Mike Reeves
9dc31b6db4
Merge pull request #10193 from Security-Onion-Solutions/2.4/dev
...
2.4.1
2023-04-24 13:29:45 -04:00
Mike Reeves
083d96fab2
Merge pull request #10192 from Security-Onion-Solutions/2.4.1
...
Update VERIFY_ISO.md
2023-04-24 11:41:04 -04:00
Mike Reeves
f21e717dcd
Update README.md
2023-04-24 11:39:39 -04:00
Mike Reeves
87e9d2997b
Update VERIFY_ISO.md
2023-04-24 11:37:35 -04:00
Josh Patterson
288b5ac4d2
Merge pull request #10184 from Security-Onion-Solutions/2.4/hsschedule
...
rename highstate schedule
2023-04-24 09:34:11 -04:00
m0duspwnens
533c3b7569
rename highstate schedule
2023-04-24 09:31:32 -04:00
weslambert
32874d2e9d
Merge pull request #10175 from Security-Onion-Solutions/fix/setup_docker_image_display_and_log
...
Display output and write to a log for Docker image operations during setup
2023-04-20 17:15:09 -04:00
Wes
fca7753f73
Display output and write to log for Docker image downloads
2023-04-20 20:56:04 +00:00
Doug Burks
fcdb02d61e
Merge pull request #10174 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Overview Customization link #10173
2023-04-20 16:28:01 -04:00
Doug Burks
4dcc79d245
FIX: Overview Customization link #10173
2023-04-20 16:26:51 -04:00
weslambert
6c7b4e5492
Merge pull request #10166 from Security-Onion-Solutions/fix/elasticsearch_curl_config
...
Don't distribute curl configuration to nodes that don't need it
2023-04-20 08:47:47 -04:00
Wes
a341f1b7b7
Don't distribute curl configuration to nodes that don't need it
2023-04-20 12:31:50 +00:00
weslambert
01bd3545d0
Merge pull request #10162 from Security-Onion-Solutions/fix/elastic_agent_metadata
...
Rename @metadata to metadata to ensure it's not lost between Logstash pipelines
2023-04-19 16:25:01 -04:00
Wes
d823d5dcc9
Rename @metadata to metadata to ensure it's not lost between Logstash pipelines
2023-04-19 20:17:10 +00:00
Josh Patterson
9fed2ac616
Merge pull request #10159 from Security-Onion-Solutions/ui/globals
...
fix globals being changed via ui
2023-04-19 12:22:42 -04:00
m0duspwnens
d5ab8ff191
create the local global pillar directory
2023-04-19 11:44:03 -04:00
m0duspwnens
2b28283095
Merge remote-tracking branch 'origin/2.4/dev' into ui/globals
2023-04-19 11:23:29 -04:00
Josh Brower
499b889b56
Merge pull request #10158 from Security-Onion-Solutions/2.4/fleet
...
Gen installers at the end setup
2023-04-19 11:12:22 -04:00
Josh Brower
aa5063c5df
Gen installers at the end setup
2023-04-19 11:11:08 -04:00
m0duspwnens
9f07388fa4
fix global location for fleet node
2023-04-19 10:47:08 -04:00
m0duspwnens
cd674947bb
Merge remote-tracking branch 'origin/2.4/dev' into ui/globals
2023-04-19 10:45:56 -04:00
m0duspwnens
976ad4152d
move soc_global and adv_global pillar file under pillar/global/
2023-04-19 10:44:02 -04:00
Josh Brower
2633f348ac
Merge pull request #10157 from Security-Onion-Solutions/2.4/fleet
...
Fix cert gen
2023-04-19 10:25:24 -04:00
Josh Brower
1ab72e9288
Fix cert gen
2023-04-19 10:23:13 -04:00
Josh Brower
ef92fba867
Merge pull request #10156 from Security-Onion-Solutions/2.4/fleet
...
2.4/fleet
2023-04-19 10:06:03 -04:00
Josh Brower
36c96c4beb
Remove dep vars
2023-04-19 10:02:24 -04:00
Josh Brower
d79ad53daf
Merge pull request #10153 from Security-Onion-Solutions/fleet-sa
...
FEATURE: Dedicated Fleet Node
2023-04-19 09:12:30 -04:00
Josh Brower
4c4b873eca
Add integrations and cleanup
2023-04-19 09:04:33 -04:00
Josh Patterson
a062939705
Merge pull request #10152 from Security-Onion-Solutions/issue/10050
...
Issue/10050
2023-04-18 11:58:04 -04:00
Jason Ertel
3f14885539
Merge pull request #10151 from Security-Onion-Solutions/kilo
...
avoid docker and lo nics getting used by test profiles
2023-04-18 11:56:35 -04:00
Jason Ertel
393077ba9e
avoid docker and lo nics getting used by test profiles
2023-04-18 11:43:24 -04:00
m0duspwnens
b0f9585da1
Merge remote-tracking branch 'origin/2.4/dev' into issue/10050
2023-04-18 11:31:00 -04:00
m0duspwnens
7c8ba04820
set file limit for zeek container
2023-04-18 11:30:39 -04:00
Josh Brower
31f83c6dee
Re-enabled Fleet Setup during setup
2023-04-17 15:00:51 -04:00
Josh Brower
8cccaef664
mkdirs as needed
2023-04-17 12:28:07 -04:00
Josh Brower
1944d09978
Logstash certs fixup
2023-04-17 11:34:57 -04:00
Josh Brower
a7d282b412
Firewall fixup
2023-04-15 18:33:44 -04:00
Jason Ertel
aade62491c
Merge pull request #10132 from Security-Onion-Solutions/kilo
...
fix log dir
2023-04-14 16:58:14 -04:00
Jason Ertel
b901555793
fix log dir
2023-04-14 16:56:40 -04:00
Josh Patterson
debe146dcf
Merge pull request #10131 from Security-Onion-Solutions/m0duspwnens-patch-1
...
USER=root no longer needed for so-status cron
2023-04-14 16:23:27 -04:00
Josh Patterson
c8ef8cc88e
USER=root no longer needed for so-status cron
2023-04-14 16:18:48 -04:00
Jason Ertel
9bd176621d
Merge pull request #10130 from Security-Onion-Solutions/kilo
...
detect root using id command
2023-04-14 16:17:44 -04:00
Jason Ertel
05baaacc83
detect root using id command
2023-04-14 16:15:39 -04:00
Jason Ertel
9bc44c122f
Merge pull request #10129 from Security-Onion-Solutions/kilo
...
wrong and
2023-04-14 12:46:11 -04:00
Jason Ertel
1fdd8acd0c
wrong and
2023-04-14 12:35:32 -04:00
Josh Brower
92a6eac976
fix EA wrapper gen
2023-04-14 12:09:18 -04:00
Jason Ertel
dc227df229
Merge pull request #10128 from Security-Onion-Solutions/kilo
...
Skip raid state for cloud images
2023-04-14 10:31:17 -04:00
Jason Ertel
ff35a58f3f
Skip raid state for cloud images
2023-04-14 10:24:54 -04:00
Josh Patterson
64fde6b02e
Merge pull request #10124 from Security-Onion-Solutions/2.4/ubuntu
...
2.4/ubuntu
2023-04-13 16:35:53 -04:00
m0duspwnens
1047462898
add identifiers for all cron.present
2023-04-13 16:25:47 -04:00
m0duspwnens
76ba89c356
fix so-status cron to work with ubuntu
2023-04-13 16:01:43 -04:00
weslambert
f3b4ee6a0b
Merge pull request #10121 from Security-Onion-Solutions/fix/elasticsearch_deletion_improvements
...
Simplify deletion logic and add stderr and stdout logging within script
2023-04-13 11:10:50 -04:00
Wes
d6421ee7cc
Simplify deletion logic and add stderr and stdout logging within script
2023-04-13 15:04:16 +00:00
Doug Burks
148ef5833e
Merge pull request #10120 from Security-Onion-Solutions/2.4/fix-suricata-dns
...
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 11:00:24 -04:00
Doug Burks
a67cbb3276
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 10:56:17 -04:00
m0duspwnens
0485c83388
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/ubuntu
2023-04-13 09:10:58 -04:00
Jason Ertel
a8d3363a6f
Merge pull request #10115 from Security-Onion-Solutions/kilo
...
discover appliance model grain during setup
2023-04-12 19:12:45 -04:00
Jason Ertel
dba7b84adb
discover appliance model grain during setup
2023-04-12 19:02:04 -04:00
Josh Brower
2567ceea74
Fix path
2023-04-12 16:51:40 -04:00
Josh Brower
4ec31dbf35
Refactoring Fleet setup redux
2023-04-12 16:40:28 -04:00
m0duspwnens
e4e326cd06
limit whiptail install options for ubuntu
2023-04-12 15:44:42 -04:00
m0duspwnens
0d17f4f486
python modules for filecheck
2023-04-12 14:38:21 -04:00
Mike Reeves
7838393b9f
Merge pull request #10112 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update defaults.yaml
2023-04-12 10:32:54 -04:00
m0duspwnens
c90c72dbba
provide info when running apt-get update and upgrade
2023-04-12 10:17:13 -04:00
Mike Reeves
04eb73ac27
Update defaults.yaml
2023-04-12 10:06:23 -04:00
m0duspwnens
de082f6100
install chrony in ntp state
2023-04-12 09:26:04 -04:00
weslambert
2c44c8e468
Merge pull request #10108 from Security-Onion-Solutions/fix/elastic_clear
...
Update Elastic clear utility script
2023-04-11 17:24:21 -04:00
Wes
06b60ca96b
Don't stop Elastic Fleet for now
2023-04-11 21:11:12 +00:00
Wes
4d64a9777e
Update Elastic clear utility script
2023-04-11 21:06:20 +00:00
m0duspwnens
26a12477ac
python3-rich for ubuntu and chrony pkg for all
2023-04-11 15:36:57 -04:00
weslambert
43447e5df5
Merge pull request #10106 from Security-Onion-Solutions/fix/kibana_16.04_dashboards_remove
...
Remove Security Onion 16.04 dashboards
2023-04-11 14:41:12 -04:00
m0duspwnens
c66f595666
unsure prereqs for sensor
2023-04-11 13:48:59 -04:00
m0duspwnens
ad64b873c0
ubuntu changes
2023-04-11 12:58:40 -04:00
Wes
c6be0a48a1
Remove Security Onion 16.04 dashboards
2023-04-11 15:05:41 +00:00
weslambert
5eb0364a98
Merge pull request #10105 from Security-Onion-Solutions/fix/elasticsearch_template_loading_so-searchnode
...
Only load pipelines and templates if the node role is not 'so-searchnode'
2023-04-11 10:45:52 -04:00
Wes
8d0074c712
Only load pipelines and tempaltes if the node role is not 'so-searchnode'
2023-04-11 14:15:21 +00:00
Jason Ertel
3883a89212
Merge pull request #10102 from Security-Onion-Solutions/kilo
...
elastic-fleet typo fix; remote dev enhancement
2023-04-10 14:09:20 -04:00
Jason Ertel
cfa61a6c26
correct salt state
2023-04-10 14:04:19 -04:00
Jason Ertel
7f28cdd2a3
provide means for using salt-relay with local development against remove VMs
2023-04-10 14:04:03 -04:00
m0duspwnens
9ea3eaafae
fix merge conflict
2023-04-10 09:09:43 -04:00
m0duspwnens
16249cc80d
salt install for ubuntu
2023-04-10 09:06:55 -04:00
m0duspwnens
2589670755
set forceType
2023-04-06 15:16:04 -04:00
Josh Brower
17bc96c3b3
Refactoring Fleet setup
2023-04-06 13:21:19 -04:00
Josh Patterson
b87ee4904f
Merge pull request #10096 from Security-Onion-Solutions/salt3006rc3
...
only install salt-minion on non manager
2023-04-06 11:07:26 -04:00
m0duspwnens
7519a8c39d
only install salt-minion on non manager
2023-04-06 10:20:17 -04:00
m0duspwnens
df4bf95b93
sort local.zeek so redef is last
2023-04-06 09:54:59 -04:00
m0duspwnens
602e00058a
Merge remote-tracking branch 'remotes/origin/2.4/dev' into issue/10050
2023-04-06 09:13:27 -04:00
Josh Patterson
6aba7b6bcf
Merge pull request #10091 from Security-Onion-Solutions/salt3006rc3
...
Salt3006rc3
2023-04-05 16:42:36 -04:00
Josh Patterson
ff7aaa95e1
Merge branch '2.4/dev' into salt3006rc3
2023-04-05 16:38:41 -04:00
m0duspwnens
f166919160
use dockerpy 5.0.2
2023-04-05 15:35:48 -04:00
m0duspwnens
aecbfd28ee
install salt module deps from local
2023-04-05 13:08:50 -04:00
m0duspwnens
b24e3ff6c4
add requests 2.25.1
2023-04-04 16:59:35 -04:00
Josh Brower
cda67b2894
Ded Fleet Node - checkpoint
2023-04-04 16:11:22 -04:00
m0duspwnens
6040c5062b
include whl files for salt module dependencies
2023-04-04 16:08:35 -04:00
m0duspwnens
d83266c546
remove unrecognized keyword arguments
2023-04-04 09:58:44 -04:00
m0duspwnens
6039a1430e
x509 changes for salt 3006
2023-04-04 08:55:10 -04:00
Josh Brower
c2d4e870c8
Fixup Elastic Fleet
2023-04-03 16:50:34 -04:00
Josh Patterson
1faceddc40
Merge pull request #10085 from Security-Onion-Solutions/saltrc3key
...
Saltrc3key
2023-04-03 11:27:04 -04:00
Josh Patterson
471f467e63
Merge pull request #10084 from Security-Onion-Solutions/saltrc3key
...
add new salt key since rc3 has been added to repo
2023-04-03 11:23:57 -04:00
m0duspwnens
a0d8be4dc6
add new salt key since rc3 has been added to repo
2023-04-03 10:44:44 -04:00
Josh Brower
035451cdb8
Cleanup conflict leftovers
2023-04-03 07:30:25 -04:00
Josh Brower
af392681e3
Merge remote-tracking branch 'remotes/origin/2.4/dev' into fleet-sa
2023-04-03 07:27:04 -04:00
Josh Brower
a0bb6a700a
Merge pull request #10082 from Security-Onion-Solutions/2.4/elasticagent8.7
...
Update elastic agent binaries - 8.7.0
2023-03-31 18:40:43 -04:00
Josh Brower
ad000550a6
Update elastic agent binaries - 8.7.0
2023-03-31 16:46:24 -04:00
m0duspwnens
0fc6a74b6d
update salt versions on defaults
2023-03-31 15:02:40 -04:00
m0duspwnens
0b96635bcc
salt3006rc3
2023-03-31 14:52:40 -04:00
Doug Burks
5b2e39f80d
Merge pull request #10078 from Security-Onion-Solutions/2.4/fix-elasticsearch-roles
...
FIX: SOC only displaying data for users assigned the superuser role #10068
2023-03-31 09:26:58 -04:00
Doug Burks
a8b6470a14
Update limited-auditor.json
2023-03-31 09:22:42 -04:00
Doug Burks
e945f1c38f
Update limited-analyst.json
2023-03-31 09:22:28 -04:00
Doug Burks
d0dff9572d
Update auditor.json
2023-03-31 09:22:15 -04:00
Doug Burks
68e8c159ce
Update analyst.json
2023-03-31 09:21:59 -04:00
Josh Brower
a8038c90ce
Merge pull request #10077 from Security-Onion-Solutions/2.4/Elastic8.7.0
...
2.4/elastic8.7.0
2023-03-31 08:57:20 -04:00
Josh Brower
91c990e30a
UPGRADE: Elastic 8.7.0
2023-03-31 08:52:43 -04:00
Josh Brower
b6b49c876b
UPGRADE: Elastic to 8.7.0
2023-03-31 08:51:51 -04:00
Doug Burks
cf98a95dd1
Merge pull request #10072 from Security-Onion-Solutions/2.4/so-user-formatting
...
fix formatting in so-user
2023-03-30 17:03:29 -04:00
Doug Burks
921e79c56c
fix formatting in so-user
2023-03-30 16:55:30 -04:00
weslambert
2cfbf30f05
Merge pull request #10070 from Security-Onion-Solutions/fix/cloud_test
...
Fix cloud sniffing interface configuration
2023-03-30 14:41:59 -04:00
weslambert
3e08506c4e
Fix syntax for $is_cloud test
2023-03-30 13:26:36 -04:00
Wes
d4cba6908e
Use dynamic interface value instead of explicitly setting it to 'bond0'
2023-03-30 16:17:34 +00:00
Wes
dfd3456343
Add logging for cloud detection and interface settings
2023-03-30 16:15:41 +00:00
Wes
3cd1598067
Only perform bond interface operations if it is not a cloud installation
2023-03-30 16:11:50 +00:00
m0duspwnens
1be86cdf8e
issue 10050 and issue 10062
2023-03-29 17:21:40 -04:00
Mike Reeves
bdae8d5017
Merge pull request #10042 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2023-03-28 16:21:50 -04:00
Mike Reeves
d5e17da9d3
Update VERSION
2023-03-28 16:20:40 -04:00
Mike Reeves
b2a2dc5aea
Merge pull request #10037 from Security-Onion-Solutions/2.4/dev
...
2.4.0 Beta 1
2023-03-28 16:08:01 -04:00
Josh Patterson
72078848d3
Merge pull request #10041 from Security-Onion-Solutions/firsthighstatecronfix
...
add path to first highstate cron
2023-03-28 14:38:19 -04:00
Josh Patterson
af4acd5597
add path to first highstate cron
2023-03-28 14:37:28 -04:00
weslambert
de902ebd02
Merge pull request #10024 from Security-Onion-Solutions/esspace
...
Manage disk-based index deletion via so-curator-cluster-delete
2023-03-28 12:25:19 -04:00
Wes
6099a04e41
Change how the size is determined, in case there a decimal value is provided
2023-03-28 16:04:54 +00:00
Jason Ertel
44c696a495
Merge pull request #10036 from Security-Onion-Solutions/commonprofile
...
ensure scripts are run as root, have copyright, and path is correct
2023-03-28 11:59:10 -04:00
Josh Patterson
16606c1aaa
Merge pull request #10038 from Security-Onion-Solutions/addbangs
...
change #/bin/bash to #!/bin/bash
2023-03-28 11:58:09 -04:00
Jason Ertel
4efe22efb3
Update so-elasticsearch-cluster-settings
2023-03-28 11:57:41 -04:00
Jason Ertel
591129b98c
Update so-elasticsearch-pipelines
2023-03-28 11:57:22 -04:00
Jason Ertel
60d770411a
Update so-elasticsearch-roles-load
2023-03-28 11:57:07 -04:00
Jason Ertel
5f49a120de
Update so-elasticsearch-templates-load
2023-03-28 11:56:51 -04:00
m0duspwnens
64446f585c
change #/bin/bash to #!/bin/bash
2023-03-28 11:55:47 -04:00
Wes
ed8f944638
Fix typo in GLOBALS reference
2023-03-28 15:55:33 +00:00
Mike Reeves
74840264d7
Update so-elasticsearch-cluster-space-used
2023-03-28 11:49:05 -04:00
Jason Ertel
492fe1fc85
Ensure /usr/sbin is in path
2023-03-28 11:48:31 -04:00
Mike Reeves
e77e645a36
Update so-elasticsearch-cluster-space-total
2023-03-28 11:45:57 -04:00
Mike Reeves
636505ef98
Add license and common
2023-03-28 11:18:56 -04:00
weslambert
942182e826
Remove additional copyright in so-curator-cluster-delete-delete
2023-03-28 11:00:14 -04:00
weslambert
303fec6302
Fix verbiage for so-curator-cluster-delete-delete
2023-03-28 10:59:39 -04:00
weslambert
9411f5ca79
Fix closed index function and check
2023-03-28 10:54:21 -04:00
Wes
d494381e9d
Update verbiage for so-curator-cluster-delete
2023-03-28 14:18:49 +00:00
Wes
e1bda5acfd
Update verbiage for so-curator-cluster-delete-delete
2023-03-28 14:18:27 +00:00
Wes
138b312705
Fix script name
2023-03-28 13:52:59 +00:00
Wes
82efce0b31
Ensure so-curator-cluster-delete is run to manage so-curator-cluster-delete-delete
2023-03-28 13:23:23 +00:00
Wes
1ab253b8c3
Use explicit path to so-elasticsearch-query
2023-03-28 13:18:14 +00:00
Wes
a1394b9102
Use explicit path to so-elasticsearch-query
2023-03-28 13:18:00 +00:00
Wes
b3b030958c
Use explicit path to so-elasticsearch-query
2023-03-28 13:17:23 +00:00
Josh Patterson
ebdd74a420
Merge pull request #10032 from Security-Onion-Solutions/evalelasticfleet
...
add elasticfleet state to top for eval node
2023-03-28 09:03:16 -04:00
m0duspwnens
d886265211
add elasticfleet state to top for eval node
2023-03-28 09:01:41 -04:00
Wes
adbc9df222
Changes for LOG_SIZE_LIMIT
2023-03-28 12:54:32 +00:00
Doug Burks
1ad65f6326
Merge pull request #10030 from Security-Onion-Solutions/dougburks-patch-1
...
Update soc_idh.yaml
2023-03-28 08:54:12 -04:00
Doug Burks
46d9e0b804
Update soc_idh.yaml
2023-03-28 08:53:05 -04:00
Wes
f854d92cab
Remove the cluster space configuration script reference from the Elasticsearch state
2023-03-28 12:27:45 +00:00
Wes
22e8e3be28
Remove the cluster space configuration script
2023-03-28 12:27:12 +00:00
Wes
4352825ceb
Calculate log size limit every time so-curator-cluster-delete-delete runs
2023-03-28 12:25:49 +00:00
Wes
e2290d8a8e
Remove unncessary Salt logic for Elasticsearch
2023-03-28 12:19:36 +00:00
Wes
c68235c169
Fix Curator script name
2023-03-28 02:27:27 +00:00
Wes
a38aa903ac
Configure cluster space settings
2023-03-28 01:36:52 +00:00
Wes
fc0b9fa47c
Remove Curator closed index deletion scripts
2023-03-28 00:57:45 +00:00
Wes
32e92d10ad
Add new cluster space management scripts
2023-03-28 00:55:56 +00:00
Wes
7030f35561
Update Curator state
2023-03-28 00:54:36 +00:00
Wes
934b8894e2
Update Curator scripts
2023-03-28 00:54:04 +00:00
Jason Ertel
100d9f14e9
Merge pull request #10023 from Security-Onion-Solutions/kilo
...
fix role
2023-03-27 19:31:06 -04:00
Jason Ertel
34cd823cd4
fix role
2023-03-27 18:59:32 -04:00
Josh Patterson
a86da24bde
Merge pull request #10021 from Security-Onion-Solutions/bpffix
...
remove default zeek bpf
2023-03-27 17:01:36 -04:00
m0duspwnens
fcb6f3eaf1
remove default zeek bpf
2023-03-27 16:59:27 -04:00
Mike Reeves
6cc510d51b
Merge pull request #10020 from Security-Onion-Solutions/kilo
...
add minion CIDR to search also
2023-03-27 16:56:56 -04:00
Jason Ertel
2b1576249a
add minion CIDR to search also
2023-03-27 16:44:21 -04:00
Josh Brower
2dd48c6f0b
Merge pull request #10019 from Security-Onion-Solutions/2.4/idhfix
...
Add annotations
2023-03-27 15:19:15 -04:00
Josh Brower
d22a5b2eb3
Add annotations
2023-03-27 15:16:47 -04:00
Josh Patterson
8b626d2c67
Merge pull request #10018 from Security-Onion-Solutions/managersaltrestart
...
Managersaltrestart
2023-03-27 13:37:04 -04:00
m0duspwnens
0d87a5d739
import sensor vars in import vars
2023-03-27 12:51:29 -04:00
Mike Reeves
6c3c5730c5
Add curator settings
2023-03-27 12:33:34 -04:00
Mike Reeves
2cb6f0f1e6
Add curator settings
2023-03-27 12:30:39 -04:00
m0duspwnens
42cc419e00
restart salt master and minion after manager install completes
2023-03-27 11:30:03 -04:00
Mike Reeves
7752529b42
Merge pull request #10015 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-common
2023-03-27 10:51:26 -04:00
Mike Reeves
7f395c4c1e
Update so-common
2023-03-27 10:49:36 -04:00
Mike Reeves
94ae7469e3
Merge pull request #10012 from Security-Onion-Solutions/pkg
...
Modify reposync useragent
2023-03-27 10:21:35 -04:00
Mike Reeves
2a288c7e4a
Update so-functions
2023-03-27 10:18:57 -04:00
Mike Reeves
1602551295
Modify reposync useragent
2023-03-27 10:14:32 -04:00
Mike Reeves
72d01b13ed
Modify reposync useragent
2023-03-27 10:12:13 -04:00
Mike Reeves
f34bb40025
Merge pull request #10011 from Security-Onion-Solutions/pkg
...
Add unzip
2023-03-27 09:28:05 -04:00
Mike Reeves
8246293983
Add unzip
2023-03-27 08:40:36 -04:00
Josh Patterson
80043d154a
Merge pull request #10004 from Security-Onion-Solutions/guifixes
...
Guifixes
2023-03-24 16:58:19 -04:00
m0duspwnens
aa66a6471a
Merge remote-tracking branch 'origin/2.4/dev' into guifixes
2023-03-24 16:16:32 -04:00
m0duspwnens
1a6d887b5f
idh setup changes
2023-03-24 16:16:22 -04:00
Mike Reeves
3fed3b3f3e
Merge pull request #10003 from Security-Onion-Solutions/mirrorz
...
Add additional mirror
2023-03-24 15:13:03 -04:00
Mike Reeves
cb2fdae368
Switch Repos
2023-03-24 14:40:59 -04:00
Josh Brower
d9e1a54479
Merge pull request #10001 from Security-Onion-Solutions/2.4/playbookfix
...
Fix errors
2023-03-24 14:31:43 -04:00
Mike Reeves
afe4d75d91
Switch Repos
2023-03-24 14:13:48 -04:00
Doug Burks
7ced7488c7
Merge pull request #10000 from Security-Onion-Solutions/dougburks-patch-1
...
Add four new GeoIP dashboards
2023-03-24 14:11:58 -04:00
Doug Burks
5be5466efe
fix GeoIP queries
2023-03-24 14:03:12 -04:00
Mike Reeves
b2c2e1574f
Switch Repos
2023-03-24 14:02:13 -04:00
Doug Burks
a9dc7a14cb
fix GeoIP queries
2023-03-24 13:56:51 -04:00
m0duspwnens
627b243cac
Merge remote-tracking branch 'origin/2.4/dev' into guifixes
2023-03-24 13:52:38 -04:00
m0duspwnens
462b2b23b9
rework idh for web ui
2023-03-24 13:52:21 -04:00
Doug Burks
aa9d44ab09
Add four new GeoIP dashboards
2023-03-24 13:51:13 -04:00
Jason Ertel
890e1897af
Merge pull request #9999 from Security-Onion-Solutions/kilo
...
prune system volumes during upgrade
2023-03-24 13:30:57 -04:00
Jason Ertel
0be57e686e
prune system volumes during upgrade
2023-03-24 13:22:21 -04:00
Josh Brower
16bc63233f
Fix errors
2023-03-24 09:33:12 -04:00
Mike Reeves
e38b0313c7
Merge pull request #9994 from Security-Onion-Solutions/hotones
...
Switch up elastic roles
2023-03-23 16:59:49 -04:00
Josh Brower
c6f6f306a7
Merge pull request #9993 from Security-Onion-Solutions/2.4/ingestsoclogs
...
SOC Logs & Hunt Query
2023-03-23 16:25:32 -04:00
Josh Brower
bad905f54c
SOC Logs & Hunt Query
2023-03-23 16:22:59 -04:00
Mike Reeves
90159f4bcd
Switch up elastic roles
2023-03-23 15:09:40 -04:00
weslambert
0f66645a89
Merge pull request #9990 from Security-Onion-Solutions/fix/elasticsearch_node_attrs_remove
...
Remove node attrs configuration since node roles will be used
2023-03-23 13:48:00 -04:00
weslambert
0a9a064648
Remove node attrs configuration since node roles will be used
2023-03-23 13:45:51 -04:00
weslambert
d6bc20a2b8
Merge pull request #9986 from Security-Onion-Solutions/fix/elastic_agent_template_changes
...
Elastic Agent template changes
2023-03-23 13:07:22 -04:00
Mike Reeves
886bcda38c
Merge pull request #9988 from Security-Onion-Solutions/repofun
...
Add Repo Sync
2023-03-23 12:49:06 -04:00
Mike Reeves
3b671efa8e
Fix cache location
2023-03-23 12:47:48 -04:00
Mike Reeves
0a096712cb
Fix cache location
2023-03-23 12:39:31 -04:00
Mike Reeves
c977f38a58
Change repo conf permissions
2023-03-23 11:56:40 -04:00
Mike Reeves
8f4076ccd6
Change repo conf permissions
2023-03-23 11:46:32 -04:00
Mike Reeves
3756c93518
Change repo download script location
2023-03-23 11:05:48 -04:00
Mike Reeves
b68cf85392
Change repo download script location
2023-03-23 11:04:26 -04:00
Mike Reeves
e52087b742
Saltify it up
2023-03-23 10:54:01 -04:00
Mike Reeves
02aa8662f7
Saltify it up
2023-03-23 10:52:05 -04:00
Mike Reeves
f8d5acd37d
Saltify it up
2023-03-23 10:43:47 -04:00
Mike Reeves
b3ea4194dd
Only allow reposync to run on managers
2023-03-23 09:49:02 -04:00
Wes
84360aa9bf
Set replicas for Osquery manager indices to 0
2023-03-22 21:47:49 +00:00
Josh Patterson
c64987e756
Merge pull request #9985 from Security-Onion-Solutions/m0duspwnens-patch-1
...
ensure highstate schedule added sooner in highstate
2023-03-22 17:24:23 -04:00
Josh Patterson
c8e93f0388
Update top.sls
2023-03-22 17:22:21 -04:00
Wes
3fba27a0d4
Ensure component template files are in the correct directory
2023-03-22 20:45:33 +00:00
Wes
28f5dcd43b
Add managed generic Elastic Agent log component templates
2023-03-22 19:57:46 +00:00
Wes
eaaa028999
Update Elastic Agent template settings
2023-03-22 19:52:13 +00:00
Mike Reeves
f8e59478f4
Merge pull request #9984 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update config.map.jinja
2023-03-22 15:49:35 -04:00
Mike Reeves
d2bc5e4af2
Update config.map.jinja
2023-03-22 15:45:51 -04:00
Josh Patterson
4f995c1c7e
Merge pull request #9983 from Security-Onion-Solutions/2.4/zeekbpf
...
add sensor vars to eval
2023-03-22 12:23:07 -04:00
weslambert
bc2a84c631
Merge pull request #9982 from Security-Onion-Solutions/fix/elastic_integration_and_pipeline_strelka
...
Change data stream name and 'event.dataset' value for Strelka events
2023-03-22 11:08:58 -04:00
weslambert
6d87620c6a
Explicitly set 'event.dataset' as 'file'
2023-03-22 11:04:18 -04:00
weslambert
68380d7ecb
Change data_stream.dataset from 'file' to 'strelka'
2023-03-22 11:02:38 -04:00
m0duspwnens
5a2ef21ce4
add sensor vars to eval
2023-03-22 09:55:30 -04:00
m0duspwnens
fdaf8e8c68
idh changes for web ui
2023-03-22 09:38:40 -04:00
Mike Reeves
00b1ecb7d9
Merge pull request #9979 from Security-Onion-Solutions/esfun
...
Elastic Fixes
2023-03-22 08:51:24 -04:00
Mike Reeves
007e2baf41
Change Elastic Logic
2023-03-21 17:46:52 -04:00
Mike Reeves
5fc297b8c1
Change Elastic Logic
2023-03-21 16:52:08 -04:00
Mike Reeves
07f303205a
Merge pull request #9977 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Update so-minion
2023-03-21 15:50:52 -04:00
Mike Reeves
aeb6d47637
Update so-minion
2023-03-21 13:39:24 -04:00
Josh Brower
a247d1cc50
Merge pull request #9978 from Security-Onion-Solutions/2.4/updateEA
...
2.4/update ea
2023-03-21 13:27:59 -04:00
Mike Reeves
30fc74ac09
Update so-minion
2023-03-21 12:53:35 -04:00
Josh Brower
cd6bf0fe78
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/updateEA
2023-03-21 12:48:30 -04:00
Josh Brower
d87060b56e
Update Elastic Agent to 8.6.2
2023-03-21 12:48:02 -04:00
Mike Reeves
1526a7de11
Rework IDH phase 1
2023-03-21 11:26:30 -04:00
Mike Reeves
d89310e479
Rework IDH phase 1
2023-03-21 11:25:06 -04:00
Mike Reeves
bd17121834
Rework IDH phase 1
2023-03-21 11:23:31 -04:00
Jason Ertel
ca363053e6
Merge pull request #9975 from Security-Onion-Solutions/kilo
...
catch errors and exit with proper exit code
2023-03-21 10:51:36 -04:00
Josh Patterson
a0eea10a1d
Merge pull request #9974 from Security-Onion-Solutions/saltlogging
...
use saltversion grain to determine installed version
2023-03-21 10:46:57 -04:00
Jason Ertel
efd5f7b8a2
catch errors and exit with proper exit code
2023-03-21 10:44:21 -04:00
m0duspwnens
05b1a445d3
use saltversion grain to determine installed version
2023-03-21 10:12:10 -04:00
Josh Patterson
cdb714f331
Merge pull request #9973 from Security-Onion-Solutions/2.4/zeekbpf
...
2.4/zeekbpf
2023-03-21 09:54:39 -04:00
Mike Reeves
9ca9b9d4da
Rework IDH phase 1
2023-03-21 09:53:06 -04:00
Mike Reeves
a3d38dd2e7
Rework IDH phase 1
2023-03-21 09:49:28 -04:00
Mike Reeves
41554e8311
Merge pull request #9969 from Security-Onion-Solutions/guifixes
...
Add several annotations
2023-03-21 08:51:53 -04:00
Mike Reeves
444988f287
Adjust annotations
2023-03-21 08:48:02 -04:00
m0duspwnens
02c79463e1
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/zeekbpf
2023-03-21 08:45:07 -04:00
Mike Reeves
64904406b6
Adjust annotations
2023-03-21 08:41:48 -04:00
Josh Brower
1f23e4aafe
Merge pull request #9966 from Security-Onion-Solutions/2.4/kratosfix
...
Fix Kratos parsing
2023-03-21 07:12:49 -04:00
Mike Reeves
bc7261acfe
Adjust patch annotations
2023-03-20 20:16:43 -04:00
Mike Reeves
01d470a426
Adjust patch annotations
2023-03-20 20:13:29 -04:00
Mike Reeves
f810f9cbf0
Adjust patch annotations
2023-03-20 20:12:26 -04:00
Mike Reeves
507142cde4
Adjust patch annotations
2023-03-20 20:02:23 -04:00
Jason Ertel
331d4833b1
Merge pull request #9967 from Security-Onion-Solutions/kilo
...
Kilo
2023-03-20 18:27:35 -04:00
Jason Ertel
2e6fa1eff0
Merge branch '2.4/dev' into kilo
2023-03-20 18:15:00 -04:00
m0duspwnens
0fff3a5a11
suricata bpf
2023-03-20 17:31:56 -04:00
Mike Reeves
eb61b0c98f
Adjust sensor annotations
2023-03-20 17:10:36 -04:00
m0duspwnens
252afa8499
bpf for pcap
2023-03-20 17:10:34 -04:00
Mike Reeves
a6e34ae1d7
Adjust manager annotations
2023-03-20 16:54:57 -04:00
Josh Brower
df036206a8
Fix Kratos parsing
2023-03-20 16:53:25 -04:00
Mike Reeves
27fdad4a25
Adjust manager annotations
2023-03-20 16:52:22 -04:00
Mike Reeves
0bb2fd7d45
Adjust manager annotations
2023-03-20 16:50:18 -04:00
Mike Reeves
bb3480cd76
Adjust host annotations
2023-03-20 16:20:22 -04:00
Mike Reeves
22c3a4d398
Adjust elasticsearch annotations
2023-03-20 16:08:26 -04:00
Mike Reeves
8c2a43c073
Adjust docker annotations
2023-03-20 15:51:48 -04:00
Mike Reeves
fe13f90394
Adjust docker annotations
2023-03-20 15:33:22 -04:00
m0duspwnens
903ad530fe
move zeek bpf from zeek pillar to bpf pillar
2023-03-20 15:28:33 -04:00
Mike Reeves
9a43cd71e0
Adjust docker annotations
2023-03-20 15:19:54 -04:00
Jason Ertel
c43194665e
add sudo prefix
2023-03-20 12:57:13 -04:00
Mike Reeves
a22af96403
Merge branch '2.4/dev' of https://github.com/Security-Onion-Solutions/securityonion into guifixes
2023-03-20 12:26:48 -04:00
Josh Brower
03393a95d9
Merge pull request #9963 from Security-Onion-Solutions/2.4/fixidh
...
Remove hosts file edit
2023-03-20 12:15:12 -04:00
Josh Brower
325e767587
Remove hosts file edit
2023-03-20 12:11:45 -04:00
Jason Ertel
1771a3123f
Merge pull request #9961 from Security-Onion-Solutions/kilo
...
Backup old setup logs earlier in setup
2023-03-20 11:24:08 -04:00
Mike Reeves
823dde2856
Adjust repo sync
2023-03-20 11:17:15 -04:00
Jason Ertel
6b8b7df3c2
Move old setup/error logs before any logs are written on a subsequent setup invocation
2023-03-20 11:04:28 -04:00
Jason Ertel
da1c501cf7
Move old setup/error logs before any logs are written on a subsequent setup invocation
2023-03-20 11:01:07 -04:00
Jason Ertel
604db7534c
Merge branch '2.4/dev' into kilo
2023-03-20 10:46:37 -04:00
Jason Ertel
43712182a0
update help for clarity
2023-03-20 10:46:23 -04:00
Mike Reeves
9487dbffdf
Merge pull request #9960 from Security-Onion-Solutions/guifixes
...
Add gui components for fleet
2023-03-20 09:54:50 -04:00
Mike Reeves
cdbbc8e64c
Add gui components for fleet
2023-03-20 09:46:57 -04:00
Mike Reeves
1a70a6eb30
Merge pull request #9949 from Security-Onion-Solutions/guifixes
...
Change the salt dir for elastic fleet
2023-03-20 08:59:09 -04:00
Mike Reeves
da3fa31439
Merge branch '2.4/dev' into guifixes
2023-03-20 08:57:42 -04:00
Josh Brower
542eb19cdc
Merge pull request #9954 from Security-Onion-Solutions/2.4/whiptailsummary
...
Dist vs. non-Dist Install Summary
2023-03-20 08:37:10 -04:00
Josh Brower
c89bae7319
Wording tweaks
2023-03-20 07:51:44 -04:00
Josh Brower
3073b752bd
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/whiptailsummary
2023-03-20 07:48:40 -04:00
Josh Brower
d23c09a2ee
Merge pull request #9956 from Security-Onion-Solutions/2.4/kibanaui
...
Setup Kibana default space
2023-03-20 07:39:43 -04:00
Josh Brower
b59466139a
Merge pull request #9959 from Security-Onion-Solutions/2.4/curlquiet
...
2.4/wgetquiet
2023-03-20 07:37:30 -04:00
Josh Brower
cbf7b66729
Set wget to be quiet
2023-03-20 07:29:10 -04:00
Josh Brower
5b9ff06a85
Setup Kibana default space
2023-03-19 09:17:12 -04:00
Josh Brower
792732a8cf
summary changes
2023-03-18 13:09:46 -04:00
Josh Brower
536391bb3b
rename elasticfleet state
2023-03-17 16:14:29 -04:00
Mike Reeves
caa08e9cf0
Change the salt dir for elastic fleet
2023-03-17 11:44:56 -04:00
Mike Reeves
460f84d80f
Merge pull request #9950 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update so-functions
2023-03-17 11:36:31 -04:00
Mike Reeves
d7b0ed93c9
Update so-functions
2023-03-17 11:27:29 -04:00
Mike Reeves
4944365341
Change the salt dir for elastic fleet
2023-03-17 11:02:02 -04:00
Doug Burks
8a9bc8aefa
Merge pull request #9948 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typo and improve formatting in so-whiptail
2023-03-17 10:25:48 -04:00
Doug Burks
c5b16494d7
Fix typo and improve formatting in so-whiptail
2023-03-17 10:21:21 -04:00
Josh Brower
b9c4e647c4
Merge pull request #9946 from Security-Onion-Solutions/2.4/whiptailchanges
...
Add next steps to install summary
2023-03-17 10:16:05 -04:00
Josh Brower
8f5daa785b
Add next steps to install summary
2023-03-17 10:14:44 -04:00
Josh Patterson
9893fce105
Merge pull request #9945 from Security-Onion-Solutions/2.4/strelka
...
2.4/strelka
2023-03-17 09:55:45 -04:00
m0duspwnens
91da3fd797
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/strelka
2023-03-17 08:39:10 -04:00
m0duspwnens
924d598a8a
add filecheck_runas
2023-03-17 08:38:56 -04:00
Mike Reeves
c7099280da
Merge pull request #9944 from Security-Onion-Solutions/guifixes
...
Change yum to dnf
2023-03-17 08:28:26 -04:00
Mike Reeves
bd1eb9c7df
Change yum to dnf
2023-03-16 18:05:38 -04:00
m0duspwnens
dd4461daf4
remove other filecheck map import
2023-03-16 17:50:19 -04:00
m0duspwnens
a9b8877268
remove filecheckdefaults from strelka init
2023-03-16 17:15:52 -04:00
m0duspwnens
7950f692a8
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/strelka
2023-03-16 16:41:24 -04:00
m0duspwnens
0dfbbfcf8e
fix spacing on filecheck config
2023-03-16 16:37:38 -04:00
m0duspwnens
2056ce37c6
strelka ui things
2023-03-16 16:32:41 -04:00
Mike Reeves
e88d459ef4
Merge pull request #9942 from Security-Onion-Solutions/guifixes
...
Fix Repo Issues and Change curl to check for Salt ports
2023-03-16 15:59:47 -04:00
Mike Reeves
d12367ed75
Force package update before syncing the repo
2023-03-16 15:54:00 -04:00
Mike Reeves
ef4882198a
Force package update before syncing the repo
2023-03-16 15:48:57 -04:00
Mike Reeves
2b65c1498d
Force package update before syncing the repo
2023-03-16 15:45:04 -04:00
Mike Reeves
957467eae0
Force package update before syncing the repo
2023-03-16 15:41:29 -04:00
Mike Reeves
849e82e39f
Force package updates and curl check fix
2023-03-16 15:36:43 -04:00
Mike Reeves
6e3194486c
Force package update before syncing the repo
2023-03-16 13:50:22 -04:00
Josh Brower
336cf3ccf8
Merge pull request #9940 from Security-Onion-Solutions/2.4/idh-logs
...
Add IDH log ingest
2023-03-16 13:16:17 -04:00
Josh Brower
d78128dbf4
Formatting
2023-03-16 13:11:12 -04:00
Josh Brower
a96473554d
Add IDH log ingest
2023-03-16 12:56:04 -04:00
Mike Reeves
53e93f01c6
Force an update after repo is configured
2023-03-16 09:49:57 -04:00
Mike Reeves
d0955b3e91
Merge pull request #9937 from Security-Onion-Solutions/guifixes
...
Re-Work Backups
2023-03-16 09:42:07 -04:00
Jason Ertel
ad2616900c
Merge pull request #9939 from Security-Onion-Solutions/kilo
...
automated testing support; removal of nonexistent ScanRuby strelka scanner
2023-03-16 09:30:05 -04:00
Jason Ertel
3ab3e4712c
remove kilo for merge
2023-03-16 09:16:28 -04:00
Jason Ertel
49df376bcc
Remove non-existant Ruby scanner
2023-03-15 19:24:03 -04:00
Mike Reeves
f288d0dd61
Re-Work Backups
2023-03-15 17:58:15 -04:00
Mike Reeves
3156b1ed0c
Re-Work Backups
2023-03-15 17:53:14 -04:00
Mike Reeves
c355e6eaf0
Merge pull request #9935 from Security-Onion-Solutions/guifixes
...
Fix IDS tools
2023-03-15 17:27:07 -04:00
Mike Reeves
d4f5209e39
Re-Work IDSTOOLS
2023-03-15 17:22:54 -04:00
Mike Reeves
afcd1155bf
Re-Work IDSTOOLS
2023-03-15 17:19:33 -04:00
Mike Reeves
28dc490775
Re-Work IDSTOOLS
2023-03-15 16:58:52 -04:00
Mike Reeves
02d013c0cc
Re-Work IDSTOOLS
2023-03-15 16:47:43 -04:00
Mike Reeves
b56baf900c
Re-Work IDSTOOLS
2023-03-15 16:44:53 -04:00
Jason Ertel
49a9affe2a
Merge branch '2.4/dev' into kilo
2023-03-15 16:39:26 -04:00
Mike Reeves
0d30c14561
Re-Work IDSTOOLS
2023-03-15 16:33:33 -04:00
Jason Ertel
fbefe229c1
add test support to so-minion
2023-03-15 15:27:26 -04:00
Mike Reeves
a36a6d5659
Strelka UI components
2023-03-15 10:40:16 -04:00
Josh Patterson
b809b22566
Merge pull request #9931 from Security-Onion-Solutions/2.4/strelka
...
2.4/strelka
2023-03-14 16:16:53 -04:00
m0duspwnens
f9b8c78d74
move repos to rules dir
2023-03-14 14:43:13 -04:00
m0duspwnens
7cf4e6b03b
add rules dir, change so-yar-update to save to local/salt/strelka/rules
2023-03-14 13:59:31 -04:00
m0duspwnens
5f7256c826
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/strelka
2023-03-14 13:26:15 -04:00
m0duspwnens
b38d5df684
set default mime_db
2023-03-14 13:25:51 -04:00
weslambert
4e0390963b
Merge pull request #9928 from Security-Onion-Solutions/fix/curator_elastic_agent_filebeat_actions_close
...
Fix Curator Action Files
2023-03-14 10:58:53 -04:00
weslambert
8eba3426be
Remove extra dash for 'logs-elastic_agent-metricbeat-default' key
2023-03-14 10:51:50 -04:00
weslambert
7c39938e14
Change 'elastic_agent.filebeat' to 'elastic_agent-filebeat'
2023-03-14 10:48:50 -04:00
weslambert
123275ca35
Merge pull request #9926 from Security-Onion-Solutions/fix/curator_additional_elastic_agent_indices
...
Add more Elastic Agent Curator actions
2023-03-14 09:59:47 -04:00
Wes
766e6a7974
Add 'logs-windows-sysmon_operational-delete' for Windows Sysmon operational indices
2023-03-14 13:51:49 +00:00
Wes
f0d4c16b2b
Add more Elastic Agent index keys for Curator
2023-03-14 13:49:13 +00:00
Wes
412e5c0402
Add more Elastic Agent Curator action files
2023-03-14 13:46:08 +00:00
Josh Brower
fbac23c28d
Merge pull request #9925 from Security-Onion-Solutions/2.4/fiedfix
...
Removes Suricata host.* fields
2023-03-14 07:38:05 -04:00
weslambert
ebc943fcab
Merge pull request #9924 from Security-Onion-Solutions/fix/curator_action_file_system_syslog_delete
...
Fix Elastic Agent system syslog default delete file configuration
2023-03-13 17:28:38 -04:00
weslambert
486de12ca5
Delete logs-system-auth-syslog-close.yaml
2023-03-13 17:27:52 -04:00
weslambert
f4112b30c0
Fix index reference for system auth default
2023-03-13 17:27:06 -04:00
weslambert
bab40de58d
Fix system auth default key value
2023-03-13 17:26:05 -04:00
weslambert
785f100132
Fix system auth default key value
2023-03-13 17:25:33 -04:00
weslambert
8ade7b85fc
Fix system syslog default key value
2023-03-13 17:24:40 -04:00
weslambert
c2701f1835
Fix system syslog default key value
2023-03-13 17:24:12 -04:00
weslambert
d5bb223235
Fix system syslog delete file configuration
2023-03-13 17:10:52 -04:00
weslambert
bb711a2a15
Merge pull request #9923 from Security-Onion-Solutions/fix/curator_default_elastic_agent_logs
...
Add Elastic Agent default indices to be managed by Curator
2023-03-13 16:59:40 -04:00
Wes
efc5832499
Add Elastic Agent default log action files
2023-03-13 20:54:38 +00:00
Wes
8d395dc465
Add Elastic Agent default data stream backing indices for management by Curator
2023-03-13 20:54:13 +00:00
m0duspwnens
9d4e1cc149
jinja for strelka
2023-03-13 16:48:21 -04:00
Josh Brower
f7be4ba31c
Remove host field from NIDS logs
2023-03-13 14:07:17 -04:00
Josh Brower
126add7ddd
Merge pull request #9922 from Security-Onion-Solutions/2.4/fieldfixes
...
auto-apply firewall rules
2023-03-13 12:00:28 -04:00
Josh Brower
b3a2680847
auto-apply firewall rules
2023-03-13 11:41:36 -04:00
weslambert
1774d16d9a
Merge pull request #9921 from Security-Onion-Solutions/fix/elasticsearch_template_data_stream_configuration
...
Move data stream configuration outside of ILM policy definition
2023-03-13 09:29:42 -04:00
Wes
e105e56fac
Move data stream configuration outside of ILM policy definition
2023-03-13 13:27:02 +00:00
m0duspwnens
58343e39fa
2.4 strelka
2023-03-10 17:32:14 -05:00
weslambert
a844819261
Merge pull request #9919 from Security-Onion-Solutions/fix/elasticsearch_ilm_policy_elastic_agent_default
...
Add index lifecycle management policy definitions for default Elastic Agent data streams
2023-03-10 17:02:27 -05:00
weslambert
16d9478196
Add index lifecycle management policy definitions for default Elastic Agent data streams
2023-03-10 16:54:47 -05:00
Jason Ertel
5804409fcf
Merge branch '2.4/dev' into kilo
2023-03-10 15:13:57 -05:00
Jason Ertel
5301f442f9
distributed testing
2023-03-09 19:31:04 -05:00
Jason Ertel
ed8a23cedc
distributed testing
2023-03-09 17:01:38 -05:00
Jason Ertel
0ee870a199
cleanup unnecessary code
2023-03-09 15:40:51 -05:00
Jason Ertel
23b344bf14
distributed testing
2023-03-09 15:04:42 -05:00
Josh Brower
2fe8668f1b
Merge pull request #9891 from Security-Onion-Solutions/2.4/huntqueries
...
Initial updates for 2.4 fieldnames
2023-03-09 14:37:50 -05:00
Josh Brower
73abf8dbfd
Generic host dashboard
2023-03-09 14:32:52 -05:00
Jason Ertel
894a20b3ad
autodetect manager IP
2023-03-09 12:58:51 -05:00
Jason Ertel
ecc300197d
autodetect manager IP
2023-03-09 12:11:27 -05:00
Jason Ertel
b1f201ca87
autodetect manager IP
2023-03-09 12:05:42 -05:00
Jason Ertel
a4409b2979
autodetect manager IP
2023-03-09 11:47:35 -05:00
Jason Ertel
b6ce9f489a
autodetect manager IP
2023-03-09 11:02:01 -05:00
Josh Brower
1493806040
Change host dashboard titles
2023-03-08 17:03:02 -05:00
Josh Brower
a5c89bfaa1
update sysmon dashboards
2023-03-08 16:49:34 -05:00
Jason Ertel
b9e3024521
fix user sync issue after setup finishes
2023-03-08 15:10:31 -05:00
Josh Patterson
d75866caec
Merge pull request #9912 from Security-Onion-Solutions/2.4/heavynode
...
2.4/heavynode
2023-03-08 14:11:43 -05:00
m0duspwnens
61879a8d33
merge with dev and resolve conflicts in salt/top
2023-03-08 09:04:09 -05:00
Jason Ertel
0f456e6ecd
Merge branch '2.4/dev' into kilo
2023-03-07 16:18:30 -05:00
weslambert
7ad34ee8d7
Merge pull request #9910 from Security-Onion-Solutions/fix/curator_so_curator_cluster_warm
...
Remove reference to 'so-curator-cluster-warm' script since it has been removed
2023-03-07 16:18:05 -05:00
weslambert
2d7ce41a70
Remove reference to 'so-curator-cluster-warm' script since it has been removed
2023-03-07 16:16:55 -05:00
weslambert
a738c7c36d
Merge pull request #9907 from Security-Onion-Solutions/fix/curator_global_delete_action
...
Add the new Security Onion index format to the global delete action file for Curator
2023-03-07 16:03:28 -05:00
Josh Brower
6f82cf3807
Merge pull request #9906 from Security-Onion-Solutions/2.4/setupfix
...
Remove EA install from manager highstates
2023-03-07 15:33:34 -05:00
Jason Ertel
a3e05d782e
Merge branch '2.4/dev' into kilo
2023-03-07 15:26:01 -05:00
weslambert
e93c052d34
Add the new index format to the global delete action file for Curator
2023-03-07 15:21:53 -05:00
Josh Brower
fd2312a2ac
Remove EA install from manager highstates
2023-03-07 15:13:35 -05:00
Jason Ertel
4f3cb2eb3d
Clarify playbook load time log message
2023-03-07 14:42:10 -05:00
weslambert
8c79d7e40d
Merge pull request #9905 from Security-Onion-Solutions/fix/curator_new_action_files
...
Add New Curator Action Files
2023-03-07 12:44:25 -05:00
Wes
f50639d2d2
Fix import and syslog actions
2023-03-07 17:41:48 +00:00
Wes
26c9813276
Add keys for new Curator actions to defaults.yaml
2023-03-07 17:29:07 +00:00
Wes
88d98af243
Add new Curator action files to Curator close and delete scripts
2023-03-07 17:21:03 +00:00
Wes
d636546871
Add new Curator action files
2023-03-07 17:15:25 +00:00
weslambert
f0b7a75ae8
Merge pull request #9904 from Security-Onion-Solutions/fix/curator_clean_up_action_files
...
Clean Up Old Curator Action Files
2023-03-07 11:52:28 -05:00
Wes
073054b447
Remove 'so-curator-cluster-warm' and remove unncessary Curator default values
2023-03-07 16:21:55 +00:00
Wes
df94e830c5
Remove unnecessary Curator action files
2023-03-07 16:15:41 +00:00
m0duspwnens
2767d4bee3
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-07 10:36:12 -05:00
m0duspwnens
14aa9ac5c9
apply elastic-fleet state to managers
2023-03-07 10:35:49 -05:00
weslambert
deda0fa279
Merge pull request #9902 from Security-Onion-Solutions/fix/so-status_curator
...
Add Curator to so-status Output
2023-03-07 10:17:14 -05:00
Wes
086b3bf528
Add Curator to so-status output
2023-03-07 15:14:53 +00:00
Jason Ertel
66bb829505
if -i, either success or failure must be present
2023-03-06 22:18:08 -05:00
Jason Ertel
b641dc37b6
use high error code to flag an unrecoverable error
2023-03-06 18:56:04 -05:00
Jason Ertel
f77068f73f
setup and so-verify/so-status interop
2023-03-06 18:37:37 -05:00
m0duspwnens
691080de88
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-06 16:04:14 -05:00
Jason Ertel
1998c66073
Merge branch '2.4/dev' into kilo
2023-03-06 15:59:21 -05:00
Jason Ertel
1945659369
Error is too common, found even in dashboard titles
2023-03-06 15:59:08 -05:00
Josh Brower
3eb839bd21
Merge pull request #9897 from Security-Onion-Solutions/2.4/dev-fleet
...
Fleet - setup ES output for all Managers
2023-03-06 15:54:03 -05:00
Josh Brower
a6db2d4502
Fleet - setup ES output for all Managers
2023-03-06 15:50:09 -05:00
m0duspwnens
0f9803120e
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-06 13:55:09 -05:00
m0duspwnens
b6d55bedc8
make influxdb token accessible to all nodes
2023-03-06 13:50:17 -05:00
Josh Brower
8fae826a3a
Merge pull request #9890 from Security-Onion-Solutions/2.4/fixosquerylink
...
Fixup osquery SO Hunt link
2023-03-06 07:25:00 -05:00
Doug Burks
1e31966d8d
Merge pull request #9893 from Security-Onion-Solutions/2.4/enable-zeek-vlan
...
2.4/enable zeek vlan
2023-03-06 07:20:45 -05:00
Doug Burks
a2bda07820
add VLAN dashboard
2023-03-05 15:24:11 -05:00
Doug Burks
19ab2a5a46
rename suricata vlan field to network.vlan.id
2023-03-05 05:57:52 -05:00
Josh Brower
9db6df0f14
Initial updates for 2.4 fieldnames
2023-03-04 15:19:19 -05:00
Josh Brower
f0db5cf657
Fixup osquery SO Hunt link
2023-03-04 11:50:01 -05:00
Doug Burks
4a2e75dd8c
fix formatting
2023-03-03 17:16:45 -05:00
Jason Ertel
a45763f9a2
Merge branch '2.4/dev' into kilo
2023-03-03 16:01:06 -05:00
Doug Burks
e24296d536
add SOC Dashboards groupby for Zeek conn vlan field
2023-03-03 15:23:43 -05:00
Doug Burks
9940a36722
update Elasticsearch ingest for Zeek conn vlan field
2023-03-03 15:22:43 -05:00
Doug Burks
adb925b4d6
enable zeek vlan script
2023-03-03 12:48:42 -05:00
m0duspwnens
e3f9b5297a
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-02 16:58:56 -05:00
Jason Ertel
fd2068be88
Switch back to kilo images
2023-03-02 15:23:53 -05:00
m0duspwnens
e6167dc34a
heavynode changes
2023-03-02 15:09:59 -05:00
Mike Reeves
26dbaeb7ac
Merge pull request #9882 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-functions
2023-03-02 11:36:24 -05:00
Mike Reeves
2b0ea8eb8b
Update so-functions
2023-03-02 11:34:36 -05:00
weslambert
196a6ce984
Merge pull request #9881 from Security-Onion-Solutions/fix/curator_configuration_update_8.0.x
...
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-02 08:51:14 -05:00
weslambert
06d1f0f913
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-02 08:46:52 -05:00
Mike Reeves
204f423051
Merge pull request #9878 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2023-03-01 21:37:17 -05:00
Mike Reeves
af284b9aae
Update init.sls
2023-03-01 16:38:48 -05:00
Jason Ertel
41bc1cd36f
Merge branch '2.4/dev' into kilo
2023-03-01 09:53:59 -05:00
Mike Reeves
2091806f1f
Merge pull request #9864 from Security-Onion-Solutions/setuperrors
...
Fix some errors in setup
2023-03-01 09:48:20 -05:00
m0duspwnens
704365c6eb
only stdout redirect
2023-03-01 09:44:48 -05:00
m0duspwnens
a79c380e2b
use cmd.run to populate metrics_link
2023-03-01 09:18:58 -05:00
weslambert
a5c2c0fb20
Merge pull request #9866 from Security-Onion-Solutions/fix/soc_elasticsearch_ilm_annotations_verbiage
...
Various adjustments to descriptions
2023-02-28 16:46:53 -05:00
m0duspwnens
c4e1ec781e
apply influxdb before highstate in setup
2023-02-28 16:31:35 -05:00
Jason Ertel
13182fcda2
refactor automated testing inputs due to streamlined setup process
2023-02-28 16:31:17 -05:00
weslambert
134caa7f58
Various adjustments to descriptions
2023-02-28 16:31:16 -05:00
m0duspwnens
8772dcaa10
ensure influxdb is running
2023-02-28 15:57:54 -05:00
Jason Ertel
205e344034
dynamically choose test NICs in alphanumeric sort order
2023-02-28 15:40:08 -05:00
Jason Ertel
749c299ed2
refactor automated testing inputs due to streamlined setup process
2023-02-28 15:34:09 -05:00
Josh Brower
96467f0bd8
Merge pull request #9865 from Security-Onion-Solutions/2.4/fleet-esoutput
...
Move Output to ES
2023-02-28 15:20:46 -05:00
m0duspwnens
052e0dea2e
create and manage metrics_link in a file for soc
2023-02-28 14:47:44 -05:00
Jason Ertel
d456f681f1
refactor automated testing inputs due to streamlined setup process
2023-02-28 14:45:21 -05:00
Jason Ertel
8f20e2bcb9
refactor automated testing inputs due to streamlined setup process
2023-02-28 14:29:22 -05:00
Jason Ertel
9c3cc17153
refactor automated testing inputs due to streamlined setup process
2023-02-28 13:44:38 -05:00
Jason Ertel
d5df1a106a
refactor automated testing inputs due to streamlined setup process
2023-02-28 13:43:52 -05:00
Mike Reeves
ff495cb20e
fix formatting issue
2023-02-28 10:41:44 -05:00
Mike Reeves
34f5dbeba0
Merge branch 'setuperrors' of https://github.com/Security-Onion-Solutions/securityonion into setuperrors
2023-02-28 09:41:10 -05:00
Mike Reeves
c00d671098
backup influx dir
2023-02-28 09:40:57 -05:00
Josh Patterson
cbcd3c9dd9
Update defaults.map.jinja
2023-02-27 15:39:03 -05:00
Josh Patterson
8632606a24
Update defaults.map.jinja
2023-02-27 15:37:35 -05:00
Mike Reeves
1692970789
back out verify changes since underlying errors should be fixed
2023-02-27 15:22:08 -05:00
Josh Patterson
8d33f01936
Update defaults.map.jinja
2023-02-27 15:01:31 -05:00
Mike Reeves
aa7b05d639
small cleanup
2023-02-27 14:12:26 -05:00
Mike Reeves
9967e91825
remove mysql check
2023-02-27 13:42:11 -05:00
Josh Patterson
fb5aad34e0
Merge pull request #9861 from Security-Onion-Solutions/somefixes2
...
Somefixes2
2023-02-27 13:14:08 -05:00
m0duspwnens
44ed48033c
move requirement
2023-02-27 13:04:23 -05:00
m0duspwnens
068d383442
change to service.running
2023-02-27 12:44:46 -05:00
m0duspwnens
b4015ac73e
add sensor to node_containers
2023-02-27 10:05:08 -05:00
Josh Brower
f7176f9989
Move Output to ES
2023-02-27 09:58:43 -05:00
Josh Patterson
dd8f6a460b
Merge pull request #9853 from Security-Onion-Solutions/somefixes2
...
custom hostgroups in soc ui
2023-02-24 16:25:48 -05:00
m0duspwnens
d12ea041bf
capitalize
2023-02-24 16:20:16 -05:00
m0duspwnens
6b486d9604
move to default
2023-02-24 15:55:27 -05:00
m0duspwnens
fa5b9799f5
add firewall.soc to top for managers
2023-02-24 15:26:39 -05:00
m0duspwnens
d502d95dba
changes for soc firewall
2023-02-24 15:24:02 -05:00
m0duspwnens
29c68c1273
fix bracket, add output to template
2023-02-24 14:32:35 -05:00
m0duspwnens
3e2e68fbd0
custom hostgroups in soc
2023-02-24 14:24:47 -05:00
Jason Ertel
aed41404fc
Merge pull request #9852 from Security-Onion-Solutions/kilo
...
Remove FleetDM tool from SOC instead of deactivating it; generate SRV key during setup
2023-02-24 13:05:58 -05:00
Mike Reeves
2b683b09e1
Merge pull request #9851 from Security-Onion-Solutions/somefixes2
...
Fix install
2023-02-24 12:24:43 -05:00
Mike Reeves
afccd3f820
comment out minion installs for now
2023-02-24 12:21:14 -05:00
Mike Reeves
a25acb4558
comment out minion installs for now
2023-02-24 12:19:57 -05:00
Mike Reeves
a0eb505db0
Add fireall custom groups
2023-02-24 11:12:17 -05:00
Mike Reeves
99105c7563
Add fireall custom groups
2023-02-24 10:43:41 -05:00
Jason Ertel
316db85584
Generate SOC SRVKey during setup
2023-02-24 10:20:23 -05:00
Jason Ertel
d3c5d0569a
Remove FleetDM tool instead of deactivating it
2023-02-24 10:20:02 -05:00
Mike Reeves
57a02396de
Merge pull request #9849 from Security-Onion-Solutions/somefixes2
...
Playbook fix
2023-02-24 10:08:58 -05:00
Mike Reeves
29cf95d6eb
remove yum versionlock
2023-02-24 10:06:43 -05:00
Mike Reeves
39361c2ab0
unfix playbook fix
2023-02-24 10:01:27 -05:00
Mike Reeves
1289500e03
unfix playbook fix
2023-02-24 09:55:49 -05:00
Mike Reeves
663af7935b
Merge pull request #9847 from Security-Onion-Solutions/somefixes
2023-02-23 20:05:51 -05:00
Mike Reeves
cd56d3a799
unfix playbook fix
2023-02-23 16:18:22 -05:00
Mike Reeves
bf512d56ec
unfix playbook fix
2023-02-23 16:12:57 -05:00
Mike Reeves
b206b23fe1
unfix playbook fix
2023-02-23 16:09:54 -05:00
Mike Reeves
6141906b76
Merge pull request #9840 from Security-Onion-Solutions/reposync
...
Rocky 9 support
2023-02-23 12:30:38 -05:00
m0duspwnens
8f46e4aa30
set docker extra_hosts for soc
2023-02-23 12:26:58 -05:00
Jason Ertel
4222b09970
Merge branch '2.4/dev' into reposync
2023-02-23 12:15:03 -05:00
Jason Ertel
b62a0c5d5c
Merge pull request #9846 from Security-Onion-Solutions/kilo
...
Kilo
2023-02-23 12:12:06 -05:00
Jason Ertel
7067f9cd9c
allow the rpm gpg key filename
2023-02-23 12:09:55 -05:00
Jason Ertel
265447801e
allow the rpm gpg key filename
2023-02-23 12:08:43 -05:00
Jason Ertel
52f0ccf00d
Merge branch '2.4/dev' into kilo
2023-02-23 12:03:34 -05:00
Mike Reeves
2ebd9b3598
use hostnames please
2023-02-23 11:19:13 -05:00
Mike Reeves
4896452245
use hostnames please
2023-02-23 11:13:54 -05:00
Mike Reeves
9441d47c6a
Merge branch 'reposync' of https://github.com/Security-Onion-Solutions/securityonion into reposync
2023-02-23 11:11:38 -05:00
Mike Reeves
148b0b1c4c
use hostnames please
2023-02-23 11:11:29 -05:00
m0duspwnens
399e4de73c
stop and disable firewalld
2023-02-23 11:04:23 -05:00
m0duspwnens
96b1fb4782
change to eval
2023-02-23 10:51:14 -05:00
Mike Reeves
7f2d263046
fix nginx config
2023-02-23 10:16:34 -05:00
Mike Reeves
3fed04a532
fix nginx config
2023-02-23 09:52:24 -05:00
Mike Reeves
95f254dc63
Change elastalert ip
2023-02-23 09:37:20 -05:00
Mike Reeves
dc2fed5b04
Change elastalert ip
2023-02-23 09:34:16 -05:00
Mike Reeves
6927e28def
Change kibana IP
2023-02-23 09:25:16 -05:00
m0duspwnens
4db404b6f5
remove jinja from kibana defaults
2023-02-23 09:21:19 -05:00
Mike Reeves
7b30064d86
Chane Elastalert to use hosntame
2023-02-23 09:10:20 -05:00
Mike Reeves
0ec0983d7b
Chane Elastalert to use hosntame
2023-02-23 08:57:30 -05:00
weslambert
ee311de9c8
Merge pull request #9841 from Security-Onion-Solutions/fix/soc_analyzers_analyzerNodeId
...
Change 'GLOBALS.minion_id' to 'GLOBALS.hostname' for 'analyzerNodeId' value to ensure SOC creates analyzer jobs in the correct directory
2023-02-22 16:26:03 -05:00
Mike Reeves
7987cde668
Merge branch 'reposync' of https://github.com/Security-Onion-Solutions/securityonion into reposync
2023-02-22 16:25:04 -05:00
Mike Reeves
8e83407974
change playbook to use hostname
2023-02-22 16:24:35 -05:00
weslambert
ecf70847fd
Change 'GLOBALS.minion_id' to 'GLOBALS.hostname' for 'analyzerNodeId' value to ensure SOC creates analyzer jobs in the correct directory
2023-02-22 16:23:48 -05:00
m0duspwnens
0d0a61bd4a
remove so-grafana from node containers
2023-02-22 15:29:30 -05:00
Mike Reeves
5bc1dc9567
change playbook to use hostname
2023-02-22 15:19:27 -05:00
Mike Reeves
45434b06a4
change playbook to use hostname
2023-02-22 15:08:56 -05:00
Mike Reeves
6e59cc3409
change playbook to use hostname
2023-02-22 14:56:53 -05:00
Mike Reeves
417fff924d
change playbook to use hostname
2023-02-22 14:53:02 -05:00
Mike Reeves
1c1e613351
change playbook to use hostname
2023-02-22 14:48:55 -05:00
m0duspwnens
bf8e6c64d6
add sobip to global vars
2023-02-22 14:41:14 -05:00
Mike Reeves
68708accde
change playbook to use hostname
2023-02-22 14:32:49 -05:00
Mike Reeves
59c700ad10
change playbook to use hostname
2023-02-22 14:15:10 -05:00
Mike Reeves
c6a46d1eb3
change playbook to use hostname
2023-02-22 14:14:27 -05:00
Mike Reeves
c20a7e6cf9
fix yaml
2023-02-22 13:48:40 -05:00
Mike Reeves
3deb619737
add watchdog
2023-02-22 12:58:39 -05:00
Mike Reeves
7c64dad95b
add mysql
2023-02-22 11:28:46 -05:00
m0duspwnens
6dd09fb2c5
remove filebeat
2023-02-22 10:42:45 -05:00
m0duspwnens
b8966aa33a
fix role match
2023-02-22 10:24:51 -05:00
Mike Reeves
76011c96d6
fix conflict
2023-02-22 10:20:14 -05:00
Mike Reeves
c3784fe548
remove grafana
2023-02-22 10:09:52 -05:00
m0duspwnens
db3a46b6a1
fix indent
2023-02-22 10:07:04 -05:00
m0duspwnens
d0bb7dc475
repo for rocky
2023-02-22 10:04:43 -05:00
m0duspwnens
53b58d532a
apply docker state during setup
2023-02-22 09:35:37 -05:00
Mike Reeves
327855b0af
add docker
2023-02-22 09:28:51 -05:00
m0duspwnens
56ccf5c504
remove podman
2023-02-22 09:13:16 -05:00
Mike Reeves
7b6db5d95a
add docker
2023-02-22 09:08:39 -05:00
Mike Reeves
8645cd0c3b
add docker
2023-02-22 08:57:00 -05:00
m0duspwnens
cc654fda9f
fw 2.4 update
2023-02-21 15:43:41 -05:00
m0duspwnens
f2b0d67d8b
update fw rules
2023-02-21 15:20:49 -05:00
m0duspwnens
de499ead0c
update fw rules
2023-02-21 15:11:14 -05:00
m0duspwnens
a3bda9b322
podman changes to disable mgmt of iptables
2023-02-21 13:48:25 -05:00
Josh Brower
3a2ec8e8bf
Merge pull request #9830 from Security-Onion-Solutions/2.4/IDHMerge
...
Initial support for IDH
2023-02-21 12:19:53 -05:00
Josh Brower
b62cc32b1a
Initial support for IDH
2023-02-21 11:52:37 -05:00
Mike Reeves
bc054a15d3
add createrepo
2023-02-21 10:15:47 -05:00
Mike Reeves
c4a5470454
fix reposync
2023-02-21 10:06:01 -05:00
Mike Reeves
b402b84d11
fix reposync
2023-02-21 10:04:56 -05:00
Mike Reeves
f34e144629
removes filebeat
2023-02-21 10:01:27 -05:00
Mike Reeves
6cfa16c251
fix reposync script
2023-02-21 10:00:09 -05:00
Mike Reeves
173b15b46e
Add python3-rich for sostatus
2023-02-21 09:58:07 -05:00
m0duspwnens
653062b7c9
run podman state early
2023-02-21 09:46:52 -05:00
Jason Ertel
2b6685c887
restore kilo version
2023-02-21 09:27:02 -05:00
Jason Ertel
f00c7169ce
update test scenarios
2023-02-21 09:24:55 -05:00
m0duspwnens
5fff06602a
change symlink
2023-02-17 15:41:49 -05:00
Mike Reeves
4bafb40894
fix registry from restart
2023-02-17 15:38:54 -05:00
m0duspwnens
03cd67431d
start and enable podman services
2023-02-17 15:36:45 -05:00
m0duspwnens
160ed46d96
podman and remove filebeat
2023-02-17 14:59:39 -05:00
Mike Reeves
6fd68351ec
fix more python depends
2023-02-17 14:30:55 -05:00
m0duspwnens
49549c3d61
remove unneedfuls from podman state
2023-02-17 14:24:55 -05:00
m0duspwnens
9d4e4830dd
add podman state
2023-02-17 14:19:57 -05:00
Mike Reeves
b53aa08eeb
remove grafana and filebeat
2023-02-17 13:58:45 -05:00
Mike Reeves
c6266e9f91
add m2crypto
2023-02-17 13:54:46 -05:00
Mike Reeves
c6cbb4857d
add rsync
2023-02-17 13:53:36 -05:00
Mike Reeves
bcf1fe8dad
fix reposync script
2023-02-17 13:48:10 -05:00
Mike Reeves
12398bdf24
add m2crypto
2023-02-17 13:34:21 -05:00
Josh Patterson
ba5b125952
Update minion.defaults.yaml
2023-02-17 13:25:01 -05:00
Mike Reeves
e3e8d30161
fix python docker name
2023-02-17 13:17:57 -05:00
Mike Reeves
4bb49ad617
add some deps
2023-02-17 13:11:13 -05:00
Mike Reeves
e7f35673e0
replace centos
2023-02-17 11:38:50 -05:00
Mike Reeves
ba9c52db37
replace centos
2023-02-17 11:37:28 -05:00
Mike Reeves
43c177727c
replace centos
2023-02-17 11:32:05 -05:00
Mike Reeves
c6919a09da
replace centos
2023-02-17 11:26:11 -05:00
m0duspwnens
d8e85cbc28
change salt version
2023-02-17 11:20:16 -05:00
Mike Reeves
0a7ad4d211
yum-utils
2023-02-17 11:16:02 -05:00
Mike Reeves
54fc07b5b8
yum-utils
2023-02-17 11:07:44 -05:00
m0duspwnens
8b680693f4
remove patch pkg and patching of influx
2023-02-17 11:01:17 -05:00
Mike Reeves
353b77cd59
add minions.d dir
2023-02-17 10:40:43 -05:00
Doug Burks
eef81fdd1b
Merge pull request #9805 from Security-Onion-Solutions/2.4/upgrade-elastic-8.6.2
...
2.4/upgrade elastic 8.6.2
2023-02-17 08:03:09 -05:00
Doug Burks
ef3abe158c
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:07:20 -05:00
Doug Burks
dfa5503e41
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:06:36 -05:00
Mike Reeves
405060674c
Salt 3006 temp
2023-02-16 17:49:07 -05:00
Jason Ertel
1f37af0e57
Merge pull request #9800 from Security-Onion-Solutions/kilo
...
influx upgrade
2023-02-16 13:51:53 -05:00
Jason Ertel
59b1af15db
correct top order for import
2023-02-16 13:49:19 -05:00
Jason Ertel
79041d091e
influx upgrade
2023-02-16 13:22:13 -05:00
Jason Ertel
e4de89c960
Merge pull request #9798 from Security-Onion-Solutions/jertel-remove-kilo-from-ver
...
Update VERSION
2023-02-16 10:57:19 -05:00
Jason Ertel
dcbf5a2fa6
Update VERSION
2023-02-16 10:55:32 -05:00
Jason Ertel
6e9d1f7c2c
Merge pull request #9797 from Security-Onion-Solutions/kilo
...
Influx upgrade
2023-02-16 10:46:57 -05:00
weslambert
5e94a2cd74
Merge pull request #9790 from Security-Onion-Solutions/fix/kibana_default_data_view
...
Change default data view from '*:so-*' to 'logs-*'
2023-02-15 14:21:55 -05:00
weslambert
b7ad4e0570
Change default data view from 'so-*' to 'logs-*'
2023-02-15 14:19:29 -05:00
weslambert
967440f49f
Merge pull request #9789 from Security-Onion-Solutions/fix/kibana_visualization_index-pattern_reference
...
Replace 'so-*' index-pattern reference with 'logs-*' for Kibana dashboard visualizations
2023-02-15 11:33:44 -05:00
Wes
790b3c5635
Replace 'so-*' index-pattern reference with 'logs-*' for Kibana dashboard visualizations
2023-02-15 16:30:56 +00:00
Mike Reeves
01edb5dc00
Update repo URL
2023-02-15 11:09:37 -05:00
Jason Ertel
c43ccb7ed2
influx upgrade
2023-02-15 09:47:18 -05:00
Jason Ertel
a9b3594b35
merge
2023-02-15 08:06:41 -05:00
Jason Ertel
8746f55834
influx upgrade
2023-02-15 08:03:22 -05:00
Mike Reeves
577e3c27fe
Update repo URL
2023-02-14 13:52:21 -05:00
Mike Reeves
2cddcc8b8d
Change some order in repo sync
2023-02-14 13:38:28 -05:00
Mike Reeves
4c2142b181
add key for so packages
2023-02-14 13:21:37 -05:00
Mike Reeves
4dcdea58d7
add key for so packages
2023-02-14 13:16:13 -05:00
Mike Reeves
0f51e7bb98
fix key locations for rocky
2023-02-14 13:14:21 -05:00
Jason Ertel
1fa526cd0e
influx upgrade
2023-02-14 11:22:54 -05:00
Mike Reeves
4741038a41
fix function
2023-02-14 10:15:35 -05:00
Mike Reeves
89bd9163fb
reposync attempt for reocky
2023-02-14 10:08:34 -05:00
Mike Reeves
b2d85b843f
reposync
2023-02-14 09:00:10 -05:00
Jason Ertel
d15158e77a
influx upgrade
2023-02-13 20:52:12 -05:00
Jason Ertel
0890129c69
influx upgrade
2023-02-13 19:30:10 -05:00
Jason Ertel
e3ca0345a8
upgrade influx
2023-02-13 15:41:37 -05:00
Jason Ertel
1fa8294ee6
influx upgrade
2023-02-13 14:56:51 -05:00
weslambert
689ba5f341
Merge pull request #9778 from Security-Onion-Solutions/fix/filebeat_remove_docker_image
...
Remove 'so-filebeat' from list of trusted containers
2023-02-13 10:00:36 -05:00
weslambert
40d3269db3
Remove 'so-filebeat' from list of trusted containers
2023-02-13 09:58:39 -05:00
Jason Ertel
7b3acd53a1
upgrade influx
2023-02-13 09:55:45 -05:00
Jason Ertel
47af14c265
upgrade influx
2023-02-13 09:51:48 -05:00
Jason Ertel
34d19e308f
influx upgrade
2023-02-10 19:42:25 -05:00
Jason Ertel
e5c26032c4
influx upgrade
2023-02-10 19:37:59 -05:00
Jason Ertel
4f0af9ac6b
influx upgrade
2023-02-10 18:41:29 -05:00
Jason Ertel
0056b8f703
influx upgrade
2023-02-10 18:35:18 -05:00
Jason Ertel
39009ce938
influx upgrade
2023-02-10 18:32:01 -05:00
Jason Ertel
7dee2686ac
influx upgrade
2023-02-10 18:19:31 -05:00
Jason Ertel
cd27ae89cc
influx upgrade
2023-02-10 16:34:06 -05:00
weslambert
21ca8a9c50
Merge pull request #9770 from Security-Onion-Solutions/fix/elasticsearch_ilm_soc_annotations_settings
...
Add SOC annotation settings for Elasticsearch's ILM feature
2023-02-10 15:51:29 -05:00
weslambert
acda03ce40
Add annotation settings for Elasticsearch's ILM feature, and remove various index keys
2023-02-10 14:57:11 -05:00
weslambert
f2f318982e
Merge pull request #9768 from Security-Onion-Solutions/fix/elasticsearch_ilm_policy_load_additions
...
Manage Elasticsearch index lifecycle management policies in Elasticsearch state
2023-02-10 14:16:32 -05:00
Wes
1255c60317
Move policy load script into Elasticsearch state script directory
2023-02-10 18:59:45 +00:00
Wes
994eabae1b
Manage policy loading in Elasticsearch state
2023-02-10 18:57:19 +00:00
weslambert
82119b0247
Merge pull request #9765 from Security-Onion-Solutions/fix/elastic_utility_scripts_permissions
...
Ensure Elastic utility scripts have the correct permissions
2023-02-10 10:30:14 -05:00
Wes
1d0e09bdf7
Ensure Elastic utility scripts have the correct permissions
2023-02-10 15:26:46 +00:00
weslambert
7564a82b52
Merge pull request #9764 from Security-Onion-Solutions/fix/elasticsearch_ilm_dynamic_policy_loadiing
...
ILM Policy Changes
2023-02-10 10:17:14 -05:00
Wes
c9118699a9
Add index management lifecycle policy defintion and reference in index template
2023-02-10 15:10:30 +00:00
Wes
d17cf89c68
Fix Bash shebang
2023-02-10 15:01:09 +00:00
Wes
7b7461ef01
Dynamically load index management lifecycle policies based on pillar values
2023-02-10 14:59:29 +00:00
Jason Ertel
e77813a173
influx upgrade
2023-02-09 19:14:58 -05:00
Jason Ertel
0eec8b22a2
influx upgrade
2023-02-09 18:27:14 -05:00
Jason Ertel
0e50d36da6
upgrade influx
2023-02-09 16:18:04 -05:00
Jason Ertel
067b6bacd1
merge from 2.4/dev
2023-02-09 11:57:51 -05:00
weslambert
84c5d2fee9
Merge pull request #9753 from Security-Onion-Solutions/fix/elasticsearch_ilm_policy_load_additional_policies
...
Add index lifecycle policy templates for other logs
2023-02-09 10:59:24 -05:00
Wes
ee7f299e6d
Fix typo - 'Kratos' to 'Kibana'
2023-02-09 15:56:36 +00:00
Wes
bb6fc8da19
Add policy templates for other logs
2023-02-09 15:51:58 +00:00
weslambert
364799dcc5
Merge pull request #9751 from Security-Onion-Solutions/fix/elastic_fleet_output_temp_change
...
Temporarily use Elasticsearch output for standalone installations
2023-02-09 09:37:14 -05:00
weslambert
b744dc0641
Add so-eval to list of modes using the Elasticsearch output for Elastic Agent and Fleet
2023-02-09 09:35:29 -05:00
weslambert
613793ad9b
Temporarily use Elasticsearch output for Standalone installations
2023-02-09 09:32:04 -05:00
Jason Ertel
28eee48a7c
influx upgrade
2023-02-08 20:38:29 -05:00
Jason Ertel
849e53e1eb
upgrade influx
2023-02-08 17:40:27 -05:00
Josh Patterson
131d9b5898
Merge pull request #9747 from Security-Onion-Solutions/2.4/firewall
...
ensure node_data is populated with self
2023-02-08 17:29:07 -05:00
m0duspwnens
8a00521092
ensure node_data is populated with self if logstash:nodes data doesnt exist, ie import node
2023-02-08 17:19:20 -05:00
weslambert
32823ef640
Merge pull request #9746 from Security-Onion-Solutions/feature/elasticsearch_ilm_utility_scripts
...
Add Elasticsearch ILM utility scripts
2023-02-08 16:43:44 -05:00
Wes
b319b50fa1
Add initial ILM status script
2023-02-08 21:39:33 +00:00
Wes
1d6c03feb1
Rename initial ILM lifecycle status explanation script
2023-02-08 21:34:39 +00:00
Wes
91d24d36f9
Add initial ILM lifecycle status explanation script
2023-02-08 21:34:15 +00:00
Wes
3e31bda285
Fix typo in Elasticsearch portion of script names
2023-02-08 21:32:17 +00:00
Wes
1de3871ee9
Add initial ILM service restart script
2023-02-08 21:30:25 +00:00
Wes
03849b0659
Add initial ILM service start script
2023-02-08 21:29:38 +00:00
Wes
b38f4ca766
Add initial ILM service stop script
2023-02-08 21:29:16 +00:00
Wes
8027055086
Add initial ILM policy delete script
2023-02-08 21:09:42 +00:00
Jason Ertel
8ff0cf21cd
influx upgrade
2023-02-08 16:03:10 -05:00
Wes
d6d01f8542
Add initial ILM policy view script
2023-02-08 21:01:02 +00:00
Jason Ertel
c43e69ad93
influx upgrade
2023-02-08 15:57:14 -05:00
Jason Ertel
abbc92a58d
upgrade influx
2023-02-08 15:14:46 -05:00
Wes
713e9ee215
Create initial template for ILM policy load script
2023-02-08 20:10:41 +00:00
Jason Ertel
22eaeb1462
upgrade influx
2023-02-08 15:00:44 -05:00
Jason Ertel
2fddcc1e99
upgrade influx
2023-02-08 14:57:57 -05:00
Jason Ertel
67c8f6ba69
avoid cr/lr
2023-02-08 14:25:36 -05:00
Jason Ertel
44e60f1e57
upgrade influx
2023-02-08 14:03:27 -05:00
Jason Ertel
51674b3a5b
upgrade influx
2023-02-08 13:50:32 -05:00
Jason Ertel
4c42671a21
Merge branch '2.4/dev' into kilo
2023-02-08 13:49:07 -05:00
Jason Ertel
a1ac1785d3
upgrade influx
2023-02-08 13:40:27 -05:00
Josh Patterson
3b9bdecab8
Merge pull request #9745 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-02-08 13:26:40 -05:00
Jason Ertel
ea0c3db8e1
upgrade influxdb
2023-02-08 13:23:45 -05:00
m0duspwnens
3d34a49e44
change to new local ports file
2023-02-08 13:21:48 -05:00
m0duspwnens
19f49dde75
recusivly copy the firewall files for setup
2023-02-08 13:14:08 -05:00
Josh Patterson
d6fb0598df
Merge pull request #9743 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-02-08 11:37:05 -05:00
m0duspwnens
31daeef30d
2.4 fw changes
2023-02-08 11:01:26 -05:00
m0duspwnens
342b9619b0
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-08 09:18:21 -05:00
m0duspwnens
fb7ebcac7e
2.4 fw changes
2023-02-08 09:18:05 -05:00
Doug Burks
291bdc0d82
Merge pull request #9726 from Security-Onion-Solutions/2.4/change-radio-to-menu
...
FIX: Minimize keystrokes and errors in Setup by changing radio lists to menus where appropriate #9725
2023-02-06 12:11:21 -05:00
Doug Burks
cd38ecb300
change whiptail selections from radiolist to menu where appropriate
2023-02-06 11:52:42 -05:00
Josh Patterson
22a18d8855
Merge pull request #9717 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-02-03 11:04:36 -05:00
m0duspwnens
e8a1e164aa
add so.version module
2023-02-03 10:58:08 -05:00
m0duspwnens
e0e094cd95
rename sosbip and sosrange to sobip and sorange
2023-02-03 10:10:51 -05:00
m0duspwnens
a37f0fd0c0
rename sosbridge to sobridge
2023-02-03 10:07:07 -05:00
m0duspwnens
6e45f1b6e1
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-03 09:55:50 -05:00
m0duspwnens
df9ef9ffc7
add managersearch
2023-02-03 09:55:33 -05:00
weslambert
bee5a1e9e8
Merge pull request #9711 from Security-Onion-Solutions/fix/so_import_pcap_suricata_metadata_disable_zeek
...
Only run Zeek if it is defined as the metadata engine
2023-02-02 13:27:35 -05:00
m0duspwnens
3e808a70fa
allow managersearch. comment out localhost allow in setup
2023-02-02 12:11:03 -05:00
Wes
bc082dff99
Only run Zeek if it is defined as 'mdengine'
2023-02-02 16:22:42 +00:00
m0duspwnens
33787d345b
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-02 10:04:01 -05:00
m0duspwnens
9eae31e488
add managersearch to allowed roles for so-firewall. fix setup error from so-firewall "Please specify a role with --role="
2023-02-02 10:03:22 -05:00
weslambert
395cbf330a
Merge pull request #9706 from Security-Onion-Solutions/fix/suricata_metadata
...
Add Suricata metadata configuration
2023-02-02 09:54:49 -05:00
Wes
5fba3c5872
Add Suricata metadata configuration
2023-02-02 14:48:01 +00:00
m0duspwnens
3ba64f7545
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-02 09:31:40 -05:00
weslambert
eb7b6e78b9
Merge pull request #9702 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_disable
...
Disable loading of Kibana and Logstash integration policies
2023-02-01 16:02:56 -05:00
weslambert
d242050627
Disable loading of Kibana and Logstash logs for now since there are issues with the packages from the registry
2023-02-01 15:59:35 -05:00
Josh Brower
e4b10aa28c
Remove endif
2023-02-01 15:47:26 -05:00
Josh Brower
1c1b079058
Change default output
2023-02-01 15:42:05 -05:00
weslambert
3dfa7959b3
Merge pull request #9698 from Security-Onion-Solutions/fix/strelka_yara_exclusion_2_4
...
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:38:38 -05:00
weslambert
2101ca60e9
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:25:46 -05:00
m0duspwnens
33668105a5
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-01 11:32:02 -05:00
m0duspwnens
d2dd68eb44
add global vars for managersearch
2023-02-01 11:31:36 -05:00
Josh Brower
967a0807ad
Fix typo
2023-02-01 09:16:34 -05:00
Josh Patterson
77749adc8f
Merge pull request #9691 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-31 17:11:57 -05:00
m0duspwnens
6ec086e24a
add influxdb as extra_hosts for grafana container
2023-01-31 17:10:11 -05:00
Josh Brower
b8d8a5fd6b
Remove default outputs
2023-01-31 17:02:41 -05:00
m0duspwnens
6f1438148f
allow elastic agent access
2023-01-31 16:54:46 -05:00
m0duspwnens
12bede5e77
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-31 16:10:50 -05:00
Josh Brower
18a54b86f4
More fixes
2023-01-31 14:57:39 -05:00
weslambert
056bcd0121
Merge pull request #9683 from Security-Onion-Solutions/fix/kibana_osquery_live_query_link_remove
...
Remove OSQuery live query link
2023-01-31 13:38:07 -05:00
m0duspwnens
8cbafb52d8
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-31 13:32:51 -05:00
m0duspwnens
16e1e297a0
allow elasticsearch_rest
2023-01-31 13:32:33 -05:00
weslambert
98bea0322e
Merge pull request #9688 from Security-Onion-Solutions/fix/elastic_agent_elasticsearch_output_typo_fix
...
Fix Elastic Agent Elasticsearch output typo
2023-01-31 12:57:38 -05:00
weslambert
74eed31eec
Change Elasticsearch output name from 'so-manager_elasticsearch2' to 'so-manager_elasticsearch'
2023-01-31 12:55:03 -05:00
m0duspwnens
aa411e2682
allow influxdb on manager and managersearch
2023-01-31 12:42:46 -05:00
weslambert
cbf2bd1373
Remove OSQuery live query link
2023-01-31 10:59:17 -05:00
m0duspwnens
0ba193c7a4
allow docker_registry fw
2023-01-31 10:55:14 -05:00
m0duspwnens
e09a86dc30
2.4 searchnode es config
2023-01-31 10:54:40 -05:00
m0duspwnens
8dc7a9da9e
add searchnode global vars
2023-01-31 10:52:35 -05:00
Doug Burks
acffc5ee07
Merge pull request #9682 from Security-Onion-Solutions/fix/suricata-dhcp-parsing-2.4
...
2.4: Improve Suricata DHCP parsing and dashboard
2023-01-31 10:18:41 -05:00
Doug Burks
a44d83d69b
Improve Suricata DHCP parsing and dashboard
2023-01-31 08:33:38 -05:00
weslambert
bde828cd4f
Merge pull request #9676 from Security-Onion-Solutions/fix/so-import-evtx_updates
...
Updates to so-import-evtx
2023-01-31 08:17:02 -05:00
weslambert
0436f885b8
Set values for '@timestamp' and 'event.ingested'
2023-01-31 08:04:49 -05:00
Wes
5472f53c9f
Remove bind mount and reference the correctly named entrypoint script
2023-01-30 21:24:30 +00:00
Wes
0156784687
Add EVTX integration policy for 'so-import-evtx'
2023-01-30 21:22:37 +00:00
Wes
cc100e50cd
Update so-import-evtx to convert EVTX to a JSON file instead of streaming to Elasticsearch
2023-01-30 21:09:58 +00:00
weslambert
b1eb16d3a2
Merge pull request #9670 from Security-Onion-Solutions/fix/elastic_agent_integration_policies_zeek_exclude_files
...
Remove 'prospector.scanner' prefix from 'exclude_files' configuration
2023-01-27 16:53:02 -05:00
weslambert
8240e5b20d
Remove 'prospector.scanner' prefix from 'exclude_files' configuration
2023-01-27 16:46:43 -05:00
Doug Burks
a13baf7bb8
Merge pull request #9669 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typos in so-elastic-fleet-integration-policy-load
2023-01-27 15:52:47 -05:00
Doug Burks
b160d0add5
Fix typos in so-elastic-fleet-integration-policy-load
2023-01-27 15:45:58 -05:00
Doug Burks
209f732176
Merge pull request #9668 from Security-Onion-Solutions/fix/elastic_agent_integration_policies_zeek
...
Fix syntax for Zeek Elastic Agent integration policies
2023-01-27 15:30:50 -05:00
weslambert
68fac4488e
Fix syntax for Zeek integration policies
2023-01-27 15:27:15 -05:00
weslambert
fa9e62a816
Merge pull request #9665 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_import_suricata_event.category
...
Change event.category from 'file' to 'network' in Import Suricata integration policy
2023-01-27 12:03:34 -05:00
weslambert
e47f64bd04
Change event.category from 'file' to 'network'
2023-01-27 12:00:30 -05:00
weslambert
6d2f379ba5
Merge pull request #9664 from Security-Onion-Solutions/fix/elastic_agent_integration_policies_zeek_exclude_files
...
Update Zeek file exclusions and add a minor output formatting change
2023-01-27 11:58:19 -05:00
weslambert
f49627cec1
Update Zeek file exclusions and add a minor output formatting change
2023-01-27 11:47:14 -05:00
weslambert
5ab3d1e8f1
Merge pull request #9663 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_zeek_import_ics_tag
...
Change 'pipeline' to 'import.file' so that ICS tag conditional is applied to the correct field
2023-01-27 11:34:28 -05:00
weslambert
6b251a2596
Change 'pipeline' to 'import.file' so that ICS tag conditional is applied to the correct field
2023-01-27 11:30:06 -05:00
Josh Brower
17af095e14
Fix firewall
2023-01-27 11:28:54 -05:00
weslambert
5468aa82b0
Merge pull request #9662 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_event.dataset_rename
...
Change event.dataset value for zeek.files and zeek.tunnels ingest pipelines
2023-01-27 11:19:45 -05:00
weslambert
2772b03dca
Change event.dataset value from 'tunnels' to 'tunnel'
2023-01-27 11:03:49 -05:00
weslambert
716ec7f936
Change event.dataset value from 'files' to 'file'
2023-01-27 11:02:44 -05:00
Josh Brower
a71cbcfc9b
Pull in upstream changes
2023-01-27 07:53:53 -05:00
Josh Brower
29aa6dceed
Add logstash
2023-01-27 07:49:21 -05:00
Doug Burks
83aad48e3a
Merge pull request #9657 from Security-Onion-Solutions/2.4/elastic-8.6.1
...
UPGRADE: Elastic 8.6.1 #9594 (2.4)
2023-01-26 16:24:42 -05:00
Doug Burks
86ca51ff99
Update to Elastic 8.6.1
2023-01-26 16:18:06 -05:00
Doug Burks
a27fc5c768
Update to Elastic 8.6.1
2023-01-26 16:17:36 -05:00
m0duspwnens
d5b5a36f28
remove data.nodestab from searchnodes pillar
2023-01-26 16:17:33 -05:00
m0duspwnens
75d73e4620
add yum portgroups for amnager
2023-01-26 15:35:22 -05:00
m0duspwnens
2fed977692
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-26 13:55:09 -05:00
m0duspwnens
f2d3298f14
allow nodes to connect to salt for manager and managersearch
2023-01-26 13:54:52 -05:00
weslambert
27b1f1bd07
Merge pull request #9654 from Security-Onion-Solutions/fix/logstash_cleanup
...
