Doug Burks
484aa7b207
Merge pull request #8336 from Security-Onion-Solutions/hotfix/2.3.140
...
Hotfix/2.3.140
2022-07-19 16:13:47 -04:00
Mike Reeves
6986448239
Merge pull request #8333 from Security-Onion-Solutions/2.3.140hotfix
...
2.3.140 Hotfix
2022-07-19 14:47:50 -04:00
Mike Reeves
dd48d66c1c
2.3.140 Hotfix
2022-07-19 14:39:44 -04:00
Mike Reeves
440f4e75c1
Merge pull request #8332 from Security-Onion-Solutions/dev
...
Merge Hotfix
2022-07-19 13:30:20 -04:00
weslambert
c795a70e9c
Merge pull request #8329 from Security-Onion-Solutions/fix/elastalert_stop_check_enabled
...
Check to ensure Elastalert is enabled and suppress missing container error output
2022-07-19 13:27:35 -04:00
weslambert
340dbe8547
Check to see if Elastalert is enabled before trying to run 'so-elastalert-stop'. Also suppress error output for when so-elastalert container is not present.
2022-07-19 13:25:09 -04:00
Mike Reeves
52a5e743e9
Merge pull request #8327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-07-19 11:17:13 -04:00
Wes Lambert
5ceff52796
Move Elastalert indices check to function and call from beginning of soup and during pre-upgrade to 2.3.140
2022-07-19 14:54:39 +00:00
Wes Lambert
f3a0ab0b2d
Perform Elastalert index check twice
2022-07-19 14:48:19 +00:00
Wes Lambert
4a7c994b66
Revise Elastalert index check deletion logic
2022-07-19 14:31:45 +00:00
Mike Reeves
07b8785f3d
Update soup
2022-07-19 10:23:10 -04:00
Mike Reeves
9a1092ab01
Update HOTFIX
2022-07-19 10:21:36 -04:00
Mike Reeves
fbcbfaf7c3
Merge pull request #8310 from Security-Onion-Solutions/dev
...
2.3.140
2022-07-18 11:23:54 -04:00
Mike Reeves
497110d6cd
Merge pull request #8320 from Security-Onion-Solutions/2.3.140-2
...
2.3.140
2022-07-18 10:57:53 -04:00
Mike Reeves
3711eb52b8
2.3.140
2022-07-18 10:54:50 -04:00
weslambert
8099b1688b
Merge pull request #8319 from Security-Onion-Solutions/fix/elasticsearch_query_missing_query_path
...
Fix missing query path for so-elasticsearch-query
2022-07-18 09:47:16 -04:00
weslambert
2914007393
Add forward slash to fix issue with missing query path
2022-07-18 09:07:34 -04:00
weslambert
f5e10430ed
Add forward slash to fix issue with missing query path
2022-07-18 09:07:13 -04:00
Mike Reeves
b5a78d4577
Merge pull request #8309 from Security-Onion-Solutions/2.3.140
...
2.3.140
2022-07-15 13:36:31 -04:00
Mike Reeves
0a14dad849
Update VERIFY_ISO.md
2022-07-15 13:31:51 -04:00
Mike Reeves
3430df6a20
2.3.140
2022-07-15 13:26:25 -04:00
Mike Reeves
881915f871
Merge pull request #8306 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update defaults.yaml
2022-07-14 16:20:29 -04:00
Mike Reeves
cf8c6a6e94
Update defaults.yaml
2022-07-14 15:17:27 -04:00
weslambert
52ebbf8ff3
Merge pull request #8304 from Security-Onion-Solutions/fix/kibana_space_defaults_web_response_url
...
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:08:02 -04:00
weslambert
2443e8b97e
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:04:56 -04:00
weslambert
4241eb4b29
Merge pull request #8298 from Security-Onion-Solutions/fix/kibana_space_defaults_shebang
...
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:50:21 -04:00
weslambert
0fd4f34b5b
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:48:39 -04:00
Josh Patterson
37df49d4f3
Merge pull request #8296 from Security-Onion-Solutions/elastalert_esversion_check
...
use onlyif requisite instead
2022-07-13 15:22:40 -04:00
m0duspwnens
7d7cf42d9a
use onlyif requisite instead
2022-07-13 15:21:34 -04:00
Doug Burks
de0a7d3bcd
Merge pull request #8293 from Security-Onion-Solutions/dougburks-patch-1
...
change hyperlink for Elastic 8 issues
2022-07-13 12:41:50 -04:00
Doug Burks
c67a58a5b1
change hyperlink for Elastic 8 issues
2022-07-13 12:40:03 -04:00
Josh Patterson
e79ca4bb9b
Merge pull request #8291 from Security-Onion-Solutions/elastalert_esversion_check
...
do not start elastalert if elasticsearch is not v8
2022-07-13 11:24:12 -04:00
m0duspwnens
086cf3996d
do not start elastalert if elasticsearch is not v8
2022-07-13 11:21:27 -04:00
Doug Burks
7ae5d49a4a
Merge pull request #8290 from Security-Onion-Solutions/dougburks-patch-1
...
increment version to 2.3.140
2022-07-13 09:33:37 -04:00
Doug Burks
34d3c6a882
increment version to 2.3.140
2022-07-13 09:32:28 -04:00
weslambert
4a5664db7b
Merge pull request #8289 from Security-Onion-Solutions/fix/soup_unsupported_indices_check
...
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:15:22 -04:00
weslambert
513c7ae56c
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:13:28 -04:00
weslambert
fa894cf83b
Merge pull request #8288 from Security-Onion-Solutions/fix/soup_elastalert_indices_deletion_check
...
Ensure Elastalert indices are deleted before continuing with SOUP
2022-07-13 08:44:04 -04:00
weslambert
8e92060c29
Ensure Elastalert indices are deleted before continuing with SOUP -- if they are not, generate a failure condition
2022-07-13 08:38:55 -04:00
weslambert
d7eb8b9bcb
Merge pull request #8281 from Security-Onion-Solutions/fix/soup_elasticsearch8_index_compatibility
...
SOUP - Check for indices created by Elasticsearch 6
2022-07-12 16:20:47 -04:00
weslambert
d0a0ca8458
Update exit code for ES checks
2022-07-12 16:15:44 -04:00
Josh Patterson
57b79421d8
Merge pull request #8280 from Security-Onion-Solutions/fix_filebeat
...
move port bindings back under port bindings
2022-07-12 16:12:49 -04:00
weslambert
4502182b53
Typo - Ensure Elasticsearch version 6 indices are checked
2022-07-12 15:35:46 -04:00
weslambert
0fc6f7b022
Add check for Elasticsearch 6 indices
2022-07-12 15:34:24 -04:00
m0duspwnens
ec451c19f8
move port bindings back under port bindings
2022-07-12 15:17:25 -04:00
weslambert
e9a22d0aff
Merge pull request #8275 from Security-Onion-Solutions/fix/filebeat_es_output_additions
...
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
2022-07-11 19:03:07 -04:00
weslambert
11d3ed36b7
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
...
Add outputs for Elasticsearch and Kibana for Eval/Import Mode, since Logstash is not used in Eval Mode or Import Mode. Otherwise, logs from these inputs end up in a filebeat-prefixed index.
2022-07-11 17:22:09 -04:00
weslambert
d828bbfe47
Merge pull request #8273 from Security-Onion-Solutions/fix/kibana_space_defaults_cases
...
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:39:30 -04:00
weslambert
bd32394560
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:38:05 -04:00
weslambert
6f4f050a96
Merge pull request #8272 from Security-Onion-Solutions/fix/soup_kibana_space_defaults
...
Run so-kibana-space-defaults when upgrading to 2.3.140
2022-07-11 14:47:11 -04:00
weslambert
f77edaa5c9
Run so-kibana-space-defaults to re-establish the default enabled features since Fleet feature name changed
2022-07-11 14:41:23 -04:00
Jason Ertel
15124b6ad7
Merge pull request #8271 from Security-Onion-Solutions/kilo
...
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:47:28 -04:00
Jason Ertel
077053afbd
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:43:41 -04:00
weslambert
dd1d5b1a83
Merge pull request #8270 from Security-Onion-Solutions/fix/curator_actions_delete_kratos
...
Add delete and warm action for Kratos indices in applicable Curator delete/warm scripts
2022-07-11 11:39:43 -04:00
weslambert
e82b6fcdec
Typo - Change 'delete' to 'warm'
2022-07-11 11:34:53 -04:00
weslambert
8c8ac41b36
Add action for Kratos indices
2022-07-11 11:32:03 -04:00
weslambert
b611dda143
Add delete action for Kratos indices
2022-07-11 11:31:22 -04:00
weslambert
3f5b98d14d
Merge pull request #8269 from Security-Onion-Solutions/fix/curator_actions_kratos
...
Add Curator actions and adjust Curator close scripts to account for so-kibana and so-kratos indices
2022-07-11 11:21:20 -04:00
Wes Lambert
0b6219d95f
Adjust Curator close scripts to include Kibana and Kratos indices
2022-07-11 14:51:33 +00:00
Wes Lambert
2f729e24d9
Add Curator action files for Kratos indices
2022-07-11 14:34:10 +00:00
weslambert
992b6e14de
Merge pull request #8268 from Security-Onion-Solutions/fix/kibana_disable_fleetv2
...
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:09:12 -04:00
weslambert
09a1d8c549
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:06:24 -04:00
Jason Ertel
f28c6d590a
Merge pull request #8263 from Security-Onion-Solutions/kilo
...
Remove Jinja from yaml files before parsing
2022-07-08 20:32:22 -04:00
Jason Ertel
4f8bb6049b
Future proof the jinja check to ensure the script does not silently overwrite jinja templates
2022-07-08 17:30:00 -04:00
Jason Ertel
a8e6b26406
Remove Jinja from yaml files before parsing
2022-07-08 17:07:24 -04:00
weslambert
2903bdbc7e
Merge pull request #8260 from Security-Onion-Solutions/fix/kratos_dedicated_index_and_filestream_id_additions
...
Add dedicated index for Kratos and IDs for all filestream inputs
2022-07-08 12:04:40 -04:00
Wes Lambert
5c90fce3a1
Add Kratos Logstash output to search pipeline for Logstash
2022-07-08 15:58:00 +00:00
Wes Lambert
26698cfd07
Add Logstash output for dedicated Kratos index
2022-07-08 15:55:55 +00:00
Wes Lambert
764e8688b1
Modify Kratos input to use dedicated index and add filestream ID for all applicable inputs
2022-07-08 15:53:55 +00:00
Wes Lambert
b06c16f750
Add ingest node pipeline for Kratos
2022-07-08 15:53:00 +00:00
weslambert
42cfab4544
Merge pull request #8256 from Security-Onion-Solutions/fix/kibana_restart_after_role_sync
...
Restart Kibana in case it times out before being able to read role update
2022-07-07 17:44:47 -04:00
weslambert
4bbc901860
Restart Kibana in case it times out before being able to read in new role configuration
2022-07-07 17:19:02 -04:00
weslambert
a343f8ced0
Merge pull request #8255 from Security-Onion-Solutions/fix/so_kibana_user_role
...
Force so-user to sync roles to ensure so_kibana role change
2022-07-07 16:19:30 -04:00
weslambert
85be2f4f99
Force so-user to sync roles to ensure so_kibana role change from superuser to kibana_system
2022-07-07 15:55:44 -04:00
weslambert
8b3fa0c4c6
Merge pull request #8252 from Security-Onion-Solutions/feature/elastic_8_3_2
...
Update to Elastic 8.3.2
2022-07-07 11:14:14 -04:00
weslambert
ede845ce00
Update to Kibana 8.3.2
2022-07-07 11:05:44 -04:00
weslambert
42c96553c5
Update to Kibana 8.3.2
2022-07-07 11:04:43 -04:00
Mike Reeves
41d5cdd78c
Merge pull request #8246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2022-07-06 16:39:38 -04:00
Mike Reeves
c819d3a558
Update soup
2022-07-06 16:36:57 -04:00
Mike Reeves
c00d33632a
Update soup
2022-07-06 16:23:02 -04:00
Mike Reeves
a1ee793607
Merge pull request #8242 from Security-Onion-Solutions/fixsoup
...
Move soup order
2022-07-06 09:18:16 -04:00
Mike Reeves
1589107b97
Move soup order
2022-07-06 08:59:21 -04:00
Mike Reeves
31688ee898
Merge pull request #8238 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Make soup enforce versions
2022-07-05 16:56:14 -04:00
Mike Reeves
f1d188a46d
Update soup
2022-07-05 16:50:20 -04:00
Mike Reeves
5f0c3aa7ae
Update soup
2022-07-05 16:49:20 -04:00
weslambert
2b73cd1156
Merge pull request #8236 from Security-Onion-Solutions/fix/localfile_analyzer
...
Strip quotes and ensure file_path is typed as a list (localfile analyzer)
2022-07-05 16:28:56 -04:00
Mike Reeves
c6fac28804
Update soup
2022-07-05 16:26:44 -04:00
Jason Ertel
9d43b7ec89
Rollback string manipulation in favor of fixed unit tests
2022-07-05 16:21:27 -04:00
Jason Ertel
f6266b19cc
Fix unit test issues
2022-07-05 16:20:24 -04:00
Mike Reeves
df0a774ffd
Make soup enforce versions
2022-07-05 16:17:32 -04:00
weslambert
77ee30f31a
Merge pull request #8237 from Security-Onion-Solutions/feature/elastic_8_3_1
...
Bump Elastic to 8.3.1
2022-07-05 14:50:24 -04:00
weslambert
2938464501
Update to Kibana 8.3.1
2022-07-05 14:46:02 -04:00
weslambert
79e88c9ca3
Update to Kibana 8.3.1
2022-07-05 14:45:30 -04:00
Wes Lambert
e96206d065
Strip quotes and ensure file_path is typed as a list
2022-07-05 14:25:54 +00:00
Josh Brower
7fa9ca8fc6
Merge pull request #8233 from Security-Onion-Solutions/fix/remove-sudo-bpf
...
Remove unneeded sudo
2022-07-05 09:23:48 -04:00
Josh Brower
a1d1779126
Remove unneeded sudo
2022-07-05 09:21:05 -04:00
Josh Patterson
fb365739ae
Merge pull request #8225 from Security-Onion-Solutions/salltupdate
...
bootstrap-salt can now update to minor version with -r
2022-07-01 08:53:59 -04:00
m0duspwnens
5f898ae569
change to egrep
2022-07-01 08:47:46 -04:00
m0duspwnens
f0ff0d51f7
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 16:59:54 -04:00
m0duspwnens
7524ea2c05
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 15:10:13 -04:00
Mike Reeves
6bb979e2b6
Merge pull request #8219 from Security-Onion-Solutions/salty
...
