Mike Reeves
d99acdb72c
Merge pull request #3209 from Security-Onion-Solutions/dev
...
2.3.30
2021-03-01 15:09:29 -05:00
Mike Reeves
0d70d2e6f8
Merge pull request #3208 from Security-Onion-Solutions/sigs
...
Update Signatures
2021-03-01 14:48:04 -05:00
Mike Reeves
64b37cedc7
Update Signatures
2021-03-01 14:45:51 -05:00
Mike Reeves
852f588512
Merge pull request #3207 from Security-Onion-Solutions/telegraf_suri_meta
...
Telegraf suri meta
2021-03-01 13:59:36 -05:00
m0duspwnens
a197d5addf
revert version to 2.3.30 https://github.com/Security-Onion-Solutions/securityonion/issues/3206
2021-03-01 13:58:04 -05:00
m0duspwnens
3983e08fe5
exclude zeekcaptureloss when suricata metadata selected https://github.com/Security-Onion-Solutions/securityonion/issues/3206
2021-03-01 13:31:05 -05:00
Mike Reeves
8f8651c52c
Merge pull request #3204 from Security-Onion-Solutions/foxtrot
...
Update VERSION file to 2.3.40
2021-03-01 12:18:50 -05:00
Jason Ertel
85e059a766
Update VERSION file to 2.3.40
2021-03-01 12:16:46 -05:00
Mike Reeves
2df871adcd
Merge pull request #3199 from Security-Onion-Solutions/dev
...
2.3.30 Release
2021-03-01 12:11:19 -05:00
William Wernert
3e1a31c0b0
Merge pull request #3201 from Security-Onion-Solutions/sigs
...
Release 2.3.30 sig
2021-03-01 10:49:55 -05:00
Mike Reeves
4e9bfbefda
Merge pull request #3200 from Security-Onion-Solutions/release-merge-fix
...
Release merge fix
2021-03-01 10:49:41 -05:00
Mike Reeves
1a1e3caec8
Release 2.3.30 sig
2021-03-01 10:48:22 -05:00
William Wernert
be7dcdb442
Merge branch 'master' into release-merge-fix
...
# Conflicts:
# README.md
# VERIFY_ISO.md
# VERSION
# salt/docker_clean/init.sls
# salt/soc/files/soc/changes.json
2021-03-01 10:45:51 -05:00
Mike Reeves
8a9c7fa279
Merge pull request #3198 from Security-Onion-Solutions/sigs
...
Add Signature Files
2021-03-01 10:42:15 -05:00
Mike Reeves
bfa7c85e27
Release 2.3.30
2021-03-01 10:40:41 -05:00
Mike Reeves
ed2c836250
Merge pull request #3196 from Security-Onion-Solutions/foxtrot
...
Update changes for 2.3.30
2021-03-01 10:00:12 -05:00
Jason Ertel
1ae46b82ec
Update changes for 2.3.30
2021-03-01 09:58:39 -05:00
Mike Reeves
6e8777b9d6
Merge pull request #3193 from Security-Onion-Solutions/bugfix/revert-default-route-msg
...
Revert "[refactor] Make default route message a warning"
2021-03-01 09:49:58 -05:00
William Wernert
def3637bf6
Revert "[refactor] Make default route message a warning"
...
This reverts commit be1f641bf0 .
2021-03-01 09:46:28 -05:00
Mike Reeves
64cc894948
Merge pull request #3192 from Security-Onion-Solutions/bugfix/input-validation-fixes
...
Bugfix/input validation fixes
2021-03-01 09:27:48 -05:00
Mike Reeves
55b6efba7b
Merge pull request #3189 from Security-Onion-Solutions/bugfix/mtu-input
...
Add max to MTU input validation to encompass default + jumbo frames
2021-03-01 09:26:54 -05:00
William Wernert
cf9be3521d
[fix] Don't validate LS/ES heap sizes
...
* Also remove comments + fix indent
2021-03-01 09:17:36 -05:00
William Wernert
6113bcc261
[fix] Increase max integer value
2021-03-01 09:16:51 -05:00
William Wernert
810ffbdaf5
Add max to MTU input validation to encompass default + jumbo frames
2021-03-01 08:41:19 -05:00
Mike Reeves
c1a8e1971b
Merge pull request #3174 from Security-Onion-Solutions/foxtrot
2021-02-27 09:49:46 -05:00
Jason Ertel
7451aa990b
Improve formatting of changes list
2021-02-27 08:14:44 -05:00
Jason Ertel
839ab30b2c
Merge pull request #3171 from Security-Onion-Solutions/foxtrot
...
Add changes.json for 2.3.30
2021-02-26 18:16:20 -05:00
Jason Ertel
9631327c71
Add changes.json for 2.3.30
2021-02-26 18:11:13 -05:00
Josh Patterson
b6fe8dec3b
Merge pull request #3170 from Security-Onion-Solutions/bugfix/setup-configure-network
...
Fix logic for configure network option in setup
2021-02-26 15:43:38 -05:00
William Wernert
fd877a2256
Fix logic for configure network option in setup
2021-02-26 15:40:20 -05:00
Mike Reeves
26a22b8e3b
Merge pull request #3169 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-02-26 14:37:09 -05:00
Jason Ertel
cc15e9a0b1
Merge branch 'dev' into foxtrot
2021-02-26 14:26:48 -05:00
Jason Ertel
4a03862fc4
Add suricata distributed automations
2021-02-26 14:26:28 -05:00
William Wernert
069f6eccbf
Merge pull request #3157 from Security-Onion-Solutions/feature/default-route-warn
...
[refactor] Make default route message a warning
2021-02-26 10:29:43 -05:00
William Wernert
be1f641bf0
[refactor] Make default route message a warning
...
Don't force users to exit setup if the default route and management NIC's IP don't match,
just warn them
2021-02-26 10:27:14 -05:00
William Wernert
8910b5c3a7
Merge pull request #3155 from Security-Onion-Solutions/bugfix/fleet-hostname-input
...
[fix] Change logic for collecting fleet custom hostname
2021-02-26 09:16:22 -05:00
William Wernert
333a7e6173
[fix] Change logic for collecting fleet custom hostname
2021-02-26 09:14:30 -05:00
Josh Patterson
b893a2b887
Merge pull request #3154 from Security-Onion-Solutions/salt-3002.5
...
upgrade to Salt 3002.5
2021-02-26 08:57:23 -05:00
m0duspwnens
b4c1c56e72
Merge remote-tracking branch 'remotes/origin/dev' into salt-3002.5
2021-02-26 08:38:02 -05:00
Josh Brower
45f626887d
Merge pull request #3153 from Security-Onion-Solutions/bugfix/so-playbook-sigmarefresh
...
Fix so-playbook-sigma-refresh
2021-02-26 08:36:36 -05:00
Josh Brower
5678e66b39
Fix so-playbook-sigma-refresh
2021-02-26 08:33:24 -05:00
m0duspwnens
9fa625189f
upgrade to salt 3002.5 https://github.com/Security-Onion-Solutions/securityonion/issues/3147
2021-02-25 20:07:29 -05:00
Mike Reeves
e06ca75677
Merge pull request #3144 from Security-Onion-Solutions/interfaces
...
Don't disable NICs
2021-02-25 17:28:47 -05:00
Mike Reeves
a47a3d51c9
Merge pull request #3139 from Security-Onion-Solutions/feature/soup-log_size_limit
...
Show log_size_limit message at end of soup instead of during
2021-02-25 17:10:38 -05:00
William Wernert
b024dae72e
[fix] Don't call set_main_ip a second time
2021-02-25 15:19:28 -05:00
Josh Patterson
8a0e0e88e0
Merge pull request #3142 from Security-Onion-Solutions/issue/3130
...
stop zeek state.db from getting owned by root
2021-02-25 15:01:20 -05:00
Mike Reeves
2c8bc16c8f
Remove some nmcli business
2021-02-25 13:43:02 -05:00
Mike Reeves
37c13362df
Netowrk Manager needs to chill
2021-02-25 13:20:29 -05:00
Mike Reeves
51e8839daf
Inverse NIC offload
2021-02-25 11:46:00 -05:00
m0duspwnens
fcd3f81400
fix quotes
2021-02-25 11:16:53 -05:00
m0duspwnens
c8213fa3d4
change docker exec
2021-02-25 11:07:54 -05:00
m0duspwnens
add66e750e
forgot to add -c
2021-02-25 10:49:09 -05:00
William Wernert
6a097beaff
Show log_size_limit message at end of soup instead of during
2021-02-25 10:47:29 -05:00
Doug Burks
79fefd83ef
Merge pull request #3134 from Security-Onion-Solutions/issue/3128
...
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 07:11:20 -08:00
m0duspwnens
d52abcbcbd
ensure zeekctl is run as user zeek https://github.com/Security-Onion-Solutions/securityonion/issues/3130
2021-02-25 09:58:07 -05:00
Doug Burks
c18c865764
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 09:23:19 -05:00
Doug Burks
ef1e296415
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 08:52:34 -05:00
Mike Reeves
ae89260793
Merge pull request #3127 from Security-Onion-Solutions/foxtrot
...
Add automation files for Suricata metadata
2021-02-25 08:26:20 -05:00
Jason Ertel
34dab9009c
Ensure Zeek spool dir is owned by Zeek to allow Zeek to start correctly
2021-02-25 08:10:13 -05:00
Jason Ertel
ef7cdf27bf
Add automation files for Suricata metadata
2021-02-25 07:43:11 -05:00
Mike Reeves
c39b516f38
Merge pull request #3121 from Security-Onion-Solutions/strelkainstall
...
Fix Strelka Rule updates, repo fix
2021-02-24 17:13:41 -05:00
Mike Reeves
39860ea6bd
Merge pull request #3123 from Security-Onion-Solutions/kilo
...
Add function to soup to notify user of log_size_limit issues
2021-02-24 17:09:07 -05:00
Mike Reeves
701cfe7e9a
Merge branch 'dev' into strelkainstall
2021-02-24 17:07:26 -05:00
William Wernert
4ae34f928c
Merge branch 'dev' into kilo
...
# Conflicts:
# setup/so-functions
2021-02-24 17:05:53 -05:00
Mike Reeves
ff577cdf41
Merge pull request #3079 from petiepooo/feature/eslogsize
...
calculate log_size_limit based on /nsm/elasticsearch
2021-02-24 17:03:35 -05:00
William Wernert
4a6ad7c87e
Set MAINIP to MNIC_IP when using a VPN
2021-02-24 16:31:45 -05:00
Mike Reeves
b30f964974
Moving the wildcard
2021-02-24 16:09:37 -05:00
Mike Reeves
262bf03595
Testing capitals
2021-02-24 16:04:53 -05:00
Mike Reeves
ae17a3aeb8
Fix Syntax try 3
2021-02-24 16:02:36 -05:00
Mike Reeves
ab66f175c5
Fix Syntax
2021-02-24 16:01:18 -05:00
Mike Reeves
8f3ba7633c
Fix Syntax
2021-02-24 15:57:18 -05:00
Mike Reeves
5949119cb5
Bypass route check
2021-02-24 15:53:55 -05:00
Mike Reeves
6058400aad
Bypass route check
2021-02-24 15:52:50 -05:00
William Wernert
f042312aac
Merge branch 'dev' into kilo
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-02-24 15:42:10 -05:00
Mike Reeves
52fd3c0470
Merge pull request #3122 from Security-Onion-Solutions/strelka_repo_update
...
Modify soup to add Strelka rule repo in pillar
2021-02-24 15:35:35 -05:00
Wes Lambert
6ea8eab9af
Modify soup to add Strelka rule repo in pillar
2021-02-24 20:32:47 +00:00
William Wernert
775f274962
Also check /nsm/elasticsearch in soup log_size_limit check
...
Reflect changes from PR#3079
2021-02-24 14:36:41 -05:00
William Wernert
e500e24802
Only show log_size_limit warning on dist if heavynode pillars exist
2021-02-24 13:56:59 -05:00
William Wernert
298f7da90b
Fix indent in set_default_log_size
2021-02-24 13:56:33 -05:00
Mike Reeves
38d60752b7
Merge pull request #3110 from Security-Onion-Solutions/dockerclean
...
Docker Cleanup
2021-02-24 13:44:06 -05:00
Josh Patterson
25ca70efd8
Merge pull request #3120 from Security-Onion-Solutions/issue/3115
...
ensure log_level and log_level_logfile are set to info in /etc/salt/minion
2021-02-24 13:36:34 -05:00
Mike Reeves
bdfec5176d
Dont disable unused interfaces during setup
2021-02-24 13:22:06 -05:00
William Wernert
ece79379a5
Add file name/path to log_size_limit message
2021-02-24 12:54:14 -05:00
William Wernert
ac6f1df86f
[fix] Only check log_size_limit on .2X -> .30
...
* Since we're showing a message in the middle of soup, wait for keypress if it's shown
2021-02-24 12:35:17 -05:00
William Wernert
4507a89d95
tar arg fix (-x -> -z)
2021-02-24 12:24:54 -05:00
William Wernert
2be7ccac33
Add function to notify user that log_size_limit may be incorrect
2021-02-24 12:24:32 -05:00
m0duspwnens
eba5d271aa
logfile is 1 word https://github.com/Security-Onion-Solutions/securityonion/issues/3115
2021-02-24 11:56:43 -05:00
m0duspwnens
3552abfca1
ensure info log level -
2021-02-24 11:50:08 -05:00
Mike Reeves
1d45472b48
Fix Strelka Rule updates, repo fix
2021-02-24 11:30:43 -05:00
Mike Reeves
68c683e3bf
Merge pull request #3114 from Security-Onion-Solutions/foxtrot
...
Add retry support for 'docker pull' command
2021-02-24 11:25:14 -05:00
Jason Ertel
050058a959
Add retry support for 'docker pull' command
2021-02-24 09:34:14 -05:00
Mike Reeves
09c94ddf95
Docker Cleanup
2021-02-24 08:57:25 -05:00
Mike Reeves
54367db99b
Merge pull request #3108 from Security-Onion-Solutions/issue/3056
...
add estimated EPS graphs to Grafana for manager, mastersearch and standalone nodes
2021-02-24 08:49:36 -05:00
Mike Reeves
56daae64be
Merge pull request #3097 from Security-Onion-Solutions/sometacleanup
...
Clean up on sid numbers
2021-02-24 08:24:48 -05:00
Mike Reeves
00deab9305
Merge pull request #3100 from Security-Onion-Solutions/kilo
...
Add so-preflight + usage to so-monitor-add, fix managersearch missing from so-rule
2021-02-23 17:32:41 -05:00
Mike Reeves
fa6fd20ff9
Merge pull request #3088 from Security-Onion-Solutions/soupairgap
...
Syn the latest rules on an airgap install
2021-02-23 17:31:29 -05:00
Mike Reeves
d195efa8e5
Merge pull request #3098 from Security-Onion-Solutions/feature/update-soup
...
Update SOUP with so-playbook-sigma-refresh
2021-02-23 15:46:48 -05:00
Josh Brower
a7eb3cd38d
Add so-playbook-sigma-refresh
2021-02-23 15:43:09 -05:00
Mike Reeves
5baa4cb6a5
Clean up on sid numbers
2021-02-23 15:42:58 -05:00
William Wernert
a361ca0e19
[fix] Add managersearch node type to so-rule pillar search
2021-02-23 14:15:17 -05:00
William Wernert
9cf15cdae5
[fix] Reword so-monitor-add help message
2021-02-23 13:55:18 -05:00
William Wernert
d5477b4721
Add usage/help message to so-monitor-add
2021-02-23 13:48:54 -05:00
William Wernert
5a2fa26d72
Add ET OPEN/PRO URLs
2021-02-23 13:47:52 -05:00
William Wernert
61a23509a1
[fix] grep -q doesn't give output to parse, so remove the flag
2021-02-23 13:43:10 -05:00
William Wernert
25698dafe3
Add initial pre-flight check script
2021-02-23 13:25:54 -05:00
Mike Reeves
186710964b
Fix Airgap Rule Path
2021-02-23 13:07:23 -05:00
Mike Reeves
3b32eb539f
Copy latest rules when using airgaps
2021-02-23 11:21:23 -05:00
m0duspwnens
6ee69ff21b
Merge remote-tracking branch 'remotes/origin/dev' into issue/3056
2021-02-23 11:11:50 -05:00
m0duspwnens
00cc640224
add EPS to managersearch dashboard
2021-02-23 11:08:08 -05:00
Mike Reeves
40721d7dec
Merge pull request #3084 from Security-Onion-Solutions/feature/log-rotate
...
Configure fleet result.log to rotate
2021-02-23 10:20:53 -05:00
m0duspwnens
e76ee07932
add CPUS for cpu count
2021-02-23 10:10:58 -05:00
Josh Brower
122e34b69c
Configure fleet result.log to rotate
2021-02-23 10:06:24 -05:00
m0duspwnens
1f2475c1c5
add eps graph to manager
2021-02-23 10:06:11 -05:00
m0duspwnens
141fbaced1
add eps graph to standalone
2021-02-23 09:40:21 -05:00
William Wernert
fa9fe82046
Merge pull request #3082 from Security-Onion-Solutions/kilo
...
Add so-rule script + soup pillar changes
2021-02-23 08:56:49 -05:00
William Wernert
fad87a8789
Fix function name (.20 -> .2X)
2021-02-23 08:51:44 -05:00
William Wernert
9287209750
Merge branch 'soup2.3.30' into feature/so-rules
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-02-22 16:07:15 -05:00
William Wernert
982967fdde
Merge branch 'dev' into feature/so-rules
2021-02-22 16:01:48 -05:00
William Wernert
fb3af255d9
Add more info to apply messaging
2021-02-22 15:50:07 -05:00
William Wernert
3e3c923ab9
Arrange missing pillar error message better
2021-02-22 15:44:29 -05:00
William Wernert
b00cc88801
[fix] Unreverse apply prompt actions
2021-02-22 15:43:56 -05:00
William Wernert
e9b85337ff
[fix] Only prompt if entry doesn't exist, deep compare arrays
2021-02-22 15:41:09 -05:00
William Wernert
fd33a6cebe
Rename script, prompt user to apply if they didn't pass --apply
2021-02-22 15:32:18 -05:00
William Wernert
cdf766eeae
explicitely -> explicitly
2021-02-22 14:30:26 -05:00
William Wernert
8fc82fa3ef
Fix minion pillar directory
2021-02-22 14:27:22 -05:00
Mike Reeves
6ed1cc3875
Add Soup Functions
2021-02-22 14:02:37 -05:00
Doug Burks
84f138772f
Merge pull request #3072 from Security-Onion-Solutions/kilo
...
Additional fine tuning of Suricata metadata support
2021-02-22 10:57:02 -08:00
doug
71c7ffae3e
Improve support for Suricata metadata #2200
2021-02-22 13:49:29 -05:00
doug
bcce205430
Improve support for Suricata metadata #2200
2021-02-22 13:00:14 -05:00
Jason Ertel
943cbdbf1f
Merge pull request #3073 from Security-Onion-Solutions/delta
...
Apply action on PR only now that PRs are mandatory
2021-02-22 12:50:38 -05:00
Jason Ertel
43e0c3a60b
Apply action on PR only now that PRs are mandatory
2021-02-22 12:35:17 -05:00
Mike Reeves
d5069d12cf
Merge pull request #3071 from Security-Onion-Solutions/delta
...
Add acng to import installs for consistency
2021-02-22 11:34:23 -05:00
William Wernert
e65c9e5c7c
Don't expect apply arg at beginning of command
2021-02-22 11:29:30 -05:00
William Wernert
4bcb7403a9
Add apply option to end of command
2021-02-22 11:27:03 -05:00
William Wernert
bef3a6921c
[fix] SID wildcards are not parsed by idstools, remove
2021-02-22 11:12:02 -05:00
William Wernert
f7bef9200b
[fix] Only look for manager-type pillars
...
* SID disabling is only managed globally for now, so don't give the option to edit a different pillar
2021-02-22 10:38:53 -05:00
William Wernert
bb6f3107bc
[fix] idstools can run on an import node as well
2021-02-22 10:29:40 -05:00
doug
3467f30603
Improve support for Suricata metadata #2200
2021-02-22 10:27:24 -05:00
Doug Burks
d4ee2b86e6
Merge pull request #3070 from Security-Onion-Solutions/dev
...
Dev to Kilo
2021-02-22 07:22:49 -08:00
William Wernert
f2a1e89633
Merge branch 'dev' into feature/so-rules
2021-02-22 10:03:14 -05:00
William Wernert
abae673568
Update help text to reflect arg requirement changes
2021-02-22 10:00:29 -05:00
Jason Ertel
747d62dae5
Add acng to import installs for consistency
2021-02-22 09:44:24 -05:00
Josh Brower
5ca3dc492c
Merge pull request #3061 from Security-Onion-Solutions/foxtrot
...
Fix Playbook Fields & Mappings
2021-02-21 09:40:59 -05:00
Doug Burks
85b9cac110
Merge pull request #3063 from Security-Onion-Solutions/dev
...
Dev to kilo
2021-02-21 03:40:05 -08:00
Mike Reeves
40780f192e
Merge pull request #3062 from Security-Onion-Solutions/delta
...
fix merge issue
2021-02-20 19:15:16 -05:00
Jason Ertel
7222f1faa5
fix merge issue
2021-02-20 16:41:12 -05:00
Mike Reeves
e07e0b201d
Merge pull request #3058 from Security-Onion-Solutions/delta
...
Fix intermittent Suricata rules load issue
2021-02-20 10:27:13 -05:00
Jason Ertel
9d3c82a589
Disable unused features for import installations
2021-02-19 20:14:55 -05:00
Jason Ertel
04b3a20e22
Merge branch 'dev' into delta
2021-02-19 20:12:07 -05:00
Mike Reeves
cb6fe75ddb
Merge pull request #3055 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Rename filter.rules to filters.rules
2021-02-19 15:36:01 -05:00
Mike Reeves
8ab12c71a1
Rename filter.rules to filters.rules
2021-02-19 15:34:45 -05:00
Josh Brower
046cc0fbb0
Merge pull request #3052 from Security-Onion-Solutions/feature/sigma-tweaks
...
Feature/sigma tweaks
2021-02-19 15:16:34 -05:00
Josh Brower
8c69e19419
Add sigma refresh script
2021-02-19 15:14:37 -05:00
Josh Brower
2a324eac32
Add sigma refresh script
2021-02-19 15:12:55 -05:00
Mike Reeves
8db3602679
Merge pull request #3049 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix name and update examples
2021-02-19 15:01:04 -05:00
Mike Reeves
08abad747d
Fix name and update examples
2021-02-19 14:59:27 -05:00
William Wernert
c73970620d
[fix] Correct indent
2021-02-19 14:38:43 -05:00
William Wernert
34174a3290
Print relevant help if no/partial command passed
2021-02-19 14:34:32 -05:00
Mike Reeves
0ea29144a8
Merge pull request #3047 from Security-Onion-Solutions/surifile2
...
Suricata as Meta Data, File Extraction, And Parsing changes
2021-02-19 14:09:38 -05:00
Doug Burks
3ea1ec99d5
Merge pull request #3048 from Security-Onion-Solutions/kilo
...
Update syslog ingest parser to accomodate pfSense filterlog changes #3033
2021-02-19 11:02:56 -08:00
Jason Ertel
9302b9302b
Clear salt fileserver cache to ensure the new local.rules file gets picked up on the filesync
2021-02-19 11:13:31 -05:00
Mike Reeves
b4b449aa14
Pull in Suricata changes
2021-02-19 11:01:15 -05:00
William Wernert
4689e32ce4
Add sed for curly braces in minion pillars to soup
2021-02-19 10:18:06 -05:00
William Wernert
2184c6d59f
[fix] Create dict value if it doesn't exist
2021-02-19 09:31:22 -05:00
William Wernert
9183c0a92c
[feat] Initial so-rules script
...
* Quote curly braces in minion pillar, need to add sed function in soup
2021-02-19 09:24:12 -05:00
doug
88eb5b1d61
Update syslog ingest parser to accomodate pfSense filterlog changes #3033
2021-02-19 08:02:32 -05:00
Doug Burks
5493b3ef91
Merge pull request #3032 from Security-Onion-Solutions/dev
...
Update kilo to latest dev
2021-02-19 04:53:23 -08:00
Josh Patterson
4a510df205
Merge pull request #3026 from Security-Onion-Solutions/delta
...
Delta
2021-02-18 16:31:18 -05:00
Jason Ertel
faa78c0e26
Salt doesn't like a name starting with a non alpha-numeric char. Switch back to long if/then format
2021-02-18 14:51:09 -05:00
Josh Patterson
79e7b1da4d
Merge pull request #3021 from Security-Onion-Solutions/issue/2989
...
change suricata clean cron to run once a day
2021-02-18 14:07:40 -05:00
m0duspwnens
03487c2a31
change suricata clean cron to run once a day
2021-02-18 14:06:45 -05:00
Jason Ertel
e912b2fd96
Move idstools to run after nginx runs
2021-02-18 12:50:00 -05:00
Josh Patterson
0ab9577863
Merge pull request #3018 from Security-Onion-Solutions/all_rules_dont_show_changes
...
dont show changes since file can be large
2021-02-18 12:23:54 -05:00
m0duspwnens
bf100a2310
dont show changes since file can be large
2021-02-18 12:23:22 -05:00
Josh Patterson
2092044335
Merge pull request #3017 from Security-Onion-Solutions/issue/1237
...
load templates all the time
2021-02-18 12:13:49 -05:00
m0duspwnens
e730efb4ec
load templates all the time
2021-02-18 12:12:18 -05:00
Josh Patterson
76cdc45fad
Merge pull request #3016 from Security-Onion-Solutions/all_rules_dont_show_changes
...