FIX: Logstash Pipeline Cleanup
2023-01-26 13:19:50 -05:00
Wes
e4271043c6
Remove unnecessary Logstash pipelines
2023-01-26 18:05:14 +00:00
Wes
b3123f7895
Remove unnecessary Logstash pipelines from the pillar
2023-01-26 17:57:07 +00:00
Mike Reeves
282d0f88db
Merge pull request #9652 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-verify
2023-01-26 12:33:46 -05:00
Mike Reeves
25a6eba166
Update so-verify
2023-01-26 12:30:35 -05:00
weslambert
a8d2631d75
Merge pull request #9650 from Security-Onion-Solutions/fix/elastic_agent_add_import_mode
...
Elastic Agent - Import Mode
2023-01-26 11:33:20 -05:00
Josh Patterson
881c8337a3
Merge pull request #9641 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-26 11:21:30 -05:00
Wes
b381c5424e
Remove extra whitespace after 'so-elastic-agent-builder' line in 'so-image-common'
2023-01-26 16:13:23 +00:00
Mike Reeves
a9919e7547
Merge pull request #9648 from Security-Onion-Solutions/mkr24
...
Enable Proxy Support
2023-01-26 11:12:35 -05:00
Wes
f1db1bc273
Ensure Kratos events are sent to a data stream instead of an index
2023-01-26 16:12:06 +00:00
Wes
7d68ef0e8b
Add Elastic Agent and Fleet to firewall configuration for Import Mode
2023-01-26 16:07:31 +00:00
Wes
43ffcb1d63
Allow setup to set up Elastic Fleet for Import Mode
2023-01-26 16:05:16 +00:00
Wes
8051fc70eb
Temporarily disable the loading of the RITA package policy
2023-01-26 16:03:59 +00:00
Wes
a9a119f1ab
Add Elasticsearch output to 'so-elastic-fleet-setup' for Import Mode
2023-01-26 16:02:27 +00:00
Wes
6a803dfe35
Add Elastic Fleet to top file configuration for Import Mode
2023-01-26 16:01:03 +00:00
Wes
1fb6cf7bfe
Add Elastic Fleet to allowed states for Import Mode
2023-01-26 15:59:49 +00:00
m0duspwnens
1d2f491084
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-26 10:49:00 -05:00
m0duspwnens
aafbdf6afc
adjust retry and timeout for wait_for_influxdb
2023-01-26 10:12:37 -05:00
Mike Reeves
2456aac311
Proxy Stuff
2023-01-26 09:57:44 -05:00
m0duspwnens
08750154b4
add missing quotes in check_web_pass
2023-01-26 09:11:28 -05:00
Mike Reeves
9e146184d6
Proxy Stuff
2023-01-25 17:43:02 -05:00
Mike Reeves
c57d390bac
Proxy Stuff
2023-01-25 17:40:40 -05:00
weslambert
211b87e7ae
Merge pull request #9644 from Security-Onion-Solutions/revert-9640-fix/elastic_agent_import_mode
...
Revert "Elastic Agent and Fleet - Import Mode"
2023-01-25 17:23:27 -05:00
weslambert
6ee66a34bc
Revert "Elastic Agent and Fleet - Import Mode"
2023-01-25 17:12:03 -05:00
weslambert
6785e0ec9e
Merge pull request #9640 from Security-Onion-Solutions/fix/elastic_agent_import_mode
...
Elastic Agent and Fleet - Import Mode
2023-01-25 17:01:33 -05:00
weslambert
c73cd78f08
Merge pull request #9643 from Security-Onion-Solutions/2.4/dev
...
Merge Dev
2023-01-25 16:59:47 -05:00
m0duspwnens
790aa6b684
add logstash pillar items for minions
2023-01-25 15:18:56 -05:00
Wes
5c58cda872
Move certificate configuration outside of conditional logic
2023-01-25 19:29:50 +00:00
m0duspwnens
b7a5937dc1
add soc_logstash and adv_logstash to nodes in pillar/top
2023-01-25 14:04:36 -05:00
Mike Reeves
31f591a098
Merge pull request #9635 from Security-Onion-Solutions/mkr24
...
Ubuntu support changes
2023-01-25 13:34:44 -05:00
Wes
c3717dae67
Add Elastic Fleet firewall configuration for Import Mode
2023-01-25 18:27:00 +00:00
Mike Reeves
498301b111
Salt for Ubuntu
2023-01-25 12:00:19 -05:00
Mike Reeves
704d99e757
Salt for Ubuntu
2023-01-25 11:50:19 -05:00
Mike Reeves
9243b01cbb
Salt for Ubuntu
2023-01-25 11:44:22 -05:00
Jason Ertel
c9f18891b2
Merge pull request #9639 from Security-Onion-Solutions/kilo
...
auto extract source/dest IP on case related event attachments; improve so-verify stream to console
2023-01-25 11:37:16 -05:00
Wes
86a925e1c7
Download Elastic Agent images for Import Mode
2023-01-25 16:09:12 +00:00
Jason Ertel
31d7e05c45
refactor so-verify to ensure output streams to console
2023-01-25 10:59:50 -05:00
Wes
838beabae5
Add missing single quote for Elastic Agent Elasticsearch output
2023-01-25 15:58:06 +00:00
m0duspwnens
3f99e3402e
add elasticsearch pillar files to manager and adv_elasticsearch to those that had soc_elasticsearch
2023-01-25 10:53:58 -05:00
Wes
c46b5e734b
Add 'elastic-fleet' to the list of allowed states for Import Mode
2023-01-25 14:38:23 +00:00
m0duspwnens
1b3f50a463
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-25 09:22:17 -05:00
Wes
1414b75e01
Allow 'elastic-fleet' state to be applied for Import Mode
2023-01-25 14:07:25 +00:00
Wes
506baa854d
Configure Elasticsearch output if running Import Mode
2023-01-25 13:52:54 +00:00
weslambert
4868bd8f5e
Merge pull request #9638 from Security-Onion-Solutions/fix/elastic_agent_integration_kratos_data_stream_rename
...
Rename Kratos Data Stream
2023-01-25 08:45:37 -05:00
weslambert
c9f458e1e2
Set event.dataset for all Kratos logs to 'access' for now
2023-01-25 08:19:50 -05:00
weslambert
7bf9d77962
Rename Kratos data stream
2023-01-25 08:18:21 -05:00
m0duspwnens
d1460ae01f
add node_data.ips pillar. grab influx host ip for soc extra_hosts
2023-01-24 17:05:40 -05:00
Mike Reeves
161881efbb
Salt for Ubuntu
2023-01-24 16:25:26 -05:00
Mike Reeves
d5f8ea8661
Salt for Ubuntu
2023-01-24 16:05:16 -05:00
Mike Reeves
53d6823ba7
Salt for Ubuntu
2023-01-24 16:00:03 -05:00
Mike Reeves
5a223981ca
Salt for Ubuntu
2023-01-24 15:57:05 -05:00
Mike Reeves
177ddc1183
Salt for Ubuntu
2023-01-24 15:48:48 -05:00
Mike Reeves
20f7a77886
Salt for Ubuntu
2023-01-24 15:43:12 -05:00
Mike Reeves
b89e7efeea
Salt for Ubuntu
2023-01-24 15:30:46 -05:00
weslambert
3f9764d22d
Merge pull request #9633 from Security-Onion-Solutions/fix/elastic_agent_more_improvements
...
More Elastic Agent Integration Improvements
2023-01-24 15:16:52 -05:00
Mike Reeves
a048034f16
Salt for Ubuntu
2023-01-24 13:38:39 -05:00
Josh Brower
81ee333b07
Initial support - Elastic Fleet Node
2023-01-24 13:36:30 -05:00
Jason Ertel
7b1f867ac3
Add defaults for auto extracted observables
2023-01-24 13:17:50 -05:00
Wes
4b9c92c53d
Set RITA event.dataset value explicitly
2023-01-24 18:00:34 +00:00
Wes
38ead7cb82
Remove import tag for now
2023-01-24 17:58:19 +00:00
Wes
44d149b1c3
Allow imported data to use a tag of 'import'
2023-01-24 17:01:52 +00:00
Wes
1e5377c78a
Condense RITA integration policies, add ICS tags, and improve output readability
2023-01-24 16:56:20 +00:00
m0duspwnens
b23575d85e
add global vars for manager
2023-01-24 11:03:03 -05:00
Jason Ertel
b0709e93fa
test workflow
2023-01-24 10:50:52 -05:00
Jason Ertel
fd7d51a59b
Merge pull request #9630 from Security-Onion-Solutions/kilo
...
Kilo
2023-01-24 10:45:12 -05:00
Jason Ertel
0dc5e7e714
try paths with wildcard
2023-01-24 10:38:59 -05:00
Jason Ertel
62b96c3698
rework filter for action
2023-01-24 10:31:02 -05:00
Jason Ertel
ec2e923530
Add proper spacing between headers and content
2023-01-24 10:28:39 -05:00
Jason Ertel
2bffd9b473
Merge pull request #9628 from Security-Onion-Solutions/kilo
...
try paths filter on both even though docs only mention support for push
2023-01-24 10:27:30 -05:00
Jason Ertel
cfc232eafa
try paths filter on both even though docs only mention support for push
2023-01-24 10:23:42 -05:00
m0duspwnens
6d3f57d648
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-24 10:17:24 -05:00
m0duspwnens
50895ee304
need to set_minion_info in setup for each node type
2023-01-24 10:16:58 -05:00
weslambert
7e0e5071d9
Merge pull request #9627 from Security-Onion-Solutions/fix/elastic_agent_integration_improvements
...
Elastic Agent Integration Improvements
2023-01-24 10:10:01 -05:00
Mike Reeves
2da30f42d4
Check for Ubuntu
2023-01-24 10:07:32 -05:00
Wes
7b4d8a47f0
Add copyright header to 'so-elastic-fleet-*' scripts
2023-01-24 15:07:00 +00:00
Josh Patterson
095ca29aca
Merge pull request #9626 from Security-Onion-Solutions/2.4/firewall
...
change MASTER to MANAGER in so-minion
2023-01-24 09:46:17 -05:00
Wes
f19cf75311
Change how event.dataset is determined for Suricata events
2023-01-24 14:45:00 +00:00
m0duspwnens
ee98e0684e
change MASTER to MANAGER
2023-01-24 09:44:01 -05:00
Josh Patterson
b797e356b4
Merge pull request #9624 from Security-Onion-Solutions/2.4/firewall
...
remove filebeat and redis(commented out) from telegraf config
2023-01-24 09:01:59 -05:00
m0duspwnens
88107fe0df
remove filebeat and redis(commented out) from telegraf config
2023-01-24 08:59:51 -05:00
Wes
51692ac66c
Update index pattern in various template definitions to match new data stream naming convention
2023-01-23 21:52:44 +00:00
Wes
40c6b380df
Update Import and Zeek integration policies; also update Zeek ingest node pipelines to set event.dataset.
2023-01-23 21:44:46 +00:00
Wes
d342f3c4b8
Add 'so-elastic-fleet-integration-policy-bulk-delete' to perform bulk deletion of integration policies
2023-01-23 21:38:13 +00:00
Josh Patterson
a503632f30
Merge pull request #9620 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-23 15:56:53 -05:00
m0duspwnens
d1ec7c8ace
remove to match with 2.4/dev
2023-01-23 15:50:53 -05:00
Jason Ertel
5da1b03d9b
Merge pull request #9619 from Security-Onion-Solutions/kilo
...
switch MySQL 8 to use native password for playbook compat; fix so-verify mail inspection
2023-01-23 15:14:00 -05:00
Jason Ertel
5a016312f6
switch MySQL 8 to use native password to avoid playbook incompatibility
2023-01-23 14:53:39 -05:00
m0duspwnens
90a224793e
merge with 2.4dev and fix conflict
2023-01-23 14:49:32 -05:00
m0duspwnens
22fbb953ea
create cronjob to run highstate after setup
2023-01-23 14:46:26 -05:00
Jason Ertel
d421aa82a2
do not treat all installs as ISO; fix check for non-empty mail files
2023-01-23 14:04:26 -05:00
Josh Patterson
1039e77550
Merge pull request #9617 from Security-Onion-Solutions/2.4/firewall
...
allow elastic agent on sensors to connect to managers
2023-01-23 13:19:49 -05:00
Mike Reeves
f077b5c96d
Remove 18.04
2023-01-23 13:11:50 -05:00
Josh Brower
f811223ba7
Merge pull request #9614 from Security-Onion-Solutions/playbookfixup
...
Playbookfixup
2023-01-23 08:20:06 -05:00
Josh Brower
d3cb57bba2
Rerun the playbook state
2023-01-23 08:16:28 -05:00
m0duspwnens
a1fa4e3ef2
revert reload_modules since bugged
2023-01-20 15:43:57 -05:00
Josh Brower
1ab8c712e4
remove exit condition
2023-01-20 15:17:04 -05:00
Jason Ertel
a613d960b9
Merge pull request #9608 from Security-Onion-Solutions/kilo
...
setup improvements
2023-01-20 13:11:11 -05:00
Jason Ertel
9541214073
logCmd with tee is eating the exit code
2023-01-20 12:26:52 -05:00
Jason Ertel
56478da0b2
eliminate find/exec issue altogether to keep it simple
2023-01-20 11:58:29 -05:00
Jason Ertel
c3384d8381
further improvements
2023-01-20 11:23:13 -05:00
Jason Ertel
1e4f9c9f26
use newer find syntax to allow the exec to work inside a quoted string
2023-01-20 11:01:02 -05:00
Jason Ertel
fea4a1b33d
Merge branch '2.4/dev' into kilo
2023-01-20 10:33:17 -05:00
Jason Ertel
ece63b72e2
Ensure so-verify output is logged
2023-01-20 07:38:58 -05:00
Jason Ertel
46aa7ebdf3
correct find/exec syntax
2023-01-20 06:48:33 -05:00
weslambert
9c83b775ee
Merge pull request #9604 from Security-Onion-Solutions/feature/sensoroni_scripts
...
Add scripts for starting, stopping, and restarting Sensoroni
2023-01-19 16:59:29 -05:00
Wes
739c174898
Add scripts for starting, stopping, and restarting Sensoroni
2023-01-19 21:50:10 +00:00
Jason Ertel
4044706cd9
Merge pull request #9603 from Security-Onion-Solutions/kilo
...
Handle setup failures
2023-01-19 15:49:41 -05:00
Jason Ertel
79fb5dc525
prevent false success occurring when deleting the grafana dashboard
2023-01-19 14:19:55 -05:00
Jason Ertel
59177288ef
correct grep patterns
2023-01-19 13:56:14 -05:00
Jason Ertel
85b5d1b317
Merge branch '2.4/dev' into kilo
2023-01-19 12:53:36 -05:00
Jason Ertel
6b7a8e1fcd
fix verify path
2023-01-19 12:53:24 -05:00
Josh Brower
027c83b5ea
Merge pull request #9601 from Security-Onion-Solutions/disablecontainer
...
Fixup
2023-01-19 11:47:04 -05:00
Josh Brower
4369d2385b
Temp disable Elastic Registry Repo
2023-01-19 11:45:13 -05:00
Jason Ertel
c5260e4787
verify setup
2023-01-19 11:25:59 -05:00
Jason Ertel
35835edf96
Merge branch '2.4/dev' into kilo
2023-01-19 11:04:32 -05:00
weslambert
8c4e00cfbd
Merge pull request #9600 from Security-Onion-Solutions/fix/elasticsearch_template_logs_default_remove
...
Remove default "logs-*" template settings for now
2023-01-19 10:30:44 -05:00
weslambert
7d3f6121eb
Remove default "logs-*" template settings for now
2023-01-19 10:29:10 -05:00
Jason Ertel
05c7999df3
merge
2023-01-19 10:06:58 -05:00
Jason Ertel
05a6d702b0
Add logic to determine if setup succeeded and provide relevant output
2023-01-19 10:03:03 -05:00
Josh Brower
8ce96942c1
Merge pull request #9599 from Security-Onion-Solutions/disablecontainer
...
Temp disable Elastic Registry Repo
2023-01-19 07:27:51 -05:00
Josh Brower
e83e54936e
Temp disable Elastic Registry Repo
2023-01-19 07:25:25 -05:00
weslambert
90f3e33cc6
Merge pull request #9597 from Security-Onion-Solutions/fix/elasticsearch_template_logs_default_priority_modification
...
Modify default 'logs-*' Elasticsearch template priority
2023-01-18 17:30:52 -05:00
weslambert
7a499c9051
Modify default 'logs-*' template priority
2023-01-18 17:24:07 -05:00
m0duspwnens
1eafb8d62a
reload salt modules when docker is installed
2023-01-18 13:46:06 -05:00
m0duspwnens
d501b0fac9
add elastic agent to assigned hostgroups
2023-01-18 09:46:55 -05:00
weslambert
1bf088e976
Merge pull request #9591 from Security-Onion-Solutions/fix/kibana_basepath_rewrite_disable
...
Disable Kibana's native base path rewrite and add publicBaseUrl
2023-01-17 16:59:06 -05:00
weslambert
1fed3cf474
Disable Kibana's native base path rewrite and add publicBaseUrl
2023-01-17 16:54:31 -05:00
Josh Patterson
e0f8315d27
Merge pull request #9590 from Security-Onion-Solutions/2.4/firewall
...
create /opt/so/ for non manager nodes during setup
2023-01-17 15:36:34 -05:00
m0duspwnens
dbfe176b45
create /opt/so/ for non manager nodes during setup
2023-01-17 14:15:44 -05:00
Josh Patterson
2842178396
Merge pull request #9588 from Security-Onion-Solutions/2.4/firewall
...
fix iptables
2023-01-17 13:50:16 -05:00
m0duspwnens
aa858bab45
fix iptables
2023-01-17 13:48:39 -05:00
weslambert
1723f58c04
Merge pull request #9579 from Security-Onion-Solutions/fix/elasticsearch_templates_so-ids
...
Remove so-ids since the data stream is now 'logs-suricata-*'
2023-01-13 16:17:38 -05:00
weslambert
ca80548bf0
Remove so-ids since the data stream is now 'logs-suricata-*'
2023-01-13 16:15:58 -05:00
weslambert
3e5127810d
Merge pull request #9577 from Security-Onion-Solutions/fix/elasticsearch_elastic_agent_templates
...
Make sure Elastic Agent data streams do not use replicas
2023-01-13 16:12:09 -05:00
weslambert
73a4dae28e
Make sure Elastic Agent data streams do not use replicas
2023-01-13 16:10:44 -05:00
Josh Patterson
3efca0010a
Merge pull request #9573 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-13 12:41:58 -05:00
m0duspwnens
3653df4d5f
spell it right
2023-01-13 10:18:13 -05:00
m0duspwnens
6033e9a0de
use port_bindings from docker defaults in docker states
2023-01-13 10:15:10 -05:00
weslambert
7cba5626b7
Merge pull request #9570 from Security-Onion-Solutions/fix/elasticsearch_templates_elastic_agent
...
Change priority for Elastic Agent Elasticsearch index templates
2023-01-12 16:48:12 -05:00
m0duspwnens
a69b0951d3
add strelka containers
2023-01-12 16:47:34 -05:00
weslambert
654d869e3e
Change priority from 500 to 200 for Elastic Agent index templates to avoid collisions with other templates
2023-01-12 16:46:08 -05:00
m0duspwnens
d163d834d4
allow for binding ip and ports to different port number
2023-01-12 16:42:45 -05:00
weslambert
be6b42494c
Merge pull request #9569 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_kratos
...
Kratos Index Changes
2023-01-12 15:33:51 -05:00
weslambert
fb8d8ea972
Update Elasticsearch index template for Kratos
2023-01-12 15:31:41 -05:00
weslambert
9416552338
Don't set the Kratos index explicitly
2023-01-12 15:25:35 -05:00
Mike Reeves
6c8b17d4d1
Merge pull request #9567 from Security-Onion-Solutions/mkr24
...
Fix nsm
2023-01-12 10:43:42 -05:00
Mike Reeves
8c5a060a80
Fix nsm
2023-01-12 10:41:54 -05:00
weslambert
66f9a06458
Merge pull request #9566 from Security-Onion-Solutions/fix/elastic_fleet_integration_policy_load
...
Fix Zeek import policies and remove unnecessary dash in RITAENABLED statement
2023-01-11 16:17:40 -05:00
Wes
0e437f84e7
Add back echo statement to print the import policy being loaded
2023-01-11 21:13:30 +00:00
Wes
ea01e68846
Fix Zeek import policies and remove unnecessary dash in RITAENABLED statement
2023-01-11 21:01:31 +00:00
Josh Patterson
add71cbdee
Merge pull request #9565 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-11 15:04:25 -05:00
Mike Reeves
60d476457a
Merge pull request #9564 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update 0900_input_redis.conf.jinja
2023-01-11 14:54:40 -05:00
m0duspwnens
80f65fcd62
remove 514/tcp from filebeat for now
2023-01-11 14:54:05 -05:00
Mike Reeves
66924b63a7
Update 9999_output_redis.conf.jinja
2023-01-11 14:53:16 -05:00
Mike Reeves
bdaed849ea
Update 0900_input_redis.conf.jinja
2023-01-11 14:52:32 -05:00
m0duspwnens
0d45c1583e
add so-filebeat docker container ports and add to standalone
2023-01-11 14:48:20 -05:00
m0duspwnens
81e07997f0
add so-elastic-fleet docker container ports and add to standalone
2023-01-11 14:28:35 -05:00
Mike Reeves
4923fb1c35
Merge pull request #9563 from Security-Onion-Solutions/mkr24
...
Optimize reinstall process
2023-01-11 12:44:52 -05:00
Mike Reeves
8fa8b89d9c
Fix reinstall logic
2023-01-11 12:43:22 -05:00
Mike Reeves
bab010a109
Fix reinstall logic
2023-01-11 12:40:18 -05:00
Mike Reeves
c07821a612
Fix reinstall logic
2023-01-11 12:32:43 -05:00
weslambert
acad7acc4a
Merge pull request #9562 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_load_suricata_import
...
Move Suricata import policy definition so that it does not get caught in the for loop for Zeek policies
2023-01-11 12:27:37 -05:00
Mike Reeves
b36f1bc79e
Fix reinstall logic
2023-01-11 12:26:50 -05:00
weslambert
4391c22335
Move Suricata import policy definition so that it does not get caught in the for loop for Zeek policies
2023-01-11 12:23:50 -05:00
weslambert
39d1f07fab
Merge pull request #9561 from Security-Onion-Solutions/fix/filebeat_remove_module_setup
...
Remove pipeline.load from top.sls so that Filebeat module loading is not attempted
2023-01-11 12:21:39 -05:00
Mike Reeves
35e0a78cad
Fix reinstall logic
2023-01-11 12:20:57 -05:00
weslambert
b3e0183e39
Remove pipeline.load from top.sls so that Filebeat module loading is not attempted
2023-01-11 12:19:06 -05:00
Mike Reeves
708ba13721
Fix reinstall logic
2023-01-11 12:18:02 -05:00
Mike Reeves
eee433e8c4
Fix reinstall logic
2023-01-11 12:17:13 -05:00
Mike Reeves
cd57ff9820
Fix reinstall logic
2023-01-11 12:16:18 -05:00
Mike Reeves
6d1e6fc358
Fix reinstall logic
2023-01-11 12:15:21 -05:00
Mike Reeves
0531d369aa
Fix reinstall logic
2023-01-11 11:09:06 -05:00
Mike Reeves
55911ef649
Fix reinstall logic
2023-01-11 11:05:01 -05:00
weslambert
355953427c
Merge pull request #9553 from Security-Onion-Solutions/feature/filebeat_to_elastic_agent_conversion
...
Initial Conversion of Filebeat Inputs to Elastic Agent Inputs
2023-01-11 09:22:40 -05:00
Wes
52b620b137
Add additional conditional logic for Filebeat and disable Filebeat
2023-01-11 14:10:11 +00:00
Wes
33e2affb1d
Remove newlines from end of Syslog processor definitions
2023-01-11 14:08:28 +00:00
Wes
c3b83f1fc8
Update template settings to use data streams
2023-01-11 14:03:11 +00:00
Wes
5062dd2873
Suricata Elasticsearch ingest node pipeline changes - set 'alert' dataset
2023-01-11 14:02:09 +00:00
Wes
2e886d0c55
Remove data_index_name processor since we are using data streams
2023-01-11 13:58:38 +00:00
Wes
5d86edeed4
Modify Logstash Elastic Agent output to accomodate for events with and without 'metadata.pipeline'
2023-01-11 13:57:32 +00:00
Wes
caf0ea6b53
Add Elastic Agent policy view script
2023-01-11 13:56:21 +00:00
Wes
a146f1134e
Add Elastic Agent utility scripts
2023-01-11 13:54:42 +00:00
Mike Reeves
7cecc910d5
Merge pull request #9458 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-11 08:49:15 -05:00
Doug Burks
668fe10fc0
Merge pull request #9552 from Security-Onion-Solutions/fix/import-unnecessary-processes
...
Prevent unnecessary processes in Import Mode
2023-01-11 08:07:40 -05:00
m0duspwnens
76fff1b1e0
add logstash ports
2023-01-10 17:02:54 -05:00
Josh Patterson
5993d06896
Merge pull request #9548 from Security-Onion-Solutions/2.4minefunctionsconf
...
Update so-functions
2023-01-10 16:58:09 -05:00
Josh Patterson
64af393f40
Update so-functions
...
change MAININT to MNIC
2023-01-10 16:57:17 -05:00
Doug Burks
c15db73561
Avoid unnecessary Zeek processes in Import Mode
2023-01-10 16:48:47 -05:00
Doug Burks
554754421c
Avoid unecessary Suricata processes in Import Mode
2023-01-10 16:48:06 -05:00
Doug Burks
322efa304a
Avoid unnecessary processes in Import Mode
2023-01-10 16:47:18 -05:00
Mike Reeves
9995d06626
Merge branch '2.4/firewall' of https://github.com/Security-Onion-Solutions/securityonion into 2.4/firewall
2023-01-10 16:09:04 -05:00
Mike Reeves
ab3a7abcc7
run restore each time
2023-01-10 16:08:44 -05:00
Josh Patterson
f039ecb5ce
Merge pull request #9547 from Security-Onion-Solutions/2.4/dev
...
2.4/dev
2023-01-10 13:42:44 -05:00
Mike Reeves
38962520ac
Merge pull request #9546 from Security-Onion-Solutions/2.4minefunctionsconf
...
Update so-functions
2023-01-10 13:39:56 -05:00
Josh Patterson
0151830c85
Update so-functions
2023-01-10 13:37:56 -05:00
Mike Reeves
85978180c2
Merge pull request #9545 from Security-Onion-Solutions/revert-9544-2.4createrepoinstall
...
Revert "ensure yum-utils and createrepo are installed from so remote repo"
2023-01-10 13:13:31 -05:00
Mike Reeves
d3b8fbaafc
Revert "ensure yum-utils and createrepo are installed from so remote repo"
2023-01-10 13:13:13 -05:00
Josh Patterson
745387a756
Merge pull request #9544 from Security-Onion-Solutions/2.4createrepoinstall
...
ensure yum-utils and createrepo are installed from so remote repo
2023-01-10 11:53:36 -05:00
m0duspwnens
39d808cb8f
resolve conflict
2023-01-10 11:50:58 -05:00
Josh Patterson
ab8f41ecb5
Merge branch '2.4/firewall' into 2.4createrepoinstall
2023-01-10 11:38:31 -05:00
m0duspwnens
d2e623747d
ensure yum-utils and createrepo are installed from so remote repo
2023-01-10 11:34:50 -05:00
Mike Reeves
3e9bddcd11
Changes to iptables.jinja
2023-01-09 15:36:23 -05:00
Mike Reeves
302bf28b6c
Merge branch '2.4/firewall' of https://github.com/Security-Onion-Solutions/securityonion into 2.4/firewall
2023-01-09 15:00:05 -05:00
Mike Reeves
5058210bbb
Changes to iptables.jinja
2023-01-09 14:59:55 -05:00
m0duspwnens
ac157432de
include docker
2023-01-09 14:58:36 -05:00
m0duspwnens
ec5c565cec
put elastalert on sosbridge
2023-01-09 14:49:33 -05:00
m0duspwnens
dbbcea0009
look for True
2023-01-09 11:53:32 -05:00
m0duspwnens
c313b19b50
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-09 11:18:08 -05:00
Mike Reeves
73ae48d28e
Merge pull request #9539 from Security-Onion-Solutions/mkr24
...
Changes to accept minion
2023-01-09 11:17:45 -05:00
Mike Reeves
0e1e9ff343
Changes to accept minion
2023-01-09 11:15:29 -05:00
Doug Burks
c3a5a02010
Merge pull request #9529 from Security-Onion-Solutions/dougburks-patch-1
...
Add missing Zeek log to filebeat defaults.yaml
2023-01-06 14:34:02 -05:00
Doug Burks
c1dfb9f935
Add missing Zeek log to filebeat defaults.yaml
2023-01-06 14:27:40 -05:00
Doug Burks
54e554eb3b
Merge pull request #9528 from Security-Onion-Solutions/dougburks-patch-1
...
Remove line numbers from vi
2023-01-06 14:25:19 -05:00
Doug Burks
10e82c5f1c
Remove line numbers from vi
2023-01-06 14:23:54 -05:00
m0duspwnens
d4c6834cd0
merge with 2.4/dev
2023-01-06 14:01:58 -05:00
m0duspwnens
4aacc6d1db
change role names in so-firewall-minion
2023-01-06 11:09:09 -05:00
m0duspwnens
cb1822a62d
change ref to DOCKER.sosrange
2023-01-05 15:57:06 -05:00
m0duspwnens
f10238da42
fw changes
2023-01-04 16:06:14 -05:00
Mike Reeves
2e53476a06
Merge pull request #9516 from Security-Onion-Solutions/mkr24
...
Add PW auth for Redis
2023-01-04 14:50:27 -05:00
Mike Reeves
275aead5b9
Allow auth for redis check for tgraf
2023-01-04 14:30:28 -05:00
Mike Reeves
e52b54720a
Allow auth for redis check for tgraf
2023-01-04 14:26:24 -05:00
Mike Reeves
5afad52b3f
Allow auth for redis check for tgraf
2023-01-04 14:18:08 -05:00
Mike Reeves
9bc08661c5
Allow auth for redis check for tgraf
2023-01-04 14:15:53 -05:00
Mike Reeves
48a3f4e261
Allow auth for redis check for tgraf
2023-01-04 14:14:10 -05:00
Doug Burks
723362e685
Merge pull request #9514 from Security-Onion-Solutions/fix/jinja-whitespace-2.4
...
fix jinja whitespace 2.4
2023-01-04 13:56:24 -05:00
doug
7ba4bdd87b
fix jinja whitespace
2023-01-04 13:50:25 -05:00
Mike Reeves
831300b540
Require password auth for redis access
2023-01-04 11:02:40 -05:00
Doug Burks
4c1fc4c679
Merge pull request #9511 from Security-Onion-Solutions/fix/sysmon-fields-2.4
...
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:58:16 -05:00
Doug Burks
5754365c6d
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:42:24 -05:00
Mike Reeves
761fbd0edf
Merge pull request #9504 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soc_global.yaml
2023-01-03 12:24:58 -05:00
Mike Reeves
08d7b24fb4
Update soc_global.yaml
2023-01-03 12:17:51 -05:00
Mike Reeves
df89445ab5
Update soc_global.yaml
2023-01-03 12:17:14 -05:00
m0duspwnens
203e612452
enable icc and hostbinding on sosbridge
2023-01-03 11:21:05 -05:00
weslambert
2c3bd6e3fd
Merge pull request #9502 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_rita_beacon_2_4
...
Update RITA beacon parsing
2023-01-03 11:14:04 -05:00
m0duspwnens
c35a3e122f
add ip to container.add containers to sosbridge
2023-01-03 11:13:50 -05:00
Wes
c8ff2c7a06
Update RITA beacon parsing
2023-01-03 16:03:49 +00:00
Doug Burks
3c91d842f5
Merge pull request #9499 from Security-Onion-Solutions/fix/sysmon-parsing-2.4
...
FIX: Sysmon logs are missing event.category and event.dataset #8194
2023-01-03 09:05:55 -05:00
doug
4e5d1d587e
update sysmon ingest parser and Sysmon File dashboard
2023-01-03 09:02:17 -05:00
Jason Ertel
8d797ad9df
Merge pull request #9490 from Security-Onion-Solutions/kilo
...
Ensure create/update dates are both reset when an admin sets a user pass
2022-12-30 11:47:01 -05:00
Jason Ertel
a89976779d
Ensure create/update dates are both reset when an admin sets a user's password
2022-12-30 11:30:09 -05:00
Mike Reeves
058b4013aa
Merge pull request #9470 from Security-Onion-Solutions/kilo
...
Kilo
2022-12-23 10:37:22 -05:00
Jason Ertel
136867c96a
ensure zombie pipe is destroyed before SOC restarts
2022-12-23 10:27:49 -05:00
Mike Reeves
1b946ced7f
Merge pull request #9469 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soc_global.yaml
2022-12-23 08:58:07 -05:00
Mike Reeves
75ffd1f56b
Update soc_global.yaml
2022-12-23 08:55:19 -05:00
Doug Burks
f335e7e477
Merge pull request #9466 from Security-Onion-Solutions/2.4/fix-grafana-playbook-links
...
Remove Grafana and Playbook links for Import mode
2022-12-22 16:09:46 -05:00
Doug Burks
5be074bbea
Remove Grafana and Playbook links for Import mode
2022-12-22 15:45:25 -05:00
m0duspwnens
24876eecd9
change refs from sosnet to sosbridge
2022-12-22 14:02:40 -05:00
Mike Reeves
3f0ded0638
Merge pull request #9464 from Security-Onion-Solutions/mkr24
...
Add global annotation and influx support
2022-12-22 13:57:56 -05:00
Mike Reeves
cd77e71d8d
Create annotation file for global settings
2022-12-22 13:37:41 -05:00
Mike Reeves
78f851e6c2
Create annotation file for global settings
2022-12-22 13:35:37 -05:00
Doug Burks
b02ba7edf7
Merge pull request #9463 from Security-Onion-Solutions/2.4/fix-grafana-eval
...
Enable Grafana in EVAL mode
2022-12-22 13:30:54 -05:00
m0duspwnens
90882ce1db
disable docker from managing iptables
2022-12-22 13:26:10 -05:00
Mike Reeves
a924d48408
Specify Influxdb host
2022-12-22 13:12:19 -05:00
Mike Reeves
308228620a
Specify Influxdb host
2022-12-22 13:05:33 -05:00
Mike Reeves
4620cd5edf
Merge pull request #9462 from Security-Onion-Solutions/mkr24
...
Modify manager for repo
2022-12-22 13:01:58 -05:00
Doug Burks
2df4755fef
Enable Grafana in EVAL mode
2022-12-22 12:54:57 -05:00
Mike Reeves
cf02b8e191
Modify manager for repo
2022-12-22 10:34:33 -05:00
Jason Ertel
a077645bb4
Merge branch '2.4/dev' into kilo
2022-12-22 10:27:13 -05:00
Jason Ertel
b6f37f8499
Correct indentation of client section
2022-12-22 10:26:51 -05:00
Doug Burks
f1d31a0c41
Merge pull request #9459 from Security-Onion-Solutions/2.4/fix-influxdb-telegraf
...
Make influxdb and telegraf consistent across import and eval modes
2022-12-22 10:26:36 -05:00
Doug Burks
e95034886e
add influxdb and telegraf to import mode
2022-12-22 09:49:57 -05:00
Doug Burks
9352854fe4
enable influxdb for eval and import modes
2022-12-22 09:48:38 -05:00
Doug Burks
75e16963c8
add influxdb and telegraf to import mode
2022-12-22 09:47:47 -05:00
Doug Burks
dfd5947051
add influxdb and telegraf to import mode
2022-12-22 09:46:27 -05:00
m0duspwnens
b4908e2bb9
add iptables.jinja
2022-12-22 09:31:45 -05:00
Jason Ertel
ba13ad7151
Merge pull request #9454 from Security-Onion-Solutions/kilo
...
fix redis defaults to force string keys instead of numeric
2022-12-21 18:16:40 -05:00
Jason Ertel
38634fde17
fix redis defaults to force string keys instead of numeric
2022-12-21 18:15:17 -05:00
Jason Ertel
8b6006e9c3
fix redis defaults to force string keys instead of numeric
2022-12-21 18:14:18 -05:00
Jason Ertel
3fd210463e
fix redis defaults to force string keys instead of numeric
2022-12-21 18:11:39 -05:00
Doug Burks
f99279ca24
Merge pull request #9453 from Security-Onion-Solutions/feature/improve-dashboards-2.4
...
FEATURE: Improve SOC Dashboards #9450 2.4
2022-12-21 15:46:11 -05:00
Doug Burks
69415a0d8d
Improve Strelka dashboard
2022-12-21 15:34:35 -05:00
Doug Burks
506556f0d2
Improve Firewall dashboard
2022-12-21 15:29:09 -05:00
Doug Burks
d7b2c88201
Improve Software dashboard
2022-12-21 15:24:58 -05:00
Doug Burks
4519c533a2
Improve Intel dashboard
2022-12-21 15:20:27 -05:00
Josh Patterson
8d35e0120e
Merge pull request #9451 from Security-Onion-Solutions/2.4/so-kibana-config-load
...
need space between curl.config and -X
2022-12-21 15:11:54 -05:00
m0duspwnens
6d6fa4c1e3
need space between curl.config and -X
2022-12-21 15:06:56 -05:00
m0duspwnens
accc293c8a
2.4 firewall changes
2022-12-21 15:03:45 -05:00
Doug Burks
3a367d69f4
Improve FTP dashboard
2022-12-21 14:37:17 -05:00
Doug Burks
a4f1f75306
Improve NIDS Alerts dashboard
2022-12-21 14:33:01 -05:00
Jason Ertel
5a5c565fae
Merge pull request #9449 from Security-Onion-Solutions/kilo
...
Ensure user/pass values are quoted due to symbol chars appearing in values
2022-12-21 14:02:38 -05:00
Jason Ertel
0889d49025
Ensure user/pass values are quoted due to symbol chars appearing in the values
2022-12-21 14:00:10 -05:00
Doug Burks
3d1ce4ef10
Improve SOC dashboards
2022-12-21 13:26:04 -05:00
Jason Ertel
33a1aea729
Merge pull request #9448 from Security-Onion-Solutions/kilo
...
improve so-status rendering on terminals that only support 8 colors
2022-12-21 10:14:47 -05:00
Jason Ertel
8e63909edf
improve so-status rendering on terminals that only support 8 colors
2022-12-21 10:11:38 -05:00
Mike Reeves
ab9edd4e6b
Merge pull request #9421 from Security-Onion-Solutions/mkr24
...
Redis defaults.yaml
2022-12-21 09:15:49 -05:00
Mike Reeves
aa7690864a
Modify redis config defaults
2022-12-20 22:05:04 -05:00
Mike Reeves
e1d0f99a14
Modify redis config defaults
2022-12-20 22:00:10 -05:00
Mike Reeves
38e23a0110
Modify Kratos config defaults
2022-12-20 21:21:18 -05:00
Mike Reeves
3768c0fee2
Fix Redis
2022-12-20 21:16:53 -05:00
Mike Reeves
8c6a2ce83a
Fix Kratos mode
2022-12-20 21:00:06 -05:00
Mike Reeves
9428949c79
Fix Kratos top
2022-12-20 20:56:06 -05:00
Mike Reeves
90061e2683
Fix Kratos top
2022-12-20 20:54:43 -05:00
Mike Reeves
c3917a373c
Fix Kratos top
2022-12-20 20:52:01 -05:00
m0duspwnens
318aac880e
file.managed for kratos schema
2022-12-20 17:40:29 -05:00
m0duspwnens
16b882a10e
new states for kratos config and schema
2022-12-20 15:34:58 -05:00
Mike Reeves
eaa705ee3e
Fix Kratos Pillar entry
2022-12-20 14:38:17 -05:00
Jason Ertel
2edc3cac11
Clarify Kratos annotations
2022-12-20 14:08:49 -05:00
Mike Reeves
13e5fa7544
SOC files for Kratos
2022-12-20 13:30:51 -05:00
m0duspwnens
a2d0de7e49
kratos config jinja
2022-12-20 12:15:33 -05:00
Josh Brower
f7150d423c
Merge pull request #9440 from Security-Onion-Solutions/fleet-setup-fixes
...
Make Fleet setup less fragile
2022-12-20 11:55:14 -05:00
Josh Brower
73a9c3bb38
Make Fleet setup less fragile
2022-12-20 11:52:56 -05:00
Doug Burks
03f682dbec
Merge pull request #9439 from Security-Onion-Solutions/2.4/remove-old-whiptail
...
Remove whiptail_network_init_notice
2022-12-20 11:16:24 -05:00
Mike Reeves
c0c2d28d19
SOC files for Redis
2022-12-20 11:09:49 -05:00
Doug Burks
1371c4d01f
remove whiptail_network_init_notice from so-whiptail
2022-12-20 10:46:14 -05:00
Doug Burks
388e0a08ae
remove old whiptail reference from so-functions
2022-12-20 10:45:30 -05:00
Doug Burks
6487e6e1f0
remove old whiptail reference from so-setup
2022-12-20 10:44:37 -05:00
Doug Burks
d4c54ce161
Merge pull request #9438 from Security-Onion-Solutions/dougburks-patch-1
...
so-status should ignore commented entries in so-status.conf
2022-12-20 09:16:21 -05:00
Doug Burks
894434715b
so-status should ignore commented entries in so-status.conf
...
Import mode comments out so-steno, so-suricata, and so-zeek in so-status.conf, so so-status should ignore these lines.
2022-12-20 09:05:07 -05:00
Doug Burks
86fc0e11b0
Merge pull request #9436 from Security-Onion-Solutions/2.4/improve-import
...
Import mode does not need Elastic Fleet or Playbook
2022-12-20 07:32:24 -05:00
Doug Burks
69811b4d74
Import mode does not need Elastic Fleet or Playbook
2022-12-20 06:46:01 -05:00
Doug Burks
316d2cd9a5
Merge pull request #9435 from Security-Onion-Solutions/2.4/fix-import
...
Fix Import Mode in 2.4
2022-12-20 06:13:37 -05:00
doug
cd55be2f83
move IMPORT to top of list
2022-12-19 16:58:43 -05:00
doug
9d8951ceb8
fix import
2022-12-19 16:55:16 -05:00
Doug Burks
7168c4f91a
fix import in so-setup
2022-12-19 16:48:35 -05:00
Mike Reeves
aea91cc776
Merge branch 'mkr24' of https://github.com/Security-Onion-Solutions/securityonion into mkr24
2022-12-19 16:21:47 -05:00
Mike Reeves
74af54a200
SOC file for influx
2022-12-19 16:16:48 -05:00
m0duspwnens
6a4718ec0f
merge defaults with pillar
2022-12-19 15:55:35 -05:00
m0duspwnens
30419e5b2b
fix import and jinja spacing
2022-12-19 14:51:12 -05:00
m0duspwnens
ce0b920195
jinja conf for influxdb
2022-12-19 14:44:52 -05:00
m0duspwnens
e5d38255fa
jinja conf for influxdb
2022-12-19 14:42:48 -05:00
Josh Brower
b901efc90d
Merge pull request #9434 from Security-Onion-Solutions/2.4/allow-editing-efpolicies
...
Unmanage default policies
2022-12-19 14:33:16 -05:00
Josh Brower
6d07ab0c40
Unmanage default policies
2022-12-19 14:27:36 -05:00
Mike Reeves
c20f8c230b
Initial SOC file for influx
2022-12-19 14:02:01 -05:00
Doug Burks
cf884c68a7
Merge pull request #9433 from Security-Onion-Solutions/dougburks-patch-1
...
Remove another hardcoded docs URL
2022-12-19 13:16:42 -05:00
Doug Burks
0494efaea0
remove temporary message
2022-12-19 13:15:02 -05:00
Mike Reeves
149038d08e
pillar tops
2022-12-19 12:06:45 -05:00
Mike Reeves
fde65db021
Add influx pillars during setup
2022-12-19 12:03:00 -05:00
Mike Reeves
61bfeb82d9
fix defaults for influx
2022-12-19 11:01:19 -05:00
Mike Reeves
56f326d123
fix defaults for influx
2022-12-19 10:46:39 -05:00
Doug Burks
d7b47814dc
Merge pull request #9432 from Security-Onion-Solutions/2.4/refactor-docs-url
...
2.4: Refactor docs URL
2022-12-19 10:43:22 -05:00
Mike Reeves
d9343d8450
fix defaults for redis
2022-12-19 10:38:11 -05:00
Mike Reeves
42157ff2b1
fix defaults for redis
2022-12-19 10:36:35 -05:00
Doug Burks
df1b564d17
Replace hardcoded URL in so-analyst-install with new $DOC_BASE_URL variable from so-common
2022-12-19 10:30:29 -05:00
Doug Burks
73f2789c95
Replace hardcoded URLs in soup with new $DOC_BASE_URL variable from so-common
2022-12-19 10:28:20 -05:00
m0duspwnens
3c00d67879
fix redis defaults
2022-12-19 10:24:28 -05:00
Doug Burks
a28f804f7f
Replace hardcoded URLs with new $DOC_BASE_URL variable from so-common
2022-12-19 10:24:03 -05:00
Doug Burks
042693895a
add new DOC_BASE_URL variable to so-common
2022-12-19 10:21:54 -05:00
m0duspwnens
01d6b2b1f1
jinja the redis config
2022-12-19 10:14:48 -05:00
weslambert
c220c322ef
Merge pull request #9431 from Security-Onion-Solutions/fix/elasticsearch_templates_elastic_agent
...
Remove 'so-' prefix for Elastic Agent/Fleet component templates
2022-12-19 10:14:39 -05:00
weslambert
fd1be0ab2c
Remove 'so-' prefix for Elastic Agent/Fleet component templates
2022-12-19 10:11:26 -05:00
Mike Reeves
4c90c1af12
Add defaults for redis
2022-12-18 18:07:02 -05:00
Doug Burks
c25a828dd2
Merge pull request #9417 from Security-Onion-Solutions/2.4/eval
...
Fix EVAL mode in 2.4
2022-12-16 16:39:46 -05:00
Doug Burks
0fa6ca3880
init.sls needs to import GLOBALS
2022-12-16 15:59:17 -05:00
Jason Ertel
1b42965a6d
Merge pull request #9416 from Security-Onion-Solutions/jertel/lic
...
license key format change and eventFields dedup
2022-12-16 15:58:08 -05:00
Jason Ertel
fa7488effb
change format of license key for compat with config alignment
2022-12-16 15:56:02 -05:00
Mike Reeves
93a8b76070
Add defaults for influxdb
2022-12-16 15:17:25 -05:00
Doug Burks
490e97b49f
Merge pull request #9415 from Security-Onion-Solutions/2.4/dev
...
2.4/dev
2022-12-16 15:07:39 -05:00
Doug Burks
4384b83b65
Merge pull request #9412 from Security-Onion-Solutions/dougburks-patch-1
...
fix telegraf_pillar
2022-12-16 13:51:32 -05:00
Doug Burks
9c4d441b4d
fix telegraf_pillar
2022-12-16 13:36:26 -05:00
doug
b9e51fc7cf
first round of fixes for eval mode
2022-12-16 13:24:02 -05:00
Doug Burks
93056e802f
remove old comment
2022-12-16 13:17:27 -05:00
Mike Reeves
3f4ad8b983
Merge pull request #9411 from Security-Onion-Solutions/mkr24
...
Change telegraf to match config map standard
2022-12-16 13:10:15 -05:00
Jason Ertel
b37697e95d
Switch license key to single line to avoid multiline/list conflicts
2022-12-16 12:50:22 -05:00
Mike Reeves
676aec7576
Add config map
2022-12-16 11:22:53 -05:00
Mike Reeves
b5cc5a023d
Merge pull request #9410 from Security-Onion-Solutions/mkr24
...
Add Telegraf to the GUI for 2.4
2022-12-16 08:44:57 -05:00
Mike Reeves
5badfb9cf5
Fix pillar
2022-12-16 08:38:31 -05:00
Jason Ertel
7853d972b6
Set default key to empty string to ensure new keys are type aligned correctly
2022-12-15 18:31:47 -05:00
Mike Reeves
8a0991afd0
Fix pillar
2022-12-15 15:05:57 -05:00
Jason Ertel
f84ceca03e
consolidate eventFields from hunt and dashbaords into a single setting
2022-12-15 14:22:23 -05:00
Mike Reeves
6b3149f4e9
Fix the pillar top
2022-12-15 14:03:21 -05:00
Mike Reeves
175f413beb
Minor gui tweak
2022-12-15 13:36:00 -05:00
Mike Reeves
121d07733f
Merge the defaults and pillar for telegraf
2022-12-15 13:29:31 -05:00
Mike Reeves
e55086230d
Merge the defaults and pillar for telegraf
2022-12-15 13:28:29 -05:00
Mike Reeves
d37a4b14ca
Spelling error
2022-12-15 12:02:01 -05:00
Mike Reeves
fd27044471
Spelling error
2022-12-15 11:57:06 -05:00
Mike Reeves
ed87b08fc1
Spelling error
2022-12-15 10:59:07 -05:00
Mike Reeves
5d732872d6
Add soc gui info for telegraf
2022-12-15 10:51:22 -05:00
Mike Reeves
28e8c54443
Wire telegraf initial commit
2022-12-15 10:43:58 -05:00
Jason Ertel
6a73410be9
Merge pull request #9394 from Security-Onion-Solutions/jertel/mvkr
...
move Kratos DB to /nsm
2022-12-14 15:00:44 -05:00
Jason Ertel
52c4553ea6
move Kratos DB to /nsm
2022-12-14 14:28:34 -05:00
Jason Ertel
9885f418fa
move Kratos DB to /nsm
2022-12-14 14:22:55 -05:00
Mike Reeves
c79457b41d
Merge pull request #9386 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update config.map.jinja
2022-12-13 13:56:14 -05:00
Mike Reeves
6352b3fd53
Update config.map.jinja
2022-12-13 13:55:09 -05:00
Doug Burks
61c976f8a6
Merge pull request #9384 from Security-Onion-Solutions/2.4/streamline-setup
...
miscellaneous improvements for 2.4
2022-12-13 13:43:31 -05:00
Doug Burks
07df9ad0e0
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:30:38 -05:00
Doug Burks
ca3c99ac99
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:29:59 -05:00
doug
6eedae601f
improve welcome screen
2022-12-13 12:35:43 -05:00
doug
d58579d916
improve grammar
2022-12-13 12:05:02 -05:00
weslambert
09b012ad4e
Merge pull request #9372 from Security-Onion-Solutions/fix/sensoroni_analyzers_configuration_check_2_4
...
Fix localfile analyzer 'file_path' check and add new list value verification function for helpers
2022-12-13 11:47:18 -05:00
doug
0072cc42db
add extra newline
2022-12-13 11:34:29 -05:00
doug
0f84f419b2
fix sizing
2022-12-13 11:31:12 -05:00
Wes
3ab8a0be60
Update tests to account for change in 'file_path' value verification
2022-12-13 16:29:18 +00:00
Wes
eae05e83e6
Use new list verification function for 'file_path'
2022-12-13 16:28:50 +00:00
Wes
117d230b9d
Add new test for list value verification function
2022-12-13 16:28:22 +00:00
Wes
5422c5b3e2
Add new function to verify list value
2022-12-13 16:27:58 +00:00
doug
d3a8bdff52
setup improvements
2022-12-13 11:20:00 -05:00
Doug Burks
f94eb243e4
Merge pull request #9367 from Security-Onion-Solutions/dougburks-patch-1
...
Upgrade to Elastic 8.5.3
2022-12-13 10:14:41 -05:00
Doug Burks
3dd4e31f49
Upgrade to Elastic 8.5.3 in config_saved_objects.ndjson
2022-12-13 10:07:52 -05:00
Doug Burks
2004184b72
Upgrade to Elastic 8.5.3 in so-kibana-config-load
2022-12-13 10:06:23 -05:00
Doug Burks
ed8bf884eb
Merge pull request #9355 from Security-Onion-Solutions/fix/2.4-ics
...
Fix ICS and other issues in 2.4
2022-12-12 09:18:14 -05:00
Doug Burks
e1d200e6ce
Remove duplicate TDS dashboard from defaults.yaml
2022-12-11 14:39:08 -05:00
Doug Burks
72f71ba695
Fix TDS dashboard in defaults.yaml
2022-12-11 14:36:27 -05:00
Doug Burks
be75062612
Update so-import-pcap
2022-12-10 15:17:02 -05:00
Doug Burks
da8e098655
update so-import-evtx
2022-12-10 15:16:32 -05:00
Doug Burks
cb16bd36fb
fix descriptions in defaults.yaml
2022-12-10 14:31:59 -05:00
Doug Burks
cf7d8076e9
remove old Wazuh Hunt queries in defaults.yaml
2022-12-10 14:21:58 -05:00
Doug Burks
cd664b2d39
remove old Modbus dashboard from defaults.yaml
2022-12-10 14:16:39 -05:00
Doug Burks
7f07a94a98
remove old DNP3 and Wazuh dashboards from defaults.yaml
2022-12-10 14:14:24 -05:00
Doug Burks
8a0f94f8df
increase window width to accommodate extra text in so-whiptail
2022-12-10 11:24:11 -05:00
Doug Burks
66ad10cf77
fix airgap text in so-whiptail
2022-12-10 10:41:30 -05:00
Doug Burks
de2427cabe
add -p option to mkdir in so-elastic-fleet-setup
2022-12-10 08:20:38 -05:00
Doug Burks
187ca4c453
Update soc defaults.yaml to include dnp3_control and dnp3_objects eventfields
2022-12-10 07:33:09 -05:00
Doug Burks
c4ea39d1ba
Merge pull request #9349 from Security-Onion-Solutions/fix/2.4-ics
...
2.4: Fix multiple ICS issues and keep import indices open as in 2.3
2022-12-09 15:09:49 -05:00
doug
c2e10a4359
remove duplicate import iteration from so-functions
2022-12-09 11:00:06 -05:00
doug
90093395b6
keep so-import indices open as in 2.3
2022-12-09 10:23:09 -05:00
doug
565ca4e94f
keep so-import indices open as in 2.3
2022-12-09 08:49:25 -05:00
weslambert
69c7bb11c6
Merge pull request #9343 from Security-Onion-Solutions/fix/analyzers_localfile_file_path
...
FIX: Ensure file path is ascertainable by localfile.py for localfile analyzer
2022-12-08 17:08:19 -05:00
weslambert
9477f29432
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 17:06:43 -05:00
doug
5c00ab7b7f
correct order in defaults.yaml
2022-12-08 16:50:34 -05:00
doug
07a4919cd3
remove old opcua files
2022-12-08 16:43:11 -05:00
doug
7cfb688890
update defaults.yaml
2022-12-08 16:32:04 -05:00
Doug Burks
cf53242cf8
Merge pull request #9334 from Security-Onion-Solutions/dougburks-patch-1
...
update wording in so-whiptail
2022-12-08 10:43:22 -05:00
Doug Burks
c01486b009
update wording in so-whiptail
2022-12-08 10:32:03 -05:00
Mike Reeves
8af9dddd2e
Merge pull request #9326 from Security-Onion-Solutions/config
...
Switch back to older style redirect due to incompatibility with Ubuntu 18
2022-12-07 14:10:23 -05:00
Jason Ertel
0bbc68edae
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:08:11 -05:00
Jason Ertel
ef3def156d
Switch back to older style redirect due to incompatibility with Ubuntu 18
2022-12-07 14:03:31 -05:00
Mike Reeves
71e0d7c499
Merge pull request #9325 from Security-Onion-Solutions/config
...
Switch back to grep instead of pgrep
2022-12-07 12:13:27 -05:00
Jason Ertel
9f72cfa1fc
roll back to grep instead of pgrep due to cron issue
2022-12-07 12:08:31 -05:00
Jason Ertel
fde33de030
Use original style due to pgrep conflict with cron
2022-12-07 11:51:49 -05:00
Jason Ertel
d1f554723a
Merge pull request #9317 from Security-Onion-Solutions/config
...
Reduce cron noise; ensure filecheck is restarted if modified
2022-12-07 08:41:04 -05:00
Jason Ertel
e849783a86
Reduce cron noise; ensure filecheck is restarted if modified
2022-12-07 08:36:56 -05:00
weslambert
2240283457
Merge pull request #9316 from Security-Onion-Solutions/fix/ics_scada_filebeat_disable_ecat_arp_info
...
Disable Filebeat input for 'ecat_arp_info' Zeek logs
2022-12-07 08:08:42 -05:00
weslambert
def0c85349
Disable Filebeat input for 'ecat_arp_info' Zeek logs
2022-12-07 08:00:21 -05:00
weslambert
31832ae150
Merge pull request #9309 from Security-Onion-Solutions/fix/ignore_additional_strelka_rules_causing_compilation_errors
...
Ignore additional rules causing YARA compilation errors
2022-12-06 14:01:14 -05:00
weslambert
7ce0924382
Ignore additional rules causing compilation errors
2022-12-06 13:59:21 -05:00
weslambert
73304e049c
Merge pull request #9304 from Security-Onion-Solutions/feature/ics_scada_additions
...
Port STUN, TDS, WireGuard, and ICS/SCADA Changes from 2.3 to 2.4
2022-12-06 13:14:47 -05:00
weslambert
a626acced0
Add new ICS/SCADA event fields to the dashboards section of the configuration and remove extra space in key names.
2022-12-06 13:11:55 -05:00
Jason Ertel
6443e702a5
Merge pull request #9305 from Security-Onion-Solutions/config
...
Filecheck support for Suricata
2022-12-06 12:53:19 -05:00
Jason Ertel
88410bc8f8
Merge branch '2.4/dev' into config
2022-12-06 12:38:43 -05:00
Jason Ertel
168cd00e1b
Handle suricata extracted with filecheck
2022-12-06 12:34:02 -05:00
Wes
1b5c1fecd4
Revert SOC default 'alerts' event fields and specify additional event fields for ICS/SCADA events
2022-12-06 17:28:30 +00:00
Wes
b048eec3c0
Add STUN, TDS, WireGuard, and ICS/SCADA dashboard queries
2022-12-06 17:17:49 +00:00
Wes
f44eee134a
Add default queries and ICS/SCADA queries
2022-12-06 16:52:20 +00:00
Wes
c741fe6b4d
Ensure ICS/SCADA plugins/scripts are enabled
2022-12-06 16:23:26 +00:00
Wes
be5775e4a0
Ensure Filebeat defaults file is updated with ICS/SCADA log references
2022-12-06 16:15:09 +00:00
Wes
499b5d95f2
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-12-06 16:01:57 +00:00
Wes
14af1d36cb
Ensure ICS/SCADA pipelines are present
2022-12-06 15:58:47 +00:00
Jason Ertel
fd13c7ccc0
Additional metadata for soc
2022-12-05 09:03:22 -05:00
Mike Reeves
7e102949a6
Merge pull request #9268 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update init.sls
2022-12-02 12:58:12 -05:00
Mike Reeves
f083b3867b
Update init.sls
2022-12-02 09:40:35 -05:00
Mike Reeves
55444288bc
Merge pull request #9254 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update filecheck
2022-11-30 11:04:18 -05:00
Mike Reeves
f83545c556
Update filecheck
2022-11-30 11:02:56 -05:00
weslambert
117a3d486a
Merge pull request #9210 from Security-Onion-Solutions/fix/add_missing_opcua_activate_session_pipelines_2_4
...
Add Missing OPCUA Activate Session Pipelines
2022-11-22 16:01:45 -05:00
Wes
7f324bc47e
Remove extra space used during testing
2022-11-22 20:52:08 +00:00
Wes
a6bc5b108f
Add missing OPCUA 'activate_session' pipelines
2022-11-22 20:51:44 +00:00
weslambert
090f8309c2
Merge pull request #9207 from Security-Onion-Solutions/fix/ingest_typos_2_4
...
Fix spelling of 'wireguard.responses' field name
2022-11-22 15:36:04 -05:00
m0duspwnens
b95a83b016
Merge remote-tracking branch 'remotes/origin/2.4/dev' into dockerips
2022-11-22 14:17:19 -05:00
m0duspwnens
b05839bb93
use single quote
2022-11-22 13:07:58 -05:00
weslambert
356904f751
Fix spelling of 'wireguard.responses' field name
2022-11-22 13:03:04 -05:00
weslambert
f9cc7888f4
Merge pull request #9204 from Security-Onion-Solutions/fix/ics_ingest_field_names_2_4
...
Fix ICS Ingest Field Names
2022-11-22 12:30:17 -05:00
weslambert
6b77843e52
Fix format/speliing for 'enip.status_code' field name
2022-11-22 12:07:55 -05:00
weslambert
13faf63770
Fix spelling for 'stun.class' field name
2022-11-22 12:07:15 -05:00
m0duspwnens
6d89d58c50
ensure createrepo and yum-utils is installed from so repo
2022-11-22 11:10:30 -05:00
m0duspwnens
4b6b42f9b9
dont try to add sosnet if it exists
2022-11-22 10:19:18 -05:00
weslambert
b801997709
Merge pull request #9196 from Security-Onion-Solutions/fix/missing_ics_pipelines_2_4
...
Add COTP and TDS ingest pipelines
2022-11-22 08:44:19 -05:00
Wes
a38e312df4
Add COTP and TDS ingest pipelines
2022-11-22 13:36:27 +00:00
weslambert
bde899e7cb
Merge pull request #9194 from Security-Onion-Solutions/fix/ics_tag_syntax_error_2_4
...
Fix syntax error for 'ics' tag logic
2022-11-22 07:32:54 -05:00
weslambert
d2bc1a5523
Fix syntax error for 'ics' tag logic
2022-11-22 07:24:54 -05:00
weslambert
68efd817e0
Merge pull request #9189 from Security-Onion-Solutions/feature/filebeat_config_ics_event_tag_2_4
...
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 17:06:14 -05:00
weslambert
fe180d5657
Fix indentation
2022-11-21 17:02:17 -05:00
weslambert
9994d47a43
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 16:46:47 -05:00
Doug Burks
6e1e6e15e8
Merge pull request #9186 from Security-Onion-Solutions/dougburks-patch-2
...
Add ICS/SCADA logs to filebeat defaults.yaml
2022-11-21 13:30:35 -05:00
Doug Burks
febb781428
Add ICS/SCADA logs to filebeat defaults.yaml
2022-11-21 12:10:55 -05:00
weslambert
061f0b0595
Merge pull request #9159 from Security-Onion-Solutions/feature/additional_ics_scada_ingest_pipelines_2_4
...
Add additional ICS/SCADA ingest node pipelines
2022-11-21 10:32:00 -05:00
Doug Burks
5a0fe6050b
Merge pull request #9179 from Security-Onion-Solutions/dougburks-patch-2
...
Simplify version in README.md to just 2.4
2022-11-21 08:46:33 -05:00
Doug Burks
778ee4b00f
Simplify version in README.md to just 2.4
2022-11-21 08:39:18 -05:00
Jason Ertel
5f59ae52d5
Merge pull request #9162 from Security-Onion-Solutions/config
...
Config
2022-11-17 11:50:35 -05:00
Wes
05b9a067fd
Add additional ICS/SCADA ingest node pipelines
2022-11-17 16:03:21 +00:00
Jason Ertel
ed9aa5b73f
Ensure filecheck is up by checking every minute
2022-11-17 10:48:53 -05:00
Jason Ertel
7f7e5474ed
Add more logging for filecheck monitoring, and ensure scripts are accessible to salt-relay
2022-11-17 10:43:05 -05:00
Jason Ertel
0ffef75d7b
Move background jobs to cron
2022-11-17 09:50:41 -05:00
Jason Ertel
c572848ece
temporarily remove filecheck for debug purposes
2022-11-17 08:06:24 -05:00
Jason Ertel
7cd5d625d1
temporarily remove salt-pipe for debug purposes
2022-11-16 20:45:50 -05:00
Jason Ertel
4497037442
Use bg:True to send cmd to background
2022-11-16 20:03:54 -05:00
weslambert
c14c8c1306
Merge pull request #9154 from Security-Onion-Solutions/fix/ics_scada_ingest_pipeline_updates_2_4
...
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 16:17:19 -05:00
Wes
638a3568b0
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 21:11:21 +00:00
m0duspwnens
d97e13b473
add /24 back to default bip, rever daemon.json
2022-11-16 14:47:40 -05:00
m0duspwnens
a3b505971b
remove /24 from docker bip
2022-11-16 12:51:43 -05:00
Josh Brower
98af16055c
Merge pull request #9151 from Security-Onion-Solutions/2.4/elasticfleet-ag
...
Initial support for Elastic Fleet Package Registry
2022-11-16 08:45:29 -05:00
Josh Brower
8db49feb32
Use our docker image
2022-11-16 08:24:25 -05:00
m0duspwnens
9ffde8bff5
ensure options are strings
2022-11-15 17:46:08 -05:00
m0duspwnens
19f043cfe2
add some options for sosnet
2022-11-15 17:39:08 -05:00
m0duspwnens
54e4749ddf
remove comma
2022-11-15 17:30:55 -05:00
m0duspwnens
d246aa6a80
we dont need default network config
2022-11-15 17:14:33 -05:00
m0duspwnens
75825617da
add soc to sosnet
2022-11-15 17:13:25 -05:00
m0duspwnens
edd993fd82
change dupe soc to elastalert
2022-11-15 16:02:17 -05:00
Mike Reeves
813e59aa61
Add statics
2022-11-15 13:23:35 -05:00
Josh Brower
48d191b656
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/elasticfleet-ag
2022-11-15 12:13:05 -05:00
Josh Patterson
a371c89f38
Update top.sls
2022-11-15 11:52:51 -05:00
Josh Patterson
1c242fb7f3
Update top.sls
2022-11-15 11:52:25 -05:00
Josh Patterson
c0afcca87a
Update init.sls
2022-11-15 11:16:18 -05:00
Mike Reeves
591616fe5b
Add statics to all containers
2022-11-15 11:05:17 -05:00
Mike Reeves
efc8621524
Fix some settings and add all defaults
2022-11-15 10:31:37 -05:00
Mike Reeves
6016b0e38a
Add dynamic ability for IP range for sosnet
2022-11-14 20:20:38 -05:00
Mike Reeves
e41361e127
Add Docker IP Skeleton
2022-11-14 17:43:14 -05:00
Mike Reeves
a40e10da83
Add Docker IP Skeleton
2022-11-14 17:41:38 -05:00
Mike Reeves
3378f58300
Add Docker IP Skeleton
2022-11-14 17:07:42 -05:00
Mike Reeves
a2d3b95e92
Add Docker IP Skeleton
2022-11-14 13:04:31 -05:00
Mike Reeves
5c50fdb74c
Add Docker IP Skeleton
2022-11-14 13:00:56 -05:00
Mike Reeves
f1135342a9
Add Docker IP Skeleton
2022-11-14 11:17:48 -05:00
Doug Burks
a2da8e5e08
Merge pull request #9129 from Security-Onion-Solutions/dougburks-patch-1
...
fix descriptions in files related to analyzers
2022-11-12 19:26:34 +00:00
Doug Burks
632464335f
fix descriptions in files related to analyzers
2022-11-12 13:14:02 -05:00
Doug Burks
f77db78219
fix descriptions in files related to analyzers
2022-11-12 13:13:30 -05:00
Doug Burks
2f4ce91678
fix descriptions in files related to analyzers
2022-11-12 13:12:58 -05:00
Doug Burks
154dff98de
fix descriptions in files related to analyzers
2022-11-12 13:12:23 -05:00
Doug Burks
a15ca3cc49
fix descriptions in files related to analyzers
2022-11-12 13:11:38 -05:00
Doug Burks
a6ad7fa3ac
Merge pull request #9125 from Security-Onion-Solutions/dougburks-patch-2
...
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 21:33:43 +00:00
Doug Burks
40f5bb25ef
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 16:28:23 -05:00
Josh Patterson
7420c31411
Merge pull request #9096 from Security-Onion-Solutions/salt3005.1_2.4
...
roll back to salt 3004.2
2022-11-08 15:47:00 -05:00
m0duspwnens
00cb0f5abb
roll back to salt 3004.2
2022-11-08 15:45:18 -05:00
Mike Reeves
bf31b593ed
Merge pull request #9055 from Security-Onion-Solutions/strelkastuff
...
Strelkastuff
2022-11-08 13:45:42 -05:00
Josh Patterson
4870b4b91f
Merge pull request #9095 from Security-Onion-Solutions/salt3005.1_2.4
...
upgrade to salt 3005.1
2022-11-08 13:45:24 -05:00
m0duspwnens
1a678064dc
upgrade to salt 3005.1
2022-11-08 13:42:24 -05:00
Josh Brower
c389944e5c
Initial support for Elastic Package Registry
2022-11-08 09:56:53 -05:00
Mike Reeves
de19a4dc53
Add Strelka Filecheck
2022-11-02 10:04:33 -04:00
Mike Reeves
d97de9fd0d
Add Strelka Filecheck
2022-11-02 10:02:21 -04:00
Mike Reeves
bf5df1ac51
Add Strelka Filecheck
2022-11-02 09:57:07 -04:00
Mike Reeves
225c33e5c9
Add Strelka Filecheck
2022-11-02 09:46:23 -04:00
Mike Reeves
4187363451
Add Strelka Filecheck
2022-11-02 09:44:08 -04:00
Doug Burks
f3fc52dd2c
Merge pull request #9041 from Security-Onion-Solutions/dougburks-patch-1
...
https://github.com/Security-Onion-Solutions/securityonion/pull/8952
2022-11-01 13:40:51 +00:00
Doug Burks
2030f08b54
https://github.com/Security-Onion-Solutions/securityonion/pull/8952
2022-11-01 09:35:53 -04:00
Jason Ertel
55f22af758
Merge pull request #9017 from Security-Onion-Solutions/config
...
Retry so-user commands if another process is currently using so-user
2022-10-27 15:41:37 -04:00
Jason Ertel
35fab05bdd
Retry so-user commands if another process is currently using so-user
2022-10-27 15:25:08 -04:00
Jason Ertel
d7b370e31b
Merge pull request #9010 from Security-Onion-Solutions/config
...
regex should match entire input against allowed logLevel values
2022-10-27 13:17:51 -04:00
Josh Patterson
c6ebe5c8dd
Merge pull request #9016 from Security-Onion-Solutions/patch2.4
...
Patch2.4
2022-10-27 13:07:54 -04:00
m0duspwnens
8af0334c3c
Merge remote-tracking branch 'remotes/origin/2.4/dev' into patch2.4
2022-10-27 11:08:32 -04:00
m0duspwnens
6525e0f201
setup no longer add patch pillar to minion
2022-10-27 10:56:29 -04:00
m0duspwnens
a95c2a690a
add defaults and map for patch state
2022-10-27 10:54:29 -04:00
Jason Ertel
6347532dd8
regex should match entire input against allowed logLevel values
2022-10-26 18:48:20 -04:00
weslambert
8b0ea7104f
Merge pull request #9003 from Security-Onion-Solutions/fix/remove_ja3er_references
...
Remove JA3er references
2022-10-26 10:37:45 -04:00
weslambert
0ede5a7313
Remove JA3er references
2022-10-26 10:24:25 -04:00
weslambert
409b8c276e
Merge pull request #8999 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Fix PyYAML .whl file name and remove JA3er analyzer
2022-10-25 15:32:20 -04:00
Wes
803d2d4d75
Add PyYAML .whl files back since they were 'deleted' in the previous commit
2022-10-25 19:15:54 +00:00
Wes
0267ece4bf
Fix PyYAML .whl file name and remove JA3er analyzer
2022-10-25 19:11:52 +00:00
Josh Patterson
d148febc99
Merge pull request #8967 from Security-Onion-Solutions/curator2.4
...
add line space
2022-10-21 11:56:01 -04:00
m0duspwnens
8c5197c2ea
add line space
2022-10-21 11:49:01 -04:00
Josh Patterson
8197017b6c
Merge pull request #8966 from Security-Onion-Solutions/curator2.4
...
Curator2.4
2022-10-21 11:26:51 -04:00
m0duspwnens
8b5c79fb39
add so-kratos and so-ossec to curator defaults
2022-10-21 11:21:03 -04:00
m0duspwnens
71eaa715b6
update jinja
2022-10-21 11:09:52 -04:00
m0duspwnens
c880be8d45
use curator defaults.yaml merged with pillar for actions
2022-10-21 10:38:32 -04:00
Josh Patterson
3af271a13c
Merge pull request #8930 from Security-Onion-Solutions/statesglobals
...
Statesglobals
2022-10-17 16:06:42 -04:00
m0duspwnens
998870ac87
Merge remote-tracking branch 'remotes/origin/2.4/dev' into statesglobals
2022-10-17 15:58:44 -04:00
m0duspwnens
b089a58243
use registry_host instead of manager
2022-10-17 15:53:29 -04:00
m0duspwnens
09b7af2998
fix typo
2022-10-17 15:50:48 -04:00
m0duspwnens
deba743ef0
fix elasticsearch auth globals
2022-10-13 13:54:52 -04:00
m0duspwnens
04b4030eb6
only add elasticsearch.auth to elasticsearch global var if auth exists
2022-10-13 12:31:41 -04:00
Doug Burks
7ede0c3c76
Merge pull request #8915 from Security-Onion-Solutions/dougburks-patch-2
...
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 13:04:23 +00:00
Doug Burks
f6151b3895
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 09:03:10 -04:00
Jason Ertel
fd6bea92da
Merge pull request #8913 from Security-Onion-Solutions/config
...
retry up to 25 minutes if APT is locked by an unattended upgrade. This is an increase from 8 minutes.
2022-10-13 07:01:00 -04:00
Jason Ertel
1c23d91a3b
retry up to 25 minutes if APT is locked by an unattended upgrade. This is an increase from 8 minutes.
2022-10-13 06:57:17 -04:00
m0duspwnens
78b496a689
fix mine_functions.conf
2022-10-12 16:03:44 -04:00
m0duspwnens
95f7cb6bcd
change file_mode to mode
2022-10-12 14:21:55 -04:00
m0duspwnens
eed3746ebc
fix some globals
2022-10-12 13:39:37 -04:00
m0duspwnens
6a17f201a2
changes for backup state
2022-10-12 11:31:42 -04:00
weslambert
078213ddb3
Merge pull request #8898 from Security-Onion-Solutions/feature/elastic-agent-configuration-log-package
...
Add log package for Fleet to allow for custom log ingestion
2022-10-11 12:14:15 -04:00
weslambert
dd09ce7aab
Add log package for Fleet to allow for custom log ingestion
2022-10-11 12:00:57 -04:00
m0duspwnens
b526532ab6
use global vars in states
2022-10-11 11:57:15 -04:00
Doug Burks
2c5038aa9c
Merge pull request #8879 from Security-Onion-Solutions/2.4/improve-sysmon-dashboards
...
improve sysmon dashboards
2022-10-07 16:46:51 +00:00
doug
d65fde9536
improve sysmon dashboards
2022-10-07 12:23:40 -04:00
weslambert
8437592bb5
Merge pull request #8869 from Security-Onion-Solutions/feature/elastic-8.4.3
...
Elastic 8.4.3
2022-10-06 16:03:36 -04:00
weslambert
bee1b06f76
Update to Kibana 8.4.3
2022-10-06 15:14:43 -04:00
weslambert
985e1728d7
Update to Kibana 8.4.3
2022-10-06 15:13:27 -04:00
Mike Reeves
46bdd1acad
Merge pull request #8837 from Security-Onion-Solutions/config
...
Add SOC annotations
2022-10-03 08:46:46 -04:00
Jason Ertel
0fdec03fa9
use yaml anchor to avoid duplicated annotations
2022-09-30 15:15:35 -04:00
Jason Ertel
30a23a4cd0
Add SOC annotations
2022-09-30 15:00:08 -04:00
Jason Ertel
fe62744c05
Merge pull request #8825 from Security-Onion-Solutions/config
...
resolve inode issue with soc_users_roles when deleting a user; other minor improvements
2022-09-27 17:38:20 -04:00
Jason Ertel
5708f3595e
Avoid overwriting the file inode since it's mapped into a running container
2022-09-27 17:27:28 -04:00
Jason Ertel
e519548557
add logLevel default and annotation for quick access to enabling debug logs
2022-09-27 16:55:28 -04:00
Jason Ertel
981371c72f
log salt-relay responses for troubleshooting assistance
2022-09-27 16:48:47 -04:00
Jason Ertel
16d24d4bc9
Merge pull request #8822 from Security-Onion-Solutions/config
...
user management / sync
2022-09-27 11:14:32 -04:00
Jason Ertel
53b4f01921
replace quotes on minion arg
2022-09-27 10:54:08 -04:00
Jason Ertel
851e44e5fa
ensure salt-relay is restarted when SOC is manually restarted
2022-09-27 10:31:14 -04:00
Jason Ertel
7f7f2c15d0
add support for querying active salt jobs (future use)
2022-09-27 10:29:21 -04:00
Josh Patterson
004fa8167e
Merge pull request #8821 from Security-Onion-Solutions/fix/soc2.4
...
Fix/soc2.4
2022-09-27 10:15:04 -04:00
m0duspwnens
6bd4860f19
fix path
2022-09-27 09:57:01 -04:00
m0duspwnens
42b03ca6df
add missing soc things
2022-09-27 09:53:48 -04:00
Jason Ertel
556ddc2ee4
sync in background
2022-09-27 09:24:34 -04:00
Jason Ertel
8e175b2d3f
add manual sync
2022-09-27 07:05:04 -04:00
Mike Reeves
e032a9f449
Merge pull request #8816 from Security-Onion-Solutions/funstuff
2022-09-26 18:15:14 -04:00
Mike Reeves
2066efcabf
Add Rules to sync
2022-09-26 17:18:28 -04:00
Mike Reeves
37c98c14cd
Fix zeek logs in filebeat
2022-09-26 17:11:10 -04:00
Mike Reeves
aa7dd47b00
Fix zeek logs in filebeat
2022-09-26 17:01:44 -04:00
Doug Burks
ea8d9362ae
Merge pull request #8813 from Security-Onion-Solutions/dougburks-patch-1
...
Change managing-rules.html to rules.html in soc_idstools.yaml
2022-09-26 19:00:41 +00:00
Doug Burks
80201f1465
Change managing-rules.html to rules.html in soc_idstools.yaml
2022-09-26 14:58:51 -04:00
Jason Ertel
0ad1a1a262
so-user and salt-relay updates for user management
2022-09-26 14:57:33 -04:00
Doug Burks
1b13e454f8
Merge pull request #8812 from Security-Onion-Solutions/2.4/dev-fix-screenshots
...
fix screenshots in README.md
2022-09-26 17:49:10 +00:00
doug
97a6b3c2f3
fix screenshots
2022-09-26 13:46:46 -04:00
Josh Brower
97f42dcce5
Merge pull request #8811 from Security-Onion-Solutions/2.4/elastic-fleet
...
Live Query - View in Hunt fix
2022-09-26 09:35:12 -04:00
Josh Brower
a0b579019f
Live Query - View in Hunt fix
2022-09-26 09:27:09 -04:00
Doug Burks
4e5eb1cbb8
Merge pull request #8807 from Security-Onion-Solutions/2.4/dev-ocd
...
initial quick OCD pass
2022-09-23 20:39:54 +00:00
doug
fee5a7bea9
initial quick OCD pass
2022-09-23 16:29:55 -04:00
Josh Brower
d698238ed1
Merge pull request #8799 from Security-Onion-Solutions/2.4/elastic-fleet
...
Live Query - View in Hunt link
2022-09-23 15:00:32 -04:00
Mike Reeves
e3f4a58989
Merge pull request #8804 from Security-Onion-Solutions/funstuff
...
Firewall and More
2022-09-23 14:00:51 -04:00
Mike Reeves
d26be44df1
update soc_firewall.yaml
2022-09-23 13:09:46 -04:00
Mike Reeves
3e2be096be
update soc_firewall.yaml
2022-09-23 13:08:03 -04:00
Mike Reeves
2b9322b823
Helps if you add the IP address
2022-09-23 08:52:58 -04:00
Josh Patterson
02f1d24ea6
remove minion hg
2022-09-23 08:40:25 -04:00
Josh Patterson
975c7fabcc
remove minion hg
2022-09-23 08:39:48 -04:00
Josh Patterson
5e32e333c4
remove minion hg
2022-09-23 08:37:59 -04:00
Josh Brower
c7eccfd0c5
Live Query - View in Hunt link
2022-09-22 20:17:57 -04:00
Mike Reeves
a7872234ab
Remove NTP from setup
2022-09-22 17:07:00 -04:00
Mike Reeves
4b059ce7fb
Firewall Changes
2022-09-22 17:04:18 -04:00
Mike Reeves
75b058c37f
Firewall Changes
2022-09-22 17:03:03 -04:00
Mike Reeves
f9c77900ae
Firewall Changes
2022-09-22 16:54:57 -04:00
Mike Reeves
81f79c3a02
Firewall Changes
2022-09-22 16:33:08 -04:00
Josh Patterson
3100efc954
fix syntax
2022-09-22 16:03:12 -04:00
Mike Reeves
4eebd855ac
Firewall Changes
2022-09-22 15:47:16 -04:00
m0duspwnens
abee5afd7b
adjust standalone firewall assigned_hostgroups
2022-09-22 15:40:52 -04:00
m0duspwnens
06d3681cec
2.4/firewall
2022-09-22 13:39:10 -04:00
weslambert
49dace66de
Merge pull request #8796 from Security-Onion-Solutions/fix/elasticsearch_fleet_component_template_syntax
...
Fix syntax for Fleet component templates
2022-09-22 11:14:16 -04:00
Wes
0fd5fee868
Fix syntax for Fleet component templates
2022-09-22 15:07:43 +00:00
m0duspwnens
c77fcc74c1
merge in 2.4./firewall changes
2022-09-22 10:55:39 -04:00
m0duspwnens
2995ae32bd
2.4 fw changes
2022-09-22 10:49:26 -04:00
weslambert
e35c77be62
Merge pull request #8785 from Security-Onion-Solutions/fix/elasticsearch_component_templates_fleet_main
...
Add additional component templates for Fleet and fix references for Elastic Agent index templates in defaults.yaml
2022-09-20 17:02:02 -04:00
Wes
46dd4c2749
Rename component mappings and references for Security Onion
2022-09-20 20:33:06 +00:00
Josh Patterson
f0ddfecd42
Merge pull request #8784 from Security-Onion-Solutions/2.4/zeek
...
2.4/zeek
2022-09-20 16:28:40 -04:00
Wes
7f2c5bc757
Add component templates for Fleet
2022-09-20 20:27:26 +00:00
m0duspwnens
e1ea3c2031
soc for zeek
2022-09-20 16:22:54 -04:00
Mike Reeves
85339d7cb1
Add helpLinks to everything
2022-09-20 15:43:34 -04:00
Doug Burks
8a537204d6
Merge pull request #8783 from Security-Onion-Solutions/2.4/fix-docs-links
...
fix docs links
2022-09-20 19:34:01 +00:00
m0duspwnens
1685e0e6db
few more
2022-09-20 15:25:50 -04:00
Doug Burks
0137004344
Fix releaseNotesUrl in defaults.yaml
2022-09-20 15:16:53 -04:00
Doug Burks
530c497800
Update motd.md
2022-09-20 15:16:04 -04:00
Doug Burks
0eafed32a4
Update docs links in README.md
2022-09-20 15:13:14 -04:00
Mike Reeves
097c05b114
Cleanup on aisle 4
2022-09-20 13:49:26 -04:00
Mike Reeves
0ade4d7847
Adjust portgroup yaml
2022-09-20 13:45:29 -04:00
Mike Reeves
b622940f3f
Remvoe NTP from setup
2022-09-20 13:32:41 -04:00
Mike Reeves
555bd678fb
Change Firewall Pillar Structure
2022-09-20 13:28:32 -04:00
Mike Reeves
27a9edbef7
Change Firewall Pillar Structure
2022-09-20 13:20:16 -04:00
m0duspwnens
75aa121b2d
fix some things
2022-09-20 13:19:15 -04:00
Doug Burks
bc57a74ac8
Merge pull request #8782 from Security-Onion-Solutions/dougburks-patch-1
...
change version to 2.4.0
2022-09-20 16:52:39 +00:00
Doug Burks
aadce055d1
change version to 2.4.0
2022-09-20 12:49:14 -04:00
Mike Reeves
678d5c5c9c
Replace so-firewall
2022-09-20 11:22:20 -04:00
m0duspwnens
29285b8fb1
fix conflixt in zeek/init.sls
2022-09-20 11:12:44 -04:00
m0duspwnens
d1ee3a7d04
zeek 2.4
2022-09-20 11:11:29 -04:00
Mike Reeves
9fffe1b5fa
Replace so-firewall
2022-09-20 11:11:19 -04:00
Doug Burks
8c88285365
Merge pull request #8780 from Security-Onion-Solutions/2.4/sysmon-fix-bryant
...
2.4/sysmon fix bryant
2022-09-20 14:32:35 +00:00
Doug Burks
df18f8f886
Merge pull request #8779 from Security-Onion-Solutions/2.4/dev
...
2.4/dev
2022-09-20 13:32:54 +00:00
Josh Brower
0815b607e6
Merge pull request #8778 from Security-Onion-Solutions/2.4/elastic-fleet
...
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-20 08:29:47 -04:00
Josh Brower
120fdef173
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-20 08:27:47 -04:00
Josh Brower
da8d09713f
Merge pull request #8776 from Security-Onion-Solutions/2.4/elastic-fleet
...
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-20 06:20:51 -04:00
Josh Brower
3eb4adc5c3
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-19 20:12:47 -04:00
Mike Reeves
512c044d80
Thresholding
2022-09-19 16:53:51 -04:00
weslambert
d4fb78fe3b
Merge pull request #8775 from Security-Onion-Solutions/fix/elasticsearch_elastic_agent_index_templates_load
...
Update so-elasticsearch-templates-load to allow for proper loading of differently formatted Elastic Agent index templates
2022-09-19 16:44:21 -04:00
weslambert
509c32482f
Update so-elasticsearch-templates-load to allow for proper loading of differently formatted Elastic Agent index templates
2022-09-19 16:39:49 -04:00
Mike Reeves
a1aae627a2
Merge pull request #8771 from Security-Onion-Solutions/funstuff
...
Add NTP and NGINX
2022-09-19 16:33:05 -04:00
Mike Reeves
e72eae2e8a
NGINX fun
2022-09-19 16:23:46 -04:00
Mike Reeves
fad0e0a145
NGINX fun
2022-09-19 16:14:37 -04:00
Mike Reeves
cb2e46f275
NGINX fun
2022-09-19 16:11:49 -04:00
Josh Brower
b38804840d
Merge pull request #8772 from Security-Onion-Solutions/2.4/grafana-ids
...
Grafana SOC Redirect
2022-09-19 16:02:41 -04:00
Josh Brower
80919827c6
Fixup index patterns
2022-09-19 15:55:23 -04:00
Josh Patterson
0367365225
Merge pull request #8773 from Security-Onion-Solutions/fix/soc2.4
...
fix some soc defaults
2022-09-19 15:54:25 -04:00
m0duspwnens
30afc88322
fix some soc defaults
2022-09-19 15:51:29 -04:00
Josh Brower
ea7979cfdd
Add Elastic Agent datastreams to SOC index
2022-09-19 15:33:15 -04:00
m0duspwnens
79785fc053
zeek jinja
2022-09-19 15:26:32 -04:00
Mike Reeves
22e8c7ef3e
Add NTP
2022-09-19 15:10:11 -04:00
Mike Reeves
2abfcdc042
Add NTP
2022-09-19 14:48:40 -04:00
doug
fdffac83e1
sysmon fix by bryant
2022-09-19 14:47:45 -04:00
Mike Reeves
17cbe38c25
Add NTP
2022-09-19 14:32:29 -04:00
Mike Reeves
74ccf333e0
Add NTP
2022-09-19 14:30:23 -04:00
Mike Reeves
44be7b4969
Add NTP
2022-09-19 14:26:16 -04:00
Mike Reeves
03ea714dc1
Add NTP
2022-09-19 14:06:46 -04:00
Mike Reeves
f7e614f358
Add NTP
2022-09-19 14:06:30 -04:00
Josh Brower
d28a9ecec2
Set Dashboard UUID
2022-09-19 13:32:04 -04:00
weslambert
4c2ac9dd93
Merge pull request #8770 from Security-Onion-Solutions/fix/elasticsearch_cluster_settings
...
Re-establish Elasticsearch cluster (search) settings
2022-09-19 12:10:55 -04:00
Wes
9095bc2205
Re-establish Elasticsearch cluster (search) settings
2022-09-19 15:41:54 +00:00
Mike Reeves
0a885221e8
Merge pull request #8769 from Security-Onion-Solutions/funstuff
...
Firewall and Sensoroni Fix
2022-09-19 11:05:46 -04:00
Mike Reeves
32034078fa
Fix sensoroni Agent
2022-09-19 10:48:36 -04:00
Mike Reeves
aa8ce074f7
Fix sensoroni Agent
2022-09-19 10:43:05 -04:00
Mike Reeves
04a0be8247
Merge branch '2.4/dev' into funstuff
2022-09-19 10:41:53 -04:00
Mike Reeves
e3e6e7b4e8
Fix sensoroni Agent
2022-09-19 10:41:01 -04:00
Jason Ertel
21f8b3b61c
Merge pull request #8768 from Security-Onion-Solutions/config
...
refactor sostatus telegraf input script
2022-09-19 10:35:22 -04:00
Jason Ertel
ae6fbab45d
refactor sostatus telegraf input script
2022-09-19 10:27:20 -04:00
Mike Reeves
f4508aa534
Fix sensoroni Agent
2022-09-19 10:22:32 -04:00
Mike Reeves
61f3479d92
Merge branch '2.4/dev' into funstuff
2022-09-19 09:40:27 -04:00
Mike Reeves
9bdb364122
Firewall Fun
2022-09-19 09:39:42 -04:00
Jason Ertel
f2b09c84d4
Merge pull request #8767 from Security-Onion-Solutions/config
...
Config
2022-09-19 09:18:10 -04:00
Jason Ertel
7d965b5cda
Ensure so-status does not get jinjafied
2022-09-19 09:17:06 -04:00
Jason Ertel
b4add5ebb3
Merge pull request #8766 from Security-Onion-Solutions/config
...
complete rewrite of so-status
2022-09-19 07:40:51 -04:00
Mike Reeves
d7585e1b3d
Firewall Fun
2022-09-17 10:03:18 -04:00
Mike Reeves
4a68a5e054
Firewall Fun
2022-09-17 09:57:43 -04:00
Mike Reeves
98ae6149dc
Firewall Fun
2022-09-17 09:54:20 -04:00
Mike Reeves
e717579113
Firewall Fun
2022-09-17 09:51:26 -04:00
Mike Reeves
8a26b3fa04
Firewall Fun
2022-09-17 09:47:15 -04:00
Mike Reeves
724d5d952a
Firewall Fun
2022-09-17 09:46:07 -04:00
Mike Reeves
b6a1040090
Firewall Fun
2022-09-17 09:42:35 -04:00
Mike Reeves
f3056c7057
Firewall Fun
2022-09-17 09:39:49 -04:00
Mike Reeves
4b1031efa4
Firewall Fun
2022-09-17 09:34:35 -04:00
Jason Ertel
9542a5ada2
complete rewrite of so-status
2022-09-16 17:46:52 -04:00
weslambert
0a8aae8180
Merge pull request #8757 from Security-Onion-Solutions/fix/elastic_agent_templates_managed_by_securityonion
...
Change managed_by value from 'fleet' to 'security_onion' for Elastic Agent templates in defaults.yaml
2022-09-16 17:20:03 -04:00
Wes
12e940f809
Change managed_by value from 'fleet' to 'security_onion' for Elastic Agent templates in defaults.yaml
2022-09-16 20:55:49 +00:00
Mike Reeves
d02c6808a4
Firewall Fun
2022-09-16 13:44:54 -04:00
Mike Reeves
1c9069690f
Firewall Fun
2022-09-16 13:38:07 -04:00
Mike Reeves
0eb6388ea3
Firewall Fun
2022-09-16 13:34:11 -04:00
Mike Reeves
6649ffd8b5
Firewall Fun
2022-09-16 13:33:26 -04:00
Mike Reeves
70c95c7c7b
Firewall Fun
2022-09-16 13:31:23 -04:00
Mike Reeves
bc1921bd0e
Firewall Fun
2022-09-16 13:30:07 -04:00
Josh Brower
eba82553a1
Merge pull request #8755 from Security-Onion-Solutions/2.4/tls
...
Change ssl_ecdh_curve
2022-09-16 13:28:35 -04:00
Mike Reeves
384478836a
Firewall Fun
2022-09-16 13:02:11 -04:00
Mike Reeves
f14a8f3d01
Firewall Fun
2022-09-16 12:55:56 -04:00
Mike Reeves
943b98f091
IDS Tools rule management
2022-09-16 11:16:05 -04:00
Mike Reeves
f9e9e4ce1d
IDS Tools rule management
2022-09-16 11:14:09 -04:00
Mike Reeves
ae5eea6e3a
IDS Tools rule management
2022-09-16 11:12:03 -04:00
Mike Reeves
5e151a9fed
Fix minion pillar for remote sensors
2022-09-16 10:43:36 -04:00
Mike Reeves
958d2494a8
Zeek Test
2022-09-16 10:27:42 -04:00
Mike Reeves
2a51ecb1ac
Zeek Test
2022-09-16 09:10:09 -04:00
Josh Brower
d5debd9b6b
Change ssl_ecdh_curve
2022-09-16 09:06:09 -04:00
Mike Reeves
f02db7a815
Zeek Test
2022-09-16 09:05:16 -04:00
Mike Reeves
58ab91ea84
Add BPF
2022-09-16 08:50:17 -04:00
Mike Reeves
9a6fe3e8de
Add BPF
2022-09-16 08:36:44 -04:00
Mike Reeves
2c0d90bea4
Make test ping retry
2022-09-15 17:07:02 -04:00
Mike Reeves
c50a1608af
Make test ping retry
2022-09-15 17:01:53 -04:00
weslambert
6212a288e4
Merge pull request #8752 from Security-Onion-Solutions/fix/logstash_remove_osquery_livequery_output_configuration
...
Remove Osquery live query Logstash output configuration
2022-09-15 15:53:49 -04:00
Mike Reeves
e6c0c2ce19
Modify Steno Config
2022-09-15 15:46:28 -04:00
Wes
1a90eeb1b1
Remove Osquery live query Logstash output configuration
2022-09-15 19:45:28 +00:00
m0duspwnens
5a9b3f6821
fix diskfreepercantage
2022-09-15 15:39:31 -04:00
m0duspwnens
62f5ee04a4
fix source for steno config
2022-09-15 15:13:40 -04:00
m0duspwnens
52b58ad6ae
jinja for steno/pcap
2022-09-15 15:12:40 -04:00
Mike Reeves
9a75d939b4
Modify Steno Config
2022-09-15 13:55:39 -04:00
Mike Reeves
3286d55ef2
Modify Steno Config
2022-09-15 13:46:14 -04:00
Mike Reeves
c49c7348ff
Merge pull request #8751 from Security-Onion-Solutions/funstuff
...
Funstuff
2022-09-15 13:15:51 -04:00
Mike Reeves
7d6e847f86
Fix Zeek PIllar
2022-09-15 13:11:03 -04:00
Mike Reeves
73d45bd9fc
Update defaults for Steno
2022-09-15 12:56:02 -04:00
Mike Reeves
383714ec06
Fix pcap error
2022-09-15 12:38:55 -04:00
Mike Reeves
4357f013f0
Merge pull request #8748 from Security-Onion-Solutions/funstuff
...
Fix setup error
2022-09-15 11:12:21 -04:00
Mike Reeves
2e4f122e57
Fix setup error
2022-09-15 11:10:33 -04:00
Mike Reeves
b93c38759b
Merge pull request #8747 from Security-Onion-Solutions/funstuff
...
Fix setup error
2022-09-15 10:58:59 -04:00
Mike Reeves
8e99e02787
Fix setup error
2022-09-15 10:57:52 -04:00
Mike Reeves
1c00344327
Merge pull request #8746 from Security-Onion-Solutions/funstuff
...
Fix for Suricata
2022-09-15 10:53:22 -04:00
Mike Reeves
0351ef4ff5
Fix Suricata analyzers list
2022-09-15 10:48:08 -04:00
m0duspwnens
845d2e33bd
remove dupe afpacket
2022-09-15 10:44:39 -04:00
m0duspwnens
4cb955fe8d
jinja for the suricata outputs
2022-09-15 10:35:59 -04:00
Josh Brower
99f54acef1
Merge pull request #8742 from Security-Onion-Solutions/2.4/elastic-fleet
...
2.4/elastic fleet
2022-09-15 07:16:37 -04:00
Josh Brower
bdfde669f3
remove outdated scripts
2022-09-14 18:38:08 -04:00
Josh Brower
798b39ec09
elastic-fleet so-status & restart scripts
2022-09-14 18:36:26 -04:00
Mike Reeves
8528645c2c
Update suricata_config.map.jinja
2022-09-14 15:02:55 -04:00
Mike Reeves
f8c1571a91
Update suricata_config.map.jinja
2022-09-14 14:43:04 -04:00
Mike Reeves
30a469ea63
Update afpacket.map.jinja
2022-09-14 14:36:13 -04:00
Josh Brower
0c1f9eaa37
Merge pull request #8739 from Security-Onion-Solutions/2.4/elastic-fleet
...