Salty
2022-06-30 13:34:03 -04:00
Mike Reeves
8b3d5e808e
Fix repo location
2022-06-30 13:30:56 -04:00
Mike Reeves
e86b7bff84
Fix repo location
2022-06-30 13:29:21 -04:00
Josh Patterson
69ce3613ff
Merge pull request #8217 from Security-Onion-Solutions/salltupdate
...
point to salt3004.2
2022-06-30 11:29:35 -04:00
m0duspwnens
0ebd957308
point to salt3004.2
2022-06-30 11:26:03 -04:00
Josh Patterson
c3979f5a32
Merge pull request #8207 from Security-Onion-Solutions/salltupdate
...
Saltupdate 3004.2
2022-06-28 11:20:53 -04:00
m0duspwnens
8fccd4598a
update saltstack.list for 3004.2
2022-06-27 16:23:01 -04:00
weslambert
3552dfac03
Merge pull request #8199 from Security-Onion-Solutions/fix/filebeat_filestream_elastic8
...
Change type from 'log' to 'filestream' to ensure compatibility with E…
2022-06-27 14:58:54 -04:00
Josh Patterson
fba5592f62
Update minion.defaults.yaml
2022-06-27 12:10:18 -04:00
Josh Patterson
05e84699d1
Update master.defaults.yaml
2022-06-27 12:09:39 -04:00
Mike Reeves
f36c8da1fe
Update so-functions
2022-06-27 12:04:33 -04:00
Mike Reeves
080daee1d8
Update so-functions
2022-06-27 11:43:01 -04:00
Mike Reeves
909e876509
Update ubuntu.sls
2022-06-27 11:41:49 -04:00
Jason Ertel
ac68fa822b
Merge pull request #8200 from Security-Onion-Solutions/contrib
...
Add gh action for contrib check
2022-06-27 11:25:10 -04:00
Jason Ertel
675ace21f5
Add gh action for contrib check
2022-06-27 11:11:15 -04:00
weslambert
85f790b28a
Change type from 'log' to 'filestream' to ensure compatibility with Elastic 8
2022-06-27 10:39:58 -04:00
weslambert
d0818e83c9
Merge pull request #8197 from Security-Onion-Solutions/fix/localfile_analyzer_csv_path
...
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:36:59 -04:00
weslambert
568b43d0af
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:10:13 -04:00
Jason Ertel
2e123b7a4f
Merge pull request #8175 from Security-Onion-Solutions/kilo
...
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 08:16:39 -04:00
Jason Ertel
ba6f716e4a
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 06:09:04 -04:00
weslambert
10bcc43e85
Merge pull request #8167 from Security-Onion-Solutions/feature/update_es_8_2_3
...
Update to Elastic 8.2.3
2022-06-21 16:11:39 -04:00
weslambert
af687fb2b5
Update config_saved_objects.ndjson
2022-06-21 16:06:28 -04:00
weslambert
776cc30a8e
Update to ES 8.2.3
2022-06-21 16:06:01 -04:00
Doug Burks
00cf0b38d0
Merge pull request #8165 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve default dashboards #8136
2022-06-21 12:57:46 -04:00
Doug Burks
94c637449d
FIX: Improve default dashboards #8136
2022-06-21 12:53:06 -04:00
Josh Brower
0a203add3b
Merge pull request #8145 from Security-Onion-Solutions/defensivedepth-patch-1
...
pin v1.6.0
2022-06-17 13:14:58 -04:00
Josh Brower
b8ee896f8a
pin v1.6.0
2022-06-17 12:38:54 -04:00
Josh Brower
238e671f34
Merge pull request #8129 from Security-Onion-Solutions/fix/curator-cron
...
Change curator to daily for true cluster
2022-06-15 11:40:53 -04:00
Josh Brower
072cb3cca2
Change curator to daily for true cluster
2022-06-15 11:38:38 -04:00
weslambert
44595cb333
Merge pull request #8123 from Security-Onion-Solutions/foxtrot
...
Merge foxtrot into dev
2022-06-14 15:44:13 -04:00
weslambert
959cec1845
Delete Elastalert indices before upgrading to Elastic 8
2022-06-14 11:40:11 -04:00
Doug Burks
286909af4b
Merge pull request #8113 from Security-Onion-Solutions/fix/pfsense-category
...
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:08:00 -04:00
doug
025993407e
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:03:44 -04:00
weslambert
151a42734c
Update Elastic version to 8.2.2
2022-06-08 15:07:45 -04:00
weslambert
11e3576e0d
Update Elastic version to 8.2.2
2022-06-08 15:07:07 -04:00
weslambert
adeccd0e7f
Merge pull request #8097 from Security-Onion-Solutions/dev
...
Merge latest dev into foxtrot
2022-06-08 15:01:09 -04:00
weslambert
aadf391e5a
Temporarily downgrade version for merge
2022-06-08 14:59:01 -04:00
weslambert
47f74fa5c6
Temporarily downgrade version for merge
2022-06-08 14:58:05 -04:00
Jason Ertel
e405750d26
Merge pull request #8095 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.140
2022-06-08 09:07:56 -04:00
Jason Ertel
e36c33485d
Bump version to 2.3.140
2022-06-08 09:04:57 -04:00
Mike Reeves
65165e52f4
Merge pull request #8086 from Security-Onion-Solutions/dev
...
2.3.130
2022-06-07 15:51:12 -04:00
Mike Reeves
2cceae54df
Merge pull request #8087 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 13:44:38 -04:00
Mike Reeves
8912e241aa
2.3.130
2022-06-07 13:41:51 -04:00
Mike Reeves
7357f157ec
Merge pull request #8085 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 12:04:47 -04:00
Mike Reeves
37881bd4b6
2.3.130
2022-06-07 11:34:10 -04:00
Josh Brower
2574f0e23d
Merge pull request #8081 from Security-Onion-Solutions/fix/fleetdm-websockets
...
Allow websockets for fleetdm
2022-06-06 19:15:02 -04:00
Josh Brower
c9d9804c3a
Allow websockets for fleetdm
2022-06-06 17:26:24 -04:00
Doug Burks
73baa1d2f0
Merge pull request #8073 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md to include links to Dashboards and Cases
2022-06-04 08:53:54 -04:00
Doug Burks
dce415297c
improve readability in motd.md
2022-06-04 06:59:09 -04:00
Doug Burks
de126647f8
Update motd.md to include links to Dashboards and Cases
2022-06-04 06:55:08 -04:00
Doug Burks
c34f456151
Merge pull request #8069 from Security-Onion-Solutions/dougburks-patch-1
...
add bar and pie examples to overview dashboard in dashboards.queries.…
2022-06-03 15:04:16 -04:00
Doug Burks
83bff5ee87
add bar and pie examples to overview dashboard in dashboards.queries.json
2022-06-03 15:02:40 -04:00
Doug Burks
918f431728
Merge pull request #8065 from Security-Onion-Solutions/dougburks-patch-1
...
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:13:39 -04:00
Doug Burks
4a886338c8
fix description field for default dashboard in dashboards.queries.json
2022-06-03 11:10:01 -04:00
Doug Burks
7da1802eae
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:03:48 -04:00
Mike Reeves
ff92b524c2
Merge pull request #8062 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2022-06-02 11:51:42 -04:00
Mike Reeves
395eaa39b4
Update soup
2022-06-02 11:45:37 -04:00
Mike Reeves
2867a32931
Merge pull request #8061 from Security-Onion-Solutions/soup130
...
soup for 130
2022-06-02 10:42:17 -04:00
Mike Reeves
fce43cf390
soup for 130
2022-06-02 10:33:18 -04:00
Josh Patterson
e5c9b91529
Merge pull request #8054 from Security-Onion-Solutions/dmz_receiver
...
Dmz receiver
2022-06-01 15:31:42 -04:00
m0duspwnens
e5b74bcb78
remove podman state
2022-06-01 15:26:25 -04:00
Doug Burks
91f8d3e5e9
Merge pull request #8050 from Security-Onion-Solutions/fix/elastalert-query
...
FIX: Elastalert query in Hunt #8049
2022-05-31 16:54:34 -04:00
Doug Burks
269b16bbfd
https://github.com/Security-Onion-Solutions/securityonion/issues/8049
2022-05-31 16:51:05 -04:00
Doug Burks
cd382a1b25
FIX: Elastalert query in Hunt #8049
2022-05-31 16:50:32 -04:00
Doug Burks
e1c9b0d108
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:52 -04:00
Doug Burks
9a98667e85
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:11 -04:00
weslambert
494ce0756d
Merge pull request #8045 from Security-Onion-Solutions/fix/mhr_naming
...
Fix naming for Malware Hash Registry analyzer
2022-05-31 07:52:48 -04:00
Wes Lambert
7f30a364ee
Make sure everything is added back after renaming mhr to malwarehashregistry
2022-05-31 11:44:35 +00:00
Wes Lambert
c82aa89497
Fix Malware Hash Registry naming so it's more descriptive in SOC
2022-05-31 11:41:48 +00:00
Josh Brower
025677a1e6
Merge pull request #8034 from Security-Onion-Solutions/feature/sigmafp
...
Feature/SigmaCustomFilters
2022-05-31 07:25:44 -04:00
Josh Brower
a5361fb745
Change Target_log name
2022-05-28 18:07:05 -04:00
Mike Reeves
30d7801ae1
Merge pull request #8033 from Security-Onion-Solutions/kilo
2022-05-28 11:38:35 -04:00
Jason Ertel
210bc556db
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:29:04 -04:00
Jason Ertel
e87e672b9e
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:28:20 -04:00
Jason Ertel
a70da41f20
Merge pull request #8032 from Security-Onion-Solutions/kilo
...
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:34:40 -04:00
Jason Ertel
8bb02763dc
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:28:10 -04:00
weslambert
a59ada695b
Merge pull request #8031 from Security-Onion-Solutions/fix/screenshots
...
Fix/screenshots
2022-05-27 17:05:51 -04:00
doug
b93a108386
update Cases screenshot in README
2022-05-27 16:33:08 -04:00
doug
6089f3906d
update screenshots and README
2022-05-27 16:32:00 -04:00
Josh Brower
94ee45ac63
Merge pull request #8029 from Security-Onion-Solutions/upgrade/navigator
...
Upgrade Navigator to 4.6.4
2022-05-27 14:46:59 -04:00
Josh Brower
43cb78a6a8
Upgrade Navigator
2022-05-27 14:21:11 -04:00
Josh Patterson
76bb1fbbcc
Merge pull request #8014 from Security-Onion-Solutions/issue/7918
...
manage suricata classifications.config
2022-05-26 13:13:03 -04:00
m0duspwnens
53d6e1d30d
simplfy
2022-05-26 11:51:17 -04:00
m0duspwnens
1bfde852f5
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:43:31 -04:00
m0duspwnens
53883e4ade
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:40:33 -04:00
weslambert
1a0ac4d253
Merge pull request #8007 from Security-Onion-Solutions/fix/filestream-id
...
Add filestream input ID for RITA logs
2022-05-25 10:11:36 -04:00
weslambert
44622350ea
Add ID for RITA filestream inputs
2022-05-25 10:09:01 -04:00
weslambert
99864f4787
Merge pull request #8001 from Security-Onion-Solutions/feature/analyzer_readme
...
Add configuration requirements for various analyzers
2022-05-25 09:33:07 -04:00
Doug Burks
6bd02c0b99
Merge pull request #8003 from Security-Onion-Solutions/feature/elastic-7.17.4
...
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:24:13 -04:00
Doug Burks
1d0bb21908
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:30 -04:00
Doug Burks
bde06e7ec5
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:01 -04:00
Wes Lambert
b93512eb01
Adjust verbiage around pillar configuration
2022-05-24 12:36:32 +00:00
Wes Lambert
92dee14ee8
Add configuration requirements for various analyzers
2022-05-24 12:29:14 +00:00
weslambert
3e6dfcfaca
Merge pull request #7996 from Security-Onion-Solutions/weslambert-patch-2
...
Create Virustotal README
2022-05-23 11:43:43 -04:00
weslambert
a6f1bf3aef
Create Virustotal README
2022-05-23 11:39:44 -04:00
Jason Ertel
88f17f037e
Merge pull request #7982 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.9.0-alpha.3
2022-05-19 13:28:58 -04:00
Jason Ertel
c20859f8c3
Upgrade to Kratos 0.9.0-alpha.3
2022-05-18 17:05:21 -04:00
Jason Ertel
c95bafd521
Merge pull request #7969 from Security-Onion-Solutions/fix/helpers-analyzers
...
Only import yaml module when config is loaded
2022-05-18 07:15:32 -04:00
Wes Lambert
429ccb2dcc
Only import yaml module when config is loaded
2022-05-18 02:07:39 +00:00
weslambert
94ca3ddbda
Merge pull request #7961 from Security-Onion-Solutions/weslambert-patch-1
...
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 13:33:24 -04:00
weslambert
d3206a048f
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 12:49:16 -04:00
weslambert
ff855eb8f7
Merge pull request #7958 from Security-Onion-Solutions/feature/mhr_analyzer
...
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 12:42:01 -04:00
Wes Lambert
8af1f19ac3
Another no_results change
2022-05-17 16:12:43 +00:00
Wes Lambert
e4a7e3cba6
Change 'No results found.' to 'no_results'
2022-05-17 16:11:58 +00:00
weslambert
2688083ff1
Merge pull request #7959 from Security-Onion-Solutions/feature/whoislookup-analyzer
...
Add Whoislookup RDAP-based analyzer
2022-05-17 12:09:06 -04:00
Wes Lambert
766e9748c5
Add Whoislookup RDAP-based analyzer
2022-05-17 15:52:12 +00:00
weslambert
3761b491c0
Remove whitespace
2022-05-17 10:50:33 -04:00
Wes Lambert
e8fc3ccdf4
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 14:44:53 +00:00
Doug Burks
eb9597217c
Merge pull request #7949 from Security-Onion-Solutions/fix/dashboards-hunt-queries
...
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:47:06 -04:00
doug
5cbb50a781
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:33:48 -04:00
Jason Ertel
685789de33
Merge pull request #7936 from Security-Onion-Solutions/kilo
...
Improved unit test coverage of new analyzers; Utilize localized summa…
2022-05-12 16:47:18 -04:00
Jason Ertel
b45b6b198b
Improved unit test coverage of new analyzers; Utilize localized summaries; Require 100% code coverage on analyzers
2022-05-12 16:32:47 -04:00
weslambert
6c506bbab0
Merge pull request #7935 from Security-Onion-Solutions/fix/pulsedive
...
Fix Pulsedive analyzer logic
2022-05-12 15:20:15 -04:00
Wes Lambert
3dc266cfa9
Add test for when indicator is not found
2022-05-12 19:02:41 +00:00
Wes Lambert
a233c08830
Update logic to handle indicators that are not present in database.
2022-05-12 19:02:02 +00:00
Doug Burks
58b049257d
Merge pull request #7932 from Security-Onion-Solutions/dougburks-patch-1
...
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:24:18 -04:00
Doug Burks
6ed3f42449
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:23:00 -04:00
m0duspwnens
d8abc0a195
if in dmz_nodes dont add to filebeta
2022-05-11 11:51:18 -04:00
m0duspwnens
a641346c02
prevent nodes with logstash:dmz:true from being added to logstash:nodes pillar
2022-05-10 17:28:19 -04:00
Jason Ertel
60b55acd6f
Merge pull request #7926 from Security-Onion-Solutions/kilo
...