Don't show changes because all.rules can be large
2021-02-18 12:00:08 -05:00
m0duspwnens
069997a65c
Don't show changes because all.rules can be large
2021-02-18 11:56:25 -05:00
Jason Ertel
6f7bc650a0
Apply reserved ports if the existing file is 0 bytes
2021-02-18 11:20:13 -05:00
Josh Patterson
a9da761fab
Merge pull request #3012 from Security-Onion-Solutions/issue/2989
...
Issue/2989
2021-02-18 10:52:23 -05:00
m0duspwnens
95df18c545
limit eve logs and gz files based on days
2021-02-18 10:45:20 -05:00
m0duspwnens
a4d5f58256
fix surilogcompress
2021-02-18 10:33:47 -05:00
Josh Patterson
3f7cdb933f
Merge pull request #3010 from Security-Onion-Solutions/issue/2989
...
Issue/2989
2021-02-18 09:58:35 -05:00
m0duspwnens
74ca4487de
ensure at least 2 eve files are kept https://github.com/Security-Onion-Solutions/securityonion/issues/2989
2021-02-18 09:51:40 -05:00
m0duspwnens
4b07d5e457
add identifier to eve clean cron
2021-02-18 09:39:54 -05:00
m0duspwnens
041d193f2d
fix brackets
2021-02-18 09:37:37 -05:00
m0duspwnens
0bef8b6662
limit number of eve.json files for suricata https://github.com/Security-Onion-Solutions/securityonion/issues/2989
2021-02-18 09:26:59 -05:00
Josh Brower
b5087b815a
Merge pull request #3002 from Security-Onion-Solutions/feature/sigma-tweaks
...
Update .security analyzer
2021-02-17 16:38:22 -05:00
Josh Brower
d2a74c80e2
Update .security analyzer
2021-02-17 16:37:31 -05:00
Josh Brower
741f674a4c
Merge pull request #3001 from Security-Onion-Solutions/dev
...
Dev
2021-02-17 16:36:49 -05:00
Pete
29c5f3212f
make log_size_limit calculation more specific
...
Extend the directory traversal into /nsm/elasticsearch in case that's a separate mountpoint from /nsm/.
2021-02-17 16:53:31 +00:00
Josh Patterson
174ed84750
Merge pull request #2993 from Security-Onion-Solutions/issue/2736
...
logrotate strelka
2021-02-17 11:47:52 -05:00
m0duspwnens
7a595df5b6
strelka logrotate - https://github.com/Security-Onion-Solutions/securityonion/issues/2736
2021-02-17 11:17:41 -05:00
m0duspwnens
2b07d89b5a
error: /opt/so/conf/sensor-rotate.conf:8 unknown option 'endscript' -- ignoring line
2021-02-17 11:01:18 -05:00
m0duspwnens
e6ae1af85f
test rotating strelka log at 100k
2021-02-17 10:47:06 -05:00
Josh Patterson
ce313d8dc4
Merge pull request #2992 from Security-Onion-Solutions/issue/2737
...
fix logic for log_size_limit
2021-02-17 10:09:54 -05:00
Josh Patterson
fddef1a6f4
Merge pull request #2985 from Security-Onion-Solutions/issue/2915
...
remove old backup files
2021-02-17 09:43:58 -05:00
William Wernert
cda36f178b
Merge pull request #2979 from Security-Onion-Solutions/foxtrot
...
Setup fixes/improvements
2021-02-16 17:14:59 -05:00
Josh Patterson
bec437c2cf
Merge pull request #2984 from Security-Onion-Solutions/issue/2737
...
Issue/2737
2021-02-16 15:41:46 -05:00
m0duspwnens
996bf0768b
fix logic for log_size_limit https://github.com/Security-Onion-Solutions/securityonion/issues/2737
2021-02-16 15:40:01 -05:00
William Wernert
0bd5ddf6a6
Grammar + misc fixes per PR review
...
* Remove unnecessary `apt-get update` commands
* Change `if ! (command); then exit 1; fi` to `command || exit 1` to avoid subshell
2021-02-16 14:17:41 -05:00
Doug Burks
8016511414
Merge pull request #2981 from Security-Onion-Solutions/kilo
...
Hunt: improve Wazuh queries #2383
2021-02-16 10:38:53 -08:00
Josh Patterson
eb18ec552c
Merge pull request #2980 from Security-Onion-Solutions/issue/2915
...
Issue/2915
2021-02-16 12:01:37 -05:00
doug
fabe3c87f2
Hunt: improve Wazuh queries #2383
2021-02-16 11:56:14 -05:00
m0duspwnens
7099ed4bf5
delete many backup files
2021-02-16 11:55:49 -05:00
m0duspwnens
1ccc5480e1
remove oldest backup
2021-02-16 11:40:45 -05:00
Doug Burks
d6fa54b606
Merge pull request #2975 from Security-Onion-Solutions/kilo
...
Issues 2954 and 2361 - Kibana config
2021-02-16 08:30:46 -08:00
William Wernert
3323e900ef
[fix] Fix indent (pt 2)
2021-02-16 11:17:36 -05:00
William Wernert
7a9f801eb1
[fix] Add more apt-get update commands
...
Fixes #2962
2021-02-16 10:24:58 -05:00
William Wernert
38a5b86813
Make apt-get syntax consistent
2021-02-16 10:24:07 -05:00
William Wernert
23221065eb
Preset MANAGERUPDATES var for airgap since we don't prompt now
2021-02-16 09:43:54 -05:00
William Wernert
5e8d09be51
[fix] Fix indent
2021-02-16 09:42:35 -05:00
doug
397d8d0964
Kibana 7.10.2 config changes #2954
2021-02-14 07:04:51 -05:00
doug
3248edea8b
Update Kibana dashboard hyperlinks to new url format #2361
2021-02-12 17:25:42 -05:00
Josh Patterson
bf3b609a44
Merge pull request #2955 from Security-Onion-Solutions/issue/1237
...
Issue/1237
2021-02-12 16:04:58 -05:00
m0duspwnens
100601c452
only laod templates if they change https://github.com/Security-Onion-Solutions/securityonion/issues/1237
2021-02-12 16:03:45 -05:00
doug
31a0c2bc82
Update Kibana dashboard hyperlinks to new url format #2361
2021-02-12 15:37:25 -05:00
doug
797d2c4dba
Kibana 7.10.2 config changes #2954
2021-02-12 15:35:06 -05:00
Doug Burks
fd4cb0b7a8
Kibana 7.10.2 config changes #2954
2021-02-12 14:05:29 -05:00
Doug Burks
c717773fc3
Kibana 7.10.2 config changes #2954
2021-02-12 14:04:00 -05:00
Josh Patterson
ce04b109fe
Merge pull request #2950 from Security-Onion-Solutions/delta
...
Disable ICMP timestamps by default
2021-02-12 13:54:59 -05:00
William Wernert
4affb20b27
Give context to metadata tool choice
2021-02-12 13:42:14 -05:00
William Wernert
724f5cad78
Warn user if using "securityonion" as hostname
2021-02-12 12:55:55 -05:00
William Wernert
8323f3f57a
[fix] Fix logic to correctly hide prompt
2021-02-12 12:23:45 -05:00
Josh Patterson
a8598a50e4
Merge pull request #2953 from Security-Onion-Solutions/issue/2756
...
remove /etc/yum.repos.d/salt-2019-2-5.repo if present
2021-02-12 12:05:21 -05:00
m0duspwnens
3b0c2b3e91
remove /etc/yum.repos.d/salt-2019-2-5.repo if present https://github.com/Security-Onion-Solutions/securityonion/issues/2756
2021-02-12 12:04:08 -05:00
William Wernert
1ffa7afefa
eval-net answerfile corrections
...
* HOSTNAME: standalone -> eval
* install_type: STANDALONE -> EVAL
2021-02-11 16:20:29 -05:00
William Wernert
188d844d27
Redirect stderr of minion grep to /dev/null
2021-02-11 13:49:39 -05:00
m0duspwnens
b4e9a44572
Merge remote-tracking branch 'remotes/origin/dev' into issue/1704
2021-02-11 11:10:06 -05:00
m0duspwnens
7e4d7a6985
drop icmp timestamp replies https://github.com/Security-Onion-Solutions/securityonion/issues/1704
2021-02-11 11:09:21 -05:00
William Wernert
d9b4c09cf0
[fix] Don't show irrelevant prompts during airgap setup
2021-02-11 10:52:18 -05:00
William Wernert
ce8db8abdb
[fix] Only run salt commands during reinstall if master is configured
2021-02-11 10:51:04 -05:00
Josh Patterson
bf8ca590d0
Merge pull request #2932 from Security-Onion-Solutions/delta
...
only save at the end
2021-02-11 09:25:31 -05:00
Mike Reeves
97594f84cb
Merge pull request #2930 from Security-Onion-Solutions/vpn
...
VPN Configuration
2021-02-11 09:21:17 -05:00
Mike Reeves
f8903c2554
Fix extra character
2021-02-10 12:58:02 -05:00
Mike Reeves
9eb1e6a448
Prevent the tun interface from being disabled
2021-02-10 12:51:26 -05:00
m0duspwnens
3cfbc61f4e
only save at the end
2021-02-10 11:15:39 -05:00
Mike Reeves
10553938b5
Merge pull request #2901 from Security-Onion-Solutions/curatorwarm
...
add warm node action for hot/warm
2021-02-08 12:08:23 -05:00
Mike Reeves
125f7d6262
add warm node action for hot/warm
2021-02-08 11:49:49 -05:00
Mike Reeves
940bac3634
Merge pull request #2889 from Security-Onion-Solutions/backupsfix
...
Backupsfix
2021-02-08 10:40:20 -05:00
Mike Reeves
5043b970ef
Fix tar syntax
2021-02-06 19:14:44 -05:00
Mike Reeves
a3ca84db66
Fix backupdir name state
2021-02-06 15:32:42 -05:00
Mike Reeves
bf79c92456
Lock down Backups folder permissions
2021-02-05 22:31:08 -05:00
Mike Reeves
8f97973fac
Lock down Backups folder permissions
2021-02-05 22:17:31 -05:00
Jason Ertel
4d6d2edd17
Merge pull request #2872 from Security-Onion-Solutions/automation/ami
...
Add locking to so-firewall
2021-02-04 16:14:16 -05:00
Jason Ertel
e427f8178d
Implement locking to so-firewall script
2021-02-04 16:06:11 -05:00
Jason Ertel
a13b31fbcc
Merge branch 'dev' into automation/ami
2021-02-04 16:05:39 -05:00
Mike Reeves
d4e5ab477f
Merge pull request #2854 from Security-Onion-Solutions/revert-2830-filebeatlimits
...
Revert "Make filebeat retry forever"
2021-02-03 22:26:03 -05:00
Jason Ertel
58e4205602
Revert "Make filebeat retry forever"
2021-02-03 21:46:29 -05:00
Jason Ertel
6b54a29ac7
Remove 'new user' references from so-user
2021-02-03 15:23:58 -05:00
Jason Ertel
3ebedcd4e8
Merge pull request #2830 from Security-Onion-Solutions/filebeatlimits
...
Make filebeat retry forever
2021-02-03 11:32:05 -05:00
Mike Reeves
179efa3a51
Merge pull request #2833 from Security-Onion-Solutions/automation/ami
...
Adjust AMI test network
2021-02-02 21:05:34 -05:00
Jason Ertel
91480abaa0
Adjust AMI test network
2021-02-02 17:41:41 -05:00
Mike Reeves
55a8f6aa7a
Make filebeat retry forever
2021-02-02 16:41:52 -05:00
William Wernert
8f0b0ac936
Merge pull request #2825 from Security-Onion-Solutions/foxtrot
...
Setup: dpkg retry, whiptail changes, fix zeek state condition
2021-02-02 14:41:48 -05:00
Josh Patterson
ef2fe2bb61
Merge pull request #2828 from Security-Onion-Solutions/delta
...
adjust timeout for ssl states and pillarize ElastAlert
2021-02-02 13:35:28 -05:00
William Wernert
46581c0528
[fix] Don't use ZEEKVERSION var, check pillar value
2021-02-02 12:45:56 -05:00
William Wernert
2253603544
[fix] Don't try to inherit home net on standalone
2021-02-02 12:11:47 -05:00
Jason Ertel
e7e1f4c155
Merge pull request #2820 from Security-Onion-Solutions/automation/ami
...
Adjust automation files for distributed AMI
2021-02-01 15:33:53 -05:00
m0duspwnens
b3c08229db
Merge remote-tracking branch 'remotes/origin/sslstate/timeouts_retry' into delta
2021-02-01 15:33:31 -05:00
Jason Ertel
f736d9f8dd
Adjust automation files for distributed AMI
2021-02-01 15:27:53 -05:00
m0duspwnens
8cf0a3da98
remove seconds
2021-02-01 15:19:47 -05:00
William Wernert
8d01b87ab5
Merge branch 'dev' into foxtrot
2021-02-01 13:56:33 -05:00
William Wernert
8f476bbbdd
[fix] Add back removed if statement
2021-02-01 13:11:51 -05:00
m0duspwnens
8ff6d1639a
Merge remote-tracking branch 'remotes/origin/dev' into issue/1191
2021-02-01 12:51:00 -05:00
William Wernert
daebe90b6e
[fix] fix retry command handling
...
* use eval "$cmd" to handle strings correctly
* add-apt-repo doesn't need dpkg lock so don't use retry for those lines
2021-02-01 12:06:19 -05:00
William Wernert
44617fdddf
[fix] Run command being retried within quotes
2021-02-01 11:28:28 -05:00
William Wernert
02f0ef989b
[fix] <cmd> || <fail_reactor>; exit 1 will always exit, fix this
2021-02-01 11:11:01 -05:00
William Wernert
36ce389202
Remove wait_for_apt, use common retry function to run apt commands
2021-02-01 10:55:14 -05:00
Jason Ertel
1c8a8f6b7b
Merge pull request #2805 from Security-Onion-Solutions/elasticrollback
...
Add features option back
2021-01-30 21:00:10 -05:00
Mike Reeves
160d307f4a
Disable ML for features #2788
2021-01-30 20:00:41 -05:00
Mike Reeves
4212afe0c9
Add features option back
2021-01-30 19:57:18 -05:00
m0duspwnens
0ea504c16a
remove space
2021-01-29 17:32:48 -05:00
m0duspwnens
8ca15a6679
Merge remote-tracking branch 'remotes/origin/dev' into issue/1191
2021-01-29 16:54:26 -05:00
Mike Reeves
929896c191
Merge pull request #2797 from Security-Onion-Solutions/raid2
...
Raid Setup for Appliances
2021-01-29 16:30:43 -05:00
Mike Reeves
22e6e45667
Remove other changes
2021-01-29 16:14:14 -05:00
William Wernert
edfd985353
Merge branch 'bugfix/zeek-prompts' into foxtrot
2021-01-29 16:04:56 -05:00
Mike Reeves
18f2c7b482
Raid Setup for Appliances
2021-01-29 16:03:18 -05:00
Mike Reeves
aa93e2b48f
Merge pull request #2794 from Security-Onion-Solutions/foxtrot
...
Add retry capabilities to image/sig pulls
2021-01-29 15:57:41 -05:00
William Wernert
7a3c7322fc
[fix] Only check for ZEEKVERSION on manager installs
2021-01-29 15:36:50 -05:00
m0duspwnens
618b94b9b6
add newline
2021-01-29 15:31:05 -05:00
m0duspwnens
f50a89a0cf
watch elastalert config and restart docker if chagnes
2021-01-29 15:28:59 -05:00
m0duspwnens
482b6eb699
Merge remote-tracking branch 'remotes/origin/dev' into sslstate/timeouts_retry
2021-01-29 13:44:27 -05:00
m0duspwnens
e6ecd609cc
change timeouts to 30s
2021-01-29 13:44:11 -05:00
Jason Ertel
2926527ad0
Place sig keys in same dir as other sig files
2021-01-29 13:21:58 -05:00
Jason Ertel
73909c4dea
Place sig keys in same dir as other sig files
2021-01-29 13:00:56 -05:00
Jason Ertel
c055427e40
Add support for image key/sig retries
2021-01-29 11:18:06 -05:00
Jason Ertel
194f480017
Airgap fix for import nodes missing rules
2021-01-28 13:03:47 -05:00
m0duspwnens
0936dbdb1c
add timeouts and retries to ca/ssl states
2021-01-28 11:40:31 -05:00
Jason Ertel
f12947362b
Adjust test network IPs
2021-01-28 11:35:10 -05:00
Jason Ertel
bfa6aabc4b
Correct automation for airgap import to avoid infinite loop during setup
2021-01-28 10:38:03 -05:00
Jason Ertel
34c2116669
Adjust test network allocation
2021-01-27 16:02:36 -05:00
m0duspwnens
b7aef32eeb
fix missing }
2021-01-27 15:50:23 -05:00
m0duspwnens
8df9e020ac
pillarize elastalert https://github.com/Security-Onion-Solutions/securityonion/issues/1191
2021-01-27 15:35:29 -05:00
m0duspwnens
0ac19142c4
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-27 10:52:05 -05:00
Josh Brower
d277bf6d05
Merge pull request #2749 from Security-Onion-Solutions/bugfix/osquery-wel-parsing
...
Update Osquery Windows Eventlog Parsing
2021-01-27 09:17:17 -05:00
Josh Brower
13ab4c66eb
Update Osquery Windows Eventlog Parsing
2021-01-27 09:15:54 -05:00
William Wernert
f5c044e3e3
[fix] Log directory fixes
...
* The playbook log dir is owned by the socore group, so we can use `su root socore`
* Addresses https://github.com/Security-Onion-Solutions/securityonion/pull/2681#issuecomment-767761670
---
* influxdb runs as root, so we can set the log directory permissions to 755 for this service
2021-01-26 16:07:34 -05:00
m0duspwnens
be0b2b99e9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-26 13:48:49 -05:00
William Wernert
1939fe85d7
[fix] Revert directory permission changes
2021-01-26 13:41:10 -05:00
Josh Patterson
f8242a931c
Merge pull request #2733 from Security-Onion-Solutions/automation/ssh_prompts
...
fix if statement for isntalling sshpass
2021-01-26 09:57:32 -05:00
m0duspwnens
ffd01d6975
fix if statement for isntalling sshpass
2021-01-26 09:49:19 -05:00
m0duspwnens
f1faab7b1a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-26 09:04:00 -05:00
William Wernert
7b2ec05dbf
[fix] Add missing fi
2021-01-25 19:57:34 -05:00
Mike Reeves
bcd5bdd82d
Merge pull request #2730 from Security-Onion-Solutions/telegraf3
...
Add EPS and RAID status collection for telegraf
2021-01-25 19:37:03 -05:00
Mike Reeves
3b1cea94d1
Merge branch 'dev' into telegraf3
2021-01-25 19:36:49 -05:00
Mike Reeves
88abd284a7
Fix Conflicts
2021-01-25 19:35:32 -05:00
Mike Reeves
891a7592d8
Fix Conflicts
2021-01-25 19:33:49 -05:00
Mike Reeves
e43a80b9c6
Add EPS and RAID status collection for telegraf
2021-01-25 19:28:30 -05:00
Mike Reeves
4ef38f8d04
Add EPS and RAID status collection for telegraf
2021-01-25 19:14:46 -05:00
Josh Patterson
049daa6701
Merge pull request #2725 from Security-Onion-Solutions/automation/ssh_prompts
...
Automation/ssh prompts
2021-01-25 17:21:55 -05:00
Jason Ertel
df21b28d5c
Update copyright year
2021-01-25 17:11:42 -05:00
Jason Ertel
b0c74cf38c
Add import automation files for other platforms
2021-01-25 16:46:52 -05:00
Jason Ertel
ae233b5757
Update AMI automation files for distributed install
2021-01-25 15:53:25 -05:00
Jason Ertel
8ec0b95f02
Rename AMI automation files for consistency with other files
2021-01-25 15:53:25 -05:00
m0duspwnens
2f8b5afe3e
Merge remote-tracking branch 'remotes/origin/issue/2722' into automation/ssh_prompts
2021-01-25 15:23:39 -05:00
m0duspwnens
944817732b
grep for the scrip to be running https://github.com/Security-Onion-Solutions/securityonion/issues/2722
2021-01-25 15:22:04 -05:00
m0duspwnens
17a1189e42
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-25 15:20:46 -05:00
m0duspwnens
50345628f0
Merge remote-tracking branch 'remotes/origin/dev' into automation/ssh_prompts
2021-01-25 13:48:08 -05:00
m0duspwnens
7dcca6f364
change when we detect os and wait_for_apt when installing sshpass
2021-01-25 13:47:51 -05:00
Mike Reeves
6e9bdde9e2
Merge pull request #2721 from Security-Onion-Solutions/sosappliance
...
Fix function for appliances
2021-01-25 13:26:28 -05:00
Mike Reeves
2e32b53158
Fix function for appliances
2021-01-25 13:20:46 -05:00
m0duspwnens
e1f7c090f3
detect os and cloud sooner
2021-01-25 10:25:41 -05:00
William Wernert
2a4eac74c4
Merge pull request #2681 from Masaya-A/logrotate-fix
...
Log Rotation Fix (common-rotate)
2021-01-25 10:14:39 -05:00
m0duspwnens
fe09479dde
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-25 09:55:52 -05:00
Masaya-A
995d618ff5
Add cron.absent to remove old cron job if present
2021-01-25 15:45:33 +09:00
Mike Reeves
560e510b44
Merge pull request #2715 from Security-Onion-Solutions/sosappliance
...
Sosappliance
2021-01-24 12:06:18 -05:00
Mike Reeves
b4c8b439a0
Detect if this is an SOS appliance
2021-01-24 12:02:34 -05:00
Mike Reeves
85e2a14f1e
Put functions in correct order
2021-01-24 11:52:45 -05:00
Jason Ertel
6f14f27ca0
Add automation files for distributed network variations
2021-01-23 11:04:07 -05:00
William Wernert
59a4b148bc
Merge branch 'dev' into logrotate-fix
2021-01-22 15:20:55 -05:00
William Wernert
2159914742
Merge pull request #2708 from Security-Onion-Solutions/bugfix/telegraf-zombie-procs
...
Bugfix/telegraf zombie procs
2021-01-22 15:20:09 -05:00
Jason Ertel
47d69bbc9e
Move from quay.io to ghcr.io
2021-01-22 13:53:49 -05:00
William Wernert
7273c8a066
[fix] Also rotate stenographer log as per #2681
2021-01-22 12:46:21 -05:00
William Wernert
4079f8a8e8
[fix] Telegraf doesn't clean up zombie processes, use init flag to fix this
2021-01-22 12:23:09 -05:00
William Wernert
f1781b1fde
[fix] Set timeout for scripts (15s, 3x default 5s)
2021-01-22 12:15:29 -05:00
Jason Ertel
537f7529f8
Increase Kibana wait from 3 minutes to 15 minutes due to the longer init time needed for Kibana to start (because of the recent ES changes)
2021-01-22 10:09:15 -05:00
Masaya-A
249651edc7
Delete suri-rotate.conf
2021-01-22 10:08:23 +09:00
Masaya-A
e0bbc8cc51
Delete surirotate
2021-01-22 10:08:07 +09:00
Masaya-A
f156106e57
Update salt/common/files/log-rotate.conf
...
Co-authored-by: William Wernert <william.wernert@gmail.com >
2021-01-22 09:29:08 +09:00
Masaya-A
bcdf826204
Update init.sls
2021-01-22 09:26:52 +09:00
Mike Reeves
636687ac59
Merge pull request #2702 from Security-Onion-Solutions/essecurity
...
SSL with Elastic Basic license. Remove features option.
2021-01-21 13:57:28 -05:00
Mike Reeves
9408d62c65
Remove features
2021-01-21 13:55:53 -05:00
Mike Reeves
f85ecf254e
Fix dupe
2021-01-21 13:21:08 -05:00
Mike Reeves
9f984036c5
Use the internmediate cert
2021-01-21 13:00:46 -05:00
Mike Reeves
b0914fa604
try .p12
2021-01-21 12:46:00 -05:00
Mike Reeves
9759990233
Switch to java key store
2021-01-21 12:29:45 -05:00
Mike Reeves
bb523c44e6
Enable features temporarily
2021-01-21 12:19:41 -05:00
Mike Reeves
013b706ce4
Enable http ssl
2021-01-21 12:13:23 -05:00
weslambert
583b65e952
Fix syntax
2021-01-21 11:52:23 -05:00
Mike Reeves
84b75a38a3
Fix error in init.sls for ES
2021-01-21 11:21:04 -05:00
Mike Reeves
6de70ec820
Update docker mappings for ES
2021-01-21 11:12:12 -05:00
weslambert
d6043d091b
Merge pull request #2701 from Security-Onion-Solutions/feature/filebeat_events
...