EA Certs & image
2022-09-14 14:20:17 -04:00
Mike Reeves
90ed4fd4cb
Fix Suricata
2022-09-14 14:18:10 -04:00
Josh Brower
1c671b47d7
Run container as elastic-fleet user
2022-09-14 14:17:54 -04:00
Mike Reeves
ee59822097
Fix Suricata
2022-09-14 14:15:50 -04:00
Mike Reeves
74a8bd17ea
Fix Suricata
2022-09-14 13:56:17 -04:00
Mike Reeves
c60afba450
Fix core count
2022-09-14 12:30:22 -04:00
Mike Reeves
8049f9b9e4
Fix so-minion error for setup
2022-09-14 12:22:10 -04:00
Mike Reeves
8a5a58c647
Fix so-minion error for setup
2022-09-14 12:21:21 -04:00
Mike Reeves
547abb0fe1
Remove learn
2022-09-14 12:12:33 -04:00
Mike Reeves
be4c15877a
Improve pcap defaults
2022-09-14 11:11:21 -04:00
Mike Reeves
0a40bfcb88
Change how pcap is written to the minion file
2022-09-14 11:00:22 -04:00
Josh Brower
b7b92c73a3
add so-elastic-agent to container list
2022-09-14 11:00:16 -04:00
Josh Brower
334a0d7b1c
Start using so-elastic-agent container
2022-09-14 10:33:27 -04:00
weslambert
39c7c8cf80
Merge pull request #8738 from Security-Onion-Solutions/fix/remove_old_pipeline_config
...
Remove old Logstash pipeline configuration - initial cleanup
2022-09-14 10:30:37 -04:00
Wes
926a1e0189
Remove Snort output configuration
2022-09-14 14:22:00 +00:00
Wes
ce3ea456b6
Remove flow output configuration
2022-09-14 14:21:21 +00:00
Wes
d1a8b88eb9
Remove postprocess configuration
2022-09-14 14:20:24 +00:00
Wes
e3cd8a9c6a
Remove main pipeline configuration
2022-09-14 14:20:08 +00:00
Wes
43f89adbd4
Remove preprocess configuration
2022-09-14 14:19:07 +00:00
Mike Reeves
a4dc63f3a4
Change how zeek and suri are populated in the minion file
2022-09-14 09:53:57 -04:00
Josh Brower
6945596eee
Tweak elastic agent ssl gen
2022-09-14 08:10:42 -04:00
Josh Brower
bf14612258
Change out Elastic Fleet certs
2022-09-13 15:58:53 -04:00
Jason Ertel
0d32cc38d6
Merge pull request #8733 from Security-Onion-Solutions/config
...
Always use local docs
2022-09-13 14:40:10 -04:00
Mike Reeves
d36f2f642f
Merge pull request #8734 from Security-Onion-Solutions/funstuff
...
Updates for grafana
2022-09-13 14:39:49 -04:00
Jason Ertel
deb19d24b8
Always use local docs
2022-09-13 14:24:35 -04:00
Jason Ertel
d1eb7ef849
Always use local docs
2022-09-13 14:23:50 -04:00
Mike Reeves
064b64f68a
Add Grafana annotation
2022-09-13 14:00:04 -04:00
Mike Reeves
de047cea8e
Add Grafana annotation
2022-09-13 13:56:37 -04:00
Jason Ertel
810d89eb6c
Merge pull request #8731 from Security-Onion-Solutions/config
...
Remove comments to avoid confusing config viewers within SOC
2022-09-13 12:16:38 -04:00
Mike Reeves
8e8223b767
Merge pull request #8732 from Security-Onion-Solutions/funstuff
...
Update watermark settings
2022-09-13 12:16:17 -04:00
Mike Reeves
b38f0fa996
Update watermark settings
2022-09-13 12:13:45 -04:00
Jason Ertel
d12ff79af0
Remove comments to avoid confusing config viewers within SOC
2022-09-13 12:08:19 -04:00
Jason Ertel
8c5cba58aa
Merge pull request #8730 from Security-Onion-Solutions/config
...
Config
2022-09-13 11:52:05 -04:00
Mike Reeves
8144588534
Merge pull request #8729 from Security-Onion-Solutions/funstuff
...
Fix advanced view
2022-09-13 11:50:43 -04:00
Jason Ertel
d2fc712400
Initial SOC annotations
2022-09-13 11:49:19 -04:00
Jason Ertel
21c7f940d7
Update copyrights
2022-09-13 11:48:25 -04:00
Mike Reeves
df1a64b5e0
Modify more defaults
2022-09-13 11:45:59 -04:00
Mike Reeves
a32ff6f403
Modify Suricata defaults
2022-09-13 11:29:31 -04:00
Mike Reeves
bc2aced20d
Merge pull request #8726 from Security-Onion-Solutions/funstuff
...
Fix Typeo
2022-09-13 07:22:06 -04:00
Josh Brower
0c7ee56ee3
Merge pull request #8725 from Security-Onion-Solutions/2.4/elastic-fleet
...
Fix elastic agent gen script
2022-09-13 07:18:47 -04:00
Mike Reeves
74d991da45
Fix Typeo
2022-09-13 07:17:03 -04:00
Josh Brower
4a28841a7c
Fix elastic agent gen script
2022-09-13 06:38:05 -04:00
Mike Reeves
85e74485e7
Merge pull request #8723 from Security-Onion-Solutions/funstuff
...
Fix Dev
2022-09-12 17:43:34 -04:00
Mike Reeves
ec187e9d85
Pull in dev
2022-09-12 17:35:42 -04:00
Mike Reeves
6e052a3063
Pull in dev
2022-09-12 17:17:14 -04:00
Mike Reeves
440861998c
Merge pull request #8722 from Security-Onion-Solutions/funstuff
...
Add More Logging
2022-09-12 16:50:28 -04:00
Mike Reeves
a01fadd067
Add more logging to setup process
2022-09-12 15:56:08 -04:00
Mike Reeves
7ec66d1cd1
Add more logging to setup process
2022-09-12 15:46:33 -04:00
Mike Reeves
ea7c8e1fd9
Add more logging to setup process
2022-09-12 15:43:18 -04:00
weslambert
94f47a847d
Merge pull request #8721 from Security-Onion-Solutions/fix/elasticsearch_elastic_agent_template_defaults
...
Add back Elastic Agent default templates
2022-09-12 15:23:23 -04:00
Mike Reeves
17239ac6e4
Add more logging to setup process
2022-09-12 15:18:09 -04:00
weslambert
030f4d228a
Add back Elastic Agent default templates
2022-09-12 15:10:24 -04:00
Mike Reeves
f555846544
Add more logging to setup process
2022-09-12 15:06:29 -04:00
Mike Reeves
a168aa8b81
Add more logging to setup process
2022-09-12 14:53:34 -04:00
Mike Reeves
181e94a69d
Add more logging to setup process
2022-09-12 14:35:32 -04:00
Mike Reeves
2de2b0eb23
Add more logging to setup process
2022-09-12 14:31:10 -04:00
Mike Reeves
07263e03cb
Add more logging to setup process
2022-09-12 14:30:28 -04:00
Mike Reeves
c8a9fc2f26
Add more logging to setup process
2022-09-12 14:27:35 -04:00
Mike Reeves
9ca2e6e871
Add more logging to setup process
2022-09-12 14:20:59 -04:00
Josh Brower
905068f7bf
Merge pull request #8720 from Security-Onion-Solutions/2.4/elastic-fleet
...
Add so-elastic-agent-builder
2022-09-12 13:40:28 -04:00
Mike Reeves
2254512a2a
Add more logging to setup process
2022-09-12 12:48:02 -04:00
Josh Brower
0df7d0249a
Add so-elastic-agent-builder
2022-09-12 12:22:35 -04:00
Josh Brower
3708c9b4d9
Merge pull request #8715 from Security-Onion-Solutions/2.4/elastic-fleet
...
Add links to tools menu
2022-09-12 09:34:17 -04:00
Josh Brower
9f99939bda
Add links to tools menu
2022-09-12 09:28:10 -04:00
Josh Brower
e700a43a40
Merge pull request #8714 from Security-Onion-Solutions/2.4/elastic-fleet
...
2.4/elastic fleet
2022-09-12 08:34:28 -04:00
Mike Reeves
8b9fdef25c
Merge pull request #8708 from Security-Onion-Solutions/funstuff
2022-09-11 07:35:35 -04:00
Mike Reeves
3de4e56db9
Fix ES merge
2022-09-10 19:25:01 -04:00
Mike Reeves
a3d9b1d83b
Merge pull request #8707 from Security-Onion-Solutions/funstuff
...
Funstuff
2022-09-09 16:32:32 -04:00
Mike Reeves
f2ff8ca4e2
Create advanced files
2022-09-09 16:29:50 -04:00
Mike Reeves
9df2aaacb0
Create advanced files
2022-09-09 16:26:59 -04:00
Mike Reeves
8a7b194f2b
Create advanced files
2022-09-09 16:24:41 -04:00
Mike Reeves
57c303b9ca
Create advanced files
2022-09-09 16:23:32 -04:00
Mike Reeves
f8c6b82ed9
Merge pull request #8706 from Security-Onion-Solutions/funstuff
...
Fix yaml for idh,es,kib,esalert
2022-09-09 15:57:04 -04:00
Mike Reeves
037d5d1c46
Fix yaml for idh,es,kib,esalert
2022-09-09 15:55:51 -04:00
Mike Reeves
aa17837936
Merge pull request #8705 from Security-Onion-Solutions/funstuff
...
Fix yaml for idh,es,kib,esalert
2022-09-09 15:47:59 -04:00
Mike Reeves
16f2059f17
Fix yaml for idh,es,kib,esalert
2022-09-09 15:46:48 -04:00
Mike Reeves
e2eaefab6e
Fix yaml for idh,es,kib,esalert
2022-09-09 15:45:13 -04:00
Josh Patterson
c6421275f7
Merge pull request #8704 from Security-Onion-Solutions/influx/defaults
...
remove jinja from influxdb defaults.yaml
2022-09-09 15:42:46 -04:00
m0duspwnens
9a08decadb
remove jinja from influxdb defaults.yaml
2022-09-09 15:41:20 -04:00
Mike Reeves
cc08e5a42c
Merge pull request #8703 from Security-Onion-Solutions/funstuff
...
Fix yaml for idh,es,kib,esalert
2022-09-09 15:38:07 -04:00
Mike Reeves
1f3b170213
Fix yaml for idh,es,kib,esalert
2022-09-09 15:36:57 -04:00
Mike Reeves
74ef6c0ed0
Fix yaml for idh,es,kib,esalert
2022-09-09 15:30:28 -04:00
Josh Brower
09a1032f77
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/elastic-fleet
2022-09-09 15:08:25 -04:00
Josh Brower
921d644a0b
Elastic Fleet wrapper
2022-09-09 15:05:31 -04:00
Josh Patterson
54f7cefa28
Merge pull request #8702 from Security-Onion-Solutions/fix/soc2.4
...
add salt bind for soc
2022-09-09 14:45:31 -04:00
m0duspwnens
b5fb7596b0
add salt bind for soc
2022-09-09 14:44:41 -04:00
Josh Patterson
7dd65909f2
Merge pull request #8701 from Security-Onion-Solutions/fix/soc2.4
...
add saltPipe
2022-09-09 14:40:08 -04:00
m0duspwnens
0f2e9764ab
add saltPipe
2022-09-09 14:39:20 -04:00
Josh Patterson
deaecad8fd
Merge pull request #8700 from Security-Onion-Solutions/fix/soc2.4
...
Fix/soc2.4
2022-09-09 14:32:41 -04:00
m0duspwnens
5ccc103083
fix soc dashboards and things
2022-09-09 14:31:04 -04:00
m0duspwnens
5bb001281b
soc defaults changes - client child of server
2022-09-08 15:57:18 -04:00
Mike Reeves
ce59a8a225
Merge pull request #8697 from Security-Onion-Solutions/funstuff
...
move endgamehost
2022-09-08 14:12:43 -04:00
Mike Reeves
8c12b26847
touch the soc file
2022-09-08 14:08:24 -04:00
Mike Reeves
9c9509594a
move endgamehost
2022-09-08 13:55:35 -04:00
Jason Ertel
cfb3893c2b
Merge pull request #8694 from Security-Onion-Solutions/salt-relay
...
Salt relay
2022-09-08 10:31:28 -04:00
Jason Ertel
b7bbe7d69f
Add copyright notice
2022-09-08 10:27:56 -04:00
Jason Ertel
193c3fc4cd
Add salt relay
2022-09-08 10:26:39 -04:00
Mike Reeves
6ab9cc6d53
Merge pull request #8693 from Security-Onion-Solutions/funstuff
...
Add an older version of so-status
2022-09-08 09:04:41 -04:00
Mike Reeves
3785b97d95
so-status
2022-09-08 08:48:49 -04:00
weslambert
c25b981c50
Merge pull request #8688 from Security-Onion-Solutions/elastic_agent_security_subfield_additions
...
Elastic Agent .security subfield additions
2022-09-08 08:05:16 -04:00
Wes
86d60e444d
Add Elastic Agent index/template configuration to defaults file
2022-09-08 00:20:22 +00:00
Josh Brower
d9ae646ef2
Merge pull request #8682 from Security-Onion-Solutions/2.4/elastic-fleet
...
2.4/elastic fleet
2022-09-07 18:53:35 -04:00
Wes
b39a5061ca
Load Elastic Agent component templates (managed by Security Onion)
2022-09-07 21:26:43 +00:00
Wes
eeffded248
Remove duplicate security subfield configuration from component templates
2022-09-07 21:23:04 +00:00
Josh Brower
f00aafdfb2
Elastic Agent - move gen installers
2022-09-07 16:57:11 -04:00
Josh Brower
e8af315e40
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/elastic-fleet
2022-09-07 16:32:31 -04:00
Jason Ertel
df6ba5cbe9
initial salt relay script for comms with soc
2022-09-07 16:19:16 -04:00
Josh Brower
e3e0e4c6ed
Merge pull request #8681 from Security-Onion-Solutions/playbookfix
...
Update so-playbook-reset
2022-09-07 16:01:37 -04:00
Josh Brower
39ed582a72
Update so-playbook-reset
2022-09-07 15:59:54 -04:00
Mike Reeves
40131daeed
Merge pull request #8680 from Security-Onion-Solutions/funstuff
...
Funstuff
2022-09-07 15:46:48 -04:00
Mike Reeves
5b65fdcc1c
Remove crossthestreams
2022-09-07 15:42:22 -04:00
Mike Reeves
6d1bc78f7b
Remove crossthestreams
2022-09-07 15:41:21 -04:00
Mike Reeves
6adcb4c968
Remove crossthestreams
2022-09-07 15:38:55 -04:00
Wes
3c50072690
Add Elastic Agent component templates
2022-09-07 18:51:57 +00:00
Josh Brower
ce688cfb91
Elastic Agent setup changes
2022-09-07 10:23:26 -04:00
Mike Reeves
f7f5d414c4
Merge pull request #8677 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2022-09-07 09:56:26 -04:00
Mike Reeves
2fb1f14d09
Update VERSION
2022-09-07 09:55:41 -04:00
Josh Patterson
de456a402c
Merge pull request #8676 from Security-Onion-Solutions/index_settings_False
...
Update so-functions
2022-09-07 09:40:12 -04:00
Josh Patterson
dfd505dfaa
Update so-functions
2022-09-07 09:38:22 -04:00
Mike Reeves
b76bf0a6e0
Merge pull request #8675 from Security-Onion-Solutions/gitfoo
...
Move In Day
2022-09-07 09:21:03 -04:00
Mike Reeves
c9dd2beaaa
Move In Day
2022-09-07 09:15:58 -04:00
Mike Reeves
2bd9dd80e2
Move In Day
2022-09-07 09:06:25 -04:00
Josh Patterson
dcb7b49dbe
Merge pull request #8451 from Security-Onion-Solutions/issue/8441_3
...
manage salt-minion start delay with systemd drop-in file -
2022-08-02 16:39:45 -04:00
m0duspwnens
a965301b2e
manage salt-minion start delay with systemd drop-in file - https://github.com/Security-Onion-Solutions/securityonion/issues/8441
2022-08-02 16:37:27 -04:00
Mike Reeves
fbcbfaf7c3
Merge pull request #8310 from Security-Onion-Solutions/dev
...
2.3.140
2022-07-18 11:23:54 -04:00
Mike Reeves
497110d6cd
Merge pull request #8320 from Security-Onion-Solutions/2.3.140-2
...
2.3.140
2022-07-18 10:57:53 -04:00
Mike Reeves
3711eb52b8
2.3.140
2022-07-18 10:54:50 -04:00
weslambert
8099b1688b
Merge pull request #8319 from Security-Onion-Solutions/fix/elasticsearch_query_missing_query_path
...
Fix missing query path for so-elasticsearch-query
2022-07-18 09:47:16 -04:00
weslambert
2914007393
Add forward slash to fix issue with missing query path
2022-07-18 09:07:34 -04:00
weslambert
f5e10430ed
Add forward slash to fix issue with missing query path
2022-07-18 09:07:13 -04:00
Mike Reeves
b5a78d4577
Merge pull request #8309 from Security-Onion-Solutions/2.3.140
...
2.3.140
2022-07-15 13:36:31 -04:00
Mike Reeves
0a14dad849
Update VERIFY_ISO.md
2022-07-15 13:31:51 -04:00
Mike Reeves
3430df6a20
2.3.140
2022-07-15 13:26:25 -04:00
Mike Reeves
881915f871
Merge pull request #8306 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update defaults.yaml
2022-07-14 16:20:29 -04:00
Mike Reeves
cf8c6a6e94
Update defaults.yaml
2022-07-14 15:17:27 -04:00
weslambert
52ebbf8ff3
Merge pull request #8304 from Security-Onion-Solutions/fix/kibana_space_defaults_web_response_url
...
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:08:02 -04:00
weslambert
2443e8b97e
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:04:56 -04:00
weslambert
4241eb4b29
Merge pull request #8298 from Security-Onion-Solutions/fix/kibana_space_defaults_shebang
...
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:50:21 -04:00
weslambert
0fd4f34b5b
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:48:39 -04:00
Josh Patterson
37df49d4f3
Merge pull request #8296 from Security-Onion-Solutions/elastalert_esversion_check
...
use onlyif requisite instead
2022-07-13 15:22:40 -04:00
m0duspwnens
7d7cf42d9a
use onlyif requisite instead
2022-07-13 15:21:34 -04:00
Doug Burks
de0a7d3bcd
Merge pull request #8293 from Security-Onion-Solutions/dougburks-patch-1
...
change hyperlink for Elastic 8 issues
2022-07-13 12:41:50 -04:00
Doug Burks
c67a58a5b1
change hyperlink for Elastic 8 issues
2022-07-13 12:40:03 -04:00
Josh Patterson
e79ca4bb9b
Merge pull request #8291 from Security-Onion-Solutions/elastalert_esversion_check
...
do not start elastalert if elasticsearch is not v8
2022-07-13 11:24:12 -04:00
m0duspwnens
086cf3996d
do not start elastalert if elasticsearch is not v8
2022-07-13 11:21:27 -04:00
Doug Burks
7ae5d49a4a
Merge pull request #8290 from Security-Onion-Solutions/dougburks-patch-1
...
increment version to 2.3.140
2022-07-13 09:33:37 -04:00
Doug Burks
34d3c6a882
increment version to 2.3.140
2022-07-13 09:32:28 -04:00
weslambert
4a5664db7b
Merge pull request #8289 from Security-Onion-Solutions/fix/soup_unsupported_indices_check
...
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:15:22 -04:00
weslambert
513c7ae56c
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:13:28 -04:00
weslambert
fa894cf83b
Merge pull request #8288 from Security-Onion-Solutions/fix/soup_elastalert_indices_deletion_check
...
Ensure Elastalert indices are deleted before continuing with SOUP
2022-07-13 08:44:04 -04:00
weslambert
8e92060c29
Ensure Elastalert indices are deleted before continuing with SOUP -- if they are not, generate a failure condition
2022-07-13 08:38:55 -04:00
weslambert
d7eb8b9bcb
Merge pull request #8281 from Security-Onion-Solutions/fix/soup_elasticsearch8_index_compatibility
...
SOUP - Check for indices created by Elasticsearch 6
2022-07-12 16:20:47 -04:00
weslambert
d0a0ca8458
Update exit code for ES checks
2022-07-12 16:15:44 -04:00
Josh Patterson
57b79421d8
Merge pull request #8280 from Security-Onion-Solutions/fix_filebeat
...
move port bindings back under port bindings
2022-07-12 16:12:49 -04:00
weslambert
4502182b53
Typo - Ensure Elasticsearch version 6 indices are checked
2022-07-12 15:35:46 -04:00
weslambert
0fc6f7b022
Add check for Elasticsearch 6 indices
2022-07-12 15:34:24 -04:00
m0duspwnens
ec451c19f8
move port bindings back under port bindings
2022-07-12 15:17:25 -04:00
weslambert
e9a22d0aff
Merge pull request #8275 from Security-Onion-Solutions/fix/filebeat_es_output_additions
...
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
2022-07-11 19:03:07 -04:00
weslambert
11d3ed36b7
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
...
Add outputs for Elasticsearch and Kibana for Eval/Import Mode, since Logstash is not used in Eval Mode or Import Mode. Otherwise, logs from these inputs end up in a filebeat-prefixed index.
2022-07-11 17:22:09 -04:00
weslambert
d828bbfe47
Merge pull request #8273 from Security-Onion-Solutions/fix/kibana_space_defaults_cases
...
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:39:30 -04:00
weslambert
bd32394560
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:38:05 -04:00
weslambert
6f4f050a96
Merge pull request #8272 from Security-Onion-Solutions/fix/soup_kibana_space_defaults
...
Run so-kibana-space-defaults when upgrading to 2.3.140
2022-07-11 14:47:11 -04:00
weslambert
f77edaa5c9
Run so-kibana-space-defaults to re-establish the default enabled features since Fleet feature name changed
2022-07-11 14:41:23 -04:00
Jason Ertel
15124b6ad7
Merge pull request #8271 from Security-Onion-Solutions/kilo
...
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:47:28 -04:00
Jason Ertel
077053afbd
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:43:41 -04:00
weslambert
dd1d5b1a83
Merge pull request #8270 from Security-Onion-Solutions/fix/curator_actions_delete_kratos
...
Add delete and warm action for Kratos indices in applicable Curator delete/warm scripts
2022-07-11 11:39:43 -04:00
weslambert
e82b6fcdec
Typo - Change 'delete' to 'warm'
2022-07-11 11:34:53 -04:00
weslambert
8c8ac41b36
Add action for Kratos indices
2022-07-11 11:32:03 -04:00
weslambert
b611dda143
Add delete action for Kratos indices
2022-07-11 11:31:22 -04:00
weslambert
3f5b98d14d
Merge pull request #8269 from Security-Onion-Solutions/fix/curator_actions_kratos
...
Add Curator actions and adjust Curator close scripts to account for so-kibana and so-kratos indices
2022-07-11 11:21:20 -04:00
Wes Lambert
0b6219d95f
Adjust Curator close scripts to include Kibana and Kratos indices
2022-07-11 14:51:33 +00:00
Wes Lambert
2f729e24d9
Add Curator action files for Kratos indices
2022-07-11 14:34:10 +00:00
weslambert
992b6e14de
Merge pull request #8268 from Security-Onion-Solutions/fix/kibana_disable_fleetv2
...
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:09:12 -04:00
weslambert
09a1d8c549
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:06:24 -04:00
Jason Ertel
f28c6d590a
Merge pull request #8263 from Security-Onion-Solutions/kilo
...
Remove Jinja from yaml files before parsing
2022-07-08 20:32:22 -04:00
Jason Ertel
4f8bb6049b
Future proof the jinja check to ensure the script does not silently overwrite jinja templates
2022-07-08 17:30:00 -04:00
Jason Ertel
a8e6b26406
Remove Jinja from yaml files before parsing
2022-07-08 17:07:24 -04:00
weslambert
2903bdbc7e
Merge pull request #8260 from Security-Onion-Solutions/fix/kratos_dedicated_index_and_filestream_id_additions
...
Add dedicated index for Kratos and IDs for all filestream inputs
2022-07-08 12:04:40 -04:00
Wes Lambert
5c90fce3a1
Add Kratos Logstash output to search pipeline for Logstash
2022-07-08 15:58:00 +00:00
Wes Lambert
26698cfd07
Add Logstash output for dedicated Kratos index
2022-07-08 15:55:55 +00:00
Wes Lambert
764e8688b1
Modify Kratos input to use dedicated index and add filestream ID for all applicable inputs
2022-07-08 15:53:55 +00:00
Wes Lambert
b06c16f750
Add ingest node pipeline for Kratos
2022-07-08 15:53:00 +00:00
weslambert
42cfab4544
Merge pull request #8256 from Security-Onion-Solutions/fix/kibana_restart_after_role_sync
...
Restart Kibana in case it times out before being able to read role update
2022-07-07 17:44:47 -04:00
weslambert
4bbc901860
Restart Kibana in case it times out before being able to read in new role configuration
2022-07-07 17:19:02 -04:00
weslambert
a343f8ced0
Merge pull request #8255 from Security-Onion-Solutions/fix/so_kibana_user_role
...
Force so-user to sync roles to ensure so_kibana role change
2022-07-07 16:19:30 -04:00
weslambert
85be2f4f99
Force so-user to sync roles to ensure so_kibana role change from superuser to kibana_system
2022-07-07 15:55:44 -04:00
weslambert
8b3fa0c4c6
Merge pull request #8252 from Security-Onion-Solutions/feature/elastic_8_3_2
...
Update to Elastic 8.3.2
2022-07-07 11:14:14 -04:00
weslambert
ede845ce00
Update to Kibana 8.3.2
2022-07-07 11:05:44 -04:00
weslambert
42c96553c5
Update to Kibana 8.3.2
2022-07-07 11:04:43 -04:00
Mike Reeves
41d5cdd78c
Merge pull request #8246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2022-07-06 16:39:38 -04:00
Mike Reeves
c819d3a558
Update soup
2022-07-06 16:36:57 -04:00
Mike Reeves
c00d33632a
Update soup
2022-07-06 16:23:02 -04:00
Mike Reeves
a1ee793607
Merge pull request #8242 from Security-Onion-Solutions/fixsoup
...
Move soup order
2022-07-06 09:18:16 -04:00
Mike Reeves
1589107b97
Move soup order
2022-07-06 08:59:21 -04:00
Mike Reeves
31688ee898
Merge pull request #8238 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Make soup enforce versions
2022-07-05 16:56:14 -04:00
Mike Reeves
f1d188a46d
Update soup
2022-07-05 16:50:20 -04:00
Mike Reeves
5f0c3aa7ae
Update soup
2022-07-05 16:49:20 -04:00
weslambert
2b73cd1156
Merge pull request #8236 from Security-Onion-Solutions/fix/localfile_analyzer
...
Strip quotes and ensure file_path is typed as a list (localfile analyzer)
2022-07-05 16:28:56 -04:00
Mike Reeves
c6fac28804
Update soup
2022-07-05 16:26:44 -04:00
Jason Ertel
9d43b7ec89
Rollback string manipulation in favor of fixed unit tests
2022-07-05 16:21:27 -04:00
Jason Ertel
f6266b19cc
Fix unit test issues
2022-07-05 16:20:24 -04:00
Mike Reeves
df0a774ffd
Make soup enforce versions
2022-07-05 16:17:32 -04:00
weslambert
77ee30f31a
Merge pull request #8237 from Security-Onion-Solutions/feature/elastic_8_3_1
...
Bump Elastic to 8.3.1
2022-07-05 14:50:24 -04:00
weslambert
2938464501
Update to Kibana 8.3.1
2022-07-05 14:46:02 -04:00
weslambert
79e88c9ca3
Update to Kibana 8.3.1
2022-07-05 14:45:30 -04:00
Wes Lambert
e96206d065
Strip quotes and ensure file_path is typed as a list
2022-07-05 14:25:54 +00:00
Josh Brower
7fa9ca8fc6
Merge pull request #8233 from Security-Onion-Solutions/fix/remove-sudo-bpf
...
Remove unneeded sudo
2022-07-05 09:23:48 -04:00
Josh Brower
a1d1779126
Remove unneeded sudo
2022-07-05 09:21:05 -04:00
Josh Patterson
fb365739ae
Merge pull request #8225 from Security-Onion-Solutions/salltupdate
...
bootstrap-salt can now update to minor version with -r
2022-07-01 08:53:59 -04:00
m0duspwnens
5f898ae569
change to egrep
2022-07-01 08:47:46 -04:00
m0duspwnens
f0ff0d51f7
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 16:59:54 -04:00
m0duspwnens
7524ea2c05
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 15:10:13 -04:00
Mike Reeves
6bb979e2b6
Merge pull request #8219 from Security-Onion-Solutions/salty
...
Salty
2022-06-30 13:34:03 -04:00
Mike Reeves
8b3d5e808e
Fix repo location
2022-06-30 13:30:56 -04:00
Mike Reeves
e86b7bff84
Fix repo location
2022-06-30 13:29:21 -04:00
Josh Patterson
69ce3613ff
Merge pull request #8217 from Security-Onion-Solutions/salltupdate
...
point to salt3004.2
2022-06-30 11:29:35 -04:00
m0duspwnens
0ebd957308
point to salt3004.2
2022-06-30 11:26:03 -04:00
Josh Patterson
c3979f5a32
Merge pull request #8207 from Security-Onion-Solutions/salltupdate
...
Saltupdate 3004.2
2022-06-28 11:20:53 -04:00
m0duspwnens
8fccd4598a
update saltstack.list for 3004.2
2022-06-27 16:23:01 -04:00
weslambert
3552dfac03
Merge pull request #8199 from Security-Onion-Solutions/fix/filebeat_filestream_elastic8
...
Change type from 'log' to 'filestream' to ensure compatibility with E…
2022-06-27 14:58:54 -04:00
Josh Patterson
fba5592f62
Update minion.defaults.yaml
2022-06-27 12:10:18 -04:00
Josh Patterson
05e84699d1
Update master.defaults.yaml
2022-06-27 12:09:39 -04:00
Mike Reeves
f36c8da1fe
Update so-functions
2022-06-27 12:04:33 -04:00
Mike Reeves
080daee1d8
Update so-functions
2022-06-27 11:43:01 -04:00
Mike Reeves
909e876509
Update ubuntu.sls
2022-06-27 11:41:49 -04:00
Jason Ertel
ac68fa822b
Merge pull request #8200 from Security-Onion-Solutions/contrib
...
Add gh action for contrib check
2022-06-27 11:25:10 -04:00
Jason Ertel
675ace21f5
Add gh action for contrib check
2022-06-27 11:11:15 -04:00
weslambert
85f790b28a
Change type from 'log' to 'filestream' to ensure compatibility with Elastic 8
2022-06-27 10:39:58 -04:00
weslambert
d0818e83c9
Merge pull request #8197 from Security-Onion-Solutions/fix/localfile_analyzer_csv_path
...
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:36:59 -04:00
weslambert
568b43d0af
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:10:13 -04:00
Jason Ertel
2e123b7a4f
Merge pull request #8175 from Security-Onion-Solutions/kilo
...
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 08:16:39 -04:00
Jason Ertel
ba6f716e4a
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 06:09:04 -04:00
weslambert
10bcc43e85
Merge pull request #8167 from Security-Onion-Solutions/feature/update_es_8_2_3
...
Update to Elastic 8.2.3
2022-06-21 16:11:39 -04:00
weslambert
af687fb2b5
Update config_saved_objects.ndjson
2022-06-21 16:06:28 -04:00
weslambert
776cc30a8e
Update to ES 8.2.3
2022-06-21 16:06:01 -04:00
Doug Burks
00cf0b38d0
Merge pull request #8165 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve default dashboards #8136
2022-06-21 12:57:46 -04:00
Doug Burks
94c637449d
FIX: Improve default dashboards #8136
2022-06-21 12:53:06 -04:00
Josh Brower
0a203add3b
Merge pull request #8145 from Security-Onion-Solutions/defensivedepth-patch-1
...
pin v1.6.0
2022-06-17 13:14:58 -04:00
Josh Brower
b8ee896f8a
pin v1.6.0
2022-06-17 12:38:54 -04:00
Josh Brower
238e671f34
Merge pull request #8129 from Security-Onion-Solutions/fix/curator-cron
...
Change curator to daily for true cluster
2022-06-15 11:40:53 -04:00
Josh Brower
072cb3cca2
Change curator to daily for true cluster
2022-06-15 11:38:38 -04:00
weslambert
44595cb333
Merge pull request #8123 from Security-Onion-Solutions/foxtrot
...
Merge foxtrot into dev
2022-06-14 15:44:13 -04:00
weslambert
959cec1845
Delete Elastalert indices before upgrading to Elastic 8
2022-06-14 11:40:11 -04:00
Doug Burks
286909af4b
Merge pull request #8113 from Security-Onion-Solutions/fix/pfsense-category
...
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:08:00 -04:00
doug
025993407e
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:03:44 -04:00
weslambert
151a42734c
Update Elastic version to 8.2.2
2022-06-08 15:07:45 -04:00
weslambert
11e3576e0d
Update Elastic version to 8.2.2
2022-06-08 15:07:07 -04:00
weslambert
adeccd0e7f
Merge pull request #8097 from Security-Onion-Solutions/dev
...
Merge latest dev into foxtrot
2022-06-08 15:01:09 -04:00
weslambert
aadf391e5a
Temporarily downgrade version for merge
2022-06-08 14:59:01 -04:00
weslambert
47f74fa5c6
Temporarily downgrade version for merge
2022-06-08 14:58:05 -04:00
Jason Ertel
e405750d26
Merge pull request #8095 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.140
2022-06-08 09:07:56 -04:00
Jason Ertel
e36c33485d
Bump version to 2.3.140
2022-06-08 09:04:57 -04:00
Mike Reeves
65165e52f4
Merge pull request #8086 from Security-Onion-Solutions/dev
...
2.3.130
2022-06-07 15:51:12 -04:00
Mike Reeves
2cceae54df
Merge pull request #8087 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 13:44:38 -04:00
Mike Reeves
8912e241aa
2.3.130
2022-06-07 13:41:51 -04:00
Mike Reeves
7357f157ec
Merge pull request #8085 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 12:04:47 -04:00
Mike Reeves
37881bd4b6
2.3.130
2022-06-07 11:34:10 -04:00
Josh Brower
2574f0e23d
Merge pull request #8081 from Security-Onion-Solutions/fix/fleetdm-websockets
...
Allow websockets for fleetdm
2022-06-06 19:15:02 -04:00
Josh Brower
c9d9804c3a
Allow websockets for fleetdm
2022-06-06 17:26:24 -04:00
Doug Burks
73baa1d2f0
Merge pull request #8073 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md to include links to Dashboards and Cases
2022-06-04 08:53:54 -04:00
Doug Burks
dce415297c
improve readability in motd.md
2022-06-04 06:59:09 -04:00
Doug Burks
de126647f8
Update motd.md to include links to Dashboards and Cases
2022-06-04 06:55:08 -04:00
Doug Burks
c34f456151
Merge pull request #8069 from Security-Onion-Solutions/dougburks-patch-1
...
add bar and pie examples to overview dashboard in dashboards.queries.…
2022-06-03 15:04:16 -04:00
Doug Burks
83bff5ee87
add bar and pie examples to overview dashboard in dashboards.queries.json
2022-06-03 15:02:40 -04:00
Doug Burks
918f431728
Merge pull request #8065 from Security-Onion-Solutions/dougburks-patch-1
...
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:13:39 -04:00
Doug Burks
4a886338c8
fix description field for default dashboard in dashboards.queries.json
2022-06-03 11:10:01 -04:00
Doug Burks
7da1802eae
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:03:48 -04:00
Mike Reeves
ff92b524c2
Merge pull request #8062 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2022-06-02 11:51:42 -04:00
Mike Reeves
395eaa39b4
Update soup
2022-06-02 11:45:37 -04:00
Mike Reeves
2867a32931
Merge pull request #8061 from Security-Onion-Solutions/soup130
...
soup for 130
2022-06-02 10:42:17 -04:00
Mike Reeves
fce43cf390
soup for 130
2022-06-02 10:33:18 -04:00
Josh Patterson
e5c9b91529
Merge pull request #8054 from Security-Onion-Solutions/dmz_receiver
...
Dmz receiver
2022-06-01 15:31:42 -04:00
m0duspwnens
e5b74bcb78
remove podman state
2022-06-01 15:26:25 -04:00
Doug Burks
91f8d3e5e9
Merge pull request #8050 from Security-Onion-Solutions/fix/elastalert-query
...
FIX: Elastalert query in Hunt #8049
2022-05-31 16:54:34 -04:00
Doug Burks
269b16bbfd
https://github.com/Security-Onion-Solutions/securityonion/issues/8049
2022-05-31 16:51:05 -04:00
Doug Burks
cd382a1b25
FIX: Elastalert query in Hunt #8049
2022-05-31 16:50:32 -04:00
Doug Burks
e1c9b0d108
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:52 -04:00
Doug Burks
9a98667e85
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:11 -04:00
weslambert
494ce0756d
Merge pull request #8045 from Security-Onion-Solutions/fix/mhr_naming
...
Fix naming for Malware Hash Registry analyzer
2022-05-31 07:52:48 -04:00
Wes Lambert
7f30a364ee
Make sure everything is added back after renaming mhr to malwarehashregistry
2022-05-31 11:44:35 +00:00
Wes Lambert
c82aa89497
Fix Malware Hash Registry naming so it's more descriptive in SOC
2022-05-31 11:41:48 +00:00
Josh Brower
025677a1e6
Merge pull request #8034 from Security-Onion-Solutions/feature/sigmafp
...
Feature/SigmaCustomFilters
2022-05-31 07:25:44 -04:00
Josh Brower
a5361fb745
Change Target_log name
2022-05-28 18:07:05 -04:00
Mike Reeves
30d7801ae1
Merge pull request #8033 from Security-Onion-Solutions/kilo
2022-05-28 11:38:35 -04:00
Jason Ertel
210bc556db
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:29:04 -04:00
Jason Ertel
e87e672b9e
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:28:20 -04:00
Jason Ertel
a70da41f20
Merge pull request #8032 from Security-Onion-Solutions/kilo
...
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:34:40 -04:00
Jason Ertel
8bb02763dc
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:28:10 -04:00
weslambert
a59ada695b
Merge pull request #8031 from Security-Onion-Solutions/fix/screenshots
...
Fix/screenshots
2022-05-27 17:05:51 -04:00
doug
b93a108386
update Cases screenshot in README
2022-05-27 16:33:08 -04:00
doug
6089f3906d
update screenshots and README
2022-05-27 16:32:00 -04:00
Josh Brower
94ee45ac63
Merge pull request #8029 from Security-Onion-Solutions/upgrade/navigator
...
Upgrade Navigator to 4.6.4
2022-05-27 14:46:59 -04:00
Josh Brower
43cb78a6a8
Upgrade Navigator
2022-05-27 14:21:11 -04:00
Josh Patterson
76bb1fbbcc
Merge pull request #8014 from Security-Onion-Solutions/issue/7918
...
manage suricata classifications.config
2022-05-26 13:13:03 -04:00
m0duspwnens
53d6e1d30d
simplfy
2022-05-26 11:51:17 -04:00
m0duspwnens
1bfde852f5
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:43:31 -04:00
m0duspwnens
53883e4ade
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:40:33 -04:00
weslambert
1a0ac4d253
Merge pull request #8007 from Security-Onion-Solutions/fix/filestream-id
...
Add filestream input ID for RITA logs
2022-05-25 10:11:36 -04:00
weslambert
44622350ea
Add ID for RITA filestream inputs
2022-05-25 10:09:01 -04:00
weslambert
99864f4787
Merge pull request #8001 from Security-Onion-Solutions/feature/analyzer_readme
...
Add configuration requirements for various analyzers
2022-05-25 09:33:07 -04:00
Doug Burks
6bd02c0b99
Merge pull request #8003 from Security-Onion-Solutions/feature/elastic-7.17.4
...
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:24:13 -04:00
Doug Burks
1d0bb21908
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:30 -04:00
Doug Burks
bde06e7ec5
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:01 -04:00
Wes Lambert
b93512eb01
Adjust verbiage around pillar configuration
2022-05-24 12:36:32 +00:00
Wes Lambert
92dee14ee8
Add configuration requirements for various analyzers
2022-05-24 12:29:14 +00:00
weslambert
3e6dfcfaca
Merge pull request #7996 from Security-Onion-Solutions/weslambert-patch-2
...
Create Virustotal README
2022-05-23 11:43:43 -04:00
weslambert
a6f1bf3aef
Create Virustotal README
2022-05-23 11:39:44 -04:00
Jason Ertel
88f17f037e
Merge pull request #7982 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.9.0-alpha.3
2022-05-19 13:28:58 -04:00
Jason Ertel
c20859f8c3
Upgrade to Kratos 0.9.0-alpha.3
2022-05-18 17:05:21 -04:00
Jason Ertel
c95bafd521
Merge pull request #7969 from Security-Onion-Solutions/fix/helpers-analyzers
...
Only import yaml module when config is loaded
2022-05-18 07:15:32 -04:00
Wes Lambert
429ccb2dcc
Only import yaml module when config is loaded
2022-05-18 02:07:39 +00:00
weslambert
94ca3ddbda
Merge pull request #7961 from Security-Onion-Solutions/weslambert-patch-1
...
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 13:33:24 -04:00
weslambert
d3206a048f
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 12:49:16 -04:00
weslambert
ff855eb8f7
Merge pull request #7958 from Security-Onion-Solutions/feature/mhr_analyzer
...
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 12:42:01 -04:00
Wes Lambert
8af1f19ac3
Another no_results change
2022-05-17 16:12:43 +00:00
Wes Lambert
e4a7e3cba6
Change 'No results found.' to 'no_results'
2022-05-17 16:11:58 +00:00
weslambert
2688083ff1
Merge pull request #7959 from Security-Onion-Solutions/feature/whoislookup-analyzer
...
Add Whoislookup RDAP-based analyzer
2022-05-17 12:09:06 -04:00
Wes Lambert
766e9748c5
Add Whoislookup RDAP-based analyzer
2022-05-17 15:52:12 +00:00
weslambert
3761b491c0
Remove whitespace
2022-05-17 10:50:33 -04:00
Wes Lambert
e8fc3ccdf4
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 14:44:53 +00:00
Doug Burks
eb9597217c
Merge pull request #7949 from Security-Onion-Solutions/fix/dashboards-hunt-queries
...
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:47:06 -04:00
doug
5cbb50a781
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:33:48 -04:00
Jason Ertel
685789de33
Merge pull request #7936 from Security-Onion-Solutions/kilo
...
Improved unit test coverage of new analyzers; Utilize localized summa…
2022-05-12 16:47:18 -04:00
Jason Ertel
b45b6b198b
Improved unit test coverage of new analyzers; Utilize localized summaries; Require 100% code coverage on analyzers
2022-05-12 16:32:47 -04:00
weslambert
6c506bbab0
Merge pull request #7935 from Security-Onion-Solutions/fix/pulsedive
...
Fix Pulsedive analyzer logic
2022-05-12 15:20:15 -04:00
Wes Lambert
3dc266cfa9
Add test for when indicator is not found
2022-05-12 19:02:41 +00:00
Wes Lambert
a233c08830
Update logic to handle indicators that are not present in database.
2022-05-12 19:02:02 +00:00
Doug Burks
58b049257d
Merge pull request #7932 from Security-Onion-Solutions/dougburks-patch-1
...
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:24:18 -04:00
Doug Burks
6ed3f42449
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:23:00 -04:00
m0duspwnens
d8abc0a195
if in dmz_nodes dont add to filebeta
2022-05-11 11:51:18 -04:00
m0duspwnens
a641346c02
prevent nodes with logstash:dmz:true from being added to logstash:nodes pillar
2022-05-10 17:28:19 -04:00
Jason Ertel
60b55acd6f
Merge pull request #7926 from Security-Onion-Solutions/kilo
...
Add support for analyzers in airgapped environments
2022-05-10 17:12:18 -04:00
Jason Ertel
35e47c8c3e
Add support for analyzers in airgapped environments
2022-05-10 16:51:00 -04:00
weslambert
7f797a11f8
Merge pull request #7924 from Security-Onion-Solutions/analyzer-docs
...
Update analyzer docs with information about analyzers that require au…
2022-05-10 09:40:50 -04:00
Jason Ertel
91a7f25d3a
Corrected brand name capitalization
2022-05-10 09:39:19 -04:00
weslambert
34d57c386b
Update analyzer docs with information about analyzers that require authentication
2022-05-10 09:32:18 -04:00
weslambert
000e813fbb
Merge pull request #7921 from Security-Onion-Solutions/fix/analyzer-packages
...
Update analyzer packages to those downloaded by Alpine and add additional build script option
2022-05-09 16:43:31 -04:00
Wes Lambert
555ca2e277
Update analyzer build/testing script to download necessary Python packages
2022-05-09 20:06:39 +00:00
Wes Lambert
32adba6141
Update analyzer packages with those built from native (Alpine) Docker image
2022-05-09 20:04:41 +00:00
Jason Ertel
e19635e44a
Merge pull request #7920 from Security-Onion-Solutions/kilo
...
Disable MRU queries on dashboards
2022-05-09 15:08:55 -04:00
Jason Ertel
31c04aabdd
Disable MRU queries on dashboards
2022-05-09 15:06:43 -04:00
Jason Ertel
dc209a37cd
Merge pull request #7916 from Security-Onion-Solutions/kilo
...
Disable actions on dashboards group-by tables
2022-05-09 11:52:22 -04:00
Jason Ertel
3f35dc54d2
Disable actions on dashboards group-by tables
2022-05-09 11:44:39 -04:00
Josh Brower
8e368bdebe
Merge in upstream dev
2022-05-06 20:01:07 -04:00
Jason Ertel
0e64a9e5c3
Merge pull request #7912 from Security-Onion-Solutions/kilo
...
Add dashboard ref to soc.json
2022-05-06 15:18:05 -04:00
Jason Ertel
0786191fc9
Add dashboard ref to soc.json
2022-05-06 15:16:27 -04:00
Jason Ertel
60763c38db
Merge pull request #7911 from Security-Onion-Solutions/kilo
...
Analyzers + Dashboards
2022-05-06 13:50:54 -04:00
weslambert
9800f59ed7
Add Urlscan to observable support matrix
2022-05-06 13:11:43 -04:00
Wes Lambert
ccac71f649
Fix formatting/whitespace
2022-05-06 17:08:40 +00:00
Wes Lambert
1990ba0cf0
Fix formatting/whitespace
2022-05-06 17:08:33 +00:00
Wes Lambert
8ff5778569
Add Urlscan analyzer and tests
2022-05-06 17:01:06 +00:00
Jason Ertel
bee4cf4c52
Fix typo in analyzer desc
2022-05-06 09:20:03 -04:00
Jason Ertel
105c95909c
Dashboard queries
2022-05-04 19:32:06 -04:00
Jason Ertel
890bcd58f9
Merge branch 'dev' into kilo
2022-05-04 19:25:08 -04:00
weslambert
a96c665d04
Change test name for EmailRep
2022-05-03 14:13:25 -04:00
weslambert
f3a91d9fcd
Add EmailRep analyzer to observable support matrix
2022-05-03 10:10:57 -04:00
Wes Lambert
5a9acb3857
Add EmailRep analyzer and tests
2022-05-03 14:06:32 +00:00
Wes Lambert
8b5666b238
Ensure API key is used
2022-05-03 12:48:06 +00:00
weslambert
efb229cfcb
Update to match configuration in analyzer dir
2022-05-02 16:35:21 -04:00
weslambert
2fcb2b081d
Update allowed complexity to 12
2022-05-02 16:14:43 -04:00
weslambert
25f17a5efd
Update allowed complexity to 11
2022-04-29 09:42:57 -04:00
weslambert
66b4fe9f58
Add additional information around URI and User Agent
2022-04-28 17:14:36 -04:00
Wes Lambert
c001708707
Add Pulsedive analyzer and tests
2022-04-28 20:56:03 +00:00
weslambert
4edd729596
Add initial supported observable matrix/table
2022-04-27 08:58:34 -04:00
Wes Lambert
76f183b112
Add Greynoise analyzer and tests
2022-04-26 17:25:35 +00:00
Wes Lambert
bd63753d80
Update analyzer name/description
2022-04-25 19:27:10 +00:00
Wes Lambert
15fcaa7030
Add localfile analyzer and tests
2022-04-25 19:23:35 +00:00
Jason Ertel
71a86b0a3c
Merge pull request #7856 from Security-Onion-Solutions/bumpver
...
Bump version
2022-04-25 13:01:19 -04:00
Jason Ertel
e2145720bd
Bump version
2022-04-25 12:10:29 -04:00
Mike Reeves
b4aa59c619
Merge pull request #7853 from Security-Onion-Solutions/dev
...
2.3.120
2022-04-25 11:33:05 -04:00
Mike Reeves
6975153cf4
Merge pull request #7852 from Security-Onion-Solutions/2.3.120
...
2.3.120
2022-04-25 08:59:52 -04:00
Mike Reeves
0935f51667
2.3.120
2022-04-25 08:57:35 -04:00
Mike Reeves
f92d65737b
2.3.120
2022-04-25 08:53:04 -04:00
Josh Patterson
8f5967911b
Merge pull request #7847 from Security-Onion-Solutions/m0duspwnens-patch-1
...
add eval
2022-04-22 16:06:01 -04:00
Josh Patterson
80eb31368a
add eval
2022-04-22 16:04:29 -04:00
Jason Ertel
d8fdf2b701
Merge branch 'dev' into kilo
2022-04-22 15:11:24 -04:00
Jason Ertel
459d388614
Only override nameservers if the first nameserver given is non empty
2022-04-22 15:08:56 -04:00
Wes Lambert
fbf6e64e67
Add initial OTX analyzer and tests
2022-04-22 17:13:40 +00:00
weslambert
677db7c563
Merge pull request #7841 from Security-Onion-Solutions/weslambert-patch-2
...
Update shard count for Zeek in setup
2022-04-21 17:27:57 -04:00
weslambert
1bb216954c
Merge pull request #7840 from Security-Onion-Solutions/weslambert-patch-1
...
Update shards for Zeek
2022-04-21 17:26:57 -04:00
weslambert
c81988ab00
Update shard count for Zeek in setup
2022-04-21 17:26:30 -04:00
weslambert
542db5b7f5
Update defaults.yaml
2022-04-21 17:24:24 -04:00
Wes Lambert
b2db32a2c7
Add function/test for non-existent VT api_key
2022-04-21 17:33:24 +00:00
Wes Lambert
9287d6adf7
Reduce size of test output for test
2022-04-21 16:56:22 +00:00
Wes Lambert
c8e189f35a
Add source-packages for JA3er
2022-04-21 16:46:45 +00:00
Wes Lambert
5afcc8de4f
Add JA3er analyzer and associated test
2022-04-21 16:42:46 +00:00
weslambert
d7eed52fae
Change -f to -r
2022-04-21 09:46:44 -04:00
Doug Burks
2910b56ea1
Merge pull request #7835 from Security-Onion-Solutions/elastic-7.17.3
...
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 09:02:51 -04:00
Doug Burks
e608285341
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:57:08 -04:00
Doug Burks
04856540dc
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:54:09 -04:00
Doug Burks
feb7eeeb8e
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:47:40 -04:00
Doug Burks
44f4b1da7f
Merge pull request #7832 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-04-20 17:00:09 -04:00
Doug Burks
1edb443c5d
so-playbook-sync pgrep should be more strict to avoid multiple matches on Ubuntu
2022-04-20 16:48:26 -04:00
Doug Burks
8fc03afdc0
so-sensor-clean pgrep should be more strict to avoid matching multiples on Ubuntu
2022-04-20 16:47:18 -04:00
Mike Reeves
fe09b5b0d1
Merge pull request #7831 from Security-Onion-Solutions/awlocal
...
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:42:58 -04:00
Mike Reeves
c3952e94c8
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:36:38 -04:00
Doug Burks
3aac644da5
Merge pull request #7830 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve Zeek file extraction #7829
2022-04-20 14:13:13 -04:00
Doug Burks
15ef0968d9
FIX: Improve Zeek file extraction #7829
2022-04-20 14:01:46 -04:00
Jason Ertel
aeb70dad8f
Doc updates
2022-04-19 14:31:21 -04:00
Jason Ertel
4129cef9fb
Add new spamhaus analyzer
2022-04-19 12:12:52 -04:00
Josh Patterson
40d9335573
Merge pull request #7822 from Security-Onion-Solutions/workstation_state
...
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:21:35 -04:00
m0duspwnens
807f6adf1e
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:19:09 -04:00
Doug Burks
6339ee3bf3
Merge pull request #7818 from Security-Onion-Solutions/dougburks-patch-1
...
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:35:22 -04:00
Doug Burks
5d62ece03b
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:33:54 -04:00
Doug Burks
6905ca276a
Merge pull request #7816 from Security-Onion-Solutions/dougburks-patch-1
...
remove old comments from so-whiptail
2022-04-18 11:30:43 -04:00
Doug Burks
3682754399
remove old comments from so-whiptail
2022-04-18 11:29:46 -04:00
Jason Ertel
0cb73d8f6a
Merge branch 'dev' into kilo
2022-04-18 11:04:32 -04:00
Mike Reeves
186258687e
Merge pull request #7815 from Security-Onion-Solutions/awlocal
...
Fix Analyst Install Loop
2022-04-18 11:04:10 -04:00
Mike Reeves
012ff3e1bc
Fix Analyst Install Loop
2022-04-18 11:02:19 -04:00
Josh Brower
891a197a6a
Merge pull request #7814 from Security-Onion-Solutions/defensivedepth-patch-2
...
Fix ES/LS Log Pruning
2022-04-18 10:45:27 -04:00
Josh Brower
b35b505f0a
Fix pattern matching
2022-04-18 10:39:04 -04:00
Josh Brower
2b39570b08
Fix matching logic
2022-04-18 10:37:38 -04:00
Jason Ertel
159122b52c
Merge branch 'dev' into kilo
2022-04-18 10:11:37 -04:00
Doug Burks
3fb7399000
Merge pull request #7813 from Security-Onion-Solutions/dougburks-patch-1
...
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 08:24:52 -04:00
Doug Burks
400879c079
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 07:53:57 -04:00
Doug Burks
62f3f13bbc
Merge pull request #7803 from Security-Onion-Solutions/dougburks-patch-1
...
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:48:12 -04:00
Doug Burks
0eda9a3bd7
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:45:01 -04:00
Doug Burks
ee00678362
Merge pull request #7802 from Security-Onion-Solutions/dougburks-patch-1
...
Replace old saltstack repo in so-preflight
2022-04-15 13:17:14 -04:00
Doug Burks
ce192c2526
Update so-preflight
2022-04-15 13:11:15 -04:00
Josh Brower
d60d31f723
Merge pull request #7801 from Security-Onion-Solutions/defensivedepth-patch-1
...
Remove thehive entries from so-status
2022-04-15 12:25:21 -04:00
Josh Brower
bd19da1878
Remove thehive entries from so-status
2022-04-15 12:21:56 -04:00
Doug Burks
f461d01961
Merge pull request #7800 from Security-Onion-Solutions/dougburks-patch-1
...
Improve grammar in so-whiptail
2022-04-15 10:52:29 -04:00
Doug Burks
a69d361d1b
Improve grammar in so-whiptail
2022-04-15 10:45:34 -04:00
Josh Brower
19cba9dca9
Merge pull request #7798 from Security-Onion-Solutions/awlocal
...
Make analyst iso install init management interface
2022-04-15 07:26:53 -04:00
Mike Reeves
5081a81a6c
Make analyst iso install init management interface
2022-04-14 20:00:58 -04:00
Josh Patterson
ba61057433
Merge pull request #7796 from Security-Onion-Solutions/fix_analyst_setup
...
Fix analyst setup
2022-04-14 16:12:53 -04:00
m0duspwnens
b8a80f76cf
change words
2022-04-14 16:09:39 -04:00
Josh Patterson
be2573bb7d
Merge pull request #7794 from Security-Onion-Solutions/soup_salt_influx
...
remove influxdb module patched state files when salt is upgraded
2022-04-14 16:08:10 -04:00
m0duspwnens
36aef87a3c
remove cd before running so-setup analyst
2022-04-14 16:03:43 -04:00
m0duspwnens
02c19da3c4
remove influxdb module patched state files when salt is upgraded
2022-04-14 15:00:14 -04:00
Josh Patterson
2d094a3bfc
Merge pull request #7784 from Security-Onion-Solutions/workstation_script
...
modify so-analyst-install to work with new states and install on managers
2022-04-13 14:37:24 -04:00
m0duspwnens
371fda09db
fix copy paste fail
2022-04-13 14:28:05 -04:00
m0duspwnens
149375115e
warn about required reboot and prompt if reboot desired at completion of install
2022-04-13 14:26:14 -04:00
m0duspwnens
4728bea633
fix typo
2022-04-13 14:03:09 -04:00
m0duspwnens
3ee09db752
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:48 -04:00
m0duspwnens
6477e6c5a2
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:39 -04:00
m0duspwnens
2389d3fac9
modify so-analyst-install to work with new states and install on managers
2022-04-13 12:32:05 -04:00
Mike Reeves
ecc29b586d
Merge pull request #7772 from Security-Onion-Solutions/awlocal
2022-04-12 15:45:56 -04:00
Mike Reeves
2977604d96
Merge branch 'awlocal' of https://github.com/Security-Onion-Solutions/securityonion into awlocal
2022-04-12 15:39:45 -04:00
Mike Reeves
5253cb5d25
Remove keys at the end of an install
2022-04-12 15:33:17 -04:00
Josh Brower
1cb5a791ca
Add idh req_storage elif
2022-04-12 14:29:07 -04:00
Mike Reeves
8408628b03
Stop thehive on soup
2022-04-12 13:54:08 -04:00
Mike Reeves
02f4cd9926
Replace salt code on a saltstack update
2022-04-12 12:15:22 -04:00
Mike Reeves
c1824e9f17
Replace salt code on a saltstack update
2022-04-12 11:55:45 -04:00
Mike Reeves
081d7e3a09
Replace salt code on a saltstack update
2022-04-12 11:20:26 -04:00
Mike Reeves
a7221ba2b4
Remove summary for thins the workstation doesnt care about
2022-04-12 11:06:12 -04:00
Mike Reeves
aa90a016d7
Change disk requirements for IDH
2022-04-12 10:44:45 -04:00
Josh Patterson
dbddff7be7
Merge pull request #7766 from Security-Onion-Solutions/issue/7763
...
Issue/7763
2022-04-11 16:44:04 -04:00
Josh Brower
f1574de827
Merge pull request #7765 from Security-Onion-Solutions/fix/compress-clean-elastic-logs
...
Compress + Clean ES & Logstash App Logs
2022-04-11 16:43:03 -04:00
Josh Brower
886d69fb38
Compress + Clean ES & Logstash App Logs
2022-04-11 16:09:24 -04:00
m0duspwnens
d68b6e7c9a
only start if exit code != 0
2022-04-11 16:03:00 -04:00
m0duspwnens
d102ca298d
move messages about starting services on soup failure before exit message
2022-04-11 16:01:36 -04:00
m0duspwnens
9914148441
more verbose
2022-04-11 15:51:11 -04:00
m0duspwnens
464772d7d3
start salt-master and salt-minion service is soup fails and exits
2022-04-11 15:43:09 -04:00
Mike Reeves
13f6957ae8
Merge pull request #7764 from Security-Onion-Solutions/awlocal
2022-04-11 15:40:06 -04:00
m0duspwnens
2a18059ad9
use quotes
2022-04-11 15:37:07 -04:00
m0duspwnens
01510c184a
set_os and set_cron_service_name sooner
2022-04-11 15:36:02 -04:00
Mike Reeves
eb2d759bf8
Add more whiptail menus
2022-04-11 15:14:29 -04:00
Mike Reeves
5ed7361e3a
Add more whiptail menus
2022-04-11 15:14:06 -04:00
m0duspwnens
6ed8694008
dont need to pass -t
2022-04-11 15:11:57 -04:00
m0duspwnens
79dc2374e0
check that salt-master is running before requiring manager
2022-04-11 15:09:00 -04:00
m0duspwnens
a2180a6721
ensure salt-master service is running before proceeding with soup
2022-04-11 15:01:41 -04:00
Mike Reeves
f9633e7287
Add more whiptail menus
2022-04-11 14:51:17 -04:00
Mike Reeves
0b2745b342
Sending things to the screen
2022-04-11 11:49:24 -04:00
Mike Reeves
ea34b69795
Sending things to the screen
2022-04-11 11:46:42 -04:00
Mike Reeves
97e691c321
Sending things to the screen
2022-04-11 11:43:13 -04:00
Mike Reeves
a3bf904e2d
Import GPG
2022-04-11 11:32:08 -04:00
Mike Reeves
9ed49ef318
Import GPG
2022-04-11 11:29:56 -04:00
Mike Reeves
f7760394a1
Import GPG
2022-04-11 11:25:54 -04:00
Mike Reeves
d9416f3828
Salt local install of Analyst Workstation
2022-04-11 11:04:25 -04:00
Jason Ertel
2d025e944c
Add yaml since helpers module uses it
2022-04-09 17:48:21 -04:00
Jason Ertel
202ca34c6f
Remove obsolete source/site pkg dirs
2022-04-09 14:36:21 -04:00
Jason Ertel
f9568626f2
Merge branch 'dev' into kilo
2022-04-09 09:02:55 -04:00
Jason Ertel
224e30c0ee
Change localized table layout
2022-04-08 17:31:15 -04:00
Jason Ertel
ebcfbaa06d
Analyzer improvements
2022-04-08 16:57:40 -04:00
Josh Patterson
365866c9cc
Merge pull request #7750 from Security-Onion-Solutions/issue_7730
...
ensure bash is used for influx query
2022-04-08 15:26:24 -04:00
m0duspwnens
59d5be682a
ensure bash is used for influx query
2022-04-08 15:01:38 -04:00
Mike Reeves
7805311ea2
Merge pull request #7748 from Security-Onion-Solutions/bravo
...
Bravo
2022-04-08 14:48:54 -04:00
Josh Patterson
8757ca0dfb
Merge pull request #7749 from Security-Onion-Solutions/issue/7113
...
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:10:54 -04:00
m0duspwnens
3e8c687d61
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:05:38 -04:00
Jason Ertel
13c9af5a5a
Clearing hotfix
2022-04-08 10:23:44 -04:00
Mike Reeves
a5313b330f
Merge master into dev
2022-04-08 09:07:46 -04:00
Mike Reeves
0bc3d5d757
Merge pull request #7741 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110 20220407
2022-04-07 16:30:50 -04:00
Mike Reeves
6d88a5b541
Merge pull request #7740 from Security-Onion-Solutions/hfix0407
...
2.3.110 hotfix 0407
2022-04-07 16:11:58 -04:00
Mike Reeves
6a28e752f0
2.3.110 hotfix 0407
2022-04-07 16:03:13 -04:00
Josh Brower
ae8d300567
Merge pull request #7738 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Include firewall state
2022-04-07 14:52:31 -04:00
Mike Reeves
2ad3f63cb5
Merge pull request #7739 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-04-07 14:46:20 -04:00
Mike Reeves
93e04850c4
Update HOTFIX
2022-04-07 14:40:54 -04:00
Josh Brower
36b2d78dfe
Include firewall state
2022-04-07 14:02:21 -04:00
Jason Ertel
44e318e046
Provide CLI feedback for missing input
2022-04-07 10:16:44 -04:00
Josh Patterson
09e7b5a8bf
Merge pull request #7733 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-07 09:05:51 -04:00
m0duspwnens
8fbd16f75d
ensure salt.list is absent
2022-04-07 09:03:51 -04:00
m0duspwnens
722b200e16
add retry to apt_update incase running in background
2022-04-07 08:58:07 -04:00
m0duspwnens
b2a98af18b
proper formatting
2022-04-07 08:55:30 -04:00
m0duspwnens
be3769fd7c
run apt-get update if saltstack.list changes
2022-04-07 08:53:44 -04:00
m0duspwnens
08ac696f14
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-06 17:38:06 -04:00
Josh Brower
86771e1fe6
Merge pull request #7732 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Feature/idh allow multiple int
2022-04-06 17:21:30 -04:00
Josh Brower
f5e539a05c
Initial support for restricting IDH services on MGT IP
2022-04-06 17:16:38 -04:00
Josh Patterson
0c1ac729e1
Merge pull request #7731 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update the centos repo for airgap prior to applying hotfix
2022-04-06 17:00:09 -04:00
m0duspwnens
833106775f
update the centos repo for airgap prior to applying hotfix or standard soup run
2022-04-06 16:53:55 -04:00
Mike Reeves
fbd417b09e
Merge pull request #7720 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-05 20:29:17 -04:00
Mike Reeves
4224d1f258
Merge pull request #7719 from Security-Onion-Solutions/hfix0405
...
2.3.110 hotfix 0405
2022-04-05 19:17:42 -04:00
Mike Reeves
79175b57fa
2.3.110 hotfix 0405
2022-04-05 19:15:20 -04:00
Josh Patterson
5717382340
Merge pull request #7717 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
use -r for bootstrap-salt for ubuntu
2022-04-05 17:37:22 -04:00
m0duspwnens
cf68aeb36e
use -r for bootstrap-salt for ubuntu
2022-04-05 17:35:03 -04:00
Josh Patterson
882eb83fee
Merge pull request #7716 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
point to so repo
2022-04-05 17:30:10 -04:00
m0duspwnens
89c7f5b356
point to so repo
2022-04-05 17:28:47 -04:00
Mike Reeves
bed9a20025
Merge pull request #7714 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
proper salt format
2022-04-05 15:45:36 -04:00
m0duspwnens
89518b5939
proper salt format
2022-04-05 15:44:06 -04:00
Mike Reeves
07b14d7fa7
Merge pull request #7713 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update update_repo function
2022-04-05 15:42:45 -04:00
m0duspwnens
1248ba8924
update update_repo function
2022-04-05 15:40:39 -04:00
Josh Patterson
cbbe3b9248
Merge pull request #7712 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
add deb to saltstack.list
2022-04-05 14:45:46 -04:00
m0duspwnens
b467cde9ad
add deb to saltstack.list
2022-04-05 14:42:36 -04:00
Josh Patterson
6d6f328cad
Merge pull request #7711 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
manage repo conf for ubuntu
2022-04-05 13:50:32 -04:00
m0duspwnens
020871ef61
update hotfix version
2022-04-05 13:49:28 -04:00
m0duspwnens
e08b13629a
manage repo conf for ubuntu
2022-04-05 13:41:26 -04:00
Jason Ertel
d8defdd7b0
Improve unit test stability
2022-04-05 07:36:25 -04:00
Jason Ertel
d2fa80e48a
Update status codes to match SOC
2022-04-05 07:20:23 -04:00
Doug Burks
1e187f0c44
Merge pull request #7703 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-04 23:37:28 -04:00
Josh Brower
7906c053b1
Initial support for restricting IDH services on MGT IP
2022-04-04 16:46:05 -04:00
Mike Reeves
f5073243f9
Merge pull request #7702 from Security-Onion-Solutions/hfix0401
...
2.3.110 hotfix 0401
2022-04-04 16:13:08 -04:00
Mike Reeves
0c7a07f5c0
Merge pull request #7667 from Security-Onion-Solutions/analystsetup
...
Analyst Setup
2022-04-04 16:09:13 -04:00
Mike Reeves
04370a04ce
2.3.110 hotfix 0401
2022-04-04 16:06:20 -04:00
Jason Ertel
04eef0d31f
Merge branch 'dev' into kilo
2022-04-04 15:59:09 -04:00
Jason Ertel
7df6833568
Add unit tests for Urlhaus; remove placeholder whois analyzer
2022-04-04 15:58:53 -04:00
Josh Patterson
809bc1858c
Merge pull request #7700 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
salt 3004.1 hotfix
2022-04-04 13:32:34 -04:00
m0duspwnens
f9563b2dc4
patch influxdb modules
2022-04-04 12:57:36 -04:00
m0duspwnens
b7aff4f4df
remove influxdb state files
2022-04-04 12:28:23 -04:00
m0duspwnens
1e955e0d38
enable highstate before highstate run for hotfix
2022-04-04 11:28:03 -04:00
m0duspwnens
127420b472
hotfix function for 2.3.10 hotfix 1
2022-04-04 10:39:44 -04:00
Wes Lambert
07cf3469a0
Remove pyyaml for requirements file
2022-04-04 11:40:02 +00:00
Wes Lambert
39101cafd1
Add UrlHaus analyzer and helpers script
2022-04-01 21:11:57 +00:00
Mike Reeves
5387caf6f4
fix formatting
2022-04-01 16:50:55 -04:00
Mike Reeves
07783713e6
fix formatting
2022-04-01 16:22:40 -04:00
Mike Reeves
5974279ed7
fix formatting
2022-04-01 16:17:22 -04:00
Mike Reeves
277c7d9d33
fix formatting
2022-04-01 16:05:37 -04:00
Mike Reeves
d20a07bb5f
fix formatting
2022-04-01 16:00:44 -04:00
Josh Patterson
7f4c2687cf
Merge pull request #7691 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove influx patch state files
2022-04-01 15:58:03 -04:00
m0duspwnens
48e40513ff
remove influx patch state files
2022-04-01 15:53:48 -04:00
Mike Reeves
a449a91f38
fix formatting
2022-04-01 15:52:38 -04:00
Mike Reeves
76f43380d9
fix so salt master gets installed
2022-04-01 14:29:24 -04:00
Mike Reeves
7c39559787
fix so salt master gets installed
2022-04-01 14:19:17 -04:00
Jason Ertel
cedb23f4bc
Merge pull request #7689 from Security-Onion-Solutions/esup
...
Upgrade to ES 7.17.2
2022-04-01 13:57:04 -04:00
Jason Ertel
6e7b2ccedc
Upgrade to ES 7.17.2
2022-04-01 13:50:57 -04:00
Mike Reeves
8e9386fcd4
fix the yum commands
2022-04-01 13:17:13 -04:00
Mike Reeves
97fc652a97
fix the yum commands
2022-04-01 11:54:55 -04:00
Mike Reeves
2782c9b464
Update salt versions
2022-04-01 11:26:58 -04:00
Josh Patterson
c429423dae
Merge pull request #7683 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
Update to salt 3004.1
2022-04-01 11:19:31 -04:00
m0duspwnens
45dd7d4758
salt 3004.1 in setup
2022-04-01 11:17:38 -04:00
Josh Patterson
b5ce8756e9
Merge pull request #7686 from Security-Onion-Solutions/workstation_state
...
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:06:53 -04:00
m0duspwnens
e14463c0ab
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:05:34 -04:00
Mike Reeves
d524f3833b
Let the patch pillar do its work
2022-04-01 10:09:55 -04:00
Josh Patterson
f71fcdaed7
salt 3004.1
2022-04-01 09:55:55 -04:00
Josh Patterson
d95391505f
Update minion.defaults.yaml
2022-04-01 09:55:03 -04:00
Mike Reeves
0b80dad2c0
Merge pull request #7682 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-04-01 09:53:57 -04:00
Mike Reeves
02a96c409e
Update HOTFIX
2022-04-01 09:52:57 -04:00
Mike Reeves
cb2044cee9
Fix the analyst pillar
2022-04-01 09:29:29 -04:00
Mike Reeves
64e480714a
Fix the analyst pillar
2022-04-01 09:10:38 -04:00
Jason Ertel
2dc370c8b6
Add source packages to salt state
2022-03-31 18:56:38 -04:00
Jason Ertel
57dc848792
Support analyzer deps
2022-03-31 16:48:13 -04:00
Jason Ertel
9947ba6e43
Support CentOS paths
2022-03-31 16:47:56 -04:00
Jason Ertel
48fbc2290f
Add dep support for analyzers
2022-03-31 13:59:35 -04:00
Mike Reeves
edc6a461ec
Fix analyst pillar
2022-03-31 13:57:37 -04:00
Mike Reeves
63eb15aa6d
Run anayst Pillar
2022-03-31 13:35:30 -04:00
Mike Reeves
5264526ff1
Fix salt master declaration
2022-03-31 12:05:59 -04:00
Mike Reeves
c9eb188a79
Only run specific states during install for AW
2022-03-31 12:01:55 -04:00
Mike Reeves
ad833965a0
Fix extra space
2022-03-31 11:12:10 -04:00
Mike Reeves
179aa5e29c
Add firewall rules for Analyst workstation
2022-03-31 10:49:38 -04:00
Josh Patterson
86b311c468
Merge pull request #7675 from Security-Onion-Solutions/issue/7203
...
different systemd unit files for ubuntu and centos
2022-03-31 10:18:10 -04:00
m0duspwnens
fc60f64ddb
different systemd unit files for ubuntu and centos
2022-03-31 10:11:43 -04:00
Jason Ertel
1aba4da2bb
Correct analyzer path
2022-03-30 21:01:07 -04:00
Mike Reeves
a049e458c6
Add workstation to the salt config
2022-03-30 14:03:52 -04:00
Jason Ertel
45f511caab
Remove extra comma
2022-03-30 13:21:35 -04:00
Mike Reeves
f43a6757e0
Add analyst install network stack
2022-03-30 11:16:00 -04:00
Mike Reeves
c3d3806f65
Add analyst install network stack
2022-03-30 11:14:35 -04:00
Mike Reeves
dceb46888f
Add analyst install network stack
2022-03-30 11:06:59 -04:00
Jason Ertel
e667bb1e59
merge
2022-03-30 10:57:40 -04:00
Mike Reeves
816d0b1075
Don't prompt for install type since we know its analyst
2022-03-29 17:35:13 -04:00
Mike Reeves
c4a4e9737b
Set standalone to load Xwindows
2022-03-29 17:31:53 -04:00
Josh Patterson
1cb48fc6a8
Merge pull request #7668 from Security-Onion-Solutions/issue/7203
...
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 17:30:32 -04:00
Mike Reeves
45161b2a39
Set standalone to load Xwindows
2022-03-29 17:28:32 -04:00
Mike Reeves
67582be575
Set standalone to load Xwindows
2022-03-29 17:23:38 -04:00
Mike Reeves
86e32f3e6c
Set standalone to load Xwindows
2022-03-29 17:13:47 -04:00
Mike Reeves
053ec81285
Set standalone to load Xwindows
2022-03-29 17:12:25 -04:00
Mike Reeves
853235ca9b
Set standalone to load Xwindows
2022-03-29 17:11:19 -04:00
Mike Reeves
afb918d79c
Set standalone to load Xwindows
2022-03-29 17:08:03 -04:00
m0duspwnens
7a4d93f09b
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 15:44:05 -04:00
Jason Ertel
b2a96fab7e
merge
2022-03-29 14:07:20 -04:00
Jason Ertel
d2bf6d5618
Add build script to help pre-validate analyzers before pushing
2022-03-29 14:04:23 -04:00
Jason Ertel
484ef4bc31
Ensure generated python files are not pushed to version control
2022-03-29 13:51:12 -04:00
Jason Ertel
cb491630ae
Analyzer CI
2022-03-29 13:40:56 -04:00
Jason Ertel
0a8d24a225
Add automated CI for analyzers
2022-03-29 13:10:04 -04:00
Mike Reeves
3ace55dfe5
Add initial analyst install code
2022-03-29 12:49:30 -04:00
Mike Reeves
102d2507cb
Add initial analyst install code
2022-03-29 12:48:52 -04:00
Mike Reeves
0d23688aa0
Add initial analyst install code
2022-03-29 12:46:45 -04:00
Mike Reeves
80af497f95
Add initial analyst install code
2022-03-29 12:43:20 -04:00
Mike Reeves
990470a765
Add initial analyst install option to so-setup
2022-03-29 10:41:45 -04:00
Josh Patterson
f5095b273d
Merge pull request #7665 from Security-Onion-Solutions/workstation_state
...
Workstation state
2022-03-29 10:27:07 -04:00
m0duspwnens
e3f3af52e1
fix spacing
2022-03-29 10:19:29 -04:00
m0duspwnens
2f489895ef
top match and remove_gui state
2022-03-29 10:17:21 -04:00
weslambert
7f7eaf173b
Merge pull request #7663 from Security-Onion-Solutions/fix/strelka_fw
...
Add strelka_frontend to heavynode, sensor, and standalone role FW por…
2022-03-28 16:14:25 -04:00
weslambert
6004dde54a
Add strelka_frontend to heavynode, sensor, and standalone role FW portgroups
2022-03-28 16:05:07 -04:00
Jason Ertel
c23b87965f
Merge branch 'dev' into kilo
2022-03-28 15:53:33 -04:00
Jason Ertel
deb9b0e5ef
Add analyze feature
2022-03-28 15:53:24 -04:00
m0duspwnens
0ddfaf8d74
changes for workstation
2022-03-28 15:34:15 -04:00
weslambert
fb7160cba5
Merge pull request #7644 from Security-Onion-Solutions/fix/syslog_pr_adjustment
...
Update with changes from Abe's PR and other fixes
2022-03-25 13:59:20 -04:00
weslambert
e6599cd10e
Update with changes from Abe's PR and other fixes
2022-03-25 13:57:44 -04:00
weslambert
c02d7fab50
Merge pull request #7636 from Security-Onion-Solutions/feature/rita
...
Parsing of RITA Logs
2022-03-24 13:05:22 -04:00
weslambert
fbc86f43ec
Add exclude filter for logs for when there are no results from analysis
2022-03-24 13:03:03 -04:00
weslambert
4c93217aac
Merge pull request #7635 from Security-Onion-Solutions/fix/process_mappings_keyword
...
Additional .keyword shims for process mappings
2022-03-24 12:53:16 -04:00
Wes Lambert
fe1b72655b
Additional .keyword shims for process mappings
2022-03-24 16:45:06 +00:00
m0duspwnens
293de159db
fix package names
2022-03-24 11:33:16 -04:00
m0duspwnens
7cfc52da8a
fix include
2022-03-24 10:02:25 -04:00
m0duspwnens
a0841ee7a7
workstation state
2022-03-24 09:57:58 -04:00
weslambert
5160a55dcf
Merge pull request #7629 from Security-Onion-Solutions/fix/roles_load_check_cluster_health
...
Check ES cluster health before trying to load roles
2022-03-23 11:07:24 -04:00
weslambert
1f2bca599f
Check cluster health before trying to load roles for ES
2022-03-23 11:00:26 -04:00
Wes Lambert
8a56c88773
Adjust log file paths
2022-03-22 17:51:17 +00:00
Wes Lambert
57f01c70ec
Remove extra forward slash in log path
2022-03-22 17:45:23 +00:00
Wes Lambert
2487d468ab
Add RITA Elasticsearch ingest pipeline config
2022-03-22 17:38:22 +00:00
Wes Lambert
f613d8ad86
Add RITA Logstash config
2022-03-22 17:36:18 +00:00
weslambert
bb9d6673ec
Fix casing
2022-03-21 12:38:50 -04:00
weslambert
9afa949623
Don't rotate Filebeat log on startup
2022-03-21 12:38:12 -04:00
weslambert
b2c26807a3
Add xpack.reporting.kibanaServer.hostname to defaults file
2022-03-21 09:30:25 -04:00
Wes Lambert
faeaa948c8
Remove extra Salt logic and clean up output format of resultant script
2022-03-19 04:31:48 +00:00
Wes Lambert
1a6ef0cc6b
Re-enable FB module load
2022-03-19 03:55:40 +00:00
Wes Lambert
a18b38de4d
Update so-filebeat-module-setup to use new load style to avoid having to explicitly enabled filesets
2022-03-19 03:54:41 +00:00
Wes Lambert
2e7d314650
Remove Cyberark module
2022-03-19 03:43:55 +00:00
Wes Lambert
c97847f0e2
Remove Threat Intel Recored Future fileset
2022-03-19 03:43:34 +00:00
Wes Lambert
59a2ac38f5
Disable FB module load for now
2022-03-18 22:12:09 +00:00
Wes Lambert
543bf9a7a7
Update Kibana version to 8
2022-03-18 22:07:21 +00:00
Wes Lambert
d111c08fb3
Update Curator commands with new Filebeat module variables
2022-03-18 21:45:33 +00:00
Doug Burks
a3f8a10eb9
Merge pull request #7608 from Security-Onion-Solutions/fix/telegraf-non-root
...
FIX: Run telegraf as non-root #7468
2022-03-18 15:17:28 -04:00
weslambert
a9ea99daa8
Switch from so_elastic user to so_kibana user for Elastic 8
2022-03-18 15:09:50 -04:00
weslambert
cb0d4acd57
Remove X-Pack ML entry for Elastic 8
2022-03-18 14:46:28 -04:00
Doug Burks
eda7a8d7ea
FIX: Update telegraf influxdbsize.sh to collect influxdb size from influxdb_size.log #7468
2022-03-18 13:15:43 -04:00
Doug Burks
f7dc5588ae
FIX: Update common init.sls to create cron job to write influxdb size for telegraf #7468
2022-03-18 13:13:46 -04:00
Doug Burks
c13994994b
FIX: Update telegraf init.sls to run telegraf as non-root #7468
2022-03-18 13:11:56 -04:00
weslambert
e0374be4aa
Update version from 7.16.2 to 8.1.0 for Kibana config
2022-03-18 11:57:33 -04:00
weslambert
6f294cc0c2
Change Kibana user role from superuser to kibana_system for Elastic 8
2022-03-18 11:54:08 -04:00
weslambert
5ec5b9a2ee
Remove older module config files
2022-03-18 10:14:13 -04:00
weslambert
c659a443b0
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:25:10 -04:00
weslambert
99430fddeb
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:24:39 -04:00
weslambert
7128b04636
Remove indices.query.bool.max_clause_count because it is dynamically allocated in Elastic 8
2022-03-17 21:20:41 -04:00
weslambert
712a92aa39
Switch from log input to filestream input
2022-03-17 21:18:03 -04:00
Wes Lambert
6e2aaa0098
Clean up original map file
2022-03-17 21:08:57 +00:00
Wes Lambert
09892a815b
Add back bind mounts and remove THIRDPARTY
2022-03-17 21:06:07 +00:00
Wes Lambert
a60ef33930
Reorganize FB module management
2022-03-17 21:01:03 +00:00
Josh Patterson
949365c636
Merge pull request #7602 from Security-Onion-Solutions/issue/7601
...
prevent so-setup iso from running on ubuntu
2022-03-17 11:37:53 -04:00
m0duspwnens
a896348743
prevent so-setup iso from running on ubuntu - https://github.com/Security-Onion-Solutions/securityonion/issues/7601
2022-03-17 11:31:16 -04:00
Josh Brower
5b9c82a434
Merge pull request #7494 from Security-Onion-Solutions/fix/fleetdm-custom-hostname
...
Force regen of ssl cert
2022-03-16 15:17:05 -04:00
Doug Burks
50477071b8
Merge pull request #7588 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-03-16 13:54:00 -04:00
Doug Burks
e65f2a5513
FIX: Prevent multiple instances of so-sensor-clean #6622
2022-03-16 13:28:39 -04:00
Doug Burks
e56f90d83c
FIX: Prevent multiple instances of so-playbook-sync #6622
2022-03-16 13:27:37 -04:00
weslambert
aaded58131
Merge pull request #7565 from Security-Onion-Solutions/fix/es_template_fix
...
Custom ES template fixes
2022-03-15 11:09:46 -04:00
Doug Burks
9bf0265cea
Merge pull request #7566 from Security-Onion-Solutions/feature/hunt-soc-auth
...
FEATURE: Add new Hunt query for SOC logins #7327
2022-03-15 10:58:40 -04:00
Mike Reeves
e01c1398d5
Merge pull request #7564 from Security-Onion-Solutions/removethehive
...
Removethehive
2022-03-15 10:56:08 -04:00
Wes Lambert
42d6c3a956
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
2022-03-15 14:55:04 +00:00
Doug Burks
eec44a6b02
Add a SOC Auth query to hunt.queries.json
2022-03-15 10:38:46 -04:00
Doug Burks
d1e1887e36
Add support for Kratos audit logs in hunt.eventfields.json
2022-03-15 10:37:58 -04:00
Wes Lambert
5f56c7a261
Replace ELASTICCURL with so-elasticsearch-query
2022-03-15 14:32:00 +00:00
weslambert
d46620ea2a
Merge pull request #7561 from Security-Onion-Solutions/es_template_map_fix
...
Custom ES Template Fixes
2022-03-15 10:01:42 -04:00
Jason Ertel
408f9d6695
Update .gitleaks.toml
2022-03-15 09:53:27 -04:00
Jason Ertel
b810f14428
Update .gitleaks.toml
2022-03-15 09:53:11 -04:00
Jason Ertel
cec9cba40e
Create .gitleaks.toml
2022-03-15 09:47:57 -04:00
Jason Ertel
8ebeeb497f
add configuration to override leak detector defaults
2022-03-15 09:43:09 -04:00
Mike Reeves
9c80ff4f65
Remove hive from more files
2022-03-15 09:37:58 -04:00
Mike Reeves
81f0aa58b8
Remove hive from more files
2022-03-15 08:28:03 -04:00
Doug Burks
63cef4daff
Merge pull request #7557 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: surilogcompress cron job not running
2022-03-15 07:41:05 -04:00
Doug Burks
db4f138a78
FIX: surilogcompress cron job not running
...
The suricata user was originally created with `/opt/so/conf/suricata` as its home directory. I think at some point we changed permissions on `/opt/so/conf` and at that point the `surilogcompress` cron job stopped working. Changing the home directory to `/nsm/suricata` works on all of my PROD systems (including Ubuntu and CentOS).
For more information, please see:
https://github.com/Security-Onion-Solutions/securityonion/issues/7133
2022-03-15 07:10:02 -04:00
Mike Reeves
b5b60af16f
Remove hive from so-user
2022-03-14 15:06:07 -04:00
Mike Reeves
b83fec6fd2
More hive remova
2022-03-14 14:51:39 -04:00
Mike Reeves
ff30f572d7
Remove thehive from image common
2022-03-14 10:40:41 -04:00
Mike Reeves
95195c07fc
Disable hive in automation files
2022-03-14 10:36:23 -04:00
Jason Ertel
16f673d956
Merge pull request #7541 from Security-Onion-Solutions/kilo
...
Add assignee field to case list
2022-03-14 08:49:46 -04:00
Jason Ertel
5a28725def
Add assignee to case list
2022-03-14 08:45:28 -04:00
Wes Lambert
ba24f75893
Fix index typo
2022-03-11 18:11:16 +00:00
Wes Lambert
70ed20f691
Add new sls file for custom ES index templates
2022-03-11 18:07:23 +00:00
Wes Lambert
d12ff503c2
Chage role loading verbiage
2022-03-11 16:23:19 +00:00
Wes Lambert
dc258cf043
Load custom component templates in so-elasticsearch-templates-load
2022-03-11 16:22:55 +00:00
Wes Lambert
8e43a6e571
Don't generate index template if index_template definition is not present in pillar
2022-03-11 16:22:06 +00:00
m0duspwnens
e1e8a20e11
make sure values exist in data structure
2022-03-10 17:09:00 -05:00
Josh Brower
f0e44827a5
rm extra line
2022-03-10 08:48:46 -05:00
Josh Brower
814e16ba95
Force regen of ssl cert
2022-03-10 08:47:26 -05:00
Mike Reeves
7ca06df66f
Merge pull request #7484 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-03-09 14:50:52 -05:00
Mike Reeves
6f15acd2f9
Update VERSION
2022-03-09 14:50:14 -05:00
Mike Reeves
3725130128
Merge pull request #7481 from Security-Onion-Solutions/dev
...
2.3.110
2022-03-09 14:44:40 -05:00
Mike Reeves
2c66fa1883
Merge pull request #7482 from Security-Onion-Solutions/kilo
...
Merge master with .100 hotfix #3 into dev
2022-03-09 12:24:04 -05:00
Jason Ertel
61a3155dfa
merge from master
2022-03-09 12:22:24 -05:00
Mike Reeves
99f25deb80
Merge pull request #7480 from Security-Onion-Solutions/2.3.110rel
...
2.3.110
2022-03-09 12:16:31 -05:00
Mike Reeves
0cb628f565
2.3.110
2022-03-09 12:12:32 -05:00
weslambert
262e68cb75
Merge pull request #7469 from Security-Onion-Solutions/fix/kibana_config_load_template
...
Add .template extension to ensure we are loading the template and not the resultant file
2022-03-08 21:12:29 -05:00
weslambert
c83b63d0d8
Add .template extension to load template file
2022-03-08 20:53:16 -05:00
weslambert
8d9ddf5f1b
Add .template extension to load template
2022-03-08 20:52:13 -05:00
weslambert
8115da358f
Add .template extension to load template file
2022-03-08 20:51:50 -05:00
Doug Burks
06efef7b81
Merge pull request #7467 from Security-Onion-Solutions/dougburks-patch-1
...
Revert security_opt addition in telegraf init.sls
2022-03-08 18:51:52 -05:00
Doug Burks
b76c01ef53
Revert security_opt addition in telegraf init.sls
2022-03-08 18:27:15 -05:00
weslambert
5f3c29b7f8
Merge pull request #7466 from Security-Onion-Solutions/fix/process_name_keyword
...
Add process.name.keyword
2022-03-08 12:47:31 -05:00
weslambert
65f998d6f7
Remove process.name.keyword for future-proofing
2022-03-08 12:44:51 -05:00
weslambert
406267a892
Add process.name.keyword
2022-03-08 12:42:34 -05:00
weslambert
d9c3160fbf
Merge pull request #7465 from Security-Onion-Solutions/fix/kibana_saved_objects_load
...
Kibana dashboard/saved objects loading improvements
2022-03-08 12:22:55 -05:00
Wes Lambert
d392cb258c
Switch Kibana state to kibana.so_savedobjects_defaults in top file
2022-03-08 16:59:48 +00:00
Wes Lambert
86e228b200
Add .template extension for future-proofing config files
2022-03-08 16:58:37 +00:00
Wes Lambert
a6fd1023b4
Fix criteria for successful execution
2022-03-08 16:57:26 +00:00
Wes Lambert
3f31f7fd41
Add .template extension to fix script behavior and not modify watched file
2022-03-08 16:43:43 +00:00
Jason Ertel
f64da9632f
Merge pull request #7461 from Security-Onion-Solutions/kilo
...
Gracefully handle situations where another process is using the Kratos DB while so-user executes
2022-03-08 11:02:14 -05:00
Jason Ertel
0cec5879bb
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:55:26 -05:00
Jason Ertel
d8ca4976be
Merge branch 'dev' into kilo
2022-03-08 10:41:40 -05:00
Jason Ertel
914d81ca07
Revert "Gracefully handle situations when another process is using the Kratos DB"
...
This reverts commit f2865d8b7f .
2022-03-08 10:40:20 -05:00
Jason Ertel
f2865d8b7f
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:38:05 -05:00
Wes Lambert
28554164cd
Remove drop file when securitySolution saved objects change
2022-03-08 14:39:23 +00:00
Wes Lambert
14dddd8649
Remove drop file when config saved objects change
2022-03-08 14:37:15 +00:00
Wes Lambert
c0f49f6fb0
Remove drop file when dashbaord saved objects change
2022-03-08 14:35:04 +00:00
Wes Lambert
d10d4acf9f
Modify Kibana config load script to drop file if successfully executed
2022-03-08 14:33:15 +00:00
Doug Burks
da8e885ede
Merge pull request #7451 from Security-Onion-Solutions/fix/docker-apparmor
...
Update init.sls to avoid telegraf apparmor issues
2022-03-07 17:06:42 -05:00
Doug Burks
104de2a3c9
Update init.sls to avoid telegraf apparmor issues
...
See #2560
2022-03-07 16:11:22 -05:00
Mike Reeves
fb59421f5b
Merge pull request #7446 from Security-Onion-Solutions/fixpipelineload
...
Only load pipelines on change
2022-03-07 15:17:32 -05:00
weslambert
e2bda255cc
Merge pull request #7447 from Security-Onion-Solutions/fix/es_templates_soup
...
Remove old Elasticsearch index templates during SOUP
2022-03-07 15:10:44 -05:00
Mike Reeves
4eb37fd5a9
Update init.sls
2022-03-07 15:09:36 -05:00
Wes Lambert
fa9be58b23
Specify index templates
2022-03-07 20:04:23 +00:00
Wes Lambert
647b316a96
Remove old ES index templates
...
Signed-off-by: Wes Lambert <wlambertts@gmail.com >
2022-03-07 20:02:45 +00:00
Mike Reeves
d33db6fb23
Only load pipelines on change
2022-03-07 14:25:46 -05:00
weslambert
eac120f4c2
Merge pull request #7444 from Security-Onion-Solutions/fix/dtc_client_override
...
Add DTC client mappings
2022-03-07 13:38:19 -05:00
Wes Lambert
c549b20221
Add DTC client mappings
2022-03-07 18:36:26 +00:00
Mike Reeves
e6132be4e6
Merge pull request #7443 from Security-Onion-Solutions/fixtemplates
...
Only load templates on change
2022-03-07 10:42:51 -05:00
Mike Reeves
c67604590d
Only load templates on change
2022-03-07 09:52:18 -05:00
weslambert
5600b55f05
Merge pull request #7427 from Security-Onion-Solutions/fix/syslog_kibana_viz
...
Replace syslog facility and severity with label fields in Kibana syslog dashboard
2022-03-07 08:14:35 -05:00
Doug Burks
a59779905f
Merge pull request #7437 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo
2022-03-07 08:05:07 -05:00
Doug Burks
848a5c6350
fix typo
2022-03-07 08:03:41 -05:00
Wes Lambert
33ba45472f
Replace syslog facility and severity with label fields
2022-03-04 21:40:41 +00:00
weslambert
ee4035f022
Merge pull request #7426 from Security-Onion-Solutions/fix/syslog_zeek
...
Change to label fields for syslog facility and severity
2022-03-04 16:31:45 -05:00
weslambert
f71ccadb8a
Change to label fields for Zeek syslog
2022-03-04 16:29:55 -05:00
weslambert
fc3273fa49
Change to label fields to comply with what's defined in Filebeat template
2022-03-04 16:29:01 -05:00
weslambert
3148fa0e06
Merge pull request #7422 from Security-Onion-Solutions/fix/syslog_dot_keyword
...
.keyword additions and increase max_clause_count
2022-03-04 15:32:29 -05:00
weslambert
254cf53c2f
Increase clause count to 3500
2022-03-04 10:36:37 -05:00
Wes Lambert
ffae22beef
Add DTC syslog mappings for .keyword and add refs to defaults.yml
2022-03-04 13:04:11 +00:00
weslambert
93c2f82345
Merge pull request #7413 from Security-Onion-Solutions/fix/add_keyword_subfield
...
Add .keyword subfield for more mappings
2022-03-03 10:42:38 -05:00
Wes Lambert
1f71816ad7
Add keyword subfield for DTC winlog mappings
2022-03-03 14:54:30 +00:00
Wes Lambert
1c086e36da
Add missing comma for file mappings
2022-03-03 13:49:54 +00:00
Wes Lambert
aa8d24b6cd
Add DTC destination, source, and winlog mapping references to templates in defaults file
2022-03-03 13:42:20 +00:00
Wes Lambert
85979cbce8
Add file, process, and winlog mapping changes
2022-03-03 13:37:27 +00:00
Wes Lambert
8f97f09c9c
Additional .keyword changes for host.hostname client.address, and event.action
2022-03-02 21:54:46 +00:00
Wes Lambert
3ee46e4c29
Add .keyword for destination/source geo.country_name
2022-03-02 21:50:03 +00:00
weslambert
a21060306c
Merge pull request #7404 from Security-Onion-Solutions/fix/field_limit_adjustment
...
Adjust field limit for now due to component template errors
2022-03-02 11:41:35 -05:00
Wes Lambert
c5b16fdf3b
Adjust field limit for now
2022-03-02 16:33:39 +00:00
weslambert
b80e82aaf6
Merge pull request #7396 from Security-Onion-Solutions/fix/dot_security
...
Revert back to usage of .security field
2022-03-02 10:42:29 -05:00
Josh Brower
2ba72791aa
Remove sigma regen cron
2022-03-02 10:31:15 -05:00
Mike Reeves
d570b56c55
Merge pull request #7392 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix 2.3.100 20220301
2022-03-02 10:24:50 -05:00
Mike Reeves
ff4345d3aa
Merge pull request #7393 from Security-Onion-Solutions/jertelhf
...
Jertelhf
2022-03-02 10:20:29 -05:00
Jason Ertel
e59f0d69d9
Merge branch 'master' into jertelhf
2022-03-02 10:18:14 -05:00
Mike Reeves
ad2b69c9de
Merge pull request #7391 from Security-Onion-Solutions/hf0301
...