Add support for analyzers in airgapped environments
2022-05-10 17:12:18 -04:00
Jason Ertel
35e47c8c3e
Add support for analyzers in airgapped environments
2022-05-10 16:51:00 -04:00
weslambert
7f797a11f8
Merge pull request #7924 from Security-Onion-Solutions/analyzer-docs
...
Update analyzer docs with information about analyzers that require au…
2022-05-10 09:40:50 -04:00
Jason Ertel
91a7f25d3a
Corrected brand name capitalization
2022-05-10 09:39:19 -04:00
weslambert
34d57c386b
Update analyzer docs with information about analyzers that require authentication
2022-05-10 09:32:18 -04:00
weslambert
000e813fbb
Merge pull request #7921 from Security-Onion-Solutions/fix/analyzer-packages
...
Update analyzer packages to those downloaded by Alpine and add additional build script option
2022-05-09 16:43:31 -04:00
Wes Lambert
555ca2e277
Update analyzer build/testing script to download necessary Python packages
2022-05-09 20:06:39 +00:00
Wes Lambert
32adba6141
Update analyzer packages with those built from native (Alpine) Docker image
2022-05-09 20:04:41 +00:00
Jason Ertel
e19635e44a
Merge pull request #7920 from Security-Onion-Solutions/kilo
...
Disable MRU queries on dashboards
2022-05-09 15:08:55 -04:00
Jason Ertel
31c04aabdd
Disable MRU queries on dashboards
2022-05-09 15:06:43 -04:00
Jason Ertel
dc209a37cd
Merge pull request #7916 from Security-Onion-Solutions/kilo
...
Disable actions on dashboards group-by tables
2022-05-09 11:52:22 -04:00
Jason Ertel
3f35dc54d2
Disable actions on dashboards group-by tables
2022-05-09 11:44:39 -04:00
Josh Brower
8e368bdebe
Merge in upstream dev
2022-05-06 20:01:07 -04:00
Jason Ertel
0e64a9e5c3
Merge pull request #7912 from Security-Onion-Solutions/kilo
...
Add dashboard ref to soc.json
2022-05-06 15:18:05 -04:00
Jason Ertel
0786191fc9
Add dashboard ref to soc.json
2022-05-06 15:16:27 -04:00
Jason Ertel
60763c38db
Merge pull request #7911 from Security-Onion-Solutions/kilo
...
Analyzers + Dashboards
2022-05-06 13:50:54 -04:00
weslambert
9800f59ed7
Add Urlscan to observable support matrix
2022-05-06 13:11:43 -04:00
Wes Lambert
ccac71f649
Fix formatting/whitespace
2022-05-06 17:08:40 +00:00
Wes Lambert
1990ba0cf0
Fix formatting/whitespace
2022-05-06 17:08:33 +00:00
Wes Lambert
8ff5778569
Add Urlscan analyzer and tests
2022-05-06 17:01:06 +00:00
Jason Ertel
bee4cf4c52
Fix typo in analyzer desc
2022-05-06 09:20:03 -04:00
Jason Ertel
105c95909c
Dashboard queries
2022-05-04 19:32:06 -04:00
Jason Ertel
890bcd58f9
Merge branch 'dev' into kilo
2022-05-04 19:25:08 -04:00
weslambert
a96c665d04
Change test name for EmailRep
2022-05-03 14:13:25 -04:00
weslambert
f3a91d9fcd
Add EmailRep analyzer to observable support matrix
2022-05-03 10:10:57 -04:00
Wes Lambert
5a9acb3857
Add EmailRep analyzer and tests
2022-05-03 14:06:32 +00:00
Wes Lambert
8b5666b238
Ensure API key is used
2022-05-03 12:48:06 +00:00
weslambert
efb229cfcb
Update to match configuration in analyzer dir
2022-05-02 16:35:21 -04:00
weslambert
2fcb2b081d
Update allowed complexity to 12
2022-05-02 16:14:43 -04:00
weslambert
25f17a5efd
Update allowed complexity to 11
2022-04-29 09:42:57 -04:00
weslambert
66b4fe9f58
Add additional information around URI and User Agent
2022-04-28 17:14:36 -04:00
Wes Lambert
c001708707
Add Pulsedive analyzer and tests
2022-04-28 20:56:03 +00:00
weslambert
4edd729596
Add initial supported observable matrix/table
2022-04-27 08:58:34 -04:00
Wes Lambert
76f183b112
Add Greynoise analyzer and tests
2022-04-26 17:25:35 +00:00
Wes Lambert
bd63753d80
Update analyzer name/description
2022-04-25 19:27:10 +00:00
Wes Lambert
15fcaa7030
Add localfile analyzer and tests
2022-04-25 19:23:35 +00:00
Jason Ertel
71a86b0a3c
Merge pull request #7856 from Security-Onion-Solutions/bumpver
...
Bump version
2022-04-25 13:01:19 -04:00
Jason Ertel
e2145720bd
Bump version
2022-04-25 12:10:29 -04:00
Mike Reeves
b4aa59c619
Merge pull request #7853 from Security-Onion-Solutions/dev
...
2.3.120
2022-04-25 11:33:05 -04:00
Mike Reeves
6975153cf4
Merge pull request #7852 from Security-Onion-Solutions/2.3.120
...
2.3.120
2022-04-25 08:59:52 -04:00
Mike Reeves
0935f51667
2.3.120
2022-04-25 08:57:35 -04:00
Mike Reeves
f92d65737b
2.3.120
2022-04-25 08:53:04 -04:00
Josh Patterson
8f5967911b
Merge pull request #7847 from Security-Onion-Solutions/m0duspwnens-patch-1
...
add eval
2022-04-22 16:06:01 -04:00
Josh Patterson
80eb31368a
add eval
2022-04-22 16:04:29 -04:00
Jason Ertel
d8fdf2b701
Merge branch 'dev' into kilo
2022-04-22 15:11:24 -04:00
Jason Ertel
459d388614
Only override nameservers if the first nameserver given is non empty
2022-04-22 15:08:56 -04:00
Wes Lambert
fbf6e64e67
Add initial OTX analyzer and tests
2022-04-22 17:13:40 +00:00
weslambert
677db7c563
Merge pull request #7841 from Security-Onion-Solutions/weslambert-patch-2
...
Update shard count for Zeek in setup
2022-04-21 17:27:57 -04:00
weslambert
1bb216954c
Merge pull request #7840 from Security-Onion-Solutions/weslambert-patch-1
...
Update shards for Zeek
2022-04-21 17:26:57 -04:00
weslambert
c81988ab00
Update shard count for Zeek in setup
2022-04-21 17:26:30 -04:00
weslambert
542db5b7f5
Update defaults.yaml
2022-04-21 17:24:24 -04:00
Wes Lambert
b2db32a2c7
Add function/test for non-existent VT api_key
2022-04-21 17:33:24 +00:00
Wes Lambert
9287d6adf7
Reduce size of test output for test
2022-04-21 16:56:22 +00:00
Wes Lambert
c8e189f35a
Add source-packages for JA3er
2022-04-21 16:46:45 +00:00
Wes Lambert
5afcc8de4f
Add JA3er analyzer and associated test
2022-04-21 16:42:46 +00:00
weslambert
d7eed52fae
Change -f to -r
2022-04-21 09:46:44 -04:00
Doug Burks
2910b56ea1
Merge pull request #7835 from Security-Onion-Solutions/elastic-7.17.3
...
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 09:02:51 -04:00
Doug Burks
e608285341
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:57:08 -04:00
Doug Burks
04856540dc
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:54:09 -04:00
Doug Burks
feb7eeeb8e
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:47:40 -04:00
Doug Burks
44f4b1da7f
Merge pull request #7832 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-04-20 17:00:09 -04:00
Doug Burks
1edb443c5d
so-playbook-sync pgrep should be more strict to avoid multiple matches on Ubuntu
2022-04-20 16:48:26 -04:00
Doug Burks
8fc03afdc0
so-sensor-clean pgrep should be more strict to avoid matching multiples on Ubuntu
2022-04-20 16:47:18 -04:00
Mike Reeves
fe09b5b0d1
Merge pull request #7831 from Security-Onion-Solutions/awlocal
...
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:42:58 -04:00
Mike Reeves
c3952e94c8
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:36:38 -04:00
Doug Burks
3aac644da5
Merge pull request #7830 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve Zeek file extraction #7829
2022-04-20 14:13:13 -04:00
Doug Burks
15ef0968d9
FIX: Improve Zeek file extraction #7829
2022-04-20 14:01:46 -04:00
Jason Ertel
aeb70dad8f
Doc updates
2022-04-19 14:31:21 -04:00
Jason Ertel
4129cef9fb
Add new spamhaus analyzer
2022-04-19 12:12:52 -04:00
Josh Patterson
40d9335573
Merge pull request #7822 from Security-Onion-Solutions/workstation_state
...
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:21:35 -04:00
m0duspwnens
807f6adf1e
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:19:09 -04:00
Doug Burks
6339ee3bf3
Merge pull request #7818 from Security-Onion-Solutions/dougburks-patch-1
...
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:35:22 -04:00
Doug Burks
5d62ece03b
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:33:54 -04:00
Doug Burks
6905ca276a
Merge pull request #7816 from Security-Onion-Solutions/dougburks-patch-1
...
remove old comments from so-whiptail
2022-04-18 11:30:43 -04:00
Doug Burks
3682754399
remove old comments from so-whiptail
2022-04-18 11:29:46 -04:00
Jason Ertel
0cb73d8f6a
Merge branch 'dev' into kilo
2022-04-18 11:04:32 -04:00
Mike Reeves
186258687e
Merge pull request #7815 from Security-Onion-Solutions/awlocal
...
Fix Analyst Install Loop
2022-04-18 11:04:10 -04:00
Mike Reeves
012ff3e1bc
Fix Analyst Install Loop
2022-04-18 11:02:19 -04:00
Josh Brower
891a197a6a
Merge pull request #7814 from Security-Onion-Solutions/defensivedepth-patch-2
...
Fix ES/LS Log Pruning
2022-04-18 10:45:27 -04:00
Josh Brower
b35b505f0a
Fix pattern matching
2022-04-18 10:39:04 -04:00
Josh Brower
2b39570b08
Fix matching logic
2022-04-18 10:37:38 -04:00
Jason Ertel
159122b52c
Merge branch 'dev' into kilo
2022-04-18 10:11:37 -04:00
Doug Burks
3fb7399000
Merge pull request #7813 from Security-Onion-Solutions/dougburks-patch-1
...
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 08:24:52 -04:00
Doug Burks
400879c079
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 07:53:57 -04:00
Doug Burks
62f3f13bbc
Merge pull request #7803 from Security-Onion-Solutions/dougburks-patch-1
...
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:48:12 -04:00
Doug Burks
0eda9a3bd7
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:45:01 -04:00
Doug Burks
ee00678362
Merge pull request #7802 from Security-Onion-Solutions/dougburks-patch-1
...
Replace old saltstack repo in so-preflight
2022-04-15 13:17:14 -04:00
Doug Burks
ce192c2526
Update so-preflight
2022-04-15 13:11:15 -04:00
Josh Brower
d60d31f723
Merge pull request #7801 from Security-Onion-Solutions/defensivedepth-patch-1
...
Remove thehive entries from so-status
2022-04-15 12:25:21 -04:00
Josh Brower
bd19da1878
Remove thehive entries from so-status
2022-04-15 12:21:56 -04:00
Doug Burks
f461d01961
Merge pull request #7800 from Security-Onion-Solutions/dougburks-patch-1
...
Improve grammar in so-whiptail
2022-04-15 10:52:29 -04:00
Doug Burks
a69d361d1b
Improve grammar in so-whiptail
2022-04-15 10:45:34 -04:00
Josh Brower
19cba9dca9
Merge pull request #7798 from Security-Onion-Solutions/awlocal
...
Make analyst iso install init management interface
2022-04-15 07:26:53 -04:00
Mike Reeves
5081a81a6c
Make analyst iso install init management interface
2022-04-14 20:00:58 -04:00
Josh Patterson
ba61057433
Merge pull request #7796 from Security-Onion-Solutions/fix_analyst_setup
...
Fix analyst setup
2022-04-14 16:12:53 -04:00
m0duspwnens
b8a80f76cf
change words
2022-04-14 16:09:39 -04:00
Josh Patterson
be2573bb7d
Merge pull request #7794 from Security-Onion-Solutions/soup_salt_influx
...
remove influxdb module patched state files when salt is upgraded
2022-04-14 16:08:10 -04:00
m0duspwnens
36aef87a3c
remove cd before running so-setup analyst
2022-04-14 16:03:43 -04:00
m0duspwnens
02c19da3c4
remove influxdb module patched state files when salt is upgraded
2022-04-14 15:00:14 -04:00
Josh Patterson
2d094a3bfc
Merge pull request #7784 from Security-Onion-Solutions/workstation_script
...
modify so-analyst-install to work with new states and install on managers
2022-04-13 14:37:24 -04:00
m0duspwnens
371fda09db
fix copy paste fail
2022-04-13 14:28:05 -04:00
m0duspwnens
149375115e
warn about required reboot and prompt if reboot desired at completion of install
2022-04-13 14:26:14 -04:00
m0duspwnens
4728bea633
fix typo
2022-04-13 14:03:09 -04:00
m0duspwnens
3ee09db752
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:48 -04:00
m0duspwnens
6477e6c5a2
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:39 -04:00
m0duspwnens
2389d3fac9
modify so-analyst-install to work with new states and install on managers
2022-04-13 12:32:05 -04:00
Mike Reeves
ecc29b586d
Merge pull request #7772 from Security-Onion-Solutions/awlocal
2022-04-12 15:45:56 -04:00
Mike Reeves
2977604d96
Merge branch 'awlocal' of https://github.com/Security-Onion-Solutions/securityonion into awlocal
2022-04-12 15:39:45 -04:00
Mike Reeves
5253cb5d25
Remove keys at the end of an install
2022-04-12 15:33:17 -04:00
Josh Brower
1cb5a791ca
Add idh req_storage elif
2022-04-12 14:29:07 -04:00
Mike Reeves
8408628b03
Stop thehive on soup
2022-04-12 13:54:08 -04:00
Mike Reeves
02f4cd9926
Replace salt code on a saltstack update
2022-04-12 12:15:22 -04:00
Mike Reeves
c1824e9f17
Replace salt code on a saltstack update
2022-04-12 11:55:45 -04:00
Mike Reeves
081d7e3a09
Replace salt code on a saltstack update
2022-04-12 11:20:26 -04:00
Mike Reeves
a7221ba2b4
Remove summary for thins the workstation doesnt care about
2022-04-12 11:06:12 -04:00
Mike Reeves
aa90a016d7
Change disk requirements for IDH
2022-04-12 10:44:45 -04:00
Josh Patterson
dbddff7be7
Merge pull request #7766 from Security-Onion-Solutions/issue/7763
...
