13 12:29:59 -04:00
Doug Burks
a75e986836
Update so-elastic-clear
2020-10-13 12:18:27 -04:00
Mike Reeves
c388966e7e
Add airgap config
2020-10-13 12:05:19 -04:00
William Wernert
0cd80de2b3
[fix] Hard code NIDS to Suricata since Snort is not yet supported
2020-10-13 10:31:44 -04:00
William Wernert
a459511812
Merge pull request #1512 from Security-Onion-Solutions/bugfix/whiptail-punctuation
...
Bugfix/whiptail punctuation
2020-10-13 10:26:26 -04:00
William Wernert
9dc491bd71
[refactor] Fixes per style guide
2020-10-13 10:23:47 -04:00
William Wernert
f5ea8325fe
[fix] Standardize input prompts
...
* All prompts that are questions end in "?"
* All other prompts end in ":"
* Any additional sentences after a prompt follow normal grammatical rules for punctuation
2020-10-13 09:45:32 -04:00
Doug Burks
ad50b5d640
elasticsearch _cat/indices output has changed between 6 and 7
2020-10-13 06:33:40 -04:00
Doug Burks
21b1becd7e
Update so-elasticsearch-pipelines-list
2020-10-12 16:34:30 -04:00
Doug Burks
5458c57cc9
Update so-elasticsearch-pipeline-stats
2020-10-12 16:32:11 -04:00
Doug Burks
68e34b781a
Update so-elasticsearch-templates-load
2020-10-12 16:10:38 -04:00
Doug Burks
4c43262610
Update so-elasticsearch-templates-list
2020-10-12 16:08:06 -04:00
weslambert
a17a2ad3de
Merge pull request #1507 from Security-Onion-Solutions/fix/zeek_smb_ts_common
...
Ensure Zeek logs without ts field have an @timestamp field associated
2020-10-12 13:21:15 -04:00
Wes Lambert
14559b081d
Ensure Zeek logs without ts field have an @timestamp field associated
2020-10-12 17:19:23 +00:00
weslambert
748ff0dbeb
Merge pull request #1506 from Security-Onion-Solutions/fix/index_dates
...
Fix/index dates
2020-10-12 11:45:08 -04:00
Wes Lambert
4fc4913d1e
Don't predefine index date for Filebeat ES outputs
2020-10-12 15:44:00 +00:00
Wes Lambert
884cc2d054
Don't predefine index date for Logstash outputs
2020-10-12 15:41:47 +00:00
Doug Burks
553ce3e363
only include extra_hosts if nodestab exists
2020-10-12 10:13:05 -04:00
Mike Reeves
e0fe63d263
Merge pull request #1505 from Security-Onion-Solutions/experimental
...
Fix Cross Cluster Search Acks
2020-10-12 09:24:16 -04:00
Mike Reeves
f5cfd480a3
Moar encryptions
2020-10-12 09:12:36 -04:00
Jason Ertel
3fff1451d4
Enable high strength cipher for golang compatibility
2020-10-11 22:31:29 -04:00
Mike Reeves
9695e63950
fix template statement
2020-10-11 17:21:57 -04:00
Mike Reeves
96083e1458
update logstash outputs
2020-10-11 17:06:56 -04:00
Mike Reeves
deb0f640d6
add jinja templates
2020-10-11 17:02:07 -04:00
Mike Reeves
b7c4fd94c4
get pipelines to load
2020-10-11 16:57:08 -04:00
Mike Reeves
e4ce17d4de
Turn on SSL output
2020-10-11 16:10:55 -04:00
Mike Reeves
a7bd1c2ce5
Turn on SSL output
2020-10-11 15:58:12 -04:00
Josh Patterson
c9c8c5e5f5
Merge pull request #1502 from Security-Onion-Solutions/quickfix/socrestart
...
watch all the files in the dir
2020-10-11 14:20:34 -04:00
m0duspwnens
c1e6c5688d
watch all the files in the dir
2020-10-11 14:19:44 -04:00
Mike Reeves
29c3948f95
Fix soc.json
2020-10-11 14:09:14 -04:00
Mike Reeves
31e0b5c81c
Add nodes to soc.json
2020-10-11 11:28:49 -04:00
Mike Reeves
73aade1223
Enable rest access from manager to sn
2020-10-11 11:02:20 -04:00
Mike Reeves
271e40337b
Enable jinja for tls
2020-10-11 10:57:04 -04:00
Mike Reeves
f6f9097cd9
Enable tls for 9200 on search capable nodes
2020-10-11 10:53:54 -04:00
Doug Burks
3cfee82b59
Update Hunt fields for firewall #1500
2020-10-10 08:18:00 -04:00
Doug Burks
87574181d5
Add Community ID to pfsense filterlog #1501
2020-10-10 08:11:51 -04:00
Doug Burks
5f15320b9d
Update Hunt fields for firewall #1500
2020-10-10 07:54:48 -04:00
Doug Burks
8d1ba1f4db
fix pfsense firewall udp parsing
2020-10-10 07:38:47 -04:00
Doug Burks
8cfabf101c
Update Hunt query for firewall #1499
2020-10-10 07:17:49 -04:00
Doug Burks
9aa4112de1
Remove extra comma
2020-10-10 06:10:10 -04:00
weslambert
12c3c351d8
Merge pull request #1498 from Security-Onion-Solutions/feature/filterlog
...
Feature/filterlog
2020-10-09 20:05:21 -04:00
Wes Lambert
28a1f7f88a
Remove pfsense tag
2020-10-10 00:03:51 +00:00
Wes Lambert
b55ffa44f8
Fix module,dataset rename
2020-10-10 00:01:37 +00:00
Wes Lambert
69a04dedd3
Filterlog config changes
2020-10-09 23:56:52 +00:00
Josh Patterson
930ec33cb7
Merge pull request #1496 from Security-Onion-Solutions/issue/1489
...
move salt master config file, copy salt-master service file and enabl…
2020-10-09 13:45:19 -04:00
m0duspwnens
6172268661
move salt master config file, copy salt-master service file and enable service restarts - https://github.com/Security-Onion-Solutions/securityonion/issues/1489
2020-10-09 13:27:46 -04:00
Josh Patterson
336400e642
Merge pull request #1495 from Security-Onion-Solutions/issue/1403
...
Issue/1403
2020-10-09 12:24:56 -04:00
m0duspwnens
ea1324e498
fix LOSS calc line
2020-10-09 11:54:39 -04:00
m0duspwnens
3f007b6af7
Merge remote-tracking branch 'remotes/origin/dev' into issue/1403
2020-10-09 11:40:01 -04:00
m0duspwnens
f5cacd66b8
correct zeekcaptureloss script to work on zeek standalone
2020-10-09 11:39:44 -04:00
Jason Ertel
40ff628c0b
Replace simple pillar lookup with salt equivalent to ensure quoted values are handled properly
2020-10-09 11:10:46 -04:00
William Wernert
97fce74263
[fix] Rename playbook key and add new admin/automation psswds
2020-10-09 09:59:08 -04:00
William Wernert
d7961fdbb8
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion into dev
2020-10-09 08:51:45 -04:00
William Wernert
5a8d776a62
[ix] Correct sls syntax
2020-10-09 08:51:35 -04:00
Josh Patterson
4af87ffcbe
Merge pull request #1492 from Security-Onion-Solutions/issue/1403
...
change capture loss to every 5 minutes and default grafana dashboard …
2020-10-08 17:52:52 -04:00
m0duspwnens
f38519247b
change capture loss to every 5 minutes and default grafana dashboard to 1h
2020-10-08 17:52:02 -04:00
William Wernert
065fe9042d
[fix] Make sure Playbook is up before creating user
2020-10-08 17:01:12 -04:00
weslambert
993aabedf2
Merge pull request #1491 from Security-Onion-Solutions/fix/so-elasticsearch-pipeline-stats-dots
...
Ensure pipelines with dots in names can be referenced
2020-10-08 15:41:44 -04:00
weslambert
06706d29f2
Ensure pipelines with dots in names can be referenced
2020-10-08 15:41:17 -04:00
weslambert
f41987024f
Merge pull request #1490 from Security-Onion-Solutions/feature/so-elastic-pipeline-stats
...
Add pipeline stats script
2020-10-08 15:12:55 -04:00
Wes Lambert
1efb39a71b
Add pipeline stats script
2020-10-08 19:11:41 +00:00
m0duspwnens
52e8265511
update is_airgap for soup
2020-10-08 14:16:19 -04:00
Mike Reeves
26317efe79
Update Soup
2020-10-08 14:05:52 -04:00
William Wernert
0795aa39ba
Merge pull request #1487 from Security-Onion-Solutions/feature/rotate-logs
...
Feature/rotate logs
2020-10-08 12:48:01 -04:00
William Wernert
2ad3f9da11
[fix] Wazuh not saving .log files anymore, only check .json files
2020-10-08 12:41:51 -04:00
William Wernert
034750fe5b
Merge branch 'dev' into feature/rotate-logs
...
# Conflicts:
# setup/so-functions
2020-10-08 12:36:30 -04:00
William Wernert
e1d8f578c2
[feat] Add log dirs for playbook + influxdb
2020-10-08 12:35:14 -04:00
Josh Patterson
2156adcf70
Merge pull request #1486 from Security-Onion-Solutions/fix/estemplates
...
fix templates not applying to searchnode.
2020-10-08 11:19:14 -04:00
m0duspwnens
e7abbf19af
fix templates not applying to searchnode. so-searchnode role doesnt exists searchnodes are so-node role
2020-10-08 11:17:26 -04:00
weslambert
0f5f781024
Merge pull request #1484 from Security-Onion-Solutions/fix/strelka_rule_null_safe_2
...
More fixes for rule field
2020-10-08 09:37:44 -04:00
Wes Lambert
a6d3dcf398
More fixes for rule field
2020-10-08 13:36:47 +00:00
weslambert
5e4bbcd4ca
Merge pull request #1483 from Security-Onion-Solutions/fix/strelka_rule_null_safe
...
Add null safe check for rule
2020-10-08 09:15:29 -04:00
Wes Lambert
a2e2f23a8d
Add null safe check for rule
2020-10-08 13:14:39 +00:00
weslambert
3ec9206b17
Merge pull request #1482 from Security-Onion-Solutions/fix/network_transport_kibana_viz
...
Fix network transport Kibana viz
2020-10-08 08:18:12 -04:00
Wes Lambert
adf0ef87c9
Fix network transport Kibana viz
2020-10-08 12:17:15 +00:00
weslambert
7767d3897b
Merge pull request #1481 from Security-Onion-Solutions/fix/network_transport_lower
...
Lowercase network.transport
2020-10-08 08:00:22 -04:00
weslambert
5ada85942b
Lowercase network.transport
2020-10-08 07:59:57 -04:00
Doug Burks
2489ca608a
Improve Hunt FTP queries #1479
2020-10-08 05:30:17 -04:00
Josh Patterson
0a982dec95
Merge pull request #1477 from Security-Onion-Solutions/issue/1403
...
Issue/1403
2020-10-07 17:47:21 -04:00
m0duspwnens
be7167d99b
Merge remote-tracking branch 'remotes/origin/dev' into issue/1403
2020-10-07 17:45:22 -04:00
m0duspwnens
821ce19aad
new dashboard for sensors
2020-10-07 17:38:16 -04:00
m0duspwnens
1bdc45ef0e
new dashboard for sensors
2020-10-07 17:37:11 -04:00
m0duspwnens
4f8bb9c2f1
updates to standalone and eval dashboards
2020-10-07 16:48:29 -04:00
m0duspwnens
7dd839cfa2
add zeek capture loss graph and resize redis queue for standalone
2020-10-07 15:53:31 -04:00
weslambert
7befff3baa
Merge pull request #1474 from Security-Onion-Solutions/fix/common_nids
...
Don't use regex for determining rule type
2020-10-07 12:16:55 -04:00
Wes Lambert
7543144afe
Don't use regex for determining rule type
2020-10-07 16:15:43 +00:00
weslambert
7787f81bdd
Merge pull request #1473 from Security-Onion-Solutions/fix/logstash_output_wazuh
...
Remove dataset name since pipeline no longer in use
2020-10-07 11:49:40 -04:00
weslambert
8e829b47ae
Remove dataset name since pipeline no longer in use
2020-10-07 11:48:56 -04:00
m0duspwnens
8540a691dc
only send loss if timestamp on data has changed
2020-10-07 11:23:06 -04:00
weslambert
8015676e01
Merge pull request #1472 from Security-Onion-Solutions/fix/rename-signature_info
...
Change rule.signature_info to rule.reference and ensure common.nids e…
2020-10-07 11:21:18 -04:00
Wes Lambert
015a441e79
Change rule.signature_info to rule.reference and ensure common.nids exists
2020-10-07 15:20:26 +00:00
weslambert
a1866e5229
Merge pull request #1471 from Security-Onion-Solutions/fix/ingest-updates
...
Fix/ingest updates
2020-10-07 11:15:55 -04:00
m0duspwnens
1106b2bf96
only send loss if timestamp on data has changed
2020-10-07 11:15:10 -04:00
Wes Lambert
f0a1457ffd
Update common.nids
2020-10-07 15:14:08 +00:00
m0duspwnens
d09f0f841e
only send loss if timestamp on data has changed
2020-10-07 11:13:03 -04:00
m0duspwnens
6f2d47cc40
only send loss if timestamp on data has changed
2020-10-07 11:11:06 -04:00
m0duspwnens
2317e8b348
only send loss if timestamp on data has changed
2020-10-07 11:08:41 -04:00
m0duspwnens
f96d6ae4f4
only send loss if timestamp on data has changed
2020-10-07 11:06:54 -04:00
m0duspwnens
5e534571ff
set timestamp with capture loss
2020-10-07 10:20:51 -04:00
m0duspwnens
14dd80b410
handle whitespace
2020-10-06 18:46:32 -04:00
m0duspwnens
af2df2c7d1
just print the loss
2020-10-06 18:44:22 -04:00
m0duspwnens
f95712c502
update log file
2020-10-06 18:38:51 -04:00
m0duspwnens
48ca2cdff1
fix pillars we check
2020-10-06 18:10:41 -04:00
m0duspwnens
4a236b3f75
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1403
2020-10-06 18:05:47 -04:00
m0duspwnens
73ce948d42
add zeekcaptureloss to data to influxdb. rename broloss to zeekloss - https://github.com/Security-Onion-Solutions/securityonion/issues/1403
2020-10-06 18:05:41 -04:00
Mike Reeves
fd4bb81f29
Fix ZEEKLOGS pillar
2020-10-06 17:38:05 -04:00
William Wernert
d84f85335e
[fix] Add jinja option, missing log dirs, compress option
2020-10-06 17:18:39 -04:00
Wes Lambert
8c07c098f6
Pipeline cleanup
2020-10-06 20:14:15 +00:00
Wes Lambert
350cc41740
Let zeek.common handle common fields for zeek.tunnels
2020-10-06 20:12:23 +00:00
William Wernert
b64a91f13c
[refactor] Remove nocompress option
2020-10-06 14:51:43 -04:00
William Wernert
27351fa520
[fix] Correct jinja syntax + indent all lines
2020-10-06 14:51:42 -04:00
Josh Patterson
7d14c68d70
Merge pull request #1468 from Security-Onion-Solutions/issue/163
...
fix yum db if corrupted -
2020-10-06 14:29:11 -04:00
m0duspwnens
035d215398
fix yum db if corrupted - https://github.com/Security-Onion-Solutions/securityonion/issues/163
2020-10-06 14:28:01 -04:00
Josh Patterson
51d3defe76
Merge pull request #1467 from Security-Onion-Solutions/issue/1460
...
Issue/1460
2020-10-06 14:06:01 -04:00
m0duspwnens
3d71766b64
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1460
2020-10-06 13:58:02 -04:00
m0duspwnens
34dfc809c7
handle thread count for suricata and default max-pending-packets to 5000 - https://github.com/Security-Onion-Solutions/securityonion/issues/1460
2020-10-06 13:57:50 -04:00
Mike Reeves
f809cf5216
Update so-functions
2020-10-06 13:27:23 -04:00
William Wernert
bd4292711e
[fix] Redirect missing lines to global pillar
2020-10-06 13:23:26 -04:00
William Wernert
9737b01676
[feat] Move logrotate configuration settings to pillar
2020-10-06 13:22:44 -04:00
William Wernert
94f15c63ce
[fix] Correct indent in common init.sls
2020-10-06 13:21:37 -04:00
weslambert
a16419b997
Merge pull request #1466 from Security-Onion-Solutions/fix/so-elasticsearch-templates-load
...
Rename so-elasticsearch-templates to so-elasticsearch-templates-load
2020-10-06 13:19:54 -04:00
Wes Lambert
a6a69c57d1
Rename so-elasticsearch-templates to so-elasticsearch-templates-load
2020-10-06 17:18:42 +00:00
weslambert
6cdff854f3
Merge pull request #1465 from Security-Onion-Solutions/feature/so-elasticsearch-templates-list
...
Add so-elasticsearch-templates-list
2020-10-06 13:16:11 -04:00
Wes Lambert
787f1d8732
Add so-elasticsearch-templates-list
2020-10-06 17:15:27 +00:00
weslambert
1a2921c2bc
Merge pull request #1463 from Security-Onion-Solutions/feature/so-elasticsearch-pipelines-list
...
Add so-elasticsearch-pipelines-list and fix common script perms
2020-10-06 13:04:24 -04:00
Wes Lambert
4a5d50cf80
Add so-elasticsearch-pipelines-list and fix common script perms
2020-10-06 17:01:58 +00:00
Josh Patterson
1b3eca80d7
Merge pull request #1462 from Security-Onion-Solutions/issue/1371
...
handle install locations of files copied
2020-10-06 11:41:37 -04:00
m0duspwnens
5eada1cdd5
handle install locations of files copied
2020-10-06 11:39:34 -04:00
Josh Patterson
4b1a8d7512
Merge pull request #1461 from Security-Onion-Solutions/issue/1371
...
Issue/1371
2020-10-06 11:22:58 -04:00
m0duspwnens
a5f4c96db0
qol user interaction improvements to analyst install
2020-10-06 11:19:43 -04:00
m0duspwnens
4eea0a464c
include remaining log functions from so-functions
2020-10-06 10:57:43 -04:00
m0duspwnens
7840002d18
update log file in title func
2020-10-06 10:51:31 -04:00
m0duspwnens
85168e9318
add title function
2020-10-06 10:49:38 -04:00
m0duspwnens
2420cd5db1
add some system characteristics to log like normal install does
2020-10-06 10:46:11 -04:00
Doug Burks
a686704d37
remove rule.uuid now that underlying issue has been resolved
2020-10-06 09:39:57 -04:00
weslambert
706c81daca
Merge pull request #1459 from Security-Onion-Solutions/feature/strelka_yara_alert
...
Add Strelka YARA matches as alerts
2020-10-06 08:23:16 -04:00
Wes Lambert
019bec992d
Add Strelka YARA matches as alerts
2020-10-06 12:19:44 +00:00
Josh Patterson
e2a787095c
Merge pull request #1458 from Security-Onion-Solutions/issue/1290
...
change for network miner 2.6 - https://github.com/Security-Onion-Solu…
2020-10-05 18:38:14 -04:00
m0duspwnens
acabcd27a7
change for network miner 2.6 - https://github.com/Security-Onion-Solutions/securityonion/issues/1290
2020-10-05 18:17:24 -04:00
Josh Patterson
24ff34ee81
Merge pull request #1457 from Security-Onion-Solutions/issue/1371
...
Issue/1371
2020-10-05 15:51:35 -04:00
Josh Brower
2e012432b4
Merge pull request #1455 from Security-Onion-Solutions/feature/training-req
...
Write out nested json
2020-10-05 15:34:43 -04:00
Josh Brower
de9ace62d4
Write out nested json
2020-10-05 15:34:02 -04:00
Josh Patterson
faf5e7a643
Merge pull request #1454 from Security-Onion-Solutions/issue/1444
...
logstash changes per https://github.com/Security-Onion-Solutions/secu…
2020-10-05 14:12:05 -04:00
m0duspwnens
748dc5ba91
logstash changes per https://github.com/Security-Onion-Solutions/securityonion/issues/1444
2020-10-05 14:10:05 -04:00
William Wernert
5dfd11a018
[feat] Add wazuh archive cleanup + fix indentation
2020-10-05 13:58:49 -04:00
William Wernert
e6cb75ce7e
[feat] Add common logrotate cron+config
2020-10-05 13:57:36 -04:00
Josh Patterson
f7daa391c7
Merge pull request #1453 from Security-Onion-Solutions/issue/1441
...
enable suricata threshold-file and point to proper file
2020-10-05 12:56:39 -04:00
Doug Burks
a45aa43f41
Add trailing comma to "thehive" stanza
2020-10-05 12:35:33 -04:00
m0duspwnens
63884b73e1
enable suricata threshold-file and point to proper file - https://github.com/Security-Onion-Solutions/securityonion/issues/1441
2020-10-05 12:10:52 -04:00
weslambert
9f4cb42c4f
Merge pull request #1452 from Security-Onion-Solutions/fix/kibana_case_create
...
Change alert to case
2020-10-05 11:46:14 -04:00
Wes Lambert
575da0f9d3
Change alert to case
2020-10-05 15:45:10 +00:00
weslambert
f4fcc052ca
Merge pull request #1451 from Security-Onion-Solutions/fix/wazuh_rule_cat
...
Put back rule.category for Wazuh alerts
2020-10-05 11:35:20 -04:00
weslambert
bc31e19e37
Put back rule.category for Wazuh alerts
2020-10-05 11:34:29 -04:00
weslambert
6e2319f6da
Merge pull request #1449 from Security-Onion-Solutions/fix/wazuh_logging
...
Adjust Wazuh logging so we don't log alerts to a separate file and so…
2020-10-05 10:04:01 -04:00
weslambert
968dce0aee
Adjust Wazuh logging so we don't log alerts to a separate file and so we don't write a separate log file for non-JSON for archives
2020-10-05 10:03:40 -04:00
Jason Ertel
1ebe970876
Disable escalate button if thehive is not enabled
2020-10-05 09:54:18 -04:00
weslambert
6b292ea62b
Merge pull request #1448 from Security-Onion-Solutions/fix/so_elastic_clear
...
Fix/so elastic clear
2020-10-05 09:40:04 -04:00
Wes Lambert
da8957b4f4
Use Elasticsearch pillar vs manager IP for so-elastic-clear
2020-10-05 13:37:06 +00:00
Wes Lambert
1970d95d5f
Make Filebeat registry persistent to avoid re-reading old data
2020-10-05 13:30:04 +00:00
Doug Burks
e7cba6ba1d
Change SOC Alerts eventFetchLimit from 5000 to 500 #1447
2020-10-05 09:29:01 -04:00
Doug Burks
948e0c4c61
Add rule.name to Hunt Wazuh Alerts query #1442
2020-10-05 09:26:13 -04:00
Jason Ertel
cf5b1245ea
Add configurable flags to enable/disable dismiss and escalate buttons
2020-10-05 09:16:17 -04:00
weslambert
771d091d6e
Merge pull request #1446 from Security-Onion-Solutions/feature/wazuh_severity
...
Add event.severity and event.severity_label config for Wazuh alerts
2020-10-05 08:52:20 -04:00
Wes Lambert
77d31cb289
Add event.severity and event.severity_label config for Wazuh alerts
2020-10-05 12:50:29 +00:00
weslambert
203e84d2cf
Update comma verbiage for HOME_NET in whiptail menu
2020-10-05 08:08:22 -04:00
Josh Brower
7b05cf4266
Merge pull request #1443 from Security-Onion-Solutions/feature/training-req
...
Feature/training req
2020-10-04 21:37:03 -04:00
Josh Brower
8a78485906
Config Playbook SOC Alerts
2020-10-04 21:35:42 -04:00
Josh Brower
c80b6ce104
Add so-allow-view and playbook event.sev.label
2020-10-04 20:39:21 -04:00
m0duspwnens
467e5b34cc
analyst node changes
2020-10-02 16:40:25 -04:00
m0duspwnens
20307b703e
analyst node changes
2020-10-02 16:21:31 -04:00
m0duspwnens
6a0f04d24a
analyst node changes
2020-10-02 16:14:15 -04:00
m0duspwnens
5a5007c07d
analyst node changes
2020-10-02 15:50:49 -04:00
m0duspwnens
fde6f128ab
analyst node changes
2020-10-02 15:26:13 -04:00
m0duspwnens
1be3323265
analyst node changes
2020-10-02 15:25:42 -04:00
m0duspwnens
47762816a7
analyst node changes
2020-10-02 14:57:22 -04:00
m0duspwnens
40647ce54c
analyst node changes
2020-10-02 14:40:15 -04:00
William Wernert
8310559273
Merge pull request #1440 from Security-Onion-Solutions/feature/generate-playbook-api-key
...
