Mike Reeves
5344d30d56
Merge pull request #2003 from Security-Onion-Solutions/dev
...
2.3.10
2020-11-19 16:48:53 -05:00
Mike Reeves
4051111999
Update hashes and keys
2020-11-19 16:00:40 -05:00
Mike Reeves
316a1c02f1
Update soup to display what its doing
2020-11-19 15:19:50 -05:00
Josh Patterson
c07f62f8d1
Merge pull request #2007 from Security-Onion-Solutions/fix/minon
...
kill salt process with soup and dont restart salt-minion service when…
2020-11-19 15:17:58 -05:00
m0duspwnens
cdc7a5cc7c
kill salt process with soup and dont restart salt-minion service when salt upgrade
2020-11-19 15:17:11 -05:00
Josh Patterson
10a3e6f414
Merge pull request #2006 from Security-Onion-Solutions/fix/minon
...
change typo on minon to minion
2020-11-19 15:11:16 -05:00
m0duspwnens
2a3951ab36
change typo on minon to minion
2020-11-19 15:08:08 -05:00
Mike Reeves
67a8c4e8cb
Update Readme
2020-11-19 11:27:15 -05:00
Mike Reeves
177819447b
Update Sigs and Hashes
2020-11-19 11:26:08 -05:00
Mike Reeves
3be1c9ae32
Clean up 2.3.1 dockers
2020-11-19 09:58:08 -05:00
Josh Brower
b79e1c3225
Merge pull request #1987 from Security-Onion-Solutions/bugfix/playbookdb-user
...
playbook mysqluser
2020-11-18 20:48:49 -05:00
Josh Brower
d3065005ca
playbook mysqluser
2020-11-18 20:48:02 -05:00
Josh Patterson
26e97d5875
Merge pull request #1984 from Security-Onion-Solutions/salt/3002.2
...
upgrade from salt 3002.1 to salt 3002.2
2020-11-18 18:26:11 -05:00
m0duspwnens
d68726f6ef
upgrade from salt 3002.1 to salt 3002.2
2020-11-18 18:25:02 -05:00
Josh Patterson
f81da406da
Merge pull request #1983 from Security-Onion-Solutions/soup-verify-salt
...
dont highstate, just restart salt-minion
2020-11-18 17:40:36 -05:00
m0duspwnens
afd466cd2b
dont highstate, just restart salt-minion
2020-11-18 17:27:25 -05:00
Josh Patterson
6d228a836f
Merge pull request #1982 from Security-Onion-Solutions/soup-verify-salt
...
add -X so bootstrap doesnt try to start salt-minion during soup
2020-11-18 16:45:05 -05:00
m0duspwnens
1805effdc0
add -X so bootstrap doesnt try to start salt-minion during soup
2020-11-18 16:32:53 -05:00
Jason Ertel
1170b04a87
Update changes for 2.3.10
2020-11-18 16:18:00 -05:00
Josh Patterson
c0b43d3319
Merge pull request #1981 from Security-Onion-Solutions/soup-verify-salt
...
add back -s
2020-11-18 15:50:04 -05:00
m0duspwnens
6cc9d1c076
add back -s
2020-11-18 15:49:30 -05:00
William Wernert
1c55bb6db2
[fix] Only backup /nsm/mysql and /nsm/wazuh
2020-11-18 15:34:40 -05:00
Josh Brower
3d0003555a
Merge pull request #1980 from Security-Onion-Solutions/bugfix/soup-regen-osquery
...
SOUP - Regen Osquery Packages
2020-11-18 14:56:23 -05:00
Josh Brower
0830f63c4e
SOUP - Regen Osquery Packages
2020-11-18 14:55:14 -05:00
Josh Patterson
adbd8d6956
Merge pull request #1979 from Security-Onion-Solutions/soup-verify-salt
...
Soup verify salt
2020-11-18 14:49:03 -05:00
William Wernert
80d0080f70
[fix] Only set is_reinstall if it's needed
2020-11-18 14:47:53 -05:00
m0duspwnens
af6e14dc6f
highstate , merge with dev fix conflict
2020-11-18 14:47:40 -05:00
William Wernert
8b6b7cbd11
[fix] Check if $is_reinstall is true
2020-11-18 14:46:22 -05:00
William Wernert
e65c53dbb1
[fix] Don't rename /nsm/docker-registry
2020-11-18 14:01:33 -05:00
m0duspwnens
ceef07b74b
remove pkill
2020-11-18 14:00:01 -05:00
William Wernert
280cde43ff
[fix] install_type -> setup_type
2020-11-18 13:51:55 -05:00
William Wernert
81b9658499
[fix] Don't remove accept_changes file
2020-11-18 13:51:55 -05:00
weslambert
04c6bed779
Merge pull request #1977 from Security-Onion-Solutions/fix/zeek_log_inode_cleanup
...
Change clean_removed to true to clean up tracking of Zeek logs removed fr…
2020-11-18 13:49:46 -05:00
weslambert
6b4af30fc1
Change clean_removed to true cleanup tracking of Zeek logs removed from current
2020-11-18 13:47:32 -05:00
m0duspwnens
1e2b404836
remove -s
2020-11-18 13:29:42 -05:00
m0duspwnens
276c011a4f
queue state and change upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 13:22:11 -05:00
William Wernert
34fd80182e
[fix][wip] Don't use variable for accept_changes file
2020-11-18 12:54:36 -05:00
Jason Ertel
57e9f69c97
Add new so-ip-update script (Work in progress)
2020-11-18 12:35:38 -05:00
William Wernert
0542e0aa04
[fix] info -> title
2020-11-18 12:35:16 -05:00
m0duspwnens
d0e7b5b55a
only ensure salt-minion service is running if salt is on right verison https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 12:32:21 -05:00
William Wernert
ad74b4b3e0
[refactor][fix] Update reinstall logic
...
* Only set reinstall flag if new accept_changes file exists
* Instead of stopping highstate from running, kill all salt processes and remove their configs
* Make end of non-reinstall logs clear in cases where user cancels (and log not rotated)
2020-11-18 12:29:54 -05:00
m0duspwnens
ce70e0a61f
changes to upgradecommand https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 11:51:28 -05:00
William Wernert
8a4defcffa
[refactor] Check for setup log earlier
...
* Check for sosetuo.log before any scripts besides so-variables are sourced to make sure the log hasn't been created yet.
2020-11-18 11:16:36 -05:00
m0duspwnens
bddc3d6df9
kill all salt-minion again since they hang and redirect highstate to a logfile
2020-11-18 10:40:23 -05:00
m0duspwnens
4bb1ad9799
dont restart or kill salt-minon in upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 09:29:09 -05:00
William Wernert
bc0c395b7f
Merge pull request #1963 from Security-Onion-Solutions/feature/rem-so-setup-perm-entry
...
Feature/rem so-setup perm entry
2020-11-18 09:12:25 -05:00
m0duspwnens
67dc71ab49
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-18 08:36:23 -05:00
m0duspwnens
c95619d335
change upgradecommand order https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 08:35:56 -05:00
Jason Ertel
bfbc0f354c
Only default to logging out to tty if tty exists as a character device
2020-11-17 22:48:40 -05:00
m0duspwnens
5c6e9e0e3a
run a highstate and let that start the salt-minion back up https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 19:40:42 -05:00
m0duspwnens
7291d64e82
pkill salt-minion before restartiong salt-minion service https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 18:38:01 -05:00
m0duspwnens
695cce0b50
upgrad command changes https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 17:54:56 -05:00
m0duspwnens
42126f125b
change verison check to !=
2020-11-17 17:00:59 -05:00
m0duspwnens
2bfc48be35
change check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:31:11 -05:00
m0duspwnens
7d1cf56160
change check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:29:35 -05:00
m0duspwnens
1fd2196dd5
fix check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:18:50 -05:00
m0duspwnens
65b84f1bd7
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-17 16:09:47 -05:00
m0duspwnens
fcfd3e3758
change location yum/apt verison locks https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 16:09:30 -05:00
William Wernert
ee3708a428
[fix] Move sudoers check in soup to correct place + fix styling issue
2020-11-17 15:44:20 -05:00
William Wernert
b146700303
[feat] Remove so-setup permission from sudoers file after iso setup
...
Closes #1701
2020-11-17 15:36:25 -05:00
Jason Ertel
1ec8b52353
Replace scan.exiftool.* fields due to reduction in strelka field counts
2020-11-17 15:12:06 -05:00
Josh Patterson
f8346cde08
Merge pull request #1962 from Security-Onion-Solutions/soup-verify-salt
...
Soup verify salt
2020-11-17 15:08:32 -05:00
m0duspwnens
e162be2e1d
change salt upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 14:29:39 -05:00
m0duspwnens
4f4f64a47d
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-17 13:16:18 -05:00
m0duspwnens
4cd1086efa
new way for soup to install and resart salt for upgrade
2020-11-17 13:15:55 -05:00
Mike Reeves
2184c3b8ee
Revert "The Hive ES update"
...
This reverts commit 88c2ee0d36 .
2020-11-17 12:51:42 -05:00
Mike Reeves
65d28f98b5
Revert "The Hive ES Update"
...
This reverts commit f31d459a24 .
2020-11-17 12:51:13 -05:00
Jason Ertel
aa8d9c12a0
Remove yara rule update that can't succeed since the script doesn't exist at this point of the setup process
2020-11-17 12:15:27 -05:00
Mike Reeves
f31d459a24
The Hive ES Update
2020-11-17 11:59:03 -05:00
Mike Reeves
88c2ee0d36
The Hive ES update
2020-11-17 11:58:22 -05:00
Jason Ertel
d13733e716
Queue the registry state in case a highstate is already active
2020-11-17 09:59:09 -05:00
Josh Patterson
86922a2388
Merge pull request #1959 from Security-Onion-Solutions/soup-verify-salt
...
verify new salt version is installed during soup if not, exit before proceeding
2020-11-17 09:53:08 -05:00
m0duspwnens
65440f9aef
verify new salt version is installed during soup if not, exit before proceeding
2020-11-17 09:51:28 -05:00
William Wernert
12c661101a
Merge pull request #1958 from Security-Onion-Solutions/feat/require-min-nics
...
Feat/require min nics
2020-11-17 09:49:09 -05:00
William Wernert
79b63ed14b
[fix] Use singular when needed for requirements
2020-11-17 09:47:08 -05:00
Josh Brower
cc4357d567
Merge pull request #1954 from Security-Onion-Solutions/bugfix/ingest-mappings
...
Cleanup & fix sysmon pid ingest
2020-11-17 09:05:31 -05:00
Jason Ertel
b9267ee015
Add missing newline after armor header
2020-11-17 09:00:02 -05:00
Jason Ertel
5c310327e4
Merge pull request #1942 from Security-Onion-Solutions/jertel/refactor-seed
...
Jertel/refactor seed
2020-11-16 18:46:28 -05:00
Jason Ertel
4311f66110
Remove unnecessary redirect
2020-11-16 16:58:09 -05:00
Josh Patterson
a8644478b5
Merge pull request #1939 from Security-Onion-Solutions/fix/nginx-nonmanager
...
fix nginx for non manaager/fleet nodes
2020-11-16 16:47:39 -05:00
m0duspwnens
4436f02f6d
fix nginx for non manaager/fleet nodes
2020-11-16 16:46:22 -05:00
Jason Ertel
3cf8afc1dd
Remove unused redirect descriptors and ensure gpg import output is not leaked to console
2020-11-16 16:39:54 -05:00
Josh Patterson
f1e33b6eea
Merge pull request #1938 from Security-Onion-Solutions/fix/so.status-module
...
fix so-status to work with so.status module and change padding
2020-11-16 16:35:08 -05:00
m0duspwnens
0d9b22fe2d
fix so-status to work with so.status module and change padding
2020-11-16 16:33:29 -05:00
William Wernert
a08923030b
[feat] Exit setup if less than required number of NICs present
2020-11-16 16:26:38 -05:00
Jason Ertel
1ec4af1a4d
Destroy the old registry before updating SO images
2020-11-16 15:41:15 -05:00
Jason Ertel
5ae78d4108
Install curl in order to test for cloud
2020-11-16 15:31:40 -05:00
Jason Ertel
3bae243915
Continued refactoring of bash
2020-11-16 15:20:00 -05:00
Jason Ertel
8234b6f835
Switch remaining containers over to new registries; Continued bash refactoring
2020-11-16 15:11:08 -05:00
Josh Patterson
55231eab25
Merge pull request #1934 from Security-Onion-Solutions/fix/so-status-in-setup
...
redirect output from setting up so-status stuff in so-setup
2020-11-16 14:57:58 -05:00
m0duspwnens
e956ee9324
redirect output from setting up so-status stuff in so-setup
2020-11-16 14:56:20 -05:00
Jason Ertel
a343e3f31e
Save descriptors while inside the progress pipe
2020-11-16 14:10:48 -05:00
Jason Ertel
2ff738a61c
Refactor docker_seed_registry to eliminate duplicate logic
2020-11-16 13:27:23 -05:00
William Wernert
c226c1d902
[fix] Redirect stderr when checking for link state
2020-11-16 11:30:47 -05:00
Josh Patterson
7a49c55ea0
Merge pull request #1930 from Security-Onion-Solutions/issue/1831
...
Issue/1831
2020-11-16 10:09:49 -05:00
m0duspwnens
cc50eba6cb
make sure /opt/so/log/salt/so-salt-minion-check gets touched even if salt-minon verison isnt correct https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-16 10:01:40 -05:00
m0duspwnens
5c25dcf192
add /opt/so/log/salt/so-salt-minion-check to log rotate https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-16 09:50:10 -05:00
Jason Ertel
c744d389f7
More bash cleanup
2020-11-15 10:44:14 -05:00
Jason Ertel
76c917d977
Continued bash cleanup
2020-11-15 09:57:12 -05:00
Josh Brower
1908a68330
Cleanup & fix sysmon pid ingest
2020-11-14 16:19:23 -05:00
Jason Ertel
d22040fb5d
Annual fall bash cleanup event
2020-11-14 11:53:31 -05:00
Jason Ertel
372f694cc1
Set curl type to 'features' when adding features to existing installation
2020-11-14 11:04:40 -05:00
Jason Ertel
1c079f7ff4
Remove duplicate docker pull/sigverify logic from so-features-enable; Provide current SO version to curl
2020-11-14 10:35:45 -05:00
m0duspwnens
4e6e29e7dc
update logging
2020-11-13 20:26:06 -05:00
m0duspwnens
43a244e0da
change log path https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 19:37:03 -05:00
m0duspwnens
e958246457
touch file at start of highstate, just kill salt dont systemctl stop it https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 19:34:17 -05:00
m0duspwnens
b210092534
logging changes issue/1831
2020-11-13 19:09:53 -05:00
m0duspwnens
e820c6fa42
logging changes issue/1831
2020-11-13 19:04:09 -05:00
m0duspwnens
71a409f210
fix threshold logic https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 18:23:55 -05:00
m0duspwnens
a5823be0ac
fix typo
2020-11-13 17:55:19 -05:00
Mike Reeves
13c261178a
fix soup so-image-common
2020-11-13 17:26:04 -05:00
m0duspwnens
2f0eaff8b3
sbin
2020-11-13 17:25:45 -05:00
Mike Reeves
977eea131e
fix soup so-image-common
2020-11-13 17:18:55 -05:00
Mike Reeves
fb9b07b0eb
fix soup so-image-common
2020-11-13 17:13:05 -05:00
m0duspwnens
6a010bb3e6
change var name
2020-11-13 17:08:47 -05:00
Mike Reeves
51b3e066be
fix soup so-image-common
2020-11-13 17:01:42 -05:00
Mike Reeves
7dfb8f5b12
fix soup so-image-common
2020-11-13 16:50:12 -05:00
Mike Reeves
23f2dee840
fix soup so-image-common
2020-11-13 16:30:34 -05:00
m0duspwnens
4275fcbf22
Merge remote-tracking branch 'remotes/origin/dev' into issue/1831
2020-11-13 16:28:58 -05:00
Jason Ertel
ee97f5eaac
Remove unnecessary branch var; allow skipping of tag/push step
2020-11-13 16:17:09 -05:00
m0duspwnens
0a807621cc
check health of salt-minion https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 16:02:28 -05:00
Mike Reeves
8577fa63a3
fix network install download
2020-11-13 14:28:27 -05:00
Mike Reeves
50175f7e42
soup should now copy the common image functions
2020-11-13 14:25:29 -05:00
Mike Reeves
3173c6fd3c
Change user agent string for docker refresh
2020-11-13 14:09:29 -05:00
Mike Reeves
069908ec56
Change user agent string for docker refresh
2020-11-13 13:55:26 -05:00
Mike Reeves
09f3199cc2
Change user agent string for docker refresh
2020-11-13 13:39:52 -05:00
Josh Brower
adec9ad48b
Merge pull request #1916 from Security-Onion-Solutions/feature/so-playbook-reset
...
Feature/so playbook reset
2020-11-13 11:21:50 -05:00
Josh Brower
8b3262ce1b
Add so-playbook-reset
2020-11-13 11:20:39 -05:00
weslambert
4fad0e3a98
Merge pull request #1914 from Security-Onion-Solutions/fix/syslog_parsing
...
Syslog updates
2020-11-13 11:07:53 -05:00
Wes Lambert
fddfb8eb92
Syslog updates
2020-11-13 16:06:22 +00:00
Jason Ertel
210a7bc65b
Merge curator closed-delete-delete changes from the abandoned 2.3.3 release
2020-11-13 10:05:23 -05:00
William Wernert
8a7ff3260d
Merge pull request #1911 from Security-Onion-Solutions/feature/ssh-harden-script
...
[feat] Add ssh-harden script
2020-11-13 09:00:07 -05:00
William Wernert
2f27b6f2fa
[feat] Add ssh-harden script
2020-11-13 08:51:28 -05:00
Mike Reeves
52e909007f
Change url and clean up sigs
2020-11-12 16:08:27 -05:00
Mike Reeves
80aeffe1ad
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-12 11:53:41 -05:00
Mike Reeves
cbca2d702f
Add Version back to sig files
2020-11-12 11:53:30 -05:00
Automation
af44cce423
Auto-publish so-acng image signature
2020-11-12 16:39:54 +00:00
Automation
7d81080076
Auto-publish so-grafana image signature
2020-11-12 16:39:24 +00:00
Automation
6194d85180
Auto-publish so-idstools image signature
2020-11-12 16:38:38 +00:00
Automation
88675ec2ee
Auto-publish so-strelka-manager image signature
2020-11-12 16:37:53 +00:00
Automation
9c0a1bc8b9
Auto-publish so-fleet image signature
2020-11-12 16:37:24 +00:00
Automation
52babc686d
Auto-publish so-fleet-launcher image signature
2020-11-12 16:36:51 +00:00
Automation
9370e5b8bc
Auto-publish so-freqserver image signature
2020-11-12 16:36:01 +00:00
Automation
6c1d5451eb
Auto-publish so-strelka-backend image signature
2020-11-12 16:35:16 +00:00
Automation
f50e6ab929
Auto-publish so-strelka-filestream image signature
2020-11-12 16:34:12 +00:00
Automation
67f18a02ea
Auto-publish so-strelka-frontend image signature
2020-11-12 16:33:37 +00:00
Mike Reeves
7f491545fa
Fix Variable for docker inspect
2020-11-12 11:31:27 -05:00
Automation
9b33201ba5
Auto-publish so-minio image signature
2020-11-12 16:30:56 +00:00
Mike Reeves
aefcb9a491
Fix Variable for docker
2020-11-12 11:28:58 -05:00
Automation
fee52f8b86
Auto-publish so-redis image signature
2020-11-12 16:28:23 +00:00
Automation
e434ccd3d3
Auto-publish so-soctopus image signature
2020-11-12 16:18:25 +00:00
Automation
70a0cbae23
Auto-publish so-telegraf image signature
2020-11-12 16:17:22 +00:00
Automation
04263101cf
Auto-publish so-kibana image signature
2020-11-12 16:15:27 +00:00
Mike Reeves
312f99966e
Change docker inspect to a variable to speed it up
2020-11-12 09:39:13 -05:00
Mike Reeves
667800d830
Change docker inspect to variable to speed it up
2020-11-12 09:35:19 -05:00
Mike Reeves
2fba02f71b
Grab specific digest so re-installs work
2020-11-12 09:29:18 -05:00
Josh Patterson
4ce0b770a5
Merge pull request #1898 from jtgreen-cse/patch-3
...
fix for #1725 , grafana queries use non_negative_ variants
2020-11-12 08:55:12 -05:00
Mike Reeves
1de862985c
Merge pull request #1893 from Security-Onion-Solutions/gpg
...
GPG Docker Image Verification
2020-11-12 08:46:34 -05:00
Jason Green
4e40392c55
fix for #1725 , grafana queries use non_negative_ variants
2020-11-12 07:34:51 -05:00
Automation
d1fe79b642
Auto-publish so-thehive-es image signature
2020-11-12 02:55:19 +00:00
Automation
f96cc35d37
Auto-publish so-thehive-cortex image signature
2020-11-12 02:53:56 +00:00
Automation
388f1e753d
Auto-publish so-strelka-manager image signature
2020-11-12 02:52:24 +00:00
Automation
42382d00d8
Auto-publish so-strelka-frontend image signature
2020-11-12 02:51:38 +00:00
Automation
b086f5e5c1
Auto-publish so-strelka-filestream image signature
2020-11-12 02:50:51 +00:00
Automation
0b0f9854f9
Auto-publish so-strelka-backend image signature
2020-11-12 02:49:47 +00:00
Automation
3107f46940
Auto-publish so-logstash image signature
2020-11-12 02:48:28 +00:00
Automation
202c672798
Auto-publish so-kibana image signature
2020-11-12 02:47:00 +00:00
Automation
6ac1bc5623
Auto-publish so-freqserver image signature
2020-11-12 02:45:21 +00:00
Automation
e002015ce2
Auto-publish so-fleet-launcher image signature
2020-11-12 02:44:31 +00:00
Automation
61b5e009c7
Auto-publish so-filebeat image signature
2020-11-12 02:43:27 +00:00
Automation
f3aadcd553
Auto-publish so-elasticsearch image signature
2020-11-12 02:42:22 +00:00
Automation
71370d4522
Auto-publish so-elasticsearch image signature
2020-11-12 02:41:12 +00:00
Automation
c287b5f826
Auto-publish so-elastalert image signature
2020-11-12 02:39:48 +00:00
Automation
4286ac0dfd
Auto-publish so-domainstats image signature
2020-11-12 02:38:46 +00:00
Automation
adc937295b
Auto-publish so-tcpreplay image signature
2020-11-12 02:37:39 +00:00
Automation
96bf2c57e7
Auto-publish so-pcaptools image signature
2020-11-12 02:36:20 +00:00
Automation
5f7a28dd5d
Auto-publish so-telegraf image signature
2020-11-12 02:35:22 +00:00
Automation
3560ba933b
Auto-publish so-suricata image signature
2020-11-12 02:34:18 +00:00
Automation
9c20450832
Auto-publish so-soctopus image signature
2020-11-12 02:33:10 +00:00
Automation
d71daef2e9
Auto-publish so-playbook image signature
2020-11-12 02:31:59 +00:00
Automation
c3ae80e2c1
Auto-publish so-logstash image signature
2020-11-12 02:30:36 +00:00
Automation
2098dd16ff
Auto-publish so-influxdb image signature
2020-11-12 02:29:02 +00:00
Automation
3b4c9e02e7
Auto-publish so-idstools image signature
2020-11-12 02:28:04 +00:00
Automation
adc99ff06d
Auto-publish so-filebeat image signature
2020-11-12 02:26:57 +00:00
Automation
f9b26c9a8f
Auto-publish so-thehive image signature
2020-11-12 02:25:44 +00:00
Automation
41a123c22b
Auto-publish so-grafana image signature
2020-11-12 02:24:19 +00:00
Automation
966089e1d0
Auto-publish so-curator image signature
2020-11-12 02:22:56 +00:00
Automation
3034d5ef98
Auto-publish so-kratos image signature
2020-11-12 02:22:11 +00:00
Automation
5ab169ea52
Auto-publish so-kibana image signature
2020-11-12 02:21:20 +00:00
Automation
f858027da1
Auto-publish so-wazuh image signature
2020-11-12 02:19:52 +00:00
Automation
c7517b37fa
Auto-publish so-steno image signature
2020-11-12 02:18:25 +00:00
Automation
2f315ba5a0
Auto-publish so-redis image signature
2020-11-12 02:17:06 +00:00
Automation
ed883f173b
Auto-publish so-mysql image signature
2020-11-12 02:16:12 +00:00
Automation
a46ad6fe81
Auto-publish so-minio image signature
2020-11-12 02:15:06 +00:00
Automation
42fc0add5e
Auto-publish so-fleet image signature
2020-11-12 02:14:08 +00:00
Automation
f6c2983bd1
Auto-publish so-zeek image signature
2020-11-12 02:12:58 +00:00
Automation
0b8e19bfc8
Auto-publish so-acng image signature
2020-11-12 02:11:20 +00:00
Automation
bee829697e
Auto-publish so-soc image signature
2020-11-12 02:10:11 +00:00
Mike Reeves
ed025851ca
Change soup for new gpg verification
2020-11-11 20:13:21 -05:00
Automation
94ab77b14d
Auto-publish so-nginx image signature
2020-11-12 00:57:45 +00:00
Mike Reeves
b113dce140
remove size from gpg sig
2020-11-11 19:49:25 -05:00
Automation
a2ef12eb6a
Auto-publish so-nginx image signature
2020-11-12 00:46:11 +00:00
Automation
eb0b909cd2
Auto-publish so-nginx image signature
2020-11-12 00:41:23 +00:00
Automation
7ef2056f17
Auto-publish so-steno image signature
2020-11-11 22:17:26 +00:00
Automation
b12f29d48a
Auto-publish so-thehive-es image signature
2020-11-11 22:16:06 +00:00
Automation
5fd1fd9b0d
Auto-publish so-thehive-cortex image signature
2020-11-11 22:14:47 +00:00
Automation
ad0ecff8c5
Auto-publish so-strelka-manager image signature
2020-11-11 22:13:19 +00:00
Automation
88b6ae1b2f
Auto-publish so-strelka-frontend image signature
2020-11-11 22:12:32 +00:00
Automation
9772fd181c
Auto-publish so-strelka-filestream image signature
2020-11-11 22:11:36 +00:00
Automation
cfff8319bb
Auto-publish so-strelka-backend image signature
2020-11-11 22:10:44 +00:00
Automation
0dc7c8b0e7
Auto-publish so-logstash image signature
2020-11-11 22:09:47 +00:00
Automation
3ccd8b40b2
Auto-publish so-kibana image signature
2020-11-11 22:08:21 +00:00
Automation
ca94bd12cf
Auto-publish so-fleet-launcher image signature
2020-11-11 22:06:47 +00:00
Automation
d650e68472
Auto-publish so-filebeat image signature
2020-11-11 22:05:38 +00:00
Automation
70f9bad827
Auto-publish so-elasticsearch image signature
2020-11-11 22:04:36 +00:00
Automation
c3d6e168ae
Auto-publish so-elasticsearch image signature
2020-11-11 22:03:08 +00:00
Automation
5c9c1915f1
Auto-publish so-domainstats image signature
2020-11-11 22:01:41 +00:00
Automation
32912f2c87
Auto-publish so-freqserver image signature
2020-11-11 22:00:41 +00:00
Automation
fb70e1e40c
Auto-publish so-elastalert image signature
2020-11-11 21:59:35 +00:00
Automation
4106d88338
Auto-publish so-tcpreplay image signature
2020-11-11 21:58:50 +00:00
Automation
93f57b73e2
Auto-publish so-pcaptools image signature
2020-11-11 21:57:37 +00:00
Automation
4fa0b6be0e
Auto-publish so-telegraf image signature
2020-11-11 21:56:53 +00:00
Automation
7ec2d85286
Auto-publish so-suricata image signature
2020-11-11 21:56:06 +00:00
Automation
763d5425a5
Auto-publish so-soctopus image signature
2020-11-11 21:55:11 +00:00
Automation
4be594cbb9
Auto-publish so-playbook image signature
2020-11-11 21:54:12 +00:00
Automation
e6fd3160ca
Auto-publish so-logstash image signature
2020-11-11 21:52:59 +00:00
Automation
07871987e4
Auto-publish so-influxdb image signature
2020-11-11 21:51:49 +00:00
Automation
3c33a38098
Auto-publish so-idstools image signature
2020-11-11 21:50:43 +00:00
Automation
b24bf9b6a9
Auto-publish so-filebeat image signature
2020-11-11 21:49:41 +00:00
Automation
373d9256f2
Auto-publish so-thehive image signature
2020-11-11 21:48:26 +00:00
Automation
dde7e0bd11
Auto-publish so-grafana image signature
2020-11-11 21:46:55 +00:00
Automation
017c9c9874
Auto-publish so-curator image signature
2020-11-11 21:45:36 +00:00
Automation
871f919c27
Auto-publish so-kratos image signature
2020-11-11 21:44:53 +00:00
Automation
f67c26a8f2
Auto-publish so-kibana image signature
2020-11-11 21:43:58 +00:00
Automation
038e8fceb7
Auto-publish so-wazuh image signature
2020-11-11 21:42:21 +00:00
weslambert
8c6adc21a8
Merge pull request #1891 from Security-Onion-Solutions/syslog_cef
...