Issue/7763
2022-04-11 16:44:04 -04:00
Josh Brower
f1574de827
Merge pull request #7765 from Security-Onion-Solutions/fix/compress-clean-elastic-logs
...
Compress + Clean ES & Logstash App Logs
2022-04-11 16:43:03 -04:00
Josh Brower
886d69fb38
Compress + Clean ES & Logstash App Logs
2022-04-11 16:09:24 -04:00
m0duspwnens
d68b6e7c9a
only start if exit code != 0
2022-04-11 16:03:00 -04:00
m0duspwnens
d102ca298d
move messages about starting services on soup failure before exit message
2022-04-11 16:01:36 -04:00
m0duspwnens
9914148441
more verbose
2022-04-11 15:51:11 -04:00
m0duspwnens
464772d7d3
start salt-master and salt-minion service is soup fails and exits
2022-04-11 15:43:09 -04:00
Mike Reeves
13f6957ae8
Merge pull request #7764 from Security-Onion-Solutions/awlocal
2022-04-11 15:40:06 -04:00
m0duspwnens
2a18059ad9
use quotes
2022-04-11 15:37:07 -04:00
m0duspwnens
01510c184a
set_os and set_cron_service_name sooner
2022-04-11 15:36:02 -04:00
Mike Reeves
eb2d759bf8
Add more whiptail menus
2022-04-11 15:14:29 -04:00
Mike Reeves
5ed7361e3a
Add more whiptail menus
2022-04-11 15:14:06 -04:00
m0duspwnens
6ed8694008
dont need to pass -t
2022-04-11 15:11:57 -04:00
m0duspwnens
79dc2374e0
check that salt-master is running before requiring manager
2022-04-11 15:09:00 -04:00
m0duspwnens
a2180a6721
ensure salt-master service is running before proceeding with soup
2022-04-11 15:01:41 -04:00
Mike Reeves
f9633e7287
Add more whiptail menus
2022-04-11 14:51:17 -04:00
Mike Reeves
0b2745b342
Sending things to the screen
2022-04-11 11:49:24 -04:00
Mike Reeves
ea34b69795
Sending things to the screen
2022-04-11 11:46:42 -04:00
Mike Reeves
97e691c321
Sending things to the screen
2022-04-11 11:43:13 -04:00
Mike Reeves
a3bf904e2d
Import GPG
2022-04-11 11:32:08 -04:00
Mike Reeves
9ed49ef318
Import GPG
2022-04-11 11:29:56 -04:00
Mike Reeves
f7760394a1
Import GPG
2022-04-11 11:25:54 -04:00
Mike Reeves
d9416f3828
Salt local install of Analyst Workstation
2022-04-11 11:04:25 -04:00
Jason Ertel
2d025e944c
Add yaml since helpers module uses it
2022-04-09 17:48:21 -04:00
Jason Ertel
202ca34c6f
Remove obsolete source/site pkg dirs
2022-04-09 14:36:21 -04:00
Jason Ertel
f9568626f2
Merge branch 'dev' into kilo
2022-04-09 09:02:55 -04:00
Jason Ertel
224e30c0ee
Change localized table layout
2022-04-08 17:31:15 -04:00
Jason Ertel
ebcfbaa06d
Analyzer improvements
2022-04-08 16:57:40 -04:00
Josh Patterson
365866c9cc
Merge pull request #7750 from Security-Onion-Solutions/issue_7730
...
ensure bash is used for influx query
2022-04-08 15:26:24 -04:00
m0duspwnens
59d5be682a
ensure bash is used for influx query
2022-04-08 15:01:38 -04:00
Mike Reeves
7805311ea2
Merge pull request #7748 from Security-Onion-Solutions/bravo
...
Bravo
2022-04-08 14:48:54 -04:00
Josh Patterson
8757ca0dfb
Merge pull request #7749 from Security-Onion-Solutions/issue/7113
...
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:10:54 -04:00
m0duspwnens
3e8c687d61
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:05:38 -04:00
Jason Ertel
13c9af5a5a
Clearing hotfix
2022-04-08 10:23:44 -04:00
Mike Reeves
a5313b330f
Merge master into dev
2022-04-08 09:07:46 -04:00
Mike Reeves
0bc3d5d757
Merge pull request #7741 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110 20220407
2022-04-07 16:30:50 -04:00
Mike Reeves
6d88a5b541
Merge pull request #7740 from Security-Onion-Solutions/hfix0407
...
2.3.110 hotfix 0407
2022-04-07 16:11:58 -04:00
Mike Reeves
6a28e752f0
2.3.110 hotfix 0407
2022-04-07 16:03:13 -04:00
Josh Brower
ae8d300567
Merge pull request #7738 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Include firewall state
2022-04-07 14:52:31 -04:00
Mike Reeves
2ad3f63cb5
Merge pull request #7739 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-04-07 14:46:20 -04:00
Mike Reeves
93e04850c4
Update HOTFIX
2022-04-07 14:40:54 -04:00
Josh Brower
36b2d78dfe
Include firewall state
2022-04-07 14:02:21 -04:00
Jason Ertel
44e318e046
Provide CLI feedback for missing input
2022-04-07 10:16:44 -04:00
Josh Patterson
09e7b5a8bf
Merge pull request #7733 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-07 09:05:51 -04:00
m0duspwnens
8fbd16f75d
ensure salt.list is absent
2022-04-07 09:03:51 -04:00
m0duspwnens
722b200e16
add retry to apt_update incase running in background
2022-04-07 08:58:07 -04:00
m0duspwnens
b2a98af18b
proper formatting
2022-04-07 08:55:30 -04:00
m0duspwnens
be3769fd7c
run apt-get update if saltstack.list changes
2022-04-07 08:53:44 -04:00
m0duspwnens
08ac696f14
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-06 17:38:06 -04:00
Josh Brower
86771e1fe6
Merge pull request #7732 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Feature/idh allow multiple int
2022-04-06 17:21:30 -04:00
Josh Brower
f5e539a05c
Initial support for restricting IDH services on MGT IP
2022-04-06 17:16:38 -04:00
Josh Patterson
0c1ac729e1
Merge pull request #7731 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update the centos repo for airgap prior to applying hotfix
2022-04-06 17:00:09 -04:00
m0duspwnens
833106775f
update the centos repo for airgap prior to applying hotfix or standard soup run
2022-04-06 16:53:55 -04:00
Mike Reeves
fbd417b09e
Merge pull request #7720 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-05 20:29:17 -04:00
Mike Reeves
4224d1f258
Merge pull request #7719 from Security-Onion-Solutions/hfix0405
...
2.3.110 hotfix 0405
2022-04-05 19:17:42 -04:00
Mike Reeves
79175b57fa
2.3.110 hotfix 0405
2022-04-05 19:15:20 -04:00
Josh Patterson
5717382340
Merge pull request #7717 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
use -r for bootstrap-salt for ubuntu
2022-04-05 17:37:22 -04:00
m0duspwnens
cf68aeb36e
use -r for bootstrap-salt for ubuntu
2022-04-05 17:35:03 -04:00
Josh Patterson
882eb83fee
Merge pull request #7716 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
point to so repo
2022-04-05 17:30:10 -04:00
m0duspwnens
89c7f5b356
point to so repo
2022-04-05 17:28:47 -04:00
Mike Reeves
bed9a20025
Merge pull request #7714 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
proper salt format
2022-04-05 15:45:36 -04:00
m0duspwnens
89518b5939
proper salt format
2022-04-05 15:44:06 -04:00
Mike Reeves
07b14d7fa7
Merge pull request #7713 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update update_repo function
2022-04-05 15:42:45 -04:00
m0duspwnens
1248ba8924
update update_repo function
2022-04-05 15:40:39 -04:00
Josh Patterson
cbbe3b9248
Merge pull request #7712 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
add deb to saltstack.list
2022-04-05 14:45:46 -04:00
m0duspwnens
b467cde9ad
add deb to saltstack.list
2022-04-05 14:42:36 -04:00
Josh Patterson
6d6f328cad
Merge pull request #7711 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
manage repo conf for ubuntu
2022-04-05 13:50:32 -04:00
m0duspwnens
020871ef61
update hotfix version
2022-04-05 13:49:28 -04:00
m0duspwnens
e08b13629a
manage repo conf for ubuntu
2022-04-05 13:41:26 -04:00
Jason Ertel
d8defdd7b0
Improve unit test stability
2022-04-05 07:36:25 -04:00
Jason Ertel
d2fa80e48a
Update status codes to match SOC
2022-04-05 07:20:23 -04:00
Doug Burks
1e187f0c44
Merge pull request #7703 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-04 23:37:28 -04:00
Josh Brower
7906c053b1
Initial support for restricting IDH services on MGT IP
2022-04-04 16:46:05 -04:00
Mike Reeves
f5073243f9
Merge pull request #7702 from Security-Onion-Solutions/hfix0401
...
2.3.110 hotfix 0401
2022-04-04 16:13:08 -04:00
Mike Reeves
0c7a07f5c0
Merge pull request #7667 from Security-Onion-Solutions/analystsetup
...
Analyst Setup
2022-04-04 16:09:13 -04:00
Mike Reeves
04370a04ce
2.3.110 hotfix 0401
2022-04-04 16:06:20 -04:00
Jason Ertel
04eef0d31f
Merge branch 'dev' into kilo
2022-04-04 15:59:09 -04:00
Jason Ertel
7df6833568
Add unit tests for Urlhaus; remove placeholder whois analyzer
2022-04-04 15:58:53 -04:00
Josh Patterson
809bc1858c
Merge pull request #7700 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
salt 3004.1 hotfix
2022-04-04 13:32:34 -04:00
m0duspwnens
f9563b2dc4
patch influxdb modules
2022-04-04 12:57:36 -04:00
m0duspwnens
b7aff4f4df
remove influxdb state files
2022-04-04 12:28:23 -04:00
m0duspwnens
1e955e0d38
enable highstate before highstate run for hotfix
2022-04-04 11:28:03 -04:00
m0duspwnens
127420b472
hotfix function for 2.3.10 hotfix 1
2022-04-04 10:39:44 -04:00
Wes Lambert
07cf3469a0
Remove pyyaml for requirements file
2022-04-04 11:40:02 +00:00
Wes Lambert
39101cafd1
Add UrlHaus analyzer and helpers script
2022-04-01 21:11:57 +00:00
Mike Reeves
5387caf6f4
fix formatting
2022-04-01 16:50:55 -04:00
Mike Reeves
07783713e6
fix formatting
2022-04-01 16:22:40 -04:00
Mike Reeves
5974279ed7
fix formatting
2022-04-01 16:17:22 -04:00
Mike Reeves
277c7d9d33
fix formatting
2022-04-01 16:05:37 -04:00
Mike Reeves
d20a07bb5f
fix formatting
2022-04-01 16:00:44 -04:00
Josh Patterson
7f4c2687cf
Merge pull request #7691 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove influx patch state files
2022-04-01 15:58:03 -04:00
m0duspwnens
48e40513ff
remove influx patch state files
2022-04-01 15:53:48 -04:00
Mike Reeves
a449a91f38
fix formatting
2022-04-01 15:52:38 -04:00
Mike Reeves
76f43380d9
fix so salt master gets installed
2022-04-01 14:29:24 -04:00
Mike Reeves
7c39559787
fix so salt master gets installed
2022-04-01 14:19:17 -04:00
Jason Ertel
cedb23f4bc
Merge pull request #7689 from Security-Onion-Solutions/esup
...
Upgrade to ES 7.17.2
2022-04-01 13:57:04 -04:00
Jason Ertel
6e7b2ccedc
Upgrade to ES 7.17.2
2022-04-01 13:50:57 -04:00
Mike Reeves
8e9386fcd4
fix the yum commands
2022-04-01 13:17:13 -04:00
Mike Reeves
97fc652a97
fix the yum commands
2022-04-01 11:54:55 -04:00
Mike Reeves
2782c9b464
Update salt versions
2022-04-01 11:26:58 -04:00
Josh Patterson
c429423dae
Merge pull request #7683 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
Update to salt 3004.1
2022-04-01 11:19:31 -04:00
m0duspwnens
45dd7d4758
salt 3004.1 in setup
2022-04-01 11:17:38 -04:00
Josh Patterson
b5ce8756e9
Merge pull request #7686 from Security-Onion-Solutions/workstation_state
...
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:06:53 -04:00
m0duspwnens
e14463c0ab
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:05:34 -04:00
Mike Reeves
d524f3833b
Let the patch pillar do its work
2022-04-01 10:09:55 -04:00
Josh Patterson
f71fcdaed7
salt 3004.1
2022-04-01 09:55:55 -04:00
Josh Patterson
d95391505f
Update minion.defaults.yaml
2022-04-01 09:55:03 -04:00
Mike Reeves
0b80dad2c0
Merge pull request #7682 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-04-01 09:53:57 -04:00
Mike Reeves
02a96c409e
Update HOTFIX
2022-04-01 09:52:57 -04:00
Mike Reeves
cb2044cee9
Fix the analyst pillar
2022-04-01 09:29:29 -04:00
Mike Reeves
64e480714a
Fix the analyst pillar
2022-04-01 09:10:38 -04:00
Jason Ertel
2dc370c8b6
Add source packages to salt state
2022-03-31 18:56:38 -04:00
Jason Ertel
57dc848792
Support analyzer deps
2022-03-31 16:48:13 -04:00
Jason Ertel
9947ba6e43
Support CentOS paths
2022-03-31 16:47:56 -04:00
Jason Ertel
48fbc2290f
Add dep support for analyzers
2022-03-31 13:59:35 -04:00
Mike Reeves
edc6a461ec
Fix analyst pillar
2022-03-31 13:57:37 -04:00
Mike Reeves
63eb15aa6d
Run anayst Pillar
2022-03-31 13:35:30 -04:00
Mike Reeves
5264526ff1
Fix salt master declaration
2022-03-31 12:05:59 -04:00
Mike Reeves
c9eb188a79
Only run specific states during install for AW
2022-03-31 12:01:55 -04:00
Mike Reeves
ad833965a0
Fix extra space
2022-03-31 11:12:10 -04:00
Mike Reeves
179aa5e29c
Add firewall rules for Analyst workstation
2022-03-31 10:49:38 -04:00
Josh Patterson
86b311c468
Merge pull request #7675 from Security-Onion-Solutions/issue/7203
...
different systemd unit files for ubuntu and centos
2022-03-31 10:18:10 -04:00
m0duspwnens
fc60f64ddb
different systemd unit files for ubuntu and centos
2022-03-31 10:11:43 -04:00
Jason Ertel
1aba4da2bb
Correct analyzer path
2022-03-30 21:01:07 -04:00
Mike Reeves
a049e458c6
Add workstation to the salt config
2022-03-30 14:03:52 -04:00
Jason Ertel
45f511caab
Remove extra comma
2022-03-30 13:21:35 -04:00
Mike Reeves
f43a6757e0
Add analyst install network stack
2022-03-30 11:16:00 -04:00
Mike Reeves
c3d3806f65
Add analyst install network stack
2022-03-30 11:14:35 -04:00
Mike Reeves
dceb46888f
Add analyst install network stack
2022-03-30 11:06:59 -04:00
Jason Ertel
e667bb1e59
merge
2022-03-30 10:57:40 -04:00
Mike Reeves
816d0b1075
Don't prompt for install type since we know its analyst
2022-03-29 17:35:13 -04:00
Mike Reeves
c4a4e9737b
Set standalone to load Xwindows
2022-03-29 17:31:53 -04:00
Josh Patterson
1cb48fc6a8
Merge pull request #7668 from Security-Onion-Solutions/issue/7203
...