Feature/generate playbook api key
2020-10-02 14:37:58 -04:00
William Wernert
2a100c0dcc
Add OLD_ prefix + only update rules if playbook enabled
2020-10-02 14:34:30 -04:00
William Wernert
d0c267ca90
Fix sed command to not delete lines after match
2020-10-02 14:31:16 -04:00
William Wernert
54da2b869c
Add OLD_ db init files for soup compatibility
2020-10-02 14:12:23 -04:00
William Wernert
ab662e9b81
Merge branch 'dev' into feature/generate-playbook-api-key
...
# Conflicts:
# salt/common/tools/sbin/soup
2020-10-02 13:48:52 -04:00
William Wernert
db12b6f3c6
Remove salt call to automation_user_create
2020-10-02 13:17:57 -04:00
William Wernert
96d32fda51
Add old api key to pillar during soup
2020-10-02 13:16:58 -04:00
Mike Reeves
15f0c98281
Fix Formatting
2020-10-02 13:06:03 -04:00
m0duspwnens
d0da7ade6a
analyst node changes
2020-10-02 12:15:00 -04:00
m0duspwnens
c4e0fa0939
analyst node changes
2020-10-02 12:12:28 -04:00
m0duspwnens
e11717c4d0
analyst node changes
2020-10-02 11:28:53 -04:00
m0duspwnens
76a13e99da
new wallpaper
2020-10-02 10:12:36 -04:00
William Wernert
20fd757847
Run playbook-ruleupdate after soctopus is running
2020-10-02 10:05:10 -04:00
William Wernert
39e14b3910
Merge branch 'dev' into feature/generate-playbook-api-key
2020-10-02 08:39:09 -04:00
Mike Reeves
c7fcdc8084
Merge pull request #1438 from Security-Onion-Solutions/socyaml
...
Socyaml
2020-10-01 18:08:33 -04:00
Mike Reeves
4991ea8de3
Jason made me rename json
2020-10-01 18:07:06 -04:00
Mike Reeves
36ccece724
commas gone crazy
2020-10-01 18:02:06 -04:00
Mike Reeves
a0432e97b0
Python print ftl
2020-10-01 17:57:56 -04:00
m0duspwnens
733b1376c5
analyst node changes
2020-10-01 17:53:20 -04:00
Mike Reeves
490278a4c3
Add alert events filed
2020-10-01 17:49:17 -04:00
Mike Reeves
bd5efbabd9
Fix Mode
2020-10-01 17:43:43 -04:00
Mike Reeves
8fa426f265
Cleanup sync
2020-10-01 17:41:55 -04:00
Mike Reeves
9d9d3aac53
Switch to JSON from yaml
2020-10-01 17:37:57 -04:00
Mike Reeves
744a8bca73
More json for soc
2020-10-01 17:30:23 -04:00
Mike Reeves
8a41636e7f
More json for soc
2020-10-01 17:28:45 -04:00
Mike Reeves
dc79dca7fe
More json for soc
2020-10-01 17:25:51 -04:00
Mike Reeves
1c55f738ec
More json for soc
2020-10-01 17:23:29 -04:00
William Wernert
e98012ae2c
Fix jinja and change state orrder in setup
2020-10-01 17:16:26 -04:00
Mike Reeves
92fa33159e
More json for soc
2020-10-01 17:12:08 -04:00
m0duspwnens
72c6fe2184
analyst node changes
2020-10-01 17:05:59 -04:00
Mike Reeves
5730c85988
More json for soc
2020-10-01 17:04:15 -04:00
Mike Reeves
63be0734c9
More json for soc
2020-10-01 17:00:25 -04:00
Mike Reeves
5653828154
More json for soc
2020-10-01 16:57:04 -04:00
weslambert
2d2f4de337
Merge pull request #1437 from Security-Onion-Solutions/fix/kib_scripted_thehive
...
Update scripted field for TheHive case
2020-10-01 16:54:02 -04:00
Wes Lambert
8a81a5148b
Update scripted field for TheHive case
2020-10-01 20:52:57 +00:00
weslambert
98bef8fb9d
Merge pull request #1436 from Security-Onion-Solutions/fix/kibana_soc_thehive_case
...
Add SOC url for api integration
2020-10-01 16:47:11 -04:00
Wes Lambert
eced18c3cc
Add SOC url for api integration
2020-10-01 20:29:28 +00:00
Jason Ertel
8e15ed56d6
'Escalated' filter toggle will auto-enable 'acknowledged' filter toggle
2020-10-01 16:23:47 -04:00
m0duspwnens
76c98200f3
analyst node changes
2020-10-01 16:21:51 -04:00
Mike Reeves
cc2f2de5b5
soc.json stuff
2020-10-01 15:23:07 -04:00
Mike Reeves
b423e8d22a
soc.json stuff
2020-10-01 15:20:13 -04:00
Mike Reeves
1a561f6b12
soc.json stuff
2020-10-01 15:18:34 -04:00
William Wernert
a5bf4bbb35
Fix test for key in global.sls
2020-10-01 14:47:18 -04:00
m0duspwnens
964bad4657
analyst node changes
2020-10-01 13:53:38 -04:00
Doug Burks
e836f96c65
move rule.uuid after rule.name
2020-10-01 12:09:52 -04:00
Doug Burks
4851069a10
remove rule.gid from Alerts groupby since Wazuh and Playbook may not have that field
2020-10-01 11:51:40 -04:00
William Wernert
040730e8f5
Rename script for consistent naming
2020-10-01 11:22:11 -04:00
William Wernert
afb777fc8f
Add automation user creation to soup when resetting playbook db
2020-10-01 11:13:24 -04:00
m0duspwnens
75d49845f2
changes to analyst setup script
2020-10-01 10:43:33 -04:00
Doug Burks
bc19cce4c2
Acknowledging an alert may acknowledge more alerts than intended #1426
2020-10-01 10:00:54 -04:00
Doug Burks
26781de244
Add Strelka query to Hunt #1433
2020-10-01 06:59:36 -04:00
William Wernert
2264b6e51c
Add comments to shell code explaining curl statements
2020-09-30 19:54:34 -04:00
William Wernert
03b97cce75
Fix comment in new state + remove useless sleep command
2020-09-30 19:49:13 -04:00
William Wernert
11ae904100
Quiet script output + fix pillar value
2020-09-30 19:46:18 -04:00
weslambert
6818de9e64
Merge pull request #1431 from Security-Onion-Solutions/fix/elastlert_rules
...
Remove rule sync, since we don't have any rules to sync
2020-09-30 18:36:11 -04:00
weslambert
887937a75d
Remove rule sync, since we don't have any rules to sync
2020-09-30 18:35:35 -04:00
William Wernert
596f2d31e4
Automation -> automation
2020-09-30 17:04:24 -04:00
William Wernert
3ec255ecee
Remove old api token from sql
2020-09-30 17:03:35 -04:00
William Wernert
6361c790e9
Move automation user create to separate script to run after playbook state
2020-09-30 17:02:02 -04:00
William Wernert
8e80b41ca9
Remove Automation user from sql, gen user + store api key
2020-09-30 16:32:43 -04:00
Jason Ertel
1454201505
Disable thehivealerter
2020-09-30 15:26:29 -04:00
Jason Ertel
3af6e9e1fe
Remove mount point for SOCtopus generated playbook rules to avoid them activating and sending alerts to TheHive
2020-09-30 15:14:45 -04:00
Mike Reeves
8b5ff31351
Merge pull request #1430 from Security-Onion-Solutions/redis
...
Add Redis pillar and fix idstools
2020-09-30 15:09:59 -04:00
Mike Reeves
7314e2dea8
Add Redis pillar and fix idstools
2020-09-30 15:08:44 -04:00
Jason Ertel
ff04bb507a
Remove default Elastalert rules to stop automated alerts from being sent to thehive
2020-09-30 15:06:54 -04:00
weslambert
5b16a65422
Merge pull request #1429 from Security-Onion-Solutions/fix/zeek_server_ip
...
Fix issue with null Zeek server IP
2020-09-30 13:54:50 -04:00
Wes Lambert
02d2e5e2c6
Fix isue with null Zeek server IP
2020-09-30 17:53:30 +00:00
William Wernert
f3b8da1f9d
Fix Engrish (can causing -> can cause)
2020-09-30 13:40:57 -04:00
William Wernert
25d4bde33b
Merge pull request #1428 from Security-Onion-Solutions/feature/warn-dhcp
...
Add warning about IP address changing for network/DHCP iso installs
2020-09-30 13:13:40 -04:00
William Wernert
1ff20f7e27
Add warning about IP address changing for network/DHCP iso installs
2020-09-30 13:11:33 -04:00
weslambert
defe832121
Merge pull request #1427 from Security-Onion-Solutions/fix/wazuh_filebeat
...
Fix Filebeat config for Wazuh
2020-09-30 10:59:01 -04:00
Wes Lambert
d8f70397f7
Fix Filebeat config for Wazuh
2020-09-30 14:57:56 +00:00
weslambert
dac2ad5dbf
Merge pull request #1425 from Security-Onion-Solutions/feature/soctopus_pillar
...
Add initial implementation of SOCtopus pillar
2020-09-30 10:25:26 -04:00
Wes Lambert
c62acf5e4e
Add initial implmentation of SOCtopus pillar
2020-09-30 14:24:15 +00:00
Josh Patterson
10f4e09b70
Merge pull request #1424 from Security-Onion-Solutions/issue/1070
...
Issue/1070
2020-09-30 10:11:37 -04:00
William Wernert
00785c6ba5
Merge pull request #1418 from Security-Onion-Solutions/feature/replace-hardcoded-pass
...
Feature/replace hardcoded pass
2020-09-30 08:56:35 -04:00
Doug Burks
0a995f4a7a
Update README.md
2020-09-30 07:43:20 -04:00
m0duspwnens
85969dc16d
add quotes and remove quotes
2020-09-29 16:29:05 -04:00
m0duspwnens
bf99bab6c0
add quotes and remove quotes
2020-09-29 16:26:45 -04:00
weslambert
401764437f
Merge pull request #1421 from Security-Onion-Solutions/fix/ip_type
...
Ensure IPs are typed as IP and ports as integer
2020-09-29 14:21:25 -04:00
Wes Lambert
36019727b3
Ensure IPs are typed as IP and ports as integer
2020-09-29 18:20:15 +00:00
m0duspwnens
547c3ff52c
single quote inputs to yaml files
2020-09-29 13:59:16 -04:00
William Wernert
7d43d48aca
Remove bad line in playbook_db_init.sh
2020-09-29 11:13:09 -04:00
William Wernert
55058a11aa
Generate passwords for Grafana + Playbook default users
2020-09-29 11:12:09 -04:00
William Wernert
ebe00822f8
Merge pull request #1417 from Security-Onion-Solutions/bugfix/local_zeeklogs
...
Bugfix/local zeeklogs
2020-09-29 08:58:02 -04:00
Doug Burks
60134829d5
Alerts - Drilldown should display rule.uuid #1416
2020-09-29 07:51:45 -04:00
Doug Burks
c7b43ac220
Update soc.json
2020-09-29 07:41:49 -04:00
Doug Burks
a7f24b62e6
Hunt - improve NIDS query and eventFields #1415
2020-09-29 07:34:44 -04:00
Josh Patterson
9ca13ebccd
Merge pull request #1414 from Security-Onion-Solutions/issue/1404
...
change so salt module to /usr/sbin/so-status
2020-09-28 18:31:26 -04:00
Mike Reeves
c828a2ea75
Merge pull request #1413 from Security-Onion-Solutions/experimental
...
Airgap SOUP!
2020-09-28 17:47:38 -04:00
m0duspwnens
8741520263
change so salt module to /usr/sbin/so-status
2020-09-28 17:31:05 -04:00
Mike Reeves
6b8b0f1b26
Change add registry
2020-09-28 16:48:02 -04:00
William Wernert
f77305e22f
Generate zeeklogs sls earlier to avoid error
2020-09-28 16:45:06 -04:00
William Wernert
f782299281
Remove preconfigured zeeklog + create it during setup
2020-09-28 15:12:36 -04:00
Josh Patterson
fa6396b121
Merge pull request #1410 from Security-Onion-Solutions/fix/disable_auto_start
...
send to dev/null to prevent output
2020-09-28 15:07:40 -04:00
weslambert
3d6c956e02
Merge pull request #1409 from Security-Onion-Solutions/feature/wazuh_wel
...
Add initial parsing for Wazuh WEL/Sysmon
2020-09-28 15:07:15 -04:00
m0duspwnens
0bb1ba2853
send to dev/null to prevent output
2020-09-28 15:06:43 -04:00
Wes Lambert
869767d9d9
Add initial parsing for Wazuh WEL/Sysmon
2020-09-28 19:04:21 +00:00
Josh Patterson
0944cd1bcd
Merge pull request #1408 from Security-Onion-Solutions/issue/1093
...
Issue/1093
2020-09-28 14:45:18 -04:00
m0duspwnens
3b709e7877
remove cleaning of webpasswd1
2020-09-28 14:44:14 -04:00
Doug Burks
6e9e4dc99c
Hunt third magnifying glass should group output by event.module and event.dataset #1407
2020-09-28 14:19:55 -04:00
Mike Reeves
2cdf76473c
Add Registry back from cleanup
2020-09-28 14:19:43 -04:00
m0duspwnens
053b19de11
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-28 13:25:42 -04:00
m0duspwnens
bda9078843
check for invalid characters in fleet user password
2020-09-28 13:25:23 -04:00
Doug Burks
0516a9ddd5
Alerts page "Hunt for this field" action should quote field and group output #1406
2020-09-28 12:35:08 -04:00
m0duspwnens
85e53c53af
reject passwords with single or double quotes or backslashes
2020-09-28 11:51:19 -04:00
Mike Reeves
6a4d6f7a6d
Additional logic
2020-09-28 10:12:52 -04:00
William Wernert
66b7678df8
Merge pull request #1405 from Security-Onion-Solutions/feature/setup-cleanup
...
Feature/setup cleanup
2020-09-28 09:47:52 -04:00
William Wernert
3b9de2b7ca
Disable ipv6 earlier in setup
2020-09-28 09:14:45 -04:00
William Wernert
a60bf11daa
Make sure zeek log is only written on whiptail success
2020-09-28 09:11:50 -04:00
William Wernert
05729d216a
Don't direct user to check log in so-zeek-log, none exists
2020-09-28 08:45:59 -04:00
Doug Burks
3904295137
Hunt - improve HTTP queries #1401
2020-09-27 08:04:28 -04:00
Doug Burks
aa7f927ffd
Hunt - improve x509 queries #1400
2020-09-27 07:17:46 -04:00
Jason Ertel
68f18da832
Add alert query toggle filters for ack'd and escalated alerts
2020-09-25 17:03:42 -04:00
William Wernert
dc330a774e
Exit so-zeek-logs if user cancels
2020-09-25 16:30:16 -04:00
William Wernert
9acf610262
Also disable ipv6 for install
2020-09-25 16:10:26 -04:00
William Wernert
d76a4b1359
Show welcome screen on both iso and network installs
2020-09-25 14:59:27 -04:00
Doug Burks
11b200e9c0
Hunt - remove SMTP fields #1397
2020-09-25 14:17:14 -04:00
Doug Burks
20a56d0831
Hunt - add network.community_id column to Events table for more data types #1396
2020-09-25 13:18:28 -04:00
weslambert
6bfef773f2
Merge pull request #1392 from Security-Onion-Solutions/bugfix/config_dev_nullify
...
dev nullify so-config-backup cron job
2020-09-24 21:00:18 -04:00
weslambert
b3f9ee3b34
dev nullify so-config-backup cron job
2020-09-24 20:59:42 -04:00
Jason Ertel
c0be252f9f
SOC config adjustments for alerting
2020-09-24 16:37:27 -04:00
Josh Patterson
04f2595fa1
Merge pull request #1389 from Security-Onion-Solutions/issue/1388
...
fix common salt package name for salt.master state for ubuntu
2020-09-24 12:36:26 -04:00
Mike Reeves
e30958b9ec
Airgap SOUP changes
2020-09-24 11:41:02 -04:00
m0duspwnens
d9005c157d
fix common salt package name for salt.master state for ubuntu - https://github.com/Security-Onion-Solutions/securityonion/issues/1388
2020-09-24 11:26:58 -04:00
Doug Burks
62dbe425a6
Hunt - fix x509 eventFields #1387
2020-09-24 07:52:46 -04:00
Doug Burks
2b8b8e2f40
Hunt - fix file eventFields #1386
2020-09-24 07:44:28 -04:00
Doug Burks
60daacd6dc
Hunt - fix DHCP eventFields #1385
2020-09-24 07:34:29 -04:00
weslambert
a09002edae
Merge pull request #1384 from Security-Onion-Solutions/bugfix/config_backup
...
Add back missing # sign
2020-09-23 21:34:52 -04:00
weslambert
5b93c40ce4
Add back missing # sign
2020-09-23 21:34:10 -04:00
m0duspwnens
3ba8f47d9c
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-23 15:01:48 -04:00
m0duspwnens
6f7dbee36e
remove single quotes from secrets pillar
2020-09-23 14:57:26 -04:00
Mike Reeves
fd302c6363
make autocomplete with sudo work
2020-09-23 13:19:37 -04:00
m0duspwnens
70f98e2eea
take care single quotes if they are in the WEBPASSWD
2020-09-23 13:00:18 -04:00
m0duspwnens
b32bc8b542
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-23 12:07:12 -04:00
Mike Reeves
aca98e01f3
Set the path
2020-09-23 12:00:25 -04:00
Jason Ertel
2f7c0c34e6
Support backslashes in SOC passwords
2020-09-23 10:09:21 -04:00
weslambert
4f228c1b7c
Merge pull request #1379 from Security-Onion-Solutions/feature/config_backup
...
Feature/config backup
2020-09-23 09:58:05 -04:00
Wes Lambert
71734ddc0a
Add cron job to common state for daily config backup
2020-09-23 13:55:32 +00:00
Wes Lambert
57732b360e
Add config backup script
2020-09-23 13:47:14 +00:00
Wes Lambert
4d42d04cc3
Fix backup pillar definition
2020-09-23 13:45:42 +00:00
Wes Lambert
d02c440934
Add backup params to global.sls
2020-09-22 21:05:57 +00:00
m0duspwnens
77a9bf2697
test single quotes in secrets pillar
2020-09-22 13:16:20 -04:00
Josh Brower
18a881ccab
Merge pull request #1377 from Security-Onion-Solutions/bugfix/docker_cleanup
...
fix docker_clean syntax
2020-09-21 19:42:11 -04:00
Josh Brower
8bb527b4f1
fix docker_clean syntax
2020-09-21 19:41:39 -04:00
Jason Ertel
694635a38f
Add pivot to hunt as a new alerts quick action
2020-09-21 17:10:03 -04:00
Mike Reeves
0f1b92cea9
Update so-rule-update
2020-09-21 15:40:38 -04:00
Mike Reeves
48b17ee51a
Merge pull request #1375 from Security-Onion-Solutions/gaupgrade
...
Upgrade to GA including Docker Cleanup
2020-09-21 13:14:49 -04:00
Mike Reeves
d56a9e1f86
Upgrade to GA including Docker Cleanup
2020-09-21 13:14:06 -04:00
Josh Brower
ffdf7e1db4
Merge pull request #1374 from Security-Onion-Solutions/feature/so-user-list
...
Add so-user-list
2020-09-21 10:03:02 -04:00
Josh Brower
3cd11807cd
Add so-user-list
2020-09-21 10:02:10 -04:00
Jason Ertel
8f4a6df53a
Add event.module to default alert query
2020-09-21 09:06:56 -04:00
Jason Ertel
fc51c2aef4
Group by community ID on second alert quick query
2020-09-19 08:39:01 -04:00
Jason Ertel
5b38acb64b
Add alerting configuration for soc container
2020-09-18 13:51:23 -04:00
Josh Patterson
2b155b5581
Merge pull request #1368 from Security-Onion-Solutions/issue/1367
...
add so-fleet so standalone fleet gets the redis pki
2020-09-18 13:41:43 -04:00
m0duspwnens
40f6fed2a5
add so-fleet so standalone fleet gets the redis pki
2020-09-18 13:40:27 -04:00
Jason Ertel
1610445b4e
Validate password before creating user
2020-09-18 08:29:30 -04:00
Jason Ertel
0c12025599
Do not restart mysql after setup when running automated tests
2020-09-18 08:22:28 -04:00
Mike Reeves
33e381ad15
Update VERSION
2020-09-17 15:08:36 -04:00
Mike Reeves
bafb13fd6d
Merge pull request #1363 from Security-Onion-Solutions/dev
...
RC3
2020-09-17 15:05:33 -04:00
Mike Reeves
56e9f09c20
Update VERIFY_ISO.md
2020-09-17 11:02:16 -04:00
Mike Reeves
6cd30ce52f
Update Sig
2020-09-17 10:56:29 -04:00
Mike Reeves
3fb98bfd4d
Update VERIFY_ISO.md
2020-09-17 10:54:18 -04:00
Mike Reeves
4701091f76
Update VERIFY_ISO.md
2020-09-17 10:54:01 -04:00
Doug Burks
57e45308af
Fix pivot from TheHive to Kibana #1362
2020-09-17 08:05:55 -04:00
Doug Burks
c9c1245d1e
change from 2.1 RC2 to 2.2 RC3
2020-09-17 08:01:10 -04:00
Mike Reeves
7415c7fe81
Fix dashboard script
2020-09-16 14:55:32 -04:00
Mike Reeves
eac58f8f34
Merge pull request #1346 from Security-Onion-Solutions/rc3upgrade
...
Rc3upgrade
2020-09-16 14:29:53 -04:00
Mike Reeves
52072e0484
Update soup
2020-09-16 14:08:48 -04:00
doug
840b54d73c
make so-analyst executable
2020-09-16 13:11:49 -04:00
Mike Reeves
5910fe642c
Fix Update XML
2020-09-16 13:08:21 -04:00
Mike Reeves
a0f64440e0
Update changes.json
2020-09-16 13:06:26 -04:00
weslambert
74e4adda11
Merge pull request #1357 from Security-Onion-Solutions/feature/dashboard_updates_2
...
Add All Logs for Connections dashboard
2020-09-16 11:56:38 -04:00
Wes Lambert
44ef935d65
Add All Logs for Connections dashboard
2020-09-16 15:55:28 +00:00
Mike Reeves
3e0e41be32
Update changes.json
2020-09-16 11:41:21 -04:00
Mike Reeves
1801361cf8
Update changes.json
2020-09-16 11:40:05 -04:00
weslambert
6325b30a21
Merge pull request #1356 from Security-Onion-Solutions/feature/dashboard_updates
...
Kibana dashboard updates
2020-09-16 11:19:27 -04:00
Wes Lambert
bd8d2fc271
Kibana dashboard updates
2020-09-16 15:17:26 +00:00
Josh Patterson
6e0806a587
Merge pull request #1353 from Security-Onion-Solutions/fix/strelkaconfig
...
fix sensor mainip logic for strelka yaml files
2020-09-16 10:32:58 -04:00
m0duspwnens
4ee3e1ed01
fix sensor mainip logic for strelka yaml files
2020-09-16 10:29:23 -04:00
Josh Patterson
b7e41b53cb
Merge pull request #1352 from Security-Onion-Solutions/fix/es_templates
...
fix MYIP
2020-09-16 10:12:27 -04:00
m0duspwnens
3fe276dbb5
fix MYIP
2020-09-16 10:11:39 -04:00
Josh Patterson
66f21c4568
Merge pull request #1350 from Security-Onion-Solutions/fix/es_templates
...
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:54:16 -04:00
Josh Brower
d5fd15962c
Merge pull request #1351 from Security-Onion-Solutions/bugfix/tcpreplay
...
Fix so-test
2020-09-16 09:52:08 -04:00
Josh Brower
dd2d736bc1
Fix so-test
2020-09-16 09:51:38 -04:00
m0duspwnens
dd56d7d2d1
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:48:38 -04:00
weslambert
6806bd2461
Merge pull request #1348 from Security-Onion-Solutions/bugfix/es_template_load
...
Ensure templates are loaded for heavy nodes
2020-09-15 17:15:56 -04:00
weslambert
fbf037f460
Ensure templates are loaded for heavy nodes
2020-09-15 17:14:06 -04:00
Josh Brower
46a1369e81
Merge pull request #1347 from Security-Onion-Solutions/bugfix/tcpreplay
...
