Mike Reeves
36207d0440
Merge pull request #2417 from Security-Onion-Solutions/patch/2.3.21
...
2.3.21
2020-12-21 20:02:04 -05:00
Mike Reeves
88bfe7c49c
Update VERIFY_ISO.md
2020-12-21 19:52:31 -05:00
Mike Reeves
7116c2103b
Update Docker Clean
2020-12-21 17:06:14 -05:00
Mike Reeves
b49355d346
Update changes.json
2020-12-21 16:54:55 -05:00
Mike Reeves
aecde2dd54
Update README.md
2020-12-21 16:54:10 -05:00
Mike Reeves
f2d8c7f10d
Update VERSION
2020-12-21 16:53:30 -05:00
Mike Reeves
627d4da432
Merge pull request #2403 from Security-Onion-Solutions/fix/so-analyst-typo
...
fix typo in so-analyst-install warning
2020-12-21 11:48:25 -05:00
m0duspwnens
a18c89d804
fix typo in so-analyst-install warning
2020-12-21 11:42:03 -05:00
Mike Reeves
7b8f5aa8a9
Merge pull request #2402 from Security-Onion-Solutions/dev
...
2.3.20
2020-12-21 10:26:50 -05:00
Mike Reeves
1f9151b407
Update README.md
2020-12-21 10:21:28 -05:00
TOoSmOotH
def8dc0e1e
2.3.20 ISO sig
2020-12-21 09:58:25 -05:00
Mike Reeves
88be7bca3f
Update VERIFY_ISO.md
2020-12-21 09:56:18 -05:00
Mike Reeves
a0f00e09c1
2.3.20 Readme Update
2020-12-21 09:55:23 -05:00
weslambert
def08895d5
Merge pull request #2393 from Security-Onion-Solutions/fix/strelka_filestream
...
Fix/strelka filestream
2020-12-18 15:48:54 -05:00
weslambert
2fee2ca143
Change identifier name to be more descriptive
2020-12-18 15:40:54 -05:00
weslambert
7453626b06
Add identifier
2020-12-18 15:39:52 -05:00
Josh Patterson
4ccb80c9c8
Merge pull request #2392 from Security-Onion-Solutions/fix/sensoroni_fw
...
fix duplicate state name for fw
2020-12-18 15:02:52 -05:00
m0duspwnens
ad45779978
fix duplicate state name for fw
2020-12-18 15:01:55 -05:00
Josh Patterson
83326518c4
Merge pull request #2391 from Security-Onion-Solutions/fix/sensoroni_fw
...
Fix/sensoroni fw
2020-12-18 14:16:33 -05:00
m0duspwnens
66f62b912e
Merge remote-tracking branch 'remotes/origin/dev' into fix/sensoroni_fw
2020-12-18 14:14:55 -05:00
m0duspwnens
4bbedfa027
put portgroup name in statename
2020-12-18 14:14:45 -05:00
Josh Patterson
5275583098
Merge pull request #2388 from Security-Onion-Solutions/fix/grafana_sensor_uptime
...
limit sensor uptime in grafana dash to 2 decimal
2020-12-18 13:41:54 -05:00
m0duspwnens
e756bbc430
limit sensor uptime in grafana dash to 2 decimal
2020-12-18 13:40:55 -05:00
Mike Reeves
dea88e4c68
Update soup
2020-12-18 13:27:08 -05:00
Josh Patterson
dec6cdd3c5
Merge pull request #2385 from Security-Onion-Solutions/fix/sensoroni_fw
...
add sensoroni port to minions for manager nodes
2020-12-18 13:08:16 -05:00
m0duspwnens
dbf82a891f
add sensoroni port to minions for manager nodes
2020-12-18 13:06:14 -05:00
Mike Reeves
96bd1e72a7
Update soup
2020-12-18 11:55:24 -05:00
weslambert
1a463bccaf
Add cron.absent to remove old cron job if present
2020-12-18 11:25:14 -05:00
Josh Patterson
b0db910e7a
Merge pull request #2384 from Security-Onion-Solutions/fix/telegraf_stenoloss
...
make sure timestamp on steno log line has changed so we don't snapshot the drop%
2020-12-18 11:02:29 -05:00
m0duspwnens
90dcad7e6f
make sure timestamp on steno log line has changed so we dont snapshot the drop%
2020-12-18 11:00:24 -05:00
weslambert
9493aad1a5
Read from dedicated unprocessed dir
2020-12-18 10:53:17 -05:00
weslambert
bf76c1b58c
Create unprocessed dir and move Zeek extracted files there
2020-12-18 10:52:14 -05:00
Mike Reeves
575098e368
Update init.sls
2020-12-17 20:23:38 -05:00
Mike Reeves
39425c1ba8
Fix extra extrahosts
2020-12-17 20:15:56 -05:00
TOoSmOotH
6448ddc31a
Allow SNs to resolve the ES master
2020-12-17 20:08:21 -05:00
Josh Patterson
89a9816d50
Merge pull request #2379 from Security-Onion-Solutions/fix/telegraf-suriloss
...
tell dc to use 4 decimal spot for suriloss calc
2020-12-17 18:08:35 -05:00
m0duspwnens
412e8eeccb
tell dc to use 4 decimal spot for suriloss calc
2020-12-17 18:05:25 -05:00
Mike Reeves
6ccbe47f10
Fix Jinja
2020-12-17 16:34:49 -05:00
Mike Reeves
6fcc11eac2
Fix setup
2020-12-17 16:31:25 -05:00
Mike Reeves
b6f2cdce8c
Fix whiptail menu
2020-12-17 15:57:13 -05:00
Jason Ertel
370a2cdb81
Update change.json for 2.3.20
2020-12-17 15:49:09 -05:00
TOoSmOotH
96ebb98fc6
Change wording about true clustering again
2020-12-17 15:34:29 -05:00
TOoSmOotH
336ec18e09
Change wording about true clustering
2020-12-17 15:32:34 -05:00
TOoSmOotH
d99596ad06
Fix Docker Settings on new installs
2020-12-17 15:21:29 -05:00
William Wernert
1f523deaea
[fix] Playbook setup bug fixes
...
* Increase timeout for port check
* Exit with non-zero code in user create script if timeout exceeded or error occurs
2020-12-17 12:23:06 -05:00
Jason Ertel
e0dc6cbb41
Update screenshots with new Grid menu change
2020-12-17 11:15:49 -05:00
Josh Brower
5719b12968
Merge pull request #2373 from Security-Onion-Solutions/bugfix/so-suricata-testrule
...
Fix so-suricata-testrule
2020-12-17 11:08:26 -05:00
Josh Brower
73ad89f4ba
Fix so-suricata-testrule
2020-12-17 11:05:57 -05:00
Josh Patterson
011dc48d96
Merge pull request #2363 from Security-Onion-Solutions/fix/grafana-eval
...
Fix/grafana eval
2020-12-16 18:05:02 -05:00
m0duspwnens
027929bb6d
fix eval grafana dashboard
2020-12-16 17:59:54 -05:00
TOoSmOotH
345710a48d
Make sure thehive is up then soup by hitting api
2020-12-16 17:41:38 -05:00
m0duspwnens
90e499f6e9
fix eval grafana dashboard
2020-12-16 17:25:56 -05:00
TOoSmOotH
23110d3b33
Make sure thehive is up then soup
2020-12-16 17:23:51 -05:00
William Wernert
384456a991
[fix] Make repo directory during soup if it doesn't exist
2020-12-16 16:18:17 -05:00
TOoSmOotH
6e84227525
Add DB migration for thehive
2020-12-16 16:06:05 -05:00
Josh Patterson
3ff99da302
Merge pull request #2359 from Security-Onion-Solutions/fix/so-status-import-node
...
Fix/so status import node
2020-12-16 14:22:08 -05:00
m0duspwnens
2d497cb724
change to just Hunt
2020-12-16 14:15:57 -05:00
Mike Reeves
eecb323459
remove extra state.apply common
2020-12-16 13:12:38 -05:00
m0duspwnens
2e278586f2
disable steno in so-status for import node
2020-12-16 13:03:24 -05:00
m0duspwnens
81e2b4d572
Merge remote-tracking branch 'remotes/origin/dev' into fix/so-status-import-node
2020-12-16 12:02:39 -05:00
m0duspwnens
96b72d46be
show steno,zeek,suricata as disabled in so-status on import node
2020-12-16 12:01:48 -05:00
Mike Reeves
09b5e6d227
Fix SSL issue
2020-12-16 11:57:27 -05:00
William Wernert
9c8fc5e6ed
[fix] Make parent directories if needed
2020-12-16 11:16:14 -05:00
William Wernert
6ba3c16c75
[fix] Actually count containers when checking count
2020-12-16 11:10:57 -05:00
William Wernert
d670f96dc0
[fix] Exit on command failure in so-catrust
2020-12-16 11:07:00 -05:00
William Wernert
a959b4b2cd
[fix] Helix sensor needs so-soc and so-elasticsearch images downloaded
2020-12-16 11:00:48 -05:00
William Wernert
142649b396
[fix] Fix comparator
2020-12-16 10:38:34 -05:00
William Wernert
e464117e8a
[fix] Run so-catrust in ES state on Helix sensor install
2020-12-16 10:19:44 -05:00
William Wernert
aa0d43b1db
[fix] Always define ismanager var
2020-12-16 09:55:09 -05:00
Josh Patterson
bdbb466d69
Merge pull request #2357 from Security-Onion-Solutions/fix/sensoroni_steno_pillar
...
Fix/sensoroni steno pillar
2020-12-16 09:40:06 -05:00
TOoSmOotH
8889c79afd
Run a common state first to fix docker race condition
2020-12-16 09:39:41 -05:00
m0duspwnens
448d0e079e
add whitespace removal to the front
2020-12-16 09:39:25 -05:00
m0duspwnens
f0999abd8e
add missing %
2020-12-16 09:38:21 -05:00
m0duspwnens
c68b87db56
set steno running default based on sensor role or not
2020-12-16 09:33:44 -05:00
William Wernert
a1fc354a89
[fix] Correct ordering of printf lines
2020-12-16 09:32:36 -05:00
TOoSmOotH
b858136672
Add jertel complaince
2020-12-16 09:24:59 -05:00
William Wernert
af149d04a9
[fix] Only run portions of ES state, do not run container
2020-12-16 09:18:40 -05:00
William Wernert
a4897d2063
[fix] Add Elasticsearch to containers running on Helix sensor
2020-12-16 09:07:38 -05:00
TOoSmOotH
805e25f495
Fix typeo
2020-12-15 20:40:59 -05:00
TOoSmOotH
4ca4141819
Fix conditional statement
2020-12-15 19:29:35 -05:00
TOoSmOotH
f1be6cc259
Check MD5 of all components
2020-12-15 18:32:07 -05:00
TOoSmOotH
e30d7a8d8e
Fix upgrade docker variable
2020-12-15 18:25:41 -05:00
TOoSmOotH
87882b4d91
Fix upgrade function
2020-12-15 18:18:26 -05:00
TOoSmOotH
082fd51b05
Remove extra variable
2020-12-15 17:07:40 -05:00
TOoSmOotH
04a26df4f7
Fix the features suffix
2020-12-15 17:05:33 -05:00
Jason Ertel
e3c8018824
Toggle strelka rules after the user is prompted it strelka should be installed to ensure strelka rules are updated later during the setup process
2020-12-15 16:44:52 -05:00
TOoSmOotH
7909834722
Clean up previous upgrade dirs in temp
2020-12-15 16:23:49 -05:00
Mike Reeves
06dd3432f8
Copy the correct files over that soup needs
2020-12-15 16:13:51 -05:00
Mike Reeves
6cab65a548
Update so-image-common
2020-12-15 16:06:21 -05:00
Jason Ertel
e58ca93896
Add logging for strelka configuration during setup
2020-12-15 15:46:59 -05:00
William Wernert
15347d1209
[fix] More condition changes for Helix
2020-12-15 15:08:33 -05:00
William Wernert
c7c3d004ca
[fix] More helix -> helixsensor
2020-12-15 14:01:19 -05:00
William Wernert
1825776271
[fix] helix -> helixsensor
2020-12-15 13:58:36 -05:00
William Wernert
951556902c
[fix] Accept salt key on Helix Sensor install
2020-12-15 13:41:00 -05:00
William Wernert
7ba10ee698
[fix] Add HELIXSENSOR to case for Ubuntu
2020-12-15 13:38:00 -05:00
William Wernert
343e9f8b2c
[fix] Only try to stop/remove containers if at least one exists
2020-12-15 13:37:46 -05:00
William Wernert
e89c06f71b
[fix] Add backslash for newline
2020-12-15 13:37:21 -05:00
William Wernert
f7d02763e8
[fix] Move FEATURESCHECK var assignment, fix indentation
2020-12-15 13:07:21 -05:00
William Wernert
f70d828aa6
[fix] Create array correctly
2020-12-15 13:04:09 -05:00
Jason Ertel
3da7a26e88
Remove jinja whitespace trimming to avoid syntax error in bash
2020-12-15 12:37:05 -05:00
Mike Reeves
922534a5da
Merge pull request #2352 from Security-Onion-Solutions/soup2320
...
SOUP Features
2020-12-15 12:07:19 -05:00
TOoSmOotH
80a61d3316
SOUP Features
2020-12-15 12:06:30 -05:00
Mike Reeves
bf1f00d2fe
Merge pull request #2348 from Security-Onion-Solutions/soup2320
...
SOUP Changes
2020-12-14 21:19:45 -05:00
TOoSmOotH
cbd59ed86a
SOUP Changes
2020-12-14 20:46:31 -05:00
Josh Brower
efe44323cb
Merge pull request #2346 from Security-Onion-Solutions/bugfix/fleet-patch
...
Swap localhost for 127.0.0.1
2020-12-14 15:49:58 -05:00
William Wernert
aa281f849f
[feat] Add message about dropping to command line when setting up ssh key
2020-12-14 15:31:25 -05:00
William Wernert
f4c4a16f54
Merge pull request #2343 from Security-Onion-Solutions/experimental
...
Experimental
2020-12-14 14:27:52 -05:00
Jason Ertel
aa479b9c8e
Move node address/desc into the minion pillar
2020-12-14 12:42:16 -05:00
William Wernert
3e2a9cc884
Merge branch 'dev' into experimental
2020-12-14 12:32:53 -05:00
William Wernert
a533e6fa35
[fix] Always set INSTALLUSERNAME var
2020-12-14 11:42:34 -05:00
Josh Patterson
de3f86724a
Merge pull request #2335 from Security-Onion-Solutions/issue/1586
...
remove old firewall ports pillar file
2020-12-14 11:15:34 -05:00
m0duspwnens
4e04f31b8e
remove old firewall ports pillar file https://github.com/Security-Onion-Solutions/securityonion/issues/1586
2020-12-14 10:24:49 -05:00
Doug Burks
7a314b5935
Prevent Wazuh "last -n 20" logs from going to Alerts queue #2321
2020-12-12 11:35:29 -05:00
Doug Burks
61ae187d03
revert previous commit #2321
2020-12-12 10:12:23 -05:00
Josh Brower
73d23e6d17
Revert "Initial support - Playbook Overrides"
...
This reverts commit 8915e49288 .
2020-12-12 10:07:30 -05:00
Josh Brower
8faf80a03b
Revert "Playbook db updates"
...
This reverts commit 35be785f7a .
2020-12-12 10:07:23 -05:00
Mike Reeves
b5ed973abd
Merge pull request #2138 from OmerTirosh/OmerTirosh-fix-win.eventlog
...
Fix Error: SO elasticsearch ingest failed to convert 'winlog.event_data.SubjectUserName' to 'user.name'
2020-12-12 10:00:27 -05:00
Doug Burks
85aac4ad75
Prevent Wazuh "last -n 20" logs from going to Alerts queue #2321
2020-12-12 09:22:08 -05:00
Jason Ertel
fd7fe72b2a
Correct default address pool base value
2020-12-11 23:29:59 -05:00
Jason Ertel
c5a3597564
Swap AWS interfaces
2020-12-11 21:57:56 -05:00
Josh Brower
66495e6bae
Swap localhost for 127.0.0.1
2020-12-11 17:38:42 -05:00
Jason Ertel
42c8f1e325
Use eth0/eth1 instead of ens5/ens6 in AWS
2020-12-11 15:34:16 -05:00
Jason Ertel
bb61c1f745
Cleanup bash imports/sources, function definitions, and variables
2020-12-11 15:33:31 -05:00
Josh Patterson
e4eea6a616
Merge pull request #2320 from Security-Onion-Solutions/issue/2319
...
zeek file extraction can now be manipulated with zeek pillar
2020-12-11 14:38:10 -05:00
m0duspwnens
09b3a4a0dd
merge pillar with the defaults https://github.com/Security-Onion-Solutions/securityonion/issues/2319
2020-12-11 14:35:06 -05:00
m0duspwnens
b8e8510dd2
merge pillar with the defaults https://github.com/Security-Onion-Solutions/securityonion/issues/2319
2020-12-11 14:26:32 -05:00
Jason Ertel
eb735c7289
Replace duplicate random generator with common function
2020-12-11 13:22:13 -05:00
Josh Patterson
2f2867804a
Merge pull request #2318 from Security-Onion-Solutions/issue/1175
...
pillarize grafana and allow for grafana alerts to be created
2020-12-11 12:36:06 -05:00
m0duspwnens
d877fac786
add null for max graph value https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 12:28:43 -05:00
m0duspwnens
c88a1a943d
update search and sensor node dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 12:21:16 -05:00
m0duspwnens
e3335a3106
update managersearch dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 12:00:02 -05:00
m0duspwnens
0a77a28e06
guage to graph cor cpu on manager and eval https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:51:42 -05:00
m0duspwnens
6eb64227ae
update manager dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:44:21 -05:00
m0duspwnens
5a95181b2b
update eval version 1 https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:36:19 -05:00
m0duspwnens
2fc151d923
update eval dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:34:08 -05:00
William Wernert
db276d9020
[fix] Always set hostname
2020-12-11 11:02:27 -05:00
m0duspwnens
33fde42dbc
dont show legend on pcap retention panel
2020-12-11 10:42:30 -05:00
m0duspwnens
e0e38ac37f
update standlone dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 10:39:25 -05:00
William Wernert
75c5abef30
[fix] Add all selected options to install_opts
2020-12-11 10:16:00 -05:00
Jason Ertel
0915ae30e4
Add timestamps to so-yara-update output
2020-12-11 10:08:10 -05:00
Jason Ertel
14f28e38be
Ensure so-yara-updata script is logging to a file during cron job execution
2020-12-11 10:04:43 -05:00
William Wernert
870cc6b79b
[fix][typo] readaraay -> readarray
2020-12-11 09:39:22 -05:00
William Wernert
3c7a8fe92f
[fix] Don't cd in so-variables
2020-12-11 09:39:00 -05:00
William Wernert
b6a0e692c6
[refactor] Use command -v for netplan check
2020-12-11 09:38:44 -05:00
m0duspwnens
fbcc62d5c5
Merge remote-tracking branch 'remotes/origin/dev' into issue/1175
2020-12-10 15:17:45 -05:00
m0duspwnens
733f5a5021
allowUiUpdates to dashboards to allow for alert creation on stock dashboards issue/1175
2020-12-10 15:17:22 -05:00
William Wernert
25f2075e22
[fix] Revert bad change to whiptail_basic_zeek
2020-12-10 15:01:10 -05:00
William Wernert
5c4103681c
[fix] Save original argument array to use later
2020-12-10 14:45:24 -05:00
William Wernert
ab856532e6
[fix] Show airgap option on import install
2020-12-10 14:20:48 -05:00
William Wernert
58bcc79c54
[fix] Create full dir structure, rm /root/install_opt on failure
2020-12-10 14:17:47 -05:00
William Wernert
1f1cfde3ac
[fix] Make directory for new setup download
2020-12-10 14:03:54 -05:00
William Wernert
bc6a0c1e6f
[fix] Add missing append flags to tee
2020-12-10 13:54:41 -05:00
William Wernert
8302119756
[fix] Don't redirect entire download function to setup log
2020-12-10 13:26:19 -05:00
William Wernert
21e107f2e8
[fix] Remove sudo from version check, only remove known_hosts entry if exists
2020-12-10 13:13:45 -05:00
Mike Reeves
cd6a945a24
Merge pull request #2298 from Security-Onion-Solutions/escluster
...
Traditional ES Clustering Support
2020-12-10 12:07:17 -05:00
m0duspwnens
4ee944448f
remove $Interval template var since alerts cant be crated when it is used https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-10 12:05:57 -05:00
TOoSmOotH
42833b2086
Make non clustered node attributes
2020-12-10 11:14:32 -05:00
TOoSmOotH
d9d7f49b96
Adjust elasticsearch.yml
2020-12-10 11:09:38 -05:00
William Wernert
86313796a5
[fix] Set manager_ver in download function
2020-12-10 11:00:52 -05:00
weslambert
24fce27e62
Merge pull request #2297 from Security-Onion-Solutions/feature/idstools_arg
...
Add ability to supply an arg, for example overriding 15 min limit
2020-12-10 09:31:50 -05:00
Wes Lambert
45faa7fda4
Add ability to supply an arg, for example overriding 15 min limit
2020-12-10 14:30:29 +00:00
weslambert
c2cf2c4987
Merge pull request #2296 from Security-Onion-Solutions/fix/suricata_ftp_data
...
Add initial suricata.ftp_data pipeline
2020-12-10 09:17:01 -05:00
TOoSmOotH
379f1d98d8
fix addtotab
2020-12-10 09:15:17 -05:00
Wes Lambert
f689722559
Add initial suricata.ftp_data pipeline
2020-12-10 14:14:50 +00:00
weslambert
d09daef094
Merge pull request #2288 from Security-Onion-Solutions/fix/strelka_rules
...
Expand STRELKARULES
2020-12-09 17:05:44 -05:00
weslambert
0b2e2739bd
Expand STRELKARULES
2020-12-09 17:05:11 -05:00
m0duspwnens
ea1bd63f60
makedirs and place readme file for grafana https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 16:59:38 -05:00
TOoSmOotH
af15f0eb38
remove ml node.role
2020-12-09 16:23:38 -05:00
TOoSmOotH
101ddd18a5
Fix print statments
2020-12-09 16:08:09 -05:00
Mike Reeves
3a903501fd
Merge pull request #2286 from Security-Onion-Solutions/newescluster
...
Newescluster
2020-12-09 16:01:46 -05:00
m0duspwnens
8db79ae852
comment out some defaults file https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 16:01:09 -05:00
m0duspwnens
e05da4efc2
remove odl grafana.ini file https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 15:53:01 -05:00
Mike Reeves
30e69bf7b2
Merge branch 'escluster' into newescluster
2020-12-09 15:23:49 -05:00
TOoSmOotH
0a48f7d5dc
Simplify logic
2020-12-09 15:22:09 -05:00
m0duspwnens
c320efe7e4
fix whitespace https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 14:33:19 -05:00
m0duspwnens
617ed2a7c2
add a place to place files referenced in the config https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 14:06:54 -05:00
William Wernert
522399e4ab
Merge branch 'feature/setup' into experimental
2020-12-09 13:13:58 -05:00
William Wernert
a2e48f91b2
[fix] Add manager to hosts before attempting ssh
2020-12-09 13:13:51 -05:00
William Wernert
987008811c
[fix] Make repo directory before using it
2020-12-09 12:47:35 -05:00
m0duspwnens
c5c053d24a
change to header
2020-12-09 11:59:06 -05:00
m0duspwnens
75ea648cf9
change to file.managed https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 11:57:28 -05:00
William Wernert
e29fa7ba70
Merge branch 'feature/setup' into experimental
2020-12-09 11:51:18 -05:00
William Wernert
282b4090ce
[fix] Actually call nic comparison function, redirect tarball gen to setup_log
2020-12-09 11:51:07 -05:00
TOoSmOotH
e983322a18
Fix elastic if statement
2020-12-09 11:31:22 -05:00
m0duspwnens
6b479c5a89
pillarize grafana https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 11:10:00 -05:00
William Wernert
223856c0b9
[fix] Don't redirect whiptail message, use SIGINT instead of SIGKILL
2020-12-09 10:16:42 -05:00
William Wernert
795cacecf3
[fix] Fix cut command options
2020-12-09 10:06:14 -05:00
William Wernert
f3ce2fc71e
[fix] new_setup -> manager_setup
2020-12-09 10:06:02 -05:00
William Wernert
51650147ef
[fix] Only show network init message if valid
2020-12-09 09:59:44 -05:00
William Wernert
950c05e53d
[fix] Only move error log if present
2020-12-09 09:50:30 -05:00
William Wernert
652c4d49c9
[fix] Remove extra semicolon
2020-12-09 09:47:57 -05:00
TOoSmOotH
6ceecbd524
Fixing some elasticsearch logic
2020-12-09 09:42:03 -05:00
William Wernert
a8f1ec37a3
[refactor] Remove is_smooshed var
2020-12-08 15:29:48 -05:00
William Wernert
813fe77582
[feat] Run so-analyst-install after network init
2020-12-08 15:29:31 -05:00
William Wernert
b41ba1ea3c
[feat] Compare setup version to manager, dl tarball + exec on mismatch
2020-12-08 15:29:04 -05:00
William Wernert
4899ea23f8
[fix] Put conditions in install_cleanup function
2020-12-08 14:03:59 -05:00
William Wernert
4210d25fae
[feat] Init network + soremote key early
2020-12-08 14:03:21 -05:00
William Wernert
65d994a2f8
[feat] Generate gzipped tarball of repo during setup and soup
2020-12-08 14:02:45 -05:00
William Wernert
997e2735e3
[refactor] Press -> select
2020-12-08 13:59:42 -05:00
TOoSmOotH
d6fa739c60
Adding queue=True
2020-12-08 11:17:47 -05:00
Josh Brower
f34a10a986
Merge pull request #2259 from Security-Onion-Solutions/feature/playbook-updates2
...