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 17:30:32 -04:00
Mike Reeves
45161b2a39
Set standalone to load Xwindows
2022-03-29 17:28:32 -04:00
Mike Reeves
67582be575
Set standalone to load Xwindows
2022-03-29 17:23:38 -04:00
Mike Reeves
86e32f3e6c
Set standalone to load Xwindows
2022-03-29 17:13:47 -04:00
Mike Reeves
053ec81285
Set standalone to load Xwindows
2022-03-29 17:12:25 -04:00
Mike Reeves
853235ca9b
Set standalone to load Xwindows
2022-03-29 17:11:19 -04:00
Mike Reeves
afb918d79c
Set standalone to load Xwindows
2022-03-29 17:08:03 -04:00
m0duspwnens
7a4d93f09b
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 15:44:05 -04:00
Jason Ertel
b2a96fab7e
merge
2022-03-29 14:07:20 -04:00
Jason Ertel
d2bf6d5618
Add build script to help pre-validate analyzers before pushing
2022-03-29 14:04:23 -04:00
Jason Ertel
484ef4bc31
Ensure generated python files are not pushed to version control
2022-03-29 13:51:12 -04:00
Jason Ertel
cb491630ae
Analyzer CI
2022-03-29 13:40:56 -04:00
Jason Ertel
0a8d24a225
Add automated CI for analyzers
2022-03-29 13:10:04 -04:00
Mike Reeves
3ace55dfe5
Add initial analyst install code
2022-03-29 12:49:30 -04:00
Mike Reeves
102d2507cb
Add initial analyst install code
2022-03-29 12:48:52 -04:00
Mike Reeves
0d23688aa0
Add initial analyst install code
2022-03-29 12:46:45 -04:00
Mike Reeves
80af497f95
Add initial analyst install code
2022-03-29 12:43:20 -04:00
Mike Reeves
990470a765
Add initial analyst install option to so-setup
2022-03-29 10:41:45 -04:00
Josh Patterson
f5095b273d
Merge pull request #7665 from Security-Onion-Solutions/workstation_state
...
Workstation state
2022-03-29 10:27:07 -04:00
m0duspwnens
e3f3af52e1
fix spacing
2022-03-29 10:19:29 -04:00
m0duspwnens
2f489895ef
top match and remove_gui state
2022-03-29 10:17:21 -04:00
weslambert
7f7eaf173b
Merge pull request #7663 from Security-Onion-Solutions/fix/strelka_fw
...
Add strelka_frontend to heavynode, sensor, and standalone role FW por…
2022-03-28 16:14:25 -04:00
weslambert
6004dde54a
Add strelka_frontend to heavynode, sensor, and standalone role FW portgroups
2022-03-28 16:05:07 -04:00
Jason Ertel
c23b87965f
Merge branch 'dev' into kilo
2022-03-28 15:53:33 -04:00
Jason Ertel
deb9b0e5ef
Add analyze feature
2022-03-28 15:53:24 -04:00
m0duspwnens
0ddfaf8d74
changes for workstation
2022-03-28 15:34:15 -04:00
weslambert
fb7160cba5
Merge pull request #7644 from Security-Onion-Solutions/fix/syslog_pr_adjustment
...
Update with changes from Abe's PR and other fixes
2022-03-25 13:59:20 -04:00
weslambert
e6599cd10e
Update with changes from Abe's PR and other fixes
2022-03-25 13:57:44 -04:00
weslambert
c02d7fab50
Merge pull request #7636 from Security-Onion-Solutions/feature/rita
...
Parsing of RITA Logs
2022-03-24 13:05:22 -04:00
weslambert
fbc86f43ec
Add exclude filter for logs for when there are no results from analysis
2022-03-24 13:03:03 -04:00
weslambert
4c93217aac
Merge pull request #7635 from Security-Onion-Solutions/fix/process_mappings_keyword
...
Additional .keyword shims for process mappings
2022-03-24 12:53:16 -04:00
Wes Lambert
fe1b72655b
Additional .keyword shims for process mappings
2022-03-24 16:45:06 +00:00
m0duspwnens
293de159db
fix package names
2022-03-24 11:33:16 -04:00
m0duspwnens
7cfc52da8a
fix include
2022-03-24 10:02:25 -04:00
m0duspwnens
a0841ee7a7
workstation state
2022-03-24 09:57:58 -04:00
weslambert
5160a55dcf
Merge pull request #7629 from Security-Onion-Solutions/fix/roles_load_check_cluster_health
...
Check ES cluster health before trying to load roles
2022-03-23 11:07:24 -04:00
weslambert
1f2bca599f
Check cluster health before trying to load roles for ES
2022-03-23 11:00:26 -04:00
Wes Lambert
8a56c88773
Adjust log file paths
2022-03-22 17:51:17 +00:00
Wes Lambert
57f01c70ec
Remove extra forward slash in log path
2022-03-22 17:45:23 +00:00
Wes Lambert
2487d468ab
Add RITA Elasticsearch ingest pipeline config
2022-03-22 17:38:22 +00:00
Wes Lambert
f613d8ad86
Add RITA Logstash config
2022-03-22 17:36:18 +00:00
weslambert
bb9d6673ec
Fix casing
2022-03-21 12:38:50 -04:00
weslambert
9afa949623
Don't rotate Filebeat log on startup
2022-03-21 12:38:12 -04:00
weslambert
b2c26807a3
Add xpack.reporting.kibanaServer.hostname to defaults file
2022-03-21 09:30:25 -04:00
Wes Lambert
faeaa948c8
Remove extra Salt logic and clean up output format of resultant script
2022-03-19 04:31:48 +00:00
Wes Lambert
1a6ef0cc6b
Re-enable FB module load
2022-03-19 03:55:40 +00:00
Wes Lambert
a18b38de4d
Update so-filebeat-module-setup to use new load style to avoid having to explicitly enabled filesets
2022-03-19 03:54:41 +00:00
Wes Lambert
2e7d314650
Remove Cyberark module
2022-03-19 03:43:55 +00:00
Wes Lambert
c97847f0e2
Remove Threat Intel Recored Future fileset
2022-03-19 03:43:34 +00:00
Wes Lambert
59a2ac38f5
Disable FB module load for now
2022-03-18 22:12:09 +00:00
Wes Lambert
543bf9a7a7
Update Kibana version to 8
2022-03-18 22:07:21 +00:00
Wes Lambert
d111c08fb3
Update Curator commands with new Filebeat module variables
2022-03-18 21:45:33 +00:00
Doug Burks
a3f8a10eb9
Merge pull request #7608 from Security-Onion-Solutions/fix/telegraf-non-root
...
FIX: Run telegraf as non-root #7468
2022-03-18 15:17:28 -04:00
weslambert
a9ea99daa8
Switch from so_elastic user to so_kibana user for Elastic 8
2022-03-18 15:09:50 -04:00
weslambert
cb0d4acd57
Remove X-Pack ML entry for Elastic 8
2022-03-18 14:46:28 -04:00
Doug Burks
eda7a8d7ea
FIX: Update telegraf influxdbsize.sh to collect influxdb size from influxdb_size.log #7468
2022-03-18 13:15:43 -04:00
Doug Burks
f7dc5588ae
FIX: Update common init.sls to create cron job to write influxdb size for telegraf #7468
2022-03-18 13:13:46 -04:00
Doug Burks
c13994994b
FIX: Update telegraf init.sls to run telegraf as non-root #7468
2022-03-18 13:11:56 -04:00
weslambert
e0374be4aa
Update version from 7.16.2 to 8.1.0 for Kibana config
2022-03-18 11:57:33 -04:00
weslambert
6f294cc0c2
Change Kibana user role from superuser to kibana_system for Elastic 8
2022-03-18 11:54:08 -04:00
weslambert
5ec5b9a2ee
Remove older module config files
2022-03-18 10:14:13 -04:00
weslambert
c659a443b0
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:25:10 -04:00
weslambert
99430fddeb
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:24:39 -04:00
weslambert
7128b04636
Remove indices.query.bool.max_clause_count because it is dynamically allocated in Elastic 8
2022-03-17 21:20:41 -04:00
weslambert
712a92aa39
Switch from log input to filestream input
2022-03-17 21:18:03 -04:00
Wes Lambert
6e2aaa0098
Clean up original map file
2022-03-17 21:08:57 +00:00
Wes Lambert
09892a815b
Add back bind mounts and remove THIRDPARTY
2022-03-17 21:06:07 +00:00
Wes Lambert
a60ef33930
Reorganize FB module management
2022-03-17 21:01:03 +00:00
Josh Patterson
949365c636
Merge pull request #7602 from Security-Onion-Solutions/issue/7601
...
prevent so-setup iso from running on ubuntu
2022-03-17 11:37:53 -04:00
m0duspwnens
a896348743
prevent so-setup iso from running on ubuntu - https://github.com/Security-Onion-Solutions/securityonion/issues/7601
2022-03-17 11:31:16 -04:00
Josh Brower
5b9c82a434
Merge pull request #7494 from Security-Onion-Solutions/fix/fleetdm-custom-hostname
...
Force regen of ssl cert
2022-03-16 15:17:05 -04:00
Doug Burks
50477071b8
Merge pull request #7588 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-03-16 13:54:00 -04:00
Doug Burks
e65f2a5513
FIX: Prevent multiple instances of so-sensor-clean #6622
2022-03-16 13:28:39 -04:00
Doug Burks
e56f90d83c
FIX: Prevent multiple instances of so-playbook-sync #6622
2022-03-16 13:27:37 -04:00
weslambert
aaded58131
Merge pull request #7565 from Security-Onion-Solutions/fix/es_template_fix
...
Custom ES template fixes
2022-03-15 11:09:46 -04:00
Doug Burks
9bf0265cea
Merge pull request #7566 from Security-Onion-Solutions/feature/hunt-soc-auth
...
FEATURE: Add new Hunt query for SOC logins #7327
2022-03-15 10:58:40 -04:00
Mike Reeves
e01c1398d5
Merge pull request #7564 from Security-Onion-Solutions/removethehive
...
Removethehive
2022-03-15 10:56:08 -04:00
Wes Lambert
42d6c3a956
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
2022-03-15 14:55:04 +00:00
Doug Burks
eec44a6b02
Add a SOC Auth query to hunt.queries.json
2022-03-15 10:38:46 -04:00
Doug Burks
d1e1887e36
Add support for Kratos audit logs in hunt.eventfields.json
2022-03-15 10:37:58 -04:00
Wes Lambert
5f56c7a261
Replace ELASTICCURL with so-elasticsearch-query
2022-03-15 14:32:00 +00:00
weslambert
d46620ea2a
Merge pull request #7561 from Security-Onion-Solutions/es_template_map_fix
...
Custom ES Template Fixes
2022-03-15 10:01:42 -04:00
Jason Ertel
408f9d6695
Update .gitleaks.toml
2022-03-15 09:53:27 -04:00
Jason Ertel
b810f14428
Update .gitleaks.toml
2022-03-15 09:53:11 -04:00
Jason Ertel
cec9cba40e
Create .gitleaks.toml
2022-03-15 09:47:57 -04:00
Jason Ertel
8ebeeb497f
add configuration to override leak detector defaults
2022-03-15 09:43:09 -04:00
Mike Reeves
9c80ff4f65
Remove hive from more files
2022-03-15 09:37:58 -04:00
Mike Reeves
81f0aa58b8
Remove hive from more files
2022-03-15 08:28:03 -04:00
Doug Burks
63cef4daff
Merge pull request #7557 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: surilogcompress cron job not running
2022-03-15 07:41:05 -04:00
Doug Burks
db4f138a78
FIX: surilogcompress cron job not running
...
The suricata user was originally created with `/opt/so/conf/suricata` as its home directory. I think at some point we changed permissions on `/opt/so/conf` and at that point the `surilogcompress` cron job stopped working. Changing the home directory to `/nsm/suricata` works on all of my PROD systems (including Ubuntu and CentOS).
For more information, please see:
https://github.com/Security-Onion-Solutions/securityonion/issues/7133
2022-03-15 07:10:02 -04:00
Mike Reeves
b5b60af16f
Remove hive from so-user
2022-03-14 15:06:07 -04:00
Mike Reeves
b83fec6fd2
More hive remova
2022-03-14 14:51:39 -04:00
Mike Reeves
ff30f572d7
Remove thehive from image common
2022-03-14 10:40:41 -04:00
Mike Reeves
95195c07fc
Disable hive in automation files
2022-03-14 10:36:23 -04:00
Jason Ertel
16f673d956
Merge pull request #7541 from Security-Onion-Solutions/kilo
...
Add assignee field to case list
2022-03-14 08:49:46 -04:00
Jason Ertel
5a28725def
Add assignee to case list
2022-03-14 08:45:28 -04:00
Wes Lambert
ba24f75893
Fix index typo
2022-03-11 18:11:16 +00:00
Wes Lambert
70ed20f691
Add new sls file for custom ES index templates
2022-03-11 18:07:23 +00:00
Wes Lambert
d12ff503c2
Chage role loading verbiage
2022-03-11 16:23:19 +00:00
Wes Lambert
dc258cf043
Load custom component templates in so-elasticsearch-templates-load
2022-03-11 16:22:55 +00:00
Wes Lambert
8e43a6e571
Don't generate index template if index_template definition is not present in pillar
2022-03-11 16:22:06 +00:00
m0duspwnens
e1e8a20e11
make sure values exist in data structure
2022-03-10 17:09:00 -05:00
Josh Brower
f0e44827a5
rm extra line
2022-03-10 08:48:46 -05:00
Josh Brower
814e16ba95
Force regen of ssl cert
2022-03-10 08:47:26 -05:00
Mike Reeves
7ca06df66f
Merge pull request #7484 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-03-09 14:50:52 -05:00
Mike Reeves
6f15acd2f9
Update VERSION
2022-03-09 14:50:14 -05:00
Mike Reeves
3725130128
Merge pull request #7481 from Security-Onion-Solutions/dev
...
2.3.110
2022-03-09 14:44:40 -05:00
Mike Reeves
2c66fa1883
Merge pull request #7482 from Security-Onion-Solutions/kilo
...
Merge master with .100 hotfix #3 into dev
2022-03-09 12:24:04 -05:00
Jason Ertel
61a3155dfa
merge from master
2022-03-09 12:22:24 -05:00
Mike Reeves
99f25deb80
Merge pull request #7480 from Security-Onion-Solutions/2.3.110rel
...