Allow for Filebeat queue/output adjustments via pillar
2021-01-21 10:36:33 -05:00
Wes Lambert
19d22e1f8a
Allow for Filebeat queue/output adjustments via pillar
2021-01-21 15:34:54 +00:00
Mike Reeves
35c741ae63
Turn on Xpack SSL
2021-01-21 09:49:31 -05:00
m0duspwnens
76aadbd04e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-21 09:30:03 -05:00
weslambert
a99246c600
Merge pull request #2698 from Security-Onion-Solutions/fix/reserved_ports
...
Fix/reserved ports
2021-01-21 08:39:35 -05:00
Wes Lambert
0039877779
Check for port availability for Wazuh and Strelka
2021-01-21 13:29:09 +00:00
Wes Lambert
9a91674688
Add reserved ports file for sysctl
2021-01-21 13:18:22 +00:00
Wes Lambert
74e315841a
Modify common to reserve Docker proxy ports
2021-01-21 13:17:16 +00:00
Masaya-A
cd5abf924c
To make log rotation working
2021-01-21 09:31:15 +09:00
Masaya-A
845ab92d36
To make log rotation working
2021-01-21 09:30:34 +09:00
Josh Patterson
516634ef8d
Merge pull request #2691 from Security-Onion-Solutions/issue/2679
...
Issue/2679
2021-01-20 17:41:43 -05:00
m0duspwnens
18217ba38b
change so-searchnode role to so-node https://github.com/Security-Onion-Solutions/securityonion/issues/2679
2021-01-20 17:40:02 -05:00
m0duspwnens
6e756b3586
allow heathcheck state for standalone and heavynode
2021-01-20 17:34:53 -05:00
Josh Patterson
e7e6243399
Merge pull request #2689 from Security-Onion-Solutions/issue/2679
...
Issue/2679
2021-01-20 15:14:38 -05:00
m0duspwnens
18278a97ac
fix salt top formatting
2021-01-20 15:13:55 -05:00
m0duspwnens
b693373d8d
change how we allow or disallow states to be run https://github.com/Security-Onion-Solutions/securityonion/issues/2679
2021-01-20 15:09:53 -05:00
Jason Ertel
58f922aac3
Skip image pull if so-tcpreplay image already exists and is current
2021-01-20 11:17:10 -05:00
m0duspwnens
b1c5b83fd5
removing old search node logic and managersensor from salt top
2021-01-20 09:53:42 -05:00
m0duspwnens
caaa8cc764
add schedule state to fleet node so it gets highstate schedule
2021-01-20 09:46:49 -05:00
Masaya-A
d53945888c
Add sensoroni dir
2021-01-20 14:54:55 +09:00
Masaya-A
d3d11ff67b
Delete some directories
...
Delete some directories that should not be handled by common-rotate.
2021-01-20 13:42:20 +09:00
Masaya-A
b2b221fa46
Specify the file name for Suricata
...
stats.log will be rotated by surirotate
2021-01-20 13:20:04 +09:00
Masaya-A
e20891ac44
Fix spacing
2021-01-20 13:10:33 +09:00
Masaya-A
8cca792a8f
To avoid lots of "[stenoloss.sh] <defunct>"
2021-01-20 12:16:17 +09:00
Masaya-A
5dad143c42
Need full path in order to work on cron
2021-01-20 12:14:09 +09:00
Masaya-A
9dd3199ec4
Merge pull request #1 from Security-Onion-Solutions/dev
...
Update Dev
2021-01-20 12:09:35 +09:00
Jason Ertel
71e0014115
Wrap parenthesis around correlation filter to allow additional filtering
2021-01-19 17:51:23 -05:00
m0duspwnens
0fec46505d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-19 14:35:53 -05:00
William Wernert
8023e79020
[fix] Don't remove answer file when checking version on manager, file does not yet exist
2021-01-19 11:28:33 -05:00
m0duspwnens
3ef8106d8d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-19 11:28:27 -05:00
William Wernert
650008e1e6
[fix] Replace leftover /root/install_opt strings with variable
2021-01-19 11:20:53 -05:00
Jason Ertel
d91913e58e
Redirect tcpreplay warnings to dev null when running so-test
2021-01-18 21:42:50 -05:00
Mike Reeves
12aa4033b6
Fix soup in case airgap is in the hostname
2021-01-18 18:08:34 -05:00
Jason Ertel
a795f0a487
Correct airgap IPs; Remove auto tcpreplay during post-setup phase
2021-01-16 12:01:49 -05:00
Jason Ertel
2006677a22
Add default customization file (Blank)
2021-01-15 20:08:27 -05:00
William Wernert
32839f8a53
[feat] Various input validation changes + fixes
...
* Keep invalid input in subsequent prompts
* Remove useless placeholder values
* Only set PROCS variable once
* Make input collection loops more consistent
2021-01-15 18:05:29 -05:00
Jason Ertel
0af6afa216
Add method for making adjustments to the SOC UI
2021-01-15 16:26:06 -05:00
William Wernert
8cb836a17a
[fix] Don't preset HOSTNAME var, interferes with automation
2021-01-15 16:22:07 -05:00
William Wernert
432d231a0e
[fix] Don't use set -e since we depend on non-zero exit codes for this function
2021-01-15 13:52:10 -05:00
William Wernert
9726ff9ce6
[fix] Correct logic for verbose flag
2021-01-15 13:39:12 -05:00
Mike Reeves
9cf63545bc
Merge pull request #2640 from Masaya-A/influxdb/strengthen
...
Disable weak cipher suites from influxdb
2021-01-15 10:50:21 -05:00
m0duspwnens
76c7c46887
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-15 10:48:19 -05:00
William Wernert
e440f6c44a
[fix] Set variables used by sensor pillar before generating the pillar
2021-01-15 10:29:51 -05:00
William Wernert
ed129bcf1f
[fix] Add verbose flag so that so-monitor-add only sees necessary information
2021-01-15 09:25:04 -05:00
William Wernert
f4de5e28bf
[fix] Padding 3->4 spaces, don't use lookup_pillar before salt is installed
2021-01-15 08:57:14 -05:00
Jason Ertel
07b5f1d23e
Rename functions to avoid naming conflict with setup vars
2021-01-15 08:55:30 -05:00
William Wernert
0f6805823e
[fix] Add spacing to whiptail menu + preset err
2021-01-15 08:35:37 -05:00
Masaya-A
0d93b15a63
Disable weak cipher suites from influxdb
...
The default config of influxdb enables use of some weak cipher suites such as RC4 and 3DES(SWEET32).
To disable them, a list of enabled ciphers added into influxdb.conf.
2021-01-15 11:47:04 +09:00
William Wernert
dbe22f901d
[fix] Add jinja raw block to so-common
2021-01-14 14:54:37 -05:00
William Wernert
ebc5a4314a
[feat] Add salt logs to log rotation config
2021-01-14 13:43:00 -05:00
William Wernert
df07cc578c
[fix] Only update err if return code is non-zero
2021-01-14 13:20:56 -05:00
William Wernert
2e23e0d690
[fix] Only update err if return code is non-zero
2021-01-14 13:20:29 -05:00
William Wernert
a7b9b565fd
[fix] Only return after all interfaces added to bond0
2021-01-14 13:19:29 -05:00
William Wernert
e7070ef217
Merge pull request #2630 from Security-Onion-Solutions/feature/setup
...
Input validation + so-monitor-add
2021-01-14 13:17:01 -05:00
William Wernert
8793965f4a
[fix] Capitalization
2021-01-14 13:12:12 -05:00
William Wernert
ddcd487edc
[fix] Remove files not in dev
2021-01-14 13:08:11 -05:00
William Wernert
0db439df1e
Merge branch 'dev' into feature/setup
2021-01-14 13:06:32 -05:00
William Wernert
82c7832d60
[fix] Fix indent in valid_hostname
2021-01-14 12:58:21 -05:00
m0duspwnens
a2b52a1a98
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-14 10:44:53 -05:00
William Wernert
3c22738ae1
[fix] Add example CIDR notation, remove placeholder X.X.X.X
2021-01-14 10:38:47 -05:00
Jason Ertel
9d0dca05b1
Adjusted logic on so-tcpreplay to handle init for standalone/eval nodes
2021-01-13 22:29:58 -05:00
Jason Ertel
2ccf77eaef
Rename network automation files
2021-01-13 17:29:48 -05:00
William Wernert
8245b25835
[fix] Move metadata function
2021-01-13 17:28:19 -05:00
William Wernert
b68685e00e
[fix] Correct metadata function name
2021-01-13 17:26:27 -05:00
William Wernert
90f085b2d7
[fix] Fail setup early if we can't determine version of manager
2021-01-13 15:57:21 -05:00
Jason Ertel
6d6779bba6
Added automation files for network eval/standalone installs; Reduced Zeek threads from 7 to 2 on all test nodes
2021-01-13 15:43:43 -05:00
Jason Ertel
0a1ab29d19
Add distributed airgap automation files
2021-01-13 14:28:54 -05:00
Jason Ertel
ea1ab75072
Refactored so-common node type checks for improved readability; Updated so-tcpreplay to support distributed grids
2021-01-13 12:42:54 -05:00
William Wernert
6ea3a651a4
[fix] Fix unit tests for dns list
2021-01-13 11:37:48 -05:00
William Wernert
4dc3a6aa35
[refactor] Standardize list inputs to comma separated
2021-01-13 11:36:20 -05:00
Josh Patterson
59b016695f
Merge pull request #2611 from Security-Onion-Solutions/issue/2095
...
pillarize disk freespace for steno
2021-01-13 11:11:27 -05:00
m0duspwnens
df590bfd23
pillarize disk freespace for steno https://github.com/Security-Onion-Solutions/securityonion/issues/2095
2021-01-13 11:09:38 -05:00
William Wernert
d254fd960a
[feat] Add message explaining strings cannot contain spaces
2021-01-13 11:04:35 -05:00
m0duspwnens
489f702e47
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-13 10:47:13 -05:00
William Wernert
0734998315
[fix] patch_schedule should not be local
2021-01-13 10:39:24 -05:00
Jason Ertel
9b060fb2d1
Adjust automation defaults for sensors and search nodes
2021-01-13 10:39:10 -05:00
Jason Ertel
bb386f9935
Allow passwordless sudo during tests for all nodes, not just manager; Only run so-test on sensor nodes during test runs
2021-01-13 10:39:05 -05:00
William Wernert
ebac17ce38
[wip] Attempting to fix missing patch schedule prompts
2021-01-13 10:29:36 -05:00
Mike Reeves
2950779d91
Fix stralka rule update
2021-01-13 09:57:12 -05:00
Josh Patterson
02d4813ef7
Merge pull request #2609 from Security-Onion-Solutions/issue/2590
...
Issue/2590
2021-01-12 16:43:45 -05:00
m0duspwnens
225ed1c14a
change suriloss and zeekloss to be more similar code style
2021-01-12 16:39:19 -05:00
m0duspwnens
96dab31ab0
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/2590
2021-01-12 14:29:59 -05:00
Josh Patterson
aa8a14d74a
Merge pull request #2606 from Security-Onion-Solutions/automation/ssh_prompts
...
fix quotes
2021-01-12 14:08:08 -05:00
m0duspwnens
dbb9f90f00
fix quotes
2021-01-12 14:07:04 -05:00
William Wernert
dd20002fd5
[fix] Dockernet prompt is negative, continue on "no"
2021-01-12 11:28:24 -05:00
William Wernert
5c6f8f9d47
[fix] Correct function call (pt 2)
2021-01-12 11:27:03 -05:00
William Wernert
ff69d022b3
[fix] Correct function call
2021-01-12 11:26:20 -05:00
William Wernert
fb31b56c8b
[fix] Only check for network init file if iso
2021-01-12 11:22:52 -05:00
William Wernert
38e37a0385
[refactor] Remove whiptail shard count prompt
2021-01-12 11:04:40 -05:00
William Wernert
5d077d278e
[feat] Add input validation to inputbox whiptail prompts
2021-01-12 11:02:33 -05:00
William Wernert
0dc0780e28
[feat] Add unit tests for input validation
2021-01-12 11:02:00 -05:00
William Wernert
332c6877b8
[fix] Add extra arg to printf instead of using echo
2021-01-12 11:01:25 -05:00
William Wernert
ef7a934b9d
[feat] Add functions for input validation
2021-01-12 11:01:04 -05:00
m0duspwnens
cc0697cefa
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-12 10:29:49 -05:00
Josh Patterson
4f384991ba
Merge pull request #2601 from Security-Onion-Solutions/automation/ssh_prompts
...
remote quotes
2021-01-12 09:54:10 -05:00
m0duspwnens
9405990a2e
remote quotes
2021-01-12 09:50:08 -05:00
m0duspwnens
6ea1a83afe
resolve some issues with the zeekloss script https://github.com/Security-Onion-Solutions/securityonion/issues/2590
2021-01-11 14:10:08 -05:00
m0duspwnens
4d84b64056
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-11 12:43:37 -05:00
Jason Ertel
8b49876e26
First pass at distribute ISO automation files
2021-01-11 12:04:57 -05:00
Jason Ertel
bc8e200919
Continued retry implementation for salt-key acceptance; improve timestamp coverage in setup
2021-01-10 02:34:46 -05:00
Jason Ertel
63047b4b85
Add retry logic around salt key acceptance during setup
2021-01-10 00:57:43 -05:00
Josh Patterson
95a9d14832
Merge pull request #2578 from Security-Onion-Solutions/salt/info_logging
...
increase salt logging to info
2021-01-08 16:34:26 -05:00
m0duspwnens
f07e583013
increase salt logging to info
2021-01-08 16:33:38 -05:00
m0duspwnens
ae63b52e7a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-08 15:30:15 -05:00
Jason Ertel
9eedb874fb
Add eval and standalone airgap automations
2021-01-08 12:37:54 -05:00
Jason Ertel
a6f88b2843
Correct eval AMI automation vars
2021-01-07 15:22:34 -05:00
m0duspwnens
86cb1abad4
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-07 15:12:36 -05:00
Jason Ertel
567d80bb01
Update sed to disable sudo password prompt for automated testing
2021-01-07 11:33:59 -05:00
Josh Patterson
d2848b9985
Merge pull request #2561 from Security-Onion-Solutions/automation/so-status
...
add description for exit code 99
2021-01-07 11:24:14 -05:00
m0duspwnens
83e7493691
add description for exit code 99
2021-01-07 11:23:39 -05:00
William Wernert
1ec45fb4ae
[fix] Only show Zeek prompts if Zeek was selected as the MD tool
...
Resolves #900
2021-01-07 10:37:25 -05:00
William Wernert
c1e32ed680
[refactor] Rename MD tool function to be more clear
2021-01-07 10:36:32 -05:00
William Wernert
fa06a38a3b
[refactor] Remove duplicate function
2021-01-07 10:36:01 -05:00
Josh Patterson
d287dd2412
Merge pull request #2557 from Security-Onion-Solutions/automation/so-status
...
Automation/so status
2021-01-07 09:07:12 -05:00
Josh Patterson
8fa2b14c98
Merge pull request #2539 from Security-Onion-Solutions/automation/ssh_prompts
...
Automation/ssh prompts
2021-01-07 09:06:10 -05:00
Jason Ertel
948f900673
Drop password requirement for sudo access during automated tests
2021-01-06 20:39:44 -05:00
m0duspwnens
a5735e6654
return 99 if setup is running
2021-01-06 20:14:42 -05:00
m0duspwnens
ae7c0a26be
add a quiet mode to so-status for automation testing
2021-01-06 18:46:21 -05:00
Jason Ertel
bbdb47703d
Rename automation files to match environment names for consistency
2021-01-06 17:21:46 -05:00
Wes Lambert
7f64d57111
Reserve port for Wazuh API and check if port is already in use
2021-01-06 14:37:28 -05:00
Wes Lambert
e7db1a99bd
Set @timestamp to winlog.systemTime
2021-01-06 14:37:28 -05:00
Mike Reeves
7d25e8a08b
Remove ERSPAN so log doesn't show a warning
2021-01-06 14:37:28 -05:00
Masaya-A
d37023e0f5
Make yum removing unneeded packages
...
Reference: https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2020-09-03/finding/V-204452
2021-01-06 14:37:28 -05:00
William Wernert
9d8fb79d9f
[feat] Reorder network-only prompt
2021-01-06 14:37:27 -05:00
weslambert
c864cc607f
Remove multiple old so-yara-update cron jobs, if needed
2021-01-06 14:37:27 -05:00
William Wernert
80a3d8dcf8
[fix] Fix automation compatibility
2021-01-06 14:37:27 -05:00
William Wernert
ac35a345ff
[fix] Don't prompt to only set up network and then skip if network was previously configured
2021-01-06 14:37:27 -05:00
weslambert
958635b012
Remove old Strelka cron job
2021-01-06 14:37:27 -05:00
William Wernert
6ba11f835d
[fix] Remove condition for stopping SOC, since the parent condition covers what's tested
2021-01-06 14:37:27 -05:00
Jason Ertel
1cc8a78aa5
Only stop SOC if is_manager or is_import
2021-01-06 14:37:27 -05:00
Jason Ertel
7dcd934269
so-fleet-setup doesn't need an interactive terminal to run, remove 'it'
2021-01-06 14:37:27 -05:00
Jason Ertel
bedbd39b82
tcpreplay doesn't need an interactive terminal to run, remove 'it'
2021-01-06 14:37:27 -05:00
Jason Ertel
7d97e3590c
Redirect tcpreplay init output to file
2021-01-06 14:37:27 -05:00
Jason Ertel
bdbc637852
Stop SOC prior to opening the firewall for analysts, this ensures no outside requests can be processed prior to the server rebooting
2021-01-06 14:37:27 -05:00
Jason Ertel
10d04f760d
Use manager internal IP for intra-service comms
2021-01-06 14:37:26 -05:00
Jason Ertel
ebb0e615b9
Fix script typo to correctly run the so-test
2021-01-06 14:37:26 -05:00
Jason Ertel
f20feabda2
Reboot to ensure thehive falls in line before kicking off the test
2021-01-06 14:37:26 -05:00
Jason Ertel
9b40318bfe
Ensure so-test is logged
2021-01-06 14:37:26 -05:00
Jason Ertel
fc44474519
Add eval automation
2021-01-06 14:37:26 -05:00
Jason Ertel
229657f7d2
Use AMI's public IP for external access
2021-01-06 14:37:26 -05:00
Jason Ertel
fb28faa4e3
Monitor interface will not always be bond0 - pull correct value from pillar; Replay test data after automated test installations complete.
2021-01-06 14:37:26 -05:00
weslambert
36ae09ac4a
Merge pull request #2545 from Security-Onion-Solutions/fix/wazuh_port_reservation
...
Reserve port for Wazuh API and check if port is already in use
2021-01-06 11:49:23 -05:00
weslambert
55344725e7
Merge pull request #2544 from Security-Onion-Solutions/fix/winlog_timestamp
...
Set @timestamp to winlog.systemTime
2021-01-06 11:49:01 -05:00
Wes Lambert
875908dc90
Set @timestamp to winlog.systemTime
2021-01-06 16:47:35 +00:00
Wes Lambert
f2b677bfcb
Reserve port for Wazuh API and check if port is already in use
2021-01-06 15:52:10 +00:00
m0duspwnens
48f81d9ac6
reduce setting ssh commands down to 1 function and 1 function call
2021-01-06 08:58:33 -05:00
m0duspwnens
94fd79cd28
originally had sshpass package install reveresed, fixed it here
2021-01-06 08:51:33 -05:00
m0duspwnens
aecc0c025e
fix comment
2021-01-06 08:49:08 -05:00
m0duspwnens
91ad7f26bf
no longer need to pass $automated to compare_versions
2021-01-06 08:45:33 -05:00
m0duspwnens
c65e722164
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-06 08:39:56 -05:00
m0duspwnens
749b21e684
make sure ssh commands get set whether automated install or not
2021-01-05 14:12:43 -05:00
Mike Reeves
1154b533d6
Remove ERSPAN so log doesn't show a warning
2021-01-05 13:56:56 -05:00
m0duspwnens
0f9bf9deb6
make sshcmd, scpcmd, ssh_copy_id_cmd global to so-functions;
2021-01-05 13:49:51 -05:00
m0duspwnens
c93dfa7b33
hardcode automation pw
2021-01-05 11:47:22 -05:00
m0duspwnens
81c4d879eb
first round of testing for automated testing ssh/scp
2021-01-05 10:26:19 -05:00
Mike Reeves
dc429494ac
Merge pull request #2370 from Masaya-A/improve/yum
...
Make yum removing unneeded packages
2021-01-05 09:26:04 -05:00
William Wernert
294601ff64
[feat] Reorder network-only prompt
2021-01-04 16:40:16 -05:00
weslambert
707528d7e8
Merge pull request #2530 from Security-Onion-Solutions/fix/strelka_cron_2
...
Remove multiple old so-yara-update cron jobs, if needed
2021-01-04 16:30:22 -05:00
weslambert
c1e245043e
Remove multiple old so-yara-update cron jobs, if needed
2021-01-04 16:29:32 -05:00
William Wernert
f94e421f4e
[fix] Fix automation compatibility
2021-01-04 14:46:48 -05:00
m0duspwnens
38f985ae22
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-04 14:10:41 -05:00
William Wernert
9d674d6d3a
[feat] Add so-monitor-add script
2021-01-04 13:35:14 -05:00
William Wernert
7bfac1e8df
[fix] Don't prompt to only set up network and then skip if network was previously configured
2021-01-04 11:58:25 -05:00
William Wernert
65c3849c7b
Merge pull request #2527 from Security-Onion-Solutions/feature/setup
...
Feature/setup
2021-01-04 11:41:07 -05:00
William Wernert
f8c7413b15
[fix] Move is_iso variable assignment up
2021-01-04 10:37:07 -05:00
weslambert
e51f60f7fa
Merge pull request #2521 from Security-Onion-Solutions/fix/strelka_rule_cron
...
Remove old Strelka cron job
2021-01-04 10:19:50 -05:00
weslambert
535820bfa7
Remove old Strelka cron job
2021-01-04 10:18:32 -05:00
William Wernert
0fa001ed92
[fix] Add more logic to network-only process
2021-01-04 09:27:22 -05:00
William Wernert
a714d36b99
[fix] Remove condition for stopping SOC, since the parent condition covers what's tested
2021-01-02 21:03:15 -05:00
Jason Ertel
455da7ec5d
Only stop SOC if is_manager or is_import
2020-12-31 15:09:22 -05:00
Jason Ertel
4b244645ba
so-fleet-setup doesn't need an interactive terminal to run, remove 'it'
2020-12-31 10:52:59 -05:00
Jason Ertel
6b81419d38
tcpreplay doesn't need an interactive terminal to run, remove 'it'
2020-12-30 22:02:19 -05:00
Jason Ertel
e167bfed20
Redirect tcpreplay init output to file
2020-12-30 18:48:56 -05:00
Jason Ertel
df305c49a6
Stop SOC prior to opening the firewall for analysts, this ensures no outside requests can be processed prior to the server rebooting
2020-12-30 16:33:46 -05:00
William Wernert
3f3fe78322
[fix] Correct reversed logic
2020-12-30 14:01:20 -05:00
Jason Ertel
13f0ddabfc
Use manager internal IP for intra-service comms
2020-12-30 12:02:42 -05:00
Jason Ertel
19d14cf277
Fix script typo to correctly run the so-test
2020-12-30 10:31:04 -05:00
Jason Ertel
a49ddfb887
Reboot to ensure thehive falls in line before kicking off the test
2020-12-29 20:42:50 -05:00
Jason Ertel
827a571db8
Ensure so-test is logged
2020-12-29 17:25:53 -05:00
Jason Ertel
989e2b8b78
Add eval automation
2020-12-29 16:15:10 -05:00
William Wernert
0a57b78900
[feat] Add option to set up only network on an iso
2020-12-29 12:52:21 -05:00
Jason Ertel
74dd2187fb
Use AMI's public IP for external access
2020-12-29 11:16:57 -05:00
Jason Ertel
ea5e25c4a5
Monitor interface will not always be bond0 - pull correct value from pillar; Replay test data after automated test installations complete.
2020-12-29 10:34:31 -05:00
William Wernert
afe40fe87b
Merge pull request #2478 from Security-Onion-Solutions/feature/wait-for-apt
...