Update syslog pipeline to allow for initial CEF parsing and pipeline …
2020-11-11 16:40:55 -05:00
Automation
75b26fb2af
Auto-publish so-redis image signature
2020-11-11 21:39:49 +00:00
Wes Lambert
8258b782fc
Update syslog pipeline to allow for initial CEF parsing and pipeline targeting
2020-11-11 21:39:40 +00:00
Automation
d73542d274
Auto-publish so-nginx image signature
2020-11-11 21:38:45 +00:00
Automation
1092aa2cb1
Auto-publish so-mysql image signature
2020-11-11 21:37:49 +00:00
Automation
8668cf9a9c
Auto-publish so-minio image signature
2020-11-11 21:36:45 +00:00
Automation
b9440364f7
Auto-publish so-fleet image signature
2020-11-11 21:35:44 +00:00
Automation
4f0ebfaf1f
Auto-publish so-zeek image signature
2020-11-11 21:34:50 +00:00
Automation
b090656269
Auto-publish so-acng image signature
2020-11-11 21:33:29 +00:00
Automation
16e0a26869
Auto-publish so-soc image signature
2020-11-11 21:30:17 +00:00
Automation
bc362acf82
Auto-publish so-soc image signature
2020-11-11 21:05:43 +00:00
Jason Ertel
79cbc747ea
Run leaktest on any branch
2020-11-11 15:52:48 -05:00
Mike Reeves
2269695e75
Change gpg to sig
2020-11-11 15:50:52 -05:00
Jason Ertel
710afe9355
Merge pull request #1889 from Security-Onion-Solutions/leaktest
...
Create leaktest.yml
2020-11-11 15:46:50 -05:00
Jason Ertel
ac236a0538
Move image sigs into versioned dir
2020-11-11 15:42:25 -05:00
Jason Ertel
eb7e8079ec
Create leaktest.yml
2020-11-11 15:39:06 -05:00
Mike Reeves
8512042132
Change Sig Path
2020-11-11 15:37:11 -05:00
Automation
a234e1c898
Auto-publish so-thehive-es image signature
2020-11-11 20:20:56 +00:00
Automation
25c91192a1
Auto-publish so-thehive-cortex image signature
2020-11-11 20:19:33 +00:00
Automation
22f19bbe9e
Auto-publish so-strelka-manager image signature
2020-11-11 20:18:03 +00:00
Automation
3b31a8d8cb
Auto-publish so-strelka-frontend image signature
2020-11-11 20:17:09 +00:00
Automation
cd868d1edb
Auto-publish so-strelka-filestream image signature
2020-11-11 20:16:30 +00:00
Automation
b31ea84c00
Auto-publish so-strelka-backend image signature
2020-11-11 20:15:36 +00:00
Automation
4ed6355186
Auto-publish so-logstash image signature
2020-11-11 20:14:14 +00:00
Automation
e51c2152fa
Auto-publish so-kibana image signature
2020-11-11 20:12:38 +00:00
Automation
7af1b7a539
Auto-publish so-fleet-launcher image signature
2020-11-11 20:11:29 +00:00
Automation
debbe965fe
Auto-publish so-filebeat image signature
2020-11-11 20:10:27 +00:00
Automation
3bbaca41c9
Auto-publish so-elasticsearch image signature
2020-11-11 20:09:30 +00:00
Automation
f2d25439e2
Auto-publish so-elasticsearch image signature
2020-11-11 20:08:10 +00:00
Automation
472fdd935e
Auto-publish so-domainstats image signature
2020-11-11 20:06:33 +00:00
Automation
14304c0f28
Auto-publish so-freqserver image signature
2020-11-11 20:05:36 +00:00
Automation
6a60890c36
Auto-publish so-elastalert image signature
2020-11-11 20:04:37 +00:00
Automation
687120ce4a
Auto-publish so-tcpreplay image signature
2020-11-11 20:03:28 +00:00
Automation
5e3f99c567
Auto-publish so-pcaptools image signature
2020-11-11 20:02:05 +00:00
Automation
c2ed0a6c72
Auto-publish so-telegraf image signature
2020-11-11 20:00:55 +00:00
Automation
8ed6a3ed78
Auto-publish so-suricata image signature
2020-11-11 19:59:46 +00:00
Automation
0511c851a2
Auto-publish so-soctopus image signature
2020-11-11 19:58:35 +00:00
Automation
0c7db56053
Auto-publish so-playbook image signature
2020-11-11 19:57:18 +00:00
Automation
7fae7500e8
Auto-publish so-logstash image signature
2020-11-11 19:55:41 +00:00
Automation
25b771d36f
Auto-publish so-influxdb image signature
2020-11-11 19:54:19 +00:00
Automation
6febc290a8
Auto-publish so-idstools image signature
2020-11-11 19:53:15 +00:00
Automation
9e9a023377
Auto-publish so-thehive image signature
2020-11-11 19:52:11 +00:00
Automation
f069b8cced
Auto-publish so-filebeat image signature
2020-11-11 19:50:50 +00:00
Automation
0d42bfb7f4
Auto-publish so-grafana image signature
2020-11-11 19:49:26 +00:00
Automation
4ccc898054
Auto-publish so-curator image signature
2020-11-11 19:48:16 +00:00
Automation
2010712929
Auto-publish so-kratos image signature
2020-11-11 19:47:11 +00:00
Automation
0ad0255e8c
Auto-publish so-kibana image signature
2020-11-11 19:46:20 +00:00
Automation
ca28cc7a17
Auto-publish so-wazuh image signature
2020-11-11 19:44:58 +00:00
Automation
0fce6823db
Auto-publish so-steno image signature
2020-11-11 19:43:44 +00:00
Automation
0db072d9b2
Auto-publish so-redis image signature
2020-11-11 19:42:27 +00:00
Automation
0c3a7a6214
Auto-publish so-nginx image signature
2020-11-11 19:41:26 +00:00
Automation
a58b487a0a
Auto-publish so-mysql image signature
2020-11-11 19:40:32 +00:00
Automation
061b8d5b9b
Auto-publish so-minio image signature
2020-11-11 19:39:38 +00:00
Automation
ff1dab283c
Auto-publish so-fleet image signature
2020-11-11 19:38:45 +00:00
Automation
319867ef10
Auto-publish so-zeek image signature
2020-11-11 19:38:01 +00:00
Automation
c21131b77a
Auto-publish so-acng image signature
2020-11-11 19:36:46 +00:00
Automation
638d9ddee3
Auto-publish so-soc image signature
2020-11-11 19:35:45 +00:00
Automation
dded28a54a
Auto-publish so-kibana image signature
2020-11-11 19:33:55 +00:00
Automation
7132011ece
Auto-publish so-steno image signature
2020-11-11 19:32:05 +00:00
Mike Reeves
3a622ee71e
Hash and sig update
2020-11-11 14:29:47 -05:00
Automation
fdc1468a11
Auto-publish so-wazuh image signature
2020-11-11 18:54:25 +00:00
Automation
691f64f8a3
Auto-publish so-nginx image signature
2020-11-11 18:53:13 +00:00
Mike Reeves
a29def504e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into gpg
2020-11-11 13:52:31 -05:00
Mike Reeves
8160ef104d
Merge pull request #1887 from Security-Onion-Solutions/scriptpids
...
Make sure scripts don't run if they are already running
2020-11-11 13:51:51 -05:00
Automation
52ee26c334
Auto-publish so-mysql image signature
2020-11-11 18:25:23 +00:00
Automation
d2c1fed2df
Auto-publish so-strelka-backend image signature
2020-11-11 18:14:28 +00:00
Automation
1521224100
Auto-publish so-strelka-filestream image signature
2020-11-11 18:12:47 +00:00
Automation
97f5f8438c
Auto-publish so-thehive-es image signature
2020-11-11 18:11:17 +00:00
Mike Reeves
978ba5b3ad
Update zeekloss.sh
2020-11-11 13:09:52 -05:00
Automation
80b926bc31
Auto-publish so-logstash image signature
2020-11-11 18:09:41 +00:00
Mike Reeves
a4df3623be
Update zeekcaptureloss.sh
2020-11-11 13:09:31 -05:00
Mike Reeves
4a80c37167
Update suriloss.sh
2020-11-11 13:09:08 -05:00
Mike Reeves
8e88c350d5
Update stenoloss.sh
2020-11-11 13:08:43 -05:00
Mike Reeves
a6a9f03cb0
Update redis.sh
2020-11-11 13:08:28 -05:00
Automation
3a9c9e3d99
Auto-publish so-strelka-frontend image signature
2020-11-11 18:08:03 +00:00
Automation
307af1248c
Auto-publish so-thehive-cortex image signature
2020-11-11 18:05:26 +00:00
Automation
0224adb7c8
Auto-publish so-strelka-manager image signature
2020-11-11 18:02:54 +00:00
Automation
f4a804b88c
Auto-publish so-fleet-launcher image signature
2020-11-11 17:58:56 +00:00
Automation
ea88fa7319
Auto-publish so-soctopus image signature
2020-11-11 17:56:28 +00:00
Mike Reeves
c9bfd8a253
Update oldpcap.sh
2020-11-11 12:55:28 -05:00
Mike Reeves
ee0e1ce8d7
Update influxdbsize.sh
2020-11-11 12:55:08 -05:00
Mike Reeves
814aa85dba
Update helixeps.sh
2020-11-11 12:54:48 -05:00
Mike Reeves
c5ddddda2a
Update checkfiles.sh
2020-11-11 12:54:31 -05:00
Mike Reeves
c75536db6d
Update so-curator-delete
2020-11-11 12:54:04 -05:00
Mike Reeves
c11d8367fa
Update so-curator-closed-delete-delete
2020-11-11 12:53:36 -05:00
Mike Reeves
8320421d42
Update so-curator-closed-delete
2020-11-11 12:53:05 -05:00
Automation
33bf799b47
Auto-publish so-freqserver image signature
2020-11-11 17:52:55 +00:00
Mike Reeves
047ab95e68
Update so-curator-close
2020-11-11 12:52:38 -05:00
Mike Reeves
2eb3378b62
Update so-curator-closed-delete
2020-11-11 12:50:59 -05:00
Automation
a354a6279b
Auto-publish so-idstools image signature
2020-11-11 17:49:25 +00:00
Mike Reeves
578250a994
Update so-curator-delete
2020-11-11 12:48:55 -05:00
Mike Reeves
e68f90c3b5
Update so-curator-closed-delete-delete
2020-11-11 12:48:28 -05:00
Automation
5a9211693c
Auto-publish so-kratos image signature
2020-11-11 17:48:03 +00:00
Automation
1e2df983af
Auto-publish so-redis image signature
2020-11-11 17:46:57 +00:00
Mike Reeves
d85c99abf3
Update so-curator-close
2020-11-11 12:46:44 -05:00
Mike Reeves
c0897c7e5a
Update so-curator-close
2020-11-11 12:46:19 -05:00
Automation
b4989c6c0e
Auto-publish so-minio image signature
2020-11-11 17:43:17 +00:00
Automation
7a79ef6ddb
Auto-publish so-zeek image signature
2020-11-11 17:41:08 +00:00
Automation
8aa3a508fa
Auto-publish so-acng image signature
2020-11-11 17:39:18 +00:00
Automation
b320a1d63e
Auto-publish so-fleet image signature
2020-11-11 17:12:03 +00:00
Automation
2a119d7824
Auto-publish so-soc image signature
2020-11-11 17:08:52 +00:00
Mike Reeves
73c17b77ae
Update zeekcaptureloss.sh
2020-11-11 11:43:48 -05:00
Mike Reeves
edb0d71e87
Update zeekloss.sh
2020-11-11 11:43:28 -05:00
Mike Reeves
6ff1922788
Update zeekcaptureloss.sh
2020-11-11 11:42:58 -05:00
Josh Patterson
758bee3a20
Merge pull request #1886 from Security-Onion-Solutions/issue/1681
...
Issue/1681
2020-11-11 11:40:08 -05:00
m0duspwnens
529da993aa
Merge remote-tracking branch 'remotes/origin/dev' into issue/1681
2020-11-11 11:39:08 -05:00
m0duspwnens
5a95159ec3
just use so-status.conf for containers to fix salt warning https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-11 11:38:48 -05:00
Automation
fc9c31706d
Auto-publish so-acng image signature
2020-11-11 16:31:42 +00:00
Mike Reeves
9548b3df54
Update stenoloss.sh
2020-11-11 11:23:20 -05:00
Mike Reeves
d3f65ac1a8
Update redis.sh
2020-11-11 11:22:52 -05:00
Mike Reeves
cb46c13054
Update oldpcap.sh
2020-11-11 11:22:28 -05:00
Mike Reeves
a4d3e109e6
Update influxdbsize.sh
2020-11-11 11:17:18 -05:00
Mike Reeves
711f5ab38f
Update helixeps.sh
2020-11-11 11:16:47 -05:00
Mike Reeves
ea1227de9d
Update checkfiles.sh
2020-11-11 11:16:15 -05:00
Mike Reeves
f9b52677d7
Update suriloss.sh
2020-11-11 11:15:45 -05:00
weslambert
533a65205f
Merge pull request #1885 from Security-Onion-Solutions/fix/syslog_application
...
Add check for field
2020-11-11 10:33:24 -05:00
weslambert
ea1f53b40c
Add check for field
2020-11-11 10:29:58 -05:00
Josh Patterson
0f4f029e92
Merge pull request #1883 from Security-Onion-Solutions/issue/1857
...
add top change for fleet getting mysql state back
2020-11-11 09:18:06 -05:00
m0duspwnens
da9a915421
add top change for fleet getting mysql state back was reverted in https://github.com/Security-Onion-Solutions/securityonion/pull/1880/files
2020-11-11 09:15:50 -05:00
weslambert
280fc501f9
Merge pull request #1882 from Security-Onion-Solutions/fix/extra_top_var
...
Fix duplicate vars
2020-11-11 08:53:43 -05:00
weslambert
625307ac5f
Fix duplicate vars
2020-11-11 08:52:39 -05:00
weslambert
44677ad521
Merge pull request #1880 from Security-Onion-Solutions/disable_elastic
...
Allow for disabling Elastic stack via pillar
2020-11-11 08:29:23 -05:00
Wes Lambert
1c326f561b
Allow for disabling Elastic stack via pillar
2020-11-11 13:26:59 +00:00
Josh Patterson
7b64f93bce
Merge pull request #1874 from Security-Onion-Solutions/issue/1681
...
Issue/1681
2020-11-10 17:57:48 -05:00
m0duspwnens
15f243f0ce
change names of acng and docker registry containers https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 17:51:00 -05:00
m0duspwnens
edb00c2058
remove redundant common from top, create so-status conf files on manager before registry state https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 17:09:38 -05:00
m0duspwnens
9e612e98ed
merge with dev
2020-11-10 15:43:40 -05:00
m0duspwnens
1fc94a8f59
change to so-acng for so-status https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:37:03 -05:00
m0duspwnens
c58039ab47
rename state https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:34:10 -05:00
m0duspwnens
1fca5e65df
redo how containers get added to so-status https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:31:47 -05:00
Mike Reeves
9a59ceee4e
move to so-image-common
2020-11-10 12:16:54 -05:00
Mike Reeves
c5bf9bf90d
rework soup and docker refresh
2020-11-10 12:05:08 -05:00
William Wernert
676b4f0777
[fix] Close connection in mysql_conn module
2020-11-10 11:42:40 -05:00
William Wernert
6557155a8a
Merge pull request #1868 from Security-Onion-Solutions/feature/improve-mysql-dep
...
Feature/improve mysql dep
2020-11-10 11:04:23 -05:00
William Wernert
d3227bbcb1
[refactor] Code cleanup pt. 3
2020-11-10 11:03:43 -05:00
William Wernert
7f218e5297
[feat] Also run query against mysql to ensure queries can complete
2020-11-10 11:02:34 -05:00
William Wernert
b3c527e7a9
[refactor] Code cleanup pt. 2
2020-11-10 10:05:06 -05:00
William Wernert
54d732a060
[refactor] Code cleanup
2020-11-10 10:01:10 -05:00
William Wernert
22b7de819c
[fix] Put mysql import in try,catch in case it hasn't been installed
2020-11-10 10:00:21 -05:00
William Wernert
dba30fb0ed
[refactor] Split 15 min mysql startup between two wait states
2020-11-10 09:48:20 -05:00
Mike Reeves
7ca8fefded
gpg sign images
2020-11-10 09:45:06 -05:00
Josh Patterson
95b24b1684
Merge pull request #1865 from Security-Onion-Solutions/issue/1864
...
make so-status line color same as service state
2020-11-09 18:17:05 -05:00
m0duspwnens
66cd91c0a7
make so-status line color same as service state https://github.com/Security-Onion-Solutions/securityonion/issues/1864
2020-11-09 18:16:02 -05:00
Josh Patterson
64199c81e1
Merge pull request #1863 from Security-Onion-Solutions/issue/1857
...
Issue/1857
2020-11-09 17:54:25 -05:00
m0duspwnens
ae5bc297dd
remove extra squigly https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 17:06:32 -05:00
m0duspwnens
f5a1bd4074
only try to get enrollsecret if fleet is already enabled https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 16:25:28 -05:00
m0duspwnens
407a655717
merge with dev
2020-11-09 15:29:19 -05:00
m0duspwnens
0e19594c97
enable fleet in global pillars before running fleet state during setup https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 15:25:11 -05:00
William Wernert
ff4d7a6cb6
[fix] Sync modules so states can use our modules during setup
2020-11-09 14:01:19 -05:00
William Wernert
f647a06239
[fix] Correct percentage steps
2020-11-09 13:37:42 -05:00
Josh Patterson
d122ca1ba3
Merge pull request #1861 from Security-Onion-Solutions/issue/1857
...
fix top logic for mysql for fleet/playbook
2020-11-09 13:16:28 -05:00
m0duspwnens
5616aa6beb
fix top logic for mysql - https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 13:12:45 -05:00
William Wernert
394fa727cb
[fix] Don't overwrite mysql module
2020-11-09 13:05:29 -05:00
William Wernert
9960cf0592
[feat] Add salt module to check if mysql is accepting db connections
2020-11-09 12:05:37 -05:00
weslambert
059c4e03e1
Merge pull request #1860 from Security-Onion-Solutions/strelka-parsing
...
Pull out additional fields from Exif info
2020-11-09 11:54:55 -05:00
Wes Lambert
7e578d2ce0
Pull out additional fields from Exif info
2020-11-09 16:53:53 +00:00
William Wernert
12125deecb
[feat] Show link state in whiptail menus
2020-11-09 11:06:08 -05:00
William Wernert
51256983da
[fix] Make sure pip is installed on Ubuntu
2020-11-06 08:53:30 -05:00
William Wernert
0718dbbd4d
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion into dev
2020-11-06 08:52:42 -05:00
William Wernert
6b2ab67c58
[fix] Bump version of navigator json to 3.0 + fix booleans
2020-11-06 08:52:36 -05:00
Josh Patterson
64fd27fd78
Merge pull request #1843 from Security-Onion-Solutions/issue/1536
...
increase so-status padding by 1
2020-11-05 19:10:06 -05:00
m0duspwnens
7eb0dab6c7
increase padding by 1 - https://github.com/Security-Onion-Solutions/securityonion/issues/1536
2020-11-05 19:08:19 -05:00
Josh Patterson
0caf054da0
Merge pull request #1842 from Security-Onion-Solutions/issue/1764
...
show if disabled regardless of highstate status
2020-11-05 18:50:09 -05:00
m0duspwnens
21b284fb10
show if disabled regardless of highstate status - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:46:11 -05:00
Josh Patterson
3d1412a138
Merge pull request #1841 from Security-Onion-Solutions/issue/1764
...
Issue/1764
2020-11-05 18:24:51 -05:00
m0duspwnens
c7b4a5351c
fix logic - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:17:11 -05:00
m0duspwnens
a95129b8c2
add color - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:03:42 -05:00
m0duspwnens
695bace3e8
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:54:10 -05:00
m0duspwnens
47cac59adb
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:52:28 -05:00
m0duspwnens
1a75ebdca3
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:51:51 -05:00
m0duspwnens
8da070d511
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:46:23 -05:00
William Wernert
d2ea197ce0
[fix] Remove old entry for manager from known_hosts
...
Resolves #1839
2020-11-05 14:40:00 -05:00
William Wernert
b528fe1a03
[fix] Only show analyst on network installs
...
Closes #1682
2020-11-05 14:39:04 -05:00
weslambert
3abe8cb397
Merge pull request #1836 from Security-Onion-Solutions/fix/wazuh_agent_register
...
Don't sleep if not registering agent
2020-11-05 14:03:32 -05:00
weslambert
2911e37b70
Don't sleep if not registering agent
2020-11-05 14:03:08 -05:00
William Wernert
4fed5c2518
Merge pull request #1822 from Security-Onion-Solutions/feature/setup-idempotency
...
Feature/setup idempotency
2020-11-05 13:48:18 -05:00
William Wernert
a5833f1f77
Merge branch 'dev' into feature/setup-idempotency
...
# Conflicts:
# setup/so-functions
2020-11-05 13:48:05 -05:00
William Wernert
b27b2e358b
[fix] Set MSRVIP variable before hosts file is overwritten
2020-11-05 13:38:08 -05:00
William Wernert
915aaf58f2
[fix] Always set MSRVIP because /etc/hosts is wiped
2020-11-05 13:28:21 -05:00
William Wernert
f058fb460d
[fix] Don't modify hosts file during whiptail menus
2020-11-05 13:25:02 -05:00
William Wernert
f7394559d4
[fix] Only add entry to /etc/hosts if unable to resolve hostname
2020-11-05 13:16:52 -05:00
Josh Patterson
ec3f35c360
Merge pull request #1832 from Security-Onion-Solutions/patch_2.3.3
...
Patch 2.3.3
2020-11-05 10:00:43 -05:00
Josh Patterson
fea6e6f4f9
Merge branch 'dev' into patch_2.3.3
2020-11-05 09:58:43 -05:00
William Wernert
cb75b2df65
[revert] Remove wazuh-agent package as well
2020-11-04 16:23:51 -05:00
William Wernert
4369b8d0f6
[fix] Remove wazuh-agent package as well
2020-11-04 16:14:58 -05:00
William Wernert
5cb8d0beda
[fix] Add -q flag to grep
2020-11-04 14:23:24 -05:00
William Wernert
b4446cba9a
[refactor][wip] Also backup directories in /nsm
2020-11-04 14:20:51 -05:00
William Wernert
1e41b9ba31
[fix] Add conditions for commands so they're less likely to fail
2020-11-04 14:20:26 -05:00
William Wernert
b2759c4c7c
[fix] Uninstall launcher if installed
2020-11-04 14:19:25 -05:00
Mike Reeves
6b144903fc
Update VERIFY_ISO.md
2020-11-04 13:47:37 -05:00
Mike Reeves
3825becd1b
Update changes.json
2020-11-04 13:44:52 -05:00
Mike Reeves
2aa21512e5
Update soup
2020-11-04 13:40:45 -05:00
William Wernert
3150367b1d
[fix] Add epoch string to /opt/so folder name
2020-11-04 12:52:37 -05:00
William Wernert
3ac9c43b7b
Merge branch 'dev' into feature/setup-idempotency
2020-11-04 12:44:14 -05:00
William Wernert
b643363e82
[fix] Directories need -r flag
2020-11-04 12:07:34 -05:00
Jason Ertel
8d5c29340e
Add screenshots to readme
2020-11-04 12:03:57 -05:00
Jason Ertel
1e9e156a87
Improve issue template directions
2020-11-04 11:49:22 -05:00
Jason Ertel
a364f13d24
Add issue template
2020-11-04 11:42:39 -05:00
William Wernert
3d70698647
[fix] Remove old mysql db directory
2020-11-04 11:26:56 -05:00
Mike Reeves
e989fc7041
Update map.jinja
2020-11-04 10:58:52 -05:00
William Wernert
49af35b440
[fix][wip] Add reinstall_init function (part 3)
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-04 10:38:48 -05:00
Mike Reeves
4592e2d4d7
add airgap option to upgradecommand
2020-11-04 10:08:01 -05:00
Mike Reeves
ec64314b70
Fix soup to clear yum cache for airgap
2020-11-04 10:00:44 -05:00
Mike Reeves
cf001875c2
Update soup
2020-11-03 20:14:15 -05:00
Mike Reeves
c7367eea38
Fix AGREPO Variable
2020-11-03 19:08:58 -05:00
William Wernert
db31cf3083
[refactor][fix] Remove old so-* containers, make fs changes after whiptail menus
2020-11-03 18:10:16 -05:00
Mike Reeves
8edb1529a9
Update soup
2020-11-03 17:36:53 -05:00
Mike Reeves
e8616e4d46
Update soup
2020-11-03 17:19:55 -05:00
William Wernert
3bf57382ce
[fix] Change when /opt/so is removed
2020-11-03 17:05:34 -05:00
Jason Ertel
def993f4ed
Improve salt version update comment
2020-11-03 16:50:22 -05:00
William Wernert
96ec483ae4
[fix][wip] Remove /opt/so directory during reinstall
2020-11-03 16:49:00 -05:00
William Wernert
6169758f4e
[fix] 0 -> root so file owner is set correctly
2020-11-03 16:47:59 -05:00
William Wernert
1c91e2d50b
[fix] Add minion_config variable so sed works
2020-11-03 15:48:08 -05:00
William Wernert
57e7e61f21
[fix] Don't add proxy to yum.conf on manager nodes
2020-11-03 15:45:19 -05:00
William Wernert
93ab4b5d4f
[fix][wip] Add reinstall_init function (part 2)
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-03 15:44:37 -05:00
William Wernert
00fc256c37
[fix][wip] Add reinstall_init function
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-03 14:51:35 -05:00
Mike Reeves
887f412e48
Remove docker_clean from docker_update function
2020-11-03 13:54:00 -05:00
Jason Ertel
aa9aa59213
Correct cheatsheetUrl for airgap installs
2020-11-03 12:27:55 -05:00
m0duspwnens
a859aa4f48
upgrade from salt 3001.1 to salt 3002.1 - https://github.com/Security-Onion-Solutions/securityonion/issues/1807
2020-11-03 11:54:28 -05:00
Jason Ertel
82a7b7e02d
Upgrade to Kratos 0.5.3-alpha1
2020-11-03 11:50:25 -05:00
Mike Reeves
85ea61bf98
Update VERSION
2020-11-03 11:40:03 -05:00
Mike Reeves
7f4b8e8183
Update README.md
2020-11-03 11:39:42 -05:00
Josh Patterson
1f8b139462
Merge pull request #1806 from Security-Onion-Solutions/issue/1782
...