Playbook db updates
2020-12-08 10:36:42 -05:00
Josh Brower
35be785f7a
Playbook db updates
2020-12-08 10:35:50 -05:00
Jason Ertel
5d955bcdb7
Enable new SoStatus module in SOC for managing grid status
2020-12-08 09:22:18 -05:00
Josh Brower
5f756549b1
Merge pull request #2254 from Security-Onion-Solutions/feature/playbook-updates2
...
Initial support - Playbook Overrides
2020-12-07 22:30:50 -05:00
Josh Brower
8915e49288
Initial support - Playbook Overrides
2020-12-07 22:28:58 -05:00
Josh Patterson
2d9c6a42bf
Merge pull request #2249 from Security-Onion-Solutions/issue/2188
...
Issue/2188
2020-12-07 16:52:34 -05:00
Josh Brower
35ea6c36d2
Merge pull request #2247 from Security-Onion-Solutions/feature/so-suricata-ruletest
...
so-suricata-testrule initial commit
2020-12-07 15:12:20 -05:00
William Wernert
64dc9f8d4e
[fix] Only list ipv4 addresses when checking mysql
2020-12-07 14:40:32 -05:00
William Wernert
d88364c9fd
[feat] Create error log for easy copy/paste
...
Resolves #2165
2020-12-07 14:18:01 -05:00
William Wernert
08ab36927d
[refactor] Kill parent script on exit
2020-12-07 14:16:54 -05:00
William Wernert
6fc3232637
[fix] Set INSTALLUSERNAME to the user running the script
...
Resolves #2243
2020-12-07 14:16:06 -05:00
William Wernert
4363b082bb
Merge branch 'dev' into feature/setup
2020-12-07 14:15:11 -05:00
Mike Reeves
8ea088c3fc
Restart Elastic on addition of node.
2020-12-07 14:09:41 -05:00
m0duspwnens
b5e0b21400
Merge remote-tracking branch 'remotes/origin/dev' into issue/2188
2020-12-07 11:52:09 -05:00
m0duspwnens
19d27c7d68
remove docker-ce-cli from common state
2020-12-07 11:50:47 -05:00
William Wernert
38324c226e
[fix] Don't let grep output message on file not found
2020-12-07 10:58:58 -05:00
m0duspwnens
4fe2de2637
upgrade docker https://github.com/Security-Onion-Solutions/securityonion/issues/2188
2020-12-07 10:47:20 -05:00
William Wernert
edc8ccd1b6
Merge branch 'feature/main-ip-validation' into feature/setup
2020-12-07 09:53:38 -05:00
William Wernert
3136c66780
[fix] Bring back network setup before setting MAINIP var
2020-12-07 08:50:53 -05:00
Josh Brower
134d9bc89a
so-suricata-testrule initial commit
2020-12-06 17:08:11 -05:00
William Wernert
d724fe7357
Merge pull request #2201 from Security-Onion-Solutions/bugfix/reinstall
...
Bugfix/reinstall
2020-12-04 09:38:46 -05:00
William Wernert
fca50660a2
[fix] Trap argument off by one
2020-12-04 09:33:28 -05:00
William Wernert
1c1b835c71
Merge branch 'bugfix/reinstall' into experimental
2020-12-03 15:44:04 -05:00
William Wernert
7b43c2955e
[fix] kill old restart pid and assign new pid for start
2020-12-03 15:42:15 -05:00
William Wernert
ff1cfb578f
Only kill+start on final loop and increase time between status checks
2020-12-03 15:42:15 -05:00
William Wernert
7458313d3d
[fix] Also kill+start while trying to restart service initially
2020-12-03 15:42:15 -05:00
William Wernert
39dce13cf6
[fix] Move set_redirect out of sub-shell
2020-12-03 15:42:15 -05:00
William Wernert
916db4acec
[fix] kill/start after if statement
2020-12-03 15:42:15 -05:00
William Wernert
2e516629f9
[fix] Kill + start salt-minion if it isn't responding
2020-12-03 15:42:15 -05:00
William Wernert
3273a63662
[fix] kill old restart pid and assign new pid for start
2020-12-03 15:38:26 -05:00
William Wernert
660c768f8f
Only kill+start on final loop and increase time between status checks
2020-12-03 15:38:26 -05:00
William Wernert
ebade0a5a6
[fix] Also kill+start while trying to restart service initially
2020-12-03 15:38:26 -05:00
William Wernert
ac85cbc3f1
[fix] Move set_redirect out of sub-shell
2020-12-03 15:38:26 -05:00
William Wernert
b5bfad07dc
[fix] kill/start after if statement
2020-12-03 15:38:26 -05:00
William Wernert
3049718660
[fix] Kill + start salt-minion if it isn't responding
2020-12-03 15:38:25 -05:00
William Wernert
80ce8b5e41
[refactor] Run all changes inside whiptail progress, use grep -q
2020-12-03 15:38:25 -05:00
William Wernert
2c208ec943
[fix] kill -> stop, add indent to service check, revert incorrect logic
2020-12-03 15:38:25 -05:00
William Wernert
76fff28dfa
[fix] Correct logic for service check + bash trap
2020-12-03 15:38:25 -05:00
William Wernert
af8295a651
[reafactor] systemctl stop -> kill
2020-12-03 15:38:25 -05:00
William Wernert
ddcf5dec5b
[refactor] Run all changes inside whiptail progress, use grep -q
2020-12-03 13:59:25 -05:00
Jason Ertel
967111decc
Add node address to sensoroni pillar
2020-12-03 11:24:45 -05:00
Mike Reeves
94253e92a6
Adjust the elasticsearch config
2020-12-03 10:38:18 -05:00
William Wernert
f410c451cd
[fix] kill -> stop, add indent to service check, revert incorrect logic
2020-12-03 10:31:45 -05:00
William Wernert
786665d8cf
[fix] Correct logic for service check + bash trap
2020-12-03 10:18:44 -05:00
weslambert
c41d4373b7
Merge pull request #2192 from Security-Onion-Solutions/fix/elasticsearch_bool_query_clause_count
...
Add indices.query.bool.max_clause_count to allow for wildcard searche…
2020-12-03 09:30:24 -05:00
weslambert
95570976a8
Add indices.query.bool.max_clause_count to allow for wildcard searches targeting more than 1024 fields
2020-12-03 09:29:44 -05:00
weslambert
a84f816eff
Merge pull request #2189 from Security-Onion-Solutions/feature/so-elastic-scripts
...
so-elastic scripts
2020-12-03 09:20:47 -05:00
Wes Lambert
4ce3ec7582
Make scripts executable
2020-12-03 14:18:22 +00:00
Wes Lambert
f96365baba
Add intial grouped Elastic start/stop/restart scripts
2020-12-03 14:17:32 +00:00
William Wernert
9c919f3c92
[reafactor] systemctl stop -> kill
2020-12-02 17:07:49 -05:00
Jason Ertel
cf0ec2f78f
Default to the node's primary IP for the description field
2020-12-02 16:38:33 -05:00
Mike Reeves
3e322c38eb
Fix config for single cluster mode
2020-12-02 15:33:35 -05:00
William Wernert
46d2342c8b
Merge branch 'bugfix/reinstall' into experimental
2020-12-02 14:45:46 -05:00
Mike Reeves
d004263b71
Add Elastic Clustering
2020-12-02 14:33:22 -05:00
William Wernert
fc7fe23590
[fix] Correct signal naming
2020-12-02 14:06:50 -05:00
William Wernert
cc5d54764a
[fix] sed masks command return code, remove
2020-12-02 13:54:02 -05:00
William Wernert
8fe43d6d56
[fix] Print WARNING instead of ERROR if minion is not responding initially
2020-12-02 13:35:57 -05:00
Mike Reeves
69ae4577f5
Merge pull request #2174 from Security-Onion-Solutions/escluster
...
Escluster
2020-12-02 13:23:08 -05:00
William Wernert
467f9923b0
[refactor] Add trap to handle script exits, change what files are deleted in /etc/salt/
2020-12-02 13:19:34 -05:00
weslambert
c819729cd6
Don't use max_files or time_to_live for shutdown params
2020-12-02 13:17:19 -05:00
Josh Patterson
54d8dcdbb0
Merge pull request #2173 from Security-Onion-Solutions/issue/2079
...
Issue/2079
2020-12-02 11:46:29 -05:00
William Wernert
2d4fe58299
[fix] Also kill currently running jobs
2020-12-01 21:43:38 -05:00
William Wernert
4b5b936abb
[fix] echo -> return
2020-12-01 21:40:41 -05:00
William Wernert
2d6feea5c5
[fix] Syntax fixes
2020-12-01 21:21:32 -05:00
William Wernert
38028a543a
[feat] Add timeout for salt services to stop during reinstall init
2020-12-01 21:18:24 -05:00
Jason Ertel
b7bc8db3b2
Modify PCAP quick action to work off of network community ID; Add new Correlate quick action
2020-12-01 17:37:44 -05:00
Jason Ertel
81b86bf7f2
Switch PCAP quick actions to support alternative lookup link when a single event ID is not available
2020-12-01 16:04:50 -05:00
m0duspwnens
ff6951cd95
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/2079
2020-12-01 15:38:15 -05:00
m0duspwnens
141d7a35c9
if true cluster enabled allow search nodes to talk to each other https://github.com/Security-Onion-Solutions/securityonion/issues/2079
2020-12-01 15:38:09 -05:00
William Wernert
c2e7e42509
[fix] Don't SIGKILL salt services + disable highstate schedule
2020-12-01 15:36:05 -05:00
weslambert
0e8f547087
Merge pull request #2160 from Security-Onion-Solutions/fix/strelka_mmbot
...
Remove ScanMmbot
2020-12-01 11:26:14 -05:00
weslambert
9517cb2a58
Remove ScanMmbot
2020-12-01 11:25:51 -05:00
Josh Brower
c303cdff09
Merge pull request #2150 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fleet Fixes - mysql race condition
2020-11-30 18:06:30 -05:00
Josh Brower
e7a927188b
Fleet Fixes - mysql race condition
2020-11-30 17:28:11 -05:00
William Wernert
8a8885e14f
[feat] Verify that main ip = mngmt ip
...
* Add a check to check whether the src ip in the routing table is also the ip assigned to the management nic
2020-11-30 16:53:02 -05:00
Josh Brower
8e9458ca84
Merge pull request #2149 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fix Fleet setup errors
2020-11-30 12:06:36 -05:00
Josh Brower
5d2acf4011
Fix Fleet setup errors
2020-11-30 12:06:02 -05:00
William Wernert
8964444eeb
[fix] Correct count print in mysql_conn
2020-11-30 11:32:43 -05:00
William Wernert
ec81e8565f
[fix] Add safety logic to retry var in mysql_conn
2020-11-30 11:32:28 -05:00
William Wernert
040b435278
[refactor] Fail mysql_conn if the mainint has > 1 ip address
2020-11-30 11:10:50 -05:00
Josh Brower
704f024441
Merge pull request #2146 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fleet standalone - fix event
2020-11-30 10:33:05 -05:00
Josh Brower
65d8005629
Fleet standalone - fix event
2020-11-30 10:32:39 -05:00
Josh Brower
7fddf99648
Merge pull request #2128 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fix Fleet setup errors
2020-11-27 13:59:19 -05:00
Josh Brower
f52c30bff5
Fix Fleet setup errors
2020-11-27 13:58:41 -05:00
Josh Brower
19a33c5c2a
Merge pull request #2126 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Bugfix/fleet standalone
2020-11-27 11:45:25 -05:00
Josh Brower
19b36f0468
Fleet standalone redirect fix
2020-11-27 11:43:51 -05:00
Josh Brower
95a664e12a
Merge pull request #2103 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fleet standalone fix
2020-11-25 14:09:27 -05:00
Josh Brower
38afd67108
Fleet standalone fix
2020-11-25 14:08:30 -05:00
Jason Ertel
979f171828
Add missing comma to sensoroni.json
2020-11-25 12:29:45 -05:00
Jason Ertel
8f9081618f
Add role to sensoroni.json file
2020-11-25 11:11:46 -05:00
Jason Ertel
7fb264b4fe
Use double quotes around agent key to ensure interpolation
2020-11-24 17:17:50 -05:00
Jason Ertel
d20560385f
Remove /nsm/wazuh/etc subdir state since confirmed the Wazuh docker container itself
2020-11-24 16:50:46 -05:00
Jason Ertel
e1147398cc
Ensure /nsm/wazuh is owned by ossec
2020-11-24 15:48:46 -05:00
Jason Ertel
8864428a00
Ensure setup output is redirected to logfile
2020-11-24 15:45:40 -05:00
Jason Ertel
ea9bbfd1aa
Improve wazuh agent registration with retry logic to wait for manager to become ready
2020-11-24 13:53:20 -05:00
weslambert
0c4ee94472
Merge pull request #2077 from Security-Onion-Solutions/fix/thehive_upgrade_conf
...
Fix/thehive upgrade conf
2020-11-24 11:52:51 -05:00
weslambert
39bf60feb7
Add digit
2020-11-24 11:52:20 -05:00
weslambert
35653d2e66
Changes for ES7
2020-11-24 11:51:19 -05:00
weslambert
eb2364b926
Changes for ES7
2020-11-24 11:49:08 -05:00
Josh Patterson
9bb485cdc9
Merge pull request #2074 from Security-Onion-Solutions/issue/2040
...
Issue/2040
2020-11-24 11:45:08 -05:00
m0duspwnens
fe2662cab8
dont enable steno pillar on import node https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 11:42:03 -05:00
m0duspwnens
995a377432
squigly comma if steno enabled https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 11:31:41 -05:00
weslambert
e3a41c2a94
Changes for ES7 elasticsearch.yml
2020-11-24 11:20:09 -05:00
Mike Reeves
ddca9563e5
Merge branch 'mkrmerge' into escluster
2020-11-24 10:29:57 -05:00
OmerTirosh
e2ee0db727
Ignore failure for rename processor
...
Ignore failure for winlog.event_data.SubjectUserName rename processor.
For some event ids (for example 4688), this field already been added in winlogbeat JS processor.
Therefor, elastic throw [user.name] already exists error.
2020-11-24 17:21:47 +02:00
m0duspwnens
4dfd49ef39
add vars https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 10:11:28 -05:00
m0duspwnens
65334d15ea
https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 09:33:38 -05:00
Jason Ertel
1e32a01657
Create symlink before registration otherwise registration script can't save it's state (.log) file into the conf subdir; add more logging output to track down registration failures
2020-11-23 18:36:19 -05:00
Jason Ertel
bafefb980b
Update so-elastalert-test script for compatibility with SO 2.3
2020-11-23 10:45:56 -05:00
Mike Reeves
426769588a
Merge pull request #1739 from jtgreen-cse/patch-2
...
fix for Windows events via osquery
2020-11-21 13:27:05 -05:00
Josh Patterson
a183be489c
Merge pull request #2030 from Security-Onion-Solutions/master
...
Merge master to dev
2020-11-20 17:00:31 -05:00
Josh Patterson
b29ffcac92
Merge pull request #2029 from Security-Onion-Solutions/soup-ubuntu-salt
...
fix issue with proper salt.minion state execution for ubuntu
2020-11-20 16:55:45 -05:00
Jason Ertel
78f5727f6f
Improve so-ip-update prompts
2020-11-20 15:16:07 -05:00
m0duspwnens
0d3754200f
fix issue with proper salt.minion state execution for ubuntu
2020-11-20 14:27:07 -05:00
Jason Ertel
bc40a2bfc5
Correct so-import-pcap wrapping; add so-pcap-import alias for so-import-pcap; prompt to reboot after changing IP address on manager; ensure all tools have exec bit set
2020-11-20 14:14:03 -05:00
Jason Ertel
f074179656
Correct so-import-pcap wrapping; add so-pcap-import alias for so-import-pcap; prompt to reboot after changing IP address on manager; ensure all tools have exec bit set
2020-11-20 14:14:03 -05:00
William Wernert
b6e36d4d06
Merge pull request #2023 from Security-Onion-Solutions/bugfix/bug-hunt
...
Bugfix/bug hunt
2020-11-20 13:04:33 -05:00
William Wernert
2e6be747d9
[fix] Fixes for quiet flag in so-ssh-harden
2020-11-20 11:18:40 -05:00
William Wernert
1a11c24f03
[fix] Add newline escapes to so-ssh-harden
2020-11-20 11:13:40 -05:00
William Wernert
d15064b294
Merge branch 'dev' into bugfix/bug-hunt
2020-11-20 10:15:52 -05:00
William Wernert
d3ef46a5f6
Merge pull request #2020 from Security-Onion-Solutions/bugfix/pre-whiptail-message
...
[fix] Remove echo redirect at beginning of install
2020-11-20 10:15:24 -05:00
William Wernert
9d837f7b45
[fix] Reload sshd if config changes are made
...
Fixes #1976
2020-11-20 10:09:14 -05:00
William Wernert
e62b52da1b
[fix] Add condition to zeek state during setup for ZEEKVERSION
...
Fixes #1990
2020-11-20 09:58:07 -05:00
William Wernert
79ec1de83a
[fix] Add exit check for static ip whiptail menus
...
Fixes #1992
2020-11-20 09:56:48 -05:00
Jason Ertel
9fb8a6d482
Increment version to 2.3.20
2020-11-19 16:53:34 -05:00
Mike Reeves
5344d30d56
Merge pull request #2003 from Security-Onion-Solutions/dev
...
2.3.10
2020-11-19 16:48:53 -05:00
Mike Reeves
4051111999
Update hashes and keys
2020-11-19 16:00:40 -05:00
Mike Reeves
316a1c02f1
Update soup to display what its doing
2020-11-19 15:19:50 -05:00
Josh Patterson
c07f62f8d1
Merge pull request #2007 from Security-Onion-Solutions/fix/minon
...
kill salt process with soup and dont restart salt-minion service when…
2020-11-19 15:17:58 -05:00
m0duspwnens
cdc7a5cc7c
kill salt process with soup and dont restart salt-minion service when salt upgrade
2020-11-19 15:17:11 -05:00
Josh Patterson
10a3e6f414
Merge pull request #2006 from Security-Onion-Solutions/fix/minon
...
change typo on minon to minion
2020-11-19 15:11:16 -05:00
m0duspwnens
2a3951ab36
change typo on minon to minion
2020-11-19 15:08:08 -05:00
Mike Reeves
67a8c4e8cb
Update Readme
2020-11-19 11:27:15 -05:00
Mike Reeves
177819447b
Update Sigs and Hashes
2020-11-19 11:26:08 -05:00
Mike Reeves
3be1c9ae32
Clean up 2.3.1 dockers
2020-11-19 09:58:08 -05:00
William Wernert
ac3b5e4f1b
[fix] Remove echo redirect at beginning of install
2020-11-19 09:48:56 -05:00
Josh Brower
b79e1c3225
Merge pull request #1987 from Security-Onion-Solutions/bugfix/playbookdb-user
...
playbook mysqluser
2020-11-18 20:48:49 -05:00
Josh Brower
d3065005ca
playbook mysqluser
2020-11-18 20:48:02 -05:00
Josh Patterson
26e97d5875
Merge pull request #1984 from Security-Onion-Solutions/salt/3002.2
...
upgrade from salt 3002.1 to salt 3002.2
2020-11-18 18:26:11 -05:00
m0duspwnens
d68726f6ef
upgrade from salt 3002.1 to salt 3002.2
2020-11-18 18:25:02 -05:00
Josh Patterson
f81da406da
Merge pull request #1983 from Security-Onion-Solutions/soup-verify-salt
...
dont highstate, just restart salt-minion
2020-11-18 17:40:36 -05:00
m0duspwnens
afd466cd2b
dont highstate, just restart salt-minion
2020-11-18 17:27:25 -05:00
Josh Patterson
6d228a836f
Merge pull request #1982 from Security-Onion-Solutions/soup-verify-salt
...
add -X so bootstrap doesnt try to start salt-minion during soup
2020-11-18 16:45:05 -05:00
m0duspwnens
1805effdc0
add -X so bootstrap doesnt try to start salt-minion during soup
2020-11-18 16:32:53 -05:00
Jason Ertel
1170b04a87
Update changes for 2.3.10
2020-11-18 16:18:00 -05:00
Josh Patterson
c0b43d3319
Merge pull request #1981 from Security-Onion-Solutions/soup-verify-salt
...
add back -s
2020-11-18 15:50:04 -05:00
m0duspwnens
6cc9d1c076
add back -s
2020-11-18 15:49:30 -05:00
William Wernert
1c55bb6db2
[fix] Only backup /nsm/mysql and /nsm/wazuh
2020-11-18 15:34:40 -05:00
Josh Brower
3d0003555a
Merge pull request #1980 from Security-Onion-Solutions/bugfix/soup-regen-osquery
...
SOUP - Regen Osquery Packages
2020-11-18 14:56:23 -05:00
Josh Brower
0830f63c4e
SOUP - Regen Osquery Packages
2020-11-18 14:55:14 -05:00
Josh Patterson
adbd8d6956
Merge pull request #1979 from Security-Onion-Solutions/soup-verify-salt
...
Soup verify salt
2020-11-18 14:49:03 -05:00
William Wernert
80d0080f70
[fix] Only set is_reinstall if it's needed
2020-11-18 14:47:53 -05:00
m0duspwnens
af6e14dc6f
highstate , merge with dev fix conflict
2020-11-18 14:47:40 -05:00
William Wernert
8b6b7cbd11
[fix] Check if $is_reinstall is true
2020-11-18 14:46:22 -05:00
William Wernert
e65c53dbb1
[fix] Don't rename /nsm/docker-registry
2020-11-18 14:01:33 -05:00
m0duspwnens
ceef07b74b
remove pkill
2020-11-18 14:00:01 -05:00
William Wernert
280cde43ff
[fix] install_type -> setup_type
2020-11-18 13:51:55 -05:00
William Wernert
81b9658499
[fix] Don't remove accept_changes file
2020-11-18 13:51:55 -05:00
weslambert
04c6bed779
Merge pull request #1977 from Security-Onion-Solutions/fix/zeek_log_inode_cleanup
...
Change clean_removed to true to clean up tracking of Zeek logs removed fr…
2020-11-18 13:49:46 -05:00
weslambert
6b4af30fc1
Change clean_removed to true cleanup tracking of Zeek logs removed from current
2020-11-18 13:47:32 -05:00
m0duspwnens
1e2b404836
remove -s
2020-11-18 13:29:42 -05:00
m0duspwnens
276c011a4f
queue state and change upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 13:22:11 -05:00
William Wernert
34fd80182e
[fix][wip] Don't use variable for accept_changes file
2020-11-18 12:54:36 -05:00
Jason Ertel
57e9f69c97
Add new so-ip-update script (Work in progress)
2020-11-18 12:35:38 -05:00
William Wernert
0542e0aa04
[fix] info -> title
2020-11-18 12:35:16 -05:00
m0duspwnens
d0e7b5b55a
only ensure salt-minion service is running if salt is on right verison https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 12:32:21 -05:00
William Wernert
ad74b4b3e0
[refactor][fix] Update reinstall logic
...
* Only set reinstall flag if new accept_changes file exists
* Instead of stopping highstate from running, kill all salt processes and remove their configs
* Make end of non-reinstall logs clear in cases where user cancels (and log not rotated)
2020-11-18 12:29:54 -05:00
m0duspwnens
ce70e0a61f
changes to upgradecommand https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 11:51:28 -05:00
William Wernert
8a4defcffa
[refactor] Check for setup log earlier
...
* Check for sosetuo.log before any scripts besides so-variables are sourced to make sure the log hasn't been created yet.
2020-11-18 11:16:36 -05:00
m0duspwnens
bddc3d6df9
kill all salt-minion again since they hang and redirect highstate to a logfile
2020-11-18 10:40:23 -05:00
m0duspwnens
4bb1ad9799
dont restart or kill salt-minon in upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 09:29:09 -05:00
William Wernert
bc0c395b7f
Merge pull request #1963 from Security-Onion-Solutions/feature/rem-so-setup-perm-entry
...