Feature/wait for apt
2020-12-28 18:29:20 -05:00
William Wernert
e9a6155e44
Merge branch 'dev' into feature/wait-for-apt
2020-12-28 18:26:38 -05:00
Jason Ertel
deb38844ba
Correct hive init urls
2020-12-28 16:20:33 -05:00
William Wernert
97466957a7
[fix] Fix text printed to whiptail progress bar
2020-12-28 15:06:03 -05:00
William Wernert
cdb6dfcea0
[fix][wip] Fix whiptail output
2020-12-28 14:55:15 -05:00
William Wernert
5059373485
[fix] Change text printed to whiptail progress bar
2020-12-28 14:43:33 -05:00
William Wernert
af62e64852
[fix] Message changes
2020-12-28 14:40:17 -05:00
William Wernert
b03408df6b
[fix] Add missing function
2020-12-28 14:30:34 -05:00
William Wernert
5836d22525
[fix] Change text printed to whiptail progress bar
2020-12-28 14:29:03 -05:00
William Wernert
a4239d7fe4
[fix] Clarify why dpkg lock is needed
2020-12-28 14:20:37 -05:00
William Wernert
5bd15b91ea
[fix] Message formatting changes
2020-12-28 14:18:43 -05:00
William Wernert
a0533dd6b5
[feat] Increase retry_count, decrease wait time, change wording
2020-12-28 14:17:27 -05:00
William Wernert
f7a60a011b
[fix] Message formatting
2020-12-28 14:06:33 -05:00
William Wernert
17160dcdbe
[fix] Don't repeat fail message on last attempt
2020-12-28 14:02:46 -05:00
William Wernert
0dd80a664f
[fix] Only call progress callback if arg passed
2020-12-28 14:00:09 -05:00
William Wernert
1e0525b1ad
[fix] Only call progress callback if arg passed
2020-12-28 13:57:44 -05:00
William Wernert
7050b1fce5
[fix] Don't use same variable for increment and limit
2020-12-28 13:55:03 -05:00
Jason Ertel
7fe0182ede
Refactor so-test and so-tcpreplay to be compatible with SO 2.3.20+; Change hive_init and cortex_init to initialize the cortex and fleet services directly on the manager IP instead of attempting to use the public URL
2020-12-28 11:26:56 -05:00
William Wernert
4d1cb37468
[feat] Add function to wait for dpkg lock
2020-12-28 09:35:51 -05:00
Jason Ertel
8f15d794bc
Silence curl progress output during hive/cortex init
2020-12-24 08:44:28 -05:00
Jason Ertel
baf5be1a3a
Return adequate exit code when init fails; Logs output of init scripts for troubleshooting failed installations
2020-12-23 20:14:46 -05:00
Jason Ertel
9cf150f988
Switch from Jinja syntax to bash
2020-12-23 15:11:43 -05:00
m0duspwnens
7800e90776
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-23 14:53:27 -05:00
Jason Ertel
2d44b69e8d
Refactor hive and cortex init to use wait loops instead of hardcoded sleeps
2020-12-23 12:12:38 -05:00
Jason Ertel
aa5c0a7351
Clarify prompt instructions for so-elastalert-test
2020-12-23 09:37:44 -05:00
Jason Ertel
eef1f49d09
Corrected cortex_init process which was incorrectly attempting to access ES via the external URL; Removing 1-2 minute sleeps during init to see if those are no longer needed
2020-12-22 22:56:01 -05:00
Jason Ertel
cfe5019f51
Add firewall listhogroups and listportgroups commands; Change AMI test defaults to use a custom hostname for cypress access
2020-12-22 17:59:59 -05:00
weslambert
f6a199156b
Merge pull request #2428 from Security-Onion-Solutions/feature/strelka_pillar_repos
...
Support setting rule repos via pillar
2020-12-22 10:38:01 -05:00
Wes Lambert
ac96ded2dc
Support setting rule repos via pillar
2020-12-22 15:36:15 +00:00
Mike Reeves
aa15f3ca4a
Merge pull request #2425 from Security-Onion-Solutions/patch/2.3.21
...
2.3.21 ISO sig
2020-12-22 08:39:00 -05:00
TOoSmOotH
3a3182a51f
2.3.21 ISO sig
2020-12-22 08:32:58 -05:00
Mike Reeves
36207d0440
Merge pull request #2417 from Security-Onion-Solutions/patch/2.3.21
...
2.3.21
2020-12-21 20:02:04 -05:00
Mike Reeves
88bfe7c49c
Update VERIFY_ISO.md
2020-12-21 19:52:31 -05:00
Mike Reeves
7116c2103b
Update Docker Clean
2020-12-21 17:06:14 -05:00
Mike Reeves
b49355d346
Update changes.json
2020-12-21 16:54:55 -05:00
Mike Reeves
aecde2dd54
Update README.md
2020-12-21 16:54:10 -05:00
Mike Reeves
f2d8c7f10d
Update VERSION
2020-12-21 16:53:30 -05:00
Mike Reeves
627d4da432
Merge pull request #2403 from Security-Onion-Solutions/fix/so-analyst-typo
...
fix typo in so-analyst-install warning
2020-12-21 11:48:25 -05:00
m0duspwnens
a18c89d804
fix typo in so-analyst-install warning
2020-12-21 11:42:03 -05:00
m0duspwnens
416d98071d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 11:39:23 -05:00
Mike Reeves
d73f3bb6f8
Update README.md
2020-12-21 10:53:41 -05:00
Mike Reeves
48931116ab
Update VERSION
2020-12-21 10:52:37 -05:00
Mike Reeves
7b8f5aa8a9
Merge pull request #2402 from Security-Onion-Solutions/dev
...
2.3.20
2020-12-21 10:26:50 -05:00
m0duspwnens
544c473338
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 10:21:48 -05:00
Mike Reeves
1f9151b407
Update README.md
2020-12-21 10:21:28 -05:00
m0duspwnens
5d0cef5e3d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 10:21:24 -05:00
TOoSmOotH
def8dc0e1e
2.3.20 ISO sig
2020-12-21 09:58:25 -05:00
Mike Reeves
88be7bca3f
Update VERIFY_ISO.md
2020-12-21 09:56:18 -05:00
Mike Reeves
a0f00e09c1
2.3.20 Readme Update
2020-12-21 09:55:23 -05:00
weslambert
def08895d5
Merge pull request #2393 from Security-Onion-Solutions/fix/strelka_filestream
...
Fix/strelka filestream
2020-12-18 15:48:54 -05:00
weslambert
2fee2ca143
Change identifier name to be more descriptive
2020-12-18 15:40:54 -05:00
weslambert
7453626b06
Add identifier
2020-12-18 15:39:52 -05:00
Josh Patterson
4ccb80c9c8
Merge pull request #2392 from Security-Onion-Solutions/fix/sensoroni_fw
...
fix duplicate state name for fw
2020-12-18 15:02:52 -05:00
m0duspwnens
ad45779978
fix duplicate state name for fw
2020-12-18 15:01:55 -05:00
Josh Patterson
83326518c4
Merge pull request #2391 from Security-Onion-Solutions/fix/sensoroni_fw
...
Fix/sensoroni fw
2020-12-18 14:16:33 -05:00
m0duspwnens
66f62b912e
Merge remote-tracking branch 'remotes/origin/dev' into fix/sensoroni_fw
2020-12-18 14:14:55 -05:00
m0duspwnens
4bbedfa027
put portgroup name in statename
2020-12-18 14:14:45 -05:00
m0duspwnens
7653ad56a9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 14:11:21 -05:00
Josh Patterson
5275583098
Merge pull request #2388 from Security-Onion-Solutions/fix/grafana_sensor_uptime
...
limit sensor uptime in grafana dash to 2 decimal
2020-12-18 13:41:54 -05:00
m0duspwnens
e756bbc430
limit sensor uptime in grafana dash to 2 decimal
2020-12-18 13:40:55 -05:00
m0duspwnens
1374ac0628
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 13:39:27 -05:00
Mike Reeves
dea88e4c68
Update soup
2020-12-18 13:27:08 -05:00
Josh Patterson
dec6cdd3c5
Merge pull request #2385 from Security-Onion-Solutions/fix/sensoroni_fw
...
add sensoroni port to minions for manager nodes
2020-12-18 13:08:16 -05:00
m0duspwnens
dbf82a891f
add sensoroni port to minions for manager nodes
2020-12-18 13:06:14 -05:00
m0duspwnens
b506f0455f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 12:38:44 -05:00
Mike Reeves
96bd1e72a7
Update soup
2020-12-18 11:55:24 -05:00
weslambert
1a463bccaf
Add cron.absent to remove old cron job if present
2020-12-18 11:25:14 -05:00
Josh Patterson
b0db910e7a
Merge pull request #2384 from Security-Onion-Solutions/fix/telegraf_stenoloss
...
make sure timestamp on steno log line has changed so we don't snapshot the drop%
2020-12-18 11:02:29 -05:00
m0duspwnens
90dcad7e6f
make sure timestamp on steno log line has changed so we dont snapshot the drop%
2020-12-18 11:00:24 -05:00
m0duspwnens
e7a833e890
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 10:57:18 -05:00
weslambert
9493aad1a5
Read from dedicated unprocessed dir
2020-12-18 10:53:17 -05:00
weslambert
bf76c1b58c
Create unprocessed dir and move Zeek extracted files there
2020-12-18 10:52:14 -05:00
Mike Reeves
575098e368
Update init.sls
2020-12-17 20:23:38 -05:00
Mike Reeves
39425c1ba8
Fix extra extrahosts
2020-12-17 20:15:56 -05:00
TOoSmOotH
6448ddc31a
Allow SNs to resolve the ES master
2020-12-17 20:08:21 -05:00
Josh Patterson
89a9816d50
Merge pull request #2379 from Security-Onion-Solutions/fix/telegraf-suriloss
...
tell dc to use 4 decimal spot for suriloss calc
2020-12-17 18:08:35 -05:00
m0duspwnens
412e8eeccb
tell dc to use 4 decimal spot for suriloss calc
2020-12-17 18:05:25 -05:00
m0duspwnens
6e202f2ee0
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-17 17:21:01 -05:00
Mike Reeves
6ccbe47f10
Fix Jinja
2020-12-17 16:34:49 -05:00
Mike Reeves
6fcc11eac2
Fix setup
2020-12-17 16:31:25 -05:00
Mike Reeves
b6f2cdce8c
Fix whiptail menu
2020-12-17 15:57:13 -05:00
Jason Ertel
370a2cdb81
Update change.json for 2.3.20
2020-12-17 15:49:09 -05:00
TOoSmOotH
96ebb98fc6
Change wording about true clustering again
2020-12-17 15:34:29 -05:00
TOoSmOotH
336ec18e09
Change wording about true clustering
2020-12-17 15:32:34 -05:00
TOoSmOotH
d99596ad06
Fix Docker Settings on new installs
2020-12-17 15:21:29 -05:00
William Wernert
1f523deaea
[fix] Playbook setup bug fixes
...
* Increase timeout for port check
* Exit with non-zero code in user create script if timeout exceeded or error occurs
2020-12-17 12:23:06 -05:00
Jason Ertel
e0dc6cbb41
Update screenshots with new Grid menu change
2020-12-17 11:15:49 -05:00
Josh Brower
5719b12968
Merge pull request #2373 from Security-Onion-Solutions/bugfix/so-suricata-testrule
...
Fix so-suricata-testrule
2020-12-17 11:08:26 -05:00
Josh Brower
73ad89f4ba
Fix so-suricata-testrule
2020-12-17 11:05:57 -05:00
Masaya-A
59ae5f63cf
Make yum removing unneeded packages
...
Reference: https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2020-09-03/finding/V-204452
2020-12-17 22:14:03 +09:00
Josh Patterson
011dc48d96
Merge pull request #2363 from Security-Onion-Solutions/fix/grafana-eval
...
Fix/grafana eval
2020-12-16 18:05:02 -05:00
m0duspwnens
027929bb6d
fix eval grafana dashboard
2020-12-16 17:59:54 -05:00
TOoSmOotH
345710a48d
Make sure thehive is up then soup by hitting api
2020-12-16 17:41:38 -05:00
m0duspwnens
90e499f6e9
fix eval grafana dashboard
2020-12-16 17:25:56 -05:00
TOoSmOotH
23110d3b33
Make sure thehive is up then soup
2020-12-16 17:23:51 -05:00
William Wernert
384456a991
[fix] Make repo directory during soup if it doesn't exist
2020-12-16 16:18:17 -05:00
TOoSmOotH
6e84227525
Add DB migration for thehive
2020-12-16 16:06:05 -05:00
Josh Patterson
3ff99da302
Merge pull request #2359 from Security-Onion-Solutions/fix/so-status-import-node
...
Fix/so status import node
2020-12-16 14:22:08 -05:00
m0duspwnens
2d497cb724
change to just Hunt
2020-12-16 14:15:57 -05:00
Mike Reeves
eecb323459
remove extra state.apply common
2020-12-16 13:12:38 -05:00
m0duspwnens
2e278586f2
disable steno in so-status for import node
2020-12-16 13:03:24 -05:00
m0duspwnens
81e2b4d572
Merge remote-tracking branch 'remotes/origin/dev' into fix/so-status-import-node
2020-12-16 12:02:39 -05:00
m0duspwnens
96b72d46be
show steno,zeek,suricata as disabled in so-status on import node
2020-12-16 12:01:48 -05:00
Mike Reeves
09b5e6d227
Fix SSL issue
2020-12-16 11:57:27 -05:00
William Wernert
9c8fc5e6ed
[fix] Make parent directories if needed
2020-12-16 11:16:14 -05:00
William Wernert
6ba3c16c75
[fix] Actually count containers when checking count
2020-12-16 11:10:57 -05:00
William Wernert
d670f96dc0
[fix] Exit on command failure in so-catrust
2020-12-16 11:07:00 -05:00
William Wernert
a959b4b2cd
[fix] Helix sensor needs so-soc and so-elasticsearch images downloaded
2020-12-16 11:00:48 -05:00
m0duspwnens
9fd2ab530e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-16 10:53:35 -05:00
William Wernert
142649b396
[fix] Fix comparator
2020-12-16 10:38:34 -05:00
William Wernert
e464117e8a
[fix] Run so-catrust in ES state on Helix sensor install
2020-12-16 10:19:44 -05:00
William Wernert
aa0d43b1db
[fix] Always define ismanager var
2020-12-16 09:55:09 -05:00
Josh Patterson
bdbb466d69
Merge pull request #2357 from Security-Onion-Solutions/fix/sensoroni_steno_pillar
...
Fix/sensoroni steno pillar
2020-12-16 09:40:06 -05:00
TOoSmOotH
8889c79afd
Run a common state first to fix docker race condition
2020-12-16 09:39:41 -05:00
m0duspwnens
448d0e079e
add whitespace removal to the front
2020-12-16 09:39:25 -05:00
m0duspwnens
f0999abd8e
add missing %
2020-12-16 09:38:21 -05:00
m0duspwnens
c68b87db56
set steno running default based on sensor role or not
2020-12-16 09:33:44 -05:00
William Wernert
a1fc354a89
[fix] Correct ordering of printf lines
2020-12-16 09:32:36 -05:00
TOoSmOotH
b858136672
Add jertel complaince
2020-12-16 09:24:59 -05:00
William Wernert
af149d04a9
[fix] Only run portions of ES state, do not run container
2020-12-16 09:18:40 -05:00
William Wernert
a4897d2063
[fix] Add Elasticsearch to containers running on Helix sensor
2020-12-16 09:07:38 -05:00
m0duspwnens
fffca7e0d8
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-16 08:59:39 -05:00
TOoSmOotH
805e25f495
Fix typeo
2020-12-15 20:40:59 -05:00
TOoSmOotH
4ca4141819
Fix conditional statement
2020-12-15 19:29:35 -05:00
TOoSmOotH
f1be6cc259
Check MD5 of all components
2020-12-15 18:32:07 -05:00
TOoSmOotH
e30d7a8d8e
Fix upgrade docker variable
2020-12-15 18:25:41 -05:00
TOoSmOotH
87882b4d91
Fix upgrade function
2020-12-15 18:18:26 -05:00
TOoSmOotH
082fd51b05
Remove extra variable
2020-12-15 17:07:40 -05:00
TOoSmOotH
04a26df4f7
Fix the features suffix
2020-12-15 17:05:33 -05:00
Jason Ertel
e3c8018824
Toggle strelka rules after the user is prompted it strelka should be installed to ensure strelka rules are updated later during the setup process
2020-12-15 16:44:52 -05:00
TOoSmOotH
7909834722
Clean up previous upgrade dirs in temp
2020-12-15 16:23:49 -05:00
Mike Reeves
06dd3432f8
Copy the correct files over that soup needs
2020-12-15 16:13:51 -05:00
Mike Reeves
6cab65a548
Update so-image-common
2020-12-15 16:06:21 -05:00
Jason Ertel
e58ca93896
Add logging for strelka configuration during setup
2020-12-15 15:46:59 -05:00
William Wernert
15347d1209
[fix] More condition changes for Helix
2020-12-15 15:08:33 -05:00
William Wernert
c7c3d004ca
[fix] More helix -> helixsensor
2020-12-15 14:01:19 -05:00
William Wernert
1825776271
[fix] helix -> helixsensor
2020-12-15 13:58:36 -05:00
William Wernert
951556902c
[fix] Accept salt key on Helix Sensor install
2020-12-15 13:41:00 -05:00
William Wernert
7ba10ee698
[fix] Add HELIXSENSOR to case for Ubuntu
2020-12-15 13:38:00 -05:00
William Wernert
343e9f8b2c
[fix] Only try to stop/remove containers if at least one exists
2020-12-15 13:37:46 -05:00
William Wernert
e89c06f71b
[fix] Add backslash for newline
2020-12-15 13:37:21 -05:00
William Wernert
f7d02763e8
[fix] Move FEATURESCHECK var assignment, fix indentation
2020-12-15 13:07:21 -05:00
William Wernert
f70d828aa6
[fix] Create array correctly
2020-12-15 13:04:09 -05:00
Jason Ertel
3da7a26e88
Remove jinja whitespace trimming to avoid syntax error in bash
2020-12-15 12:37:05 -05:00
Mike Reeves
922534a5da
Merge pull request #2352 from Security-Onion-Solutions/soup2320
...
SOUP Features
2020-12-15 12:07:19 -05:00
TOoSmOotH
80a61d3316
SOUP Features
2020-12-15 12:06:30 -05:00
Mike Reeves
bf1f00d2fe
Merge pull request #2348 from Security-Onion-Solutions/soup2320
...
SOUP Changes
2020-12-14 21:19:45 -05:00
TOoSmOotH
cbd59ed86a
SOUP Changes
2020-12-14 20:46:31 -05:00
Josh Brower
efe44323cb
Merge pull request #2346 from Security-Onion-Solutions/bugfix/fleet-patch
...
Swap localhost for 127.0.0.1
2020-12-14 15:49:58 -05:00
William Wernert
aa281f849f
[feat] Add message about dropping to command line when setting up ssh key
2020-12-14 15:31:25 -05:00
William Wernert
f4c4a16f54
Merge pull request #2343 from Security-Onion-Solutions/experimental
...
Experimental
2020-12-14 14:27:52 -05:00
Jason Ertel
aa479b9c8e
Move node address/desc into the minion pillar
2020-12-14 12:42:16 -05:00
William Wernert
3e2a9cc884
Merge branch 'dev' into experimental
2020-12-14 12:32:53 -05:00
William Wernert
a533e6fa35
[fix] Always set INSTALLUSERNAME var
2020-12-14 11:42:34 -05:00
m0duspwnens
3a66af0b16
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-14 11:36:03 -05:00
Josh Patterson
de3f86724a
Merge pull request #2335 from Security-Onion-Solutions/issue/1586
...
remove old firewall ports pillar file
2020-12-14 11:15:34 -05:00
m0duspwnens
4e04f31b8e
remove old firewall ports pillar file https://github.com/Security-Onion-Solutions/securityonion/issues/1586
2020-12-14 10:24:49 -05:00
m0duspwnens
32482710db
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-14 10:14:44 -05:00
Doug Burks
7a314b5935
Prevent Wazuh "last -n 20" logs from going to Alerts queue #2321
2020-12-12 11:35:29 -05:00
Doug Burks
61ae187d03
revert previous commit #2321
2020-12-12 10:12:23 -05:00
Josh Brower
73d23e6d17
Revert "Initial support - Playbook Overrides"
...
This reverts commit 8915e49288 .
2020-12-12 10:07:30 -05:00
Josh Brower
8faf80a03b
Revert "Playbook db updates"
...
This reverts commit 35be785f7a .
2020-12-12 10:07:23 -05:00
Mike Reeves
b5ed973abd
Merge pull request #2138 from OmerTirosh/OmerTirosh-fix-win.eventlog
...
Fix Error: SO elasticsearch ingest failed to convert 'winlog.event_data.SubjectUserName' to 'user.name'
2020-12-12 10:00:27 -05:00
Doug Burks
85aac4ad75
Prevent Wazuh "last -n 20" logs from going to Alerts queue #2321
2020-12-12 09:22:08 -05:00
Jason Ertel
fd7fe72b2a
Correct default address pool base value
2020-12-11 23:29:59 -05:00
Jason Ertel
c5a3597564
Swap AWS interfaces
2020-12-11 21:57:56 -05:00
Josh Brower
66495e6bae
Swap localhost for 127.0.0.1
2020-12-11 17:38:42 -05:00
Jason Ertel
42c8f1e325
Use eth0/eth1 instead of ens5/ens6 in AWS
2020-12-11 15:34:16 -05:00
Jason Ertel
bb61c1f745
Cleanup bash imports/sources, function definitions, and variables
2020-12-11 15:33:31 -05:00
Josh Patterson
e4eea6a616
Merge pull request #2320 from Security-Onion-Solutions/issue/2319
...
zeek file extraction can now be manipulated with zeek pillar
2020-12-11 14:38:10 -05:00
m0duspwnens
09b3a4a0dd
merge pillar with the defaults https://github.com/Security-Onion-Solutions/securityonion/issues/2319
2020-12-11 14:35:06 -05:00
m0duspwnens
b8e8510dd2
merge pillar with the defaults https://github.com/Security-Onion-Solutions/securityonion/issues/2319
2020-12-11 14:26:32 -05:00
m0duspwnens
95c068a37f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-11 14:13:48 -05:00
Jason Ertel
eb735c7289
Replace duplicate random generator with common function
2020-12-11 13:22:13 -05:00
Josh Patterson
2f2867804a
Merge pull request #2318 from Security-Onion-Solutions/issue/1175
...
pillarize grafana and allow for grafana alerts to be created
2020-12-11 12:36:06 -05:00
m0duspwnens
d877fac786
add null for max graph value https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 12:28:43 -05:00
m0duspwnens
c88a1a943d
update search and sensor node dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 12:21:16 -05:00
m0duspwnens
e3335a3106
update managersearch dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 12:00:02 -05:00
m0duspwnens
0a77a28e06
guage to graph cor cpu on manager and eval https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:51:42 -05:00
m0duspwnens
6eb64227ae
update manager dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:44:21 -05:00
m0duspwnens
5a95181b2b
update eval version 1 https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:36:19 -05:00
m0duspwnens
2fc151d923
update eval dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 11:34:08 -05:00
William Wernert
db276d9020
[fix] Always set hostname
2020-12-11 11:02:27 -05:00
m0duspwnens
33fde42dbc
dont show legend on pcap retention panel
2020-12-11 10:42:30 -05:00
m0duspwnens
e0e38ac37f
update standlone dashboard panaels from guage to graph https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-11 10:39:25 -05:00
William Wernert
75c5abef30
[fix] Add all selected options to install_opts
2020-12-11 10:16:00 -05:00
Jason Ertel
0915ae30e4
Add timestamps to so-yara-update output
2020-12-11 10:08:10 -05:00
Jason Ertel
14f28e38be
Ensure so-yara-updata script is logging to a file during cron job execution
2020-12-11 10:04:43 -05:00
William Wernert
870cc6b79b
[fix][typo] readaraay -> readarray
2020-12-11 09:39:22 -05:00
William Wernert
3c7a8fe92f
[fix] Don't cd in so-variables
2020-12-11 09:39:00 -05:00
William Wernert
b6a0e692c6
[refactor] Use command -v for netplan check
2020-12-11 09:38:44 -05:00
m0duspwnens
fbcc62d5c5
Merge remote-tracking branch 'remotes/origin/dev' into issue/1175
2020-12-10 15:17:45 -05:00
m0duspwnens
733f5a5021
allowUiUpdates to dashboards to allow for alert creation on stock dashboards issue/1175
2020-12-10 15:17:22 -05:00
William Wernert
25f2075e22
[fix] Revert bad change to whiptail_basic_zeek
2020-12-10 15:01:10 -05:00
William Wernert
5c4103681c
[fix] Save original argument array to use later
2020-12-10 14:45:24 -05:00
William Wernert
ab856532e6
[fix] Show airgap option on import install
2020-12-10 14:20:48 -05:00
William Wernert
58bcc79c54
[fix] Create full dir structure, rm /root/install_opt on failure
2020-12-10 14:17:47 -05:00
William Wernert
1f1cfde3ac
[fix] Make directory for new setup download
2020-12-10 14:03:54 -05:00
William Wernert
bc6a0c1e6f
[fix] Add missing append flags to tee
2020-12-10 13:54:41 -05:00
William Wernert
8302119756
[fix] Don't redirect entire download function to setup log
2020-12-10 13:26:19 -05:00
William Wernert
21e107f2e8
[fix] Remove sudo from version check, only remove known_hosts entry if exists
2020-12-10 13:13:45 -05:00
Mike Reeves
cd6a945a24
Merge pull request #2298 from Security-Onion-Solutions/escluster
...
Traditional ES Clustering Support
2020-12-10 12:07:17 -05:00
m0duspwnens
4ee944448f
remove $Interval template var since alerts cant be crated when it is used https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-10 12:05:57 -05:00
TOoSmOotH
42833b2086
Make non clustered node attributes
2020-12-10 11:14:32 -05:00
TOoSmOotH
d9d7f49b96
Adjust elasticsearch.yml
2020-12-10 11:09:38 -05:00
William Wernert
86313796a5
[fix] Set manager_ver in download function
2020-12-10 11:00:52 -05:00
weslambert
24fce27e62
Merge pull request #2297 from Security-Onion-Solutions/feature/idstools_arg
...