2.3.110
2022-03-09 12:16:31 -05:00
Mike Reeves
0cb628f565
2.3.110
2022-03-09 12:12:32 -05:00
weslambert
262e68cb75
Merge pull request #7469 from Security-Onion-Solutions/fix/kibana_config_load_template
...
Add .template extension to ensure we are loading the template and not the resultant file
2022-03-08 21:12:29 -05:00
weslambert
c83b63d0d8
Add .template extension to load template file
2022-03-08 20:53:16 -05:00
weslambert
8d9ddf5f1b
Add .template extension to load template
2022-03-08 20:52:13 -05:00
weslambert
8115da358f
Add .template extension to load template file
2022-03-08 20:51:50 -05:00
Doug Burks
06efef7b81
Merge pull request #7467 from Security-Onion-Solutions/dougburks-patch-1
...
Revert security_opt addition in telegraf init.sls
2022-03-08 18:51:52 -05:00
Doug Burks
b76c01ef53
Revert security_opt addition in telegraf init.sls
2022-03-08 18:27:15 -05:00
weslambert
5f3c29b7f8
Merge pull request #7466 from Security-Onion-Solutions/fix/process_name_keyword
...
Add process.name.keyword
2022-03-08 12:47:31 -05:00
weslambert
65f998d6f7
Remove process.name.keyword for future-proofing
2022-03-08 12:44:51 -05:00
weslambert
406267a892
Add process.name.keyword
2022-03-08 12:42:34 -05:00
weslambert
d9c3160fbf
Merge pull request #7465 from Security-Onion-Solutions/fix/kibana_saved_objects_load
...
Kibana dashboard/saved objects loading improvements
2022-03-08 12:22:55 -05:00
Wes Lambert
d392cb258c
Switch Kibana state to kibana.so_savedobjects_defaults in top file
2022-03-08 16:59:48 +00:00
Wes Lambert
86e228b200
Add .template extension for future-proofing config files
2022-03-08 16:58:37 +00:00
Wes Lambert
a6fd1023b4
Fix criteria for successful execution
2022-03-08 16:57:26 +00:00
Wes Lambert
3f31f7fd41
Add .template extension to fix script behavior and not modify watched file
2022-03-08 16:43:43 +00:00
Jason Ertel
f64da9632f
Merge pull request #7461 from Security-Onion-Solutions/kilo
...
Gracefully handle situations where another process is using the Kratos DB while so-user executes
2022-03-08 11:02:14 -05:00
Jason Ertel
0cec5879bb
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:55:26 -05:00
Jason Ertel
d8ca4976be
Merge branch 'dev' into kilo
2022-03-08 10:41:40 -05:00
Jason Ertel
914d81ca07
Revert "Gracefully handle situations when another process is using the Kratos DB"
...
This reverts commit f2865d8b7f .
2022-03-08 10:40:20 -05:00
Jason Ertel
f2865d8b7f
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:38:05 -05:00
Wes Lambert
28554164cd
Remove drop file when securitySolution saved objects change
2022-03-08 14:39:23 +00:00
Wes Lambert
14dddd8649
Remove drop file when config saved objects change
2022-03-08 14:37:15 +00:00
Wes Lambert
c0f49f6fb0
Remove drop file when dashbaord saved objects change
2022-03-08 14:35:04 +00:00
Wes Lambert
d10d4acf9f
Modify Kibana config load script to drop file if successfully executed
2022-03-08 14:33:15 +00:00
Doug Burks
da8e885ede
Merge pull request #7451 from Security-Onion-Solutions/fix/docker-apparmor
...
Update init.sls to avoid telegraf apparmor issues
2022-03-07 17:06:42 -05:00
Doug Burks
104de2a3c9
Update init.sls to avoid telegraf apparmor issues
...
See #2560
2022-03-07 16:11:22 -05:00
Mike Reeves
fb59421f5b
Merge pull request #7446 from Security-Onion-Solutions/fixpipelineload
...
Only load pipelines on change
2022-03-07 15:17:32 -05:00
weslambert
e2bda255cc
Merge pull request #7447 from Security-Onion-Solutions/fix/es_templates_soup
...
Remove old Elasticsearch index templates during SOUP
2022-03-07 15:10:44 -05:00
Mike Reeves
4eb37fd5a9
Update init.sls
2022-03-07 15:09:36 -05:00
Wes Lambert
fa9be58b23
Specify index templates
2022-03-07 20:04:23 +00:00
Wes Lambert
647b316a96
Remove old ES index templates
...
Signed-off-by: Wes Lambert <wlambertts@gmail.com >
2022-03-07 20:02:45 +00:00
Mike Reeves
d33db6fb23
Only load pipelines on change
2022-03-07 14:25:46 -05:00
weslambert
eac120f4c2
Merge pull request #7444 from Security-Onion-Solutions/fix/dtc_client_override
...
Add DTC client mappings
2022-03-07 13:38:19 -05:00
Wes Lambert
c549b20221
Add DTC client mappings
2022-03-07 18:36:26 +00:00
Mike Reeves
e6132be4e6
Merge pull request #7443 from Security-Onion-Solutions/fixtemplates
...
Only load templates on change
2022-03-07 10:42:51 -05:00
Mike Reeves
c67604590d
Only load templates on change
2022-03-07 09:52:18 -05:00
weslambert
5600b55f05
Merge pull request #7427 from Security-Onion-Solutions/fix/syslog_kibana_viz
...
Replace syslog facility and severity with label fields in Kibana syslog dashboard
2022-03-07 08:14:35 -05:00
Doug Burks
a59779905f
Merge pull request #7437 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo
2022-03-07 08:05:07 -05:00
Doug Burks
848a5c6350
fix typo
2022-03-07 08:03:41 -05:00
Wes Lambert
33ba45472f
Replace syslog facility and severity with label fields
2022-03-04 21:40:41 +00:00
weslambert
ee4035f022
Merge pull request #7426 from Security-Onion-Solutions/fix/syslog_zeek
...
Change to label fields for syslog facility and severity
2022-03-04 16:31:45 -05:00
weslambert
f71ccadb8a
Change to label fields for Zeek syslog
2022-03-04 16:29:55 -05:00
weslambert
fc3273fa49
Change to label fields to comply with what's defined in Filebeat template
2022-03-04 16:29:01 -05:00
weslambert
3148fa0e06
Merge pull request #7422 from Security-Onion-Solutions/fix/syslog_dot_keyword
...
.keyword additions and increase max_clause_count
2022-03-04 15:32:29 -05:00
weslambert
254cf53c2f
Increase clause count to 3500
2022-03-04 10:36:37 -05:00
Wes Lambert
ffae22beef
Add DTC syslog mappings for .keyword and add refs to defaults.yml
2022-03-04 13:04:11 +00:00
weslambert
93c2f82345
Merge pull request #7413 from Security-Onion-Solutions/fix/add_keyword_subfield
...
Add .keyword subfield for more mappings
2022-03-03 10:42:38 -05:00
Wes Lambert
1f71816ad7
Add keyword subfield for DTC winlog mappings
2022-03-03 14:54:30 +00:00
Wes Lambert
1c086e36da
Add missing comma for file mappings
2022-03-03 13:49:54 +00:00
Wes Lambert
aa8d24b6cd
Add DTC destination, source, and winlog mapping references to templates in defaults file
2022-03-03 13:42:20 +00:00
Wes Lambert
85979cbce8
Add file, process, and winlog mapping changes
2022-03-03 13:37:27 +00:00
Wes Lambert
8f97f09c9c
Additional .keyword changes for host.hostname client.address, and event.action
2022-03-02 21:54:46 +00:00
Wes Lambert
3ee46e4c29
Add .keyword for destination/source geo.country_name
2022-03-02 21:50:03 +00:00
weslambert
a21060306c
Merge pull request #7404 from Security-Onion-Solutions/fix/field_limit_adjustment
...
Adjust field limit for now due to component template errors
2022-03-02 11:41:35 -05:00
Wes Lambert
c5b16fdf3b
Adjust field limit for now
2022-03-02 16:33:39 +00:00
weslambert
b80e82aaf6
Merge pull request #7396 from Security-Onion-Solutions/fix/dot_security
...
Revert back to usage of .security field
2022-03-02 10:42:29 -05:00
Josh Brower
2ba72791aa
Remove sigma regen cron
2022-03-02 10:31:15 -05:00
Mike Reeves
d570b56c55
Merge pull request #7392 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix 2.3.100 20220301
2022-03-02 10:24:50 -05:00
Mike Reeves
ff4345d3aa
Merge pull request #7393 from Security-Onion-Solutions/jertelhf
...
Jertelhf
2022-03-02 10:20:29 -05:00
Jason Ertel
e59f0d69d9
Merge branch 'master' into jertelhf
2022-03-02 10:18:14 -05:00
Mike Reeves
ad2b69c9de
Merge pull request #7391 from Security-Onion-Solutions/hf0301
...
Hotfix 2.3.100 20220301
2022-03-02 10:08:27 -05:00
Mike Reeves
e874c32c08
Hotfix 2.3.100-20220301
2022-03-02 10:05:41 -05:00
Wes Lambert
ab9b81ea39
Change match_only_text to text for mac in host mappings
2022-03-02 15:01:05 +00:00
Wes Lambert
ed620b93b7
Add custom analyzer definition to all SO/DTC mappings
2022-03-02 14:43:19 +00:00
Wes Lambert
27c8eaa630
Update all other mappings for .security where applicable
2022-03-02 14:39:23 +00:00
Wes Lambert
e925d435ff
Update event, file, and host mappings to include .security
2022-03-02 14:33:52 +00:00
Wes Lambert
496b161253
Update ECS mappings to include .security
2022-03-02 14:27:36 +00:00
Wes Lambert
aae2fd1fbb
Update DNS mappings to include .security
2022-03-02 14:27:15 +00:00
Wes Lambert
0b45cf7ae1
Update base mappings to include .security
2022-03-02 14:25:57 +00:00
Wes Lambert
d89af5f04f
Update agent mappings to include .security
2022-03-02 14:25:14 +00:00
Wes Lambert
2d2ec45029
Modify base ECS mappings to include .security where possible, as well as custom analyzer definition
2022-03-02 14:19:36 +00:00
weslambert
93386f4620
Merge pull request #7389 from Security-Onion-Solutions/fix/revert_text
...
Fix/revert text
2022-03-02 09:17:46 -05:00
Mike Reeves
c0649a863b
Merge pull request #7376 from Security-Onion-Solutions/hfnew
...
Curator Fixes
2022-03-01 14:38:31 -05:00
Mike Reeves
e93dbb5347
Update Hotfix
2022-03-01 14:37:03 -05:00
doug
bbced5b52f
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:52 -05:00
Doug Burks
f134c74585
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:41 -05:00
Wes Lambert
5489b8559d
Revert "Switch from .security to match_only_text"
...
This reverts commit f7862af934 .
2022-03-01 18:44:00 +00:00
Wes Lambert
2a9caccc7c
Revert "Add additional .text subfield mappings"
...
This reverts commit 61dadc6249 .
2022-03-01 18:43:24 +00:00
Doug Burks
adf3dc0cf6
Merge pull request #7370 from Security-Onion-Solutions/fix/syslog
...
Revert syslog pipeline updates from Abe's PR for now
2022-03-01 11:13:13 -05:00
Wes Lambert
a290602a70
Revert syslog pipeline updates from Abe' PR for now
2022-03-01 15:31:07 +00:00
weslambert
4201ee45c6
Merge pull request #7369 from Security-Onion-Solutions/fix/ingest_timestamp
...
Rename ingest timestamp to event.ingested
2022-03-01 10:11:16 -05:00
Wes Lambert
038dc49098
Temporarily increase field limit before trimming efforts
2022-03-01 15:06:28 +00:00
Wes Lambert
dc07adca63
Rename ingest.timestamp to event.ingested
2022-03-01 15:05:08 +00:00
Josh Brower
39718561ce
Merge pull request #7366 from Security-Onion-Solutions/delta
...
Enable state tracking for sigma refresh
2022-03-01 05:53:14 -05:00
Josh Brower
e960d99901
Enable state tracking for sigma refresh
2022-02-28 21:18:41 -05:00
Josh Brower
09f1a5025d
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-28 21:18:07 -05:00
Josh Brower
41a58b791a
Enable state tracking for sigma refresh
2022-02-28 21:17:59 -05:00
Jason Ertel
73b2a36e89
Merge pull request #7365 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.17.1
2022-02-28 18:26:31 -05:00
Jason Ertel
f147bb33ed
Upgrade to ES 7.17.1
2022-02-28 18:18:09 -05:00
Josh Patterson
6b3b5e9a1f
Merge pull request #7363 from Security-Onion-Solutions/soup_singlenode_30
...
allow for check_log_size_limit to work without salt-master running
2022-02-28 17:13:42 -05:00
Josh Brower
f824717094
Merge pull request #7364 from Security-Onion-Solutions/delta
...
IDH Node verbiage
2022-02-28 17:09:08 -05:00
Josh Brower
0cee0d5dea
IDH Node verbiage
2022-02-28 16:47:24 -05:00
Josh Brower
d71bde0e38
Merge pull request #7362 from Security-Onion-Solutions/delta
...
Navigator - include attack json for airgap
2022-02-28 16:33:10 -05:00
Josh Brower
2075412ca2
Navigator - include attack json for airgap
2022-02-28 16:15:30 -05:00
m0duspwnens
a51f833f36
output only the value for log_size_limit
2022-02-28 16:13:43 -05:00
Jason Ertel
04a99a0adc
Merge pull request #7361 from Security-Onion-Solutions/kilo
...
Clear out hotfix file
2022-02-28 16:04:30 -05:00
Jason Ertel
166ac0d194
Clear out hotfix file
2022-02-28 16:01:42 -05:00
m0duspwnens
8d12e136f2
Merge remote-tracking branch 'remotes/origin/dev' into soup_singlenode_30
2022-02-28 15:43:37 -05:00
m0duspwnens
710059211d
remove debug echo, mkdir verbose
2022-02-28 14:54:39 -05:00
weslambert
a1c0ae4aab
Merge pull request #7356 from Security-Onion-Solutions/fix/es_config_load_order
...
Run template load first to prevent issues with pipeline changes that …
2022-02-28 14:50:22 -05:00
m0duspwnens
80e5198f9e
combine local and default pillars to get pillar values locally
2022-02-28 14:35:16 -05:00
m0duspwnens
dc24cb711d
need local to be --local
2022-02-28 13:50:08 -05:00
m0duspwnens
c5bf818049
debug messages and pass local to lookup_salt_value
2022-02-28 13:39:50 -05:00
weslambert
414b9dcd59
Run template load first to prevent issues with pipeline changes that generate new indices
2022-02-28 12:33:18 -05:00
m0duspwnens
cd981fa2ae
forgot then for if
2022-02-28 12:25:06 -05:00
m0duspwnens
278235b0ca
update so-common lookup_salt_value to accept local option. soup get minion id from grains with local option
2022-02-28 12:15:23 -05:00
weslambert
a9caef9596
Merge pull request #7338 from Security-Onion-Solutions/fix/endgame_template
...