Feature/rem so-setup perm entry
2020-11-18 09:12:25 -05:00
m0duspwnens
67dc71ab49
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-18 08:36:23 -05:00
m0duspwnens
c95619d335
change upgradecommand order https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 08:35:56 -05:00
Jason Ertel
bfbc0f354c
Only default to logging out to tty if tty exists as a character device
2020-11-17 22:48:40 -05:00
m0duspwnens
5c6e9e0e3a
run a highstate and let that start the salt-minion back up https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 19:40:42 -05:00
m0duspwnens
7291d64e82
pkill salt-minion before restartiong salt-minion service https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 18:38:01 -05:00
m0duspwnens
695cce0b50
upgrad command changes https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 17:54:56 -05:00
m0duspwnens
42126f125b
change verison check to !=
2020-11-17 17:00:59 -05:00
m0duspwnens
2bfc48be35
change check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:31:11 -05:00
m0duspwnens
7d1cf56160
change check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:29:35 -05:00
m0duspwnens
1fd2196dd5
fix check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:18:50 -05:00
m0duspwnens
65b84f1bd7
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-17 16:09:47 -05:00
m0duspwnens
fcfd3e3758
change location yum/apt verison locks https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 16:09:30 -05:00
William Wernert
ee3708a428
[fix] Move sudoers check in soup to correct place + fix styling issue
2020-11-17 15:44:20 -05:00
William Wernert
b146700303
[feat] Remove so-setup permission from sudoers file after iso setup
...
Closes #1701
2020-11-17 15:36:25 -05:00
Jason Ertel
1ec8b52353
Replace scan.exiftool.* fields due to reduction in strelka field counts
2020-11-17 15:12:06 -05:00
Josh Patterson
f8346cde08
Merge pull request #1962 from Security-Onion-Solutions/soup-verify-salt
...
Soup verify salt
2020-11-17 15:08:32 -05:00
m0duspwnens
e162be2e1d
change salt upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 14:29:39 -05:00
m0duspwnens
4f4f64a47d
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-17 13:16:18 -05:00
m0duspwnens
4cd1086efa
new way for soup to install and resart salt for upgrade
2020-11-17 13:15:55 -05:00
Mike Reeves
2184c3b8ee
Revert "The Hive ES update"
...
This reverts commit 88c2ee0d36 .
2020-11-17 12:51:42 -05:00
Mike Reeves
65d28f98b5
Revert "The Hive ES Update"
...
This reverts commit f31d459a24 .
2020-11-17 12:51:13 -05:00
Jason Ertel
aa8d9c12a0
Remove yara rule update that can't succeed since the script doesn't exist at this point of the setup process
2020-11-17 12:15:27 -05:00
Mike Reeves
f31d459a24
The Hive ES Update
2020-11-17 11:59:03 -05:00
Mike Reeves
88c2ee0d36
The Hive ES update
2020-11-17 11:58:22 -05:00
Jason Ertel
d13733e716
Queue the registry state in case a highstate is already active
2020-11-17 09:59:09 -05:00
Josh Patterson
86922a2388
Merge pull request #1959 from Security-Onion-Solutions/soup-verify-salt
...
verify new salt version is installed during soup if not, exit before proceeding
2020-11-17 09:53:08 -05:00
m0duspwnens
65440f9aef
verify new salt version is installed during soup if not, exit before proceeding
2020-11-17 09:51:28 -05:00
William Wernert
12c661101a
Merge pull request #1958 from Security-Onion-Solutions/feat/require-min-nics
...
Feat/require min nics
2020-11-17 09:49:09 -05:00
William Wernert
79b63ed14b
[fix] Use singular when needed for requirements
2020-11-17 09:47:08 -05:00
Josh Brower
cc4357d567
Merge pull request #1954 from Security-Onion-Solutions/bugfix/ingest-mappings
...
Cleanup & fix sysmon pid ingest
2020-11-17 09:05:31 -05:00
Jason Ertel
b9267ee015
Add missing newline after armor header
2020-11-17 09:00:02 -05:00
Jason Ertel
5c310327e4
Merge pull request #1942 from Security-Onion-Solutions/jertel/refactor-seed
...
Jertel/refactor seed
2020-11-16 18:46:28 -05:00
Jason Ertel
4311f66110
Remove unnecessary redirect
2020-11-16 16:58:09 -05:00
Josh Patterson
a8644478b5
Merge pull request #1939 from Security-Onion-Solutions/fix/nginx-nonmanager
...
fix nginx for non manaager/fleet nodes
2020-11-16 16:47:39 -05:00
m0duspwnens
4436f02f6d
fix nginx for non manaager/fleet nodes
2020-11-16 16:46:22 -05:00
Jason Ertel
3cf8afc1dd
Remove unused redirect descriptors and ensure gpg import output is not leaked to console
2020-11-16 16:39:54 -05:00
Josh Patterson
f1e33b6eea
Merge pull request #1938 from Security-Onion-Solutions/fix/so.status-module
...
fix so-status to work with so.status module and change padding
2020-11-16 16:35:08 -05:00
m0duspwnens
0d9b22fe2d
fix so-status to work with so.status module and change padding
2020-11-16 16:33:29 -05:00
William Wernert
a08923030b
[feat] Exit setup if less than required number of NICs present
2020-11-16 16:26:38 -05:00
Jason Ertel
1ec4af1a4d
Destroy the old registry before updating SO images
2020-11-16 15:41:15 -05:00
Jason Ertel
5ae78d4108
Install curl in order to test for cloud
2020-11-16 15:31:40 -05:00
Jason Ertel
3bae243915
Continued refactoring of bash
2020-11-16 15:20:00 -05:00
Jason Ertel
8234b6f835
Switch remaining containers over to new registries; Continued bash refactoring
2020-11-16 15:11:08 -05:00
Josh Patterson
55231eab25
Merge pull request #1934 from Security-Onion-Solutions/fix/so-status-in-setup
...
redirect output from setting up so-status stuff in so-setup
2020-11-16 14:57:58 -05:00
m0duspwnens
e956ee9324
redirect output from setting up so-status stuff in so-setup
2020-11-16 14:56:20 -05:00
Jason Ertel
a343e3f31e
Save descriptors while inside the progress pipe
2020-11-16 14:10:48 -05:00
Jason Ertel
2ff738a61c
Refactor docker_seed_registry to eliminate duplicate logic
2020-11-16 13:27:23 -05:00
William Wernert
c226c1d902
[fix] Redirect stderr when checking for link state
2020-11-16 11:30:47 -05:00
Josh Patterson
7a49c55ea0
Merge pull request #1930 from Security-Onion-Solutions/issue/1831
...
Issue/1831
2020-11-16 10:09:49 -05:00
m0duspwnens
cc50eba6cb
make sure /opt/so/log/salt/so-salt-minion-check gets touched even if salt-minon verison isnt correct https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-16 10:01:40 -05:00
m0duspwnens
5c25dcf192
add /opt/so/log/salt/so-salt-minion-check to log rotate https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-16 09:50:10 -05:00
Jason Ertel
c744d389f7
More bash cleanup
2020-11-15 10:44:14 -05:00
Jason Ertel
76c917d977
Continued bash cleanup
2020-11-15 09:57:12 -05:00
Josh Brower
1908a68330
Cleanup & fix sysmon pid ingest
2020-11-14 16:19:23 -05:00
Jason Ertel
d22040fb5d
Annual fall bash cleanup event
2020-11-14 11:53:31 -05:00
Jason Ertel
372f694cc1
Set curl type to 'features' when adding features to existing installation
2020-11-14 11:04:40 -05:00
Jason Ertel
1c079f7ff4
Remove duplicate docker pull/sigverify logic from so-features-enable; Provide current SO version to curl
2020-11-14 10:35:45 -05:00
m0duspwnens
4e6e29e7dc
update logging
2020-11-13 20:26:06 -05:00
m0duspwnens
43a244e0da
change log path https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 19:37:03 -05:00
m0duspwnens
e958246457
touch file at start of highstate, just kill salt dont systemctl stop it https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 19:34:17 -05:00
m0duspwnens
b210092534
logging changes issue/1831
2020-11-13 19:09:53 -05:00
m0duspwnens
e820c6fa42
logging changes issue/1831
2020-11-13 19:04:09 -05:00
m0duspwnens
71a409f210
fix threshold logic https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 18:23:55 -05:00
m0duspwnens
a5823be0ac
fix typo
2020-11-13 17:55:19 -05:00
Mike Reeves
13c261178a
fix soup so-image-common
2020-11-13 17:26:04 -05:00
m0duspwnens
2f0eaff8b3
sbin
2020-11-13 17:25:45 -05:00
Mike Reeves
977eea131e
fix soup so-image-common
2020-11-13 17:18:55 -05:00
Mike Reeves
fb9b07b0eb
fix soup so-image-common
2020-11-13 17:13:05 -05:00
m0duspwnens
6a010bb3e6
change var name
2020-11-13 17:08:47 -05:00
Mike Reeves
51b3e066be
fix soup so-image-common
2020-11-13 17:01:42 -05:00
Mike Reeves
7dfb8f5b12
fix soup so-image-common
2020-11-13 16:50:12 -05:00
Mike Reeves
23f2dee840
fix soup so-image-common
2020-11-13 16:30:34 -05:00
m0duspwnens
4275fcbf22
Merge remote-tracking branch 'remotes/origin/dev' into issue/1831
2020-11-13 16:28:58 -05:00
Jason Ertel
ee97f5eaac
Remove unnecessary branch var; allow skipping of tag/push step
2020-11-13 16:17:09 -05:00
m0duspwnens
0a807621cc
check health of salt-minion https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 16:02:28 -05:00
Mike Reeves
8577fa63a3
fix network install download
2020-11-13 14:28:27 -05:00
Mike Reeves
50175f7e42
soup should now copy the common image functions
2020-11-13 14:25:29 -05:00
Mike Reeves
3173c6fd3c
Change user agent string for docker refresh
2020-11-13 14:09:29 -05:00
Mike Reeves
069908ec56
Change user agent string for docker refresh
2020-11-13 13:55:26 -05:00
Mike Reeves
09f3199cc2
Change user agent string for docker refresh
2020-11-13 13:39:52 -05:00
Josh Brower
adec9ad48b
Merge pull request #1916 from Security-Onion-Solutions/feature/so-playbook-reset
...
Feature/so playbook reset
2020-11-13 11:21:50 -05:00
Josh Brower
8b3262ce1b
Add so-playbook-reset
2020-11-13 11:20:39 -05:00
weslambert
4fad0e3a98
Merge pull request #1914 from Security-Onion-Solutions/fix/syslog_parsing
...
Syslog updates
2020-11-13 11:07:53 -05:00
Wes Lambert
fddfb8eb92
Syslog updates
2020-11-13 16:06:22 +00:00
Jason Ertel
210a7bc65b
Merge curator closed-delete-delete changes from the abandoned 2.3.3 release
2020-11-13 10:05:23 -05:00
William Wernert
8a7ff3260d
Merge pull request #1911 from Security-Onion-Solutions/feature/ssh-harden-script
...
[feat] Add ssh-harden script
2020-11-13 09:00:07 -05:00
William Wernert
2f27b6f2fa
[feat] Add ssh-harden script
2020-11-13 08:51:28 -05:00
Mike Reeves
52e909007f
Change url and clean up sigs
2020-11-12 16:08:27 -05:00
Mike Reeves
80aeffe1ad
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-12 11:53:41 -05:00
Mike Reeves
cbca2d702f
Add Version back to sig files
2020-11-12 11:53:30 -05:00
Automation
af44cce423
Auto-publish so-acng image signature
2020-11-12 16:39:54 +00:00
Automation
7d81080076
Auto-publish so-grafana image signature
2020-11-12 16:39:24 +00:00
Automation
6194d85180
Auto-publish so-idstools image signature
2020-11-12 16:38:38 +00:00
Automation
88675ec2ee
Auto-publish so-strelka-manager image signature
2020-11-12 16:37:53 +00:00
Automation
9c0a1bc8b9
Auto-publish so-fleet image signature
2020-11-12 16:37:24 +00:00
Automation
52babc686d
Auto-publish so-fleet-launcher image signature
2020-11-12 16:36:51 +00:00
Automation
9370e5b8bc
Auto-publish so-freqserver image signature
2020-11-12 16:36:01 +00:00
Automation
6c1d5451eb
Auto-publish so-strelka-backend image signature
2020-11-12 16:35:16 +00:00
Automation
f50e6ab929
Auto-publish so-strelka-filestream image signature
2020-11-12 16:34:12 +00:00
Automation
67f18a02ea
Auto-publish so-strelka-frontend image signature
2020-11-12 16:33:37 +00:00
Mike Reeves
7f491545fa
Fix Variable for docker inspect
2020-11-12 11:31:27 -05:00
Automation
9b33201ba5
Auto-publish so-minio image signature
2020-11-12 16:30:56 +00:00
Mike Reeves
aefcb9a491
Fix Variable for docker
2020-11-12 11:28:58 -05:00
Automation
fee52f8b86
Auto-publish so-redis image signature
2020-11-12 16:28:23 +00:00
Automation
e434ccd3d3
Auto-publish so-soctopus image signature
2020-11-12 16:18:25 +00:00
Automation
70a0cbae23
Auto-publish so-telegraf image signature
2020-11-12 16:17:22 +00:00
Automation
04263101cf
Auto-publish so-kibana image signature
2020-11-12 16:15:27 +00:00
Mike Reeves
312f99966e
Change docker inspect to a variable to speed it up
2020-11-12 09:39:13 -05:00
Mike Reeves
667800d830
Change docker inspect to variable to speed it up
2020-11-12 09:35:19 -05:00
Mike Reeves
2fba02f71b
Grab specific digest so re-installs work
2020-11-12 09:29:18 -05:00
Josh Patterson
4ce0b770a5
Merge pull request #1898 from jtgreen-cse/patch-3
...
fix for #1725 , grafana queries use non_negative_ variants
2020-11-12 08:55:12 -05:00
Mike Reeves
1de862985c
Merge pull request #1893 from Security-Onion-Solutions/gpg
...
GPG Docker Image Verification
2020-11-12 08:46:34 -05:00
Jason Green
4e40392c55
fix for #1725 , grafana queries use non_negative_ variants
2020-11-12 07:34:51 -05:00
Automation
d1fe79b642
Auto-publish so-thehive-es image signature
2020-11-12 02:55:19 +00:00
Automation
f96cc35d37
Auto-publish so-thehive-cortex image signature
2020-11-12 02:53:56 +00:00
Automation
388f1e753d
Auto-publish so-strelka-manager image signature
2020-11-12 02:52:24 +00:00
Automation
42382d00d8
Auto-publish so-strelka-frontend image signature
2020-11-12 02:51:38 +00:00
Automation
b086f5e5c1
Auto-publish so-strelka-filestream image signature
2020-11-12 02:50:51 +00:00
Automation
0b0f9854f9
Auto-publish so-strelka-backend image signature
2020-11-12 02:49:47 +00:00
Automation
3107f46940
Auto-publish so-logstash image signature
2020-11-12 02:48:28 +00:00
Automation
202c672798
Auto-publish so-kibana image signature
2020-11-12 02:47:00 +00:00
Automation
6ac1bc5623
Auto-publish so-freqserver image signature
2020-11-12 02:45:21 +00:00
Automation
e002015ce2
Auto-publish so-fleet-launcher image signature
2020-11-12 02:44:31 +00:00
Automation
61b5e009c7
Auto-publish so-filebeat image signature
2020-11-12 02:43:27 +00:00
Automation
f3aadcd553
Auto-publish so-elasticsearch image signature
2020-11-12 02:42:22 +00:00
Automation
71370d4522
Auto-publish so-elasticsearch image signature
2020-11-12 02:41:12 +00:00
Automation
c287b5f826
Auto-publish so-elastalert image signature
2020-11-12 02:39:48 +00:00
Automation
4286ac0dfd
Auto-publish so-domainstats image signature
2020-11-12 02:38:46 +00:00
Automation
adc937295b
Auto-publish so-tcpreplay image signature
2020-11-12 02:37:39 +00:00
Automation
96bf2c57e7
Auto-publish so-pcaptools image signature
2020-11-12 02:36:20 +00:00
Automation
5f7a28dd5d
Auto-publish so-telegraf image signature
2020-11-12 02:35:22 +00:00
Automation
3560ba933b
Auto-publish so-suricata image signature
2020-11-12 02:34:18 +00:00
Automation
9c20450832
Auto-publish so-soctopus image signature
2020-11-12 02:33:10 +00:00
Automation
d71daef2e9
Auto-publish so-playbook image signature
2020-11-12 02:31:59 +00:00
Automation
c3ae80e2c1
Auto-publish so-logstash image signature
2020-11-12 02:30:36 +00:00
Automation
2098dd16ff
Auto-publish so-influxdb image signature
2020-11-12 02:29:02 +00:00
Automation
3b4c9e02e7
Auto-publish so-idstools image signature
2020-11-12 02:28:04 +00:00
Automation
adc99ff06d
Auto-publish so-filebeat image signature
2020-11-12 02:26:57 +00:00
Automation
f9b26c9a8f
Auto-publish so-thehive image signature
2020-11-12 02:25:44 +00:00
Automation
41a123c22b
Auto-publish so-grafana image signature
2020-11-12 02:24:19 +00:00
Automation
966089e1d0
Auto-publish so-curator image signature
2020-11-12 02:22:56 +00:00
Automation
3034d5ef98
Auto-publish so-kratos image signature
2020-11-12 02:22:11 +00:00
Automation
5ab169ea52
Auto-publish so-kibana image signature
2020-11-12 02:21:20 +00:00
Automation
f858027da1
Auto-publish so-wazuh image signature
2020-11-12 02:19:52 +00:00
Automation
c7517b37fa
Auto-publish so-steno image signature
2020-11-12 02:18:25 +00:00
Automation
2f315ba5a0
Auto-publish so-redis image signature
2020-11-12 02:17:06 +00:00
Automation
ed883f173b
Auto-publish so-mysql image signature
2020-11-12 02:16:12 +00:00
Automation
a46ad6fe81
Auto-publish so-minio image signature
2020-11-12 02:15:06 +00:00
Automation
42fc0add5e
Auto-publish so-fleet image signature
2020-11-12 02:14:08 +00:00
Automation
f6c2983bd1
Auto-publish so-zeek image signature
2020-11-12 02:12:58 +00:00
Automation
0b8e19bfc8
Auto-publish so-acng image signature
2020-11-12 02:11:20 +00:00
Automation
bee829697e
Auto-publish so-soc image signature
2020-11-12 02:10:11 +00:00
Mike Reeves
ed025851ca
Change soup for new gpg verification
2020-11-11 20:13:21 -05:00
Automation
94ab77b14d
Auto-publish so-nginx image signature
2020-11-12 00:57:45 +00:00
Mike Reeves
b113dce140
remove size from gpg sig
2020-11-11 19:49:25 -05:00
Automation
a2ef12eb6a
Auto-publish so-nginx image signature
2020-11-12 00:46:11 +00:00
Automation
eb0b909cd2
Auto-publish so-nginx image signature
2020-11-12 00:41:23 +00:00
Automation
7ef2056f17
Auto-publish so-steno image signature
2020-11-11 22:17:26 +00:00
Automation
b12f29d48a
Auto-publish so-thehive-es image signature
2020-11-11 22:16:06 +00:00
Automation
5fd1fd9b0d
Auto-publish so-thehive-cortex image signature
2020-11-11 22:14:47 +00:00
Automation
ad0ecff8c5
Auto-publish so-strelka-manager image signature
2020-11-11 22:13:19 +00:00
Automation
88b6ae1b2f
Auto-publish so-strelka-frontend image signature
2020-11-11 22:12:32 +00:00
Automation
9772fd181c
Auto-publish so-strelka-filestream image signature
2020-11-11 22:11:36 +00:00
Automation
cfff8319bb
Auto-publish so-strelka-backend image signature
2020-11-11 22:10:44 +00:00
Automation
0dc7c8b0e7
Auto-publish so-logstash image signature
2020-11-11 22:09:47 +00:00
Automation
3ccd8b40b2
Auto-publish so-kibana image signature
2020-11-11 22:08:21 +00:00
Automation
ca94bd12cf
Auto-publish so-fleet-launcher image signature
2020-11-11 22:06:47 +00:00
Automation
d650e68472
Auto-publish so-filebeat image signature
2020-11-11 22:05:38 +00:00
Automation
70f9bad827
Auto-publish so-elasticsearch image signature
2020-11-11 22:04:36 +00:00
Automation
c3d6e168ae
Auto-publish so-elasticsearch image signature
2020-11-11 22:03:08 +00:00
Automation
5c9c1915f1
Auto-publish so-domainstats image signature
2020-11-11 22:01:41 +00:00
Automation
32912f2c87
Auto-publish so-freqserver image signature
2020-11-11 22:00:41 +00:00
Automation
fb70e1e40c
Auto-publish so-elastalert image signature
2020-11-11 21:59:35 +00:00
Automation
4106d88338
Auto-publish so-tcpreplay image signature
2020-11-11 21:58:50 +00:00
Automation
93f57b73e2
Auto-publish so-pcaptools image signature
2020-11-11 21:57:37 +00:00
Automation
4fa0b6be0e
Auto-publish so-telegraf image signature
2020-11-11 21:56:53 +00:00
Automation
7ec2d85286
Auto-publish so-suricata image signature
2020-11-11 21:56:06 +00:00
Automation
763d5425a5
Auto-publish so-soctopus image signature
2020-11-11 21:55:11 +00:00
Automation
4be594cbb9
Auto-publish so-playbook image signature
2020-11-11 21:54:12 +00:00
Automation
e6fd3160ca
Auto-publish so-logstash image signature
2020-11-11 21:52:59 +00:00
Automation
07871987e4
Auto-publish so-influxdb image signature
2020-11-11 21:51:49 +00:00
Automation
3c33a38098
Auto-publish so-idstools image signature
2020-11-11 21:50:43 +00:00
Automation
b24bf9b6a9
Auto-publish so-filebeat image signature
2020-11-11 21:49:41 +00:00
Automation
373d9256f2
Auto-publish so-thehive image signature
2020-11-11 21:48:26 +00:00
Automation
dde7e0bd11
Auto-publish so-grafana image signature
2020-11-11 21:46:55 +00:00
Automation
017c9c9874
Auto-publish so-curator image signature
2020-11-11 21:45:36 +00:00
Automation
871f919c27
Auto-publish so-kratos image signature
2020-11-11 21:44:53 +00:00
Automation
f67c26a8f2
Auto-publish so-kibana image signature
2020-11-11 21:43:58 +00:00
Automation
038e8fceb7
Auto-publish so-wazuh image signature
2020-11-11 21:42:21 +00:00
weslambert
8c6adc21a8
Merge pull request #1891 from Security-Onion-Solutions/syslog_cef
...
Update syslog pipeline to allow for initial CEF parsing and pipeline …
2020-11-11 16:40:55 -05:00
Automation
75b26fb2af
Auto-publish so-redis image signature
2020-11-11 21:39:49 +00:00
Wes Lambert
8258b782fc
Update syslog pipeline to allow for initial CEF parsing and pipeline targeting
2020-11-11 21:39:40 +00:00
Automation
d73542d274
Auto-publish so-nginx image signature
2020-11-11 21:38:45 +00:00
Automation
1092aa2cb1
Auto-publish so-mysql image signature
2020-11-11 21:37:49 +00:00
Automation
8668cf9a9c
Auto-publish so-minio image signature
2020-11-11 21:36:45 +00:00
Automation
b9440364f7
Auto-publish so-fleet image signature
2020-11-11 21:35:44 +00:00
Automation
4f0ebfaf1f
Auto-publish so-zeek image signature
2020-11-11 21:34:50 +00:00
Automation
b090656269
Auto-publish so-acng image signature
2020-11-11 21:33:29 +00:00
Automation
16e0a26869
Auto-publish so-soc image signature
2020-11-11 21:30:17 +00:00
Automation
bc362acf82
Auto-publish so-soc image signature
2020-11-11 21:05:43 +00:00
Jason Ertel
79cbc747ea
Run leaktest on any branch
2020-11-11 15:52:48 -05:00
Mike Reeves
2269695e75
Change gpg to sig
2020-11-11 15:50:52 -05:00
Jason Ertel
710afe9355
Merge pull request #1889 from Security-Onion-Solutions/leaktest
...