Add so-test
2020-09-15 13:20:56 -04:00
Josh Brower
2516429834
Add so-test
2020-09-15 13:14:00 -04:00
Mike Reeves
fc8ffd2080
Made the version update more reliable
2020-09-15 11:09:01 -04:00
Mike Reeves
ee4b35f2e4
Rename zeekversion.map.jinja to mdengine.map.jinja
2020-09-14 22:30:10 -04:00
Mike Reeves
c31d998061
Disk Space Check Final Final Final
2020-09-14 20:17:28 -04:00
Mike Reeves
62a8e676d9
Disk Space Check Final Final
2020-09-14 20:11:04 -04:00
Mike Reeves
9ef2b93586
Disk Space Check Final Final
2020-09-14 20:09:53 -04:00
Mike Reeves
eafb4e81a5
Disk Space Check Final Final
2020-09-14 20:01:53 -04:00
Mike Reeves
6eb3333af4
Disk Space Check Final
2020-09-14 19:46:16 -04:00
Mike Reeves
07e536df98
Disk Space Check
2020-09-14 19:42:58 -04:00
Mike Reeves
e8d2a6fdc2
Disk Space Check
2020-09-14 19:32:14 -04:00
Mike Reeves
1bc5e33007
Rotate Mysql Container Log
2020-09-14 16:27:32 -04:00
Mike Reeves
e2ecfca4c1
Merge pull request #1343 from Security-Onion-Solutions/rc3upgrade
...
Upgrade Fun
2020-09-14 14:54:37 -04:00
Mike Reeves
0a0e00866c
Upgrade Fun
2020-09-14 14:50:22 -04:00
Mike Reeves
38266f7db8
Merge pull request #1342 from Security-Onion-Solutions/experimental
...
Fix ruleupdate setting
2020-09-14 14:26:31 -04:00
Mike Reeves
9957fdec0f
Fix ruleupdate setting
2020-09-14 14:17:55 -04:00
Josh Patterson
32632864eb
Merge pull request #1341 from Security-Onion-Solutions/issue/1066
...
change how we determine how to run so-status
2020-09-14 12:43:05 -04:00
m0duspwnens
b559e5dd32
change how we determine how to run so-status
2020-09-14 12:40:39 -04:00
Jason Ertel
f86780a0db
Open PCAPs in same tab, but open external sites in new tabs
2020-09-14 10:41:39 -04:00
Mike Reeves
1958fef4ad
Merge pull request #1338 from Security-Onion-Solutions/experimental
...
Fix strelka rules
2020-09-14 09:58:34 -04:00
Mike Reeves
ee1317adf1
Merge branch 'experimental' of https://github.com/Security-Onion-Solutions/securityonion into experimental
2020-09-14 09:57:14 -04:00
Mike Reeves
d1836fb3a3
Fix Salt issue with script
2020-09-14 09:57:08 -04:00
Josh Patterson
67c1ece0bb
Merge pull request #1337 from Security-Onion-Solutions/issue/1066
...
Issue/1066
2020-09-14 09:38:15 -04:00
m0duspwnens
b93d149631
fix so-status
2020-09-14 09:36:26 -04:00
m0duspwnens
46cbcfa330
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1066
2020-09-14 08:45:54 -04:00
Mike Reeves
841db1b4b9
Merge pull request #1336 from Security-Onion-Solutions/experimental
...
Get Rules onto the install for airgap
2020-09-13 14:58:36 -04:00
Mike Reeves
112a0b426e
Merge branch 'dev' into experimental
2020-09-13 14:54:00 -04:00
Doug Burks
18dc7a915a
Hunt: Fix Tunnel query #1335
2020-09-13 08:26:33 -04:00
Jason Ertel
89c38541ee
Force all SOC quick actions to open in new tab
2020-09-13 02:52:25 -04:00
Mike Reeves
d6d22fb0e0
Fix Strelka
2020-09-12 23:07:35 -04:00
Mike Reeves
bb936c5bee
Fix Strelka
2020-09-12 23:07:15 -04:00
Mike Reeves
259df2ed6b
Fix Strelka
2020-09-12 23:06:06 -04:00
Doug Burks
311d67b934
Hunt: fix RFB groupby #1332
2020-09-12 06:14:58 -04:00
Josh Patterson
f03b128924
Merge pull request #1331 from Security-Onion-Solutions/fix/top
...
add redis to eval if playbook enabled
2020-09-11 18:31:19 -04:00
m0duspwnens
5f567368be
add redis to eval if playbook enabled
2020-09-11 18:30:21 -04:00
m0duspwnens
77911acfb4
so-status module
2020-09-11 18:28:53 -04:00
Mike Reeves
48d1d0c168
Strelkas Rules Update
2020-09-11 18:24:56 -04:00
Josh Patterson
2d508d9e57
Merge pull request #1328 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-11 15:02:30 -04:00
m0duspwnens
15563f2ee6
add nginx to top for sensor
2020-09-11 12:28:42 -04:00
m0duspwnens
bb0e686444
add elasticsearch to top for nodes missing it
2020-09-11 11:35:17 -04:00
Mike Reeves
46866f40b3
Merge pull request #1325 from Security-Onion-Solutions/experimental
...
Update Script
2020-09-11 11:02:57 -04:00
Mike Reeves
6e0cdf7be4
Update Script help
2020-09-11 11:01:56 -04:00
m0duspwnens
5f7c270984
only allow strelka to run on nodes that are sensors
2020-09-11 10:22:12 -04:00
Mike Reeves
af9a19b6e8
Merge pull request #1321 from Security-Onion-Solutions/experimental
...
IDS Tools now with Airgap support
2020-09-10 19:05:16 -04:00
Mike Reeves
53319738c4
Fix Nginx state
2020-09-10 16:56:48 -04:00
Mike Reeves
ef46094b0c
Update all nginx configs
2020-09-10 13:55:56 -04:00
Josh Patterson
53ff87b0ee
Merge pull request #1312 from Security-Onion-Solutions/issue/1281
...
add elasticsearch state to top for manager node
2020-09-10 12:47:05 -04:00
m0duspwnens
bc420d4a02
add
2020-09-10 11:57:15 -04:00
Josh Patterson
ca26548b2c
Merge pull request #1310 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-10 10:08:25 -04:00
m0duspwnens
0ed9c65646
remove logic from fleet state to only run if in top
2020-09-10 10:07:05 -04:00
Doug Burks
8c280221da
Hunt: Fix Intel groupby #1131
2020-09-10 07:00:54 -04:00
Doug Burks
24c325e9a1
Fix Elasticsearch parsing for Zeek Intel Indicator #1309
2020-09-10 06:41:19 -04:00
Josh Brower
56587f0df5
Merge pull request #1308 from Security-Onion-Solutions/feature/wel-ingest
...
Add event.category to WEL
2020-09-10 06:16:56 -04:00
Josh Brower
c3b2d98ffb
Add event.category to WEL
2020-09-10 06:15:30 -04:00
Doug Burks
7161a662aa
improve Wazuh support in Hunt
2020-09-10 06:03:33 -04:00
Mike Reeves
5d4e8925a3
Add Firewall Logic
2020-09-09 21:16:40 -04:00
Mike Reeves
45b11b2321
Fix Rulecat
2020-09-09 18:38:07 -04:00
Doug Burks
d18c498574
Update so-features-enable
2020-09-09 17:32:42 -04:00
m0duspwnens
09cc8ae1fb
fail the state if it isnt in top
2020-09-09 16:48:50 -04:00
m0duspwnens
01c9f7b2ae
merge with dev and resolve conflicts
2020-09-09 16:23:36 -04:00
Mike Reeves
7ebf93fcb5
IDSTools Overhaul
2020-09-09 15:53:32 -04:00
Josh Patterson
1e32b32659
Merge pull request #1302 from Security-Onion-Solutions/fix/sostatus
...
Fix/sostatus
2020-09-09 15:07:12 -04:00
m0duspwnens
39f200f565
fix whitespace
2020-09-09 14:59:21 -04:00
Mike Reeves
a77532c1d8
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 14:57:17 -04:00
Mike Reeves
04f4539385
Fix Airgap Repo Name
2020-09-09 14:57:10 -04:00
m0duspwnens
b0c526364f
handle strelka
2020-09-09 14:55:54 -04:00
m0duspwnens
921262b9a5
prevent duplicate containers for so-stauts
2020-09-09 14:07:38 -04:00
Jason Ertel
a5b87850df
Remove user sync between SOC and Cortex due to the unnecesary complexities involved with this style of integration
2020-09-09 14:07:36 -04:00
m0duspwnens
05d736d2df
handle strelka
2020-09-09 14:00:58 -04:00
m0duspwnens
918d9cf00f
handle strelka
2020-09-09 13:57:53 -04:00
m0duspwnens
3433b90029
fix so-status for strelka and wazuh
2020-09-09 13:53:10 -04:00
Doug Burks
82b582540e
Add period
2020-09-09 12:56:19 -04:00
Doug Burks
90ba1be978
Improve formatting of NIDS selection screen
2020-09-09 12:55:14 -04:00
m0duspwnens
e84507c386
Merge remote-tracking branch 'remotes/origin/dev' into fix/sostatus
2020-09-09 12:51:01 -04:00
m0duspwnens
9ee9a199b1
predefine each component as 0 to fix issues with it being unset
2020-09-09 12:50:22 -04:00
Jason Ertel
fc4ad1d556
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:22:38 -04:00
Jason Ertel
9babc445ce
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:07:23 -04:00
Mike Reeves
90feb503ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 10:54:53 -04:00
Mike Reeves
426257443a
Final airgap tweaks
2020-09-09 10:54:47 -04:00
Doug Burks
eaf3281ab7
Remove Suricata version numbers from Setup screens #1300
...
https://github.com/Security-Onion-Solutions/securityonion/issues/1300
2020-09-09 10:43:41 -04:00
Josh Patterson
c2398f966b
Merge pull request #1295 from Security-Onion-Solutions/fix/salt-ca-ssl
...
Fix/salt ca ssl
2020-09-09 10:36:54 -04:00
m0duspwnens
7facff2b7d
change from cmd.run to cp.get_file_str
2020-09-09 10:34:53 -04:00
Jason Ertel
ad05e75ce7
Add new quick actions to SOC config template
2020-09-09 00:46:23 -04:00
Mike Reeves
7d524a0723
Add Firewall Rule for yum and airgap
2020-09-08 18:51:14 -04:00
Josh Patterson
d7016b4557
Merge pull request #1298 from Security-Onion-Solutions/issue/1291
...
Issue/1291
2020-09-08 17:40:33 -04:00
m0duspwnens
da34222931
makedirs
2020-09-08 17:36:27 -04:00
m0duspwnens
eeb6c3128b
add salt.master state to manager nodes
2020-09-08 17:27:13 -04:00
m0duspwnens
da3d0948b4
creating engine to watch the health of the salt mine
2020-09-08 16:49:38 -04:00
Jason Ertel
710a2be422
Add new so-user-enable script and change so-user-disable to call 'so-user disable' instead of deleting the SOC user
2020-09-08 16:24:18 -04:00
Mike Reeves
7c41c31359
Fix airgap statement
2020-09-08 14:48:37 -04:00
Mike Reeves
7371f9236e
Update top.sls
2020-09-08 14:18:56 -04:00
Mike Reeves
1aea3f4f85
Merge pull request #1297 from Security-Onion-Solutions/experimental
...
Add Airgap code
2020-09-08 09:26:41 -04:00
Doug Burks
f8ebed43d7
fix spacing
2020-09-07 04:45:26 -04:00
Doug Burks
f5916e26a2
read ca.crt from filesystem when possible
2020-09-07 04:42:11 -04:00
weslambert
b6b52671e2
Merge pull request #1294 from Security-Onion-Solutions/fix/wazuh_agent_name
...
Fix typo
2020-09-05 08:17:09 -04:00
Wes Lambert
f9884606df
Fix typo
2020-09-05 12:15:55 +00:00
Jason Ertel
f27e5164d0
Update to latest kratos; add support for a custom status trait to represent whether a user is locked or not; refactor so-user to use new enable/disable capabilities in SOC; remove 'delete' option from so-user usage to avoid having user lists out of sync across SOC and external apps
2020-09-04 17:01:52 -04:00
Josh Brower
351e7761ef
Merge pull request #1292 from Security-Onion-Solutions/bugfix/playbook-rulesets
...
Update SOCtopus.conf
2020-09-04 14:15:18 -04:00
Josh Brower
39cc7151a5
Update SOCtopus.conf
2020-09-04 14:14:53 -04:00
Doug Burks
f8e68c82e4
downgrade to Mono 4.2.1.102 and NetworkMiner 2.4
2020-09-04 10:12:28 -04:00
Doug Burks
c050003b5a
Install file-roller for opening zip files
2020-09-04 07:14:01 -04:00
Doug Burks
a2265fac4f
NetworkMiner has a compatibility issue with Mono 6 right now
2020-09-04 06:50:22 -04:00
Doug Burks
1fc64d3eef
so-analyst should install gedit
2020-09-03 16:46:14 -04:00
Josh Patterson
c71a154e81
Merge pull request #1288 from Security-Onion-Solutions/quickfix/standalonetop
...
add elasticsearch to standalone top
2020-09-03 15:55:43 -04:00
m0duspwnens
05b8b71af2
add elasticsearch to standalone top
2020-09-03 15:54:24 -04:00
Mike Reeves
b2ee757db2
Airgap Time
2020-09-03 10:35:12 -04:00
weslambert
b10dd40376
Merge pull request #1287 from Security-Onion-Solutions/fix/suri_home_net
...
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:51 -04:00
weslambert
8db8dcb71a
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:14 -04:00
m0duspwnens
770cd6eafc
add endif
2020-09-02 16:19:58 -04:00
Mike Reeves
9745191f19
Add Airgap State
2020-09-02 16:17:44 -04:00
m0duspwnens
a229ae82ce
only allow state to run if it is in top for the node
2020-09-02 16:15:52 -04:00
weslambert
870e042c4c
Merge pull request #1285 from Security-Onion-Solutions/fix/so_stop_start_restart
...
Require at least one arg for start/stop/restart scripts
2020-09-02 14:58:19 -04:00
Wes Lambert
770aaf415c
Require at least on arg for start/stop/restart scripts
2020-09-02 18:55:59 +00:00
Jason Ertel
0142f43493
Add so-user-disable script which deletes the SOC user and disables the users in Fleet, TheHive, and Cortex
2020-09-02 13:54:50 -04:00
m0duspwnens
9d85b3223f
fix note about localrules
2020-09-02 11:46:48 -04:00
Josh Patterson
066c795e71
Merge pull request #1279 from Security-Onion-Solutions/fix/redhat
...
move redhat with centos
2020-09-02 09:12:44 -04:00
m0duspwnens
1f8f197066
move redhat with centos
2020-09-02 09:12:05 -04:00
weslambert
d35cca7fc5
Merge pull request #1278 from Security-Onion-Solutions/fix/elastalert_extra_hosts
...
Add manager to hosts file
2020-09-02 07:44:49 -04:00
weslambert
5d920885e0
Add manager to hosts file
2020-09-02 07:43:55 -04:00
Josh Patterson
7fa083069d
Merge pull request #1277 from Security-Onion-Solutions/issue/968
...
Issue/968
2020-09-01 15:43:22 -04:00
m0duspwnens
08ca2055dc
fix telegraf file input for zeek log
2020-09-01 15:34:06 -04:00
m0duspwnens
93f30a2064
fix telegraf config
2020-09-01 15:29:29 -04:00
m0duspwnens
b13b07eddf
add newline to end
2020-09-01 15:10:56 -04:00
m0duspwnens
01777c64d9
fix influxtime
2020-09-01 14:58:48 -04:00
m0duspwnens
b6d66bddfc
add redis to proper node types. grafana dahsboard changes. change zeek_restart to not use telegraf socket but read from file instead
2020-09-01 14:38:10 -04:00
Josh Brower
6cd0d16b91
Merge pull request #1276 from Security-Onion-Solutions/feature/import-wel
...
Initial support for evtx import
2020-09-01 13:48:12 -04:00
Josh Brower
a79d0319cd
Initial support for evtx import
2020-09-01 13:47:27 -04:00
Mike Reeves
951fe2ac69
Create repo
2020-09-01 11:26:33 -04:00
Mike Reeves
9cff7c1427
Enable airgap functions
2020-09-01 11:24:22 -04:00
Mike Reeves
643dab12d0
Enable airgap
2020-09-01 11:09:33 -04:00
Josh Patterson
67766745a4
Merge pull request #1275 from Security-Onion-Solutions/fix/redhat
...
resolve issue with salt state if os is redhat
2020-09-01 10:44:59 -04:00
m0duspwnens
2fee151bff
resolve issue with salt state if os is redhat
2020-09-01 10:43:21 -04:00
m0duspwnens
ada1c81ab7
manager and standalone dashboard changes
2020-09-01 10:40:20 -04:00
Jason Ertel
ff5d1cd815
Expand nginx body size limit to 2.5GB to handle 2G PCAPs from sensors
2020-09-01 10:07:28 -04:00
Doug Burks
45c0a7ac77
Kernel messages can overwrite whiptail screen #812
...
Kernel messages can overwrite whiptail screen #812
2020-09-01 08:55:34 -04:00
m0duspwnens
a1a7b36319
merge with dev and resolve conflict
2020-08-31 16:05:34 -04:00
m0duspwnens
31f25eca57
fix grafana related issues. add redis to standalone
2020-08-31 15:56:58 -04:00
weslambert
011958a2f3
Merge pull request #1274 from Security-Onion-Solutions/fix/zeek_syslog
...
Ensure Zeek syslog log is enabled for Import node
2020-08-31 13:08:44 -04:00
Wes Lambert
ae3fe9e892
Ensure Zeek syslog log is enabled for Import node
2020-08-31 17:07:16 +00:00
weslambert
96f25914db
Merge pull request #1273 from Security-Onion-Solutions/fix/zeek_syslog_default
...
Fix/zeek syslog default
2020-08-31 12:32:52 -04:00
Wes Lambert
5ed5e6603d
Fix space
2020-08-31 16:32:12 +00:00
Wes Lambert
26ffc44fd1
Only enable syslog log by default in Eval mode
2020-08-31 16:30:32 +00:00
Jason Ertel
dc3b065a41
Set exec bit on new user-add scripts
2020-08-31 10:57:23 -04:00
weslambert
6350c83e05
Merge pull request #1272 from Security-Onion-Solutions/feature/wazuh_mgmt_wrappers
...
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 10:55:25 -04:00
Wes Lambert
46e7e121e3
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 14:54:24 +00:00
weslambert
5db70cbd59
Merge pull request #1271 from Security-Onion-Solutions/fix/remove_minio
...
Remove minio for now
2020-08-31 10:29:30 -04:00
Wes Lambert
6d14f2af96
Remove minio for now
2020-08-31 14:07:47 +00:00
weslambert
42bd75a1cc
Merge pull request #1270 from Security-Onion-Solutions/fix/elastalert_startup
...
Wait for Elasticsearch indices to be queryable before starting Elasta…
2020-08-31 09:56:18 -04:00
Wes Lambert
9abbda8e04
Wait for Elasticsearch indices to be queryable before starting Elastalert container
2020-08-31 13:54:49 +00:00
Jason Ertel
189c02648d
Move container status check to so-common
2020-08-31 09:52:06 -04:00
Jason Ertel
8e06f0453e
Only add users to aux systems if those systems are currently running
2020-08-31 09:41:06 -04:00
Doug Burks
9680270b20
Set default monospace font to Liberation
2020-08-30 16:42:44 -04:00
Doug Burks
2f09156a02
quote filename when spawning NetworkMiner
2020-08-30 16:10:47 -04:00
Doug Burks
77b3ebdabe
Hunt Events table should show ssl.server_name when searching for ssl
...
Hunt Events table should show ssl.server_name when searching for ssl #1267
2020-08-30 06:56:15 -04:00
Doug Burks
13ce439678
Update README
2020-08-29 06:52:26 -04:00
Doug Burks
df5ef7c956
Update so-analyst
2020-08-29 06:07:58 -04:00
Doug Burks
1e1212bf41
Update so-analyst
2020-08-29 05:59:21 -04:00
Doug Burks
c20f47ffd6
make chaosreader executable
2020-08-29 04:52:21 -04:00
Doug Burks
c21b347549
Update README
2020-08-29 04:46:00 -04:00
Doug Burks
f6f990ca9f
Update README
2020-08-28 16:44:41 -04:00
Doug Burks
8344e38d91
Add files via upload
2020-08-28 16:43:28 -04:00
Josh Brower
764ba4a0e9
Merge pull request #1266 from Security-Onion-Solutions/bugfix/event.code-parsing
...
Set event.code to string for WEL
2020-08-28 13:49:01 -04:00
Josh Brower
b7dd14b8f0
Set event.code to string for WEL
2020-08-28 13:40:04 -04:00
Jason Ertel
3877706f20
Remove auto-start regardless of how setup was started
2020-08-28 09:10:35 -04:00
Jason Ertel
4e3e83820f
Correct pillar key for thehive
2020-08-28 08:17:42 -04:00
Josh Patterson
f4dc67e32a
Merge pull request #1264 from Security-Onion-Solutions/issue/1063
...
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:25:26 -04:00
m0duspwnens
b1e7ffc173
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:24:26 -04:00
Jason Ertel
a3e34bfaca
Add users to Fleet, TheHive, and Cortex when adding a user to SO via so-user-add command
2020-08-27 16:58:02 -04:00
Josh Patterson
9d30b58247
Merge pull request #1262 from Security-Onion-Solutions/issue/643
...
remove space
2020-08-27 15:09:05 -04:00
m0duspwnens
aa60ec8e5a
remove space
2020-08-27 15:07:45 -04:00
Josh Patterson
2559f740f1
Merge pull request #1260 from Security-Onion-Solutions/issue/643
...
Issue/643
2020-08-27 14:35:39 -04:00
m0duspwnens
dbb1390c42
move README to /
2020-08-27 14:32:51 -04:00
Mike Reeves
2b0b695ee4
Fix duplicate docker
2020-08-27 10:15:22 -04:00
Mike Reeves
dc6c0cc71c
Merge pull request #1259 from Security-Onion-Solutions/issue/286
...
Issue/286
2020-08-27 10:13:17 -04:00
m0duspwnens
e9b7538ee8
fix a couple things, add another package
2020-08-26 17:58:27 -04:00
m0duspwnens
16c3b9539b
fix a couple things, add another package
2020-08-26 17:51:04 -04:00
m0duspwnens
cc88c4c35f
adding so-analyst script to create analyst workstatin
2020-08-26 17:39:11 -04:00
weslambert
509985ed07
Merge pull request #1254 from Security-Onion-Solutions/fix/sensor_clean
...
Cron updates
2020-08-26 11:03:03 -04:00
weslambert
000c2abb33
Update timing for so-yara-update
2020-08-26 11:02:33 -04:00
Mike Reeves
19130b563d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/286
2020-08-26 11:01:01 -04:00
Mike Reeves
e1a52a4921
Update core counts if heavy node or SA
2020-08-26 11:00:23 -04:00
Mike Reeves
86584d90d7
Merge pull request #1253 from Security-Onion-Solutions/issue/1078
...
Issue/1078 Update Docker
2020-08-26 10:36:34 -04:00
Mike Reeves
e993397173
Update docker to latest version
2020-08-26 10:35:17 -04:00
Josh Brower
c38f4ad4ae
Merge pull request #1251 from Security-Onion-Solutions/feature/fleet3.1
...
Upgraded to Fleet 3.1
2020-08-26 06:14:34 -04:00
Josh Brower
67e0a219e6
Upgraded to Fleet 3.1
2020-08-26 06:13:45 -04:00
Josh Brower
b6ebcf6551
Merge pull request #1250 from Security-Onion-Solutions/feature/es-security-field
...
Adds new .security analyzed subfield
2020-08-26 05:12:23 -04:00
Josh Brower
1cf7301db4
Adds new .security analyzed subfield
2020-08-26 05:11:42 -04:00
Jason Ertel
3122280bd5
Update version to 2.2.0-rc.3
2020-08-25 15:16:09 -04:00
weslambert
ce49e050bc
Update timing for sensor clean cron
2020-08-25 12:14:43 -04:00
weslambert
61cc5b9712
Merge pull request #1246 from Security-Onion-Solutions/fix/sensor_clean_log
...
Fix/sensor clean log
2020-08-25 11:36:10 -04:00
Wes Lambert
c03812f7ab
Add rotation for sensor_clean log
2020-08-25 15:34:30 +00:00
weslambert
a8f727ad40
Don't write to log if not past CRIT_DISK_USAGE
2020-08-25 11:19:36 -04:00
Mike Reeves
6c5f8f7d53
Merge pull request #1240 from Security-Onion-Solutions/issue/1225
...
Remove duplicate IDSTools entries
2020-08-24 10:41:18 -04:00
Mike Reeves
52602f527e
Merge pull request #1238 from Security-Onion-Solutions/issue/796
...
Add /usr/sbin to the path
2020-08-24 10:39:29 -04:00
Mike Reeves
bc6eb74af2
Merge pull request #1230 from Security-Onion-Solutions/dev
...