Hotfix 2.3.100 20220301
2022-03-02 10:08:27 -05:00
Mike Reeves
e874c32c08
Hotfix 2.3.100-20220301
2022-03-02 10:05:41 -05:00
Wes Lambert
ab9b81ea39
Change match_only_text to text for mac in host mappings
2022-03-02 15:01:05 +00:00
Wes Lambert
ed620b93b7
Add custom analyzer definition to all SO/DTC mappings
2022-03-02 14:43:19 +00:00
Wes Lambert
27c8eaa630
Update all other mappings for .security where applicable
2022-03-02 14:39:23 +00:00
Wes Lambert
e925d435ff
Update event, file, and host mappings to include .security
2022-03-02 14:33:52 +00:00
Wes Lambert
496b161253
Update ECS mappings to include .security
2022-03-02 14:27:36 +00:00
Wes Lambert
aae2fd1fbb
Update DNS mappings to include .security
2022-03-02 14:27:15 +00:00
Wes Lambert
0b45cf7ae1
Update base mappings to include .security
2022-03-02 14:25:57 +00:00
Wes Lambert
d89af5f04f
Update agent mappings to include .security
2022-03-02 14:25:14 +00:00
Wes Lambert
2d2ec45029
Modify base ECS mappings to include .security where possible, as well as custom analyzer definition
2022-03-02 14:19:36 +00:00
weslambert
93386f4620
Merge pull request #7389 from Security-Onion-Solutions/fix/revert_text
...
Fix/revert text
2022-03-02 09:17:46 -05:00
Mike Reeves
c0649a863b
Merge pull request #7376 from Security-Onion-Solutions/hfnew
...
Curator Fixes
2022-03-01 14:38:31 -05:00
Mike Reeves
e93dbb5347
Update Hotfix
2022-03-01 14:37:03 -05:00
doug
bbced5b52f
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:52 -05:00
Doug Burks
f134c74585
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:41 -05:00
Wes Lambert
5489b8559d
Revert "Switch from .security to match_only_text"
...
This reverts commit f7862af934 .
2022-03-01 18:44:00 +00:00
Wes Lambert
2a9caccc7c
Revert "Add additional .text subfield mappings"
...
This reverts commit 61dadc6249 .
2022-03-01 18:43:24 +00:00
Doug Burks
adf3dc0cf6
Merge pull request #7370 from Security-Onion-Solutions/fix/syslog
...
Revert syslog pipeline updates from Abe's PR for now
2022-03-01 11:13:13 -05:00
Wes Lambert
a290602a70
Revert syslog pipeline updates from Abe' PR for now
2022-03-01 15:31:07 +00:00
weslambert
4201ee45c6
Merge pull request #7369 from Security-Onion-Solutions/fix/ingest_timestamp
...
Rename ingest timestamp to event.ingested
2022-03-01 10:11:16 -05:00
Wes Lambert
038dc49098
Temporarily increase field limit before trimming efforts
2022-03-01 15:06:28 +00:00
Wes Lambert
dc07adca63
Rename ingest.timestamp to event.ingested
2022-03-01 15:05:08 +00:00
Josh Brower
39718561ce
Merge pull request #7366 from Security-Onion-Solutions/delta
...
Enable state tracking for sigma refresh
2022-03-01 05:53:14 -05:00
Josh Brower
e960d99901
Enable state tracking for sigma refresh
2022-02-28 21:18:41 -05:00
Josh Brower
09f1a5025d
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-28 21:18:07 -05:00
Josh Brower
41a58b791a
Enable state tracking for sigma refresh
2022-02-28 21:17:59 -05:00
Jason Ertel
73b2a36e89
Merge pull request #7365 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.17.1
2022-02-28 18:26:31 -05:00
Jason Ertel
f147bb33ed
Upgrade to ES 7.17.1
2022-02-28 18:18:09 -05:00
Josh Patterson
6b3b5e9a1f
Merge pull request #7363 from Security-Onion-Solutions/soup_singlenode_30
...
allow for check_log_size_limit to work without salt-master running
2022-02-28 17:13:42 -05:00
Josh Brower
f824717094
Merge pull request #7364 from Security-Onion-Solutions/delta
...
IDH Node verbiage
2022-02-28 17:09:08 -05:00
Josh Brower
0cee0d5dea
IDH Node verbiage
2022-02-28 16:47:24 -05:00
Josh Brower
d71bde0e38
Merge pull request #7362 from Security-Onion-Solutions/delta
...
Navigator - include attack json for airgap
2022-02-28 16:33:10 -05:00
Josh Brower
2075412ca2
Navigator - include attack json for airgap
2022-02-28 16:15:30 -05:00
m0duspwnens
a51f833f36
output only the value for log_size_limit
2022-02-28 16:13:43 -05:00
Jason Ertel
04a99a0adc
Merge pull request #7361 from Security-Onion-Solutions/kilo
...
Clear out hotfix file
2022-02-28 16:04:30 -05:00
Jason Ertel
166ac0d194
Clear out hotfix file
2022-02-28 16:01:42 -05:00
m0duspwnens
8d12e136f2
Merge remote-tracking branch 'remotes/origin/dev' into soup_singlenode_30
2022-02-28 15:43:37 -05:00
m0duspwnens
710059211d
remove debug echo, mkdir verbose
2022-02-28 14:54:39 -05:00
weslambert
a1c0ae4aab
Merge pull request #7356 from Security-Onion-Solutions/fix/es_config_load_order
...
Run template load first to prevent issues with pipeline changes that …
2022-02-28 14:50:22 -05:00
m0duspwnens
80e5198f9e
combine local and default pillars to get pillar values locally
2022-02-28 14:35:16 -05:00
m0duspwnens
dc24cb711d
need local to be --local
2022-02-28 13:50:08 -05:00
m0duspwnens
c5bf818049
debug messages and pass local to lookup_salt_value
2022-02-28 13:39:50 -05:00
weslambert
414b9dcd59
Run template load first to prevent issues with pipeline changes that generate new indices
2022-02-28 12:33:18 -05:00
m0duspwnens
cd981fa2ae
forgot then for if
2022-02-28 12:25:06 -05:00
m0duspwnens
278235b0ca
update so-common lookup_salt_value to accept local option. soup get minion id from grains with local option
2022-02-28 12:15:23 -05:00
weslambert
a9caef9596
Merge pull request #7338 from Security-Onion-Solutions/fix/endgame_template
...
Revert Endgame index name changes
2022-02-28 08:13:09 -05:00
Doug Burks
e0b3635318
Merge pull request #7339 from Security-Onion-Solutions/fix/zeek_dns-import
...
Avoid changing _index for imported logs
2022-02-27 05:09:00 -05:00
Doug Burks
32b71fdcac
Avoid changing _index for imported logs
2022-02-26 10:36:09 -05:00
Wes Lambert
bd1b21a5b6
Revert Endgame index name changes
2022-02-26 02:53:57 +00:00
weslambert
56cb8d62ab
Merge pull request #7337 from Security-Onion-Solutions/fix/pb_overrides
...
Fix formatting for PB overrides
2022-02-25 20:48:38 -05:00
weslambert
e942d81433
Ensure correct formatting for source override
2022-02-25 19:14:58 -05:00
weslambert
a511fd33e9
Ensure correct formatting for destination override
2022-02-25 19:14:21 -05:00
Doug Burks
74037e6f00
Merge pull request #7335 from Security-Onion-Solutions/fix/soup-postversion
...
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 15:27:31 -05:00
Josh Brower
25b0069353
Merge pull request #7334 from Security-Onion-Solutions/delta
...
IDH Setup - dont show ssh fix screen
2022-02-25 15:01:25 -05:00
Josh Brower
6a270eb8b3
IDH Setup - dont show ssh fix screen - fix
2022-02-25 14:58:30 -05:00
Josh Brower
ee39ec1882
IDH Setup - dont show ssh fix screen
2022-02-25 14:55:28 -05:00
Doug Burks
8df47e809d
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 14:30:59 -05:00
Mike Reeves
fa15a2e012
Merge pull request #7333 from Security-Onion-Solutions/endgamecurator
...
Fix endgame index name
2022-02-25 13:31:29 -05:00
Mike Reeves
15924ebe0f
Fix endgame index name
2022-02-25 13:29:29 -05:00
weslambert
c95f48e49a
Merge pull request #7330 from Security-Onion-Solutions/fix/pb-override
...
Override destination/source mappings with .keyword for Playbook
2022-02-25 13:07:31 -05:00
Wes Lambert
a8bdff89ae
Move files into SO component template directory
2022-02-25 18:00:16 +00:00
Wes Lambert
08097fe9ec
Add Playbook override mappings
2022-02-25 17:58:51 +00:00
Josh Brower
ce4c859f3a
Merge pull request #7328 from Security-Onion-Solutions/fix/soup-sigma-refresh
...
.110 Post processing - sigma refresh
2022-02-25 12:24:19 -05:00
Josh Patterson
9de9d92b2b
Merge pull request #7329 from Security-Onion-Solutions/delta
...
add extra hosts for filebeat on idh node
2022-02-25 12:23:37 -05:00
m0duspwnens
d76facb1bb
add extra hosts for idh node
2022-02-25 12:21:43 -05:00
Josh Brower
1abf27873d
.110 Post processing - sigma refresh
2022-02-25 12:19:59 -05:00
weslambert
a6ab09501e
Merge pull request #7326 from Security-Onion-Solutions/fix/additional_text_subfield_mappings
...
Add additional .text subfield mappings
2022-02-25 11:29:26 -05:00
Wes Lambert
61dadc6249
Add additional .text subfield mappings
2022-02-25 16:27:37 +00:00
Josh Brower
be80f0530c
Merge pull request #7321 from Security-Onion-Solutions/delta
...
IDH Improvements
2022-02-24 21:27:36 -05:00
Josh Brower
96ed3cb158
IDH - Setup Summary new lines
2022-02-24 20:59:47 -05:00
Josh Brower
4a597b9f0e
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-24 19:58:10 -05:00
Josh Brower
cf7325a546
IDH - Play tweaks, Setup summary, log rotate
2022-02-24 19:57:11 -05:00
Josh Patterson
8302c45059
Merge pull request #7320 from Security-Onion-Solutions/delta_ssh
...
default to false if local role doesnt exist
2022-02-24 18:06:19 -05:00
m0duspwnens
0970bbc983
default to false if local role doesnt exist
2022-02-24 17:55:50 -05:00
Josh Brower
e8e683c2e9
Merge pull request #7319 from Security-Onion-Solutions/delta
...
Add and Update IDH Plays
2022-02-24 15:48:38 -05:00
Josh Brower
fbc702375c
Add and Update IDH Plays
2022-02-24 15:06:04 -05:00
Josh Patterson
5c747fbb4c
Merge pull request #7318 from Security-Onion-Solutions/delta_ssh
...
change name of selinux policy state for idh node
2022-02-24 14:49:55 -05:00
m0duspwnens
8b61d4818d
change name of selinux policy state for idh node
2022-02-24 14:47:14 -05:00
weslambert
22b01dab1e
Merge pull request #7317 from Security-Onion-Solutions/fix/add_text_subfield_to_dtc_mappings
...
Add .text subfield mappings for DTC where fields are defined
2022-02-24 14:47:11 -05:00
Wes Lambert
0f8a39002f
Add .text subfield mappings for DTC where fields are defined
2022-02-24 19:39:52 +00:00
weslambert
5e29c71381
Merge pull request #7315 from Security-Onion-Solutions/fix/split_zeek_dns
...
Split Zeek DNS records into a separate index
2022-02-24 13:21:52 -05:00
weslambert
23fb62c0d6
Split Zeek DNS records into a separate index
2022-02-24 12:52:25 -05:00
weslambert
313487a887
Merge pull request #7313 from Security-Onion-Solutions/fix/kibana_dashboard_load
...
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:48:28 -05:00
weslambert
bc1794e437
Fix function name
2022-02-24 09:42:14 -05:00
Josh Patterson
d7aa413c46
Merge pull request #7314 from Security-Onion-Solutions/delta
...
default port 2222 for ssh idh node
2022-02-24 09:37:11 -05:00
weslambert
45ccfc5ad4
Add back post to .100 and call for .110
2022-02-24 09:35:43 -05:00
weslambert
582bf4c64c
Remove dashboard updates for .100 so we don't run twice
2022-02-24 09:25:59 -05:00
weslambert
7f08ecdcbe
Add function reference for .110 post changes
2022-02-24 09:25:15 -05:00
weslambert
a22e470038
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:20:44 -05:00
weslambert
bc2c1b4ccc
Merge pull request #6935 from abesinger/issue/6912
...
Updated syslog pipeline, resolves #6912 .
2022-02-24 08:33:55 -05:00
Josh Brower
5779e40401
Merge pull request #7308 from Security-Onion-Solutions/defensivedepth-patch-1
...
UC true
2022-02-24 07:48:39 -05:00
Josh Brower
585c275df6
UC true
2022-02-23 19:35:10 -05:00
Josh Brower
babc114d27
Merge branch 'delta' of https://github.com/Security-Onion-Solutions/securityonion into delta
2022-02-23 19:33:18 -05:00
Josh Brower
2bf20bd1f0
UC true
2022-02-23 19:33:10 -05:00
Josh Patterson
a9c6dc32ab
Merge pull request #7305 from Security-Onion-Solutions/delta_ssh
...
allow only manager to connect to ssh port for idh node
2022-02-23 15:17:31 -05:00
m0duspwnens
61ae61953f
allow only manager to connect to ssh port for idh node
2022-02-23 15:14:11 -05:00
weslambert
2aa811dcd2
Merge pull request #7300 from Security-Onion-Solutions/fix/new_es_template_config
...
Add IDH and Kratos index templates
2022-02-23 12:24:38 -05:00
weslambert
6a0ecb9e9c
Add IDH and Kratos index templates
2022-02-23 12:13:46 -05:00
Josh Brower
b7b2183c15
Merge pull request #7296 from Security-Onion-Solutions/delta
...
IDH - Import & Enables Plays
2022-02-23 10:52:37 -05:00
weslambert
00dbf54a5f
Merge pull request #7295 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-functions
2022-02-23 10:50:32 -05:00
Josh Brower
83aa261d88
IDH - Import & Enables Plays
2022-02-23 10:50:13 -05:00
Mike Reeves
c4cc3fa35f
Update so-functions
2022-02-23 10:47:37 -05:00
Josh Brower
0121eda536
Merge pull request #7282 from Security-Onion-Solutions/delta
...
Initial Support - IDH Node
2022-02-23 08:49:40 -05:00
Doug Burks
aadc2a844b
Merge pull request #7284 from Security-Onion-Solutions/fix/so-curator-closed-delete
...
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:40:23 -05:00
doug
1392fc37e8
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:00:52 -05:00
weslambert
9f7612b599
Merge pull request #7283 from Security-Onion-Solutions/fix/match_only_text
...
Switch from .security to using match_only_text with .text
2022-02-22 15:41:29 -05:00
Wes Lambert
f7862af934
Switch from .security to match_only_text
2022-02-22 20:33:49 +00:00
Josh Brower
1d95aca4de
IDH - VNC default port
2022-02-22 14:16:45 -05:00
Josh Brower
99554d5db8
IDH - UDP vs TCP support
2022-02-22 14:10:05 -05:00
Josh Brower
df9fc807a3
IDH - restart scripts, filebeat fix
2022-02-22 08:05:53 -05:00
Josh Brower
3610b0cd30
merge in dev
2022-02-21 16:52:53 -05:00
Josh Brower
eea2b9ccfd
IDH - Play - ssh
2022-02-21 16:43:26 -05:00
Josh Brower
05be776f4b
IDH - so-status
2022-02-21 16:41:36 -05:00
Doug Burks
5b46d19b13
Merge pull request #7273 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:25:58 -05:00
Doug Burks
1abd824c5f
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:00:05 -05:00
Josh Brower
2203e2fedd
IDH - Final setup fixes
2022-02-19 21:01:48 -05:00
Josh Brower
780cd38adf
IDH - setup tweaks
2022-02-19 12:28:45 -05:00
Mike Reeves
fc0e27a7ae
Merge pull request #7261 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update networks.cfg.jinja
2022-02-18 20:03:47 -05:00
Mike Reeves
0d1da5d1dc
Update networks.cfg.jinja
2022-02-18 20:02:50 -05:00
Josh Brower
bf477a1c19
IDH - Initial whiptail
2022-02-18 17:21:04 -05:00
weslambert
3124f2bd12
Merge pull request #7255 from Security-Onion-Solutions/fix/remove_old_templates
...
Remove old index templates
2022-02-18 15:23:07 -05:00
Jason Ertel
380f0ef93a
Merge pull request #7256 from Security-Onion-Solutions/kilo
...
Update password len requirements; clarify password update help
2022-02-18 15:19:08 -05:00
Jason Ertel
93e9548eaf
Require a minimum of 8 characters for passwords, to match Kratos min requirements
2022-02-18 15:14:48 -05:00
Wes Lambert
4d1533537b
Remove old index templates
2022-02-18 20:08:13 +00:00
Josh Brower
0362afb260
IDH - Finalize Firewall config
2022-02-18 13:23:48 -05:00
Josh Patterson
d14967dd45
Merge pull request #7251 from Security-Onion-Solutions/issue/7233
...
dont allow $ to be used for elasticsearch:auth or kibana:secrets
2022-02-18 13:22:22 -05:00
m0duspwnens
cb55af4c1c
dont allow $ to be used for elasticsearch:auth or kibana:secrets - https://github.com/Security-Onion-Solutions/securityonion/issues/7233
2022-02-18 13:13:56 -05:00
weslambert
87a5e64f12
Merge pull request #7249 from Security-Onion-Solutions/fix/component_index_association
...
Update component -> index association for file/scan mappings for Strelka
2022-02-18 12:19:41 -05:00
Josh Brower
8de5a054d4
Merge pull request #7248 from Security-Onion-Solutions/feature/kratos-log-ingest
...
Ingest Kratos logs
2022-02-18 11:56:20 -05:00
William Wernert
786b01c85a
Merge pull request #6496 from JamesMConroy/so-staus-tty
...
so-staus detects tty
2022-02-18 11:52:18 -05:00
Josh Brower
118277ebc5
Ingest Kratos logs
2022-02-18 11:49:02 -05:00
Mike Reeves
27299cbe1b
Merge pull request #7247 from christopherwoodall/patch-7
...
Update so-setup
2022-02-18 11:47:19 -05:00
Christopher Woodall
118266bf5f
Update so-setup
...
Patch so setup to ignore deprecation warnings.
2022-02-18 11:38:56 -05:00
Mike Reeves
5d949de146
Merge pull request #7246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update networks.cfg.jinja
2022-02-18 11:28:57 -05:00
Mike Reeves
6f4ee4123a
Update networks.cfg.jinja
2022-02-18 11:26:58 -05:00
Mike Reeves
e4148818d8
Merge pull request #7226 from Security-Onion-Solutions/zeekhn
...
Add Zeek Homenet in networks.cfg
2022-02-18 11:11:56 -05:00
Mike Reeves
becdc34677
Merge pull request #7227 from hacker0ni/patch-1
...
Allow downgrades in docker_install
2022-02-18 11:10:26 -05:00
Mike Reeves
95eab61615
Rename to the .jinja standard
2022-02-18 11:06:33 -05:00
Mike Reeves
9341669a15
Merge pull request #7244 from christopherwoodall/patch-6
...
Update config.map.jinja
2022-02-18 09:57:33 -05:00
Jason Ertel
fdc63b5816
Clarify so-user update usage/help
2022-02-18 09:41:09 -05:00
Christopher Woodall
eaff6a12de
Update config.map.jinja
...
Extend the array instead of appending.
2022-02-18 08:50:28 -05:00
weslambert
6ee3287d2d
Update component -> index association for file/scan mappings for Strelka
2022-02-18 08:12:34 -05:00
James Conroy
91c207cd38
Update salt/common/tools/sbin/so-status
...
Removed # {% raw %} from line 170
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:43 -06:00
James Conroy
b774e62dfa
Update salt/common/tools/sbin/so-status
...
Add salt raw directive
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:25 -06:00
Josh Brower
f995d0768f
IDH - Initial firewall support
2022-02-17 15:54:20 -05:00
Doug Burks
3b887c7b1a
Merge pull request #7239 from Security-Onion-Solutions/dougburks-patch-1
...
so-ip-update needs to queue the Kibana dashboard update
2022-02-17 15:54:10 -05:00
Doug Burks
b4b7938ce2
so-ip-update needs to queue the Kibana dashboard update in case a salt operation is already running
2022-02-17 15:47:33 -05:00
Doug Burks
e5d7c1c77a
Merge pull request #7238 from Security-Onion-Solutions/dougburks-patch-1-1
...
so-ip-update needs to update Kibana dashboards
2022-02-17 14:53:31 -05:00
Doug Burks
1a96162966
so-ip-update needs to update Kibana dashboards
2022-02-17 14:49:55 -05:00
hacker0ni
bc72b3da91
Allow downgrades in docker_install
...
When running the installer again on a new node, it tries to pull the docker packages but since the installer ran again before, the install command fails on Ubuntu 18.04 stating that the `--allow-downgrades` is not specified in the command. This change adds that to circumvent the issue.
2022-02-17 11:47:36 -05:00
Mike Reeves
3e194c9b4b
Walk the homenet for zeek
2022-02-17 11:33:22 -05:00
Josh Brower
6c124733b5
IDH - Enable default states
2022-02-17 10:50:26 -05:00
weslambert
6842099e11
Merge pull request #7224 from Security-Onion-Solutions/fix/zeek_viz
...
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 10:05:46 -05:00
Wes Lambert
5c1f61bda8
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 15:03:46 +00:00
weslambert
53c7ad6041
Merge pull request #7223 from Security-Onion-Solutions/fix/shard_settings_setup
...
Ensure setup configures pillar correctly for index settings
2022-02-17 09:48:11 -05:00
Josh Brower
ef4df58510
IDH - Jinjafy hostname
2022-02-17 09:00:57 -05:00
weslambert
c0f9cb188b
Add missing colon
2022-02-17 07:58:05 -05:00
weslambert
d309c4fc0a
Update pillar structure for index_settings/shards
2022-02-17 07:10:29 -05:00
Jason Ertel
cb9712aa08
Merge pull request #7217 from Security-Onion-Solutions/kilo
...
MFA
2022-02-16 16:47:40 -05:00
weslambert
d084625ee0
Merge pull request #7218 from Security-Onion-Solutions/fix/composable_templates_soup
...
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:24:57 -05:00
weslambert
e71b606dd6
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:22:06 -05:00
weslambert
f1f9322bee
Merge pull request #7216 from Security-Onion-Solutions/fix/es_template_netflow_mappings_indent
...
Fix indent for so-netflow component template references
2022-02-16 14:47:31 -05:00
weslambert
185ea2fd99
Fix indent for so-netflow component template references
2022-02-16 14:46:12 -05:00
Mike Reeves
89eb2d0a8b
Add netowrks.cfg to Zeek
2022-02-16 14:24:58 -05:00
Jason Ertel
2c4ba75c0c
Merge branch 'dev' into kilo
2022-02-15 17:05:24 -05:00
weslambert
9e222b1464
Merge pull request #7206 from Security-Onion-Solutions/feature/template-reorg
...
Re-organize Elasticsearch Index Templates
2022-02-15 16:50:14 -05:00
Josh Brower
3ccef12df7
IDH - Pillarize OpenCanary Config
2022-02-15 13:57:31 -05:00
Wes Lambert
4fa3749418
Remove bind or ES templates
2022-02-15 18:08:03 +00:00
Wes Lambert
786a189f65
Merge branch 'feature/template-reorg' of https://github.com/security-onion-solutions/securityonion into feature/template-reorg
2022-02-15 17:06:02 +00:00
Wes Lambert
de731fc05d
Remove default templates from ES template pillar since they are now managed in the defaults file.
2022-02-15 17:04:57 +00:00
Wes Lambert
3df58eadd1
Modify logic to include custom templates
2022-02-15 17:00:24 +00:00
weslambert
1a53ec4372
Fix malformed copy/paste
2022-02-15 11:14:10 -05:00
Wes Lambert
dce3b7a874
Update defaults file to include ES index templates
2022-02-15 15:53:07 +00:00
Jason Ertel
377fe1987d
Merge branch 'dev' into kilo
2022-02-15 07:49:26 -05:00
Jason Ertel
d97423e9f8
Enable MFA support
2022-02-15 07:49:12 -05:00
Wes Lambert
8e389bf6e5
Add ES template map file
2022-02-14 15:38:32 +00:00
Wes Lambert
ebce67060f
Initial template refactor
2022-02-14 15:20:33 +00:00
James Conroy
a43ac2aea2
Move the jinja endraw directive below is_tty
...
This will prevent jninja from interpreting the shell string length
expansion as the start of jninja comments
2022-02-12 12:25:24 -06:00
James Conroy
95b4f7b4ef
Update the PADDING_CONSTENT to 15
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3046e811f0
Use spaces to define centerd justification output
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
6a1e586b8c
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
01346cbb06
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3adb6c1389
Renamed colors to attributes
...
Also correctly used tput to assign blue color
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dabae3888f
Renamed colors to attributes
...
As suggested by rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
c69e968790
Renamed Colors to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dfcabb5722
Seperate bold attribute from colors
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
b9b3876069
Exit with an error code if the user isn't root
2022-02-12 12:25:23 -06:00
James Conroy
bfcfad2e7d
Check for tty in main
...
So that the value is set every time it is checked
2022-02-12 12:25:23 -06:00
James Conroy
163182c858
Don't set the padding constant if not in a tty
...
This will preserve the original width from before my changes
2022-02-12 12:25:23 -06:00
James Conroy
6b4549499d
Don't split lines after standalone tests
...
This is to make the formatting consistent with the rest of the scripts
2022-02-12 12:25:23 -06:00
James Conroy
68a5826d70
Always print a line of '-'
...
Even when not printing to a tty
This is behavior preferred by the team
2022-02-12 12:25:22 -06:00
James Conroy
daa73c8845
Removed MYNAME variable
...
Preferring to just use the value of $0 instead
2022-02-12 12:25:22 -06:00
James Conroy
7f694c17ed
Revert improvements to usage function
...
Made to make it more consistent with the rest of the scripts in
Security Onion
2022-02-12 12:25:22 -06:00
James Conroy
fd9a03a77f
Added Changes Suggested by Reviewer
...
Added a missing semi colon between a local variable's declaration and
assignment
Removed an unused return value
Made a TODO more descriptive
2022-02-12 12:25:22 -06:00
James Conroy
2993a20947
Moved line declaration out of tty conditional
...
This way it will always be set to ""
2022-02-12 12:25:22 -06:00
James Conroy
ac5527e1ab
Added Comments for future enhancements
2022-02-12 12:25:22 -06:00
James Conroy
715f9da6e2
Reworked tty detection and status printing
...
I was able to reduce the line count and make the script more reliable
2022-02-12 12:25:22 -06:00
James Conroy
caa06b026f
Refactored to reduce length and number of lines
2022-02-12 12:25:21 -06:00
James Conroy
a048de65ca
Print help message if not running as root
2022-02-12 12:25:21 -06:00
James Conroy
f807471a17
Only print color codes if we're printing to a tty
...
If we're not printing to a tty the escape sequences can only clutter the
screen.
Also removed a redundant function to print lines if not printing to a
tty. It was only called if docker wasn't running, not if the output
wasn't a tty.
2022-02-12 12:25:21 -06:00
James Conroy
81122d0693
Updated the useage function to use printf
...
Using a hear doc means we have to exactly specify the formatting. Useing
printf handles formatting for us
2022-02-12 12:25:21 -06:00
Josh Brower
1e5b9ef0bf
IDH - Enable Filebeat
2022-02-10 11:37:10 -05:00
Josh Brower
b66472eced
IDH - disable nginx
2022-02-09 14:56:56 -05:00
Josh Brower
f31fbbf1ed
IDH - states allowed
2022-02-09 13:57:18 -05:00
William Wernert
1fee5e6a60
Merge pull request #7162 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Also merge CONTRIBUTING.md changes to dev
2022-02-09 11:59:00 -05:00
William Wernert
bc5fa55ecd
Merge pull request #7160 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Update CONTRIBUTING.md
2022-02-09 11:49:52 -05:00
William Wernert
2e2eed9f42
PR's -> pull requests
2022-02-09 11:45:12 -05:00
William Wernert
3f83191083
Update CONTRIBUTING.md
2022-02-09 11:34:39 -05:00
Josh Brower
30c40ed3d7
IDH Initial Support
2022-02-09 10:37:47 -05:00
Mike Reeves
d63fe73c90
Merge pull request #7157 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update to 7.17.0
2022-02-09 09:46:25 -05:00
Mike Reeves
51bd266717
Update to 7.17.0
2022-02-09 09:44:28 -05:00
weslambert
380fa7d0c8
Merge pull request #7153 from Security-Onion-Solutions/fix/dtc_event_mappings
...
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 16:36:49 -05:00
Wes Lambert
9b841fd872
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 21:34:32 +00:00
weslambert
c216457a3e
Merge pull request #7147 from Security-Onion-Solutions/fix/ct_snyk
...
Add Snyk component template
2022-02-08 10:25:27 -05:00
Wes Lambert
c2c4e4df17
Add Snyk component template
2022-02-08 15:23:43 +00:00
weslambert
7be1549d41
Merge pull request #7146 from Security-Onion-Solutions/feature/additional_dtc_ct
...
Additional component templates
2022-02-08 10:12:31 -05:00
Josh Brower
ac8e06e79b
Initial support - IDH Node
2022-02-08 09:08:52 -05:00
Josh Brower
a3602c9eb9
Initial support - IDH Node
2022-02-08 08:24:15 -05:00
Wes Lambert
f9a50d33c3
Add new templates
2022-02-08 13:17:23 +00:00
Wes Lambert
2951e12c96
Remove snyk component template for now and fix folder structure
2022-02-08 13:16:59 +00:00
Wes Lambert
6d0ca6fcbb
Fix mangled key name/typo
2022-02-08 12:59:07 +00:00
Wes Lambert
2dd5db15b6
Add component and index template listing scripts
2022-02-08 03:40:42 +00:00
Wes Lambert
5090854d4d
Add additional component templates and index template references
2022-02-08 03:03:55 +00:00
Josh Brower
37b17b8821
Initial support - IDH Node
2022-02-07 19:27:51 -05:00
Josh Brower
f590bc43a6
Initial support - IDH Node
2022-02-07 19:09:27 -05:00
Josh Brower
7a9cb6d110
Initial support - IDH Node
2022-02-07 16:49:11 -05:00
weslambert
b41c5439c6
Merge pull request #7141 from Security-Onion-Solutions/fix/index_template_mapping_reference
...
Add mapping references for new component templates to index templates
2022-02-07 15:06:19 -05:00
Wes Lambert
1366e5288e
Add mappings references for new component templates to index templates
2022-02-07 19:54:23 +00:00
weslambert
f9196a8228
Merge pull request #7140 from Security-Onion-Solutions/feature/dtc_new_mappings
...
New DTC/Component Template Mappings
2022-02-07 14:47:07 -05:00
Wes Lambert
03bfb052ed
Add component templates for Elasticsearch, Kibana, Logstash, Netflow, Suricata, and Zeek
2022-02-07 19:42:24 +00:00
Josh Brower
9b1fac8417
Initial support - IDH Node
2022-02-07 14:36:40 -05:00
weslambert
c9b40d8569
Merge pull request #7136 from Security-Onion-Solutions/feature/so_es_indices_list_sort
...
Sort index listing alphabetically and add header
2022-02-07 09:34:58 -05:00
Wes Lambert
50215c550b
Sort index listing alphabetically and add header (@gebhard73)
2022-02-07 14:31:42 +00:00
Josh Patterson
ee17064585
Merge pull request #7122 from Security-Onion-Solutions/soup_docker_iso
...
Soup docker iso
2022-02-07 09:29:35 -05:00
Josh Patterson
e0c0eba24e
Update soup
2022-02-07 09:23:30 -05:00
Josh Patterson
7d09d1f7e2
Update soup
2022-02-07 09:22:43 -05:00
Mike Reeves
77fc9df448
Merge pull request #7134 from Security-Onion-Solutions/mastermerger
...
Mastermerger
2022-02-07 08:38:27 -05:00
Mike Reeves
abd121733f
Merge branch 'master' into mastermerger
2022-02-07 08:34:17 -05:00
m0duspwnens
7c31eb1288
mount iso at different point
2022-02-04 16:07:06 -05:00
m0duspwnens
780aace854
set AGDOCKER
2022-02-04 15:44:25 -05:00
m0duspwnens
eb0696b425
update dockers if -f used
2022-02-04 15:36:44 -05:00
m0duspwnens
267ef354c2
unmount iso after updating dockers
2022-02-04 15:09:35 -05:00
m0duspwnens
23fbf140ba
soup with dockers from iso
2022-02-04 15:06:42 -05:00
weslambert
d0b54a3a34
Merge pull request #7119 from Security-Onion-Solutions/feature/dtc_additional
...
Add additional scan and rule fileset mappings
2022-02-04 14:14:20 -05:00
Wes Lambert
317f6471d8
Add additional scan and rule filset mappings
2022-02-04 19:05:09 +00:00
weslambert
08c7181f1a
Merge pull request #7118 from Security-Onion-Solutions/fix/dtc_file_mappings
...
Fix/dtc file mappings
2022-02-04 13:22:11 -05:00
Wes Lambert
1ce8bb3523
Fix winlog mapping reference reversion
2022-02-04 18:14:01 +00:00
Wes Lambert
5e03b1a5de
Fix reference for file mappings in template
2022-02-04 18:11:03 +00:00
weslambert
898db542bf
Merge pull request #7117 from Security-Onion-Solutions/feature/winlog_dtc_mappings
...
Add winlog mappings
2022-02-04 12:16:16 -05:00
weslambert
66452b14ef
Merge pull request #7116 from Security-Onion-Solutions/fix/endgame_mappings
...
Fix EG template and mappings
2022-02-04 12:16:07 -05:00
Wes Lambert
69cb83cac9
Add winlog mappings
2022-02-04 17:08:26 +00:00
Wes Lambert
f3902cf77d
Fix EG template and mappings
2022-02-04 16:00:16 +00:00
weslambert
1af63edc6b
Merge pull request #7115 from Security-Onion-Solutions/feature/additional_dtc_mappings
...
Additional DTC mapping changes
2022-02-04 10:46:47 -05:00
Wes Lambert
a3031b2b5c
Additional DTC mapping changes
2022-02-04 15:38:51 +00:00
Doug Burks
e54ece06a2
Merge pull request #7106 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-03 16:25:04 -05:00
Mike Reeves
cc986c8d7c
Merge pull request #7105 from Security-Onion-Solutions/23100hotfix2
...
2.3.100 Hotfix 2
2022-02-03 16:04:06 -05:00
Mike Reeves
b7732fb14a
2.3.100 Hotfix 2
2022-02-03 15:58:26 -05:00
Mike Reeves
6f03662120
Merge pull request #7102 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update HOTFIX
2022-02-03 15:08:52 -05:00
Mike Reeves
4f2952105e
Update HOTFIX
2022-02-03 15:06:18 -05:00
Josh Patterson
b34d0d7f7a
Merge pull request #7100 from Security-Onion-Solutions/100_hotfix_2
...
100 hotfix 2
2022-02-03 13:15:37 -05:00
weslambert
1edc1dd842
Merge pull request #7096 from Security-Onion-Solutions/fix/dtc-ct-keyword-subfield
...
Add more DTC transition mappings
2022-02-03 12:35:34 -05:00
Wes Lambert
1ce386bb7f
Add more DTC transition mappings
2022-02-03 17:33:05 +00:00
weslambert
c7d23df000
Merge pull request #7076 from Security-Onion-Solutions/fix/zeek_dns_answers_name
...
Rename dns.answers to prevent field conflict
2022-02-03 12:22:26 -05:00
m0duspwnens
797d769661
use actual hostname in logstash:nodes pillar
2022-02-03 10:36:18 -05:00
Mike Reeves
bbd2f0da2b
Merge pull request #7094 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update distributed-airgap-manager
2022-02-03 10:36:09 -05:00
Mike Reeves
5c39162aef
Update distributed-airgap-sensor
2022-02-03 10:34:55 -05:00
Mike Reeves
d8a4301533
Update distributed-airgap-manager
2022-02-03 10:34:12 -05:00
Doug Burks
c39047666b
Merge pull request #7082 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-02 16:38:27 -05:00
Mike Reeves
5c75bb8e7a
Merge pull request #7080 from Security-Onion-Solutions/23100hotfix
...
2.3.100 Hotfix
2022-02-02 16:30:46 -05:00
Mike Reeves
83683ec27e
2.3.100 Hotfix
2022-02-02 16:23:51 -05:00
Mike Reeves
b94cae0176
2.3.100 Hotfix
2022-02-02 16:22:44 -05:00
Mike Reeves
fc0824ceb0
2.3.100 Hotfix
2022-02-02 16:20:49 -05:00
weslambert
c5b5c5858e
Rename to prevent field conflict
2022-02-02 14:31:46 -05:00
weslambert
5e9e0d971b
Merge pull request #7070 from Security-Onion-Solutions/feature/composable_templates
...
Initial composable template configuration and base mappings
2022-02-02 10:25:15 -05:00
Mike Reeves
73a43f3816
Merge pull request #7069 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-02-02 09:57:26 -05:00
Mike Reeves
8152aec22e
Update HOTFIX
2022-02-02 09:49:19 -05:00
Mike Reeves
0e28e1e4cb
Merge pull request #7066 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2022-02-02 09:22:00 -05:00
Josh Patterson
13f87e4654
Merge pull request #7067 from Security-Onion-Solutions/m0duspwnens-patch-2.3.100
...
FIX: ssl state and manager hostname with uppercase
2022-02-02 09:21:54 -05:00
Josh Patterson
a02fb37493
Update init.sls
2022-02-02 09:18:02 -05:00
Mike Reeves
eaeed07fd4
Update acng.conf
2022-02-02 09:12:29 -05:00
Wes Lambert
9db1510b0e
Initial composable template configuration and base mappings
2022-02-02 02:08:31 +00:00
Jason Ertel
1bac031975
Merge pull request #7058 from Security-Onion-Solutions/kilo
...
Bump to 2.3.110
2022-02-01 15:04:48 -05:00
Jason Ertel
c5d6f09320
Bump to 2.3.110
2022-02-01 15:03:41 -05:00
Mike Reeves
943edd0303
Merge pull request #7042 from Security-Onion-Solutions/dev
...
2.3.100 Release
2022-01-31 16:29:57 -05:00
Mike Reeves
b49524a293
Merge pull request #7041 from Security-Onion-Solutions/23100release
...
2.3.100 Release
2022-01-31 14:07:02 -05:00
Mike Reeves
6dc8415af5
2.3.100 Release
2022-01-31 14:05:22 -05:00
Doug Burks
7927534279
Merge pull request #7040 from Security-Onion-Solutions/dougburks-patch-1
...
Update version from 2.3.91 to 2.3.100
2022-01-31 13:32:05 -05:00
Doug Burks
e0f6b9af3a
Update version from 2.3.91 to 2.3.100
2022-01-31 13:27:45 -05:00
weslambert
6a2111c2ae
Merge pull request #7037 from Security-Onion-Solutions/fix/revert_zeek_dns_answers
...
Revert back to dns.answers for now
2022-01-31 09:55:22 -05:00
weslambert
367b59188b
Revert back to dns.answers for now
2022-01-31 09:54:39 -05:00
Josh Patterson
d3fc61e557
Merge pull request #7035 from Security-Onion-Solutions/soup_salt_repo
...
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager…
2022-01-31 09:05:45 -05:00
m0duspwnens
4dd0ce9f2c
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager and managerupdates is enabled
2022-01-31 09:01:18 -05:00
Josh Patterson
0c5b4c6070
Merge pull request #7033 from Security-Onion-Solutions/receiver_grafana
...
Receiver grafana
2022-01-31 08:41:56 -05:00
Josh Patterson
a8983dd895
Merge pull request #7028 from Security-Onion-Solutions/soup_salt_repo
...
Soup salt repo
2022-01-31 08:21:17 -05:00
m0duspwnens
e189f10a1b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into soup_salt_repo
2022-01-29 11:04:07 -05:00
m0duspwnens
a90660c07b
ensure salt-latest.repo is absent, salt.minion state include repo.client
2022-01-29 11:04:03 -05:00
Mike Reeves
bb87c85e07
Merge pull request #7027 from Security-Onion-Solutions/fix/soup-kibana
...
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 10:07:36 -05:00
Doug Burks
bc0a362b39
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 08:02:56 -05:00
m0duspwnens
3aee8656d4
fix %} - add redis to receiver telegraf
2022-01-28 17:45:12 -05:00
m0duspwnens
980a1a0c3d
add redis to receiver telegraf
2022-01-28 17:44:04 -05:00
m0duspwnens
bf26ae8e41
add receiver to allowed dashboards
2022-01-28 17:32:53 -05:00
m0duspwnens
da3e1e402a
add receiver dashboard grafana
2022-01-28 17:27:58 -05:00
m0duspwnens
1cd1ad9214
add inputs for so-receiver to telegraf conf
2022-01-28 17:18:31 -05:00
Josh Patterson
ddba4a5fe5
Merge pull request #7024 from Security-Onion-Solutions/soup_receiver
...
Soup receiver
2022-01-28 17:01:04 -05:00
m0duspwnens
c8b1e6f501
remove -X from UPGRADECOMMAND so salt-minion starts after upgrade
2022-01-28 15:49:53 -05:00
m0duspwnens
c45efebc7f
Merge remote-tracking branch 'remotes/origin/dev' into soup_receiver
2022-01-28 15:27:27 -05:00
m0duspwnens
014696f62f
fix receiver append to assigned_hostgroups.local.map.yaml
2022-01-28 15:26:37 -05:00
m0duspwnens
6b18551dd1
skip applying repo.client if airgap and saltupgrade prior to yum clean all
2022-01-28 14:39:10 -05:00
weslambert
4ecf4ab253
Merge pull request #7020 from Security-Onion-Solutions/feature/dash_updates
...
EG and HL Dashboard Updates
2022-01-28 13:19:02 -05:00
m0duspwnens
75b8d6a0c5
ensure /etc/yum.repos.d/securityonioncache.repo is absent if global:managerupdate = 0
2022-01-28 13:09:48 -05:00
weslambert
5142e6ccc7
Update so-kibana-config-load
2022-01-28 13:01:33 -05:00
Wes Lambert
3b76c2421c
Update to allow for passing HL saved objects
2022-01-28 17:59:34 +00:00
m0duspwnens
e82c6a2393
default for managerupdate should be int not a string
2022-01-28 12:50:58 -05:00
m0duspwnens
905ca35e93
use sed instead of echo
2022-01-28 11:19:54 -05:00
m0duspwnens
3977146a16
add receiver to firewall files during soup
2022-01-28 10:36:30 -05:00
Josh Patterson
5a37b14809
Merge pull request #7017 from Security-Onion-Solutions/issue/7016
...
dont apply wazuh state on sensors if it is disabled globally
2022-01-28 09:33:34 -05:00
m0duspwnens
15c29bda74
dont apply wazuh state on sensors if it is disabled globally - https://github.com/Security-Onion-Solutions/securityonion/issues/7016
2022-01-28 09:31:02 -05:00
Josh Patterson
d0186c8c1b
Merge pull request #7011 from Security-Onion-Solutions/fix/reinstall
...
https://github.com/Security-Onion-Solutions/securityonion/issues/7010
2022-01-27 16:40:37 -05:00
Jason Ertel
ac21bd1e29
Merge pull request #7009 from Security-Onion-Solutions/kilo
...
Add new abbreviated result limit param
2022-01-27 15:55:42 -05:00
Jason Ertel
14c587fca2
Add new abbreviated result limit param
2022-01-27 15:51:02 -05:00
m0duspwnens
6cc8e4355e
exclude salt ERROR seen during reinstall
2022-01-27 15:31:42 -05:00
m0duspwnens
e63f35a223
change to test
2022-01-27 15:19:33 -05:00
weslambert
69689b470b
Merge pull request #7005 from Security-Onion-Solutions/fix/revert_cases_field_limit
...
Revert field limit from testing
2022-01-27 11:33:31 -05:00
weslambert
fc0a5bce86
Revert field limit from testing
2022-01-27 11:18:35 -05:00
weslambert
39257df396
Merge pull request #7004 from Security-Onion-Solutions/fix/revert_dtc
...
Revert changes to common template
2022-01-27 11:15:50 -05:00
weslambert
60a0204975
Revert changes to common template
2022-01-27 11:02:47 -05:00
William Wernert
c6b11f4e05
Merge pull request #7001 from Security-Onion-Solutions/fix/so-rule-string-split
...
Fix error message printing in so-rule
2022-01-26 16:08:00 -05:00
William Wernert
4532de368a
Fix error message printing in so-rule
2022-01-26 16:04:45 -05:00
m0duspwnens
9e2278a199
Merge remote-tracking branch 'remotes/origin/dev' into fix/reinstall
2022-01-26 15:48:46 -05:00
weslambert
e303fb12cf
Merge pull request #7000 from Security-Onion-Solutions/fix/zeek_dns_answers_pipeline
...
Fix Zeek field name so it doesn't conflict with mapping of other dns.…
2022-01-26 15:04:12 -05:00
weslambert
8f0a327cb5
Fix Zeek field name so it doesn't conflict with mapping of other dns.answers fields
2022-01-26 15:02:59 -05:00
weslambert
bdc5e89822
Merge pull request #6999 from Security-Onion-Solutions/fix/case_mapping_changes_temp
...
Mapping changes for case index
2022-01-26 14:59:45 -05:00
weslambert
1b3e7f9d79
Temp changes while adjusting mapping
2022-01-26 14:57:16 -05:00
Josh Patterson
4f30d43611
Merge pull request #6998 from Security-Onion-Solutions/es_binds
...
mount repo dir in container same as defined on host
2022-01-26 13:59:17 -05:00
m0duspwnens
c80adc0430
mount repo dir in container same as defined on host
2022-01-26 13:42:56 -05:00
weslambert
e77648c475
Merge pull request #6994 from Security-Onion-Solutions/feature/dtc
...
Additional DTC changes
2022-01-26 12:22:48 -05:00
Jason Ertel
c2636036ee
Merge pull request #6995 from Security-Onion-Solutions/kilo
...
store related event data as a flattened object blob
2022-01-26 12:21:02 -05:00
Wes Lambert
e10749a495
Additional changes to template to accomodate default fields and keyword subfield
2022-01-26 17:16:29 +00:00
Jason Ertel
ed9b74dc33
store related event data as a flattened object blob
2022-01-26 12:16:05 -05:00
m0duspwnens
2aa19b78da
dont remove ca-certificates.crt
2022-01-26 11:27:35 -05:00
m0duspwnens
1337af9d69
more dupes
2022-01-26 11:07:06 -05:00
m0duspwnens
a0e493a186
remove dupe ids
2022-01-26 10:50:35 -05:00
m0duspwnens
a43fb293fc
remove role logic
2022-01-26 10:26:52 -05:00
m0duspwnens
8aa002b82e
add states to remove ca and ssl keys and certs and call them during reinstall.
2022-01-26 09:33:19 -05:00
m0duspwnens
8ce0f5b7be
log removal of root cron
2022-01-26 08:31:37 -05:00
Josh Patterson
26e03ccad2
Merge pull request #6978 from Security-Onion-Solutions/es_binds
...
allow for path.repo mounts for elasticsearch
2022-01-25 16:13:49 -05:00
m0duspwnens
dd00e3babc
use .get since repo may not exist
2022-01-25 13:18:21 -05:00
m0duspwnens
5d2b3992e2
dont need to set ES_PATH_REPO
2022-01-25 13:11:53 -05:00
m0duspwnens
7b6eeac03f
dnt mount under /repo in the container
2022-01-25 13:08:46 -05:00
m0duspwnens
00e17d5c78
put repos in /repo in es container
2022-01-25 13:03:54 -05:00
m0duspwnens
a17e1aa87a
930 for group
2022-01-25 13:00:04 -05:00
m0duspwnens
4423e93880
prevent path.repo from being put in elasticsearch.yml if the symlink doesnt exist
2022-01-25 12:57:05 -05:00
m0duspwnens
e62de2934c
fix test for es repo
2022-01-25 12:24:03 -05:00
m0duspwnens
a92e2a917b
change repos to repo
2022-01-25 10:53:28 -05:00
m0duspwnens
a72f12c4c7
add path.repo mount if symlink exists
2022-01-25 10:50:00 -05:00
Josh Patterson
9a45a9799b
Merge pull request #6974 from Security-Onion-Solutions/issue/6599
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6599
2022-01-25 09:11:33 -05:00
weslambert
ba52bd3835
Update template with syntax fixes
2022-01-25 08:56:03 -05:00
m0duspwnens
edd8709cdd
remove export LC_CTYPE="en_US.UTF-8" from soup
2022-01-24 19:42:56 -05:00
m0duspwnens
d6fc436d49
copy files to default salt base
2022-01-24 19:30:34 -05:00
m0duspwnens
82e2b2b611
dont escape raw and endraw
2022-01-24 17:03:25 -05:00
m0duspwnens
d083338350
adding --local
2022-01-24 16:46:29 -05:00
m0duspwnens
e3f1b456e6
add raw end raw back
2022-01-24 16:09:15 -05:00
m0duspwnens
268e07e2a2
remove jinja from soup scripts
2022-01-24 15:49:55 -05:00
Doug Burks
80b7487d45
Merge pull request #6968 from Security-Onion-Solutions/dougburks-patch-1
...
Update CONTRIBUTING.md with warning about more involved PRs
2022-01-24 10:39:40 -05:00
Jason Ertel
4ab7a6a079
Merge pull request #6967 from Security-Onion-Solutions/kilo
...
Copyright year and format update
2022-01-24 10:39:31 -05:00
Doug Burks
5f67dfd432
Update CONTRIBUTING.md
2022-01-24 10:36:22 -05:00
Jason Ertel
eefcc929c2
Update copyright pattern to match other repos
2022-01-24 10:09:23 -05:00
Jason Ertel
a4d2807fbb
Switch to httpcase for consistency
2022-01-24 09:45:07 -05:00
Doug Burks
fb5bff3913
Merge pull request #6956 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typos in ssh_warning
2022-01-24 09:39:40 -05:00
Jason Ertel
7c22f46a55
Update copyright year for 2022
2022-01-24 09:35:29 -05:00
Doug Burks
b103420100
fix typo in so-setup
2022-01-22 10:25:37 -05:00
Doug Burks
304ef64bc8
fix another typo in ssh_warning
2022-01-22 10:24:36 -05:00
Doug Burks
1e14e2977f
Fix typo in ssh_warning
2022-01-22 10:21:14 -05:00
Josh Patterson
86cfa07af9
Merge pull request #6955 from Security-Onion-Solutions/issue/6810
...
Issue/6810
2022-01-21 17:37:59 -05:00
m0duspwnens
32080b02e4
dont use logCmd for moving repo files after centos-release update
2022-01-21 17:28:40 -05:00
m0duspwnens
58c5db3bf6
reorder process in securityonion_repo function
2022-01-21 15:15:48 -05:00
m0duspwnens
9e5fb458b4
update saltstack repo location for securityonioncache.repo / managerupdates=1
2022-01-21 14:38:42 -05:00
weslambert
f7a4cc20f2
Update so-common-template.json.jinja
2022-01-21 12:36:38 -05:00
Josh Patterson
36fc25f78e
Merge pull request #6953 from Security-Onion-Solutions/issue/6492
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 12:09:13 -05:00
m0duspwnens
e7852d7700
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 11:59:27 -05:00
Josh Patterson
0257d09cf8
Merge pull request #6949 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-21 08:46:54 -05:00
m0duspwnens
878c3fe6d9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-21 08:09:24 -05:00
m0duspwnens
281e5d9b25
remove salt.enable_higstate state
2022-01-21 08:09:04 -05:00
m0duspwnens
baa93301b5
enable cron at the end of soup
2022-01-20 16:53:33 -05:00
m0duspwnens
00d0eb1ce5
fix setting var
2022-01-20 16:37:33 -05:00
m0duspwnens
01cb505338
start cron and enable highstate if soup exits on error
2022-01-20 16:31:01 -05:00
William Wernert
ec023f8f7c
Merge pull request #6937 from Security-Onion-Solutions/fix/fail-preflight-early
...
Correctly handle failure to install curl in so-preflight
2022-01-20 16:03:20 -05:00
m0duspwnens
e1757926cf
start cron and reenable highstate on soup exit
2022-01-20 15:26:03 -05:00
William Wernert
357cd059aa
Use ret_code in prereq function to return failures
2022-01-20 13:53:59 -05:00
weslambert
1b860e11e7
Merge pull request #6936 from Security-Onion-Solutions/fix/field_conflicts
...
Remove dynamic keyword template to prevent field conflicts with mappi…
2022-01-20 12:48:15 -05:00
weslambert
d1efa71c57
Remove dynamic keyword template to prevent field conflicts with mappings defined in common template
2022-01-20 12:34:32 -05:00
Josh Patterson
c57b2d005e
Merge pull request #6933 from Security-Onion-Solutions/issue/6810
...
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:57:56 -05:00
m0duspwnens
9b2459d8ba
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:52:48 -05:00
weslambert
d0c8dd0626
Merge pull request #6931 from Security-Onion-Solutions/fix/cases_dynamic_disable
...
Disable dynamic mapping and increase order to reduce potential field …
2022-01-20 09:48:01 -05:00
weslambert
e137ad60c5
Disable dynamic mapping and increase order to reduce potential field conflicts
2022-01-20 09:44:41 -05:00
Josh Patterson
93236738de
Merge pull request #6930 from Security-Onion-Solutions/issue/6810
...
upgrade salt to 3004
2022-01-20 08:28:20 -05:00
abesinger
31d22e717d
Updated syslog pipeline, resolves #6912 . Also cleaned up formatting to make it more readable.
2022-01-19 18:45:26 -06:00
m0duspwnens
fc65f7bb84
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 15:35:28 -05:00
m0duspwnens
67e34b2402
reorder yum operations in securityonion_repo function
2022-01-19 15:35:04 -05:00
Jason Ertel
e984b0b9c4
Merge pull request #6921 from Security-Onion-Solutions/kilo
...
remove unused fields object from related case schema
2022-01-19 14:42:05 -05:00
Jason Ertel
dc44a91398
Prefix all SO fields to avoid potential conflicts with future ECS changes
2022-01-19 14:26:22 -05:00
m0duspwnens
a861801a24
more logCmd
2022-01-19 13:38:10 -05:00
m0duspwnens
fbe54b9ee8
yum clean all needs to happen before repo files are moved or the clean doesnt clean anything
2022-01-19 12:33:58 -05:00
m0duspwnens
7ebba1f325
use show_changes: False to prevent es pw from being shown when running the state
2022-01-19 12:11:38 -05:00
m0duspwnens
f8ac37c101
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 11:57:37 -05:00
m0duspwnens
4d078046d6
quote ES_PASS due to new characters in random string for elasticsearch:auth pw generation
2022-01-19 11:55:25 -05:00
William Wernert
13dbd0034f
Merge pull request #6924 from Security-Onion-Solutions/fix/whiptail-height
...
Fix height of node whiptail menu
2022-01-19 11:18:44 -05:00
William Wernert
c10ab712d5
Fix height of node whiptail menu
2022-01-19 11:05:34 -05:00
Jason Ertel
d7ba1cedff
remove unused fields object from related case schema
2022-01-19 08:39:21 -05:00
m0duspwnens
55a262646c
use logCmd
2022-01-19 08:34:54 -05:00
William Wernert
a3925d231c
Merge pull request #6909 from Security-Onion-Solutions/fix/preflight-curl
...
Install curl in preflight script to avoid error on Ubuntu
2022-01-18 13:39:44 -05:00
William Wernert
c0c42c3574
Install curl in preflight script to avoid error on Ubuntu
...
Also add check for already installed curl later in setup
2022-01-18 13:17:56 -05:00
m0duspwnens
f006d1a22c
logCmd commands in securityonion_repo function
2022-01-18 12:34:23 -05:00
m0duspwnens
a2ed9a86ff
remove influixdb salt state files and update patch files for influxdb salt modules/state
2022-01-18 11:33:36 -05:00
Josh Brower
19ccd5f8e9
Merge pull request #6904 from Security-Onion-Solutions/fix/fleetdm-disable-vuln-feature
...
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:48:06 -05:00
Josh Brower
c4babf22d6
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:38:55 -05:00
Mike Reeves
7eb564db14
Merge pull request #6901 from Security-Onion-Solutions/elasticupdate
...
Elastic 7.16.3
2022-01-18 09:47:36 -05:00
Mike Reeves
2e4e59bbe8
Elastic 7.16.3
2022-01-18 09:42:06 -05:00
m0duspwnens
87999453f2
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-18 09:13:10 -05:00
m0duspwnens
3bd26f05d4
account for salt 3004 adding new chars to random.get_str
2022-01-14 18:02:18 -05:00
m0duspwnens
a46a740170
account for salt 3004 adding new chars to random.get_str
2022-01-14 17:23:29 -05:00
Mike Reeves
71da74fd00
Merge pull request #6878 from Security-Onion-Solutions/fix/scan_pe_sections_entropy
...
Fix/scan pe sections entropy
2022-01-14 17:02:32 -05:00
weslambert
c512351dd6
Add mapping for scan.exiftool and scan.pe.sections.entropy
2022-01-14 17:01:13 -05:00
weslambert
a90bc9dba9
Add mapping for scan.pe.sections.entropy
2022-01-14 16:58:53 -05:00
m0duspwnens
02ce5c3236
update install salt to 3004
2022-01-14 13:47:16 -05:00
m0duspwnens
b6b2e06fbc
change module to cmd for onchanges_in
2022-01-14 12:44:58 -05:00
m0duspwnens
f5fe466410
repo update
2022-01-14 12:02:35 -05:00
Jason Ertel
a63787daba
Merge pull request #6864 from Security-Onion-Solutions/kilo
...
Add default queries for cases to show user's assigned cases
2022-01-13 17:15:02 -05:00
Jason Ertel
6b0b7245f0
Add default queries for cases to show user's assigned cases
2022-01-13 17:10:08 -05:00
m0duspwnens
bda9221d6f
upgrade salt to 3004 and update bootstrap-salt.sh
2022-01-13 13:26:11 -05:00
Josh Patterson
b2434faf10
Merge pull request #6862 from Security-Onion-Solutions/issue/6811
...
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:06:43 -05:00
m0duspwnens
82db3fa3c0
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:02:01 -05:00
Josh Patterson
78bb6e4176
Merge pull request #6856 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-13 11:03:51 -05:00
m0duspwnens
06c0cebb26
merge with dev
2022-01-13 09:44:26 -05:00
m0duspwnens
389ff1a46d
create enable_highstate state to reenable highstate following minion restart if it was previously disabled. same with cron
2022-01-13 09:39:46 -05:00
m0duspwnens
a28bb23d20
fix os_family for cron state map
2022-01-12 17:27:47 -05:00
m0duspwnens
443dc6ebaa
move branch echo to main so it is in the log
2022-01-12 16:14:49 -05:00
m0duspwnens
03b9b74ace
stop cron before soup upgrades the manager, start cron at the end. add cron state that is in included in common
2022-01-12 16:04:10 -05:00
Mike Reeves
e123dd4bb2
Merge pull request #6844 from Security-Onion-Solutions/highlanderml
...
Add additional highlander settings
2022-01-12 13:34:22 -05:00
Josh Patterson
5889ce02cd
Merge pull request #6845 from Security-Onion-Solutions/23100soup_jpp
...
remove mine push from 2.3.100 function
2022-01-12 13:34:06 -05:00
Josh Patterson
776e4c6e12
Update soup
2022-01-12 13:32:46 -05:00
Josh Patterson
035984569b
Merge branch 'dev' into 23100soup_jpp
2022-01-12 13:31:46 -05:00
Josh Patterson
da30f66096
remove mine push from 2.3.100 function
2022-01-12 13:29:34 -05:00
Mike Reeves
c525bf310d
Add additional highlander settings
2022-01-12 13:19:40 -05:00
Mike Reeves
ee44edfe75
Add additional highlander settings
2022-01-12 13:18:44 -05:00
m0duspwnens
0cf877f169
kill any possible queued salt jobs before stopping salt-master
2022-01-12 12:27:19 -05:00
Mike Reeves
f836d3ad16
Merge pull request #6843 from Security-Onion-Solutions/23100soup_jpp
...
push ips of mainint to salt mine
2022-01-12 12:25:51 -05:00
Josh Patterson
5b347600e9
push ips of mainint to salt mine
2022-01-12 12:24:52 -05:00
m0duspwnens
0388912ba7
kill all salt jobs across grid before stopping salt-master. kill all salt jobs on manager before stopping salt-minion.
2022-01-12 11:05:47 -05:00
m0duspwnens
494737549d
move some es script to src elasticsearch/tools/sbin and dst /usr/sbin. set requires
2022-01-12 10:20:05 -05:00
Mike Reeves
22096174bb
Merge pull request #6841 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix some formatting
2022-01-12 09:39:15 -05:00
Mike Reeves
1d94e3ac69
Fix some formatting
2022-01-12 09:38:22 -05:00
m0duspwnens
abf3a9401b
listen instead to not start service if not running then restart if changes to files
2022-01-11 18:31:35 -05:00
m0duspwnens
ae0f392035
wait for salt-master and salt-minin to exit. disable highstate before stopping salt-minion. apply salt-minion state before first highstate to update configs
2022-01-11 16:57:29 -05:00
Mike Reeves
53d2e20e48
Merge pull request #6834 from Security-Onion-Solutions/nohive
...
Remove hive install option
2022-01-11 16:50:18 -05:00
Mike Reeves
4ff5fc3b38
Remove hive install option
2022-01-11 14:38:38 -05:00
m0duspwnens
5ade8193f0
move highstate messages for more accurate final highstate message
2022-01-11 13:41:51 -05:00
m0duspwnens
0ef130bd38
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:12:07 -05:00
m0duspwnens
e33a9eb45c
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:11:25 -05:00
m0duspwnens
9d19cba600
log time when salt services stopped and started
2022-01-11 13:09:05 -05:00
m0duspwnens
baf297ab0a
merge with dev, resolve conflict
2022-01-11 11:24:10 -05:00
m0duspwnens
14eed8e5b9
redirect to setup_log
2022-01-11 11:20:30 -05:00
Josh Brower
5083be4ce7
Merge pull request #6816 from Security-Onion-Solutions/fix/wazuh-parsing-v2
...
Fix Wazuh WEL Parsing
2022-01-11 11:17:24 -05:00
Doug Burks
a3c8335130
Merge pull request #6827 from Security-Onion-Solutions/dougburks-patch-1
...
Remove unnecessary word
2022-01-11 11:06:40 -05:00
Doug Burks
29d8dbe371
Remove unnecessary word
2022-01-11 11:05:30 -05:00
m0duspwnens
91ef9b9366
update salt mine before salt-master and salt-minion get stopped
2022-01-11 10:57:48 -05:00
m0duspwnens
328d6cdeb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 10:02:18 -05:00
Mike Reeves
a9e58e2aba
Merge pull request #6826 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2022-01-11 10:01:49 -05:00
Mike Reeves
8ad36fc7b9
Update init.sls
2022-01-11 10:01:14 -05:00
m0duspwnens
87756cdbc9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:57:31 -05:00
Mike Reeves
7937487ee9
Merge pull request #6825 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update init.sls
2022-01-11 09:57:10 -05:00
Mike Reeves
770a389410
Update init.sls
2022-01-11 09:56:22 -05:00
m0duspwnens
b5c274de10
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:48:31 -05:00
m0duspwnens
a8d1b9eb90
restart salt-minion at end of run if mine_functions changes
2022-01-11 09:29:12 -05:00
m0duspwnens
86c8fc6c1c
need to update mine after salt-master starts
2022-01-11 08:56:38 -05:00
weslambert
17509a9231
Merge pull request #6822 from Security-Onion-Solutions/fix/event_fields
...
Add event.acknowledged and event.escalated mappings
2022-01-10 16:14:45 -05:00
weslambert
84f7c6b13b
Add event.acknowledged and event.escalated mappings
2022-01-10 16:08:35 -05:00
m0duspwnens
716c98ec61
requires and ordering for socusersroles state
2022-01-10 14:39:00 -05:00
Josh Brower
56aa24d874
Fix Wazuh WEL Parsing
2022-01-10 13:55:38 -05:00
Mike Reeves
b7a90a88f9
Merge pull request #6815 from Security-Onion-Solutions/esbackup
...
Add ability to specify local backup dir
2022-01-10 13:31:24 -05:00
weslambert
1dc363138a
Merge pull request #6814 from Security-Onion-Solutions/fix/template_typo
...
Fix typo -- replace period with comma
2022-01-10 13:30:13 -05:00
weslambert
1c3eeb5a34
Fix typo -- replace period with comma
2022-01-10 13:29:06 -05:00
m0duspwnens
beb9a33628
only include curl.config if elasticsearch:auth is enabled
2022-01-10 11:48:16 -05:00
Mike Reeves
dbba7d7226
Add ability to specify local backup dir
2022-01-10 11:31:41 -05:00
m0duspwnens
291ac7d361
https://github.com/Security-Onion-Solutions/securityonion/issues/6811
2022-01-10 10:36:42 -05:00
Josh Patterson
43eda0c5a3
Merge pull request #6796 from Security-Onion-Solutions/fix/wazuh_register_agent
...
dont try to register if state file exists
2022-01-07 16:07:56 -05:00
m0duspwnens
715d3f0e7e
dont try to register if state file exists
2022-01-07 16:05:55 -05:00
Jason Ertel
db04646735
Merge pull request #6794 from Security-Onion-Solutions/kilo
...
Update field mappings based on Wes' feedback
2022-01-07 16:03:05 -05:00
Jason Ertel
66c9e20c6a
Add wilcards for CCS compatibility
2022-01-07 15:57:08 -05:00
Josh Patterson
ed97fe0b65
Merge pull request #6795 from Security-Onion-Solutions/fix/wazuh_register_agent
...
Fix/wazuh register agent
2022-01-07 15:52:17 -05:00
m0duspwnens
3a86af8de2
quote $API_RESULT
2022-01-07 15:49:53 -05:00
m0duspwnens
7ee913eb1f
if /opt/so/conf/wazuh/initial_agent_registration.log doesnt exist, and agent is already registered, touch file and exit 0 to prevent salt error
2022-01-07 15:46:47 -05:00
Jason Ertel
d3656a7777
Merge branch 'dev' into kilo
2022-01-07 13:41:35 -05:00
Josh Patterson
3c44f6fd41
Merge pull request #6793 from Security-Onion-Solutions/23100soup_jpp
...
23100soup
2022-01-07 13:32:33 -05:00
Jason Ertel
391db568b0
Update field mappings based on Wes' feedback
2022-01-07 13:28:36 -05:00
Jason Ertel
a4f01d4412
Merge pull request #6792 from Security-Onion-Solutions/kilo
...
Add case exclusion toggle to Hunt to avoid hunt results getting case …
2022-01-07 13:02:27 -05:00
Jason Ertel
9ef83da23f
Add case exclusion toggle to Hunt to avoid hunt results getting case data hits unintentionally
2022-01-07 12:58:35 -05:00
m0duspwnens
871fd115ae
put so-firewalll in /usr/sbin since salt-master isnt running at this time
2022-01-07 12:04:19 -05:00
weslambert
218f7f3a13
Merge pull request #6790 from Security-Onion-Solutions/fix/dtc_severity_label
...
Add event.severity_label
2022-01-07 11:44:30 -05:00
weslambert
770e53d914
Add keyword subfield for event.severity_label
2022-01-07 11:21:57 -05:00
weslambert
c69e1353d9
Add event.severity_label
2022-01-07 11:19:54 -05:00
m0duspwnens
fd0e5d7d29
make sure so-firewall is up to date
2022-01-07 11:10:48 -05:00
Josh Brower
ae6aa0dafd
Merge pull request #6789 from Security-Onion-Solutions/fix/wazuh-parsing-revert
...
Revert Wazuh parser update
2022-01-07 10:53:53 -05:00
Josh Brower
5d4ea2ba3a
Revert Wazuh parser update
2022-01-07 10:51:24 -05:00
weslambert
a7e7566532
Merge pull request #6780 from Security-Onion-Solutions/feature/datatype_compliance
...
Initial commit for data type compliance
2022-01-06 16:38:17 -05:00
m0duspwnens
5ecb63f5cf
prevent exit if minion doesnt respond
2022-01-06 16:17:51 -05:00
Josh Brower
ca4aaae47c
Merge pull request #6778 from Security-Onion-Solutions/fix/wazuh-parsing
...
Uppercase first char in Wazuh WEL
2022-01-06 16:01:09 -05:00
Josh Brower
277c7f1ef8
Uppercase first char in Wazuh WEL
2022-01-06 14:58:50 -05:00
m0duspwnens
cd590b894a
check that ossec.conf exists
2022-01-06 12:39:48 -05:00
weslambert
3f02003ea2
Merge pull request #6777 from Security-Onion-Solutions/fix/deprecation_ecs_compatibility_logstash
...
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:31:51 -05:00
weslambert
8e2f500b9c
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:24:04 -05:00
weslambert
099e3e1ceb
Merge pull request #6775 from Security-Onion-Solutions/fix/deprecation_warning_suppress
...
Add logger stanza to suppress ES deprecation warning messages
2022-01-06 10:45:37 -05:00
weslambert
900d12b556
Add logger stanza to suppress deprecation warning messages for now due to current system index access warning messages flooding the ES log
2022-01-06 10:35:50 -05:00
Jason Ertel
8cf7ea8b87
Merge pull request #6772 from Security-Onion-Solutions/kilo
...
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 19:15:02 -05:00
Josh Patterson
eaa6597cd7
Merge pull request #6773 from Security-Onion-Solutions/issue/6765
...
Issue/6765
2022-01-05 18:11:06 -05:00
m0duspwnens
6338ba2e45
remove /var/cache/salt/ for reinstall
2022-01-05 16:54:56 -05:00
m0duspwnens
8af74e8bb3
remove more salt configs for reinstall
2022-01-05 16:53:54 -05:00
m0duspwnens
9357995bfa
remove root cron and restore yeselastic.txt
2022-01-05 16:04:32 -05:00
weslambert
2fb488f768
Merge pull request #6769 from Security-Onion-Solutions/fix/id_fielddata_deprecation
...
Fix issue with _id field fielddata/deprecation
2022-01-05 15:40:25 -05:00
Wes Lambert
1cafacfa51
Update saved objects to reflect removal of TheHive scripted field and replacement of PCAP pivot with Hunt pivot
2022-01-05 20:36:23 +00:00
weslambert
c1a88977cf
Disable fielddata for _id field by default (since it is deprecated and can be memory-intensive)
2022-01-05 15:23:52 -05:00
m0duspwnens
0ff5e3cf6f
require so-elasticsearch container to be running to run the scripts
2022-01-05 14:48:41 -05:00
m0duspwnens
8950f94fb0
restore state files so python3-influxdb state doesnt try to patch during a restinstall
2022-01-05 12:02:53 -05:00
Wes Lambert
b60837e71a
Initial commit for data type compliance
2022-01-05 16:38:56 +00:00
Jason Ertel
4f8524e0ac
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 11:13:12 -05:00
weslambert
2f9672d3ea
Merge pull request #6764 from Security-Onion-Solutions/feature/soup_branch
...
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:54:29 -05:00
weslambert
db43e21378
Fix indentation
2022-01-05 10:46:41 -05:00
weslambert
4d8b417fc9
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:41:27 -05:00
Jason Ertel
89415b12ce
Merge pull request #6762 from Security-Onion-Solutions/kilo
...
Switch soc.json to use lowercase labels in default queries; Also enab…
2022-01-05 09:59:39 -05:00
Jason Ertel
4bfdfffe21
Switch soc.json to use lowercase labels in default queries; Also enable the 'Add Case' feature
2022-01-05 09:54:13 -05:00
Mike Reeves
1adc4c5346
Merge pull request #6752 from Security-Onion-Solutions/ubufix
...
Fix docker holds so re-install will work properly
2022-01-04 18:56:06 -05:00
Mike Reeves
3ca0ce9eea
Update so-functions
2022-01-04 18:47:35 -05:00
Mike Reeves
e869013057
Remove docker the reinstall it
2022-01-04 15:24:10 -05:00
Mike Reeves
dd104c9490
Add holds for ubuntu
2022-01-04 13:07:09 -05:00
m0duspwnens
7bb9b6efa9
populate mine with network.ip_addrs pillar.host.mainint for each host prior to highstate
2022-01-04 10:27:45 -05:00
Mike Reeves
288389c93e
Soup changes for 2.3.100
2022-01-04 08:38:14 -05:00
Josh Patterson
4247a3a816
Merge pull request #6730 from Security-Onion-Solutions/fix/ub1804ssl
...
more detailed logging for the retry command
2021-12-30 13:19:58 -05:00
m0duspwnens
cc2f6e23ca
more detailed logging for the retry command
2021-12-30 13:09:29 -05:00
Josh Patterson
064355dfb5
Merge pull request #6729 from Security-Onion-Solutions/fix/ub1804ssl
...
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 11:38:32 -05:00
m0duspwnens
d274615376
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 10:45:30 -05:00
Josh Patterson
78eda75c0f
Merge pull request #6725 from Security-Onion-Solutions/fix/ub1804ssl
...
add option to look for failed outout in retry function in so-common. …
2021-12-29 18:18:12 -05:00
m0duspwnens
200736a118
add option to look for failed outout in retry function in so-common. look for Err: when running soapt-get update in setup
2021-12-29 18:15:16 -05:00
Jason Ertel
1d136b611a
Merge pull request #6723 from Security-Onion-Solutions/kilo
...
Uniform presets
2021-12-29 16:49:41 -05:00
Jason Ertel
e6051cb653
Switch all presets to lowercase for uniformity
2021-12-29 16:42:34 -05:00
Jason Ertel
74dbc4bf67
Merge pull request #6720 from Security-Onion-Solutions/kilo
...
Add case template to eval install types; also improve clarity of case queries
2021-12-29 11:41:06 -05:00
Josh Patterson
a2f1f52450
Merge pull request #6719 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-29 11:39:10 -05:00
Jason Ertel
1d885a5419
Add case template to eval installs
2021-12-29 11:38:38 -05:00
m0duspwnens
b414e22e95
remove spaces in function
2021-12-29 11:37:22 -05:00
m0duspwnens
4c54d45681
some echos for logging
2021-12-29 11:36:12 -05:00
m0duspwnens
c6e9b00488
Merge remote-tracking branch 'remotes/origin/dev' into fix/ub1804ssl
2021-12-29 11:22:25 -05:00
m0duspwnens
b027da6378
wait for the salt-minion service to be ready for requests prior to running ssl state
2021-12-29 11:18:38 -05:00
Jason Ertel
fb02d0d35c
clarify case filters
2021-12-29 11:07:36 -05:00
Jason Ertel
d4f3615cae
Merge pull request #6717 from Security-Onion-Solutions/kilo
...
Support CCS in CM
2021-12-29 09:12:13 -05:00
Jason Ertel
e5110ac4e8
Use CCS compatible index
2021-12-29 09:08:10 -05:00
Jason Ertel
e87cbc37a4
Add case template
2021-12-28 19:17:15 -05:00
Josh Patterson
3b130ab202
Merge pull request #6712 from Security-Onion-Solutions/fix/ub1804ssl
...
all run ssl state during setup
2021-12-28 16:34:58 -05:00
m0duspwnens
22afe99719
all run ssl state during setup
2021-12-28 16:24:17 -05:00
Doug Burks
e56a9a5f22
Merge pull request #6711 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-analyst-install
2021-12-28 15:24:19 -05:00
Josh Patterson
7655920068
Merge pull request #6710 from Security-Onion-Solutions/fix/ub1804ssl
...
add mine function to signing_policies.conf
2021-12-28 15:23:36 -05:00
Doug Burks
463925686d
fix typo in so-analyst-install
2021-12-28 15:23:17 -05:00
m0duspwnens
2a5b4ef276
add mine function to signing_policies.conf. no longer need to check if mine in ca during manager install
2021-12-28 15:19:06 -05:00
Josh Patterson
7029c3a94a
Merge pull request #6707 from Security-Onion-Solutions/fix/ub1804ssl
...
put x509 signing policies in place when minion is configured
2021-12-28 12:05:20 -05:00
m0duspwnens
67a9f4d22e
put x509 signing policies in place when minion is configured
2021-12-28 12:03:10 -05:00
Josh Patterson
a5746d4919
Merge pull request #6706 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-28 11:27:15 -05:00
m0duspwnens
487ac24306
revert back to getting ca from mine
2021-12-28 11:16:01 -05:00
m0duspwnens
2405de4b82
fix require
2021-12-28 11:00:35 -05:00
m0duspwnens
9e3c289562
remove restarting salt in ssl generation. sperate ca and ssl generation into seperate functions
2021-12-28 10:43:45 -05:00
m0duspwnens
f2adcf4ca5
ensure /etc/pki is created and simplify ca logic for non manager in ssl state
2021-12-28 10:41:57 -05:00
Jason Ertel
0072ae253b
Merge pull request #6705 from Security-Onion-Solutions/kilo
...
Initial CM Impl; Improve so-user script
2021-12-28 08:36:59 -05:00
Jason Ertel
5a4473ecd6
fix indent
2021-12-28 08:33:31 -05:00
Jason Ertel
f335670b3f
Add new client-side param for cases
2021-12-27 21:53:30 -05:00
Jason Ertel
194e4119f0
Correct missing json vars
2021-12-27 20:36:28 -05:00
Jason Ertel
09626deb05
Correct var names for jinja
2021-12-27 18:01:15 -05:00
Jason Ertel
ae7a4b6528
More syntax corrections
2021-12-27 16:18:12 -05:00
Jason Ertel
0a255e5765
Resolve syntax error
2021-12-27 15:15:33 -05:00
Jason Ertel
789719d25e
Correct preset file syntax
2021-12-27 13:21:13 -05:00
Jason Ertel
7140255d95
Add missing presets file
2021-12-27 12:27:04 -05:00
Jason Ertel
ab3319b472
Add artifact support
2021-12-27 10:49:10 -05:00
Jason Ertel
b0d36f2ed2
Ensure update timestamp is updated when changing passwords; this ensures the sync will automatically follow
2021-12-21 13:38:35 -05:00
Jason Ertel
62e5914ab8
Merge branch 'dev' into kilo
2021-12-21 13:37:37 -05:00
Jason Ertel
2f88f08be2
Merge pull request #6649 from Security-Onion-Solutions/2.3.91-merge
...
2.3.91 merge
2021-12-21 09:39:14 -05:00
Jason Ertel
9aeaa1fccc
resolved merge conflicts
2021-12-21 09:35:57 -05:00
Jason Ertel
2c9062efb7
resolved merge conflicts
2021-12-21 09:34:39 -05:00
Doug Burks
c8de36d467
Merge pull request #6646 from Security-Onion-Solutions/patch/2.3.91
...
Patch/2.3.91
2021-12-21 09:27:14 -05:00
doug
284e0e9108
fix hashes in VERIFY_ISO.md
2021-12-20 17:27:19 -05:00
doug
e66b023c9c
update README.md for 2.3.91
2021-12-20 17:23:52 -05:00
doug
9f47522591
add sig for 2.3.91 ISO and update VERIFY_ISO.md
2021-12-20 17:21:53 -05:00
Jason Ertel
35617acaeb
Update cacerts to reflect new path; this changed due to ES 7.16.2
2021-12-20 12:12:00 -05:00
Jason Ertel
6f116a2d01
Switch to new Ubuntu SSL dir
2021-12-20 09:43:59 -05:00
Jason Ertel
d6c651af1c
Remove old patch dir from previously-patched installations
2021-12-20 09:42:27 -05:00
Jason Ertel
203e8a7873
Bump version to 2.3.91
2021-12-20 09:33:20 -05:00
Jason Ertel
b8fcec04b8
Remove patched jar due to upgrade of Elastic images to 7.16.2
2021-12-20 09:27:03 -05:00
Jason Ertel
6556a37869
Merge branch 'master' into patch/1.3.91
2021-12-20 09:20:03 -05:00
Jason Ertel
5af2bd8fa4
Upgrade to Elastic 7.16.2
2021-12-20 09:16:28 -05:00
Josh Patterson
d33cf19e3d
Merge pull request #6612 from Security-Onion-Solutions/issue/6469
...
add managersearch to list
2021-12-16 13:57:53 -05:00
m0duspwnens
a46a876ec6
add managersearch to list
2021-12-16 13:48:41 -05:00
Josh Brower
affe5b9ac0
Merge pull request #6605 from Security-Onion-Solutions/fix/fleet-ips
...
Fix cidr for fleet custom docker range
2021-12-16 11:55:11 -05:00
Josh Patterson
e0c8e03882
Merge pull request #6604 from Security-Onion-Solutions/issue/6469
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6469
2021-12-16 11:54:05 -05:00
Josh Brower
a23824e199
Fix cidr for fleet custom docker range
2021-12-16 11:53:26 -05:00
m0duspwnens
ae342ab673
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-16 11:33:09 -05:00
m0duspwnens
b4b8b91ccd
simplify ip logic wazuh-register-agent, mine_interval to 35 minutes
2021-12-16 11:24:35 -05:00
m0duspwnens
2e4ed8062e
simplify wazuh agent ip logic
2021-12-16 11:11:01 -05:00
m0duspwnens
bd7ef1cc59
fix whitespace control
2021-12-16 09:19:20 -05:00
Jason Ertel
8ec671422f
Merge pull request #6593 from Security-Onion-Solutions/esup
...
Finish upgrade of ES to 7.16.1
2021-12-16 07:59:34 -05:00
Jason Ertel
1268f8f92b
Upgrade ES to 7.16.1
2021-12-16 07:57:42 -05:00
Jason Ertel
d4f395b7f4
Fix query name for open cases
2021-12-15 20:02:35 -05:00
Jason Ertel
c68efd56c2
Merge branch 'dev' into kilo
2021-12-15 20:01:55 -05:00
m0duspwnens
a7600f7f43
update scripts to use their own ip
2021-12-15 17:31:39 -05:00
Mike Reeves
0f76227631
Merge pull request #6585 from Security-Onion-Solutions/unhotfix
...
Unhotfix
2021-12-15 17:23:02 -05:00
m0duspwnens
d0b0970353
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-15 17:08:56 -05:00
Mike Reeves
465ba1b7d3
Change CA certs location
2021-12-15 17:08:36 -05:00
m0duspwnens
f9b04ab96a
add node's own ip to FILEBEAT_EXTRA_HOSTS
2021-12-15 16:53:22 -05:00
m0duspwnens
522bc1d2b8
fix loadbalance logic and whitespace for filebeat.yml
2021-12-15 16:21:08 -05:00
m0duspwnens
cf2f4bad09
have standalone and managersearch pull from redis nodes
2021-12-15 15:27:23 -05:00
Mike Reeves
61955b7928
Change CA certs location
2021-12-15 13:50:19 -05:00
Jason Ertel
ffa8ca57a7
Merge pull request #6579 from Security-Onion-Solutions/unhotfix
...
Remove some previous hotfix code
2021-12-15 12:34:00 -05:00
Mike Reeves
7cd1b1c482
Remove some previous hotfix code
2021-12-15 12:26:53 -05:00
m0duspwnens
6ab2bdef0c
add sensoroni state to receiver node
2021-12-15 10:45:54 -05:00
m0duspwnens
ce0a39db4b
remove old EXTRAHOSTNAME EXTRAHOSTIP from being set for logstash
2021-12-15 09:43:46 -05:00
m0duspwnens
ea89d2074b
remove ca from allowed_hosts on so-receiver
2021-12-15 09:32:12 -05:00
m0duspwnens
759bf9837e
pillar top clean up for receiver and logstash.nodes
2021-12-15 09:31:03 -05:00
m0duspwnens
d9a384cc29
remove global:pipeline pillar call from logstash pipeline pillars
2021-12-15 09:30:15 -05:00
m0duspwnens
176ef852c8
clean up assinged hostgroups for receiver
2021-12-15 08:28:40 -05:00
Doug Burks
09f0bdba91
Merge pull request #6574 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-image-common
2021-12-15 07:45:24 -05:00
Doug Burks
7d1f9c51e8
fix typo in so-image-common
2021-12-15 07:24:30 -05:00
m0duspwnens
024860d0ae
rename EXTRA_NODES to LOGSTASH_NODES AND REDIS_NODES
2021-12-14 23:43:06 -05:00
m0duspwnens
0c6aba16ec
fix redis input
2021-12-14 23:42:37 -05:00
m0duspwnens
15b8d80b71
fix host for input_redis
2021-12-14 18:51:43 -05:00
m0duspwnens
55b74abcc5
extra_hosts and redis_input for logstash
2021-12-14 18:49:30 -05:00
m0duspwnens
4da017d61c
change extra_hosts for docker container
2021-12-14 17:05:30 -05:00
m0duspwnens
a31d61e151
handle ca for redis
2021-12-14 16:43:04 -05:00
m0duspwnens
841b91e052
exclude elasticsearch and managerssl keys and certs from receiver
2021-12-14 16:05:47 -05:00
m0duspwnens
d0b6d5bba6
remove so-eval from lists since it doesnt run logstash
2021-12-14 15:33:06 -05:00
m0duspwnens
a31f034f2e
remove receiver add node for cacerts and tls-ca-bundle for logstash bind
2021-12-14 15:02:59 -05:00
m0duspwnens
6962e3f9b3
fix logstash certs mapped into container
2021-12-14 14:52:15 -05:00
m0duspwnens
c490a3be36
move node_data pillar to logstash:nodes, set extra hosts for filebeat docker
2021-12-14 13:32:42 -05:00
Mike Reeves
5006e34208
Merge pull request #6560 from Security-Onion-Solutions/mergerz
...
Merge latest hotfix
2021-12-14 10:57:49 -05:00
Mike Reeves
30344ba0ef
Fix conflicts
2021-12-14 10:55:19 -05:00
m0duspwnens
6518691c55
sort the items
2021-12-13 18:16:25 -05:00
m0duspwnens
067e79894f
fix loop for node_data
2021-12-13 16:26:38 -05:00
m0duspwnens
6de2f5bd03
fix node_data
2021-12-13 15:55:09 -05:00
m0duspwnens
8d0872bce5
create node_data pillar from mine data, use node_data pillar for filebeat config
2021-12-13 15:48:30 -05:00
Mike Reeves
85cf096322
Merge pull request #6541 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-13 12:41:24 -05:00
Mike Reeves
4eaf3f8d8b
Merge pull request #6540 from Security-Onion-Solutions/2390hotfix3
...
2.3.90-20211213 Hotfix
2021-12-13 12:12:03 -05:00
Mike Reeves
d90904b4d4
2.3.90-20211213 Hotfix
2021-12-13 12:09:09 -05:00
Mike Reeves
65cc9930e7
Merge pull request #6537 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-12-13 11:13:40 -05:00
Mike Reeves
7f982d2824
Update HOTFIX
2021-12-13 11:12:18 -05:00
Mike Reeves
d3ac1f7994
Merge pull request #6533 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Add missing logstash lib
2021-12-13 09:30:32 -05:00
Jason Ertel
c94d5fa9dc
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:27:13 -05:00
Mike Reeves
83d1cdad90
Merge pull request #6532 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:05:30 -05:00
Jason Ertel
8365b5f140
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:02:41 -05:00
m0duspwnens
86f67198bf
loadbalance filebeat if across managers and receivers
2021-12-10 17:43:06 -05:00
Mike Reeves
4d6cd66d9d
Merge pull request #6521 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-10 16:20:29 -05:00
Mike Reeves
1946965c5f
Merge pull request #6520 from Security-Onion-Solutions/2390hotfix0day
...
2.3.90-20211210 Hotfix
2021-12-10 15:49:38 -05:00
Mike Reeves
c9a14788ed
2.3.90-20211210 Hotfix
2021-12-10 15:42:53 -05:00
m0duspwnens
fe7247f876
update fw for receiver and add mine_functions for ip_addr
2021-12-10 15:28:40 -05:00
Mike Reeves
ce963a02d9
Merge pull request #6517 from Security-Onion-Solutions/ES0day2
...
Add JVM Options for logstash
2021-12-10 14:25:52 -05:00
Mike Reeves
dcd56de890
Update log4j2.properties
2021-12-10 14:23:38 -05:00
Mike Reeves
3d7b963912
Update log4j2.properties
2021-12-10 14:16:16 -05:00
Mike Reeves
09253b637e
Create jvm.options
2021-12-10 14:12:43 -05:00
Mike Reeves
c81ce48bff
Update log4j2.properties
2021-12-10 14:10:35 -05:00
Mike Reeves
73ec595baa
Update init.sls
2021-12-10 14:10:05 -05:00
Mike Reeves
04862fcc06
Merge pull request #6514 from Security-Onion-Solutions/ES0day2
...
Throw the log4j into the java options
2021-12-10 12:04:31 -05:00
Mike Reeves
45346b6318
Update log4j2.properties
2021-12-10 12:01:39 -05:00
Mike Reeves
e48de18480
Update init.sls
2021-12-10 12:00:12 -05:00
Mike Reeves
66c8cc6e86
Update init.sls
2021-12-10 11:59:12 -05:00
Mike Reeves
8dcb64d87c
Update init.sls
2021-12-10 11:56:33 -05:00
Mike Reeves
ae3e980852
Merge pull request #6513 from Security-Onion-Solutions/EShotfix
...
Update log4j2.properties
2021-12-10 10:35:43 -05:00
Mike Reeves
11f1fe7ab1
Update HOTFIX
2021-12-10 10:21:50 -05:00
Mike Reeves
4561e13871
Update log4j2.properties
2021-12-10 10:19:58 -05:00
Mike Reeves
ea26e402c8
Update log4j2.properties
2021-12-10 10:17:49 -05:00
m0duspwnens
54c32acdbf
dont call logstash_pillar if manager or helix
2021-12-09 15:26:00 -05:00
Jason Ertel
83d86aebb1
Perform full email match
2021-12-09 15:04:00 -05:00
m0duspwnens
d94496bb90
remove minio_key and add missing endif
2021-12-09 13:24:20 -05:00
m0duspwnens
c2a952796c
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:13:18 -05:00
Mike Reeves
b92cbb01b3
SSL modifications
2021-12-09 13:13:01 -05:00
m0duspwnens
5b70d5510f
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:12:00 -05:00
Jason Ertel
2761662eb9
Add status presets
2021-12-09 13:09:56 -05:00
Mike Reeves
a7f0d81555
SSL modifications
2021-12-09 13:07:00 -05:00
Josh Brower
d3bbae23ca
Merge pull request #6499 from Security-Onion-Solutions/fix/beats-logstash
...
Use id for doc id if it exists
2021-12-09 09:47:14 -05:00
Josh Brower
656ea974dc
Use id for doc id if it exists
2021-12-09 09:16:58 -05:00
Jason Ertel
a9b7b9ee92
Jinjafy case params
2021-12-08 17:41:48 -05:00
m0duspwnens
7390b03dc1
dont show es options in final whiptail setup confirmation
2021-12-08 14:58:34 -05:00
m0duspwnens
b4bc32d3ca
set logstash pillar and enable avanced ls menu for so-receiver
2021-12-08 14:33:15 -05:00
m0duspwnens
ecc8594d44
prevent so-receiver from getting extra keys/certs
2021-12-08 13:32:56 -05:00
m0duspwnens
59464af10c
filebeat certs for logstash on so-receiver
2021-12-08 09:41:17 -05:00
m0duspwnens
1ef63f3a23
ssl things for so-receiver
2021-12-08 09:08:46 -05:00
m0duspwnens
c80059efb0
change from || to &&
2021-12-07 17:11:15 -05:00
m0duspwnens
8c95d0f36b
set ip for wazuh-register-agent and dont apply nginx in setup for receiver
2021-12-07 16:50:41 -05:00
m0duspwnens
429b9cab2f
set ip for ossec.conf
2021-12-07 16:22:07 -05:00
m0duspwnens
f8da5c7fe9
start of fw rules for receiver
2021-12-07 15:59:11 -05:00
m0duspwnens
06010bd157
add so-receiver to allowed_states
2021-12-07 13:34:06 -05:00
Jason Ertel
b73eb76c94
Make case module dynamic
2021-12-07 11:51:02 -05:00
m0duspwnens
f3ec5df447
add receiver node
2021-12-07 11:13:51 -05:00
m0duspwnens
7549e34881
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-07 10:57:12 -05:00
m0duspwnens
ba30c59ec7
add receiver node
2021-12-07 10:56:35 -05:00
Mike Reeves
892899b7f9
Merge pull request #6477 from Security-Onion-Solutions/merge-202112071526
...
Merge hotfix
2021-12-07 10:30:13 -05:00
Jason Ertel
702d95c63a
Merge branch 'master' into merge-202112071527
2021-12-07 10:28:00 -05:00
m0duspwnens
96666ab307
add receiver node
2021-12-07 10:19:32 -05:00
Mike Reeves
9f41df641e
Merge pull request #6470 from Security-Onion-Solutions/hotfix/2.3.90
...
HOTFIX: 2.3.90-20211206
2021-12-07 09:51:01 -05:00
Mike Reeves
9f94ecfab7
Merge pull request #6466 from Security-Onion-Solutions/2390updates3
...
2.3.90 hotfix 20211206
2021-12-06 11:07:14 -05:00
Mike Reeves
4188282724
2.3.90 hotfix 20211206
2021-12-06 11:03:49 -05:00
Mike Reeves
3945933dec
Merge pull request #6446 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-12-06 09:38:02 -05:00
Mike Reeves
73a1a3878f
Update HOTFIX
2021-12-06 09:37:07 -05:00
weslambert
ff25d6f80b
Merge pull request #6447 from Security-Onion-Solutions/eg_dashes
...
Add initial EG dashboards
2021-12-03 18:05:22 -05:00
Wes Lambert
0571612ea1
Add initial EG dashes
2021-12-03 22:38:30 +00:00
Mike Reeves
f697d88090
Update HOTFIX
2021-12-03 15:36:16 -05:00
Mike Reeves
ad03241910
Merge pull request #6445 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Apply hotfix to all 2.3.90 installs
2021-12-03 15:24:33 -05:00
Mike Reeves
f82d204c0e
Update soup
2021-12-03 15:20:33 -05:00
Mike Reeves
780daf8aa7
Apply hotfix to all 2.3.90 installs
2021-12-03 15:15:45 -05:00
Josh Patterson
5008b647b0
Merge pull request #6441 from Security-Onion-Solutions/hf/soc_append2.3.90
...
export LC_CTYPE="en_US.UTF-8" in soup
2021-12-03 15:10:12 -05:00
m0duspwnens
65b1ab833d
run salt-call locally as if no Salt master were present during reinstall - https://github.com/Security-Onion-Solutions/securityonion/discussions/6435
2021-12-03 12:00:29 -05:00
m0duspwnens
c6773a0bbc
move "Preparing soup" to main so shows in soup.log
2021-12-03 10:26:22 -05:00
m0duspwnens
ff2d2c7c04
export LC_CTYPE="en_US.UTF-8" - https://github.com/Security-Onion-Solutions/securityonion/discussions/6431
2021-12-02 16:39:32 -05:00
Mike Reeves
6c7a1f23f5
Merge pull request #6440 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Fix for the clustername used in wrong context
2021-12-02 15:35:26 -05:00
Mike Reeves
f5761c73a5
Fix for the clustername used in wrong context
2021-12-02 15:30:35 -05:00
Mike Reeves
8448778ecd
Merge pull request #6438 from Security-Onion-Solutions/hf/soc_append2.3.90
...
hf/soc append2.3.90
2021-12-02 15:10:51 -05:00
m0duspwnens
8d667795a7
only add soc:es_index_patterns to pillar if not already present
2021-12-02 10:28:17 -05:00
m0duspwnens
7a664ab8f7
more error proof up_to_2.3.90 function
2021-12-02 10:02:26 -05:00
Jason Ertel
83fab42b6e
Merge pull request #6433 from Security-Onion-Solutions/kilo
...
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:39:14 -05:00
Jason Ertel
e549cfdf82
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:35:13 -05:00
Josh Brower
c7a9fb1fa3
Merge pull request #6432 from Security-Onion-Solutions/fix/fleet-nginx
...
Fix FleetDM nginx errors
2021-12-02 08:30:28 -05:00
Josh Brower
97cd679d74
Fix FleetDM nginx errors
2021-12-02 08:17:01 -05:00
William Wernert
3bd8bcba12
Merge pull request #6421 from Security-Onion-Solutions/hotfix-merge
...
Hotfix merge
2021-12-01 14:49:05 -05:00
William Wernert
6e7188b4d8
Merge branch 'hotfix/2.3.90' into hotfix-merge
...