Create leaktest.yml
2020-11-11 15:46:50 -05:00
Jason Ertel
ac236a0538
Move image sigs into versioned dir
2020-11-11 15:42:25 -05:00
Jason Ertel
eb7e8079ec
Create leaktest.yml
2020-11-11 15:39:06 -05:00
Mike Reeves
8512042132
Change Sig Path
2020-11-11 15:37:11 -05:00
Automation
a234e1c898
Auto-publish so-thehive-es image signature
2020-11-11 20:20:56 +00:00
Automation
25c91192a1
Auto-publish so-thehive-cortex image signature
2020-11-11 20:19:33 +00:00
Automation
22f19bbe9e
Auto-publish so-strelka-manager image signature
2020-11-11 20:18:03 +00:00
Automation
3b31a8d8cb
Auto-publish so-strelka-frontend image signature
2020-11-11 20:17:09 +00:00
Automation
cd868d1edb
Auto-publish so-strelka-filestream image signature
2020-11-11 20:16:30 +00:00
Automation
b31ea84c00
Auto-publish so-strelka-backend image signature
2020-11-11 20:15:36 +00:00
Automation
4ed6355186
Auto-publish so-logstash image signature
2020-11-11 20:14:14 +00:00
Automation
e51c2152fa
Auto-publish so-kibana image signature
2020-11-11 20:12:38 +00:00
Automation
7af1b7a539
Auto-publish so-fleet-launcher image signature
2020-11-11 20:11:29 +00:00
Automation
debbe965fe
Auto-publish so-filebeat image signature
2020-11-11 20:10:27 +00:00
Automation
3bbaca41c9
Auto-publish so-elasticsearch image signature
2020-11-11 20:09:30 +00:00
Automation
f2d25439e2
Auto-publish so-elasticsearch image signature
2020-11-11 20:08:10 +00:00
Automation
472fdd935e
Auto-publish so-domainstats image signature
2020-11-11 20:06:33 +00:00
Automation
14304c0f28
Auto-publish so-freqserver image signature
2020-11-11 20:05:36 +00:00
Automation
6a60890c36
Auto-publish so-elastalert image signature
2020-11-11 20:04:37 +00:00
Automation
687120ce4a
Auto-publish so-tcpreplay image signature
2020-11-11 20:03:28 +00:00
Automation
5e3f99c567
Auto-publish so-pcaptools image signature
2020-11-11 20:02:05 +00:00
Automation
c2ed0a6c72
Auto-publish so-telegraf image signature
2020-11-11 20:00:55 +00:00
Automation
8ed6a3ed78
Auto-publish so-suricata image signature
2020-11-11 19:59:46 +00:00
Automation
0511c851a2
Auto-publish so-soctopus image signature
2020-11-11 19:58:35 +00:00
Automation
0c7db56053
Auto-publish so-playbook image signature
2020-11-11 19:57:18 +00:00
Automation
7fae7500e8
Auto-publish so-logstash image signature
2020-11-11 19:55:41 +00:00
Automation
25b771d36f
Auto-publish so-influxdb image signature
2020-11-11 19:54:19 +00:00
Automation
6febc290a8
Auto-publish so-idstools image signature
2020-11-11 19:53:15 +00:00
Automation
9e9a023377
Auto-publish so-thehive image signature
2020-11-11 19:52:11 +00:00
Automation
f069b8cced
Auto-publish so-filebeat image signature
2020-11-11 19:50:50 +00:00
Automation
0d42bfb7f4
Auto-publish so-grafana image signature
2020-11-11 19:49:26 +00:00
Automation
4ccc898054
Auto-publish so-curator image signature
2020-11-11 19:48:16 +00:00
Automation
2010712929
Auto-publish so-kratos image signature
2020-11-11 19:47:11 +00:00
Automation
0ad0255e8c
Auto-publish so-kibana image signature
2020-11-11 19:46:20 +00:00
Automation
ca28cc7a17
Auto-publish so-wazuh image signature
2020-11-11 19:44:58 +00:00
Automation
0fce6823db
Auto-publish so-steno image signature
2020-11-11 19:43:44 +00:00
Automation
0db072d9b2
Auto-publish so-redis image signature
2020-11-11 19:42:27 +00:00
Automation
0c3a7a6214
Auto-publish so-nginx image signature
2020-11-11 19:41:26 +00:00
Automation
a58b487a0a
Auto-publish so-mysql image signature
2020-11-11 19:40:32 +00:00
Automation
061b8d5b9b
Auto-publish so-minio image signature
2020-11-11 19:39:38 +00:00
Automation
ff1dab283c
Auto-publish so-fleet image signature
2020-11-11 19:38:45 +00:00
Automation
319867ef10
Auto-publish so-zeek image signature
2020-11-11 19:38:01 +00:00
Automation
c21131b77a
Auto-publish so-acng image signature
2020-11-11 19:36:46 +00:00
Automation
638d9ddee3
Auto-publish so-soc image signature
2020-11-11 19:35:45 +00:00
Automation
dded28a54a
Auto-publish so-kibana image signature
2020-11-11 19:33:55 +00:00
Automation
7132011ece
Auto-publish so-steno image signature
2020-11-11 19:32:05 +00:00
Mike Reeves
3a622ee71e
Hash and sig update
2020-11-11 14:29:47 -05:00
Automation
fdc1468a11
Auto-publish so-wazuh image signature
2020-11-11 18:54:25 +00:00
Automation
691f64f8a3
Auto-publish so-nginx image signature
2020-11-11 18:53:13 +00:00
Mike Reeves
a29def504e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into gpg
2020-11-11 13:52:31 -05:00
Mike Reeves
8160ef104d
Merge pull request #1887 from Security-Onion-Solutions/scriptpids
...
Make sure scripts don't run if they are already running
2020-11-11 13:51:51 -05:00
Automation
52ee26c334
Auto-publish so-mysql image signature
2020-11-11 18:25:23 +00:00
Automation
d2c1fed2df
Auto-publish so-strelka-backend image signature
2020-11-11 18:14:28 +00:00
Automation
1521224100
Auto-publish so-strelka-filestream image signature
2020-11-11 18:12:47 +00:00
Automation
97f5f8438c
Auto-publish so-thehive-es image signature
2020-11-11 18:11:17 +00:00
Mike Reeves
978ba5b3ad
Update zeekloss.sh
2020-11-11 13:09:52 -05:00
Automation
80b926bc31
Auto-publish so-logstash image signature
2020-11-11 18:09:41 +00:00
Mike Reeves
a4df3623be
Update zeekcaptureloss.sh
2020-11-11 13:09:31 -05:00
Mike Reeves
4a80c37167
Update suriloss.sh
2020-11-11 13:09:08 -05:00
Mike Reeves
8e88c350d5
Update stenoloss.sh
2020-11-11 13:08:43 -05:00
Mike Reeves
a6a9f03cb0
Update redis.sh
2020-11-11 13:08:28 -05:00
Automation
3a9c9e3d99
Auto-publish so-strelka-frontend image signature
2020-11-11 18:08:03 +00:00
Automation
307af1248c
Auto-publish so-thehive-cortex image signature
2020-11-11 18:05:26 +00:00
Automation
0224adb7c8
Auto-publish so-strelka-manager image signature
2020-11-11 18:02:54 +00:00
Automation
f4a804b88c
Auto-publish so-fleet-launcher image signature
2020-11-11 17:58:56 +00:00
Automation
ea88fa7319
Auto-publish so-soctopus image signature
2020-11-11 17:56:28 +00:00
Mike Reeves
c9bfd8a253
Update oldpcap.sh
2020-11-11 12:55:28 -05:00
Mike Reeves
ee0e1ce8d7
Update influxdbsize.sh
2020-11-11 12:55:08 -05:00
Mike Reeves
814aa85dba
Update helixeps.sh
2020-11-11 12:54:48 -05:00
Mike Reeves
c5ddddda2a
Update checkfiles.sh
2020-11-11 12:54:31 -05:00
Mike Reeves
c75536db6d
Update so-curator-delete
2020-11-11 12:54:04 -05:00
Mike Reeves
c11d8367fa
Update so-curator-closed-delete-delete
2020-11-11 12:53:36 -05:00
Mike Reeves
8320421d42
Update so-curator-closed-delete
2020-11-11 12:53:05 -05:00
Automation
33bf799b47
Auto-publish so-freqserver image signature
2020-11-11 17:52:55 +00:00
Mike Reeves
047ab95e68
Update so-curator-close
2020-11-11 12:52:38 -05:00
Mike Reeves
2eb3378b62
Update so-curator-closed-delete
2020-11-11 12:50:59 -05:00
Automation
a354a6279b
Auto-publish so-idstools image signature
2020-11-11 17:49:25 +00:00
Mike Reeves
578250a994
Update so-curator-delete
2020-11-11 12:48:55 -05:00
Mike Reeves
e68f90c3b5
Update so-curator-closed-delete-delete
2020-11-11 12:48:28 -05:00
Automation
5a9211693c
Auto-publish so-kratos image signature
2020-11-11 17:48:03 +00:00
Automation
1e2df983af
Auto-publish so-redis image signature
2020-11-11 17:46:57 +00:00
Mike Reeves
d85c99abf3
Update so-curator-close
2020-11-11 12:46:44 -05:00
Mike Reeves
c0897c7e5a
Update so-curator-close
2020-11-11 12:46:19 -05:00
Automation
b4989c6c0e
Auto-publish so-minio image signature
2020-11-11 17:43:17 +00:00
Automation
7a79ef6ddb
Auto-publish so-zeek image signature
2020-11-11 17:41:08 +00:00
Automation
8aa3a508fa
Auto-publish so-acng image signature
2020-11-11 17:39:18 +00:00
Automation
b320a1d63e
Auto-publish so-fleet image signature
2020-11-11 17:12:03 +00:00
Automation
2a119d7824
Auto-publish so-soc image signature
2020-11-11 17:08:52 +00:00
Mike Reeves
73c17b77ae
Update zeekcaptureloss.sh
2020-11-11 11:43:48 -05:00
Mike Reeves
edb0d71e87
Update zeekloss.sh
2020-11-11 11:43:28 -05:00
Mike Reeves
6ff1922788
Update zeekcaptureloss.sh
2020-11-11 11:42:58 -05:00
Josh Patterson
758bee3a20
Merge pull request #1886 from Security-Onion-Solutions/issue/1681
...
Issue/1681
2020-11-11 11:40:08 -05:00
m0duspwnens
529da993aa
Merge remote-tracking branch 'remotes/origin/dev' into issue/1681
2020-11-11 11:39:08 -05:00
m0duspwnens
5a95159ec3
just use so-status.conf for containers to fix salt warning https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-11 11:38:48 -05:00
Automation
fc9c31706d
Auto-publish so-acng image signature
2020-11-11 16:31:42 +00:00
Mike Reeves
9548b3df54
Update stenoloss.sh
2020-11-11 11:23:20 -05:00
Mike Reeves
d3f65ac1a8
Update redis.sh
2020-11-11 11:22:52 -05:00
Mike Reeves
cb46c13054
Update oldpcap.sh
2020-11-11 11:22:28 -05:00
Mike Reeves
a4d3e109e6
Update influxdbsize.sh
2020-11-11 11:17:18 -05:00
Mike Reeves
711f5ab38f
Update helixeps.sh
2020-11-11 11:16:47 -05:00
Mike Reeves
ea1227de9d
Update checkfiles.sh
2020-11-11 11:16:15 -05:00
Mike Reeves
f9b52677d7
Update suriloss.sh
2020-11-11 11:15:45 -05:00
weslambert
533a65205f
Merge pull request #1885 from Security-Onion-Solutions/fix/syslog_application
...
Add check for field
2020-11-11 10:33:24 -05:00
weslambert
ea1f53b40c
Add check for field
2020-11-11 10:29:58 -05:00
Josh Patterson
0f4f029e92
Merge pull request #1883 from Security-Onion-Solutions/issue/1857
...
add top change for fleet getting mysql state back
2020-11-11 09:18:06 -05:00
m0duspwnens
da9a915421
add top change for fleet getting mysql state back was reverted in https://github.com/Security-Onion-Solutions/securityonion/pull/1880/files
2020-11-11 09:15:50 -05:00
weslambert
280fc501f9
Merge pull request #1882 from Security-Onion-Solutions/fix/extra_top_var
...
Fix duplicate vars
2020-11-11 08:53:43 -05:00
weslambert
625307ac5f
Fix duplicate vars
2020-11-11 08:52:39 -05:00
weslambert
44677ad521
Merge pull request #1880 from Security-Onion-Solutions/disable_elastic
...
Allow for disabling Elastic stack via pillar
2020-11-11 08:29:23 -05:00
Wes Lambert
1c326f561b
Allow for disabling Elastic stack via pillar
2020-11-11 13:26:59 +00:00
Josh Patterson
7b64f93bce
Merge pull request #1874 from Security-Onion-Solutions/issue/1681
...
Issue/1681
2020-11-10 17:57:48 -05:00
m0duspwnens
15f243f0ce
change names of acng and docker registry containers https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 17:51:00 -05:00
m0duspwnens
edb00c2058
remove redundant common from top, create so-status conf files on manager before registry state https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 17:09:38 -05:00
m0duspwnens
9e612e98ed
merge with dev
2020-11-10 15:43:40 -05:00
m0duspwnens
1fc94a8f59
change to so-acng for so-status https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:37:03 -05:00
m0duspwnens
c58039ab47
rename state https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:34:10 -05:00
m0duspwnens
1fca5e65df
redo how containers get added to so-status https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:31:47 -05:00
Mike Reeves
9a59ceee4e
move to so-image-common
2020-11-10 12:16:54 -05:00
Mike Reeves
c5bf9bf90d
rework soup and docker refresh
2020-11-10 12:05:08 -05:00
William Wernert
676b4f0777
[fix] Close connection in mysql_conn module
2020-11-10 11:42:40 -05:00
William Wernert
6557155a8a
Merge pull request #1868 from Security-Onion-Solutions/feature/improve-mysql-dep
...
Feature/improve mysql dep
2020-11-10 11:04:23 -05:00
William Wernert
d3227bbcb1
[refactor] Code cleanup pt. 3
2020-11-10 11:03:43 -05:00
William Wernert
7f218e5297
[feat] Also run query against mysql to ensure queries can complete
2020-11-10 11:02:34 -05:00
William Wernert
b3c527e7a9
[refactor] Code cleanup pt. 2
2020-11-10 10:05:06 -05:00
William Wernert
54d732a060
[refactor] Code cleanup
2020-11-10 10:01:10 -05:00
William Wernert
22b7de819c
[fix] Put mysql import in try,catch in case it hasn't been installed
2020-11-10 10:00:21 -05:00
William Wernert
dba30fb0ed
[refactor] Split 15 min mysql startup between two wait states
2020-11-10 09:48:20 -05:00
Mike Reeves
7ca8fefded
gpg sign images
2020-11-10 09:45:06 -05:00
Josh Patterson
95b24b1684
Merge pull request #1865 from Security-Onion-Solutions/issue/1864
...
make so-status line color same as service state
2020-11-09 18:17:05 -05:00
m0duspwnens
66cd91c0a7
make so-status line color same as service state https://github.com/Security-Onion-Solutions/securityonion/issues/1864
2020-11-09 18:16:02 -05:00
Josh Patterson
64199c81e1
Merge pull request #1863 from Security-Onion-Solutions/issue/1857
...
Issue/1857
2020-11-09 17:54:25 -05:00
m0duspwnens
ae5bc297dd
remove extra squigly https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 17:06:32 -05:00
m0duspwnens
f5a1bd4074
only try to get enrollsecret if fleet is already enabled https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 16:25:28 -05:00
m0duspwnens
407a655717
merge with dev
2020-11-09 15:29:19 -05:00
m0duspwnens
0e19594c97
enable fleet in global pillars before running fleet state during setup https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 15:25:11 -05:00
William Wernert
ff4d7a6cb6
[fix] Sync modules so states can use our modules during setup
2020-11-09 14:01:19 -05:00
William Wernert
f647a06239
[fix] Correct percentage steps
2020-11-09 13:37:42 -05:00
Josh Patterson
d122ca1ba3
Merge pull request #1861 from Security-Onion-Solutions/issue/1857
...
fix top logic for mysql for fleet/playbook
2020-11-09 13:16:28 -05:00
m0duspwnens
5616aa6beb
fix top logic for mysql - https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 13:12:45 -05:00
William Wernert
394fa727cb
[fix] Don't overwrite mysql module
2020-11-09 13:05:29 -05:00
William Wernert
9960cf0592
[feat] Add salt module to check if mysql is accepting db connections
2020-11-09 12:05:37 -05:00
weslambert
059c4e03e1
Merge pull request #1860 from Security-Onion-Solutions/strelka-parsing
...
Pull out additional fields from Exif info
2020-11-09 11:54:55 -05:00
Wes Lambert
7e578d2ce0
Pull out additional fields from Exif info
2020-11-09 16:53:53 +00:00
William Wernert
12125deecb
[feat] Show link state in whiptail menus
2020-11-09 11:06:08 -05:00
William Wernert
51256983da
[fix] Make sure pip is installed on Ubuntu
2020-11-06 08:53:30 -05:00
William Wernert
0718dbbd4d
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion into dev
2020-11-06 08:52:42 -05:00
William Wernert
6b2ab67c58
[fix] Bump version of navigator json to 3.0 + fix booleans
2020-11-06 08:52:36 -05:00
Josh Patterson
64fd27fd78
Merge pull request #1843 from Security-Onion-Solutions/issue/1536
...
increase so-status padding by 1
2020-11-05 19:10:06 -05:00
m0duspwnens
7eb0dab6c7
increase padding by 1 - https://github.com/Security-Onion-Solutions/securityonion/issues/1536
2020-11-05 19:08:19 -05:00
Josh Patterson
0caf054da0
Merge pull request #1842 from Security-Onion-Solutions/issue/1764
...
show if disabled regardless of highstate status
2020-11-05 18:50:09 -05:00
m0duspwnens
21b284fb10
show if disabled regardless of highstate status - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:46:11 -05:00
Josh Patterson
3d1412a138
Merge pull request #1841 from Security-Onion-Solutions/issue/1764
...
Issue/1764
2020-11-05 18:24:51 -05:00
m0duspwnens
c7b4a5351c
fix logic - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:17:11 -05:00
m0duspwnens
a95129b8c2
add color - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:03:42 -05:00
m0duspwnens
695bace3e8
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:54:10 -05:00
m0duspwnens
47cac59adb
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:52:28 -05:00
m0duspwnens
1a75ebdca3
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:51:51 -05:00
m0duspwnens
8da070d511
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:46:23 -05:00
William Wernert
d2ea197ce0
[fix] Remove old entry for manager from known_hosts
...
Resolves #1839
2020-11-05 14:40:00 -05:00
William Wernert
b528fe1a03
[fix] Only show analyst on network installs
...
Closes #1682
2020-11-05 14:39:04 -05:00
weslambert
3abe8cb397
Merge pull request #1836 from Security-Onion-Solutions/fix/wazuh_agent_register
...
Don't sleep if not registering agent
2020-11-05 14:03:32 -05:00
weslambert
2911e37b70
Don't sleep if not registering agent
2020-11-05 14:03:08 -05:00
William Wernert
4fed5c2518
Merge pull request #1822 from Security-Onion-Solutions/feature/setup-idempotency
...
Feature/setup idempotency
2020-11-05 13:48:18 -05:00
William Wernert
a5833f1f77
Merge branch 'dev' into feature/setup-idempotency
...
# Conflicts:
# setup/so-functions
2020-11-05 13:48:05 -05:00
William Wernert
b27b2e358b
[fix] Set MSRVIP variable before hosts file is overwritten
2020-11-05 13:38:08 -05:00
William Wernert
915aaf58f2
[fix] Always set MSRVIP because /etc/hosts is wiped
2020-11-05 13:28:21 -05:00
William Wernert
f058fb460d
[fix] Don't modify hosts file during whiptail menus
2020-11-05 13:25:02 -05:00
William Wernert
f7394559d4
[fix] Only add entry to /etc/hosts if unable to resolve hostname
2020-11-05 13:16:52 -05:00
Josh Patterson
ec3f35c360
Merge pull request #1832 from Security-Onion-Solutions/patch_2.3.3
...
Patch 2.3.3
2020-11-05 10:00:43 -05:00
Josh Patterson
fea6e6f4f9
Merge branch 'dev' into patch_2.3.3
2020-11-05 09:58:43 -05:00
William Wernert
cb75b2df65
[revert] Remove wazuh-agent package as well
2020-11-04 16:23:51 -05:00
William Wernert
4369b8d0f6
[fix] Remove wazuh-agent package as well
2020-11-04 16:14:58 -05:00
William Wernert
5cb8d0beda
[fix] Add -q flag to grep
2020-11-04 14:23:24 -05:00
William Wernert
b4446cba9a
[refactor][wip] Also backup directories in /nsm
2020-11-04 14:20:51 -05:00
William Wernert
1e41b9ba31
[fix] Add conditions for commands so they're less likely to fail
2020-11-04 14:20:26 -05:00
William Wernert
b2759c4c7c
[fix] Uninstall launcher if installed
2020-11-04 14:19:25 -05:00
Mike Reeves
6b144903fc
Update VERIFY_ISO.md
2020-11-04 13:47:37 -05:00
Mike Reeves
3825becd1b
Update changes.json
2020-11-04 13:44:52 -05:00
Mike Reeves
2aa21512e5
Update soup
2020-11-04 13:40:45 -05:00
William Wernert
3150367b1d
[fix] Add epoch string to /opt/so folder name
2020-11-04 12:52:37 -05:00
William Wernert
3ac9c43b7b
Merge branch 'dev' into feature/setup-idempotency
2020-11-04 12:44:14 -05:00
William Wernert
b643363e82
[fix] Directories need -r flag
2020-11-04 12:07:34 -05:00
Jason Ertel
8d5c29340e
Add screenshots to readme
2020-11-04 12:03:57 -05:00
Jason Ertel
1e9e156a87
Improve issue template directions
2020-11-04 11:49:22 -05:00
Jason Ertel
a364f13d24
Add issue template
2020-11-04 11:42:39 -05:00
William Wernert
3d70698647
[fix] Remove old mysql db directory
2020-11-04 11:26:56 -05:00
Mike Reeves
e989fc7041
Update map.jinja
2020-11-04 10:58:52 -05:00
William Wernert
49af35b440
[fix][wip] Add reinstall_init function (part 3)
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-04 10:38:48 -05:00
Mike Reeves
4592e2d4d7
add airgap option to upgradecommand
2020-11-04 10:08:01 -05:00
Mike Reeves
ec64314b70
Fix soup to clear yum cache for airgap
2020-11-04 10:00:44 -05:00
Mike Reeves
cf001875c2
Update soup
2020-11-03 20:14:15 -05:00
Mike Reeves
c7367eea38
Fix AGREPO Variable
2020-11-03 19:08:58 -05:00
William Wernert
db31cf3083
[refactor][fix] Remove old so-* containers, make fs changes after whiptail menus
2020-11-03 18:10:16 -05:00
Mike Reeves
8edb1529a9
Update soup
2020-11-03 17:36:53 -05:00
Mike Reeves
e8616e4d46
Update soup
2020-11-03 17:19:55 -05:00
William Wernert
3bf57382ce
[fix] Change when /opt/so is removed
2020-11-03 17:05:34 -05:00
Jason Ertel
def993f4ed
Improve salt version update comment
2020-11-03 16:50:22 -05:00
William Wernert
96ec483ae4
[fix][wip] Remove /opt/so directory during reinstall
2020-11-03 16:49:00 -05:00
William Wernert
6169758f4e
[fix] 0 -> root so file owner is set correctly
2020-11-03 16:47:59 -05:00
William Wernert
1c91e2d50b
[fix] Add minion_config variable so sed works
2020-11-03 15:48:08 -05:00
William Wernert
57e7e61f21
[fix] Don't add proxy to yum.conf on manager nodes
2020-11-03 15:45:19 -05:00
William Wernert
93ab4b5d4f
[fix][wip] Add reinstall_init function (part 2)
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-03 15:44:37 -05:00
William Wernert
00fc256c37
[fix][wip] Add reinstall_init function
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-03 14:51:35 -05:00
Mike Reeves
887f412e48
Remove docker_clean from docker_update function
2020-11-03 13:54:00 -05:00
Jason Ertel
aa9aa59213
Correct cheatsheetUrl for airgap installs
2020-11-03 12:27:55 -05:00
m0duspwnens
a859aa4f48
upgrade from salt 3001.1 to salt 3002.1 - https://github.com/Security-Onion-Solutions/securityonion/issues/1807
2020-11-03 11:54:28 -05:00
Jason Ertel
82a7b7e02d
Upgrade to Kratos 0.5.3-alpha1
2020-11-03 11:50:25 -05:00
Mike Reeves
85ea61bf98
Update VERSION
2020-11-03 11:40:03 -05:00
Mike Reeves
7f4b8e8183
Update README.md
2020-11-03 11:39:42 -05:00
Josh Patterson
1f8b139462
Merge pull request #1806 from Security-Onion-Solutions/issue/1782
...
Issue/1782
2020-11-03 11:23:22 -05:00
m0duspwnens
562a016579
remove more from sosetup.log
2020-11-03 10:23:56 -05:00
weslambert
e040009d0b
Merge pull request #1804 from Security-Onion-Solutions/fix/wazuh_api_creds_remove
...
Remove Wazuh API creds after registering initial agent
2020-11-03 09:57:58 -05:00
Wes Lambert
7dca988c11
Remove Wazuh API creds after registering intial agent
2020-11-03 14:53:50 +00:00
Mike Reeves
f007ef0ef5
Update so-functions
2020-11-02 17:00:02 -05:00
weslambert
bfe98433f6
Merge pull request #1789 from Security-Onion-Solutions/fix/zeek_intel
...
Add Zeek intel.dat
2020-11-02 16:38:16 -05:00
Wes Lambert
05549a2362
Add Zeek intel.dat
2020-11-02 21:36:44 +00:00
m0duspwnens
7e090b0894
dont echo salt minion config file to prevent mysql.pass from showing in sosetup.log
2020-11-02 16:23:34 -05:00
weslambert
8a645edb34
Merge pull request #1788 from Security-Onion-Solutions/feature/nids_rules
...