Issue/1782
2020-11-03 11:23:22 -05:00
m0duspwnens
562a016579
remove more from sosetup.log
2020-11-03 10:23:56 -05:00
weslambert
e040009d0b
Merge pull request #1804 from Security-Onion-Solutions/fix/wazuh_api_creds_remove
...
Remove Wazuh API creds after registering initial agent
2020-11-03 09:57:58 -05:00
Wes Lambert
7dca988c11
Remove Wazuh API creds after registering intial agent
2020-11-03 14:53:50 +00:00
Mike Reeves
f007ef0ef5
Update so-functions
2020-11-02 17:00:02 -05:00
weslambert
bfe98433f6
Merge pull request #1789 from Security-Onion-Solutions/fix/zeek_intel
...
Add Zeek intel.dat
2020-11-02 16:38:16 -05:00
Wes Lambert
05549a2362
Add Zeek intel.dat
2020-11-02 21:36:44 +00:00
m0duspwnens
7e090b0894
dont echo salt minion config file to prevent mysql.pass from showing in sosetup.log
2020-11-02 16:23:34 -05:00
weslambert
8a645edb34
Merge pull request #1788 from Security-Onion-Solutions/feature/nids_rules
...
Allow for muliple files for rules
2020-11-02 16:05:53 -05:00
Wes Lambert
24a54a326c
Allow for muliple files for rules
2020-11-02 21:03:45 +00:00
Jason Ertel
184d163d65
Do not persist the Cortex PID file; This allows Cortex to recover from non-graceful container shutdowns, such as a power loss event on the host machine
2020-11-02 15:04:13 -05:00
weslambert
bb0cf9b8c7
Merge pull request #1784 from Security-Onion-Solutions/fix/strelka_exif_parsing
...
Fix/strelka exif parsing
2020-11-02 14:32:45 -05:00
Wes Lambert
3113d5fbdb
Format scan.exiftool as text
2020-11-02 19:31:14 +00:00
Wes Lambert
6420ee0310
Update parsing for scan.exiftool
2020-11-02 19:28:12 +00:00
William Wernert
033f5dbb9c
[fix] Use (mostly) absolute path when adding to PATH
2020-11-02 14:25:46 -05:00
William Wernert
1c4abcef15
[fix] Kill all jobs before checking if we can reach the salt master
2020-11-02 14:25:02 -05:00
Jason Ertel
2acb930a2e
fix: Remove crontab for automation installs
2020-11-02 11:08:45 -05:00
weslambert
37c630d6ab
Merge pull request #1776 from Security-Onion-Solutions/bugfix/af-packet-ring-size
...
Match max-pending-packets size
2020-11-02 08:39:21 -05:00
weslambert
71a260a000
Match max-pending-packets size
2020-11-02 08:38:45 -05:00
William Wernert
b489fee8b5
Merge pull request #1738 from Security-Onion-Solutions/bugfix/nginx-redirect
...
Bugfix/nginx redirect
2020-10-29 14:33:38 -04:00
William Wernert
91221c4332
[revert] Move proxy_pass back to ip
2020-10-29 10:23:12 -04:00
William Wernert
3abd1c9f16
[fix] Configure soctopus to use url_base
2020-10-28 16:08:19 -04:00
Mike Reeves
b14c1d0999
Merge pull request #1713 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:27:26 -04:00
Mike Reeves
13be0da484
Add a place where custom logstash certs can go
2020-10-28 15:26:41 -04:00
Mike Reeves
3385d98a2a
Merge pull request #1712 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:26:08 -04:00
Mike Reeves
361b13dc88
Add a place where custom logstash certs can go
2020-10-28 15:25:00 -04:00
Jason Ertel
98c669e80b
Disable nginx server version and TLSv1.0/TLSv1.1
2020-10-28 14:29:29 -04:00
William Wernert
b02d434a0e
[fix] Change any scripts using auth headers to url_base
2020-10-28 12:29:09 -04:00
William Wernert
3ee9f23d26
[fix] Use url_base in sensoroni.json instead of manager hostname
2020-10-28 12:28:34 -04:00
Jason Ertel
348c2feee2
Prevent usage of dollar signs in admin passwords during setup
2020-10-28 11:07:05 -04:00
Mike Reeves
b238c492e4
Update so-functions
2020-10-28 10:50:10 -04:00
Mike Reeves
97207bd006
Merge pull request #1702 from Security-Onion-Solutions/dockernet
...
Custom Docker IP Range
2020-10-28 10:48:56 -04:00
Mike Reeves
bed70ab6bf
Update whiptail menu for docker question
2020-10-28 10:19:15 -04:00
Mike Reeves
8173cb589b
Update whiptail menu for docker question
2020-10-28 10:17:53 -04:00
Mike Reeves
563a606e0e
Upodate dockernet menu
2020-10-28 10:14:14 -04:00
Mike Reeves
8d952eca7e
Upodate dockernet menu
2020-10-28 10:12:07 -04:00
Mike Reeves
8f7dffea4b
Upodate dockernet menu
2020-10-28 10:10:43 -04:00
weslambert
7ea8dc84b6
Merge pull request #1696 from Security-Onion-Solutions/feature/wazuh-user-mods
...
Add Wazuh user management scripts
2020-10-28 08:24:15 -04:00
Wes Lambert
453247971e
Add Wazuh user management scripts
2020-10-28 12:22:50 +00:00
Mike Reeves
741e17a637
add bip for docker
2020-10-27 18:21:53 -04:00
Mike Reeves
fedf334ee9
add bip for docker
2020-10-27 18:21:09 -04:00
Mike Reeves
8fee19ee1b
add bip for docker
2020-10-27 18:01:48 -04:00
Mike Reeves
697bc53aec
Dockernet Modifications
2020-10-27 15:08:34 -04:00
Jason Ertel
5a705fc0f2
Add Hunt quick action for hunted events, grouping by dataset and module
2020-10-27 12:30:33 -04:00
William Wernert
7b17b4abc7
Merge pull request #1680 from Security-Onion-Solutions/feature/setup-fixes
...
Feature/setup fixes
2020-10-27 12:17:21 -04:00
William Wernert
a043bc7cc4
[fix] Second if to elif
2020-10-27 12:16:19 -04:00
William Wernert
72dc267ab5
[fix] Menu sizing fixes
2020-10-27 12:14:44 -04:00
William Wernert
970be4d530
[fix] Change cd to relative
...
Since the script already changes to the correct dir, we can work from relative directories now.
2020-10-27 12:13:07 -04:00
Jason Ertel
474c4e54b4
Ensure labels and icons are associated with all quick actions
2020-10-27 12:04:57 -04:00
Mike Reeves
d4dd4aa416
Add missing comma in daemon.json
2020-10-27 11:25:45 -04:00
William Wernert
5054138be9
[feat] Add analyst option + add back helix option
2020-10-27 11:21:03 -04:00
William Wernert
83c23dd5de
[fix] Remove old got_root call
2020-10-27 11:20:39 -04:00
Mike Reeves
42e00514f5
Adding docker net setting
2020-10-27 11:09:14 -04:00
William Wernert
e75f8ba257
[fix] Move root check to top of so-setup
2020-10-27 09:39:29 -04:00
William Wernert
564ac3a4ff
Merge pull request #980 from Security-Onion-Solutions/feature/nginx-update
...
Feature/nginx update
2020-10-27 09:29:43 -04:00
William Wernert
c58deef2e0
Merge branch 'dev' into feature/nginx-update
2020-10-27 09:29:06 -04:00
Mike Reeves
0ad65c8cd4
Merge pull request #1568 from jtgreen-cse/patch-1
...
fix for rendering error >1 search node
2020-10-26 16:57:17 -04:00
William Wernert
0aaf8d6d9a
[fix] Change 301 to 307 so curl requests work as intended
2020-10-26 16:37:16 -04:00
William Wernert
37ede9b993
[wip] Redirect so-user-add to separate log so ERROR isn't in main log
2020-10-26 15:03:27 -04:00
Mike Reeves
5395983fc7
Merge pull request #1580 from Security-Onion-Solutions/feature/thehive-casetemplates
...
Add case_template field to Playbook alerts
2020-10-26 14:13:54 -04:00
William Wernert
3648e293a1
[fix] Add -L option to curl to respect redirects
2020-10-26 14:08:52 -04:00
Mike Reeves
12acc2e123
Merge pull request #1663 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERIFY_ISO.md
2020-10-26 13:10:18 -04:00
Mike Reeves
8d84718c91
Update VERIFY_ISO.md
2020-10-26 13:08:30 -04:00
Jason Ertel
3809573963
Correct cheatsheet URL for airgap installs
2020-10-26 12:16:55 -04:00
Jason Ertel
571550c019
Merge master into dev
2020-10-26 10:30:26 -04:00
William Wernert
e613bb3740
Merge branch 'dev' into feature/nginx-update
2020-10-26 10:28:14 -04:00
William Wernert
4662837075
[fix] Revert changes from merging dev
2020-10-26 10:25:16 -04:00
Mike Reeves
892ca294dc
Merge pull request #1655 from Security-Onion-Solutions/patch_2.3.2
...
2.3.2
2020-10-26 10:17:23 -04:00
Mike Reeves
45fd325307
Update VERIFY_ISO.md
2020-10-26 10:11:58 -04:00
Mike Reeves
653561ad95
Update VERIFY_ISO.md
2020-10-26 10:09:25 -04:00
Mike Reeves
f75badf43a
2.3.2 ISO info
2020-10-26 09:53:26 -04:00
Doug Burks
c61199618a
Update so-curator-closed-delete-delete
2020-10-24 07:15:43 -04:00
Mike Reeves
d9c021e86a
Update so-curator-closed-delete-delete
2020-10-23 17:07:16 -04:00
Mike Reeves
951f6ab3e2
Update VERIFY_ISO.md
2020-10-23 16:48:05 -04:00
Mike Reeves
da488945e0
Update VERIFY_ISO.md
2020-10-23 16:47:43 -04:00
Mike Reeves
b6f1cfada6
Update changes.json
2020-10-23 16:44:02 -04:00
Jason Ertel
85e0b2cab3
Add cheatsheet URL to soc.json
2020-10-23 16:35:35 -04:00
Mike Reeves
c8a6b232d5
Fix which field we return for Elastic index
2020-10-23 15:58:35 -04:00
William Wernert
fdb7cb90e3
[wip] Test alt variable usage
2020-10-23 15:36:01 -04:00
William Wernert
73b83584e6
[fix] Remove bad '_' character
2020-10-23 14:32:43 -04:00
Mike Reeves
801f4aae8e
Update README.md
2020-10-23 10:09:07 -04:00
Mike Reeves
c066cc67dc
Update VERSION
2020-10-23 10:08:45 -04:00
Josh Patterson
1185e43064
Merge pull request #1614 from Security-Onion-Solutions/issue/1573
...
Issue/1573 and Issue/1601
2020-10-22 15:57:40 -04:00
Mike Reeves
51ca661219
update wording for USB device vs CDROM
2020-10-22 14:54:34 -04:00
m0duspwnens
50a767ca6c
dont list aptcacherng in so-status if user chose open updates during setup - https://github.com/Security-Onion-Solutions/securityonion/issues/1573
2020-10-22 14:52:07 -04:00
Mike Reeves
174bbc6cd9
Update VERSION
2020-10-22 14:14:57 -04:00
William Wernert
6a08086dfa
[refactor] Make variable names consistent
2020-10-22 14:10:06 -04:00
Mike Reeves
a3579b88ae
Merge pull request #1604 from Security-Onion-Solutions/dev
...
2.3.1
2020-10-22 14:08:41 -04:00
William Wernert
6a3e921924
[fix] Fixes for fleet install
2020-10-22 13:09:26 -04:00
Mike Reeves
4a0796359b
Update README.md
2020-10-22 12:54:05 -04:00
m0duspwnens
0bfdef274b
update so-status to work with disabled containers - https://github.com/Security-Onion-Solutions/securityonion/issues/1601
2020-10-22 12:09:19 -04:00
Mike Reeves
92d397d573
Update ISO instructions
2020-10-22 11:59:39 -04:00
m0duspwnens
0b6b6e38fc
fix map for steno
2020-10-22 11:24:18 -04:00
m0duspwnens
aa59eff1ac
fix if statement
2020-10-22 10:59:03 -04:00
m0duspwnens
172ca9aa8d
add option to enable or disable to steno docker container - https://github.com/Security-Onion-Solutions/securityonion/issues/1601
2020-10-22 10:52:34 -04:00
William Wernert
79c4f07ff7
[fix] Don't listen on port 80 on all installs
2020-10-22 10:43:24 -04:00
Mike Reeves
460a391460
Update changes.json
2020-10-22 10:00:20 -04:00
Mike Reeves
905fcd06a6
Remove old 2.3.0 dockers
2020-10-22 08:51:40 -04:00
Josh Patterson
0b7f1fb189
Merge pull request #1594 from Security-Onion-Solutions/issue/1593
...
fix grabbing soversion in so-features-enable
2020-10-21 16:51:06 -04:00
m0duspwnens
712dc6b277
fix grabbing soversion in so-features-enable
2020-10-21 16:47:48 -04:00
Josh Patterson
b93709e05f
Merge pull request #1591 from Security-Onion-Solutions/issue/1590
...
fix arg for so-firewall addhostgroup
2020-10-21 15:48:02 -04:00
m0duspwnens
32294eb2ed
fix arg for so-firewall addhostgroup
2020-10-21 15:34:35 -04:00
Josh Patterson
2da656ff95
Merge pull request #1589 from Security-Onion-Solutions/issue/1551
...
only allow hosts in syslog host group to connect to manager type nodes
2020-10-21 14:41:50 -04:00
m0duspwnens
ef1e05db3e
only allow hosts in syslog host group to connect to manager type nodes
2020-10-21 14:41:03 -04:00
Josh Patterson
798abdbcde
Merge pull request #1584 from Security-Onion-Solutions/issue/1551
...
firewall to allow search nodes to connect to beats on manager
2020-10-21 12:50:49 -04:00
m0duspwnens
8805fef187
firewall to allow search nodes to connect to beats on manager
2020-10-21 12:43:28 -04:00
Josh Patterson
aafd365f2b
Merge pull request #1583 from Security-Onion-Solutions/issue/1551
...
add firewall rules for syslog
2020-10-21 11:21:18 -04:00
m0duspwnens
5f43380aa0
add firewall rules for syslog
2020-10-21 11:20:34 -04:00
Josh Brower
844ffe8fdf
nest case_template
2020-10-21 09:58:31 -04:00
Josh Brower
1e14d66f54
Add case_template field to Playbook alerts
2020-10-21 08:59:26 -04:00
weslambert
e2d95e0deb
Merge pull request #1576 from Security-Onion-Solutions/fix/comon_nids_rule_ruleset
...
Change rule_ruleset to rule.ruleset
2020-10-20 22:15:00 -04:00
weslambert
4765ef5f5c
Change rule_ruleset to rule.ruleset
2020-10-20 22:14:23 -04:00
William Wernert
d63358c8f0
[fix] Correct pillar reference + nginx errors
2020-10-20 14:30:06 -04:00
Jason Ertel
d37ddf584a
Correct quick action defaults
2020-10-20 14:12:23 -04:00
jtgreen-cse
eaa41266a2
fix for rendering error >1 search node
...
Fails rendering if you have more than one search node.
2020-10-20 13:24:53 -04:00
Mike Reeves
4a9fcfb8cf
Fix missing quote
2020-10-20 13:17:40 -04:00
Mike Reeves
a119d8f27d
Fix config for airgap installs
2020-10-20 11:28:49 -04:00
Josh Patterson
ba1dfcd774
Merge pull request #1554 from Security-Onion-Solutions/issue/1551
...
Issue/1551
2020-10-19 16:10:50 -04:00
m0duspwnens
10e4248cfc
and node that gets filebeat state now can listen for syslog - https://github.com/Security-Onion-Solutions/securityonion/issues/1551
2020-10-19 16:10:20 -04:00
William Wernert
42e285cfbe
Merge branch 'dev' into feature/nginx-update
...
# Conflicts:
# salt/nginx/etc/nginx.conf
# salt/nginx/etc/nginx.conf.so-eval
# salt/nginx/etc/nginx.conf.so-manager
# salt/nginx/etc/nginx.conf.so-standalone
2020-10-19 13:25:46 -04:00
m0duspwnens
79854f111e
add 514 tcp listener to filebeat docker and add syslog listener to fb config for manager and manager search - https://github.com/Security-Onion-Solutions/securityonion/issues/1551
2020-10-19 10:27:40 -04:00
Josh Patterson
a05329e7d8
Merge pull request #1532 from Masaya-A/patch-1
...
Grafana /nsm fix for eval/standalone
2020-10-16 16:48:12 -04:00
Masaya-A
47652ac080
Update eval.json
2020-10-17 04:45:12 +09:00
Masaya-A
964919109d
Update standalone.json
2020-10-17 04:35:39 +09:00
Jason Ertel
a968e5c23f
Increment version to 2.3.1
2020-10-16 10:57:31 -04:00
Mike Reeves
ba7b34a8ce
Merge pull request #1529 from Security-Onion-Solutions/dev
...
2.3.0 GA!
2020-10-16 10:53:53 -04:00
Mike Reeves
e2f16d51a6
Update VERIFY_ISO.md
2020-10-15 20:54:11 -04:00
Mike Reeves
42a6693101
Sig File for ISO
2020-10-15 20:36:08 -04:00
Jason Ertel
2326701cc0
Moved known issues underneath new changes
2020-10-15 19:29:33 -04:00
Jason Ertel
6ee37977c3
Fixed quotes and href targets
2020-10-15 19:25:26 -04:00
Mike Reeves
1ae35a39c3
Update changes.json
2020-10-15 19:11:55 -04:00
Mike Reeves
943aa82ce4
Update changes.json
2020-10-15 19:09:46 -04:00
Mike Reeves
131e105106
Update changes.json
2020-10-15 19:07:37 -04:00
Mike Reeves
cc56dc5a7f
Update changes.json
2020-10-15 19:05:47 -04:00
weslambert
657e251f51
Merge pull request #1528 from Security-Onion-Solutions/fix/kibana_ack
...
Update Kibana mappings for event ack/eslacation
2020-10-15 14:48:00 -04:00
Wes Lambert
d863f26f9d
Update Kibana mappings for event ack/eslacation
2020-10-15 18:46:37 +00:00
Mike Reeves
a7e0df84bb
Update README.md
2020-10-15 14:46:13 -04:00
William Wernert
1fdf431c12
[fix] so-user spelling+syntax fixes
...
* Consistent ending punctuation
* Consistent capitalization
* Correct comparison operators
2020-10-15 13:44:23 -04:00
Mike Reeves
35b10b1f91
Sensors should clean up their dockers as well
2020-10-15 10:31:51 -04:00
weslambert
36b9450a39
Merge pull request #1526 from Security-Onion-Solutions/fix/kibana_things
...
Intel mapping enforcement and winlog.verion
2020-10-15 08:43:34 -04:00
Wes Lambert
af9daa4d71
Intel mapping enforcement and winlog.verion
2020-10-15 12:42:33 +00:00
weslambert
c81ee9621d
Merge pull request #1525 from Security-Onion-Solutions/fix/kibana_discover_default
...
Fix default discover query
2020-10-14 17:44:55 -04:00
Wes Lambert
e7401b3e0c
Fix default discover query
2020-10-14 21:43:19 +00:00
weslambert
f2125242f9
Merge pull request #1523 from Security-Onion-Solutions/fix/strelka_file_mime_type
...
Rename file.flavors.mime to file.mime_type
2020-10-14 14:58:15 -04:00
Wes Lambert
54c4ee796f
Rename file.flavors.mime to file.mime_type
2020-10-14 18:56:44 +00:00
weslambert
8d4fd6c18d
Merge pull request #1522 from Security-Onion-Solutions/fix/pipeline_commmon_remove_ignore_missing
...
Fix common pipeline field removal so won't fail for missing fields
2020-10-14 09:56:34 -04:00
Wes Lambert
3c820365ab
Fix common pipeline field removal so won't fail for missing fields
2020-10-14 13:55:24 +00:00
Doug Burks
a106913d1a
Heavy node filebeat needs extra_hosts for the heavy node itself #1521
2020-10-14 09:51:59 -04:00
Josh Patterson
493c9a11df
Merge pull request #1520 from Security-Onion-Solutions/issue/1519
...
disable strelka by default for sensor nodes during setup
2020-10-14 09:38:50 -04:00
m0duspwnens
1283708186
disable strelka by default for sensor nodes during setup
2020-10-14 09:36:59 -04:00
Josh Patterson
2e62494793
Merge pull request #1518 from Security-Onion-Solutions/issue/1153
...
fix issue with schedule being placed in wrong location
2020-10-14 09:26:31 -04:00
Doug Burks
f88403e83e
use ssl on nodes that support it
2020-10-14 05:50:29 -04:00
m0duspwnens
a08d0c8b6f
fix issue with schedule being placed in wrong location
2020-10-13 18:24:44 -04:00
Josh Patterson
9f6fcb3763
Merge pull request #1516 from Security-Onion-Solutions/quickfix/managerestempalte
...
add elasticsearch template manager pillar and assign to manager node
2020-10-13 16:09:24 -04:00
m0duspwnens
1afa12e607
add elasticsearch template manager pillar and assign to manager node
2020-10-13 16:08:15 -04:00
Doug Burks
190869a1f2
enable https on elasticsearch nodes that support it
2020-10-13 16:04:55 -04:00
William Wernert
f6296c095f
[fix] Redirect stderr to stdout for crontab -l
2020-10-13 15:00:00 -04:00
Josh Patterson
15ea152b84
Merge pull request #1515 from Security-Onion-Solutions/issue/1511
...
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/1511
2020-10-13 14:17:28 -04:00
weslambert
4fff105986
Merge pull request #1514 from Security-Onion-Solutions/fix/replay_verbiage
...
Replay verbiage -- let users know when preparing to replay
2020-10-13 14:14:41 -04:00
Wes Lambert
3f8f0da468
Replay verbiage -- let users know when preparing to replay
2020-10-13 18:13:36 +00:00
m0duspwnens
2456605a54
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/1511
2020-10-13 14:10:24 -04:00
William Wernert
675db1da1b
[fix] Remove tab from string in whiptail menu
2020-10-13 13:44:51 -04:00
Doug Burks
0f68a53af4
Update so-curator-closed-delete-delete
2020-10-13 13:22:35 -04:00
Doug Burks
b004a9149e
Update so-index-list
2020-10-13 12:40:45 -04:00
Doug Burks
e5ece6cd50
Update so-index-list
2020-10-13 12:34:49 -04:00
Jason Ertel
2ad6ab7dfc
Dynamically alter docs URL based on airgap setting
2020-10-13 12:29:59 -04:00
Doug Burks
a75e986836
Update so-elastic-clear
2020-10-13 12:18:27 -04:00
Mike Reeves
c388966e7e
Add airgap config
2020-10-13 12:05:19 -04:00
William Wernert
0cd80de2b3
[fix] Hard code NIDS to Suricata since Snort is not yet supported
2020-10-13 10:31:44 -04:00
William Wernert
a459511812
Merge pull request #1512 from Security-Onion-Solutions/bugfix/whiptail-punctuation
...
Bugfix/whiptail punctuation
2020-10-13 10:26:26 -04:00
William Wernert
9dc491bd71
[refactor] Fixes per style guide
2020-10-13 10:23:47 -04:00
William Wernert
f5ea8325fe
[fix] Standardize input prompts
...
* All prompts that are questions end in "?"
* All other prompts end in ":"
* Any additional sentences after a prompt follow normal grammatical rules for punctuation
2020-10-13 09:45:32 -04:00
Doug Burks
ad50b5d640
elasticsearch _cat/indices output has changed between 6 and 7
2020-10-13 06:33:40 -04:00
Doug Burks
21b1becd7e
Update so-elasticsearch-pipelines-list
2020-10-12 16:34:30 -04:00
Doug Burks
5458c57cc9
Update so-elasticsearch-pipeline-stats
2020-10-12 16:32:11 -04:00
Doug Burks
68e34b781a
Update so-elasticsearch-templates-load
2020-10-12 16:10:38 -04:00
Doug Burks
4c43262610
Update so-elasticsearch-templates-list
2020-10-12 16:08:06 -04:00
weslambert
a17a2ad3de
Merge pull request #1507 from Security-Onion-Solutions/fix/zeek_smb_ts_common
...
Ensure Zeek logs without ts field have an @timestamp field associated
2020-10-12 13:21:15 -04:00
Wes Lambert
14559b081d
Ensure Zeek logs without ts field have an @timestamp field associated
2020-10-12 17:19:23 +00:00
weslambert
748ff0dbeb
Merge pull request #1506 from Security-Onion-Solutions/fix/index_dates
...
Fix/index dates
2020-10-12 11:45:08 -04:00
Wes Lambert
4fc4913d1e
Don't predefine index date for Filebeat ES outputs
2020-10-12 15:44:00 +00:00
Wes Lambert
884cc2d054
Don't predefine index date for Logstash outputs
2020-10-12 15:41:47 +00:00
Doug Burks
553ce3e363
only include extra_hosts if nodestab exists
2020-10-12 10:13:05 -04:00
Mike Reeves
e0fe63d263
Merge pull request #1505 from Security-Onion-Solutions/experimental
...
