Mike Reeves
c5d0286e24
Merge pull request #4254 from Security-Onion-Solutions/2.3.51
...
2.3.51
2021-05-21 12:15:04 -04:00
Mike Reeves
7aed01658f
Sig file for 2.3.51
2021-05-20 22:10:36 -04:00
Jason Ertel
b440f73336
Truncate wait_for_web_response.log before each wait invocation
2021-05-19 18:37:08 -04:00
Jason Ertel
25e2edc6d2
Reset HOTFIX with new release
2021-05-18 12:31:33 -04:00
Jason Ertel
c207504657
Merge branch '2.3.51' of ssh://github.com/security-onion-solutions/securityonion into 2.3.51
2021-05-18 09:52:07 -04:00
Jason Ertel
fe155222c2
Introduce mixed-case sensor into distributed test
2021-05-18 09:51:54 -04:00
Josh Patterson
9b4325662b
Merge pull request #4218 from Security-Onion-Solutions/issue/4207
...
Issue/4207
2021-05-18 09:04:26 -04:00
m0duspwnens
0de1c9a669
removing unreference pillar file docker/config.sls
2021-05-18 07:57:00 -04:00
m0duspwnens
ef32bff302
fix up soc.json
2021-05-17 18:29:27 -04:00
m0duspwnens
e50002e0ca
influx and grafana default for manager nodes - https://github.com/Security-Onion-Solutions/securityonion/issues/4207
2021-05-17 16:26:12 -04:00
Mike Reeves
d001597e52
Update README.md
2021-05-17 15:56:46 -04:00
Mike Reeves
4c7cee4ebc
Update VERSION
2021-05-17 15:55:49 -04:00
Mike Reeves
6eed730209
Merge pull request #4213 from Security-Onion-Solutions/zeekhotfix
...
Zeekhotfix
2021-05-17 15:55:17 -04:00
m0duspwnens
fb986b5cff
set both log levels to error
2021-05-06 14:55:14 -04:00
m0duspwnens
a49f2e2d98
change log_level_logfile to error for /opt/so/log/salt/minion
2021-05-06 13:38:16 -04:00
Mike Reeves
90b3462ead
No recurse for you
2021-05-06 13:29:15 -04:00
Mike Reeves
1de768c182
Update HOTFIX
2021-05-06 12:02:05 -04:00
Mike Reeves
96c20ea3cf
Merge pull request #4080 from Security-Onion-Solutions/hotfix2
...
GRIDFIX Hotfix
2021-05-06 10:34:17 -04:00
Mike Reeves
10c4a7fd98
Update soup
2021-05-04 09:18:59 -04:00
Mike Reeves
ffa9001df4
Update raid.sh
2021-05-04 07:57:07 -04:00
Mike Reeves
e113e75f4d
Update soup
2021-05-03 18:52:40 -04:00
Mike Reeves
9066959945
Update soup
2021-05-03 18:46:24 -04:00
Jason Ertel
6768e8ddf6
copy_new_files usage consistent across soup and hotfixapply scripts
2021-05-03 15:42:24 -04:00
Mike Reeves
a489b369d7
Jertel Compliance
2021-05-03 15:23:34 -04:00
Mike Reeves
074fe46e90
Adding airgap hotfix
2021-05-03 15:02:51 -04:00
Mike Reeves
f56244d708
Adding airgap hotfix
2021-05-03 14:39:32 -04:00
Mike Reeves
cedcf05751
Adding airgap hotfix
2021-05-03 14:38:18 -04:00
Mike Reeves
f04ed94627
Adding airgap hotfix
2021-05-03 14:33:45 -04:00
Mike Reeves
296c1c5a3c
Adding airgap hotfix
2021-05-03 14:30:53 -04:00
Mike Reeves
153394356b
Merge pull request #4003 from Security-Onion-Solutions/dev
...
2.3.50
2021-04-28 10:11:53 -04:00
Mike Reeves
bd454c7f25
Merge pull request #4016 from Security-Onion-Solutions/2350
...
Repo Fix
2021-04-27 16:02:15 -04:00
Mike Reeves
b6792f73e0
Repo Fix
2021-04-27 15:51:30 -04:00
Mike Reeves
03774e6270
Repo Fix
2021-04-27 15:46:45 -04:00
Mike Reeves
b23902fc2c
Merge pull request #4015 from Security-Onion-Solutions/importfix
...
Update import install
2021-04-27 13:38:31 -04:00
Mike Reeves
458c386377
Update import install
2021-04-27 13:37:37 -04:00
Mike Reeves
79984f4808
Merge pull request #4007 from Security-Onion-Solutions/2350
...