2.1.0
2020-08-24 10:25:28 -04:00
Doug Burks
b627f565c9
Update VERIFY_ISO.md
2020-08-24 10:03:28 -04:00
Doug Burks
a0281830f8
Update VERIFY_ISO.md
2020-08-24 06:09:30 -04:00
Mike Reeves
aa3e3c3cec
Update Sig
2020-08-23 20:25:06 -04:00
Mike Reeves
e8568dbeb0
Update VERIFY_ISO.md
2020-08-23 20:23:49 -04:00
Mike Reeves
a97ca94354
Rotate suri stats log hourly
2020-08-23 16:08:17 -04:00
Mike Reeves
ebd8105cb5
Rotate suri stats log hourly
2020-08-23 16:03:37 -04:00
Mike Reeves
02712e7f46
Add /usr/sbin to the path
2020-08-22 11:07:00 -04:00
Mike Reeves
093819b0c7
Remove duplicate IDSTools entries
2020-08-22 10:32:11 -04:00
Doug Burks
daaa2d3579
Update README.md
2020-08-21 16:24:09 -04:00
Mike Reeves
3ea5bd0c53
Update MD5 and gpg info for new iso
2020-08-21 14:44:12 -04:00
Mike Reeves
64d34e46bf
Update ISO signature
2020-08-21 14:31:04 -04:00
Jason Ertel
9c6cc81f70
Remove improper suricata logging filter - this re-enables logging output for the suricata process itself
2020-08-21 12:44:28 -04:00
Mike Reeves
bdb8f616e4
Update VERIFY_ISO.md
2020-08-21 09:08:44 -04:00
Mike Reeves
60fbe357c5
Merge branch 'master' into dev
2020-08-20 21:10:59 -04:00
Mike Reeves
d0eae47047
Update ISO download details and signature
2020-08-20 21:08:17 -04:00
Mike Reeves
05d727e599
Final changes.json update
2020-08-20 19:18:39 -04:00
Mike Reeves
2b88f22eb2
Make HUP for rotate more reliable
2020-08-20 17:57:36 -04:00
Mike Reeves
69b3de43b9
Merge pull request #1229 from Security-Onion-Solutions/fix/statslog
...
add logrotate
2020-08-20 16:53:23 -04:00
Mike Reeves
b7da768dc7
add logrotate
2020-08-20 16:46:32 -04:00
Josh Patterson
44093e7484
Merge pull request #1228 from Security-Onion-Solutions/quickfix/importnode
...
remove bonding for import node
2020-08-20 14:23:21 -04:00
m0duspwnens
a7a0520cfe
remove bonding for import node
2020-08-20 14:20:09 -04:00
Jason Ertel
d1e5649a68
Corrected JSON typo and improved formatting
2020-08-20 13:46:20 -04:00
Mike Reeves
b7d1fd54c7
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-08-20 13:26:22 -04:00
Mike Reeves
3eea2c6b10
2.1.0 Release notes in changes.json
2020-08-20 13:26:14 -04:00
Jason Ertel
377c841c31
Switch back to direct command for removing setup from bash_profile due to how sed is interpreting the quoted expression
2020-08-20 13:11:57 -04:00
Mike Reeves
073a175939
Merge pull request #1224 from Security-Onion-Solutions/fix/mkrssl
...
Point logstash to use intca.crt
2020-08-20 10:52:28 -04:00
Mike Reeves
df95baa835
Point logstash to use intca.crt
2020-08-20 10:45:48 -04:00
weslambert
12a9d26231
Merge pull request #1223 from Security-Onion-Solutions/fix/aws_fwd_defaults
...
Add defaults file for fwdnode
2020-08-20 10:17:21 -04:00
Wes Lambert
3f04e566f2
Add defaults file for fwdnode
2020-08-20 14:16:05 +00:00
Jason Ertel
896bf6b78c
Update doc links to 2.1
2020-08-20 10:08:10 -04:00
Jason Ertel
22c9180386
Improve redirection of setup command output to log file, including stderr
2020-08-20 10:04:01 -04:00
Josh Patterson
014a0054c2
Merge pull request #1221 from Security-Onion-Solutions/quickfix/managersearch
...
remove monint from managersearch since they dont have a monint
2020-08-20 09:06:30 -04:00
m0duspwnens
43f4ebbcf1
remove monint from managersearch since they dont have a monint
2020-08-20 09:05:38 -04:00
Mike Reeves
2fce138d95
Change it to grains.host instead of grains.id
2020-08-19 21:26:27 -04:00
Mike Reeves
ccc2ed4478
don't create symlinks if a heavy node
2020-08-19 21:18:57 -04:00
Mike Reeves
f9e5ea8ba7
Fix SSL for filebeat
2020-08-19 21:12:41 -04:00
Mike Reeves
f7d3dca322
Fix duplicate state
2020-08-19 21:00:28 -04:00
Mike Reeves
d969b1e1b7
Update init.sls
2020-08-19 20:56:08 -04:00
Mike Reeves
507a3e852c
Update init.sls
2020-08-19 20:02:38 -04:00
Mike Reeves
5f41d9fc25
fix filebeat certs
2020-08-19 19:51:57 -04:00
Mike Reeves
8312221c82
Update soup
2020-08-19 18:51:32 -04:00
Mike Reeves
0439cf3205
Update soup
2020-08-19 18:47:36 -04:00
Jason Ertel
2325940789
Ensure strelka manager connects to local redis on heavy nodes
2020-08-19 16:24:28 -04:00
Josh Patterson
9fce1fc47d
Merge pull request #1220 from Security-Onion-Solutions/issue/1188
...
Issue/1188
2020-08-19 16:15:43 -04:00
Jason Ertel
5ff0058a65
Ensure strelka backend, frontend, and filestream are connecting to redis locally, on heavy node instances
2020-08-19 16:13:18 -04:00
m0duspwnens
961cc67e3f
add nginx state to heavynode
2020-08-19 16:05:40 -04:00
Mike Reeves
51a52228ac
Update init.sls
2020-08-19 16:01:58 -04:00
Mike Reeves
4527758e87
Update init.sls
2020-08-19 16:00:04 -04:00
m0duspwnens
826254bc3d
give redis key to heavy node too
2020-08-19 15:59:48 -04:00
Mike Reeves
ac2cf8c6d8
Merge pull request #1219 from Security-Onion-Solutions/feature/mkrsoup
...
Feature/mkrsoup
2020-08-19 15:47:53 -04:00
Mike Reeves
db2cc5f7a7
Update init.sls
2020-08-19 15:43:51 -04:00
weslambert
d80156505c
Merge pull request #1217 from Security-Onion-Solutions/fix/aws_automation
...
Add defaults file for search node
2020-08-19 15:09:00 -04:00
Wes Lambert
ed1e346789
Add defaults file for search node
2020-08-19 19:07:24 +00:00
Mike Reeves
4c246dc30d
remove airgap install option until rc3
2020-08-19 14:40:31 -04:00
weslambert
d25afe4aa5
Merge pull request #1216 from Security-Onion-Solutions/fix/logstash_hosts
...
Add manager IP to container hosts file
2020-08-19 14:39:04 -04:00
weslambert
b5dd868d1b
Add manager IP to container hosts file
2020-08-19 14:34:28 -04:00
Mike Reeves
6edf1c14f8
Fix filebeat certs
2020-08-19 13:35:58 -04:00
Mike Reeves
bf84822d36
fix if logic
2020-08-19 13:04:10 -04:00
Mike Reeves
3d48c1f99b
Add playbook updates
2020-08-19 12:14:11 -04:00
Mike Reeves
9280dbb9d9
Update soup
2020-08-19 12:00:25 -04:00
m0duspwnens
2f0ffffca4
lock and unlock master during soup
2020-08-19 11:46:29 -04:00
Mike Reeves
f57e0fbc56
Salt ACL
2020-08-19 10:33:26 -04:00
Mike Reeves
95f006db7d
Salt ACL
2020-08-19 10:08:11 -04:00
Mike Reeves
968e481ebe
Add cross cluster for SSL
2020-08-18 17:45:14 -04:00
Mike Reeves
348e802fb7
Add cross cluster for SSL
2020-08-18 17:38:35 -04:00
Mike Reeves
afa87374ad
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/mkrsoup
2020-08-18 17:33:25 -04:00
Mike Reeves
294a197cbf
Add cross cluster for SSL
2020-08-18 16:57:38 -04:00
Josh Brower
ad0f54fc40
Merge pull request #1209 from Security-Onion-Solutions/bugfix/osquery-parsing
...
Osquery Parsing fix
2020-08-18 15:54:47 -04:00
Josh Brower
d4f7a07f85
Osquery Parsing fix
2020-08-18 15:54:11 -04:00
weslambert
ca84ae43ef
Merge pull request #1208 from Security-Onion-Solutions/fix/remove_pillar_from_setup
...
Don't echo pillar to setup log
2020-08-18 15:44:20 -04:00
weslambert
a4e986ea37
Don't echo pillar to setup log
2020-08-18 15:43:43 -04:00
Josh Patterson
be8483c580
Merge pull request #1207 from Security-Onion-Solutions/issue/1188
...
remove monint from nodestab grafana dashboard since search nodes dont…
2020-08-18 15:37:56 -04:00
m0duspwnens
65d9afd8d5
remove monint from nodestab grafana dashboard since search nodes dont have monint
2020-08-18 15:37:17 -04:00
Mike Reeves
59aa55f9bc
Add playsecrets
2020-08-18 15:29:41 -04:00
Jason Ertel
47ad3f65ef
Only fail setup when the root mailbox is not empty for ISO installations, since network installations can't be sure if the error came from setup or something unrelated
2020-08-18 15:26:30 -04:00
Josh Patterson
1bf4b86d07
Merge pull request #1206 from Security-Onion-Solutions/issue/1188
...
remove monint from manager since it doesnt have a monint
2020-08-18 15:10:40 -04:00
m0duspwnens
5a3d95d9a1
remove monint from manager since it doesnt have a monint
2020-08-18 15:09:21 -04:00
Mike Reeves
44fcd999fd
Address #1205
2020-08-18 15:08:24 -04:00
weslambert
82bfa567d0
Merge pull request #1204 from Security-Onion-Solutions/fix/enable_strelka_default
...
Enable YARA rules by default
2020-08-18 14:54:46 -04:00
weslambert
eaad0487b5
Enable YARA rules by default
2020-08-18 14:54:11 -04:00
Josh Patterson
54c43634a3
Merge pull request #1203 from Security-Onion-Solutions/issue/1188
...
add strelka to heavynode if strelka is enabled
2020-08-18 14:29:07 -04:00
m0duspwnens
c8dfc2495c
add strelka to heavynode if strelka is enabled - https://github.com/Security-Onion-Solutions/securityonion/issues/1188
2020-08-18 14:21:23 -04:00
Jason Ertel
45d957566d
Only show 'Waiting for TheHive to start up' status if setup is actually installing thehive
2020-08-18 11:36:29 -04:00
Josh Patterson
b214b20e58
Merge pull request #1201 from Security-Onion-Solutions/issue/1063
...
fix monint for several node types for grafana
2020-08-18 10:53:30 -04:00
m0duspwnens
9f8f59f4df
fix monint for several node types for grafana
2020-08-18 10:48:52 -04:00
Mike Reeves
ba192d6c32
Update addtotab.sh
2020-08-17 17:23:25 -04:00
Josh Brower
9c1c4b1a98
Merge pull request #1198 from Security-Onion-Solutions/feature/playbook-tweaks
...
Playbook schema update - RC2
2020-08-17 14:10:26 -04:00
Josh Brower
a8aa97edd2
Playbook schema update - RC2
2020-08-17 14:09:17 -04:00
Josh Patterson
1d02fbdd0b
Merge pull request #1197 from Security-Onion-Solutions/feature/soup
...
add sls extension
2020-08-17 12:27:34 -04:00
m0duspwnens
eb1272c127
add sls extension
2020-08-17 12:26:44 -04:00
Josh Patterson
5581cf6721
Merge pull request #1196 from Security-Onion-Solutions/feature/soup
...
Feature/soup
2020-08-17 10:57:32 -04:00
m0duspwnens
a82c4c24fb
move url_base from manager to global in when running soup
2020-08-17 10:55:07 -04:00
Mike Reeves
dcb110b31f
Add rc1 conditional logic
2020-08-17 09:57:00 -04:00
Jason Ertel
d8833abf73
Use load instead of import on the registry image itself
2020-08-15 09:42:56 -04:00
Josh Patterson
2c9c328a40
Merge pull request #1193 from Security-Onion-Solutions/issue/1039
...
Issue/1039
2020-08-14 18:45:12 -04:00
m0duspwnens
e6da423dc3
change reference from manager:url_base to global:url_base - https://github.com/Security-Onion-Solutions/securityonion/issues/1039
2020-08-14 17:55:30 -04:00
m0duspwnens
4946bb54d8
Merge remote-tracking branch 'remotes/origin/dev' into issue/1039
2020-08-14 17:25:13 -04:00
Josh Patterson
5663edfaee
Merge pull request #1192 from Security-Onion-Solutions/quickfix/importnoderonicheckin
...
set checking interval for sensoroni on import node
2020-08-14 17:11:35 -04:00
m0duspwnens
387c26f052
set checking interval for sensoroni on import node
2020-08-14 17:10:36 -04:00
Josh Patterson
e4b80ff183
Merge pull request #1190 from Security-Onion-Solutions/quickfix/setuplogging
...
send service status to /dev/null to prevent FP on install failure
2020-08-14 16:47:55 -04:00
m0duspwnens
43f6f5c27a
send service status to /dev/null to prevent FP on install failure
2020-08-14 16:45:28 -04:00
Josh Patterson
51cbccad09
Merge pull request #1189 from Security-Onion-Solutions/quickfix/modulerun
...
use new module.run style
2020-08-14 16:39:17 -04:00
m0duspwnens
5220b5ae0c
use new module.run style
2020-08-14 16:37:45 -04:00
Josh Patterson
6b6f39edde
Merge pull request #1187 from Security-Onion-Solutions/quickfix/heavyfw
...
heavynode firewall rules
2020-08-14 16:01:56 -04:00
m0duspwnens
47faee48a6
heavynode firewall rules
2020-08-14 15:58:59 -04:00
Mike Reeves
eb6b2f6ca0
Merge pull request #1186 from Security-Onion-Solutions/feature/airgap
...
Airgap round 1
2020-08-14 15:41:36 -04:00
Mike Reeves
bac58abf3e
Airgap round 1
2020-08-14 15:32:33 -04:00
m0duspwnens
d963222f31
provide proper url for so-import-pcap based on redirect strategy chosen during setup - https://github.com/Security-Onion-Solutions/securityonion/issues/1039
2020-08-14 15:28:47 -04:00
Jason Ertel
11ebc6b8b2
Do not cancel setup if user choose not to run so-allow during setup
2020-08-14 15:28:42 -04:00
Josh Patterson
0ba0c16c38
Merge pull request #1185 from Security-Onion-Solutions/issue/1049
...
Issue/1049
2020-08-14 14:55:14 -04:00
m0duspwnens
35027e32b3
dont constantly run steno or suricata containers for import node
2020-08-14 14:43:37 -04:00
weslambert
945bc5c6de
Merge pull request #1184 from Security-Onion-Solutions/fix/automate_ssh
...
Don't copy SSH key if automated install
2020-08-14 14:42:44 -04:00
weslambert
c9d6293f8f
Don't copy SSH key if automated install
2020-08-14 14:41:35 -04:00
Jason Ertel
7fa5e17935
Correct if logic for determining when to show web interface URL
2020-08-14 14:40:12 -04:00
m0duspwnens
f9a6b8d231
remove zeek and suricata from so-status for import node
2020-08-14 14:39:02 -04:00
m0duspwnens
3836f00309
allow sensori port for import node
2020-08-14 14:32:34 -04:00
Jason Ertel
04340728ff
Improve title spacing among standard log lines
2020-08-14 14:28:52 -04:00
m0duspwnens
ff84640aad
add pcap to import node, test not starting zeek docker by default
2020-08-14 13:59:23 -04:00
Josh Patterson
fbbec71165
Merge pull request #1183 from Security-Onion-Solutions/issue/1170
...
Issue/1170
2020-08-14 12:56:57 -04:00
m0duspwnens
b7bfa6f9a9
move functions up
2020-08-14 12:55:54 -04:00
m0duspwnens
6602ad3286
sleep for 5 seconds
2020-08-14 12:53:24 -04:00
m0duspwnens
4bb23a089e
add some parens
2020-08-14 12:48:52 -04:00
m0duspwnens
4b21c1b492
logic change
2020-08-14 12:45:50 -04:00
Mike Reeves
2a8e4e4eb2
Merge pull request #1182 from Security-Onion-Solutions/feature/airgap
...
Feature/airgap
2020-08-14 12:32:26 -04:00
m0duspwnens
9d59fc23dd
logic changes
2020-08-14 12:24:15 -04:00
Mike Reeves
c64faacdbc
Install registry if the image is local
2020-08-14 12:15:56 -04:00
Mike Reeves
18f37e3ef8
Install registry if the image is local
2020-08-14 11:49:18 -04:00
m0duspwnens
e229cb49bc
logic changes
2020-08-14 11:40:21 -04:00
Wes Lambert
7686a05f42
Set Strelka rules enabled by default for Eval Mode
2020-08-14 15:33:38 +00:00
m0duspwnens
69fd803759
change while
2020-08-14 11:30:10 -04:00
m0duspwnens
683e8a2a39
remove quotes
2020-08-14 11:24:46 -04:00
weslambert
b662f9354f
Merge pull request #1180 from Security-Onion-Solutions/fix/thehive_global
...
Only copy TheHive details to global pillar if enabled
2020-08-14 11:23:16 -04:00
Wes Lambert
ab4285aaaf
Only copy TheHive details to global pillar if enabled
2020-08-14 15:21:56 +00:00
m0duspwnens
aa2b0699d5
move parens
2020-08-14 11:20:18 -04:00
m0duspwnens
876c6c7cb0
logic changes
2020-08-14 11:16:56 -04:00
m0duspwnens
ea5116700d
stop both service then start both
2020-08-14 11:01:26 -04:00
m0duspwnens
cd1169b68d
logging changes
2020-08-14 10:53:42 -04:00
m0duspwnens
e2fbe59b7c
additional logging
2020-08-14 10:30:01 -04:00
m0duspwnens
0eb0551b68
add check if salt minion is returning jobs
2020-08-14 10:15:54 -04:00
Mike Reeves
283f91459a
Fix rule update cron
2020-08-14 10:05:56 -04:00
Mike Reeves
7309767829
Merge pull request #1178 from Security-Onion-Solutions/fix/elasticwatch
...
Add watch statements
2020-08-14 09:58:40 -04:00
Mike Reeves
a3d8b7d0d3
Add watch statements
2020-08-14 09:40:38 -04:00
Jason Ertel
78bceeb9e5
Only show the web interface link when the redirect URL is available, such as on manager nodes
2020-08-14 09:17:25 -04:00
Jason Ertel
ee62faae72
Only show the web interface link when the redirect URL is available, such as on manager nodes
2020-08-14 09:10:28 -04:00
Jason Ertel
e6830e9cba
Avoid reusing header function from so-common
2020-08-14 01:09:47 -04:00
m0duspwnens
42c1e817fe
more logging and debugging
2020-08-13 18:09:57 -04:00
m0duspwnens
f9f2744d3f
logic changes
2020-08-13 17:49:05 -04:00
Jason Ertel
3c113a7a89
Add system information at beginning of installation; provide logging functions to be used instead of echo commands
2020-08-13 17:29:50 -04:00
Josh Brower
34d8261669
Merge pull request #1176 from Security-Onion-Solutions/feature/playbook
...
Elastalert/Playbook Stability updates
2020-08-13 17:19:01 -04:00
Josh Brower
7400bbd6c1
Elastalert Stability Fixes
2020-08-13 17:14:53 -04:00
m0duspwnens
829490da19
fix errors
2020-08-13 17:05:50 -04:00
m0duspwnens
6cf623e133
some logic changes
2020-08-13 16:52:39 -04:00
Doug Burks
ed4bee0d0b
so-allow has no usage function #1133
2020-08-13 16:42:50 -04:00
m0duspwnens
3d20cc0341
some debugging
2020-08-13 16:34:18 -04:00
m0duspwnens
1b4029f74b
fix syntax errors
2020-08-13 16:18:02 -04:00
m0duspwnens
07ef464375
https://github.com/Security-Onion-Solutions/securityonion/issues/1170
2020-08-13 16:01:53 -04:00
Jason Ertel
40b5b96e17
Respond with 403 status code to unauthorized sensor requests
2020-08-13 15:00:49 -04:00
Josh Patterson
078f87d6c7
Merge pull request #1169 from Security-Onion-Solutions/issue/1049
...
remove so-registry from docker see for import node as it doesnt even …
2020-08-13 10:49:14 -04:00
m0duspwnens
8ab1cd32f0
remove so-registry from docker see for import node as it doesnt even exist
2020-08-13 10:47:57 -04:00
Josh Patterson
ae66ec5f43
Merge pull request #1168 from Security-Onion-Solutions/issue/1049
...
Issue/1049
2020-08-13 10:12:47 -04:00
m0duspwnens
9fafd5f721
update trusted containers for soup to minimize downloaded containers
2020-08-13 08:32:51 -04:00
m0duspwnens
3387114389
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-13 08:21:43 -04:00
Mike Reeves
5a53194313
Update sotls.yml
2020-08-12 21:12:48 -04:00
Mike Reeves
59ddac57bf
Rename sotls.yaml to sotls.yml
2020-08-12 17:48:37 -04:00
m0duspwnens
a746d597bb
rename to .yml
2020-08-12 17:42:45 -04:00
m0duspwnens
dbe14fcbdb
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-12 16:46:03 -04:00
Doug Burks
5640faef13
Kernel consoleblank is causing whiptail progress screen to appear to hang #1084
2020-08-12 16:34:59 -04:00
m0duspwnens
f59b8683ae
allow soup to run on import node
2020-08-12 15:48:34 -04:00
m0duspwnens
5d5fcecdca
set the cluster for import node
2020-08-12 15:46:34 -04:00
Mike Reeves
0129519d0c
Merge pull request #1165 from Security-Onion-Solutions/feature/esssl
...
TLS Transport Encryption
2020-08-12 15:39:17 -04:00
Mike Reeves
9980d02844
Elastic Transport TLSgit add .
2020-08-12 15:38:19 -04:00
Mike Reeves
7e3e4d0f54
Convert ES cert to p12
2020-08-12 15:16:12 -04:00
Mike Reeves
82821fbb25
Convert ES cert to p12
2020-08-12 15:09:52 -04:00
Mike Reeves
daaffd5185
Convert ES cert to p12
2020-08-12 15:05:33 -04:00
Mike Reeves
683799d077
Convert ES cert to p12
2020-08-12 15:02:54 -04:00
m0duspwnens
ddf3e6f943
remove logstash from docker registry seed
2020-08-12 14:05:28 -04:00
Mike Reeves
c02a363e92
Merge pull request #1163 from Security-Onion-Solutions/feature/esssl
...
Feature/esssl
2020-08-12 14:02:27 -04:00
Mike Reeves
69e7285e30
Fix a bug where minio passwrods cause issues
2020-08-12 12:44:55 -04:00
m0duspwnens
68f5c1c3c5
create web user during setup for import node
2020-08-12 12:01:25 -04:00
m0duspwnens
dcd5e95b38
add so-pcaptools to registry for import node
2020-08-12 11:57:13 -04:00
m0duspwnens
c166bc84f3
add zeek to import node top
2020-08-12 11:48:22 -04:00
m0duspwnens
41afe0ab2e
remove tab
2020-08-12 11:33:10 -04:00
m0duspwnens
b5c9d44d91
nginx config for import node
2020-08-12 11:15:14 -04:00
Mike Reeves
32083132e5
Back out some ES settings
2020-08-12 11:10:36 -04:00
m0duspwnens
dfd3a1de6a
set monitor interface to bond0 for import node
2020-08-12 10:42:07 -04:00
m0duspwnens
0f53b4d703
set esheapsize and filebeat config for import node
2020-08-12 10:39:31 -04:00
m0duspwnens
5a0df27193
rename importpcap node to import
2020-08-12 10:27:15 -04:00
m0duspwnens
6260a0aeaa
add idstools to docker registry for importpcap node
2020-08-11 16:29:35 -04:00
m0duspwnens
53b4a73bb9
add idstools to importpcap node
2020-08-11 15:59:08 -04:00
m0duspwnens
de05403237
ensure nids rules dir exists
2020-08-11 15:52:15 -04:00
Mike Reeves
0f7074a499
SSL intraca
2020-08-11 15:49:04 -04:00
Mike Reeves
65d535d893
SSL intraca
2020-08-11 15:45:17 -04:00
Mike Reeves
f862133323
SSL intraca
2020-08-11 15:37:55 -04:00
Mike Reeves
5a0aae5fe7
SSL intraca
2020-08-11 15:34:07 -04:00
Mike Reeves
a817465318
SSL intraca
2020-08-11 15:25:09 -04:00
Mike Reeves
e8b61a3828
SSL intraca
2020-08-11 15:14:29 -04:00
Mike Reeves
5f30c947c9
SSL intraca
2020-08-11 15:12:23 -04:00
Josh Brower
b724d40376
Playbook Stability Fixes
2020-08-11 15:07:16 -04:00
m0duspwnens
a81d14463c
add logstash to registry for importpcap, change PATCHSCHEDULENAME=auto
2020-08-11 15:01:20 -04:00
Mike Reeves
42c9653669
anon user hack
2020-08-11 14:45:55 -04:00
Mike Reeves
f553a8e27a
anon user hack
2020-08-11 14:40:34 -04:00
Mike Reeves
8daf11f085
Fix logstash outputs
2020-08-11 13:58:28 -04:00
m0duspwnens
40006752a1
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-11 13:30:48 -04:00
m0duspwnens
ee91450424
fix patch schedule name for importpcap node
2020-08-11 13:30:41 -04:00
weslambert
796551d71b
Merge pull request #1161 from Security-Onion-Solutions/fix/redisconf
...