Allow for muliple files for rules
2020-11-02 16:05:53 -05:00
Wes Lambert
24a54a326c
Allow for muliple files for rules
2020-11-02 21:03:45 +00:00
Jason Ertel
184d163d65
Do not persist the Cortex PID file; This allows Cortex to recover from non-graceful container shutdowns, such as a power loss event on the host machine
2020-11-02 15:04:13 -05:00
weslambert
bb0cf9b8c7
Merge pull request #1784 from Security-Onion-Solutions/fix/strelka_exif_parsing
...
Fix/strelka exif parsing
2020-11-02 14:32:45 -05:00
Wes Lambert
3113d5fbdb
Format scan.exiftool as text
2020-11-02 19:31:14 +00:00
Wes Lambert
6420ee0310
Update parsing for scan.exiftool
2020-11-02 19:28:12 +00:00
William Wernert
033f5dbb9c
[fix] Use (mostly) absolute path when adding to PATH
2020-11-02 14:25:46 -05:00
William Wernert
1c4abcef15
[fix] Kill all jobs before checking if we can reach the salt master
2020-11-02 14:25:02 -05:00
Jason Ertel
2acb930a2e
fix: Remove crontab for automation installs
2020-11-02 11:08:45 -05:00
weslambert
37c630d6ab
Merge pull request #1776 from Security-Onion-Solutions/bugfix/af-packet-ring-size
...
Match max-pending-packets size
2020-11-02 08:39:21 -05:00
weslambert
71a260a000
Match max-pending-packets size
2020-11-02 08:38:45 -05:00
jtgreen-cse
6359e03ba6
fix for Windows events via osquery
...
This change was required to properly let Windows events flow through their specific pipelines. Otherwise, the `temp` field stays around and gets ingested in ES.
2020-10-29 15:03:13 -04:00
William Wernert
b489fee8b5
Merge pull request #1738 from Security-Onion-Solutions/bugfix/nginx-redirect
...
Bugfix/nginx redirect
2020-10-29 14:33:38 -04:00
William Wernert
91221c4332
[revert] Move proxy_pass back to ip
2020-10-29 10:23:12 -04:00
Mike Reeves
57d8f25422
Create master node role in ES
2020-10-28 16:44:14 -04:00
William Wernert
3abd1c9f16
[fix] Configure soctopus to use url_base
2020-10-28 16:08:19 -04:00
Mike Reeves
b14c1d0999
Merge pull request #1713 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:27:26 -04:00
Mike Reeves
13be0da484
Add a place where custom logstash certs can go
2020-10-28 15:26:41 -04:00
Mike Reeves
3385d98a2a
Merge pull request #1712 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:26:08 -04:00
Mike Reeves
361b13dc88
Add a place where custom logstash certs can go
2020-10-28 15:25:00 -04:00
Jason Ertel
98c669e80b
Disable nginx server version and TLSv1.0/TLSv1.1
2020-10-28 14:29:29 -04:00
William Wernert
b02d434a0e
[fix] Change any scripts using auth headers to url_base
2020-10-28 12:29:09 -04:00
William Wernert
3ee9f23d26
[fix] Use url_base in sensoroni.json instead of manager hostname
2020-10-28 12:28:34 -04:00
Jason Ertel
348c2feee2
Prevent usage of dollar signs in admin passwords during setup
2020-10-28 11:07:05 -04:00
Mike Reeves
b238c492e4
Update so-functions
2020-10-28 10:50:10 -04:00
Mike Reeves
97207bd006
Merge pull request #1702 from Security-Onion-Solutions/dockernet
...
Custom Docker IP Range
2020-10-28 10:48:56 -04:00
Mike Reeves
bed70ab6bf
Update whiptail menu for docker question
2020-10-28 10:19:15 -04:00
Mike Reeves
8173cb589b
Update whiptail menu for docker question
2020-10-28 10:17:53 -04:00
Mike Reeves
563a606e0e
Upodate dockernet menu
2020-10-28 10:14:14 -04:00
Mike Reeves
8d952eca7e
Upodate dockernet menu
2020-10-28 10:12:07 -04:00
Mike Reeves
8f7dffea4b
Upodate dockernet menu
2020-10-28 10:10:43 -04:00
weslambert
7ea8dc84b6
Merge pull request #1696 from Security-Onion-Solutions/feature/wazuh-user-mods
...
Add Wazuh user management scripts
2020-10-28 08:24:15 -04:00
Wes Lambert
453247971e
Add Wazuh user management scripts
2020-10-28 12:22:50 +00:00
Mike Reeves
741e17a637
add bip for docker
2020-10-27 18:21:53 -04:00
Mike Reeves
fedf334ee9
add bip for docker
2020-10-27 18:21:09 -04:00
Mike Reeves
8fee19ee1b
add bip for docker
2020-10-27 18:01:48 -04:00
Mike Reeves
697bc53aec
Dockernet Modifications
2020-10-27 15:08:34 -04:00
Jason Ertel
5a705fc0f2
Add Hunt quick action for hunted events, grouping by dataset and module
2020-10-27 12:30:33 -04:00
William Wernert
7b17b4abc7
Merge pull request #1680 from Security-Onion-Solutions/feature/setup-fixes
...
Feature/setup fixes
2020-10-27 12:17:21 -04:00
William Wernert
a043bc7cc4
[fix] Second if to elif
2020-10-27 12:16:19 -04:00
William Wernert
72dc267ab5
[fix] Menu sizing fixes
2020-10-27 12:14:44 -04:00
William Wernert
970be4d530
[fix] Change cd to relative
...
Since the script already changes to the correct dir, we can work from relative directories now.
2020-10-27 12:13:07 -04:00
Jason Ertel
474c4e54b4
Ensure labels and icons are associated with all quick actions
2020-10-27 12:04:57 -04:00
Mike Reeves
d4dd4aa416
Add missing comma in daemon.json
2020-10-27 11:25:45 -04:00
William Wernert
5054138be9
[feat] Add analyst option + add back helix option
2020-10-27 11:21:03 -04:00
William Wernert
83c23dd5de
[fix] Remove old got_root call
2020-10-27 11:20:39 -04:00
Mike Reeves
42e00514f5
Adding docker net setting
2020-10-27 11:09:14 -04:00
William Wernert
e75f8ba257
[fix] Move root check to top of so-setup
2020-10-27 09:39:29 -04:00
William Wernert
564ac3a4ff
Merge pull request #980 from Security-Onion-Solutions/feature/nginx-update
...
Feature/nginx update
2020-10-27 09:29:43 -04:00
William Wernert
c58deef2e0
Merge branch 'dev' into feature/nginx-update
2020-10-27 09:29:06 -04:00
Mike Reeves
0ad65c8cd4
Merge pull request #1568 from jtgreen-cse/patch-1
...
fix for rendering error >1 search node
2020-10-26 16:57:17 -04:00
William Wernert
0aaf8d6d9a
[fix] Change 301 to 307 so curl requests work as intended
2020-10-26 16:37:16 -04:00
William Wernert
37ede9b993
[wip] Redirect so-user-add to separate log so ERROR isn't in main log
2020-10-26 15:03:27 -04:00
Mike Reeves
5395983fc7
Merge pull request #1580 from Security-Onion-Solutions/feature/thehive-casetemplates
...
Add case_template field to Playbook alerts
2020-10-26 14:13:54 -04:00
William Wernert
3648e293a1
[fix] Add -L option to curl to respect redirects
2020-10-26 14:08:52 -04:00
Mike Reeves
ecfd1bbe4d
Merge remote-tracking branch 'remotes/origin/dev' into escluster
2020-10-26 13:33:05 -04:00
Mike Reeves
12acc2e123
Merge pull request #1663 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERIFY_ISO.md
2020-10-26 13:10:18 -04:00
Mike Reeves
8d84718c91
Update VERIFY_ISO.md
2020-10-26 13:08:30 -04:00
Jason Ertel
3809573963
Correct cheatsheet URL for airgap installs
2020-10-26 12:16:55 -04:00
Jason Ertel
571550c019
Merge master into dev
2020-10-26 10:30:26 -04:00
William Wernert
e613bb3740
Merge branch 'dev' into feature/nginx-update
2020-10-26 10:28:14 -04:00
William Wernert
4662837075
[fix] Revert changes from merging dev
2020-10-26 10:25:16 -04:00
Mike Reeves
892ca294dc
Merge pull request #1655 from Security-Onion-Solutions/patch_2.3.2
...
2.3.2
2020-10-26 10:17:23 -04:00
Mike Reeves
45fd325307
Update VERIFY_ISO.md
2020-10-26 10:11:58 -04:00
Mike Reeves
653561ad95
Update VERIFY_ISO.md
2020-10-26 10:09:25 -04:00
Mike Reeves
f75badf43a
2.3.2 ISO info
2020-10-26 09:53:26 -04:00
Doug Burks
c61199618a
Update so-curator-closed-delete-delete
2020-10-24 07:15:43 -04:00
Mike Reeves
d9c021e86a
Update so-curator-closed-delete-delete
2020-10-23 17:07:16 -04:00
Mike Reeves
951f6ab3e2
Update VERIFY_ISO.md
2020-10-23 16:48:05 -04:00
Mike Reeves
da488945e0
Update VERIFY_ISO.md
2020-10-23 16:47:43 -04:00
Mike Reeves
b6f1cfada6
Update changes.json
2020-10-23 16:44:02 -04:00
Jason Ertel
85e0b2cab3
Add cheatsheet URL to soc.json
2020-10-23 16:35:35 -04:00
Mike Reeves
c8a6b232d5
Fix which field we return for Elastic index
2020-10-23 15:58:35 -04:00
William Wernert
fdb7cb90e3
[wip] Test alt variable usage
2020-10-23 15:36:01 -04:00
William Wernert
73b83584e6
[fix] Remove bad '_' character
2020-10-23 14:32:43 -04:00
Mike Reeves
801f4aae8e
Update README.md
2020-10-23 10:09:07 -04:00
Mike Reeves
c066cc67dc
Update VERSION
2020-10-23 10:08:45 -04:00
Josh Patterson
1185e43064
Merge pull request #1614 from Security-Onion-Solutions/issue/1573
...
Issue/1573 and Issue/1601
2020-10-22 15:57:40 -04:00
Mike Reeves
51ca661219
update wording for USB device vs CDROM
2020-10-22 14:54:34 -04:00
m0duspwnens
50a767ca6c
dont list aptcacherng in so-status if user chose open updates during setup - https://github.com/Security-Onion-Solutions/securityonion/issues/1573
2020-10-22 14:52:07 -04:00
Mike Reeves
174bbc6cd9
Update VERSION
2020-10-22 14:14:57 -04:00
William Wernert
6a08086dfa
[refactor] Make variable names consistent
2020-10-22 14:10:06 -04:00
Mike Reeves
a3579b88ae
Merge pull request #1604 from Security-Onion-Solutions/dev
...
2.3.1
2020-10-22 14:08:41 -04:00
William Wernert
6a3e921924
[fix] Fixes for fleet install
2020-10-22 13:09:26 -04:00
Mike Reeves
4a0796359b
Update README.md
2020-10-22 12:54:05 -04:00
m0duspwnens
0bfdef274b
update so-status to work with disabled containers - https://github.com/Security-Onion-Solutions/securityonion/issues/1601
2020-10-22 12:09:19 -04:00
Mike Reeves
92d397d573
Update ISO instructions
2020-10-22 11:59:39 -04:00
m0duspwnens
0b6b6e38fc
fix map for steno
2020-10-22 11:24:18 -04:00
m0duspwnens
aa59eff1ac
fix if statement
2020-10-22 10:59:03 -04:00
m0duspwnens
172ca9aa8d
add option to enable or disable to steno docker container - https://github.com/Security-Onion-Solutions/securityonion/issues/1601
2020-10-22 10:52:34 -04:00
William Wernert
79c4f07ff7
[fix] Don't listen on port 80 on all installs
2020-10-22 10:43:24 -04:00
Mike Reeves
460a391460
Update changes.json
2020-10-22 10:00:20 -04:00
Mike Reeves
905fcd06a6
Remove old 2.3.0 dockers
2020-10-22 08:51:40 -04:00
Josh Patterson
0b7f1fb189
Merge pull request #1594 from Security-Onion-Solutions/issue/1593
...
fix grabbing soversion in so-features-enable
2020-10-21 16:51:06 -04:00
m0duspwnens
712dc6b277
fix grabbing soversion in so-features-enable
2020-10-21 16:47:48 -04:00
Josh Patterson
b93709e05f
Merge pull request #1591 from Security-Onion-Solutions/issue/1590
...
fix arg for so-firewall addhostgroup
2020-10-21 15:48:02 -04:00
m0duspwnens
32294eb2ed
fix arg for so-firewall addhostgroup
2020-10-21 15:34:35 -04:00
Josh Patterson
2da656ff95
Merge pull request #1589 from Security-Onion-Solutions/issue/1551
...
only allow hosts in syslog host group to connect to manager type nodes
2020-10-21 14:41:50 -04:00
m0duspwnens
ef1e05db3e
only allow hosts in syslog host group to connect to manager type nodes
2020-10-21 14:41:03 -04:00
Josh Patterson
798abdbcde
Merge pull request #1584 from Security-Onion-Solutions/issue/1551
...
firewall to allow search nodes to connect to beats on manager
2020-10-21 12:50:49 -04:00
m0duspwnens
8805fef187
firewall to allow search nodes to connect to beats on manager
2020-10-21 12:43:28 -04:00
Josh Patterson
aafd365f2b
Merge pull request #1583 from Security-Onion-Solutions/issue/1551
...
add firewall rules for syslog
2020-10-21 11:21:18 -04:00
m0duspwnens
5f43380aa0
add firewall rules for syslog
2020-10-21 11:20:34 -04:00
Josh Brower
844ffe8fdf
nest case_template
2020-10-21 09:58:31 -04:00
Josh Brower
1e14d66f54
Add case_template field to Playbook alerts
2020-10-21 08:59:26 -04:00
weslambert
e2d95e0deb
Merge pull request #1576 from Security-Onion-Solutions/fix/comon_nids_rule_ruleset
...
Change rule_ruleset to rule.ruleset
2020-10-20 22:15:00 -04:00
weslambert
4765ef5f5c
Change rule_ruleset to rule.ruleset
2020-10-20 22:14:23 -04:00
William Wernert
d63358c8f0
[fix] Correct pillar reference + nginx errors
2020-10-20 14:30:06 -04:00
Jason Ertel
d37ddf584a
Correct quick action defaults
2020-10-20 14:12:23 -04:00
jtgreen-cse
eaa41266a2
fix for rendering error >1 search node
...
Fails rendering if you have more than one search node.
2020-10-20 13:24:53 -04:00
Mike Reeves
4a9fcfb8cf
Fix missing quote
2020-10-20 13:17:40 -04:00
Mike Reeves
a119d8f27d
Fix config for airgap installs
2020-10-20 11:28:49 -04:00
Mike Reeves
87adbb5f81
printf issues
2020-10-19 17:20:33 -04:00
Mike Reeves
722f2b3913
Fix pillar syntax
2020-10-19 17:08:06 -04:00
Mike Reeves
3cb419174a
Fix pillar syntax
2020-10-19 17:04:06 -04:00
Mike Reeves
55b6f5ce99
Fix pillar syntax
2020-10-19 17:02:26 -04:00
Mike Reeves
4e1bff2231
Fix pillar syntax
2020-10-19 16:56:13 -04:00
Mike Reeves
7e0063d474
Fix pillar syntax
2020-10-19 16:55:11 -04:00
Mike Reeves
23bc5e303e
Add clustering to ES function
2020-10-19 16:52:43 -04:00
Mike Reeves
6f703fad25
Change whiptail logic
2020-10-19 16:44:43 -04:00
Mike Reeves
c538e5f85b
Change whiptail logic
2020-10-19 16:40:56 -04:00
Mike Reeves
c22e8c08a6
Change whiptail logic
2020-10-19 16:40:22 -04:00
Mike Reeves
f893cf203f
Change whiptail logic
2020-10-19 16:38:17 -04:00
Mike Reeves
bbb825a207
Add cluster whiptail questions
2020-10-19 16:33:40 -04:00
Josh Patterson
ba1dfcd774
Merge pull request #1554 from Security-Onion-Solutions/issue/1551
...
Issue/1551
2020-10-19 16:10:50 -04:00
m0duspwnens
10e4248cfc
and node that gets filebeat state now can listen for syslog - https://github.com/Security-Onion-Solutions/securityonion/issues/1551
2020-10-19 16:10:20 -04:00
Mike Reeves
bab6b151ff
Add cluster whiptail questions
2020-10-19 16:07:22 -04:00
William Wernert
42e285cfbe
Merge branch 'dev' into feature/nginx-update
...
# Conflicts:
# salt/nginx/etc/nginx.conf
# salt/nginx/etc/nginx.conf.so-eval
# salt/nginx/etc/nginx.conf.so-manager
# salt/nginx/etc/nginx.conf.so-standalone
2020-10-19 13:25:46 -04:00
Mike Reeves
97a2d91d15
Re-arrange whiptail screens
2020-10-19 12:14:30 -04:00
m0duspwnens
79854f111e
add 514 tcp listener to filebeat docker and add syslog listener to fb config for manager and manager search - https://github.com/Security-Onion-Solutions/securityonion/issues/1551
2020-10-19 10:27:40 -04:00
Josh Patterson
a05329e7d8
Merge pull request #1532 from Masaya-A/patch-1
...
Grafana /nsm fix for eval/standalone
2020-10-16 16:48:12 -04:00
Masaya-A
47652ac080
Update eval.json
2020-10-17 04:45:12 +09:00
Masaya-A
964919109d
Update standalone.json
2020-10-17 04:35:39 +09:00
Jason Ertel
a968e5c23f
Increment version to 2.3.1
2020-10-16 10:57:31 -04:00
Mike Reeves
ba7b34a8ce
Merge pull request #1529 from Security-Onion-Solutions/dev
...
2.3.0 GA!
2020-10-16 10:53:53 -04:00
Mike Reeves
e2f16d51a6
Update VERIFY_ISO.md
2020-10-15 20:54:11 -04:00
Mike Reeves
42a6693101
Sig File for ISO
2020-10-15 20:36:08 -04:00
Jason Ertel
2326701cc0
Moved known issues underneath new changes
2020-10-15 19:29:33 -04:00
Jason Ertel
6ee37977c3
Fixed quotes and href targets
2020-10-15 19:25:26 -04:00
Mike Reeves
1ae35a39c3
Update changes.json
2020-10-15 19:11:55 -04:00
Mike Reeves
943aa82ce4
Update changes.json
2020-10-15 19:09:46 -04:00
Mike Reeves
131e105106
Update changes.json
2020-10-15 19:07:37 -04:00
Mike Reeves
cc56dc5a7f
Update changes.json
2020-10-15 19:05:47 -04:00
weslambert
657e251f51
Merge pull request #1528 from Security-Onion-Solutions/fix/kibana_ack
...
Update Kibana mappings for event ack/eslacation
2020-10-15 14:48:00 -04:00
Wes Lambert
d863f26f9d
Update Kibana mappings for event ack/eslacation
2020-10-15 18:46:37 +00:00
Mike Reeves
a7e0df84bb
Update README.md
2020-10-15 14:46:13 -04:00
William Wernert
1fdf431c12
[fix] so-user spelling+syntax fixes
...
* Consistent ending punctuation
* Consistent capitalization
* Correct comparison operators
2020-10-15 13:44:23 -04:00
Mike Reeves
35b10b1f91
Sensors should clean up their dockers as well
2020-10-15 10:31:51 -04:00
weslambert
36b9450a39
Merge pull request #1526 from Security-Onion-Solutions/fix/kibana_things
...
Intel mapping enforcement and winlog.verion
2020-10-15 08:43:34 -04:00
Wes Lambert
af9daa4d71
Intel mapping enforcement and winlog.verion
2020-10-15 12:42:33 +00:00
weslambert
c81ee9621d
Merge pull request #1525 from Security-Onion-Solutions/fix/kibana_discover_default
...
Fix default discover query
2020-10-14 17:44:55 -04:00
Wes Lambert
e7401b3e0c
Fix default discover query
2020-10-14 21:43:19 +00:00
weslambert
f2125242f9
Merge pull request #1523 from Security-Onion-Solutions/fix/strelka_file_mime_type
...
Rename file.flavors.mime to file.mime_type
2020-10-14 14:58:15 -04:00
Wes Lambert
54c4ee796f
Rename file.flavors.mime to file.mime_type
2020-10-14 18:56:44 +00:00
weslambert
8d4fd6c18d
Merge pull request #1522 from Security-Onion-Solutions/fix/pipeline_commmon_remove_ignore_missing
...
Fix common pipeline field removal so won't fail for missing fields
2020-10-14 09:56:34 -04:00
Wes Lambert
3c820365ab
Fix common pipeline field removal so won't fail for missing fields
2020-10-14 13:55:24 +00:00
Doug Burks
a106913d1a
Heavy node filebeat needs extra_hosts for the heavy node itself #1521
2020-10-14 09:51:59 -04:00
Josh Patterson
493c9a11df
Merge pull request #1520 from Security-Onion-Solutions/issue/1519
...
disable strelka by default for sensor nodes during setup
2020-10-14 09:38:50 -04:00
m0duspwnens
1283708186
disable strelka by default for sensor nodes during setup
2020-10-14 09:36:59 -04:00
Josh Patterson
2e62494793
Merge pull request #1518 from Security-Onion-Solutions/issue/1153
...
fix issue with schedule being placed in wrong location
2020-10-14 09:26:31 -04:00
Doug Burks
f88403e83e
use ssl on nodes that support it
2020-10-14 05:50:29 -04:00
m0duspwnens
a08d0c8b6f
fix issue with schedule being placed in wrong location
2020-10-13 18:24:44 -04:00
Josh Patterson
9f6fcb3763
Merge pull request #1516 from Security-Onion-Solutions/quickfix/managerestempalte
...
add elasticsearch template manager pillar and assign to manager node
2020-10-13 16:09:24 -04:00
m0duspwnens
1afa12e607
add elasticsearch template manager pillar and assign to manager node
2020-10-13 16:08:15 -04:00
Doug Burks
190869a1f2
enable https on elasticsearch nodes that support it
2020-10-13 16:04:55 -04:00
William Wernert
f6296c095f
[fix] Redirect stderr to stdout for crontab -l
2020-10-13 15:00:00 -04:00
Josh Patterson
15ea152b84
Merge pull request #1515 from Security-Onion-Solutions/issue/1511
...
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/1511
2020-10-13 14:17:28 -04:00
weslambert
4fff105986
Merge pull request #1514 from Security-Onion-Solutions/fix/replay_verbiage
...
Replay verbiage -- let users know when preparing to replay
2020-10-13 14:14:41 -04:00
Wes Lambert
3f8f0da468
Replay verbiage -- let users know when preparing to replay
2020-10-13 18:13:36 +00:00
m0duspwnens
2456605a54
changes for https://github.com/Security-Onion-Solutions/securityonion/issues/1511
2020-10-13 14:10:24 -04:00
William Wernert
675db1da1b
[fix] Remove tab from string in whiptail menu
2020-10-13 13:44:51 -04:00
Doug Burks
0f68a53af4
Update so-curator-closed-delete-delete
2020-10-13 13:22:35 -04:00
Doug Burks
b004a9149e
Update so-index-list
2020-10-13 12:40:45 -04:00
Doug Burks
e5ece6cd50
Update so-index-list
2020-10-13 12:34:49 -04:00
Jason Ertel
2ad6ab7dfc
Dynamically alter docs URL based on airgap setting
2020-10-13 12:29:59 -04:00
Doug Burks
a75e986836
Update so-elastic-clear
2020-10-13 12:18:27 -04:00
Mike Reeves
c388966e7e
Add airgap config
2020-10-13 12:05:19 -04:00
William Wernert
0cd80de2b3
[fix] Hard code NIDS to Suricata since Snort is not yet supported
2020-10-13 10:31:44 -04:00
William Wernert
a459511812
Merge pull request #1512 from Security-Onion-Solutions/bugfix/whiptail-punctuation
...
Bugfix/whiptail punctuation
2020-10-13 10:26:26 -04:00
William Wernert
9dc491bd71
[refactor] Fixes per style guide
2020-10-13 10:23:47 -04:00
William Wernert
f5ea8325fe
[fix] Standardize input prompts
...
* All prompts that are questions end in "?"
* All other prompts end in ":"
* Any additional sentences after a prompt follow normal grammatical rules for punctuation
2020-10-13 09:45:32 -04:00
Doug Burks
ad50b5d640
elasticsearch _cat/indices output has changed between 6 and 7
2020-10-13 06:33:40 -04:00
Doug Burks
21b1becd7e
Update so-elasticsearch-pipelines-list
2020-10-12 16:34:30 -04:00
Doug Burks
5458c57cc9
Update so-elasticsearch-pipeline-stats
2020-10-12 16:32:11 -04:00
Doug Burks
68e34b781a
Update so-elasticsearch-templates-load
2020-10-12 16:10:38 -04:00
Doug Burks
4c43262610
Update so-elasticsearch-templates-list
2020-10-12 16:08:06 -04:00
weslambert
a17a2ad3de
Merge pull request #1507 from Security-Onion-Solutions/fix/zeek_smb_ts_common
...