Fix Cross Cluster Search Acks
2020-10-12 09:24:16 -04:00
Mike Reeves
f5cfd480a3
Moar encryptions
2020-10-12 09:12:36 -04:00
Jason Ertel
3fff1451d4
Enable high strength cipher for golang compatibility
2020-10-11 22:31:29 -04:00
Mike Reeves
9695e63950
fix template statement
2020-10-11 17:21:57 -04:00
Mike Reeves
96083e1458
update logstash outputs
2020-10-11 17:06:56 -04:00
Mike Reeves
deb0f640d6
add jinja templates
2020-10-11 17:02:07 -04:00
Mike Reeves
b7c4fd94c4
get pipelines to load
2020-10-11 16:57:08 -04:00
Mike Reeves
e4ce17d4de
Turn on SSL output
2020-10-11 16:10:55 -04:00
Mike Reeves
a7bd1c2ce5
Turn on SSL output
2020-10-11 15:58:12 -04:00
Josh Patterson
c9c8c5e5f5
Merge pull request #1502 from Security-Onion-Solutions/quickfix/socrestart
...
watch all the files in the dir
2020-10-11 14:20:34 -04:00
m0duspwnens
c1e6c5688d
watch all the files in the dir
2020-10-11 14:19:44 -04:00
Mike Reeves
29c3948f95
Fix soc.json
2020-10-11 14:09:14 -04:00
Mike Reeves
31e0b5c81c
Add nodes to soc.json
2020-10-11 11:28:49 -04:00
Mike Reeves
73aade1223
Enable rest access from manager to sn
2020-10-11 11:02:20 -04:00
Mike Reeves
271e40337b
Enable jinja for tls
2020-10-11 10:57:04 -04:00
Mike Reeves
f6f9097cd9
Enable tls for 9200 on search capable nodes
2020-10-11 10:53:54 -04:00
Doug Burks
3cfee82b59
Update Hunt fields for firewall #1500
2020-10-10 08:18:00 -04:00
Doug Burks
87574181d5
Add Community ID to pfsense filterlog #1501
2020-10-10 08:11:51 -04:00
Doug Burks
5f15320b9d
Update Hunt fields for firewall #1500
2020-10-10 07:54:48 -04:00
Doug Burks
8d1ba1f4db
fix pfsense firewall udp parsing
2020-10-10 07:38:47 -04:00
Doug Burks
8cfabf101c
Update Hunt query for firewall #1499
2020-10-10 07:17:49 -04:00
Doug Burks
9aa4112de1
Remove extra comma
2020-10-10 06:10:10 -04:00
weslambert
12c3c351d8
Merge pull request #1498 from Security-Onion-Solutions/feature/filterlog
...
Feature/filterlog
2020-10-09 20:05:21 -04:00
Wes Lambert
28a1f7f88a
Remove pfsense tag
2020-10-10 00:03:51 +00:00
Wes Lambert
b55ffa44f8
Fix module,dataset rename
2020-10-10 00:01:37 +00:00
Wes Lambert
69a04dedd3
Filterlog config changes
2020-10-09 23:56:52 +00:00
Josh Patterson
930ec33cb7
Merge pull request #1496 from Security-Onion-Solutions/issue/1489
...
move salt master config file, copy salt-master service file and enabl…
2020-10-09 13:45:19 -04:00
m0duspwnens
6172268661
move salt master config file, copy salt-master service file and enable service restarts - https://github.com/Security-Onion-Solutions/securityonion/issues/1489
2020-10-09 13:27:46 -04:00
Josh Patterson
336400e642
Merge pull request #1495 from Security-Onion-Solutions/issue/1403
...
Issue/1403
2020-10-09 12:24:56 -04:00
m0duspwnens
ea1324e498
fix LOSS calc line
2020-10-09 11:54:39 -04:00
m0duspwnens
3f007b6af7
Merge remote-tracking branch 'remotes/origin/dev' into issue/1403
2020-10-09 11:40:01 -04:00
m0duspwnens
f5cacd66b8
correct zeekcaptureloss script to work on zeek standalone
2020-10-09 11:39:44 -04:00
Jason Ertel
40ff628c0b
Replace simple pillar lookup with salt equivalent to ensure quoted values are handled properly
2020-10-09 11:10:46 -04:00
William Wernert
97fce74263
[fix] Rename playbook key and add new admin/automation psswds
2020-10-09 09:59:08 -04:00
William Wernert
d7961fdbb8
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion into dev
2020-10-09 08:51:45 -04:00
William Wernert
5a8d776a62
[ix] Correct sls syntax
2020-10-09 08:51:35 -04:00
Josh Patterson
4af87ffcbe
Merge pull request #1492 from Security-Onion-Solutions/issue/1403
...
change capture loss to every 5 minutes and default grafana dashboard …
2020-10-08 17:52:52 -04:00
m0duspwnens
f38519247b
change capture loss to every 5 minutes and default grafana dashboard to 1h
2020-10-08 17:52:02 -04:00
William Wernert
065fe9042d
[fix] Make sure Playbook is up before creating user
2020-10-08 17:01:12 -04:00
weslambert
993aabedf2
Merge pull request #1491 from Security-Onion-Solutions/fix/so-elasticsearch-pipeline-stats-dots
...
Ensure pipelines with dots in names can be referenced
2020-10-08 15:41:44 -04:00
weslambert
06706d29f2
Ensure pipelines with dots in names can be referenced
2020-10-08 15:41:17 -04:00
weslambert
f41987024f
Merge pull request #1490 from Security-Onion-Solutions/feature/so-elastic-pipeline-stats
...
Add pipeline stats script
2020-10-08 15:12:55 -04:00
Wes Lambert
1efb39a71b
Add pipeline stats script
2020-10-08 19:11:41 +00:00
m0duspwnens
52e8265511
update is_airgap for soup
2020-10-08 14:16:19 -04:00
Mike Reeves
26317efe79
Update Soup
2020-10-08 14:05:52 -04:00
William Wernert
0795aa39ba
Merge pull request #1487 from Security-Onion-Solutions/feature/rotate-logs
...
Feature/rotate logs
2020-10-08 12:48:01 -04:00
William Wernert
2ad3f9da11
[fix] Wazuh not saving .log files anymore, only check .json files
2020-10-08 12:41:51 -04:00
William Wernert
034750fe5b
Merge branch 'dev' into feature/rotate-logs
...
# Conflicts:
# setup/so-functions
2020-10-08 12:36:30 -04:00
William Wernert
e1d8f578c2
[feat] Add log dirs for playbook + influxdb
2020-10-08 12:35:14 -04:00
Josh Patterson
2156adcf70
Merge pull request #1486 from Security-Onion-Solutions/fix/estemplates
...
fix templates not applying to searchnode.
2020-10-08 11:19:14 -04:00
m0duspwnens
e7abbf19af
fix templates not applying to searchnode. so-searchnode role doesnt exists searchnodes are so-node role
2020-10-08 11:17:26 -04:00
weslambert
0f5f781024
Merge pull request #1484 from Security-Onion-Solutions/fix/strelka_rule_null_safe_2
...
More fixes for rule field
2020-10-08 09:37:44 -04:00
Wes Lambert
a6d3dcf398
More fixes for rule field
2020-10-08 13:36:47 +00:00
weslambert
5e4bbcd4ca
Merge pull request #1483 from Security-Onion-Solutions/fix/strelka_rule_null_safe
...
Add null safe check for rule
2020-10-08 09:15:29 -04:00
Wes Lambert
a2e2f23a8d
Add null safe check for rule
2020-10-08 13:14:39 +00:00
weslambert
3ec9206b17
Merge pull request #1482 from Security-Onion-Solutions/fix/network_transport_kibana_viz
...
Fix network transport Kibana viz
2020-10-08 08:18:12 -04:00
Wes Lambert
adf0ef87c9
Fix network transport Kibana viz
2020-10-08 12:17:15 +00:00
weslambert
7767d3897b
Merge pull request #1481 from Security-Onion-Solutions/fix/network_transport_lower
...
Lowercase network.transport
2020-10-08 08:00:22 -04:00
weslambert
5ada85942b
Lowercase network.transport
2020-10-08 07:59:57 -04:00
Doug Burks
2489ca608a
Improve Hunt FTP queries #1479
2020-10-08 05:30:17 -04:00
Josh Patterson
0a982dec95
Merge pull request #1477 from Security-Onion-Solutions/issue/1403
...
Issue/1403
2020-10-07 17:47:21 -04:00
m0duspwnens
be7167d99b
Merge remote-tracking branch 'remotes/origin/dev' into issue/1403
2020-10-07 17:45:22 -04:00
m0duspwnens
821ce19aad
new dashboard for sensors
2020-10-07 17:38:16 -04:00
m0duspwnens
1bdc45ef0e
new dashboard for sensors
2020-10-07 17:37:11 -04:00
m0duspwnens
4f8bb9c2f1
updates to standalone and eval dashboards
2020-10-07 16:48:29 -04:00
m0duspwnens
7dd839cfa2
add zeek capture loss graph and resize redis queue for standalone
2020-10-07 15:53:31 -04:00
weslambert
7befff3baa
Merge pull request #1474 from Security-Onion-Solutions/fix/common_nids
...
Don't use regex for determining rule type
2020-10-07 12:16:55 -04:00
Wes Lambert
7543144afe
Don't use regex for determining rule type
2020-10-07 16:15:43 +00:00
weslambert
7787f81bdd
Merge pull request #1473 from Security-Onion-Solutions/fix/logstash_output_wazuh
...
Remove dataset name since pipeline no longer in use
2020-10-07 11:49:40 -04:00
weslambert
8e829b47ae
Remove dataset name since pipeline no longer in use
2020-10-07 11:48:56 -04:00
m0duspwnens
8540a691dc
only send loss if timestamp on data has changed
2020-10-07 11:23:06 -04:00
weslambert
8015676e01
Merge pull request #1472 from Security-Onion-Solutions/fix/rename-signature_info
...
Change rule.signature_info to rule.reference and ensure common.nids e…
2020-10-07 11:21:18 -04:00
Wes Lambert
015a441e79
Change rule.signature_info to rule.reference and ensure common.nids exists
2020-10-07 15:20:26 +00:00
weslambert
a1866e5229
Merge pull request #1471 from Security-Onion-Solutions/fix/ingest-updates
...
Fix/ingest updates
2020-10-07 11:15:55 -04:00
m0duspwnens
1106b2bf96
only send loss if timestamp on data has changed
2020-10-07 11:15:10 -04:00
Wes Lambert
f0a1457ffd
Update common.nids
2020-10-07 15:14:08 +00:00
m0duspwnens
d09f0f841e
only send loss if timestamp on data has changed
2020-10-07 11:13:03 -04:00
m0duspwnens
6f2d47cc40
only send loss if timestamp on data has changed
2020-10-07 11:11:06 -04:00
m0duspwnens
2317e8b348
only send loss if timestamp on data has changed
2020-10-07 11:08:41 -04:00
m0duspwnens
f96d6ae4f4
only send loss if timestamp on data has changed
2020-10-07 11:06:54 -04:00
m0duspwnens
5e534571ff
set timestamp with capture loss
2020-10-07 10:20:51 -04:00
m0duspwnens
14dd80b410
handle whitespace
2020-10-06 18:46:32 -04:00
m0duspwnens
af2df2c7d1
just print the loss
2020-10-06 18:44:22 -04:00
m0duspwnens
f95712c502
update log file
2020-10-06 18:38:51 -04:00
m0duspwnens
48ca2cdff1
fix pillars we check
2020-10-06 18:10:41 -04:00
m0duspwnens
4a236b3f75
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1403
2020-10-06 18:05:47 -04:00
m0duspwnens
73ce948d42
add zeekcaptureloss to data to influxdb. rename broloss to zeekloss - https://github.com/Security-Onion-Solutions/securityonion/issues/1403
2020-10-06 18:05:41 -04:00
Mike Reeves
fd4bb81f29
Fix ZEEKLOGS pillar
2020-10-06 17:38:05 -04:00
William Wernert
d84f85335e
[fix] Add jinja option, missing log dirs, compress option
2020-10-06 17:18:39 -04:00
Wes Lambert
8c07c098f6
Pipeline cleanup
2020-10-06 20:14:15 +00:00
Wes Lambert
350cc41740
Let zeek.common handle common fields for zeek.tunnels
2020-10-06 20:12:23 +00:00
William Wernert
b64a91f13c
[refactor] Remove nocompress option
2020-10-06 14:51:43 -04:00
William Wernert
27351fa520
[fix] Correct jinja syntax + indent all lines
2020-10-06 14:51:42 -04:00
Josh Patterson
7d14c68d70
Merge pull request #1468 from Security-Onion-Solutions/issue/163
...
fix yum db if corrupted -
2020-10-06 14:29:11 -04:00
m0duspwnens
035d215398
fix yum db if corrupted - https://github.com/Security-Onion-Solutions/securityonion/issues/163
2020-10-06 14:28:01 -04:00
Josh Patterson
51d3defe76
Merge pull request #1467 from Security-Onion-Solutions/issue/1460
...
Issue/1460
2020-10-06 14:06:01 -04:00
m0duspwnens
3d71766b64
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1460
2020-10-06 13:58:02 -04:00
m0duspwnens
34dfc809c7
handle thread count for suricata and default max-pending-packets to 5000 - https://github.com/Security-Onion-Solutions/securityonion/issues/1460
2020-10-06 13:57:50 -04:00
Mike Reeves
f809cf5216
Update so-functions
2020-10-06 13:27:23 -04:00
William Wernert
bd4292711e
[fix] Redirect missing lines to global pillar
2020-10-06 13:23:26 -04:00
William Wernert
9737b01676
[feat] Move logrotate configuration settings to pillar
2020-10-06 13:22:44 -04:00
William Wernert
94f15c63ce
[fix] Correct indent in common init.sls
2020-10-06 13:21:37 -04:00
weslambert
a16419b997
Merge pull request #1466 from Security-Onion-Solutions/fix/so-elasticsearch-templates-load
...
Rename so-elasticsearch-templates to so-elasticsearch-templates-load
2020-10-06 13:19:54 -04:00
Wes Lambert
a6a69c57d1
Rename so-elasticsearch-templates to so-elasticsearch-templates-load
2020-10-06 17:18:42 +00:00
weslambert
6cdff854f3
Merge pull request #1465 from Security-Onion-Solutions/feature/so-elasticsearch-templates-list
...
Add so-elasticsearch-templates-list
2020-10-06 13:16:11 -04:00
Wes Lambert
787f1d8732
Add so-elasticsearch-templates-list
2020-10-06 17:15:27 +00:00
weslambert
1a2921c2bc
Merge pull request #1463 from Security-Onion-Solutions/feature/so-elasticsearch-pipelines-list
...
Add so-elasticsearch-pipelines-list and fix common script perms
2020-10-06 13:04:24 -04:00
Wes Lambert
4a5d50cf80
Add so-elasticsearch-pipelines-list and fix common script perms
2020-10-06 17:01:58 +00:00
Josh Patterson
1b3eca80d7
Merge pull request #1462 from Security-Onion-Solutions/issue/1371
...
handle install locations of files copied
2020-10-06 11:41:37 -04:00
m0duspwnens
5eada1cdd5
handle install locations of files copied
2020-10-06 11:39:34 -04:00
Josh Patterson
4b1a8d7512
Merge pull request #1461 from Security-Onion-Solutions/issue/1371
...
Issue/1371
2020-10-06 11:22:58 -04:00
m0duspwnens
a5f4c96db0
qol user interaction improvements to analyst install
2020-10-06 11:19:43 -04:00
m0duspwnens
4eea0a464c
include remaining log functions from so-functions
2020-10-06 10:57:43 -04:00
m0duspwnens
7840002d18
update log file in title func
2020-10-06 10:51:31 -04:00
m0duspwnens
85168e9318
add title function
2020-10-06 10:49:38 -04:00
m0duspwnens
2420cd5db1
add some system characteristics to log like normal install does
2020-10-06 10:46:11 -04:00
Doug Burks
a686704d37
remove rule.uuid now that underlying issue has been resolved
2020-10-06 09:39:57 -04:00
weslambert
706c81daca
Merge pull request #1459 from Security-Onion-Solutions/feature/strelka_yara_alert
...
Add Strelka YARA matches as alerts
2020-10-06 08:23:16 -04:00
Wes Lambert
019bec992d
Add Strelka YARA matches as alerts
2020-10-06 12:19:44 +00:00
Josh Patterson
e2a787095c
Merge pull request #1458 from Security-Onion-Solutions/issue/1290
...
change for network miner 2.6 - https://github.com/Security-Onion-Solu…
2020-10-05 18:38:14 -04:00
m0duspwnens
acabcd27a7
change for network miner 2.6 - https://github.com/Security-Onion-Solutions/securityonion/issues/1290
2020-10-05 18:17:24 -04:00
Josh Patterson
24ff34ee81
Merge pull request #1457 from Security-Onion-Solutions/issue/1371
...
Issue/1371
2020-10-05 15:51:35 -04:00
Josh Brower
2e012432b4
Merge pull request #1455 from Security-Onion-Solutions/feature/training-req
...
Write out nested json
2020-10-05 15:34:43 -04:00
Josh Brower
de9ace62d4
Write out nested json
2020-10-05 15:34:02 -04:00
Josh Patterson
faf5e7a643
Merge pull request #1454 from Security-Onion-Solutions/issue/1444
...
logstash changes per https://github.com/Security-Onion-Solutions/secu…
2020-10-05 14:12:05 -04:00
m0duspwnens
748dc5ba91
logstash changes per https://github.com/Security-Onion-Solutions/securityonion/issues/1444
2020-10-05 14:10:05 -04:00
William Wernert
5dfd11a018
[feat] Add wazuh archive cleanup + fix indentation
2020-10-05 13:58:49 -04:00
William Wernert
e6cb75ce7e
[feat] Add common logrotate cron+config
2020-10-05 13:57:36 -04:00
Josh Patterson
f7daa391c7
Merge pull request #1453 from Security-Onion-Solutions/issue/1441
...
enable suricata threshold-file and point to proper file
2020-10-05 12:56:39 -04:00
Doug Burks
a45aa43f41
Add trailing comma to "thehive" stanza
2020-10-05 12:35:33 -04:00
m0duspwnens
63884b73e1
enable suricata threshold-file and point to proper file - https://github.com/Security-Onion-Solutions/securityonion/issues/1441
2020-10-05 12:10:52 -04:00
weslambert
9f4cb42c4f
Merge pull request #1452 from Security-Onion-Solutions/fix/kibana_case_create
...
Change alert to case
2020-10-05 11:46:14 -04:00
Wes Lambert
575da0f9d3
Change alert to case
2020-10-05 15:45:10 +00:00
weslambert
f4fcc052ca
Merge pull request #1451 from Security-Onion-Solutions/fix/wazuh_rule_cat
...
Put back rule.category for Wazuh alerts
2020-10-05 11:35:20 -04:00
weslambert
bc31e19e37
Put back rule.category for Wazuh alerts
2020-10-05 11:34:29 -04:00
weslambert
6e2319f6da
Merge pull request #1449 from Security-Onion-Solutions/fix/wazuh_logging
...
Adjust Wazuh logging so we don't log alerts to a separate file and so…
2020-10-05 10:04:01 -04:00
weslambert
968dce0aee
Adjust Wazuh logging so we don't log alerts to a separate file and so we don't write a separate log file for non-JSON for archives
2020-10-05 10:03:40 -04:00
Jason Ertel
1ebe970876
Disable escalate button if thehive is not enabled
2020-10-05 09:54:18 -04:00
weslambert
6b292ea62b
Merge pull request #1448 from Security-Onion-Solutions/fix/so_elastic_clear
...
Fix/so elastic clear
2020-10-05 09:40:04 -04:00
Wes Lambert
da8957b4f4
Use Elasticsearch pillar vs manager IP for so-elastic-clear
2020-10-05 13:37:06 +00:00
Wes Lambert
1970d95d5f
Make Filebeat registry persistent to avoid re-reading old data
2020-10-05 13:30:04 +00:00
Doug Burks
e7cba6ba1d
Change SOC Alerts eventFetchLimit from 5000 to 500 #1447
2020-10-05 09:29:01 -04:00
Doug Burks
948e0c4c61
Add rule.name to Hunt Wazuh Alerts query #1442
2020-10-05 09:26:13 -04:00
Jason Ertel
cf5b1245ea
Add configurable flags to enable/disable dismiss and escalate buttons
2020-10-05 09:16:17 -04:00
weslambert
771d091d6e
Merge pull request #1446 from Security-Onion-Solutions/feature/wazuh_severity
...
Add event.severity and event.severity_label config for Wazuh alerts
2020-10-05 08:52:20 -04:00
Wes Lambert
77d31cb289
Add event.severity and event.severity_label config for Wazuh alerts
2020-10-05 12:50:29 +00:00
weslambert
203e84d2cf
Update comma verbiage for HOME_NET in whiptail menu
2020-10-05 08:08:22 -04:00
Josh Brower
7b05cf4266
Merge pull request #1443 from Security-Onion-Solutions/feature/training-req
...
Feature/training req
2020-10-04 21:37:03 -04:00
Josh Brower
8a78485906
Config Playbook SOC Alerts
2020-10-04 21:35:42 -04:00
Josh Brower
c80b6ce104
Add so-allow-view and playbook event.sev.label
2020-10-04 20:39:21 -04:00
m0duspwnens
467e5b34cc
analyst node changes
2020-10-02 16:40:25 -04:00
m0duspwnens
20307b703e
analyst node changes
2020-10-02 16:21:31 -04:00
m0duspwnens
6a0f04d24a
analyst node changes
2020-10-02 16:14:15 -04:00
m0duspwnens
5a5007c07d
analyst node changes
2020-10-02 15:50:49 -04:00
m0duspwnens
fde6f128ab
analyst node changes
2020-10-02 15:26:13 -04:00
m0duspwnens
1be3323265
analyst node changes
2020-10-02 15:25:42 -04:00
m0duspwnens
47762816a7
analyst node changes
2020-10-02 14:57:22 -04:00
m0duspwnens
40647ce54c
analyst node changes
2020-10-02 14:40:15 -04:00
William Wernert
8310559273
Merge pull request #1440 from Security-Onion-Solutions/feature/generate-playbook-api-key
...
Feature/generate playbook api key
2020-10-02 14:37:58 -04:00
William Wernert
2a100c0dcc
Add OLD_ prefix + only update rules if playbook enabled
2020-10-02 14:34:30 -04:00
William Wernert
d0c267ca90
Fix sed command to not delete lines after match
2020-10-02 14:31:16 -04:00
William Wernert
54da2b869c
Add OLD_ db init files for soup compatibility
2020-10-02 14:12:23 -04:00
William Wernert
ab662e9b81
Merge branch 'dev' into feature/generate-playbook-api-key
...
# Conflicts:
# salt/common/tools/sbin/soup
2020-10-02 13:48:52 -04:00
William Wernert
db12b6f3c6
Remove salt call to automation_user_create
2020-10-02 13:17:57 -04:00
William Wernert
96d32fda51
Add old api key to pillar during soup
2020-10-02 13:16:58 -04:00
Mike Reeves
15f0c98281
Fix Formatting
2020-10-02 13:06:03 -04:00
m0duspwnens
d0da7ade6a
analyst node changes
2020-10-02 12:15:00 -04:00
m0duspwnens
c4e0fa0939
analyst node changes
2020-10-02 12:12:28 -04:00
m0duspwnens
e11717c4d0
analyst node changes
2020-10-02 11:28:53 -04:00
m0duspwnens
76a13e99da
new wallpaper
2020-10-02 10:12:36 -04:00
William Wernert
20fd757847
Run playbook-ruleupdate after soctopus is running
2020-10-02 10:05:10 -04:00
William Wernert
39e14b3910
Merge branch 'dev' into feature/generate-playbook-api-key
2020-10-02 08:39:09 -04:00
Mike Reeves
c7fcdc8084
Merge pull request #1438 from Security-Onion-Solutions/socyaml
...
Socyaml
2020-10-01 18:08:33 -04:00
Mike Reeves
4991ea8de3
Jason made me rename json
2020-10-01 18:07:06 -04:00
Mike Reeves
36ccece724
commas gone crazy
2020-10-01 18:02:06 -04:00
Mike Reeves
a0432e97b0
Python print ftl
2020-10-01 17:57:56 -04:00
m0duspwnens
733b1376c5
analyst node changes
2020-10-01 17:53:20 -04:00
Mike Reeves
490278a4c3
Add alert events filed
2020-10-01 17:49:17 -04:00
Mike Reeves
bd5efbabd9
Fix Mode
2020-10-01 17:43:43 -04:00
Mike Reeves
8fa426f265
Cleanup sync
2020-10-01 17:41:55 -04:00
Mike Reeves
9d9d3aac53
Switch to JSON from yaml
2020-10-01 17:37:57 -04:00
Mike Reeves
744a8bca73
More json for soc
2020-10-01 17:30:23 -04:00
Mike Reeves
8a41636e7f
More json for soc
2020-10-01 17:28:45 -04:00
Mike Reeves
dc79dca7fe
More json for soc
2020-10-01 17:25:51 -04:00
Mike Reeves
1c55f738ec
More json for soc
2020-10-01 17:23:29 -04:00
William Wernert
e98012ae2c
Fix jinja and change state orrder in setup
2020-10-01 17:16:26 -04:00
Mike Reeves
92fa33159e
More json for soc
2020-10-01 17:12:08 -04:00
m0duspwnens
72c6fe2184
analyst node changes
2020-10-01 17:05:59 -04:00
Mike Reeves
5730c85988
More json for soc
2020-10-01 17:04:15 -04:00
Mike Reeves
63be0734c9
More json for soc
2020-10-01 17:00:25 -04:00
Mike Reeves
5653828154
More json for soc
2020-10-01 16:57:04 -04:00
weslambert
2d2f4de337
Merge pull request #1437 from Security-Onion-Solutions/fix/kib_scripted_thehive
...
Update scripted field for TheHive case
2020-10-01 16:54:02 -04:00
Wes Lambert
8a81a5148b
Update scripted field for TheHive case
2020-10-01 20:52:57 +00:00
weslambert
98bef8fb9d
Merge pull request #1436 from Security-Onion-Solutions/fix/kibana_soc_thehive_case
...