# Conflicts:
# HOTFIX
2021-12-01 14:40:34 -05:00
m0duspwnens
5e0ac89841
merge with master
2021-12-01 14:27:58 -05:00
Mike Reeves
8990a09d92
Merge pull request #6418 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-01 13:24:19 -05:00
Mike Reeves
946673dc3b
Merge pull request #6417 from Security-Onion-Solutions/2390updates2
...
2.3.90 hotfix airgap
2021-12-01 13:20:41 -05:00
m0duspwnens
c571b2c499
handle redirect if more than 1 match from compgen
2021-12-01 13:17:14 -05:00
Mike Reeves
80c569317f
2.3.90 hotfix airgap
2021-12-01 13:16:13 -05:00
Mike Reeves
84b91c547d
Merge pull request #6403 from Security-Onion-Solutions/dlee35-patch-1
...
add subjectAltName to filebeat.crt
2021-12-01 11:54:05 -05:00
Mike Reeves
5f121f3b99
Merge pull request #6411 from Security-Onion-Solutions/m0duspwnens-patch-1/hotfix/2.3.90
...
remove redirect to /dev/null for compgen
2021-12-01 10:17:29 -05:00
Josh Patterson
63cb486698
remove redirect to /dev/null for compgen
2021-12-01 10:16:04 -05:00
Dustin Lee
8a394380cb
add subjectAltName to filebeat.crt
...
IP SAN is required for Endgame integration w/Logstash when DNS resolution is unavailable
2021-11-30 16:24:08 -05:00
William Wernert
1a31e60e47
Merge pull request #6402 from Security-Onion-Solutions/fix/airgap-check
...
Fix/airgap check
2021-11-30 15:57:02 -05:00
William Wernert
168f860c87
Add hotfix string to HOTFIX
2021-11-30 15:49:41 -05:00
William Wernert
8d87fae6a8
Remove airgap repo file if it shouldn't exist
2021-11-30 15:46:22 -05:00
William Wernert
739efc22d2
Fix airgap check logic
2021-11-30 15:46:18 -05:00
Jason Ertel
1272de3058
Merge pull request #6378 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
bump version to 2.3.100
2021-11-29 09:57:29 -05:00
Mike Reeves
2beb69f495
Update HOTFIX
2021-11-29 09:55:32 -05:00
Mike Reeves
5a447c53d9
bump version to 2.3.100
2021-11-29 09:55:01 -05:00
Jason Ertel
31ffd6c4ec
Merge pull request #6339 from Security-Onion-Solutions/kilo
...
Merge 2.3.90 WAZUH hotfix into dev
2021-11-23 19:33:18 -05:00
Mike Reeves
4c6786a412
Merge pull request #6335 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-11-23 16:51:27 -05:00
Mike Reeves
5062e910e2
Merge pull request #6334 from Security-Onion-Solutions/2390updates
...
2.3.90 hotfix soup
2021-11-23 15:41:21 -05:00
Mike Reeves
1f9dc0db1f
2.3.90 hotfix soup
2021-11-23 15:40:04 -05:00
Mike Reeves
c536e11383
2.3.90 hotfix soup
2021-11-23 15:32:41 -05:00
Mike Reeves
faa8464b60
Merge pull request #6333 from Security-Onion-Solutions/kilo
...
Correct if check to inline the command instead of checking for emptin…
2021-11-23 14:53:24 -05:00
Jason Ertel
4f283c2d86
Suppres grep output
2021-11-23 14:52:40 -05:00
Jason Ertel
801d42ed20
Correct if check to inline the command instead of checking for emptiness of a variable
2021-11-23 14:51:06 -05:00
Mike Reeves
30a1ffc1c7
Merge pull request #6329 from Security-Onion-Solutions/kilo
...
2.3.90 WAZUH
2021-11-23 13:37:41 -05:00
Jason Ertel
59fc122eec
Force restart of wazuh since conf file is changing
2021-11-23 13:29:04 -05:00
Jason Ertel
52ffa27eda
Update hotfix file
2021-11-23 13:22:47 -05:00
Jason Ertel
bd59d65f02
Strip trailing newlines from version and hotfix files
2021-11-23 13:12:27 -05:00
Jason Ertel
01ceded223
Handle CRs in hotfix
2021-11-23 13:03:40 -05:00
Jason Ertel
3c37bd61ab
Add debug logging
2021-11-23 12:46:59 -05:00
Jason Ertel
a35670c889
Merge branch 'hotfix/1.3.90' into kilo
2021-11-23 12:38:57 -05:00
Jason Ertel
7627d37386
Add 2.3.90 WAZUH hotfix corrective function
2021-11-23 12:21:28 -05:00
Jason Ertel
273842eb43
Merge pull request #6328 from Security-Onion-Solutions/kilo
...
WAZUH hotfix
2021-11-23 12:06:34 -05:00
Jason Ertel
0dd251e2a9
Fix typo in whiptail prompt
2021-11-23 11:19:53 -05:00
Josh Patterson
c67b2b6936
Update soup
...
only check if salt was upgraded if upgrade_salt function was called
2021-11-23 11:14:10 -05:00
Jason Ertel
af4c04be59
Fix #6325 - Prevent XML header from outputting to ossec.conf
2021-11-23 10:57:21 -05:00
Jason Ertel
4672b0c15c
Fix #6317 - Do not attempt to whitelist when wazuh isn't enabled
2021-11-23 10:06:14 -05:00
Jason Ertel
9737a4088c
Merge pull request #6327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-11-23 09:25:43 -05:00
Mike Reeves
d8d429c71a
Update HOTFIX
2021-11-23 09:19:41 -05:00
Mike Reeves
3bfc3b8943
Merge pull request #6301 from Security-Onion-Solutions/dev
...
2.3.90
2021-11-22 13:15:23 -05:00
Mike Reeves
4ad6d616ae
Merge pull request #6313 from Security-Onion-Solutions/2390update
...
2390update
2021-11-22 09:04:16 -05:00
Mike Reeves
759c0b858a
2.3.90
2021-11-22 09:01:12 -05:00
Mike Reeves
c17a49a730
Merge pull request #6302 from Security-Onion-Solutions/fix/md5soup
...
Fix/md5soup
2021-11-19 16:45:02 -05:00
m0duspwnens
c0f183fb5e
add comment
2021-11-19 16:37:27 -05:00
m0duspwnens
d602339c45
render and md5sum soup and so-common
2021-11-19 16:32:59 -05:00
Mike Reeves
0122e62920
Merge pull request #6300 from Security-Onion-Solutions/2390
...
2.3.90
2021-11-19 14:09:02 -05:00
Mike Reeves
1634105780
2.3.90
2021-11-19 14:07:03 -05:00
Josh Patterson
198a690ba1
Merge pull request #6298 from Security-Onion-Solutions/fix/soup-script-check
...
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:24:48 -05:00
William Wernert
bebd62187d
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:23:32 -05:00
Mike Reeves
a91564605c
Merge pull request #6297 from Security-Onion-Solutions/fix/soup-playbook-secrets
...
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:28:11 -05:00
William Wernert
23b91ee7e5
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:27:11 -05:00
Mike Reeves
d3f25f8d74
Merge pull request #6293 from Security-Onion-Solutions/fix/fleet-stats
...
Fix FleetDM - disable stats
2021-11-19 09:53:26 -05:00
Josh Brower
8bd4ba3acd
Fix FleetDM - disable stats
2021-11-19 09:49:34 -05:00
Josh Patterson
e5927d0bf7
Merge pull request #6290 from Security-Onion-Solutions/fleet_startup_eval
...
run redis state before fleet state for eval highstate
2021-11-18 17:54:26 -05:00
m0duspwnens
9dd89f6be7
run redis state before fleet state for eval highstate
2021-11-18 17:41:56 -05:00
Mike Reeves
796eb59dc6
Merge pull request #6288 from Security-Onion-Solutions/syncesusers_so-kratos
...
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:42:18 -05:00
m0duspwnens
55fed43469
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:35:35 -05:00
William Wernert
af83019427
Merge pull request #6287 from Security-Onion-Solutions/feat/cidr-extra-validation
...
Check for more invalid cidr syntax
2021-11-18 15:21:58 -05:00
William Wernert
4149236cda
Check for more invalid cidr syntax
2021-11-18 15:18:12 -05:00
Josh Patterson
825106d074
Merge pull request #6286 from Security-Onion-Solutions/fix/docker-upgrade
...
Prevent downgrade of docker, containerd, and docker-cli
2021-11-18 15:15:37 -05:00
William Wernert
1a3324868a
Specify version of docker-ce-rootless-extras
2021-11-18 15:12:47 -05:00
William Wernert
bc87bb4770
Specify docker cli version as well
2021-11-18 14:51:26 -05:00
William Wernert
6aae48bdae
Don't upgrade docker or containerd before versionlock is applied
2021-11-18 14:14:18 -05:00
Mike Reeves
a0425a48e6
Merge pull request #6282 from Security-Onion-Solutions/syncesusers_so-kratos
...
remove restart policy for kratos container
2021-11-18 11:43:16 -05:00
m0duspwnens
4b89bf7bbc
remove restart policy for kratos container
2021-11-18 11:41:07 -05:00
Mike Reeves
5fc5afa9ea
Merge pull request #6281 from Security-Onion-Solutions/syncesusers_so-kratos
...
install specific docker verison
2021-11-18 11:32:38 -05:00
m0duspwnens
ddec8e4da0
install specific docker verison
2021-11-18 11:29:22 -05:00
Jason Ertel
9c0e8cedba
Merge pull request #6279 from Security-Onion-Solutions/syncesusers_so-kratos
...
restart kratos if failure
2021-11-18 10:49:12 -05:00
m0duspwnens
5054da0027
restart kratos if failure
2021-11-18 10:48:06 -05:00
Jason Ertel
96f1f0174b
Merge pull request #6275 from Security-Onion-Solutions/syncesusers_so-kratos
...
break kratos state out from soc state
2021-11-18 09:13:10 -05:00
m0duspwnens
cd1f0c0440
break kratos state out from soc state
2021-11-18 09:10:00 -05:00
Mike Reeves
12546a8efa
Merge pull request #6271 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 19:48:15 -05:00
Josh Brower
3f5956b56d
Fix soup - fleetdm SA user
2021-11-17 19:47:16 -05:00
Mike Reeves
6e49ab0558
Merge pull request #6270 from Security-Onion-Solutions/fix/whiptail-text
...
Fix text cutoff
2021-11-17 19:18:46 -05:00
William Wernert
c52df32f05
Fix text cutoff
2021-11-17 19:08:10 -05:00
Josh Patterson
c0602f4222
Merge pull request #6269 from Security-Onion-Solutions/syncesusers_so-kratos
...
run elasticsearch.auth state and so-elastic-auth true before manager …
2021-11-17 18:41:18 -05:00
m0duspwnens
d4b412bcbe
run elasticsearch.auth state and so-elastic-auth true before manager in setup for syncesusers in manager state
2021-11-17 18:38:13 -05:00
Josh Brower
66e2de0934
Merge pull request #6268 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 18:26:11 -05:00
Josh Brower
c93794a402
Fix soup - fleetdm SA user
2021-11-17 18:22:34 -05:00
Josh Patterson
98efc6f2ed
Merge pull request #6267 from Security-Onion-Solutions/syncesusers_so-kratos
...
syncesusers require so-kratos
2021-11-17 18:20:53 -05:00
m0duspwnens
59ef734064
syncesusers require so-kratos
2021-11-17 18:16:06 -05:00
Josh Brower
922657afbc
Merge pull request #6266 from Security-Onion-Solutions/fix/fleet-users
...
Unset pw reset for new Fleet users
2021-11-17 17:10:27 -05:00
Josh Brower
5f3601ac78
Unset pw reset for new Fleet users
2021-11-17 17:06:01 -05:00
Josh Brower
2fe4fa06a6
Merge pull request #6265 from Security-Onion-Solutions/fix/fleet-users
...
Fix FleetDM SA Creation for SOUP
2021-11-17 14:09:59 -05:00
Josh Brower
773c580e77
Fix FleetDM SA Creation for SOUP
2021-11-17 14:08:34 -05:00
Mike Reeves
aca684d55a
Merge pull request #6264 from Security-Onion-Solutions/fix/fleet-users
...
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:16:05 -05:00
Josh Brower
6f391dbe50
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:13:25 -05:00
William Wernert
8d033264e7
Merge pull request #6262 from Security-Onion-Solutions/fix/new-cidr-test
...
Add new ipv4 address w/ cidr mask validator
2021-11-17 13:09:04 -05:00
William Wernert
262d2023b5
Add new ipv4 address w/ cidr mask validator
2021-11-17 12:41:25 -05:00
Josh Patterson
d143a309a1
Merge pull request #6261 from Security-Onion-Solutions/soup_soc_endgame
...
change how soc endgame added to manager pillar in soup
2021-11-17 11:12:17 -05:00
m0duspwnens
ac400f1c41
change how soc endgame added to manager pillar in soup
2021-11-17 11:07:12 -05:00
William Wernert
df495c0017
Merge pull request #6258 from Security-Onion-Solutions/fix/nm-conf
...
Run `check_network_manager_conf()` later in setup
2021-11-17 08:44:25 -05:00
William Wernert
8c454973ad
Run check_network_manager_conf() later in setup
...
The directory was being overwritten when network-manager was installed later
2021-11-17 08:42:27 -05:00
Josh Patterson
a16e6aca22
Merge pull request #6257 from Security-Onion-Solutions/es_soup_ingest
...
escape raw and endraw
2021-11-17 07:56:01 -05:00
m0duspwnens
ce21ae11f5
escape raw and endraw
2021-11-17 07:53:15 -05:00
Mike Reeves
fdd9706669
Merge pull request #6255 from Security-Onion-Solutions/kilo
2021-11-16 18:09:40 -05:00
Jason Ertel
8fa9a180b2
Refactor upgrade and post-upgrade version to function mappings; fix missing version upgrades from older 2.3.61 releases and earlier; Drop support for upgrading ancient RC releases
2021-11-16 18:08:28 -05:00
Josh Patterson
6288365a50
Merge pull request #6254 from Security-Onion-Solutions/es_soup_ingest
...
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:47:53 -05:00
m0duspwnens
5448107310
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:43:33 -05:00
Mike Reeves
adaf3faf90
Merge pull request #6253 from Security-Onion-Solutions/kilo
2021-11-16 16:13:31 -05:00
Jason Ertel
1bd8e226b4
Force DB migration since installations on 2.3.50 or earlier will skip the Kratos 0.6 version
2021-11-16 15:58:04 -05:00
Josh Patterson
f60f0b5b6d
Merge pull request #6246 from Security-Onion-Solutions/es_soup_ingest
...
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:05:15 -05:00
William Wernert
adc867846c
Merge pull request #6245 from Security-Onion-Solutions/fix/ubuntu-nic-unmanaged
...
Modify network-manager conf earlier in setup
2021-11-16 14:00:58 -05:00
m0duspwnens
5945326817
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:00:41 -05:00
William Wernert
90cbb5d00e
Modify network-manager conf earlier in setup
2021-11-16 13:30:09 -05:00
Josh Brower
8bb2789c6f
Merge pull request #6237 from Security-Onion-Solutions/kilo
...
Migrate to email field instead of username due to breaking change in …
2021-11-16 12:06:08 -05:00
Jason Ertel
11fc0da971
Migrate to email field instead of username due to breaking change in FleetDM 4.x
2021-11-16 12:03:46 -05:00
William Wernert
76a1d767f2
Merge pull request #6235 from Security-Onion-Solutions/feature/preflight-retry
...
Retry failed URLs in so-preflight + improve logging clarity
2021-11-16 11:11:02 -05:00
William Wernert
a2152446ea
Pad count string to align text
2021-11-16 11:08:13 -05:00
William Wernert
d4d9032bfc
Remove confusing punctuation
2021-11-16 10:56:49 -05:00
William Wernert
4e3f43bee4
Fix variable name
2021-11-16 10:53:22 -05:00
William Wernert
57377e0a0e
Add retry support + more precise logging to so-preflight
2021-11-16 10:46:48 -05:00
Mike Reeves
2514d36ccd
Merge pull request #6232 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2021-11-15 17:11:08 -05:00
Mike Reeves
809dbc0a48
Merge pull request #6233 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2021-11-15 17:10:52 -05:00
Mike Reeves
b51405d5e8
Update soup
2021-11-15 17:04:46 -05:00
Mike Reeves
d1cfc4a8dc
Merge pull request #6231 from Security-Onion-Solutions/fix/whiptail-cutoff
...
Fix whiptail description text
2021-11-15 17:02:00 -05:00
Mike Reeves
731bbabe4c
Update init.sls
2021-11-15 17:00:34 -05:00
William Wernert
d4509ff4d8
Fix whiptail description text
2021-11-15 16:29:26 -05:00
Mike Reeves
85c0b0818b
Merge pull request #6230 from Security-Onion-Solutions/fix/cidr-full-validation-bash
...
Check CIDR validity completely
2021-11-15 15:43:58 -05:00
William Wernert
f674555290
Check CIDR validity completely
2021-11-15 15:43:05 -05:00
Josh Patterson
a8aae544d5
Merge pull request #6229 from Security-Onion-Solutions/kibana_json_logging
...
change kibana logging to json
2021-11-15 14:27:04 -05:00
m0duspwnens
6f9db25ea7
change kibana logging to json
2021-11-15 14:23:47 -05:00
Mike Reeves
405e78858a
Merge pull request #6228 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2021-11-15 14:07:23 -05:00
Mike Reeves
146e1f4297
Update soup
2021-11-15 14:05:29 -05:00
Mike Reeves
f78e0fb7b9
Merge pull request #6227 from Security-Onion-Solutions/fix/fleetlogging
...
Fix env var for logging
2021-11-15 14:00:31 -05:00
Josh Brower
6e6d2d1949
Fix env var for logging
2021-11-15 13:52:35 -05:00
Josh Patterson
ca5d20fecb
Merge pull request #6225 from Security-Onion-Solutions/clean_meta_data
...
clean metadata with cmd.run instead of pkg module due to False return…
2021-11-15 11:03:41 -05:00
m0duspwnens
dcfaece8b1
clean metadata with cmd.run instead of pkg module due to False return from module
2021-11-15 11:00:31 -05:00
Mike Reeves
af0e062193
Merge pull request #6221 from Security-Onion-Solutions/fix/var-reference
...
Fix variable reference in so-functions
2021-11-15 09:49:07 -05:00
Mike Reeves
56acedfbf7
Merge pull request #6220 from Security-Onion-Solutions/fix/revert-python-validation
...
Fix/revert python validation
2021-11-15 09:44:31 -05:00
William Wernert
4b0a5c3a17
Un-revert validation test script
2021-11-15 09:43:43 -05:00
William Wernert
052192e1d6
Revert "Use python lib to make cidr validation more strict"
...
This reverts commit 569cb24861 .
2021-11-15 09:43:18 -05:00
weslambert
92131d4bb7
Merge pull request #6215 from Security-Onion-Solutions/fix/eg_spelling
...
Fix spelling
2021-11-12 21:13:28 -05:00
weslambert
9ac1cb0e76
Fix spelling
2021-11-12 21:12:09 -05:00
Josh Patterson
ffbb04bb5a
Merge pull request #6213 from Security-Onion-Solutions/issue/5809
...
Issue/5809
2021-11-12 15:07:54 -05:00
m0duspwnens
cc1dea446c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/5809
2021-11-12 15:02:22 -05:00
m0duspwnens
7f3379e034
verify manager pillars can be rendered before proceeding with soup - https://github.com/Security-Onion-Solutions/securityonion/issues/5809
2021-11-12 15:02:16 -05:00
weslambert
8c46a2d1db
Merge pull request #6210 from Security-Onion-Solutions/fix/soc_pillar_soup
...
Add SOC pillar entry
2021-11-12 13:35:46 -05:00
William Wernert
ba621639bd
Merge pull request #6201 from Security-Onion-Solutions/fix/cidr-ip-validation
...
Improve cidr validation in setup and match ip validation to similar method
2021-11-12 13:34:19 -05:00
Wes Lambert
2fb9196604
Move logic above version declaration
2021-11-12 18:26:21 +00:00
Wes Lambert
48c71c8b12
Add soc pillar entry
2021-11-12 18:23:09 +00:00
weslambert
8d185ced61
Merge pull request #6209 from Security-Onion-Solutions/fix/endgame_setup
...
Adjust manager pillar config for Endgame and defaults
2021-11-12 12:27:55 -05:00
William Wernert
9141c271f0
Fix indent
2021-11-12 12:25:32 -05:00
weslambert
bc2e470da9
Fix indentation
2021-11-12 12:20:00 -05:00
weslambert
0f817cd735
Merge pull request #6208 from Security-Onion-Solutions/fix/endgame_pivot
...
Make Endgame pivot independent
2021-11-12 12:17:24 -05:00
weslambert
df5901a65d
Adjust how manager pillar is populated for ENDGAME and default SOC config
2021-11-12 12:16:26 -05:00
weslambert
3cd1b5687e
Make pivot condition independent for ENDGAMEHOST
2021-11-12 12:06:39 -05:00
Josh Patterson
86a42addf0
Merge pull request #6207 from Security-Onion-Solutions/so_elastic_auth_password_reset
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:43:31 -05:00
m0duspwnens
6bf4d5a576
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:37:55 -05:00
William Wernert
efa5eb9f7f
Merge pull request #6184 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-11 13:57:07 -05:00
Josh Patterson
22959f0260
Merge pull request #6195 from Security-Onion-Solutions/issue/6146
...
Issue/6146
2021-11-11 11:47:33 -05:00
m0duspwnens
8da2133cff
give kibana.secrets pillar to import node
2021-11-11 11:31:07 -05:00
William Wernert
1472af4fc3
Merge branch 'dev' into foxtrot
2021-11-11 09:03:05 -05:00
Josh Brower
f91a6d3cb6
Merge pull request #6194 from Security-Onion-Solutions/fix/fleetstandalone
...
Add Fleet Standalone Node to manager ssl
2021-11-11 08:52:29 -05:00
Josh Brower
96f427d924
Add so-fleet to cert requirements
2021-11-11 08:45:22 -05:00
Josh Brower
184356618c
Add Fleet Standalone Node to manager ssl
2021-11-11 08:28:22 -05:00
William Wernert
ed3b2e4569
Put entire ref to doc page on new line
2021-11-10 17:46:35 -05:00
William Wernert
62b41af069
Fix docs link being cut off
2021-11-10 17:17:19 -05:00
William Wernert
569cb24861
Use python lib to make cidr validation more strict
...
Also update ipv4 validation to match the method used to validate cidr strings
2021-11-10 16:53:01 -05:00
William Wernert
ac22df8381
Merge branch 'dev' into foxtrot
2021-11-10 16:51:31 -05:00
Mike Reeves
446d6bd532
Merge pull request #6189 from Security-Onion-Solutions/soup2390
...
Soup2390
2021-11-10 16:49:46 -05:00
Mike Reeves
fcf889be2f
Add soup to 2.3.90
2021-11-10 16:46:24 -05:00
Mike Reeves
8168f19b31
Add soup to 2.3.90
2021-11-10 16:37:54 -05:00
Mike Reeves
ba553d971c
Add soup to 2.3.90
2021-11-10 16:31:44 -05:00
Mike Reeves
9137454a25
Add soup placeholders
2021-11-10 16:08:07 -05:00
m0duspwnens
7ebd861e32
enable secureCookies, security.encryptionKey and reporting.encryptionKey - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-10 16:05:40 -05:00
William Wernert
d110b63050
Merge pull request #6187 from Security-Onion-Solutions/fix/so-rule-modify-example
...
Fix `so-rule modify` example
2021-11-10 14:31:28 -05:00
William Wernert
3806f10f8b
Fix so-rule modify example
2021-11-10 14:18:32 -05:00
Jason Ertel
83bd314a63
Merge pull request #6186 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.2
2021-11-10 14:06:08 -05:00
Jason Ertel
6cd7b252df
Upgrade to ES 7.15.2
2021-11-10 13:59:55 -05:00
Jason Ertel
dea03bbf5e
Upgrade to ES 7.15.2
2021-11-10 13:44:20 -05:00
Josh Brower
9edc543262
Merge pull request #6183 from Security-Onion-Solutions/delta
...
Upgrade FleetDM to 4.5
2021-11-10 11:35:12 -05:00
Josh Brower
d3dc5ffc5a
Fix salt syntax
2021-11-10 11:28:48 -05:00
William Wernert
2c296e832f
Remove references to CURCLOSEDAYS in setup
...
Curator is configured differently now so the variable set during setup is no longer in use
2021-11-10 11:25:51 -05:00
Josh Brower
b350174df1
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-11-10 11:08:36 -05:00
Josh Brower
67ebfeab16
Disable FleetDM usage stats
2021-11-10 10:49:56 -05:00
Josh Brower
435f430747
Fix enroll secret parsing
2021-11-10 10:24:53 -05:00
Josh Patterson
aa9e1701f0
Merge pull request #6180 from Security-Onion-Solutions/issue/5794
...
timeout wazuh-register-agent faster
2021-11-10 09:58:05 -05:00
m0duspwnens
02d9b87f66
https://github.com/Security-Onion-Solutions/securityonion/issues/5794
2021-11-10 09:54:51 -05:00
Josh Patterson
cfd46c1e58
Merge pull request #6176 from Security-Onion-Solutions/bravo
...
Grafana improvements, pillarize kibana
2021-11-10 09:18:47 -05:00
m0duspwnens
392305e4ed
add engame changes that were missing from merge somehow
2021-11-10 09:01:42 -05:00
m0duspwnens
5ff14ab652
Merge remote-tracking branch 'origin/issue/6007' into bravo
2021-11-09 18:31:56 -05:00
m0duspwnens
1890c7244a
set elasticsearch:auth to persist through user pw change
2021-11-09 18:25:17 -05:00
m0duspwnens
a8c4ed7bbf
set elasticsearch:auth:enabled True in auth pillar
2021-11-09 18:05:05 -05:00
m0duspwnens
91f54537d7
handle elasticsearch.auth state like kibana.secrets
2021-11-09 17:52:38 -05:00
m0duspwnens
7e3a4656aa
change xpack update
2021-11-09 17:33:09 -05:00
m0duspwnens
8a04fcd919
change how key is added
2021-11-09 17:07:20 -05:00
m0duspwnens
409ab623a5
ensure kibana pillar dir exists
2021-11-09 16:49:45 -05:00
m0duspwnens
ac85d1598e
dont show changes
2021-11-09 16:44:54 -05:00
m0duspwnens
4c8e68e014
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-11-09 16:42:47 -05:00
m0duspwnens
57c6e26634
encrypt kibana saved objects - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-09 16:41:25 -05:00
m0duspwnens
b6a1d7418e
fix typo, dont show changes for kibana.yaml or dashboard so
2021-11-09 16:14:48 -05:00
weslambert
6eb1a0b0ae
Merge pull request #6169 from Security-Onion-Solutions/fix/ingest_dynamic_ref
...
Add dynamic conf to config change check
2021-11-09 16:11:38 -05:00
weslambert
9301b8f5b9
Add dynamic conf to config change check
2021-11-09 15:56:52 -05:00
m0duspwnens
202977a323
create so script to load saved object defaults
2021-11-09 15:54:15 -05:00
weslambert
9597373e4a
Merge pull request #6167 from Security-Onion-Solutions/ecs_pipeline_common
...
Add config for dynamically formatted ingest pipelines
2021-11-09 15:41:43 -05:00
Wes Lambert
f80b70e008
Add config for dynamically formatted ingest pipelines
2021-11-09 20:07:53 +00:00
William Wernert
04d2b52306
Fix IP route whiptail error
2021-11-09 14:03:32 -05:00
m0duspwnens
af7830c2be
remove reference to saved_objects in defaults
2021-11-09 13:52:47 -05:00
m0duspwnens
3c3cb47b88
merge with dev
2021-11-09 13:07:35 -05:00
m0duspwnens
da4e92a7a3
change config id
2021-11-09 12:13:28 -05:00
Mike Reeves
3afb0bd263
Merge pull request #6161 from Security-Onion-Solutions/sslchange
...
Enable Subject Alt Name for registry
2021-11-09 10:53:38 -05:00
Josh Brower
f6e6b20392
Add Name and OrgName to Fleet setup
2021-11-09 09:20:47 -05:00
William Wernert
3835a4401e
Merge pull request #6157 from Security-Onion-Solutions/foxtrot
...
Fix preflight script on centos
2021-11-09 08:49:46 -05:00
William Wernert
4bae57d994
Fix preflight printing to log
2021-11-09 08:34:02 -05:00
William Wernert
ea7289d92e
Fix preflight script on centos
2021-11-09 08:20:19 -05:00
m0duspwnens
48eaf190e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6007
2021-11-08 17:00:06 -05:00
m0duspwnens
497de0fede
hide vars on pipeline overview
2021-11-08 16:54:39 -05:00
m0duspwnens
70e3bc7eb8
hide vars on pipeline overview
2021-11-08 16:52:15 -05:00
Mike Reeves
eefc9cfcb6
Enable Subject Alt Name for registry
2021-11-08 16:50:43 -05:00
m0duspwnens
42b8955883
panel cleanup
2021-11-08 16:33:57 -05:00
m0duspwnens
f6b753b805
panel cleanup
2021-11-08 16:26:41 -05:00
m0duspwnens
17fc03a553
pipleine overview tc changes
2021-11-08 16:15:42 -05:00
weslambert
8bf88043ac
Merge pull request #6149 from Security-Onion-Solutions/add_test_pipeline
...
Add ECS testing pipeline
2021-11-08 15:43:03 -05:00
m0duspwnens
79640342f2
update redis queue query
2021-11-08 15:20:28 -05:00
Mike Reeves
3ad47742bd
Merge pull request #6150 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2021-11-08 15:18:35 -05:00
Mike Reeves
a8c02252dc
Update acng.conf
2021-11-08 15:16:05 -05:00
m0duspwnens
fbef420155
update redis queue query
2021-11-08 15:15:53 -05:00
m0duspwnens
ccd84e441d
add redis queue to pipeline overview
2021-11-08 15:09:46 -05:00
Wes Lambert
46d3eb452d
Add ECS testing pipeline
2021-11-08 20:08:56 +00:00
Josh Brower
083d467aa9
Update to FleetDM 4.5
2021-11-08 15:05:58 -05:00
m0duspwnens
f026ac1b41
pipeline overview tc changes
2021-11-08 15:02:52 -05:00
m0duspwnens
9ea292b11e
fix query
2021-11-08 13:48:33 -05:00
m0duspwnens
e2ee460fdd
fix gridPos
2021-11-08 12:39:23 -05:00
m0duspwnens
5b70ff61d1
fix gridPos
2021-11-08 12:37:03 -05:00
m0duspwnens
3b2ca89852
use endif not fi
2021-11-08 12:20:07 -05:00
m0duspwnens
199c97684c
fix nontc name in defaults
2021-11-08 12:10:23 -05:00
m0duspwnens
d67e34dac4
add pipeline overview for true cluster
2021-11-08 12:09:35 -05:00
William Wernert
49a573074e
Merge pull request #6142 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-08 11:29:58 -05:00
William Wernert
6c16d6d222
Update invalid hostname message
2021-11-08 11:15:28 -05:00
William Wernert
acba82d194
Update dist install menus' top text
2021-11-08 11:04:51 -05:00
William Wernert
f66d915f5d
Normal hostname check already checks for localhost
2021-11-08 10:38:30 -05:00
William Wernert
ee2dd75dfd
Fix variable ref
2021-11-08 10:36:36 -05:00
William Wernert
50b7779d6e
Make manager hostname error more specific
2021-11-08 10:35:28 -05:00
William Wernert
ad71485361
Fix whiptail height
2021-11-08 10:21:55 -05:00
William Wernert
8b2cccdf4a
More whiptail formatting
2021-11-08 10:21:17 -05:00
William Wernert
dbe4a7de63
Fix new whiptail layouts
2021-11-08 10:19:38 -05:00
William Wernert
9c4bba9ac9
Fix variable reference
2021-11-08 10:08:23 -05:00
Doug Burks
b3fd7c548c
Merge pull request #6135 from Security-Onion-Solutions/dougburks-patch-1
...
Improve clarity in CONTRIBUTING.md
2021-11-08 08:53:50 -05:00
Doug Burks
dcf6dfb676
Improve clarity
2021-11-08 06:38:16 -05:00
William Wernert
246d41c552
Add additional checks for manager hostname + ip
...
Check for current hostname, ip, and localhost (ip + string) when setting the manager ip and hostname
2021-11-05 15:56:08 -04:00
William Wernert
988932293f
Whiptail changes
...
* Ask whether to join to or create new dist install
* Also add links to architecture on install type prompts
2021-11-05 15:54:17 -04:00
m0duspwnens
0b28e89f3c
change how telegraf script determine if there is already and instance of the script already running
2021-11-04 23:22:13 -04:00
m0duspwnens
665732bd32
dont show points
2021-11-04 14:23:11 -04:00
m0duspwnens
b599b49630
enable beat input plugin for telegraf
2021-11-04 13:52:45 -04:00
m0duspwnens
edb3b602a9
pipeline overview dashboard changs
2021-11-04 10:59:01 -04:00
William Wernert
a4289b7ab9
Merge pull request #6107 from Security-Onion-Solutions/foxtrot
...
Manage docker gid and run preflight check during setup
2021-11-04 10:07:05 -04:00
Mike Reeves
9b0ce8b395
Merge pull request #6090 from Security-Onion-Solutions/commonupdate
...
Make common template honor replicas
2021-11-03 14:04:19 -04:00
m0duspwnens
05456b38d1
update panel
2021-11-03 13:54:05 -04:00
m0duspwnens
4fc58e7a5a
update panel
2021-11-03 13:51:57 -04:00
Mike Reeves
dc07aba63d
Update so-common-template.json.jinja
2021-11-03 13:50:31 -04:00
m0duspwnens
f1d66e2d51
change searchnode var
2021-11-03 13:40:09 -04:00
m0duspwnens
fab0dd2bad
add repeating es ingest panel for nontc
2021-11-03 13:25:42 -04:00
Mike Reeves
747f14d60e
Make common template honor replicas
2021-11-03 13:11:38 -04:00
William Wernert
fb35ff40b4
Just hide whiptail cancel message on test installs
2021-11-03 10:41:44 -04:00
m0duspwnens
2cb31a4c05
fix query
2021-11-03 09:27:02 -04:00
m0duspwnens
32f986c505
change panel
2021-11-03 09:23:21 -04:00
m0duspwnens
c8ee67f354
update panel for pipeline_overview
2021-11-03 09:12:32 -04:00
m0duspwnens
db80315c06
rename panel
2021-11-03 08:37:33 -04:00
m0duspwnens
8e3b08a831
start of pipeline dashboard
2021-11-03 08:33:20 -04:00
m0duspwnens
677f62ebd1
dont show changes for telegraf conf
2021-11-02 18:22:37 -04:00
William Wernert
d927e79154
Exit on failed preflight check during testing
2021-11-02 16:17:08 -04:00
William Wernert
8670aa6cd8
Run check-update in preflight instead of update
2021-11-02 14:29:58 -04:00
William Wernert
7c7c225a41
Fix tmp file check
2021-11-02 14:01:21 -04:00
m0duspwnens
54b034b537
fix spacing on es input
2021-11-02 13:43:59 -04:00
m0duspwnens
2232759fa4
rename file
2021-11-02 12:21:54 -04:00
m0duspwnens
f65eea6a03
rename file
2021-11-02 12:09:32 -04:00
William Wernert
e4a77acfe6
Move whiptail menus outside of progress func
2021-11-02 12:03:42 -04:00
William Wernert
9671dab2a3
Make so-preflight executable
2021-11-02 11:48:24 -04:00
William Wernert
e6adb46364
Run so-preflight during setup
2021-11-02 11:18:23 -04:00
m0duspwnens
7abb2e5935
monitor interface graph total
2021-11-02 11:07:29 -04:00
m0duspwnens
561f86eac8
change eps graphs to use logstash data and not consumptioneps script
2021-11-02 11:06:29 -04:00
William Wernert
9a9d1480de
Manage docker group's gid to prevent gid overlap
2021-11-02 10:41:36 -04:00
Josh Brower
8b52f87a60
Merge pull request #6066 from Security-Onion-Solutions/fix/evtx-import-elastic-creds
...
Fix/evtx import elastic creds
2021-11-02 09:25:25 -04:00
Josh Brower
a6f399acf4
Fix evtx import logging
2021-11-02 09:19:32 -04:00
Josh Brower
3534256517
Add evtx import logging
2021-11-02 09:03:52 -04:00
m0duspwnens
b109d95d6f
add max to zeek capture loss legend
2021-11-02 09:02:48 -04:00
Josh Brower
b756c0cd38
Pull ES Creds at Runtime
2021-11-02 08:57:11 -04:00
m0duspwnens
3517ea3f2a
select last value for cpucount var
2021-11-02 08:41:57 -04:00
m0duspwnens
5d414c8bdd
remove logstash row from manager
2021-11-02 08:36:13 -04:00
Josh Brower
2b56b53c15
Merge pull request #6064 from Security-Onion-Solutions/feature/support_non-wel_beats
...
Support non-WEL Beats
2021-11-02 08:29:48 -04:00
Josh Brower
2ba619144c
Support non-WEL Beats
2021-11-02 08:23:29 -04:00
m0duspwnens
a9be0a0409
create and add mon traffic combined graph to sensor dash
2021-11-02 07:55:39 -04:00
m0duspwnens
bf116d210e
mostly overview dash panel changes
2021-11-01 17:48:02 -04:00
William Wernert
f8b62b63f9
Merge pull request #6061 from Security-Onion-Solutions/foxtrot
...
Fix NIC string values for VLAN tagged interfaces
2021-11-01 16:43:52 -04:00
m0duspwnens
f4d9455872
revert to b63b50d98c
2021-11-01 16:10:13 -04:00
m0duspwnens
936c796b9d
Revert "graph changes"
...
This reverts commit 8857fca797 .
2021-11-01 15:19:50 -04:00
m0duspwnens
8ff122262c
Revert "update many panels"
...
This reverts commit b63b50d98c .
2021-11-01 14:50:57 -04:00
m0duspwnens
c4a1fbd82a
remove old json
2021-11-01 14:39:03 -04:00
m0duspwnens
8857fca797
graph changes
2021-11-01 14:36:41 -04:00
m0duspwnens
b63b50d98c
update many panels
2021-11-01 14:06:01 -04:00
William Wernert
c17187708e
Merge branch 'dev' into foxtrot
2021-11-01 12:46:43 -04:00
Mike Reeves
095e6bd48c
Merge pull request #6044 from Burak-PLT/patch-1
...
Update auth.sls
2021-11-01 10:22:16 -04:00
m0duspwnens
c4b9244f9a
add gridPos
2021-10-29 17:24:50 -04:00
m0duspwnens
2ba548fcfc
grafana bug fixes and improvements - https://github.com/Security-Onion-Solutions/securityonion/issues/6007
2021-10-29 17:11:51 -04:00
William Wernert
f76a52b2ee
Fix NIC string values for VLAN tagged interfaces
2021-10-29 13:34:23 -04:00
William Wernert
b555ad16da
Merge pull request #6052 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-10-29 10:52:51 -04:00
William Wernert
b1c67f696e
Re-order logic to maintain backwards compatibility
2021-10-29 10:47:05 -04:00
William Wernert
d08149f728
Don't set INTERWEBS variable on automated minions
2021-10-29 10:11:47 -04:00
William Wernert
a5cba5ecf8
Merge branch 'dev' into foxtrot
2021-10-29 10:01:46 -04:00
Burak-PLT
f081938be5
Update auth.sls
...
Change default password lengths to 72 characters from 20.
2021-10-28 16:00:58 -04:00
William Wernert
c2b18efdbb
Minions still need to be ISO installs to be airgap
2021-10-28 11:59:42 -04:00
William Wernert
6b480a5ba4
Change airgap check to something that doesn't require root
2021-10-28 11:51:50 -04:00
William Wernert
d6eeb0b735
Gen ssh key sooner
2021-10-28 10:04:03 -04:00
Josh Patterson
3000c57428
Merge pull request #6039 from Security-Onion-Solutions/issue/5759
...
Issue/5759
2021-10-28 09:24:44 -04:00
m0duspwnens
5c5b4004e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/5759
2021-10-28 08:52:04 -04:00
Josh Patterson
05e0f92ec5
Merge pull request #6036 from Security-Onion-Solutions/issue/5955
...
include ssl state in telegraf state
2021-10-28 08:50:57 -04:00
m0duspwnens
0cea5e8f22
include ssl state in telegraf state
2021-10-28 08:46:27 -04:00
m0duspwnens
7eb42fa6bd
change boolean
2021-10-28 08:43:03 -04:00
m0duspwnens
18ce9c7819
disable zeekpacketlosscron and telegraf checks if zeek is diabled via pillar
2021-10-28 07:46:02 -04:00
Mike Reeves
b3e5319806
Merge pull request #6028 from Security-Onion-Solutions/telecluster
...
Enable cluster stats
2021-10-27 16:37:42 -04:00
Mike Reeves
c8c8cf203f
Enable cluster stats
2021-10-27 15:44:52 -04:00
Josh Patterson
19056b9177
Merge pull request #6027 from Security-Onion-Solutions/issue/5955
...
Issue/5955
2021-10-27 15:07:22 -04:00
William Wernert
75490a2536
Fix typo
2021-10-27 14:59:24 -04:00
William Wernert
eee612e73d
Make folder/file states explicit
...
Rather than using /nsm/zeek (max_depth: 1) create explicit states for /nsm/zeek/spool and /nsm/zeek/spool/state.db that set correct ownership
2021-10-27 11:43:09 -04:00
William Wernert
9e9079f9cb
Reorder airgap prompt and add additional logic
...
Setup should now only ask the user whether to setup as airgap on manager-type installs. For all distributed minions setup will now inherit the airgap boolean from the manager.
2021-10-27 11:03:00 -04:00
William Wernert
331801eec2
Merge branch 'dev' into foxtrot
2021-10-27 10:58:16 -04:00
William Wernert
a0216cea57
Merge pull request #6021 from Security-Onion-Solutions/fix/update-mysql-root-user
...
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:55:11 -04:00
m0duspwnens
e7f43cff5e
limit nodes that bind filebeat certs in so-logstash
2021-10-27 10:45:10 -04:00
William Wernert
90d473f2d6
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:42:33 -04:00
m0duspwnens
bf403a8307
only manager nodes get cert, key and att&ck binds
2021-10-27 09:47:12 -04:00
m0duspwnens
58d62f29ea
include ssl state in registry state
2021-10-26 11:55:47 -04:00
Mike Reeves
bcf03773c0
Merge pull request #6009 from Security-Onion-Solutions/stenoports
...
Remove port bindings for steno
2021-10-26 10:58:11 -04:00
m0duspwnens
c0dd9efd9b
change so-thehive-es binds and requires
2021-10-26 10:50:16 -04:00
m0duspwnens
36ae07b78e
change timeout from 60 to 120
2021-10-26 10:49:50 -04:00
Mike Reeves
d77328608e
Remove port bindings for steno
...
Steno runs in host mode so port bindings are not required
2021-10-26 10:23:33 -04:00
m0duspwnens
682cbfd223
remove the mode
2021-10-26 09:23:24 -04:00
m0duspwnens
fa2edb2b59
make cortex_init and hive_init time out after 1 minutes vs 5 minutes
2021-10-26 08:39:30 -04:00
m0duspwnens
0c679b62b2
Merge remote-tracking branch 'remotes/origin/dev' into issue/5955
2021-10-25 16:29:41 -04:00
m0duspwnens
7e8d74e770
just use mode
2021-10-25 15:50:27 -04:00
m0duspwnens
9a78d13bee
change perms on mysql
2021-10-25 15:37:23 -04:00
Jason Ertel
c469d12a49
Merge pull request #6002 from Security-Onion-Solutions/kilo
...
Update whiptail links to use latest docs
2021-10-25 15:08:31 -04:00
Jason Ertel
d5f42e0d7c
Update whiptail links to use latest docs
2021-10-25 15:06:42 -04:00
weslambert
926551d398
Merge pull request #5998 from Security-Onion-Solutions/fix/hl_host_name
...
Rename HTTP client headers and host
2021-10-25 13:21:11 -04:00
weslambert
3be0d05eea
Update field removal based on HTTP input changes
2021-10-25 13:16:30 -04:00
weslambert
7fa43a276a
Rename default headers and host for HTTP input
2021-10-25 13:15:20 -04:00
William Wernert
2bfedbd581
Merge pull request #5996 from Security-Onion-Solutions/fix/escape-node-desc
...
Escape single quotes and allow for any character in node description
2021-10-25 10:53:36 -04:00
William Wernert
dca30146ab
Merge branch 'dev' into foxtrot
2021-10-25 10:50:25 -04:00
William Wernert
6e34905b42
Escape single quotes and allow for any character in node description
2021-10-25 10:48:09 -04:00
m0duspwnens
ee7e714f43
change to file_mode
2021-10-22 16:55:23 -04:00
m0duspwnens
d7e5377a44
more requires
2021-10-22 16:46:45 -04:00
William Wernert
38b16a507b
Update ip for root user in mysql when running so-ip-update
2021-10-22 15:29:32 -04:00
William Wernert
17af513692
Escape single quotes and allow for any character in node description
2021-10-22 15:28:37 -04:00
m0duspwnens
283f7296bc
fix require
2021-10-22 14:45:22 -04:00
m0duspwnens
9f6407fcb0
fix dupe ids
2021-10-22 14:26:04 -04:00
m0duspwnens
f61400680d
fix dupe ids
2021-10-22 14:22:15 -04:00
m0duspwnens
fed8bfac67
more requires on docker containers
2021-10-22 14:10:59 -04:00
William Wernert
62971d8c15
Add Fleet custom hostname to end summary
2021-10-22 11:57:47 -04:00
William Wernert
352e30f9e1
Add CUSTOM_FLEET_HOSTNAME to subjectAltName of fleet.key
...
Resolves #4319
2021-10-22 11:16:29 -04:00
m0duspwnens
451b19dc4d
change from file to x509
2021-10-22 09:53:20 -04:00
William Wernert
d5d970672d
Merge pull request #5974 from Security-Onion-Solutions/foxtrot
...
Add so-deny script + rewrite so-allow to match
2021-10-21 16:37:05 -04:00
m0duspwnens
f93c6146f5
docker binds requires
2021-10-21 15:24:55 -04:00
weslambert
40dd33affe
Merge pull request #5971 from Security-Onion-Solutions/feature/es_templates
...
Add .keyword subfield for conflict fields
2021-10-21 15:07:00 -04:00
William Wernert
f374dcbb58
Check for IP environment variable in so-allow and so-deny
2021-10-21 13:54:06 -04:00
weslambert
77ee1db44c
Add .keyword subfield for conflict fields
2021-10-21 12:56:03 -04:00
Josh Patterson
8784d65023
Merge pull request #5967 from Security-Onion-Solutions/issue/5954
...
require files before starting soc or kratos
2021-10-21 11:15:36 -04:00
William Wernert
15fe7512b7
Install lxml during setup and in common state
2021-10-21 10:49:41 -04:00
William Wernert
0beeeb94bf
Actually add new so-allow script
2021-10-21 10:48:17 -04:00
m0duspwnens
928aed27c5
require files before starting soc or kratos
2021-10-20 17:04:02 -04:00
William Wernert
387d4d6ad5
Add so-deny script + rewrite so-allow to match so-deny
2021-10-20 16:44:57 -04:00
William Wernert
adf6cb4b3c
Merge branch 'dev' into foxtrot
2021-10-20 16:44:50 -04:00
William Wernert
0ed2ce0766
Fix validation.sh tests
2021-10-20 16:44:09 -04:00
William Wernert
b5cb47e066
Fix sbin perms
2021-10-20 16:43:55 -04:00
Josh Patterson
8061508330
Merge pull request #5961 from Security-Onion-Solutions/issue/5960
...
Issue/5960
2021-10-20 16:08:50 -04:00
m0duspwnens
adffb11800
fix redis port
2021-10-20 15:39:21 -04:00
m0duspwnens
8619af59cc
servers to list format
2021-10-20 15:02:33 -04:00
m0duspwnens
7ecfb55b70
fix pillar call
2021-10-20 14:50:50 -04:00
m0duspwnens
b496810b63
add redis and logstash input plugins to telegraf
2021-10-20 14:46:47 -04:00
Mike Reeves
e1ad02c28d
Merge pull request #5949 from Security-Onion-Solutions/kilo
...
Fix Docker-created corruption of SOC user roles file
2021-10-19 18:37:37 -04:00
Jason Ertel
2f8bb5a2a6
Fix Docker-created corruption of SOC user roles file
2021-10-19 16:04:10 -04:00
weslambert
6f3e441bf7
Merge pull request #5945 from Security-Onion-Solutions/fix/soc_index_pattern
...
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:05:40 -04:00
Mike Reeves
7f1585dcc0
Merge pull request #5942 from Security-Onion-Solutions/tunesteno
...
Fix Steno Math for PL
2021-10-19 13:03:50 -04:00
weslambert
9453ed7fa1
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:01:40 -04:00
Mike Reeves
64f25961b0
Fix Steno Math for PL
2021-10-19 11:15:58 -04:00
Mike Reeves
b9a3d3a6a9
Fix Steno Math for PL
2021-10-19 11:14:02 -04:00
m0duspwnens
36cb0d6c42
remove space
2021-10-18 14:34:33 -04:00
m0duspwnens
1b2268dfe5
load kibana configs during setup
2021-10-18 14:30:47 -04:00
Mike Reeves
00e5b54dda
Merge pull request #5911 from Security-Onion-Solutions/tunesteno
...
Add Steno Tuning Options
2021-10-18 09:01:14 -04:00
Mike Reeves
4016b416ec
Merge pull request #5923 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.1
2021-10-16 09:15:06 -04:00
weslambert
7590728a0b
Merge pull request #5915 from Security-Onion-Solutions/feature/ti_module
...
Add TI module
2021-10-15 17:17:33 -04:00
weslambert
bb36fc1ed8
Add TI module defaults
2021-10-15 17:16:38 -04:00
weslambert
d0a6dafc8b
Add TI module
2021-10-15 17:09:59 -04:00
m0duspwnens
76097476d3
remove includes
2021-10-15 16:57:38 -04:00
m0duspwnens
8b3b0bf160
fix opts
2021-10-15 16:51:11 -04:00
m0duspwnens
f19680b3e6
fix opts
2021-10-15 16:50:03 -04:00
m0duspwnens
7e1bbe3cc2
define MAANGER
2021-10-15 16:14:14 -04:00
m0duspwnens
947285e932
update cmd.run amd s_o files
2021-10-15 16:06:25 -04:00
m0duspwnens
1741f5068a
update config-load to do an update or import
2021-10-15 15:35:30 -04:00
Mike Reeves
a9f6c84d7c
Add Steno Tuning Options
2021-10-15 14:17:54 -04:00
weslambert
59852841ff
Add keyword subfield for event.module
2021-10-15 13:29:50 -04:00
weslambert
6f1f7d2a63
Merge pull request #5905 from Security-Onion-Solutions/feature/soc_es_index_pattern
...
Allow setting ES index patterns for SOC in pillar
2021-10-15 13:28:04 -04:00
Jason Ertel
8de8d58155
Upgrade to ES 7.15.1
2021-10-15 13:27:08 -04:00
Wes Lambert
8feeff97b5
Add EG index pattern during setup (if enabled)
2021-10-15 16:19:19 +00:00
Wes Lambert
032373187c
Allow setting ES index patterns for SOC in pillar
2021-10-15 16:02:53 +00:00
William Wernert
db2b70f655
Merge pull request #5900 from Security-Onion-Solutions/foxtrot
...
Replace rather than append to Kibana misc log
2021-10-15 10:27:25 -04:00
Jason Ertel
1800ec4570
Upgrade to Elastalert 2 v2.2.2
2021-10-15 09:25:44 -04:00
Mike Reeves
8a5960c220
Merge pull request #5896 from Security-Onion-Solutions/kilo
2021-10-14 18:05:33 -04:00
Jason Ertel
9797a15218
Fix issue with 'so-user delete' resetting all user roles - note that this function is not technically supported or published since it's not intended for production use
2021-10-14 17:23:18 -04:00
William Wernert
c7b15a9b1f
Replace rather than append to Kibana misc log
2021-10-14 15:13:55 -04:00
William Wernert
cba97802fe
Fix indent
2021-10-14 15:13:34 -04:00
William Wernert
025256aeaf
Merge pull request #5890 from Security-Onion-Solutions/foxtrot
...
Misc setup changes
2021-10-14 14:55:24 -04:00
weslambert
490f7eaf81
Merge pull request #5886 from Security-Onion-Solutions/feature/eg_pivot
...
Add EG pivot
2021-10-14 14:49:38 -04:00
m0duspwnens
6a2bf11a75
change format of file
2021-10-14 13:43:39 -04:00
m0duspwnens
78d30285b1
seperate securitySolutions load
2021-10-14 13:24:51 -04:00
Wes Lambert
f1fafa015e
Add EG to list of groups to include 127.0.0.1
2021-10-14 16:27:28 +00:00
Wes Lambert
6cdc214582
Add pillar in setup and change name of EG variable
2021-10-14 15:33:37 +00:00
Wes Lambert
15049f44b9
Add EG pivot
2021-10-14 15:15:23 +00:00
Doug Burks
42a642b85c
Merge pull request #5873 from petiepooo/enh-rediscount-tty
...
featreq: remove tty flag in redis-count script
2021-10-14 10:07:07 -04:00
weslambert
3b45e68ead
Merge pull request #5885 from Security-Onion-Solutions/feature/jinjafy_soc_actions
...
Allow SOC actions to use Jinja
2021-10-14 10:03:12 -04:00
Wes Lambert
5ee0ea3fe7
Allow SOC actions to use Jinja
2021-10-14 13:59:55 +00:00
weslambert
55c60f485c
Merge pull request #5884 from Security-Onion-Solutions/feature/hl_eg
...
Add EG firewall allowance via setup
2021-10-14 09:55:07 -04:00
Wes Lambert
78e88e0765
Add EG firewall allowance via setup
2021-10-13 21:42:54 +00:00
Wes Lambert
a9b250c0f4
Add EG firewall config
2021-10-13 21:37:59 +00:00
m0duspwnens
ae9753326a
fix var, quote vars
2021-10-13 16:38:01 -04:00
m0duspwnens
c8fb504ee0
Revert "Merge remote-tracking branch 'remotes/origin/dev' into issue/3933"
...
This reverts commit 54eec92621 , reversing
changes made to 7832e59629 .
2021-10-13 15:22:46 -04:00
m0duspwnens
54eec92621
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 15:19:33 -04:00
m0duspwnens
7832e59629
only load default kibana saved_objects during setup
2021-10-13 15:19:20 -04:00
weslambert
f9001654bb
Merge pull request #5871 from Security-Onion-Solutions/feature/hl_eg
...
Initial EG stuff
2021-10-13 15:07:03 -04:00
Wes Lambert
2a504a061b
Add Curator action files for EG indices
2021-10-13 18:40:34 +00:00
m0duspwnens
bb9c6446e4
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 14:01:36 -04:00
Pete
e7581036f7
remove tty/interactive flags
...
This call to docker exec simply returns a number. No interaction (stdin) or tty is required. Specifically, having the -t option prevents running via salt using a command such as:
> salt '*' cmd.run 'so-redis-count'
2021-10-13 13:51:05 -04:00
Wes Lambert
e1629d7ec4
Initial EG stuff
2021-10-13 17:13:07 +00:00
Josh Patterson
b4873bd296
Merge pull request #5868 from Security-Onion-Solutions/issue/5818
...
Issue/5818
2021-10-13 12:52:48 -04:00
m0duspwnens
3044edb104
update comment
2021-10-13 12:38:58 -04:00
m0duspwnens
a495779552
only 3 attempts with 120s max attemps
2021-10-13 12:34:56 -04:00
m0duspwnens
880c1b97b0
remove $ from var
2021-10-13 12:25:11 -04:00
m0duspwnens
7a4fa8879c
change count, attempts and timeout
2021-10-13 12:13:24 -04:00
m0duspwnens
adb8292814
add missing )
2021-10-13 10:37:18 -04:00
m0duspwnens
6e7a5fa326
add timeouts to check_salt_minion_status and check_salt_master_status - https://github.com/Security-Onion-Solutions/securityonion/issues/5818
2021-10-13 09:45:15 -04:00
m0duspwnens
23ea53248d
single line format
2021-10-12 14:15:37 -04:00
m0duspwnens
f1a5991699
add securitySolution.defaultIndex to defaults
2021-10-12 12:35:13 -04:00
m0duspwnens
c69ad091f7
update saved_objects config
2021-10-12 12:02:30 -04:00
William Wernert
b97361fab9
Remove references to xenial in setup
...
Resolves #4292
2021-10-12 10:23:39 -04:00
William Wernert
36e1795295
Add end of setup log messages per #5032
2021-10-12 10:19:47 -04:00
m0duspwnens
498e385484
change name to SAVED_OBJECTS
2021-10-12 10:15:39 -04:00
William Wernert
af687b0706
Remove all holds on Ubuntu reinstall
2021-10-12 10:10:34 -04:00
m0duspwnens
19489f3626
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-12 10:07:40 -04:00
m0duspwnens
89d1df8a1d
change name to SAVED_OBJECTS
2021-10-12 10:07:26 -04:00
William Wernert
946cf81a27
If ANALYST is selected immediately quit setup
2021-10-12 09:48:38 -04:00
Mike Reeves
2561480371
Merge pull request #5850 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.7.6-alpha.1
2021-10-12 08:19:25 -04:00
Jason Ertel
d21dee162d
Add Note field to user traits; Enforce max length restrictions on email, firstname, lastname, and note fields
2021-10-08 12:39:17 -04:00
Mike Reeves
444d067112
Merge pull request #5813 from Security-Onion-Solutions/macleod
...
Highlander changes
2021-10-08 10:06:18 -04:00
Mike Reeves
2a82373051
highlander fixes
2021-10-08 09:32:13 -04:00
Mike Reeves
64758a534c
Set ml to true
2021-10-08 08:42:26 -04:00
m0duspwnens
7517a63008
disabled ml
2021-10-07 13:06:52 -04:00
m0duspwnens
b2facdf31c
add securitySolutions advanced setting
2021-10-07 12:57:28 -04:00
m0duspwnens
4c54d6309c
change host to 0.0.0.0
2021-10-07 09:59:29 -04:00
Jason Ertel
62c3afc81d
Migrate users from locked to inactive during soup
2021-10-06 15:45:35 -04:00
Jason Ertel
7d8c8144b0
Drop obsolete status trait
2021-10-06 12:52:41 -04:00
Jason Ertel
a2c4fce1ef
Switch to use state attribute in identities for enabling/disabling users
2021-10-06 11:53:10 -04:00
m0duspwnens
599aba43d9
restart so-kibaba if config changes
2021-10-06 09:51:16 -04:00
m0duspwnens
fa4f92cdda
change defaults
2021-10-05 17:35:44 -04:00
m0duspwnens
5d98c0d14c
fix dict update
2021-10-05 15:57:57 -04:00
Mike Reeves
27614569e3
Fix set
2021-10-05 14:32:02 -04:00
m0duspwnens
ec357cca3c
fix cars
2021-10-05 12:57:30 -04:00
m0duspwnens
26681ac98a
var for dash saved objevs
2021-10-05 12:46:21 -04:00
m0duspwnens
748f0f2a1d
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-05 12:12:56 -04:00
Mike Reeves
869af548af
Fix spaces for highlander
2021-10-05 11:06:13 -04:00
Mike Reeves
2fd344822d
Add additional roles for highlander
2021-10-05 10:40:40 -04:00
Mike Reeves
a3e0fb127a
Merge pull request #5069 from datlife/datlife/asn-annotation
...
Add ASN annotation for IP
2021-10-05 06:50:31 -04:00
Dat
9569e73bd0
Added ASN annotation for IP
2021-10-04 12:41:20 -07:00
m0duspwnens
96d783b158
merge with dev
2021-10-04 10:39:48 -04:00
m0duspwnens
e0c097c270
add dashboard theme defaults
2021-10-04 10:36:58 -04:00
Mike Reeves
e6fce4cf3e
Merge pull request #5749 from Security-Onion-Solutions/kilo
...
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:55:53 -04:00
Jason Ertel
6ef9a5c95d
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:53:25 -04:00
Mike Reeves
727613b6e1
Merge pull request #5601 from Security-Onion-Solutions/special
...
Ubuntu 20.04 Beta
2021-10-04 08:51:01 -04:00
Mike Reeves
5013aa8490
Merge pull request #5748 from Security-Onion-Solutions/kilo
...
Merge ES Upgrade, Version Bump into dev
2021-10-04 08:48:07 -04:00
Jason Ertel
72a1b299ac
Bump to 2.3.90
2021-10-04 08:44:51 -04:00
Mike Reeves
cfaa0e679c
Merge pull request #5739 from Security-Onion-Solutions/dev
...
2.3.80
2021-10-01 15:15:54 -04:00
Mike Reeves
4ddf2b49ce
Merge pull request #5669 from Security-Onion-Solutions/2.3.80
...
2.3.80
2021-10-01 15:11:03 -04:00
m0duspwnens
bb95963d73
add missing {{}}
2021-09-30 14:40:13 -04:00
m0duspwnens
dfa9afde0e
change to mode
2021-09-30 14:33:52 -04:00
m0duspwnens
fa2333b9ef
change t file.managed
2021-09-30 14:32:28 -04:00
m0duspwnens
8b9c43915d
fix source
2021-09-30 14:30:00 -04:00
m0duspwnens
36832139b2
pillarize kibana
2021-09-30 14:28:31 -04:00
m0duspwnens
c3bf835566
kibana config
2021-09-30 14:23:49 -04:00
m0duspwnens
39d3c7c6ed
begin pillarization of kibana
2021-09-30 11:48:42 -04:00
Jason Ertel
b1a5527e82
Update ElastAlert to use ElastAlert 2
2021-09-28 07:01:47 -04:00
Jason Ertel
d0592c4293
Update ElastAlert to use ElastAlert 2
2021-09-28 00:51:29 -04:00
Mike Reeves
b1d0e3e93f
2.3.80
2021-09-27 12:32:45 -04:00
Mike Reeves
b069377c8a
2.3.80
2021-09-27 10:13:42 -04:00
Jason Ertel
e9a44c6e1b
Merge pull request #5662 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update README.md
2021-09-27 09:28:46 -04:00
Mike Reeves
275163f85d
Update README.md
2021-09-27 07:36:54 -04:00
William Wernert
98f74c25ba
Fix variable reference in so-functions
2021-09-24 12:32:56 -04:00
William Wernert
3064800820
Merge pull request #5636 from Security-Onion-Solutions/fix/soup-2.3.80
...
Misc. soup fixes
2021-09-23 13:03:43 -04:00
William Wernert
f8bea82430
Make redirect consistent with setup
2021-09-23 12:57:08 -04:00
William Wernert
8b905b585d
Fix redirect to append
2021-09-23 12:55:06 -04:00
William Wernert
b44358fc26
Add set +e after final upgrade steps and before post-upgrade checks
2021-09-23 12:49:42 -04:00
William Wernert
8a9dcb7fdb
Fix "upgrade to" message
...
Only specify "to" version and change when the upgrade message occurs
2021-09-23 12:47:22 -04:00
William Wernert
a01d49981c
Redirect thehive/cortex migrate curl output to soup log
2021-09-23 12:45:44 -04:00
William Wernert
b8b1867e52
Tell user what soup is doing at end of upgrade
2021-09-23 12:43:23 -04:00
William Wernert
292ce37ce4
Merge pull request #5632 from Security-Onion-Solutions/fix/logscan-soup
...
Add logscan to images for pull during soup if it's enabled
2021-09-23 10:13:20 -04:00
William Wernert
73dacdcbff
Add logscan to images for pull during soup if it's enabled
2021-09-23 09:52:23 -04:00
Josh Patterson
bea7555464
Merge pull request #5631 from Security-Onion-Solutions/80soup
...
80soup
2021-09-22 16:01:45 -04:00
m0duspwnens
52c1298b9b
notify of custom es config
2021-09-22 15:16:07 -04:00
m0duspwnens
cdb9dcbaec
notify of custom es config
2021-09-22 15:07:36 -04:00
Mike Reeves
37153288e8
Merge pull request #5627 from Security-Onion-Solutions/80soup
...
ignore manager pillar file for noderoutetype
2021-09-22 12:03:55 -04:00
m0duspwnens
edf75255cf
ignore manager pillar file for noderoutetype
2021-09-22 12:01:32 -04:00
Jason Ertel
9eb6f5942e
Merge pull request #5623 from Security-Onion-Solutions/kilo
...
Prevent email addresses from having uppercase characters
2021-09-22 09:10:38 -04:00
Jason Ertel
dae41d279a
Prevent emails addresses from having uppercase characters
2021-09-22 08:25:55 -04:00
Mike Reeves
07288367cf
Merge pull request #5611 from Security-Onion-Solutions/80soup
...
match elasticsearch at beginning of line
2021-09-21 15:42:09 -04:00
m0duspwnens
f4186feffa
move node_route_type
2021-09-21 15:40:49 -04:00
m0duspwnens
d82e91f69e
match elasticsearch at beginning of line
2021-09-21 13:54:45 -04:00
Josh Patterson
a2680fad0a
Merge pull request #5605 from Security-Onion-Solutions/80soup
...
fi xquotes
2021-09-21 13:02:58 -04:00
m0duspwnens
5c2be487f5
fi xquotes
2021-09-21 13:01:40 -04:00
Mike Reeves
531c9de488
Merge pull request #5600 from petiepooo/petiepooo-raidstat-fix
...
missing dollarsign
2021-09-21 11:35:57 -04:00
Pete
19efa493ad
missing dollarsign
2021-09-21 11:21:07 -04:00
Mike Reeves
0db3f14261
Merge pull request #5598 from Security-Onion-Solutions/80soup
...
Soup Changes for True Clusters
2021-09-21 09:57:12 -04:00
Mike Reeves
ed28e4d000
Soup Changes for True Clusters
2021-09-21 09:55:49 -04:00
Mike Reeves
2c8cbf0db1
Soup Changes for True Clusters
2021-09-21 09:53:09 -04:00
Mike Reeves
c1537335b1
Fix Python Problem
2021-09-20 19:05:01 -04:00
Mike Reeves
5f475ff9cb
Fix Python Problem
2021-09-20 18:46:43 -04:00
Mike Reeves
481ffb1cda
Fix Grain
2021-09-20 18:12:18 -04:00
Mike Reeves
50b78681f2
Ubuntu 20.04 Support
2021-09-20 17:24:47 -04:00
Jason Ertel
3924b8f5db
Merge pull request #5586 from Security-Onion-Solutions/kilo
...
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:56:30 -04:00
Jason Ertel
a9049eccd4
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:30:05 -04:00
Mike Reeves
1a7237bcdf
Merge pull request #5583 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2021-09-20 10:44:20 -04:00
Mike Reeves
1e5e1c9ef0
Update soup
2021-09-20 10:42:55 -04:00
Josh Patterson
47cd1ddc0a
Merge pull request #5580 from Security-Onion-Solutions/issue/1257
...
Issue/1257 - Pillarize ES
2021-09-20 09:31:03 -04:00
m0duspwnens
aed73511e4
file cleanup, comment cleanup
2021-09-20 09:24:03 -04:00
Jason Ertel
a3f62c81c3
Merge pull request #5577 from Security-Onion-Solutions/kilo
...
Continuation of auth enhancements
2021-09-20 06:30:36 -04:00
Jason Ertel
730503b69c
Ensure highstate migrates user roles
2021-09-18 23:17:49 -04:00
Jason Ertel
3508f3d8c1
Ensure ES user/role files are generated even if the primary admin user isn't yet created, since the system users are necessary for other installation functions
2021-09-18 19:20:43 -04:00
Jason Ertel
5704906b11
Create empty files for Docker to mount while installation continues
2021-09-18 15:49:05 -04:00
Jason Ertel
357c1db445
Recover from situation where roles file is corrupted
2021-09-18 11:08:35 -04:00
Jason Ertel
5377a1a85e
Recover from situation where roles file is corrupted
2021-09-18 11:06:54 -04:00
Jason Ertel
7f2d7eb038
Continue migration of user emails to IDs
2021-09-18 07:20:34 -04:00
Jason Ertel
30e781d076
Use user ID instead of email as role master
2021-09-17 17:54:38 -04:00
m0duspwnens
01323cc192
fix clustername redirect
2021-09-17 15:44:54 -04:00
m0duspwnens
109c83d8c3
move custom es cluster name pillar location
2021-09-17 15:29:41 -04:00
m0duspwnens
e864bc5404
move custom es cluster name pillar location
2021-09-17 15:28:35 -04:00
Josh Brower
22eb82e950
Merge pull request #5566 from Security-Onion-Solutions/feature/disable_services
...
Add support for disabling Zeek and Suricata
2021-09-17 14:18:03 -04:00
m0duspwnens
b877aa44bc
update dict
2021-09-17 14:10:45 -04:00
Josh Brower
4d307c53e8
Add support for disabling Zeek and Suricata
2021-09-17 13:01:50 -04:00
m0duspwnens
d0c87cd317
allow for pillar override of defaults
2021-09-17 12:11:12 -04:00
m0duspwnens
0d074dafd4
add missing defaults
2021-09-17 09:52:50 -04:00
m0duspwnens
5b77dc109f
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-16 16:54:23 -04:00
m0duspwnens
3ce48acadd
change cluster_settings to config
2021-09-16 16:44:31 -04:00
Jason Ertel
fbd9bab2f1
Split apart roles and users into separate maps
2021-09-16 16:08:55 -04:00
m0duspwnens
5526a2bc3a
reduce defaults.yaml
2021-09-16 15:32:08 -04:00
weslambert
18d81352c6
Merge pull request #5537 from Security-Onion-Solutions/delta
...
Add improved ignore functionality for YARA rules used by Strelka and add default ignored rules that break compilation
2021-09-16 10:38:49 -04:00
m0duspwnens
889d235c45
no box type more manager in true cluster
2021-09-16 09:15:24 -04:00
Jason Ertel
3fc26312e0
Remove x-user-id header from unauthenticated proxied requests
2021-09-16 08:52:31 -04:00
Jason Ertel
b81d38e392
Merge branch 'dev' into kilo
2021-09-16 07:44:35 -04:00
Jason Ertel
82da0041a4
Add limited roles with restricted visibility
2021-09-16 07:44:15 -04:00
m0duspwnens
782b01e76f
seed_hosts to list
2021-09-15 17:07:52 -04:00
m0duspwnens
3bf9685df8
fix seed_hosts append
2021-09-15 17:00:16 -04:00
m0duspwnens
4cf91f6c86
fix dict update
2021-09-15 15:51:00 -04:00
m0duspwnens
a43b37f234
fix dict update
2021-09-15 15:49:18 -04:00
m0duspwnens
e0dc62b6e9
fix dict update
2021-09-15 15:43:47 -04:00
m0duspwnens
c213834316
update the dict
2021-09-15 15:24:40 -04:00
Josh Brower
c06668c68e
Merge pull request #5527 from Security-Onion-Solutions/feature/so-import-evtx
...
Feature/so import evtx
2021-09-15 14:17:15 -04:00
Josh Brower
a75238bc3f
so-import-evtx - fix ingest formatting
2021-09-15 14:13:16 -04:00
Josh Brower
ac417867ed
so-import-evtx - final fixes
2021-09-15 14:06:08 -04:00
m0duspwnens
1614b70853
update cluster name if true cluster
2021-09-15 13:45:43 -04:00
Mike Reeves
0882158e03
Merge pull request #5525 from Security-Onion-Solutions/soup80
...
soup changes 2.3.80
2021-09-15 13:44:54 -04:00
m0duspwnens
1a03853a7c
fix extend
2021-09-15 13:38:29 -04:00
Mike Reeves
aff571faf2
soup changes 2.3.80
2021-09-15 13:32:52 -04:00
m0duspwnens
e0faa4c75b
Merge branch 'issue/1257' of https://github.com/Security-Onion-Solutions/securityonion into issue/1257
2021-09-15 13:09:35 -04:00
m0duspwnens
e3e2e1d851
logic for truecluster to map file
2021-09-15 13:09:04 -04:00
weslambert
2affaf07a2
Merge pull request #5521 from Security-Onion-Solutions/fix/strelka-yara
...
Fix/strelka yara
2021-09-15 11:33:44 -04:00
weslambert
39e5ded58d
Refactor ignore list and only ignore for signature-base for now
2021-09-15 11:32:29 -04:00
weslambert
4d41d3aee1
Ignore these rules by default because they are causing issues with YARA compilation with Strelka
2021-09-15 10:29:11 -04:00
weslambert
5c8067728e
Remove unnecessary logic
2021-09-15 10:22:17 -04:00
Josh Brower
1d905124d3
Merge pull request #5519 from Security-Onion-Solutions/fix/fleet-link
...
Fix Fleet Link Logic
2021-09-15 09:30:21 -04:00
Josh Brower
e0a289182f
Fix Fleet Link Logic
2021-09-15 09:28:23 -04:00
m0duspwnens
551dba955c
set roles empty list
2021-09-15 09:20:33 -04:00
Jason Ertel
9970e54081
Adjust custom_role examples to be more realistic
2021-09-14 14:03:22 -04:00
Jason Ertel
ff989b1c73
Include wording in so-user relating to optional role parameter
2021-09-14 14:03:00 -04:00
Mike Reeves
2ffb723bbd
Rename so-common-template.json to so-common-template.json.jinja
2021-09-14 13:58:45 -04:00
Mike Reeves
6ae2fba71f
Update search.sls
2021-09-14 13:57:26 -04:00
Mike Reeves
2cc25587d9
Update eval.sls
2021-09-14 13:57:04 -04:00
Mike Reeves
614a6dc9fe
Update manager.sls
2021-09-14 13:56:43 -04:00
Josh Brower
4b7667d87f
Merge pull request #5508 from Security-Onion-Solutions/fix/fleet-link
...
Fleet SA - SOC Link Fix
2021-09-14 13:29:20 -04:00
Josh Brower
74b0b365bd
Fleet SA - SOC Link Fix
2021-09-14 13:23:07 -04:00
Josh Brower
0b0d508585
so-import-evtx - tweaks
2021-09-14 12:01:14 -04:00
m0duspwnens
0534a2dda3
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-13 15:04:50 -04:00
m0duspwnens
f8ab0ac8a9
config changes
2021-09-13 15:04:39 -04:00
m0duspwnens
0ae09cc630
config changes
2021-09-13 09:49:56 -04:00
Mike Reeves
332c4dda22
Merge pull request #5469 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Allow so-rule-update to accept any number of args
2021-09-10 14:41:55 -04:00
William Wernert
679faddd52
Update so-rule-update to pass all args to docker exec
...
Instead of passing $1, build a string from all args and add that to the command string for the docker exec statement
2021-09-10 13:44:37 -04:00
William Wernert
0b42b19763
Update so-rule-update to source so-common
2021-09-10 13:41:58 -04:00
William Wernert
943bd3e902
Merge pull request #5468 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Add `--force` flag to idstools-rulecat under so-rule-update
2021-09-10 13:17:16 -04:00
Mike Reeves
4af6a901a1
Merge pull request #5461 from Security-Onion-Solutions/truclusterrator
...
Add new hunt fields
2021-09-10 13:17:01 -04:00
William Wernert
9c310de459
Add --force flag to idstools-rulecat under so-rule-update
...
This forces idstools to pull from the url each time, which prevents it from clearing all.rules if idstools-rulecat is run twice within 15 minutes by any method (either restarting the container or running so-rule-update)
2021-09-10 13:15:09 -04:00
Mike Reeves
4f6a3269cb
Add more detail to syscollector
2021-09-10 09:59:47 -04:00
Doug Burks
6a2e1df7d4
Merge pull request #5460 from Security-Onion-Solutions/feature/welcome-link-docs
...
FEATURE: Add docs link to Setup #5459
2021-09-10 07:27:48 -04:00
doug
db50ef71b4
FEATURE: Add docs link to Setup #5459
2021-09-10 06:19:16 -04:00
Jason Ertel
4e2d5018a2
Merge pull request #5455 from Security-Onion-Solutions/kilo
...
Consolidate whiptail screens
2021-09-09 14:57:28 -04:00
Jason Ertel
94688a9adb
Eliminate adv component popup
2021-09-09 14:29:09 -04:00
Jason Ertel
63f67b3500
Rephrase screen that warns about more RAM requirements
2021-09-09 14:16:05 -04:00
Mike Reeves
eaa5e41651
Merge pull request #5450 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Raid Status for cloud
2021-09-09 11:09:49 -04:00
Mike Reeves
c83f119cc0
Update so-raid-status
2021-09-09 10:59:35 -04:00
Mike Reeves
5d235e932c
Fix Raid Status for cloud
2021-09-09 10:46:28 -04:00
m0duspwnens
93f2cd75a4
add the jinja template
2021-09-09 10:19:46 -04:00
m0duspwnens
f06ab8b77d
testing defaults.yaml
2021-09-09 08:55:36 -04:00
weslambert
03b45512fa
Merge pull request #5436 from Security-Onion-Solutions/fix/kibana_server_url
...
Incude server.publicBaseUrl
2021-09-08 12:13:48 -04:00
weslambert
b8600be0f1
Incude server.publicBaseUrl
2021-09-08 12:12:09 -04:00
Jason Ertel
19a02baa7c
Merge pull request #5425 from Security-Onion-Solutions/kilo
...
Auth enhancements
2021-09-07 13:10:36 -04:00
Jason Ertel
3c59579f99
Add maintenance privilege for analysts to refresh indices
2021-09-07 13:03:30 -04:00
Mike Reeves
3f989590ad
Merge pull request #5402 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Enable index sorting by default but allow it to be disabled
2021-09-07 11:28:40 -04:00
Jason Ertel
72cff7ec7a
Merge branch 'dev' into kilo
2021-09-07 10:49:08 -04:00
Mike Reeves
e3900606dc
Enable index sorting by default but allow it to be disabled
2021-09-04 10:42:18 -04:00
Mike Reeves
a2fd8ae200
Merge pull request #5401 from rwaight/dev
...
Enable index sorting in `so-common-template.json`
2021-09-04 10:32:57 -04:00
Rob Waight
b7591093cf
Add index sorting to so-common-template.json
...
Add index sorting to so-common-template.json
2021-09-04 09:45:03 -04:00
Rob Waight
51439cd1ab
Merge pull request #1 from Security-Onion-Solutions/dev
...
sync with SO/Dev
2021-09-04 09:43:23 -04:00
Jason Ertel
94ea1f856b
Add auditor role; update analyst role with correct syntax
2021-09-03 15:59:48 -04:00
Jason Ertel
fbbb7f4e85
Add auditor role; update analyst role with correct syntax
2021-09-03 15:54:05 -04:00
Mike Reeves
7b3a0cd1e4
Merge pull request #5394 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Add maxfiles to the steno config
2021-09-03 10:49:59 -04:00
Mike Reeves
9fb28709d5
Add maxfiles to the steno config
2021-09-03 10:47:00 -04:00
Jason Ertel
649f339934
Correct typo
2021-09-02 20:30:48 -04:00
Jason Ertel
f659079542
Consolidate password validation messaging
2021-09-02 19:12:32 -04:00
Jason Ertel
ce70380f0f
resolve so-user errors from recent auth changes
2021-09-02 17:59:33 -04:00
Jason Ertel
c4d402d8b4
Ensure role file exists before ES state is run
2021-09-02 15:45:47 -04:00
Mike Reeves
9f5dafd560
More Event Fields
2021-09-02 13:48:18 -04:00
Mike Reeves
1cee603ee4
Squid event fields
2021-09-02 13:24:04 -04:00
William Wernert
a14854d56d
Merge pull request #5383 from Security-Onion-Solutions/feature/soup-y
...
Add logic to check unattended flag when checking OS updates
2021-09-02 11:50:45 -04:00
Mike Reeves
2bf471054b
Cloudtrail Event Fields
2021-09-02 11:46:18 -04:00
William Wernert
56894b9581
Add logic to check unattended flag when checking if updates are available
2021-09-02 11:15:32 -04:00
Jason Ertel
10126bb7ef
Auth enhancements
2021-09-02 09:44:57 -04:00
Jason Ertel
6dfc943e8c
Merge pull request #5382 from Security-Onion-Solutions/kilo
...
Correct invalid password message
2021-09-02 07:15:09 -04:00
Jason Ertel
84ecc3cba7
Merge branch 'dev' into kilo
2021-09-02 07:09:36 -04:00
Jason Ertel
0ad3d826eb
Invalid password message should also mention that dollar signs are not allowed
2021-09-02 07:07:36 -04:00
William Wernert
d785dafe2f
Merge pull request #5374 from Security-Onion-Solutions/feature/soup-y
...
Add unattended soup flag, and iso location argument for air gap
2021-09-01 16:48:55 -04:00
Mike Reeves
e3dffcc2cb
Merge pull request #5373 from Security-Onion-Solutions/truclusterrator
...
Add eventfields for new default logs
2021-09-01 16:48:51 -04:00
Mike Reeves
556bad6925
Add eventfields for new default logs
2021-09-01 15:13:43 -04:00
William Wernert
446821e9fd
Use exit code 0 when printing error message before exiting soup
2021-09-01 15:11:18 -04:00
William Wernert
576c893eb3
Exit on missing file argument
2021-09-01 15:08:53 -04:00
Mike Reeves
34a5d6e56a
Merge pull request #5367 from Security-Onion-Solutions/truclusterrator
...
Allow closing of fb module indices in global
2021-09-01 10:54:02 -04:00
Mike Reeves
324e6b12e2
Add jinja template
2021-09-01 09:32:32 -04:00
Mike Reeves
007b15979a
Non Cluster honor closed indices values
2021-09-01 09:25:14 -04:00
Mike Reeves
c168703e9f
Merge pull request #5362 from Security-Onion-Solutions/truclusterrator
...
True Cluster Curator Overhaul
2021-08-31 17:17:47 -04:00
Mike Reeves
527a793e94
Only enable curator on Manager in true cluster
2021-08-31 16:59:41 -04:00
Mike Reeves
61ebedc0e9
Only enable curator on Manager in true cluster
2021-08-31 16:56:08 -04:00
Mike Reeves
e09aa4e5d4
Only enable curator on Manager in true cluster
2021-08-31 16:35:19 -04:00
Mike Reeves
e7b04b862f
Only enable curator on Manager in true cluster
2021-08-31 16:21:48 -04:00
Mike Reeves
62edfd0b7f
Only enable curator on Manager in true cluster
2021-08-31 16:20:42 -04:00
Mike Reeves
958575c22a
Only enable curator on Manager in true cluster
2021-08-31 16:17:55 -04:00
Mike Reeves
0c8e11dc9f
Only enable curator on Manager in true cluster
2021-08-31 16:13:05 -04:00
Mike Reeves
5b9ef3bc0d
Only enable curator on Manager in true cluster
2021-08-31 15:55:44 -04:00
Mike Reeves
c12f380bc3
Only enable curator on Manager in true cluster
2021-08-31 15:51:34 -04:00
Mike Reeves
dc25ed2594
Add logic for cronjobs
2021-08-31 15:43:48 -04:00
Mike Reeves
9f51f02ab4
Add logic for cronjobs
2021-08-31 15:40:09 -04:00
Mike Reeves
f6f4375e13
Add logic for cronjobs
2021-08-31 15:34:26 -04:00
Mike Reeves
ed116cf850
Add Actions for warm indices
2021-08-31 15:09:26 -04:00
Mike Reeves
476ecccbc1
Add Actions for warm indices
2021-08-31 15:08:10 -04:00
Mike Reeves
c09cebbd6b
Add Actions for close and delete in cluster mode
2021-08-31 13:42:11 -04:00
Mike Reeves
0ed92fd9bd
Merge pull request #5359 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 Wazuh hotfix into dev
2021-08-31 13:39:21 -04:00
Jason Ertel
c3454c9e8a
Merge branch 'master' into kilo
2021-08-31 13:37:46 -04:00
Mike Reeves
3425a0fe78
Delete Curators for all modules
2021-08-31 11:12:21 -04:00
Mike Reeves
9605eda559
Close Curators for all modules
2021-08-31 10:49:39 -04:00
Mike Reeves
ff09d9ca58
Merge pull request #5355 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERIFY_ISO.md
2021-08-31 10:06:12 -04:00
Mike Reeves
77b82bf2c0
Update VERIFY_ISO.md
2021-08-31 10:01:32 -04:00
Mike Reeves
ccc8f9ff0a
Merge pull request #5353 from Security-Onion-Solutions/hotfix/2.3.70
2021-08-31 09:57:05 -04:00
Mike Reeves
43d20226a8
Merge pull request #5352 from Security-Onion-Solutions/wazhf
...
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:47:14 -04:00
Mike Reeves
4fe0a1d7b4
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:39:37 -04:00
Mike Reeves
7a48a94624
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-31 08:22:55 -04:00
Mike Reeves
1aacc27cd4
Merge pull request #5340 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-08-30 17:48:53 -04:00
Mike Reeves
92858cd13a
Update HOTFIX
2021-08-30 17:38:29 -04:00
Mike Reeves
99cb38362a
Merge pull request #5339 from Security-Onion-Solutions/hotfix/wazuh-update-exclude
...
wazuh-agent fix + pull in master
2021-08-30 17:37:47 -04:00
William Wernert
bfd632e20a
Add wazuh to exclude arg when running yum update
2021-08-30 14:21:13 -04:00
Mike Reeves
518f9fceb0
Merge pull request #5337 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2021-08-30 12:33:43 -04:00
Mike Reeves
2b34da0fee
Update HOTFIX
2021-08-30 12:32:44 -04:00
William Wernert
72859adb13
Fix typo in so-checkin
2021-08-27 15:23:01 -04:00
Mike Reeves
a27263435a
Add Templates for all filebeat modules
2021-08-27 14:41:04 -04:00
Mike Reeves
f8cdf5bca3
Add Templates for all filebeat modules
2021-08-27 14:39:02 -04:00
William Wernert
ca5339341f
Fix batch size regex to disallow 0
2021-08-27 11:34:28 -04:00
William Wernert
c5d120293d
Initial work to add unattended option to soup
2021-08-27 11:33:51 -04:00
Jason Ertel
12b5c0899b
merge
2021-08-27 08:20:23 -04:00
Jason Ertel
09d5097837
Remove unused automation files
2021-08-25 21:08:49 -04:00
Jason Ertel
de5f823abf
Add automation for deploy-vader env
2021-08-25 18:28:17 -04:00
Josh Brower
7b93f355e2
so-import-evtx - timestamp extraction
2021-08-25 15:17:19 -04:00
m0duspwnens
a27569f20b
remove source when contents provided
2021-08-25 12:32:17 -04:00
m0duspwnens
fd1e632386
cleanup yaml
2021-08-25 12:08:43 -04:00
m0duspwnens
0681d29bb0
starting es pillarization
2021-08-25 10:23:06 -04:00
Josh Brower
ef650c6ee6
Merge pull request #5235 from Security-Onion-Solutions/feature/so-playbook-import
...
Initial version so-playbook-import
2021-08-24 10:40:07 -04:00
Mike Reeves
24f36bb4c9
Merge pull request #5284 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 GRAFANA hotfix to dev
2021-08-24 10:27:09 -04:00
m0duspwnens
9783d13ea3
remove identifier from HOTFIX file
2021-08-24 10:22:01 -04:00
m0duspwnens
427ec98ce5
fix merge conflict in HOTFIX file
2021-08-24 10:20:42 -04:00
Josh Patterson
72ba29fb7b
Merge pull request #5282 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-24 10:15:33 -04:00
Josh Patterson
2859bff0e4
Merge pull request #5281 from Security-Onion-Solutions/grafana_fleet_hotfix
...
sig files and iso info
2021-08-24 10:01:10 -04:00
Mike Reeves
6e921415ea
sig files and iso info
2021-08-24 10:00:06 -04:00
Mike Reeves
2f8b68e67a
sig files and iso info
2021-08-24 09:58:28 -04:00
Mike Reeves
e762491039
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-24 09:50:41 -04:00
Mike Reeves
11381e304b
Merge pull request #5273 from Security-Onion-Solutions/kilo
...
Switch to new Curator auth params
2021-08-24 08:29:47 -04:00
Jason Ertel
6d49bca0ac
Switch to new auth params
2021-08-23 15:36:11 -04:00
Josh Patterson
8ea89932ae
Merge pull request #5270 from Security-Onion-Solutions/grafana_fleet_hotfix
...
Grafana fleet hotfix
2021-08-23 13:10:35 -04:00
m0duspwnens
f87cf123b0
fix typo - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:08:11 -04:00
m0duspwnens
80f4d03254
place unique identifier on same line for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:05:28 -04:00
m0duspwnens
a9cc68f89e
add unique identifier for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:02:49 -04:00
m0duspwnens
b053f29a89
only create dashboards for certain node types - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 12:58:52 -04:00
Mike Reeves
19cfce5e0b
Add curator delete yml files
2021-08-23 10:47:41 -04:00
Mike Reeves
c4a32ca631
Merge pull request #5259 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 CURATOR Hotfix to Dev
2021-08-23 09:37:50 -04:00
Jason Ertel
b78da5c237
Merge hotfix to dev; reset to .80
2021-08-23 09:36:20 -04:00
Mike Reeves
0abf7593ed
Merge pull request #5233 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-23 09:28:07 -04:00
Josh Brower
aa420b914b
Initial version so-playbook-import
2021-08-20 16:27:09 -04:00
Mike Reeves
f096b513b7
Merge pull request #5232 from Security-Onion-Solutions/cfixhfix
...
Cfixhfix
2021-08-20 15:40:44 -04:00
Mike Reeves
51b517581a
2.3.70 sigs
2021-08-20 15:38:56 -04:00
Mike Reeves
936c998ecb
CURATOR ISO info
2021-08-20 12:49:55 -04:00
Mike Reeves
02372d130a
Merge pull request #5224 from Security-Onion-Solutions/curator_cron
...
remove the curator cronjobs if it is disabled
2021-08-20 10:44:55 -04:00
m0duspwnens
6f9a263af3
remove the curator cronjobs if it is disabled
2021-08-20 10:40:15 -04:00
Mike Reeves
43ffaab82c
Merge pull request #5213 from Security-Onion-Solutions/hotfix/curator
...
stop curator and remove from so-status for manager
2021-08-19 15:45:17 -04:00
m0duspwnens
dccfdb14e4
stop curator and remove from so-status for manager
2021-08-19 15:40:17 -04:00
Josh Patterson
21f3b3d985
Merge pull request #5212 from Security-Onion-Solutions/hotfix/curator
...
just dont run curator on manager
2021-08-19 15:27:55 -04:00
m0duspwnens
e2d74b115f
just dont run curator on manager
2021-08-19 15:26:22 -04:00
Mike Reeves
13741400f1
Merge pull request #5210 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2021-08-19 15:02:52 -04:00
Mike Reeves
d0f587858c
Merge pull request #5211 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Curator
2021-08-19 15:02:28 -04:00
Mike Reeves
acca8cc5d2
Update HOTFIX
2021-08-19 15:01:21 -04:00
Mike Reeves
ef950955bd
Update VERSION
2021-08-19 15:00:51 -04:00
Josh Patterson
9a8ccef828
Merge pull request #5209 from Security-Onion-Solutions/issue/5195
...
fix error in telegraf log
2021-08-19 13:27:08 -04:00
m0duspwnens
7b8e23fadd
fix error in telegraf log - https://github.com/Security-Onion-Solutions/securityonion/issues/5195
2021-08-19 11:11:24 -04:00
Mike Reeves
18335afa7f
Merge pull request #5204 from Security-Onion-Solutions/kilo
...
Update 2.3.80
2021-08-19 08:55:44 -04:00
Jason Ertel
41e8be87b6
Update 2.3.80
2021-08-19 08:42:29 -04:00
Doug Burks
39f32a6e13
Merge pull request #5185 from Security-Onion-Solutions/dev
...
2.3.70
2021-08-19 06:22:57 -04:00
Mike Reeves
8e9f95652d
Merge pull request #5188 from Security-Onion-Solutions/2.3.70
...
2.3.70 sigs
2021-08-18 09:37:51 -04:00
Mike Reeves
30489e4117
2.3.70 sigs
2021-08-18 09:35:48 -04:00
Mike Reeves
9dc9f10003
Merge pull request #5174 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-functions
2021-08-17 10:46:17 -04:00
Mike Reeves
1ced05c1d2
Update so-functions
2021-08-17 10:44:44 -04:00
Mike Reeves
41b246b8b3
Merge pull request #5169 from Security-Onion-Solutions/agrepo
...
Fix repo creation in airgap
2021-08-16 13:08:21 -04:00
Mike Reeves
a12f19c533
Fix repo creation in airgap
2021-08-16 13:00:52 -04:00
Josh Patterson
f1c91555ae
Merge pull request #5166 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-16 09:08:27 -04:00
Jason Ertel
e39de8c7bc
Merge pull request #5089 from Ron89/feature/thehive-userupdate
...
add user password update command
2021-08-15 09:36:35 -04:00
Mike Reeves
d0e312ec42
Merge pull request #5149 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 18:42:34 -04:00
Mike Reeves
e492833453
Grid Fixes
2021-08-13 18:32:55 -04:00
Mike Reeves
9beacacd44
Grid Fixes
2021-08-13 18:26:17 -04:00
Mike Reeves
aad14b2461
Grid Fixes
2021-08-13 18:22:02 -04:00
m0duspwnens
4955b552df
remove -
2021-08-13 17:42:37 -04:00
Mike Reeves
55e8a777d4
Merge pull request #5147 from Security-Onion-Solutions/issue/4674
...
keep the list unique
2021-08-13 17:39:54 -04:00
m0duspwnens
a98ed282c0
keep the list unique
2021-08-13 17:38:45 -04:00
Mike Reeves
7504b1cb2e
Merge pull request #5146 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 16:25:31 -04:00
m0duspwnens
afab1cb1e6
Merge remote-tracking branch 'remotes/origin/dev' into issue/2806
2021-08-13 16:19:57 -04:00
m0duspwnens
cd0b9bbe4a
dont always add curator to so-status
2021-08-13 16:19:41 -04:00
Mike Reeves
3ea29e77a9
Merge pull request #5145 from Security-Onion-Solutions/bugfix/so-logscan-soup-pull
...
Remove so-logscan from so-image-common arrays
2021-08-13 13:59:10 -04:00
William Wernert
fb4c2c35e3
Remove so-logscan from so-image-common arrays
2021-08-13 13:58:08 -04:00
HE Chong
81ccce8659
negative case where username doesn't exist now report exception as expected
2021-08-13 23:00:11 +08:00
HE Chong
0d5e3771f5
modify user password update script for theHive, keep it in consistency with Fleet counterpart.
2021-08-13 21:52:19 +08:00
HE Chong
2030ef65f1
add user password update script for Fleet
2021-08-13 21:50:24 +08:00
HE Chong
b6c361f83d
add user password update script for The Hive
2021-08-13 20:54:35 +08:00
Mike Reeves
9404cb635d
Grid Fixes
2021-08-13 08:48:47 -04:00
William Wernert
da53b39c15
Merge pull request #5142 from Security-Onion-Solutions/foxtrot
...
Add image pull script to allow so-learn to pull missing images, update wording on several whiptail prompts
2021-08-12 16:09:55 -04:00
William Wernert
86569b0599
Make sbin script permissions consistent
2021-08-12 16:05:54 -04:00
William Wernert
45aa2f72cb
Merge branch 'dev' into foxtrot
2021-08-12 15:45:12 -04:00
Mike Reeves
06b7434ca2
Merge pull request #5141 from Security-Onion-Solutions/kilo
2021-08-12 15:05:14 -04:00
Jason Ertel
258cebda6e
Correct identity update payload to not have unsupported fields
2021-08-12 15:01:45 -04:00
Jason Ertel
0cca43c4bd
Merge branch 'dev' into kilo
2021-08-12 15:01:12 -04:00
William Wernert
bf40a1038e
Whiptail changes
...
* Update wording of ip mask prompt + so-allow question for clarity
* Remove old ip+mask prompts
2021-08-12 10:32:27 -04:00
William Wernert
3312a66e75
Fix indent
2021-08-11 16:37:22 -04:00
William Wernert
4a31d6b3bc
Specify images are also verified
2021-08-11 16:35:33 -04:00
William Wernert
64dfc6e191
Fix pull logic and properly hide output
2021-08-11 16:33:45 -04:00
William Wernert
95bd7f9861
Merge branch 'dev' into foxtrot
2021-08-11 13:47:38 -04:00
William Wernert
983549711c
Pull image if missing when enabling module in so-learn
2021-08-11 13:47:31 -04:00
Josh Patterson
5922dbdf22
Merge pull request #5120 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-08-10 12:29:51 -04:00
m0duspwnens
9e48a5b57b
fix the pillar.get
2021-08-10 10:29:29 -04:00
m0duspwnens
3c1114403e
fix the pillar.get
2021-08-10 10:25:05 -04:00
m0duspwnens
8d2f614af6
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-08-10 10:16:30 -04:00
m0duspwnens
1415de858c
delete old dashboard folders via api - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-10 10:16:14 -04:00
Josh Patterson
59e9fddf18
Merge pull request #5109 from Security-Onion-Solutions/issue/4674
...
remove old dashboard dirs
2021-08-09 13:37:45 -04:00
m0duspwnens
ad3b6cf629
remove old dashboard dirs - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-09 13:34:02 -04:00
William Wernert
b12e2eded5
Merge pull request #5086 from Security-Onion-Solutions/foxtrot
...