Update Redis maxmemory settings
2020-08-11 13:27:28 -04:00
Mike Reeves
362749ca85
Make hostnames default in cross cluster
2020-08-11 13:00:42 -04:00
weslambert
b95f8a9314
Update Redis maxmemory settings
2020-08-11 12:57:57 -04:00
m0duspwnens
ec62668eb7
firewall rules for importpcap node
2020-08-11 12:31:37 -04:00
m0duspwnens
f6a85ac852
top and seed registry for importpcap node
2020-08-11 12:27:21 -04:00
Mike Reeves
94bb9e0d6c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-11 12:20:00 -04:00
Mike Reeves
95367f8d23
Fix cross cluster
2020-08-11 12:00:58 -04:00
Mike Reeves
348f7f39cc
strip node suffix
2020-08-11 11:37:53 -04:00
Mike Reeves
05a05b5e9b
use hostname for cross cluster
2020-08-11 11:15:57 -04:00
Mike Reeves
cbba473c2d
fix ssl certs for SN
2020-08-11 11:10:27 -04:00
Mike Reeves
32c407231f
fix ssl certs for SN
2020-08-11 11:08:49 -04:00
Mike Reeves
a5131da5c9
fix ssl certs for SN
2020-08-11 11:07:34 -04:00
Mike Reeves
7e0249c377
ES cleanup
2020-08-11 10:28:21 -04:00
Mike Reeves
b84d7d818f
Fix for loop
2020-08-11 10:20:02 -04:00
Mike Reeves
d941209479
Walk nodes tab
2020-08-11 10:17:28 -04:00
Mike Reeves
32f8ea3158
Removes https from rest port
2020-08-11 10:02:00 -04:00
Jason Ertel
854cc487f7
Always disable screen blanking, to simplify logic
2020-08-11 09:21:06 -04:00
Mike Reeves
59292425c0
Add transport hostname
2020-08-10 23:03:54 -04:00
Mike Reeves
ac3f490299
Add transport hostname
2020-08-10 23:02:03 -04:00
Mike Reeves
730e389aae
Add transport hostname
2020-08-10 22:57:49 -04:00
Mike Reeves
52cc56bebb
Add transport hostname
2020-08-10 22:56:15 -04:00
Mike Reeves
c3d8c599cc
Turn off user auth
2020-08-10 22:13:17 -04:00
Mike Reeves
6007a6c4d8
Things like this are why I hate Java
2020-08-10 22:10:03 -04:00
Mike Reeves
d00231af06
Things like this are why I hate Java
2020-08-10 22:05:46 -04:00
Mike Reeves
31ab1e8ed8
Things like this are why I hate Java
2020-08-10 22:03:24 -04:00
Mike Reeves
6d2be9af7e
Things like this are why I hate Java
2020-08-10 21:58:44 -04:00
Mike Reeves
cdda46ce58
ca typeo
2020-08-10 21:54:36 -04:00
Mike Reeves
811da5732a
Elastic logic fix
2020-08-10 21:51:29 -04:00
Mike Reeves
08d544e527
Fix SSL perms
2020-08-10 21:44:45 -04:00
Mike Reeves
cf5c29d01c
Change certs path on elstic
2020-08-10 21:30:53 -04:00
Mike Reeves
e28619604c
Change certs path on elstic
2020-08-10 21:26:00 -04:00
Mike Reeves
e7cd527d49
Enable SSL in elastic
2020-08-10 21:18:03 -04:00
Mike Reeves
92cc176b6d
Fix features logic in all states that use it
2020-08-10 20:59:41 -04:00
Mike Reeves
28806513d9
Logstash logic fix
2020-08-10 20:53:56 -04:00
m0duspwnens
11433b87e6
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-10 16:36:49 -04:00
Mike Reeves
788864310c
Fix ssl state
2020-08-10 14:52:20 -04:00
Mike Reeves
523e42bec8
Fix ssl state
2020-08-10 14:40:11 -04:00
Mike Reeves
9d2d8d372f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-10 14:27:08 -04:00
Mike Reeves
e659af3466
ES basic SSL
2020-08-10 14:26:56 -04:00
Josh Patterson
6bb84f8513
Merge pull request #1160 from Security-Onion-Solutions/quickfix/saltinstall
...
add replace: False to get rid of warning, eventhough it doesntt. bug …
2020-08-10 13:06:15 -04:00
m0duspwnens
1f3ceb50da
add replace: False to get rid of warning, eventhough it doesntt. bug report submitted on saltstack gh.
2020-08-10 13:04:19 -04:00
Josh Patterson
b0aa40737b
Merge pull request #1159 from Security-Onion-Solutions/quickfix/saltinstall
...
fix --exclude, add salt-minion-3001.1 where missed
2020-08-10 12:23:48 -04:00
m0duspwnens
8146930b80
fix --exclude, add salt-minion-3001.1 where missed
2020-08-10 12:22:42 -04:00
Josh Patterson
b6740ef360
Merge pull request #1158 from Security-Onion-Solutions/quickfix/saltinstall
...
upgrading to salt 3001.1
2020-08-10 10:21:55 -04:00
m0duspwnens
ab7014d70a
upgrading to salt 3001.1
2020-08-10 10:19:25 -04:00
Mike Reeves
29aaa84a6f
Merge pull request #1157 from Security-Onion-Solutions/feature/esssl
...
Feature/esssl
2020-08-08 22:20:55 -04:00
Mike Reeves
32fe3ed961
fix ports
2020-08-08 20:59:13 -04:00
Mike Reeves
63031a965a
fix ports
2020-08-08 20:48:46 -04:00
Mike Reeves
bc09a89a01
output plugin to normal port
2020-08-08 20:36:28 -04:00
Mike Reeves
9248896a20
fix redis ports
2020-08-08 20:24:30 -04:00
Mike Reeves
112dba4549
Upodate SSL
2020-08-08 20:12:17 -04:00
Mike Reeves
f154d2fa78
Upodate SSL
2020-08-08 20:04:19 -04:00
Mike Reeves
9708b02387
update pipeline
2020-08-08 18:32:36 -04:00
Mike Reeves
86fd38a347
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-08 17:32:29 -04:00
Mike Reeves
f840c85a46
make script run
2020-08-08 17:31:59 -04:00
Mike Reeves
26a095a89c
redis binds
2020-08-08 00:20:46 -04:00
Mike Reeves
8a50768e16
redis binds
2020-08-08 00:19:55 -04:00
Mike Reeves
dc12cacee0
generate redis key
2020-08-08 00:16:38 -04:00
Mike Reeves
d1c4e3d021
generate redis key
2020-08-08 00:15:36 -04:00
Mike Reeves
20dba6eaac
jruby ssl fun
2020-08-07 23:56:09 -04:00
Mike Reeves
ec1065462c
jruby ssl fun
2020-08-07 23:50:26 -04:00
Jason Ertel
5e3d21c43c
Wrap minio keys with quotes to ensure YAML parsing
2020-08-07 23:50:18 -04:00
Mike Reeves
d171adb9c9
jruby ssl fun
2020-08-07 23:39:13 -04:00
Mike Reeves
64af6f99e9
jruby ssl fun
2020-08-07 23:34:55 -04:00
Mike Reeves
2705cbbf45
jruby ssl fun
2020-08-07 23:33:02 -04:00
Mike Reeves
5525e235d1
jruby ssl fun
2020-08-07 23:28:58 -04:00
Mike Reeves
62a6f29c96
bucket stuff
2020-08-07 22:51:52 -04:00
Mike Reeves
321122cc87
update logstash
2020-08-07 22:43:34 -04:00
Mike Reeves
0d66e32305
sync cacerts
2020-08-07 22:39:29 -04:00
Mike Reeves
952234446f
fix logic
2020-08-07 22:18:58 -04:00
Mike Reeves
cca0dd9344
enable jinja
2020-08-07 22:14:33 -04:00
Mike Reeves
1b0f90b7e4
sync script
2020-08-07 22:12:47 -04:00
Mike Reeves
d15d53bcdc
Add script to extract cacerts
2020-08-07 22:04:30 -04:00
Josh Brower
4b99f55e0a
Merge pull request #1155 from Security-Onion-Solutions/feature/playbook-fixes2
...
Playbook/Nav Fixes - Issue #1064
2020-08-07 17:03:32 -04:00
Josh Brower
928e5ed832
Playbook/Nav Fixes - Issue #1064
2020-08-07 17:02:48 -04:00
m0duspwnens
30e0abf326
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-07 16:43:02 -04:00
m0duspwnens
0c2ea53f25
revert back to local_salt_dir
2020-08-07 16:42:46 -04:00
m0duspwnens
b02332d84a
fix global pillar location for setup
2020-08-07 16:18:11 -04:00
m0duspwnens
7933bafd55
more fixes for importpcap node
2020-08-07 15:46:45 -04:00
m0duspwnens
d7b55c1109
add so-status map for importpcap
2020-08-07 15:21:07 -04:00
m0duspwnens
86b118ba1a
add importpcap to local assigned hostgroups yaml
2020-08-07 15:00:32 -04:00
m0duspwnens
9649994f73
add importpcap to pillar/top
2020-08-07 14:40:02 -04:00
m0duspwnens
a8147d7d3b
add importpcap to salt_checkin for setup ssl/ca
2020-08-07 14:19:58 -04:00
Jason Ertel
847939e9b2
Fixed extra space that causes global.sls file to be empty
2020-08-07 14:11:28 -04:00
m0duspwnens
fadd81c9f3
so-importpcap to ssl state
2020-08-07 13:58:29 -04:00
m0duspwnens
7c3070655b
copy_minion_tmp_files for IMPORTPCAP too
2020-08-07 13:39:17 -04:00
Josh Brower
ff209cfd65
Merge pull request #1149 from Security-Onion-Solutions/feature/wlb-parsing
...
Ingest Parsing Update for Sysmon/WEL
2020-08-07 13:37:22 -04:00
Josh Brower
3ec1b1db71
Merge pull request #1154 from Security-Onion-Solutions/feature/playbook-fixes
...
More Playbook Fixes - Issue #1064
2020-08-07 13:36:38 -04:00
Josh Brower
a8b980b6a7
More Playbook Fixes - Issue #1064
2020-08-07 13:35:43 -04:00
m0duspwnens
2d7aefed0d
add IMPORTPCAP node to set_hostname
2020-08-07 11:42:48 -04:00
m0duspwnens
7d11fc345f
dont ask for patch schedule for importpcap node
2020-08-07 11:19:31 -04:00
m0duspwnens
24b77fa855
enlarge whiptail for install type selection
2020-08-07 11:16:52 -04:00
m0duspwnens
2c6a20fee9
enlarge whiptail for install type selection
2020-08-07 11:11:21 -04:00
m0duspwnens
d668b85033
copy_ssh_key for is_importpcap also
2020-08-07 11:09:12 -04:00
m0duspwnens
fce22c1cc4
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-07 10:27:11 -04:00
Mike Reeves
b534d2b975
Update so-functions
2020-08-07 10:05:47 -04:00
Mike Reeves
d3e6657b45
Fix Spacing
2020-08-07 10:01:40 -04:00
Mike Reeves
80550b0d76
Merge pull request #1151 from Security-Onion-Solutions/feature/minio
...
Feature/minio
2020-08-06 15:45:27 -04:00
Josh Brower
c3da302353
Merge pull request #1150 from Security-Onion-Solutions/feature/playbook-fixes
...
Simplify elastalert rules
2020-08-06 15:45:06 -04:00
Josh Brower
ddd099233a
Playbook Fixes - Issue #1064
2020-08-06 15:43:45 -04:00
Mike Reeves
bbdaee28ed
Add upload queue thread
2020-08-06 15:41:10 -04:00
Mike Reeves
16d0c02113
Fix cert dev null
2020-08-06 15:39:02 -04:00
Mike Reeves
63e31bd6b9
Add upload queue thread
2020-08-06 15:33:48 -04:00
Jason Ertel
31fd0b6407
Update the Hunt event fields lookups to reflect the latest ingest configs
2020-08-06 14:59:39 -04:00
Josh Brower
4f9ef89098
Simplify elastalert rules
2020-08-06 14:30:44 -04:00
Josh Brower
15efe77e06
Ingest Parsing Update for Sysmon/WEL
2020-08-06 13:11:47 -04:00
Mike Reeves
4936da9b5d
Merge pull request #1146 from Security-Onion-Solutions/feature/minio
...
Feature/minio
2020-08-05 23:01:58 -04:00
Mike Reeves
e7225349a6
Ability to toggle between redis and minio
2020-08-05 22:56:41 -04:00
Mike Reeves
4e40615e51
Add tuneable to the global pillar
2020-08-05 22:47:12 -04:00
Mike Reeves
d9b1127308
Switch to gzip encoding
2020-08-05 22:36:23 -04:00
m0duspwnens
d7801acea5
add mode 1
2020-08-05 17:09:41 -04:00
Mike Reeves
633c100ace
final logstash tweaks
2020-08-05 16:40:21 -04:00
Jason Ertel
30ff6d2b93
Update event fields to reflect new ECS terms - WIP
2020-08-05 16:28:36 -04:00
William Wernert
64c366971f
[fix] Redirect ca state apply in setup to /dev/null
...
Redirect ca state apply line in accept_salt_key_remote to /dev/null to avoid generating error in setup log
2020-08-05 16:13:25 -04:00
m0duspwnens
8079dc54fc
add stuff for /etc/salt/minion to get populated for importpcap node
2020-08-05 15:42:22 -04:00
m0duspwnens
83dc35c720
add importpcap mode to whiptail
2020-08-05 15:24:11 -04:00
m0duspwnens
66ca7b266c
first commit of importpcap node mode code, kek
2020-08-05 14:44:23 -04:00
Mike Reeves
cd766753eb
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/minio
2020-08-05 14:34:22 -04:00
Mike Reeves
95cae2f17a
SSL path for logstash
2020-08-05 14:14:35 -04:00
Mike Reeves
e30746c5ca
Final minio fix
2020-08-05 14:12:06 -04:00
Mike Reeves
734f2979d2
add ca.crt to lgostash docker bind
2020-08-04 23:20:51 -04:00
Mike Reeves
1855eeaa13
fix cert name
2020-08-04 23:09:08 -04:00
Mike Reeves
970ee195a1
use hostname so TLS will work
2020-08-04 23:08:33 -04:00
Mike Reeves
58872c9b48
enable ssl logstash
2020-08-04 22:40:59 -04:00
Mike Reeves
a765790d6c
fix minio container name
2020-08-04 22:37:04 -04:00
Mike Reeves
a733dceb18
enable ssl minio
2020-08-04 22:33:40 -04:00
Mike Reeves
5d4a0c53b5
add ssl cert for minio
2020-08-04 21:29:07 -04:00
Mike Reeves
61ff944087
add tmp to survive restarts
2020-08-04 18:18:06 -04:00
Mike Reeves
a2e5dca065
Fix output pillar for minio
2020-08-04 18:02:54 -04:00
Mike Reeves
38d0f519ce
Fix output pillar for minio
2020-08-04 18:00:05 -04:00
Mike Reeves
9c5a969c2e
Fix minio init
2020-08-04 17:18:09 -04:00
Mike Reeves
fd039b3008
Fix top file for minio
2020-08-04 17:11:20 -04:00
Mike Reeves
c56ead08e9
add so minio docker
2020-08-04 16:28:50 -04:00
Mike Reeves
407160b729
Update changes.json
2020-08-04 16:23:03 -04:00
Mike Reeves
24ed92c9dc
minio and change to global
2020-08-04 15:54:03 -04:00
Mike Reeves
549bf7ba19
Activate minio
2020-08-04 10:17:43 -04:00
weslambert
e9af032c28
Merge pull request #1143 from Security-Onion-Solutions/feature/aws_mgr_defaults
...
Add AWS defaults file for manager
2020-08-04 10:13:07 -04:00
Wes Lambert
46f70c254c
Add AWS defaults file for manager
2020-08-04 14:11:50 +00:00
weslambert
f7425b14e3
Merge pull request #1142 from Security-Onion-Solutions/feature/aws_eval_defaults
...
AWS defaults modifications
2020-08-03 23:51:32 -04:00
Wes Lambert
2290c28a07
AWS defaults modifications
2020-08-04 03:49:59 +00:00
Mike Reeves
7c1120e47d
Fix grafana monitor interface.
2020-08-03 18:48:01 -04:00
Jason Ertel
d1641aa0d8
chown /var/ossec dir to match the needful user/group ownership for ossec-agentd
2020-08-03 15:49:21 -04:00
Josh Patterson
51934d6e5f
Merge pull request #1137 from Security-Onion-Solutions/issue/1091
...
iunstall saltstack 3001 during setup
2020-08-03 11:39:44 -04:00
m0duspwnens
fb887f7d9e
iunstall saltstack 3001 during setup
2020-08-03 10:47:24 -04:00
weslambert
12f53ce9d9
Merge pull request #1134 from Security-Onion-Solutions/fix/aws_auto_reboot
...
Reboot after finished with setup
2020-08-03 10:31:24 -04:00
weslambert
7e2917fc99
Reboot after finished with setup
2020-08-03 10:31:03 -04:00
Jason Ertel
f47128824e
Before finishing setup, rescan the log file and root mailbox for errors
2020-08-02 09:04:29 -04:00
weslambert
9255e77263
Merge pull request #1129 from Security-Onion-Solutions/feature/aws_standalone_defaults
...
Add AWS Standalone Defaults
2020-07-31 16:15:12 -04:00
Wes Lambert
ecafbc6014
Add AWS Standalone Defaults
2020-07-31 20:12:25 +00:00
Josh Brower
f99413c84d
Merge pull request #1128 from Security-Onion-Solutions/feature/launcher-update
...
Osquery & WLB Parsing Update for WEL & Sysmon
2020-07-31 16:07:41 -04:00
Josh Brower
4d66d37ac5
Merge branch 'dev' into feature/launcher-update
2020-07-31 16:07:33 -04:00
Josh Brower
d971d07720
Osquery & WLB Parsing Update for WEL & Sysmon
2020-07-31 16:06:15 -04:00
Josh Patterson
40272b2ed0
Merge pull request #1126 from Security-Onion-Solutions/issue/1091
...
Issue/1091
2020-07-31 13:53:28 -04:00
m0duspwnens
b3b67ff2a5
Merge remote-tracking branch 'remotes/origin/dev' into issue/1091
2020-07-31 13:50:11 -04:00
m0duspwnens
d16d2b6551
full path to salt bootstrap
2020-07-31 13:42:06 -04:00
m0duspwnens
e3581bb76e
change to salt-common
2020-07-31 13:36:21 -04:00
m0duspwnens
13c9fa3089
test minion upgrade at end
2020-07-31 13:32:12 -04:00
m0duspwnens
1e1d6a395d
cant get grains.filter_by to work for some reason
2020-07-31 13:25:37 -04:00
m0duspwnens
d7ad2fbfd7
move include
2020-07-31 13:17:56 -04:00
m0duspwnens
dd865f6a68
change map
2020-07-31 13:10:37 -04:00
m0duspwnens
173f945fc0
remove comma
2020-07-31 13:01:37 -04:00
m0duspwnens
d6f89cb09a
fix ubuntu salt-common package name
2020-07-31 12:37:19 -04:00
m0duspwnens
7287f5f935
wordsmithing
2020-07-30 17:01:17 -04:00
m0duspwnens
da9dc42a47
more logging
2020-07-30 16:47:40 -04:00
m0duspwnens
2ad17dfd06
dont append
2020-07-30 16:42:59 -04:00
m0duspwnens
8d044084e1
try to log soup
2020-07-30 16:41:21 -04:00
Josh Brower
ed8d443fe5
Merge pull request #1125 from Security-Onion-Solutions/feature/launcher-update
...
Fleet - Update osquery config for 4.4 windows_events
2020-07-30 16:35:42 -04:00
Josh Brower
4e01ef2795
Fleet - Update osquery config for 4.4 windows_events
2020-07-30 16:34:48 -04:00
m0duspwnens
de7f67ff2f
fix UPGRADECOMMAND
2020-07-30 16:31:37 -04:00
m0duspwnens
f209deac98
call detect_os function
2020-07-30 16:25:45 -04:00
m0duspwnens
914d890a51
fix UPGRADECOMMAND
2020-07-30 16:21:01 -04:00
m0duspwnens
8180f2cd93
remove quotes
2020-07-30 16:13:38 -04:00
m0duspwnens
cc48b55acf
change state name
2020-07-30 16:06:01 -04:00
m0duspwnens
1492d132ca
add ability to upgrade salt minion and master for ubuntu
2020-07-30 16:00:50 -04:00
m0duspwnens
a4fc2cbd42
caps
2020-07-30 13:50:22 -04:00
m0duspwnens
4bf4634762
ensure yum versionlock with a state rather than cmd.run state
2020-07-30 13:47:21 -04:00
m0duspwnens
6812d3f5c5
change output wording, add periods
2020-07-30 13:35:09 -04:00
m0duspwnens
a562d70fe2
stop salt minion first then salt master
2020-07-30 13:18:59 -04:00
m0duspwnens
8a8705f469
move when we check for salt minion update in setup
2020-07-30 12:41:09 -04:00
m0duspwnens
9570efbf8e
fix opt check
2020-07-30 12:15:09 -04:00
m0duspwnens
c099f3c5ec
change if for optargs
2020-07-30 11:49:34 -04:00
m0duspwnens
de0b34a66b
change if for optargs
2020-07-30 11:43:18 -04:00
m0duspwnens
1c5e6fa10f
change if for optargs
2020-07-30 11:39:58 -04:00
m0duspwnens
e9d889f719
fix regex
2020-07-30 11:33:19 -04:00
m0duspwnens
2222bce77b
update regex
2020-07-30 11:22:12 -04:00
m0duspwnens
728afdcaaf
exit soup if batch size invalid
2020-07-30 11:18:27 -04:00
m0duspwnens
3d4a96fae0
update ssl state unless , check and upgrade salt minion if needed during install
2020-07-30 11:16:37 -04:00
weslambert
00ba4ca6c0
Merge pull request #1121 from Security-Onion-Solutions/fix/thehive_static
...
Fix/thehive static
2020-07-30 10:27:43 -04:00
weslambert
4282930f08
Update cortex-application.conf
2020-07-30 10:26:49 -04:00
weslambert
c58ee8a37d
Add Cortex play secret
2020-07-30 10:25:53 -04:00
weslambert
b6a053070f
Change TheHive play secret
2020-07-30 10:25:07 -04:00
weslambert
2fab00458b
Add randomized play secrets for Cortex + TheHive
2020-07-30 10:23:00 -04:00
Mike Reeves
55053748df
Merge pull request #1119 from Security-Onion-Solutions/fix/2.0.3
...
2.0.3
2020-07-30 09:52:04 -04:00
m0duspwnens
14584b28e1
include salt state in salt.minion, manager salt-minion service in salt.minion state;
2020-07-29 16:04:47 -04:00
m0duspwnens
3e78c88114
update salt top to run salt.minion state if defined version not installed. only apply other states if proper version installed
2020-07-29 15:52:48 -04:00
Mike Reeves
1e15786430
Update VERIFY_ISO.md
2020-07-29 15:48:37 -04:00
Mike Reeves
c73d4aa690
Update sig file for 2.0.3
2020-07-29 15:40:02 -04:00
m0duspwnens
22b757f112
dont install new minion if already installed
2020-07-29 15:36:35 -04:00
m0duspwnens
03144446c8
revert branch to original code
2020-07-29 14:59:00 -04:00
m0duspwnens
5a814f8312
change condidtional statement
2020-07-29 14:41:58 -04:00
m0duspwnens
8c466f548b
update wording
2020-07-29 14:38:42 -04:00
m0duspwnens
171aa1178a
fix vars and if statement
2020-07-29 14:36:42 -04:00
m0duspwnens
8a44d4752b
fix var def
2020-07-29 14:26:57 -04:00
m0duspwnens
c949845218
only try to upgrade salt on grid if salt upgraded on manager
2020-07-29 14:20:17 -04:00
m0duspwnens
b8c0653818
soup upgrade salt on minions - add batch size option
2020-07-29 14:18:11 -04:00
weslambert
646bf1cb4d
Merge pull request #1118 from Security-Onion-Solutions/fix/wazuh_register_to
...