Add ability to supply an arg, for example overriding 15 min limit
2020-12-10 09:31:50 -05:00
Wes Lambert
45faa7fda4
Add ability to supply an arg, for example overriding 15 min limit
2020-12-10 14:30:29 +00:00
weslambert
c2cf2c4987
Merge pull request #2296 from Security-Onion-Solutions/fix/suricata_ftp_data
...
Add initial suricata.ftp_data pipeline
2020-12-10 09:17:01 -05:00
TOoSmOotH
379f1d98d8
fix addtotab
2020-12-10 09:15:17 -05:00
Wes Lambert
f689722559
Add initial suricata.ftp_data pipeline
2020-12-10 14:14:50 +00:00
weslambert
d09daef094
Merge pull request #2288 from Security-Onion-Solutions/fix/strelka_rules
...
Expand STRELKARULES
2020-12-09 17:05:44 -05:00
weslambert
0b2e2739bd
Expand STRELKARULES
2020-12-09 17:05:11 -05:00
m0duspwnens
ea1bd63f60
makedirs and place readme file for grafana https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 16:59:38 -05:00
TOoSmOotH
af15f0eb38
remove ml node.role
2020-12-09 16:23:38 -05:00
TOoSmOotH
101ddd18a5
Fix print statments
2020-12-09 16:08:09 -05:00
Mike Reeves
3a903501fd
Merge pull request #2286 from Security-Onion-Solutions/newescluster
...
Newescluster
2020-12-09 16:01:46 -05:00
m0duspwnens
8db79ae852
comment out some defaults file https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 16:01:09 -05:00
m0duspwnens
e05da4efc2
remove odl grafana.ini file https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 15:53:01 -05:00
Mike Reeves
30e69bf7b2
Merge branch 'escluster' into newescluster
2020-12-09 15:23:49 -05:00
TOoSmOotH
0a48f7d5dc
Simplify logic
2020-12-09 15:22:09 -05:00
m0duspwnens
c320efe7e4
fix whitespace https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 14:33:19 -05:00
m0duspwnens
617ed2a7c2
add a place to place files referenced in the config https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 14:06:54 -05:00
William Wernert
522399e4ab
Merge branch 'feature/setup' into experimental
2020-12-09 13:13:58 -05:00
William Wernert
a2e48f91b2
[fix] Add manager to hosts before attempting ssh
2020-12-09 13:13:51 -05:00
William Wernert
987008811c
[fix] Make repo directory before using it
2020-12-09 12:47:35 -05:00
m0duspwnens
c5c053d24a
change to header
2020-12-09 11:59:06 -05:00
m0duspwnens
75ea648cf9
change to file.managed https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 11:57:28 -05:00
William Wernert
e29fa7ba70
Merge branch 'feature/setup' into experimental
2020-12-09 11:51:18 -05:00
William Wernert
282b4090ce
[fix] Actually call nic comparison function, redirect tarball gen to setup_log
2020-12-09 11:51:07 -05:00
TOoSmOotH
e983322a18
Fix elastic if statement
2020-12-09 11:31:22 -05:00
m0duspwnens
6b479c5a89
pillarize grafana https://github.com/Security-Onion-Solutions/securityonion/issues/1175
2020-12-09 11:10:00 -05:00
William Wernert
223856c0b9
[fix] Don't redirect whiptail message, use SIGINT instead of SIGKILL
2020-12-09 10:16:42 -05:00
William Wernert
795cacecf3
[fix] Fix cut command options
2020-12-09 10:06:14 -05:00
William Wernert
f3ce2fc71e
[fix] new_setup -> manager_setup
2020-12-09 10:06:02 -05:00
William Wernert
51650147ef
[fix] Only show network init message if valid
2020-12-09 09:59:44 -05:00
William Wernert
950c05e53d
[fix] Only move error log if present
2020-12-09 09:50:30 -05:00
William Wernert
652c4d49c9
[fix] Remove extra semicolon
2020-12-09 09:47:57 -05:00
TOoSmOotH
6ceecbd524
Fixing some elasticsearch logic
2020-12-09 09:42:03 -05:00
William Wernert
a8f1ec37a3
[refactor] Remove is_smooshed var
2020-12-08 15:29:48 -05:00
William Wernert
813fe77582
[feat] Run so-analyst-install after network init
2020-12-08 15:29:31 -05:00
William Wernert
b41ba1ea3c
[feat] Compare setup version to manager, dl tarball + exec on mismatch
2020-12-08 15:29:04 -05:00
William Wernert
4899ea23f8
[fix] Put conditions in install_cleanup function
2020-12-08 14:03:59 -05:00
William Wernert
4210d25fae
[feat] Init network + soremote key early
2020-12-08 14:03:21 -05:00
William Wernert
65d994a2f8
[feat] Generate gzipped tarball of repo during setup and soup
2020-12-08 14:02:45 -05:00
William Wernert
997e2735e3
[refactor] Press -> select
2020-12-08 13:59:42 -05:00
TOoSmOotH
d6fa739c60
Adding queue=True
2020-12-08 11:17:47 -05:00
m0duspwnens
2b412b6a48
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-08 10:41:28 -05:00
Josh Brower
f34a10a986
Merge pull request #2259 from Security-Onion-Solutions/feature/playbook-updates2
...
Playbook db updates
2020-12-08 10:36:42 -05:00
Josh Brower
35be785f7a
Playbook db updates
2020-12-08 10:35:50 -05:00
Jason Ertel
5d955bcdb7
Enable new SoStatus module in SOC for managing grid status
2020-12-08 09:22:18 -05:00
Josh Brower
5f756549b1
Merge pull request #2254 from Security-Onion-Solutions/feature/playbook-updates2
...
Initial support - Playbook Overrides
2020-12-07 22:30:50 -05:00
Josh Brower
8915e49288
Initial support - Playbook Overrides
2020-12-07 22:28:58 -05:00
Josh Patterson
2d9c6a42bf
Merge pull request #2249 from Security-Onion-Solutions/issue/2188
...
Issue/2188
2020-12-07 16:52:34 -05:00
Josh Brower
35ea6c36d2
Merge pull request #2247 from Security-Onion-Solutions/feature/so-suricata-ruletest
...
so-suricata-testrule initial commit
2020-12-07 15:12:20 -05:00
William Wernert
64dc9f8d4e
[fix] Only list ipv4 addresses when checking mysql
2020-12-07 14:40:32 -05:00
William Wernert
d88364c9fd
[feat] Create error log for easy copy/paste
...
Resolves #2165
2020-12-07 14:18:01 -05:00
William Wernert
08ab36927d
[refactor] Kill parent script on exit
2020-12-07 14:16:54 -05:00
William Wernert
6fc3232637
[fix] Set INSTALLUSERNAME to the user running the script
...
Resolves #2243
2020-12-07 14:16:06 -05:00
William Wernert
4363b082bb
Merge branch 'dev' into feature/setup
2020-12-07 14:15:11 -05:00
Mike Reeves
8ea088c3fc
Restart Elastic on addition of node.
2020-12-07 14:09:41 -05:00
m0duspwnens
b5e0b21400
Merge remote-tracking branch 'remotes/origin/dev' into issue/2188
2020-12-07 11:52:09 -05:00
m0duspwnens
19d27c7d68
remove docker-ce-cli from common state
2020-12-07 11:50:47 -05:00
William Wernert
38324c226e
[fix] Don't let grep output message on file not found
2020-12-07 10:58:58 -05:00
m0duspwnens
4fe2de2637
upgrade docker https://github.com/Security-Onion-Solutions/securityonion/issues/2188
2020-12-07 10:47:20 -05:00
William Wernert
edc8ccd1b6
Merge branch 'feature/main-ip-validation' into feature/setup
2020-12-07 09:53:38 -05:00
m0duspwnens
81e914ab23
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-07 09:38:04 -05:00
William Wernert
3136c66780
[fix] Bring back network setup before setting MAINIP var
2020-12-07 08:50:53 -05:00
Josh Brower
134d9bc89a
so-suricata-testrule initial commit
2020-12-06 17:08:11 -05:00
William Wernert
d724fe7357
Merge pull request #2201 from Security-Onion-Solutions/bugfix/reinstall
...
Bugfix/reinstall
2020-12-04 09:38:46 -05:00
William Wernert
fca50660a2
[fix] Trap argument off by one
2020-12-04 09:33:28 -05:00
William Wernert
1c1b835c71
Merge branch 'bugfix/reinstall' into experimental
2020-12-03 15:44:04 -05:00
William Wernert
7b43c2955e
[fix] kill old restart pid and assign new pid for start
2020-12-03 15:42:15 -05:00
William Wernert
ff1cfb578f
Only kill+start on final loop and increase time between status checks
2020-12-03 15:42:15 -05:00
William Wernert
7458313d3d
[fix] Also kill+start while trying to restart service initially
2020-12-03 15:42:15 -05:00
William Wernert
39dce13cf6
[fix] Move set_redirect out of sub-shell
2020-12-03 15:42:15 -05:00
William Wernert
916db4acec
[fix] kill/start after if statement
2020-12-03 15:42:15 -05:00
William Wernert
2e516629f9
[fix] Kill + start salt-minion if it isn't responding
2020-12-03 15:42:15 -05:00
William Wernert
3273a63662
[fix] kill old restart pid and assign new pid for start
2020-12-03 15:38:26 -05:00
William Wernert
660c768f8f
Only kill+start on final loop and increase time between status checks
2020-12-03 15:38:26 -05:00
William Wernert
ebade0a5a6
[fix] Also kill+start while trying to restart service initially
2020-12-03 15:38:26 -05:00
William Wernert
ac85cbc3f1
[fix] Move set_redirect out of sub-shell
2020-12-03 15:38:26 -05:00
William Wernert
b5bfad07dc
[fix] kill/start after if statement
2020-12-03 15:38:26 -05:00
William Wernert
3049718660
[fix] Kill + start salt-minion if it isn't responding
2020-12-03 15:38:25 -05:00
William Wernert
80ce8b5e41
[refactor] Run all changes inside whiptail progress, use grep -q
2020-12-03 15:38:25 -05:00
William Wernert
2c208ec943
[fix] kill -> stop, add indent to service check, revert incorrect logic
2020-12-03 15:38:25 -05:00
William Wernert
76fff28dfa
[fix] Correct logic for service check + bash trap
2020-12-03 15:38:25 -05:00
William Wernert
af8295a651
[reafactor] systemctl stop -> kill
2020-12-03 15:38:25 -05:00
William Wernert
ddcf5dec5b
[refactor] Run all changes inside whiptail progress, use grep -q
2020-12-03 13:59:25 -05:00
Jason Ertel
967111decc
Add node address to sensoroni pillar
2020-12-03 11:24:45 -05:00
Mike Reeves
94253e92a6
Adjust the elasticsearch config
2020-12-03 10:38:18 -05:00
William Wernert
f410c451cd
[fix] kill -> stop, add indent to service check, revert incorrect logic
2020-12-03 10:31:45 -05:00
William Wernert
786665d8cf
[fix] Correct logic for service check + bash trap
2020-12-03 10:18:44 -05:00
weslambert
c41d4373b7
Merge pull request #2192 from Security-Onion-Solutions/fix/elasticsearch_bool_query_clause_count
...
Add indices.query.bool.max_clause_count to allow for wildcard searche…
2020-12-03 09:30:24 -05:00
weslambert
95570976a8
Add indices.query.bool.max_clause_count to allow for wildcard searches targeting more than 1024 fields
2020-12-03 09:29:44 -05:00
weslambert
a84f816eff
Merge pull request #2189 from Security-Onion-Solutions/feature/so-elastic-scripts
...
so-elastic scripts
2020-12-03 09:20:47 -05:00
Wes Lambert
4ce3ec7582
Make scripts executable
2020-12-03 14:18:22 +00:00
Wes Lambert
f96365baba
Add intial grouped Elastic start/stop/restart scripts
2020-12-03 14:17:32 +00:00
William Wernert
9c919f3c92
[reafactor] systemctl stop -> kill
2020-12-02 17:07:49 -05:00
Jason Ertel
cf0ec2f78f
Default to the node's primary IP for the description field
2020-12-02 16:38:33 -05:00
Mike Reeves
3e322c38eb
Fix config for single cluster mode
2020-12-02 15:33:35 -05:00
William Wernert
46d2342c8b
Merge branch 'bugfix/reinstall' into experimental
2020-12-02 14:45:46 -05:00
Mike Reeves
d004263b71
Add Elastic Clustering
2020-12-02 14:33:22 -05:00
William Wernert
fc7fe23590
[fix] Correct signal naming
2020-12-02 14:06:50 -05:00
William Wernert
cc5d54764a
[fix] sed masks command return code, remove
2020-12-02 13:54:02 -05:00
William Wernert
8fe43d6d56
[fix] Print WARNING instead of ERROR if minion is not responding initially
2020-12-02 13:35:57 -05:00
Mike Reeves
69ae4577f5
Merge pull request #2174 from Security-Onion-Solutions/escluster
...
Escluster
2020-12-02 13:23:08 -05:00
William Wernert
467f9923b0
[refactor] Add trap to handle script exits, change what files are deleted in /etc/salt/
2020-12-02 13:19:34 -05:00
weslambert
c819729cd6
Don't use max_files or time_to_live for shutdown params
2020-12-02 13:17:19 -05:00
m0duspwnens
8983ff994c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-02 13:08:15 -05:00
Josh Patterson
54d8dcdbb0
Merge pull request #2173 from Security-Onion-Solutions/issue/2079
...
Issue/2079
2020-12-02 11:46:29 -05:00
William Wernert
2d4fe58299
[fix] Also kill currently running jobs
2020-12-01 21:43:38 -05:00
William Wernert
4b5b936abb
[fix] echo -> return
2020-12-01 21:40:41 -05:00
William Wernert
2d6feea5c5
[fix] Syntax fixes
2020-12-01 21:21:32 -05:00
William Wernert
38028a543a
[feat] Add timeout for salt services to stop during reinstall init
2020-12-01 21:18:24 -05:00
Jason Ertel
b7bc8db3b2
Modify PCAP quick action to work off of network community ID; Add new Correlate quick action
2020-12-01 17:37:44 -05:00
Jason Ertel
81b86bf7f2
Switch PCAP quick actions to support alternative lookup link when a single event ID is not available
2020-12-01 16:04:50 -05:00
m0duspwnens
ff6951cd95
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/2079
2020-12-01 15:38:15 -05:00
m0duspwnens
141d7a35c9
if true cluster enabled allow search nodes to talk to each other https://github.com/Security-Onion-Solutions/securityonion/issues/2079
2020-12-01 15:38:09 -05:00
William Wernert
c2e7e42509
[fix] Don't SIGKILL salt services + disable highstate schedule
2020-12-01 15:36:05 -05:00
weslambert
0e8f547087
Merge pull request #2160 from Security-Onion-Solutions/fix/strelka_mmbot
...
Remove ScanMmbot
2020-12-01 11:26:14 -05:00
weslambert
9517cb2a58
Remove ScanMmbot
2020-12-01 11:25:51 -05:00
m0duspwnens
3ee562a243
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-01 09:28:27 -05:00
Josh Brower
c303cdff09
Merge pull request #2150 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fleet Fixes - mysql race condition
2020-11-30 18:06:30 -05:00
Josh Brower
e7a927188b
Fleet Fixes - mysql race condition
2020-11-30 17:28:11 -05:00
William Wernert
8a8885e14f
[feat] Verify that main ip = mngmt ip
...
* Add a check to check whether the src ip in the routing table is also the ip assigned to the management nic
2020-11-30 16:53:02 -05:00
Josh Brower
8e9458ca84
Merge pull request #2149 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fix Fleet setup errors
2020-11-30 12:06:36 -05:00
Josh Brower
5d2acf4011
Fix Fleet setup errors
2020-11-30 12:06:02 -05:00
William Wernert
8964444eeb
[fix] Correct count print in mysql_conn
2020-11-30 11:32:43 -05:00
William Wernert
ec81e8565f
[fix] Add safety logic to retry var in mysql_conn
2020-11-30 11:32:28 -05:00
William Wernert
040b435278
[refactor] Fail mysql_conn if the mainint has > 1 ip address
2020-11-30 11:10:50 -05:00
m0duspwnens
ae464c38b2
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-30 11:04:34 -05:00
Josh Brower
704f024441
Merge pull request #2146 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fleet standalone - fix event
2020-11-30 10:33:05 -05:00
Josh Brower
65d8005629
Fleet standalone - fix event
2020-11-30 10:32:39 -05:00
Josh Brower
7fddf99648
Merge pull request #2128 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fix Fleet setup errors
2020-11-27 13:59:19 -05:00
Josh Brower
f52c30bff5
Fix Fleet setup errors
2020-11-27 13:58:41 -05:00
Josh Brower
19a33c5c2a
Merge pull request #2126 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Bugfix/fleet standalone
2020-11-27 11:45:25 -05:00
Josh Brower
19b36f0468
Fleet standalone redirect fix
2020-11-27 11:43:51 -05:00
Josh Brower
95a664e12a
Merge pull request #2103 from Security-Onion-Solutions/bugfix/fleet-standalone
...
Fleet standalone fix
2020-11-25 14:09:27 -05:00
Josh Brower
38afd67108
Fleet standalone fix
2020-11-25 14:08:30 -05:00
Jason Ertel
979f171828
Add missing comma to sensoroni.json
2020-11-25 12:29:45 -05:00
Jason Ertel
8f9081618f
Add role to sensoroni.json file
2020-11-25 11:11:46 -05:00
Jason Ertel
7fb264b4fe
Use double quotes around agent key to ensure interpolation
2020-11-24 17:17:50 -05:00
Jason Ertel
d20560385f
Remove /nsm/wazuh/etc subdir state since confirmed the Wazuh docker container itself
2020-11-24 16:50:46 -05:00
Jason Ertel
e1147398cc
Ensure /nsm/wazuh is owned by ossec
2020-11-24 15:48:46 -05:00
Jason Ertel
8864428a00
Ensure setup output is redirected to logfile
2020-11-24 15:45:40 -05:00
m0duspwnens
5f0f20918b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-24 14:33:05 -05:00
Jason Ertel
ea9bbfd1aa
Improve wazuh agent registration with retry logic to wait for manager to become ready
2020-11-24 13:53:20 -05:00
weslambert
0c4ee94472
Merge pull request #2077 from Security-Onion-Solutions/fix/thehive_upgrade_conf
...
Fix/thehive upgrade conf
2020-11-24 11:52:51 -05:00
weslambert
39bf60feb7
Add digit
2020-11-24 11:52:20 -05:00
weslambert
35653d2e66
Changes for ES7
2020-11-24 11:51:19 -05:00
weslambert
eb2364b926
Changes for ES7
2020-11-24 11:49:08 -05:00
Josh Patterson
9bb485cdc9
Merge pull request #2074 from Security-Onion-Solutions/issue/2040
...
Issue/2040
2020-11-24 11:45:08 -05:00
m0duspwnens
fe2662cab8
dont enable steno pillar on import node https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 11:42:03 -05:00
m0duspwnens
995a377432
squigly comma if steno enabled https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 11:31:41 -05:00
weslambert
e3a41c2a94
Changes for ES7 elasticsearch.yml
2020-11-24 11:20:09 -05:00
Mike Reeves
ddca9563e5
Merge branch 'mkrmerge' into escluster
2020-11-24 10:29:57 -05:00
OmerTirosh
e2ee0db727
Ignore failure for rename processor
...
Ignore failure for winlog.event_data.SubjectUserName rename processor.
For some event ids (for example 4688), this field already been added in winlogbeat JS processor.
Therefor, elastic throw [user.name] already exists error.
2020-11-24 17:21:47 +02:00
m0duspwnens
4dfd49ef39
add vars https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 10:11:28 -05:00
m0duspwnens
65334d15ea
https://github.com/Security-Onion-Solutions/securityonion/issues/2040
2020-11-24 09:33:38 -05:00
Jason Ertel
1e32a01657
Create symlink before registration otherwise registration script can't save it's state (.log) file into the conf subdir; add more logging output to track down registration failures
2020-11-23 18:36:19 -05:00
m0duspwnens
ae7672f395
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-23 13:44:38 -05:00
Jason Ertel
bafefb980b
Update so-elastalert-test script for compatibility with SO 2.3
2020-11-23 10:45:56 -05:00
m0duspwnens
22ebb5af03
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-23 09:29:18 -05:00
Mike Reeves
426769588a
Merge pull request #1739 from jtgreen-cse/patch-2
...
fix for Windows events via osquery
2020-11-21 13:27:05 -05:00
Josh Patterson
a183be489c
Merge pull request #2030 from Security-Onion-Solutions/master
...
Merge master to dev
2020-11-20 17:00:31 -05:00
Josh Patterson
b29ffcac92
Merge pull request #2029 from Security-Onion-Solutions/soup-ubuntu-salt
...
fix issue with proper salt.minion state execution for ubuntu
2020-11-20 16:55:45 -05:00
Jason Ertel
78f5727f6f
Improve so-ip-update prompts
2020-11-20 15:16:07 -05:00
m0duspwnens
0d3754200f
fix issue with proper salt.minion state execution for ubuntu
2020-11-20 14:27:07 -05:00
Jason Ertel
bc40a2bfc5
Correct so-import-pcap wrapping; add so-pcap-import alias for so-import-pcap; prompt to reboot after changing IP address on manager; ensure all tools have exec bit set
2020-11-20 14:14:03 -05:00
Jason Ertel
f074179656
Correct so-import-pcap wrapping; add so-pcap-import alias for so-import-pcap; prompt to reboot after changing IP address on manager; ensure all tools have exec bit set
2020-11-20 14:14:03 -05:00
William Wernert
b6e36d4d06
Merge pull request #2023 from Security-Onion-Solutions/bugfix/bug-hunt
...
Bugfix/bug hunt
2020-11-20 13:04:33 -05:00
William Wernert
2e6be747d9
[fix] Fixes for quiet flag in so-ssh-harden
2020-11-20 11:18:40 -05:00
William Wernert
1a11c24f03
[fix] Add newline escapes to so-ssh-harden
2020-11-20 11:13:40 -05:00
m0duspwnens
d178a7c5f3
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-20 10:32:32 -05:00
William Wernert
d15064b294
Merge branch 'dev' into bugfix/bug-hunt
2020-11-20 10:15:52 -05:00
William Wernert
d3ef46a5f6
Merge pull request #2020 from Security-Onion-Solutions/bugfix/pre-whiptail-message
...
[fix] Remove echo redirect at beginning of install
2020-11-20 10:15:24 -05:00
William Wernert
9d837f7b45
[fix] Reload sshd if config changes are made
...
Fixes #1976
2020-11-20 10:09:14 -05:00
William Wernert
e62b52da1b
[fix] Add condition to zeek state during setup for ZEEKVERSION
...
Fixes #1990
2020-11-20 09:58:07 -05:00
William Wernert
79ec1de83a
[fix] Add exit check for static ip whiptail menus
...
Fixes #1992
2020-11-20 09:56:48 -05:00
m0duspwnens
762441fdda
merge
2020-11-20 08:57:48 -05:00
Jason Ertel
9fb8a6d482
Increment version to 2.3.20
2020-11-19 16:53:34 -05:00
Mike Reeves
5344d30d56
Merge pull request #2003 from Security-Onion-Solutions/dev
...