Add conditional check for logscan log + add log folder to logrotate config
2021-08-06 11:32:23 -04:00
William Wernert
26030d83eb
Merge branch 'dev' into foxtrot
2021-08-06 09:44:10 -04:00
William Wernert
3b01f6431e
Add logscan to logrotate config
2021-08-06 09:43:58 -04:00
Jason Ertel
a646867593
Merge branch 'dev' into kilo
2021-08-06 09:14:45 -04:00
Josh Patterson
768e61e11a
Merge pull request #5080 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-05 12:02:42 -04:00
m0duspwnens
e72ad9eb5a
allow curator
2021-08-05 11:54:49 -04:00
m0duspwnens
ac4faf673d
add so-manager to curator.yml
2021-08-05 11:11:59 -04:00
William Wernert
dd1769fbef
Only check for logscan on manager-type and import
2021-08-05 11:02:09 -04:00
m0duspwnens
853a986082
add reqs to docker add manager to so-curator-closed-delete-delte
2021-08-05 10:36:18 -04:00
m0duspwnens
727a3742f5
run only on manager if truecluster enabled
2021-08-05 09:50:51 -04:00
Doug Burks
478a0b6a3f
Merge pull request #5075 from Security-Onion-Solutions/fix/typo
...
fix typo
2021-08-05 07:43:46 -04:00
Doug Burks
771688a70f
fix typo
2021-08-05 07:34:07 -04:00
Josh Patterson
40fa549353
Merge pull request #5066 from Security-Onion-Solutions/issue/2806
...
dont run curator on searchnode if truecluster is enabled
2021-08-04 15:01:11 -04:00
Jason Ertel
84fdc1e690
Merge pull request #5057 from Security-Onion-Solutions/bravo
...
Several Suricata things
2021-08-04 12:26:11 -04:00
Mike Reeves
71bbb41b5f
Merge branch 'dev' into bravo
2021-08-04 10:57:10 -04:00
m0duspwnens
52cb72ba67
dont run curator on searchnode if truecluster is enabled - https://github.com/Security-Onion-Solutions/securityonion/issues/2806
2021-08-04 09:40:34 -04:00
William Wernert
54a3b754e0
Merge pull request #5050 from Security-Onion-Solutions/foxtrot
...
Add logscan state, related pipeline config, and initial so-learn script
2021-08-03 16:30:07 -04:00
William Wernert
2bc88e7750
Remove learn from allowed states for helixsensor
2021-08-03 15:29:37 -04:00
William Wernert
ef59cb47dd
Use print_err function
2021-08-03 15:26:57 -04:00
William Wernert
9e5d3aa286
Fix removed root check in so-rule
2021-08-03 15:25:53 -04:00
William Wernert
25bf25eae6
Allowed states remove typo'd logscan
2021-08-03 15:24:32 -04:00
William Wernert
24f5fa66f3
Merge branch 'dev' into foxtrot
2021-08-03 13:02:29 -04:00
Mike Reeves
1aeb2d7d4f
Merge pull request #5040 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-03 10:59:28 -04:00
Jason Ertel
ee176f5bfd
Condense cloud automations
2021-08-03 07:40:50 -04:00
Jason Ertel
eb093b8e6c
Condense cloud automations
2021-08-02 21:52:42 -04:00
Jason Ertel
f88fa6e3b2
Condense cloud automations
2021-08-02 21:51:26 -04:00
Jason Ertel
724f7d4f3d
Merge pull request #5036 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-02 18:04:05 -04:00
Jason Ertel
19816d8814
Condense cloud automations
2021-08-02 17:55:27 -04:00
William Wernert
d3b170c6df
Add logscan automation file + fix enable command in setup
2021-08-02 12:37:37 -04:00
William Wernert
757091beeb
Add log_level to logscan.conf
2021-08-02 10:35:39 -04:00
William Wernert
8a49039b85
Only append source.ip to logscan.source.ips if it's been created
2021-08-02 09:50:49 -04:00
William Wernert
4f39cd1d7f
Add logscan dynamic object to so-common template mappings
2021-07-30 16:02:02 -04:00
William Wernert
2a6277c0c3
Fix field names in logscan pipeline
2021-07-30 15:46:39 -04:00
William Wernert
33bd6aed20
Fix logscan pipeline on eval
...
* Rename logscan pipeline to logscan.alert
* Add module to indices array in filebeat.yml
2021-07-30 14:41:15 -04:00
William Wernert
b9980c9d30
Fix pipeline name
2021-07-30 13:09:09 -04:00
William Wernert
01bb94514c
Correct mod_so_status to only act on single string
2021-07-30 11:05:48 -04:00
William Wernert
d71967ea1d
Fix incorrect writing of so-status.conf
2021-07-30 10:28:39 -04:00
William Wernert
0b06d0bfdb
Merge branch 'dev' into foxtrot
2021-07-29 15:15:25 -04:00
William Wernert
b2a83018ba
Remove or run logscan based on enabled bool
2021-07-29 15:14:54 -04:00
William Wernert
ba265d94f4
Change default value in learn init to a dict where approriate
2021-07-29 15:14:28 -04:00
Mike Reeves
af7b314cfe
Merge pull request #4993 from Security-Onion-Solutions/kilo
...
Merge 2.3.61 MSEARCH Hotfix into dev
2021-07-29 15:02:51 -04:00
Jason Ertel
4c6447a3da
merge 2.3.61 MSEARCH hotfix into dev
2021-07-29 15:00:58 -04:00
William Wernert
b30f771fa2
Set write_needed flag correctly, include newline in so-status.conf string
2021-07-29 14:59:26 -04:00
Mike Reeves
837c0402a0
Merge pull request #4989 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-29 14:58:25 -04:00
William Wernert
e38219aa2e
Fix learn init.sls typo
2021-07-29 14:35:02 -04:00
William Wernert
9e92f6da3d
Add container to so-status when enabling/disabling ml module
2021-07-29 14:25:20 -04:00
William Wernert
44551ea9ee
Fix so-learn list
2021-07-29 13:31:48 -04:00
William Wernert
c53da9b1ff
Fix wrong variables in learn init.sls
2021-07-29 12:04:40 -04:00
William Wernert
e1785dbd9a
Fix typo
2021-07-29 12:00:53 -04:00
William Wernert
2560a9b78c
[wip] Change learn:modules to dictionary
2021-07-29 11:58:58 -04:00
William Wernert
d53e989c55
Add ability to set cpu_period per module
2021-07-29 11:52:10 -04:00
William Wernert
211a841cdb
Fix file path in bind mount for logscan
2021-07-29 11:40:19 -04:00
Josh Patterson
50e4365475
Merge pull request #4990 from Security-Onion-Solutions/issue/4985
...
Issue/4985
2021-07-29 11:14:54 -04:00
Jason Ertel
c524b54af1
Merge pull request #4988 from Security-Onion-Solutions/mkr2361
...
2.3.61-MSEARCH
2021-07-29 11:10:41 -04:00
Mike Reeves
7591bb115e
2.3.61-MSEARCH
2021-07-29 11:09:54 -04:00
Mike Reeves
3d2da303c8
2.3.61-MSEARCH
2021-07-29 11:09:27 -04:00
Mike Reeves
f585eb6e62
2.3.61-MSEARCH
2021-07-29 11:08:03 -04:00
m0duspwnens
4b6120a46b
fix the hours get
2021-07-29 10:59:33 -04:00
Mike Reeves
d946c6d5ed
Merge pull request #4987 from Security-Onion-Solutions/kilo
...
Do not prompt about uppercased hostname during testing
2021-07-29 10:57:56 -04:00
William Wernert
5894b85bd1
Remove broken yaml dump arg, rename metavars
2021-07-29 10:57:53 -04:00
m0duspwnens
3fc43f7d92
allow for adjustment to auto patch os schedule - https://github.com/Security-Onion-Solutions/securityonion/issues/4985
2021-07-29 10:48:24 -04:00
Jason Ertel
8ed264460f
Do not prompt about uppercased hostname during testing
2021-07-29 10:45:35 -04:00
William Wernert
811b32735e
Merge branch 'dev' into foxtrot
2021-07-29 09:52:29 -04:00
Mike Reeves
4b3db0c4d2
Merge pull request #4972 from Security-Onion-Solutions/mkr2361
...
Fix Manager Search
2021-07-28 17:08:40 -04:00
Mike Reeves
281ba21298
Merge pull request #4956 from Security-Onion-Solutions/kilo
...
Merge master to dev
2021-07-28 17:07:58 -04:00
Mike Reeves
d4a177949a
Fix Manager Search
2021-07-28 17:05:16 -04:00
Mike Reeves
a42d8c9229
Fix Manager Search
2021-07-28 17:03:14 -04:00
William Wernert
dd0e407935
Use correct container name
2021-07-28 15:06:38 -04:00
William Wernert
7ef5b39b04
[wip] Fix 'Nonetype' object is not callable error
2021-07-28 14:28:00 -04:00
William Wernert
cf9121dfc2
Actually download so-learn container
2021-07-28 14:13:16 -04:00
Josh Patterson
fcfc2a65a9
Merge pull request #4968 from Security-Onion-Solutions/issue/3933
...
allow for sampleSize adjustment in kibana
2021-07-28 11:13:49 -04:00
William Wernert
91accb0bc6
[wip] Fixing so-learn script
2021-07-28 10:12:32 -04:00
William Wernert
e2abe8840f
Fix directory in logscan state
2021-07-28 10:12:19 -04:00
m0duspwnens
ead9ae8cb5
fix merge and defaults passed
2021-07-28 09:58:38 -04:00
William Wernert
455719936b
Uncomment required lines in so-learn
2021-07-28 09:53:35 -04:00
William Wernert
8d56fc71fa
Fix jinja length calculation
2021-07-28 09:53:24 -04:00
William Wernert
833d154bf4
Merge branch 'dev' into foxtrot
2021-07-28 09:50:11 -04:00
William Wernert
f31dc5abc7
Add learn to allowed states
2021-07-28 09:49:59 -04:00
m0duspwnens
9a429230fe
wrap with raw due to {{value}}
2021-07-28 09:39:35 -04:00
m0duspwnens
b36d46b7f2
change to jinja tem,plate
2021-07-28 09:27:44 -04:00
m0duspwnens
fee89665fd
dict not list for defaults
2021-07-28 09:18:15 -04:00
m0duspwnens
d78a37f9e3
allow for control of kibana discover sampleSize - https://github.com/Security-Onion-Solutions/securityonion/issues/3933
2021-07-28 09:12:31 -04:00
Jason Ertel
28c5c02ef1
Merge pull request #4958 from Security-Onion-Solutions/issue/4024
...
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:21:13 -04:00
m0duspwnens
8ffeae38bc
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:16:48 -04:00
William Wernert
f4fae7938e
Merge branch 'dev' into foxtrot
2021-07-27 16:01:44 -04:00
Jason Ertel
22920bc9a1
clear out hotfix from merge
2021-07-27 14:42:11 -04:00
Jason Ertel
ceb82cb863
Merge branch 'master' into kilo
2021-07-27 14:40:31 -04:00
Mike Reeves
1caa361e22
Merge pull request #4955 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-27 14:33:31 -04:00
Mike Reeves
da20790238
Merge pull request #4954 from Security-Onion-Solutions/mkr2361
...
Steno ISO Details
2021-07-27 11:11:22 -04:00
Mike Reeves
f359dd0cd4
Steno ISO Details
2021-07-27 11:09:25 -04:00
Josh Patterson
bee442a21f
Merge pull request #4950 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-07-27 10:28:02 -04:00
m0duspwnens
a66765e99b
remove old dashboards, set default refresh to 5m
2021-07-27 10:23:35 -04:00
m0duspwnens
0db7f91eb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-27 08:53:31 -04:00
m0duspwnens
850315dc20
remove role conditional from all panel queiries
2021-07-27 08:47:44 -04:00
Mike Reeves
d35e4bea01
Merge pull request #4932 from Security-Onion-Solutions/issue/4922
...
Issue/4922
2021-07-26 16:18:22 -04:00
Jason Ertel
356b623148
Merge pull request #4937 from Security-Onion-Solutions/kilo
...
Add Azure automations
2021-07-26 16:13:57 -04:00
Jason Ertel
3a022e7a83
Add Azure automations
2021-07-26 15:50:15 -04:00
William Wernert
64945cec16
[wip] Initial work to enable/disable "learn" modules
2021-07-26 14:24:10 -04:00
Jason Ertel
26741bdb53
Add wss: to CSP for browsers that enforce wss distinctly from other protocols
2021-07-26 10:55:30 -04:00
m0duspwnens
7aa5e857ed
update hotfix file
2021-07-26 10:46:52 -04:00
m0duspwnens
2e277bf487
change container to abesent of pcap is disabled
2021-07-26 10:08:59 -04:00
m0duspwnens
e4f46c6e14
hide role template var from all dash except overview
2021-07-26 09:36:05 -04:00
m0duspwnens
e9d90644fd
fix query and allow for setting text and value of servername template var
2021-07-23 16:52:07 -04:00
m0duspwnens
5a06f0dce9
role template var now selects default role
2021-07-23 16:34:58 -04:00
m0duspwnens
08e9a58f2e
simply to one servername.json
2021-07-23 16:09:25 -04:00
m0duspwnens
e1f0c8e87c
add "list" bast to tempating defs for overview
2021-07-23 15:43:31 -04:00
m0duspwnens
17a532f7b5
add new templating defs to overview
2021-07-23 15:41:03 -04:00
m0duspwnens
c7306dda12
fix servername_eval template var, test using 1 servername template var
2021-07-23 15:38:45 -04:00
m0duspwnens
00d311cd6c
fix nodetype listing
2021-07-23 14:40:44 -04:00
m0duspwnens
f8d2a7f449
fix nodetype listing
2021-07-23 13:43:35 -04:00
m0duspwnens
a02a928996
add missing ]
2021-07-23 13:33:25 -04:00
m0duspwnens
eb661b7a24
add ability to set title for dashboards, only create dashboards/dirs if that node type exists
2021-07-23 13:31:44 -04:00
m0duspwnens
6aea607f21
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-23 11:12:48 -04:00
m0duspwnens
41e747dcc1
add servername_all template var
2021-07-23 10:55:15 -04:00
m0duspwnens
d3d02faa1c
remove detailed
2021-07-23 10:52:30 -04:00
m0duspwnens
7a85a3c7f7
move dashboard location
2021-07-23 10:20:57 -04:00
m0duspwnens
fceb2851ef
add eval dashboard
2021-07-23 09:02:40 -04:00
William Wernert
2f118781ea
Merge branch 'dev' into foxtrot
2021-07-23 08:54:08 -04:00
William Wernert
b8e3a45a7e
[wip] Add logscan state
...
Do not add state to top file or setup yet, script will be written to enable the feature shortly
2021-07-23 08:53:45 -04:00
m0duspwnens
61312397e1
update container uptime panel
2021-07-23 08:25:43 -04:00
m0duspwnens
8ea4682aab
add docker container uptime to overview dash
2021-07-23 07:34:01 -04:00
m0duspwnens
3b6befdb97
adjust gridpos
2021-07-22 15:05:37 -04:00
m0duspwnens
613979ea3f
remove extra comma
2021-07-22 15:03:58 -04:00
m0duspwnens
191def686b
add packet loss panels
2021-07-22 15:02:06 -04:00
Mike Reeves
f986e0dc78
Merge pull request #4892 from Security-Onion-Solutions/kilo
...
Merge master back to dev
2021-07-22 14:37:40 -04:00
Jason Ertel
08e75567d4
merge master to kilo
2021-07-22 14:34:24 -04:00
Mike Reeves
668199f1a8
Merge pull request #4889 from Security-Onion-Solutions/2361update
...
2.3.61
2021-07-22 14:29:13 -04:00
Jason Ertel
7a753a56ec
Update README with 2.3.61
2021-07-22 13:54:04 -04:00
m0duspwnens
7b38b4e280
fix {{}}
2021-07-22 13:36:44 -04:00
m0duspwnens
7dc2e2ca73
add option to hide trend on zeek packet loss graph
2021-07-22 13:35:25 -04:00
m0duspwnens
44eb23615a
change to packet_loss
2021-07-22 13:20:19 -04:00
m0duspwnens
d47566f667
remove monitor inbound graph
2021-07-22 13:18:31 -04:00
m0duspwnens
9ae84c8108
add network and tool packetloss panels to overview
2021-07-22 13:16:39 -04:00
Mike Reeves
578c7aac35
2.3.61
2021-07-22 13:06:26 -04:00
m0duspwnens
1c460cc19c
fix traffic overview graphs
2021-07-22 10:31:47 -04:00
m0duspwnens
ff436aea93
allow multi and all for manint and monint vars
2021-07-22 10:06:31 -04:00
m0duspwnens
aa333794f7
add disk usage percent graphs
2021-07-22 09:54:17 -04:00
doug
3d3593a1a9
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-22 09:50:21 -04:00
Jason Ertel
257062e20c
Update release notes link to match top right menu for airgap
2021-07-22 09:48:34 -04:00
doug
fa9d7afb46
FIX: Airgap link to Release Notes #4685
2021-07-22 09:42:37 -04:00
m0duspwnens
ae5f351e1a
change row name
2021-07-22 09:31:17 -04:00
m0duspwnens
257a88ec8e
change row name
2021-07-22 09:30:43 -04:00
m0duspwnens
e1e6304a8a
rename
2021-07-22 09:29:37 -04:00
m0duspwnens
a81ef0017c
rename panels source, reorg overview
2021-07-22 09:15:22 -04:00
m0duspwnens
b89162e086
change id
2021-07-22 08:01:54 -04:00
m0duspwnens
a6630540a4
add system uptime graph to overview dash
2021-07-21 18:11:42 -04:00
m0duspwnens
a528c5d54b
role first var for overview
2021-07-21 17:41:53 -04:00
m0duspwnens
690699ddf7
update template vars to use regex for $servername
2021-07-21 17:17:23 -04:00
m0duspwnens
cd8d9c657e
add mgmt interface traffic graphs to overview
2021-07-21 16:24:16 -04:00
m0duspwnens
f732b80b92
add swap usage percent to overview dash
2021-07-21 15:48:04 -04:00
Jason Ertel
ad8c12afa5
Upgrade ES to 7.13.4
2021-07-21 15:07:02 -04:00
m0duspwnens
479fcb6c46
add panel for memory usage percent
2021-07-21 15:00:05 -04:00
Jason Ertel
74874dfff2
Allow web pages to load blob data
2021-07-21 14:59:33 -04:00
m0duspwnens
ceb108a5fe
set min yaxes to 0
2021-07-21 14:47:57 -04:00
m0duspwnens
235d8b7cf0
ensure role matches
2021-07-21 14:44:07 -04:00
Mike Reeves
7c9df2d75a
Update HOTFIX
2021-07-21 14:40:53 -04:00
Mike Reeves
43bf75217f
Update VERSION
2021-07-21 14:40:23 -04:00
m0duspwnens
9bf6d478c5
remove $col var
2021-07-21 14:36:08 -04:00
m0duspwnens
e2baa93270
remove role from node_config for telegraf
2021-07-21 14:32:01 -04:00
m0duspwnens
37fcda3817
add cpu row and panels to overview dashboard
2021-07-21 14:30:41 -04:00
m0duspwnens
457ae54341
role var
2021-07-21 11:50:06 -04:00
m0duspwnens
4cc3c5ada9
add role template var to overview dashboard
2021-07-21 11:35:02 -04:00
m0duspwnens
07d5736d61
change sort of legend
2021-07-21 11:33:48 -04:00
m0duspwnens
a7551a44e5
allow multi and all on servername_all template var
2021-07-21 11:29:30 -04:00
m0duspwnens
f4d3e13c7f
begin overview dashboard
2021-07-21 11:26:02 -04:00
m0duspwnens
47d82b3d35
sort desc remaining tooltips
2021-07-21 10:36:07 -04:00
m0duspwnens
9d06aff1d1
add manager dashboard
2021-07-21 10:23:39 -04:00
m0duspwnens
5ea8c978a0
add managersearch
2021-07-21 10:16:40 -04:00
m0duspwnens
6809c3a9f6
add mastersearch dashboard
2021-07-21 10:13:43 -04:00
m0duspwnens
761108964e
remove panels from searchnode dashboard
2021-07-21 10:05:43 -04:00
m0duspwnens
e3e74a84f2
test sort tooltip descending
2021-07-21 10:00:14 -04:00
m0duspwnens
1fee4e87c4
add searchnode dashboard
2021-07-21 09:51:49 -04:00
m0duspwnens
0c4c59375d
sort container uptime ascending
2021-07-21 09:11:39 -04:00
Mike Reeves
09165daab8
Several Suricata things
2021-07-21 09:10:33 -04:00
m0duspwnens
3393b77535
add sensor dashboard
2021-07-21 08:54:26 -04:00
m0duspwnens
d050bc02e2
dont show legend for docker uptime trend
2021-07-20 16:29:49 -04:00
m0duspwnens
af60ddf404
add docker container uptime graph
2021-07-20 16:28:07 -04:00
m0duspwnens
1bb92f63d1
add docker details
2021-07-20 15:21:59 -04:00
m0duspwnens
a405ca39fa
add redis.sh for telegraf on heavynodes
2021-07-20 14:31:09 -04:00
m0duspwnens
852b686d81
add servername vars for each role
2021-07-20 14:25:56 -04:00
m0duspwnens
608d5d3c26
change uid logic
2021-07-20 14:10:26 -04:00
m0duspwnens
6038ebb705
handle multile nodetpes and uid
2021-07-20 14:04:28 -04:00
m0duspwnens
4bb350d37d
add heavynode
2021-07-20 13:55:52 -04:00
m0duspwnens
d01ac55db1
add heavynode
2021-07-20 13:55:18 -04:00
Jason Ertel
fcde5c3c18
Merge pull request #4865 from Security-Onion-Solutions/kilo
...
Merge curator hotfix into dev
2021-07-20 11:47:49 -04:00
Jason Ertel
dbf19e134f
Merge branch 'master' into kilo
2021-07-20 11:44:10 -04:00
Mike Reeves
b13c5a3b8b
Merge pull request #4863 from Security-Onion-Solutions/hotfix/2.3.60
...
Hotfix/2.3.60 CuratorFix
2021-07-20 11:02:34 -04:00
m0duspwnens
b0c5a352c1
remove old panaels
2021-07-20 10:53:47 -04:00
m0duspwnens
d0b3cd5f66
add the detailed dash dir
2021-07-20 10:50:40 -04:00
m0duspwnens
24efdec9ea
cap the var
2021-07-20 10:48:46 -04:00
m0duspwnens
1bed818a8e
fix jinja
2021-07-20 10:47:10 -04:00
m0duspwnens
3c4c52567d
fix jinja
2021-07-20 10:46:41 -04:00
m0duspwnens
87ae14d11c
fix jinja
2021-07-20 10:44:32 -04:00
m0duspwnens
258d303e7f
change how dashboards are deployed
2021-07-20 10:43:00 -04:00
m0duspwnens
458350e1a8
new redis queue stat panel, change to lastnotnull
2021-07-20 09:45:28 -04:00
Mike Reeves
fe7ee1e2c7
Merge pull request #4862 from Security-Onion-Solutions/curatorfix
...
Curator Fix
2021-07-20 09:26:54 -04:00
m0duspwnens
d8910a0097
add redis queue to overview, reposition overview panels
2021-07-20 09:22:43 -04:00
Mike Reeves
3b6e683d37
Curator Fix
2021-07-20 09:21:22 -04:00
m0duspwnens
90f6bad6ce
panel title change
2021-07-20 08:54:39 -04:00
m0duspwnens
fcc6802f86
convert all singlestat to stat
2021-07-20 08:51:53 -04:00
m0duspwnens
3b9bc77ecc
remove scopedvars
2021-07-19 17:51:43 -04:00
m0duspwnens
0fb4500fcc
add legends
2021-07-19 17:39:32 -04:00
m0duspwnens
93ca00c7fe
change min y
2021-07-19 17:29:57 -04:00
m0duspwnens
522f2a3f9f
maxdatapoints and min interval
2021-07-19 17:19:56 -04:00
m0duspwnens
40ddf5f49c
fix cords
2021-07-19 16:30:02 -04:00
m0duspwnens
60356eacce
make the ids unique
2021-07-19 16:26:09 -04:00
m0duspwnens
158f3bf092
add row_stenographer
2021-07-19 16:18:02 -04:00
m0duspwnens
ebf3c65bed
add many more panels
2021-07-19 16:02:40 -04:00
William Wernert
df6d1d72e2
Merge branch 'dev' into feature/logscan
2021-07-19 15:19:59 -04:00
weslambert
72542322ca
Merge pull request #4857 from Security-Onion-Solutions/fix/beats_output_fb_modules
...
Check if Filebeat modules are being used for incoming (external) Beats
2021-07-19 13:11:06 -04:00
weslambert
fea4f3f973
Check if Filebeat modules are being used for incoming Beats
2021-07-19 12:57:42 -04:00
Mike Reeves
7878180f54
Merge pull request #4854 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2021-07-19 12:50:23 -04:00
Mike Reeves
0669aa6bbd
Update HOTFIX
2021-07-19 12:49:43 -04:00
Mike Reeves
2c4924a602
Merge pull request #4853 from Security-Onion-Solutions/fix/curator_http_auth
...
Use http_auth instead of username/password until Curator is updated to latest version
2021-07-19 12:45:29 -04:00
weslambert
bde86e0383
Use http_auth instead of username/password until Curator is upgraded to next version
2021-07-19 12:42:46 -04:00
Jason Ertel
bab18275bc
Merge pull request #4836 from Security-Onion-Solutions/fix/airgap-release-notes
...
FIX: Airgap link to Release Notes #4685
2021-07-17 11:05:33 -04:00
doug
7e86681509
FIX: Airgap link to Release Notes #4685
2021-07-16 16:50:49 -04:00
William Wernert
c2fc2df54c
Merge pull request #4835 from Security-Onion-Solutions/feature/uppercase-warning
...
Show warning to user when trying to use uppercase characters in hostname or domain name
2021-07-16 15:44:47 -04:00
William Wernert
0deb77468f
Change uppercase regex
...
Check for any uppercase characters rather than revalidating input sans uppercase
2021-07-16 15:39:09 -04:00
William Wernert
9bf1d3e0c6
Misc fixes
2021-07-16 14:59:44 -04:00
William Wernert
3a12d28d20
Merge branch 'dev' into feature/logscan
2021-07-16 14:13:19 -04:00
William Wernert
e8ba4bdc6c
Add quotes to string
2021-07-16 14:07:23 -04:00
William Wernert
b552973e00
Add logic to show uppercase warning message when appropriate
2021-07-15 16:36:46 -04:00
William Wernert
ac98e1fd0f
Remove testing default values, change wording, set default option to no
2021-07-15 16:36:24 -04:00
m0duspwnens
4246aac51b
unhide disk var
2021-07-15 13:57:43 -04:00
William Wernert
33f396bdae
Add uppercase warning function
2021-07-15 13:53:57 -04:00
William Wernert
ff25cecd54
Remove unused function
2021-07-15 13:53:31 -04:00
m0duspwnens
e88b258208
add maxDataPoints and min interval to more panels
2021-07-15 11:53:24 -04:00
m0duspwnens
1cbf895e0e
add missing ,
2021-07-15 11:27:19 -04:00
m0duspwnens
7dc1f5c445
add maxDataPoints and min interval to some panels for testing
2021-07-15 11:25:20 -04:00
m0duspwnens
439e049948
revert to $__interval
2021-07-15 10:17:21 -04:00
m0duspwnens
fbf26bef8d
test new groupby interval for trend on monitor packets
2021-07-15 08:42:53 -04:00
m0duspwnens
c1f550382c
remove interval var
2021-07-15 08:31:42 -04:00
m0duspwnens
23fb6a5c02
rename
2021-07-14 18:04:33 -04:00
m0duspwnens
d632266092
fix jinja
2021-07-14 18:01:56 -04:00
m0duspwnens
4ea3ab9538
add disk iops graphs
2021-07-14 17:58:49 -04:00
m0duspwnens
725161ea6e
fix datasource
2021-07-14 16:07:14 -04:00
m0duspwnens
fccd86f676
add disk var to standalone
2021-07-14 16:04:55 -04:00
m0duspwnens
0f0a977ed9
add disk var
2021-07-14 16:04:17 -04:00
Jason Ertel
7f9d0b59b8
Merge pull request #4808 from Security-Onion-Solutions/kilo
...
Merge hotfix from master into dev; add `so-firewall apply` feature to dev
2021-07-14 15:49:12 -04:00
m0duspwnens
b0d510167c
change title
2021-07-14 15:36:26 -04:00
m0duspwnens
4971933201
rename file
2021-07-14 15:34:39 -04:00
m0duspwnens
693a9b30ae
add swap, adjust cords
2021-07-14 15:33:28 -04:00
Jason Ertel
76c285158a
Merge branch 'master' into kilo
2021-07-14 15:24:35 -04:00
Jason Ertel
08517e3732
Merge branch 'dev' into kilo
2021-07-14 15:24:29 -04:00
m0duspwnens
59530f4263
cahnge nullPointMode
2021-07-14 14:54:48 -04:00
Mike Reeves
5d48fb41ba
Merge pull request #4800 from Security-Onion-Solutions/hotfix/2.3.60
2021-07-14 14:54:00 -04:00
m0duspwnens
4acebe7f59
replace $interval with $__interval
2021-07-14 14:47:02 -04:00
m0duspwnens
a44a7b7161
change title
2021-07-14 14:45:17 -04:00
m0duspwnens
be13f0a066
change id
2021-07-14 14:31:25 -04:00
m0duspwnens
98ce77c2b1
add disk usage graphs
2021-07-14 14:28:25 -04:00
m0duspwnens
275a491cac
cords
2021-07-14 13:44:47 -04:00
m0duspwnens
1c868f85c4
fix cords;
2021-07-14 13:25:17 -04:00
m0duspwnens
b6deacf86d
cords
2021-07-14 13:11:48 -04:00
Mike Reeves
ebe5ef6535
Merge pull request #4799 from Security-Onion-Solutions/agsoupupdate
...
Update ISO info
2021-07-14 12:07:35 -04:00
m0duspwnens
294f91473c
fix packets legend
2021-07-14 11:49:24 -04:00
m0duspwnens
902f04efb4
set 0 as min
2021-07-14 11:44:14 -04:00
m0duspwnens
ca2989c0e5
fix network cords
2021-07-14 11:42:01 -04:00
m0duspwnens
2d9697cd66
fix network cords
2021-07-14 11:40:31 -04:00
m0duspwnens
b4111a9f79
fix network cords
2021-07-14 11:38:16 -04:00
m0duspwnens
7f8212fdba
add trend, add network graphs
2021-07-14 11:31:48 -04:00
weslambert
7e1be8a3a4
Merge pull request #4798 from Security-Onion-Solutions/fix/strelka_filepath_mapping
...
Replace staging with processed in Strelka file path mapping
2021-07-14 11:16:15 -04:00
Wes Lambert
05aad07bfc
Replace staging path with processed path for analyzed files
2021-07-14 15:04:46 +00:00
Mike Reeves
92a80f9a58
Update ISO info
2021-07-14 10:30:10 -04:00
m0duspwnens
4b4ceb525a
trends for load and process status
2021-07-14 10:29:35 -04:00
weslambert
42ba9888d7
Merge pull request #4797 from Security-Onion-Solutions/fix/wazuh_data_port
...
Change field name and mapping for Wazuh's data.port
2021-07-14 10:14:53 -04:00
William Wernert
818f912a90
[fix] Remove indent
2021-07-14 10:13:14 -04:00
m0duspwnens
dae64b82ff
add trend to cpu
2021-07-14 10:09:34 -04:00
m0duspwnens
53c6edcbdb
add trends memory usage and network graphs
2021-07-14 09:57:43 -04:00
Wes Lambert
723172bc1f
Add path_unmatch for data.port so it is not mapped as integer
2021-07-14 13:45:09 +00:00
Wes Lambert
323b5d6694
Add dynamic mapping for wazuh
2021-07-14 13:43:34 +00:00
Wes Lambert
441cd3fc59
Move Wazuh-specific data to wazuh.data
2021-07-14 13:42:51 +00:00
m0duspwnens
1d23d1b2e2
start network row
2021-07-14 09:21:46 -04:00
Jason Ertel
1dd81b6d49
Merge pull request #4790 from Security-Onion-Solutions/agsoupupdate
...
Remove old airgap scripts
2021-07-13 15:45:45 -04:00
Mike Reeves
741e825ab9
Remove old airgap scripts
2021-07-13 15:44:26 -04:00
William Wernert
e41811fbd0
[fix] Typo
2021-07-13 15:14:13 -04:00
m0duspwnens
f111106a9f
fix cords
2021-07-13 14:13:19 -04:00
m0duspwnens
f9e29eaede
update memory usage graph panel
2021-07-13 14:09:23 -04:00
William Wernert
e7a6172d7e
[fix] Add single quotes to strings
2021-07-13 14:07:27 -04:00
m0duspwnens
ec8f9228e8
add memory and docker container rows
2021-07-13 14:01:42 -04:00
m0duspwnens
6c12e26632
add mem usage, add docker graphs back, update nsm usage thresh
2021-07-13 13:55:01 -04:00
m0duspwnens
9a6ac7bd20
change panels
2021-07-13 12:30:45 -04:00
m0duspwnens
5b3751da70
new load averages panel
2021-07-13 12:24:32 -04:00
m0duspwnens
65127eb226
fix servername var
2021-07-13 12:04:52 -04:00
William Wernert
115e0a6fee
[fix] Add missing comma
2021-07-13 12:04:10 -04:00
m0duspwnens
ddfab44883
new id
2021-07-13 11:59:01 -04:00
Mike Reeves
6eab390962
Merge pull request #4788 from Security-Onion-Solutions/fix/fbpipeline
...
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:40:58 -04:00
Mike Reeves
35388056d3
Merge pull request #4789 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-07-13 11:40:44 -04:00
Mike Reeves
e2c5967191
Update HOTFIX
2021-07-13 11:38:20 -04:00
weslambert
7cdb967810
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:36:18 -04:00
m0duspwnens
8900d52c33
change y
2021-07-13 11:30:14 -04:00
m0duspwnens
bab72393e6
query and id changes
2021-07-13 11:23:06 -04:00
William Wernert
e059c25ebc
[fix][wip] Fix pipeline parsing errors
2021-07-13 11:05:05 -04:00
m0duspwnens
c87ca8f5dc
spacing
2021-07-13 10:42:33 -04:00
m0duspwnens
e01e3cdd43
change file name
2021-07-13 10:25:26 -04:00
m0duspwnens
2ab9ade761
add missing gridPos
2021-07-13 10:22:48 -04:00
m0duspwnens
0b35b8f6d6
add cpu row
2021-07-13 10:19:20 -04:00
William Wernert
9ff95f66dd
Merge branch 'dev' into feature/logscan
2021-07-13 10:02:58 -04:00
William Wernert
c1523c4936
Merge pull request #4782 from Security-Onion-Solutions/feature/check-local-mods
...
Add jinja raw tag
2021-07-13 08:58:25 -04:00
m0duspwnens
b6e31278a7
move old panels into old for organization
2021-07-13 08:57:01 -04:00
William Wernert
ca2b24f735
Add jinja raw tag
2021-07-13 08:46:57 -04:00
William Wernert
2b0bca8e55
Merge branch 'dev' into feature/logscan
2021-07-12 14:58:30 -04:00
m0duspwnens
98fe7e8700
fix mean
2021-07-12 14:37:17 -04:00
m0duspwnens
0acc3cc537
rename
2021-07-12 14:32:37 -04:00
m0duspwnens
8491ffde07
add docker container network usage graphs
2021-07-12 14:18:54 -04:00
Doug Burks
2ea3989497
Merge pull request #4775 from Security-Onion-Solutions/fix/suricata-dns-response-code
...
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:40:14 -04:00
doug
e6f9592cde
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:24:21 -04:00
William Wernert
222d79bf53
Merge pull request #4774 from Security-Onion-Solutions/feature/check-local-mods
...
Compare local files to their defaults to check for potentially breaking changes
2021-07-12 12:00:18 -04:00
m0duspwnens
19d9258717
add postfix , change color
2021-07-12 11:22:48 -04:00
m0duspwnens
b46456b78e
move math, add 2 decimal spot
2021-07-12 11:16:33 -04:00
m0duspwnens
cebc2ef09d
add missing ,
2021-07-12 11:13:32 -04:00
m0duspwnens
c4ff8f6876
convert seconds to days
2021-07-12 11:12:28 -04:00
m0duspwnens
619022ef7f
2 new panels to overview
2021-07-12 11:09:23 -04:00
weslambert
c0f3c5b3db
Merge pull request #4773 from Security-Onion-Solutions/feature/filebeat-logging-level
...
Allow setting Filebeat logging level in pillar
2021-07-12 10:55:43 -04:00
m0duspwnens
860b8bf945
panel changes
2021-07-12 10:34:39 -04:00
m0duspwnens
694db81b80
fix locations and panel ids
2021-07-12 10:29:09 -04:00
weslambert
a895270bc8
Allow setting Filebeat logging level in pillar
2021-07-12 10:27:43 -04:00
m0duspwnens
7474b451ca
rename file
2021-07-12 10:24:12 -04:00
m0duspwnens
e8eecc8bc1
rename file
2021-07-12 10:22:25 -04:00
m0duspwnens
28e33b413c
add more panels for overview
2021-07-12 10:17:23 -04:00
Jason Ertel
78c58e61ea
Resolves #4765
2021-07-12 09:38:01 -04:00
William Wernert
f3ecdf21bf
Revert "Add newline to local modifications warning"
...
This reverts commit ff656365d2 .
2021-07-12 09:28:24 -04:00
William Wernert
ff656365d2
Add newline to local modifications warning
2021-07-12 09:22:22 -04:00
William Wernert
ea7c09bb00
Merge branch 'dev' into feature/check-local-mods
2021-07-12 09:20:10 -04:00
Jason Ertel
e23f7cd3e7
Merge pull request #4766 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.70
2021-07-10 13:01:54 -04:00
Jason Ertel
c6bb32b862
Bump version to 2.3.70
2021-07-10 07:34:52 -04:00
m0duspwnens
0bde69b441
update panel
2021-07-09 16:47:39 -04:00
m0duspwnens
6fbafb74bd
update panel
2021-07-09 16:45:02 -04:00
m0duspwnens
9572c1f663
fix var
2021-07-09 16:33:09 -04:00
m0duspwnens
0fedb0f2c5
add 5 minute load avg panel
2021-07-09 16:29:48 -04:00
m0duspwnens
33d3aef9f5
yamlize gridpos
2021-07-09 16:14:25 -04:00
m0duspwnens
fb8ccedf66
reduce height by 2
2021-07-09 16:04:55 -04:00
m0duspwnens
efcf0accc1
change IDs
2021-07-09 16:01:57 -04:00
m0duspwnens
f556d5c07d
change row id
2021-07-09 15:58:45 -04:00
m0duspwnens
6c1f424c0b
fix row_overview
2021-07-09 15:56:27 -04:00
William Wernert
90970f97e8
Add function to check if files copied to local have been changed in default
2021-07-09 15:44:27 -04:00
m0duspwnens
d3137dc6b9
add row panels
2021-07-09 15:43:51 -04:00
m0duspwnens
efaf53f2f7
add a panel header, change memeory usage panel
2021-07-09 15:13:50 -04:00
m0duspwnens
beb7b89275
yamlize the gridpos for panels
2021-07-09 14:13:00 -04:00
Jason Ertel
8c15fa1627
Merge pull request #4758 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.13.3; Use nginx reverse proxy for access to Playbook and Soctopus
2021-07-09 12:40:33 -04:00
m0duspwnens
bc814c9be6
new panels, add containers var, hide manint and monint var from dash
2021-07-09 11:21:06 -04:00
William Wernert
bac7ef71d8
Add logscan.source.ips field
2021-07-09 10:55:11 -04:00
m0duspwnens
dd199ea30f
remove quotes if pillar doesnt exist
2021-07-09 10:00:47 -04:00
m0duspwnens
fc8acac1a5
change id
2021-07-08 17:39:34 -04:00
m0duspwnens
fec269c3e7
add combined container mem panel
2021-07-08 17:28:18 -04:00
m0duspwnens
8e366fd633
add combined container mem panel
2021-07-08 17:27:51 -04:00
m0duspwnens
f7d54186dd
remove all panels from standalone
2021-07-08 17:11:33 -04:00
m0duspwnens
ab92fb3910
add cpucount to standalone
2021-07-08 17:08:45 -04:00
m0duspwnens
6783e2e28b
dont hide cpucount on dashboard
2021-07-08 17:06:21 -04:00
m0duspwnens
4e47d3f458
remove single quotes
2021-07-08 17:04:41 -04:00
m0duspwnens
b265c7dcb7
single quote cpucount
2021-07-08 17:00:17 -04:00
m0duspwnens
f4fae89b8e
fix copy paste error
2021-07-08 16:50:25 -04:00
m0duspwnens
45f0b4c85f
manint and monint
2021-07-08 16:43:53 -04:00
m0duspwnens
7c80483f6e
change CPUS to $cpucount
2021-07-08 16:39:14 -04:00
Jason Ertel
08ba4fdbee
Update Kibana saved objects to 7.13.3
2021-07-08 16:34:16 -04:00
m0duspwnens
7085796601
replace SERVERNAME with $servername
2021-07-08 16:33:21 -04:00
m0duspwnens
091b5f73b1
update var
2021-07-08 14:43:38 -04:00
Jason Ertel
0c079edc1a
Reverse proxy requests to playbook, soctopus, and nodered
2021-07-08 14:27:16 -04:00
m0duspwnens
54cdfb89f6
remove common_standalone.json.jinja
2021-07-08 14:14:40 -04:00
m0duspwnens
f56514ed7d
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-08 14:12:26 -04:00
m0duspwnens
56697fde19
create common dashboard and define templates/dashbaord vars
2021-07-08 14:10:22 -04:00
William Wernert
80525ee736
[wip] Add logscan pipeline
2021-07-08 12:29:50 -04:00
Jason Ertel
a43bdd9aad
Merge pull request #4723 from Security-Onion-Solutions/dev
...
HEAVYNODE_REDIS hotfix
2021-07-08 11:42:22 -04:00
m0duspwnens
20360d0bb0
create node_config measurement for nodes to be used for grafana dashboard vars
2021-07-08 11:18:25 -04:00
Josh Patterson
70d7513f84
Merge pull request #4729 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 14:49:38 -04:00
Josh Patterson
12b7fd3ab4
whitespace
2021-07-07 14:48:07 -04:00
Josh Patterson
c32b5b5429
whitespace
2021-07-07 14:47:16 -04:00
Josh Patterson
ea2a748dba
whitespace
2021-07-07 14:44:44 -04:00
Josh Patterson
c1d7d8c55a
add new line
2021-07-07 14:43:20 -04:00
Josh Patterson
a3c58d8445
remove heavy soup
2021-07-07 14:42:38 -04:00
Josh Patterson
cfc5c2aef6
do ; instead of &&
2021-07-07 14:32:57 -04:00
Josh Patterson
313260a0c5
add heavy action in soup for ssl redis, es, ls, fb
2021-07-07 14:22:45 -04:00
Josh Patterson
ee548aaf83
Merge pull request #4728 from Security-Onion-Solutions/fix/heavyfix
...
remove soup control of heavy
2021-07-07 14:01:32 -04:00
m0duspwnens
5eab57e500
remove soup control of heavy
2021-07-07 13:58:52 -04:00
Josh Patterson
6f48fdad42
Merge pull request #4727 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 12:15:50 -04:00
m0duspwnens
98fb5109d7
tell heavys to update ssl and restart containers for HEAVYNODE_SSL_LOGSTASH_REDIS_PIPELINES hotfix
2021-07-07 12:05:38 -04:00
m0duspwnens
9c2ead16cc
common name changes, allow cert to be managed regardless of expire date for heavy node
2021-07-07 10:22:37 -04:00
Jason Ertel
c4293c6119
Merge pull request #4724 from Security-Onion-Solutions/kilo
...
Merge master into dev via kilo
2021-07-07 07:21:21 -04:00
Jason Ertel
13c392d758
Merge branch 'master' into kilo
2021-07-07 06:40:30 -04:00
m0duspwnens
35f10518b2
map file into container
2021-07-06 17:12:21 -04:00
m0duspwnens
03066c4674
rename file
2021-07-06 17:08:29 -04:00
m0duspwnens
e33a6892b3
point to new location
2021-07-06 16:58:15 -04:00
m0duspwnens
87bb3f4a6b
quote the 5m
2021-07-06 16:45:10 -04:00
m0duspwnens
62bfaa4e45
send node_config data into telegraf for dashboard queries
2021-07-06 16:30:35 -04:00
Josh Patterson
9e94e605ee
Merge pull request #4715 from Security-Onion-Solutions/fix/heavyfix
...
add to HOTFIX file
2021-07-06 16:01:11 -04:00
m0duspwnens
f8dc647b1f
add to HOTFIX file
2021-07-06 15:59:35 -04:00
Josh Patterson
fc727d6909
Merge pull request #4711 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-06 15:56:02 -04:00
m0duspwnens
c1d61dc624
add to HOTFIX file
2021-07-06 15:54:15 -04:00
m0duspwnens
0627ca2fc2
use heavynode hostname for certs if heavynode. changes to logstash pipeline for redis if heavynode
2021-07-06 15:32:39 -04:00
weslambert
ce0b064972
Add conditional for heavynode for redis and elasticsearch
2021-07-06 14:21:29 -04:00
weslambert
2f3f04e4ca
Change from nodename to host
2021-07-06 14:18:39 -04:00
weslambert
2e91f27336
Add conditional for heavynode
2021-07-06 14:17:49 -04:00
weslambert
10b1829830
Add conditional for heavynode
2021-07-06 14:16:34 -04:00
weslambert
4946f32d88
Add extra_hosts entry for local instance when running as heavy node
2021-07-06 14:14:58 -04:00
m0duspwnens
dc1363aaf5
create file for telegraf to read node config details
2021-07-06 13:06:03 -04:00
m0duspwnens
a5067718d2
comma control
2021-07-06 11:06:35 -04:00
m0duspwnens
98505a9a3f
beginning of managing individual panels in grafana
2021-07-06 10:08:36 -04:00
Mike Reeves
e054fdb464
Merge pull request #4680 from Security-Onion-Solutions/dev
...
ECSFIX HOTFIX
2021-07-02 11:16:49 -04:00
Mike Reeves
3c8ad18693
Merge pull request #4683 from Security-Onion-Solutions/2.3.60ecs
...
2.3.60 ECSFIX
2021-07-02 11:05:17 -04:00
Mike Reeves
0a91f571c1
2.3.60 ECSFIX
2021-07-02 10:41:15 -04:00
Mike Reeves
8db5284f6e
Merge pull request #4679 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update telegraf.conf
2021-07-02 09:48:33 -04:00
Mike Reeves
22aa695508
Update telegraf.conf
2021-07-02 09:47:31 -04:00
m0duspwnens
a16f733622
add individual panels
2021-07-02 09:35:04 -04:00
Mike Reeves
af7d6c8cb5
Merge pull request #4678 from Security-Onion-Solutions/ecsfix1
...
ECS Hotfix
2021-07-02 09:14:42 -04:00
Mike Reeves
693f455862
ECS hotfix
2021-07-02 08:55:49 -04:00
Mike Reeves
b0abd290a9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-02 08:47:02 -04:00
Mike Reeves
0a9686f584
Merge pull request #4669 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
2.3.70
2021-07-01 14:39:01 -04:00
Mike Reeves
0b11bf6266
Update VERSION
2021-07-01 14:37:56 -04:00
Mike Reeves
d26056d272
Merge pull request #4655 from Security-Onion-Solutions/dev
...
2.3.60
2021-07-01 14:31:04 -04:00
Mike Reeves
724f9ec76f
Merge pull request #4667 from Security-Onion-Solutions/2.3.60v2
...
2.3.60
2021-07-01 13:11:10 -04:00
Mike Reeves
d583c79936
2.3.60
2021-07-01 13:09:09 -04:00
Mike Reeves
73b47716bc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-01 13:00:30 -04:00
Josh Patterson
4eaef94454
Merge pull request #4664 from Security-Onion-Solutions/influx_scripts
...
so-influxdb-downsample script improvements
2021-07-01 10:28:21 -04:00
m0duspwnens
21c9c7b8f4
only render main script if a manager type node
2021-07-01 07:56:45 -04:00
m0duspwnens
108fb12612
s/Migrating/Downsampling
2021-06-30 17:53:09 -04:00
m0duspwnens
eb8a030966
reset vars in jinja loop
2021-06-30 17:41:38 -04:00
m0duspwnens
9235bb35a1
fix jinja whatspace and add defaults
2021-06-30 17:30:33 -04:00
m0duspwnens
7b281abf0c
migrate script now goes through each day and measurement
2021-06-30 17:21:18 -04:00
Mike Reeves
b5fecd30cf
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 17:05:17 -04:00
Mike Reeves
26ff50f85c
Merge pull request #4659 from Security-Onion-Solutions/kilo
2021-06-30 16:34:16 -04:00
Mike Reeves
2eb1ba565f
Merge pull request #4658 from Security-Onion-Solutions/fix/so-docker-prune
2021-06-30 16:34:05 -04:00
William Wernert
4dbb869952
Fix typo
2021-06-30 16:21:09 -04:00
Jason Ertel
f3041a8d7e
Ensure all curl's to Kibana are properly sessioned and/or authenticated depending on elastic auth toggle
2021-06-30 16:09:08 -04:00
William Wernert
4109cdec53
Refactor so-docker-prune to prevent exceptions when removing images
...
* Prune containers at beginning of script so stopped containers using old images are removed
* Add force=True arg to remove() call to ensure an image is still deleted on the off chance a container is still using that image
* Add exception handling to continue removing containers instead of exiting if the script fails to remove a container
2021-06-30 15:35:01 -04:00
Josh Patterson
cdced887d1
Merge pull request #4654 from Security-Onion-Solutions/2.3.60
...
2.3.60
2021-06-30 12:40:00 -04:00
Mike Reeves
77ca922f62
2.3.60
2021-06-30 12:37:30 -04:00
Mike Reeves
a08166f27d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 11:38:15 -04:00
Mike Reeves
b9c56d1885
Merge pull request #4647 from Security-Onion-Solutions/fb-module-template
2021-06-30 09:38:20 -04:00
weslambert
fcbacd473d
Add ELK, redis
2021-06-30 09:34:56 -04:00
weslambert
06d77d9972
Update so-common-template.json
2021-06-30 09:31:32 -04:00
Mike Reeves
ee9c4f130e
Merge pull request #4646 from Security-Onion-Solutions/influx_scripts
2021-06-30 08:58:33 -04:00
m0duspwnens
ada729087d
add script to drop autogen, rename so-influxdb-migrate to so-influxdb-downsample
2021-06-30 08:14:52 -04:00
m0duspwnens
aa47a72656
source common to require root
2021-06-30 07:25:51 -04:00
Jason Ertel
857ec70abb
Merge pull request #4639 from Security-Onion-Solutions/issue/4609
...
grafana dashboards with trends
2021-06-29 22:23:31 -04:00
m0duspwnens
149f837223
Merge remote-tracking branch 'remotes/origin/dev' into issue/4609
2021-06-29 22:20:28 -04:00
m0duspwnens
37d6529ae0
fix load panel for manager graf
2021-06-29 22:18:17 -04:00
m0duspwnens
8d3ae65e04
fix load graf standalone
2021-06-29 22:13:51 -04:00
m0duspwnens
649e539ca6
add trends to sensor dash
2021-06-29 22:08:29 -04:00
m0duspwnens
45e90750a0
add trends for searchnode grafs
2021-06-29 21:37:20 -04:00
Mike Reeves
ce2a8917a6
Merge pull request #4635 from Security-Onion-Solutions/kilo
2021-06-29 21:21:55 -04:00
m0duspwnens
b22cd2d27c
managersearch dash with trends
2021-06-29 21:07:02 -04:00
m0duspwnens
813ef7d81a
new eval dashboard with trends
2021-06-29 20:23:27 -04:00
m0duspwnens
88275cd968
remove trend zeek capture loss, turn on line and points for capture loss standalone graf
2021-06-29 19:50:53 -04:00
m0duspwnens
3a47563b27
remove queries manager dashboard
2021-06-29 19:26:40 -04:00
m0duspwnens
ebb45a866b
remove queries from standalone dashboard
2021-06-29 19:20:29 -04:00
Mike Reeves
1433822437
Merge pull request #4637 from Security-Onion-Solutions/influxdb_cqs
...
Influxdb cqs - fix the query groupby
2021-06-29 19:08:56 -04:00
m0duspwnens
4a5b416a0b
Merge remote-tracking branch 'remotes/origin/influxdb_cqs' into issue/4609
2021-06-29 18:55:38 -04:00
Jason Ertel
cad4efdded
Fixed PCAP files are readable by root only, which prevents Suricata from being able to scan the file during import
2021-06-29 17:51:04 -04:00
m0duspwnens
f73a8d4d80
Merge remote-tracking branch 'remotes/origin/dev' into influxdb_cqs
2021-06-29 17:15:14 -04:00
m0duspwnens
dac19d224f
update cq
2021-06-29 17:15:00 -04:00
m0duspwnens
fa3e5eebe2
update manager dashboard
2021-06-29 15:11:31 -04:00
Jason Ertel
b64749c9d7
Merge pull request #4630 from Security-Onion-Solutions/dougburks-patch-1
...
Move salt lines after shebang
2021-06-29 13:33:00 -04:00
Doug Burks
822165f168
Move salt lines after shebang
2021-06-29 13:32:02 -04:00
m0duspwnens
2d16463fc6
Merge remote-tracking branch 'remotes/origin/dev' into issue/4609
2021-06-29 12:05:12 -04:00
m0duspwnens
3d8cbe9427
add trend lines
2021-06-29 11:22:14 -04:00
m0duspwnens
f18b64faaf
new standalone dashboard
2021-06-29 11:11:23 -04:00
Jason Ertel
95c7a7e9de
Merge pull request #4629 from Security-Onion-Solutions/influxdb_cqs
...
Influxdb cqs
2021-06-29 10:01:07 -04:00
m0duspwnens
ca152ab04c
redefine measurements
2021-06-29 09:54:17 -04:00
m0duspwnens
bf8bba7b84
only set measurements if conditions are met
2021-06-29 08:57:51 -04:00
m0duspwnens
3f2f699449
Merge remote-tracking branch 'remotes/origin/dev' into influxdb_cqs
2021-06-29 07:46:42 -04:00
m0duspwnens
6b68a39cbe
handle senario where there are no measurements
2021-06-29 07:46:25 -04:00
Jason Ertel
8867840215
Merge pull request #4628 from Security-Onion-Solutions/influxdb_cqs
...
Influxdb cqs
2021-06-28 17:10:27 -04:00
m0duspwnens
1c516daa96
fix measurement list
2021-06-28 17:05:32 -04:00
m0duspwnens
21c9388ee6
generate measurement list and cq for each
2021-06-28 16:12:36 -04:00
m0duspwnens
c72146587a
standalone dashboard
2021-06-28 16:07:32 -04:00
m0duspwnens
0ba685d0e2
change time filter
2021-06-28 12:36:06 -04:00
m0duspwnens
ce98f46331
update standalone dashboard for new influx
2021-06-28 08:49:02 -04:00
m0duspwnens
d6aa672556
updating standalone dashboard
2021-06-25 17:30:25 -04:00
Jason Ertel
6d2761b155
Merge pull request #4625 from Security-Onion-Solutions/foxtrot
...
Add Elasticsearch and Kibana to list of services that use webuser creds
2021-06-25 15:58:56 -04:00
Doug Burks
127afe1582
Merge pull request #4624 from Security-Onion-Solutions/fix/soup-grammar
...
fix soup grammar
2021-06-25 11:19:22 -04:00
doug
a3d7f4e35d
fix grammar
2021-06-25 11:16:26 -04:00
Mike Reeves
8eb163532d
Merge pull request #4620 from Security-Onion-Solutions/modulefix
...
Fix filebeat modules
2021-06-24 15:59:16 -04:00
Mike Reeves
ea50023ca5
Fix filebeat modules
2021-06-24 15:53:14 -04:00
Mike Reeves
846aef1bd6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-24 14:54:51 -04:00
Mike Reeves
143f2eb1a8
Merge pull request #4616 from Security-Onion-Solutions/airsoup
...
remove some debug statements
2021-06-24 13:31:17 -04:00
Mike Reeves
3f8cb23cf6
remove some debug statements
2021-06-24 13:29:16 -04:00
Mike Reeves
f92709b03b
Merge pull request #4614 from Security-Onion-Solutions/airsoup
...
Airsoup
2021-06-24 11:37:16 -04:00
Mike Reeves
81bb7c6534
remove a net check
2021-06-24 11:32:01 -04:00
Mike Reeves
bdd1074be7
remove a net check
2021-06-24 11:24:12 -04:00
Mike Reeves
42a63f8ea5
remove a net check
2021-06-24 11:15:16 -04:00
Mike Reeves
3c85db1769
Fix regression
2021-06-24 11:04:56 -04:00
Mike Reeves
930d5b3627
Revert "Move up script verification"
...
This reverts commit 66e88cef42 .
2021-06-24 10:52:53 -04:00
Mike Reeves
a1ec40b547
Revert "Move up script verification"
...
This reverts commit 2681903c93 .
2021-06-24 10:52:27 -04:00
William Wernert
022f9ea76e
Add Elasticsearch and Kibana to list of services that use webuser creds
2021-06-24 10:45:12 -04:00
Mike Reeves
2681903c93
Move up script verification
2021-06-24 10:24:00 -04:00
Jason Ertel
403d10cc75
Merge pull request #4611 from Security-Onion-Solutions/airsoup
...
Move up script verification
2021-06-24 10:05:05 -04:00
Mike Reeves
66e88cef42
Move up script verification
2021-06-24 10:03:38 -04:00
Jason Ertel
8f9d1b99e2
Merge pull request #4610 from Security-Onion-Solutions/airsoup
...
Fix airgap check
2021-06-24 09:51:47 -04:00
Mike Reeves
4af2f6d84a
Fix airgap check
2021-06-24 09:49:57 -04:00
Mike Reeves
78fa4feac6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-23 15:38:38 -04:00
Jason Ertel
5189f38766
Merge pull request #4601 from Security-Onion-Solutions/kilo
...
Elastic auth related adjustments; Soup error handling corrections, ES pipeline load improvements
2021-06-23 14:46:05 -04:00
Jason Ertel
243e888717
Add queue=True -- needed for all salt commands, not just state changes
2021-06-23 14:41:38 -04:00
weslambert
c5b81f2f4b
Fix output so that it can be redirected to local file with appropriate syntax
2021-06-23 14:41:38 -04:00
Mike Reeves
caa14e0cad
Fix Retry Spam
2021-06-23 14:41:38 -04:00
weslambert
d411a9e1ff
Merge pull request #4597 from Security-Onion-Solutions/fix/pipeline-view-output
...
Fix output so that it can be redirected to local file with appropriat…
2021-06-23 09:24:41 -04:00
weslambert
3fbc850774
Fix output so that it can be redirected to local file with appropriate syntax
2021-06-23 09:17:37 -04:00
Jason Ertel
d16febcae1
Merge pull request #4591 from Security-Onion-Solutions/kilo
...
Require either true | false in parameter to so-elastic-auth and ensur…
2021-06-22 15:31:48 -04:00
Jason Ertel
26bb6cc011
Require either true | false in parameter to so-elastic-auth and ensure all minions are fully updated with the new auth setting
2021-06-22 15:29:48 -04:00
Jason Ertel
bc80ef9a80
Merge pull request #4590 from Security-Onion-Solutions/kilo
...
only attempt to upgrade salt on minions if the minion count it > 1
2021-06-22 11:36:37 -04:00
m0duspwnens
9fad0876c5
only attempt to upgrade salt on minions if the minion count it > 1
2021-06-22 11:31:31 -04:00
Jason Ertel
914e635b4a
Merge pull request #4589 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Retry Spam
2021-06-22 10:15:39 -04:00
Mike Reeves
85bb234cf9
Fix Retry Spam
2021-06-22 10:14:33 -04:00
Mike Reeves
f7675a5dea
Merge pull request #4588 from Security-Onion-Solutions/souperduper
...
let the first highstate pass
2021-06-22 09:58:00 -04:00
Josh Patterson
7b662055dd
Merge pull request #4587 from Security-Onion-Solutions/kilo
...
fix timeout for docker_container.running for so-dockerregistry
2021-06-22 09:56:24 -04:00
m0duspwnens
d78c6f1a74
Merge branch 'kilo' of https://github.com/Security-Onion-Solutions/securityonion into kilo
2021-06-22 09:54:35 -04:00
m0duspwnens
9fa83d1cee
change to client_timeout
2021-06-22 09:54:25 -04:00
Mike Reeves
6e780164ea
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-22 09:52:44 -04:00
Jason Ertel
2ca8da0710
Merge pull request #4585 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-22 08:38:39 -04:00
Jason Ertel
c3deabae36
Update init.sls
2021-06-22 08:30:54 -04:00
m0duspwnens
9cdbcb72ac
Merge branch 'kilo' of https://github.com/Security-Onion-Solutions/securityonion into kilo
2021-06-22 08:23:26 -04:00
m0duspwnens
bc86590411
only add sosyncuser cron if startup_states: highstate is set in minion config
2021-06-22 08:23:16 -04:00
Jason Ertel
cb167f3d74
Merge pull request #4584 from Security-Onion-Solutions/kilo
...
retry on so-dockerregistry
2021-06-22 08:08:28 -04:00
Jason Ertel
8ddc99e91f
Allow for adjusting SOC session timeout
2021-06-22 08:07:52 -04:00
Jason Ertel
dcc9af946a
Avoid logging when sync is unnecessary due to cronjob log output spam
2021-06-22 08:07:52 -04:00
m0duspwnens
e4e3b199fc
retry on so-dockerregistry
2021-06-22 08:05:08 -04:00
Josh Patterson
bf61c82cf2
Merge pull request #4581 from Security-Onion-Solutions/kilo
...
adding elasticsearch.auth to heavynode and searchnode
2021-06-21 14:48:32 -04:00
m0duspwnens
c9ee28ce01
adding elasticsearch.auth to heavynode and searchnode
2021-06-21 14:47:24 -04:00
Jason Ertel
5135beb036
Merge pull request #4579 from Security-Onion-Solutions/kilo
...
Improve user sync algorithm
2021-06-21 12:40:27 -04:00
Jason Ertel
f36ef86ccc
Improve algorithm for determining if a user sync is necessary; Apply salt state in foreground to avoid collisions with setup salt states.
2021-06-21 12:38:02 -04:00
Jason Ertel
5e042bf4b8
Improve algorithm for determining if a user sync is necessary; Apply salt state in foreground to avoid collisions with setup salt states.
2021-06-21 12:16:47 -04:00
Josh Brower
130ce34686
Merge pull request #4578 from Security-Onion-Solutions/fix/esAlerter
...
esalerter ES creds fix
2021-06-21 11:08:59 -04:00
Josh Brower
591ef540a6
esalerter ES creds fix
2021-06-21 10:50:09 -04:00
Josh Patterson
697f6ab538
Merge pull request #4577 from Security-Onion-Solutions/issue/1333
...
remove the salt-minion check for schedules
2021-06-21 09:05:18 -04:00
m0duspwnens
ba5b5db2c4
remove the salt-minion check for schedules
2021-06-21 08:56:24 -04:00
Jason Ertel
e7afbab6a1
Merge pull request #4576 from Security-Onion-Solutions/kilo
...
Fix intermittent 'like' failures; Ensure bash is on first line of loa…
2021-06-21 07:09:10 -04:00
Jason Ertel
5298cb8cfb
Update copyrights
2021-06-21 07:06:49 -04:00
Jason Ertel
777bece2eb
Fix intermittent 'like' failures; Ensure bash is on first line of load templates script
2021-06-20 22:14:13 -04:00
Mike Reeves
7daad1a52a
Merge pull request #4571 from Security-Onion-Solutions/kilo
...
Ensure htpasswd exists earlier in the install process
2021-06-18 21:45:29 -04:00
Jason Ertel
60fd3c6bd3
Ensure htpasswd exists earlier in the install process
2021-06-18 20:01:32 -04:00
Josh Patterson
dc1c82f347
Merge pull request #4567 from Security-Onion-Solutions/issue/1333
...
Issue/1333
2021-06-18 16:12:42 -04:00
m0duspwnens
c7a58816b6
move condition to avoid wrong notic about schedule not set in pillar
2021-06-18 15:30:51 -04:00
m0duspwnens
48c3cb4816
if the salt-minion service isnt running when the state is rendered, dont try to apply schedule - https://github.com/Security-Onion-Solutions/securityonion/issues/1333
2021-06-18 14:56:01 -04:00
Jason Ertel
6e7f2107cb
Merge pull request #4566 from Security-Onion-Solutions/kilo
...
Remove unused mode
2021-06-18 14:45:02 -04:00
Jason Ertel
101b835cf6
Remove unused mode
2021-06-18 14:34:42 -04:00
Jason Ertel
558a90aaf8
Merge pull request #4563 from Security-Onion-Solutions/kilo
...
Disable HaveIBeenPwned API (pwnedpasswords.com)
2021-06-18 08:41:23 -04:00
Jason Ertel
1d4161ba31
Disable HaveIBeenPwned API (pwnedpasswords.com)
2021-06-18 08:36:36 -04:00
Mike Reeves
78d53af27c
Merge pull request #4562 from Security-Onion-Solutions/kilo
...
Fix wrong grep file
2021-06-17 21:19:05 -04:00
Jason Ertel
188b4424e4
Fix wrong grep file
2021-06-17 21:00:56 -04:00
Mike Reeves
0615d635eb
let the first highstate pass
2021-06-17 16:12:39 -04:00
Mike Reeves
85d7e75fb1
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 16:09:11 -04:00
Jason Ertel
833559dde6
Merge pull request #4559 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-17 15:55:28 -04:00
Jason Ertel
b294cee278
Remove passwords from soctopus templates since these are the basis for elastalert rules, which will use the user/pass at the elastalert global config level
2021-06-17 15:53:07 -04:00
Jason Ertel
afe7ddb480
Remove passwords from soctopus templates since these are the basis for elastalert rules, which will use the user/pass at the elastalert global config level
2021-06-17 15:51:53 -04:00
Jason Ertel
98526af82a
Merge pull request #4558 from Security-Onion-Solutions/kilo
...
Lock so-user to avoid two processes from overwriting eachother
2021-06-17 15:23:42 -04:00
Jason Ertel
0cb4562254
Lock so-user to avoid two processes from overwriting eachother
2021-06-17 15:19:39 -04:00
Josh Patterson
70f0ee719c
Merge pull request #4557 from Security-Onion-Solutions/fix_soup_elasticcurl
...
Fix soup elasticcurl
2021-06-17 15:02:27 -04:00
m0duspwnens
63b120e9e2
use just curl for elastic in soup
2021-06-17 14:56:05 -04:00
m0duspwnens
d587120613
set ELASTICCUURL default as curl
2021-06-17 14:42:04 -04:00
Mike Reeves
0dc4bc3cee
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 13:30:58 -04:00
Josh Patterson
79aad225a4
Merge pull request #4552 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-17 09:38:41 -04:00
m0duspwnens
8cd2bc7c13
adding so-eval to ES_INCLUDED_NODES
2021-06-17 09:37:21 -04:00
m0duspwnens
2a5198cae4
change perms to resolve error about module-setup.yml being 660
2021-06-17 08:49:21 -04:00
Jason Ertel
b8c463db82
Merge pull request #4551 from Security-Onion-Solutions/kilo
...
Fix require statement
2021-06-16 21:49:47 -04:00
Jason Ertel
059b016c62
Fix require statement
2021-06-16 21:48:31 -04:00
Jason Ertel
f1429632d2
Merge pull request #4549 from Security-Onion-Solutions/kilo
...
Elastic auth: Fun with Salt
2021-06-16 17:57:58 -04:00
Jason Ertel
2d34208269
Elastic auth: Fun with Salt
2021-06-16 17:52:22 -04:00
Jason Ertel
36c9054744
Merge pull request #4547 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-16 14:55:27 -04:00
William Wernert
5e11efb0b9
Merge pull request #4548 from Security-Onion-Solutions/fix/soup-merge-fix
...
Fix merge issue in soup
2021-06-16 14:36:24 -04:00
William Wernert
703988b376
Fix merge issue in soup
2021-06-16 14:28:20 -04:00
Jason Ertel
fefd2677fb
Only include so-common if available. It only is used for requiring root, but since this script is needed before common is installed, we can safely assume that it's being run as root already (during the install)
2021-06-16 14:26:26 -04:00
Jason Ertel
a323aeb8fa
Allow so-elastic-auth to run before common even though the script has dependency on a common-provided script (benign error). This is needed first since common will need to know if auth is enabled
2021-06-16 14:23:58 -04:00
Mike Reeves
8d6b0e23ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-16 13:23:44 -04:00
Jason Ertel
edac99e5a9
Merge pull request #4546 from Security-Onion-Solutions/kilo
...
Accept either 200 or 401 instead of wasting 3 minutes waiting for thi…
2021-06-16 11:41:23 -04:00
Jason Ertel
dd14235e31
Accept either 200 or 401 instead of wasting 3 minutes waiting for this to timeout
2021-06-16 11:39:21 -04:00
Jason Ertel
15eadd4f89
Merge pull request #4545 from Security-Onion-Solutions/kilo
...
Merge kilo to dev for additional ES Auth changes
2021-06-16 11:04:39 -04:00
Jason Ertel
09fbb045a1
If ES auth disabled ensure user/pass are blank
2021-06-16 09:59:57 -04:00
Josh Patterson
7bdd0d3bf1
Merge pull request #4543 from Security-Onion-Solutions/issue/2977
...
Issue/2977
2021-06-16 08:16:36 -04:00
m0duspwnens
ebea9a7198
remove space
2021-06-16 08:07:28 -04:00
m0duspwnens
ad9441bb60
prevent suricata state from running on manager and managersearch https://github.com/Security-Onion-Solutions/securityonion/issues/2977
2021-06-16 08:06:26 -04:00
Jason Ertel
989f9dce42
Ensure sqlite.db exists before querying it; Execute so-elastic-auth after common state has been applied and redirect output to setup log
2021-06-15 16:57:13 -04:00
Jason Ertel
b95437347e
Upgrade ES to 7.13.2
2021-06-15 12:50:57 -04:00
Jason Ertel
2d27e0d9a9
Merge pull request #4530 from Security-Onion-Solutions/kilo
...
Elastic auth
2021-06-15 11:15:19 -04:00
Jason Ertel
c3c078e5be
Merge pull request #4522 from Security-Onion-Solutions/feature/contributing-md
...
Add CONTRIBUTING.md
2021-06-15 10:25:07 -04:00
Jason Ertel
dd8eb29a18
Continue merge of ECS into Elastic Auth
2021-06-15 09:11:58 -04:00
William Wernert
2d5591a87f
Remove draft label
2021-06-14 16:33:52 -04:00
William Wernert
71b079eb54
Add bullet detailing linking pull request to issue
2021-06-14 16:04:22 -04:00
William Wernert
ca6f3807fc
Don't use idioms, and remove TBD lines
2021-06-14 15:58:21 -04:00
Doug Burks
c2f6a6983d
Merge pull request #4521 from Security-Onion-Solutions/feature/security-md
...
Create SECURITY.md
2021-06-14 15:51:55 -04:00
Jason Ertel
3891ca2929
Use correct mode param to file.recurse
2021-06-14 15:46:25 -04:00
Doug Burks
20437ef2c7
Create SECURITY.md
2021-06-14 15:42:18 -04:00
William Wernert
7de02d541f
Increase width of verified commit screenshot
2021-06-14 15:28:44 -04:00
William Wernert
68e4c5e469
Add CONTRIBUTING.md draft, move markdown images to assets/images
2021-06-14 15:21:46 -04:00
Jason Ertel
62187807f0
Specify elastic creds for playbook alert templates
2021-06-14 14:08:14 -04:00
Jason Ertel
37f4caf536
Make new ECS changes Elastic-auth compatible
2021-06-14 12:13:50 -04:00
Jason Ertel
fca1c6e957
Merge branch 'dev' into kilo
2021-06-14 10:40:04 -04:00
Josh Patterson
0de7e71fa0
Merge pull request #4517 from Security-Onion-Solutions/fix/filebeat
...
update roles that include es state
2021-06-14 10:02:50 -04:00
m0duspwnens
fd5d540c78
update roles that include es state
2021-06-14 10:00:19 -04:00
m0duspwnens
d2069dc5f2
update roles that include es state
2021-06-14 09:58:50 -04:00
Mike Reeves
2ac832678f
Merge pull request #4513 from Security-Onion-Solutions/fix/filebeat
...
fix two bugs
2021-06-14 08:53:13 -04:00
m0duspwnens
5941332d49
fix two bugs
2021-06-14 08:51:29 -04:00
Josh Patterson
45732bd87a
Merge pull request #4494 from Security-Onion-Solutions/fix_module_config_jinja
...
dont loop if modules arent defined for the node
2021-06-11 13:54:15 -04:00
m0duspwnens
f7600af89b
dont loop if modules arent defined for the node
2021-06-11 13:52:33 -04:00
Josh Patterson
5108121b59
Merge pull request #4489 from Security-Onion-Solutions/hotfix/soup_salt
...
Hotfix/soup salt
2021-06-10 16:04:27 -04:00
Josh Patterson
c2339c84e7
Merge branch 'dev' into hotfix/soup_salt
2021-06-10 15:48:00 -04:00
Jason Ertel
7205c5cb7b
Provide timestamp as arg to SOC PCAP pivots
2021-06-10 15:21:03 -04:00
m0duspwnens
ff807c9a6f
empty hotfix file for merge into dev
2021-06-10 14:06:24 -04:00
Mike Reeves
0341eb5d8f
Merge pull request #4479 from Security-Onion-Solutions/hotfix/soup_salt
...
Hotfix/soup salt
2021-06-10 13:44:10 -04:00
Mike Reeves
a2e1b1de3a
Merge pull request #4484 from Security-Onion-Solutions/pipeline
...
Pipeline
2021-06-10 13:41:14 -04:00
m0duspwnens
e64059bd7b
remove unneeded function
2021-06-10 09:31:10 -04:00
m0duspwnens
46b1de97f5
change function name
2021-06-10 09:30:03 -04:00
Mike Reeves
ca7d2c6d64
Merge branch 'pipeline' of https://github.com/Security-Onion-Solutions/securityonion into pipeline
2021-06-10 09:20:38 -04:00
Mike Reeves
12d4d4a4f7
Dynamix Pipelines take 2
2021-06-10 09:19:15 -04:00
m0duspwnens
7c92054f13
soup hotfix to updating repos for earlier versions of SO so salt will isntall
2021-06-10 09:13:15 -04:00
weslambert
1bef1d5652
Update to apply to any so-prefixed index
2021-06-10 08:16:00 -04:00
Jason Ertel
89a02383b8
Correct cronjob path issue for sysctl; suppress diff outputs from users/roles files; suppress salt state output during user sync
2021-06-09 16:31:32 -04:00
Mike Reeves
7fba904f75
Dynamix Pipelines take 1
2021-06-09 15:32:39 -04:00
Mike Reeves
1c7741fdbe
Add templates for SO logs
2021-06-09 12:38:19 -04:00
Mike Reeves
4c90a0ed7e
Add templates for SO logs
2021-06-09 12:04:32 -04:00
m0duspwnens
a82b174826
perform the repo changes for any upgrade
2021-06-09 11:53:10 -04:00
Mike Reeves
579ff8c0b4
Add verbosity to checkin
2021-06-09 11:40:17 -04:00
Mike Reeves
264080546c
Add log path
2021-06-09 11:37:27 -04:00
Jason Ertel
a0c65e2333
Ensure elastic minions also update their auth files
2021-06-09 09:38:50 -04:00
Jason Ertel
dd73ad544c
Rename PATH var to avoid collision with OS PATH var; wrapped password var in quotes to support spaces in Fleet/TheHive passwords
2021-06-09 09:06:29 -04:00
Mike Reeves
33db9023eb
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:50:39 -04:00
Mike Reeves
88eea03f97
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:36:50 -04:00
Mike Reeves
a959ec1eb1
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:23:31 -04:00
Mike Reeves
3e138cbc6d
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:14:46 -04:00
Jason Ertel
9b61723194
Merge branch 'dev' into kilo
2021-06-08 11:04:09 -04:00
Jason Ertel
d2381b0209
Ensure empty/aborted users/roles files do not get copied onto final filenames
2021-06-08 11:03:56 -04:00
Mike Reeves
4972f69dd6
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-06-08 11:03:14 -04:00
Mike Reeves
56eb220ed6
Revert to SO taxonomy for zeek and suricata
2021-06-08 09:52:05 -04:00
Jason Ertel
343c47d67a
Add so-elasticsearch-query tool
2021-06-07 17:26:07 -04:00
Jason Ertel
e53f2217ec
Add so-elasticsearch-query tool
2021-06-07 17:24:22 -04:00
Mike Reeves
016a5a5914
Merge pull request #4432 from Security-Onion-Solutions/merge_2.3.52
...
Merge 2.3.52
2021-06-07 14:10:16 -04:00
William Wernert
9f2adfb67a
Merge branch 'master' into merge_2.3.52
...
# Conflicts:
# VERSION
2021-06-07 14:08:17 -04:00
Mike Reeves
6e92e7283d
Merge pull request #4411 from Security-Onion-Solutions/hotfix-0528
...
2.3.52
2021-06-07 13:55:51 -04:00
Mike Reeves
e3c16147ce
2.3.52
2021-06-07 09:34:22 -04:00
Jason Ertel
14aa9805b4
Stop failing an install because salt is already running when a highstate is applied at 95%
2021-06-06 18:20:57 -04:00
Jason Ertel
fdab17a3b9
Due to dir ownership restrictions need to run crossthestreams and eval as root
2021-06-06 16:36:35 -04:00
Jason Ertel
bebba7d280
Switch ownership of curl config to socore
2021-06-06 07:43:53 -04:00
Jason Ertel
11b2b2a893
Switch ownership of curl config to socore
2021-06-06 05:42:34 -04:00
Jason Ertel
84141082ab
Avoid applying state when adding web user
2021-06-05 08:41:48 -04:00
Jason Ertel
ba29b5e036
Do not apply salt state if already applying a state
2021-06-04 21:56:41 -04:00
Jason Ertel
e22421ec99
Refactor users/roles management via salt due to Salt's clobbering of the inode which breaks Docker mounts
2021-06-04 20:01:30 -04:00
Jason Ertel
416b38fc71
Use cronjob to ensure user synchronization
2021-06-04 11:24:58 -04:00
William Wernert
fd5fcfeaae
Merge pull request #4402 from Security-Onion-Solutions/foxtrot
...
Use variable for whiptail title and make sure all menus in setup have the same title
2021-06-04 11:10:01 -04:00
Mike Reeves
75ff268ecc
2.3.52
2021-06-04 11:03:08 -04:00
Mike Reeves
9f98b8ad2f
2.3.52
2021-06-04 10:59:18 -04:00
Jason Ertel
316035910f
Remove inotify beacon due to it not functioning as documented; Add back so-user changes to sync upon so-user changes
2021-06-03 15:15:35 -04:00
William Wernert
d1d09d4aab
Remove useless variable assignment
2021-06-03 14:20:52 -04:00
Mike Reeves
31365b266a
Update so-zeek-stats
2021-06-03 13:53:11 -04:00
Mike Reeves
2f34e7eeed
Update HOTFIX
2021-06-03 11:04:10 -04:00
William Wernert
3aff3ac7e4
Change logic to check for unmanaged nics
...
Resolves issue mentioned in #4327
2021-06-03 11:00:20 -04:00
William Wernert
d1a185aaae
Further standardize whiptail titles
2021-06-03 10:59:14 -04:00
Mike Reeves
ff10432124
Update VERSION
2021-06-03 10:57:20 -04:00
William Wernert
bb5b805983
Merge branch 'fix/missing-version-string' into foxtrot
2021-06-03 10:45:02 -04:00
Jason Ertel
58ae3479dc
Fix mispelled db filename; ensure ELASTICCURL is used for loading config objects
2021-06-03 10:11:10 -04:00
William Wernert
d55e007032
Merge pull request #4386 from Security-Onion-Solutions/foxtrot
...
Update wording for iso location prompt in soup
2021-06-03 09:55:15 -04:00
Jason Ertel
2af43d62eb
Wrap curl param in quotes for function call
2021-06-03 08:53:59 -04:00
Jason Ertel
5c527b2c48
Rename username param to user since logstash is 'unique'
2021-06-03 07:51:43 -04:00
Jason Ertel
e6165f0046
Update kibana config load for auth changes
2021-06-03 07:47:32 -04:00
Jason Ertel
70427bc676
Merge branch 'dev' into kilo
2021-06-03 07:41:35 -04:00
Mike Reeves
9ec7cbef8e
Merge pull request #4391 from Security-Onion-Solutions/es-7.13.1
...
Es 7.13.1 saved objects update
2021-06-02 20:23:40 -04:00
Jason Ertel
719d841353
Update saved objects
2021-06-02 20:15:03 -04:00
Jason Ertel
fa6af06204
Avoid running highstate during setup when flipping auth flag
2021-06-02 17:13:59 -04:00
weslambert
cba719b3a0
Remove extra comma
2021-06-02 16:42:09 -04:00
weslambert
4241bb08b8
Add suricata/zeek until we migrate templates
2021-06-02 16:37:43 -04:00
Jason Ertel
901242f7e9
remove extra parenthesis
2021-06-02 16:23:45 -04:00
weslambert
4c74e7f308
Add event.kind and set name to module[dot]dataset
2021-06-02 15:35:26 -04:00
weslambert
db48c15f1d
Create event.kind field and rename dataset to be module[dot]dataset
2021-06-02 15:33:18 -04:00
weslambert
a1b34e7a88
Fix Suricata index name
2021-06-02 15:30:14 -04:00
Jason Ertel
fc6b3726a4
Fix missing colon for mode
2021-06-02 15:23:16 -04:00
Mike Reeves
9c9bcac61b
Update DNS queries
2021-06-02 15:01:14 -04:00
Jason Ertel
588da4d7dc
Resolve salt pillar/state/jinja race condition
2021-06-02 14:34:21 -04:00
Mike Reeves
e42db3cd2d
Fix some hunt queries
2021-06-02 14:05:02 -04:00
Mike Reeves
e8cc88174f
Fix some hunt queries
2021-06-02 13:55:05 -04:00
Mike Reeves
7b7111e12c
Fix some hunt queries
2021-06-02 13:53:39 -04:00
William Wernert
b3f2c60065
Whiptail title fixes
...
- Use a variable for the title
- Fix cases where the whiptail title wasn't changed previously
2021-06-02 12:38:32 -04:00
Jason Ertel
20e896cacf
Update all configs to pass user/pass to ES
2021-06-02 12:17:15 -04:00
William Wernert
afbf7de9e3
Remove empty lines in iso location prompt
2021-06-02 11:05:43 -04:00
Jason Ertel
4ff85ab0c4
Merge branch 'dev' into kilo
2021-06-02 10:39:51 -04:00
Jason Ertel
dd7388e577
Merge pull request #4382 from Security-Onion-Solutions/jertel/timeouts
...
Increase SOC API timeouts and ES timeout from 2m to 5m
2021-06-02 10:28:36 -04:00
Mike Reeves
77f13961ad
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-06-02 10:12:17 -04:00
Mike Reeves
e00fe0a732
Enable for all modes
2021-06-02 10:02:11 -04:00
Jason Ertel
c757d21360
Increase default SOC API and ES timeouts from 2m to 5m
2021-06-02 09:38:59 -04:00
Jason Ertel
3a134cc706
fix merge conflicts
2021-06-02 09:16:28 -04:00
Jason Ertel
7aede4d058
Persist chown/chmod settings on users/roles files
2021-06-02 09:01:16 -04:00
Mike Reeves
5983eae3a8
fix filebeat module syntax
2021-06-01 17:47:13 -04:00
Josh Patterson
9d6dca9c64
Merge pull request #4372 from Security-Onion-Solutions/pipeline_userpass
...
fix typo
2021-06-01 17:46:41 -04:00
m0duspwnens
7b68c1bc9b
fix typo
2021-06-01 17:45:52 -04:00
Josh Patterson
9d905368ca
Merge pull request #4371 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-06-01 17:01:51 -04:00
m0duspwnens
867613669d
changes for syncing users
2021-06-01 17:01:03 -04:00
Mike Reeves
fd1de624c8
Disable TTY for filebeat script
2021-06-01 14:50:21 -04:00
Jason Ertel
2a2247e1da
Additional so-user sync adjustments
2021-06-01 14:45:01 -04:00
Jason Ertel
7a59bee315
Add so-elastic-auth script
2021-06-01 12:48:53 -04:00
William Wernert
91c8a7c65b
Use correct syntax for tar to drop directory structure
2021-06-01 12:16:56 -04:00
Mike Reeves
73a0b31380
elastic pipeline enable
2021-06-01 12:12:20 -04:00
m0duspwnens
ef00695b07
fix typo
2021-06-01 11:31:50 -04:00
m0duspwnens
bfaffbc87e
add reactor and beacon for sqlite db
2021-06-01 11:15:28 -04:00
William Wernert
e800d62df4
Merge branch 'dev' into fix/update-iso-soup-wording
2021-06-01 11:12:17 -04:00
Josh Patterson
6fe765434e
Merge pull request #4362 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-06-01 10:56:29 -04:00
m0duspwnens
7e48740ea7
fix merge conflict
2021-06-01 10:56:02 -04:00
m0duspwnens
d25a439bd4
more changes
2021-06-01 10:53:58 -04:00
Jason Ertel
ed8c85df2b
Only sync web users if teh sqlite db exists
2021-06-01 10:26:33 -04:00
Josh Patterson
c4ae8c3418
Merge pull request #4359 from Security-Onion-Solutions/pipeline_userpass
...
generate pillar file if auth enabled or not
2021-06-01 09:38:34 -04:00
m0duspwnens
f87dce8ec1
generate pillar file if auth enabled or not
2021-06-01 09:38:07 -04:00
Josh Patterson
5d2f1c8e11
Merge pull request #4357 from Security-Onion-Solutions/pipeline_userpass
...
fix logic
2021-06-01 08:36:48 -04:00
m0duspwnens
1aa2852ed6
fix logic
2021-06-01 08:35:43 -04:00
Jason Ertel
a42a406f53
Remove extra users file mounts; disable elastic anon access when auth enabled
2021-05-29 07:52:08 -04:00
Jason Ertel
47b56e78b3
Fix missing endif
2021-05-28 20:07:51 -04:00
Josh Patterson
52db7b32ef
Merge pull request #4335 from Security-Onion-Solutions/pipeline_userpass
...
fix logic on password created in pillar and fix how me manage
2021-05-28 18:29:59 -04:00
m0duspwnens
3aad5a30e9
fix logic on password created in pillar and fix how me manage
2021-05-28 18:28:53 -04:00
Jason Ertel
b8a10f2e86
Support multiple elastic system users
2021-05-28 15:59:51 -04:00
Josh Patterson
4e8dc0e3b9
Merge pull request #4334 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-05-28 15:29:07 -04:00
m0duspwnens
edf60f80f7
manager and common states now require elasticsearch.auth state
2021-05-28 15:26:26 -04:00
William Wernert
a94c598d00
Merge pull request #4333 from Security-Onion-Solutions/feature/show-version-in-setup
...
Show version in setup
2021-05-28 15:15:43 -04:00
m0duspwnens
68abaa5e3c
update auth.map and curl.config to use new elasticsearch:auth pillar format
2021-05-28 14:03:21 -04:00
m0duspwnens
63b31de2b8
add additional users - manage file if user name isnt returned from grepping the file
2021-05-28 13:58:03 -04:00
Mike Reeves
eac5c604bd
Update packetloss.sh
2021-05-28 12:57:35 -04:00
Mike Reeves
e7d8df499c
Update HOTFIX
2021-05-28 12:55:57 -04:00
Josh Patterson
35845440c6
Merge pull request #4330 from Security-Onion-Solutions/pipeline_userpass
...
remove unneeded curl.config template
2021-05-28 10:38:43 -04:00
m0duspwnens
18926009d3
remove unneeded curl.config template
2021-05-28 10:38:06 -04:00
William Wernert
d55a9e6274
Add version to all whiptail titles
2021-05-28 10:20:19 -04:00
William Wernert
ba011581ef
Add version to ending summary
2021-05-28 10:14:58 -04:00
Jason Ertel
1788ceccea
Merge pull request #4329 from Security-Onion-Solutions/fix/kibana_7.13.0
...
bump Kibana version to 7.13.0
2021-05-28 09:14:18 -04:00
doug
ada8255af0
bump version to 7.13.0
2021-05-28 08:59:40 -04:00
Josh Patterson
f1a6f66d49
Merge pull request #4317 from Security-Onion-Solutions/pipeline_userpass
...
remove vault pg from when i was testing
2021-05-27 13:55:01 -04:00
m0duspwnens
423793ecf9
remove vault pg from testing
2021-05-27 13:50:22 -04:00
Josh Patterson
94cfa3c9d0
Merge pull request #4314 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-05-27 11:34:34 -04:00
m0duspwnens
0134ceef16
merge and resolve conflict in elasticsearch state
2021-05-27 11:33:44 -04:00
m0duspwnens
b23ce7462e
add depenency
2021-05-27 11:26:25 -04:00
Doug Burks
cf3dda6869
Merge pull request #4300 from j-bernal/patch-1
...
Update so-whiptail
2021-05-27 07:58:16 -04:00
m0duspwnens
dc8520df42
user curl.config for curl and elasticscripts
2021-05-26 18:04:30 -04:00
Jason Ertel
d9c5976ed0
Merge pull request #4304 from Security-Onion-Solutions/feature/1596
...
add menu.actions.json and update soc.json
2021-05-26 16:41:30 -04:00
doug
aeea5701e4
completely disable both alerts.actions.json and hunt.actions.json
2021-05-26 16:34:05 -04:00
m0duspwnens
7263e35a89
happy little comment
2021-05-26 14:52:59 -04:00
m0duspwnens
4d991d3773
propogate users and users_roles
2021-05-26 14:52:10 -04:00
Mike Reeves
bfcde15a24
elastic pipeline test
2021-05-26 14:22:14 -04:00
doug
ee675546ac
add menu.actions.json and update soc.json
2021-05-26 14:09:00 -04:00
Jason Ertel
b43e6c5d6b
Salt will handle auto-sync
2021-05-26 13:51:24 -04:00
Jason Ertel
c531ef0773
Move user sync'd files to saltstack for grid propagation
2021-05-26 13:44:30 -04:00
Jason Ertel
a6a4c03029
Improve error scenarios for user sync; Ensure user sync runs before Elastic container starts
2021-05-26 12:08:10 -04:00
Mike Reeves
b525cfc787
Remove old modules
2021-05-26 11:07:53 -04:00
m0duspwnens
842aa97f7e
load filebeat modules when es container starts and if fb container is running
2021-05-26 11:00:18 -04:00
Mike Reeves
34d4eedf67
Remove old modules
2021-05-26 10:11:47 -04:00
Josh Brower
4a109d6af1
Merge pull request #4299 from Security-Onion-Solutions/feature/so-pcap-pull
...
Feature/so-pcap-export
2021-05-26 09:59:45 -04:00
John Bernal
cb40a76247
Update so-whiptail
...
Updated Zeek capitalization when prompting for the number of processes.
2021-05-26 09:55:14 -04:00
Josh Brower
ed249600d3
Merge remote-tracking branch 'remotes/origin/dev' into feature/so-pcap-pull
2021-05-26 09:52:58 -04:00
Josh Brower
0187c9d6df
Adds so-pcap-export
2021-05-26 09:51:37 -04:00
William Wernert
6da37966d9
Update wording for iso location prompt in soup
2021-05-26 09:32:25 -04:00
m0duspwnens
525d4325c7
define ZEEKLOGLOOKUP in the yaml
2021-05-25 17:18:58 -04:00
m0duspwnens
ecf7e25a51
fix merge conflict
2021-05-25 17:16:44 -04:00
Jason Ertel
ec2f8fe6c8
Synchronize SOC passwords with Elastic
2021-05-25 17:16:05 -04:00
m0duspwnens
dfaf40f583
add zeekloglookup to translate zeeklogs to filebeat filesets
2021-05-25 17:14:26 -04:00
Mike Reeves
543154f037
Remove old modules
2021-05-25 16:58:18 -04:00
Mike Reeves
cd3e355f84
Fix zeek depth
2021-05-25 16:54:20 -04:00
m0duspwnens
2eee6b45bc
Merge branch 'pipeline' of https://github.com/Security-Onion-Solutions/securityonion into pipeline
2021-05-25 16:52:08 -04:00
m0duspwnens
0de5c6f204
fix sodefault modules
2021-05-25 16:52:02 -04:00
Mike Reeves
9363fc153c
Fix pillar for module
2021-05-25 16:44:13 -04:00
m0duspwnens
2aacd5b9b6
so defaults filebeat modules
2021-05-25 16:40:50 -04:00
m0duspwnens
c3b2e1e8b2
dont show changes
2021-05-25 16:16:57 -04:00
m0duspwnens
e261c197f3
add elasticsearch.auth state to statnalone node
2021-05-25 13:46:18 -04:00
m0duspwnens
747dc77c92
comment out the hackery
2021-05-25 13:23:26 -04:00
m0duspwnens
35cc7b27e9
remove extra quote
2021-05-25 13:12:30 -04:00
William Wernert
67828a86c1
Merge pull request #4289 from Security-Onion-Solutions/foxtrot
...
Soup error handling, reorder sensoroni state
2021-05-25 12:42:01 -04:00
m0duspwnens
58ec31d6c7
pass ELASTICAUTH to script
2021-05-25 12:02:41 -04:00
m0duspwnens
6da0b57ce1
fix file.file_exists
2021-05-25 11:55:22 -04:00
m0duspwnens
8d9d5a267a
generate elasticsearch.auth pillar if it doesnt exist
2021-05-25 11:52:58 -04:00
William Wernert
94af55a951
Fix typo
2021-05-25 11:25:37 -04:00
William Wernert
192cec1825
Change how version with dashes are handled by so-docker-prune
2021-05-25 11:25:12 -04:00
Mike Reeves
1e564c2140
Fix zeek jinja
2021-05-25 10:22:36 -04:00
William Wernert
7e008378ba
Replace string with variable, remove unnecessary text
2021-05-25 09:23:44 -04:00
William Wernert
dbc4ffd69a
Fix typo
2021-05-25 09:20:45 -04:00
m0duspwnens
5a1e8d9fe9
update kibana scripts for elastic auth
2021-05-25 08:50:55 -04:00
Mike Reeves
5e5d30a377
Fix 3rd party modules
2021-05-25 08:26:25 -04:00
William Wernert
3bc0def02a
Add failure message to salt-master check
2021-05-24 16:45:05 -04:00
m0duspwnens
bd301880ad
define the default
2021-05-24 16:32:30 -04:00
m0duspwnens
2deb703272
map users_roles and users conf into docker container
2021-05-24 16:30:55 -04:00
Jason Ertel
8c6489a49a
Initial pass at synchronizing users file
2021-05-24 15:48:05 -04:00
m0duspwnens
87609ba5d1
fix elasticcurl if auth is enabled
2021-05-24 15:44:01 -04:00
m0duspwnens
ba3a51387c
set default to False
2021-05-24 15:31:46 -04:00
William Wernert
ffd5bfc480
Force images from automated branches to a very high semver
2021-05-24 15:25:03 -04:00
m0duspwnens
a4226cc39a
use elastic map file
2021-05-24 15:14:05 -04:00
William Wernert
dcb89b704a
Move sensoroni state out of the * block of top.sls
...