Fix/wazuh registration timeout
2020-07-29 13:53:45 -04:00
weslambert
c48ba8abaf
Re-arrange config
2020-07-29 13:52:12 -04:00
weslambert
9db390023b
Increase timeout from 10s to 30s
2020-07-29 13:51:46 -04:00
m0duspwnens
0de6e86cdb
dont run booststrap-salt if the proper version is installed
2020-07-29 13:39:55 -04:00
m0duspwnens
b9d0bd86ca
fbkeylink and fbcertlink owned by socore:socore
2020-07-29 13:27:06 -04:00
m0duspwnens
9b29dff04f
only generate p8 files if the key used for genetation changes
2020-07-29 11:40:45 -04:00
m0duspwnens
dca3855f81
remove always update if branch specified
2020-07-29 10:50:11 -04:00
m0duspwnens
b67e3507d3
always update and clean dockers
2020-07-29 10:13:30 -04:00
Mike Reeves
e3da326fcb
Remove non used pillar items
2020-07-29 09:27:18 -04:00
weslambert
4b36c4a809
Merge pull request #1115 from Security-Onion-Solutions/fix/remove_ls_syslog
...
Remove LS syslog port binding
2020-07-29 08:35:41 -04:00
weslambert
7d432091e2
Remove LS syslog port binding
2020-07-29 08:35:07 -04:00
Josh Brower
e7b9e001e1
mysql init.sls - change startup time from 2 min to 15min
...
Closes https://github.com/Security-Onion-Solutions/securityonion/issues/1106
2020-07-28 22:08:00 -04:00
m0duspwnens
f056a0a17b
use import_yaml
2020-07-28 17:09:53 -04:00
m0duspwnens
8905869db2
move salt pillars to defaults
2020-07-28 16:58:44 -04:00
m0duspwnens
bfae439c90
salt state distribute bootstrap script
2020-07-28 16:37:14 -04:00
Doug Burks
cf63e891b5
Update changes.json
2020-07-28 16:29:03 -04:00
m0duspwnens
4d5c8e5c2b
add salt minion state to install/upgrade salt-minion
2020-07-28 16:22:42 -04:00
Mike Reeves
b46b7ae1a0
Update changes.json
2020-07-28 16:19:16 -04:00
Mike Reeves
db89089291
Update README.md
2020-07-28 16:15:59 -04:00
Mike Reeves
1ff440b7b0
Update VERSION
2020-07-28 16:15:23 -04:00
Josh Brower
b1c09a9b72
Typo fix - ingest parser - win.eventlogs
2020-07-28 15:23:17 -04:00
m0duspwnens
c00b452f8d
change module.run for ca state
2020-07-28 15:10:16 -04:00
m0duspwnens
73830123b6
Merge remote-tracking branch 'remotes/origin/dev' into issue/1091
2020-07-28 14:32:07 -04:00
m0duspwnens
307945e260
dont state salt-minion service, allow salt state to start it during highstate
2020-07-28 13:51:28 -04:00
m0duspwnens
2067cc118f
remove broken logging
2020-07-28 13:25:43 -04:00
m0duspwnens
77acb8f348
change ot /opt/so/log
2020-07-28 13:20:01 -04:00
m0duspwnens
d8375cce14
touch soup log
2020-07-28 13:15:47 -04:00
m0duspwnens
73a1a05404
change back sed delimiters, last highstate log level to info
2020-07-28 13:11:38 -04:00
Josh Brower
fe76f1c87c
Merge pull request #1111 from Security-Onion-Solutions/feature/refactor-sysmon-parsing
...
initial refactor - beats/sysmon parsing
2020-07-28 11:04:13 -04:00
Josh Brower
55e60cb749
initial refactor - beats/sysmon parsing
2020-07-28 11:03:33 -04:00
m0duspwnens
fb453a0d9c
change sed delimiters in soup
2020-07-28 08:13:03 -04:00
m0duspwnens
254dcdb2f0
prevent dockers from redownloading if we are updating soup to a branch
2020-07-27 18:19:26 -04:00
m0duspwnens
f42a39ca69
allow soup to continue update if branch is specified
2020-07-27 18:08:27 -04:00
m0duspwnens
e811718ebc
change to salt 3001.1, fix dupe state name, add git branch option to soup
2020-07-27 17:53:02 -04:00
m0duspwnens
7606cc0ad0
changes to ssl state for salt 3001
2020-07-27 15:51:31 -04:00
weslambert
0f6ecdf38a
Merge pull request #1104 from Security-Onion-Solutions/feature/cortex_orguser
...
Create default orguser if empty
2020-07-27 09:50:23 -04:00
Wes Lambert
e81fd7464b
Create default orguser if empty
2020-07-27 13:49:17 +00:00
weslambert
ced51761fa
Merge pull request #1103 from Security-Onion-Solutions/feature/wazuh_version
...
Bump Wazuh version
2020-07-27 09:46:27 -04:00
Wes Lambert
ac5aeb4801
Bump Wazuh version
2020-07-27 13:45:34 +00:00
weslambert
88ffd0c17c
Merge pull request #1101 from Security-Onion-Solutions/feature/wazuh_symlinks
...
Add Wazuh Wazuh symlinks for config/rules
2020-07-27 08:15:58 -04:00
Wes Lambert
51e27cadc8
Add Wazuh Wazuh symlinks for cpnfig/rules
2020-07-27 12:14:43 +00:00
weslambert
2d2bebdd9c
Merge pull request #1100 from Security-Onion-Solutions/feature/wazuh_nsm
...
Move Wazuh from /opt/so/ to /nsm/wazuh
2020-07-27 07:59:39 -04:00
Wes Lambert
958ee25f6d
Move Wazuh from /opt/so/ to /nsm/wazuh
2020-07-27 11:58:12 +00:00
weslambert
2d096ddd66
Merge pull request #1096 from Security-Onion-Solutions/fix/elastalert_thehive
...
Make sure we are searching all clusters when running rules
2020-07-24 18:05:46 -04:00
Wes Lambert
3ac9f1800b
Make sure we are searching all clusters when running rules
2020-07-24 22:04:30 +00:00
m0duspwnens
78491e1fc5
soup update salt on manager for centos - https://github.com/Security-Onion-Solutions/securityonion/issues/1091
2020-07-24 15:06:06 -04:00
William Wernert
6c9c60b8dd
Merge branch 'master' into dev
...
# Conflicts:
# VERSION
2020-07-24 11:50:34 -04:00
Doug Burks
25f6ec861a
Merge pull request #1090 from Security-Onion-Solutions/fix/2.0.2
...
Fix/2.0.2
2020-07-24 11:47:19 -04:00
Mike Reeves
2cabcd4239
Update sig file and hashes
2020-07-24 10:19:38 -04:00
Mike Reeves
91e7a474d5
Update VERIFY_ISO.md
2020-07-24 10:18:09 -04:00
Mike Reeves
79c45156c2
Update changes.json
2020-07-23 22:13:02 -04:00
Mike Reeves
31daad1e5b
Update VERIFY_ISO.md
...
still needs MD5s etc
2020-07-23 22:11:22 -04:00
Mike Reeves
650c983a2e
Update README.md
2020-07-23 22:09:05 -04:00
Mike Reeves
95bb1147ca
Update VERSION
2020-07-23 22:08:23 -04:00
Jason Ertel
ec09c064d0
If SENSOR_CHECKIN_INTERVAL_MS is still not set when using in a template, fallback to 10s
2020-07-23 21:19:45 -04:00
Jason Ertel
39426afffd
Ensure SENSOR_CHECKIN_INTERVAL_MS var is non-null before saving static pillar
2020-07-23 21:00:10 -04:00
Jason Ertel
9eeb527ea7
Include UTC parameter when providing a hyperlink to Hunt from so-import-pcap output
2020-07-23 17:18:42 -04:00
Mike Reeves
bb6871a54a
Merge pull request #1087 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERIFY_ISO.md
2020-07-23 15:29:32 -04:00
Mike Reeves
261310ce92
Update VERIFY_ISO.md
2020-07-23 15:28:37 -04:00
Mike Reeves
5417b31a10
Merge pull request #1086 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERIFY_ISO.md
2020-07-23 15:27:27 -04:00
Mike Reeves
11932366cd
Update VERIFY_ISO.md
2020-07-23 15:25:53 -04:00
Doug Burks
2f73dcc6f6
Merge pull request #1085 from Security-Onion-Solutions/fix/2.0.1sig
...
Update Signature and hashes
2020-07-23 15:23:58 -04:00
Mike Reeves
acf20bf2e8
Update Signature and hashes
2020-07-23 15:20:22 -04:00
Mike Reeves
4d84b840e4
Update Signature and hashes
2020-07-23 15:16:39 -04:00
Mike Reeves
c112dfa098
Merge pull request #1074 from Security-Onion-Solutions/fix/2.0.1sig
...
Update Signature and Download Links
2020-07-23 13:36:30 -04:00
Mike Reeves
3dd8e1998d
Update Signature and Download Links
2020-07-23 13:33:12 -04:00
Mike Reeves
d66f424e5e
Merge pull request #1072 from Security-Onion-Solutions/fix/2.0.1-pcap-interval
...
Fix/2.0.1 Update Readme and changes.json
2020-07-23 12:12:13 -04:00
Mike Reeves
4b127010ee
Update changes.json
2020-07-23 11:59:20 -04:00
Mike Reeves
75477fe9bf
Update changes.json
2020-07-23 11:56:14 -04:00
Mike Reeves
30fa9872f9
Update README.md
2020-07-23 10:38:26 -04:00
Jason Ertel
1e993da31d
Merge master into dev to pull in 2.0.1-rc.1 patch
2020-07-23 09:56:42 -04:00
Mike Reeves
42390eb8a2
Merge pull request #1069 from Security-Onion-Solutions/fix/2.0.1-pcap-interval
...
Fix/2.0.1 pcap interval and security fixes
2020-07-23 09:53:56 -04:00
Mike Reeves
ff77abfdc8
Update soup
...
Remove strelka that isn't an image. Fix formatting
2020-07-23 09:51:52 -04:00
Mike Reeves
74faab92ab
Remove variables.txt
2020-07-23 09:21:05 -04:00
Mike Reeves
201efd285a
Fix passwords from conflicting with yaml
2020-07-22 16:34:50 -04:00
Mike Reeves
6d6ba04dcd
Fix version replace
2020-07-22 16:15:32 -04:00
Mike Reeves
b24c82d49c
Fix Docker List
2020-07-22 16:09:28 -04:00
Mike Reeves
b9e6ddf7df
Clean up static.sls passwords
2020-07-22 15:50:56 -04:00
Jason Ertel
46e7d29f12
Add support for custom branches in soup
2020-07-22 14:35:50 -04:00
Jason Ertel
cb46ca4832
Ensure distributed installations have the check-in interval correctly set
2020-07-22 14:26:55 -04:00
William Wernert
f3c24f1f01
[fix] Add check for $TESTING
2020-07-21 16:43:21 -04:00
William Wernert
c70bb9e58f
Merge pull request #1053 from Security-Onion-Solutions/feature/storage-calculation
...
Feature/storage calculation
2020-07-21 16:41:12 -04:00
William Wernert
752d1bceb4
[fix] Remove old storage space check
2020-07-21 16:36:37 -04:00
William Wernert
ddf0a5055e
[fix] Exit on NO
2020-07-21 16:34:08 -04:00
William Wernert
003271127a
[feat] Only check storage during setup on a network install
2020-07-21 16:32:28 -04:00
William Wernert
c531395452
Merge branch 'dev' into feature/storage-calculation
2020-07-21 16:24:28 -04:00
William Wernert
e43829b22c
[fix] Add then to if statement
2020-07-21 16:24:13 -04:00
William Wernert
d6f7dcb630
[refactor] Changes to storage requirements
...
See #1047
2020-07-21 15:35:13 -04:00
Jason Ertel
d2df405cf0
so-import-pcap improvements: Ensure PCAP filenames with spaces are handled properly; Provide link directly to the imported logs, filtered by import ID; Require sudo access to run so-import-pcap
2020-07-21 11:07:09 -04:00
Mike Reeves
abc68c2efb
Update VERIFY_ISO.md
2020-07-21 08:51:46 -04:00
Mike Reeves
f5665ad700
Merge pull request #1045 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERIFY_ISO.md
2020-07-21 08:49:53 -04:00
Mike Reeves
3141e2eca1
Update VERIFY_ISO.md
2020-07-21 08:46:38 -04:00
Jason Ertel
3281467994
When running in automated mode, cat all piped in input to setup log
2020-07-20 20:26:35 -04:00
Jason Ertel
e881f4c92b
Increment VERSION for dev to 2.1.0-rc.2; Add more logging to troubleshoot automated setup not initiating post-installation steps
2020-07-20 17:37:53 -04:00
Mike Reeves
6c49addbec
Merge pull request #1040 from Security-Onion-Solutions/dev
...
Update ISO Signature
2020-07-20 17:01:02 -04:00
Mike Reeves
a891fed1be
Create VERIFY_ISO.md
2020-07-20 16:58:32 -04:00
Mike Reeves
bbd1e9ba74
Create KEYS
2020-07-20 16:36:23 -04:00
Doug Burks
da3b055428
Update README.md
2020-07-20 16:33:39 -04:00
Doug Burks
a7fdd21284
Update README.md
2020-07-20 16:30:25 -04:00
Mike Reeves
1b02ad0d46
Upload ISO sig
2020-07-20 16:13:07 -04:00
Josh Brower
6d1ad3f2e0
Merge pull request #1038 from Security-Onion-Solutions/dev
...
Fix for telegraf
2020-07-20 14:38:12 -04:00
Josh Patterson
666464c7f2
Merge pull request #1037 from Security-Onion-Solutions/quickfix/grafana
...
ensure telegraf hostname is lowercase
2020-07-20 14:36:49 -04:00
m0duspwnens
fc14f4d8d8
ensure telegraf hostname is lowercase
2020-07-20 14:35:47 -04:00
Doug Burks
095e637dfa
Merge pull request #1036 from Security-Onion-Solutions/dev
...
2.0.0.rc.1
2020-07-20 14:35:16 -04:00
William Wernert
edcf834635
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
...
# Conflicts:
# salt/common/tools/sbin/so-elastic-clear
2020-07-20 14:23:23 -04:00
William Wernert
9be4756a90
[fix] Resolve merge commits
2020-07-20 14:22:55 -04:00
bryant-treacle
9ff3ffc401
Issue #885 : so-elastic-clear not removing so-* indices
2020-07-20 14:21:17 -04:00
Mike Reeves
a642ea0e98
Merge branch 'master' into dev
2020-07-20 13:27:44 -04:00
Mike Reeves
0b0543045b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-07-20 10:15:53 -04:00
Mike Reeves
9565050b82
Fix Features script
2020-07-20 10:15:47 -04:00
Jason Ertel
beda859207
Update changes.json sub-bullets to improve communication of the content
2020-07-20 08:47:39 -04:00
Jason Ertel
bd70fdbb33
Corrected JSON syntax to avoid a blank Overview screen in SOC; Applied HTML formatting of changes.json summaries for better markup handling.
2020-07-19 08:11:57 -04:00
Jason Ertel
053f27eb35
Run setterm, to blank terminal, only for non-automated installations
2020-07-19 06:58:28 -04:00
Mike Reeves
514df1211e
Soup Update
2020-07-18 23:34:45 -04:00
Mike Reeves
28a954db82
Soup Update
2020-07-18 23:24:22 -04:00
Mike Reeves
0302d2b6ac
Soup Update
2020-07-18 23:19:52 -04:00
Mike Reeves
74e6846e84
Soup Update
2020-07-18 23:19:14 -04:00
Mike Reeves
954c12acfb
Soup Update
2020-07-18 23:16:39 -04:00
Mike Reeves
872f849204
Soup Update
2020-07-18 23:12:53 -04:00
Mike Reeves
5bab5ae7d1
Soup Update
2020-07-18 23:10:37 -04:00
Mike Reeves
27568f0047
Soup Update
2020-07-18 23:09:18 -04:00
Mike Reeves
095a87dc46
Soup Update
2020-07-18 23:06:31 -04:00
Mike Reeves
847a9d76e0
Soup Update
2020-07-18 23:02:28 -04:00
Mike Reeves
fbc8a90083
Soup Update
2020-07-18 22:58:15 -04:00
Mike Reeves
7b1ca5f361
Fix common tools permissions
2020-07-18 22:50:08 -04:00
Mike Reeves
1bcbcb1f98
Fix idstools jinja
2020-07-18 22:46:57 -04:00
Mike Reeves
517edf1938
Update Release Notes
2020-07-18 17:55:35 -04:00
Mike Reeves
64bd70bb48
Update Release Notes
2020-07-18 17:50:25 -04:00
Mike Reeves
f4c23fcc2e
Merge pull request #1033 from Security-Onion-Solutions/fix/idstools
...
Fix/idstools
2020-07-18 17:33:54 -04:00
Mike Reeves
16906b8361
Merge branch 'dev' into fix/idstools
2020-07-18 17:32:54 -04:00
Mike Reeves
3de2afe618
Fix final bugs
2020-07-18 17:29:11 -04:00
Jason Ertel
23420ace56
Prevent nmcli, setterm, and echo output from leaking to console and crontab output
2020-07-18 08:38:09 -04:00
Mike Reeves
1d24d7bc7f
Misc pillars
2020-07-17 17:38:10 -04:00
Mike Reeves
b75487dc74
Update so-functions
2020-07-17 17:36:13 -04:00
Mike Reeves
aaca5c7ff2
Update rulecat.conf
2020-07-17 17:35:16 -04:00
Mike Reeves
2e2bcfb3b7
Fix functions so pillars are correct
2020-07-17 17:33:36 -04:00
Mike Reeves
e78a14e2c7
Merge pull request #1032 from Security-Onion-Solutions/fix/idstools
...
IDSTOOLS Pillar Items
2020-07-17 16:00:59 -04:00
Mike Reeves
693a101d34
IDSTOOLS Pillar Items
2020-07-17 15:59:58 -04:00
William Wernert
3c855ed793
[fix] Set $percentage since it only exists in previous subshell
2020-07-17 15:38:14 -04:00
Mike Reeves
d3529686cc
Merge pull request #1031 from Security-Onion-Solutions/quickfix/bro2zeeklogs
...
change reference from bro to zeek
2020-07-17 14:53:47 -04:00
m0duspwnens
7176fdf7a1
rename from bro to zeek
2020-07-17 14:53:01 -04:00
m0duspwnens
e3efaee864
change reference from bro to zeek
2020-07-17 14:41:44 -04:00
Mike Reeves
74f6f2abee
Update soup
2020-07-17 13:38:55 -04:00
Josh Patterson
0d737b8f41
Merge pull request #1030 from Security-Onion-Solutions/quickfix/schedulesetup
...
remove quotes
2020-07-17 13:30:43 -04:00
William Wernert
5570c778ad
[feat] Add hostname formatting check for manager hostname
2020-07-17 13:30:08 -04:00
m0duspwnens
6ba342c084
remove quotes
2020-07-17 13:30:05 -04:00
William Wernert
1309e0c7ad
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-17 13:09:21 -04:00
William Wernert
446817353d
[refactor] | tee ... >> to > ... 2>> to show errors in log
2020-07-17 13:09:18 -04:00
Josh Brower
3c6ae08d4d
Merge pull request #1029 from Security-Onion-Solutions/bugfix/fleet-eval
...
Kibana Fleet Pivot Fix
2020-07-17 13:01:08 -04:00
Josh Brower
da155b5dea
Kibana Fleet Pivot Fix
2020-07-17 13:00:03 -04:00
William Wernert
1abf324654
[fix] Set py_ver_url_path for all install types
2020-07-17 12:59:17 -04:00
William Wernert
d88e15ecb4
[fix] Use | tee instead of redirect when already redirecting to setup log
2020-07-17 12:33:25 -04:00
William Wernert
9cbc7ad8f5
[fix] guage -> gauge
2020-07-17 12:08:16 -04:00
William Wernert
1bd154760d
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-17 11:09:11 -04:00
William Wernert
ede250d9e4
[feat] Merge access method dialogs together
2020-07-17 11:09:08 -04:00
William Wernert
d97271cca3
[fix] Don't drop to shell while running so-allow
2020-07-17 11:08:31 -04:00
Mike Reeves
17e3bde2f8
Create home dir for adduser function
2020-07-17 10:55:30 -04:00
Josh Brower
083e43b26b
Merge pull request #1028 from Security-Onion-Solutions/bugfix/fleet-eval
...
Eval Ubuntu Fleet fix
2020-07-17 10:27:51 -04:00
Josh Brower
6e4eb76393
Eval Ubuntu Fleet fix
2020-07-17 10:25:48 -04:00
Josh Patterson
5633eed6a4
Merge pull request #1027 from Security-Onion-Solutions/quickfix/schedulesetup
...
dont try to copy schedules if the directory is empty
2020-07-17 10:24:50 -04:00
m0duspwnens
2541f4d8e8
dont try to copy schedules if the directory is empty
2020-07-17 10:23:51 -04:00
Josh Patterson
e6b795e8b3
Merge pull request #1026 from Security-Onion-Solutions/quickfix/schedulesetup
...
dont try to copy schedules if the directory is empty
2020-07-17 10:07:17 -04:00
m0duspwnens
6f077e66e6
dont try to copy schedules if the directory is empty
2020-07-17 10:05:54 -04:00
weslambert
2341d9592e
Merge pull request #1025 from Security-Onion-Solutions/fix/wazuh_cleanup
...
Change verbiage
2020-07-17 09:39:21 -04:00
weslambert
e91aa751a7
Change verbiage
2020-07-17 09:38:43 -04:00
William Wernert
958d614bef
[fix] Only show motd ip message on manager node
2020-07-17 09:21:47 -04:00
Josh Brower
442e870c16
Merge pull request #1024 from Security-Onion-Solutions/bugfix/kibana-dashboard-updates
...
Kibana dashboard updates
2020-07-17 08:15:33 -04:00
Josh Brower
32a6f825c2
Kibana dashboard updates
2020-07-17 08:14:37 -04:00
Josh Patterson
06c4924b70
Merge pull request #1023 from Security-Onion-Solutions/quickfix/yum
...
change from manager to master for salt config.get
2020-07-16 21:06:35 -04:00
m0duspwnens
cc77a50d8d
change from manager to master for salt config.get
2020-07-16 21:05:44 -04:00
Mike Reeves
2d68d5419b
fix adtotab perms
2020-07-16 19:47:15 -04:00
Mike Reeves
258d9d3bfc
change salt perms
2020-07-16 17:07:04 -04:00
Mike Reeves
03ff592aa4
Merge pull request #1022 from Security-Onion-Solutions/fix/telegrafperms
...
Fix salt refresh script
2020-07-16 16:38:40 -04:00
Mike Reeves
21f09a9cd5
Fix salt refresh script
2020-07-16 16:37:48 -04:00
Josh Brower
4fd1daeca1
Merge pull request #1021 from Security-Onion-Solutions/bugfix/fleet-packages-urlbase
...
Osquery packages hostname fix
2020-07-16 16:36:30 -04:00
Josh Brower
51beb52bb8
Osquery packages hostname fix
2020-07-16 16:35:51 -04:00
Mike Reeves
20446ed3aa
Merge pull request #1020 from Security-Onion-Solutions/fix/telegrafperms
...
Fix/telegrafperms
2020-07-16 16:34:04 -04:00
Mike Reeves
d31ce4aa48
Fix soup issues
2020-07-16 16:32:38 -04:00
Mike Reeves
07626905c5
Fix telegraf script perms
2020-07-16 15:20:11 -04:00
Josh Patterson
5634446fcb
Merge pull request #1019 from Security-Onion-Solutions/quickfix/lstoes
...
fix the container watch for logstash container state
2020-07-16 15:06:29 -04:00
m0duspwnens
c61a52cc5e
fix the container watch for logstash container state
2020-07-16 15:05:54 -04:00
William Wernert
25dbcfaebe
[refactor] Add check for "Result: False" in setup
2020-07-16 14:08:56 -04:00
Josh Patterson
f1d8548913
Merge pull request #1017 from Security-Onion-Solutions/quickfix/lstoes
...
dont run templates script if there arent templates
2020-07-16 13:37:15 -04:00
m0duspwnens
9606d86e84
dont run templates script if there arent templates
2020-07-16 13:36:44 -04:00
William Wernert
8f62cd8f82
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-16 11:33:20 -04:00
William Wernert
a041be5c21
[fix] Don't force YARA Strelka rules during setup
2020-07-16 11:33:11 -04:00
phil1090
5d2c6d330f
Update README.md
2020-07-16 10:15:40 -04:00
Josh Patterson
582edd7aac
Merge pull request #1016 from Security-Onion-Solutions/quickfix/lstoes
...
including elasticsearch in logstash state
2020-07-16 10:13:18 -04:00
m0duspwnens
f10f47ad4e
including elasticsearch in logstash state
2020-07-16 10:12:10 -04:00
weslambert
f8bb094546
Merge pull request #1014 from Security-Onion-Solutions/fix/strelka_standalone
...