Add SOC url for api integration
2020-10-01 16:47:11 -04:00
Wes Lambert
eced18c3cc
Add SOC url for api integration
2020-10-01 20:29:28 +00:00
Jason Ertel
8e15ed56d6
'Escalated' filter toggle will auto-enable 'acknowledged' filter toggle
2020-10-01 16:23:47 -04:00
m0duspwnens
76c98200f3
analyst node changes
2020-10-01 16:21:51 -04:00
Mike Reeves
cc2f2de5b5
soc.json stuff
2020-10-01 15:23:07 -04:00
Mike Reeves
b423e8d22a
soc.json stuff
2020-10-01 15:20:13 -04:00
Mike Reeves
1a561f6b12
soc.json stuff
2020-10-01 15:18:34 -04:00
William Wernert
a5bf4bbb35
Fix test for key in global.sls
2020-10-01 14:47:18 -04:00
m0duspwnens
964bad4657
analyst node changes
2020-10-01 13:53:38 -04:00
Doug Burks
e836f96c65
move rule.uuid after rule.name
2020-10-01 12:09:52 -04:00
Doug Burks
4851069a10
remove rule.gid from Alerts groupby since Wazuh and Playbook may not have that field
2020-10-01 11:51:40 -04:00
William Wernert
040730e8f5
Rename script for consistent naming
2020-10-01 11:22:11 -04:00
William Wernert
afb777fc8f
Add automation user creation to soup when resetting playbook db
2020-10-01 11:13:24 -04:00
m0duspwnens
75d49845f2
changes to analyst setup script
2020-10-01 10:43:33 -04:00
Doug Burks
bc19cce4c2
Acknowledging an alert may acknowledge more alerts than intended #1426
2020-10-01 10:00:54 -04:00
Doug Burks
26781de244
Add Strelka query to Hunt #1433
2020-10-01 06:59:36 -04:00
William Wernert
2264b6e51c
Add comments to shell code explaining curl statements
2020-09-30 19:54:34 -04:00
William Wernert
03b97cce75
Fix comment in new state + remove useless sleep command
2020-09-30 19:49:13 -04:00
William Wernert
11ae904100
Quiet script output + fix pillar value
2020-09-30 19:46:18 -04:00
weslambert
6818de9e64
Merge pull request #1431 from Security-Onion-Solutions/fix/elastlert_rules
...
Remove rule sync, since we don't have any rules to sync
2020-09-30 18:36:11 -04:00
weslambert
887937a75d
Remove rule sync, since we don't have any rules to sync
2020-09-30 18:35:35 -04:00
William Wernert
596f2d31e4
Automation -> automation
2020-09-30 17:04:24 -04:00
William Wernert
3ec255ecee
Remove old api token from sql
2020-09-30 17:03:35 -04:00
William Wernert
6361c790e9
Move automation user create to separate script to run after playbook state
2020-09-30 17:02:02 -04:00
William Wernert
8e80b41ca9
Remove Automation user from sql, gen user + store api key
2020-09-30 16:32:43 -04:00
Jason Ertel
1454201505
Disable thehivealerter
2020-09-30 15:26:29 -04:00
Jason Ertel
3af6e9e1fe
Remove mount point for SOCtopus generated playbook rules to avoid them activating and sending alerts to TheHive
2020-09-30 15:14:45 -04:00
Mike Reeves
8b5ff31351
Merge pull request #1430 from Security-Onion-Solutions/redis
...
Add Redis pillar and fix idstools
2020-09-30 15:09:59 -04:00
Mike Reeves
7314e2dea8
Add Redis pillar and fix idstools
2020-09-30 15:08:44 -04:00
Jason Ertel
ff04bb507a
Remove default Elastalert rules to stop automated alerts from being sent to thehive
2020-09-30 15:06:54 -04:00
weslambert
5b16a65422
Merge pull request #1429 from Security-Onion-Solutions/fix/zeek_server_ip
...
Fix issue with null Zeek server IP
2020-09-30 13:54:50 -04:00
Wes Lambert
02d2e5e2c6
Fix isue with null Zeek server IP
2020-09-30 17:53:30 +00:00
William Wernert
f3b8da1f9d
Fix Engrish (can causing -> can cause)
2020-09-30 13:40:57 -04:00
William Wernert
25d4bde33b
Merge pull request #1428 from Security-Onion-Solutions/feature/warn-dhcp
...
Add warning about IP address changing for network/DHCP iso installs
2020-09-30 13:13:40 -04:00
William Wernert
1ff20f7e27
Add warning about IP address changing for network/DHCP iso installs
2020-09-30 13:11:33 -04:00
weslambert
defe832121
Merge pull request #1427 from Security-Onion-Solutions/fix/wazuh_filebeat
...
Fix Filebeat config for Wazuh
2020-09-30 10:59:01 -04:00
Wes Lambert
d8f70397f7
Fix Filebeat config for Wazuh
2020-09-30 14:57:56 +00:00
weslambert
dac2ad5dbf
Merge pull request #1425 from Security-Onion-Solutions/feature/soctopus_pillar
...
Add initial implementation of SOCtopus pillar
2020-09-30 10:25:26 -04:00
Wes Lambert
c62acf5e4e
Add initial implmentation of SOCtopus pillar
2020-09-30 14:24:15 +00:00
Josh Patterson
10f4e09b70
Merge pull request #1424 from Security-Onion-Solutions/issue/1070
...
Issue/1070
2020-09-30 10:11:37 -04:00
William Wernert
00785c6ba5
Merge pull request #1418 from Security-Onion-Solutions/feature/replace-hardcoded-pass
...
Feature/replace hardcoded pass
2020-09-30 08:56:35 -04:00
Doug Burks
0a995f4a7a
Update README.md
2020-09-30 07:43:20 -04:00
m0duspwnens
85969dc16d
add quotes and remove quotes
2020-09-29 16:29:05 -04:00
m0duspwnens
bf99bab6c0
add quotes and remove quotes
2020-09-29 16:26:45 -04:00
weslambert
401764437f
Merge pull request #1421 from Security-Onion-Solutions/fix/ip_type
...
Ensure IPs are typed as IP and ports as integer
2020-09-29 14:21:25 -04:00
Wes Lambert
36019727b3
Ensure IPs are typed as IP and ports as integer
2020-09-29 18:20:15 +00:00
m0duspwnens
547c3ff52c
single quote inputs to yaml files
2020-09-29 13:59:16 -04:00
William Wernert
7d43d48aca
Remove bad line in playbook_db_init.sh
2020-09-29 11:13:09 -04:00
William Wernert
55058a11aa
Generate passwords for Grafana + Playbook default users
2020-09-29 11:12:09 -04:00
William Wernert
ebe00822f8
Merge pull request #1417 from Security-Onion-Solutions/bugfix/local_zeeklogs
...
Bugfix/local zeeklogs
2020-09-29 08:58:02 -04:00
Doug Burks
60134829d5
Alerts - Drilldown should display rule.uuid #1416
2020-09-29 07:51:45 -04:00
Doug Burks
c7b43ac220
Update soc.json
2020-09-29 07:41:49 -04:00
Doug Burks
a7f24b62e6
Hunt - improve NIDS query and eventFields #1415
2020-09-29 07:34:44 -04:00
Josh Patterson
9ca13ebccd
Merge pull request #1414 from Security-Onion-Solutions/issue/1404
...
change so salt module to /usr/sbin/so-status
2020-09-28 18:31:26 -04:00
Mike Reeves
c828a2ea75
Merge pull request #1413 from Security-Onion-Solutions/experimental
...
Airgap SOUP!
2020-09-28 17:47:38 -04:00
m0duspwnens
8741520263
change so salt module to /usr/sbin/so-status
2020-09-28 17:31:05 -04:00
Mike Reeves
6b8b0f1b26
Change add registry
2020-09-28 16:48:02 -04:00
William Wernert
f77305e22f
Generate zeeklogs sls earlier to avoid error
2020-09-28 16:45:06 -04:00
William Wernert
f782299281
Remove preconfigured zeeklog + create it during setup
2020-09-28 15:12:36 -04:00
Josh Patterson
fa6396b121
Merge pull request #1410 from Security-Onion-Solutions/fix/disable_auto_start
...
send to dev/null to prevent output
2020-09-28 15:07:40 -04:00
weslambert
3d6c956e02
Merge pull request #1409 from Security-Onion-Solutions/feature/wazuh_wel
...
Add initial parsing for Wazuh WEL/Sysmon
2020-09-28 15:07:15 -04:00
m0duspwnens
0bb1ba2853
send to dev/null to prevent output
2020-09-28 15:06:43 -04:00
Wes Lambert
869767d9d9
Add initial parsing for Wazuh WEL/Sysmon
2020-09-28 19:04:21 +00:00
Josh Patterson
0944cd1bcd
Merge pull request #1408 from Security-Onion-Solutions/issue/1093
...
Issue/1093
2020-09-28 14:45:18 -04:00
m0duspwnens
3b709e7877
remove cleaning of webpasswd1
2020-09-28 14:44:14 -04:00
Doug Burks
6e9e4dc99c
Hunt third magnifying glass should group output by event.module and event.dataset #1407
2020-09-28 14:19:55 -04:00
Mike Reeves
2cdf76473c
Add Registry back from cleanup
2020-09-28 14:19:43 -04:00
m0duspwnens
053b19de11
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-28 13:25:42 -04:00
m0duspwnens
bda9078843
check for invalid characters in fleet user password
2020-09-28 13:25:23 -04:00
Doug Burks
0516a9ddd5
Alerts page "Hunt for this field" action should quote field and group output #1406
2020-09-28 12:35:08 -04:00
m0duspwnens
85e53c53af
reject passwords with single or double quotes or backslashes
2020-09-28 11:51:19 -04:00
Mike Reeves
6a4d6f7a6d
Additional logic
2020-09-28 10:12:52 -04:00
William Wernert
66b7678df8
Merge pull request #1405 from Security-Onion-Solutions/feature/setup-cleanup
...
Feature/setup cleanup
2020-09-28 09:47:52 -04:00
William Wernert
3b9de2b7ca
Disable ipv6 earlier in setup
2020-09-28 09:14:45 -04:00
William Wernert
a60bf11daa
Make sure zeek log is only written on whiptail success
2020-09-28 09:11:50 -04:00
William Wernert
05729d216a
Don't direct user to check log in so-zeek-log, none exists
2020-09-28 08:45:59 -04:00
Doug Burks
3904295137
Hunt - improve HTTP queries #1401
2020-09-27 08:04:28 -04:00
Doug Burks
aa7f927ffd
Hunt - improve x509 queries #1400
2020-09-27 07:17:46 -04:00
Jason Ertel
68f18da832
Add alert query toggle filters for ack'd and escalated alerts
2020-09-25 17:03:42 -04:00
William Wernert
dc330a774e
Exit so-zeek-logs if user cancels
2020-09-25 16:30:16 -04:00
William Wernert
9acf610262
Also disable ipv6 for install
2020-09-25 16:10:26 -04:00
William Wernert
d76a4b1359
Show welcome screen on both iso and network installs
2020-09-25 14:59:27 -04:00
Doug Burks
11b200e9c0
Hunt - remove SMTP fields #1397
2020-09-25 14:17:14 -04:00
Doug Burks
20a56d0831
Hunt - add network.community_id column to Events table for more data types #1396
2020-09-25 13:18:28 -04:00
weslambert
6bfef773f2
Merge pull request #1392 from Security-Onion-Solutions/bugfix/config_dev_nullify
...
dev nullify so-config-backup cron job
2020-09-24 21:00:18 -04:00
weslambert
b3f9ee3b34
dev nullify so-config-backup cron job
2020-09-24 20:59:42 -04:00
Jason Ertel
c0be252f9f
SOC config adjustments for alerting
2020-09-24 16:37:27 -04:00
Josh Patterson
04f2595fa1
Merge pull request #1389 from Security-Onion-Solutions/issue/1388
...
fix common salt package name for salt.master state for ubuntu
2020-09-24 12:36:26 -04:00
Mike Reeves
e30958b9ec
Airgap SOUP changes
2020-09-24 11:41:02 -04:00
m0duspwnens
d9005c157d
fix common salt package name for salt.master state for ubuntu - https://github.com/Security-Onion-Solutions/securityonion/issues/1388
2020-09-24 11:26:58 -04:00
Doug Burks
62dbe425a6
Hunt - fix x509 eventFields #1387
2020-09-24 07:52:46 -04:00
Doug Burks
2b8b8e2f40
Hunt - fix file eventFields #1386
2020-09-24 07:44:28 -04:00
Doug Burks
60daacd6dc
Hunt - fix DHCP eventFields #1385
2020-09-24 07:34:29 -04:00
weslambert
a09002edae
Merge pull request #1384 from Security-Onion-Solutions/bugfix/config_backup
...
Add back missing # sign
2020-09-23 21:34:52 -04:00
weslambert
5b93c40ce4
Add back missing # sign
2020-09-23 21:34:10 -04:00
m0duspwnens
3ba8f47d9c
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-23 15:01:48 -04:00
m0duspwnens
6f7dbee36e
remove single quotes from secrets pillar
2020-09-23 14:57:26 -04:00
Mike Reeves
fd302c6363
make autocomplete with sudo work
2020-09-23 13:19:37 -04:00
m0duspwnens
70f98e2eea
take care single quotes if they are in the WEBPASSWD
2020-09-23 13:00:18 -04:00
m0duspwnens
b32bc8b542
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-23 12:07:12 -04:00
Mike Reeves
aca98e01f3
Set the path
2020-09-23 12:00:25 -04:00
Jason Ertel
2f7c0c34e6
Support backslashes in SOC passwords
2020-09-23 10:09:21 -04:00
weslambert
4f228c1b7c
Merge pull request #1379 from Security-Onion-Solutions/feature/config_backup
...
Feature/config backup
2020-09-23 09:58:05 -04:00
Wes Lambert
71734ddc0a
Add cron job to common state for daily config backup
2020-09-23 13:55:32 +00:00
Wes Lambert
57732b360e
Add config backup script
2020-09-23 13:47:14 +00:00
Wes Lambert
4d42d04cc3
Fix backup pillar definition
2020-09-23 13:45:42 +00:00
Wes Lambert
d02c440934
Add backup params to global.sls
2020-09-22 21:05:57 +00:00
m0duspwnens
77a9bf2697
test single quotes in secrets pillar
2020-09-22 13:16:20 -04:00
Josh Brower
18a881ccab
Merge pull request #1377 from Security-Onion-Solutions/bugfix/docker_cleanup
...
fix docker_clean syntax
2020-09-21 19:42:11 -04:00
Josh Brower
8bb527b4f1
fix docker_clean syntax
2020-09-21 19:41:39 -04:00
Jason Ertel
694635a38f
Add pivot to hunt as a new alerts quick action
2020-09-21 17:10:03 -04:00
Mike Reeves
0f1b92cea9
Update so-rule-update
2020-09-21 15:40:38 -04:00
Mike Reeves
48b17ee51a
Merge pull request #1375 from Security-Onion-Solutions/gaupgrade
...
Upgrade to GA including Docker Cleanup
2020-09-21 13:14:49 -04:00
Mike Reeves
d56a9e1f86
Upgrade to GA including Docker Cleanup
2020-09-21 13:14:06 -04:00
Josh Brower
ffdf7e1db4
Merge pull request #1374 from Security-Onion-Solutions/feature/so-user-list
...
Add so-user-list
2020-09-21 10:03:02 -04:00
Josh Brower
3cd11807cd
Add so-user-list
2020-09-21 10:02:10 -04:00
Jason Ertel
8f4a6df53a
Add event.module to default alert query
2020-09-21 09:06:56 -04:00
Jason Ertel
fc51c2aef4
Group by community ID on second alert quick query
2020-09-19 08:39:01 -04:00
Jason Ertel
5b38acb64b
Add alerting configuration for soc container
2020-09-18 13:51:23 -04:00
Josh Patterson
2b155b5581
Merge pull request #1368 from Security-Onion-Solutions/issue/1367
...
add so-fleet so standalone fleet gets the redis pki
2020-09-18 13:41:43 -04:00
m0duspwnens
40f6fed2a5
add so-fleet so standalone fleet gets the redis pki
2020-09-18 13:40:27 -04:00
Jason Ertel
1610445b4e
Validate password before creating user
2020-09-18 08:29:30 -04:00
Jason Ertel
0c12025599
Do not restart mysql after setup when running automated tests
2020-09-18 08:22:28 -04:00
Mike Reeves
33e381ad15
Update VERSION
2020-09-17 15:08:36 -04:00
Mike Reeves
bafb13fd6d
Merge pull request #1363 from Security-Onion-Solutions/dev
...
RC3
2020-09-17 15:05:33 -04:00
Mike Reeves
56e9f09c20
Update VERIFY_ISO.md
2020-09-17 11:02:16 -04:00
Mike Reeves
6cd30ce52f
Update Sig
2020-09-17 10:56:29 -04:00
Mike Reeves
3fb98bfd4d
Update VERIFY_ISO.md
2020-09-17 10:54:18 -04:00
Mike Reeves
4701091f76
Update VERIFY_ISO.md
2020-09-17 10:54:01 -04:00
Doug Burks
57e45308af
Fix pivot from TheHive to Kibana #1362
2020-09-17 08:05:55 -04:00
Doug Burks
c9c1245d1e
change from 2.1 RC2 to 2.2 RC3
2020-09-17 08:01:10 -04:00
Mike Reeves
7415c7fe81
Fix dashboard script
2020-09-16 14:55:32 -04:00
Mike Reeves
eac58f8f34
Merge pull request #1346 from Security-Onion-Solutions/rc3upgrade
...
Rc3upgrade
2020-09-16 14:29:53 -04:00
Mike Reeves
52072e0484
Update soup
2020-09-16 14:08:48 -04:00
doug
840b54d73c
make so-analyst executable
2020-09-16 13:11:49 -04:00
Mike Reeves
5910fe642c
Fix Update XML
2020-09-16 13:08:21 -04:00
Mike Reeves
a0f64440e0
Update changes.json
2020-09-16 13:06:26 -04:00
weslambert
74e4adda11
Merge pull request #1357 from Security-Onion-Solutions/feature/dashboard_updates_2
...
Add All Logs for Connections dashboard
2020-09-16 11:56:38 -04:00
Wes Lambert
44ef935d65
Add All Logs for Connections dashboard
2020-09-16 15:55:28 +00:00
Mike Reeves
3e0e41be32
Update changes.json
2020-09-16 11:41:21 -04:00
Mike Reeves
1801361cf8
Update changes.json
2020-09-16 11:40:05 -04:00
weslambert
6325b30a21
Merge pull request #1356 from Security-Onion-Solutions/feature/dashboard_updates
...
Kibana dashboard updates
2020-09-16 11:19:27 -04:00
Wes Lambert
bd8d2fc271
Kibana dashboard updates
2020-09-16 15:17:26 +00:00
Josh Patterson
6e0806a587
Merge pull request #1353 from Security-Onion-Solutions/fix/strelkaconfig
...
fix sensor mainip logic for strelka yaml files
2020-09-16 10:32:58 -04:00
m0duspwnens
4ee3e1ed01
fix sensor mainip logic for strelka yaml files
2020-09-16 10:29:23 -04:00
Josh Patterson
b7e41b53cb
Merge pull request #1352 from Security-Onion-Solutions/fix/es_templates
...
fix MYIP
2020-09-16 10:12:27 -04:00
m0duspwnens
3fe276dbb5
fix MYIP
2020-09-16 10:11:39 -04:00
Josh Patterson
66f21c4568
Merge pull request #1350 from Security-Onion-Solutions/fix/es_templates
...
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:54:16 -04:00
Josh Brower
d5fd15962c
Merge pull request #1351 from Security-Onion-Solutions/bugfix/tcpreplay
...
Fix so-test
2020-09-16 09:52:08 -04:00
Josh Brower
dd2d736bc1
Fix so-test
2020-09-16 09:51:38 -04:00
m0duspwnens
dd56d7d2d1
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:48:38 -04:00
weslambert
6806bd2461
Merge pull request #1348 from Security-Onion-Solutions/bugfix/es_template_load
...
Ensure templates are loaded for heavy nodes
2020-09-15 17:15:56 -04:00
weslambert
fbf037f460
Ensure templates are loaded for heavy nodes
2020-09-15 17:14:06 -04:00
Josh Brower
46a1369e81
Merge pull request #1347 from Security-Onion-Solutions/bugfix/tcpreplay
...
Add so-test
2020-09-15 13:20:56 -04:00
Josh Brower
2516429834
Add so-test
2020-09-15 13:14:00 -04:00
Mike Reeves
fc8ffd2080
Made the version update more reliable
2020-09-15 11:09:01 -04:00
Mike Reeves
ee4b35f2e4
Rename zeekversion.map.jinja to mdengine.map.jinja
2020-09-14 22:30:10 -04:00
Mike Reeves
c31d998061
Disk Space Check Final Final Final
2020-09-14 20:17:28 -04:00
Mike Reeves
62a8e676d9
Disk Space Check Final Final
2020-09-14 20:11:04 -04:00
Mike Reeves
9ef2b93586
Disk Space Check Final Final
2020-09-14 20:09:53 -04:00
Mike Reeves
eafb4e81a5
Disk Space Check Final Final
2020-09-14 20:01:53 -04:00
Mike Reeves
6eb3333af4
Disk Space Check Final
2020-09-14 19:46:16 -04:00
Mike Reeves
07e536df98
Disk Space Check
2020-09-14 19:42:58 -04:00
Mike Reeves
e8d2a6fdc2
Disk Space Check
2020-09-14 19:32:14 -04:00
Mike Reeves
1bc5e33007
Rotate Mysql Container Log
2020-09-14 16:27:32 -04:00
Mike Reeves
e2ecfca4c1
Merge pull request #1343 from Security-Onion-Solutions/rc3upgrade
...
Upgrade Fun
2020-09-14 14:54:37 -04:00
Mike Reeves
0a0e00866c
Upgrade Fun
2020-09-14 14:50:22 -04:00
Mike Reeves
38266f7db8
Merge pull request #1342 from Security-Onion-Solutions/experimental
...
Fix ruleupdate setting
2020-09-14 14:26:31 -04:00
Mike Reeves
9957fdec0f
Fix ruleupdate setting
2020-09-14 14:17:55 -04:00
Josh Patterson
32632864eb
Merge pull request #1341 from Security-Onion-Solutions/issue/1066
...
change how we determine how to run so-status
2020-09-14 12:43:05 -04:00
m0duspwnens
b559e5dd32
change how we determine how to run so-status
2020-09-14 12:40:39 -04:00
Jason Ertel
f86780a0db
Open PCAPs in same tab, but open external sites in new tabs
2020-09-14 10:41:39 -04:00
Mike Reeves
1958fef4ad
Merge pull request #1338 from Security-Onion-Solutions/experimental
...
Fix strelka rules
2020-09-14 09:58:34 -04:00
Mike Reeves
ee1317adf1
Merge branch 'experimental' of https://github.com/Security-Onion-Solutions/securityonion into experimental
2020-09-14 09:57:14 -04:00
Mike Reeves
d1836fb3a3
Fix Salt issue with script
2020-09-14 09:57:08 -04:00
Josh Patterson
67c1ece0bb
Merge pull request #1337 from Security-Onion-Solutions/issue/1066
...
Issue/1066
2020-09-14 09:38:15 -04:00
m0duspwnens
b93d149631
fix so-status
2020-09-14 09:36:26 -04:00
m0duspwnens
46cbcfa330
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1066
2020-09-14 08:45:54 -04:00
Mike Reeves
841db1b4b9
Merge pull request #1336 from Security-Onion-Solutions/experimental
...
Get Rules onto the install for airgap
2020-09-13 14:58:36 -04:00
Mike Reeves
112a0b426e
Merge branch 'dev' into experimental
2020-09-13 14:54:00 -04:00
Doug Burks
18dc7a915a
Hunt: Fix Tunnel query #1335
2020-09-13 08:26:33 -04:00
Jason Ertel
89c38541ee
Force all SOC quick actions to open in new tab
2020-09-13 02:52:25 -04:00
Mike Reeves
d6d22fb0e0
Fix Strelka
2020-09-12 23:07:35 -04:00
Mike Reeves
bb936c5bee
Fix Strelka
2020-09-12 23:07:15 -04:00
Mike Reeves
259df2ed6b
Fix Strelka
2020-09-12 23:06:06 -04:00
Doug Burks
311d67b934
Hunt: fix RFB groupby #1332
2020-09-12 06:14:58 -04:00
Josh Patterson
f03b128924
Merge pull request #1331 from Security-Onion-Solutions/fix/top
...
add redis to eval if playbook enabled
2020-09-11 18:31:19 -04:00
m0duspwnens
5f567368be
add redis to eval if playbook enabled
2020-09-11 18:30:21 -04:00
m0duspwnens
77911acfb4
so-status module
2020-09-11 18:28:53 -04:00
Mike Reeves
48d1d0c168
Strelkas Rules Update
2020-09-11 18:24:56 -04:00
Josh Patterson
2d508d9e57
Merge pull request #1328 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-11 15:02:30 -04:00
m0duspwnens
15563f2ee6
add nginx to top for sensor
2020-09-11 12:28:42 -04:00
m0duspwnens
bb0e686444
add elasticsearch to top for nodes missing it
2020-09-11 11:35:17 -04:00
Mike Reeves
46866f40b3
Merge pull request #1325 from Security-Onion-Solutions/experimental
...
Update Script
2020-09-11 11:02:57 -04:00
Mike Reeves
6e0cdf7be4
Update Script help
2020-09-11 11:01:56 -04:00
m0duspwnens
5f7c270984
only allow strelka to run on nodes that are sensors
2020-09-11 10:22:12 -04:00
Mike Reeves
af9a19b6e8
Merge pull request #1321 from Security-Onion-Solutions/experimental
...
IDS Tools now with Airgap support
2020-09-10 19:05:16 -04:00
Mike Reeves
53319738c4
Fix Nginx state
2020-09-10 16:56:48 -04:00
Mike Reeves
ef46094b0c
Update all nginx configs
2020-09-10 13:55:56 -04:00
Josh Patterson
53ff87b0ee
Merge pull request #1312 from Security-Onion-Solutions/issue/1281
...
add elasticsearch state to top for manager node
2020-09-10 12:47:05 -04:00
m0duspwnens
bc420d4a02
add
2020-09-10 11:57:15 -04:00
Josh Patterson
ca26548b2c
Merge pull request #1310 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-10 10:08:25 -04:00
m0duspwnens
0ed9c65646
remove logic from fleet state to only run if in top
2020-09-10 10:07:05 -04:00
Doug Burks
8c280221da
Hunt: Fix Intel groupby #1131
2020-09-10 07:00:54 -04:00
Doug Burks
24c325e9a1
Fix Elasticsearch parsing for Zeek Intel Indicator #1309
2020-09-10 06:41:19 -04:00
Josh Brower
56587f0df5
Merge pull request #1308 from Security-Onion-Solutions/feature/wel-ingest
...
Add event.category to WEL
2020-09-10 06:16:56 -04:00
Josh Brower
c3b2d98ffb
Add event.category to WEL
2020-09-10 06:15:30 -04:00
Doug Burks
7161a662aa
improve Wazuh support in Hunt
2020-09-10 06:03:33 -04:00
Mike Reeves
5d4e8925a3
Add Firewall Logic
2020-09-09 21:16:40 -04:00
Mike Reeves
45b11b2321
Fix Rulecat
2020-09-09 18:38:07 -04:00
Doug Burks
d18c498574
Update so-features-enable
2020-09-09 17:32:42 -04:00
m0duspwnens
09cc8ae1fb
fail the state if it isnt in top
2020-09-09 16:48:50 -04:00
m0duspwnens
01c9f7b2ae
merge with dev and resolve conflicts
2020-09-09 16:23:36 -04:00
Mike Reeves
7ebf93fcb5
IDSTools Overhaul
2020-09-09 15:53:32 -04:00
Josh Patterson
1e32b32659
Merge pull request #1302 from Security-Onion-Solutions/fix/sostatus
...