Resolves #3559
2021-05-24 13:45:12 -04:00
William Wernert
686c7c5a6c
Add exception handling for docker API error to so-docker-prune
2021-05-24 13:26:43 -04:00
Jason Ertel
409eea677d
Continue removal of argon hashing
2021-05-24 11:50:53 -04:00
William Wernert
99d41d1606
Add ending newline to soup
2021-05-24 11:29:40 -04:00
Jason Ertel
915b7aa2df
Switch Kratos config from argon2 to bcrypt12
2021-05-24 10:52:54 -04:00
m0duspwnens
e2d5102a0e
changes for script to auth to elastic
2021-05-24 10:13:29 -04:00
Mike Reeves
e5a41b60ef
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-05-24 09:14:03 -04:00
Jason Ertel
0572ea4095
Fail curl command if a failing status code is returned by the remote server
2021-05-21 17:27:11 -04:00
Jason Ertel
71032150c5
Add secure HTTP headers to all SO application responses to reduce exposure to browser and other HTTP-related vulnerabilities
2021-05-21 17:27:00 -04:00
Jason Ertel
36d13dd414
Merge branch 'dev' into kilo
2021-05-21 17:26:50 -04:00
William Wernert
946e369a44
Merge branch 'dev' into foxtrot
2021-05-21 15:26:24 -04:00
Mike Reeves
18922ed6f5
Merge pull request #4263 from Security-Onion-Solutions/feature/merge-2.3.51
...
Merge 2.3.51 into dev
2021-05-21 12:47:15 -04:00
William Wernert
c1dd4dafe4
Fix influx state
2021-05-21 12:41:10 -04:00
William Wernert
fe3aec173f
Merge branch 'master' into feature/merge-2.3.51
...
# Conflicts:
# VERSION
# salt/influxdb/init.sls
2021-05-21 12:31:54 -04:00
Mike Reeves
c5d0286e24
Merge pull request #4254 from Security-Onion-Solutions/2.3.51
...
2.3.51
2021-05-21 12:15:04 -04:00
Mike Reeves
7aed01658f
Sig file for 2.3.51
2021-05-20 22:10:36 -04:00
Mike Reeves
de4fde4ee3
Merge pull request #4248 from Masaya-A/MAC-Address
...
Showing Mac Address to select suitable NICs (Discussions #4214 )
2021-05-19 21:18:15 -04:00
Masaya-A
3450219bc7
Drop error to /dev/null
2021-05-20 09:33:14 +09:00
Jason Ertel
b440f73336
Truncate wait_for_web_response.log before each wait invocation
2021-05-19 18:37:08 -04:00
Masaya-A
6af126b872
Fix array
2021-05-19 10:02:19 +09:00
Masaya-A
ac42cba50b
Adding MAC Address for NIC List
2021-05-19 09:06:02 +09:00
Masaya-A
5d263f63cb
Merge pull request #10 from Security-Onion-Solutions/dev
...
Dev Sync
2021-05-19 08:59:49 +09:00
William Wernert
f445186f1e
Remove redundant error messages
2021-05-18 13:38:55 -04:00
Jason Ertel
25e2edc6d2
Reset HOTFIX with new release
2021-05-18 12:31:33 -04:00
William Wernert
bdd53ed5e3
Change retry delay + count
2021-05-18 12:23:40 -04:00
Jason Ertel
c207504657
Merge branch '2.3.51' of ssh://github.com/security-onion-solutions/securityonion into 2.3.51
2021-05-18 09:52:07 -04:00
Jason Ertel
fe155222c2
Introduce mixed-case sensor into distributed test
2021-05-18 09:51:54 -04:00
Josh Patterson
9b4325662b
Merge pull request #4218 from Security-Onion-Solutions/issue/4207
...
Issue/4207
2021-05-18 09:04:26 -04:00
m0duspwnens
0de1c9a669
removing unreference pillar file docker/config.sls
2021-05-18 07:57:00 -04:00
m0duspwnens
ef32bff302
fix up soc.json
2021-05-17 18:29:27 -04:00
m0duspwnens
e50002e0ca
influx and grafana default for manager nodes - https://github.com/Security-Onion-Solutions/securityonion/issues/4207
2021-05-17 16:26:12 -04:00
William Wernert
dbd5ef70c9
Change retry delay + count
2021-05-17 16:19:31 -04:00
William Wernert
ce9554281e
Fix backwards logic
2021-05-17 16:08:34 -04:00
William Wernert
4e1fba5b38
Only echo error code if not using retry
2021-05-17 16:04:13 -04:00
William Wernert
3f238f7a4a
Set flag so trap doesn't repeat info
2021-05-17 16:02:52 -04:00
William Wernert
b89091cc7d
Try retrying in curl instead of shell function
2021-05-17 15:58:25 -04:00
Mike Reeves
d001597e52
Update README.md
2021-05-17 15:56:46 -04:00
Mike Reeves
4c7cee4ebc
Update VERSION
2021-05-17 15:55:49 -04:00
Mike Reeves
6eed730209
Merge pull request #4213 from Security-Onion-Solutions/zeekhotfix
...
Zeekhotfix
2021-05-17 15:55:17 -04:00
William Wernert
992b76a0f0
Remove debug lines
2021-05-17 15:38:10 -04:00
William Wernert
2bcd51b21c
Fix error message
2021-05-17 15:10:57 -04:00
William Wernert
3625453668
Don't unmount airgap directory if not airgap
2021-05-17 11:00:28 -04:00
William Wernert
5821a122cc
Merge branch 'dev' into issue/3220
2021-05-17 10:58:06 -04:00
Josh Patterson
891e414cb6
Merge pull request #4202 from Security-Onion-Solutions/issue/3264
...
Issue/3264
2021-05-14 16:30:16 -04:00
m0duspwnens
54f9e3ff9d
remove leading space on comment line
2021-05-14 16:24:16 -04:00
m0duspwnens
1c0cc15fdb
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-14 15:19:58 -04:00
m0duspwnens
231e07dbbd
circumvent file.patch putting ERROR in log if patch doesnt need applied
2021-05-14 15:19:45 -04:00
m0duspwnens
3859f6464a
dont be quiet on first grep
2021-05-14 08:56:42 -04:00
Mike Reeves
71a74a6656
Added updated script and core modules
2021-05-13 13:07:16 -04:00
Josh Patterson
3668d1aadf
Merge pull request #4188 from Security-Onion-Solutions/issue/3264
...
install influxdb and grafana during setup prior to final highstate
2021-05-13 11:46:57 -04:00
m0duspwnens
d3af06e7a4
handle exception if influxdb module doesnt exist
2021-05-13 11:00:42 -04:00
m0duspwnens
74f2a61b25
install influxdb and grafana during setup prior to final highstate
2021-05-13 09:06:47 -04:00
Mike Reeves
68a667ee7c
Add thirfpartydefaults.yml
2021-05-12 15:31:19 -04:00
William Wernert
192b5db25a
Add true to end of functions ending with shorthand comparison
...
Functions ending with test using [[ <false> ]] && <cmd> will trip set -e, so adding true to the last line of the function will prevent the function from returning a nonzero code
2021-05-12 15:26:39 -04:00
William Wernert
9ced391c11
Fix indent in main(), re-add trap, remove ERR_HANDLED variable
2021-05-12 13:20:59 -04:00
William Wernert
807b525c79
Temp remove exit on failure + bash trap
2021-05-12 11:19:33 -04:00
William Wernert
7bd04deae7
Unset exit on failure for pkill command
2021-05-12 10:45:03 -04:00
William Wernert
c379822bf0
Set variable to skip trap if error already handled
2021-05-11 12:59:49 -04:00
m0duspwnens
ad67167e97
remove whitespace control
2021-05-11 12:58:21 -04:00
m0duspwnens
4012a8276c
add template for module .yml file
2021-05-11 12:22:25 -04:00
m0duspwnens
efc028d0a5
handle the docker port bindings for filebeat modules
2021-05-10 18:08:47 -04:00
Mike Reeves
01a121e029
Add defaults.yml
2021-05-10 15:29:50 -04:00
William Wernert
f793450d97
Return actual exit code from retry
2021-05-10 13:22:13 -04:00
William Wernert
fec868432f
Try to fix bash trap
2021-05-10 11:59:22 -04:00
William Wernert
d3b08beb53
Only cat file if it exists
2021-05-10 11:11:54 -04:00
William Wernert
a75d4841d0
Add debug lines
2021-05-10 11:05:24 -04:00
William Wernert
8b3730748b
Add debug line and remove exit command on retry failure
2021-05-10 10:58:29 -04:00
William Wernert
de5552c91a
Merge branch 'dev' into issue/3220
2021-05-10 10:33:52 -04:00
m0duspwnens
a7e6dec51d
Merge remote-tracking branch 'remotes/origin/dev' into kilo
2021-05-10 09:57:50 -04:00
Josh Patterson
26335a9b42
Merge pull request #4140 from Security-Onion-Solutions/issue/3264
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-05-10 08:14:12 -04:00
William Wernert
f8dd6890b2
Unset/set exit on command fail for retries
2021-05-07 16:50:59 -04:00
m0duspwnens
1c103f92f2
Merge remote-tracking branch 'remotes/origin/issue/3264' into kilo
2021-05-07 14:48:42 -04:00
m0duspwnens
e3ce683970
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-07 14:48:16 -04:00
m0duspwnens
9eb63b17f9
exit if retry fails
2021-05-07 14:48:02 -04:00
m0duspwnens
755370eff0
Merge remote-tracking branch 'remotes/origin/dev' into kilo
2021-05-07 14:46:08 -04:00
Jason Ertel
407ad51244
Merge pull request #4139 from Security-Onion-Solutions/issue/4081
...
FEATURE: Pivot from Alerts/Hunt to CyberChef #4081
2021-05-07 13:31:21 -04:00
Doug Burks
293fb0a76d
FEATURE: Pivot from Alerts/Hunt to CyberChef #4081
2021-05-07 13:23:46 -04:00
Doug Burks
2e228c8355
FEATURE: Pivot from Alerts/Hunt to CyberChef #4081
2021-05-07 13:22:03 -04:00
m0duspwnens
009f7617c1
check salt-master is responding
2021-05-07 12:47:22 -04:00
m0duspwnens
b39c8c1f1f
exit after 50 tries if manager cant connect to iteself via salt
2021-05-07 11:02:23 -04:00
William Wernert
7b29c6427b
Add preliminary error handling in soup
2021-05-07 10:55:17 -04:00
m0duspwnens
d0e084b8ea
change command to test if salt-master is accepting connections
2021-05-07 10:20:04 -04:00
m0duspwnens
46223e0b30
add quotes around minionid
2021-05-07 08:59:47 -04:00
m0duspwnens
5d3b147b42
change retry command
2021-05-06 20:32:26 -04:00
m0duspwnens
6474c296e1
dont need to specify dest rp
2021-05-06 20:26:13 -04:00
m0duspwnens
b8ad80ae35
update comment
2021-05-06 17:49:40 -04:00
m0duspwnens
78240b4b52
change retry command
2021-05-06 17:49:02 -04:00
m0duspwnens
e7c716ede4
merge with dev, use retry to check if manager up instead of sleep in soup
2021-05-06 16:44:34 -04:00
m0duspwnens
fb986b5cff
set both log levels to error
2021-05-06 14:55:14 -04:00
m0duspwnens
a49f2e2d98
change log_level_logfile to error for /opt/so/log/salt/minion
2021-05-06 13:38:16 -04:00
Mike Reeves
90b3462ead
No recurse for you
2021-05-06 13:29:15 -04:00
m0duspwnens
da528e802f
ensure migration script doesnt migrate the current days data and fix downsample cq to move from so_short_term rp
2021-05-06 12:52:47 -04:00
Josh Brower
23b4327c28
Merge pull request #4072 from petiepooo/fix-sleep
...
fix 5-second sleep
2021-05-06 12:48:34 -04:00
Mike Reeves
1de768c182
Update HOTFIX
2021-05-06 12:02:05 -04:00
William Wernert
9f6dfa4d2e
Merge pull request #4112 from Security-Onion-Solutions/master
...
Bring hotfix changes into dev
2021-05-06 10:44:25 -04:00
Mike Reeves
96c20ea3cf
Merge pull request #4080 from Security-Onion-Solutions/hotfix2
...
GRIDFIX Hotfix
2021-05-06 10:34:17 -04:00
Wes Lambert
728d1f7540
Make Zeek and Suricata great again
2021-05-06 14:06:17 +00:00
Wes Lambert
ee92ba20b0
Add modules path reference
2021-05-06 13:56:39 +00:00
Wes Lambert
1b749cf004
Additional config
2021-05-06 13:55:07 +00:00
Wes Lambert
37929dbd7d
Add additional config for Filebeat modules
2021-05-06 13:54:28 +00:00
Wes Lambert
865ba912f8
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-05-06 13:19:31 +00:00
m0duspwnens
9dbb9f519b
create so_short_term rp as default so that autogen can just be dropped once data is downsampled
2021-05-06 09:14:49 -04:00
m0duspwnens
20188549f7
add the logic for so-influxdb-migrate
2021-05-05 19:28:16 -04:00
m0duspwnens
925be17d51
clean some commas in so-influxdb-clean
2021-05-05 15:59:18 -04:00
m0duspwnens
0ea4c99102
remove support for months as it isnt supported in InfluxQL
2021-05-05 15:32:53 -04:00
m0duspwnens
db98b7ed27
verify with user before proceedig to clean
2021-05-05 15:08:11 -04:00
m0duspwnens
44de611097
rename to so-influxdb-clean
2021-05-05 14:57:39 -04:00
m0duspwnens
a5ee8fb59d
fix the issues with so-influxdb-clear
2021-05-05 14:56:53 -04:00
m0duspwnens
e532804474
move to proper dir
2021-05-05 13:42:21 -04:00
m0duspwnens
ce24781446
first take at so-infludb-clean
2021-05-05 13:29:24 -04:00
weslambert
c867d6648a
Merge pull request #4098 from Security-Onion-Solutions/delta
...
Add ignore above for message keyword field
2021-05-05 08:53:39 -04:00
m0duspwnens
8ae5ae7e57
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-05 08:33:47 -04:00
m0duspwnens
6a639edb05
have cq created once again
2021-05-05 08:33:31 -04:00
Wes Lambert
a1a79719fc
Add ignore above for message keyword field
2021-05-05 12:07:30 +00:00
m0duspwnens
c5f99b012e
comment out creation of cq to test data migration
2021-05-04 13:58:53 -04:00
m0duspwnens
fcd1bea4a3
remove auto data migration, change duration from 0s to 0d
2021-05-04 12:06:03 -04:00
Mike Reeves
0622c77a7f
Add filebeat modules
2021-05-04 10:50:13 -04:00
Mike Reeves
8aaf3e1052
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-04 10:44:13 -04:00
m0duspwnens
3dcaa1f6fb
more logging for influxdb migration
2021-05-04 10:37:25 -04:00
m0duspwnens
2d91e509fa
update wording
2021-05-04 10:34:13 -04:00
m0duspwnens
a0f1839162
run in background
2021-05-04 09:59:16 -04:00
m0duspwnens
e2f52765e4
add newline
2021-05-04 09:34:42 -04:00
m0duspwnens
f186a3dde9
make sure user sees influxdb migration message by requiring enter to be pressed to continue
2021-05-04 09:30:38 -04:00
Mike Reeves
10c4a7fd98
Update soup
2021-05-04 09:18:59 -04:00
m0duspwnens
9b065155f4
log iunfluxdb migration to new log
2021-05-04 08:56:13 -04:00
m0duspwnens
12306368cf
add post upgrade function for 2.3.60 soup to migrate influxdb data
2021-05-04 08:37:52 -04:00
Mike Reeves
ffa9001df4
Update raid.sh
2021-05-04 07:57:07 -04:00
Mike Reeves
e113e75f4d
Update soup
2021-05-03 18:52:40 -04:00
Mike Reeves
9066959945
Update soup
2021-05-03 18:46:24 -04:00
Jason Ertel
6768e8ddf6
copy_new_files usage consistent across soup and hotfixapply scripts
2021-05-03 15:42:24 -04:00
Mike Reeves
a489b369d7
Jertel Compliance
2021-05-03 15:23:34 -04:00
Mike Reeves
074fe46e90
Adding airgap hotfix
2021-05-03 15:02:51 -04:00
Mike Reeves
f56244d708
Adding airgap hotfix
2021-05-03 14:39:32 -04:00
Mike Reeves
cedcf05751
Adding airgap hotfix
2021-05-03 14:38:18 -04:00
Mike Reeves
f04ed94627
Adding airgap hotfix
2021-05-03 14:33:45 -04:00
Mike Reeves
296c1c5a3c
Adding airgap hotfix
2021-05-03 14:30:53 -04:00
weslambert
d4e8ea8e72
Merge pull request #4079 from Security-Onion-Solutions/delta
...
Add event_data to common template so elastalert/playbook event_data f…
2021-05-03 13:45:17 -04:00
Wes Lambert
619402cc67
Add event_data to common template so elastalert/playbook event_data fields can be indexed and searchable
2021-05-03 17:03:30 +00:00
m0duspwnens
b01bfda862
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-03 11:49:09 -04:00
William Wernert
da19df5174
Merge pull request #4076 from Security-Onion-Solutions/issue/4004
...
Don't ask for node description on eval and import installs
2021-05-03 11:43:37 -04:00
William Wernert
19dd9b97d2
Don't ask for node description on eval and import installs
2021-05-03 09:40:53 -04:00
Mike Reeves
21b92ac077
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-02 13:06:29 -04:00
Pete
b80dd1ef3e
fix 5-second sleep
...
using wait here instead of sleep tries to wait until pid 5 exits and generates the error
> /usr/sbin/so-playbook-reset: line 25: wait: pid 5 is not a child of this shell
2021-04-30 20:21:50 +00:00
m0duspwnens
d6b9154a88
change how version to be installed is defined to work with centos
2021-04-30 14:48:51 -04:00
m0duspwnens
f9573f7972
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-30 13:33:47 -04:00
m0duspwnens
038cadeae8
change version to 2.3.60 to prepare to push to dev
2021-04-30 12:31:57 -04:00
m0duspwnens
e32ca284c5
ensure proper version of python3-influxdb is installed prior to running the states that require it
2021-04-30 11:10:31 -04:00
Mike Reeves
a56426010d
Merge pull request #4057 from Security-Onion-Solutions/kilo
2021-04-29 17:46:26 -04:00
Jason Ertel
dda07af4d4
Update Kibana config defaults
2021-04-29 17:44:15 -04:00
Mike Reeves
81bfb202f7
Merge pull request #4055 from Security-Onion-Solutions/kilo
2021-04-29 15:37:34 -04:00
Jason Ertel
b6561fd8e2
Update defaultRoute with new path structure
2021-04-29 15:35:22 -04:00
m0duspwnens
d475e50bef
add deps for ubuntu
2021-04-29 13:49:15 -04:00
m0duspwnens
689a01423f
fix deps
2021-04-29 13:28:31 -04:00
m0duspwnens
888d637b67
add %}
2021-04-29 13:26:24 -04:00
m0duspwnens
e7660d68cb
add %}
2021-04-29 13:25:29 -04:00
m0duspwnens
450a01784b
support installing via pip for ubuntu
2021-04-29 13:22:31 -04:00
Mike Reeves
5d8cb511be
Merge pull request #4046 from Security-Onion-Solutions/kilo
...
Switch to the ES-included community_id plugin
2021-04-29 12:11:44 -04:00
Jason Ertel
44ad8ce888
Switch to the ES-included community_id plugin
2021-04-29 12:08:07 -04:00
Jason Ertel
14572d9eab
Merge pull request #4045 from Security-Onion-Solutions/ktbackup
...
Add Grid nodeid fix and Kratos backup to include Kratos
2021-04-29 11:55:46 -04:00
Mike Reeves
76d735ff43
Add ID Fix to nodeID
2021-04-29 11:49:20 -04:00
Mike Reeves
02b621bd2c
Add Kratos to Backups
2021-04-29 11:29:07 -04:00
Mike Reeves
96eab86bc6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-29 11:19:19 -04:00
m0duspwnens
93ee96b1cd
Ignore "Status .* was not found" due to output from salt http.query or http.wait_for_successful_query states used with retry
2021-04-29 10:19:42 -04:00
m0duspwnens
907dbe6388
for for influx to be up so the reliant states dont fail
2021-04-29 08:47:33 -04:00
m0duspwnens
f8e01d5d53
let the state retry incase influxdb isnt fully up yet
2021-04-29 06:43:05 -04:00
m0duspwnens
454b541a2e
merge with dev, change version so test box doesnt try to upgrade to 2.3.60
2021-04-28 18:04:14 -04:00
m0duspwnens
2b9b22cd90
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-28 18:02:01 -04:00
m0duspwnens
5584c4f1ae
define and install the dependencies for python36-influxdb
2021-04-28 18:01:33 -04:00
Mike Reeves
9830f661c8
Merge pull request #4031 from Security-Onion-Solutions/kilo
...
Remove unused and incorrectly formatted osraid metric
2021-04-28 13:34:57 -04:00
Jason Ertel
7a21c44727
Remove unused and incorrectly formatted osraid metric
2021-04-28 13:27:11 -04:00
Mike Reeves
4c55e5a6cc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-28 10:27:55 -04:00
Mike Reeves
f0012015e6
Merge pull request #4018 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update raid.sh
2021-04-28 10:27:35 -04:00
Mike Reeves
14557983e1
Update raid.sh
2021-04-28 10:24:39 -04:00
Jason Ertel
865e5cb120
Merge pull request #4017 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2021-04-28 10:19:07 -04:00
m0duspwnens
d9cb018a7d
merge with dev, resolve conflicts
2021-04-28 10:19:01 -04:00
Mike Reeves
8dd9564171
Update VERSION
2021-04-28 10:17:37 -04:00
Mike Reeves
153394356b
Merge pull request #4003 from Security-Onion-Solutions/dev
...
2.3.50
2021-04-28 10:11:53 -04:00
Mike Reeves
bd454c7f25
Merge pull request #4016 from Security-Onion-Solutions/2350
...
Repo Fix
2021-04-27 16:02:15 -04:00
Mike Reeves
b6792f73e0
Repo Fix
2021-04-27 15:51:30 -04:00
Mike Reeves
03774e6270
Repo Fix
2021-04-27 15:46:45 -04:00
Mike Reeves
77533f7873
Repo Fix
2021-04-27 15:45:35 -04:00
Mike Reeves
a6b2eefee1
Prompt airgap to update
2021-04-27 15:33:52 -04:00
Mike Reeves
4cea08c080
Prompt airgap to update
2021-04-27 15:32:00 -04:00
Mike Reeves
b23902fc2c
Merge pull request #4015 from Security-Onion-Solutions/importfix
...
Update import install
2021-04-27 13:38:31 -04:00
Mike Reeves
458c386377
Update import install
2021-04-27 13:37:37 -04:00
Mike Reeves
79984f4808
Merge pull request #4007 from Security-Onion-Solutions/2350
...
Repo Fix
2021-04-26 16:40:28 -04:00
Mike Reeves
167e656abb
Repo Fix
2021-04-26 16:38:12 -04:00
Josh Patterson
f2b1b9a073
Merge pull request #4006 from Security-Onion-Solutions/2350
...
Prompt airgap to update
2021-04-26 15:38:23 -04:00
Mike Reeves
939414aef6
Prompt airgap to update
2021-04-26 15:36:56 -04:00
Josh Patterson
6a956702df
Merge pull request #4005 from Security-Onion-Solutions/2350
...
Repo Fix
2021-04-26 14:52:00 -04:00
Mike Reeves
df22269fc9
Repo Fix
2021-04-26 14:49:44 -04:00
Mike Reeves
d36237ee87
Merge pull request #4002 from Security-Onion-Solutions/2350
...
2.3.50 sig files
2021-04-26 09:32:10 -04:00
Mike Reeves
0499b141ed
2.3.50 sig files
2021-04-26 09:20:03 -04:00
Mike Reeves
d56e66917a
2.3.50 sig files
2021-04-26 09:18:15 -04:00
Mike Reeves
0654c6511a
Merge pull request #4001 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update README.md
2021-04-26 09:10:56 -04:00
Mike Reeves
bbe2f81cb6
Update README.md
2021-04-26 08:53:58 -04:00
Jason Ertel
33bdd96221
Merge pull request #3996 from Security-Onion-Solutions/updateag
...
Prompt airgap to update
2021-04-25 12:25:45 -04:00
Mike Reeves
6135d89721
Prompt airgap to update
2021-04-25 12:19:34 -04:00
Mike Reeves
abbe0ec819
Merge pull request #3995 from Security-Onion-Solutions/updateag
...
Fix updates for airgap
2021-04-25 11:26:20 -04:00
Mike Reeves
4d0b06dfc7
Fix updates for airgap
2021-04-25 11:01:21 -04:00
Mike Reeves
0505664b84
Merge pull request #3987 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Prime the CentOS Repos
2021-04-23 12:11:01 -04:00
Mike Reeves
f2628f2e5b
Prime the CentOS Repos
2021-04-23 12:09:41 -04:00
Mike Reeves
fcaabaade0
Merge pull request #3986 from Security-Onion-Solutions/grafanaeps
...
remove eps graph from manager and update to consumptioneps for standalone and managersearch
2021-04-23 12:08:06 -04:00
m0duspwnens
fff12b423a
remove eps graph from manager and update to consumptioneps for standalone and managersearch
2021-04-23 11:56:27 -04:00
Jason Ertel
b81ac6b7bd
Merge pull request #3983 from Security-Onion-Solutions/kilo
...
Update MOTD with training link and simplify customization commands
2021-04-23 11:03:57 -04:00
Jason Ertel
f4606828c7
Update MOTD with training link and simply customization commands
2021-04-23 10:42:14 -04:00
Josh Patterson
4e2ffbf5e5
Merge pull request #3971 from Security-Onion-Solutions/issue/3501
...
let remote nodes upgrade on their own time
2021-04-22 16:35:26 -04:00
m0duspwnens
7c7624c87e
let remote nodes upgrade on their own time
2021-04-22 16:32:58 -04:00
Josh Patterson
7da091375e
Merge pull request #3968 from Security-Onion-Solutions/issue/3501
...
Issue/3501
2021-04-22 15:37:59 -04:00
m0duspwnens
4f545eefc2
update preflight
2021-04-22 15:27:57 -04:00
m0duspwnens
90683a7e04
fix UPDATE_DIR var
2021-04-22 15:22:55 -04:00
m0duspwnens
36bc4f4aa8
remove by package name not wildcard
2021-04-22 15:21:36 -04:00
Mike Reeves
694c3b87fe
Merge pull request #3967 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2021-04-22 14:18:46 -04:00
Mike Reeves
e7d3369cef
Update soup
2021-04-22 14:17:38 -04:00
Josh Patterson
fb6fa789b7
Merge pull request #3965 from Security-Onion-Solutions/soversion2
...
Soversion2
2021-04-22 13:45:56 -04:00
Mike Reeves
b7c6110e57
sync soversion
2021-04-22 13:41:58 -04:00
Mike Reeves
93148e4adc
sync soversion
2021-04-22 13:39:33 -04:00
Mike Reeves
016837df28
sync soversion
2021-04-22 13:36:52 -04:00
Mike Reeves
4b78b114f7
Merge pull request #3964 from Security-Onion-Solutions/fix/so-playbook-sync
...
Fix so-playbook-sync
2021-04-22 13:28:25 -04:00
Josh Brower
94352c212f
Fix so-playbook-sync
2021-04-22 13:26:41 -04:00
Mike Reeves
3a65f7875e
Merge pull request #3963 from Security-Onion-Solutions/fixsaltsoup
...
fix SALTNOTHELD for salt.minion
2021-04-22 13:25:05 -04:00
m0duspwnens
781ac0293c
fix SALTNOTHELD for salt.minion
2021-04-22 13:22:08 -04:00
Mike Reeves
a93b75af05
Merge pull request #3962 from Security-Onion-Solutions/fixsaltsoup
...
Fixsaltsoup
2021-04-22 11:52:05 -04:00
m0duspwnens
a49d6a8d5c
apply highstate to minions instead of just salt.minion for soup if salt needs upgraded
2021-04-22 11:47:53 -04:00
m0duspwnens
440c546bb4
remove docker-ce.repo
2021-04-22 11:41:14 -04:00
Mike Reeves
8c67ec5316
Merge pull request #3961 from Security-Onion-Solutions/fix/extra-paren
...
Remove extra paren
2021-04-22 11:27:16 -04:00
William Wernert
41a5818bb7
Remove extra paren
2021-04-22 11:26:15 -04:00
Mike Reeves
ee48bb9b2a
Merge pull request #3959 from Security-Onion-Solutions/fix/zeekpillar
...
Fix Zeek Setting for close-delete
2021-04-22 10:55:46 -04:00
Mike Reeves
a41c40ccbb
Fix Zeek Setting for close-delete
2021-04-22 10:53:59 -04:00
Mike Reeves
3d65135993
Merge pull request #3954 from Security-Onion-Solutions/feature/vim
...
Make sure VIM is installed with correct settings
2021-04-22 09:52:02 -04:00
Mike Reeves
9ba7beed95
Merge pull request #3957 from Security-Onion-Solutions/fix/yum-conf
...
Add support for legacy grids
2021-04-22 09:44:51 -04:00
William Wernert
7176a4214b
Add support for legacy grids
2021-04-22 09:42:39 -04:00
Josh Brower
8f37b6b73b
Make sure VIM is installed with correct settings
2021-04-22 09:35:42 -04:00
Josh Patterson
f0e9b09d8f
Merge pull request #3951 from Security-Onion-Solutions/issue/3948
...
fix salt retries
2021-04-22 08:50:14 -04:00
Mike Reeves
0bfe2aa6b6
Merge pull request #3950 from Security-Onion-Solutions/fix/correct-pillar
...
Use correct pillar value in yum.conf template
2021-04-22 08:40:09 -04:00
William Wernert
1519936e44
Use correct pillar value in yum.conf template
2021-04-22 08:37:49 -04:00
m0duspwnens
1d8e065902
fix salt retries - https://github.com/Security-Onion-Solutions/securityonion/issues/3948
2021-04-22 08:35:50 -04:00
Josh Patterson
fb3b4dc44a
Merge pull request #3949 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Roll back cluster changes
2021-04-22 08:29:13 -04:00
Mike Reeves
fae72aa243
Roll back cluster changes
2021-04-22 08:25:01 -04:00
m0duspwnens
28982e0e0b
fix requirement
2021-04-21 19:22:07 -04:00
m0duspwnens
1fbf77d090
fix state name
2021-04-21 18:53:00 -04:00
Mike Reeves
81581711da
Merge pull request #3940 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-04-21 18:44:37 -04:00
m0duspwnens
6c8a2e68d9
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-21 18:24:07 -04:00
m0duspwnens
f5ddb084b6
create salt.helper-packages state, use it to install the patch package
2021-04-21 18:22:44 -04:00
m0duspwnens
21077ef26e
undo path change
2021-04-21 18:09:11 -04:00
m0duspwnens
5cedf98f55
change path
2021-04-21 18:05:52 -04:00
Mike Reeves
0a2d44131b
Merge pull request #3939 from Security-Onion-Solutions/soupmkr
...
send suricata compress to dev/null
2021-04-21 18:00:03 -04:00
William Wernert
c297031f6b
Surround scalar in single quotes
2021-04-21 17:58:13 -04:00
William Wernert
071e5166b4
Set package manager source in patch pillar for yum.conf
2021-04-21 17:57:02 -04:00
Mike Reeves
c337be8f4f
send suricata compress to dev/null
2021-04-21 17:27:52 -04:00
Josh Patterson
22a7729fcf
Merge pull request #3938 from Security-Onion-Solutions/soupmkr
...
soup will now ask to update packages
2021-04-21 17:20:18 -04:00
m0duspwnens
a7247e9812
update package name
2021-04-21 17:17:49 -04:00
m0duspwnens
c9298137b5
adding docker-ce.repo to delete list
2021-04-21 17:08:35 -04:00
m0duspwnens
17c95723ec
update package name
2021-04-21 16:44:40 -04:00
Mike Reeves
fa972ea110
soup will now ask to update packages
2021-04-21 16:37:13 -04:00
William Wernert
261e7f7fd9
sed and grep need input files
2021-04-21 16:29:24 -04:00
Mike Reeves
b5b0c262c1
soup will now ask to update packages
2021-04-21 16:25:41 -04:00
William Wernert
c1ae7ff3b6
Set proxy, replace when setting up yum for manager proxy
2021-04-21 16:18:20 -04:00
Mike Reeves
5c4be5e1cd
soup will now ask to update packages
2021-04-21 16:15:40 -04:00
William Wernert
f3d663f090
Don't set yum/apt proxy if updating through manager
2021-04-21 15:59:37 -04:00
Mike Reeves
73001713e3
soup will now ask to update packages
2021-04-21 15:51:28 -04:00
Mike Reeves
13ad07cd88
soup will now ask to update packages
2021-04-21 15:41:58 -04:00
Mike Reeves
7335611166
soup will now ask to update packages
2021-04-21 15:35:05 -04:00
William Wernert
d5717b7011
Merge branch 'dev' into foxtrot
2021-04-21 14:45:11 -04:00
Josh Patterson
df2420f6fe
Merge pull request #3936 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Fix Security onion repo
2021-04-21 14:44:50 -04:00
Mike Reeves
06ccad334b
Fix Security
2021-04-21 14:43:15 -04:00
Mike Reeves
dd1fff59d7
Merge pull request #3934 from bryant-treacle/Issue-#3926
...
Update threading.map.jinja
2021-04-21 12:22:16 -04:00
William Wernert
428be2b8ad
Merge pull request #3935 from Security-Onion-Solutions/fix/manager-check
...
Fix salt-master check
2021-04-21 12:10:14 -04:00
m0duspwnens
1f654d4444
fix the state apply
2021-04-21 12:04:58 -04:00
William Wernert
075ba0d83b
Fix salt-master check
2021-04-21 12:01:21 -04:00
bryant-treacle
f14df24ddc
Update threading.map.jinja
2021-04-21 11:49:29 -04:00
m0duspwnens
0a01d7b041
fix var
2021-04-21 11:14:13 -04:00
m0duspwnens
b53017ee87
ensure salt python modules are installed and patched during soup
2021-04-21 10:44:46 -04:00
William Wernert
b618207f51
Merge branch 'dev' into foxtrot
2021-04-21 10:23:10 -04:00
m0duspwnens
af86a9dac0
handle different paths for salt states/modules based on os
2021-04-21 09:52:22 -04:00
m0duspwnens
d792c65ce3
change how influx is patch and python3-influxdb is installed
2021-04-21 09:25:25 -04:00
m0duspwnens
8eef574342
install python3-influxdb and create requires
2021-04-21 08:28:01 -04:00
m0duspwnens
2d0594398c
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-20 15:53:34 -04:00
Josh Patterson
86e7c0f87d
Merge pull request #3927 from Security-Onion-Solutions/telefix1
...
Add Security Onion Repo
2021-04-20 15:47:28 -04:00
Mike Reeves
cc4c092301
Add Security Onion Repo
2021-04-20 15:44:35 -04:00
William Wernert
3f007f1026
Disable fastestmirror during setup + soup
2021-04-20 15:18:06 -04:00
William Wernert
3d90423495
Fix summary message to preserve empty line
2021-04-20 14:44:58 -04:00
William Wernert
113e558a05
Set manager early for proxy config
2021-04-20 14:32:17 -04:00
William Wernert
ca9ac46cd2
Add keypress instruction at end of summary
2021-04-20 13:27:52 -04:00
William Wernert
95bb757b03
Fix salt-master check
2021-04-20 13:12:55 -04:00
William Wernert
369c0b43f5
Further jinja fixes
2021-04-20 12:55:23 -04:00
William Wernert
cd0a115ac7
Fix acng config and don't show changes when proxy string can exist in file
2021-04-20 12:55:00 -04:00
William Wernert
bbf16d0f11
Show airgap prompt within if statement + persist variable for node installs
2021-04-20 11:34:17 -04:00
m0duspwnens
115764ae38
merge with dev and fix merge conflict in so-functions https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-20 10:03:15 -04:00
Mike Reeves
3b203b9a31
Merge pull request #3922 from Security-Onion-Solutions/telefix1
...
Adjust sostatus timers
2021-04-20 08:14:34 -04:00
Mike Reeves
5072c24134
Adjust sostatus timers
2021-04-20 08:12:44 -04:00
William Wernert
b449955711
Proxy whiptail fixes
...
* Don't try to set up proxy/manager proxy during network only flow
* Fix logic to never show new menu on airgap, set MANAGERUPDATES to 1 on airgap minions
2021-04-19 16:26:53 -04:00
Mike Reeves
e9b86388da
Merge pull request #3912 from Security-Onion-Solutions/telefix1
...
Change telegraf scripts to new method of process detection
2021-04-19 14:40:06 -04:00
Mike Reeves
be6933e8fb
Change EPS for Telegraf
2021-04-19 14:20:00 -04:00
William Wernert
6156e754c4
Merge branch 'dev' into foxtrot
2021-04-19 14:15:23 -04:00
William Wernert
d2067a42bd
Don't skip new menu on airgap minions
2021-04-19 14:12:53 -04:00
William Wernert
b37da027fd
ECDSA to ED25519
2021-04-19 14:08:25 -04:00
William Wernert
d8457255cb
n -> z
2021-04-19 14:06:10 -04:00
William Wernert
7948906f51
Fix minion airgap logic
2021-04-19 14:04:01 -04:00
William Wernert
ba9a45bd0f
Split network init + ssh copy notices
2021-04-19 14:02:00 -04:00
William Wernert
07e0ce563d
Symmetrical spaces + remove useless logic
2021-04-19 13:50:30 -04:00
William Wernert
002fa99055
Fix whiptail order
2021-04-19 13:47:50 -04:00
William Wernert
59247b4579
Add exit check to new menu
2021-04-19 13:45:01 -04:00
Josh Patterson
a70b631b2c
Merge pull request #3911 from Security-Onion-Solutions/issue/3501
...
Issue/3501
2021-04-19 13:43:34 -04:00
Mike Reeves
0c0edbaac8
Change EPS for Telegraf
2021-04-19 13:29:46 -04:00
Mike Reeves
54322f5e9d
Change EPS for Telegraf
2021-04-19 13:17:02 -04:00
Mike Reeves
f5b0411772
Change EPS for Telegraf
2021-04-19 13:11:19 -04:00
Mike Reeves
31f193c397
Change EPS for Telegraf
2021-04-19 12:36:46 -04:00
William Wernert
c907d416df
Set proxy for apt cacher too
2021-04-19 11:27:17 -04:00
William Wernert
e8553162a5
[refactor] Change how whiptail asks for proxy settings
2021-04-19 10:51:39 -04:00
Mike Reeves
af7b6af32f
Merge pull request #3901 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix beat script location
2021-04-19 09:44:59 -04:00
m0duspwnens
9e57fd2df0
cant pipe to grep without , python_shell=True
2021-04-19 09:00:30 -04:00
Mike Reeves
ef0669aabb
Fix beat script location
2021-04-17 18:24:33 -04:00
William Wernert
58febe7955
[fix] so-docker-prune breaks when multiple "so-" images share a version
2021-04-16 16:04:07 -04:00
m0duspwnens
1b15f01874
fix salt.master state
2021-04-16 13:09:01 -04:00
m0duspwnens
24b263c812
only hold/unhold packages if not already unheld/held
2021-04-16 11:37:18 -04:00
m0duspwnens
9d676efada
move salt_minion_service state outside jinja if
2021-04-15 12:45:34 -04:00
m0duspwnens
9d01387a04
remove references to the common salt package
2021-04-15 11:57:25 -04:00
m0duspwnens
22edbcc111
can use SPLITCHAR before defined
2021-04-15 11:29:01 -04:00
m0duspwnens
2f198ed9fb
change how salt is held and unheld from updates
2021-04-15 09:42:00 -04:00
weslambert
427dd31fcb
Merge pull request #3876 from Security-Onion-Solutions/delta
...
FIX:Remove ESUSER/ESPASS for now to prevent issues with attempting Elasti…
2021-04-15 08:11:15 -04:00
Wes Lambert
f61bf73f97
Remove ESUSER/ESPASS for now to prevent issues with attempting Elastic Auth when connecting to ES.
2021-04-15 11:59:34 +00:00
Josh Patterson
923d50d91e
Merge pull request #3875 from Security-Onion-Solutions/issue/3543
...
add delay for salt-minion service starting
2021-04-14 16:34:21 -04:00
m0duspwnens
71d7ca8958
only manage service file if the right salt version is installed
2021-04-14 15:48:33 -04:00
m0duspwnens
d42cd52ae1
Merge remote-tracking branch 'remotes/origin/dev' into issue/3543
2021-04-14 15:23:51 -04:00
Mike Reeves
f177819e4f
Merge pull request #3871 from Security-Onion-Solutions/beatstats
...
Beatstats
2021-04-14 15:03:13 -04:00
m0duspwnens
f60da54ff0
remove extra lines at end
2021-04-14 11:11:13 -04:00
m0duspwnens
d003d4941b
fix bad typing
2021-04-14 11:10:19 -04:00
m0duspwnens
48c531bc2c
fix file defaults def
2021-04-14 11:09:13 -04:00
m0duspwnens
47aa66876d
fix import
2021-04-14 11:07:16 -04:00
m0duspwnens
9bfdae9cd5
fix import
2021-04-14 11:06:06 -04:00
m0duspwnens
a50b3e8475
add delay to salt-minion service starting - https://github.com/Security-Onion-Solutions/securityonion/issues/3543
2021-04-14 10:22:06 -04:00
Mike Reeves
6fc7ed1a25
Add telegraf scripts to track eps and failures for beats
2021-04-13 20:51:27 -04:00
Mike Reeves
904d34977f
Add telegraf scripts to track eps and failures for beats
2021-04-13 20:48:53 -04:00
Mike Reeves
aa66b6226f
Add hostname to the listener
2021-04-13 20:22:51 -04:00
Mike Reeves
db7dcd76cd
Add hostname to the listener
2021-04-13 20:21:32 -04:00
Mike Reeves
7153f58a03
Add Firewall for Beats port
2021-04-13 20:17:26 -04:00
Mike Reeves
621e5c1cf8
Enable Filebeat Stats
2021-04-13 19:18:10 -04:00
Mike Reeves
26547f4e96
Merge pull request #3864 from Security-Onion-Solutions/agauto
...
Fix Airgap Automation
2021-04-13 15:36:08 -04:00
Mike Reeves
989c2b23b1
Fix Airgap Automation
2021-04-13 15:34:03 -04:00
Josh Patterson
e16875da0c
Merge pull request #3855 from Security-Onion-Solutions/salt3003
...
Salt3003
2021-04-13 13:23:21 -04:00
Josh Brower
2b06223d7c
Merge pull request #3856 from Security-Onion-Solutions/feature/osquery-ingest-timestamp
...
Differentiate between event & ingest timestamp
2021-04-13 13:00:52 -04:00
Josh Brower
7cbeed985a
Differentiate between event & ingest timestamp
2021-04-13 12:55:40 -04:00
m0duspwnens
78ff84f968
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-13 12:05:58 -04:00
m0duspwnens
eb94c011e2
update location of yum keys and repo files for setup
2021-04-13 11:15:15 -04:00
m0duspwnens
325264dafd
point to new repo location
2021-04-12 17:44:50 -04:00
William Wernert
2392c0e2d4
Merge pull request #3846 from Security-Onion-Solutions/foxtrot
...
Setup changes/fixes
2021-04-12 16:39:08 -04:00
m0duspwnens
eb7bf58f30
fix issues with repo.client state
2021-04-12 16:33:32 -04:00
William Wernert
9d09e7bec3
Fix sostatus log cron job
2021-04-12 16:25:17 -04:00
William Wernert
25637b74db
Add back removed testing skip
2021-04-12 16:14:47 -04:00
William Wernert
cc344d921a
Skip whiptail during testing, echo error message to setup log
2021-04-12 16:13:32 -04:00
Josh Brower
2fa01c9386
Merge pull request #3845 from Security-Onion-Solutions/fix/wazuh-wel-alerts
...
Fix Wazuh WEL Shipping
2021-04-12 15:22:57 -04:00
Josh Brower
cf4de255ec
Fix Wazuh WEL Shipping
2021-04-12 15:18:18 -04:00
m0duspwnens
9240d376f3
combine client repo management into 1 state
2021-04-12 14:31:41 -04:00
William Wernert
8cb4a75eb1
Merge branch 'dev' into feature/setup-check-manager
2021-04-12 13:14:51 -04:00
William Wernert
73a1bdd885
Send stdout to log, and actually populate error message
2021-04-12 12:59:45 -04:00
William Wernert
5d98c896a3
/opt/so/log needs 755 permissions for soremote to read sostatus log
2021-04-12 12:53:17 -04:00
Mike Reeves
03abf4d4ee
Merge pull request #3828 from Security-Onion-Solutions/kilo
...
Do not set influxdb hostUrl if import node since import nodes don't r…
2021-04-09 21:43:25 -04:00
Jason Ertel
8facbcf18c
Do not set influxdb hostUrl if import node since import nodes don't run influxdb
2021-04-09 20:40:44 -04:00
Jason Ertel
280958e298
Merge pull request #3826 from Security-Onion-Solutions/kilo
...
Add raid/process status to Grid
2021-04-09 16:33:14 -04:00
Jason Ertel
5cb73ced36
Add Influx module to SOC config
2021-04-09 14:58:15 -04:00
Jason Ertel
21d922c640
Merge branch 'dev' into kilo
2021-04-09 10:24:27 -04:00
William Wernert
4db20a00ff
Add quotes around description, since it can contain spaces
2021-04-09 10:16:19 -04:00
William Wernert
026ce76966
Change airgap prompt to menu
2021-04-09 10:11:00 -04:00
William Wernert
764307bfa0
Reformat airgap whiptail prompt
2021-04-09 10:09:28 -04:00
William Wernert
fc9df2bbae
Update airgap question to ask during minion installs too
2021-04-09 10:00:50 -04:00
William Wernert
9b5276f1ab
Remove bad || statement
2021-04-09 09:59:54 -04:00
William Wernert
b2fcd438c2
Initial support for checking state of manager during setup
2021-04-09 09:39:33 -04:00
m0duspwnens
ecda46c04b
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-09 09:37:35 -04:00
Josh Patterson
69ad3ad491
Merge pull request #3817 from Security-Onion-Solutions/saltver
...
Do not upgrade salt on ISO installs
2021-04-09 08:50:08 -04:00
Mike Reeves
c9feda1168
Do not upgrade salt on ISO installs
2021-04-09 08:48:29 -04:00
Jason Ertel
d5bc7ec627
Merge branch 'dev' into kilo
2021-04-08 18:43:37 -04:00
m0duspwnens
6650ad5cdd
make the -r for all
2021-04-08 14:04:30 -04:00
William Wernert
0ea57b4848
Merge pull request #3805 from Security-Onion-Solutions/foxtrot
...
Setup option summary + proxy test fix
2021-04-08 12:00:23 -04:00
Mike Reeves
ea9103ad53
Merge pull request #3806 from Security-Onion-Solutions/saltfix
...
Fix Telegraf sostatus
2021-04-08 11:51:24 -04:00
Mike Reeves
b53815d04a
Fix Telegraf sostatus
2021-04-08 11:42:41 -04:00
Jason Ertel
5ef336fed2
Merge branch 'dev' into kilo
2021-04-08 11:23:07 -04:00
Jason Ertel
f7f95b6c54
Add model to sensoroni agent config
2021-04-08 11:22:54 -04:00
Mike Reeves
28666e0db2
Merge pull request #3804 from Security-Onion-Solutions/saltfix
...
Fix Repos by forcing removal
2021-04-08 11:08:35 -04:00
Mike Reeves
09b14e6a86
Fix Repo Logic
2021-04-08 10:38:50 -04:00
Mike Reeves
4c5f373ffa
Fix Repo Logic
2021-04-08 10:37:44 -04:00
Mike Reeves
fdaf251ba0
Fix Repo Logic
2021-04-08 10:36:52 -04:00
Mike Reeves
951369c2d6
Fix Repo Logic
2021-04-08 10:25:36 -04:00
Mike Reeves
ce9f781d81
Fix Repo Logic
2021-04-08 10:24:04 -04:00
Mike Reeves
725320ebc8
Fix Repo Logic
2021-04-08 10:02:11 -04:00
m0duspwnens
dce476b604
change back to saltstack3003 repo
2021-04-08 09:54:41 -04:00
Mike Reeves
b609f250c3
Merge pull request #3798 from Security-Onion-Solutions/saltfix
...
Fix so repo for salt
2021-04-08 08:48:57 -04:00
Mike Reeves
d4a3bc4550
Fix so repo for salt
2021-04-08 08:43:20 -04:00
William Wernert
a5f5888913
Summary order change
2021-04-07 17:03:08 -04:00
Mike Reeves
9a7a7a3b12
Merge pull request #3795 from Security-Onion-Solutions/telemetric
...
Add raid bind
2021-04-07 16:33:14 -04:00
Mike Reeves
3caaf06820
Add sostatus for telegraf
2021-04-07 16:30:16 -04:00
Mike Reeves
8ab4dd10d4
Add sostatus for telegraf
2021-04-07 16:29:44 -04:00
Mike Reeves
9baa9767ca
Add raid bind
2021-04-07 16:12:51 -04:00
William Wernert
3c69c0c24c
Correct patch schedule name logic in summary
2021-04-07 14:15:02 -04:00
William Wernert
3a4cf8aa26
Add proxy url/user to summary
2021-04-07 13:54:01 -04:00
m0duspwnens
c4f0119276
fix check if repo file exists
2021-04-07 13:51:40 -04:00
William Wernert
ec076bba4a
MTU is not always set by the user, so don't always show in summary
2021-04-07 13:42:18 -04:00
William Wernert
f83ac5a278
Print install summary to file and setup log after user confirms
2021-04-07 13:38:47 -04:00
m0duspwnens
425e5bc4c3
add some quotes
2021-04-07 13:31:43 -04:00
William Wernert
5e5df4d65a
Merge branch 'feature/setup-end-screen' into foxtrot
2021-04-07 13:23:45 -04:00
William Wernert
377b14ccb1
ESCLUSTERNAME is empty for standalone, so check if it's set before listing
2021-04-07 13:20:55 -04:00
William Wernert
ceb1ea61dc
Summary screen changes
2021-04-07 13:15:49 -04:00
m0duspwnens
249fa06fc7
echo when performing the repo actions for 2.3.50
2021-04-07 13:03:27 -04:00
m0duspwnens
5578206bf1
need to make the repo changes before we try to upgrade sa;t
2021-04-07 12:41:01 -04:00
Josh Patterson
ceb4d4ace4
Merge pull request #3790 from Security-Onion-Solutions/airgapfix
...
Fix Logic for Airgap distributed
2021-04-07 12:37:11 -04:00
Mike Reeves
c8c1553247
Fix Logic for Airgap distributed
2021-04-07 12:36:50 -04:00
Mike Reeves
ed0cd97de5
Fix Logic for Airgap distributed
2021-04-07 12:34:23 -04:00
m0duspwnens
b7aa9ddaa3
run preupgrade changes if 2.3.40
2021-04-07 11:37:55 -04:00
m0duspwnens
54e0394776
change from saltstack3003 to just saltstack for repo
2021-04-07 10:57:09 -04:00
m0duspwnens
080ecba8e6
change delrepos
2021-04-07 10:54:46 -04:00
William Wernert
5b3014496b
Proxy fixes
...
* Adjust proxy test timeout
* Don't show proxy on error
* Add echo statement so user knows what setup is doing
2021-04-07 10:35:59 -04:00
Mike Reeves
95b440de43
Merge pull request #3783 from Security-Onion-Solutions/airgapfix
...
Fix Logic for Airgap distributed
2021-04-07 10:18:07 -04:00
William Wernert
88c565feae
Fix proxy test logic
2021-04-07 10:14:16 -04:00
Mike Reeves
5cd7d65b3f
Fix Logic for Airgap distributed
2021-04-07 10:03:33 -04:00
m0duspwnens
8f208728dd
change delete repos
2021-04-07 09:10:16 -04:00
William Wernert
099ac2ff19
Minor formatting changes to whiptail end screen
2021-04-07 09:06:22 -04:00
Jason Ertel
fb02a10bfb
Merge pull request #3781 from Security-Onion-Solutions/waagent
...
Detect if running in an Azure VM
2021-04-07 08:35:36 -04:00
Jason Ertel
ee079f1132
Merge from dev
2021-04-07 08:09:24 -04:00
m0duspwnens
9b19f93ad0
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 16:46:12 -04:00
Mike Reeves
6f7e6cee80
Force it
2021-04-06 16:43:42 -04:00
m0duspwnens
a95ead1ec8
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 16:31:16 -04:00
Mike Reeves
51bf988d31
Add .repo extension
2021-04-06 16:21:19 -04:00
m0duspwnens
73e00dbe30
change salt upgrade in soup
2021-04-06 16:07:08 -04:00
m0duspwnens
f522799b36
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 15:58:21 -04:00
Mike Reeves
b50700114c
Add the do
2021-04-06 15:58:08 -04:00
m0duspwnens
9c7309797a
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 15:48:36 -04:00
Mike Reeves
92768ecd08
Add upgrade function
2021-04-06 15:47:50 -04:00
Mike Reeves
af6403f874
soup salt and repos ohh my
2021-04-06 15:45:05 -04:00
William Wernert
6d6829ba34
Remove duplicate variable assignment
2021-04-06 13:21:07 -04:00
William Wernert
b70d9c0892
Add end summary and warning about SSH host key change
2021-04-06 13:20:56 -04:00
m0duspwnens
80509fbbc6
fix -R repo option
2021-04-06 12:23:11 -04:00
m0duspwnens
914a01e321
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-06 12:02:22 -04:00
m0duspwnens
6da84c7c87
strip trailing /
2021-04-06 12:00:36 -04:00
m0duspwnens
521dbbd90a
change repo path
2021-04-06 11:45:59 -04:00
m0duspwnens
01f95c846c
remove trailing /
2021-04-06 11:41:06 -04:00
m0duspwnens
049001d572
set repo url for salt upgrade for centos
2021-04-06 09:48:21 -04:00
m0duspwnens
1ea0be0097
remove references to 3003.1 change to 3003
2021-04-06 09:15:22 -04:00
William Wernert
b6dba26e2c
Merge pull request #3767 from Security-Onion-Solutions/foxtrot
...
Move function call using nmcli to prevent error during setup
2021-04-06 09:11:23 -04:00
m0duspwnens
5525b9e97d
point to new salt repo
2021-04-06 08:30:57 -04:00
Jason Ertel
919eec497d
Merge branch 'dev' into waagent
2021-04-05 20:19:30 -04:00
Josh Patterson
8dc915e965
Merge pull request #3770 from Security-Onion-Solutions/newrepo
...
Fix Spelling issue
2021-04-05 18:53:19 -04:00
Mike Reeves
168d0bcaf4
Fix Spelling issue
2021-04-05 18:30:07 -04:00
Mike Reeves
08a857239c
Merge pull request #3769 from Security-Onion-Solutions/newrepo
...
Add some manager logic
2021-04-05 17:50:05 -04:00
Mike Reeves
a38015bd98
Add some manager logic
2021-04-05 17:28:04 -04:00
m0duspwnens
3a1c478d9a
compare the new var
2021-04-05 16:56:34 -04:00
Jason Ertel
5f6770925d
speculative commit
2021-04-05 16:52:12 -04:00
m0duspwnens
89f72bb6ed
check if . in new version, append .1 if not
2021-04-05 16:44:51 -04:00
Jason Ertel
4d9f928aed
Merge branch 'dev' into kilo
2021-04-05 15:57:59 -04:00
m0duspwnens
83bf709290
use -r for salt boostrap in soup as well
2021-04-05 15:12:53 -04:00
Mike Reeves
d62ab60d48
Merge pull request #3768 from Security-Onion-Solutions/newrepo
...
Newrepo
2021-04-05 15:03:44 -04:00
Mike Reeves
fc88634159
Set the Repo for airgap during install
2021-04-05 15:01:21 -04:00
m0duspwnens
ae83fa61f3
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-05 14:36:21 -04:00
Josh Patterson
3adc2a8e63
Merge pull request #3766 from Security-Onion-Solutions/newrepo
...
Newrepo
2021-04-05 14:35:46 -04:00
Mike Reeves
97503bc35d
Merge pull request #3761 from Security-Onion-Solutions/newraid
...
Newraid
2021-04-05 14:31:51 -04:00
m0duspwnens
9b8b5e6173
use -r by default to disable salt bootstrap from doing repo things
2021-04-05 14:12:24 -04:00
m0duspwnens
ba3c65d49f
Merge remote-tracking branch 'remotes/origin/issue/3501' into salt3003.1
2021-04-05 12:52:48 -04:00
William Wernert
1dc45541eb
Merge branch 'dev' into foxtrot
2021-04-05 12:41:08 -04:00
William Wernert
6f784565d4
Merge branch 'fix/nmcli-ami-error' into foxtrot
2021-04-05 12:41:02 -04:00
William Wernert
c864936c15
Merge pull request #3762 from Security-Onion-Solutions/foxtrot
...
Refactor so-ssh-harden
2021-04-05 12:39:51 -04:00
Mike Reeves
a824813cdb
Add model to sensoroni config
2021-04-05 12:10:29 -04:00
Mike Reeves
bad22ab541
Add model to sensoroni config
2021-04-05 12:08:38 -04:00
Mike Reeves
f41ee1457b
Merge pull request #3755 from Security-Onion-Solutions/issue/3753
...
FIX: Hunt query for HTTP EXE downloads should work for both Zeek and …
2021-04-05 11:42:45 -04:00
Mike Reeves
5aefa2a024
Fix Raid for Jertel compliance
2021-04-05 11:41:19 -04:00
Mike Reeves
f9dc040c7f
Fix Raid
2021-04-05 11:38:39 -04:00
m0duspwnens
1c3a7094bd
upgrade salt to 3003.1
2021-04-05 11:05:48 -04:00
Mike Reeves
d43cb3e133
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-04-05 10:48:01 -04:00
m0duspwnens
534dbf9761
change the upgrade command - https://github.com/Security-Onion-Solutions/securityonion/issues/3501
2021-04-05 09:07:00 -04:00
Doug Burks
8ca0626387
FIX: Hunt query for HTTP EXE downloads should work for both Zeek and Suricata #3753
2021-04-05 06:55:40 -04:00
Jason Ertel
e430be1017
Enable Flux compatibility mode to prepare for eventual migration to 2.0
2021-04-02 16:36:29 -04:00
William Wernert
d19c03efef
Refactor search of config lines
...
* Create arrays for each line and loop through them for better code readability
* Add more host key algorithms for removal
* Update regex to look for a comma or EOL at the end of the search term, to avoid missing last item in list
2021-04-02 14:49:22 -04:00
William Wernert
8b8086b91a
Update wording, as the new key tends to be ED25519, not ECDSA
2021-04-02 10:20:28 -04:00
William Wernert
fd57996bc6
Change behavior of adding lines to sshd config
...
* Replace existing lines in cases where a change has already been made
2021-04-02 10:00:27 -04:00
William Wernert
43c31b4e66
Fix script so changes are actually made
2021-04-01 14:56:05 -04:00
William Wernert
fa373e9db0
Merge branch 'fix/ssh-harden-setup' into foxtrot
2021-04-01 11:04:10 -04:00
William Wernert
58989398e0
Merge pull request #3721 from Security-Onion-Solutions/foxtrot
...
Allow user to enter a description during setup
2021-04-01 11:02:23 -04:00
m0duspwnens
5cda35db0a
change defaults for testing - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-01 10:45:54 -04:00
Mike Reeves
c60d4aca16
Merge pull request #3724 from Masaya-A/Fix-https
...
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 10:36:02 -04:00
Mike Reeves
234dec3f63
Merge pull request #3734 from Security-Onion-Solutions/zeekports
...
Reserve ports for Zeek
2021-04-01 10:35:16 -04:00
Mike Reeves
7d489ea34f
Merge pull request #3735 from Security-Onion-Solutions/kilo
...
For hunt quick actions, pipe value to 'escape' operator to escape bac…
2021-04-01 10:35:01 -04:00
Mike Reeves
7c6b037ae5
Reserve ports for Zeek
2021-04-01 10:30:52 -04:00
Mike Reeves
40313fc2f5
Reserve ports for Zeek
2021-04-01 10:29:58 -04:00
m0duspwnens
4f3b3a787c
change defaults for testing, remove measurements list since cq uses wildcard now - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-01 10:18:29 -04:00
Mike Reeves
0d05612393
Reserve ports for Zeek
2021-04-01 10:00:55 -04:00
Masaya-A
bc04cae918
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 16:59:47 +09:00
Masaya-A
908c5f8ef6
Merge pull request #8 from Security-Onion-Solutions/dev
...
Dev Sync 20210401
2021-04-01 16:55:41 +09:00
Mike Reeves
88eab86528
Manage the repo files
2021-03-31 17:07:30 -04:00
Mike Reeves
9645988555
Manage the repo files
2021-03-31 17:06:26 -04:00
Mike Reeves
1509722185
Manage the repo files
2021-03-31 17:04:56 -04:00
Mike Reeves
bfc5bb011f
Manage the repo files
2021-03-31 17:03:52 -04:00
Mike Reeves
13421bb04b
Manage the repo files
2021-03-31 16:59:15 -04:00
Josh Patterson
6cebc41353
Merge pull request #3720 from Security-Onion-Solutions/issue/3709
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 16:54:15 -04:00
Mike Reeves
f387c4327a
Manage the repo files
2021-03-31 16:53:20 -04:00
Mike Reeves
358f397535
Manage the repo files
2021-03-31 16:50:43 -04:00
Mike Reeves
9b84a92ced
Manage the repo files
2021-03-31 16:47:04 -04:00
William Wernert
a8483cb30e
Merge branch 'dev' into foxtrot
2021-03-31 16:02:26 -04:00
William Wernert
dfe5e73608
Merge branch 'feature/node-description' into foxtrot
2021-03-31 16:02:12 -04:00
William Wernert
3de980e4a1
Move function call to run after Network Manager is installed
2021-03-31 16:00:37 -04:00
Josh Brower
2b86241450
Merge pull request #3717 from Security-Onion-Solutions/fix/playbook-timestamps
...
Fix Playbook Alert timestamps
2021-03-31 15:47:11 -04:00
Josh Brower
ef98445560
Fix Playbook Alert timestamps
2021-03-31 15:44:41 -04:00
m0duspwnens
f7e99b4961
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 15:17:15 -04:00
Jason Ertel
820b01405f
For hunt quick actions, pipe value to 'escape' operator to escape backslashes and double quotes
2021-03-31 14:57:36 -04:00
William Wernert
2a595f03b7
Merge pull request #3630 from Security-Onion-Solutions/foxtrot
...
Add option to configure chrony as an ntp service
2021-03-31 13:41:06 -04:00
William Wernert
761a12ebbb
Fix variable name
2021-03-31 13:32:49 -04:00
William Wernert
1c4ba28336
[fix] host_pillar overwrites the file, so run ntp_pillar after it
2021-03-31 13:28:42 -04:00
Mike Reeves
f8d7241354
Fix repo file path
2021-03-31 12:55:46 -04:00
Mike Reeves
89922a439e
Move repo files
2021-03-31 12:37:33 -04:00
Josh Brower
209d348108
Merge pull request #3688 from Security-Onion-Solutions/fix/playbook-sync
...
Fix sensor cleanup & playbook sync scripts
2021-03-31 11:59:27 -04:00
Jason Ertel
cdf3254485
Merge pull request #3708 from Security-Onion-Solutions/newrepo
...
Add Wazuh 4 repo
2021-03-31 09:29:50 -04:00
Mike Reeves
5e25d762c4
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-31 09:28:18 -04:00
Mike Reeves
46865809ed
Fix Automation Testing round 2
2021-03-31 09:28:02 -04:00
Mike Reeves
bb39ccc1aa
Fix Automation Testing
2021-03-31 09:25:21 -04:00
Mike Reeves
0d077b0d49
Merge pull request #3704 from gebhard73/patch-2
...
Update so-index-list
2021-03-31 09:18:29 -04:00
William Wernert
04920dcbed
Merge branch 'dev' into foxtrot
2021-03-31 09:15:17 -04:00
William Wernert
c03e2b2c11
Move ntp server array to its own pillar in the minion sls file
2021-03-31 09:14:40 -04:00
Mike Reeves
5203c25971
Add Wazuh 4 Repo
2021-03-31 09:13:38 -04:00
Mike Reeves
b485531bd8
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-31 09:12:56 -04:00
weslambert
5eb0137c21
Merge pull request #3705 from Security-Onion-Solutions/delta
...
Enforce date type for ingest.timestamp
2021-03-31 08:40:41 -04:00
Wes Lambert
942de130ca
Enforce date type for ingest.timestamp
2021-03-31 12:24:51 +00:00
gebhard73
0b9cf57b5f
Update so-index-list
...
Sort by index name.
2021-03-31 14:22:06 +02:00
Mike Reeves
e92f5c122c
Merge pull request #3689 from Security-Onion-Solutions/kilo
...
Remove incompatible example
2021-03-30 16:08:16 -04:00
William Wernert
177989269f
Better formatting of chrony.conf
2021-03-30 15:50:37 -04:00
William Wernert
fd51b327ee
Add messaging to explain chronyc output to log
2021-03-30 15:23:57 -04:00
William Wernert
be6eb3ed6c
Restart chrony in case it's already running
2021-03-30 14:17:05 -04:00
m0duspwnens
8e55e0b994
start graphing data from so_long_term
2021-03-30 13:36:52 -04:00
Josh Brower
679925ebd9
Fix sensor cleanup & playbook sync scripts
2021-03-30 13:29:56 -04:00
weslambert
ff317cdcf1
Merge pull request #3684 from Security-Onion-Solutions/delta
...
Add Elastic scripts
2021-03-30 12:06:00 -04:00
Wes Lambert
7049383ba6
Add Elastic scripts
2021-03-30 15:47:05 +00:00
Mike Reeves
2534ca7eb7
Merge pull request #3633 from Security-Onion-Solutions/newrepo
...
Attempt to use so repo for network install
2021-03-30 11:37:46 -04:00
Mike Reeves
b2138045c0
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-30 11:29:22 -04:00
Mike Reeves
fc3fd00216
Fix formatting
2021-03-30 11:28:47 -04:00
Mike Reeves
09064baf71
Update so-common
2021-03-30 11:21:19 -04:00
Mike Reeves
5f5a53b8bb
Push repolist to dev null
2021-03-30 11:14:58 -04:00
William Wernert
25eca39428
Always ask for ntp setup on iso installs, don't ask on network installs
2021-03-30 09:54:21 -04:00
m0duspwnens
30c6d4756a
change default long term resolution to 5m
2021-03-30 09:38:37 -04:00
William Wernert
0e9ffe033d
Show message about setting up network earlier during setup
2021-03-30 09:30:06 -04:00
Jason Ertel
e98f3e54c0
Merge branch 'dev' into kilo
2021-03-29 17:37:18 -04:00
Mike Reeves
3fce63e0c5
Fix Repo Again
2021-03-29 16:43:44 -04:00
Mike Reeves
f73bf947bc
Fix repo url
2021-03-29 15:42:26 -04:00
Mike Reeves
1a58479f39
Fix acng passthrough
2021-03-29 15:15:34 -04:00
m0duspwnens
d1150f150f
loop through the rps
2021-03-29 10:59:18 -04:00
m0duspwnens
e0f4abaa09
try to do it with just 1 cq, modify defaults for testing
2021-03-29 10:36:56 -04:00
William Wernert
d81d4e7474
Merge branch 'dev' into foxtrot
2021-03-29 09:36:38 -04:00
William Wernert
2ff790699f
[fix] Set ntp_string to empty, not ntp_servers
2021-03-29 09:36:24 -04:00
Jason Ertel
6bce8e8e2c
Remove incompatible example
2021-03-29 07:30:26 -04:00
Mike Reeves
d889bd2694
Fix Security Onio Pub Key
2021-03-28 22:32:03 -04:00
Mike Reeves
5882642c32
fixpath for GPG Keys for real
2021-03-28 22:10:02 -04:00
Mike Reeves
362bf55526
fixpath for GPG keys
2021-03-28 22:01:58 -04:00
Jason Ertel
0945747a70
Merge pull request #3649 from Security-Onion-Solutions/kilo
...
Support custom login banner
2021-03-26 22:33:36 -04:00
Mike Reeves
bab062e52b
Fix acng to actually cache
2021-03-26 16:21:03 -04:00
Mike Reeves
955d41abde
Fix acng to actually cache
2021-03-26 16:18:49 -04:00
Mike Reeves
26f8ae87c5
Fix acng to actually cache
2021-03-26 16:10:00 -04:00
Mike Reeves
8819cc1371
Fix acng to actually cache
2021-03-26 16:01:22 -04:00
Jason Ertel
9d6c2a5f15
Merge branch 'dev' into kilo
2021-03-26 15:58:05 -04:00
Jason Ertel
0195d366cc
Add custom banner to login page
2021-03-26 14:44:31 -04:00
William Wernert
eb674b3b93
Validate list of ntp servers (ip4, hostname, or fqdn)
2021-03-25 14:45:33 -04:00
William Wernert
150e724a4a
Fix chrony install logic + add sleep for chrony to finish sync
2021-03-25 13:37:54 -04:00
Mike Reeves
af3951e1ad
Attempt to use so repo for network install
2021-03-25 11:51:55 -04:00
m0duspwnens
889e624a8c
add shard_duration to state and defaults - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-03-25 09:33:10 -04:00
m0duspwnens
cd0ab5c709
add support for shard_duration to influxdb module and influxdb_retention_policy state - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-03-25 08:50:32 -04:00
Masaya-A
16f88c38de
Merge pull request #7 from Security-Onion-Solutions/dev
...
Dev Sync
2021-03-25 09:09:38 +09:00
m0duspwnens
d75fafb19c
add support for shard_duration to influxdb module and influxdb_retention_policy state - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-03-24 17:30:27 -04:00
Jason Ertel
909a1badcb
Merge pull request #3622 from Security-Onion-Solutions/kilo
...
Correct local online docs link to release notes
2021-03-24 15:01:35 -04:00
Jason Ertel
7fc2467951
Correct local online docs link to release notes
2021-03-24 15:00:02 -04:00
William Wernert
c6a257bc50
Merge branch 'dev' into feature/ntp-service
2021-03-24 11:50:47 -04:00
Mike Reeves
f0c19cf2af
Merge pull request #3616 from Security-Onion-Solutions/kilo
2021-03-24 11:48:31 -04:00
Jason Ertel
08f46a779a
Remove freqserver, minio, and domainstats from image list
2021-03-24 11:32:29 -04:00
m0duspwnens
11c3f14b42
end patch files with newline
2021-03-24 10:35:20 -04:00
William Wernert
982f2de33c
[fix] Refactor so-ssh-harden
...
* Create a temp file to make changes, and only copy back over if any changes are made
* Test changes as they're made, and exit if the test fails
* Only add lines if they don't already exist in the config
2021-03-24 09:48:00 -04:00
m0duspwnens
53528d486c
remove minio
2021-03-24 09:44:56 -04:00
m0duspwnens
3a8aea0de6
removing domainstats and freqserver from so-image-common
2021-03-24 09:11:48 -04:00
Jason Ertel
79ad87f83c
Remove freqserver, minio, and domainstats from image list
2021-03-23 21:16:17 -04:00
Jason Ertel
887920e7c5
Implement customizable overview page
2021-03-23 16:44:08 -04:00
Jason Ertel
2d8c73d317
Merge branch 'dev' into kilo
2021-03-23 16:31:44 -04:00
Jason Ertel
5ade0b9f40
Implement customizable overview page
2021-03-23 16:31:41 -04:00
m0duspwnens
a3e11f017b
merge with 2.3.40
2021-03-23 14:34:52 -04:00
William Wernert
23cd006724
so-ssh-harden fixes
...
* Change when script is run during setup
* Add newlines to sshd config for legibility
2021-03-23 14:06:10 -04:00
William Wernert
3287a777a2
[fix] Pre-fill hostname re-enter on default
2021-03-23 11:41:12 -04:00
William Wernert
9f0afd90f1
[fix] Add missing backslash
2021-03-23 11:27:37 -04:00
William Wernert
2d873b92fa
Fix ntp logic elsewhere
2021-03-23 10:22:41 -04:00
William Wernert
0e9c81c145
Fix logic around ntp prompt
2021-03-23 09:44:44 -04:00
William Wernert
884343b299
Merge branch 'dev' into feature/ntp-service
2021-03-23 09:36:41 -04:00
William Wernert
184c763b02
[fix] Export correct variable to check later in setup
2021-03-23 09:36:08 -04:00
William Wernert
ace30c07ea
[fix] Also sync time before updating system clock
2021-03-23 09:22:09 -04:00
William Wernert
b3f558a1f8
[fix] Also check if proxy is set before asking for ntp servers
2021-03-23 09:14:34 -04:00
Masaya-A
151376a18f
Merge pull request #5 from Security-Onion-Solutions/dev
...
Dev Sync
2021-03-23 14:27:29 +09:00
Jason Ertel
197693df4e
Merge pull request #3580 from Security-Onion-Solutions/kilo
...
Upgrade to version 2.3.50
2021-03-22 21:10:05 -04:00
William Wernert
449e0d853c
Initial support for ntp service via chronyd
2021-03-22 15:52:51 -04:00
Jason Ertel
8448588809
Upgrade to version 2.3.50
2021-03-22 15:04:02 -04:00
Mike Reeves
cdb16e3e5a
Merge pull request #3579 from Security-Onion-Solutions/kilo
...
Revert upgrade to version 2.3.50
2021-03-22 14:55:21 -04:00
Jason Ertel
86cb59d5ae
Revert upgrade to version 2.3.50
2021-03-22 14:53:36 -04:00
Mike Reeves
b4172565e8
Merge pull request #3578 from Security-Onion-Solutions/kilo
...
Upgrade to version 2.3.50
2021-03-22 14:50:27 -04:00
Jason Ertel
b83ae4bded
Upgrade to version 2.3.50
2021-03-22 14:49:14 -04:00
Mike Reeves
afed0b70eb
Merge pull request #3572 from Security-Onion-Solutions/dev
...
2.3.40
2021-03-22 14:43:34 -04:00
William Wernert
50fa0dc81a
Allow user to enter a description during setup
...
Resolves #2404
2021-03-22 11:32:37 -04:00
Jason Ertel
e9bd3888c4
Merge pull request #3571 from Security-Onion-Solutions/2340sigrtd
...
Verify ISO and update gpg
2021-03-22 10:03:42 -04:00
Mike Reeves
ea5624b4bf
Update date
2021-03-22 10:02:04 -04:00
Mike Reeves
11cb843fb4
Verify ISO and update gpg
2021-03-22 09:59:48 -04:00
Mike Reeves
57664a3c8a
Merge pull request #3570 from Security-Onion-Solutions/Update-Readme
...
Update README.md
2021-03-22 09:14:34 -04:00
Mike Reeves
71d4d7ee8f
Update README.md
2021-03-22 09:03:47 -04:00
Mike Reeves
25c9e70658
Merge pull request #3564 from Security-Onion-Solutions/fix/dash
...
Fix Dashboard Placeholder
2021-03-20 16:10:07 -04:00
Mike Reeves
e06e023d8e
Fix Dashboard Placeholder
2021-03-20 14:05:55 -04:00
Mike Reeves
4fe14dbfd8
Merge pull request #3558 from Security-Onion-Solutions/fix/https-playbook-alerter
...
Fix https Playbook Alerter
2021-03-19 16:39:35 -04:00
Josh Brower
2425355680
Fix https Playbook Alerter
2021-03-19 16:38:33 -04:00
Josh Patterson
30b948f6b8
Merge pull request #3557 from Security-Onion-Solutions/suri-eve-file-mode
...
prevent salt warning about file mode
2021-03-19 16:24:26 -04:00
m0duspwnens
e87fb013dc
prevent salt warning - The 'file_mode' argument will be ignored. Please use 'mode' instead to set file permissions.
2021-03-19 16:21:18 -04:00
Mike Reeves
908a9c2c06
Merge pull request #3550 from Security-Onion-Solutions/issue/3493
...
fix docker-ce holds
2021-03-19 15:18:45 -04:00
m0duspwnens
d0f938a600
fix docker-ce holds
2021-03-19 15:16:58 -04:00
Mike Reeves
ee2a6f8be9
Merge pull request #3549 from Security-Onion-Solutions/saved_objects
...
Update saved objects and remove index patterns because this is now handled by Field Caps API
2021-03-19 14:32:55 -04:00
Wes Lambert
b481cf885b
Update saved objects and remove index patterns because this is now handled by Field Caps API
2021-03-19 18:30:42 +00:00
Mike Reeves
890c0da81a
Merge pull request #3546 from Security-Onion-Solutions/kilo
...
Update release notes for 2.3.40
2021-03-19 11:25:15 -04:00
Jason Ertel
e69f6270f9
Merge branch 'dev' into kilo
2021-03-19 11:15:47 -04:00
Jason Ertel
83a3488a06
Update changes.json to reflect 2.3.40 changes
2021-03-19 11:15:27 -04:00
Mike Reeves
de61886441
Merge pull request #3544 from Security-Onion-Solutions/feature/setup-kibana-space
...
Configure default Space in Kibana during setup
2021-03-19 09:02:18 -04:00
Josh Brower
9d533e5db0
Merge pull request #3542 from Security-Onion-Solutions/fix/fleet-custom-hostname
...
Fix Fleet Custom Hostname Reactor
2021-03-19 08:21:30 -04:00
Josh Brower
d020f1d1a1
Fix Fleet Custom Hostname Reactor
2021-03-19 08:15:47 -04:00
William Wernert
b595c6ddf7
Configure default Space in Kibana during setup
2021-03-18 16:00:13 -04:00
Mike Reeves
28999af493
Merge pull request #3539 from Security-Onion-Solutions/fix/postsoup
...
Fix/postsoup
2021-03-18 15:46:36 -04:00
Josh Brower
77b8aecfd9
add so-kibana-space-defaults
2021-03-18 15:40:12 -04:00
Mike Reeves
2e84af621e
Add postloop for 2.3.40
2021-03-18 15:14:10 -04:00
William Wernert
6b2947ca6a
Merge pull request #3535 from Security-Onion-Solutions/fix/cloud-var
...
Set is_cloud variable in the main shell process
2021-03-18 14:00:58 -04:00
Mike Reeves
2bd3a6418d
Merge pull request #3536 from Security-Onion-Solutions/kilo
...
Refresh fieldcaps every 5 minutes
2021-03-18 13:57:24 -04:00
Jason Ertel
cc30abfe1b
Refresh fieldcaps every 5 minutes
2021-03-18 13:48:57 -04:00
William Wernert
0edf419bcb
Remove redundant message
2021-03-18 13:16:45 -04:00
William Wernert
360f0d4dfd
Also print stdout message to log
2021-03-18 13:12:16 -04:00
William Wernert
27ff823bc0
[fix] Don't set is_cloud in a subshell
2021-03-18 13:09:46 -04:00
Mike Reeves
1f85506fb1
Merge pull request #3532 from Security-Onion-Solutions/fix/packaging
...
Also add python packaging lib package to common state
2021-03-18 11:30:56 -04:00
William Wernert
cb0fb93f77
Also add python packaging lib package to common state
2021-03-18 11:28:25 -04:00
William Wernert
fcf0417fbf
Merge pull request #3528 from Security-Onion-Solutions/fix/default-no-proxy
...
Change proxy prompt to default to no
2021-03-18 09:57:03 -04:00
William Wernert
c910a2d2a0
Change proxy prompt to default to no
2021-03-18 09:52:11 -04:00
William Wernert
066a8598a6
Merge pull request #3523 from Security-Onion-Solutions/issue/3493
...
fix docker versions in setup
2021-03-18 09:31:35 -04:00
William Wernert
b5770964c4
Merge pull request #3522 from Security-Onion-Solutions/fix/install-network-manager
...
[fix] CentOS ami does not include NetworkManager, so install it
2021-03-18 09:10:41 -04:00
William Wernert
31725ac627
[fix] Indent
2021-03-18 09:09:29 -04:00
m0duspwnens
dbe54708ef
fix docker versions in setup https://github.com/Security-Onion-Solutions/securityonion/issues/3493
2021-03-18 09:09:28 -04:00
William Wernert
163cb8f3ca
[fix] Typo
2021-03-18 09:08:31 -04:00
William Wernert
4f104c860e
[fix] CentOS ami does not include NetworkManager, so install it
2021-03-18 09:00:02 -04:00
Mike Reeves
db605adaf6
Merge pull request #3517 from Security-Onion-Solutions/fix/restarting-docker-message
2021-03-17 21:15:37 -04:00
Mike Reeves
308f10fbdd
Merge pull request #3510 from Security-Onion-Solutions/kilo
2021-03-17 21:14:45 -04:00
William Wernert
6e3d951b01
[fix] Show message in terminal when restarting Docker to avoid confusion
2021-03-17 20:17:23 -04:00
Mike Reeves
9a2b5fa301
Merge pull request #3516 from Security-Onion-Solutions/add_suricata_eve_clean
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3515
2021-03-17 18:50:23 -04:00
m0duspwnens
ec179f8e9b
https://github.com/Security-Onion-Solutions/securityonion/issues/3515
2021-03-17 18:44:25 -04:00
Jason Ertel
bc002cb9fb
Merge branch 'dev' into kilo
2021-03-17 18:29:52 -04:00
Jason Ertel
4e9f629231
Reformat inactiveTools list in JSON format
2021-03-17 18:25:05 -04:00
Mike Reeves
75f9138a40
Merge pull request #3514 from Security-Onion-Solutions/fix/accept-hostname-proxy
...
[fix] Also accept a hostname in the proxy URL
2021-03-17 17:51:59 -04:00
William Wernert
96ac742b69
[fix] Also accept a hostname in the proxy URL
2021-03-17 17:31:47 -04:00
Jason Ertel
42809083e8
Merge branch 'dev' into kilo
2021-03-17 17:14:29 -04:00
Mike Reeves
a3b7388aba
Merge pull request #3511 from Security-Onion-Solutions/fix/elastic-license-agree
...
Make the Elastic license prompt case insensitive
2021-03-17 16:57:32 -04:00
William Wernert
7da027abc1
Make the Elastic license prompt case insensitive
2021-03-17 16:55:34 -04:00
Jason Ertel
4de809ecbd
Automatically hide SOC tools that are not installed. Resolves #1643 .
2021-03-17 16:13:50 -04:00
Josh Brower
8fd3f102f1
Merge pull request #3509 from Security-Onion-Solutions/fix/kibana-space-defaults
...
Add space defaults script
2021-03-17 15:55:11 -04:00
Josh Brower
7583593152
Add space defaults scripot
2021-03-17 15:47:36 -04:00
Jason Ertel
dc0d989942
Merge pull request #3504 from Security-Onion-Solutions/issue/3493
...
UPGRADE: docker-ce, docker-ce-cli, containerd to latest
2021-03-17 13:51:31 -04:00
William Wernert
46d346aa62
Merge pull request #3503 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-03-17 12:07:40 -04:00
William Wernert
16d6e116fa
Merge branch 'dev' into foxtrot
...
# Conflicts:
# salt/idstools/init.sls
2021-03-17 11:52:54 -04:00
Mike Reeves
52b836d456
Merge pull request #3498 from Security-Onion-Solutions/fix/so-rule-apply
...
Fix so-rule apply - manually tested
2021-03-17 11:28:16 -04:00
William Wernert
8aac9d6bea
Reorder states in sync_files.sls
2021-03-17 10:46:17 -04:00
William Wernert
99a37a56a9
[fix] Change the commands so-rule uses to apply changes
2021-03-17 10:36:43 -04:00
m0duspwnens
f63cc10602
https://github.com/Security-Onion-Solutions/securityonion/issues/3493
2021-03-17 10:26:52 -04:00
William Wernert
c0163108ab
Merge branch 'dev' into foxtrot
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-03-17 10:23:51 -04:00
m0duspwnens
aa14dda155
https://github.com/Security-Onion-Solutions/securityonion/issues/3493
2021-03-17 10:20:20 -04:00
Mike Reeves
fbdb627ab7
Merge pull request #3488 from Security-Onion-Solutions/issue/3288
...
insert instead of append
2021-03-17 09:17:20 -04:00
m0duspwnens
68ce7a902d
insert instead of append
2021-03-17 09:14:19 -04:00
Doug Burks
2ba130b44c
Merge pull request #3487 from Security-Onion-Solutions/issue/3486
...
FEATURE: soup should provide some initial information and then prompt…
2021-03-17 09:02:29 -04:00
Doug Burks
d32c1de411
FEATURE: soup should provide some initial information and then prompt the user to continue #3486
2021-03-17 09:00:46 -04:00
Josh Brower
d21abd9693
Merge pull request #3482 from Security-Onion-Solutions/feature/revert-livequery-hunt
...
Temp revert Fleet Live Query to Hunt
2021-03-17 08:29:28 -04:00
Josh Brower
bba9913be1
Temp revert Fleet Live Query to Hunt
2021-03-17 08:25:25 -04:00
Jason Ertel
1b6f681ae1
Merge pull request #3477 from Security-Onion-Solutions/esheap
...
Esheap
2021-03-17 08:14:13 -04:00
Mike Reeves
137e1a699d
Fix the math
2021-03-16 19:01:10 -04:00
Mike Reeves
2f3488b134
Merge pull request #3476 from Security-Onion-Solutions/issue/3288
...
Issue/3288
2021-03-16 18:56:07 -04:00
Mike Reeves
7719a26a96
Change ES Heap calculation
2021-03-16 18:53:41 -04:00
m0duspwnens
53c3b19a08
Merge remote-tracking branch 'remotes/origin/dev' into issue/3288
2021-03-16 16:46:32 -04:00
Doug Burks
065f1c2927
Merge pull request #3473 from Security-Onion-Solutions/fix/shorten-elastic-license-url
...
Shorten Elastic License URL to avoid line wrap
2021-03-16 16:43:38 -04:00
Doug Burks
388524ec4e
Shorten Elastic License URL to avoid line wrap
2021-03-16 16:39:14 -04:00
m0duspwnens
38a497932c
https://github.com/Security-Onion-Solutions/securityonion/issues/3288
2021-03-16 16:36:35 -04:00
weslambert
8d29f757b1
Merge pull request #3471 from Security-Onion-Solutions/kilo
...
Reverse Zeek index close/delete count for Curator
2021-03-16 14:34:46 -04:00
Josh Brower
b56434aea1
Merge pull request #3470 from Security-Onion-Solutions/feature/disable-features-ui
...
Feature/disable certain features in Kibana UI
2021-03-16 14:00:21 -04:00
Josh Brower
abd4f92088
Cleanup curl output
2021-03-16 13:53:28 -04:00
Josh Brower
c855e0a55a
Disable certain Features within the default space
2021-03-16 13:48:13 -04:00
Wes Lambert
7a02150389
Reverse Zeek index close/delete count for Curator
2021-03-16 17:16:55 +00:00
weslambert
5fd483a99d
Merge pull request #3466 from Security-Onion-Solutions/soup2340
...
Soup for 2.3.40
2021-03-16 13:03:33 -04:00
Mike Reeves
d92c1c11aa
Merge pull request #3463 from Security-Onion-Solutions/kilo
...
Ignore TIME_WAIT when checking for Strelka frontend port reservation
2021-03-16 12:59:16 -04:00
Mike Reeves
71c6bb71c1
Merge remote-tracking branch 'remotes/origin/dev' into soup2340
2021-03-16 12:56:24 -04:00
Mike Reeves
e528d84ebe
Update Elastic License Text
2021-03-16 12:56:06 -04:00
William Wernert
129db23062
Move interface message to later in setup
2021-03-16 12:34:44 -04:00
William Wernert
1e7aaf9ffb
Collect manager info before showing message about copying ssh key
2021-03-16 12:32:37 -04:00
Mike Reeves
2851840e76
Fix Logging
2021-03-16 12:18:01 -04:00
Josh Brower
7b748128ea
Merge pull request #3462 from Security-Onion-Solutions/delta
...
Fixes IP & Port mappings
2021-03-16 12:05:23 -04:00
Josh Brower
4d6cac4a2a
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-03-16 11:57:17 -04:00
William Wernert
c8bbe078a6
Use more lines on proxy error message
2021-03-16 11:42:15 -04:00
William Wernert
6a48d7f478
Print curl error to populate variable
2021-03-16 11:34:36 -04:00
Wes Lambert
038c58f3d5
Ignore TIME_WAIT when checking for Strelka frontend port reservation
2021-03-16 14:51:16 +00:00
William Wernert
59c62393b5
Change back to validating proxy, show user error message from curl
2021-03-16 10:18:02 -04:00
Mike Reeves
00025e5c74
Fix Syntax Error
2021-03-16 09:34:53 -04:00
Josh Brower
71ae5b60ea
Update Sigmac mappings and config for IPs and ports
2021-03-16 09:32:40 -04:00
Josh Brower
44c75122ed
Update Sigmac mappings and config for IPs and ports
2021-03-16 09:05:35 -04:00
Mike Reeves
8d23518f90
Update Elastic Link
2021-03-15 17:50:06 -04:00
Mike Reeves
9a4c4448f3
Fix whiptail display
2021-03-15 17:45:44 -04:00
Mike Reeves
12501e0079
Add check license to its own logic
2021-03-15 17:41:45 -04:00
Mike Reeves
72759de97f
Fix so-common syntax
2021-03-15 17:37:44 -04:00
Mike Reeves
67e0d450e4
Add Elastic License Prompts
2021-03-15 17:32:36 -04:00
Mike Reeves
05ec7dba21
Merge pull request #3452 from Security-Onion-Solutions/Telegraf-Fix
...
Turn off SSL Verification in Telegraf
2021-03-15 16:47:27 -04:00
Mike Reeves
674bb342ea
Turn off SSL Verification in Telegraf
2021-03-15 16:39:43 -04:00
Josh Brower
5fe025318b
Update Sigmac mappings and config for IPs and ports
2021-03-15 15:53:00 -04:00
William Wernert
086f2b3437
Change when prereq packages are installed to follow new order
2021-03-15 14:59:24 -04:00
Mike Reeves
c93aab7a85
Merge pull request #3448 from Security-Onion-Solutions/kilo
...
Allow for moving Strelka files to processed directory after scanning
2021-03-15 14:51:04 -04:00
William Wernert
efc0463201
Change when proxy + variables are set so strings are built correctly
2021-03-15 14:45:23 -04:00
William Wernert
55aee69a74
Merge branch 'dev' into foxtrot
2021-03-15 12:34:24 -04:00
William Wernert
6ae3a26cbe
Revert all proxy changes on reinstall
2021-03-15 12:34:13 -04:00
Wes Lambert
f142b754dc
Add Strelka files.processed directory so files will be moved from staging to processed
2021-03-15 15:43:31 +00:00
Wes Lambert
b6a785395d
Add Strelka staging directory for state
2021-03-15 15:42:13 +00:00
Mike Reeves
ab75d0e563
soup for 2.3.40
2021-03-15 10:51:31 -04:00
Mike Reeves
79c7af9a31
soup for 2.3.40
2021-03-15 10:48:24 -04:00
Masaya-A
236373cda2
Merge pull request #2 from Security-Onion-Solutions/dev
...
Dev Sync
2021-03-14 20:27:50 +09:00
Mike Reeves
d931e57fd8
Merge pull request #3428 from Security-Onion-Solutions/kilo
2021-03-12 17:03:48 -05:00
Doug Burks
cfdf9703ab
Merge pull request #3427 from Security-Onion-Solutions/issue/3340
...
FEATURE: soup should output more guidance for distributed deployments at the end #3340
2021-03-12 15:27:26 -05:00
Doug Burks
da7adab566
FEATURE: soup should output more guidance for distributed deployments at the end #3340
2021-03-12 12:59:17 -05:00
William Wernert
f80dfda60b
Only run initial installer progress to 98 to avoid sitting at 100
2021-03-12 11:39:44 -05:00
William Wernert
302d6e03be
Merge branch 'dev' into foxtrot
2021-03-12 11:36:26 -05:00
Mike Reeves
4ac408ad38
Merge pull request #3423 from Security-Onion-Solutions/issue/3422
...
FIX: Improve Setup verbiage #3422
2021-03-12 11:04:25 -05:00
doug
edb88ac09a
FIX: Improve Setup verbiage #3422
2021-03-12 10:54:44 -05:00
Jason Ertel
747f387936
Replace salt's http.wait_for_successful_query with so-common's wait_for_web_response due to issues with salt
2021-03-12 10:42:18 -05:00
Jason Ertel
8cddfeb47d
Provide pillar for each client param
2021-03-12 07:42:10 -05:00
Doug Burks
555f9b5091
Merge pull request #3417 from Security-Onion-Solutions/issue/3413
...
FIX: SMTP shoud read SNMP on Kibana SNMP view #3413
2021-03-12 06:52:21 -05:00
doug
a5779a520c
FIX: SMTP shoud read SNMP on Kibana SNMP view #3413
2021-03-12 06:48:57 -05:00
Jason Ertel
a7ea0808c3
Merge pull request #3399 from Security-Onion-Solutions/kilo
...
feature: Show job owner/submitter. Resolves #2775
2021-03-12 06:45:34 -05:00
Jason Ertel
462f76e2bb
Remove client params block in favor in individual settings that will go into the pillar
2021-03-12 06:38:53 -05:00
Jason Ertel
b5cf9ae820
Merge branch 'dev' into kilo
2021-03-11 18:01:17 -05:00
Jason Ertel
80987dfd1d
Support overrides of client params
2021-03-11 18:01:04 -05:00
William Wernert
6842204981
Ask for hostname earlier in setup
2021-03-11 16:55:06 -05:00
Doug Burks
ab1c84afca
Merge pull request #3409 from Security-Onion-Solutions/issue/3408
...
FIX: Populate http.status_message field #3408
2021-03-11 16:45:53 -05:00
doug
adbc7436b6
FIX: Populate http.status_message field #3408
2021-03-11 16:42:20 -05:00
William Wernert
6d431c0bda
Add more info to comment
2021-03-11 16:36:56 -05:00
William Wernert
b14b9e8e17
[fix] Fix dependency install progress bar
2021-03-11 16:34:54 -05:00
William Wernert
b35e65190e
[fix] Fix dependency install progress bar
2021-03-11 16:30:14 -05:00
William Wernert
8e8bb1489b
Redirect output of kill command
2021-03-11 16:13:52 -05:00
William Wernert
e2fc1b0b39
Redirect output of kill command
2021-03-11 16:06:49 -05:00
William Wernert
3306ffa792
Only collect proxy once, include manager in no_proxy value on minions
2021-03-11 16:03:43 -05:00
William Wernert
a86b2ab653
[fix] Remove additional collect_proxy call
2021-03-11 15:54:46 -05:00
William Wernert
5612fc10d4
[feat] Remove setup dependency on bc
2021-03-11 15:53:04 -05:00
Jason Ertel
286351f424
Merge branch 'dev' into kilo
2021-03-11 15:32:38 -05:00
Jason Ertel
908720592a
Upgrade saved objects to 7.11.2
2021-03-11 15:32:22 -05:00
William Wernert
66da3e380f
[fix] Set percentage value when needed
2021-03-11 15:25:38 -05:00
William Wernert
e60bc87ffa
Install setup required packages later so that also uses the proxy
2021-03-11 15:20:39 -05:00
m0duspwnens
c4da576030
ensure the presence of the telegraf database
2021-03-11 12:20:32 -05:00
William Wernert
0d01f63e3b
[fix] Confirm proxy password
2021-03-11 11:46:46 -05:00
Jason Ertel
79dd0d1809
Fix indentation
2021-03-11 11:13:14 -05:00
Mike Reeves
cdd95986a8
Merge pull request #3398 from Security-Onion-Solutions/issue/3397
...
FIX: Improve Suricata DHCP logging and parsing #3397
2021-03-11 11:07:53 -05:00
doug
b4ad7e7359
FIX: Improve Suricata DHCP logging and parsing #3397
2021-03-11 11:01:51 -05:00
m0duspwnens
465253a769
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-03-11 10:55:19 -05:00
William Wernert
0434ffac38
Merge branch 'dev' into foxtrot
2021-03-11 10:52:36 -05:00
William Wernert
506162bfcc
Use auth for automated proxy test
2021-03-11 10:52:17 -05:00
m0duspwnens
3b74d987c1
fix retry in ca state. add subjectAltName to influxdb.crt
2021-03-11 10:49:15 -05:00
m0duspwnens
3385ba2ca2
verify ssl
2021-03-11 09:35:54 -05:00
m0duspwnens
6dba2879c5
change so_long_term rp to 6h for tetsing
2021-03-11 09:25:44 -05:00
m0duspwnens
8fc1656939
fix timeouts / retries in ssl state
2021-03-11 09:24:57 -05:00
Doug Burks
adb25d63d2
Merge pull request #3396 from Security-Onion-Solutions/issue/3295
...
FIX: Improve DHCP leases query in Hunt #3395
2021-03-11 08:22:48 -05:00
Doug Burks
85aaa71006
FIX: Improve DHCP leases query in Hunt #3395
2021-03-11 08:01:27 -05:00
William Wernert
750de6333d
[fix] Remove last bad usage of cortexkey
2021-03-10 16:24:21 -05:00
William Wernert
9ffbb9d37e
[fix] Use update so-cortex-user-enable with correct pillar
...
Fixes #3388
2021-03-10 16:17:10 -05:00
William Wernert
157badf448
[fix] Use correct pillar value for api key
...