Fix module eval
2020-07-16 09:32:06 -04:00
Wes Lambert
8275f458a1
Fix module eval
2020-07-16 13:30:38 +00:00
William Wernert
5190e5d434
Update README.md
2020-07-16 09:20:20 -04:00
weslambert
7fecfdab32
Update README.md
2020-07-16 08:14:47 -04:00
weslambert
f7d527bb90
Update README.md
2020-07-16 08:14:23 -04:00
Josh Brower
350d2fbeda
Update README.md
2020-07-15 19:07:25 -04:00
Josh Brower
29c28fcb5e
Update README.md
2020-07-15 19:06:36 -04:00
Josh Brower
48c9244a81
Update README.md
2020-07-15 19:05:49 -04:00
Mike Reeves
a4672dedee
Update README.md
2020-07-15 18:17:05 -04:00
Mike Reeves
473606371a
Fix Features Download
2020-07-15 17:49:13 -04:00
Mike Reeves
d71dc89b13
New SOUP
2020-07-15 17:46:33 -04:00
Jason Ertel
9781d8d0e7
Ensure permissions are consistently applied to all imported PCAP files
2020-07-15 13:53:28 -04:00
Jason Ertel
0a976861f3
Dynamically set sensor checkin interval; allow overrides if var is preset
2020-07-15 13:22:14 -04:00
Josh Brower
80e081e828
Merge pull request #1010 from Security-Onion-Solutions/bugfix/playbook-anonymous-perms
...
Playbook anonymous perms fix
2020-07-15 12:40:47 -04:00
Josh Brower
d11ef08961
Playbook anonymous perms fix
2020-07-15 12:37:04 -04:00
Jason Ertel
3c42f50e99
Ensure whiptail success/summary screen is final step before reboot
2020-07-15 11:12:48 -04:00
Josh Patterson
83428d4785
Merge pull request #1009 from Security-Onion-Solutions/quickfix/lstoes
...
load templates for es for eval
2020-07-15 08:32:50 -04:00
m0duspwnens
e4fff05dbc
load templates for es for eval
2020-07-15 08:30:43 -04:00
Jason Ertel
9dc1151347
Imported logs are sent to so-import index on eval installations
2020-07-14 22:59:42 -04:00
Jason Ertel
b53ce392ef
Improve grammer of summary screen in whiptail
2020-07-14 22:45:38 -04:00
Jason Ertel
c0960e58e8
Improve grammer of so-allow input prompt
2020-07-14 19:42:53 -04:00
Josh Patterson
549916306c
Merge pull request #1008 from Security-Onion-Solutions/quickfix/lstoes
...
Quickfix/lstoes
2020-07-14 17:37:19 -04:00
m0duspwnens
5cf71596b2
add curlys
2020-07-14 17:36:52 -04:00
Jason Ertel
acb800d1c9
Using static UID for Grafana overview dashboard to allow SOC to directly link to those dashboards
2020-07-14 17:36:30 -04:00
Jason Ertel
9bbbaa485c
Switch PM to AM since we want to span midnight to midnight
2020-07-14 17:36:30 -04:00
m0duspwnens
acaec6c125
remove recurse causing issues
2020-07-14 17:12:29 -04:00
Josh Brower
e7e1982862
Merge pull request #1007 from Security-Onion-Solutions/bugfix/ingest-parsing
...
Parsing & Hunt query updates
2020-07-14 17:00:04 -04:00
Josh Brower
8647944ae6
Parsing & Hunt query updates
2020-07-14 16:59:06 -04:00
Mike Reeves
55056f3193
Merge pull request #1006 from Security-Onion-Solutions/fix/perms
...
Change opt/so perms
2020-07-14 16:19:02 -04:00
m0duspwnens
57bf23d83c
move templates from logstash to elasticsearch
2020-07-14 16:07:46 -04:00
Doug Burks
a1e6a85a68
explicitly set Suricata timestamp timezone to UTC
2020-07-14 15:49:46 -04:00
weslambert
7a36803e2c
Merge pull request #1002 from Security-Onion-Solutions/fix/strelka_observer
...
Add observer name for Strelka events
2020-07-14 13:39:52 -04:00
Wes Lambert
f9df39977b
Add observer name for Strelka events
2020-07-14 17:38:43 +00:00
weslambert
7ed902c0ae
Merge pull request #1001 from Security-Onion-Solutions/fix/suricata_timestamp
...
Convert message timestamp to @timestamp
2020-07-14 13:34:58 -04:00
Josh Brower
47388fa98d
Merge pull request #998 from Security-Onion-Solutions/bugfix/fleet-soimage-fix
...
Fleet reactor fix
2020-07-14 13:06:52 -04:00
Josh Brower
ba8395fc11
Fleet reactor fix
2020-07-14 13:04:29 -04:00
William Wernert
3df5904269
Merge pull request #979 from Security-Onion-Solutions/feature/setup
...
Feature/setup
2020-07-14 11:17:03 -04:00
William Wernert
caf9e3f75a
[fix] Redirect hive_init output to log
2020-07-14 11:13:50 -04:00
William Wernert
ad3c4c4950
[fix] master -> manager
2020-07-14 11:09:12 -04:00
Mike Reeves
57cd2cdbeb
Change opt/so perms
2020-07-14 10:37:49 -04:00
William Wernert
4ab90a9a30
[fix] Move redirect var to function after $MAINIP has been set
2020-07-14 10:12:51 -04:00
Mike Reeves
f2d9abf1a5
Merge pull request #996 from Security-Onion-Solutions/fix/curator
...
Add all actions to cron
2020-07-14 10:05:27 -04:00
Mike Reeves
e404a41d8a
Add all actions to cron
2020-07-14 10:04:15 -04:00
Mike Reeves
15be31af6d
Merge pull request #995 from Security-Onion-Solutions/fix/curator
...
Fix spelling error in actions
2020-07-14 09:43:41 -04:00
Jason Ertel
67f2edce28
Resolve merge conflict that reverted import URL back to Kibana
2020-07-14 09:40:16 -04:00
Mike Reeves
d4e6189f6e
Fix spelling error in actions
2020-07-14 09:39:56 -04:00
Wes Lambert
d6afde90b0
Convert message timestamp to @timestamp
2020-07-14 13:37:00 +00:00
Josh Brower
0c9c66f6e1
Merge pull request #993 from Security-Onion-Solutions/bugfix/playbook-init
...
Bugfix/playbook init
2020-07-14 09:14:56 -04:00
Josh Brower
2c72940010
Playbook db init fix
2020-07-14 09:09:55 -04:00
Josh Brower
b884e09e7a
Playbook db init fix
2020-07-14 09:09:47 -04:00
William Wernert
178ac79da8
[refactor] Set $REDIRECTIT outside of subshell
2020-07-14 09:05:09 -04:00
Jason Ertel
09c460dbe9
Switch to final image repository prefix 'securityonion' for RC1
2020-07-14 00:45:20 -04:00
Jason Ertel
d75d64c8ed
Mount imported pcap dirs into sensoroni container for imported PCAP pivots
2020-07-13 21:03:47 -04:00
Jason Ertel
8f66a27f07
Refactor image repository to a single variable
2020-07-13 18:26:43 -04:00
Jason Ertel
f67f0679ae
Add new so-pcaptools image to docker list for network install
2020-07-13 16:02:22 -04:00
William Wernert
aa4d435020
[fix] Don't run so-allow before setup complete menu
2020-07-13 15:21:05 -04:00
William Wernert
81c8185cb5
[refactor] Delete check for network install since we check /nsm now
2020-07-13 14:53:47 -04:00
William Wernert
1cf0732991
Merge branch 'dev' into feature/setup
...
# Conflicts:
# setup/so-setup
2020-07-13 14:35:24 -04:00
William Wernert
00f178197c
[fix] Evaluate $success early to avoid checking against other output
2020-07-13 14:34:11 -04:00
Mike Reeves
98811c147d
Merge pull request #989 from Security-Onion-Solutions/feature/isosetup
...
Fix username so install works properly from ISO
2020-07-13 14:27:20 -04:00
Mike Reeves
55869c4f81
Fix username so install works properly from ISO
2020-07-13 14:25:10 -04:00
William Wernert
c585713122
[style] Change SO_ERROR check to non-empty check
2020-07-13 13:28:54 -04:00
Josh Patterson
8dc63a1f52
Merge pull request #987 from Security-Onion-Solutions/quickfix/patchschedule
...
Quickfix/patchschedule
2020-07-13 11:35:00 -04:00
m0duspwnens
59c00057b1
fix patch pillar, select patch hours on 1 screen
2020-07-13 11:34:30 -04:00
m0duspwnens
ef3c5d1fe0
fix patch pillar, select patch hours on 1 screen
2020-07-13 11:31:37 -04:00
William Wernert
06aa63dd14
Merge branch 'dev' into feature/setup
2020-07-13 11:24:04 -04:00
Mike Reeves
3bc492ebde
Merge pull request #986 from Security-Onion-Solutions/feature/isosetup
...
Removes create admin user from setup
2020-07-13 11:13:10 -04:00
Mike Reeves
dc0aa270d9
Fix ISO rsync
2020-07-13 11:12:11 -04:00
Mike Reeves
14faa3b898
Clean up bash profile
2020-07-13 11:08:04 -04:00
Mike Reeves
a6cceef986
Removes create admin user from setup
2020-07-13 10:55:55 -04:00
Josh Patterson
db80675609
Merge pull request #985 from Security-Onion-Solutions/quickfix/elasticpillar
...
prevent elasticsearch pillar being added twice for managers and helix
2020-07-13 09:48:44 -04:00
m0duspwnens
242e17b329
prevent elasticsearch pillar being added twice for managers and helix
2020-07-13 09:45:11 -04:00
William Wernert
c31c24ccd8
[fix] Check /nsm instead of / for free space
2020-07-13 09:12:24 -04:00
Josh Brower
e62381e998
Merge pull request #982 from Security-Onion-Solutions/bugfix/alerting
...
Misc fixes
2020-07-10 19:50:27 -04:00
Josh Brower
65062d93f4
Misc fixes
2020-07-10 19:43:43 -04:00
William Wernert
99dc16d644
Merge pull request #981 from Security-Onion-Solutions/bugfix/disk-space-network-only
...
[fix] Only check for disk space on a network install
2020-07-10 18:52:48 -04:00
William Wernert
605daaf66b
[fix] Only check for disk space on a network install
2020-07-10 18:45:34 -04:00
William Wernert
056b3a0629
Merge branch 'dev' into feature/setup
...
# Conflicts:
# setup/so-setup
2020-07-10 18:41:24 -04:00
William Wernert
f9c8f8cdca
[fix] Set SKIP_REBOOT on any failure during setup
2020-07-10 18:40:39 -04:00
William Wernert
aee304e5d5
[fix] master -> manager
2020-07-10 18:13:20 -04:00
William Wernert
4cfecae3b2
[ix] Remove grafanapassword pillar key
2020-07-10 17:59:51 -04:00
William Wernert
ce7373501b
[fix] Add fallback for hive + cortex users
2020-07-10 17:58:47 -04:00
William Wernert
571e97cdf7
Merge branch 'dev' into feature/setup
...
# Conflicts:
# salt/thehive/scripts/cortex_init
# salt/thehive/scripts/hive_init
# setup/so-functions
# setup/so-whiptail
2020-07-10 17:42:56 -04:00
William Wernert
547298fce0
[refactor] Hide output for cortex and thehive init scripts
2020-07-10 17:34:33 -04:00
weslambert
ef64048fc6
Merge pull request #978 from Security-Onion-Solutions/fix/sensor-clean
...
Fix value
2020-07-10 17:17:57 -04:00
weslambert
eb2dc0be4c
Fix value
2020-07-10 17:17:33 -04:00
Josh Patterson
69023cdb31
Merge pull request #976 from Security-Onion-Solutions/issue/404
...
Issue/404
2020-07-10 16:28:28 -04:00
m0duspwnens
13af4cacb0
merge with dev and resolve conflicts
2020-07-10 16:27:10 -04:00
Mike Reeves
755f47da2d
Merge pull request #975 from Security-Onion-Solutions/fix/lstemplate
...
Fix/lstemplate
2020-07-10 15:55:50 -04:00
Mike Reeves
46d572fa8c
Fix Filebeat spacing
2020-07-10 15:51:12 -04:00
weslambert
9b079df9f5
Merge pull request #974 from Security-Onion-Solutions/fix/sensor_clean
...
Fix/sensor clean
2020-07-10 15:35:57 -04:00
Wes Lambert
d7f7fb801c
Set role
2020-07-10 19:35:27 +00:00
Wes Lambert
37ab252e01
Add sensor proc eval
2020-07-10 19:30:08 +00:00
William Wernert
f56811e745
[feat] Use setup user+pass for TheHive, Cortex, and Fleet as well
2020-07-10 14:40:04 -04:00
William Wernert
67c8836cd6
[fix] Use 100GB min space for standalone also
2020-07-10 14:39:02 -04:00
William Wernert
72aa91b763
[feat] Add message in setup and motd on where to access SOC
2020-07-10 14:38:21 -04:00
m0duspwnens
9730c4561d
add elasticsearch pillar to manager
2020-07-10 14:08:39 -04:00
Jason Ertel
358ef78cd9
Do not stop curator since imported data will now be placed into a longer term so-import index
2020-07-10 13:58:52 -04:00
Jason Ertel
811bbb4cb0
Require sudo to run an import
2020-07-10 13:58:52 -04:00
weslambert
33375a0809
Merge pull request #973 from Security-Onion-Solutions/fix/curator_logsizelimit
...
Move zeek_clean to so-sensor-clean
2020-07-10 13:57:58 -04:00
Wes Lambert
6e99ca600f
Move zeek_clean to so-sensor-clean
2020-07-10 17:56:40 +00:00
Mike Reeves
5eb33d5ac7
Logstash Import and Template Assignment
2020-07-10 13:53:55 -04:00
m0duspwnens
24b8f81e38
merge with dev and resolve conflicts
2020-07-10 12:20:14 -04:00
Mike Reeves
bbef7955b2
Update eval.sls
2020-07-10 11:36:46 -04:00
Mike Reeves
9da4dd0ac9
Merge pull request #971 from Security-Onion-Solutions/feature/espillarz
...
Feature/espillarz
2020-07-10 11:35:24 -04:00
Mike Reeves
c656bec9c0
Merge branch 'dev' into feature/espillarz
2020-07-10 11:35:12 -04:00
m0duspwnens
0a1b5f29eb
merge with dev and resolv conflicts
2020-07-10 10:48:49 -04:00
m0duspwnens
1f48dc765e
merge with dev and resolv conflicts
2020-07-10 10:36:48 -04:00
Mike Reeves
3706aa76d8
Add jinja extension
2020-07-10 10:35:31 -04:00
Doug Burks
2ce254dfb0
add new DPD query to Hunt
2020-07-10 06:00:36 -04:00
Doug Burks
f5114c034d
change Log Type query in Hunt to include event.dataset in the groupby
2020-07-10 05:52:10 -04:00
Mike Reeves
1a6c4c12b4
Fix elasticsearch yaml
2020-07-09 21:56:32 -04:00
Jason Ertel
6bfd777d25
Enabled elastalert log
2020-07-09 21:34:35 -04:00
Mike Reeves
8ef18f9044
Fiz pillar
2020-07-09 18:51:59 -04:00
m0duspwnens
b2e7a4221c
master to manager for ssl signing policy
2020-07-09 17:19:17 -04:00
Mike Reeves
9a7035326d
Update Logstash pillar
2020-07-09 17:09:20 -04:00
m0duspwnens
9c2dcd2318
fix reference to master grain
2020-07-09 17:06:44 -04:00
Mike Reeves
ad6c9e7fe9
recurse actions for curator
2020-07-09 16:58:35 -04:00
Mike Reeves
6094d19b0b
Make hot default
2020-07-09 16:54:31 -04:00
Mike Reeves
3c6465bb7f
ES Jinja the config
2020-07-09 16:42:39 -04:00
Jason Ertel
33179141a1
Enable PCAP pivots from imports
2020-07-09 16:11:38 -04:00
m0duspwnens
5ca3ecf4bd
fix reference to master grain
2020-07-09 15:42:39 -04:00
Josh Brower
7b91704894
Merge pull request #970 from Security-Onion-Solutions/defensivedepth-patch-2-host-pillar
...
Update so-setup
2020-07-09 15:32:38 -04:00
Josh Brower
58d290aa57
Update so-setup
2020-07-09 15:32:19 -04:00
William Wernert
c5eff1d89e
[feat][WIP] Add option to run so-allow -a <ip/cidr> during setup
2020-07-09 14:47:55 -04:00
Josh Brower
206bdc60f3
Merge pull request #967 from Security-Onion-Solutions/feature/low-level-alerts
...
Feature - low level alerts
2020-07-09 13:56:31 -04:00
m0duspwnens
bdd0f64462
add period
2020-07-09 13:54:48 -04:00
Josh Brower
52f7111e1d
Feature - low level alerts
2020-07-09 13:53:55 -04:00
m0duspwnens
aea3099df6
change wording
2020-07-09 13:52:31 -04:00
m0duspwnens
823ee42120
https://github.com/Security-Onion-Solutions/securityonion/issues/404
2020-07-09 13:45:24 -04:00
Mike Reeves
7c6677916a
Curator actions
2020-07-09 12:56:29 -04:00
Mike Reeves
357efac873
Add index specific curator settings
2020-07-09 12:10:53 -04:00
Mike Reeves
ca20279a09
Add curator to static pillar
2020-07-09 12:00:07 -04:00
Mike Reeves
96bcf9d9f3
Add temaplte files per index
2020-07-09 11:51:55 -04:00
m0duspwnens
3cf31e2460
https://github.com/Security-Onion-Solutions/securityonion/issues/404
2020-07-09 11:27:06 -04:00
Mike Reeves
9c2f7d574d
Add ES settings to pillar
2020-07-09 11:19:02 -04:00
Mike Reeves
2c32c24bf0
Fix logstash logic
2020-07-09 09:16:48 -04:00
Josh Patterson
2bfdb09674
Merge pull request #966 from Security-Onion-Solutions/issue/959
...
fix typo
2020-07-09 08:52:30 -04:00
m0duspwnens
d539f1ddf8
fix typo
2020-07-09 08:51:53 -04:00
Doug Burks
8dfafffef0
remove duplicate line for message2.conn_uids
2020-07-09 06:44:08 -04:00
weslambert
818f7f56b2
Merge pull request #965 from Security-Onion-Solutions/feature/add_gcp_check
...
Add GCP and make cloud check more generic
2020-07-08 23:31:37 -04:00
weslambert
c01047fad2
Add /dev/null
2020-07-08 23:30:50 -04:00
weslambert
889ba67d85
Move EC2 to more generic cloud verbiage
2020-07-08 23:27:46 -04:00
weslambert
ce00d829e1
Move EC2 to more generic cloud verbiage and check for GCP
2020-07-08 23:26:48 -04:00
weslambert
67fb46f519
Merge pull request #963 from Security-Onion-Solutions/fix/curator_logsizelimit
...
Add standalone evaluation for log_size_limit
2020-07-08 15:40:54 -04:00
Josh Patterson
99ce77e9bd
Merge pull request #962 from Security-Onion-Solutions/issue/959
...
pillarize yum.conf installonly_limit and proxy
2020-07-08 15:39:22 -04:00
Wes Lambert
f2cea273b6
Add standalone evaluation for log_size_limit
2020-07-08 19:39:14 +00:00
m0duspwnens
59061926f0
pillarize yum.conf installonly_limit and proxy
2020-07-08 15:37:20 -04:00
weslambert
beda67d2a9
Merge pull request #955 from Security-Onion-Solutions/fix/strelka_message_drop
...
Drop message field and original exiftool keys
2020-07-08 10:56:06 -04:00
weslambert
4cf31e1ee7
Drop message field and original exiftool keys
2020-07-08 10:55:40 -04:00
Doug Burks
fef803a86c
Add ignore_failure to geoip processor calls #942
2020-07-08 10:41:14 -04:00
Josh Patterson
3352eb77e9
Merge pull request #954 from Security-Onion-Solutions/issue/825
...
add pillar example for filebeat inputs/output
2020-07-08 09:53:18 -04:00
m0duspwnens
5f68542241
add pillar example for filebeat inputs/output
2020-07-08 09:52:25 -04:00
weslambert
9c11de5455
Merge pull request #953 from Security-Onion-Solutions/fix/zeek_files_uid
...
Rename uids to uid
2020-07-08 09:40:04 -04:00
weslambert
b25a3b6986
Rename uids to uid
2020-07-08 09:39:37 -04:00
weslambert
88b7a31195
Merge pull request #952 from Security-Onion-Solutions/fix/wazuh_authdport
...
Add Wazuh Authd Port
2020-07-08 09:26:28 -04:00
weslambert
987acaeb7b
Add Wazuh Authd Port
2020-07-08 09:26:04 -04:00
Josh Brower
10cbc96f48
Merge pull request #948 from Security-Onion-Solutions/fix/fleet
...
Fleet setup bugfix
2020-07-07 20:56:43 -04:00
Josh Brower
b4b122dbd9
Fleet setup bugfix
2020-07-07 20:55:47 -04:00
William Wernert
4231fb1d1a
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-07 17:38:30 -04:00
William Wernert
72a98b33a7
[fix] Change test to check value of $SO_ERROR
2020-07-07 17:38:23 -04:00
Mike Reeves
cdce804c9f
Update 9700_output_strelka.conf.jinja
2020-07-07 17:36:49 -04:00
weslambert
2992938596
Merge pull request #947 from Security-Onion-Solutions/fix/strelka_exiftool
...
Add fields for exiftool keys
2020-07-07 17:13:57 -04:00
Mike Reeves
fc377cd3c1
Merge pull request #945 from Security-Onion-Solutions/issue/929
...
SSL Lockdown
2020-07-07 16:31:33 -04:00
Mike Reeves
1954a389b0
Update so-functions
2020-07-07 16:12:07 -04:00
Mike Reeves
9576151993
Merge pull request #944 from Security-Onion-Solutions/issue/937
...
Issue/937
2020-07-07 16:07:47 -04:00
Wes Lambert
3b50ce032a
Add fields for exiftool keys
2020-07-07 20:02:09 +00:00
Josh Patterson
07cc89e4d6
Merge pull request #943 from Security-Onion-Solutions/issue/825
...
Pillarize filebeat inputs and output
2020-07-07 15:51:08 -04:00
m0duspwnens
fff713db85
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/825
2020-07-07 15:48:47 -04:00
Mike Reeves
eccfaf94fb
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/937
2020-07-07 15:10:12 -04:00
Jason Ertel
f4f189cc50
correct capitalization of true
2020-07-07 14:28:11 -04:00
William Wernert
640cfee3e1
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-07-07 13:13:28 -04:00
William Wernert
3815f7e58e
[refactor] Edit logic around setup failure/completion
...
* Always run `install_cleanup` and `so-allow`
* Change if statement to check whether `$success != 0` or if `$SO_ERROR` was set
* Set `$IP` only for `so-allow` instead of exporting it
2020-07-07 13:12:46 -04:00
William Wernert
1d47cec928
[refactor] Move install_cleanup outside of whiptail functions
2020-07-07 13:02:58 -04:00
William Wernert
0b995533ea
[refactor] Only notify user of error found during setup
2020-07-07 13:01:29 -04:00
Mike Reeves
ec89ab39ac
Update 9999_output_redis.conf.jinja
2020-07-07 11:56:45 -04:00
weslambert
34e06ecde1
Merge pull request #940 from Security-Onion-Solutions/feature/strelka_fuid
...
Add Zeek FUID for Strelka records
2020-07-07 11:01:09 -04:00
Wes Lambert
e0570e1db7
Add Zeek FUID for Strelka records
2020-07-07 15:00:01 +00:00
Mike Reeves
c59096d9bd
rename node pillar to elasticsearch
2020-07-07 10:42:12 -04:00
Jason Ertel
62cc02301e
Do not attempt to install a plugin or bc command if already exists
2020-07-07 10:28:15 -04:00
weslambert
d334d5ab83
Merge pull request #938 from Security-Onion-Solutions/fix/strelka_filebeat
...