Fix/sostatus
2020-09-09 15:07:12 -04:00
m0duspwnens
39f200f565
fix whitespace
2020-09-09 14:59:21 -04:00
Mike Reeves
a77532c1d8
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 14:57:17 -04:00
Mike Reeves
04f4539385
Fix Airgap Repo Name
2020-09-09 14:57:10 -04:00
m0duspwnens
b0c526364f
handle strelka
2020-09-09 14:55:54 -04:00
m0duspwnens
921262b9a5
prevent duplicate containers for so-stauts
2020-09-09 14:07:38 -04:00
Jason Ertel
a5b87850df
Remove user sync between SOC and Cortex due to the unnecesary complexities involved with this style of integration
2020-09-09 14:07:36 -04:00
m0duspwnens
05d736d2df
handle strelka
2020-09-09 14:00:58 -04:00
m0duspwnens
918d9cf00f
handle strelka
2020-09-09 13:57:53 -04:00
m0duspwnens
3433b90029
fix so-status for strelka and wazuh
2020-09-09 13:53:10 -04:00
Doug Burks
82b582540e
Add period
2020-09-09 12:56:19 -04:00
Doug Burks
90ba1be978
Improve formatting of NIDS selection screen
2020-09-09 12:55:14 -04:00
m0duspwnens
e84507c386
Merge remote-tracking branch 'remotes/origin/dev' into fix/sostatus
2020-09-09 12:51:01 -04:00
m0duspwnens
9ee9a199b1
predefine each component as 0 to fix issues with it being unset
2020-09-09 12:50:22 -04:00
Jason Ertel
fc4ad1d556
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:22:38 -04:00
Jason Ertel
9babc445ce
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:07:23 -04:00
Mike Reeves
90feb503ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 10:54:53 -04:00
Mike Reeves
426257443a
Final airgap tweaks
2020-09-09 10:54:47 -04:00
Doug Burks
eaf3281ab7
Remove Suricata version numbers from Setup screens #1300
...
https://github.com/Security-Onion-Solutions/securityonion/issues/1300
2020-09-09 10:43:41 -04:00
Josh Patterson
c2398f966b
Merge pull request #1295 from Security-Onion-Solutions/fix/salt-ca-ssl
...
Fix/salt ca ssl
2020-09-09 10:36:54 -04:00
m0duspwnens
7facff2b7d
change from cmd.run to cp.get_file_str
2020-09-09 10:34:53 -04:00
Jason Ertel
ad05e75ce7
Add new quick actions to SOC config template
2020-09-09 00:46:23 -04:00
Mike Reeves
7d524a0723
Add Firewall Rule for yum and airgap
2020-09-08 18:51:14 -04:00
Josh Patterson
d7016b4557
Merge pull request #1298 from Security-Onion-Solutions/issue/1291
...
Issue/1291
2020-09-08 17:40:33 -04:00
m0duspwnens
da34222931
makedirs
2020-09-08 17:36:27 -04:00
m0duspwnens
eeb6c3128b
add salt.master state to manager nodes
2020-09-08 17:27:13 -04:00
m0duspwnens
da3d0948b4
creating engine to watch the health of the salt mine
2020-09-08 16:49:38 -04:00
Jason Ertel
710a2be422
Add new so-user-enable script and change so-user-disable to call 'so-user disable' instead of deleting the SOC user
2020-09-08 16:24:18 -04:00
Mike Reeves
7c41c31359
Fix airgap statement
2020-09-08 14:48:37 -04:00
Mike Reeves
7371f9236e
Update top.sls
2020-09-08 14:18:56 -04:00
Mike Reeves
1aea3f4f85
Merge pull request #1297 from Security-Onion-Solutions/experimental
...
Add Airgap code
2020-09-08 09:26:41 -04:00
Doug Burks
f8ebed43d7
fix spacing
2020-09-07 04:45:26 -04:00
Doug Burks
f5916e26a2
read ca.crt from filesystem when possible
2020-09-07 04:42:11 -04:00
weslambert
b6b52671e2
Merge pull request #1294 from Security-Onion-Solutions/fix/wazuh_agent_name
...
Fix typo
2020-09-05 08:17:09 -04:00
Wes Lambert
f9884606df
Fix typo
2020-09-05 12:15:55 +00:00
Jason Ertel
f27e5164d0
Update to latest kratos; add support for a custom status trait to represent whether a user is locked or not; refactor so-user to use new enable/disable capabilities in SOC; remove 'delete' option from so-user usage to avoid having user lists out of sync across SOC and external apps
2020-09-04 17:01:52 -04:00
Josh Brower
351e7761ef
Merge pull request #1292 from Security-Onion-Solutions/bugfix/playbook-rulesets
...
Update SOCtopus.conf
2020-09-04 14:15:18 -04:00
Josh Brower
39cc7151a5
Update SOCtopus.conf
2020-09-04 14:14:53 -04:00
Doug Burks
f8e68c82e4
downgrade to Mono 4.2.1.102 and NetworkMiner 2.4
2020-09-04 10:12:28 -04:00
Doug Burks
c050003b5a
Install file-roller for opening zip files
2020-09-04 07:14:01 -04:00
Doug Burks
a2265fac4f
NetworkMiner has a compatibility issue with Mono 6 right now
2020-09-04 06:50:22 -04:00
Doug Burks
1fc64d3eef
so-analyst should install gedit
2020-09-03 16:46:14 -04:00
Josh Patterson
c71a154e81
Merge pull request #1288 from Security-Onion-Solutions/quickfix/standalonetop
...
add elasticsearch to standalone top
2020-09-03 15:55:43 -04:00
m0duspwnens
05b8b71af2
add elasticsearch to standalone top
2020-09-03 15:54:24 -04:00
Mike Reeves
b2ee757db2
Airgap Time
2020-09-03 10:35:12 -04:00
weslambert
b10dd40376
Merge pull request #1287 from Security-Onion-Solutions/fix/suri_home_net
...
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:51 -04:00
weslambert
8db8dcb71a
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:14 -04:00
m0duspwnens
770cd6eafc
add endif
2020-09-02 16:19:58 -04:00
Mike Reeves
9745191f19
Add Airgap State
2020-09-02 16:17:44 -04:00
m0duspwnens
a229ae82ce
only allow state to run if it is in top for the node
2020-09-02 16:15:52 -04:00
weslambert
870e042c4c
Merge pull request #1285 from Security-Onion-Solutions/fix/so_stop_start_restart
...
Require at least one arg for start/stop/restart scripts
2020-09-02 14:58:19 -04:00
Wes Lambert
770aaf415c
Require at least on arg for start/stop/restart scripts
2020-09-02 18:55:59 +00:00
Jason Ertel
0142f43493
Add so-user-disable script which deletes the SOC user and disables the users in Fleet, TheHive, and Cortex
2020-09-02 13:54:50 -04:00
m0duspwnens
9d85b3223f
fix note about localrules
2020-09-02 11:46:48 -04:00
Josh Patterson
066c795e71
Merge pull request #1279 from Security-Onion-Solutions/fix/redhat
...
move redhat with centos
2020-09-02 09:12:44 -04:00
m0duspwnens
1f8f197066
move redhat with centos
2020-09-02 09:12:05 -04:00
weslambert
d35cca7fc5
Merge pull request #1278 from Security-Onion-Solutions/fix/elastalert_extra_hosts
...
Add manager to hosts file
2020-09-02 07:44:49 -04:00
weslambert
5d920885e0
Add manager to hosts file
2020-09-02 07:43:55 -04:00
Josh Patterson
7fa083069d
Merge pull request #1277 from Security-Onion-Solutions/issue/968
...
Issue/968
2020-09-01 15:43:22 -04:00
m0duspwnens
08ca2055dc
fix telegraf file input for zeek log
2020-09-01 15:34:06 -04:00
m0duspwnens
93f30a2064
fix telegraf config
2020-09-01 15:29:29 -04:00
m0duspwnens
b13b07eddf
add newline to end
2020-09-01 15:10:56 -04:00
m0duspwnens
01777c64d9
fix influxtime
2020-09-01 14:58:48 -04:00
m0duspwnens
b6d66bddfc
add redis to proper node types. grafana dahsboard changes. change zeek_restart to not use telegraf socket but read from file instead
2020-09-01 14:38:10 -04:00
Josh Brower
6cd0d16b91
Merge pull request #1276 from Security-Onion-Solutions/feature/import-wel
...
Initial support for evtx import
2020-09-01 13:48:12 -04:00
Josh Brower
a79d0319cd
Initial support for evtx import
2020-09-01 13:47:27 -04:00
Mike Reeves
951fe2ac69
Create repo
2020-09-01 11:26:33 -04:00
Mike Reeves
9cff7c1427
Enable airgap functions
2020-09-01 11:24:22 -04:00
Mike Reeves
643dab12d0
Enable airgap
2020-09-01 11:09:33 -04:00
Josh Patterson
67766745a4
Merge pull request #1275 from Security-Onion-Solutions/fix/redhat
...
resolve issue with salt state if os is redhat
2020-09-01 10:44:59 -04:00
m0duspwnens
2fee151bff
resolve issue with salt state if os is redhat
2020-09-01 10:43:21 -04:00
m0duspwnens
ada1c81ab7
manager and standalone dashboard changes
2020-09-01 10:40:20 -04:00
Jason Ertel
ff5d1cd815
Expand nginx body size limit to 2.5GB to handle 2G PCAPs from sensors
2020-09-01 10:07:28 -04:00
Doug Burks
45c0a7ac77
Kernel messages can overwrite whiptail screen #812
...
Kernel messages can overwrite whiptail screen #812
2020-09-01 08:55:34 -04:00
m0duspwnens
a1a7b36319
merge with dev and resolve conflict
2020-08-31 16:05:34 -04:00
m0duspwnens
31f25eca57
fix grafana related issues. add redis to standalone
2020-08-31 15:56:58 -04:00
weslambert
011958a2f3
Merge pull request #1274 from Security-Onion-Solutions/fix/zeek_syslog
...
Ensure Zeek syslog log is enabled for Import node
2020-08-31 13:08:44 -04:00
Wes Lambert
ae3fe9e892
Ensure Zeek syslog log is enabled for Import node
2020-08-31 17:07:16 +00:00
weslambert
96f25914db
Merge pull request #1273 from Security-Onion-Solutions/fix/zeek_syslog_default
...
Fix/zeek syslog default
2020-08-31 12:32:52 -04:00
Wes Lambert
5ed5e6603d
Fix space
2020-08-31 16:32:12 +00:00
Wes Lambert
26ffc44fd1
Only enable syslog log by default in Eval mode
2020-08-31 16:30:32 +00:00
Jason Ertel
dc3b065a41
Set exec bit on new user-add scripts
2020-08-31 10:57:23 -04:00
weslambert
6350c83e05
Merge pull request #1272 from Security-Onion-Solutions/feature/wazuh_mgmt_wrappers
...
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 10:55:25 -04:00
Wes Lambert
46e7e121e3
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 14:54:24 +00:00
weslambert
5db70cbd59
Merge pull request #1271 from Security-Onion-Solutions/fix/remove_minio
...
Remove minio for now
2020-08-31 10:29:30 -04:00
Wes Lambert
6d14f2af96
Remove minio for now
2020-08-31 14:07:47 +00:00
weslambert
42bd75a1cc
Merge pull request #1270 from Security-Onion-Solutions/fix/elastalert_startup
...
Wait for Elasticsearch indices to be queryable before starting Elasta…
2020-08-31 09:56:18 -04:00
Wes Lambert
9abbda8e04
Wait for Elasticsearch indices to be queryable before starting Elastalert container
2020-08-31 13:54:49 +00:00
Jason Ertel
189c02648d
Move container status check to so-common
2020-08-31 09:52:06 -04:00
Jason Ertel
8e06f0453e
Only add users to aux systems if those systems are currently running
2020-08-31 09:41:06 -04:00
Doug Burks
9680270b20
Set default monospace font to Liberation
2020-08-30 16:42:44 -04:00
Doug Burks
2f09156a02
quote filename when spawning NetworkMiner
2020-08-30 16:10:47 -04:00
Doug Burks
77b3ebdabe
Hunt Events table should show ssl.server_name when searching for ssl
...
Hunt Events table should show ssl.server_name when searching for ssl #1267
2020-08-30 06:56:15 -04:00
Doug Burks
13ce439678
Update README
2020-08-29 06:52:26 -04:00
Doug Burks
df5ef7c956
Update so-analyst
2020-08-29 06:07:58 -04:00
Doug Burks
1e1212bf41
Update so-analyst
2020-08-29 05:59:21 -04:00
Doug Burks
c20f47ffd6
make chaosreader executable
2020-08-29 04:52:21 -04:00
Doug Burks
c21b347549
Update README
2020-08-29 04:46:00 -04:00
Doug Burks
f6f990ca9f
Update README
2020-08-28 16:44:41 -04:00
Doug Burks
8344e38d91
Add files via upload
2020-08-28 16:43:28 -04:00
Josh Brower
764ba4a0e9
Merge pull request #1266 from Security-Onion-Solutions/bugfix/event.code-parsing
...
Set event.code to string for WEL
2020-08-28 13:49:01 -04:00
Josh Brower
b7dd14b8f0
Set event.code to string for WEL
2020-08-28 13:40:04 -04:00
Jason Ertel
3877706f20
Remove auto-start regardless of how setup was started
2020-08-28 09:10:35 -04:00
Jason Ertel
4e3e83820f
Correct pillar key for thehive
2020-08-28 08:17:42 -04:00
Josh Patterson
f4dc67e32a
Merge pull request #1264 from Security-Onion-Solutions/issue/1063
...
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:25:26 -04:00
m0duspwnens
b1e7ffc173
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:24:26 -04:00
Jason Ertel
a3e34bfaca
Add users to Fleet, TheHive, and Cortex when adding a user to SO via so-user-add command
2020-08-27 16:58:02 -04:00
Josh Patterson
9d30b58247
Merge pull request #1262 from Security-Onion-Solutions/issue/643
...
remove space
2020-08-27 15:09:05 -04:00
m0duspwnens
aa60ec8e5a
remove space
2020-08-27 15:07:45 -04:00
Josh Patterson
2559f740f1
Merge pull request #1260 from Security-Onion-Solutions/issue/643
...
Issue/643
2020-08-27 14:35:39 -04:00
m0duspwnens
dbb1390c42
move README to /
2020-08-27 14:32:51 -04:00
Mike Reeves
2b0b695ee4
Fix duplicate docker
2020-08-27 10:15:22 -04:00
Mike Reeves
dc6c0cc71c
Merge pull request #1259 from Security-Onion-Solutions/issue/286
...
Issue/286
2020-08-27 10:13:17 -04:00
m0duspwnens
e9b7538ee8
fix a couple things, add another package
2020-08-26 17:58:27 -04:00
m0duspwnens
16c3b9539b
fix a couple things, add another package
2020-08-26 17:51:04 -04:00
m0duspwnens
cc88c4c35f
adding so-analyst script to create analyst workstatin
2020-08-26 17:39:11 -04:00
weslambert
509985ed07
Merge pull request #1254 from Security-Onion-Solutions/fix/sensor_clean
...
Cron updates
2020-08-26 11:03:03 -04:00
weslambert
000c2abb33
Update timing for so-yara-update
2020-08-26 11:02:33 -04:00
Mike Reeves
19130b563d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/286
2020-08-26 11:01:01 -04:00
Mike Reeves
e1a52a4921
Update core counts if heavy node or SA
2020-08-26 11:00:23 -04:00
Mike Reeves
86584d90d7
Merge pull request #1253 from Security-Onion-Solutions/issue/1078
...
Issue/1078 Update Docker
2020-08-26 10:36:34 -04:00
Mike Reeves
e993397173
Update docker to latest version
2020-08-26 10:35:17 -04:00
Josh Brower
c38f4ad4ae
Merge pull request #1251 from Security-Onion-Solutions/feature/fleet3.1
...
Upgraded to Fleet 3.1
2020-08-26 06:14:34 -04:00
Josh Brower
67e0a219e6
Upgraded to Fleet 3.1
2020-08-26 06:13:45 -04:00
Josh Brower
b6ebcf6551
Merge pull request #1250 from Security-Onion-Solutions/feature/es-security-field
...
Adds new .security analyzed subfield
2020-08-26 05:12:23 -04:00
Josh Brower
1cf7301db4
Adds new .security analyzed subfield
2020-08-26 05:11:42 -04:00
Jason Ertel
3122280bd5
Update version to 2.2.0-rc.3
2020-08-25 15:16:09 -04:00
weslambert
ce49e050bc
Update timing for sensor clean cron
2020-08-25 12:14:43 -04:00
weslambert
61cc5b9712
Merge pull request #1246 from Security-Onion-Solutions/fix/sensor_clean_log
...
Fix/sensor clean log
2020-08-25 11:36:10 -04:00
Wes Lambert
c03812f7ab
Add rotation for sensor_clean log
2020-08-25 15:34:30 +00:00
weslambert
a8f727ad40
Don't write to log if not past CRIT_DISK_USAGE
2020-08-25 11:19:36 -04:00
Mike Reeves
6c5f8f7d53
Merge pull request #1240 from Security-Onion-Solutions/issue/1225
...
Remove duplicate IDSTools entries
2020-08-24 10:41:18 -04:00
Mike Reeves
52602f527e
Merge pull request #1238 from Security-Onion-Solutions/issue/796
...
Add /usr/sbin to the path
2020-08-24 10:39:29 -04:00
Mike Reeves
bc6eb74af2
Merge pull request #1230 from Security-Onion-Solutions/dev
...
2.1.0
2020-08-24 10:25:28 -04:00
Doug Burks
b627f565c9
Update VERIFY_ISO.md
2020-08-24 10:03:28 -04:00
Doug Burks
a0281830f8
Update VERIFY_ISO.md
2020-08-24 06:09:30 -04:00
Mike Reeves
aa3e3c3cec
Update Sig
2020-08-23 20:25:06 -04:00
Mike Reeves
e8568dbeb0
Update VERIFY_ISO.md
2020-08-23 20:23:49 -04:00
Mike Reeves
a97ca94354
Rotate suri stats log hourly
2020-08-23 16:08:17 -04:00
Mike Reeves
ebd8105cb5
Rotate suri stats log hourly
2020-08-23 16:03:37 -04:00
Mike Reeves
02712e7f46
Add /usr/sbin to the path
2020-08-22 11:07:00 -04:00
Mike Reeves
093819b0c7
Remove duplicate IDSTools entries
2020-08-22 10:32:11 -04:00
Doug Burks
daaa2d3579
Update README.md
2020-08-21 16:24:09 -04:00
Mike Reeves
3ea5bd0c53
Update MD5 and gpg info for new iso
2020-08-21 14:44:12 -04:00
Mike Reeves
64d34e46bf
Update ISO signature
2020-08-21 14:31:04 -04:00
Jason Ertel
9c6cc81f70
Remove improper suricata logging filter - this re-enables logging output for the suricata process itself
2020-08-21 12:44:28 -04:00
Mike Reeves
bdb8f616e4
Update VERIFY_ISO.md
2020-08-21 09:08:44 -04:00
Mike Reeves
60fbe357c5
Merge branch 'master' into dev
2020-08-20 21:10:59 -04:00
Mike Reeves
d0eae47047
Update ISO download details and signature
2020-08-20 21:08:17 -04:00
Mike Reeves
05d727e599
Final changes.json update
2020-08-20 19:18:39 -04:00
Mike Reeves
2b88f22eb2
Make HUP for rotate more reliable
2020-08-20 17:57:36 -04:00
Mike Reeves
69b3de43b9
Merge pull request #1229 from Security-Onion-Solutions/fix/statslog
...
add logrotate
2020-08-20 16:53:23 -04:00
Mike Reeves
b7da768dc7
add logrotate
2020-08-20 16:46:32 -04:00
Josh Patterson
44093e7484
Merge pull request #1228 from Security-Onion-Solutions/quickfix/importnode
...
remove bonding for import node
2020-08-20 14:23:21 -04:00
m0duspwnens
a7a0520cfe
remove bonding for import node
2020-08-20 14:20:09 -04:00
Jason Ertel
d1e5649a68
Corrected JSON typo and improved formatting
2020-08-20 13:46:20 -04:00
Mike Reeves
b7d1fd54c7
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-08-20 13:26:22 -04:00
Mike Reeves
3eea2c6b10
2.1.0 Release notes in changes.json
2020-08-20 13:26:14 -04:00
Jason Ertel
377c841c31
Switch back to direct command for removing setup from bash_profile due to how sed is interpreting the quoted expression
2020-08-20 13:11:57 -04:00
Mike Reeves
073a175939
Merge pull request #1224 from Security-Onion-Solutions/fix/mkrssl
...
Point logstash to use intca.crt
2020-08-20 10:52:28 -04:00
Mike Reeves
df95baa835
Point logstash to use intca.crt
2020-08-20 10:45:48 -04:00
weslambert
12a9d26231
Merge pull request #1223 from Security-Onion-Solutions/fix/aws_fwd_defaults
...
Add defaults file for fwdnode
2020-08-20 10:17:21 -04:00
Wes Lambert
3f04e566f2
Add defaults file for fwdnode
2020-08-20 14:16:05 +00:00
Jason Ertel
896bf6b78c
Update doc links to 2.1
2020-08-20 10:08:10 -04:00
Jason Ertel
22c9180386
Improve redirection of setup command output to log file, including stderr
2020-08-20 10:04:01 -04:00
Josh Patterson
014a0054c2
Merge pull request #1221 from Security-Onion-Solutions/quickfix/managersearch
...
remove monint from managersearch since they dont have a monint
2020-08-20 09:06:30 -04:00
m0duspwnens
43f4ebbcf1
remove monint from managersearch since they dont have a monint
2020-08-20 09:05:38 -04:00
Mike Reeves
2fce138d95
Change it to grains.host instead of grains.id
2020-08-19 21:26:27 -04:00
Mike Reeves
ccc2ed4478
don't create symlinks if a heavy node
2020-08-19 21:18:57 -04:00
Mike Reeves
f9e5ea8ba7
Fix SSL for filebeat
2020-08-19 21:12:41 -04:00
Mike Reeves
f7d3dca322
Fix duplicate state
2020-08-19 21:00:28 -04:00
Mike Reeves
d969b1e1b7
Update init.sls
2020-08-19 20:56:08 -04:00
Mike Reeves
507a3e852c
Update init.sls
2020-08-19 20:02:38 -04:00
Mike Reeves
5f41d9fc25
fix filebeat certs
2020-08-19 19:51:57 -04:00
Mike Reeves
8312221c82
Update soup
2020-08-19 18:51:32 -04:00
Mike Reeves
0439cf3205
Update soup
2020-08-19 18:47:36 -04:00
Jason Ertel
2325940789
Ensure strelka manager connects to local redis on heavy nodes
2020-08-19 16:24:28 -04:00
Josh Patterson
9fce1fc47d
Merge pull request #1220 from Security-Onion-Solutions/issue/1188
...
Issue/1188
2020-08-19 16:15:43 -04:00
Jason Ertel
5ff0058a65
Ensure strelka backend, frontend, and filestream are connecting to redis locally, on heavy node instances
2020-08-19 16:13:18 -04:00
m0duspwnens
961cc67e3f
add nginx state to heavynode
2020-08-19 16:05:40 -04:00
Mike Reeves
51a52228ac
Update init.sls
2020-08-19 16:01:58 -04:00
Mike Reeves
4527758e87
Update init.sls
2020-08-19 16:00:04 -04:00
m0duspwnens
826254bc3d
give redis key to heavy node too
2020-08-19 15:59:48 -04:00
Mike Reeves
ac2cf8c6d8
Merge pull request #1219 from Security-Onion-Solutions/feature/mkrsoup
...
Feature/mkrsoup
2020-08-19 15:47:53 -04:00
Mike Reeves
db2cc5f7a7
Update init.sls
2020-08-19 15:43:51 -04:00
weslambert
d80156505c
Merge pull request #1217 from Security-Onion-Solutions/fix/aws_automation
...
Add defaults file for search node
2020-08-19 15:09:00 -04:00
Wes Lambert
ed1e346789
Add defaults file for search node
2020-08-19 19:07:24 +00:00
Mike Reeves
4c246dc30d
remove airgap install option until rc3
2020-08-19 14:40:31 -04:00
weslambert
d25afe4aa5
Merge pull request #1216 from Security-Onion-Solutions/fix/logstash_hosts
...
Add manager IP to container hosts file
2020-08-19 14:39:04 -04:00
weslambert
b5dd868d1b
Add manager IP to container hosts file
2020-08-19 14:34:28 -04:00
Mike Reeves
6edf1c14f8
Fix filebeat certs
2020-08-19 13:35:58 -04:00
Mike Reeves
bf84822d36
fix if logic
2020-08-19 13:04:10 -04:00
Mike Reeves
3d48c1f99b
Add playbook updates
2020-08-19 12:14:11 -04:00
Mike Reeves
9280dbb9d9
Update soup
2020-08-19 12:00:25 -04:00
m0duspwnens
2f0ffffca4
lock and unlock master during soup
2020-08-19 11:46:29 -04:00
Mike Reeves
f57e0fbc56
Salt ACL
2020-08-19 10:33:26 -04:00
Mike Reeves
95f006db7d
Salt ACL
2020-08-19 10:08:11 -04:00
Mike Reeves
968e481ebe
Add cross cluster for SSL
2020-08-18 17:45:14 -04:00
Mike Reeves
348e802fb7
Add cross cluster for SSL
2020-08-18 17:38:35 -04:00
Mike Reeves
afa87374ad
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/mkrsoup
2020-08-18 17:33:25 -04:00
Mike Reeves
294a197cbf
Add cross cluster for SSL
2020-08-18 16:57:38 -04:00
Josh Brower
ad0f54fc40
Merge pull request #1209 from Security-Onion-Solutions/bugfix/osquery-parsing
...
Osquery Parsing fix
2020-08-18 15:54:47 -04:00
Josh Brower
d4f7a07f85
Osquery Parsing fix
2020-08-18 15:54:11 -04:00
weslambert
ca84ae43ef
Merge pull request #1208 from Security-Onion-Solutions/fix/remove_pillar_from_setup
...