2.3.10
2020-11-19 16:48:53 -05:00
Mike Reeves
4051111999
Update hashes and keys
2020-11-19 16:00:40 -05:00
Mike Reeves
316a1c02f1
Update soup to display what its doing
2020-11-19 15:19:50 -05:00
Josh Patterson
c07f62f8d1
Merge pull request #2007 from Security-Onion-Solutions/fix/minon
...
kill salt process with soup and dont restart salt-minion service when…
2020-11-19 15:17:58 -05:00
m0duspwnens
cdc7a5cc7c
kill salt process with soup and dont restart salt-minion service when salt upgrade
2020-11-19 15:17:11 -05:00
Josh Patterson
10a3e6f414
Merge pull request #2006 from Security-Onion-Solutions/fix/minon
...
change typo on minon to minion
2020-11-19 15:11:16 -05:00
m0duspwnens
2a3951ab36
change typo on minon to minion
2020-11-19 15:08:08 -05:00
m0duspwnens
868286a58a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-19 15:06:10 -05:00
m0duspwnens
146c1a4d75
fix typos of minon to minion
2020-11-19 15:06:06 -05:00
Mike Reeves
67a8c4e8cb
Update Readme
2020-11-19 11:27:15 -05:00
Mike Reeves
177819447b
Update Sigs and Hashes
2020-11-19 11:26:08 -05:00
Mike Reeves
3be1c9ae32
Clean up 2.3.1 dockers
2020-11-19 09:58:08 -05:00
William Wernert
ac3b5e4f1b
[fix] Remove echo redirect at beginning of install
2020-11-19 09:48:56 -05:00
Josh Brower
b79e1c3225
Merge pull request #1987 from Security-Onion-Solutions/bugfix/playbookdb-user
...
playbook mysqluser
2020-11-18 20:48:49 -05:00
Josh Brower
d3065005ca
playbook mysqluser
2020-11-18 20:48:02 -05:00
Josh Patterson
26e97d5875
Merge pull request #1984 from Security-Onion-Solutions/salt/3002.2
...
upgrade from salt 3002.1 to salt 3002.2
2020-11-18 18:26:11 -05:00
m0duspwnens
d68726f6ef
upgrade from salt 3002.1 to salt 3002.2
2020-11-18 18:25:02 -05:00
Josh Patterson
f81da406da
Merge pull request #1983 from Security-Onion-Solutions/soup-verify-salt
...
dont highstate, just restart salt-minion
2020-11-18 17:40:36 -05:00
m0duspwnens
afd466cd2b
dont highstate, just restart salt-minion
2020-11-18 17:27:25 -05:00
Josh Patterson
6d228a836f
Merge pull request #1982 from Security-Onion-Solutions/soup-verify-salt
...
add -X so bootstrap doesnt try to start salt-minion during soup
2020-11-18 16:45:05 -05:00
m0duspwnens
1805effdc0
add -X so bootstrap doesnt try to start salt-minion during soup
2020-11-18 16:32:53 -05:00
Jason Ertel
1170b04a87
Update changes for 2.3.10
2020-11-18 16:18:00 -05:00
Josh Patterson
c0b43d3319
Merge pull request #1981 from Security-Onion-Solutions/soup-verify-salt
...
add back -s
2020-11-18 15:50:04 -05:00
m0duspwnens
6cc9d1c076
add back -s
2020-11-18 15:49:30 -05:00
William Wernert
1c55bb6db2
[fix] Only backup /nsm/mysql and /nsm/wazuh
2020-11-18 15:34:40 -05:00
Josh Brower
3d0003555a
Merge pull request #1980 from Security-Onion-Solutions/bugfix/soup-regen-osquery
...
SOUP - Regen Osquery Packages
2020-11-18 14:56:23 -05:00
Josh Brower
0830f63c4e
SOUP - Regen Osquery Packages
2020-11-18 14:55:14 -05:00
Josh Patterson
adbd8d6956
Merge pull request #1979 from Security-Onion-Solutions/soup-verify-salt
...
Soup verify salt
2020-11-18 14:49:03 -05:00
William Wernert
80d0080f70
[fix] Only set is_reinstall if it's needed
2020-11-18 14:47:53 -05:00
m0duspwnens
af6e14dc6f
highstate , merge with dev fix conflict
2020-11-18 14:47:40 -05:00
William Wernert
8b6b7cbd11
[fix] Check if $is_reinstall is true
2020-11-18 14:46:22 -05:00
William Wernert
e65c53dbb1
[fix] Don't rename /nsm/docker-registry
2020-11-18 14:01:33 -05:00
m0duspwnens
ceef07b74b
remove pkill
2020-11-18 14:00:01 -05:00
William Wernert
280cde43ff
[fix] install_type -> setup_type
2020-11-18 13:51:55 -05:00
William Wernert
81b9658499
[fix] Don't remove accept_changes file
2020-11-18 13:51:55 -05:00
weslambert
04c6bed779
Merge pull request #1977 from Security-Onion-Solutions/fix/zeek_log_inode_cleanup
...
Change clean_removed to true to clean up tracking of Zeek logs removed fr…
2020-11-18 13:49:46 -05:00
weslambert
6b4af30fc1
Change clean_removed to true cleanup tracking of Zeek logs removed from current
2020-11-18 13:47:32 -05:00
m0duspwnens
1e2b404836
remove -s
2020-11-18 13:29:42 -05:00
m0duspwnens
276c011a4f
queue state and change upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 13:22:11 -05:00
William Wernert
34fd80182e
[fix][wip] Don't use variable for accept_changes file
2020-11-18 12:54:36 -05:00
Jason Ertel
57e9f69c97
Add new so-ip-update script (Work in progress)
2020-11-18 12:35:38 -05:00
William Wernert
0542e0aa04
[fix] info -> title
2020-11-18 12:35:16 -05:00
m0duspwnens
d0e7b5b55a
only ensure salt-minion service is running if salt is on right verison https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 12:32:21 -05:00
William Wernert
ad74b4b3e0
[refactor][fix] Update reinstall logic
...
* Only set reinstall flag if new accept_changes file exists
* Instead of stopping highstate from running, kill all salt processes and remove their configs
* Make end of non-reinstall logs clear in cases where user cancels (and log not rotated)
2020-11-18 12:29:54 -05:00
m0duspwnens
ce70e0a61f
changes to upgradecommand https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 11:51:28 -05:00
William Wernert
8a4defcffa
[refactor] Check for setup log earlier
...
* Check for sosetuo.log before any scripts besides so-variables are sourced to make sure the log hasn't been created yet.
2020-11-18 11:16:36 -05:00
m0duspwnens
bddc3d6df9
kill all salt-minion again since they hang and redirect highstate to a logfile
2020-11-18 10:40:23 -05:00
m0duspwnens
4bb1ad9799
dont restart or kill salt-minon in upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 09:29:09 -05:00
William Wernert
bc0c395b7f
Merge pull request #1963 from Security-Onion-Solutions/feature/rem-so-setup-perm-entry
...
Feature/rem so-setup perm entry
2020-11-18 09:12:25 -05:00
m0duspwnens
67dc71ab49
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-18 08:36:23 -05:00
m0duspwnens
c95619d335
change upgradecommand order https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-18 08:35:56 -05:00
Jason Ertel
bfbc0f354c
Only default to logging out to tty if tty exists as a character device
2020-11-17 22:48:40 -05:00
m0duspwnens
5c6e9e0e3a
run a highstate and let that start the salt-minion back up https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 19:40:42 -05:00
m0duspwnens
7291d64e82
pkill salt-minion before restartiong salt-minion service https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 18:38:01 -05:00
m0duspwnens
695cce0b50
upgrad command changes https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 17:54:56 -05:00
m0duspwnens
42126f125b
change verison check to !=
2020-11-17 17:00:59 -05:00
m0duspwnens
2bfc48be35
change check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:31:11 -05:00
m0duspwnens
7d1cf56160
change check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:29:35 -05:00
m0duspwnens
1fd2196dd5
fix check of salt was upgraded during soup for ubuntu and centos
2020-11-17 16:18:50 -05:00
m0duspwnens
65b84f1bd7
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-17 16:09:47 -05:00
m0duspwnens
fcfd3e3758
change location yum/apt verison locks https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 16:09:30 -05:00
William Wernert
ee3708a428
[fix] Move sudoers check in soup to correct place + fix styling issue
2020-11-17 15:44:20 -05:00
William Wernert
b146700303
[feat] Remove so-setup permission from sudoers file after iso setup
...
Closes #1701
2020-11-17 15:36:25 -05:00
Jason Ertel
1ec8b52353
Replace scan.exiftool.* fields due to reduction in strelka field counts
2020-11-17 15:12:06 -05:00
Josh Patterson
f8346cde08
Merge pull request #1962 from Security-Onion-Solutions/soup-verify-salt
...
Soup verify salt
2020-11-17 15:08:32 -05:00
m0duspwnens
e162be2e1d
change salt upgrade command https://github.com/Security-Onion-Solutions/securityonion/issues/1961
2020-11-17 14:29:39 -05:00
m0duspwnens
4f4f64a47d
Merge remote-tracking branch 'remotes/origin/dev' into soup-verify-salt
2020-11-17 13:16:18 -05:00
m0duspwnens
4cd1086efa
new way for soup to install and resart salt for upgrade
2020-11-17 13:15:55 -05:00
Mike Reeves
2184c3b8ee
Revert "The Hive ES update"
...
This reverts commit 88c2ee0d36 .
2020-11-17 12:51:42 -05:00
Mike Reeves
65d28f98b5
Revert "The Hive ES Update"
...
This reverts commit f31d459a24 .
2020-11-17 12:51:13 -05:00
Jason Ertel
aa8d9c12a0
Remove yara rule update that can't succeed since the script doesn't exist at this point of the setup process
2020-11-17 12:15:27 -05:00
Mike Reeves
f31d459a24
The Hive ES Update
2020-11-17 11:59:03 -05:00
Mike Reeves
88c2ee0d36
The Hive ES update
2020-11-17 11:58:22 -05:00
Jason Ertel
d13733e716
Queue the registry state in case a highstate is already active
2020-11-17 09:59:09 -05:00
Josh Patterson
86922a2388
Merge pull request #1959 from Security-Onion-Solutions/soup-verify-salt
...
verify new salt version is installed during soup if not, exit before proceeding
2020-11-17 09:53:08 -05:00
m0duspwnens
65440f9aef
verify new salt version is installed during soup if not, exit before proceeding
2020-11-17 09:51:28 -05:00
William Wernert
12c661101a
Merge pull request #1958 from Security-Onion-Solutions/feat/require-min-nics
...
Feat/require min nics
2020-11-17 09:49:09 -05:00
William Wernert
79b63ed14b
[fix] Use singular when needed for requirements
2020-11-17 09:47:08 -05:00
Josh Brower
cc4357d567
Merge pull request #1954 from Security-Onion-Solutions/bugfix/ingest-mappings
...
Cleanup & fix sysmon pid ingest
2020-11-17 09:05:31 -05:00
Jason Ertel
b9267ee015
Add missing newline after armor header
2020-11-17 09:00:02 -05:00
Jason Ertel
5c310327e4
Merge pull request #1942 from Security-Onion-Solutions/jertel/refactor-seed
...
Jertel/refactor seed
2020-11-16 18:46:28 -05:00
Jason Ertel
4311f66110
Remove unnecessary redirect
2020-11-16 16:58:09 -05:00
Josh Patterson
a8644478b5
Merge pull request #1939 from Security-Onion-Solutions/fix/nginx-nonmanager
...
fix nginx for non manaager/fleet nodes
2020-11-16 16:47:39 -05:00
m0duspwnens
4436f02f6d
fix nginx for non manaager/fleet nodes
2020-11-16 16:46:22 -05:00
Jason Ertel
3cf8afc1dd
Remove unused redirect descriptors and ensure gpg import output is not leaked to console
2020-11-16 16:39:54 -05:00
Josh Patterson
f1e33b6eea
Merge pull request #1938 from Security-Onion-Solutions/fix/so.status-module
...
fix so-status to work with so.status module and change padding
2020-11-16 16:35:08 -05:00
m0duspwnens
0d9b22fe2d
fix so-status to work with so.status module and change padding
2020-11-16 16:33:29 -05:00
William Wernert
a08923030b
[feat] Exit setup if less than required number of NICs present
2020-11-16 16:26:38 -05:00
Jason Ertel
1ec4af1a4d
Destroy the old registry before updating SO images
2020-11-16 15:41:15 -05:00
Jason Ertel
5ae78d4108
Install curl in order to test for cloud
2020-11-16 15:31:40 -05:00
Jason Ertel
3bae243915
Continued refactoring of bash
2020-11-16 15:20:00 -05:00
Jason Ertel
8234b6f835
Switch remaining containers over to new registries; Continued bash refactoring
2020-11-16 15:11:08 -05:00
Josh Patterson
55231eab25
Merge pull request #1934 from Security-Onion-Solutions/fix/so-status-in-setup
...
redirect output from setting up so-status stuff in so-setup
2020-11-16 14:57:58 -05:00
m0duspwnens
e956ee9324
redirect output from setting up so-status stuff in so-setup
2020-11-16 14:56:20 -05:00
Jason Ertel
a343e3f31e
Save descriptors while inside the progress pipe
2020-11-16 14:10:48 -05:00
Jason Ertel
2ff738a61c
Refactor docker_seed_registry to eliminate duplicate logic
2020-11-16 13:27:23 -05:00
William Wernert
c226c1d902
[fix] Redirect stderr when checking for link state
2020-11-16 11:30:47 -05:00
Josh Patterson
7a49c55ea0
Merge pull request #1930 from Security-Onion-Solutions/issue/1831
...
Issue/1831
2020-11-16 10:09:49 -05:00
m0duspwnens
cc50eba6cb
make sure /opt/so/log/salt/so-salt-minion-check gets touched even if salt-minon verison isnt correct https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-16 10:01:40 -05:00
m0duspwnens
5c25dcf192
add /opt/so/log/salt/so-salt-minion-check to log rotate https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-16 09:50:10 -05:00
Jason Ertel
c744d389f7
More bash cleanup
2020-11-15 10:44:14 -05:00
Jason Ertel
76c917d977
Continued bash cleanup
2020-11-15 09:57:12 -05:00
Josh Brower
1908a68330
Cleanup & fix sysmon pid ingest
2020-11-14 16:19:23 -05:00
Jason Ertel
d22040fb5d
Annual fall bash cleanup event
2020-11-14 11:53:31 -05:00
Jason Ertel
372f694cc1
Set curl type to 'features' when adding features to existing installation
2020-11-14 11:04:40 -05:00
Jason Ertel
1c079f7ff4
Remove duplicate docker pull/sigverify logic from so-features-enable; Provide current SO version to curl
2020-11-14 10:35:45 -05:00
m0duspwnens
4e6e29e7dc
update logging
2020-11-13 20:26:06 -05:00
m0duspwnens
43a244e0da
change log path https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 19:37:03 -05:00
m0duspwnens
e958246457
touch file at start of highstate, just kill salt dont systemctl stop it https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 19:34:17 -05:00
m0duspwnens
b210092534
logging changes issue/1831
2020-11-13 19:09:53 -05:00
m0duspwnens
e820c6fa42
logging changes issue/1831
2020-11-13 19:04:09 -05:00
m0duspwnens
71a409f210
fix threshold logic https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 18:23:55 -05:00
m0duspwnens
a5823be0ac
fix typo
2020-11-13 17:55:19 -05:00
Mike Reeves
13c261178a
fix soup so-image-common
2020-11-13 17:26:04 -05:00
m0duspwnens
2f0eaff8b3
sbin
2020-11-13 17:25:45 -05:00
Mike Reeves
977eea131e
fix soup so-image-common
2020-11-13 17:18:55 -05:00
Mike Reeves
fb9b07b0eb
fix soup so-image-common
2020-11-13 17:13:05 -05:00
m0duspwnens
6a010bb3e6
change var name
2020-11-13 17:08:47 -05:00
Mike Reeves
51b3e066be
fix soup so-image-common
2020-11-13 17:01:42 -05:00
Mike Reeves
7dfb8f5b12
fix soup so-image-common
2020-11-13 16:50:12 -05:00
Mike Reeves
23f2dee840
fix soup so-image-common
2020-11-13 16:30:34 -05:00
m0duspwnens
4275fcbf22
Merge remote-tracking branch 'remotes/origin/dev' into issue/1831
2020-11-13 16:28:58 -05:00
Jason Ertel
ee97f5eaac
Remove unnecessary branch var; allow skipping of tag/push step
2020-11-13 16:17:09 -05:00
m0duspwnens
0a807621cc
check health of salt-minion https://github.com/Security-Onion-Solutions/securityonion/issues/1831
2020-11-13 16:02:28 -05:00
Mike Reeves
8577fa63a3
fix network install download
2020-11-13 14:28:27 -05:00
Mike Reeves
50175f7e42
soup should now copy the common image functions
2020-11-13 14:25:29 -05:00
Mike Reeves
3173c6fd3c
Change user agent string for docker refresh
2020-11-13 14:09:29 -05:00
Mike Reeves
069908ec56
Change user agent string for docker refresh
2020-11-13 13:55:26 -05:00
Mike Reeves
09f3199cc2
Change user agent string for docker refresh
2020-11-13 13:39:52 -05:00
Josh Brower
adec9ad48b
Merge pull request #1916 from Security-Onion-Solutions/feature/so-playbook-reset
...
Feature/so playbook reset
2020-11-13 11:21:50 -05:00
Josh Brower
8b3262ce1b
Add so-playbook-reset
2020-11-13 11:20:39 -05:00
weslambert
4fad0e3a98
Merge pull request #1914 from Security-Onion-Solutions/fix/syslog_parsing
...
Syslog updates
2020-11-13 11:07:53 -05:00
Wes Lambert
fddfb8eb92
Syslog updates
2020-11-13 16:06:22 +00:00
Jason Ertel
210a7bc65b
Merge curator closed-delete-delete changes from the abandoned 2.3.3 release
2020-11-13 10:05:23 -05:00
William Wernert
8a7ff3260d
Merge pull request #1911 from Security-Onion-Solutions/feature/ssh-harden-script
...
[feat] Add ssh-harden script
2020-11-13 09:00:07 -05:00
William Wernert
2f27b6f2fa
[feat] Add ssh-harden script
2020-11-13 08:51:28 -05:00
Mike Reeves
52e909007f
Change url and clean up sigs
2020-11-12 16:08:27 -05:00
Mike Reeves
80aeffe1ad
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-12 11:53:41 -05:00
Mike Reeves
cbca2d702f
Add Version back to sig files
2020-11-12 11:53:30 -05:00
Automation
af44cce423
Auto-publish so-acng image signature
2020-11-12 16:39:54 +00:00
Automation
7d81080076
Auto-publish so-grafana image signature
2020-11-12 16:39:24 +00:00
Automation
6194d85180
Auto-publish so-idstools image signature
2020-11-12 16:38:38 +00:00
Automation
88675ec2ee
Auto-publish so-strelka-manager image signature
2020-11-12 16:37:53 +00:00
Automation
9c0a1bc8b9
Auto-publish so-fleet image signature
2020-11-12 16:37:24 +00:00
Automation
52babc686d
Auto-publish so-fleet-launcher image signature
2020-11-12 16:36:51 +00:00
Automation
9370e5b8bc
Auto-publish so-freqserver image signature
2020-11-12 16:36:01 +00:00
Automation
6c1d5451eb
Auto-publish so-strelka-backend image signature
2020-11-12 16:35:16 +00:00
Automation
f50e6ab929
Auto-publish so-strelka-filestream image signature
2020-11-12 16:34:12 +00:00
Automation
67f18a02ea
Auto-publish so-strelka-frontend image signature
2020-11-12 16:33:37 +00:00
Mike Reeves
7f491545fa
Fix Variable for docker inspect
2020-11-12 11:31:27 -05:00
Automation
9b33201ba5
Auto-publish so-minio image signature
2020-11-12 16:30:56 +00:00
Mike Reeves
aefcb9a491
Fix Variable for docker
2020-11-12 11:28:58 -05:00
Automation
fee52f8b86
Auto-publish so-redis image signature
2020-11-12 16:28:23 +00:00
Automation
e434ccd3d3
Auto-publish so-soctopus image signature
2020-11-12 16:18:25 +00:00
Automation
70a0cbae23
Auto-publish so-telegraf image signature
2020-11-12 16:17:22 +00:00
Automation
04263101cf
Auto-publish so-kibana image signature
2020-11-12 16:15:27 +00:00
Mike Reeves
312f99966e
Change docker inspect to a variable to speed it up
2020-11-12 09:39:13 -05:00
Mike Reeves
667800d830
Change docker inspect to variable to speed it up
2020-11-12 09:35:19 -05:00
Mike Reeves
2fba02f71b
Grab specific digest so re-installs work
2020-11-12 09:29:18 -05:00
Josh Patterson
4ce0b770a5
Merge pull request #1898 from jtgreen-cse/patch-3
...
fix for #1725 , grafana queries use non_negative_ variants
2020-11-12 08:55:12 -05:00
Mike Reeves
1de862985c
Merge pull request #1893 from Security-Onion-Solutions/gpg
...
GPG Docker Image Verification
2020-11-12 08:46:34 -05:00
Jason Green
4e40392c55
fix for #1725 , grafana queries use non_negative_ variants
2020-11-12 07:34:51 -05:00
Automation
d1fe79b642
Auto-publish so-thehive-es image signature
2020-11-12 02:55:19 +00:00
Automation
f96cc35d37
Auto-publish so-thehive-cortex image signature
2020-11-12 02:53:56 +00:00
Automation
388f1e753d
Auto-publish so-strelka-manager image signature
2020-11-12 02:52:24 +00:00
Automation
42382d00d8
Auto-publish so-strelka-frontend image signature
2020-11-12 02:51:38 +00:00
Automation
b086f5e5c1
Auto-publish so-strelka-filestream image signature
2020-11-12 02:50:51 +00:00
Automation
0b0f9854f9
Auto-publish so-strelka-backend image signature
2020-11-12 02:49:47 +00:00
Automation
3107f46940
Auto-publish so-logstash image signature
2020-11-12 02:48:28 +00:00
Automation
202c672798
Auto-publish so-kibana image signature
2020-11-12 02:47:00 +00:00
Automation
6ac1bc5623
Auto-publish so-freqserver image signature
2020-11-12 02:45:21 +00:00
Automation
e002015ce2
Auto-publish so-fleet-launcher image signature
2020-11-12 02:44:31 +00:00
Automation
61b5e009c7
Auto-publish so-filebeat image signature
2020-11-12 02:43:27 +00:00
Automation
f3aadcd553
Auto-publish so-elasticsearch image signature
2020-11-12 02:42:22 +00:00
Automation
71370d4522
Auto-publish so-elasticsearch image signature
2020-11-12 02:41:12 +00:00
Automation
c287b5f826
Auto-publish so-elastalert image signature
2020-11-12 02:39:48 +00:00
Automation
4286ac0dfd
Auto-publish so-domainstats image signature
2020-11-12 02:38:46 +00:00
Automation
adc937295b
Auto-publish so-tcpreplay image signature
2020-11-12 02:37:39 +00:00
Automation
96bf2c57e7
Auto-publish so-pcaptools image signature
2020-11-12 02:36:20 +00:00
Automation
5f7a28dd5d
Auto-publish so-telegraf image signature
2020-11-12 02:35:22 +00:00
Automation
3560ba933b
Auto-publish so-suricata image signature
2020-11-12 02:34:18 +00:00
Automation
9c20450832
Auto-publish so-soctopus image signature
2020-11-12 02:33:10 +00:00
Automation
d71daef2e9
Auto-publish so-playbook image signature
2020-11-12 02:31:59 +00:00
Automation
c3ae80e2c1
Auto-publish so-logstash image signature
2020-11-12 02:30:36 +00:00
Automation
2098dd16ff
Auto-publish so-influxdb image signature
2020-11-12 02:29:02 +00:00
Automation
3b4c9e02e7
Auto-publish so-idstools image signature
2020-11-12 02:28:04 +00:00
Automation
adc99ff06d
Auto-publish so-filebeat image signature
2020-11-12 02:26:57 +00:00
Automation
f9b26c9a8f
Auto-publish so-thehive image signature
2020-11-12 02:25:44 +00:00
Automation
41a123c22b
Auto-publish so-grafana image signature
2020-11-12 02:24:19 +00:00
Automation
966089e1d0
Auto-publish so-curator image signature
2020-11-12 02:22:56 +00:00
Automation
3034d5ef98
Auto-publish so-kratos image signature
2020-11-12 02:22:11 +00:00
Automation
5ab169ea52
Auto-publish so-kibana image signature
2020-11-12 02:21:20 +00:00
Automation
f858027da1
Auto-publish so-wazuh image signature
2020-11-12 02:19:52 +00:00
Automation
c7517b37fa
Auto-publish so-steno image signature
2020-11-12 02:18:25 +00:00
Automation
2f315ba5a0
Auto-publish so-redis image signature
2020-11-12 02:17:06 +00:00
Automation
ed883f173b
Auto-publish so-mysql image signature
2020-11-12 02:16:12 +00:00
Automation
a46ad6fe81
Auto-publish so-minio image signature
2020-11-12 02:15:06 +00:00
Automation
42fc0add5e
Auto-publish so-fleet image signature
2020-11-12 02:14:08 +00:00
Automation
f6c2983bd1
Auto-publish so-zeek image signature
2020-11-12 02:12:58 +00:00
Automation
0b8e19bfc8
Auto-publish so-acng image signature
2020-11-12 02:11:20 +00:00
Automation
bee829697e
Auto-publish so-soc image signature
2020-11-12 02:10:11 +00:00
Mike Reeves
ed025851ca
Change soup for new gpg verification
2020-11-11 20:13:21 -05:00
Automation
94ab77b14d
Auto-publish so-nginx image signature
2020-11-12 00:57:45 +00:00
Mike Reeves
b113dce140
remove size from gpg sig
2020-11-11 19:49:25 -05:00
Automation
a2ef12eb6a
Auto-publish so-nginx image signature
2020-11-12 00:46:11 +00:00
Automation
eb0b909cd2
Auto-publish so-nginx image signature
2020-11-12 00:41:23 +00:00
Automation
7ef2056f17
Auto-publish so-steno image signature
2020-11-11 22:17:26 +00:00
Automation
b12f29d48a
Auto-publish so-thehive-es image signature
2020-11-11 22:16:06 +00:00
Automation
5fd1fd9b0d
Auto-publish so-thehive-cortex image signature
2020-11-11 22:14:47 +00:00
Automation
ad0ecff8c5
Auto-publish so-strelka-manager image signature
2020-11-11 22:13:19 +00:00
Automation
88b6ae1b2f
Auto-publish so-strelka-frontend image signature
2020-11-11 22:12:32 +00:00
Automation
9772fd181c
Auto-publish so-strelka-filestream image signature
2020-11-11 22:11:36 +00:00
Automation
cfff8319bb
Auto-publish so-strelka-backend image signature
2020-11-11 22:10:44 +00:00
Automation
0dc7c8b0e7
Auto-publish so-logstash image signature
2020-11-11 22:09:47 +00:00
Automation
3ccd8b40b2
Auto-publish so-kibana image signature
2020-11-11 22:08:21 +00:00
Automation
ca94bd12cf
Auto-publish so-fleet-launcher image signature
2020-11-11 22:06:47 +00:00
Automation
d650e68472
Auto-publish so-filebeat image signature
2020-11-11 22:05:38 +00:00
Automation
70f9bad827
Auto-publish so-elasticsearch image signature
2020-11-11 22:04:36 +00:00
Automation
c3d6e168ae
Auto-publish so-elasticsearch image signature
2020-11-11 22:03:08 +00:00
Automation
5c9c1915f1
Auto-publish so-domainstats image signature
2020-11-11 22:01:41 +00:00
Automation
32912f2c87
Auto-publish so-freqserver image signature
2020-11-11 22:00:41 +00:00
Automation
fb70e1e40c
Auto-publish so-elastalert image signature
2020-11-11 21:59:35 +00:00
Automation
4106d88338
Auto-publish so-tcpreplay image signature
2020-11-11 21:58:50 +00:00
Automation
93f57b73e2
Auto-publish so-pcaptools image signature
2020-11-11 21:57:37 +00:00
Automation
4fa0b6be0e
Auto-publish so-telegraf image signature
2020-11-11 21:56:53 +00:00
Automation
7ec2d85286
Auto-publish so-suricata image signature
2020-11-11 21:56:06 +00:00
Automation
763d5425a5
Auto-publish so-soctopus image signature
2020-11-11 21:55:11 +00:00
Automation
4be594cbb9
Auto-publish so-playbook image signature
2020-11-11 21:54:12 +00:00
Automation
e6fd3160ca
Auto-publish so-logstash image signature
2020-11-11 21:52:59 +00:00
Automation
07871987e4
Auto-publish so-influxdb image signature
2020-11-11 21:51:49 +00:00
Automation
3c33a38098
Auto-publish so-idstools image signature
2020-11-11 21:50:43 +00:00
Automation
b24bf9b6a9
Auto-publish so-filebeat image signature
2020-11-11 21:49:41 +00:00
Automation
373d9256f2
Auto-publish so-thehive image signature
2020-11-11 21:48:26 +00:00
Automation
dde7e0bd11
Auto-publish so-grafana image signature
2020-11-11 21:46:55 +00:00
Automation
017c9c9874
Auto-publish so-curator image signature
2020-11-11 21:45:36 +00:00
Automation
871f919c27
Auto-publish so-kratos image signature
2020-11-11 21:44:53 +00:00
Automation
f67c26a8f2
Auto-publish so-kibana image signature
2020-11-11 21:43:58 +00:00
Automation
038e8fceb7
Auto-publish so-wazuh image signature
2020-11-11 21:42:21 +00:00
weslambert
8c6adc21a8
Merge pull request #1891 from Security-Onion-Solutions/syslog_cef
...