Fixes #3388
2021-03-10 16:12:59 -05:00
m0duspwnens
75012cdcba
create rps and cqs
2021-03-10 15:20:11 -05:00
Jason Ertel
eefa6bb949
feature: Show job owner/submitter. Resolves #2775
2021-03-10 14:44:21 -05:00
William Wernert
19ccd0c9a2
Merge branch 'dev' into foxtrot
2021-03-10 09:33:42 -05:00
Mike Reeves
6bbcc7a5e9
Merge pull request #3382 from Security-Onion-Solutions/kilo
...
Ensure MTU is defined for advanced sensor automation
2021-03-10 09:27:20 -05:00
Jason Ertel
3eb4a37c76
Expose zeek and suri pins for automation
2021-03-10 09:26:46 -05:00
Jason Ertel
180bba782e
Expose zeek and suri pins for automation
2021-03-10 09:26:11 -05:00
Jason Ertel
b1531cc75e
Merge pull request #3384 from Security-Onion-Solutions/Eval/Import-Fix
...
Update cert location for eval.import
2021-03-10 09:15:53 -05:00
Mike Reeves
18203513ab
Update cert location for eval.import
2021-03-10 09:14:14 -05:00
Jason Ertel
46af6a5c84
Ensure MTU is defined for advanced sensor automation
2021-03-10 08:14:25 -05:00
Mike Reeves
2e74cb6abf
Merge pull request #3377 from Security-Onion-Solutions/kilo
2021-03-09 21:40:43 -05:00
Jason Ertel
a496b03de7
Add missing MTU var for automation of advanced sensor
2021-03-09 20:52:34 -05:00
William Wernert
60f40163aa
Merge branch 'dev' into foxtrot
2021-03-09 13:51:13 -05:00
Jason Ertel
46288802d1
Merge pull request #3368 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update 9101_output_osquery_livequery.conf.jinja
2021-03-09 13:16:17 -05:00
Mike Reeves
2e01330e1b
Update 9101_output_osquery_livequery.conf.jinja
2021-03-09 13:15:04 -05:00
m0duspwnens
c1e4c4cb30
fix pip and python-influxdb install
2021-03-09 11:50:27 -05:00
m0duspwnens
a3a0af64ce
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-03-09 10:34:39 -05:00
m0duspwnens
1f9e5ca3cc
install influxdb python module add test retention policies
2021-03-09 10:31:59 -05:00
William Wernert
f0e089b6bf
Merge branch 'dev' into foxtrot
2021-03-09 10:11:04 -05:00
Mike Reeves
734d25b1ac
Merge pull request #3361 from Security-Onion-Solutions/nomorefeatures
...
Make saved objects less hacky
2021-03-09 10:05:23 -05:00
Mike Reeves
49258a13a3
Make saved objects less hacky
2021-03-09 10:03:29 -05:00
Josh Brower
00da549430
Merge pull request #3358 from Security-Onion-Solutions/delta
...
FEATURE: Initial support for viewing Osquery Live Query results in Hunt
2021-03-09 09:18:57 -05:00
Jason Ertel
b1777ff10f
Merge pull request #3357 from Security-Onion-Solutions/nomorefeatures
...
SSL with Elastic Security
2021-03-08 21:22:30 -05:00
Mike Reeves
3967e581cf
Merge pull request #3356 from Security-Onion-Solutions/kilo
...
fix: Sensors can temporarily show offline while processing large PCAP…
2021-03-08 19:14:54 -05:00
William Wernert
ba71b2fbc8
Change proxy Jinja logic (none and empty string are falsy)
2021-03-08 17:36:34 -05:00
Mike Reeves
1ecb079066
Fix Kibana Script for loading dashboards
2021-03-08 17:36:07 -05:00
William Wernert
f85f86ccdd
[fix] Check for empty proxy string everywhere
2021-03-08 17:25:23 -05:00
William Wernert
8c4e66f7bb
[fix] Print error to stderr
2021-03-08 15:52:21 -05:00
William Wernert
5ee6856a07
Strip the last substring following a hyphen for automated branches
...
Also don't show the user a stack trace on invalid version strings, just alert on the bad string and exit
2021-03-08 15:43:54 -05:00
William Wernert
ed4f8025be
[fix] Also check for proxy to be empty string
2021-03-08 13:57:24 -05:00
Josh Brower
fe8788c09a
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-03-08 12:56:47 -05:00
William Wernert
5c7d3656dd
[fix] Don't try to create so_proxy during automated installs, just set it
2021-03-08 12:26:17 -05:00
Jason Ertel
84c152e233
fix: Sensors can temporarily show offline while processing large PCAP jobs. Resolves #3279 .
2021-03-08 12:05:44 -05:00
Mike Reeves
bf4ac2a312
Fix some merge conflicts
2021-03-08 11:43:24 -05:00
William Wernert
368b04b24e
Add back accidentally removed code
2021-03-08 09:04:17 -05:00
William Wernert
ca2766511b
Revert "[wip] Change when proxy is set up so main ip is known"
...
This reverts commit 1ea3cb1c61 .
# Conflicts:
# setup/so-functions
2021-03-08 09:02:53 -05:00
William Wernert
06c584910c
Merge branch 'dev' into foxtrot
2021-03-08 08:58:31 -05:00
Josh Brower
19b3c7bb07
Merge pull request #3339 from Security-Onion-Solutions/feature/live_query-hunt
...
Feature/live query hunt
2021-03-08 08:31:25 -05:00
William Wernert
49db2a016a
Merge pull request #3341 from Security-Onion-Solutions/kilo
...
Kilo
2021-03-08 08:17:29 -05:00
Jason Ertel
94610307b3
Merge branch 'dev' into kilo
2021-03-08 07:56:48 -05:00
William Wernert
35ae9363f5
[fix] Log gateway error, and don't show whiptail msg on automated installs
2021-03-05 20:15:37 -05:00
William Wernert
9c49cef2de
Merge branch 'feature/docker-prune-rework' into foxtrot
2021-03-05 14:18:57 -05:00
William Wernert
f537b3c7f7
Merge branch 'feature/setup-ssh-harden' into foxtrot
2021-03-05 14:18:35 -05:00
William Wernert
e5110dc3fc
[fix] None -> none
2021-03-05 14:08:03 -05:00
m0duspwnens
7409f15752
update all grafana queries that were using autogen to use default
2021-03-05 13:59:29 -05:00
William Wernert
50fcdb65a6
[fix] Modify the proxy automated test
...
* It makes more sense to test the proxy using a network install, not via the iso
2021-03-05 13:53:48 -05:00
William Wernert
32e7afdc5f
Merge branch 'feature/setup' into foxtrot
2021-03-05 12:53:31 -05:00
William Wernert
245902326f
[wip] Add automation support for proxy settings
2021-03-05 12:53:20 -05:00
Jason Ertel
7234353476
Merge pull request #3319 from Security-Onion-Solutions/foxtrot
...
fix: syntax error in reserved ports configuration #3308
2021-03-05 12:51:50 -05:00
William Wernert
ec04145d15
[fix] Set proxy for idstools container manually
2021-03-05 11:34:31 -05:00
Jason Ertel
61a7efeeab
fix: syntax error in reserved ports configuration; ensure ports are reserved prior to setup
2021-03-05 10:54:01 -05:00
Josh Brower
548f67ca6f
Initial support for Live Queries in Hunt
2021-03-04 18:21:13 -05:00
William Wernert
33b2bd33fe
[fix] Also create config.json so containers use proxy
2021-03-04 17:12:10 -05:00
William Wernert
e0d0baafcc
[fix] Permanently set proxy for yum using template
2021-03-04 16:40:32 -05:00
William Wernert
b3c7760ad4
[fix] Use correct variable in so-proxy.sh
2021-03-04 14:08:21 -05:00
Mike Reeves
39d4f077b4
Merge pull request #3290 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-03-04 13:44:00 -05:00
William Wernert
a435ea77e8
[fix] Also add hostname to no_proxy list
2021-03-04 12:43:42 -05:00
William Wernert
2ee8c7ad1c
[fix] Always pass $proxy_addr since we retry the surrounding function
2021-03-04 12:16:23 -05:00
William Wernert
ac0a4f4a13
Merge branch 'dev' into feature/setup
2021-03-04 12:11:17 -05:00
William Wernert
b265854644
[wip] Move proxy config to separate file
2021-03-04 12:10:42 -05:00
William Wernert
4339ded17f
[wip][fix] Don't add logic to so-setup, create wrapper function in so-functions
2021-03-04 12:10:14 -05:00
William Wernert
d19ca943cc
[fix][wip] Only setup proxy early on configure network setup
2021-03-04 11:57:16 -05:00
William Wernert
2e56252f54
[wip] Syntax fixes
2021-03-04 11:54:21 -05:00
William Wernert
13dc822197
[wip] Ask user if they want to re-enter the proxy
2021-03-04 11:53:08 -05:00
William Wernert
5a97341d33
[wip] Fix how collect_proxy function works on retry
2021-03-04 11:41:36 -05:00
William Wernert
7ee0fd6375
[wip] Specify setup log location to user when directing them to it
2021-03-04 11:31:22 -05:00
Mike Reeves
05c7bd5789
Merge pull request #3285 from Security-Onion-Solutions/elastic
...
Elastic
2021-03-04 10:57:06 -05:00
Mike Reeves
c2b347e4bb
Security Enable for only nodes and heavy
2021-03-04 10:52:01 -05:00
Mike Reeves
a0a8d12526
Enable SSL and Features
2021-03-04 10:08:28 -05:00
Mike Reeves
8c474cc7df
Merge pull request #3268 from Security-Onion-Solutions/issue/3254
...
FIX: Custom Kibana settings are not being applied properly on upgrades #3254
2021-03-04 08:39:50 -05:00
William Wernert
3d5cf128ae
[wip] Test proxy before using it
2021-03-03 15:02:21 -05:00
Mike Reeves
49371a1d6a
fix elastic output for ssl
2021-03-03 14:30:45 -05:00
William Wernert
1ea3cb1c61
[wip] Change when proxy is set up so main ip is known
...
* Also only restart docker if the command exists (i.e. docker is installed)
2021-03-03 14:20:26 -05:00
Mike Reeves
bf4249d28b
fix elastalert verification
2021-03-03 14:16:10 -05:00
William Wernert
4ffa0fbc13
[wip] Fix proxy validation
2021-03-03 14:09:59 -05:00
Mike Reeves
e0538417f1
fix http.wait
2021-03-03 14:06:35 -05:00
doug
d39b3280c8
FIX: Custom Kibana settings are not being applied properly on upgrades #3254
2021-03-03 14:04:32 -05:00
Mike Reeves
6c7111cd0a
turn off verification mode for ES
2021-03-03 13:42:04 -05:00
Mike Reeves
4de62c878c
turn on elastic security
2021-03-03 12:51:29 -05:00
William Wernert
e951e9d9c5
[wip] Further proxy changes
...
* Remove unused docker.conf template
* Rename proxy variable to avoid name collision
* Reword address prompt to specify users should not include user:pass in their input
* Actually call the collect_proxy function
2021-03-03 12:19:14 -05:00
William Wernert
26b1da744c
[wip] Reword proxy yesno prompt
2021-03-03 12:01:15 -05:00
William Wernert
83791d87c7
[wip][fix] Use passwordbox for proxy password
2021-03-03 11:58:45 -05:00
William Wernert
279a5b60b8
Soup indent fixes
2021-03-03 11:58:10 -05:00
Mike Reeves
4f34eca5b9
remove unused script
2021-03-03 10:32:23 -05:00
Mike Reeves
07b5cc3d1d
Fix https for rw indicies script
2021-03-03 10:29:41 -05:00
Mike Reeves
d7451dcd75
Merge remote-tracking branch 'origin/foxtrot' into nomorefeatures
2021-03-03 10:04:38 -05:00
Mike Reeves
4f867e5375
Fix all scripts for ssl elastic
2021-03-03 10:02:23 -05:00
William Wernert
82018a206c
[wip] Don't validate user+pass for proxy, use new variable
2021-03-03 09:56:14 -05:00
William Wernert
2b94fa366e
[wip] Add auth inputs for proxy settings, fix some broken logic
2021-03-03 09:51:38 -05:00
William Wernert
de77d3ebc9
[wip] Initial work for setting up proxy on manager
2021-03-02 17:41:49 -05:00
William Wernert
4df53b3c70
Unify log_size_limit variable value in so-curator-closed-delete-delete
2021-03-02 17:38:17 -05:00
William Wernert
497938460a
[fix] manager:log_size_limit is no longer used, remove generation
2021-03-02 16:47:49 -05:00
Mike Reeves
e0d9212e55
Make https default for all things
2021-03-02 14:01:05 -05:00
Mike Reeves
80574d3c20
Make https default for all things
2021-03-02 13:59:43 -05:00
Mike Reeves
bfd05a8cfc
Change to https for elastic connections
2021-03-02 11:32:29 -05:00
Mike Reeves
3219f4cd12
Remove Features Option
2021-03-02 11:04:50 -05:00
William Wernert
a18dd869c4
Merge branch 'dev' into feature/setup
2021-03-02 10:23:33 -05:00
William Wernert
61611b8de2
Fix Elasticsearch disk space prompt
...
Resolves #3205
2021-03-02 10:23:04 -05:00
William Wernert
0db9991307
Reword/remove some comments
2021-03-02 10:20:33 -05:00
Jason Ertel
4014dbbc3d
Revert "Move version to 2.3.31"
...
This reverts commit cf21200a36 .
2021-03-02 10:14:45 -05:00
William Wernert
35f5c7fb4b
Merge branch 'dev' into feature/docker-prune-rework
2021-03-02 09:48:41 -05:00
Jason Ertel
cf21200a36
Move version to 2.3.31
2021-03-02 09:11:49 -05:00
Mike Reeves
bff446543a
Merge pull request #3215 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-03-01 15:58:41 -05:00
Jason Ertel
53a45e1c97
Merge branch 'dev' into foxtrot
2021-03-01 15:54:41 -05:00
Jason Ertel
b37d5ae15f
Enable advanced setup for some search/sensor installs
2021-03-01 15:54:29 -05:00
Mike Reeves
85204dbb14
Merge pull request #3210 from Security-Onion-Solutions/dev2340
...
Update VERSION
2021-03-01 15:28:45 -05:00
Mike Reeves
2c75cb74db
Update VERSION
2021-03-01 15:17:38 -05:00
Mike Reeves
d99acdb72c
Merge pull request #3209 from Security-Onion-Solutions/dev
...
2.3.30
2021-03-01 15:09:29 -05:00
Mike Reeves
0d70d2e6f8
Merge pull request #3208 from Security-Onion-Solutions/sigs
...
Update Signatures
2021-03-01 14:48:04 -05:00
Mike Reeves
64b37cedc7
Update Signatures
2021-03-01 14:45:51 -05:00
Mike Reeves
852f588512
Merge pull request #3207 from Security-Onion-Solutions/telegraf_suri_meta
...
Telegraf suri meta
2021-03-01 13:59:36 -05:00
m0duspwnens
a197d5addf
revert version to 2.3.30 https://github.com/Security-Onion-Solutions/securityonion/issues/3206
2021-03-01 13:58:04 -05:00
m0duspwnens
3983e08fe5
exclude zeekcaptureloss when suricata metadata selected https://github.com/Security-Onion-Solutions/securityonion/issues/3206
2021-03-01 13:31:05 -05:00
Mike Reeves
8f8651c52c
Merge pull request #3204 from Security-Onion-Solutions/foxtrot
...
Update VERSION file to 2.3.40
2021-03-01 12:18:50 -05:00
Jason Ertel
85e059a766
Update VERSION file to 2.3.40
2021-03-01 12:16:46 -05:00
Mike Reeves
2df871adcd
Merge pull request #3199 from Security-Onion-Solutions/dev
...
2.3.30 Release
2021-03-01 12:11:19 -05:00
William Wernert
3e1a31c0b0
Merge pull request #3201 from Security-Onion-Solutions/sigs
...
Release 2.3.30 sig
2021-03-01 10:49:55 -05:00
Mike Reeves
4e9bfbefda
Merge pull request #3200 from Security-Onion-Solutions/release-merge-fix
...
Release merge fix
2021-03-01 10:49:41 -05:00
Mike Reeves
1a1e3caec8
Release 2.3.30 sig
2021-03-01 10:48:22 -05:00
William Wernert
be7dcdb442
Merge branch 'master' into release-merge-fix
...
# Conflicts:
# README.md
# VERIFY_ISO.md
# VERSION
# salt/docker_clean/init.sls
# salt/soc/files/soc/changes.json
2021-03-01 10:45:51 -05:00
Mike Reeves
8a9c7fa279
Merge pull request #3198 from Security-Onion-Solutions/sigs
...
Add Signature Files
2021-03-01 10:42:15 -05:00
Mike Reeves
bfa7c85e27
Release 2.3.30
2021-03-01 10:40:41 -05:00
Mike Reeves
ed2c836250
Merge pull request #3196 from Security-Onion-Solutions/foxtrot
...
Update changes for 2.3.30
2021-03-01 10:00:12 -05:00
Jason Ertel
1ae46b82ec
Update changes for 2.3.30
2021-03-01 09:58:39 -05:00
Mike Reeves
6e8777b9d6
Merge pull request #3193 from Security-Onion-Solutions/bugfix/revert-default-route-msg
...
Revert "[refactor] Make default route message a warning"
2021-03-01 09:49:58 -05:00
William Wernert
def3637bf6
Revert "[refactor] Make default route message a warning"
...
This reverts commit be1f641bf0 .
2021-03-01 09:46:28 -05:00
William Wernert
1834e07aad
Merge branch 'dev' into feature/docker-prune-rework
2021-03-01 09:37:47 -05:00
Mike Reeves
64cc894948
Merge pull request #3192 from Security-Onion-Solutions/bugfix/input-validation-fixes
...
Bugfix/input validation fixes
2021-03-01 09:27:48 -05:00
Mike Reeves
55b6efba7b
Merge pull request #3189 from Security-Onion-Solutions/bugfix/mtu-input
...
Add max to MTU input validation to encompass default + jumbo frames
2021-03-01 09:26:54 -05:00
William Wernert
cf9be3521d
[fix] Don't validate LS/ES heap sizes
...
* Also remove comments + fix indent
2021-03-01 09:17:36 -05:00
William Wernert
6113bcc261
[fix] Increase max integer value
2021-03-01 09:16:51 -05:00
William Wernert
810ffbdaf5
Add max to MTU input validation to encompass default + jumbo frames
2021-03-01 08:41:19 -05:00
Mike Reeves
c1a8e1971b
Merge pull request #3174 from Security-Onion-Solutions/foxtrot
2021-02-27 09:49:46 -05:00
Jason Ertel
7451aa990b
Improve formatting of changes list
2021-02-27 08:14:44 -05:00
Jason Ertel
839ab30b2c
Merge pull request #3171 from Security-Onion-Solutions/foxtrot
...
Add changes.json for 2.3.30
2021-02-26 18:16:20 -05:00
Jason Ertel
9631327c71
Add changes.json for 2.3.30
2021-02-26 18:11:13 -05:00
William Wernert
33696398eb
Add new so-docker-prune script
...
* Script will pull list of so- images and prune any older than most recent + last version
2021-02-26 18:06:07 -05:00
Josh Patterson
b6fe8dec3b
Merge pull request #3170 from Security-Onion-Solutions/bugfix/setup-configure-network
...
Fix logic for configure network option in setup
2021-02-26 15:43:38 -05:00
William Wernert
fd877a2256
Fix logic for configure network option in setup
2021-02-26 15:40:20 -05:00
Mike Reeves
26a22b8e3b
Merge pull request #3169 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-02-26 14:37:09 -05:00
Jason Ertel
cc15e9a0b1
Merge branch 'dev' into foxtrot
2021-02-26 14:26:48 -05:00
Jason Ertel
4a03862fc4
Add suricata distributed automations
2021-02-26 14:26:28 -05:00
William Wernert
069f6eccbf
Merge pull request #3157 from Security-Onion-Solutions/feature/default-route-warn
...
[refactor] Make default route message a warning
2021-02-26 10:29:43 -05:00
William Wernert
be1f641bf0
[refactor] Make default route message a warning
...
Don't force users to exit setup if the default route and management NIC's IP don't match,
just warn them
2021-02-26 10:27:14 -05:00
William Wernert
8910b5c3a7
Merge pull request #3155 from Security-Onion-Solutions/bugfix/fleet-hostname-input
...
[fix] Change logic for collecting fleet custom hostname
2021-02-26 09:16:22 -05:00
William Wernert
333a7e6173
[fix] Change logic for collecting fleet custom hostname
2021-02-26 09:14:30 -05:00
Josh Patterson
b893a2b887
Merge pull request #3154 from Security-Onion-Solutions/salt-3002.5
...
upgrade to Salt 3002.5
2021-02-26 08:57:23 -05:00
m0duspwnens
b4c1c56e72
Merge remote-tracking branch 'remotes/origin/dev' into salt-3002.5
2021-02-26 08:38:02 -05:00
Josh Brower
45f626887d
Merge pull request #3153 from Security-Onion-Solutions/bugfix/so-playbook-sigmarefresh
...
Fix so-playbook-sigma-refresh
2021-02-26 08:36:36 -05:00
Josh Brower
5678e66b39
Fix so-playbook-sigma-refresh
2021-02-26 08:33:24 -05:00
Josh Brower
b8137214e4
Initial Support - Live Query to Hunt
2021-02-26 08:08:09 -05:00
Josh Patterson
dc673eef77
Merge pull request #3148 from Security-Onion-Solutions/salt-3002.5
...
Salt 3002.5
2021-02-25 23:00:35 -05:00
m0duspwnens
9fa625189f
upgrade to salt 3002.5 https://github.com/Security-Onion-Solutions/securityonion/issues/3147
2021-02-25 20:07:29 -05:00
Mike Reeves
e06ca75677
Merge pull request #3144 from Security-Onion-Solutions/interfaces
...
Don't disable NICs
2021-02-25 17:28:47 -05:00
Mike Reeves
a47a3d51c9
Merge pull request #3139 from Security-Onion-Solutions/feature/soup-log_size_limit
...
Show log_size_limit message at end of soup instead of during
2021-02-25 17:10:38 -05:00
William Wernert
b024dae72e
[fix] Don't call set_main_ip a second time
2021-02-25 15:19:28 -05:00
Josh Patterson
8a0e0e88e0
Merge pull request #3142 from Security-Onion-Solutions/issue/3130
...
stop zeek state.db from getting owned by root
2021-02-25 15:01:20 -05:00
Mike Reeves
2c8bc16c8f
Remove some nmcli business
2021-02-25 13:43:02 -05:00
Mike Reeves
37c13362df
Netowrk Manager needs to chill
2021-02-25 13:20:29 -05:00
Mike Reeves
51e8839daf
Inverse NIC offload
2021-02-25 11:46:00 -05:00
Josh Patterson
18365ed87d
Merge pull request #3140 from Security-Onion-Solutions/issue/3130
...
Issue/3130
2021-02-25 11:27:46 -05:00
m0duspwnens
fcd3f81400
fix quotes
2021-02-25 11:16:53 -05:00
m0duspwnens
c8213fa3d4
change docker exec
2021-02-25 11:07:54 -05:00
m0duspwnens
add66e750e
forgot to add -c
2021-02-25 10:49:09 -05:00
William Wernert
6a097beaff
Show log_size_limit message at end of soup instead of during
2021-02-25 10:47:29 -05:00
Doug Burks
79fefd83ef
Merge pull request #3134 from Security-Onion-Solutions/issue/3128
...
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 07:11:20 -08:00
m0duspwnens
d52abcbcbd
ensure zeekctl is run as user zeek https://github.com/Security-Onion-Solutions/securityonion/issues/3130
2021-02-25 09:58:07 -05:00
Doug Burks
c18c865764
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 09:23:19 -05:00
Doug Burks
ef1e296415
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 08:52:34 -05:00
Mike Reeves
ae89260793
Merge pull request #3127 from Security-Onion-Solutions/foxtrot
...
Add automation files for Suricata metadata
2021-02-25 08:26:20 -05:00
Jason Ertel
34dab9009c
Ensure Zeek spool dir is owned by Zeek to allow Zeek to start correctly
2021-02-25 08:10:13 -05:00
Jason Ertel
ef7cdf27bf
Add automation files for Suricata metadata
2021-02-25 07:43:11 -05:00
Mike Reeves
c39b516f38
Merge pull request #3121 from Security-Onion-Solutions/strelkainstall
...
Fix Strelka Rule updates, repo fix
2021-02-24 17:13:41 -05:00
Mike Reeves
39860ea6bd
Merge pull request #3123 from Security-Onion-Solutions/kilo
...
Add function to soup to notify user of log_size_limit issues
2021-02-24 17:09:07 -05:00
Mike Reeves
701cfe7e9a
Merge branch 'dev' into strelkainstall
2021-02-24 17:07:26 -05:00
William Wernert
4ae34f928c
Merge branch 'dev' into kilo
...
# Conflicts:
# setup/so-functions
2021-02-24 17:05:53 -05:00
Mike Reeves
ff577cdf41
Merge pull request #3079 from petiepooo/feature/eslogsize
...
calculate log_size_limit based on /nsm/elasticsearch
2021-02-24 17:03:35 -05:00
William Wernert
4a6ad7c87e
Set MAINIP to MNIC_IP when using a VPN
2021-02-24 16:31:45 -05:00
Mike Reeves
b30f964974
Moving the wildcard
2021-02-24 16:09:37 -05:00
Mike Reeves
262bf03595
Testing capitals
2021-02-24 16:04:53 -05:00
Mike Reeves
ae17a3aeb8
Fix Syntax try 3
2021-02-24 16:02:36 -05:00
Mike Reeves
ab66f175c5
Fix Syntax
2021-02-24 16:01:18 -05:00
Mike Reeves
8f3ba7633c
Fix Syntax
2021-02-24 15:57:18 -05:00
Mike Reeves
5949119cb5
Bypass route check
2021-02-24 15:53:55 -05:00
Mike Reeves
6058400aad
Bypass route check
2021-02-24 15:52:50 -05:00
William Wernert
f042312aac
Merge branch 'dev' into kilo
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-02-24 15:42:10 -05:00
Mike Reeves
52fd3c0470
Merge pull request #3122 from Security-Onion-Solutions/strelka_repo_update
...
Modify soup to add Strelka rule repo in pillar
2021-02-24 15:35:35 -05:00
Wes Lambert
6ea8eab9af
Modify soup to add Strelka rule repo in pillar
2021-02-24 20:32:47 +00:00
William Wernert
775f274962
Also check /nsm/elasticsearch in soup log_size_limit check
...
Reflect changes from PR#3079
2021-02-24 14:36:41 -05:00
William Wernert
e500e24802
Only show log_size_limit warning on dist if heavynode pillars exist
2021-02-24 13:56:59 -05:00
William Wernert
298f7da90b
Fix indent in set_default_log_size
2021-02-24 13:56:33 -05:00
Mike Reeves
38d60752b7
Merge pull request #3110 from Security-Onion-Solutions/dockerclean
...
Docker Cleanup
2021-02-24 13:44:06 -05:00
Josh Patterson
25ca70efd8
Merge pull request #3120 from Security-Onion-Solutions/issue/3115
...
ensure log_level and log_level_logfile are set to info in /etc/salt/minion
2021-02-24 13:36:34 -05:00
Mike Reeves
bdfec5176d
Dont disable unused interfaces during setup
2021-02-24 13:22:06 -05:00
William Wernert
ece79379a5
Add file name/path to log_size_limit message
2021-02-24 12:54:14 -05:00
William Wernert
ac6f1df86f
[fix] Only check log_size_limit on .2X -> .30
...
* Since we're showing a message in the middle of soup, wait for keypress if it's shown
2021-02-24 12:35:17 -05:00
William Wernert
4507a89d95
tar arg fix (-x -> -z)
2021-02-24 12:24:54 -05:00
William Wernert
2be7ccac33
Add function to notify user that log_size_limit may be incorrect
2021-02-24 12:24:32 -05:00
Josh Patterson
81331264e7
Merge pull request #3117 from Security-Onion-Solutions/issue/3115
...
logfile is 1 word
2021-02-24 11:57:33 -05:00
m0duspwnens
eba5d271aa
logfile is 1 word https://github.com/Security-Onion-Solutions/securityonion/issues/3115
2021-02-24 11:56:43 -05:00
Josh Patterson
a9066f491d
Merge pull request #3116 from Security-Onion-Solutions/issue/3115
...
Issue/3115
2021-02-24 11:51:42 -05:00
m0duspwnens
3552abfca1
ensure info log level -
2021-02-24 11:50:08 -05:00
Mike Reeves
1d45472b48
Fix Strelka Rule updates, repo fix
2021-02-24 11:30:43 -05:00
Mike Reeves
68c683e3bf
Merge pull request #3114 from Security-Onion-Solutions/foxtrot
...
Add retry support for 'docker pull' command
2021-02-24 11:25:14 -05:00
Jason Ertel
050058a959
Add retry support for 'docker pull' command
2021-02-24 09:34:14 -05:00
Mike Reeves
09c94ddf95
Docker Cleanup
2021-02-24 08:57:25 -05:00
Mike Reeves
54367db99b
Merge pull request #3108 from Security-Onion-Solutions/issue/3056
...
add estimated EPS graphs to Grafana for manager, mastersearch and standalone nodes
2021-02-24 08:49:36 -05:00
Mike Reeves
56daae64be
Merge pull request #3097 from Security-Onion-Solutions/sometacleanup
...
Clean up on sid numbers
2021-02-24 08:24:48 -05:00
Mike Reeves
00deab9305
Merge pull request #3100 from Security-Onion-Solutions/kilo
...
Add so-preflight + usage to so-monitor-add, fix managersearch missing from so-rule
2021-02-23 17:32:41 -05:00
Mike Reeves
fa6fd20ff9
Merge pull request #3088 from Security-Onion-Solutions/soupairgap
...
Syn the latest rules on an airgap install
2021-02-23 17:31:29 -05:00
Mike Reeves
d195efa8e5
Merge pull request #3098 from Security-Onion-Solutions/feature/update-soup
...
Update SOUP with so-playbook-sigma-refresh
2021-02-23 15:46:48 -05:00
Josh Brower
a7eb3cd38d
Add so-playbook-sigma-refresh
2021-02-23 15:43:09 -05:00
Mike Reeves
5baa4cb6a5
Clean up on sid numbers
2021-02-23 15:42:58 -05:00
Josh Patterson
988ad5f8fc
Merge pull request #3086 from Security-Onion-Solutions/issue/3056
...
Issue/3056
2021-02-23 14:53:42 -05:00
William Wernert
a361ca0e19
[fix] Add managersearch node type to so-rule pillar search
2021-02-23 14:15:17 -05:00
William Wernert
9cf15cdae5
[fix] Reword so-monitor-add help message
2021-02-23 13:55:18 -05:00
William Wernert
d5477b4721
Add usage/help message to so-monitor-add
2021-02-23 13:48:54 -05:00
William Wernert
5a2fa26d72
Add ET OPEN/PRO URLs
2021-02-23 13:47:52 -05:00
William Wernert
61a23509a1
[fix] grep -q doesn't give output to parse, so remove the flag
2021-02-23 13:43:10 -05:00
William Wernert
25698dafe3
Add initial pre-flight check script
2021-02-23 13:25:54 -05:00
Mike Reeves
186710964b
Fix Airgap Rule Path
2021-02-23 13:07:23 -05:00
Mike Reeves
3b32eb539f
Copy latest rules when using airgaps
2021-02-23 11:21:23 -05:00
m0duspwnens
6ee69ff21b
Merge remote-tracking branch 'remotes/origin/dev' into issue/3056
2021-02-23 11:11:50 -05:00
m0duspwnens
00cc640224
add EPS to managersearch dashboard
2021-02-23 11:08:08 -05:00
Mike Reeves
40721d7dec
Merge pull request #3084 from Security-Onion-Solutions/feature/log-rotate
...
Configure fleet result.log to rotate
2021-02-23 10:20:53 -05:00
m0duspwnens
e76ee07932
add CPUS for cpu count
2021-02-23 10:10:58 -05:00
Josh Brower
122e34b69c
Configure fleet result.log to rotate
2021-02-23 10:06:24 -05:00
m0duspwnens
1f2475c1c5
add eps graph to manager
2021-02-23 10:06:11 -05:00
m0duspwnens
141fbaced1
add eps graph to standalone
2021-02-23 09:40:21 -05:00
William Wernert
fa9fe82046
Merge pull request #3082 from Security-Onion-Solutions/kilo
...
Add so-rule script + soup pillar changes
2021-02-23 08:56:49 -05:00
William Wernert
fad87a8789
Fix function name (.20 -> .2X)
2021-02-23 08:51:44 -05:00
William Wernert
9287209750
Merge branch 'soup2.3.30' into feature/so-rules
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-02-22 16:07:15 -05:00
William Wernert
982967fdde
Merge branch 'dev' into feature/so-rules
2021-02-22 16:01:48 -05:00
William Wernert
fb3af255d9
Add more info to apply messaging
2021-02-22 15:50:07 -05:00
William Wernert
3e3c923ab9
Arrange missing pillar error message better
2021-02-22 15:44:29 -05:00
William Wernert
b00cc88801
[fix] Unreverse apply prompt actions
2021-02-22 15:43:56 -05:00
William Wernert
e9b85337ff
[fix] Only prompt if entry doesn't exist, deep compare arrays
2021-02-22 15:41:09 -05:00
William Wernert
fd33a6cebe
Rename script, prompt user to apply if they didn't pass --apply
2021-02-22 15:32:18 -05:00
William Wernert
cdf766eeae
explicitely -> explicitly
2021-02-22 14:30:26 -05:00
William Wernert
8fc82fa3ef
Fix minion pillar directory
2021-02-22 14:27:22 -05:00
Mike Reeves
6ed1cc3875
Add Soup Functions
2021-02-22 14:02:37 -05:00
Doug Burks
84f138772f
Merge pull request #3072 from Security-Onion-Solutions/kilo
...
Additional fine tuning of Suricata metadata support
2021-02-22 10:57:02 -08:00
doug
71c7ffae3e
Improve support for Suricata metadata #2200
2021-02-22 13:49:29 -05:00
doug
bcce205430
Improve support for Suricata metadata #2200
2021-02-22 13:00:14 -05:00
Jason Ertel
943cbdbf1f
Merge pull request #3073 from Security-Onion-Solutions/delta
...
Apply action on PR only now that PRs are mandatory
2021-02-22 12:50:38 -05:00
Jason Ertel
43e0c3a60b
Apply action on PR only now that PRs are mandatory
2021-02-22 12:35:17 -05:00
Mike Reeves
d5069d12cf
Merge pull request #3071 from Security-Onion-Solutions/delta
...
Add acng to import installs for consistency
2021-02-22 11:34:23 -05:00
William Wernert
e65c9e5c7c
Don't expect apply arg at beginning of command
2021-02-22 11:29:30 -05:00
William Wernert
4bcb7403a9
Add apply option to end of command
2021-02-22 11:27:03 -05:00
William Wernert
bef3a6921c
[fix] SID wildcards are not parsed by idstools, remove
2021-02-22 11:12:02 -05:00
William Wernert
f7bef9200b
[fix] Only look for manager-type pillars
...
* SID disabling is only managed globally for now, so don't give the option to edit a different pillar
2021-02-22 10:38:53 -05:00
William Wernert
bb6f3107bc
[fix] idstools can run on an import node as well
2021-02-22 10:29:40 -05:00
doug
3467f30603
Improve support for Suricata metadata #2200
2021-02-22 10:27:24 -05:00
Doug Burks
d4ee2b86e6
Merge pull request #3070 from Security-Onion-Solutions/dev
...
Dev to Kilo
2021-02-22 07:22:49 -08:00
William Wernert
f2a1e89633
Merge branch 'dev' into feature/so-rules
2021-02-22 10:03:14 -05:00
William Wernert
abae673568
Update help text to reflect arg requirement changes
2021-02-22 10:00:29 -05:00
Jason Ertel
747d62dae5
Add acng to import installs for consistency
2021-02-22 09:44:24 -05:00
Josh Brower
5ca3dc492c
Merge pull request #3061 from Security-Onion-Solutions/foxtrot
...
Fix Playbook Fields & Mappings
2021-02-21 09:40:59 -05:00
Doug Burks
85b9cac110
Merge pull request #3063 from Security-Onion-Solutions/dev
...
Dev to kilo
2021-02-21 03:40:05 -08:00
Mike Reeves
40780f192e
Merge pull request #3062 from Security-Onion-Solutions/delta
...
fix merge issue
2021-02-20 19:15:16 -05:00
Jason Ertel
7222f1faa5
fix merge issue
2021-02-20 16:41:12 -05:00
Mike Reeves
e07e0b201d
Merge pull request #3058 from Security-Onion-Solutions/delta
...
Fix intermittent Suricata rules load issue
2021-02-20 10:27:13 -05:00
Jason Ertel
9d3c82a589
Disable unused features for import installations
2021-02-19 20:14:55 -05:00
Jason Ertel
04b3a20e22
Merge branch 'dev' into delta
2021-02-19 20:12:07 -05:00
Mike Reeves
cb6fe75ddb
Merge pull request #3055 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Rename filter.rules to filters.rules
2021-02-19 15:36:01 -05:00
Mike Reeves
8ab12c71a1
Rename filter.rules to filters.rules
2021-02-19 15:34:45 -05:00
Josh Brower
046cc0fbb0
Merge pull request #3052 from Security-Onion-Solutions/feature/sigma-tweaks
...
Feature/sigma tweaks
2021-02-19 15:16:34 -05:00
Josh Brower
8c69e19419
Add sigma refresh script
2021-02-19 15:14:37 -05:00
Josh Brower
2a324eac32
Add sigma refresh script
2021-02-19 15:12:55 -05:00
Mike Reeves
8db3602679
Merge pull request #3049 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix name and update examples
2021-02-19 15:01:04 -05:00
Mike Reeves
08abad747d
Fix name and update examples
2021-02-19 14:59:27 -05:00
William Wernert
c73970620d
[fix] Correct indent
2021-02-19 14:38:43 -05:00
William Wernert
34174a3290
Print relevant help if no/partial command passed
2021-02-19 14:34:32 -05:00
Mike Reeves
0ea29144a8
Merge pull request #3047 from Security-Onion-Solutions/surifile2
...
Suricata as Meta Data, File Extraction, And Parsing changes
2021-02-19 14:09:38 -05:00
Doug Burks
3ea1ec99d5
Merge pull request #3048 from Security-Onion-Solutions/kilo
...
Update syslog ingest parser to accomodate pfSense filterlog changes #3033
2021-02-19 11:02:56 -08:00
William Wernert
d205fff3ba
Run ssh-harden in setup per #1932
2021-02-19 13:45:23 -05:00
Jason Ertel
9302b9302b
Clear salt fileserver cache to ensure the new local.rules file gets picked up on the filesync
2021-02-19 11:13:31 -05:00
Mike Reeves
b4b449aa14
Pull in Suricata changes
2021-02-19 11:01:15 -05:00
William Wernert
4689e32ce4
Add sed for curly braces in minion pillars to soup
2021-02-19 10:18:06 -05:00
William Wernert
2184c6d59f
[fix] Create dict value if it doesn't exist
2021-02-19 09:31:22 -05:00
William Wernert
9183c0a92c
[feat] Initial so-rules script
...
* Quote curly braces in minion pillar, need to add sed function in soup
2021-02-19 09:24:12 -05:00
doug
88eb5b1d61
Update syslog ingest parser to accomodate pfSense filterlog changes #3033
2021-02-19 08:02:32 -05:00
Doug Burks
5493b3ef91
Merge pull request #3032 from Security-Onion-Solutions/dev
...
Update kilo to latest dev
2021-02-19 04:53:23 -08:00
Josh Patterson
4a510df205
Merge pull request #3026 from Security-Onion-Solutions/delta
...
Delta
2021-02-18 16:31:18 -05:00
Jason Ertel
faa78c0e26
Salt doesn't like a name starting with a non alpha-numeric char. Switch back to long if/then format
2021-02-18 14:51:09 -05:00
Josh Patterson
79e7b1da4d
Merge pull request #3021 from Security-Onion-Solutions/issue/2989
...
change suricata clean cron to run once a day
2021-02-18 14:07:40 -05:00
m0duspwnens
03487c2a31
change suricata clean cron to run once a day
2021-02-18 14:06:45 -05:00
Jason Ertel
e912b2fd96
Move idstools to run after nginx runs
2021-02-18 12:50:00 -05:00
Josh Patterson
0ab9577863
Merge pull request #3018 from Security-Onion-Solutions/all_rules_dont_show_changes
...
dont show changes since file can be large
2021-02-18 12:23:54 -05:00
m0duspwnens
bf100a2310
dont show changes since file can be large
2021-02-18 12:23:22 -05:00
Josh Patterson
2092044335
Merge pull request #3017 from Security-Onion-Solutions/issue/1237
...
load templates all the time
2021-02-18 12:13:49 -05:00
m0duspwnens
e730efb4ec
load templates all the time
2021-02-18 12:12:18 -05:00
Josh Patterson
76cdc45fad
Merge pull request #3016 from Security-Onion-Solutions/all_rules_dont_show_changes
...
Don't show changes because all.rules can be large
2021-02-18 12:00:08 -05:00
m0duspwnens
069997a65c
Don't show changes because all.rules can be large
2021-02-18 11:56:25 -05:00
Jason Ertel
6f7bc650a0
Apply reserved ports if the existing file is 0 bytes
2021-02-18 11:20:13 -05:00
Josh Patterson
a9da761fab
Merge pull request #3012 from Security-Onion-Solutions/issue/2989
...
Issue/2989
2021-02-18 10:52:23 -05:00
m0duspwnens
95df18c545
limit eve logs and gz files based on days
2021-02-18 10:45:20 -05:00
m0duspwnens
a4d5f58256
fix surilogcompress
2021-02-18 10:33:47 -05:00
Josh Patterson
3f7cdb933f
Merge pull request #3010 from Security-Onion-Solutions/issue/2989
...
Issue/2989
2021-02-18 09:58:35 -05:00
m0duspwnens
74ca4487de
ensure at least 2 eve files are kept https://github.com/Security-Onion-Solutions/securityonion/issues/2989
2021-02-18 09:51:40 -05:00
m0duspwnens
4b07d5e457
add identifier to eve clean cron
2021-02-18 09:39:54 -05:00
m0duspwnens
041d193f2d
fix brackets
2021-02-18 09:37:37 -05:00
m0duspwnens
0bef8b6662
limit number of eve.json files for suricata https://github.com/Security-Onion-Solutions/securityonion/issues/2989
2021-02-18 09:26:59 -05:00
Josh Brower
b5087b815a
Merge pull request #3002 from Security-Onion-Solutions/feature/sigma-tweaks
...
Update .security analyzer
2021-02-17 16:38:22 -05:00
Josh Brower
d2a74c80e2
Update .security analyzer
2021-02-17 16:37:31 -05:00
Josh Brower
741f674a4c
Merge pull request #3001 from Security-Onion-Solutions/dev
...
Dev
2021-02-17 16:36:49 -05:00
Pete
29c5f3212f
make log_size_limit calculation more specific
...
Extend the directory traversal into /nsm/elasticsearch in case that's a separate mountpoint from /nsm/.
2021-02-17 16:53:31 +00:00
Josh Patterson
174ed84750
Merge pull request #2993 from Security-Onion-Solutions/issue/2736
...
logrotate strelka
2021-02-17 11:47:52 -05:00
m0duspwnens
7a595df5b6
strelka logrotate - https://github.com/Security-Onion-Solutions/securityonion/issues/2736
2021-02-17 11:17:41 -05:00
m0duspwnens
2b07d89b5a
error: /opt/so/conf/sensor-rotate.conf:8 unknown option 'endscript' -- ignoring line
2021-02-17 11:01:18 -05:00
m0duspwnens
e6ae1af85f
test rotating strelka log at 100k
2021-02-17 10:47:06 -05:00
Josh Patterson
ce313d8dc4
Merge pull request #2992 from Security-Onion-Solutions/issue/2737
...
fix logic for log_size_limit
2021-02-17 10:09:54 -05:00
Josh Patterson
fddef1a6f4
Merge pull request #2985 from Security-Onion-Solutions/issue/2915
...
remove old backup files
2021-02-17 09:43:58 -05:00
William Wernert
cda36f178b
Merge pull request #2979 from Security-Onion-Solutions/foxtrot
...
Setup fixes/improvements
2021-02-16 17:14:59 -05:00
Josh Patterson
bec437c2cf
Merge pull request #2984 from Security-Onion-Solutions/issue/2737
...
Issue/2737
2021-02-16 15:41:46 -05:00
m0duspwnens
996bf0768b
fix logic for log_size_limit https://github.com/Security-Onion-Solutions/securityonion/issues/2737
2021-02-16 15:40:01 -05:00
William Wernert
0bd5ddf6a6
Grammar + misc fixes per PR review
...
* Remove unnecessary `apt-get update` commands
* Change `if ! (command); then exit 1; fi` to `command || exit 1` to avoid subshell
2021-02-16 14:17:41 -05:00
Doug Burks
8016511414
Merge pull request #2981 from Security-Onion-Solutions/kilo
...
Hunt: improve Wazuh queries #2383
2021-02-16 10:38:53 -08:00
Josh Patterson
eb18ec552c
Merge pull request #2980 from Security-Onion-Solutions/issue/2915
...
Issue/2915
2021-02-16 12:01:37 -05:00
doug
fabe3c87f2
Hunt: improve Wazuh queries #2383
2021-02-16 11:56:14 -05:00
m0duspwnens
7099ed4bf5
delete many backup files
2021-02-16 11:55:49 -05:00
m0duspwnens
1ccc5480e1
remove oldest backup
2021-02-16 11:40:45 -05:00
Doug Burks
d6fa54b606
Merge pull request #2975 from Security-Onion-Solutions/kilo
...
Issues 2954 and 2361 - Kibana config
2021-02-16 08:30:46 -08:00
William Wernert
3323e900ef
[fix] Fix indent (pt 2)
2021-02-16 11:17:36 -05:00
William Wernert
7a9f801eb1
[fix] Add more apt-get update commands
...
Fixes #2962
2021-02-16 10:24:58 -05:00
William Wernert
38a5b86813
Make apt-get syntax consistent
2021-02-16 10:24:07 -05:00
William Wernert
23221065eb
Preset MANAGERUPDATES var for airgap since we don't prompt now
2021-02-16 09:43:54 -05:00
William Wernert
5e8d09be51
[fix] Fix indent
2021-02-16 09:42:35 -05:00
doug
397d8d0964
Kibana 7.10.2 config changes #2954
2021-02-14 07:04:51 -05:00
doug
3248edea8b
Update Kibana dashboard hyperlinks to new url format #2361
2021-02-12 17:25:42 -05:00
Josh Patterson
bf3b609a44
Merge pull request #2955 from Security-Onion-Solutions/issue/1237
...
Issue/1237
2021-02-12 16:04:58 -05:00
m0duspwnens
100601c452
only laod templates if they change https://github.com/Security-Onion-Solutions/securityonion/issues/1237
2021-02-12 16:03:45 -05:00
doug
31a0c2bc82
Update Kibana dashboard hyperlinks to new url format #2361
2021-02-12 15:37:25 -05:00
doug
797d2c4dba
Kibana 7.10.2 config changes #2954
2021-02-12 15:35:06 -05:00
Doug Burks
fd4cb0b7a8
Kibana 7.10.2 config changes #2954
2021-02-12 14:05:29 -05:00
Doug Burks
c717773fc3
Kibana 7.10.2 config changes #2954
2021-02-12 14:04:00 -05:00
Josh Patterson
ce04b109fe
Merge pull request #2950 from Security-Onion-Solutions/delta
...
Disable ICMP timestamps by default
2021-02-12 13:54:59 -05:00
William Wernert
4affb20b27
Give context to metadata tool choice
2021-02-12 13:42:14 -05:00
William Wernert
724f5cad78
Warn user if using "securityonion" as hostname
2021-02-12 12:55:55 -05:00
William Wernert
8323f3f57a
[fix] Fix logic to correctly hide prompt
2021-02-12 12:23:45 -05:00
Josh Patterson
a8598a50e4
Merge pull request #2953 from Security-Onion-Solutions/issue/2756
...
remove /etc/yum.repos.d/salt-2019-2-5.repo if present
2021-02-12 12:05:21 -05:00
m0duspwnens
3b0c2b3e91
remove /etc/yum.repos.d/salt-2019-2-5.repo if present https://github.com/Security-Onion-Solutions/securityonion/issues/2756
2021-02-12 12:04:08 -05:00
William Wernert
1ffa7afefa
eval-net answerfile corrections
...
* HOSTNAME: standalone -> eval
* install_type: STANDALONE -> EVAL
2021-02-11 16:20:29 -05:00
William Wernert
188d844d27
Redirect stderr of minion grep to /dev/null
2021-02-11 13:49:39 -05:00
m0duspwnens
b4e9a44572
Merge remote-tracking branch 'remotes/origin/dev' into issue/1704
2021-02-11 11:10:06 -05:00
m0duspwnens
7e4d7a6985
drop icmp timestamp replies https://github.com/Security-Onion-Solutions/securityonion/issues/1704
2021-02-11 11:09:21 -05:00
William Wernert
d9b4c09cf0
[fix] Don't show irrelevant prompts during airgap setup
2021-02-11 10:52:18 -05:00
William Wernert
ce8db8abdb
[fix] Only run salt commands during reinstall if master is configured
2021-02-11 10:51:04 -05:00
Josh Patterson
bf8ca590d0
Merge pull request #2932 from Security-Onion-Solutions/delta
...
only save at the end
2021-02-11 09:25:31 -05:00
Mike Reeves
97594f84cb
Merge pull request #2930 from Security-Onion-Solutions/vpn
...
VPN Configuration
2021-02-11 09:21:17 -05:00
Mike Reeves
f8903c2554
Fix extra character
2021-02-10 12:58:02 -05:00
Mike Reeves
9eb1e6a448
Prevent the tun interface from being disabled
2021-02-10 12:51:26 -05:00
m0duspwnens
3cfbc61f4e
only save at the end
2021-02-10 11:15:39 -05:00
Mike Reeves
10553938b5
Merge pull request #2901 from Security-Onion-Solutions/curatorwarm
...
add warm node action for hot/warm
2021-02-08 12:08:23 -05:00
Mike Reeves
125f7d6262
add warm node action for hot/warm
2021-02-08 11:49:49 -05:00
Mike Reeves
940bac3634
Merge pull request #2889 from Security-Onion-Solutions/backupsfix
...
Backupsfix
2021-02-08 10:40:20 -05:00
Mike Reeves
5043b970ef
Fix tar syntax
2021-02-06 19:14:44 -05:00
Mike Reeves
a3ca84db66
Fix backupdir name state
2021-02-06 15:32:42 -05:00
Mike Reeves
bf79c92456
Lock down Backups folder permissions
2021-02-05 22:31:08 -05:00
Mike Reeves
8f97973fac
Lock down Backups folder permissions
2021-02-05 22:17:31 -05:00
Jason Ertel
4d6d2edd17
Merge pull request #2872 from Security-Onion-Solutions/automation/ami
...
Add locking to so-firewall
2021-02-04 16:14:16 -05:00
Jason Ertel
e427f8178d
Implement locking to so-firewall script
2021-02-04 16:06:11 -05:00
Jason Ertel
a13b31fbcc
Merge branch 'dev' into automation/ami
2021-02-04 16:05:39 -05:00
Mike Reeves
d4e5ab477f
Merge pull request #2854 from Security-Onion-Solutions/revert-2830-filebeatlimits
...
Revert "Make filebeat retry forever"
2021-02-03 22:26:03 -05:00
Jason Ertel
58e4205602
Revert "Make filebeat retry forever"
2021-02-03 21:46:29 -05:00
Jason Ertel
6b54a29ac7
Remove 'new user' references from so-user
2021-02-03 15:23:58 -05:00
Jason Ertel
3ebedcd4e8
Merge pull request #2830 from Security-Onion-Solutions/filebeatlimits
...
Make filebeat retry forever
2021-02-03 11:32:05 -05:00
Mike Reeves
179efa3a51
Merge pull request #2833 from Security-Onion-Solutions/automation/ami
...
Adjust AMI test network
2021-02-02 21:05:34 -05:00
Jason Ertel
91480abaa0
Adjust AMI test network
2021-02-02 17:41:41 -05:00
Mike Reeves
55a8f6aa7a
Make filebeat retry forever
2021-02-02 16:41:52 -05:00
William Wernert
8f0b0ac936
Merge pull request #2825 from Security-Onion-Solutions/foxtrot
...
Setup: dpkg retry, whiptail changes, fix zeek state condition
2021-02-02 14:41:48 -05:00
Josh Patterson
ef2fe2bb61
Merge pull request #2828 from Security-Onion-Solutions/delta
...
adjust timeout for ssl states and pillarize ElastAlert
2021-02-02 13:35:28 -05:00
William Wernert
46581c0528
[fix] Don't use ZEEKVERSION var, check pillar value
2021-02-02 12:45:56 -05:00
William Wernert
2253603544
[fix] Don't try to inherit home net on standalone
2021-02-02 12:11:47 -05:00
Jason Ertel
e7e1f4c155
Merge pull request #2820 from Security-Onion-Solutions/automation/ami
...
Adjust automation files for distributed AMI
2021-02-01 15:33:53 -05:00
m0duspwnens
b3c08229db
Merge remote-tracking branch 'remotes/origin/sslstate/timeouts_retry' into delta
2021-02-01 15:33:31 -05:00
Jason Ertel
f736d9f8dd
Adjust automation files for distributed AMI
2021-02-01 15:27:53 -05:00
m0duspwnens
8cf0a3da98
remove seconds
2021-02-01 15:19:47 -05:00
William Wernert
8d01b87ab5
Merge branch 'dev' into foxtrot
2021-02-01 13:56:33 -05:00
William Wernert
8f476bbbdd
[fix] Add back removed if statement
2021-02-01 13:11:51 -05:00
m0duspwnens
8ff6d1639a
Merge remote-tracking branch 'remotes/origin/dev' into issue/1191
2021-02-01 12:51:00 -05:00
William Wernert
daebe90b6e
[fix] fix retry command handling
...
* use eval "$cmd" to handle strings correctly
* add-apt-repo doesn't need dpkg lock so don't use retry for those lines
2021-02-01 12:06:19 -05:00
William Wernert
44617fdddf
[fix] Run command being retried within quotes
2021-02-01 11:28:28 -05:00
William Wernert
02f0ef989b
[fix] <cmd> || <fail_reactor>; exit 1 will always exit, fix this
2021-02-01 11:11:01 -05:00
William Wernert
36ce389202
Remove wait_for_apt, use common retry function to run apt commands
2021-02-01 10:55:14 -05:00
Jason Ertel
1c8a8f6b7b
Merge pull request #2805 from Security-Onion-Solutions/elasticrollback
...
Add features option back
2021-01-30 21:00:10 -05:00
Mike Reeves
160d307f4a
Disable ML for features #2788
2021-01-30 20:00:41 -05:00
Mike Reeves
4212afe0c9
Add features option back
2021-01-30 19:57:18 -05:00
m0duspwnens
0ea504c16a
remove space
2021-01-29 17:32:48 -05:00
m0duspwnens
8ca15a6679
Merge remote-tracking branch 'remotes/origin/dev' into issue/1191
2021-01-29 16:54:26 -05:00
Mike Reeves
929896c191
Merge pull request #2797 from Security-Onion-Solutions/raid2
...
Raid Setup for Appliances
2021-01-29 16:30:43 -05:00
Mike Reeves
22e6e45667
Remove other changes
2021-01-29 16:14:14 -05:00
William Wernert
edfd985353
Merge branch 'bugfix/zeek-prompts' into foxtrot
2021-01-29 16:04:56 -05:00
Mike Reeves
18f2c7b482
Raid Setup for Appliances
2021-01-29 16:03:18 -05:00
Mike Reeves
aa93e2b48f
Merge pull request #2794 from Security-Onion-Solutions/foxtrot
...
Add retry capabilities to image/sig pulls
2021-01-29 15:57:41 -05:00
William Wernert
7a3c7322fc
[fix] Only check for ZEEKVERSION on manager installs
2021-01-29 15:36:50 -05:00
m0duspwnens
618b94b9b6
add newline
2021-01-29 15:31:05 -05:00
m0duspwnens
f50a89a0cf
watch elastalert config and restart docker if chagnes
2021-01-29 15:28:59 -05:00
m0duspwnens
482b6eb699
Merge remote-tracking branch 'remotes/origin/dev' into sslstate/timeouts_retry
2021-01-29 13:44:27 -05:00
m0duspwnens
e6ecd609cc
change timeouts to 30s
2021-01-29 13:44:11 -05:00
Jason Ertel
2926527ad0
Place sig keys in same dir as other sig files
2021-01-29 13:21:58 -05:00
Jason Ertel
73909c4dea
Place sig keys in same dir as other sig files
2021-01-29 13:00:56 -05:00
Jason Ertel
c055427e40
Add support for image key/sig retries
2021-01-29 11:18:06 -05:00
Jason Ertel
194f480017
Airgap fix for import nodes missing rules
2021-01-28 13:03:47 -05:00
m0duspwnens
0936dbdb1c
add timeouts and retries to ca/ssl states
2021-01-28 11:40:31 -05:00
Jason Ertel
f12947362b
Adjust test network IPs
2021-01-28 11:35:10 -05:00
Jason Ertel
bfa6aabc4b
Correct automation for airgap import to avoid infinite loop during setup
2021-01-28 10:38:03 -05:00
Jason Ertel
34c2116669
Adjust test network allocation
2021-01-27 16:02:36 -05:00
m0duspwnens
b7aef32eeb
fix missing }
2021-01-27 15:50:23 -05:00
m0duspwnens
8df9e020ac
pillarize elastalert https://github.com/Security-Onion-Solutions/securityonion/issues/1191
2021-01-27 15:35:29 -05:00
m0duspwnens
0ac19142c4
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-27 10:52:05 -05:00
Josh Brower
d277bf6d05
Merge pull request #2749 from Security-Onion-Solutions/bugfix/osquery-wel-parsing
...
Update Osquery Windows Eventlog Parsing
2021-01-27 09:17:17 -05:00
Josh Brower
13ab4c66eb
Update Osquery Windows Eventlog Parsing
2021-01-27 09:15:54 -05:00
William Wernert
f5c044e3e3
[fix] Log directory fixes
...
* The playbook log dir is owned by the socore group, so we can use `su root socore`
* Addresses https://github.com/Security-Onion-Solutions/securityonion/pull/2681#issuecomment-767761670
---
* influxdb runs as root, so we can set the log directory permissions to 755 for this service
2021-01-26 16:07:34 -05:00
m0duspwnens
be0b2b99e9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-26 13:48:49 -05:00
William Wernert
1939fe85d7
[fix] Revert directory permission changes
2021-01-26 13:41:10 -05:00
Josh Patterson
f8242a931c
Merge pull request #2733 from Security-Onion-Solutions/automation/ssh_prompts
...
fix if statement for isntalling sshpass
2021-01-26 09:57:32 -05:00
m0duspwnens
ffd01d6975
fix if statement for isntalling sshpass
2021-01-26 09:49:19 -05:00
m0duspwnens
f1faab7b1a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-26 09:04:00 -05:00
William Wernert
7b2ec05dbf
[fix] Add missing fi
2021-01-25 19:57:34 -05:00
Mike Reeves
bcd5bdd82d
Merge pull request #2730 from Security-Onion-Solutions/telegraf3
...
Add EPS and RAID status collection for telegraf
2021-01-25 19:37:03 -05:00
Mike Reeves
3b1cea94d1
Merge branch 'dev' into telegraf3
2021-01-25 19:36:49 -05:00
Mike Reeves
88abd284a7
Fix Conflicts
2021-01-25 19:35:32 -05:00
Mike Reeves
891a7592d8
Fix Conflicts
2021-01-25 19:33:49 -05:00
Mike Reeves
e43a80b9c6
Add EPS and RAID status collection for telegraf
2021-01-25 19:28:30 -05:00
Mike Reeves
4ef38f8d04
Add EPS and RAID status collection for telegraf
2021-01-25 19:14:46 -05:00
Josh Patterson
049daa6701
Merge pull request #2725 from Security-Onion-Solutions/automation/ssh_prompts
...
Automation/ssh prompts
2021-01-25 17:21:55 -05:00
Jason Ertel
df21b28d5c
Update copyright year
2021-01-25 17:11:42 -05:00
Jason Ertel
b0c74cf38c
Add import automation files for other platforms
2021-01-25 16:46:52 -05:00
Jason Ertel
ae233b5757
Update AMI automation files for distributed install
2021-01-25 15:53:25 -05:00
Jason Ertel
8ec0b95f02
Rename AMI automation files for consistency with other files
2021-01-25 15:53:25 -05:00
m0duspwnens
2f8b5afe3e
Merge remote-tracking branch 'remotes/origin/issue/2722' into automation/ssh_prompts
2021-01-25 15:23:39 -05:00
m0duspwnens
944817732b
grep for the scrip to be running https://github.com/Security-Onion-Solutions/securityonion/issues/2722
2021-01-25 15:22:04 -05:00
m0duspwnens
17a1189e42
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-25 15:20:46 -05:00
m0duspwnens
50345628f0
Merge remote-tracking branch 'remotes/origin/dev' into automation/ssh_prompts
2021-01-25 13:48:08 -05:00
m0duspwnens
7dcca6f364
change when we detect os and wait_for_apt when installing sshpass
2021-01-25 13:47:51 -05:00
Mike Reeves
6e9bdde9e2
Merge pull request #2721 from Security-Onion-Solutions/sosappliance
...
Fix function for appliances
2021-01-25 13:26:28 -05:00
Mike Reeves
2e32b53158
Fix function for appliances
2021-01-25 13:20:46 -05:00
m0duspwnens
e1f7c090f3
detect os and cloud sooner
2021-01-25 10:25:41 -05:00
William Wernert
2a4eac74c4
Merge pull request #2681 from Masaya-A/logrotate-fix
...
Log Rotation Fix (common-rotate)
2021-01-25 10:14:39 -05:00
m0duspwnens
fe09479dde
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-25 09:55:52 -05:00
Masaya-A
995d618ff5
Add cron.absent to remove old cron job if present
2021-01-25 15:45:33 +09:00
Mike Reeves
560e510b44
Merge pull request #2715 from Security-Onion-Solutions/sosappliance
...
Sosappliance
2021-01-24 12:06:18 -05:00
Mike Reeves
b4c8b439a0
Detect if this is an SOS appliance
2021-01-24 12:02:34 -05:00
Mike Reeves
85e2a14f1e
Put functions in correct order
2021-01-24 11:52:45 -05:00
Jason Ertel
6f14f27ca0
Add automation files for distributed network variations
2021-01-23 11:04:07 -05:00
William Wernert
59a4b148bc
Merge branch 'dev' into logrotate-fix
2021-01-22 15:20:55 -05:00
William Wernert
2159914742
Merge pull request #2708 from Security-Onion-Solutions/bugfix/telegraf-zombie-procs
...
Bugfix/telegraf zombie procs
2021-01-22 15:20:09 -05:00
Jason Ertel
47d69bbc9e
Move from quay.io to ghcr.io
2021-01-22 13:53:49 -05:00
William Wernert
7273c8a066
[fix] Also rotate stenographer log as per #2681
2021-01-22 12:46:21 -05:00
William Wernert
4079f8a8e8
[fix] Telegraf doesn't clean up zombie processes, use init flag to fix this
2021-01-22 12:23:09 -05:00
William Wernert
f1781b1fde
[fix] Set timeout for scripts (15s, 3x default 5s)
2021-01-22 12:15:29 -05:00
Jason Ertel
537f7529f8
Increase Kibana wait from 3 minutes to 15 minutes due to the longer init time needed for Kibana to start (because of the recent ES changes)
2021-01-22 10:09:15 -05:00
Masaya-A
249651edc7
Delete suri-rotate.conf
2021-01-22 10:08:23 +09:00
Masaya-A
e0bbc8cc51
Delete surirotate
2021-01-22 10:08:07 +09:00
Masaya-A
f156106e57
Update salt/common/files/log-rotate.conf
...
Co-authored-by: William Wernert <william.wernert@gmail.com >
2021-01-22 09:29:08 +09:00
Masaya-A
bcdf826204
Update init.sls
2021-01-22 09:26:52 +09:00
Mike Reeves
636687ac59
Merge pull request #2702 from Security-Onion-Solutions/essecurity
...
SSL with Elastic Basic license. Remove features option.
2021-01-21 13:57:28 -05:00
Mike Reeves
9408d62c65
Remove features
2021-01-21 13:55:53 -05:00
Mike Reeves
f85ecf254e
Fix dupe
2021-01-21 13:21:08 -05:00
Mike Reeves
9f984036c5
Use the internmediate cert
2021-01-21 13:00:46 -05:00
Mike Reeves
b0914fa604
try .p12
2021-01-21 12:46:00 -05:00
Mike Reeves
9759990233
Switch to java key store
2021-01-21 12:29:45 -05:00
Mike Reeves
bb523c44e6
Enable features temporarily
2021-01-21 12:19:41 -05:00
Mike Reeves
013b706ce4
Enable http ssl
2021-01-21 12:13:23 -05:00
weslambert
583b65e952
Fix syntax
2021-01-21 11:52:23 -05:00
Mike Reeves
84b75a38a3
Fix error in init.sls for ES
2021-01-21 11:21:04 -05:00
Mike Reeves
6de70ec820
Update docker mappings for ES
2021-01-21 11:12:12 -05:00
weslambert
d6043d091b
Merge pull request #2701 from Security-Onion-Solutions/feature/filebeat_events
...
Allow for Filebeat queue/output adjustments via pillar
2021-01-21 10:36:33 -05:00
Wes Lambert
19d22e1f8a
Allow for Filebeat queue/output adjustments via pillar
2021-01-21 15:34:54 +00:00
Mike Reeves
35c741ae63
Turn on Xpack SSL
2021-01-21 09:49:31 -05:00
m0duspwnens
76aadbd04e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-21 09:30:03 -05:00
weslambert
a99246c600
Merge pull request #2698 from Security-Onion-Solutions/fix/reserved_ports
...
Fix/reserved ports
2021-01-21 08:39:35 -05:00
Wes Lambert
0039877779
Check for port availability for Wazuh and Strelka
2021-01-21 13:29:09 +00:00
Wes Lambert
9a91674688
Add reserved ports file for sysctl
2021-01-21 13:18:22 +00:00
Wes Lambert
74e315841a
Modify common to reserve Docker proxy ports
2021-01-21 13:17:16 +00:00
Masaya-A
cd5abf924c
To make log rotation working
2021-01-21 09:31:15 +09:00
Masaya-A
845ab92d36
To make log rotation working
2021-01-21 09:30:34 +09:00
Josh Patterson
516634ef8d
Merge pull request #2691 from Security-Onion-Solutions/issue/2679
...
Issue/2679
2021-01-20 17:41:43 -05:00
m0duspwnens
18217ba38b
change so-searchnode role to so-node https://github.com/Security-Onion-Solutions/securityonion/issues/2679
2021-01-20 17:40:02 -05:00
m0duspwnens
6e756b3586
allow heathcheck state for standalone and heavynode
2021-01-20 17:34:53 -05:00
Josh Patterson
e7e6243399
Merge pull request #2689 from Security-Onion-Solutions/issue/2679
...
Issue/2679
2021-01-20 15:14:38 -05:00
m0duspwnens
18278a97ac
fix salt top formatting
2021-01-20 15:13:55 -05:00
m0duspwnens
b693373d8d
change how we allow or disallow states to be run https://github.com/Security-Onion-Solutions/securityonion/issues/2679
2021-01-20 15:09:53 -05:00
Jason Ertel
58f922aac3
Skip image pull if so-tcpreplay image already exists and is current
2021-01-20 11:17:10 -05:00
m0duspwnens
b1c5b83fd5
removing old search node logic and managersensor from salt top
2021-01-20 09:53:42 -05:00
m0duspwnens
caaa8cc764
add schedule state to fleet node so it gets highstate schedule
2021-01-20 09:46:49 -05:00
Masaya-A
d53945888c
Add sensoroni dir
2021-01-20 14:54:55 +09:00
Masaya-A
d3d11ff67b
Delete some directories
...
Delete some directories that should not be handled by common-rotate.
2021-01-20 13:42:20 +09:00
Masaya-A
b2b221fa46
Specify the file name for Suricata
...
stats.log will be rotated by surirotate
2021-01-20 13:20:04 +09:00
Masaya-A
e20891ac44
Fix spacing
2021-01-20 13:10:33 +09:00
Masaya-A
8cca792a8f
To avoid lots of "[stenoloss.sh] <defunct>"
2021-01-20 12:16:17 +09:00
Masaya-A
5dad143c42
Need full path in order to work on cron
2021-01-20 12:14:09 +09:00
Masaya-A
9dd3199ec4
Merge pull request #1 from Security-Onion-Solutions/dev
...
Update Dev
2021-01-20 12:09:35 +09:00
Jason Ertel
71e0014115
Wrap parenthesis around correlation filter to allow additional filtering
2021-01-19 17:51:23 -05:00
m0duspwnens
0fec46505d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-19 14:35:53 -05:00
William Wernert
8023e79020
[fix] Don't remove answer file when checking version on manager, file does not yet exist
2021-01-19 11:28:33 -05:00
m0duspwnens
3ef8106d8d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-19 11:28:27 -05:00
William Wernert
650008e1e6
[fix] Replace leftover /root/install_opt strings with variable
2021-01-19 11:20:53 -05:00
Jason Ertel
d91913e58e
Redirect tcpreplay warnings to dev null when running so-test
2021-01-18 21:42:50 -05:00
Mike Reeves
12aa4033b6
Fix soup in case airgap is in the hostname
2021-01-18 18:08:34 -05:00
Jason Ertel
a795f0a487
Correct airgap IPs; Remove auto tcpreplay during post-setup phase
2021-01-16 12:01:49 -05:00
Jason Ertel
2006677a22
Add default customization file (Blank)
2021-01-15 20:08:27 -05:00
William Wernert
32839f8a53
[feat] Various input validation changes + fixes
...
* Keep invalid input in subsequent prompts
* Remove useless placeholder values
* Only set PROCS variable once
* Make input collection loops more consistent
2021-01-15 18:05:29 -05:00
Jason Ertel
0af6afa216
Add method for making adjustments to the SOC UI
2021-01-15 16:26:06 -05:00
William Wernert
8cb836a17a
[fix] Don't preset HOSTNAME var, interferes with automation
2021-01-15 16:22:07 -05:00
William Wernert
432d231a0e
[fix] Don't use set -e since we depend on non-zero exit codes for this function
2021-01-15 13:52:10 -05:00
William Wernert
9726ff9ce6
[fix] Correct logic for verbose flag
2021-01-15 13:39:12 -05:00
Mike Reeves
9cf63545bc
Merge pull request #2640 from Masaya-A/influxdb/strengthen
...
Disable weak cipher suites from influxdb
2021-01-15 10:50:21 -05:00
m0duspwnens
76c7c46887
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-15 10:48:19 -05:00
William Wernert
e440f6c44a
[fix] Set variables used by sensor pillar before generating the pillar
2021-01-15 10:29:51 -05:00
William Wernert
ed129bcf1f
[fix] Add verbose flag so that so-monitor-add only sees necessary information
2021-01-15 09:25:04 -05:00
William Wernert
f4de5e28bf
[fix] Padding 3->4 spaces, don't use lookup_pillar before salt is installed
2021-01-15 08:57:14 -05:00
Jason Ertel
07b5f1d23e
Rename functions to avoid naming conflict with setup vars
2021-01-15 08:55:30 -05:00
William Wernert
0f6805823e
[fix] Add spacing to whiptail menu + preset err
2021-01-15 08:35:37 -05:00
Masaya-A
0d93b15a63
Disable weak cipher suites from influxdb
...
The default config of influxdb enables use of some weak cipher suites such as RC4 and 3DES(SWEET32).
To disable them, a list of enabled ciphers added into influxdb.conf.
2021-01-15 11:47:04 +09:00
William Wernert
dbe22f901d
[fix] Add jinja raw block to so-common
2021-01-14 14:54:37 -05:00
William Wernert
ebc5a4314a
[feat] Add salt logs to log rotation config
2021-01-14 13:43:00 -05:00
William Wernert
df07cc578c
[fix] Only update err if return code is non-zero
2021-01-14 13:20:56 -05:00
William Wernert
2e23e0d690
[fix] Only update err if return code is non-zero
2021-01-14 13:20:29 -05:00
William Wernert
a7b9b565fd
[fix] Only return after all interfaces added to bond0
2021-01-14 13:19:29 -05:00
William Wernert
e7070ef217
Merge pull request #2630 from Security-Onion-Solutions/feature/setup
...
Input validation + so-monitor-add
2021-01-14 13:17:01 -05:00
William Wernert
8793965f4a
[fix] Capitalization
2021-01-14 13:12:12 -05:00
William Wernert
ddcd487edc
[fix] Remove files not in dev
2021-01-14 13:08:11 -05:00
William Wernert
0db439df1e
Merge branch 'dev' into feature/setup
2021-01-14 13:06:32 -05:00
William Wernert
82c7832d60
[fix] Fix indent in valid_hostname
2021-01-14 12:58:21 -05:00
m0duspwnens
a2b52a1a98
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-14 10:44:53 -05:00
William Wernert
3c22738ae1
[fix] Add example CIDR notation, remove placeholder X.X.X.X
2021-01-14 10:38:47 -05:00
Jason Ertel
9d0dca05b1
Adjusted logic on so-tcpreplay to handle init for standalone/eval nodes
2021-01-13 22:29:58 -05:00
Jason Ertel
2ccf77eaef
Rename network automation files
2021-01-13 17:29:48 -05:00
William Wernert
8245b25835
[fix] Move metadata function
2021-01-13 17:28:19 -05:00
William Wernert
b68685e00e
[fix] Correct metadata function name
2021-01-13 17:26:27 -05:00
William Wernert
90f085b2d7
[fix] Fail setup early if we can't determine version of manager
2021-01-13 15:57:21 -05:00
Jason Ertel
6d6779bba6
Added automation files for network eval/standalone installs; Reduced Zeek threads from 7 to 2 on all test nodes
2021-01-13 15:43:43 -05:00
Jason Ertel
0a1ab29d19
Add distributed airgap automation files
2021-01-13 14:28:54 -05:00
Jason Ertel
ea1ab75072
Refactored so-common node type checks for improved readability; Updated so-tcpreplay to support distributed grids
2021-01-13 12:42:54 -05:00
William Wernert
6ea3a651a4
[fix] Fix unit tests for dns list
2021-01-13 11:37:48 -05:00
William Wernert
4dc3a6aa35
[refactor] Standardize list inputs to comma separated
2021-01-13 11:36:20 -05:00
Josh Patterson
59b016695f
Merge pull request #2611 from Security-Onion-Solutions/issue/2095
...
pillarize disk freespace for steno
2021-01-13 11:11:27 -05:00
m0duspwnens
df590bfd23
pillarize disk freespace for steno https://github.com/Security-Onion-Solutions/securityonion/issues/2095
2021-01-13 11:09:38 -05:00
William Wernert
d254fd960a
[feat] Add message explaining strings cannot contain spaces
2021-01-13 11:04:35 -05:00
m0duspwnens
489f702e47
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-13 10:47:13 -05:00
William Wernert
0734998315
[fix] patch_schedule should not be local
2021-01-13 10:39:24 -05:00
Jason Ertel
9b060fb2d1
Adjust automation defaults for sensors and search nodes
2021-01-13 10:39:10 -05:00
Jason Ertel
bb386f9935
Allow passwordless sudo during tests for all nodes, not just manager; Only run so-test on sensor nodes during test runs
2021-01-13 10:39:05 -05:00
William Wernert
ebac17ce38
[wip] Attempting to fix missing patch schedule prompts
2021-01-13 10:29:36 -05:00
Mike Reeves
2950779d91
Fix stralka rule update
2021-01-13 09:57:12 -05:00
Josh Patterson
02d4813ef7
Merge pull request #2609 from Security-Onion-Solutions/issue/2590
...
Issue/2590
2021-01-12 16:43:45 -05:00
m0duspwnens
225ed1c14a
change suriloss and zeekloss to be more similar code style
2021-01-12 16:39:19 -05:00
m0duspwnens
96dab31ab0
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/2590
2021-01-12 14:29:59 -05:00
Josh Patterson
aa8a14d74a
Merge pull request #2606 from Security-Onion-Solutions/automation/ssh_prompts
...
fix quotes
2021-01-12 14:08:08 -05:00
m0duspwnens
dbb9f90f00
fix quotes
2021-01-12 14:07:04 -05:00
William Wernert
dd20002fd5
[fix] Dockernet prompt is negative, continue on "no"
2021-01-12 11:28:24 -05:00
William Wernert
5c6f8f9d47
[fix] Correct function call (pt 2)
2021-01-12 11:27:03 -05:00
William Wernert
ff69d022b3
[fix] Correct function call
2021-01-12 11:26:20 -05:00
William Wernert
fb31b56c8b
[fix] Only check for network init file if iso
2021-01-12 11:22:52 -05:00
William Wernert
38e37a0385
[refactor] Remove whiptail shard count prompt
2021-01-12 11:04:40 -05:00
William Wernert
5d077d278e
[feat] Add input validation to inputbox whiptail prompts
2021-01-12 11:02:33 -05:00
William Wernert
0dc0780e28
[feat] Add unit tests for input validation
2021-01-12 11:02:00 -05:00
William Wernert
332c6877b8
[fix] Add extra arg to printf instead of using echo
2021-01-12 11:01:25 -05:00
William Wernert
ef7a934b9d
[feat] Add functions for input validation
2021-01-12 11:01:04 -05:00
m0duspwnens
cc0697cefa
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-12 10:29:49 -05:00
Josh Patterson
4f384991ba
Merge pull request #2601 from Security-Onion-Solutions/automation/ssh_prompts
...
remote quotes
2021-01-12 09:54:10 -05:00
m0duspwnens
9405990a2e
remote quotes
2021-01-12 09:50:08 -05:00
m0duspwnens
6ea1a83afe
resolve some issues with the zeekloss script https://github.com/Security-Onion-Solutions/securityonion/issues/2590
2021-01-11 14:10:08 -05:00
m0duspwnens
4d84b64056
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-11 12:43:37 -05:00
Jason Ertel
8b49876e26
First pass at distribute ISO automation files
2021-01-11 12:04:57 -05:00
Jason Ertel
bc8e200919
Continued retry implementation for salt-key acceptance; improve timestamp coverage in setup
2021-01-10 02:34:46 -05:00
Jason Ertel
63047b4b85
Add retry logic around salt key acceptance during setup
2021-01-10 00:57:43 -05:00
Josh Patterson
95a9d14832
Merge pull request #2578 from Security-Onion-Solutions/salt/info_logging
...
increase salt logging to info
2021-01-08 16:34:26 -05:00
m0duspwnens
f07e583013
increase salt logging to info
2021-01-08 16:33:38 -05:00
m0duspwnens
ae63b52e7a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-08 15:30:15 -05:00
Jason Ertel
9eedb874fb
Add eval and standalone airgap automations
2021-01-08 12:37:54 -05:00
Jason Ertel
a6f88b2843
Correct eval AMI automation vars
2021-01-07 15:22:34 -05:00
m0duspwnens
86cb1abad4
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-07 15:12:36 -05:00
Jason Ertel
567d80bb01
Update sed to disable sudo password prompt for automated testing
2021-01-07 11:33:59 -05:00
Josh Patterson
d2848b9985
Merge pull request #2561 from Security-Onion-Solutions/automation/so-status
...
add description for exit code 99
2021-01-07 11:24:14 -05:00
m0duspwnens
83e7493691
add description for exit code 99
2021-01-07 11:23:39 -05:00
William Wernert
1ec45fb4ae
[fix] Only show Zeek prompts if Zeek was selected as the MD tool
...
Resolves #900
2021-01-07 10:37:25 -05:00
William Wernert
c1e32ed680
[refactor] Rename MD tool function to be more clear
2021-01-07 10:36:32 -05:00
William Wernert
fa06a38a3b
[refactor] Remove duplicate function
2021-01-07 10:36:01 -05:00
Josh Patterson
d287dd2412
Merge pull request #2557 from Security-Onion-Solutions/automation/so-status
...
Automation/so status
2021-01-07 09:07:12 -05:00
Josh Patterson
8fa2b14c98
Merge pull request #2539 from Security-Onion-Solutions/automation/ssh_prompts
...
Automation/ssh prompts
2021-01-07 09:06:10 -05:00
Jason Ertel
948f900673
Drop password requirement for sudo access during automated tests
2021-01-06 20:39:44 -05:00
m0duspwnens
a5735e6654
return 99 if setup is running
2021-01-06 20:14:42 -05:00
m0duspwnens
ae7c0a26be
add a quiet mode to so-status for automation testing
2021-01-06 18:46:21 -05:00
Jason Ertel
bbdb47703d
Rename automation files to match environment names for consistency
2021-01-06 17:21:46 -05:00
Wes Lambert
7f64d57111
Reserve port for Wazuh API and check if port is already in use
2021-01-06 14:37:28 -05:00
Wes Lambert
e7db1a99bd
Set @timestamp to winlog.systemTime
2021-01-06 14:37:28 -05:00
Mike Reeves
7d25e8a08b
Remove ERSPAN so log doesn't show a warning
2021-01-06 14:37:28 -05:00
Masaya-A
d37023e0f5
Make yum removing unneeded packages
...
Reference: https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2020-09-03/finding/V-204452
2021-01-06 14:37:28 -05:00
William Wernert
9d8fb79d9f
[feat] Reorder network-only prompt
2021-01-06 14:37:27 -05:00
weslambert
c864cc607f
Remove multiple old so-yara-update cron jobs, if needed
2021-01-06 14:37:27 -05:00
William Wernert
80a3d8dcf8
[fix] Fix automation compatibility
2021-01-06 14:37:27 -05:00
William Wernert
ac35a345ff
[fix] Don't prompt to only set up network and then skip if network was previously configured
2021-01-06 14:37:27 -05:00
weslambert
958635b012
Remove old Strelka cron job
2021-01-06 14:37:27 -05:00
William Wernert
6ba11f835d
[fix] Remove condition for stopping SOC, since the parent condition covers what's tested
2021-01-06 14:37:27 -05:00
Jason Ertel
1cc8a78aa5
Only stop SOC if is_manager or is_import
2021-01-06 14:37:27 -05:00
Jason Ertel
7dcd934269
so-fleet-setup doesn't need an interactive terminal to run, remove 'it'
2021-01-06 14:37:27 -05:00
Jason Ertel
bedbd39b82
tcpreplay doesn't need an interactive terminal to run, remove 'it'
2021-01-06 14:37:27 -05:00
Jason Ertel
7d97e3590c
Redirect tcpreplay init output to file
2021-01-06 14:37:27 -05:00
Jason Ertel
bdbc637852
Stop SOC prior to opening the firewall for analysts, this ensures no outside requests can be processed prior to the server rebooting
2021-01-06 14:37:27 -05:00
Jason Ertel
10d04f760d
Use manager internal IP for intra-service comms
2021-01-06 14:37:26 -05:00
Jason Ertel
ebb0e615b9
Fix script typo to correctly run the so-test
2021-01-06 14:37:26 -05:00
Jason Ertel
f20feabda2
Reboot to ensure thehive falls in line before kicking off the test
2021-01-06 14:37:26 -05:00
Jason Ertel
9b40318bfe
Ensure so-test is logged
2021-01-06 14:37:26 -05:00
Jason Ertel
fc44474519
Add eval automation
2021-01-06 14:37:26 -05:00
Jason Ertel
229657f7d2
Use AMI's public IP for external access
2021-01-06 14:37:26 -05:00
Jason Ertel
fb28faa4e3
Monitor interface will not always be bond0 - pull correct value from pillar; Replay test data after automated test installations complete.
2021-01-06 14:37:26 -05:00
weslambert
36ae09ac4a
Merge pull request #2545 from Security-Onion-Solutions/fix/wazuh_port_reservation
...
Reserve port for Wazuh API and check if port is already in use
2021-01-06 11:49:23 -05:00
weslambert
55344725e7
Merge pull request #2544 from Security-Onion-Solutions/fix/winlog_timestamp
...
Set @timestamp to winlog.systemTime
2021-01-06 11:49:01 -05:00
Wes Lambert
875908dc90
Set @timestamp to winlog.systemTime
2021-01-06 16:47:35 +00:00
Wes Lambert
f2b677bfcb
Reserve port for Wazuh API and check if port is already in use
2021-01-06 15:52:10 +00:00
m0duspwnens
48f81d9ac6
reduce setting ssh commands down to 1 function and 1 function call
2021-01-06 08:58:33 -05:00
m0duspwnens
94fd79cd28
originally had sshpass package install reveresed, fixed it here
2021-01-06 08:51:33 -05:00
m0duspwnens
aecc0c025e
fix comment
2021-01-06 08:49:08 -05:00
m0duspwnens
91ad7f26bf
no longer need to pass $automated to compare_versions
2021-01-06 08:45:33 -05:00
m0duspwnens
c65e722164
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-06 08:39:56 -05:00
m0duspwnens
749b21e684
make sure ssh commands get set whether automated install or not
2021-01-05 14:12:43 -05:00
Mike Reeves
1154b533d6
Remove ERSPAN so log doesn't show a warning
2021-01-05 13:56:56 -05:00
m0duspwnens
0f9bf9deb6
make sshcmd, scpcmd, ssh_copy_id_cmd global to so-functions;
2021-01-05 13:49:51 -05:00
m0duspwnens
c93dfa7b33
hardcode automation pw
2021-01-05 11:47:22 -05:00
m0duspwnens
81c4d879eb
first round of testing for automated testing ssh/scp
2021-01-05 10:26:19 -05:00
Mike Reeves
dc429494ac
Merge pull request #2370 from Masaya-A/improve/yum
...
Make yum removing unneeded packages
2021-01-05 09:26:04 -05:00
William Wernert
294601ff64
[feat] Reorder network-only prompt
2021-01-04 16:40:16 -05:00
weslambert
707528d7e8
Merge pull request #2530 from Security-Onion-Solutions/fix/strelka_cron_2
...
Remove multiple old so-yara-update cron jobs, if needed
2021-01-04 16:30:22 -05:00
weslambert
c1e245043e
Remove multiple old so-yara-update cron jobs, if needed
2021-01-04 16:29:32 -05:00
William Wernert
f94e421f4e
[fix] Fix automation compatibility
2021-01-04 14:46:48 -05:00
m0duspwnens
38f985ae22
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-04 14:10:41 -05:00
William Wernert
9d674d6d3a
[feat] Add so-monitor-add script
2021-01-04 13:35:14 -05:00
William Wernert
7bfac1e8df
[fix] Don't prompt to only set up network and then skip if network was previously configured
2021-01-04 11:58:25 -05:00
William Wernert
65c3849c7b
Merge pull request #2527 from Security-Onion-Solutions/feature/setup
...
Feature/setup
2021-01-04 11:41:07 -05:00
William Wernert
f8c7413b15
[fix] Move is_iso variable assignment up
2021-01-04 10:37:07 -05:00
weslambert
e51f60f7fa
Merge pull request #2521 from Security-Onion-Solutions/fix/strelka_rule_cron
...
Remove old Strelka cron job
2021-01-04 10:19:50 -05:00
weslambert
535820bfa7
Remove old Strelka cron job
2021-01-04 10:18:32 -05:00
William Wernert
0fa001ed92
[fix] Add more logic to network-only process
2021-01-04 09:27:22 -05:00
William Wernert
a714d36b99
[fix] Remove condition for stopping SOC, since the parent condition covers what's tested
2021-01-02 21:03:15 -05:00
Jason Ertel
455da7ec5d
Only stop SOC if is_manager or is_import
2020-12-31 15:09:22 -05:00
Jason Ertel
4b244645ba
so-fleet-setup doesn't need an interactive terminal to run, remove 'it'
2020-12-31 10:52:59 -05:00
Jason Ertel
6b81419d38
tcpreplay doesn't need an interactive terminal to run, remove 'it'
2020-12-30 22:02:19 -05:00
Jason Ertel
e167bfed20
Redirect tcpreplay init output to file
2020-12-30 18:48:56 -05:00
Jason Ertel
df305c49a6
Stop SOC prior to opening the firewall for analysts, this ensures no outside requests can be processed prior to the server rebooting
2020-12-30 16:33:46 -05:00
William Wernert
3f3fe78322
[fix] Correct reversed logic
2020-12-30 14:01:20 -05:00
Jason Ertel
13f0ddabfc
Use manager internal IP for intra-service comms
2020-12-30 12:02:42 -05:00
Jason Ertel
19d14cf277
Fix script typo to correctly run the so-test
2020-12-30 10:31:04 -05:00
Jason Ertel
a49ddfb887
Reboot to ensure thehive falls in line before kicking off the test
2020-12-29 20:42:50 -05:00
Jason Ertel
827a571db8
Ensure so-test is logged
2020-12-29 17:25:53 -05:00
Jason Ertel
989e2b8b78
Add eval automation
2020-12-29 16:15:10 -05:00
William Wernert
0a57b78900
[feat] Add option to set up only network on an iso
2020-12-29 12:52:21 -05:00
Jason Ertel
74dd2187fb
Use AMI's public IP for external access
2020-12-29 11:16:57 -05:00
Jason Ertel
ea5e25c4a5
Monitor interface will not always be bond0 - pull correct value from pillar; Replay test data after automated test installations complete.
2020-12-29 10:34:31 -05:00
William Wernert
afe40fe87b
Merge pull request #2478 from Security-Onion-Solutions/feature/wait-for-apt
...
Feature/wait for apt
2020-12-28 18:29:20 -05:00
William Wernert
e9a6155e44
Merge branch 'dev' into feature/wait-for-apt
2020-12-28 18:26:38 -05:00
Jason Ertel
deb38844ba
Correct hive init urls
2020-12-28 16:20:33 -05:00
William Wernert
97466957a7
[fix] Fix text printed to whiptail progress bar
2020-12-28 15:06:03 -05:00
William Wernert
cdb6dfcea0
[fix][wip] Fix whiptail output
2020-12-28 14:55:15 -05:00
William Wernert
5059373485
[fix] Change text printed to whiptail progress bar
2020-12-28 14:43:33 -05:00
William Wernert
af62e64852
[fix] Message changes
2020-12-28 14:40:17 -05:00
William Wernert
b03408df6b
[fix] Add missing function
2020-12-28 14:30:34 -05:00
William Wernert
5836d22525
[fix] Change text printed to whiptail progress bar
2020-12-28 14:29:03 -05:00
William Wernert
a4239d7fe4
[fix] Clarify why dpkg lock is needed
2020-12-28 14:20:37 -05:00
William Wernert
5bd15b91ea
[fix] Message formatting changes
2020-12-28 14:18:43 -05:00
William Wernert
a0533dd6b5
[feat] Increase retry_count, decrease wait time, change wording
2020-12-28 14:17:27 -05:00
William Wernert
f7a60a011b
[fix] Message formatting
2020-12-28 14:06:33 -05:00
William Wernert
17160dcdbe
[fix] Don't repeat fail message on last attempt
2020-12-28 14:02:46 -05:00
William Wernert
0dd80a664f
[fix] Only call progress callback if arg passed
2020-12-28 14:00:09 -05:00
William Wernert
1e0525b1ad
[fix] Only call progress callback if arg passed
2020-12-28 13:57:44 -05:00
William Wernert
7050b1fce5
[fix] Don't use same variable for increment and limit
2020-12-28 13:55:03 -05:00
Jason Ertel
7fe0182ede
Refactor so-test and so-tcpreplay to be compatible with SO 2.3.20+; Change hive_init and cortex_init to initialize the cortex and fleet services directly on the manager IP instead of attempting to use the public URL
2020-12-28 11:26:56 -05:00
William Wernert
4d1cb37468
[feat] Add function to wait for dpkg lock
2020-12-28 09:35:51 -05:00
Jason Ertel
8f15d794bc
Silence curl progress output during hive/cortex init
2020-12-24 08:44:28 -05:00
Jason Ertel
baf5be1a3a
Return adequate exit code when init fails; Logs output of init scripts for troubleshooting failed installations
2020-12-23 20:14:46 -05:00
Jason Ertel
9cf150f988
Switch from Jinja syntax to bash
2020-12-23 15:11:43 -05:00
m0duspwnens
7800e90776
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-23 14:53:27 -05:00
Jason Ertel
2d44b69e8d
Refactor hive and cortex init to use wait loops instead of hardcoded sleeps
2020-12-23 12:12:38 -05:00
Jason Ertel
aa5c0a7351
Clarify prompt instructions for so-elastalert-test
2020-12-23 09:37:44 -05:00
Jason Ertel
eef1f49d09
Corrected cortex_init process which was incorrectly attempting to access ES via the external URL; Removing 1-2 minute sleeps during init to see if those are no longer needed
2020-12-22 22:56:01 -05:00
Jason Ertel
cfe5019f51
Add firewall listhogroups and listportgroups commands; Change AMI test defaults to use a custom hostname for cypress access
2020-12-22 17:59:59 -05:00
weslambert
f6a199156b
Merge pull request #2428 from Security-Onion-Solutions/feature/strelka_pillar_repos
...
Support setting rule repos via pillar
2020-12-22 10:38:01 -05:00
Wes Lambert
ac96ded2dc
Support setting rule repos via pillar
2020-12-22 15:36:15 +00:00
Mike Reeves
aa15f3ca4a
Merge pull request #2425 from Security-Onion-Solutions/patch/2.3.21
...
2.3.21 ISO sig
2020-12-22 08:39:00 -05:00
TOoSmOotH
3a3182a51f
2.3.21 ISO sig
2020-12-22 08:32:58 -05:00
Mike Reeves
36207d0440
Merge pull request #2417 from Security-Onion-Solutions/patch/2.3.21
...
2.3.21
2020-12-21 20:02:04 -05:00
Mike Reeves
88bfe7c49c
Update VERIFY_ISO.md
2020-12-21 19:52:31 -05:00
Mike Reeves
7116c2103b
Update Docker Clean
2020-12-21 17:06:14 -05:00
Mike Reeves
b49355d346
Update changes.json
2020-12-21 16:54:55 -05:00
Mike Reeves
aecde2dd54
Update README.md
2020-12-21 16:54:10 -05:00
Mike Reeves
f2d8c7f10d
Update VERSION
2020-12-21 16:53:30 -05:00
Mike Reeves
627d4da432
Merge pull request #2403 from Security-Onion-Solutions/fix/so-analyst-typo
...
fix typo in so-analyst-install warning
2020-12-21 11:48:25 -05:00
m0duspwnens
a18c89d804
fix typo in so-analyst-install warning
2020-12-21 11:42:03 -05:00
m0duspwnens
416d98071d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 11:39:23 -05:00
Mike Reeves
d73f3bb6f8
Update README.md
2020-12-21 10:53:41 -05:00
Mike Reeves
48931116ab
Update VERSION
2020-12-21 10:52:37 -05:00
m0duspwnens
544c473338
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 10:21:48 -05:00
m0duspwnens
5d0cef5e3d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 10:21:24 -05:00
m0duspwnens
7653ad56a9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 14:11:21 -05:00
m0duspwnens
1374ac0628
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 13:39:27 -05:00
m0duspwnens
b506f0455f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 12:38:44 -05:00
m0duspwnens
e7a833e890
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 10:57:18 -05:00
m0duspwnens
6e202f2ee0
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-17 17:21:01 -05:00
Masaya-A
59ae5f63cf
Make yum removing unneeded packages
...
Reference: https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2020-09-03/finding/V-204452
2020-12-17 22:14:03 +09:00
m0duspwnens
9fd2ab530e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-16 10:53:35 -05:00
m0duspwnens
fffca7e0d8
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-16 08:59:39 -05:00
m0duspwnens
3a66af0b16
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-14 11:36:03 -05:00
m0duspwnens
32482710db
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-14 10:14:44 -05:00
m0duspwnens
95c068a37f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-11 14:13:48 -05:00
m0duspwnens
2b412b6a48
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-08 10:41:28 -05:00
m0duspwnens
81e914ab23
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-07 09:38:04 -05:00
m0duspwnens
8983ff994c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-02 13:08:15 -05:00
m0duspwnens
3ee562a243
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-01 09:28:27 -05:00
m0duspwnens
ae464c38b2
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-30 11:04:34 -05:00
m0duspwnens
5f0f20918b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-24 14:33:05 -05:00
m0duspwnens
ae7672f395
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-23 13:44:38 -05:00
m0duspwnens
22ebb5af03
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-23 09:29:18 -05:00
m0duspwnens
d178a7c5f3
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-20 10:32:32 -05:00
m0duspwnens
762441fdda
merge
2020-11-20 08:57:48 -05:00
m0duspwnens
868286a58a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-19 15:06:10 -05:00
m0duspwnens
146c1a4d75
fix typos of minon to minion
2020-11-19 15:06:06 -05:00