Ensure Zeek logs without ts field have an @timestamp field associated
2020-10-12 13:21:15 -04:00
Wes Lambert
14559b081d
Ensure Zeek logs without ts field have an @timestamp field associated
2020-10-12 17:19:23 +00:00
weslambert
748ff0dbeb
Merge pull request #1506 from Security-Onion-Solutions/fix/index_dates
...
Fix/index dates
2020-10-12 11:45:08 -04:00
Wes Lambert
4fc4913d1e
Don't predefine index date for Filebeat ES outputs
2020-10-12 15:44:00 +00:00
Wes Lambert
884cc2d054
Don't predefine index date for Logstash outputs
2020-10-12 15:41:47 +00:00
Doug Burks
553ce3e363
only include extra_hosts if nodestab exists
2020-10-12 10:13:05 -04:00
Mike Reeves
e0fe63d263
Merge pull request #1505 from Security-Onion-Solutions/experimental
...
Fix Cross Cluster Search Acks
2020-10-12 09:24:16 -04:00
Mike Reeves
f5cfd480a3
Moar encryptions
2020-10-12 09:12:36 -04:00
Jason Ertel
3fff1451d4
Enable high strength cipher for golang compatibility
2020-10-11 22:31:29 -04:00
Mike Reeves
9695e63950
fix template statement
2020-10-11 17:21:57 -04:00
Mike Reeves
96083e1458
update logstash outputs
2020-10-11 17:06:56 -04:00
Mike Reeves
deb0f640d6
add jinja templates
2020-10-11 17:02:07 -04:00
Mike Reeves
b7c4fd94c4
get pipelines to load
2020-10-11 16:57:08 -04:00
Mike Reeves
e4ce17d4de
Turn on SSL output
2020-10-11 16:10:55 -04:00
Mike Reeves
a7bd1c2ce5
Turn on SSL output
2020-10-11 15:58:12 -04:00
Josh Patterson
c9c8c5e5f5
Merge pull request #1502 from Security-Onion-Solutions/quickfix/socrestart
...
watch all the files in the dir
2020-10-11 14:20:34 -04:00
m0duspwnens
c1e6c5688d
watch all the files in the dir
2020-10-11 14:19:44 -04:00
Mike Reeves
29c3948f95
Fix soc.json
2020-10-11 14:09:14 -04:00
Mike Reeves
31e0b5c81c
Add nodes to soc.json
2020-10-11 11:28:49 -04:00
Mike Reeves
73aade1223
Enable rest access from manager to sn
2020-10-11 11:02:20 -04:00
Mike Reeves
271e40337b
Enable jinja for tls
2020-10-11 10:57:04 -04:00
Mike Reeves
f6f9097cd9
Enable tls for 9200 on search capable nodes
2020-10-11 10:53:54 -04:00
Doug Burks
3cfee82b59
Update Hunt fields for firewall #1500
2020-10-10 08:18:00 -04:00
Doug Burks
87574181d5
Add Community ID to pfsense filterlog #1501
2020-10-10 08:11:51 -04:00
Doug Burks
5f15320b9d
Update Hunt fields for firewall #1500
2020-10-10 07:54:48 -04:00
Doug Burks
8d1ba1f4db
fix pfsense firewall udp parsing
2020-10-10 07:38:47 -04:00
Doug Burks
8cfabf101c
Update Hunt query for firewall #1499
2020-10-10 07:17:49 -04:00
Doug Burks
9aa4112de1
Remove extra comma
2020-10-10 06:10:10 -04:00
weslambert
12c3c351d8
Merge pull request #1498 from Security-Onion-Solutions/feature/filterlog
...
Feature/filterlog
2020-10-09 20:05:21 -04:00
Wes Lambert
28a1f7f88a
Remove pfsense tag
2020-10-10 00:03:51 +00:00
Wes Lambert
b55ffa44f8
Fix module,dataset rename
2020-10-10 00:01:37 +00:00
Wes Lambert
69a04dedd3
Filterlog config changes
2020-10-09 23:56:52 +00:00
Josh Patterson
930ec33cb7
Merge pull request #1496 from Security-Onion-Solutions/issue/1489
...
move salt master config file, copy salt-master service file and enabl…
2020-10-09 13:45:19 -04:00
m0duspwnens
6172268661
move salt master config file, copy salt-master service file and enable service restarts - https://github.com/Security-Onion-Solutions/securityonion/issues/1489
2020-10-09 13:27:46 -04:00
Josh Patterson
336400e642
Merge pull request #1495 from Security-Onion-Solutions/issue/1403
...
Issue/1403
2020-10-09 12:24:56 -04:00
m0duspwnens
ea1324e498
fix LOSS calc line
2020-10-09 11:54:39 -04:00
m0duspwnens
3f007b6af7
Merge remote-tracking branch 'remotes/origin/dev' into issue/1403
2020-10-09 11:40:01 -04:00
m0duspwnens
f5cacd66b8
correct zeekcaptureloss script to work on zeek standalone
2020-10-09 11:39:44 -04:00
Jason Ertel
40ff628c0b
Replace simple pillar lookup with salt equivalent to ensure quoted values are handled properly
2020-10-09 11:10:46 -04:00
William Wernert
97fce74263
[fix] Rename playbook key and add new admin/automation psswds
2020-10-09 09:59:08 -04:00
William Wernert
d7961fdbb8
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion into dev
2020-10-09 08:51:45 -04:00
William Wernert
5a8d776a62
[ix] Correct sls syntax
2020-10-09 08:51:35 -04:00
Josh Patterson
4af87ffcbe
Merge pull request #1492 from Security-Onion-Solutions/issue/1403
...
change capture loss to every 5 minutes and default grafana dashboard …
2020-10-08 17:52:52 -04:00
m0duspwnens
f38519247b
change capture loss to every 5 minutes and default grafana dashboard to 1h
2020-10-08 17:52:02 -04:00
William Wernert
065fe9042d
[fix] Make sure Playbook is up before creating user
2020-10-08 17:01:12 -04:00
weslambert
993aabedf2
Merge pull request #1491 from Security-Onion-Solutions/fix/so-elasticsearch-pipeline-stats-dots
...
Ensure pipelines with dots in names can be referenced
2020-10-08 15:41:44 -04:00
weslambert
06706d29f2
Ensure pipelines with dots in names can be referenced
2020-10-08 15:41:17 -04:00
weslambert
f41987024f
Merge pull request #1490 from Security-Onion-Solutions/feature/so-elastic-pipeline-stats
...
Add pipeline stats script
2020-10-08 15:12:55 -04:00
Wes Lambert
1efb39a71b
Add pipeline stats script
2020-10-08 19:11:41 +00:00
m0duspwnens
52e8265511
update is_airgap for soup
2020-10-08 14:16:19 -04:00
Mike Reeves
26317efe79
Update Soup
2020-10-08 14:05:52 -04:00
William Wernert
0795aa39ba
Merge pull request #1487 from Security-Onion-Solutions/feature/rotate-logs
...
Feature/rotate logs
2020-10-08 12:48:01 -04:00
William Wernert
2ad3f9da11
[fix] Wazuh not saving .log files anymore, only check .json files
2020-10-08 12:41:51 -04:00
William Wernert
034750fe5b
Merge branch 'dev' into feature/rotate-logs
...
# Conflicts:
# setup/so-functions
2020-10-08 12:36:30 -04:00
William Wernert
e1d8f578c2
[feat] Add log dirs for playbook + influxdb
2020-10-08 12:35:14 -04:00
Josh Patterson
2156adcf70
Merge pull request #1486 from Security-Onion-Solutions/fix/estemplates
...
fix templates not applying to searchnode.
2020-10-08 11:19:14 -04:00
m0duspwnens
e7abbf19af
fix templates not applying to searchnode. so-searchnode role doesnt exists searchnodes are so-node role
2020-10-08 11:17:26 -04:00
weslambert
0f5f781024
Merge pull request #1484 from Security-Onion-Solutions/fix/strelka_rule_null_safe_2
...
More fixes for rule field
2020-10-08 09:37:44 -04:00
Wes Lambert
a6d3dcf398
More fixes for rule field
2020-10-08 13:36:47 +00:00
weslambert
5e4bbcd4ca
Merge pull request #1483 from Security-Onion-Solutions/fix/strelka_rule_null_safe
...
Add null safe check for rule
2020-10-08 09:15:29 -04:00
Wes Lambert
a2e2f23a8d
Add null safe check for rule
2020-10-08 13:14:39 +00:00
weslambert
3ec9206b17
Merge pull request #1482 from Security-Onion-Solutions/fix/network_transport_kibana_viz
...
Fix network transport Kibana viz
2020-10-08 08:18:12 -04:00
Wes Lambert
adf0ef87c9
Fix network transport Kibana viz
2020-10-08 12:17:15 +00:00
weslambert
7767d3897b
Merge pull request #1481 from Security-Onion-Solutions/fix/network_transport_lower
...
Lowercase network.transport
2020-10-08 08:00:22 -04:00
weslambert
5ada85942b
Lowercase network.transport
2020-10-08 07:59:57 -04:00
Doug Burks
2489ca608a
Improve Hunt FTP queries #1479
2020-10-08 05:30:17 -04:00
Josh Patterson
0a982dec95
Merge pull request #1477 from Security-Onion-Solutions/issue/1403
...
Issue/1403
2020-10-07 17:47:21 -04:00
m0duspwnens
be7167d99b
Merge remote-tracking branch 'remotes/origin/dev' into issue/1403
2020-10-07 17:45:22 -04:00
m0duspwnens
821ce19aad
new dashboard for sensors
2020-10-07 17:38:16 -04:00
m0duspwnens
1bdc45ef0e
new dashboard for sensors
2020-10-07 17:37:11 -04:00
m0duspwnens
4f8bb9c2f1
updates to standalone and eval dashboards
2020-10-07 16:48:29 -04:00
m0duspwnens
7dd839cfa2
add zeek capture loss graph and resize redis queue for standalone
2020-10-07 15:53:31 -04:00
weslambert
7befff3baa
Merge pull request #1474 from Security-Onion-Solutions/fix/common_nids
...
Don't use regex for determining rule type
2020-10-07 12:16:55 -04:00
Wes Lambert
7543144afe
Don't use regex for determining rule type
2020-10-07 16:15:43 +00:00
weslambert
7787f81bdd
Merge pull request #1473 from Security-Onion-Solutions/fix/logstash_output_wazuh
...
Remove dataset name since pipeline no longer in use
2020-10-07 11:49:40 -04:00
weslambert
8e829b47ae
Remove dataset name since pipeline no longer in use
2020-10-07 11:48:56 -04:00
m0duspwnens
8540a691dc
only send loss if timestamp on data has changed
2020-10-07 11:23:06 -04:00
weslambert
8015676e01
Merge pull request #1472 from Security-Onion-Solutions/fix/rename-signature_info
...
Change rule.signature_info to rule.reference and ensure common.nids e…
2020-10-07 11:21:18 -04:00
Wes Lambert
015a441e79
Change rule.signature_info to rule.reference and ensure common.nids exists
2020-10-07 15:20:26 +00:00
weslambert
a1866e5229
Merge pull request #1471 from Security-Onion-Solutions/fix/ingest-updates
...
Fix/ingest updates
2020-10-07 11:15:55 -04:00
m0duspwnens
1106b2bf96
only send loss if timestamp on data has changed
2020-10-07 11:15:10 -04:00
Wes Lambert
f0a1457ffd
Update common.nids
2020-10-07 15:14:08 +00:00
m0duspwnens
d09f0f841e
only send loss if timestamp on data has changed
2020-10-07 11:13:03 -04:00
m0duspwnens
6f2d47cc40
only send loss if timestamp on data has changed
2020-10-07 11:11:06 -04:00
m0duspwnens
2317e8b348
only send loss if timestamp on data has changed
2020-10-07 11:08:41 -04:00
m0duspwnens
f96d6ae4f4
only send loss if timestamp on data has changed
2020-10-07 11:06:54 -04:00
m0duspwnens
5e534571ff
set timestamp with capture loss
2020-10-07 10:20:51 -04:00
m0duspwnens
14dd80b410
handle whitespace
2020-10-06 18:46:32 -04:00
m0duspwnens
af2df2c7d1
just print the loss
2020-10-06 18:44:22 -04:00
m0duspwnens
f95712c502
update log file
2020-10-06 18:38:51 -04:00
m0duspwnens
48ca2cdff1
fix pillars we check
2020-10-06 18:10:41 -04:00
m0duspwnens
4a236b3f75
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1403
2020-10-06 18:05:47 -04:00
m0duspwnens
73ce948d42
add zeekcaptureloss to data to influxdb. rename broloss to zeekloss - https://github.com/Security-Onion-Solutions/securityonion/issues/1403
2020-10-06 18:05:41 -04:00
Mike Reeves
fd4bb81f29
Fix ZEEKLOGS pillar
2020-10-06 17:38:05 -04:00
William Wernert
d84f85335e
[fix] Add jinja option, missing log dirs, compress option
2020-10-06 17:18:39 -04:00
Wes Lambert
8c07c098f6
Pipeline cleanup
2020-10-06 20:14:15 +00:00
Wes Lambert
350cc41740
Let zeek.common handle common fields for zeek.tunnels
2020-10-06 20:12:23 +00:00
William Wernert
b64a91f13c
[refactor] Remove nocompress option
2020-10-06 14:51:43 -04:00
William Wernert
27351fa520
[fix] Correct jinja syntax + indent all lines
2020-10-06 14:51:42 -04:00
Josh Patterson
7d14c68d70
Merge pull request #1468 from Security-Onion-Solutions/issue/163
...
fix yum db if corrupted -
2020-10-06 14:29:11 -04:00
m0duspwnens
035d215398
fix yum db if corrupted - https://github.com/Security-Onion-Solutions/securityonion/issues/163
2020-10-06 14:28:01 -04:00
Josh Patterson
51d3defe76
Merge pull request #1467 from Security-Onion-Solutions/issue/1460
...
Issue/1460
2020-10-06 14:06:01 -04:00
m0duspwnens
3d71766b64
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1460
2020-10-06 13:58:02 -04:00
m0duspwnens
34dfc809c7
handle thread count for suricata and default max-pending-packets to 5000 - https://github.com/Security-Onion-Solutions/securityonion/issues/1460
2020-10-06 13:57:50 -04:00
Mike Reeves
f809cf5216
Update so-functions
2020-10-06 13:27:23 -04:00
William Wernert
bd4292711e
[fix] Redirect missing lines to global pillar
2020-10-06 13:23:26 -04:00
William Wernert
9737b01676
[feat] Move logrotate configuration settings to pillar
2020-10-06 13:22:44 -04:00
William Wernert
94f15c63ce
[fix] Correct indent in common init.sls
2020-10-06 13:21:37 -04:00
weslambert
a16419b997
Merge pull request #1466 from Security-Onion-Solutions/fix/so-elasticsearch-templates-load
...
Rename so-elasticsearch-templates to so-elasticsearch-templates-load
2020-10-06 13:19:54 -04:00
Wes Lambert
a6a69c57d1
Rename so-elasticsearch-templates to so-elasticsearch-templates-load
2020-10-06 17:18:42 +00:00
weslambert
6cdff854f3
Merge pull request #1465 from Security-Onion-Solutions/feature/so-elasticsearch-templates-list
...
Add so-elasticsearch-templates-list
2020-10-06 13:16:11 -04:00
Wes Lambert
787f1d8732
Add so-elasticsearch-templates-list
2020-10-06 17:15:27 +00:00
weslambert
1a2921c2bc
Merge pull request #1463 from Security-Onion-Solutions/feature/so-elasticsearch-pipelines-list
...
Add so-elasticsearch-pipelines-list and fix common script perms
2020-10-06 13:04:24 -04:00
Wes Lambert
4a5d50cf80
Add so-elasticsearch-pipelines-list and fix common script perms
2020-10-06 17:01:58 +00:00
Josh Patterson
1b3eca80d7
Merge pull request #1462 from Security-Onion-Solutions/issue/1371
...
handle install locations of files copied
2020-10-06 11:41:37 -04:00
m0duspwnens
5eada1cdd5
handle install locations of files copied
2020-10-06 11:39:34 -04:00
Josh Patterson
4b1a8d7512
Merge pull request #1461 from Security-Onion-Solutions/issue/1371
...
Issue/1371
2020-10-06 11:22:58 -04:00
m0duspwnens
a5f4c96db0
qol user interaction improvements to analyst install
2020-10-06 11:19:43 -04:00
m0duspwnens
4eea0a464c
include remaining log functions from so-functions
2020-10-06 10:57:43 -04:00
m0duspwnens
7840002d18
update log file in title func
2020-10-06 10:51:31 -04:00
m0duspwnens
85168e9318
add title function
2020-10-06 10:49:38 -04:00
m0duspwnens
2420cd5db1
add some system characteristics to log like normal install does
2020-10-06 10:46:11 -04:00
Doug Burks
a686704d37
remove rule.uuid now that underlying issue has been resolved
2020-10-06 09:39:57 -04:00
weslambert
706c81daca
Merge pull request #1459 from Security-Onion-Solutions/feature/strelka_yara_alert
...
Add Strelka YARA matches as alerts
2020-10-06 08:23:16 -04:00
Wes Lambert
019bec992d
Add Strelka YARA matches as alerts
2020-10-06 12:19:44 +00:00
Josh Patterson
e2a787095c
Merge pull request #1458 from Security-Onion-Solutions/issue/1290
...
change for network miner 2.6 - https://github.com/Security-Onion-Solu…
2020-10-05 18:38:14 -04:00
m0duspwnens
acabcd27a7
change for network miner 2.6 - https://github.com/Security-Onion-Solutions/securityonion/issues/1290
2020-10-05 18:17:24 -04:00
Josh Patterson
24ff34ee81
Merge pull request #1457 from Security-Onion-Solutions/issue/1371
...
Issue/1371
2020-10-05 15:51:35 -04:00
Josh Brower
2e012432b4
Merge pull request #1455 from Security-Onion-Solutions/feature/training-req
...
Write out nested json
2020-10-05 15:34:43 -04:00
Josh Brower
de9ace62d4
Write out nested json
2020-10-05 15:34:02 -04:00
Josh Patterson
faf5e7a643
Merge pull request #1454 from Security-Onion-Solutions/issue/1444
...
logstash changes per https://github.com/Security-Onion-Solutions/secu…
2020-10-05 14:12:05 -04:00
m0duspwnens
748dc5ba91
logstash changes per https://github.com/Security-Onion-Solutions/securityonion/issues/1444
2020-10-05 14:10:05 -04:00
William Wernert
5dfd11a018
[feat] Add wazuh archive cleanup + fix indentation
2020-10-05 13:58:49 -04:00
William Wernert
e6cb75ce7e
[feat] Add common logrotate cron+config
2020-10-05 13:57:36 -04:00
Josh Patterson
f7daa391c7
Merge pull request #1453 from Security-Onion-Solutions/issue/1441
...
enable suricata threshold-file and point to proper file
2020-10-05 12:56:39 -04:00
Doug Burks
a45aa43f41
Add trailing comma to "thehive" stanza
2020-10-05 12:35:33 -04:00
m0duspwnens
63884b73e1
enable suricata threshold-file and point to proper file - https://github.com/Security-Onion-Solutions/securityonion/issues/1441
2020-10-05 12:10:52 -04:00
weslambert
9f4cb42c4f
Merge pull request #1452 from Security-Onion-Solutions/fix/kibana_case_create
...
Change alert to case
2020-10-05 11:46:14 -04:00
Wes Lambert
575da0f9d3
Change alert to case
2020-10-05 15:45:10 +00:00
weslambert
f4fcc052ca
Merge pull request #1451 from Security-Onion-Solutions/fix/wazuh_rule_cat
...
Put back rule.category for Wazuh alerts
2020-10-05 11:35:20 -04:00
weslambert
bc31e19e37
Put back rule.category for Wazuh alerts
2020-10-05 11:34:29 -04:00
weslambert
6e2319f6da
Merge pull request #1449 from Security-Onion-Solutions/fix/wazuh_logging
...
Adjust Wazuh logging so we don't log alerts to a separate file and so…
2020-10-05 10:04:01 -04:00
weslambert
968dce0aee
Adjust Wazuh logging so we don't log alerts to a separate file and so we don't write a separate log file for non-JSON for archives
2020-10-05 10:03:40 -04:00
Jason Ertel
1ebe970876
Disable escalate button if thehive is not enabled
2020-10-05 09:54:18 -04:00
weslambert
6b292ea62b
Merge pull request #1448 from Security-Onion-Solutions/fix/so_elastic_clear
...
Fix/so elastic clear
2020-10-05 09:40:04 -04:00
Wes Lambert
da8957b4f4
Use Elasticsearch pillar vs manager IP for so-elastic-clear
2020-10-05 13:37:06 +00:00
Wes Lambert
1970d95d5f
Make Filebeat registry persistent to avoid re-reading old data
2020-10-05 13:30:04 +00:00
Doug Burks
e7cba6ba1d
Change SOC Alerts eventFetchLimit from 5000 to 500 #1447
2020-10-05 09:29:01 -04:00
Doug Burks
948e0c4c61
Add rule.name to Hunt Wazuh Alerts query #1442
2020-10-05 09:26:13 -04:00
Jason Ertel
cf5b1245ea
Add configurable flags to enable/disable dismiss and escalate buttons
2020-10-05 09:16:17 -04:00
weslambert
771d091d6e
Merge pull request #1446 from Security-Onion-Solutions/feature/wazuh_severity
...
Add event.severity and event.severity_label config for Wazuh alerts
2020-10-05 08:52:20 -04:00
Wes Lambert
77d31cb289
Add event.severity and event.severity_label config for Wazuh alerts
2020-10-05 12:50:29 +00:00
weslambert
203e84d2cf
Update comma verbiage for HOME_NET in whiptail menu
2020-10-05 08:08:22 -04:00
Josh Brower
7b05cf4266
Merge pull request #1443 from Security-Onion-Solutions/feature/training-req
...
Feature/training req
2020-10-04 21:37:03 -04:00
Josh Brower
8a78485906
Config Playbook SOC Alerts
2020-10-04 21:35:42 -04:00
Josh Brower
c80b6ce104
Add so-allow-view and playbook event.sev.label
2020-10-04 20:39:21 -04:00
m0duspwnens
467e5b34cc
analyst node changes
2020-10-02 16:40:25 -04:00
m0duspwnens
20307b703e
analyst node changes
2020-10-02 16:21:31 -04:00
m0duspwnens
6a0f04d24a
analyst node changes
2020-10-02 16:14:15 -04:00
m0duspwnens
5a5007c07d
analyst node changes
2020-10-02 15:50:49 -04:00
m0duspwnens
fde6f128ab
analyst node changes
2020-10-02 15:26:13 -04:00
m0duspwnens
1be3323265
analyst node changes
2020-10-02 15:25:42 -04:00
m0duspwnens
47762816a7
analyst node changes
2020-10-02 14:57:22 -04:00
m0duspwnens
40647ce54c
analyst node changes
2020-10-02 14:40:15 -04:00
William Wernert
8310559273
Merge pull request #1440 from Security-Onion-Solutions/feature/generate-playbook-api-key
...
Feature/generate playbook api key
2020-10-02 14:37:58 -04:00
William Wernert
2a100c0dcc
Add OLD_ prefix + only update rules if playbook enabled
2020-10-02 14:34:30 -04:00
William Wernert
d0c267ca90
Fix sed command to not delete lines after match
2020-10-02 14:31:16 -04:00
William Wernert
54da2b869c
Add OLD_ db init files for soup compatibility
2020-10-02 14:12:23 -04:00
William Wernert
ab662e9b81
Merge branch 'dev' into feature/generate-playbook-api-key
...
# Conflicts:
# salt/common/tools/sbin/soup
2020-10-02 13:48:52 -04:00
William Wernert
db12b6f3c6
Remove salt call to automation_user_create
2020-10-02 13:17:57 -04:00
William Wernert
96d32fda51
Add old api key to pillar during soup
2020-10-02 13:16:58 -04:00
Mike Reeves
15f0c98281
Fix Formatting
2020-10-02 13:06:03 -04:00
m0duspwnens
d0da7ade6a
analyst node changes
2020-10-02 12:15:00 -04:00
m0duspwnens
c4e0fa0939
analyst node changes
2020-10-02 12:12:28 -04:00
m0duspwnens
e11717c4d0
analyst node changes
2020-10-02 11:28:53 -04:00
m0duspwnens
76a13e99da
new wallpaper
2020-10-02 10:12:36 -04:00
William Wernert
20fd757847
Run playbook-ruleupdate after soctopus is running
2020-10-02 10:05:10 -04:00
William Wernert
39e14b3910
Merge branch 'dev' into feature/generate-playbook-api-key
2020-10-02 08:39:09 -04:00
Mike Reeves
c7fcdc8084
Merge pull request #1438 from Security-Onion-Solutions/socyaml
...