Update syslog pipeline to allow for initial CEF parsing and pipeline …
2020-11-11 16:40:55 -05:00
Automation
75b26fb2af
Auto-publish so-redis image signature
2020-11-11 21:39:49 +00:00
Wes Lambert
8258b782fc
Update syslog pipeline to allow for initial CEF parsing and pipeline targeting
2020-11-11 21:39:40 +00:00
Automation
d73542d274
Auto-publish so-nginx image signature
2020-11-11 21:38:45 +00:00
Automation
1092aa2cb1
Auto-publish so-mysql image signature
2020-11-11 21:37:49 +00:00
Automation
8668cf9a9c
Auto-publish so-minio image signature
2020-11-11 21:36:45 +00:00
Automation
b9440364f7
Auto-publish so-fleet image signature
2020-11-11 21:35:44 +00:00
Automation
4f0ebfaf1f
Auto-publish so-zeek image signature
2020-11-11 21:34:50 +00:00
Automation
b090656269
Auto-publish so-acng image signature
2020-11-11 21:33:29 +00:00
Automation
16e0a26869
Auto-publish so-soc image signature
2020-11-11 21:30:17 +00:00
Automation
bc362acf82
Auto-publish so-soc image signature
2020-11-11 21:05:43 +00:00
Jason Ertel
79cbc747ea
Run leaktest on any branch
2020-11-11 15:52:48 -05:00
Mike Reeves
2269695e75
Change gpg to sig
2020-11-11 15:50:52 -05:00
Jason Ertel
710afe9355
Merge pull request #1889 from Security-Onion-Solutions/leaktest
...
Create leaktest.yml
2020-11-11 15:46:50 -05:00
Jason Ertel
ac236a0538
Move image sigs into versioned dir
2020-11-11 15:42:25 -05:00
Jason Ertel
eb7e8079ec
Create leaktest.yml
2020-11-11 15:39:06 -05:00
Mike Reeves
8512042132
Change Sig Path
2020-11-11 15:37:11 -05:00
Automation
a234e1c898
Auto-publish so-thehive-es image signature
2020-11-11 20:20:56 +00:00
Automation
25c91192a1
Auto-publish so-thehive-cortex image signature
2020-11-11 20:19:33 +00:00
Automation
22f19bbe9e
Auto-publish so-strelka-manager image signature
2020-11-11 20:18:03 +00:00
Automation
3b31a8d8cb
Auto-publish so-strelka-frontend image signature
2020-11-11 20:17:09 +00:00
Automation
cd868d1edb
Auto-publish so-strelka-filestream image signature
2020-11-11 20:16:30 +00:00
Automation
b31ea84c00
Auto-publish so-strelka-backend image signature
2020-11-11 20:15:36 +00:00
Automation
4ed6355186
Auto-publish so-logstash image signature
2020-11-11 20:14:14 +00:00
Automation
e51c2152fa
Auto-publish so-kibana image signature
2020-11-11 20:12:38 +00:00
Automation
7af1b7a539
Auto-publish so-fleet-launcher image signature
2020-11-11 20:11:29 +00:00
Automation
debbe965fe
Auto-publish so-filebeat image signature
2020-11-11 20:10:27 +00:00
Automation
3bbaca41c9
Auto-publish so-elasticsearch image signature
2020-11-11 20:09:30 +00:00
Automation
f2d25439e2
Auto-publish so-elasticsearch image signature
2020-11-11 20:08:10 +00:00
Automation
472fdd935e
Auto-publish so-domainstats image signature
2020-11-11 20:06:33 +00:00
Automation
14304c0f28
Auto-publish so-freqserver image signature
2020-11-11 20:05:36 +00:00
Automation
6a60890c36
Auto-publish so-elastalert image signature
2020-11-11 20:04:37 +00:00
Automation
687120ce4a
Auto-publish so-tcpreplay image signature
2020-11-11 20:03:28 +00:00
Automation
5e3f99c567
Auto-publish so-pcaptools image signature
2020-11-11 20:02:05 +00:00
Automation
c2ed0a6c72
Auto-publish so-telegraf image signature
2020-11-11 20:00:55 +00:00
Automation
8ed6a3ed78
Auto-publish so-suricata image signature
2020-11-11 19:59:46 +00:00
Automation
0511c851a2
Auto-publish so-soctopus image signature
2020-11-11 19:58:35 +00:00
Automation
0c7db56053
Auto-publish so-playbook image signature
2020-11-11 19:57:18 +00:00
Automation
7fae7500e8
Auto-publish so-logstash image signature
2020-11-11 19:55:41 +00:00
Automation
25b771d36f
Auto-publish so-influxdb image signature
2020-11-11 19:54:19 +00:00
Automation
6febc290a8
Auto-publish so-idstools image signature
2020-11-11 19:53:15 +00:00
Automation
9e9a023377
Auto-publish so-thehive image signature
2020-11-11 19:52:11 +00:00
Automation
f069b8cced
Auto-publish so-filebeat image signature
2020-11-11 19:50:50 +00:00
Automation
0d42bfb7f4
Auto-publish so-grafana image signature
2020-11-11 19:49:26 +00:00
Automation
4ccc898054
Auto-publish so-curator image signature
2020-11-11 19:48:16 +00:00
Automation
2010712929
Auto-publish so-kratos image signature
2020-11-11 19:47:11 +00:00
Automation
0ad0255e8c
Auto-publish so-kibana image signature
2020-11-11 19:46:20 +00:00
Automation
ca28cc7a17
Auto-publish so-wazuh image signature
2020-11-11 19:44:58 +00:00
Automation
0fce6823db
Auto-publish so-steno image signature
2020-11-11 19:43:44 +00:00
Automation
0db072d9b2
Auto-publish so-redis image signature
2020-11-11 19:42:27 +00:00
Automation
0c3a7a6214
Auto-publish so-nginx image signature
2020-11-11 19:41:26 +00:00
Automation
a58b487a0a
Auto-publish so-mysql image signature
2020-11-11 19:40:32 +00:00
Automation
061b8d5b9b
Auto-publish so-minio image signature
2020-11-11 19:39:38 +00:00
Automation
ff1dab283c
Auto-publish so-fleet image signature
2020-11-11 19:38:45 +00:00
Automation
319867ef10
Auto-publish so-zeek image signature
2020-11-11 19:38:01 +00:00
Automation
c21131b77a
Auto-publish so-acng image signature
2020-11-11 19:36:46 +00:00
Automation
638d9ddee3
Auto-publish so-soc image signature
2020-11-11 19:35:45 +00:00
Automation
dded28a54a
Auto-publish so-kibana image signature
2020-11-11 19:33:55 +00:00
Automation
7132011ece
Auto-publish so-steno image signature
2020-11-11 19:32:05 +00:00
Mike Reeves
3a622ee71e
Hash and sig update
2020-11-11 14:29:47 -05:00
Automation
fdc1468a11
Auto-publish so-wazuh image signature
2020-11-11 18:54:25 +00:00
Automation
691f64f8a3
Auto-publish so-nginx image signature
2020-11-11 18:53:13 +00:00
Mike Reeves
a29def504e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into gpg
2020-11-11 13:52:31 -05:00
Mike Reeves
8160ef104d
Merge pull request #1887 from Security-Onion-Solutions/scriptpids
...
Make sure scripts don't run if they are already running
2020-11-11 13:51:51 -05:00
Automation
52ee26c334
Auto-publish so-mysql image signature
2020-11-11 18:25:23 +00:00
Automation
d2c1fed2df
Auto-publish so-strelka-backend image signature
2020-11-11 18:14:28 +00:00
Automation
1521224100
Auto-publish so-strelka-filestream image signature
2020-11-11 18:12:47 +00:00
Automation
97f5f8438c
Auto-publish so-thehive-es image signature
2020-11-11 18:11:17 +00:00
Mike Reeves
978ba5b3ad
Update zeekloss.sh
2020-11-11 13:09:52 -05:00
Automation
80b926bc31
Auto-publish so-logstash image signature
2020-11-11 18:09:41 +00:00
Mike Reeves
a4df3623be
Update zeekcaptureloss.sh
2020-11-11 13:09:31 -05:00
Mike Reeves
4a80c37167
Update suriloss.sh
2020-11-11 13:09:08 -05:00
Mike Reeves
8e88c350d5
Update stenoloss.sh
2020-11-11 13:08:43 -05:00
Mike Reeves
a6a9f03cb0
Update redis.sh
2020-11-11 13:08:28 -05:00
Automation
3a9c9e3d99
Auto-publish so-strelka-frontend image signature
2020-11-11 18:08:03 +00:00
Automation
307af1248c
Auto-publish so-thehive-cortex image signature
2020-11-11 18:05:26 +00:00
Automation
0224adb7c8
Auto-publish so-strelka-manager image signature
2020-11-11 18:02:54 +00:00
Automation
f4a804b88c
Auto-publish so-fleet-launcher image signature
2020-11-11 17:58:56 +00:00
Automation
ea88fa7319
Auto-publish so-soctopus image signature
2020-11-11 17:56:28 +00:00
Mike Reeves
c9bfd8a253
Update oldpcap.sh
2020-11-11 12:55:28 -05:00
Mike Reeves
ee0e1ce8d7
Update influxdbsize.sh
2020-11-11 12:55:08 -05:00
Mike Reeves
814aa85dba
Update helixeps.sh
2020-11-11 12:54:48 -05:00
Mike Reeves
c5ddddda2a
Update checkfiles.sh
2020-11-11 12:54:31 -05:00
Mike Reeves
c75536db6d
Update so-curator-delete
2020-11-11 12:54:04 -05:00
Mike Reeves
c11d8367fa
Update so-curator-closed-delete-delete
2020-11-11 12:53:36 -05:00
Mike Reeves
8320421d42
Update so-curator-closed-delete
2020-11-11 12:53:05 -05:00
Automation
33bf799b47
Auto-publish so-freqserver image signature
2020-11-11 17:52:55 +00:00
Mike Reeves
047ab95e68
Update so-curator-close
2020-11-11 12:52:38 -05:00
Mike Reeves
2eb3378b62
Update so-curator-closed-delete
2020-11-11 12:50:59 -05:00
Automation
a354a6279b
Auto-publish so-idstools image signature
2020-11-11 17:49:25 +00:00
Mike Reeves
578250a994
Update so-curator-delete
2020-11-11 12:48:55 -05:00
Mike Reeves
e68f90c3b5
Update so-curator-closed-delete-delete
2020-11-11 12:48:28 -05:00
Automation
5a9211693c
Auto-publish so-kratos image signature
2020-11-11 17:48:03 +00:00
Automation
1e2df983af
Auto-publish so-redis image signature
2020-11-11 17:46:57 +00:00
Mike Reeves
d85c99abf3
Update so-curator-close
2020-11-11 12:46:44 -05:00
Mike Reeves
c0897c7e5a
Update so-curator-close
2020-11-11 12:46:19 -05:00
Automation
b4989c6c0e
Auto-publish so-minio image signature
2020-11-11 17:43:17 +00:00
Automation
7a79ef6ddb
Auto-publish so-zeek image signature
2020-11-11 17:41:08 +00:00
Automation
8aa3a508fa
Auto-publish so-acng image signature
2020-11-11 17:39:18 +00:00
Automation
b320a1d63e
Auto-publish so-fleet image signature
2020-11-11 17:12:03 +00:00
Automation
2a119d7824
Auto-publish so-soc image signature
2020-11-11 17:08:52 +00:00
Mike Reeves
73c17b77ae
Update zeekcaptureloss.sh
2020-11-11 11:43:48 -05:00
Mike Reeves
edb0d71e87
Update zeekloss.sh
2020-11-11 11:43:28 -05:00
Mike Reeves
6ff1922788
Update zeekcaptureloss.sh
2020-11-11 11:42:58 -05:00
Josh Patterson
758bee3a20
Merge pull request #1886 from Security-Onion-Solutions/issue/1681
...
Issue/1681
2020-11-11 11:40:08 -05:00
m0duspwnens
529da993aa
Merge remote-tracking branch 'remotes/origin/dev' into issue/1681
2020-11-11 11:39:08 -05:00
m0duspwnens
5a95159ec3
just use so-status.conf for containers to fix salt warning https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-11 11:38:48 -05:00
Automation
fc9c31706d
Auto-publish so-acng image signature
2020-11-11 16:31:42 +00:00
Mike Reeves
9548b3df54
Update stenoloss.sh
2020-11-11 11:23:20 -05:00
Mike Reeves
d3f65ac1a8
Update redis.sh
2020-11-11 11:22:52 -05:00
Mike Reeves
cb46c13054
Update oldpcap.sh
2020-11-11 11:22:28 -05:00
Mike Reeves
a4d3e109e6
Update influxdbsize.sh
2020-11-11 11:17:18 -05:00
Mike Reeves
711f5ab38f
Update helixeps.sh
2020-11-11 11:16:47 -05:00
Mike Reeves
ea1227de9d
Update checkfiles.sh
2020-11-11 11:16:15 -05:00
Mike Reeves
f9b52677d7
Update suriloss.sh
2020-11-11 11:15:45 -05:00
weslambert
533a65205f
Merge pull request #1885 from Security-Onion-Solutions/fix/syslog_application
...
Add check for field
2020-11-11 10:33:24 -05:00
weslambert
ea1f53b40c
Add check for field
2020-11-11 10:29:58 -05:00
Josh Patterson
0f4f029e92
Merge pull request #1883 from Security-Onion-Solutions/issue/1857
...
add top change for fleet getting mysql state back
2020-11-11 09:18:06 -05:00
m0duspwnens
da9a915421
add top change for fleet getting mysql state back was reverted in https://github.com/Security-Onion-Solutions/securityonion/pull/1880/files
2020-11-11 09:15:50 -05:00
weslambert
280fc501f9
Merge pull request #1882 from Security-Onion-Solutions/fix/extra_top_var
...
Fix duplicate vars
2020-11-11 08:53:43 -05:00
weslambert
625307ac5f
Fix duplicate vars
2020-11-11 08:52:39 -05:00
weslambert
44677ad521
Merge pull request #1880 from Security-Onion-Solutions/disable_elastic
...
Allow for disabling Elastic stack via pillar
2020-11-11 08:29:23 -05:00
Wes Lambert
1c326f561b
Allow for disabling Elastic stack via pillar
2020-11-11 13:26:59 +00:00
Josh Patterson
7b64f93bce
Merge pull request #1874 from Security-Onion-Solutions/issue/1681
...
Issue/1681
2020-11-10 17:57:48 -05:00
m0duspwnens
15f243f0ce
change names of acng and docker registry containers https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 17:51:00 -05:00
m0duspwnens
edb00c2058
remove redundant common from top, create so-status conf files on manager before registry state https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 17:09:38 -05:00
m0duspwnens
9e612e98ed
merge with dev
2020-11-10 15:43:40 -05:00
m0duspwnens
1fc94a8f59
change to so-acng for so-status https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:37:03 -05:00
m0duspwnens
c58039ab47
rename state https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:34:10 -05:00
m0duspwnens
1fca5e65df
redo how containers get added to so-status https://github.com/Security-Onion-Solutions/securityonion/issues/1681
2020-11-10 15:31:47 -05:00
Mike Reeves
9a59ceee4e
move to so-image-common
2020-11-10 12:16:54 -05:00
Mike Reeves
c5bf9bf90d
rework soup and docker refresh
2020-11-10 12:05:08 -05:00
William Wernert
676b4f0777
[fix] Close connection in mysql_conn module
2020-11-10 11:42:40 -05:00
William Wernert
6557155a8a
Merge pull request #1868 from Security-Onion-Solutions/feature/improve-mysql-dep
...
Feature/improve mysql dep
2020-11-10 11:04:23 -05:00
William Wernert
d3227bbcb1
[refactor] Code cleanup pt. 3
2020-11-10 11:03:43 -05:00
William Wernert
7f218e5297
[feat] Also run query against mysql to ensure queries can complete
2020-11-10 11:02:34 -05:00
William Wernert
b3c527e7a9
[refactor] Code cleanup pt. 2
2020-11-10 10:05:06 -05:00
William Wernert
54d732a060
[refactor] Code cleanup
2020-11-10 10:01:10 -05:00
William Wernert
22b7de819c
[fix] Put mysql import in try,catch in case it hasn't been installed
2020-11-10 10:00:21 -05:00
William Wernert
dba30fb0ed
[refactor] Split 15 min mysql startup between two wait states
2020-11-10 09:48:20 -05:00
Mike Reeves
7ca8fefded
gpg sign images
2020-11-10 09:45:06 -05:00
Josh Patterson
95b24b1684
Merge pull request #1865 from Security-Onion-Solutions/issue/1864
...
make so-status line color same as service state
2020-11-09 18:17:05 -05:00
m0duspwnens
66cd91c0a7
make so-status line color same as service state https://github.com/Security-Onion-Solutions/securityonion/issues/1864
2020-11-09 18:16:02 -05:00
Josh Patterson
64199c81e1
Merge pull request #1863 from Security-Onion-Solutions/issue/1857
...
Issue/1857
2020-11-09 17:54:25 -05:00
m0duspwnens
ae5bc297dd
remove extra squigly https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 17:06:32 -05:00
m0duspwnens
f5a1bd4074
only try to get enrollsecret if fleet is already enabled https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 16:25:28 -05:00
m0duspwnens
407a655717
merge with dev
2020-11-09 15:29:19 -05:00
m0duspwnens
0e19594c97
enable fleet in global pillars before running fleet state during setup https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 15:25:11 -05:00
William Wernert
ff4d7a6cb6
[fix] Sync modules so states can use our modules during setup
2020-11-09 14:01:19 -05:00
William Wernert
f647a06239
[fix] Correct percentage steps
2020-11-09 13:37:42 -05:00
Josh Patterson
d122ca1ba3
Merge pull request #1861 from Security-Onion-Solutions/issue/1857
...
fix top logic for mysql for fleet/playbook
2020-11-09 13:16:28 -05:00
m0duspwnens
5616aa6beb
fix top logic for mysql - https://github.com/Security-Onion-Solutions/securityonion/issues/1857
2020-11-09 13:12:45 -05:00
William Wernert
394fa727cb
[fix] Don't overwrite mysql module
2020-11-09 13:05:29 -05:00
William Wernert
9960cf0592
[feat] Add salt module to check if mysql is accepting db connections
2020-11-09 12:05:37 -05:00
weslambert
059c4e03e1
Merge pull request #1860 from Security-Onion-Solutions/strelka-parsing
...
Pull out additional fields from Exif info
2020-11-09 11:54:55 -05:00
Wes Lambert
7e578d2ce0
Pull out additional fields from Exif info
2020-11-09 16:53:53 +00:00
William Wernert
12125deecb
[feat] Show link state in whiptail menus
2020-11-09 11:06:08 -05:00
William Wernert
51256983da
[fix] Make sure pip is installed on Ubuntu
2020-11-06 08:53:30 -05:00
William Wernert
0718dbbd4d
Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion into dev
2020-11-06 08:52:42 -05:00
William Wernert
6b2ab67c58
[fix] Bump version of navigator json to 3.0 + fix booleans
2020-11-06 08:52:36 -05:00
Josh Patterson
64fd27fd78
Merge pull request #1843 from Security-Onion-Solutions/issue/1536
...
increase so-status padding by 1
2020-11-05 19:10:06 -05:00
m0duspwnens
7eb0dab6c7
increase padding by 1 - https://github.com/Security-Onion-Solutions/securityonion/issues/1536
2020-11-05 19:08:19 -05:00
Josh Patterson
0caf054da0
Merge pull request #1842 from Security-Onion-Solutions/issue/1764
...
show if disabled regardless of highstate status
2020-11-05 18:50:09 -05:00
m0duspwnens
21b284fb10
show if disabled regardless of highstate status - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:46:11 -05:00
Josh Patterson
3d1412a138
Merge pull request #1841 from Security-Onion-Solutions/issue/1764
...
Issue/1764
2020-11-05 18:24:51 -05:00
m0duspwnens
c7b4a5351c
fix logic - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:17:11 -05:00
m0duspwnens
a95129b8c2
add color - https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 18:03:42 -05:00
m0duspwnens
695bace3e8
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:54:10 -05:00
m0duspwnens
47cac59adb
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:52:28 -05:00
m0duspwnens
1a75ebdca3
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:51:51 -05:00
m0duspwnens
8da070d511
https://github.com/Security-Onion-Solutions/securityonion/issues/1764
2020-11-05 17:46:23 -05:00
William Wernert
d2ea197ce0
[fix] Remove old entry for manager from known_hosts
...
Resolves #1839
2020-11-05 14:40:00 -05:00
William Wernert
b528fe1a03
[fix] Only show analyst on network installs
...
Closes #1682
2020-11-05 14:39:04 -05:00
weslambert
3abe8cb397
Merge pull request #1836 from Security-Onion-Solutions/fix/wazuh_agent_register
...
Don't sleep if not registering agent
2020-11-05 14:03:32 -05:00
weslambert
2911e37b70
Don't sleep if not registering agent
2020-11-05 14:03:08 -05:00
William Wernert
4fed5c2518
Merge pull request #1822 from Security-Onion-Solutions/feature/setup-idempotency
...
Feature/setup idempotency
2020-11-05 13:48:18 -05:00
William Wernert
a5833f1f77
Merge branch 'dev' into feature/setup-idempotency
...
# Conflicts:
# setup/so-functions
2020-11-05 13:48:05 -05:00
William Wernert
b27b2e358b
[fix] Set MSRVIP variable before hosts file is overwritten
2020-11-05 13:38:08 -05:00
William Wernert
915aaf58f2
[fix] Always set MSRVIP because /etc/hosts is wiped
2020-11-05 13:28:21 -05:00
William Wernert
f058fb460d
[fix] Don't modify hosts file during whiptail menus
2020-11-05 13:25:02 -05:00
William Wernert
f7394559d4
[fix] Only add entry to /etc/hosts if unable to resolve hostname
2020-11-05 13:16:52 -05:00
Josh Patterson
ec3f35c360
Merge pull request #1832 from Security-Onion-Solutions/patch_2.3.3
...