Repo Fix
2021-04-26 16:40:28 -04:00
Mike Reeves
167e656abb
Repo Fix
2021-04-26 16:38:12 -04:00
Josh Patterson
f2b1b9a073
Merge pull request #4006 from Security-Onion-Solutions/2350
...
Prompt airgap to update
2021-04-26 15:38:23 -04:00
Mike Reeves
939414aef6
Prompt airgap to update
2021-04-26 15:36:56 -04:00
Josh Patterson
6a956702df
Merge pull request #4005 from Security-Onion-Solutions/2350
...
Repo Fix
2021-04-26 14:52:00 -04:00
Mike Reeves
df22269fc9
Repo Fix
2021-04-26 14:49:44 -04:00
Mike Reeves
d36237ee87
Merge pull request #4002 from Security-Onion-Solutions/2350
...
2.3.50 sig files
2021-04-26 09:32:10 -04:00
Mike Reeves
0499b141ed
2.3.50 sig files
2021-04-26 09:20:03 -04:00
Mike Reeves
0654c6511a
Merge pull request #4001 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update README.md
2021-04-26 09:10:56 -04:00
Mike Reeves
bbe2f81cb6
Update README.md
2021-04-26 08:53:58 -04:00
Jason Ertel
33bdd96221
Merge pull request #3996 from Security-Onion-Solutions/updateag
...
Prompt airgap to update
2021-04-25 12:25:45 -04:00
Mike Reeves
6135d89721
Prompt airgap to update
2021-04-25 12:19:34 -04:00
Mike Reeves
abbe0ec819
Merge pull request #3995 from Security-Onion-Solutions/updateag
...
Fix updates for airgap
2021-04-25 11:26:20 -04:00
Mike Reeves
4d0b06dfc7
Fix updates for airgap
2021-04-25 11:01:21 -04:00
Mike Reeves
0505664b84
Merge pull request #3987 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Prime the CentOS Repos
2021-04-23 12:11:01 -04:00
Mike Reeves
f2628f2e5b
Prime the CentOS Repos
2021-04-23 12:09:41 -04:00
Mike Reeves
fcaabaade0
Merge pull request #3986 from Security-Onion-Solutions/grafanaeps
...
remove eps graph from manager and update to consumptioneps for standalone and managersearch
2021-04-23 12:08:06 -04:00
m0duspwnens
fff12b423a
remove eps graph from manager and update to consumptioneps for standalone and managersearch
2021-04-23 11:56:27 -04:00
Jason Ertel
b81ac6b7bd
Merge pull request #3983 from Security-Onion-Solutions/kilo
...
Update MOTD with training link and simplify customization commands
2021-04-23 11:03:57 -04:00
Jason Ertel
f4606828c7
Update MOTD with training link and simply customization commands
2021-04-23 10:42:14 -04:00
Josh Patterson
4e2ffbf5e5
Merge pull request #3971 from Security-Onion-Solutions/issue/3501
...
let remote nodes upgrade on their own time
2021-04-22 16:35:26 -04:00
m0duspwnens
7c7624c87e
let remote nodes upgrade on their own time
2021-04-22 16:32:58 -04:00
Josh Patterson
7da091375e
Merge pull request #3968 from Security-Onion-Solutions/issue/3501
...
Issue/3501
2021-04-22 15:37:59 -04:00
m0duspwnens
4f545eefc2
update preflight
2021-04-22 15:27:57 -04:00
m0duspwnens
90683a7e04
fix UPDATE_DIR var
2021-04-22 15:22:55 -04:00
m0duspwnens
36bc4f4aa8
remove by package name not wildcard
2021-04-22 15:21:36 -04:00
Mike Reeves
694c3b87fe
Merge pull request #3967 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2021-04-22 14:18:46 -04:00
Mike Reeves
e7d3369cef
Update soup
2021-04-22 14:17:38 -04:00
Josh Patterson
fb6fa789b7
Merge pull request #3965 from Security-Onion-Solutions/soversion2
...
Soversion2
2021-04-22 13:45:56 -04:00
Mike Reeves
b7c6110e57
sync soversion
2021-04-22 13:41:58 -04:00
Mike Reeves
93148e4adc
sync soversion
2021-04-22 13:39:33 -04:00
Mike Reeves
016837df28
sync soversion
2021-04-22 13:36:52 -04:00
Mike Reeves
4b78b114f7
Merge pull request #3964 from Security-Onion-Solutions/fix/so-playbook-sync
...