Revert Endgame index name changes
2022-02-28 08:13:09 -05:00
Doug Burks
e0b3635318
Merge pull request #7339 from Security-Onion-Solutions/fix/zeek_dns-import
...
Avoid changing _index for imported logs
2022-02-27 05:09:00 -05:00
Doug Burks
32b71fdcac
Avoid changing _index for imported logs
2022-02-26 10:36:09 -05:00
Wes Lambert
bd1b21a5b6
Revert Endgame index name changes
2022-02-26 02:53:57 +00:00
weslambert
56cb8d62ab
Merge pull request #7337 from Security-Onion-Solutions/fix/pb_overrides
...
Fix formatting for PB overrides
2022-02-25 20:48:38 -05:00
weslambert
e942d81433
Ensure correct formatting for source override
2022-02-25 19:14:58 -05:00
weslambert
a511fd33e9
Ensure correct formatting for destination override
2022-02-25 19:14:21 -05:00
Doug Burks
74037e6f00
Merge pull request #7335 from Security-Onion-Solutions/fix/soup-postversion
...
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 15:27:31 -05:00
Josh Brower
25b0069353
Merge pull request #7334 from Security-Onion-Solutions/delta
...
IDH Setup - dont show ssh fix screen
2022-02-25 15:01:25 -05:00
Josh Brower
6a270eb8b3
IDH Setup - dont show ssh fix screen - fix
2022-02-25 14:58:30 -05:00
Josh Brower
ee39ec1882
IDH Setup - dont show ssh fix screen
2022-02-25 14:55:28 -05:00
Doug Burks
8df47e809d
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 14:30:59 -05:00
Mike Reeves
fa15a2e012
Merge pull request #7333 from Security-Onion-Solutions/endgamecurator
...
Fix endgame index name
2022-02-25 13:31:29 -05:00
Mike Reeves
15924ebe0f
Fix endgame index name
2022-02-25 13:29:29 -05:00
weslambert
c95f48e49a
Merge pull request #7330 from Security-Onion-Solutions/fix/pb-override
...
Override destination/source mappings with .keyword for Playbook
2022-02-25 13:07:31 -05:00
Wes Lambert
a8bdff89ae
Move files into SO component template directory
2022-02-25 18:00:16 +00:00
Wes Lambert
08097fe9ec
Add Playbook override mappings
2022-02-25 17:58:51 +00:00
Josh Brower
ce4c859f3a
Merge pull request #7328 from Security-Onion-Solutions/fix/soup-sigma-refresh
...
.110 Post processing - sigma refresh
2022-02-25 12:24:19 -05:00
Josh Patterson
9de9d92b2b
Merge pull request #7329 from Security-Onion-Solutions/delta
...
add extra hosts for filebeat on idh node
2022-02-25 12:23:37 -05:00
m0duspwnens
d76facb1bb
add extra hosts for idh node
2022-02-25 12:21:43 -05:00
Josh Brower
1abf27873d
.110 Post processing - sigma refresh
2022-02-25 12:19:59 -05:00
weslambert
a6ab09501e
Merge pull request #7326 from Security-Onion-Solutions/fix/additional_text_subfield_mappings
...
Add additional .text subfield mappings
2022-02-25 11:29:26 -05:00
Wes Lambert
61dadc6249
Add additional .text subfield mappings
2022-02-25 16:27:37 +00:00
Josh Brower
be80f0530c
Merge pull request #7321 from Security-Onion-Solutions/delta
...
IDH Improvements
2022-02-24 21:27:36 -05:00
Josh Brower
96ed3cb158
IDH - Setup Summary new lines
2022-02-24 20:59:47 -05:00
Josh Brower
4a597b9f0e
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-24 19:58:10 -05:00
Josh Brower
cf7325a546
IDH - Play tweaks, Setup summary, log rotate
2022-02-24 19:57:11 -05:00
Josh Patterson
8302c45059
Merge pull request #7320 from Security-Onion-Solutions/delta_ssh
...
default to false if local role doesnt exist
2022-02-24 18:06:19 -05:00
m0duspwnens
0970bbc983
default to false if local role doesnt exist
2022-02-24 17:55:50 -05:00
Josh Brower
e8e683c2e9
Merge pull request #7319 from Security-Onion-Solutions/delta
...
Add and Update IDH Plays
2022-02-24 15:48:38 -05:00
Josh Brower
fbc702375c
Add and Update IDH Plays
2022-02-24 15:06:04 -05:00
Josh Patterson
5c747fbb4c
Merge pull request #7318 from Security-Onion-Solutions/delta_ssh
...
change name of selinux policy state for idh node
2022-02-24 14:49:55 -05:00
m0duspwnens
8b61d4818d
change name of selinux policy state for idh node
2022-02-24 14:47:14 -05:00
weslambert
22b01dab1e
Merge pull request #7317 from Security-Onion-Solutions/fix/add_text_subfield_to_dtc_mappings
...
Add .text subfield mappings for DTC where fields are defined
2022-02-24 14:47:11 -05:00
Wes Lambert
0f8a39002f
Add .text subfield mappings for DTC where fields are defined
2022-02-24 19:39:52 +00:00
weslambert
5e29c71381
Merge pull request #7315 from Security-Onion-Solutions/fix/split_zeek_dns
...
Split Zeek DNS records into a separate index
2022-02-24 13:21:52 -05:00
weslambert
23fb62c0d6
Split Zeek DNS records into a separate index
2022-02-24 12:52:25 -05:00
weslambert
313487a887
Merge pull request #7313 from Security-Onion-Solutions/fix/kibana_dashboard_load
...
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:48:28 -05:00
weslambert
bc1794e437
Fix function name
2022-02-24 09:42:14 -05:00
Josh Patterson
d7aa413c46
Merge pull request #7314 from Security-Onion-Solutions/delta
...
default port 2222 for ssh idh node
2022-02-24 09:37:11 -05:00
weslambert
45ccfc5ad4
Add back post to .100 and call for .110
2022-02-24 09:35:43 -05:00
weslambert
582bf4c64c
Remove dashboard updates for .100 so we don't run twice
2022-02-24 09:25:59 -05:00
weslambert
7f08ecdcbe
Add function reference for .110 post changes
2022-02-24 09:25:15 -05:00
weslambert
a22e470038
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:20:44 -05:00
weslambert
bc2c1b4ccc
Merge pull request #6935 from abesinger/issue/6912
...
Updated syslog pipeline, resolves #6912 .
2022-02-24 08:33:55 -05:00
Josh Brower
5779e40401
Merge pull request #7308 from Security-Onion-Solutions/defensivedepth-patch-1
...
UC true
2022-02-24 07:48:39 -05:00
Josh Brower
585c275df6
UC true
2022-02-23 19:35:10 -05:00
Josh Brower
babc114d27
Merge branch 'delta' of https://github.com/Security-Onion-Solutions/securityonion into delta
2022-02-23 19:33:18 -05:00
Josh Brower
2bf20bd1f0
UC true
2022-02-23 19:33:10 -05:00
Josh Patterson
a9c6dc32ab
Merge pull request #7305 from Security-Onion-Solutions/delta_ssh
...
allow only manager to connect to ssh port for idh node
2022-02-23 15:17:31 -05:00
m0duspwnens
61ae61953f
allow only manager to connect to ssh port for idh node
2022-02-23 15:14:11 -05:00
weslambert
2aa811dcd2
Merge pull request #7300 from Security-Onion-Solutions/fix/new_es_template_config
...
Add IDH and Kratos index templates
2022-02-23 12:24:38 -05:00
weslambert
6a0ecb9e9c
Add IDH and Kratos index templates
2022-02-23 12:13:46 -05:00
Josh Brower
b7b2183c15
Merge pull request #7296 from Security-Onion-Solutions/delta
...
IDH - Import & Enables Plays
2022-02-23 10:52:37 -05:00
weslambert
00dbf54a5f
Merge pull request #7295 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-functions
2022-02-23 10:50:32 -05:00
Josh Brower
83aa261d88
IDH - Import & Enables Plays
2022-02-23 10:50:13 -05:00
Mike Reeves
c4cc3fa35f
Update so-functions
2022-02-23 10:47:37 -05:00
Josh Brower
0121eda536
Merge pull request #7282 from Security-Onion-Solutions/delta
...
Initial Support - IDH Node
2022-02-23 08:49:40 -05:00
Doug Burks
aadc2a844b
Merge pull request #7284 from Security-Onion-Solutions/fix/so-curator-closed-delete
...
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:40:23 -05:00
doug
1392fc37e8
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:00:52 -05:00
weslambert
9f7612b599
Merge pull request #7283 from Security-Onion-Solutions/fix/match_only_text
...
Switch from .security to using match_only_text with .text
2022-02-22 15:41:29 -05:00
Wes Lambert
f7862af934
Switch from .security to match_only_text
2022-02-22 20:33:49 +00:00
Josh Brower
1d95aca4de
IDH - VNC default port
2022-02-22 14:16:45 -05:00
Josh Brower
99554d5db8
IDH - UDP vs TCP support
2022-02-22 14:10:05 -05:00
Josh Brower
df9fc807a3
IDH - restart scripts, filebeat fix
2022-02-22 08:05:53 -05:00
Josh Brower
3610b0cd30
merge in dev
2022-02-21 16:52:53 -05:00
Josh Brower
eea2b9ccfd
IDH - Play - ssh
2022-02-21 16:43:26 -05:00
Josh Brower
05be776f4b
IDH - so-status
2022-02-21 16:41:36 -05:00
Doug Burks
5b46d19b13
Merge pull request #7273 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:25:58 -05:00
Doug Burks
1abd824c5f
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:00:05 -05:00
Josh Brower
2203e2fedd
IDH - Final setup fixes
2022-02-19 21:01:48 -05:00
Josh Brower
780cd38adf
IDH - setup tweaks
2022-02-19 12:28:45 -05:00
Mike Reeves
fc0e27a7ae
Merge pull request #7261 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update networks.cfg.jinja
2022-02-18 20:03:47 -05:00
Mike Reeves
0d1da5d1dc
Update networks.cfg.jinja
2022-02-18 20:02:50 -05:00
Josh Brower
bf477a1c19
IDH - Initial whiptail
2022-02-18 17:21:04 -05:00
weslambert
3124f2bd12
Merge pull request #7255 from Security-Onion-Solutions/fix/remove_old_templates
...
Remove old index templates
2022-02-18 15:23:07 -05:00
Jason Ertel
380f0ef93a
Merge pull request #7256 from Security-Onion-Solutions/kilo
...
Update password len requirements; clarify password update help
2022-02-18 15:19:08 -05:00
Jason Ertel
93e9548eaf
Require a minimum of 8 characters for passwords, to match Kratos min requirements
2022-02-18 15:14:48 -05:00
Wes Lambert
4d1533537b
Remove old index templates
2022-02-18 20:08:13 +00:00
Josh Brower
0362afb260
IDH - Finalize Firewall config
2022-02-18 13:23:48 -05:00
Josh Patterson
d14967dd45
Merge pull request #7251 from Security-Onion-Solutions/issue/7233
...
dont allow $ to be used for elasticsearch:auth or kibana:secrets
2022-02-18 13:22:22 -05:00
m0duspwnens
cb55af4c1c
dont allow $ to be used for elasticsearch:auth or kibana:secrets - https://github.com/Security-Onion-Solutions/securityonion/issues/7233
2022-02-18 13:13:56 -05:00
weslambert
87a5e64f12
Merge pull request #7249 from Security-Onion-Solutions/fix/component_index_association
...
Update component -> index association for file/scan mappings for Strelka
2022-02-18 12:19:41 -05:00
Josh Brower
8de5a054d4
Merge pull request #7248 from Security-Onion-Solutions/feature/kratos-log-ingest
...
Ingest Kratos logs
2022-02-18 11:56:20 -05:00
William Wernert
786b01c85a
Merge pull request #6496 from JamesMConroy/so-staus-tty
...
so-staus detects tty
2022-02-18 11:52:18 -05:00
Josh Brower
118277ebc5
Ingest Kratos logs
2022-02-18 11:49:02 -05:00
Mike Reeves
27299cbe1b
Merge pull request #7247 from christopherwoodall/patch-7
...
Update so-setup
2022-02-18 11:47:19 -05:00
Christopher Woodall
118266bf5f
Update so-setup
...
Patch so setup to ignore deprecation warnings.
2022-02-18 11:38:56 -05:00
Mike Reeves
5d949de146
Merge pull request #7246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update networks.cfg.jinja
2022-02-18 11:28:57 -05:00
Mike Reeves
6f4ee4123a
Update networks.cfg.jinja
2022-02-18 11:26:58 -05:00
Mike Reeves
e4148818d8
Merge pull request #7226 from Security-Onion-Solutions/zeekhn
...
Add Zeek Homenet in networks.cfg
2022-02-18 11:11:56 -05:00
Mike Reeves
becdc34677
Merge pull request #7227 from hacker0ni/patch-1
...
Allow downgrades in docker_install
2022-02-18 11:10:26 -05:00
Mike Reeves
95eab61615
Rename to the .jinja standard
2022-02-18 11:06:33 -05:00
Mike Reeves
9341669a15
Merge pull request #7244 from christopherwoodall/patch-6
...
Update config.map.jinja
2022-02-18 09:57:33 -05:00
Jason Ertel
fdc63b5816
Clarify so-user update usage/help
2022-02-18 09:41:09 -05:00
Christopher Woodall
eaff6a12de
Update config.map.jinja
...
Extend the array instead of appending.
2022-02-18 08:50:28 -05:00
weslambert
6ee3287d2d
Update component -> index association for file/scan mappings for Strelka
2022-02-18 08:12:34 -05:00
James Conroy
91c207cd38
Update salt/common/tools/sbin/so-status
...
Removed # {% raw %} from line 170
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:43 -06:00
James Conroy
b774e62dfa
Update salt/common/tools/sbin/so-status
...
Add salt raw directive
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:25 -06:00
Josh Brower
f995d0768f
IDH - Initial firewall support
2022-02-17 15:54:20 -05:00
Doug Burks
3b887c7b1a
Merge pull request #7239 from Security-Onion-Solutions/dougburks-patch-1
...
so-ip-update needs to queue the Kibana dashboard update
2022-02-17 15:54:10 -05:00
Doug Burks
b4b7938ce2
so-ip-update needs to queue the Kibana dashboard update in case a salt operation is already running
2022-02-17 15:47:33 -05:00
Doug Burks
e5d7c1c77a
Merge pull request #7238 from Security-Onion-Solutions/dougburks-patch-1-1
...
so-ip-update needs to update Kibana dashboards
2022-02-17 14:53:31 -05:00
Doug Burks
1a96162966
so-ip-update needs to update Kibana dashboards
2022-02-17 14:49:55 -05:00
hacker0ni
bc72b3da91
Allow downgrades in docker_install
...
When running the installer again on a new node, it tries to pull the docker packages but since the installer ran again before, the install command fails on Ubuntu 18.04 stating that the `--allow-downgrades` is not specified in the command. This change adds that to circumvent the issue.