Socyaml
2020-10-01 18:08:33 -04:00
Mike Reeves
4991ea8de3
Jason made me rename json
2020-10-01 18:07:06 -04:00
Mike Reeves
36ccece724
commas gone crazy
2020-10-01 18:02:06 -04:00
Mike Reeves
a0432e97b0
Python print ftl
2020-10-01 17:57:56 -04:00
m0duspwnens
733b1376c5
analyst node changes
2020-10-01 17:53:20 -04:00
Mike Reeves
490278a4c3
Add alert events filed
2020-10-01 17:49:17 -04:00
Mike Reeves
bd5efbabd9
Fix Mode
2020-10-01 17:43:43 -04:00
Mike Reeves
8fa426f265
Cleanup sync
2020-10-01 17:41:55 -04:00
Mike Reeves
9d9d3aac53
Switch to JSON from yaml
2020-10-01 17:37:57 -04:00
Mike Reeves
744a8bca73
More json for soc
2020-10-01 17:30:23 -04:00
Mike Reeves
8a41636e7f
More json for soc
2020-10-01 17:28:45 -04:00
Mike Reeves
dc79dca7fe
More json for soc
2020-10-01 17:25:51 -04:00
Mike Reeves
1c55f738ec
More json for soc
2020-10-01 17:23:29 -04:00
William Wernert
e98012ae2c
Fix jinja and change state orrder in setup
2020-10-01 17:16:26 -04:00
Mike Reeves
92fa33159e
More json for soc
2020-10-01 17:12:08 -04:00
m0duspwnens
72c6fe2184
analyst node changes
2020-10-01 17:05:59 -04:00
Mike Reeves
5730c85988
More json for soc
2020-10-01 17:04:15 -04:00
Mike Reeves
63be0734c9
More json for soc
2020-10-01 17:00:25 -04:00
Mike Reeves
5653828154
More json for soc
2020-10-01 16:57:04 -04:00
weslambert
2d2f4de337
Merge pull request #1437 from Security-Onion-Solutions/fix/kib_scripted_thehive
...
Update scripted field for TheHive case
2020-10-01 16:54:02 -04:00
Wes Lambert
8a81a5148b
Update scripted field for TheHive case
2020-10-01 20:52:57 +00:00
weslambert
98bef8fb9d
Merge pull request #1436 from Security-Onion-Solutions/fix/kibana_soc_thehive_case
...
Add SOC url for api integration
2020-10-01 16:47:11 -04:00
Wes Lambert
eced18c3cc
Add SOC url for api integration
2020-10-01 20:29:28 +00:00
Jason Ertel
8e15ed56d6
'Escalated' filter toggle will auto-enable 'acknowledged' filter toggle
2020-10-01 16:23:47 -04:00
m0duspwnens
76c98200f3
analyst node changes
2020-10-01 16:21:51 -04:00
Mike Reeves
cc2f2de5b5
soc.json stuff
2020-10-01 15:23:07 -04:00
Mike Reeves
b423e8d22a
soc.json stuff
2020-10-01 15:20:13 -04:00
Mike Reeves
1a561f6b12
soc.json stuff
2020-10-01 15:18:34 -04:00
William Wernert
a5bf4bbb35
Fix test for key in global.sls
2020-10-01 14:47:18 -04:00
m0duspwnens
964bad4657
analyst node changes
2020-10-01 13:53:38 -04:00
Doug Burks
e836f96c65
move rule.uuid after rule.name
2020-10-01 12:09:52 -04:00
Doug Burks
4851069a10
remove rule.gid from Alerts groupby since Wazuh and Playbook may not have that field
2020-10-01 11:51:40 -04:00
William Wernert
040730e8f5
Rename script for consistent naming
2020-10-01 11:22:11 -04:00
William Wernert
afb777fc8f
Add automation user creation to soup when resetting playbook db
2020-10-01 11:13:24 -04:00
m0duspwnens
75d49845f2
changes to analyst setup script
2020-10-01 10:43:33 -04:00
Doug Burks
bc19cce4c2
Acknowledging an alert may acknowledge more alerts than intended #1426
2020-10-01 10:00:54 -04:00
Doug Burks
26781de244
Add Strelka query to Hunt #1433
2020-10-01 06:59:36 -04:00
William Wernert
2264b6e51c
Add comments to shell code explaining curl statements
2020-09-30 19:54:34 -04:00
William Wernert
03b97cce75
Fix comment in new state + remove useless sleep command
2020-09-30 19:49:13 -04:00
William Wernert
11ae904100
Quiet script output + fix pillar value
2020-09-30 19:46:18 -04:00
weslambert
6818de9e64
Merge pull request #1431 from Security-Onion-Solutions/fix/elastlert_rules
...
Remove rule sync, since we don't have any rules to sync
2020-09-30 18:36:11 -04:00
weslambert
887937a75d
Remove rule sync, since we don't have any rules to sync
2020-09-30 18:35:35 -04:00
William Wernert
596f2d31e4
Automation -> automation
2020-09-30 17:04:24 -04:00
William Wernert
3ec255ecee
Remove old api token from sql
2020-09-30 17:03:35 -04:00
William Wernert
6361c790e9
Move automation user create to separate script to run after playbook state
2020-09-30 17:02:02 -04:00
William Wernert
8e80b41ca9
Remove Automation user from sql, gen user + store api key
2020-09-30 16:32:43 -04:00
Jason Ertel
1454201505
Disable thehivealerter
2020-09-30 15:26:29 -04:00
Jason Ertel
3af6e9e1fe
Remove mount point for SOCtopus generated playbook rules to avoid them activating and sending alerts to TheHive
2020-09-30 15:14:45 -04:00
Mike Reeves
8b5ff31351
Merge pull request #1430 from Security-Onion-Solutions/redis
...
Add Redis pillar and fix idstools
2020-09-30 15:09:59 -04:00
Mike Reeves
7314e2dea8
Add Redis pillar and fix idstools
2020-09-30 15:08:44 -04:00
Jason Ertel
ff04bb507a
Remove default Elastalert rules to stop automated alerts from being sent to thehive
2020-09-30 15:06:54 -04:00
weslambert
5b16a65422
Merge pull request #1429 from Security-Onion-Solutions/fix/zeek_server_ip
...
Fix issue with null Zeek server IP
2020-09-30 13:54:50 -04:00
Wes Lambert
02d2e5e2c6
Fix isue with null Zeek server IP
2020-09-30 17:53:30 +00:00
William Wernert
f3b8da1f9d
Fix Engrish (can causing -> can cause)
2020-09-30 13:40:57 -04:00
William Wernert
25d4bde33b
Merge pull request #1428 from Security-Onion-Solutions/feature/warn-dhcp
...
Add warning about IP address changing for network/DHCP iso installs
2020-09-30 13:13:40 -04:00
William Wernert
1ff20f7e27
Add warning about IP address changing for network/DHCP iso installs
2020-09-30 13:11:33 -04:00
weslambert
defe832121
Merge pull request #1427 from Security-Onion-Solutions/fix/wazuh_filebeat
...
Fix Filebeat config for Wazuh
2020-09-30 10:59:01 -04:00
Wes Lambert
d8f70397f7
Fix Filebeat config for Wazuh
2020-09-30 14:57:56 +00:00
weslambert
dac2ad5dbf
Merge pull request #1425 from Security-Onion-Solutions/feature/soctopus_pillar
...
Add initial implementation of SOCtopus pillar
2020-09-30 10:25:26 -04:00
Wes Lambert
c62acf5e4e
Add initial implmentation of SOCtopus pillar
2020-09-30 14:24:15 +00:00
Josh Patterson
10f4e09b70
Merge pull request #1424 from Security-Onion-Solutions/issue/1070
...
Issue/1070
2020-09-30 10:11:37 -04:00
William Wernert
00785c6ba5
Merge pull request #1418 from Security-Onion-Solutions/feature/replace-hardcoded-pass
...
Feature/replace hardcoded pass
2020-09-30 08:56:35 -04:00
Doug Burks
0a995f4a7a
Update README.md
2020-09-30 07:43:20 -04:00
m0duspwnens
85969dc16d
add quotes and remove quotes
2020-09-29 16:29:05 -04:00
m0duspwnens
bf99bab6c0
add quotes and remove quotes
2020-09-29 16:26:45 -04:00
weslambert
401764437f
Merge pull request #1421 from Security-Onion-Solutions/fix/ip_type
...
Ensure IPs are typed as IP and ports as integer
2020-09-29 14:21:25 -04:00
Wes Lambert
36019727b3
Ensure IPs are typed as IP and ports as integer
2020-09-29 18:20:15 +00:00
m0duspwnens
547c3ff52c
single quote inputs to yaml files
2020-09-29 13:59:16 -04:00
William Wernert
7d43d48aca
Remove bad line in playbook_db_init.sh
2020-09-29 11:13:09 -04:00
William Wernert
55058a11aa
Generate passwords for Grafana + Playbook default users
2020-09-29 11:12:09 -04:00
William Wernert
ebe00822f8
Merge pull request #1417 from Security-Onion-Solutions/bugfix/local_zeeklogs
...
Bugfix/local zeeklogs
2020-09-29 08:58:02 -04:00
Doug Burks
60134829d5
Alerts - Drilldown should display rule.uuid #1416
2020-09-29 07:51:45 -04:00
Doug Burks
c7b43ac220
Update soc.json
2020-09-29 07:41:49 -04:00
Doug Burks
a7f24b62e6
Hunt - improve NIDS query and eventFields #1415
2020-09-29 07:34:44 -04:00
Josh Patterson
9ca13ebccd
Merge pull request #1414 from Security-Onion-Solutions/issue/1404
...
change so salt module to /usr/sbin/so-status
2020-09-28 18:31:26 -04:00
Mike Reeves
c828a2ea75
Merge pull request #1413 from Security-Onion-Solutions/experimental
...
Airgap SOUP!
2020-09-28 17:47:38 -04:00
m0duspwnens
8741520263
change so salt module to /usr/sbin/so-status
2020-09-28 17:31:05 -04:00
Mike Reeves
6b8b0f1b26
Change add registry
2020-09-28 16:48:02 -04:00
William Wernert
f77305e22f
Generate zeeklogs sls earlier to avoid error
2020-09-28 16:45:06 -04:00
William Wernert
f782299281
Remove preconfigured zeeklog + create it during setup
2020-09-28 15:12:36 -04:00
Josh Patterson
fa6396b121
Merge pull request #1410 from Security-Onion-Solutions/fix/disable_auto_start
...
send to dev/null to prevent output
2020-09-28 15:07:40 -04:00
weslambert
3d6c956e02
Merge pull request #1409 from Security-Onion-Solutions/feature/wazuh_wel
...
Add initial parsing for Wazuh WEL/Sysmon
2020-09-28 15:07:15 -04:00
m0duspwnens
0bb1ba2853
send to dev/null to prevent output
2020-09-28 15:06:43 -04:00
Wes Lambert
869767d9d9
Add initial parsing for Wazuh WEL/Sysmon
2020-09-28 19:04:21 +00:00
Josh Patterson
0944cd1bcd
Merge pull request #1408 from Security-Onion-Solutions/issue/1093
...
Issue/1093
2020-09-28 14:45:18 -04:00
m0duspwnens
3b709e7877
remove cleaning of webpasswd1
2020-09-28 14:44:14 -04:00
Doug Burks
6e9e4dc99c
Hunt third magnifying glass should group output by event.module and event.dataset #1407
2020-09-28 14:19:55 -04:00
Mike Reeves
2cdf76473c
Add Registry back from cleanup
2020-09-28 14:19:43 -04:00
m0duspwnens
053b19de11
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-28 13:25:42 -04:00
m0duspwnens
bda9078843
check for invalid characters in fleet user password
2020-09-28 13:25:23 -04:00
Doug Burks
0516a9ddd5
Alerts page "Hunt for this field" action should quote field and group output #1406
2020-09-28 12:35:08 -04:00
m0duspwnens
85e53c53af
reject passwords with single or double quotes or backslashes
2020-09-28 11:51:19 -04:00
Mike Reeves
6a4d6f7a6d
Additional logic
2020-09-28 10:12:52 -04:00
William Wernert
66b7678df8
Merge pull request #1405 from Security-Onion-Solutions/feature/setup-cleanup
...
Feature/setup cleanup
2020-09-28 09:47:52 -04:00
William Wernert
3b9de2b7ca
Disable ipv6 earlier in setup
2020-09-28 09:14:45 -04:00
William Wernert
a60bf11daa
Make sure zeek log is only written on whiptail success
2020-09-28 09:11:50 -04:00
William Wernert
05729d216a
Don't direct user to check log in so-zeek-log, none exists
2020-09-28 08:45:59 -04:00
Doug Burks
3904295137
Hunt - improve HTTP queries #1401
2020-09-27 08:04:28 -04:00
Doug Burks
aa7f927ffd
Hunt - improve x509 queries #1400
2020-09-27 07:17:46 -04:00
Jason Ertel
68f18da832
Add alert query toggle filters for ack'd and escalated alerts
2020-09-25 17:03:42 -04:00
William Wernert
dc330a774e
Exit so-zeek-logs if user cancels
2020-09-25 16:30:16 -04:00
William Wernert
9acf610262
Also disable ipv6 for install
2020-09-25 16:10:26 -04:00
William Wernert
d76a4b1359
Show welcome screen on both iso and network installs
2020-09-25 14:59:27 -04:00
Doug Burks
11b200e9c0
Hunt - remove SMTP fields #1397
2020-09-25 14:17:14 -04:00
Doug Burks
20a56d0831
Hunt - add network.community_id column to Events table for more data types #1396
2020-09-25 13:18:28 -04:00
weslambert
6bfef773f2
Merge pull request #1392 from Security-Onion-Solutions/bugfix/config_dev_nullify
...
dev nullify so-config-backup cron job
2020-09-24 21:00:18 -04:00
weslambert
b3f9ee3b34
dev nullify so-config-backup cron job
2020-09-24 20:59:42 -04:00
Jason Ertel
c0be252f9f
SOC config adjustments for alerting
2020-09-24 16:37:27 -04:00
Josh Patterson
04f2595fa1
Merge pull request #1389 from Security-Onion-Solutions/issue/1388
...
fix common salt package name for salt.master state for ubuntu
2020-09-24 12:36:26 -04:00
Mike Reeves
e30958b9ec
Airgap SOUP changes
2020-09-24 11:41:02 -04:00
m0duspwnens
d9005c157d
fix common salt package name for salt.master state for ubuntu - https://github.com/Security-Onion-Solutions/securityonion/issues/1388
2020-09-24 11:26:58 -04:00
Doug Burks
62dbe425a6
Hunt - fix x509 eventFields #1387
2020-09-24 07:52:46 -04:00
Doug Burks
2b8b8e2f40
Hunt - fix file eventFields #1386
2020-09-24 07:44:28 -04:00
Doug Burks
60daacd6dc
Hunt - fix DHCP eventFields #1385
2020-09-24 07:34:29 -04:00
weslambert
a09002edae
Merge pull request #1384 from Security-Onion-Solutions/bugfix/config_backup
...
Add back missing # sign
2020-09-23 21:34:52 -04:00
weslambert
5b93c40ce4
Add back missing # sign
2020-09-23 21:34:10 -04:00
m0duspwnens
3ba8f47d9c
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-23 15:01:48 -04:00
m0duspwnens
6f7dbee36e
remove single quotes from secrets pillar
2020-09-23 14:57:26 -04:00
Mike Reeves
fd302c6363
make autocomplete with sudo work
2020-09-23 13:19:37 -04:00
m0duspwnens
70f98e2eea
take care single quotes if they are in the WEBPASSWD
2020-09-23 13:00:18 -04:00
m0duspwnens
b32bc8b542
Merge remote-tracking branch 'remotes/origin/dev' into issue/1093
2020-09-23 12:07:12 -04:00
Mike Reeves
aca98e01f3
Set the path
2020-09-23 12:00:25 -04:00
Jason Ertel
2f7c0c34e6
Support backslashes in SOC passwords
2020-09-23 10:09:21 -04:00
weslambert
4f228c1b7c
Merge pull request #1379 from Security-Onion-Solutions/feature/config_backup
...
Feature/config backup
2020-09-23 09:58:05 -04:00
Wes Lambert
71734ddc0a
Add cron job to common state for daily config backup
2020-09-23 13:55:32 +00:00
Wes Lambert
57732b360e
Add config backup script
2020-09-23 13:47:14 +00:00
Wes Lambert
4d42d04cc3
Fix backup pillar definition
2020-09-23 13:45:42 +00:00
Wes Lambert
d02c440934
Add backup params to global.sls
2020-09-22 21:05:57 +00:00
m0duspwnens
77a9bf2697
test single quotes in secrets pillar
2020-09-22 13:16:20 -04:00
Josh Brower
18a881ccab
Merge pull request #1377 from Security-Onion-Solutions/bugfix/docker_cleanup
...
fix docker_clean syntax
2020-09-21 19:42:11 -04:00
Josh Brower
8bb527b4f1
fix docker_clean syntax
2020-09-21 19:41:39 -04:00
Jason Ertel
694635a38f
Add pivot to hunt as a new alerts quick action
2020-09-21 17:10:03 -04:00
Mike Reeves
0f1b92cea9
Update so-rule-update
2020-09-21 15:40:38 -04:00
Mike Reeves
48b17ee51a
Merge pull request #1375 from Security-Onion-Solutions/gaupgrade
...
Upgrade to GA including Docker Cleanup
2020-09-21 13:14:49 -04:00
Mike Reeves
d56a9e1f86
Upgrade to GA including Docker Cleanup
2020-09-21 13:14:06 -04:00
Josh Brower
ffdf7e1db4
Merge pull request #1374 from Security-Onion-Solutions/feature/so-user-list
...
Add so-user-list
2020-09-21 10:03:02 -04:00
Josh Brower
3cd11807cd
Add so-user-list
2020-09-21 10:02:10 -04:00
Jason Ertel
8f4a6df53a
Add event.module to default alert query
2020-09-21 09:06:56 -04:00
Jason Ertel
fc51c2aef4
Group by community ID on second alert quick query
2020-09-19 08:39:01 -04:00
Jason Ertel
5b38acb64b
Add alerting configuration for soc container
2020-09-18 13:51:23 -04:00
Josh Patterson
2b155b5581
Merge pull request #1368 from Security-Onion-Solutions/issue/1367
...
add so-fleet so standalone fleet gets the redis pki
2020-09-18 13:41:43 -04:00
m0duspwnens
40f6fed2a5
add so-fleet so standalone fleet gets the redis pki
2020-09-18 13:40:27 -04:00
Jason Ertel
1610445b4e
Validate password before creating user
2020-09-18 08:29:30 -04:00
Jason Ertel
0c12025599
Do not restart mysql after setup when running automated tests
2020-09-18 08:22:28 -04:00
Mike Reeves
33e381ad15
Update VERSION
2020-09-17 15:08:36 -04:00
Mike Reeves
bafb13fd6d
Merge pull request #1363 from Security-Onion-Solutions/dev
...
RC3
2020-09-17 15:05:33 -04:00
Mike Reeves
56e9f09c20
Update VERIFY_ISO.md
2020-09-17 11:02:16 -04:00
Mike Reeves
6cd30ce52f
Update Sig
2020-09-17 10:56:29 -04:00
Mike Reeves
3fb98bfd4d
Update VERIFY_ISO.md
2020-09-17 10:54:18 -04:00
Mike Reeves
4701091f76
Update VERIFY_ISO.md
2020-09-17 10:54:01 -04:00
Doug Burks
57e45308af
Fix pivot from TheHive to Kibana #1362
2020-09-17 08:05:55 -04:00
Doug Burks
c9c1245d1e
change from 2.1 RC2 to 2.2 RC3
2020-09-17 08:01:10 -04:00
Mike Reeves
7415c7fe81
Fix dashboard script
2020-09-16 14:55:32 -04:00
Mike Reeves
eac58f8f34
Merge pull request #1346 from Security-Onion-Solutions/rc3upgrade
...
Rc3upgrade
2020-09-16 14:29:53 -04:00
Mike Reeves
52072e0484
Update soup
2020-09-16 14:08:48 -04:00
doug
840b54d73c
make so-analyst executable
2020-09-16 13:11:49 -04:00
Mike Reeves
5910fe642c
Fix Update XML
2020-09-16 13:08:21 -04:00
Mike Reeves
a0f64440e0
Update changes.json
2020-09-16 13:06:26 -04:00
weslambert
74e4adda11
Merge pull request #1357 from Security-Onion-Solutions/feature/dashboard_updates_2
...
Add All Logs for Connections dashboard
2020-09-16 11:56:38 -04:00
Wes Lambert
44ef935d65
Add All Logs for Connections dashboard
2020-09-16 15:55:28 +00:00
Mike Reeves
3e0e41be32
Update changes.json
2020-09-16 11:41:21 -04:00
Mike Reeves
1801361cf8
Update changes.json
2020-09-16 11:40:05 -04:00
weslambert
6325b30a21
Merge pull request #1356 from Security-Onion-Solutions/feature/dashboard_updates
...
Kibana dashboard updates
2020-09-16 11:19:27 -04:00
Wes Lambert
bd8d2fc271
Kibana dashboard updates
2020-09-16 15:17:26 +00:00
Josh Patterson
6e0806a587
Merge pull request #1353 from Security-Onion-Solutions/fix/strelkaconfig
...
fix sensor mainip logic for strelka yaml files
2020-09-16 10:32:58 -04:00
m0duspwnens
4ee3e1ed01
fix sensor mainip logic for strelka yaml files
2020-09-16 10:29:23 -04:00
Josh Patterson
b7e41b53cb
Merge pull request #1352 from Security-Onion-Solutions/fix/es_templates
...
fix MYIP
2020-09-16 10:12:27 -04:00
m0duspwnens
3fe276dbb5
fix MYIP
2020-09-16 10:11:39 -04:00
Josh Patterson
66f21c4568
Merge pull request #1350 from Security-Onion-Solutions/fix/es_templates
...
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:54:16 -04:00
Josh Brower
d5fd15962c
Merge pull request #1351 from Security-Onion-Solutions/bugfix/tcpreplay
...
Fix so-test
2020-09-16 09:52:08 -04:00
Josh Brower
dd2d736bc1
Fix so-test
2020-09-16 09:51:38 -04:00
m0duspwnens
dd56d7d2d1
change how we determine the ip. run script on search and import nodes as well
2020-09-16 09:48:38 -04:00
weslambert
6806bd2461
Merge pull request #1348 from Security-Onion-Solutions/bugfix/es_template_load
...
Ensure templates are loaded for heavy nodes
2020-09-15 17:15:56 -04:00
weslambert
fbf037f460
Ensure templates are loaded for heavy nodes
2020-09-15 17:14:06 -04:00
Josh Brower
46a1369e81
Merge pull request #1347 from Security-Onion-Solutions/bugfix/tcpreplay
...
Add so-test
2020-09-15 13:20:56 -04:00
Josh Brower
2516429834
Add so-test
2020-09-15 13:14:00 -04:00
Mike Reeves
fc8ffd2080
Made the version update more reliable
2020-09-15 11:09:01 -04:00
Mike Reeves
ee4b35f2e4
Rename zeekversion.map.jinja to mdengine.map.jinja
2020-09-14 22:30:10 -04:00
Mike Reeves
c31d998061
Disk Space Check Final Final Final
2020-09-14 20:17:28 -04:00
Mike Reeves
62a8e676d9
Disk Space Check Final Final
2020-09-14 20:11:04 -04:00
Mike Reeves
9ef2b93586
Disk Space Check Final Final
2020-09-14 20:09:53 -04:00
Mike Reeves
eafb4e81a5
Disk Space Check Final Final
2020-09-14 20:01:53 -04:00
Mike Reeves
6eb3333af4
Disk Space Check Final
2020-09-14 19:46:16 -04:00
Mike Reeves
07e536df98
Disk Space Check
2020-09-14 19:42:58 -04:00
Mike Reeves
e8d2a6fdc2
Disk Space Check
2020-09-14 19:32:14 -04:00
Mike Reeves
1bc5e33007
Rotate Mysql Container Log
2020-09-14 16:27:32 -04:00
Mike Reeves
e2ecfca4c1
Merge pull request #1343 from Security-Onion-Solutions/rc3upgrade
...
Upgrade Fun
2020-09-14 14:54:37 -04:00
Mike Reeves
0a0e00866c
Upgrade Fun
2020-09-14 14:50:22 -04:00
Mike Reeves
38266f7db8
Merge pull request #1342 from Security-Onion-Solutions/experimental
...
Fix ruleupdate setting
2020-09-14 14:26:31 -04:00
Mike Reeves
9957fdec0f
Fix ruleupdate setting
2020-09-14 14:17:55 -04:00
Josh Patterson
32632864eb
Merge pull request #1341 from Security-Onion-Solutions/issue/1066
...
change how we determine how to run so-status
2020-09-14 12:43:05 -04:00
m0duspwnens
b559e5dd32
change how we determine how to run so-status
2020-09-14 12:40:39 -04:00
Jason Ertel
f86780a0db
Open PCAPs in same tab, but open external sites in new tabs
2020-09-14 10:41:39 -04:00
Mike Reeves
1958fef4ad
Merge pull request #1338 from Security-Onion-Solutions/experimental
...