Fix so-playbook-sync
2021-04-22 13:28:25 -04:00
Josh Brower
94352c212f
Fix so-playbook-sync
2021-04-22 13:26:41 -04:00
Mike Reeves
3a65f7875e
Merge pull request #3963 from Security-Onion-Solutions/fixsaltsoup
...
fix SALTNOTHELD for salt.minion
2021-04-22 13:25:05 -04:00
m0duspwnens
781ac0293c
fix SALTNOTHELD for salt.minion
2021-04-22 13:22:08 -04:00
Mike Reeves
a93b75af05
Merge pull request #3962 from Security-Onion-Solutions/fixsaltsoup
...
Fixsaltsoup
2021-04-22 11:52:05 -04:00
m0duspwnens
a49d6a8d5c
apply highstate to minions instead of just salt.minion for soup if salt needs upgraded
2021-04-22 11:47:53 -04:00
m0duspwnens
440c546bb4
remove docker-ce.repo
2021-04-22 11:41:14 -04:00
Mike Reeves
8c67ec5316
Merge pull request #3961 from Security-Onion-Solutions/fix/extra-paren
...
Remove extra paren
2021-04-22 11:27:16 -04:00
William Wernert
41a5818bb7
Remove extra paren
2021-04-22 11:26:15 -04:00
Mike Reeves
ee48bb9b2a
Merge pull request #3959 from Security-Onion-Solutions/fix/zeekpillar
...
Fix Zeek Setting for close-delete
2021-04-22 10:55:46 -04:00
Mike Reeves
a41c40ccbb
Fix Zeek Setting for close-delete
2021-04-22 10:53:59 -04:00
Mike Reeves
3d65135993
Merge pull request #3954 from Security-Onion-Solutions/feature/vim
...
Make sure VIM is installed with correct settings
2021-04-22 09:52:02 -04:00
Mike Reeves
9ba7beed95
Merge pull request #3957 from Security-Onion-Solutions/fix/yum-conf
...
Add support for legacy grids
2021-04-22 09:44:51 -04:00
William Wernert
7176a4214b
Add support for legacy grids
2021-04-22 09:42:39 -04:00
Josh Brower
8f37b6b73b
Make sure VIM is installed with correct settings
2021-04-22 09:35:42 -04:00
Josh Patterson
f0e9b09d8f
Merge pull request #3951 from Security-Onion-Solutions/issue/3948
...
fix salt retries
2021-04-22 08:50:14 -04:00
Mike Reeves
0bfe2aa6b6
Merge pull request #3950 from Security-Onion-Solutions/fix/correct-pillar
...
Use correct pillar value in yum.conf template
2021-04-22 08:40:09 -04:00
William Wernert
1519936e44
Use correct pillar value in yum.conf template
2021-04-22 08:37:49 -04:00
m0duspwnens
1d8e065902
fix salt retries - https://github.com/Security-Onion-Solutions/securityonion/issues/3948
2021-04-22 08:35:50 -04:00
Josh Patterson
fb3b4dc44a
Merge pull request #3949 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Roll back cluster changes
2021-04-22 08:29:13 -04:00
Mike Reeves
fae72aa243
Roll back cluster changes
2021-04-22 08:25:01 -04:00
Mike Reeves
81581711da
Merge pull request #3940 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-04-21 18:44:37 -04:00
Mike Reeves
0a2d44131b
Merge pull request #3939 from Security-Onion-Solutions/soupmkr
...
send suricata compress to dev/null
2021-04-21 18:00:03 -04:00
William Wernert
c297031f6b
Surround scalar in single quotes
2021-04-21 17:58:13 -04:00
William Wernert
071e5166b4
Set package manager source in patch pillar for yum.conf
2021-04-21 17:57:02 -04:00
Mike Reeves
c337be8f4f
send suricata compress to dev/null
2021-04-21 17:27:52 -04:00
Josh Patterson
22a7729fcf
Merge pull request #3938 from Security-Onion-Solutions/soupmkr
...