Don't echo pillar to setup log
2020-08-18 15:44:20 -04:00
weslambert
a4e986ea37
Don't echo pillar to setup log
2020-08-18 15:43:43 -04:00
Josh Patterson
be8483c580
Merge pull request #1207 from Security-Onion-Solutions/issue/1188
...
remove monint from nodestab grafana dashboard since search nodes dont…
2020-08-18 15:37:56 -04:00
m0duspwnens
65d9afd8d5
remove monint from nodestab grafana dashboard since search nodes dont have monint
2020-08-18 15:37:17 -04:00
Mike Reeves
59aa55f9bc
Add playsecrets
2020-08-18 15:29:41 -04:00
Jason Ertel
47ad3f65ef
Only fail setup when the root mailbox is not empty for ISO installations, since network installations can't be sure if the error came from setup or something unrelated
2020-08-18 15:26:30 -04:00
Josh Patterson
1bf4b86d07
Merge pull request #1206 from Security-Onion-Solutions/issue/1188
...
remove monint from manager since it doesnt have a monint
2020-08-18 15:10:40 -04:00
m0duspwnens
5a3d95d9a1
remove monint from manager since it doesnt have a monint
2020-08-18 15:09:21 -04:00
Mike Reeves
44fcd999fd
Address #1205
2020-08-18 15:08:24 -04:00
weslambert
82bfa567d0
Merge pull request #1204 from Security-Onion-Solutions/fix/enable_strelka_default
...
Enable YARA rules by default
2020-08-18 14:54:46 -04:00
weslambert
eaad0487b5
Enable YARA rules by default
2020-08-18 14:54:11 -04:00
Josh Patterson
54c43634a3
Merge pull request #1203 from Security-Onion-Solutions/issue/1188
...
add strelka to heavynode if strelka is enabled
2020-08-18 14:29:07 -04:00
m0duspwnens
c8dfc2495c
add strelka to heavynode if strelka is enabled - https://github.com/Security-Onion-Solutions/securityonion/issues/1188
2020-08-18 14:21:23 -04:00
Jason Ertel
45d957566d
Only show 'Waiting for TheHive to start up' status if setup is actually installing thehive
2020-08-18 11:36:29 -04:00
Josh Patterson
b214b20e58
Merge pull request #1201 from Security-Onion-Solutions/issue/1063
...
fix monint for several node types for grafana
2020-08-18 10:53:30 -04:00
m0duspwnens
9f8f59f4df
fix monint for several node types for grafana
2020-08-18 10:48:52 -04:00
Mike Reeves
ba192d6c32
Update addtotab.sh
2020-08-17 17:23:25 -04:00
Josh Brower
9c1c4b1a98
Merge pull request #1198 from Security-Onion-Solutions/feature/playbook-tweaks
...
Playbook schema update - RC2
2020-08-17 14:10:26 -04:00
Josh Brower
a8aa97edd2
Playbook schema update - RC2
2020-08-17 14:09:17 -04:00
Josh Patterson
1d02fbdd0b
Merge pull request #1197 from Security-Onion-Solutions/feature/soup
...
add sls extension
2020-08-17 12:27:34 -04:00
m0duspwnens
eb1272c127
add sls extension
2020-08-17 12:26:44 -04:00
Josh Patterson
5581cf6721
Merge pull request #1196 from Security-Onion-Solutions/feature/soup
...
Feature/soup
2020-08-17 10:57:32 -04:00
m0duspwnens
a82c4c24fb
move url_base from manager to global in when running soup
2020-08-17 10:55:07 -04:00
Mike Reeves
dcb110b31f
Add rc1 conditional logic
2020-08-17 09:57:00 -04:00
Jason Ertel
d8833abf73
Use load instead of import on the registry image itself
2020-08-15 09:42:56 -04:00
Josh Patterson
2c9c328a40
Merge pull request #1193 from Security-Onion-Solutions/issue/1039
...
Issue/1039
2020-08-14 18:45:12 -04:00
m0duspwnens
e6da423dc3
change reference from manager:url_base to global:url_base - https://github.com/Security-Onion-Solutions/securityonion/issues/1039
2020-08-14 17:55:30 -04:00
m0duspwnens
4946bb54d8
Merge remote-tracking branch 'remotes/origin/dev' into issue/1039
2020-08-14 17:25:13 -04:00
Josh Patterson
5663edfaee
Merge pull request #1192 from Security-Onion-Solutions/quickfix/importnoderonicheckin
...
set checking interval for sensoroni on import node
2020-08-14 17:11:35 -04:00
m0duspwnens
387c26f052
set checking interval for sensoroni on import node
2020-08-14 17:10:36 -04:00
Josh Patterson
e4b80ff183
Merge pull request #1190 from Security-Onion-Solutions/quickfix/setuplogging
...
send service status to /dev/null to prevent FP on install failure
2020-08-14 16:47:55 -04:00
m0duspwnens
43f6f5c27a
send service status to /dev/null to prevent FP on install failure
2020-08-14 16:45:28 -04:00
Josh Patterson
51cbccad09
Merge pull request #1189 from Security-Onion-Solutions/quickfix/modulerun
...
use new module.run style
2020-08-14 16:39:17 -04:00
m0duspwnens
5220b5ae0c
use new module.run style
2020-08-14 16:37:45 -04:00
Josh Patterson
6b6f39edde
Merge pull request #1187 from Security-Onion-Solutions/quickfix/heavyfw
...
heavynode firewall rules
2020-08-14 16:01:56 -04:00
m0duspwnens
47faee48a6
heavynode firewall rules
2020-08-14 15:58:59 -04:00
Mike Reeves
eb6b2f6ca0
Merge pull request #1186 from Security-Onion-Solutions/feature/airgap
...
Airgap round 1
2020-08-14 15:41:36 -04:00
Mike Reeves
bac58abf3e
Airgap round 1
2020-08-14 15:32:33 -04:00
m0duspwnens
d963222f31
provide proper url for so-import-pcap based on redirect strategy chosen during setup - https://github.com/Security-Onion-Solutions/securityonion/issues/1039
2020-08-14 15:28:47 -04:00
Jason Ertel
11ebc6b8b2
Do not cancel setup if user choose not to run so-allow during setup
2020-08-14 15:28:42 -04:00
Josh Patterson
0ba0c16c38
Merge pull request #1185 from Security-Onion-Solutions/issue/1049
...
Issue/1049
2020-08-14 14:55:14 -04:00
m0duspwnens
35027e32b3
dont constantly run steno or suricata containers for import node
2020-08-14 14:43:37 -04:00
weslambert
945bc5c6de
Merge pull request #1184 from Security-Onion-Solutions/fix/automate_ssh
...
Don't copy SSH key if automated install
2020-08-14 14:42:44 -04:00
weslambert
c9d6293f8f
Don't copy SSH key if automated install
2020-08-14 14:41:35 -04:00
Jason Ertel
7fa5e17935
Correct if logic for determining when to show web interface URL
2020-08-14 14:40:12 -04:00
m0duspwnens
f9a6b8d231
remove zeek and suricata from so-status for import node
2020-08-14 14:39:02 -04:00
m0duspwnens
3836f00309
allow sensori port for import node
2020-08-14 14:32:34 -04:00
Jason Ertel
04340728ff
Improve title spacing among standard log lines
2020-08-14 14:28:52 -04:00
m0duspwnens
ff84640aad
add pcap to import node, test not starting zeek docker by default
2020-08-14 13:59:23 -04:00
Josh Patterson
fbbec71165
Merge pull request #1183 from Security-Onion-Solutions/issue/1170
...
Issue/1170
2020-08-14 12:56:57 -04:00
m0duspwnens
b7bfa6f9a9
move functions up
2020-08-14 12:55:54 -04:00
m0duspwnens
6602ad3286
sleep for 5 seconds
2020-08-14 12:53:24 -04:00
m0duspwnens
4bb23a089e
add some parens
2020-08-14 12:48:52 -04:00
m0duspwnens
4b21c1b492
logic change
2020-08-14 12:45:50 -04:00
Mike Reeves
2a8e4e4eb2
Merge pull request #1182 from Security-Onion-Solutions/feature/airgap
...
Feature/airgap
2020-08-14 12:32:26 -04:00
m0duspwnens
9d59fc23dd
logic changes
2020-08-14 12:24:15 -04:00
Mike Reeves
c64faacdbc
Install registry if the image is local
2020-08-14 12:15:56 -04:00
Mike Reeves
18f37e3ef8
Install registry if the image is local
2020-08-14 11:49:18 -04:00
m0duspwnens
e229cb49bc
logic changes
2020-08-14 11:40:21 -04:00
Wes Lambert
7686a05f42
Set Strelka rules enabled by default for Eval Mode
2020-08-14 15:33:38 +00:00
m0duspwnens
69fd803759
change while
2020-08-14 11:30:10 -04:00
m0duspwnens
683e8a2a39
remove quotes
2020-08-14 11:24:46 -04:00
weslambert
b662f9354f
Merge pull request #1180 from Security-Onion-Solutions/fix/thehive_global
...
Only copy TheHive details to global pillar if enabled
2020-08-14 11:23:16 -04:00
Wes Lambert
ab4285aaaf
Only copy TheHive details to global pillar if enabled
2020-08-14 15:21:56 +00:00
m0duspwnens
aa2b0699d5
move parens
2020-08-14 11:20:18 -04:00
m0duspwnens
876c6c7cb0
logic changes
2020-08-14 11:16:56 -04:00
m0duspwnens
ea5116700d
stop both service then start both
2020-08-14 11:01:26 -04:00
m0duspwnens
cd1169b68d
logging changes
2020-08-14 10:53:42 -04:00
m0duspwnens
e2fbe59b7c
additional logging
2020-08-14 10:30:01 -04:00
m0duspwnens
0eb0551b68
add check if salt minion is returning jobs
2020-08-14 10:15:54 -04:00
Mike Reeves
283f91459a
Fix rule update cron
2020-08-14 10:05:56 -04:00
Mike Reeves
7309767829
Merge pull request #1178 from Security-Onion-Solutions/fix/elasticwatch
...
Add watch statements
2020-08-14 09:58:40 -04:00
Mike Reeves
a3d8b7d0d3
Add watch statements
2020-08-14 09:40:38 -04:00
Jason Ertel
78bceeb9e5
Only show the web interface link when the redirect URL is available, such as on manager nodes
2020-08-14 09:17:25 -04:00
Jason Ertel
ee62faae72
Only show the web interface link when the redirect URL is available, such as on manager nodes
2020-08-14 09:10:28 -04:00
Jason Ertel
e6830e9cba
Avoid reusing header function from so-common
2020-08-14 01:09:47 -04:00
m0duspwnens
42c1e817fe
more logging and debugging
2020-08-13 18:09:57 -04:00
m0duspwnens
f9f2744d3f
logic changes
2020-08-13 17:49:05 -04:00
Jason Ertel
3c113a7a89
Add system information at beginning of installation; provide logging functions to be used instead of echo commands
2020-08-13 17:29:50 -04:00
Josh Brower
34d8261669
Merge pull request #1176 from Security-Onion-Solutions/feature/playbook
...
Elastalert/Playbook Stability updates
2020-08-13 17:19:01 -04:00
Josh Brower
7400bbd6c1
Elastalert Stability Fixes
2020-08-13 17:14:53 -04:00
m0duspwnens
829490da19
fix errors
2020-08-13 17:05:50 -04:00
m0duspwnens
6cf623e133
some logic changes
2020-08-13 16:52:39 -04:00
Doug Burks
ed4bee0d0b
so-allow has no usage function #1133
2020-08-13 16:42:50 -04:00
m0duspwnens
3d20cc0341
some debugging
2020-08-13 16:34:18 -04:00
m0duspwnens
1b4029f74b
fix syntax errors
2020-08-13 16:18:02 -04:00
m0duspwnens
07ef464375
https://github.com/Security-Onion-Solutions/securityonion/issues/1170
2020-08-13 16:01:53 -04:00
Jason Ertel
40b5b96e17
Respond with 403 status code to unauthorized sensor requests
2020-08-13 15:00:49 -04:00
Josh Patterson
078f87d6c7
Merge pull request #1169 from Security-Onion-Solutions/issue/1049
...
remove so-registry from docker see for import node as it doesnt even …
2020-08-13 10:49:14 -04:00
m0duspwnens
8ab1cd32f0
remove so-registry from docker see for import node as it doesnt even exist
2020-08-13 10:47:57 -04:00
Josh Patterson
ae66ec5f43
Merge pull request #1168 from Security-Onion-Solutions/issue/1049
...
Issue/1049
2020-08-13 10:12:47 -04:00
m0duspwnens
9fafd5f721
update trusted containers for soup to minimize downloaded containers
2020-08-13 08:32:51 -04:00
m0duspwnens
3387114389
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-13 08:21:43 -04:00
Mike Reeves
5a53194313
Update sotls.yml
2020-08-12 21:12:48 -04:00
Mike Reeves
59ddac57bf
Rename sotls.yaml to sotls.yml
2020-08-12 17:48:37 -04:00
m0duspwnens
a746d597bb
rename to .yml
2020-08-12 17:42:45 -04:00
m0duspwnens
dbe14fcbdb
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-12 16:46:03 -04:00
Doug Burks
5640faef13
Kernel consoleblank is causing whiptail progress screen to appear to hang #1084
2020-08-12 16:34:59 -04:00
m0duspwnens
f59b8683ae
allow soup to run on import node
2020-08-12 15:48:34 -04:00
m0duspwnens
5d5fcecdca
set the cluster for import node
2020-08-12 15:46:34 -04:00
Mike Reeves
0129519d0c
Merge pull request #1165 from Security-Onion-Solutions/feature/esssl
...
TLS Transport Encryption
2020-08-12 15:39:17 -04:00
Mike Reeves
9980d02844
Elastic Transport TLSgit add .
2020-08-12 15:38:19 -04:00
Mike Reeves
7e3e4d0f54
Convert ES cert to p12
2020-08-12 15:16:12 -04:00
Mike Reeves
82821fbb25
Convert ES cert to p12
2020-08-12 15:09:52 -04:00
Mike Reeves
daaffd5185
Convert ES cert to p12
2020-08-12 15:05:33 -04:00
Mike Reeves
683799d077
Convert ES cert to p12
2020-08-12 15:02:54 -04:00
m0duspwnens
ddf3e6f943
remove logstash from docker registry seed
2020-08-12 14:05:28 -04:00
Mike Reeves
c02a363e92
Merge pull request #1163 from Security-Onion-Solutions/feature/esssl
...
Feature/esssl
2020-08-12 14:02:27 -04:00
Mike Reeves
69e7285e30
Fix a bug where minio passwrods cause issues
2020-08-12 12:44:55 -04:00
m0duspwnens
68f5c1c3c5
create web user during setup for import node
2020-08-12 12:01:25 -04:00
m0duspwnens
dcd5e95b38
add so-pcaptools to registry for import node
2020-08-12 11:57:13 -04:00
m0duspwnens
c166bc84f3
add zeek to import node top
2020-08-12 11:48:22 -04:00
m0duspwnens
41afe0ab2e
remove tab
2020-08-12 11:33:10 -04:00
m0duspwnens
b5c9d44d91
nginx config for import node
2020-08-12 11:15:14 -04:00
Mike Reeves
32083132e5
Back out some ES settings
2020-08-12 11:10:36 -04:00
m0duspwnens
dfd3a1de6a
set monitor interface to bond0 for import node
2020-08-12 10:42:07 -04:00
m0duspwnens
0f53b4d703
set esheapsize and filebeat config for import node
2020-08-12 10:39:31 -04:00
m0duspwnens
5a0df27193
rename importpcap node to import
2020-08-12 10:27:15 -04:00
m0duspwnens
6260a0aeaa
add idstools to docker registry for importpcap node
2020-08-11 16:29:35 -04:00
m0duspwnens
53b4a73bb9
add idstools to importpcap node
2020-08-11 15:59:08 -04:00
m0duspwnens
de05403237
ensure nids rules dir exists
2020-08-11 15:52:15 -04:00
Mike Reeves
0f7074a499
SSL intraca
2020-08-11 15:49:04 -04:00
Mike Reeves
65d535d893
SSL intraca
2020-08-11 15:45:17 -04:00
Mike Reeves
f862133323
SSL intraca
2020-08-11 15:37:55 -04:00
Mike Reeves
5a0aae5fe7
SSL intraca
2020-08-11 15:34:07 -04:00
Mike Reeves
a817465318
SSL intraca
2020-08-11 15:25:09 -04:00
Mike Reeves
e8b61a3828
SSL intraca
2020-08-11 15:14:29 -04:00
Mike Reeves
5f30c947c9
SSL intraca
2020-08-11 15:12:23 -04:00
Josh Brower
b724d40376
Playbook Stability Fixes
2020-08-11 15:07:16 -04:00
m0duspwnens
a81d14463c
add logstash to registry for importpcap, change PATCHSCHEDULENAME=auto
2020-08-11 15:01:20 -04:00
Mike Reeves
42c9653669
anon user hack
2020-08-11 14:45:55 -04:00
Mike Reeves
f553a8e27a
anon user hack
2020-08-11 14:40:34 -04:00
Mike Reeves
8daf11f085
Fix logstash outputs
2020-08-11 13:58:28 -04:00
m0duspwnens
40006752a1
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-11 13:30:48 -04:00
m0duspwnens
ee91450424
fix patch schedule name for importpcap node
2020-08-11 13:30:41 -04:00
weslambert
796551d71b
Merge pull request #1161 from Security-Onion-Solutions/fix/redisconf
...
Update Redis maxmemory settings
2020-08-11 13:27:28 -04:00
Mike Reeves
362749ca85
Make hostnames default in cross cluster
2020-08-11 13:00:42 -04:00
weslambert
b95f8a9314
Update Redis maxmemory settings
2020-08-11 12:57:57 -04:00
m0duspwnens
ec62668eb7
firewall rules for importpcap node
2020-08-11 12:31:37 -04:00
m0duspwnens
f6a85ac852
top and seed registry for importpcap node
2020-08-11 12:27:21 -04:00
Mike Reeves
94bb9e0d6c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-11 12:20:00 -04:00
Mike Reeves
95367f8d23
Fix cross cluster
2020-08-11 12:00:58 -04:00
Mike Reeves
348f7f39cc
strip node suffix
2020-08-11 11:37:53 -04:00
Mike Reeves
05a05b5e9b
use hostname for cross cluster
2020-08-11 11:15:57 -04:00
Mike Reeves
cbba473c2d
fix ssl certs for SN
2020-08-11 11:10:27 -04:00
Mike Reeves
32c407231f
fix ssl certs for SN
2020-08-11 11:08:49 -04:00
Mike Reeves
a5131da5c9
fix ssl certs for SN
2020-08-11 11:07:34 -04:00
Mike Reeves
7e0249c377
ES cleanup
2020-08-11 10:28:21 -04:00
Mike Reeves
b84d7d818f
Fix for loop
2020-08-11 10:20:02 -04:00
Mike Reeves
d941209479
Walk nodes tab
2020-08-11 10:17:28 -04:00
Mike Reeves
32f8ea3158
Removes https from rest port
2020-08-11 10:02:00 -04:00
Jason Ertel
854cc487f7
Always disable screen blanking, to simplify logic
2020-08-11 09:21:06 -04:00
Mike Reeves
59292425c0
Add transport hostname
2020-08-10 23:03:54 -04:00
Mike Reeves
ac3f490299
Add transport hostname
2020-08-10 23:02:03 -04:00
Mike Reeves
730e389aae
Add transport hostname
2020-08-10 22:57:49 -04:00
Mike Reeves
52cc56bebb
Add transport hostname
2020-08-10 22:56:15 -04:00
Mike Reeves
c3d8c599cc
Turn off user auth
2020-08-10 22:13:17 -04:00
Mike Reeves
6007a6c4d8
Things like this are why I hate Java
2020-08-10 22:10:03 -04:00
Mike Reeves
d00231af06
Things like this are why I hate Java
2020-08-10 22:05:46 -04:00
Mike Reeves
31ab1e8ed8
Things like this are why I hate Java
2020-08-10 22:03:24 -04:00
Mike Reeves
6d2be9af7e
Things like this are why I hate Java
2020-08-10 21:58:44 -04:00
Mike Reeves
cdda46ce58
ca typeo
2020-08-10 21:54:36 -04:00
Mike Reeves
811da5732a
Elastic logic fix
2020-08-10 21:51:29 -04:00
Mike Reeves
08d544e527
Fix SSL perms
2020-08-10 21:44:45 -04:00
Mike Reeves
cf5c29d01c
Change certs path on elstic
2020-08-10 21:30:53 -04:00
Mike Reeves
e28619604c
Change certs path on elstic
2020-08-10 21:26:00 -04:00
Mike Reeves
e7cd527d49
Enable SSL in elastic
2020-08-10 21:18:03 -04:00
Mike Reeves
92cc176b6d
Fix features logic in all states that use it
2020-08-10 20:59:41 -04:00
Mike Reeves
28806513d9
Logstash logic fix
2020-08-10 20:53:56 -04:00
m0duspwnens
11433b87e6
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-10 16:36:49 -04:00
Mike Reeves
788864310c
Fix ssl state
2020-08-10 14:52:20 -04:00
Mike Reeves
523e42bec8
Fix ssl state
2020-08-10 14:40:11 -04:00
Mike Reeves
9d2d8d372f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-10 14:27:08 -04:00
Mike Reeves
e659af3466
ES basic SSL
2020-08-10 14:26:56 -04:00
Josh Patterson
6bb84f8513
Merge pull request #1160 from Security-Onion-Solutions/quickfix/saltinstall
...
add replace: False to get rid of warning, eventhough it doesntt. bug …
2020-08-10 13:06:15 -04:00
m0duspwnens
1f3ceb50da
add replace: False to get rid of warning, eventhough it doesntt. bug report submitted on saltstack gh.
2020-08-10 13:04:19 -04:00
Josh Patterson
b0aa40737b
Merge pull request #1159 from Security-Onion-Solutions/quickfix/saltinstall
...
fix --exclude, add salt-minion-3001.1 where missed
2020-08-10 12:23:48 -04:00
m0duspwnens
8146930b80
fix --exclude, add salt-minion-3001.1 where missed
2020-08-10 12:22:42 -04:00
Josh Patterson
b6740ef360
Merge pull request #1158 from Security-Onion-Solutions/quickfix/saltinstall
...
upgrading to salt 3001.1
2020-08-10 10:21:55 -04:00
m0duspwnens
ab7014d70a
upgrading to salt 3001.1
2020-08-10 10:19:25 -04:00
Mike Reeves
29aaa84a6f
Merge pull request #1157 from Security-Onion-Solutions/feature/esssl
...
Feature/esssl
2020-08-08 22:20:55 -04:00
Mike Reeves
32fe3ed961
fix ports
2020-08-08 20:59:13 -04:00
Mike Reeves
63031a965a
fix ports
2020-08-08 20:48:46 -04:00
Mike Reeves
bc09a89a01
output plugin to normal port
2020-08-08 20:36:28 -04:00
Mike Reeves
9248896a20
fix redis ports
2020-08-08 20:24:30 -04:00
Mike Reeves
112dba4549
Upodate SSL
2020-08-08 20:12:17 -04:00
Mike Reeves
f154d2fa78
Upodate SSL
2020-08-08 20:04:19 -04:00
Mike Reeves
9708b02387
update pipeline
2020-08-08 18:32:36 -04:00
Mike Reeves
86fd38a347
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/esssl
2020-08-08 17:32:29 -04:00
Mike Reeves
f840c85a46
make script run
2020-08-08 17:31:59 -04:00
Mike Reeves
26a095a89c
redis binds
2020-08-08 00:20:46 -04:00
Mike Reeves
8a50768e16
redis binds
2020-08-08 00:19:55 -04:00
Mike Reeves
dc12cacee0
generate redis key
2020-08-08 00:16:38 -04:00
Mike Reeves
d1c4e3d021
generate redis key
2020-08-08 00:15:36 -04:00
Mike Reeves
20dba6eaac
jruby ssl fun
2020-08-07 23:56:09 -04:00
Mike Reeves
ec1065462c
jruby ssl fun
2020-08-07 23:50:26 -04:00
Jason Ertel
5e3d21c43c
Wrap minio keys with quotes to ensure YAML parsing
2020-08-07 23:50:18 -04:00
Mike Reeves
d171adb9c9
jruby ssl fun
2020-08-07 23:39:13 -04:00
Mike Reeves
64af6f99e9
jruby ssl fun
2020-08-07 23:34:55 -04:00
Mike Reeves
2705cbbf45
jruby ssl fun
2020-08-07 23:33:02 -04:00
Mike Reeves
5525e235d1
jruby ssl fun
2020-08-07 23:28:58 -04:00
Mike Reeves
62a6f29c96
bucket stuff
2020-08-07 22:51:52 -04:00
Mike Reeves
321122cc87
update logstash
2020-08-07 22:43:34 -04:00
Mike Reeves
0d66e32305
sync cacerts
2020-08-07 22:39:29 -04:00
Mike Reeves
952234446f
fix logic
2020-08-07 22:18:58 -04:00
Mike Reeves
cca0dd9344
enable jinja
2020-08-07 22:14:33 -04:00
Mike Reeves
1b0f90b7e4
sync script
2020-08-07 22:12:47 -04:00
Mike Reeves
d15d53bcdc
Add script to extract cacerts
2020-08-07 22:04:30 -04:00
Josh Brower
4b99f55e0a
Merge pull request #1155 from Security-Onion-Solutions/feature/playbook-fixes2
...
Playbook/Nav Fixes - Issue #1064
2020-08-07 17:03:32 -04:00
Josh Brower
928e5ed832
Playbook/Nav Fixes - Issue #1064
2020-08-07 17:02:48 -04:00
m0duspwnens
30e0abf326
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-07 16:43:02 -04:00
m0duspwnens
0c2ea53f25
revert back to local_salt_dir
2020-08-07 16:42:46 -04:00
m0duspwnens
b02332d84a
fix global pillar location for setup
2020-08-07 16:18:11 -04:00
m0duspwnens
7933bafd55
more fixes for importpcap node
2020-08-07 15:46:45 -04:00
m0duspwnens
d7b55c1109
add so-status map for importpcap
2020-08-07 15:21:07 -04:00
m0duspwnens
86b118ba1a
add importpcap to local assigned hostgroups yaml
2020-08-07 15:00:32 -04:00
m0duspwnens
9649994f73
add importpcap to pillar/top
2020-08-07 14:40:02 -04:00
m0duspwnens
a8147d7d3b
add importpcap to salt_checkin for setup ssl/ca
2020-08-07 14:19:58 -04:00
Jason Ertel
847939e9b2
Fixed extra space that causes global.sls file to be empty
2020-08-07 14:11:28 -04:00
m0duspwnens
fadd81c9f3
so-importpcap to ssl state
2020-08-07 13:58:29 -04:00
m0duspwnens
7c3070655b
copy_minion_tmp_files for IMPORTPCAP too
2020-08-07 13:39:17 -04:00
Josh Brower
ff209cfd65
Merge pull request #1149 from Security-Onion-Solutions/feature/wlb-parsing
...
Ingest Parsing Update for Sysmon/WEL
2020-08-07 13:37:22 -04:00
Josh Brower
3ec1b1db71
Merge pull request #1154 from Security-Onion-Solutions/feature/playbook-fixes
...