Fix strelka rules
2020-09-14 09:58:34 -04:00
Mike Reeves
ee1317adf1
Merge branch 'experimental' of https://github.com/Security-Onion-Solutions/securityonion into experimental
2020-09-14 09:57:14 -04:00
Mike Reeves
d1836fb3a3
Fix Salt issue with script
2020-09-14 09:57:08 -04:00
Josh Patterson
67c1ece0bb
Merge pull request #1337 from Security-Onion-Solutions/issue/1066
...
Issue/1066
2020-09-14 09:38:15 -04:00
m0duspwnens
b93d149631
fix so-status
2020-09-14 09:36:26 -04:00
m0duspwnens
46cbcfa330
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into issue/1066
2020-09-14 08:45:54 -04:00
Mike Reeves
841db1b4b9
Merge pull request #1336 from Security-Onion-Solutions/experimental
...
Get Rules onto the install for airgap
2020-09-13 14:58:36 -04:00
Mike Reeves
112a0b426e
Merge branch 'dev' into experimental
2020-09-13 14:54:00 -04:00
Doug Burks
18dc7a915a
Hunt: Fix Tunnel query #1335
2020-09-13 08:26:33 -04:00
Jason Ertel
89c38541ee
Force all SOC quick actions to open in new tab
2020-09-13 02:52:25 -04:00
Mike Reeves
d6d22fb0e0
Fix Strelka
2020-09-12 23:07:35 -04:00
Mike Reeves
bb936c5bee
Fix Strelka
2020-09-12 23:07:15 -04:00
Mike Reeves
259df2ed6b
Fix Strelka
2020-09-12 23:06:06 -04:00
Doug Burks
311d67b934
Hunt: fix RFB groupby #1332
2020-09-12 06:14:58 -04:00
Josh Patterson
f03b128924
Merge pull request #1331 from Security-Onion-Solutions/fix/top
...
add redis to eval if playbook enabled
2020-09-11 18:31:19 -04:00
m0duspwnens
5f567368be
add redis to eval if playbook enabled
2020-09-11 18:30:21 -04:00
m0duspwnens
77911acfb4
so-status module
2020-09-11 18:28:53 -04:00
Mike Reeves
48d1d0c168
Strelkas Rules Update
2020-09-11 18:24:56 -04:00
Josh Patterson
2d508d9e57
Merge pull request #1328 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-11 15:02:30 -04:00
m0duspwnens
15563f2ee6
add nginx to top for sensor
2020-09-11 12:28:42 -04:00
m0duspwnens
bb0e686444
add elasticsearch to top for nodes missing it
2020-09-11 11:35:17 -04:00
Mike Reeves
46866f40b3
Merge pull request #1325 from Security-Onion-Solutions/experimental
...
Update Script
2020-09-11 11:02:57 -04:00
Mike Reeves
6e0cdf7be4
Update Script help
2020-09-11 11:01:56 -04:00
m0duspwnens
5f7c270984
only allow strelka to run on nodes that are sensors
2020-09-11 10:22:12 -04:00
Mike Reeves
af9a19b6e8
Merge pull request #1321 from Security-Onion-Solutions/experimental
...
IDS Tools now with Airgap support
2020-09-10 19:05:16 -04:00
Mike Reeves
53319738c4
Fix Nginx state
2020-09-10 16:56:48 -04:00
Mike Reeves
ef46094b0c
Update all nginx configs
2020-09-10 13:55:56 -04:00
Josh Patterson
53ff87b0ee
Merge pull request #1312 from Security-Onion-Solutions/issue/1281
...
add elasticsearch state to top for manager node
2020-09-10 12:47:05 -04:00
m0duspwnens
bc420d4a02
add
2020-09-10 11:57:15 -04:00
Josh Patterson
ca26548b2c
Merge pull request #1310 from Security-Onion-Solutions/issue/1281
...
Issue/1281
2020-09-10 10:08:25 -04:00
m0duspwnens
0ed9c65646
remove logic from fleet state to only run if in top
2020-09-10 10:07:05 -04:00
Doug Burks
8c280221da
Hunt: Fix Intel groupby #1131
2020-09-10 07:00:54 -04:00
Doug Burks
24c325e9a1
Fix Elasticsearch parsing for Zeek Intel Indicator #1309
2020-09-10 06:41:19 -04:00
Josh Brower
56587f0df5
Merge pull request #1308 from Security-Onion-Solutions/feature/wel-ingest
...
Add event.category to WEL
2020-09-10 06:16:56 -04:00
Josh Brower
c3b2d98ffb
Add event.category to WEL
2020-09-10 06:15:30 -04:00
Doug Burks
7161a662aa
improve Wazuh support in Hunt
2020-09-10 06:03:33 -04:00
Mike Reeves
5d4e8925a3
Add Firewall Logic
2020-09-09 21:16:40 -04:00
Mike Reeves
45b11b2321
Fix Rulecat
2020-09-09 18:38:07 -04:00
Doug Burks
d18c498574
Update so-features-enable
2020-09-09 17:32:42 -04:00
m0duspwnens
09cc8ae1fb
fail the state if it isnt in top
2020-09-09 16:48:50 -04:00
m0duspwnens
01c9f7b2ae
merge with dev and resolve conflicts
2020-09-09 16:23:36 -04:00
Mike Reeves
7ebf93fcb5
IDSTools Overhaul
2020-09-09 15:53:32 -04:00
Josh Patterson
1e32b32659
Merge pull request #1302 from Security-Onion-Solutions/fix/sostatus
...
Fix/sostatus
2020-09-09 15:07:12 -04:00
m0duspwnens
39f200f565
fix whitespace
2020-09-09 14:59:21 -04:00
Mike Reeves
a77532c1d8
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 14:57:17 -04:00
Mike Reeves
04f4539385
Fix Airgap Repo Name
2020-09-09 14:57:10 -04:00
m0duspwnens
b0c526364f
handle strelka
2020-09-09 14:55:54 -04:00
m0duspwnens
921262b9a5
prevent duplicate containers for so-stauts
2020-09-09 14:07:38 -04:00
Jason Ertel
a5b87850df
Remove user sync between SOC and Cortex due to the unnecesary complexities involved with this style of integration
2020-09-09 14:07:36 -04:00
m0duspwnens
05d736d2df
handle strelka
2020-09-09 14:00:58 -04:00
m0duspwnens
918d9cf00f
handle strelka
2020-09-09 13:57:53 -04:00
m0duspwnens
3433b90029
fix so-status for strelka and wazuh
2020-09-09 13:53:10 -04:00
Doug Burks
82b582540e
Add period
2020-09-09 12:56:19 -04:00
Doug Burks
90ba1be978
Improve formatting of NIDS selection screen
2020-09-09 12:55:14 -04:00
m0duspwnens
e84507c386
Merge remote-tracking branch 'remotes/origin/dev' into fix/sostatus
2020-09-09 12:51:01 -04:00
m0duspwnens
9ee9a199b1
predefine each component as 0 to fix issues with it being unset
2020-09-09 12:50:22 -04:00
Jason Ertel
fc4ad1d556
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:22:38 -04:00
Jason Ertel
9babc445ce
Add Google search quick action to Hunt; Change VirusTotal quick action to be applicable to all field values
2020-09-09 12:07:23 -04:00
Mike Reeves
90feb503ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-09-09 10:54:53 -04:00
Mike Reeves
426257443a
Final airgap tweaks
2020-09-09 10:54:47 -04:00
Doug Burks
eaf3281ab7
Remove Suricata version numbers from Setup screens #1300
...
https://github.com/Security-Onion-Solutions/securityonion/issues/1300
2020-09-09 10:43:41 -04:00
Josh Patterson
c2398f966b
Merge pull request #1295 from Security-Onion-Solutions/fix/salt-ca-ssl
...
Fix/salt ca ssl
2020-09-09 10:36:54 -04:00
m0duspwnens
7facff2b7d
change from cmd.run to cp.get_file_str
2020-09-09 10:34:53 -04:00
Jason Ertel
ad05e75ce7
Add new quick actions to SOC config template
2020-09-09 00:46:23 -04:00
Mike Reeves
7d524a0723
Add Firewall Rule for yum and airgap
2020-09-08 18:51:14 -04:00
Josh Patterson
d7016b4557
Merge pull request #1298 from Security-Onion-Solutions/issue/1291
...
Issue/1291
2020-09-08 17:40:33 -04:00
m0duspwnens
da34222931
makedirs
2020-09-08 17:36:27 -04:00
m0duspwnens
eeb6c3128b
add salt.master state to manager nodes
2020-09-08 17:27:13 -04:00
m0duspwnens
da3d0948b4
creating engine to watch the health of the salt mine
2020-09-08 16:49:38 -04:00
Jason Ertel
710a2be422
Add new so-user-enable script and change so-user-disable to call 'so-user disable' instead of deleting the SOC user
2020-09-08 16:24:18 -04:00
Mike Reeves
7c41c31359
Fix airgap statement
2020-09-08 14:48:37 -04:00
Mike Reeves
7371f9236e
Update top.sls
2020-09-08 14:18:56 -04:00
Mike Reeves
1aea3f4f85
Merge pull request #1297 from Security-Onion-Solutions/experimental
...
Add Airgap code
2020-09-08 09:26:41 -04:00
Doug Burks
f8ebed43d7
fix spacing
2020-09-07 04:45:26 -04:00
Doug Burks
f5916e26a2
read ca.crt from filesystem when possible
2020-09-07 04:42:11 -04:00
weslambert
b6b52671e2
Merge pull request #1294 from Security-Onion-Solutions/fix/wazuh_agent_name
...
Fix typo
2020-09-05 08:17:09 -04:00
Wes Lambert
f9884606df
Fix typo
2020-09-05 12:15:55 +00:00
Jason Ertel
f27e5164d0
Update to latest kratos; add support for a custom status trait to represent whether a user is locked or not; refactor so-user to use new enable/disable capabilities in SOC; remove 'delete' option from so-user usage to avoid having user lists out of sync across SOC and external apps
2020-09-04 17:01:52 -04:00
Josh Brower
351e7761ef
Merge pull request #1292 from Security-Onion-Solutions/bugfix/playbook-rulesets
...
Update SOCtopus.conf
2020-09-04 14:15:18 -04:00
Josh Brower
39cc7151a5
Update SOCtopus.conf
2020-09-04 14:14:53 -04:00
Doug Burks
f8e68c82e4
downgrade to Mono 4.2.1.102 and NetworkMiner 2.4
2020-09-04 10:12:28 -04:00
Doug Burks
c050003b5a
Install file-roller for opening zip files
2020-09-04 07:14:01 -04:00
Doug Burks
a2265fac4f
NetworkMiner has a compatibility issue with Mono 6 right now
2020-09-04 06:50:22 -04:00
Doug Burks
1fc64d3eef
so-analyst should install gedit
2020-09-03 16:46:14 -04:00
Josh Patterson
c71a154e81
Merge pull request #1288 from Security-Onion-Solutions/quickfix/standalonetop
...
add elasticsearch to standalone top
2020-09-03 15:55:43 -04:00
m0duspwnens
05b8b71af2
add elasticsearch to standalone top
2020-09-03 15:54:24 -04:00
Mike Reeves
b2ee757db2
Airgap Time
2020-09-03 10:35:12 -04:00
weslambert
b10dd40376
Merge pull request #1287 from Security-Onion-Solutions/fix/suri_home_net
...
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:51 -04:00
weslambert
8db8dcb71a
Change HOME_NET and EXTERNAL_NET defaults
2020-09-03 08:15:14 -04:00
m0duspwnens
770cd6eafc
add endif
2020-09-02 16:19:58 -04:00
Mike Reeves
9745191f19
Add Airgap State
2020-09-02 16:17:44 -04:00
m0duspwnens
a229ae82ce
only allow state to run if it is in top for the node
2020-09-02 16:15:52 -04:00
weslambert
870e042c4c
Merge pull request #1285 from Security-Onion-Solutions/fix/so_stop_start_restart
...
Require at least one arg for start/stop/restart scripts
2020-09-02 14:58:19 -04:00
Wes Lambert
770aaf415c
Require at least on arg for start/stop/restart scripts
2020-09-02 18:55:59 +00:00
Jason Ertel
0142f43493
Add so-user-disable script which deletes the SOC user and disables the users in Fleet, TheHive, and Cortex
2020-09-02 13:54:50 -04:00
m0duspwnens
9d85b3223f
fix note about localrules
2020-09-02 11:46:48 -04:00
Josh Patterson
066c795e71
Merge pull request #1279 from Security-Onion-Solutions/fix/redhat
...
move redhat with centos
2020-09-02 09:12:44 -04:00
m0duspwnens
1f8f197066
move redhat with centos
2020-09-02 09:12:05 -04:00
weslambert
d35cca7fc5
Merge pull request #1278 from Security-Onion-Solutions/fix/elastalert_extra_hosts
...
Add manager to hosts file
2020-09-02 07:44:49 -04:00
weslambert
5d920885e0
Add manager to hosts file
2020-09-02 07:43:55 -04:00
Josh Patterson
7fa083069d
Merge pull request #1277 from Security-Onion-Solutions/issue/968
...
Issue/968
2020-09-01 15:43:22 -04:00
m0duspwnens
08ca2055dc
fix telegraf file input for zeek log
2020-09-01 15:34:06 -04:00
m0duspwnens
93f30a2064
fix telegraf config
2020-09-01 15:29:29 -04:00
m0duspwnens
b13b07eddf
add newline to end
2020-09-01 15:10:56 -04:00
m0duspwnens
01777c64d9
fix influxtime
2020-09-01 14:58:48 -04:00
m0duspwnens
b6d66bddfc
add redis to proper node types. grafana dahsboard changes. change zeek_restart to not use telegraf socket but read from file instead
2020-09-01 14:38:10 -04:00
Josh Brower
6cd0d16b91
Merge pull request #1276 from Security-Onion-Solutions/feature/import-wel
...
Initial support for evtx import
2020-09-01 13:48:12 -04:00
Josh Brower
a79d0319cd
Initial support for evtx import
2020-09-01 13:47:27 -04:00
Mike Reeves
951fe2ac69
Create repo
2020-09-01 11:26:33 -04:00
Mike Reeves
9cff7c1427
Enable airgap functions
2020-09-01 11:24:22 -04:00
Mike Reeves
643dab12d0
Enable airgap
2020-09-01 11:09:33 -04:00
Josh Patterson
67766745a4
Merge pull request #1275 from Security-Onion-Solutions/fix/redhat
...
resolve issue with salt state if os is redhat
2020-09-01 10:44:59 -04:00
m0duspwnens
2fee151bff
resolve issue with salt state if os is redhat
2020-09-01 10:43:21 -04:00
m0duspwnens
ada1c81ab7
manager and standalone dashboard changes
2020-09-01 10:40:20 -04:00
Jason Ertel
ff5d1cd815
Expand nginx body size limit to 2.5GB to handle 2G PCAPs from sensors
2020-09-01 10:07:28 -04:00
Doug Burks
45c0a7ac77
Kernel messages can overwrite whiptail screen #812
...
Kernel messages can overwrite whiptail screen #812
2020-09-01 08:55:34 -04:00
m0duspwnens
a1a7b36319
merge with dev and resolve conflict
2020-08-31 16:05:34 -04:00
m0duspwnens
31f25eca57
fix grafana related issues. add redis to standalone
2020-08-31 15:56:58 -04:00
weslambert
011958a2f3
Merge pull request #1274 from Security-Onion-Solutions/fix/zeek_syslog
...
Ensure Zeek syslog log is enabled for Import node
2020-08-31 13:08:44 -04:00
Wes Lambert
ae3fe9e892
Ensure Zeek syslog log is enabled for Import node
2020-08-31 17:07:16 +00:00
weslambert
96f25914db
Merge pull request #1273 from Security-Onion-Solutions/fix/zeek_syslog_default
...
Fix/zeek syslog default
2020-08-31 12:32:52 -04:00
Wes Lambert
5ed5e6603d
Fix space
2020-08-31 16:32:12 +00:00
Wes Lambert
26ffc44fd1
Only enable syslog log by default in Eval mode
2020-08-31 16:30:32 +00:00
Jason Ertel
dc3b065a41
Set exec bit on new user-add scripts
2020-08-31 10:57:23 -04:00
weslambert
6350c83e05
Merge pull request #1272 from Security-Onion-Solutions/feature/wazuh_mgmt_wrappers
...
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 10:55:25 -04:00
Wes Lambert
46e7e121e3
Add Wazuh mgmt wrappers for manage_agents and upgrade
2020-08-31 14:54:24 +00:00
weslambert
5db70cbd59
Merge pull request #1271 from Security-Onion-Solutions/fix/remove_minio
...
Remove minio for now
2020-08-31 10:29:30 -04:00
Wes Lambert
6d14f2af96
Remove minio for now
2020-08-31 14:07:47 +00:00
weslambert
42bd75a1cc
Merge pull request #1270 from Security-Onion-Solutions/fix/elastalert_startup
...
Wait for Elasticsearch indices to be queryable before starting Elasta…
2020-08-31 09:56:18 -04:00
Wes Lambert
9abbda8e04
Wait for Elasticsearch indices to be queryable before starting Elastalert container
2020-08-31 13:54:49 +00:00
Jason Ertel
189c02648d
Move container status check to so-common
2020-08-31 09:52:06 -04:00
Jason Ertel
8e06f0453e
Only add users to aux systems if those systems are currently running
2020-08-31 09:41:06 -04:00
Doug Burks
9680270b20
Set default monospace font to Liberation
2020-08-30 16:42:44 -04:00
Doug Burks
2f09156a02
quote filename when spawning NetworkMiner
2020-08-30 16:10:47 -04:00
Doug Burks
77b3ebdabe
Hunt Events table should show ssl.server_name when searching for ssl
...
Hunt Events table should show ssl.server_name when searching for ssl #1267
2020-08-30 06:56:15 -04:00
Doug Burks
13ce439678
Update README
2020-08-29 06:52:26 -04:00
Doug Burks
df5ef7c956
Update so-analyst
2020-08-29 06:07:58 -04:00
Doug Burks
1e1212bf41
Update so-analyst
2020-08-29 05:59:21 -04:00
Doug Burks
c20f47ffd6
make chaosreader executable
2020-08-29 04:52:21 -04:00
Doug Burks
c21b347549
Update README
2020-08-29 04:46:00 -04:00
Doug Burks
f6f990ca9f
Update README
2020-08-28 16:44:41 -04:00
Doug Burks
8344e38d91
Add files via upload
2020-08-28 16:43:28 -04:00
Josh Brower
764ba4a0e9
Merge pull request #1266 from Security-Onion-Solutions/bugfix/event.code-parsing
...
Set event.code to string for WEL
2020-08-28 13:49:01 -04:00
Josh Brower
b7dd14b8f0
Set event.code to string for WEL
2020-08-28 13:40:04 -04:00
Jason Ertel
3877706f20
Remove auto-start regardless of how setup was started
2020-08-28 09:10:35 -04:00
Jason Ertel
4e3e83820f
Correct pillar key for thehive
2020-08-28 08:17:42 -04:00
Josh Patterson
f4dc67e32a
Merge pull request #1264 from Security-Onion-Solutions/issue/1063
...
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:25:26 -04:00
m0duspwnens
b1e7ffc173
fix inbound for monitor traffic on standalone graphana dashboard
2020-08-27 18:24:26 -04:00
Jason Ertel
a3e34bfaca
Add users to Fleet, TheHive, and Cortex when adding a user to SO via so-user-add command
2020-08-27 16:58:02 -04:00
Josh Patterson
9d30b58247
Merge pull request #1262 from Security-Onion-Solutions/issue/643
...
remove space
2020-08-27 15:09:05 -04:00
m0duspwnens
aa60ec8e5a
remove space
2020-08-27 15:07:45 -04:00
Josh Patterson
2559f740f1
Merge pull request #1260 from Security-Onion-Solutions/issue/643
...
Issue/643
2020-08-27 14:35:39 -04:00
m0duspwnens
dbb1390c42
move README to /
2020-08-27 14:32:51 -04:00
Mike Reeves
2b0b695ee4
Fix duplicate docker
2020-08-27 10:15:22 -04:00
Mike Reeves
dc6c0cc71c
Merge pull request #1259 from Security-Onion-Solutions/issue/286
...
Issue/286
2020-08-27 10:13:17 -04:00
m0duspwnens
e9b7538ee8
fix a couple things, add another package
2020-08-26 17:58:27 -04:00
m0duspwnens
16c3b9539b
fix a couple things, add another package
2020-08-26 17:51:04 -04:00
m0duspwnens
cc88c4c35f
adding so-analyst script to create analyst workstatin
2020-08-26 17:39:11 -04:00
weslambert
509985ed07
Merge pull request #1254 from Security-Onion-Solutions/fix/sensor_clean
...
Cron updates
2020-08-26 11:03:03 -04:00
weslambert
000c2abb33
Update timing for so-yara-update
2020-08-26 11:02:33 -04:00
Mike Reeves
19130b563d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/286
2020-08-26 11:01:01 -04:00
Mike Reeves
e1a52a4921
Update core counts if heavy node or SA
2020-08-26 11:00:23 -04:00
Mike Reeves
86584d90d7
Merge pull request #1253 from Security-Onion-Solutions/issue/1078
...
Issue/1078 Update Docker
2020-08-26 10:36:34 -04:00
Mike Reeves
e993397173
Update docker to latest version
2020-08-26 10:35:17 -04:00
Josh Brower
c38f4ad4ae
Merge pull request #1251 from Security-Onion-Solutions/feature/fleet3.1
...
Upgraded to Fleet 3.1
2020-08-26 06:14:34 -04:00
Josh Brower
67e0a219e6
Upgraded to Fleet 3.1
2020-08-26 06:13:45 -04:00
Josh Brower
b6ebcf6551
Merge pull request #1250 from Security-Onion-Solutions/feature/es-security-field
...
Adds new .security analyzed subfield
2020-08-26 05:12:23 -04:00
Josh Brower
1cf7301db4
Adds new .security analyzed subfield
2020-08-26 05:11:42 -04:00
Jason Ertel
3122280bd5
Update version to 2.2.0-rc.3
2020-08-25 15:16:09 -04:00
weslambert
ce49e050bc
Update timing for sensor clean cron
2020-08-25 12:14:43 -04:00
weslambert
61cc5b9712
Merge pull request #1246 from Security-Onion-Solutions/fix/sensor_clean_log
...
Fix/sensor clean log
2020-08-25 11:36:10 -04:00
Wes Lambert
c03812f7ab
Add rotation for sensor_clean log
2020-08-25 15:34:30 +00:00
weslambert
a8f727ad40
Don't write to log if not past CRIT_DISK_USAGE
2020-08-25 11:19:36 -04:00
Mike Reeves
6c5f8f7d53
Merge pull request #1240 from Security-Onion-Solutions/issue/1225
...
Remove duplicate IDSTools entries
2020-08-24 10:41:18 -04:00
Mike Reeves
52602f527e
Merge pull request #1238 from Security-Onion-Solutions/issue/796
...
Add /usr/sbin to the path
2020-08-24 10:39:29 -04:00
Mike Reeves
02712e7f46
Add /usr/sbin to the path
2020-08-22 11:07:00 -04:00
Mike Reeves
093819b0c7
Remove duplicate IDSTools entries
2020-08-22 10:32:11 -04:00
William Wernert
6f73d62400
Merge branch 'dev' into feature/nginx-update
2020-07-20 13:13:32 -04:00
William Wernert
a5c790c31e
[fix] managerr -> manager
2020-07-10 17:50:53 -04:00
William Wernert
8b146aac32
Merge branch 'dev' into feature/nginx-update
...
# Conflicts:
# salt/nginx/etc/nginx.conf
# salt/nginx/etc/nginx.conf.so-eval
# salt/nginx/etc/nginx.conf.so-manager
# salt/nginx/etc/nginx.conf.so-managersearch
# salt/nginx/etc/nginx.conf.so-mastersearch
# salt/nginx/etc/nginx.conf.so-standalone
2020-07-10 17:49:34 -04:00
William Wernert
81006ebbd0
[fix] Reflect new manager syntax
2020-07-10 17:46:15 -04:00
William Wernert
49e5cb311e
[fix][WIP] set ssl cert for redirect 443 server block
2020-07-08 16:05:48 -04:00
William Wernert
533ed395e7
[fix][WIP] Remove ssl and http2 from redirect server block
2020-07-08 15:59:31 -04:00
William Wernert
a0ffe26334
[fix] Only one default_server is allowed per port
2020-07-08 15:56:36 -04:00
William Wernert
0c3e35c55e
[fix] correct jinja template syntax
2020-07-08 14:30:27 -04:00
William Wernert
cfd1b82e00
[refactor] Redirect to correct url_base + combine configs
2020-07-08 13:49:33 -04:00