Fix pillar reference for Strelka/FB
2020-07-07 09:48:19 -04:00
Wes Lambert
2fdd5fd77b
Fix pillar reference for Strelka/FB
2020-07-07 13:46:57 +00:00
William Wernert
e2c9184b29
[fix][refactor] Don't use relative path in so-setup-network
2020-07-07 08:45:28 -04:00
Mike Reeves
291ac3c597
Fix SSL Perms
2020-07-06 17:24:04 -04:00
Mike Reeves
be5f4b04c6
Fix SSL Perms
2020-07-06 17:21:23 -04:00
Mike Reeves
cc6d0c1cb5
Merge pull request #935 from Security-Onion-Solutions/issue/929
...
Change grafana to use anon auth
2020-07-06 16:45:19 -04:00
Mike Reeves
3b452ab597
Change grafana to use anon auth
2020-07-06 16:39:43 -04:00
Mike Reeves
cc2f023840
Merge pull request #934 from Security-Onion-Solutions/issue/142
...
Issue/142
2020-07-06 16:12:48 -04:00
Mike Reeves
f05e366d49
Fix salt upgrade script
2020-07-06 15:56:55 -04:00
Mike Reeves
be3390a796
Fix Logstash state
2020-07-06 15:53:21 -04:00
Josh Patterson
da0a0ae6ae
Merge pull request #933 from Security-Onion-Solutions/quickfix/firewall
...
add elasticsearch_rest to assigned hostgroups where missing
2020-07-06 15:20:00 -04:00
m0duspwnens
b4e556496b
add elasticsearch_rest to assigned hostgroups where missing
2020-07-06 15:18:47 -04:00
Mike Reeves
623c37f1f5
Merge remote-tracking branch 'remotes/origin/dev' into issue/142
2020-07-06 14:35:46 -04:00
Mike Reeves
1016315196
Change Logic for logstash
2020-07-06 13:58:38 -04:00
Mike Reeves
087080d583
Add logix for logstash_settings
2020-07-06 13:16:40 -04:00
William Wernert
57bbb02c65
[refactor][fix] Move nmcli status list gen to a function
...
nmcli is only assured to be installed after detect_os is run so move this command to a function so it can run after detect_os
2020-07-02 17:18:56 -04:00
William Wernert
99d490bc06
[fix][refactor] Move detect_ec2 and add echo statement
2020-07-02 17:15:46 -04:00
bryant-treacle
cfeb95a718
Merge pull request #924 from Security-Onion-Solutions/feature/so-container-scripts
...
Additional so-container scripts Issue # 701
2020-07-02 14:42:49 -04:00
William Wernert
b9a176201f
Merge pull request #913 from Security-Onion-Solutions/feature/setup-changes
...
Feature/setup changes
2020-07-02 14:01:46 -04:00
William Wernert
d2ba25e784
Merge branch 'dev' into feature/setup-changes
...
# Conflicts:
# setup/so-setup
2020-07-02 14:00:10 -04:00
weslambert
0bfa3d486e
Merge pull request #923 from Security-Onion-Solutions/fix/es-allow
...
Fix my typo
2020-07-02 13:32:45 -04:00
weslambert
bbc752b6d9
Fix my typo
2020-07-02 13:32:19 -04:00
Josh Brower
518c8db3de
Merge pull request #922 from Security-Onion-Solutions/feature/low-level-alerts
...
Initial commit - Low Level Alerts
2020-07-02 12:18:03 -04:00
Josh Brower
69ace6fbfa
Initial commit - Low Level Alerts
2020-07-02 12:16:56 -04:00
Jason Ertel
cf6a229f51
Import now requires execution on a sensor node due to the need for zeek and suricata; Automatically stop curator if curator is installed
2020-07-02 12:07:30 -04:00
Mike Reeves
541de278c9
Merge pull request #918 from Security-Onion-Solutions/versionfix
...
Versionfix
2020-07-02 10:39:15 -04:00
Mike Reeves
5df88f6f2d
Update so-functions
2020-07-02 10:36:28 -04:00
Mike Reeves
86a2650fbf
Update VERSION
2020-07-02 10:34:50 -04:00
Mike Reeves
c895503fe6
Merge pull request #917 from Security-Onion-Solutions/updateversion
...
Update VERSION
2020-07-02 10:06:23 -04:00
Mike Reeves
63ef3a1e07
Update VERSION
2020-07-02 10:05:12 -04:00
William Wernert
c7a3cc9c17
[fix][revert] Change source in so-allow to correct path
2020-07-02 08:58:14 -04:00
Jason Ertel
4cedacf8fd
Improve curator verbiage in so-import-pcap
2020-07-02 06:01:17 -04:00
Josh Brower
07d13b7ad0
Merge pull request #916 from Security-Onion-Solutions/defensivedepth-patch-1
...
Delete playbook_db_init.sql.backup
2020-07-02 05:32:45 -04:00
Josh Brower
7811ea5d4c
Delete playbook_db_init.sql.backup
2020-07-02 05:32:35 -04:00
Josh Brower
0f915ec85e
Merge pull request #915 from Security-Onion-Solutions/feature/playbook-updates
...
Feature/playbook updates
2020-07-02 05:31:30 -04:00
Josh Brower
3c93f9fd45
Playbook setup fix
2020-07-02 05:30:30 -04:00
bryant-treacle
0b10b775c5
Additional so-container scripts
2020-07-02 07:02:35 +00:00
Jason Ertel
ac01b8de4b
Stop curator when directed on PCAP imports
2020-07-01 22:04:07 -04:00
Doug Burks
98cfba18e9
fix zeek.ftp description
2020-07-01 20:27:40 -04:00
Doug Burks
f6adf4ed56
fix zeek.smb_mapping description
2020-07-01 20:26:51 -04:00
Doug Burks
2cbd5ffe61
fix zeek.ssh description
2020-07-01 20:26:06 -04:00
Jason Ertel
e3126064e8
Improve usage instructions for so-import-pcap
2020-07-01 17:58:02 -04:00
William Wernert
aeda3fde74
[revert] Remove regex from setup log grep
2020-07-01 17:39:04 -04:00
William Wernert
408b5ee32d
[ix] Fix if conditions
2020-07-01 17:25:26 -04:00
Jason Ertel
96e93b012d
Adjust imports for filebeat configuration to ensure import data is placed into ES
2020-07-01 17:18:01 -04:00
Josh Brower
d893aa0032
Playbook Updates
2020-07-01 16:48:07 -04:00
William Wernert
b671f28562
[fix] Rename function whiptail_bond_nics to whiptail_sensor_nics
2020-07-01 16:32:33 -04:00
William Wernert
85a3f3c277
Merge branch 'dev' into feature/setup-changes
2020-07-01 16:24:55 -04:00
William Wernert
b4f9fe5f54
[fix] Remove quotes
2020-07-01 16:24:41 -04:00
William Wernert
b75cb36058
Merge branch 'feature/ec2_setup' into feature/setup-changes
2020-07-01 16:23:48 -04:00
William Wernert
54c3327240
[refactor] Simplify ec2 detection + handling
2020-07-01 16:23:38 -04:00
Jason Ertel
d6feafb12a
Correct indentation in filebeat.yaml
2020-07-01 15:39:23 -04:00
Mike Reeves
ab42126d8e
Add logstash_settings pillar
2020-07-01 15:25:35 -04:00
Mike Reeves
5580f05daf
Add logstash pillar
2020-07-01 15:07:00 -04:00
Mike Reeves
f580da5d56
Update 9999_output_redis.conf.jinja
2020-07-01 14:45:54 -04:00
Mike Reeves
70e4ce3e98
Add batch to output
2020-07-01 14:38:51 -04:00
William Wernert
4b5571a8d6
[refactor][fix] Remove unnecessary variable
2020-07-01 13:56:15 -04:00
William Wernert
44890edc79
[refactor] Use regex in error check for setup log
2020-07-01 13:51:54 -04:00
Josh Patterson
549fd93cba
Merge pull request #912 from Security-Onion-Solutions/issue/642
...
Issue/642
2020-07-01 13:44:49 -04:00
m0duspwnens
f98c497d79
change setup and whiptail back to bro
2020-07-01 13:43:37 -04:00
Wes Lambert
26b0daf2da
Add other setup-related items for EC2 interface
2020-07-01 17:42:51 +00:00
m0duspwnens
fd939a06b9
whitespace cleanup
2020-07-01 13:40:40 -04:00
Wes Lambert
3cf79995a2
Modify Whiptail menu for EC2 NIC
2020-07-01 17:32:43 +00:00
m0duspwnens
38db512eda
fix spacing
2020-07-01 13:29:19 -04:00
m0duspwnens
4e7e19af54
pillarize zeek node.cfg. change reference from bro to zeek.
2020-07-01 13:26:27 -04:00
William Wernert
db764902c7
[fix] Change if condition when checking nmcli status
2020-07-01 13:05:11 -04:00
William Wernert
19b997ece0
Merge branch 'dev' into feature/setup-changes
2020-07-01 12:56:57 -04:00
William Wernert
7bb97f2b2d
[fix] Remove "Panel Title" from Kibana CPU graph
...
Resolves #874
2020-07-01 11:12:21 -04:00
William Wernert
90f4b8e043
[feat] Add welcome/instruction wording to initial menu
2020-07-01 11:03:18 -04:00
William Wernert
c97798b57d
[feat] Add check to see if bond nics are managed by Network Manager
2020-07-01 09:43:39 -04:00
William Wernert
3a9d252af3
[fix] Correct indent in create_local_directories()
2020-07-01 09:42:07 -04:00
William Wernert
de620c88a1
Merge pull request #910 from Security-Onion-Solutions/version-correction
...
Remove HH prefix to ensure compatibility with updated build system
2020-06-30 15:57:30 -04:00
Jason Ertel
a49532d15c
Remove HH prefix to ensure compatibility with updated build system
2020-06-30 15:54:56 -04:00
Jason Ertel
a3deb868ad
Improve filebeat config indentation
2020-06-30 14:57:34 -04:00
Jason Ertel
930f15eea5
Introduce so-import-pcap tool - WIP
2020-06-30 14:56:08 -04:00
William Wernert
8dedd60da8
Merge branch 'feature/fast-fail' into feature/setup-changes
2020-06-30 14:27:04 -04:00
William Wernert
ce8a59243c
[feat] Add grep for "Error" to fail if nmcli fails
2020-06-30 14:26:48 -04:00
William Wernert
8d624e6ade
[fix] Move navigatordefaultlayer file.managed state to nginx sls
2020-06-30 10:53:10 -04:00
William Wernert
cab232ae9f
[feat] Add check for disk space during setup
2020-06-30 10:11:02 -04:00
Mike Reeves
ba81b7275a
Merge pull request #909 from Security-Onion-Solutions/fix/1.4.1
...
Update to 1.4.1
2020-06-30 09:55:10 -04:00
Mike Reeves
a1791f1e2e
Update to 1.4.1
2020-06-30 09:47:20 -04:00
Mike Reeves
a74d52a986
Merge pull request #908 from Security-Onion-Solutions/bugfix/hostname-regex
...
[fix] Apply regex filter to hostname input
2020-06-30 09:14:20 -04:00
William Wernert
1022bf5b99
[fix] Apply regex filter to hostname input
2020-06-30 09:08:55 -04:00
William Wernert
9f39875192
[fix] Apply regex filter to hostname input
2020-06-30 09:01:19 -04:00
Josh Brower
376a6e5fd5
Merge pull request #907 from Security-Onion-Solutions/feature/spacing-so-allow
...
so-allow spacing fix
2020-06-30 08:13:38 -04:00
Josh Brower
1c0443458c
so-allow spacing fix
2020-06-30 08:13:00 -04:00
weslambert
0b7026a11e
Merge pull request #906 from Security-Onion-Solutions/fix/ingest_parsing
...
Fix/ingest parsing
2020-06-29 23:07:22 -04:00
Wes Lambert
84e2965fef
Addl krb fix
2020-06-30 03:06:01 +00:00
Wes Lambert
bf8798f1d1
Fix krb client/server cert subject parsing
2020-06-30 03:04:01 +00:00
Wes Lambert
8f5da66335
Add null safe operator for query name
2020-06-30 03:02:38 +00:00
Josh Patterson
46d58acdd9
Merge pull request #905 from Security-Onion-Solutions/issue/878
...
add sensoroni to so-status output for sensors
2020-06-29 16:24:41 -04:00
m0duspwnens
0f9d8024f8
add sensoroni to so-status output for sensors - https://github.com/Security-Onion-Solutions/securityonion/issues/878
2020-06-29 16:23:04 -04:00
Josh Patterson
c73071c95e
Merge pull request #904 from Security-Onion-Solutions/issue/583
...
Issue/583
2020-06-29 16:17:22 -04:00
m0duspwnens
efaf41107c
update description in localrules/local.rules for idstools
2020-06-29 16:14:36 -04:00
m0duspwnens
67f2eedad1
cleanup whitespace in idstools enable/disable.conf
2020-06-29 16:11:30 -04:00
m0duspwnens
fe8df22063
cleanup whitespace in idstools enable/disable.conf
2020-06-29 16:03:14 -04:00
William Wernert
fdaab8da9f
Merge branch 'dev' into feature/setup-changes
2020-06-29 15:54:36 -04:00
William Wernert
23c0363899
[fix] Reference correct directory in nginx sls and remove navigator sls
2020-06-29 15:54:17 -04:00
William Wernert
b97ecd2d7a
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-06-29 15:53:29 -04:00
William Wernert
0a97328acc
[fix] Apply regex filter to hostname input
2020-06-29 15:53:21 -04:00
Josh Patterson
6bc7f023ff
Merge pull request #903 from Security-Onion-Solutions/quickfix/suricata
...
fix suricata state if suripins or suri procs arent set
2020-06-29 15:39:40 -04:00
m0duspwnens
d7580fe6a0
fix suricata state if suripins or suri procs arent set
2020-06-29 15:38:05 -04:00
William Wernert
53c3b1579b
[feat] Reformat install type menu
2020-06-29 15:20:17 -04:00
William Wernert
8e15f858dd
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
...
# Conflicts:
# salt/common/tools/sbin/so-allow
2020-06-29 15:14:12 -04:00
Mike Reeves
abe063602b
Update whiptail snort
...
Update the user to let them know Snort 3.x won't work.
2020-06-29 14:57:42 -04:00
weslambert
b398d58dc9
Merge pull request #902 from Security-Onion-Solutions/feature/es_allow
...
Add ES REST API option for so-allow
2020-06-29 14:51:09 -04:00
Wes Lambert
ed60d48c81
Add ES REST API option for so-allow
2020-06-29 18:49:16 +00:00
William Wernert
8cbccb656d
[fix] Apply shellcheck fixes
2020-06-29 11:32:25 -04:00
William Wernert
b01bdf35f9
[fix] Remove port binding from telegraf docker state
2020-06-29 11:31:44 -04:00
m0duspwnens
8ee2142de4
pillarize idstools - https://github.com/Security-Onion-Solutions/securityonion/issues/583
2020-06-29 11:21:47 -04:00
Mike Reeves
378ad97e7b
Disabled socket listener
2020-06-29 11:16:19 -04:00
weslambert
b99b19ce58
Merge pull request #898 from Security-Onion-Solutions/feature/strelka_scripts
...
Add Strelka mgmt scripts
2020-06-29 09:11:16 -04:00
Wes Lambert
9ac85cf674
Add Stelka mgmt scripts
2020-06-29 13:09:14 +00:00
weslambert
6f6e8a8853
Merge pull request #897 from Security-Onion-Solutions/fix/strelka_rules
...
Fix/strelka rules
2020-06-26 16:43:21 -04:00
weslambert
c421bd464a
Remove Strelka function (in favor of direct script execution in so-setup)
2020-06-26 16:42:44 -04:00
William Wernert
22eb81128a
Merge pull request #891 from Security-Onion-Solutions/feature/navigator-to-nginx
...
Feature/navigator to nginx
2020-06-26 15:48:46 -04:00
weslambert
8c47723bc9
Run YARA update script after applying state
2020-06-26 15:45:52 -04:00
Josh Patterson
9c388cd6aa
Merge pull request #896 from Security-Onion-Solutions/feature/suripillar
...
Feature/suripillar
2020-06-26 14:44:36 -04:00
m0duspwnens
0b1a258a4b
change sensor homenet map
2020-06-26 14:43:27 -04:00
weslambert
813c243d3d
Update so-yara-update
2020-06-26 13:26:08 -04:00
m0duspwnens
2079eba0ad
Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar
2020-06-26 13:09:15 -04:00
m0duspwnens
052c65c05e
add the things to pillarize suricata - https://github.com/Security-Onion-Solutions/securityonion/issues/584
2020-06-26 13:07:41 -04:00
William Wernert
cf7e5f1b6f
[fix] Change permissions on so-yara-update + fix indents
2020-06-26 09:59:44 -04:00
Josh Brower
b895d6fa4f
Merge pull request #894 from Security-Onion-Solutions/feature/playbook-unit-testing
...
Playbook - Initial Support for Unit Testing
2020-06-26 06:33:05 -04:00
Josh Brower
7f0eacd342
Playbook - Initial Support for Unit Testing
2020-06-26 06:24:09 -04:00
Mike Reeves
1e4c967afc
Fix math for suri loss calulcations
2020-06-25 14:02:02 -04:00
Mike Reeves
1e6fab4e6e
Fix math for suri loss calulcations
2020-06-25 13:54:01 -04:00
Mike Reeves
65687fd28e
Update saltstack update to point to correct github
2020-06-25 13:02:17 -04:00
Mike Reeves
57d0603e4c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into dev
2020-06-25 12:56:38 -04:00
Mike Reeves
30ac5f9764
ADding Suricata log compression
2020-06-25 12:56:26 -04:00
weslambert
5e41bba6db
Merge pull request #892 from Security-Onion-Solutions/feature/more_strelka_rules
...
Feature/more strelka rules
2020-06-25 12:33:36 -04:00
Wes Lambert
a24402de99
More Strelka rule config
2020-06-25 16:31:04 +00:00
Wes Lambert
63c45be388
Update Strelka init for rules
2020-06-25 15:49:58 +00:00
Wes Lambert
6487fdf5e6
Add Strelka YARA function
2020-06-25 15:46:37 +00:00
William Wernert
a45fbb6f5c
Revert "[fix] discovery.zen.minimum_master_nodes is deprecated, update the key"
...
This reverts commit 8bd6c067aa .
2020-06-25 10:53:26 -04:00
bryant-treacle
00713312c6
Merge pull request #890 from Security-Onion-Solutions/fix/so-elastic-clear
...
updated so-elastic-clear with new so-* indices - #885
2020-06-24 15:09:37 -04:00
bryant-treacle
443332d584
Update so-elastic-clear
2020-06-24 15:03:25 -04:00
bryant-treacle
ffc9567278
Delete test.test
2020-06-24 15:01:30 -04:00
bryant-treacle
08220e3330
Issue #885 : so-elastic-clear not removing so-* indices
2020-06-24 18:40:11 +00:00
weslambert
83ed21314a
Merge pull request #888 from Security-Onion-Solutions/feature/strelka_rules
...
Feature/strelka rules
2020-06-24 13:28:52 -04:00
Wes Lambert
f5bb831edf
Fix comment
2020-06-24 17:27:59 +00:00
Wes Lambert
a01339039a
Update Setup for Strelka rules
2020-06-24 17:22:55 +00:00
bryant-treacle
0849014b24
Issue #885 : so-elastic-clear not removing so-* indices
2020-06-24 17:21:58 +00:00
Wes Lambert
8bfbd77367
Update whiptail for Strelka
2020-06-24 17:18:05 +00:00
William Wernert
8bd6c067aa
[fix] discovery.zen.minimum_master_nodes is deprecated, update the key
2020-06-24 13:10:18 -04:00
Wes Lambert
52a0ace1b8
Use Strelka rules if enabled
2020-06-24 17:08:58 +00:00
William Wernert
bd36749959
[feat] Remove navigator container references
2020-06-24 12:38:32 -04:00
William Wernert
4404a4f312
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev
2020-06-23 17:57:19 -04:00
William Wernert
0a0fe5914a
[fix][feat] Move navigator entries to static files + fix indent
2020-06-23 17:57:14 -04:00
weslambert
c3651f1b45
Merge pull request #884 from Security-Onion-Solutions/feature/strelka_client
...
Add FW config for Strelka frontend
2020-06-23 14:57:06 -04:00
Wes Lambert
f7eacc2b05
Add FW config for Strelka frontend
2020-06-23 18:47:23 +00:00
weslambert
685e3048ac
Merge pull request #883 from Security-Onion-Solutions/fix/hunt_files_rename
...
Update file dataset name for hunt queries
2020-06-23 13:49:52 -04:00
Wes Lambert
c0428ce79d
Update file dataset name for hunt queries
2020-06-23 17:48:12 +00:00
weslambert
13df2e6312
Merge pull request #882 from Security-Onion-Solutions/fix/files_rename
...
Move dataset from files to file
2020-06-23 13:44:26 -04:00
Wes Lambert
af451573eb
Move dataset from files to file
2020-06-23 17:43:28 +00:00
m0duspwnens
36a329214a
merge eve-log in outputs for suricata meta data generation or zeek/default - https://github.com/Security-Onion-Solutions/securityonion/issues/584
2020-06-22 16:56:03 -04:00
m0duspwnens
f1bcd35734
Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar
2020-06-22 09:13:29 -04:00
Jason Ertel
d7693f9b55
Expose pcap dir to sensoroni for epoch discovery
2020-06-22 08:27:43 -04:00
Jason Ertel
1ee3625f61
Ensure certs dir is group readable by socore since Sensoroni process will need to read the client key
2020-06-21 15:46:36 -04:00
Jason Ertel
81ed656ba0
Bind both steno and sensoroni processes to host network
2020-06-21 10:50:10 -04:00
Jason Ertel
76e3118bd3
Split Sensoroni and Stenographer executables into separate images
2020-06-21 08:33:09 -04:00
m0duspwnens
57fa2c5abe
Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar
2020-06-18 13:49:07 -04:00
Mike Reeves
6dbe83a77f
Update so-docker-refresh
2020-06-18 12:38:07 -04:00
Jason Ertel
2f3a99cfb0
fix: indentation is incorrect
2020-06-17 17:46:49 -04:00
weslambert
fb9ac58ed6
Merge pull request #869 from Security-Onion-Solutions/feature/elastic_indices_rw
...
Basic index read-only attr removal script
2020-06-17 15:00:23 -04:00
Wes Lambert
6d25151ab8
Basic index read-only attr removal script
2020-06-17 18:59:13 +00:00
Josh Brower
6794cabf9c
Merge pull request #868 from Security-Onion-Solutions/bugfix/fleet-custom-hostname
...
Fleet custom hostname regex fix
2020-06-17 14:46:07 -04:00
weslambert
569fc4ac4d
Merge pull request #867 from Security-Onion-Solutions/feature/zeek_custom_policy
...
Feature/zeek custom policy
2020-06-17 13:12:38 -04:00
Wes Lambert
90c278096c
Add custom Zeek script dir
2020-06-17 17:11:27 +00:00
Josh Brower
3418f5748c
Fleet custom hostname regex fix
2020-06-17 13:08:47 -04:00
Jason Ertel
6bf8f0af08
Eliminate multiple version definitions in this repo
2020-06-17 10:46:07 -04:00
Jason Ertel
3451f74b63
Update version to 2.0.0-rc.1
2020-06-17 10:32:39 -04:00
weslambert
b489420002
Merge pull request #865 from Security-Onion-Solutions/feature/cortex_custom
...
Feature/cortex custom
2020-06-17 09:22:42 -04:00
Wes Lambert
1beff65cc9
fix typo
2020-06-17 13:20:32 +00:00
Wes Lambert
cbfe375407
Custom analyzer and responder dirs
2020-06-17 13:16:52 +00:00
William Wernert
ce86dbfac0
[feat] Add message about root mail spool growing
2020-06-11 09:24:23 -04:00
William Wernert
07b2f2885c
[fix] Always exit on early failure
2020-06-10 15:32:46 -04:00
William Wernert
7de02752e5
[fix] Reboot on early failure too, better if statements
2020-06-10 15:29:54 -04:00
William Wernert
379a5445e8
[feat] Also exit with non-zero status for automated installs
2020-06-10 14:27:18 -04:00
William Wernert
9695b9326b
Merge branch 'dev' into feature/fast-fail
2020-06-10 14:19:44 -04:00
William Wernert
03dfece9af
[feat] Fail setup early if "ERROR" is found in setup log
2020-06-10 14:18:25 -04:00
m0duspwnens
f8193cb914
beginning to pillarize suricata
2020-06-04 09:40:38 -04:00
Mike Reeves
45d17c5148
Pillarize Suricata Round 1
2020-06-01 14:53:04 -04:00