More Playbook Fixes - Issue #1064
2020-08-07 13:36:38 -04:00
Josh Brower
a8b980b6a7
More Playbook Fixes - Issue #1064
2020-08-07 13:35:43 -04:00
m0duspwnens
2d7aefed0d
add IMPORTPCAP node to set_hostname
2020-08-07 11:42:48 -04:00
m0duspwnens
7d11fc345f
dont ask for patch schedule for importpcap node
2020-08-07 11:19:31 -04:00
m0duspwnens
24b77fa855
enlarge whiptail for install type selection
2020-08-07 11:16:52 -04:00
m0duspwnens
2c6a20fee9
enlarge whiptail for install type selection
2020-08-07 11:11:21 -04:00
m0duspwnens
d668b85033
copy_ssh_key for is_importpcap also
2020-08-07 11:09:12 -04:00
m0duspwnens
fce22c1cc4
Merge remote-tracking branch 'remotes/origin/dev' into issue/1049
2020-08-07 10:27:11 -04:00
Mike Reeves
b534d2b975
Update so-functions
2020-08-07 10:05:47 -04:00
Mike Reeves
d3e6657b45
Fix Spacing
2020-08-07 10:01:40 -04:00
Mike Reeves
80550b0d76
Merge pull request #1151 from Security-Onion-Solutions/feature/minio
...
Feature/minio
2020-08-06 15:45:27 -04:00
Josh Brower
c3da302353
Merge pull request #1150 from Security-Onion-Solutions/feature/playbook-fixes
...
Simplify elastalert rules
2020-08-06 15:45:06 -04:00
Josh Brower
ddd099233a
Playbook Fixes - Issue #1064
2020-08-06 15:43:45 -04:00
Mike Reeves
bbdaee28ed
Add upload queue thread
2020-08-06 15:41:10 -04:00
Mike Reeves
16d0c02113
Fix cert dev null
2020-08-06 15:39:02 -04:00
Mike Reeves
63e31bd6b9
Add upload queue thread
2020-08-06 15:33:48 -04:00
Jason Ertel
31fd0b6407
Update the Hunt event fields lookups to reflect the latest ingest configs
2020-08-06 14:59:39 -04:00
Josh Brower
4f9ef89098
Simplify elastalert rules
2020-08-06 14:30:44 -04:00
Josh Brower
15efe77e06
Ingest Parsing Update for Sysmon/WEL
2020-08-06 13:11:47 -04:00
Mike Reeves
4936da9b5d
Merge pull request #1146 from Security-Onion-Solutions/feature/minio
...
Feature/minio
2020-08-05 23:01:58 -04:00
Mike Reeves
e7225349a6
Ability to toggle between redis and minio
2020-08-05 22:56:41 -04:00
Mike Reeves
4e40615e51
Add tuneable to the global pillar
2020-08-05 22:47:12 -04:00
Mike Reeves
d9b1127308
Switch to gzip encoding
2020-08-05 22:36:23 -04:00
m0duspwnens
d7801acea5
add mode 1
2020-08-05 17:09:41 -04:00
Mike Reeves
633c100ace
final logstash tweaks
2020-08-05 16:40:21 -04:00
Jason Ertel
30ff6d2b93
Update event fields to reflect new ECS terms - WIP
2020-08-05 16:28:36 -04:00
William Wernert
64c366971f
[fix] Redirect ca state apply in setup to /dev/null
...
Redirect ca state apply line in accept_salt_key_remote to /dev/null to avoid generating error in setup log
2020-08-05 16:13:25 -04:00
m0duspwnens
8079dc54fc
add stuff for /etc/salt/minion to get populated for importpcap node
2020-08-05 15:42:22 -04:00
m0duspwnens
83dc35c720
add importpcap mode to whiptail
2020-08-05 15:24:11 -04:00
m0duspwnens
66ca7b266c
first commit of importpcap node mode code, kek
2020-08-05 14:44:23 -04:00
Mike Reeves
cd766753eb
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into feature/minio
2020-08-05 14:34:22 -04:00
Mike Reeves
95cae2f17a
SSL path for logstash
2020-08-05 14:14:35 -04:00
Mike Reeves
e30746c5ca
Final minio fix
2020-08-05 14:12:06 -04:00
Mike Reeves
734f2979d2
add ca.crt to lgostash docker bind
2020-08-04 23:20:51 -04:00
Mike Reeves
1855eeaa13
fix cert name
2020-08-04 23:09:08 -04:00
Mike Reeves
970ee195a1
use hostname so TLS will work
2020-08-04 23:08:33 -04:00
Mike Reeves
58872c9b48
enable ssl logstash
2020-08-04 22:40:59 -04:00
Mike Reeves
a765790d6c
fix minio container name
2020-08-04 22:37:04 -04:00
Mike Reeves
a733dceb18
enable ssl minio
2020-08-04 22:33:40 -04:00
Mike Reeves
5d4a0c53b5
add ssl cert for minio
2020-08-04 21:29:07 -04:00
Mike Reeves
61ff944087
add tmp to survive restarts
2020-08-04 18:18:06 -04:00
Mike Reeves
a2e5dca065
Fix output pillar for minio
2020-08-04 18:02:54 -04:00
Mike Reeves
38d0f519ce
Fix output pillar for minio
2020-08-04 18:00:05 -04:00
Mike Reeves
9c5a969c2e
Fix minio init
2020-08-04 17:18:09 -04:00
Mike Reeves
fd039b3008
Fix top file for minio
2020-08-04 17:11:20 -04:00
Mike Reeves
c56ead08e9
add so minio docker
2020-08-04 16:28:50 -04:00
Mike Reeves
407160b729
Update changes.json
2020-08-04 16:23:03 -04:00
Mike Reeves
24ed92c9dc
minio and change to global
2020-08-04 15:54:03 -04:00
Mike Reeves
549bf7ba19
Activate minio
2020-08-04 10:17:43 -04:00
weslambert
e9af032c28
Merge pull request #1143 from Security-Onion-Solutions/feature/aws_mgr_defaults
...
Add AWS defaults file for manager
2020-08-04 10:13:07 -04:00
Wes Lambert
46f70c254c
Add AWS defaults file for manager
2020-08-04 14:11:50 +00:00
weslambert
f7425b14e3
Merge pull request #1142 from Security-Onion-Solutions/feature/aws_eval_defaults
...
AWS defaults modifications
2020-08-03 23:51:32 -04:00
Wes Lambert
2290c28a07
AWS defaults modifications
2020-08-04 03:49:59 +00:00
Mike Reeves
7c1120e47d
Fix grafana monitor interface.
2020-08-03 18:48:01 -04:00
Jason Ertel
d1641aa0d8
chown /var/ossec dir to match the needful user/group ownership for ossec-agentd
2020-08-03 15:49:21 -04:00
Josh Patterson
51934d6e5f
Merge pull request #1137 from Security-Onion-Solutions/issue/1091
...
iunstall saltstack 3001 during setup
2020-08-03 11:39:44 -04:00
m0duspwnens
fb887f7d9e
iunstall saltstack 3001 during setup
2020-08-03 10:47:24 -04:00
weslambert
12f53ce9d9
Merge pull request #1134 from Security-Onion-Solutions/fix/aws_auto_reboot
...
Reboot after finished with setup
2020-08-03 10:31:24 -04:00
weslambert
7e2917fc99
Reboot after finished with setup
2020-08-03 10:31:03 -04:00
Jason Ertel
f47128824e
Before finishing setup, rescan the log file and root mailbox for errors
2020-08-02 09:04:29 -04:00
weslambert
9255e77263
Merge pull request #1129 from Security-Onion-Solutions/feature/aws_standalone_defaults
...
Add AWS Standalone Defaults
2020-07-31 16:15:12 -04:00
Wes Lambert
ecafbc6014
Add AWS Standalone Defaults
2020-07-31 20:12:25 +00:00
Josh Brower
f99413c84d
Merge pull request #1128 from Security-Onion-Solutions/feature/launcher-update
...
Osquery & WLB Parsing Update for WEL & Sysmon
2020-07-31 16:07:41 -04:00
Josh Brower
4d66d37ac5
Merge branch 'dev' into feature/launcher-update
2020-07-31 16:07:33 -04:00
Josh Brower
d971d07720
Osquery & WLB Parsing Update for WEL & Sysmon
2020-07-31 16:06:15 -04:00
Josh Patterson
40272b2ed0
Merge pull request #1126 from Security-Onion-Solutions/issue/1091
...
Issue/1091
2020-07-31 13:53:28 -04:00
m0duspwnens
b3b67ff2a5
Merge remote-tracking branch 'remotes/origin/dev' into issue/1091
2020-07-31 13:50:11 -04:00
m0duspwnens
d16d2b6551
full path to salt bootstrap
2020-07-31 13:42:06 -04:00
m0duspwnens
e3581bb76e
change to salt-common
2020-07-31 13:36:21 -04:00
m0duspwnens
13c9fa3089
test minion upgrade at end
2020-07-31 13:32:12 -04:00
m0duspwnens
1e1d6a395d
cant get grains.filter_by to work for some reason
2020-07-31 13:25:37 -04:00
m0duspwnens
d7ad2fbfd7
move include
2020-07-31 13:17:56 -04:00
m0duspwnens
dd865f6a68
change map
2020-07-31 13:10:37 -04:00
m0duspwnens
173f945fc0
remove comma
2020-07-31 13:01:37 -04:00
m0duspwnens
d6f89cb09a
fix ubuntu salt-common package name
2020-07-31 12:37:19 -04:00
m0duspwnens
7287f5f935
wordsmithing
2020-07-30 17:01:17 -04:00
m0duspwnens
da9dc42a47
more logging
2020-07-30 16:47:40 -04:00
m0duspwnens
2ad17dfd06
dont append
2020-07-30 16:42:59 -04:00
m0duspwnens
8d044084e1
try to log soup
2020-07-30 16:41:21 -04:00
Josh Brower
ed8d443fe5
Merge pull request #1125 from Security-Onion-Solutions/feature/launcher-update
...
Fleet - Update osquery config for 4.4 windows_events
2020-07-30 16:35:42 -04:00
Josh Brower
4e01ef2795
Fleet - Update osquery config for 4.4 windows_events
2020-07-30 16:34:48 -04:00
m0duspwnens
de7f67ff2f
fix UPGRADECOMMAND
2020-07-30 16:31:37 -04:00
m0duspwnens
f209deac98
call detect_os function
2020-07-30 16:25:45 -04:00
m0duspwnens
914d890a51
fix UPGRADECOMMAND
2020-07-30 16:21:01 -04:00
m0duspwnens
8180f2cd93
remove quotes
2020-07-30 16:13:38 -04:00
m0duspwnens
cc48b55acf
change state name
2020-07-30 16:06:01 -04:00
m0duspwnens
1492d132ca
add ability to upgrade salt minion and master for ubuntu
2020-07-30 16:00:50 -04:00
m0duspwnens
a4fc2cbd42
caps
2020-07-30 13:50:22 -04:00
m0duspwnens
4bf4634762
ensure yum versionlock with a state rather than cmd.run state
2020-07-30 13:47:21 -04:00
m0duspwnens
6812d3f5c5
change output wording, add periods
2020-07-30 13:35:09 -04:00
m0duspwnens
a562d70fe2
stop salt minion first then salt master
2020-07-30 13:18:59 -04:00
m0duspwnens
8a8705f469
move when we check for salt minion update in setup
2020-07-30 12:41:09 -04:00
m0duspwnens
9570efbf8e
fix opt check
2020-07-30 12:15:09 -04:00
m0duspwnens
c099f3c5ec
change if for optargs
2020-07-30 11:49:34 -04:00
m0duspwnens
de0b34a66b
change if for optargs
2020-07-30 11:43:18 -04:00
m0duspwnens
1c5e6fa10f
change if for optargs
2020-07-30 11:39:58 -04:00
m0duspwnens
e9d889f719
fix regex
2020-07-30 11:33:19 -04:00
m0duspwnens
2222bce77b
update regex
2020-07-30 11:22:12 -04:00
m0duspwnens
728afdcaaf
exit soup if batch size invalid
2020-07-30 11:18:27 -04:00
m0duspwnens
3d4a96fae0
update ssl state unless , check and upgrade salt minion if needed during install
2020-07-30 11:16:37 -04:00
weslambert
00ba4ca6c0
Merge pull request #1121 from Security-Onion-Solutions/fix/thehive_static
...
Fix/thehive static
2020-07-30 10:27:43 -04:00
weslambert
4282930f08
Update cortex-application.conf
2020-07-30 10:26:49 -04:00
weslambert
c58ee8a37d
Add Cortex play secret
2020-07-30 10:25:53 -04:00
weslambert
b6a053070f
Change TheHive play secret
2020-07-30 10:25:07 -04:00
weslambert
2fab00458b
Add randomized play secrets for Cortex + TheHive
2020-07-30 10:23:00 -04:00
Mike Reeves
55053748df
Merge pull request #1119 from Security-Onion-Solutions/fix/2.0.3
...
2.0.3
2020-07-30 09:52:04 -04:00
m0duspwnens
14584b28e1
include salt state in salt.minion, manager salt-minion service in salt.minion state;
2020-07-29 16:04:47 -04:00
m0duspwnens
3e78c88114
update salt top to run salt.minion state if defined version not installed. only apply other states if proper version installed
2020-07-29 15:52:48 -04:00
Mike Reeves
1e15786430
Update VERIFY_ISO.md
2020-07-29 15:48:37 -04:00
Mike Reeves
c73d4aa690
Update sig file for 2.0.3
2020-07-29 15:40:02 -04:00
m0duspwnens
22b757f112
dont install new minion if already installed
2020-07-29 15:36:35 -04:00
m0duspwnens
03144446c8
revert branch to original code
2020-07-29 14:59:00 -04:00
m0duspwnens
5a814f8312
change condidtional statement
2020-07-29 14:41:58 -04:00
m0duspwnens
8c466f548b
update wording
2020-07-29 14:38:42 -04:00
m0duspwnens
171aa1178a
fix vars and if statement
2020-07-29 14:36:42 -04:00
m0duspwnens
8a44d4752b
fix var def
2020-07-29 14:26:57 -04:00
m0duspwnens
c949845218
only try to upgrade salt on grid if salt upgraded on manager
2020-07-29 14:20:17 -04:00
m0duspwnens
b8c0653818
soup upgrade salt on minions - add batch size option
2020-07-29 14:18:11 -04:00
weslambert
646bf1cb4d
Merge pull request #1118 from Security-Onion-Solutions/fix/wazuh_register_to
...
Fix/wazuh registration timeout
2020-07-29 13:53:45 -04:00
weslambert
c48ba8abaf
Re-arrange config
2020-07-29 13:52:12 -04:00
weslambert
9db390023b
Increase timeout from 10s to 30s
2020-07-29 13:51:46 -04:00
m0duspwnens
0de6e86cdb
dont run booststrap-salt if the proper version is installed
2020-07-29 13:39:55 -04:00
m0duspwnens
b9d0bd86ca
fbkeylink and fbcertlink owned by socore:socore
2020-07-29 13:27:06 -04:00
m0duspwnens
9b29dff04f
only generate p8 files if the key used for genetation changes
2020-07-29 11:40:45 -04:00
m0duspwnens
dca3855f81
remove always update if branch specified
2020-07-29 10:50:11 -04:00
m0duspwnens
b67e3507d3
always update and clean dockers
2020-07-29 10:13:30 -04:00
Mike Reeves
e3da326fcb
Remove non used pillar items
2020-07-29 09:27:18 -04:00
weslambert
4b36c4a809
Merge pull request #1115 from Security-Onion-Solutions/fix/remove_ls_syslog
...
Remove LS syslog port binding
2020-07-29 08:35:41 -04:00
weslambert
7d432091e2
Remove LS syslog port binding
2020-07-29 08:35:07 -04:00
Josh Brower
e7b9e001e1
mysql init.sls - change startup time from 2 min to 15min
...
Closes https://github.com/Security-Onion-Solutions/securityonion/issues/1106
2020-07-28 22:08:00 -04:00
m0duspwnens
f056a0a17b
use import_yaml
2020-07-28 17:09:53 -04:00
m0duspwnens
8905869db2
move salt pillars to defaults
2020-07-28 16:58:44 -04:00
m0duspwnens
bfae439c90
salt state distribute bootstrap script
2020-07-28 16:37:14 -04:00
Doug Burks
cf63e891b5
Update changes.json
2020-07-28 16:29:03 -04:00
m0duspwnens
4d5c8e5c2b
add salt minion state to install/upgrade salt-minion
2020-07-28 16:22:42 -04:00
Mike Reeves
b46b7ae1a0
Update changes.json
2020-07-28 16:19:16 -04:00
Mike Reeves
db89089291
Update README.md
2020-07-28 16:15:59 -04:00
Mike Reeves
1ff440b7b0
Update VERSION
2020-07-28 16:15:23 -04:00
Josh Brower
b1c09a9b72
Typo fix - ingest parser - win.eventlogs
2020-07-28 15:23:17 -04:00
m0duspwnens
c00b452f8d
change module.run for ca state
2020-07-28 15:10:16 -04:00
m0duspwnens
73830123b6
Merge remote-tracking branch 'remotes/origin/dev' into issue/1091
2020-07-28 14:32:07 -04:00
m0duspwnens
307945e260
dont state salt-minion service, allow salt state to start it during highstate
2020-07-28 13:51:28 -04:00
m0duspwnens
2067cc118f
remove broken logging
2020-07-28 13:25:43 -04:00
m0duspwnens
77acb8f348
change ot /opt/so/log
2020-07-28 13:20:01 -04:00
m0duspwnens
d8375cce14
touch soup log
2020-07-28 13:15:47 -04:00
m0duspwnens
73a1a05404
change back sed delimiters, last highstate log level to info
2020-07-28 13:11:38 -04:00
Josh Brower
fe76f1c87c
Merge pull request #1111 from Security-Onion-Solutions/feature/refactor-sysmon-parsing
...
initial refactor - beats/sysmon parsing
2020-07-28 11:04:13 -04:00
Josh Brower
55e60cb749
initial refactor - beats/sysmon parsing
2020-07-28 11:03:33 -04:00
m0duspwnens
fb453a0d9c
change sed delimiters in soup
2020-07-28 08:13:03 -04:00
m0duspwnens
254dcdb2f0
prevent dockers from redownloading if we are updating soup to a branch
2020-07-27 18:19:26 -04:00
m0duspwnens
f42a39ca69
allow soup to continue update if branch is specified
2020-07-27 18:08:27 -04:00
m0duspwnens
e811718ebc
change to salt 3001.1, fix dupe state name, add git branch option to soup
2020-07-27 17:53:02 -04:00
m0duspwnens
7606cc0ad0
changes to ssl state for salt 3001
2020-07-27 15:51:31 -04:00
weslambert
0f6ecdf38a
Merge pull request #1104 from Security-Onion-Solutions/feature/cortex_orguser
...
Create default orguser if empty
2020-07-27 09:50:23 -04:00
Wes Lambert
e81fd7464b
Create default orguser if empty
2020-07-27 13:49:17 +00:00
weslambert
ced51761fa
Merge pull request #1103 from Security-Onion-Solutions/feature/wazuh_version
...
Bump Wazuh version
2020-07-27 09:46:27 -04:00
Wes Lambert
ac5aeb4801
Bump Wazuh version
2020-07-27 13:45:34 +00:00
weslambert
88ffd0c17c
Merge pull request #1101 from Security-Onion-Solutions/feature/wazuh_symlinks
...
Add Wazuh Wazuh symlinks for config/rules
2020-07-27 08:15:58 -04:00
Wes Lambert
51e27cadc8
Add Wazuh Wazuh symlinks for cpnfig/rules
2020-07-27 12:14:43 +00:00
weslambert
2d2bebdd9c
Merge pull request #1100 from Security-Onion-Solutions/feature/wazuh_nsm
...
Move Wazuh from /opt/so/ to /nsm/wazuh
2020-07-27 07:59:39 -04:00
Wes Lambert
958ee25f6d
Move Wazuh from /opt/so/ to /nsm/wazuh
2020-07-27 11:58:12 +00:00
weslambert
2d096ddd66
Merge pull request #1096 from Security-Onion-Solutions/fix/elastalert_thehive
...
Make sure we are searching all clusters when running rules
2020-07-24 18:05:46 -04:00
Wes Lambert
3ac9f1800b
Make sure we are searching all clusters when running rules
2020-07-24 22:04:30 +00:00
m0duspwnens
78491e1fc5
soup update salt on manager for centos - https://github.com/Security-Onion-Solutions/securityonion/issues/1091
2020-07-24 15:06:06 -04:00
William Wernert
6c9c60b8dd
Merge branch 'master' into dev
...
# Conflicts:
# VERSION
2020-07-24 11:50:34 -04:00
Doug Burks
25f6ec861a
Merge pull request #1090 from Security-Onion-Solutions/fix/2.0.2
...
Fix/2.0.2
2020-07-24 11:47:19 -04:00
Mike Reeves
2cabcd4239
Update sig file and hashes
2020-07-24 10:19:38 -04:00
Mike Reeves
91e7a474d5
Update VERIFY_ISO.md
2020-07-24 10:18:09 -04:00
Mike Reeves
79c45156c2
Update changes.json
2020-07-23 22:13:02 -04:00
Mike Reeves
31daad1e5b
Update VERIFY_ISO.md
...
still needs MD5s etc
2020-07-23 22:11:22 -04:00
Mike Reeves
650c983a2e
Update README.md
2020-07-23 22:09:05 -04:00
Mike Reeves
95bb1147ca
Update VERSION
2020-07-23 22:08:23 -04:00
Jason Ertel
ec09c064d0
If SENSOR_CHECKIN_INTERVAL_MS is still not set when using in a template, fallback to 10s
2020-07-23 21:19:45 -04:00
Jason Ertel
39426afffd
Ensure SENSOR_CHECKIN_INTERVAL_MS var is non-null before saving static pillar
2020-07-23 21:00:10 -04:00
Jason Ertel
9eeb527ea7
Include UTC parameter when providing a hyperlink to Hunt from so-import-pcap output
2020-07-23 17:18:42 -04:00
Mike Reeves
bb6871a54a
Merge pull request #1087 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERIFY_ISO.md
2020-07-23 15:29:32 -04:00
Mike Reeves
261310ce92
Update VERIFY_ISO.md
2020-07-23 15:28:37 -04:00
Mike Reeves
5417b31a10
Merge pull request #1086 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERIFY_ISO.md
2020-07-23 15:27:27 -04:00
Mike Reeves
11932366cd
Update VERIFY_ISO.md
2020-07-23 15:25:53 -04:00
Doug Burks
2f73dcc6f6
Merge pull request #1085 from Security-Onion-Solutions/fix/2.0.1sig
...
Update Signature and hashes
2020-07-23 15:23:58 -04:00
Mike Reeves
acf20bf2e8
Update Signature and hashes
2020-07-23 15:20:22 -04:00
Mike Reeves
4d84b840e4
Update Signature and hashes
2020-07-23 15:16:39 -04:00
Mike Reeves
c112dfa098
Merge pull request #1074 from Security-Onion-Solutions/fix/2.0.1sig
...
Update Signature and Download Links
2020-07-23 13:36:30 -04:00
Mike Reeves
3dd8e1998d
Update Signature and Download Links
2020-07-23 13:33:12 -04:00
Mike Reeves
d66f424e5e
Merge pull request #1072 from Security-Onion-Solutions/fix/2.0.1-pcap-interval
...
Fix/2.0.1 Update Readme and changes.json
2020-07-23 12:12:13 -04:00
Mike Reeves
4b127010ee
Update changes.json
2020-07-23 11:59:20 -04:00
Mike Reeves
75477fe9bf
Update changes.json
2020-07-23 11:56:14 -04:00
Mike Reeves
30fa9872f9
Update README.md
2020-07-23 10:38:26 -04:00
Jason Ertel
1e993da31d
Merge master into dev to pull in 2.0.1-rc.1 patch
2020-07-23 09:56:42 -04:00
William Wernert
f3c24f1f01
[fix] Add check for $TESTING
2020-07-21 16:43:21 -04:00
William Wernert
c70bb9e58f
Merge pull request #1053 from Security-Onion-Solutions/feature/storage-calculation
...
Feature/storage calculation
2020-07-21 16:41:12 -04:00
William Wernert
752d1bceb4
[fix] Remove old storage space check
2020-07-21 16:36:37 -04:00
William Wernert
ddf0a5055e
[fix] Exit on NO
2020-07-21 16:34:08 -04:00
William Wernert
003271127a
[feat] Only check storage during setup on a network install
2020-07-21 16:32:28 -04:00
William Wernert
c531395452
Merge branch 'dev' into feature/storage-calculation
2020-07-21 16:24:28 -04:00
William Wernert
e43829b22c
[fix] Add then to if statement
2020-07-21 16:24:13 -04:00
William Wernert
d6f7dcb630
[refactor] Changes to storage requirements
...
See #1047
2020-07-21 15:35:13 -04:00
Jason Ertel
d2df405cf0
so-import-pcap improvements: Ensure PCAP filenames with spaces are handled properly; Provide link directly to the imported logs, filtered by import ID; Require sudo access to run so-import-pcap
2020-07-21 11:07:09 -04:00
Mike Reeves
abc68c2efb
Update VERIFY_ISO.md
2020-07-21 08:51:46 -04:00
Jason Ertel
3281467994
When running in automated mode, cat all piped in input to setup log
2020-07-20 20:26:35 -04:00
Jason Ertel
e881f4c92b
Increment VERSION for dev to 2.1.0-rc.2; Add more logging to troubleshoot automated setup not initiating post-installation steps
2020-07-20 17:37:53 -04:00
William Wernert
6f73d62400
Merge branch 'dev' into feature/nginx-update
2020-07-20 13:13:32 -04:00
William Wernert
a5c790c31e
[fix] managerr -> manager
2020-07-10 17:50:53 -04:00
William Wernert
8b146aac32
Merge branch 'dev' into feature/nginx-update
...
# Conflicts:
# salt/nginx/etc/nginx.conf
# salt/nginx/etc/nginx.conf.so-eval
# salt/nginx/etc/nginx.conf.so-manager
# salt/nginx/etc/nginx.conf.so-managersearch
# salt/nginx/etc/nginx.conf.so-mastersearch
# salt/nginx/etc/nginx.conf.so-standalone
2020-07-10 17:49:34 -04:00
William Wernert
81006ebbd0
[fix] Reflect new manager syntax
2020-07-10 17:46:15 -04:00
William Wernert
49e5cb311e
[fix][WIP] set ssl cert for redirect 443 server block
2020-07-08 16:05:48 -04:00
William Wernert
533ed395e7
[fix][WIP] Remove ssl and http2 from redirect server block
2020-07-08 15:59:31 -04:00
William Wernert
a0ffe26334
[fix] Only one default_server is allowed per port
2020-07-08 15:56:36 -04:00
William Wernert
0c3e35c55e
[fix] correct jinja template syntax
2020-07-08 14:30:27 -04:00
William Wernert
cfd1b82e00
[refactor] Redirect to correct url_base + combine configs
2020-07-08 13:49:33 -04:00