2022-02-17 11:47:36 -05:00
Mike Reeves
3e194c9b4b
Walk the homenet for zeek
2022-02-17 11:33:22 -05:00
Josh Brower
6c124733b5
IDH - Enable default states
2022-02-17 10:50:26 -05:00
weslambert
6842099e11
Merge pull request #7224 from Security-Onion-Solutions/fix/zeek_viz
...
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 10:05:46 -05:00
Wes Lambert
5c1f61bda8
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 15:03:46 +00:00
weslambert
53c7ad6041
Merge pull request #7223 from Security-Onion-Solutions/fix/shard_settings_setup
...
Ensure setup configures pillar correctly for index settings
2022-02-17 09:48:11 -05:00
Josh Brower
ef4df58510
IDH - Jinjafy hostname
2022-02-17 09:00:57 -05:00
weslambert
c0f9cb188b
Add missing colon
2022-02-17 07:58:05 -05:00
weslambert
d309c4fc0a
Update pillar structure for index_settings/shards
2022-02-17 07:10:29 -05:00
Jason Ertel
cb9712aa08
Merge pull request #7217 from Security-Onion-Solutions/kilo
...
MFA
2022-02-16 16:47:40 -05:00
weslambert
d084625ee0
Merge pull request #7218 from Security-Onion-Solutions/fix/composable_templates_soup
...
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:24:57 -05:00
weslambert
e71b606dd6
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:22:06 -05:00
weslambert
f1f9322bee
Merge pull request #7216 from Security-Onion-Solutions/fix/es_template_netflow_mappings_indent
...
Fix indent for so-netflow component template references
2022-02-16 14:47:31 -05:00
weslambert
185ea2fd99
Fix indent for so-netflow component template references
2022-02-16 14:46:12 -05:00
Mike Reeves
89eb2d0a8b
Add netowrks.cfg to Zeek
2022-02-16 14:24:58 -05:00
Jason Ertel
2c4ba75c0c
Merge branch 'dev' into kilo
2022-02-15 17:05:24 -05:00
weslambert
9e222b1464
Merge pull request #7206 from Security-Onion-Solutions/feature/template-reorg
...
Re-organize Elasticsearch Index Templates
2022-02-15 16:50:14 -05:00
Josh Brower
3ccef12df7
IDH - Pillarize OpenCanary Config
2022-02-15 13:57:31 -05:00
Wes Lambert
4fa3749418
Remove bind or ES templates
2022-02-15 18:08:03 +00:00
Wes Lambert
786a189f65
Merge branch 'feature/template-reorg' of https://github.com/security-onion-solutions/securityonion into feature/template-reorg
2022-02-15 17:06:02 +00:00
Wes Lambert
de731fc05d
Remove default templates from ES template pillar since they are now managed in the defaults file.
2022-02-15 17:04:57 +00:00
Wes Lambert
3df58eadd1
Modify logic to include custom templates
2022-02-15 17:00:24 +00:00
weslambert
1a53ec4372
Fix malformed copy/paste
2022-02-15 11:14:10 -05:00
Wes Lambert
dce3b7a874
Update defaults file to include ES index templates
2022-02-15 15:53:07 +00:00
Jason Ertel
377fe1987d
Merge branch 'dev' into kilo
2022-02-15 07:49:26 -05:00
Jason Ertel
d97423e9f8
Enable MFA support
2022-02-15 07:49:12 -05:00
Wes Lambert
8e389bf6e5
Add ES template map file
2022-02-14 15:38:32 +00:00
Wes Lambert
ebce67060f
Initial template refactor
2022-02-14 15:20:33 +00:00
James Conroy
a43ac2aea2
Move the jinja endraw directive below is_tty
...
This will prevent jninja from interpreting the shell string length
expansion as the start of jninja comments
2022-02-12 12:25:24 -06:00
James Conroy
95b4f7b4ef
Update the PADDING_CONSTENT to 15
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3046e811f0
Use spaces to define centerd justification output
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
6a1e586b8c
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
01346cbb06
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3adb6c1389
Renamed colors to attributes
...
Also correctly used tput to assign blue color
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dabae3888f
Renamed colors to attributes
...
As suggested by rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
c69e968790
Renamed Colors to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dfcabb5722
Seperate bold attribute from colors
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
b9b3876069
Exit with an error code if the user isn't root
2022-02-12 12:25:23 -06:00
James Conroy
bfcfad2e7d
Check for tty in main
...
So that the value is set every time it is checked
2022-02-12 12:25:23 -06:00
James Conroy
163182c858
Don't set the padding constant if not in a tty
...
This will preserve the original width from before my changes
2022-02-12 12:25:23 -06:00
James Conroy
6b4549499d
Don't split lines after standalone tests
...
This is to make the formatting consistent with the rest of the scripts
2022-02-12 12:25:23 -06:00
James Conroy
68a5826d70
Always print a line of '-'
...
Even when not printing to a tty
This is behavior preferred by the team
2022-02-12 12:25:22 -06:00
James Conroy
daa73c8845
Removed MYNAME variable
...
Preferring to just use the value of $0 instead
2022-02-12 12:25:22 -06:00
James Conroy
7f694c17ed
Revert improvements to usage function
...
Made to make it more consistent with the rest of the scripts in
Security Onion
2022-02-12 12:25:22 -06:00
James Conroy
fd9a03a77f
Added Changes Suggested by Reviewer
...
Added a missing semi colon between a local variable's declaration and
assignment
Removed an unused return value
Made a TODO more descriptive
2022-02-12 12:25:22 -06:00
James Conroy
2993a20947
Moved line declaration out of tty conditional
...
This way it will always be set to ""
2022-02-12 12:25:22 -06:00
James Conroy
ac5527e1ab
Added Comments for future enhancements
2022-02-12 12:25:22 -06:00
James Conroy
715f9da6e2
Reworked tty detection and status printing
...
I was able to reduce the line count and make the script more reliable
2022-02-12 12:25:22 -06:00
James Conroy
caa06b026f
Refactored to reduce length and number of lines
2022-02-12 12:25:21 -06:00
James Conroy
a048de65ca
Print help message if not running as root
2022-02-12 12:25:21 -06:00
James Conroy
f807471a17
Only print color codes if we're printing to a tty
...
If we're not printing to a tty the escape sequences can only clutter the
screen.
Also removed a redundant function to print lines if not printing to a
tty. It was only called if docker wasn't running, not if the output
wasn't a tty.
2022-02-12 12:25:21 -06:00
James Conroy
81122d0693
Updated the useage function to use printf
...
Using a hear doc means we have to exactly specify the formatting. Useing
printf handles formatting for us
2022-02-12 12:25:21 -06:00
Josh Brower
1e5b9ef0bf
IDH - Enable Filebeat
2022-02-10 11:37:10 -05:00
Josh Brower
b66472eced
IDH - disable nginx
2022-02-09 14:56:56 -05:00
Josh Brower
f31fbbf1ed
IDH - states allowed
2022-02-09 13:57:18 -05:00
William Wernert
1fee5e6a60
Merge pull request #7162 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Also merge CONTRIBUTING.md changes to dev
2022-02-09 11:59:00 -05:00
William Wernert
bc5fa55ecd
Merge pull request #7160 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Update CONTRIBUTING.md
2022-02-09 11:49:52 -05:00
William Wernert
2e2eed9f42
PR's -> pull requests
2022-02-09 11:45:12 -05:00
William Wernert
3f83191083
Update CONTRIBUTING.md
2022-02-09 11:34:39 -05:00
Josh Brower
30c40ed3d7
IDH Initial Support
2022-02-09 10:37:47 -05:00
Mike Reeves
d63fe73c90
Merge pull request #7157 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update to 7.17.0
2022-02-09 09:46:25 -05:00
Mike Reeves
51bd266717
Update to 7.17.0
2022-02-09 09:44:28 -05:00
weslambert
380fa7d0c8
Merge pull request #7153 from Security-Onion-Solutions/fix/dtc_event_mappings
...
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 16:36:49 -05:00
Wes Lambert
9b841fd872
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 21:34:32 +00:00
weslambert
c216457a3e
Merge pull request #7147 from Security-Onion-Solutions/fix/ct_snyk
...
Add Snyk component template
2022-02-08 10:25:27 -05:00
Wes Lambert
c2c4e4df17
Add Snyk component template
2022-02-08 15:23:43 +00:00
weslambert
7be1549d41
Merge pull request #7146 from Security-Onion-Solutions/feature/additional_dtc_ct
...
Additional component templates
2022-02-08 10:12:31 -05:00
Josh Brower
ac8e06e79b
Initial support - IDH Node
2022-02-08 09:08:52 -05:00
Josh Brower
a3602c9eb9
Initial support - IDH Node
2022-02-08 08:24:15 -05:00
Wes Lambert
f9a50d33c3
Add new templates
2022-02-08 13:17:23 +00:00
Wes Lambert
2951e12c96
Remove snyk component template for now and fix folder structure
2022-02-08 13:16:59 +00:00
Wes Lambert
6d0ca6fcbb
Fix mangled key name/typo
2022-02-08 12:59:07 +00:00
Wes Lambert
2dd5db15b6
Add component and index template listing scripts
2022-02-08 03:40:42 +00:00
Wes Lambert
5090854d4d
Add additional component templates and index template references
2022-02-08 03:03:55 +00:00
Josh Brower
37b17b8821
Initial support - IDH Node
2022-02-07 19:27:51 -05:00
Josh Brower
f590bc43a6
Initial support - IDH Node
2022-02-07 19:09:27 -05:00
Josh Brower
7a9cb6d110
Initial support - IDH Node
2022-02-07 16:49:11 -05:00
weslambert
b41c5439c6
Merge pull request #7141 from Security-Onion-Solutions/fix/index_template_mapping_reference
...
Add mapping references for new component templates to index templates
2022-02-07 15:06:19 -05:00
Wes Lambert
1366e5288e
Add mappings references for new component templates to index templates
2022-02-07 19:54:23 +00:00
weslambert
f9196a8228
Merge pull request #7140 from Security-Onion-Solutions/feature/dtc_new_mappings
...
New DTC/Component Template Mappings
2022-02-07 14:47:07 -05:00
Wes Lambert
03bfb052ed
Add component templates for Elasticsearch, Kibana, Logstash, Netflow, Suricata, and Zeek
2022-02-07 19:42:24 +00:00
Josh Brower
9b1fac8417
Initial support - IDH Node
2022-02-07 14:36:40 -05:00
weslambert
c9b40d8569
Merge pull request #7136 from Security-Onion-Solutions/feature/so_es_indices_list_sort
...
Sort index listing alphabetically and add header
2022-02-07 09:34:58 -05:00
Wes Lambert
50215c550b
Sort index listing alphabetically and add header (@gebhard73)
2022-02-07 14:31:42 +00:00
Josh Patterson
ee17064585
Merge pull request #7122 from Security-Onion-Solutions/soup_docker_iso
...
Soup docker iso
2022-02-07 09:29:35 -05:00
Josh Patterson
e0c0eba24e
Update soup
2022-02-07 09:23:30 -05:00
Josh Patterson
7d09d1f7e2
Update soup
2022-02-07 09:22:43 -05:00
Mike Reeves
77fc9df448
Merge pull request #7134 from Security-Onion-Solutions/mastermerger
...
Mastermerger
2022-02-07 08:38:27 -05:00
Mike Reeves
abd121733f
Merge branch 'master' into mastermerger
2022-02-07 08:34:17 -05:00
m0duspwnens
7c31eb1288
mount iso at different point
2022-02-04 16:07:06 -05:00
m0duspwnens
780aace854
set AGDOCKER
2022-02-04 15:44:25 -05:00
m0duspwnens
eb0696b425
update dockers if -f used
2022-02-04 15:36:44 -05:00
m0duspwnens
267ef354c2
unmount iso after updating dockers
2022-02-04 15:09:35 -05:00
m0duspwnens
23fbf140ba
soup with dockers from iso
2022-02-04 15:06:42 -05:00
weslambert
d0b54a3a34
Merge pull request #7119 from Security-Onion-Solutions/feature/dtc_additional
...
Add additional scan and rule fileset mappings
2022-02-04 14:14:20 -05:00
Wes Lambert
317f6471d8
Add additional scan and rule filset mappings
2022-02-04 19:05:09 +00:00
weslambert
08c7181f1a
Merge pull request #7118 from Security-Onion-Solutions/fix/dtc_file_mappings
...
Fix/dtc file mappings
2022-02-04 13:22:11 -05:00
Wes Lambert
1ce8bb3523
Fix winlog mapping reference reversion
2022-02-04 18:14:01 +00:00
Wes Lambert
5e03b1a5de
Fix reference for file mappings in template
2022-02-04 18:11:03 +00:00
weslambert
898db542bf
Merge pull request #7117 from Security-Onion-Solutions/feature/winlog_dtc_mappings
...
Add winlog mappings
2022-02-04 12:16:16 -05:00
weslambert
66452b14ef
Merge pull request #7116 from Security-Onion-Solutions/fix/endgame_mappings
...
Fix EG template and mappings
2022-02-04 12:16:07 -05:00
Wes Lambert
69cb83cac9
Add winlog mappings
2022-02-04 17:08:26 +00:00
Wes Lambert
f3902cf77d
Fix EG template and mappings
2022-02-04 16:00:16 +00:00
weslambert
1af63edc6b
Merge pull request #7115 from Security-Onion-Solutions/feature/additional_dtc_mappings
...
Additional DTC mapping changes
2022-02-04 10:46:47 -05:00
Wes Lambert
a3031b2b5c
Additional DTC mapping changes
2022-02-04 15:38:51 +00:00
weslambert
1edc1dd842
Merge pull request #7096 from Security-Onion-Solutions/fix/dtc-ct-keyword-subfield
...
Add more DTC transition mappings
2022-02-03 12:35:34 -05:00
Wes Lambert
1ce386bb7f
Add more DTC transition mappings
2022-02-03 17:33:05 +00:00
weslambert
c7d23df000
Merge pull request #7076 from Security-Onion-Solutions/fix/zeek_dns_answers_name
...
Rename dns.answers to prevent field conflict
2022-02-03 12:22:26 -05:00
weslambert
c5b5c5858e
Rename to prevent field conflict
2022-02-02 14:31:46 -05:00
weslambert
5e9e0d971b
Merge pull request #7070 from Security-Onion-Solutions/feature/composable_templates
...
Initial composable template configuration and base mappings
2022-02-02 10:25:15 -05:00
Wes Lambert
9db1510b0e
Initial composable template configuration and base mappings
2022-02-02 02:08:31 +00:00
Jason Ertel
1bac031975
Merge pull request #7058 from Security-Onion-Solutions/kilo
...
Bump to 2.3.110
2022-02-01 15:04:48 -05:00
Jason Ertel
c5d6f09320
Bump to 2.3.110
2022-02-01 15:03:41 -05:00
abesinger
31d22e717d
Updated syslog pipeline, resolves #6912 . Also cleaned up formatting to make it more readable.
2022-01-19 18:45:26 -06:00