Patch 2.3.3
2020-11-05 10:00:43 -05:00
Josh Patterson
fea6e6f4f9
Merge branch 'dev' into patch_2.3.3
2020-11-05 09:58:43 -05:00
William Wernert
cb75b2df65
[revert] Remove wazuh-agent package as well
2020-11-04 16:23:51 -05:00
William Wernert
4369b8d0f6
[fix] Remove wazuh-agent package as well
2020-11-04 16:14:58 -05:00
William Wernert
5cb8d0beda
[fix] Add -q flag to grep
2020-11-04 14:23:24 -05:00
William Wernert
b4446cba9a
[refactor][wip] Also backup directories in /nsm
2020-11-04 14:20:51 -05:00
William Wernert
1e41b9ba31
[fix] Add conditions for commands so they're less likely to fail
2020-11-04 14:20:26 -05:00
William Wernert
b2759c4c7c
[fix] Uninstall launcher if installed
2020-11-04 14:19:25 -05:00
Mike Reeves
6b144903fc
Update VERIFY_ISO.md
2020-11-04 13:47:37 -05:00
Mike Reeves
3825becd1b
Update changes.json
2020-11-04 13:44:52 -05:00
Mike Reeves
2aa21512e5
Update soup
2020-11-04 13:40:45 -05:00
William Wernert
3150367b1d
[fix] Add epoch string to /opt/so folder name
2020-11-04 12:52:37 -05:00
William Wernert
3ac9c43b7b
Merge branch 'dev' into feature/setup-idempotency
2020-11-04 12:44:14 -05:00
William Wernert
b643363e82
[fix] Directories need -r flag
2020-11-04 12:07:34 -05:00
Jason Ertel
8d5c29340e
Add screenshots to readme
2020-11-04 12:03:57 -05:00
Jason Ertel
1e9e156a87
Improve issue template directions
2020-11-04 11:49:22 -05:00
Jason Ertel
a364f13d24
Add issue template
2020-11-04 11:42:39 -05:00
William Wernert
3d70698647
[fix] Remove old mysql db directory
2020-11-04 11:26:56 -05:00
Mike Reeves
e989fc7041
Update map.jinja
2020-11-04 10:58:52 -05:00
William Wernert
49af35b440
[fix][wip] Add reinstall_init function (part 3)
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-04 10:38:48 -05:00
Mike Reeves
4592e2d4d7
add airgap option to upgradecommand
2020-11-04 10:08:01 -05:00
Mike Reeves
ec64314b70
Fix soup to clear yum cache for airgap
2020-11-04 10:00:44 -05:00
Mike Reeves
cf001875c2
Update soup
2020-11-03 20:14:15 -05:00
Mike Reeves
c7367eea38
Fix AGREPO Variable
2020-11-03 19:08:58 -05:00
William Wernert
db31cf3083
[refactor][fix] Remove old so-* containers, make fs changes after whiptail menus
2020-11-03 18:10:16 -05:00
Mike Reeves
8edb1529a9
Update soup
2020-11-03 17:36:53 -05:00
Mike Reeves
e8616e4d46
Update soup
2020-11-03 17:19:55 -05:00
William Wernert
3bf57382ce
[fix] Change when /opt/so is removed
2020-11-03 17:05:34 -05:00
Jason Ertel
def993f4ed
Improve salt version update comment
2020-11-03 16:50:22 -05:00
William Wernert
96ec483ae4
[fix][wip] Remove /opt/so directory during reinstall
2020-11-03 16:49:00 -05:00
William Wernert
6169758f4e
[fix] 0 -> root so file owner is set correctly
2020-11-03 16:47:59 -05:00
William Wernert
1c91e2d50b
[fix] Add minion_config variable so sed works
2020-11-03 15:48:08 -05:00
William Wernert
57e7e61f21
[fix] Don't add proxy to yum.conf on manager nodes
2020-11-03 15:45:19 -05:00
William Wernert
93ab4b5d4f
[fix][wip] Add reinstall_init function (part 2)
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-03 15:44:37 -05:00
William Wernert
00fc256c37
[fix][wip] Add reinstall_init function
...
Create a function that, if the setup log exists, puts the system into a state where
the installer can run again without issue.
This is WIP, there are most likely still issues.
2020-11-03 14:51:35 -05:00
Mike Reeves
887f412e48
Remove docker_clean from docker_update function
2020-11-03 13:54:00 -05:00
Jason Ertel
aa9aa59213
Correct cheatsheetUrl for airgap installs
2020-11-03 12:27:55 -05:00
m0duspwnens
a859aa4f48
upgrade from salt 3001.1 to salt 3002.1 - https://github.com/Security-Onion-Solutions/securityonion/issues/1807
2020-11-03 11:54:28 -05:00
Jason Ertel
82a7b7e02d
Upgrade to Kratos 0.5.3-alpha1
2020-11-03 11:50:25 -05:00
Mike Reeves
85ea61bf98
Update VERSION
2020-11-03 11:40:03 -05:00
Mike Reeves
7f4b8e8183
Update README.md
2020-11-03 11:39:42 -05:00
Josh Patterson
1f8b139462
Merge pull request #1806 from Security-Onion-Solutions/issue/1782
...
Issue/1782
2020-11-03 11:23:22 -05:00
m0duspwnens
562a016579
remove more from sosetup.log
2020-11-03 10:23:56 -05:00
weslambert
e040009d0b
Merge pull request #1804 from Security-Onion-Solutions/fix/wazuh_api_creds_remove
...
Remove Wazuh API creds after registering initial agent
2020-11-03 09:57:58 -05:00
Wes Lambert
7dca988c11
Remove Wazuh API creds after registering intial agent
2020-11-03 14:53:50 +00:00
Mike Reeves
f007ef0ef5
Update so-functions
2020-11-02 17:00:02 -05:00
weslambert
bfe98433f6
Merge pull request #1789 from Security-Onion-Solutions/fix/zeek_intel
...
Add Zeek intel.dat
2020-11-02 16:38:16 -05:00
Wes Lambert
05549a2362
Add Zeek intel.dat
2020-11-02 21:36:44 +00:00
m0duspwnens
7e090b0894
dont echo salt minion config file to prevent mysql.pass from showing in sosetup.log
2020-11-02 16:23:34 -05:00
weslambert
8a645edb34
Merge pull request #1788 from Security-Onion-Solutions/feature/nids_rules
...
Allow for muliple files for rules
2020-11-02 16:05:53 -05:00
Wes Lambert
24a54a326c
Allow for muliple files for rules
2020-11-02 21:03:45 +00:00
Jason Ertel
184d163d65
Do not persist the Cortex PID file; This allows Cortex to recover from non-graceful container shutdowns, such as a power loss event on the host machine
2020-11-02 15:04:13 -05:00
weslambert
bb0cf9b8c7
Merge pull request #1784 from Security-Onion-Solutions/fix/strelka_exif_parsing
...
Fix/strelka exif parsing
2020-11-02 14:32:45 -05:00
Wes Lambert
3113d5fbdb
Format scan.exiftool as text
2020-11-02 19:31:14 +00:00
Wes Lambert
6420ee0310
Update parsing for scan.exiftool
2020-11-02 19:28:12 +00:00
William Wernert
033f5dbb9c
[fix] Use (mostly) absolute path when adding to PATH
2020-11-02 14:25:46 -05:00
William Wernert
1c4abcef15
[fix] Kill all jobs before checking if we can reach the salt master
2020-11-02 14:25:02 -05:00
Jason Ertel
2acb930a2e
fix: Remove crontab for automation installs
2020-11-02 11:08:45 -05:00
weslambert
37c630d6ab
Merge pull request #1776 from Security-Onion-Solutions/bugfix/af-packet-ring-size
...
Match max-pending-packets size
2020-11-02 08:39:21 -05:00
weslambert
71a260a000
Match max-pending-packets size
2020-11-02 08:38:45 -05:00
jtgreen-cse
6359e03ba6
fix for Windows events via osquery
...
This change was required to properly let Windows events flow through their specific pipelines. Otherwise, the `temp` field stays around and gets ingested in ES.
2020-10-29 15:03:13 -04:00
William Wernert
b489fee8b5
Merge pull request #1738 from Security-Onion-Solutions/bugfix/nginx-redirect
...
Bugfix/nginx redirect
2020-10-29 14:33:38 -04:00
William Wernert
91221c4332
[revert] Move proxy_pass back to ip
2020-10-29 10:23:12 -04:00
Mike Reeves
57d8f25422
Create master node role in ES
2020-10-28 16:44:14 -04:00
William Wernert
3abd1c9f16
[fix] Configure soctopus to use url_base
2020-10-28 16:08:19 -04:00
Mike Reeves
b14c1d0999
Merge pull request #1713 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:27:26 -04:00
Mike Reeves
13be0da484
Add a place where custom logstash certs can go
2020-10-28 15:26:41 -04:00
Mike Reeves
3385d98a2a
Merge pull request #1712 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:26:08 -04:00
Mike Reeves
361b13dc88
Add a place where custom logstash certs can go
2020-10-28 15:25:00 -04:00
Jason Ertel
98c669e80b
Disable nginx server version and TLSv1.0/TLSv1.1
2020-10-28 14:29:29 -04:00
William Wernert
b02d434a0e
[fix] Change any scripts using auth headers to url_base
2020-10-28 12:29:09 -04:00
William Wernert
3ee9f23d26
[fix] Use url_base in sensoroni.json instead of manager hostname
2020-10-28 12:28:34 -04:00
Jason Ertel
348c2feee2
Prevent usage of dollar signs in admin passwords during setup
2020-10-28 11:07:05 -04:00
Mike Reeves
b238c492e4
Update so-functions
2020-10-28 10:50:10 -04:00
Mike Reeves
97207bd006
Merge pull request #1702 from Security-Onion-Solutions/dockernet
...
Custom Docker IP Range
2020-10-28 10:48:56 -04:00
Mike Reeves
bed70ab6bf
Update whiptail menu for docker question
2020-10-28 10:19:15 -04:00
Mike Reeves
8173cb589b
Update whiptail menu for docker question
2020-10-28 10:17:53 -04:00
Mike Reeves
563a606e0e
Upodate dockernet menu
2020-10-28 10:14:14 -04:00
Mike Reeves
8d952eca7e
Upodate dockernet menu
2020-10-28 10:12:07 -04:00
Mike Reeves
8f7dffea4b
Upodate dockernet menu
2020-10-28 10:10:43 -04:00
weslambert
7ea8dc84b6
Merge pull request #1696 from Security-Onion-Solutions/feature/wazuh-user-mods
...
Add Wazuh user management scripts
2020-10-28 08:24:15 -04:00
Wes Lambert
453247971e
Add Wazuh user management scripts
2020-10-28 12:22:50 +00:00
Mike Reeves
741e17a637
add bip for docker
2020-10-27 18:21:53 -04:00
Mike Reeves
fedf334ee9
add bip for docker
2020-10-27 18:21:09 -04:00
Mike Reeves
8fee19ee1b
add bip for docker
2020-10-27 18:01:48 -04:00
Mike Reeves
697bc53aec
Dockernet Modifications
2020-10-27 15:08:34 -04:00
Jason Ertel
5a705fc0f2
Add Hunt quick action for hunted events, grouping by dataset and module
2020-10-27 12:30:33 -04:00
William Wernert
7b17b4abc7
Merge pull request #1680 from Security-Onion-Solutions/feature/setup-fixes
...
Feature/setup fixes
2020-10-27 12:17:21 -04:00
William Wernert
a043bc7cc4
[fix] Second if to elif
2020-10-27 12:16:19 -04:00
William Wernert
72dc267ab5
[fix] Menu sizing fixes
2020-10-27 12:14:44 -04:00
William Wernert
970be4d530
[fix] Change cd to relative
...
Since the script already changes to the correct dir, we can work from relative directories now.
2020-10-27 12:13:07 -04:00
Jason Ertel
474c4e54b4
Ensure labels and icons are associated with all quick actions
2020-10-27 12:04:57 -04:00
Mike Reeves
d4dd4aa416
Add missing comma in daemon.json
2020-10-27 11:25:45 -04:00
William Wernert
5054138be9
[feat] Add analyst option + add back helix option
2020-10-27 11:21:03 -04:00
William Wernert
83c23dd5de
[fix] Remove old got_root call
2020-10-27 11:20:39 -04:00
Mike Reeves
42e00514f5
Adding docker net setting
2020-10-27 11:09:14 -04:00
William Wernert
e75f8ba257
[fix] Move root check to top of so-setup
2020-10-27 09:39:29 -04:00
William Wernert
564ac3a4ff
Merge pull request #980 from Security-Onion-Solutions/feature/nginx-update
...
Feature/nginx update
2020-10-27 09:29:43 -04:00
William Wernert
c58deef2e0
Merge branch 'dev' into feature/nginx-update
2020-10-27 09:29:06 -04:00
Mike Reeves
0ad65c8cd4
Merge pull request #1568 from jtgreen-cse/patch-1
...
fix for rendering error >1 search node
2020-10-26 16:57:17 -04:00
William Wernert
0aaf8d6d9a
[fix] Change 301 to 307 so curl requests work as intended
2020-10-26 16:37:16 -04:00
William Wernert
37ede9b993
[wip] Redirect so-user-add to separate log so ERROR isn't in main log
2020-10-26 15:03:27 -04:00
Mike Reeves
5395983fc7
Merge pull request #1580 from Security-Onion-Solutions/feature/thehive-casetemplates
...
Add case_template field to Playbook alerts
2020-10-26 14:13:54 -04:00
William Wernert
3648e293a1
[fix] Add -L option to curl to respect redirects
2020-10-26 14:08:52 -04:00
Mike Reeves
ecfd1bbe4d
Merge remote-tracking branch 'remotes/origin/dev' into escluster
2020-10-26 13:33:05 -04:00
Mike Reeves
12acc2e123
Merge pull request #1663 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERIFY_ISO.md
2020-10-26 13:10:18 -04:00
Mike Reeves
8d84718c91
Update VERIFY_ISO.md
2020-10-26 13:08:30 -04:00
Jason Ertel
3809573963
Correct cheatsheet URL for airgap installs
2020-10-26 12:16:55 -04:00
Jason Ertel
571550c019
Merge master into dev
2020-10-26 10:30:26 -04:00
William Wernert
e613bb3740
Merge branch 'dev' into feature/nginx-update
2020-10-26 10:28:14 -04:00
William Wernert
4662837075
[fix] Revert changes from merging dev
2020-10-26 10:25:16 -04:00
Mike Reeves
892ca294dc
Merge pull request #1655 from Security-Onion-Solutions/patch_2.3.2
...
2.3.2
2020-10-26 10:17:23 -04:00
Mike Reeves
45fd325307
Update VERIFY_ISO.md
2020-10-26 10:11:58 -04:00
Mike Reeves
653561ad95
Update VERIFY_ISO.md
2020-10-26 10:09:25 -04:00
Mike Reeves
f75badf43a
2.3.2 ISO info
2020-10-26 09:53:26 -04:00
Doug Burks
c61199618a
Update so-curator-closed-delete-delete
2020-10-24 07:15:43 -04:00
Mike Reeves
d9c021e86a
Update so-curator-closed-delete-delete
2020-10-23 17:07:16 -04:00
Mike Reeves
951f6ab3e2
Update VERIFY_ISO.md
2020-10-23 16:48:05 -04:00
Mike Reeves
da488945e0
Update VERIFY_ISO.md
2020-10-23 16:47:43 -04:00
Mike Reeves
b6f1cfada6
Update changes.json
2020-10-23 16:44:02 -04:00
Jason Ertel
85e0b2cab3
Add cheatsheet URL to soc.json
2020-10-23 16:35:35 -04:00
Mike Reeves
c8a6b232d5
Fix which field we return for Elastic index
2020-10-23 15:58:35 -04:00
William Wernert
fdb7cb90e3
[wip] Test alt variable usage
2020-10-23 15:36:01 -04:00
William Wernert
73b83584e6
[fix] Remove bad '_' character
2020-10-23 14:32:43 -04:00
Mike Reeves
801f4aae8e
Update README.md
2020-10-23 10:09:07 -04:00
Mike Reeves
c066cc67dc
Update VERSION
2020-10-23 10:08:45 -04:00
Josh Patterson
1185e43064
Merge pull request #1614 from Security-Onion-Solutions/issue/1573
...
Issue/1573 and Issue/1601
2020-10-22 15:57:40 -04:00
Mike Reeves
51ca661219
update wording for USB device vs CDROM
2020-10-22 14:54:34 -04:00
m0duspwnens
50a767ca6c
dont list aptcacherng in so-status if user chose open updates during setup - https://github.com/Security-Onion-Solutions/securityonion/issues/1573
2020-10-22 14:52:07 -04:00
Mike Reeves
174bbc6cd9
Update VERSION
2020-10-22 14:14:57 -04:00
William Wernert
6a08086dfa
[refactor] Make variable names consistent
2020-10-22 14:10:06 -04:00
Mike Reeves
a3579b88ae
Merge pull request #1604 from Security-Onion-Solutions/dev
...
2.3.1
2020-10-22 14:08:41 -04:00
William Wernert
6a3e921924
[fix] Fixes for fleet install
2020-10-22 13:09:26 -04:00
Mike Reeves
4a0796359b
Update README.md
2020-10-22 12:54:05 -04:00
m0duspwnens
0bfdef274b
update so-status to work with disabled containers - https://github.com/Security-Onion-Solutions/securityonion/issues/1601
2020-10-22 12:09:19 -04:00
Mike Reeves
92d397d573
Update ISO instructions
2020-10-22 11:59:39 -04:00
m0duspwnens
0b6b6e38fc
fix map for steno
2020-10-22 11:24:18 -04:00
m0duspwnens
aa59eff1ac
fix if statement
2020-10-22 10:59:03 -04:00
m0duspwnens
172ca9aa8d
add option to enable or disable to steno docker container - https://github.com/Security-Onion-Solutions/securityonion/issues/1601
2020-10-22 10:52:34 -04:00
William Wernert
79c4f07ff7
[fix] Don't listen on port 80 on all installs
2020-10-22 10:43:24 -04:00
Mike Reeves
460a391460
Update changes.json
2020-10-22 10:00:20 -04:00
Mike Reeves
905fcd06a6
Remove old 2.3.0 dockers
2020-10-22 08:51:40 -04:00
Josh Patterson
0b7f1fb189
Merge pull request #1594 from Security-Onion-Solutions/issue/1593
...
fix grabbing soversion in so-features-enable
2020-10-21 16:51:06 -04:00
m0duspwnens
712dc6b277
fix grabbing soversion in so-features-enable
2020-10-21 16:47:48 -04:00
Josh Patterson
b93709e05f
Merge pull request #1591 from Security-Onion-Solutions/issue/1590
...
fix arg for so-firewall addhostgroup
2020-10-21 15:48:02 -04:00
m0duspwnens
32294eb2ed
fix arg for so-firewall addhostgroup
2020-10-21 15:34:35 -04:00
Josh Patterson
2da656ff95
Merge pull request #1589 from Security-Onion-Solutions/issue/1551
...
only allow hosts in syslog host group to connect to manager type nodes
2020-10-21 14:41:50 -04:00
m0duspwnens
ef1e05db3e
only allow hosts in syslog host group to connect to manager type nodes
2020-10-21 14:41:03 -04:00
Josh Patterson
798abdbcde
Merge pull request #1584 from Security-Onion-Solutions/issue/1551
...
firewall to allow search nodes to connect to beats on manager
2020-10-21 12:50:49 -04:00
m0duspwnens
8805fef187
firewall to allow search nodes to connect to beats on manager
2020-10-21 12:43:28 -04:00
Josh Patterson
aafd365f2b
Merge pull request #1583 from Security-Onion-Solutions/issue/1551
...
add firewall rules for syslog
2020-10-21 11:21:18 -04:00
m0duspwnens
5f43380aa0
add firewall rules for syslog
2020-10-21 11:20:34 -04:00
Josh Brower
844ffe8fdf
nest case_template
2020-10-21 09:58:31 -04:00
Josh Brower
1e14d66f54
Add case_template field to Playbook alerts
2020-10-21 08:59:26 -04:00
weslambert
e2d95e0deb
Merge pull request #1576 from Security-Onion-Solutions/fix/comon_nids_rule_ruleset
...
Change rule_ruleset to rule.ruleset
2020-10-20 22:15:00 -04:00
weslambert
4765ef5f5c
Change rule_ruleset to rule.ruleset
2020-10-20 22:14:23 -04:00
William Wernert
d63358c8f0
[fix] Correct pillar reference + nginx errors
2020-10-20 14:30:06 -04:00
Jason Ertel
d37ddf584a
Correct quick action defaults
2020-10-20 14:12:23 -04:00
jtgreen-cse
eaa41266a2
fix for rendering error >1 search node
...
Fails rendering if you have more than one search node.
2020-10-20 13:24:53 -04:00
Mike Reeves
4a9fcfb8cf
Fix missing quote
2020-10-20 13:17:40 -04:00
Mike Reeves
a119d8f27d
Fix config for airgap installs
2020-10-20 11:28:49 -04:00
Mike Reeves
87adbb5f81
printf issues
2020-10-19 17:20:33 -04:00
Mike Reeves
722f2b3913
Fix pillar syntax
2020-10-19 17:08:06 -04:00
Mike Reeves
3cb419174a
Fix pillar syntax
2020-10-19 17:04:06 -04:00
Mike Reeves
55b6f5ce99
Fix pillar syntax
2020-10-19 17:02:26 -04:00
Mike Reeves
4e1bff2231
Fix pillar syntax
2020-10-19 16:56:13 -04:00
Mike Reeves
7e0063d474
Fix pillar syntax
2020-10-19 16:55:11 -04:00
Mike Reeves
23bc5e303e
Add clustering to ES function
2020-10-19 16:52:43 -04:00
Mike Reeves
6f703fad25
Change whiptail logic
2020-10-19 16:44:43 -04:00
Mike Reeves
c538e5f85b
Change whiptail logic
2020-10-19 16:40:56 -04:00
Mike Reeves
c22e8c08a6
Change whiptail logic
2020-10-19 16:40:22 -04:00
Mike Reeves
f893cf203f
Change whiptail logic
2020-10-19 16:38:17 -04:00
Mike Reeves
bbb825a207
Add cluster whiptail questions
2020-10-19 16:33:40 -04:00
Josh Patterson
ba1dfcd774
Merge pull request #1554 from Security-Onion-Solutions/issue/1551
...
Issue/1551
2020-10-19 16:10:50 -04:00
m0duspwnens
10e4248cfc
and node that gets filebeat state now can listen for syslog - https://github.com/Security-Onion-Solutions/securityonion/issues/1551
2020-10-19 16:10:20 -04:00
Mike Reeves
bab6b151ff
Add cluster whiptail questions
2020-10-19 16:07:22 -04:00
William Wernert
42e285cfbe
Merge branch 'dev' into feature/nginx-update
...
# Conflicts:
# salt/nginx/etc/nginx.conf
# salt/nginx/etc/nginx.conf.so-eval
# salt/nginx/etc/nginx.conf.so-manager
# salt/nginx/etc/nginx.conf.so-standalone
2020-10-19 13:25:46 -04:00
Mike Reeves
97a2d91d15
Re-arrange whiptail screens
2020-10-19 12:14:30 -04:00
m0duspwnens
79854f111e
add 514 tcp listener to filebeat docker and add syslog listener to fb config for manager and manager search - https://github.com/Security-Onion-Solutions/securityonion/issues/1551
2020-10-19 10:27:40 -04:00
Josh Patterson
a05329e7d8
Merge pull request #1532 from Masaya-A/patch-1
...
Grafana /nsm fix for eval/standalone
2020-10-16 16:48:12 -04:00
Masaya-A
47652ac080
Update eval.json
2020-10-17 04:45:12 +09:00
Masaya-A
964919109d
Update standalone.json
2020-10-17 04:35:39 +09:00
Jason Ertel
a968e5c23f
Increment version to 2.3.1
2020-10-16 10:57:31 -04:00
William Wernert
6f73d62400
Merge branch 'dev' into feature/nginx-update
2020-07-20 13:13:32 -04:00
William Wernert
a5c790c31e
[fix] managerr -> manager
2020-07-10 17:50:53 -04:00
William Wernert
8b146aac32
Merge branch 'dev' into feature/nginx-update
...
# Conflicts:
# salt/nginx/etc/nginx.conf
# salt/nginx/etc/nginx.conf.so-eval
# salt/nginx/etc/nginx.conf.so-manager
# salt/nginx/etc/nginx.conf.so-managersearch
# salt/nginx/etc/nginx.conf.so-mastersearch
# salt/nginx/etc/nginx.conf.so-standalone
2020-07-10 17:49:34 -04:00
William Wernert
81006ebbd0
[fix] Reflect new manager syntax
2020-07-10 17:46:15 -04:00
William Wernert
49e5cb311e
[fix][WIP] set ssl cert for redirect 443 server block
2020-07-08 16:05:48 -04:00
William Wernert
533ed395e7
[fix][WIP] Remove ssl and http2 from redirect server block
2020-07-08 15:59:31 -04:00
William Wernert
a0ffe26334
[fix] Only one default_server is allowed per port
2020-07-08 15:56:36 -04:00
William Wernert
0c3e35c55e
[fix] correct jinja template syntax
2020-07-08 14:30:27 -04:00
William Wernert
cfd1b82e00
[refactor] Redirect to correct url_base + combine configs
2020-07-08 13:49:33 -04:00