soup will now ask to update packages
2021-04-21 17:20:18 -04:00
Mike Reeves
fa972ea110
soup will now ask to update packages
2021-04-21 16:37:13 -04:00
William Wernert
261e7f7fd9
sed and grep need input files
2021-04-21 16:29:24 -04:00
Mike Reeves
b5b0c262c1
soup will now ask to update packages
2021-04-21 16:25:41 -04:00
William Wernert
c1ae7ff3b6
Set proxy, replace when setting up yum for manager proxy
2021-04-21 16:18:20 -04:00
Mike Reeves
5c4be5e1cd
soup will now ask to update packages
2021-04-21 16:15:40 -04:00
William Wernert
f3d663f090
Don't set yum/apt proxy if updating through manager
2021-04-21 15:59:37 -04:00
Mike Reeves
73001713e3
soup will now ask to update packages
2021-04-21 15:51:28 -04:00
Mike Reeves
13ad07cd88
soup will now ask to update packages
2021-04-21 15:41:58 -04:00
Mike Reeves
7335611166
soup will now ask to update packages
2021-04-21 15:35:05 -04:00
William Wernert
d5717b7011
Merge branch 'dev' into foxtrot
2021-04-21 14:45:11 -04:00
Josh Patterson
df2420f6fe
Merge pull request #3936 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Fix Security onion repo
2021-04-21 14:44:50 -04:00
Mike Reeves
06ccad334b
Fix Security
2021-04-21 14:43:15 -04:00
Mike Reeves
dd1fff59d7
Merge pull request #3934 from bryant-treacle/Issue-#3926
...
Update threading.map.jinja
2021-04-21 12:22:16 -04:00
William Wernert
428be2b8ad
Merge pull request #3935 from Security-Onion-Solutions/fix/manager-check
...
Fix salt-master check
2021-04-21 12:10:14 -04:00
William Wernert
075ba0d83b
Fix salt-master check
2021-04-21 12:01:21 -04:00
bryant-treacle
f14df24ddc
Update threading.map.jinja
2021-04-21 11:49:29 -04:00
William Wernert
b618207f51
Merge branch 'dev' into foxtrot
2021-04-21 10:23:10 -04:00
Josh Patterson
86e7c0f87d
Merge pull request #3927 from Security-Onion-Solutions/telefix1
...
Add Security Onion Repo
2021-04-20 15:47:28 -04:00
Mike Reeves
cc4c092301
Add Security Onion Repo
2021-04-20 15:44:35 -04:00
William Wernert
3f007f1026
Disable fastestmirror during setup + soup
2021-04-20 15:18:06 -04:00
William Wernert
3d90423495
Fix summary message to preserve empty line
2021-04-20 14:44:58 -04:00
William Wernert
113e558a05
Set manager early for proxy config
2021-04-20 14:32:17 -04:00
William Wernert
ca9ac46cd2
Add keypress instruction at end of summary
2021-04-20 13:27:52 -04:00
William Wernert
95bb757b03
Fix salt-master check
2021-04-20 13:12:55 -04:00
William Wernert
369c0b43f5
Further jinja fixes
2021-04-20 12:55:23 -04:00
William Wernert
cd0a115ac7
Fix acng config and don't show changes when proxy string can exist in file
2021-04-20 12:55:00 -04:00
William Wernert
bbf16d0f11
Show airgap prompt within if statement + persist variable for node installs
2021-04-20 11:34:17 -04:00
Mike Reeves
3b203b9a31
Merge pull request #3922 from Security-Onion-Solutions/telefix1
...
Adjust sostatus timers
2021-04-20 08:14:34 -04:00
Mike Reeves
5072c24134
Adjust sostatus timers
2021-04-20 08:12:44 -04:00
William Wernert
b449955711
Proxy whiptail fixes
...
* Don't try to set up proxy/manager proxy during network only flow
* Fix logic to never show new menu on airgap, set MANAGERUPDATES to 1 on airgap minions
2021-04-19 16:26:53 -04:00
Mike Reeves
e9b86388da
Merge pull request #3912 from Security-Onion-Solutions/telefix1
...
Change telegraf scripts to new method of process detection
2021-04-19 14:40:06 -04:00
Mike Reeves
be6933e8fb
Change EPS for Telegraf
2021-04-19 14:20:00 -04:00
William Wernert
6156e754c4
Merge branch 'dev' into foxtrot
2021-04-19 14:15:23 -04:00
William Wernert
d2067a42bd
Don't skip new menu on airgap minions
2021-04-19 14:12:53 -04:00
William Wernert
b37da027fd
ECDSA to ED25519
2021-04-19 14:08:25 -04:00
William Wernert
d8457255cb
n -> z
2021-04-19 14:06:10 -04:00
William Wernert
7948906f51
Fix minion airgap logic
2021-04-19 14:04:01 -04:00
William Wernert
ba9a45bd0f
Split network init + ssh copy notices
2021-04-19 14:02:00 -04:00
William Wernert
07e0ce563d
Symmetrical spaces + remove useless logic
2021-04-19 13:50:30 -04:00
William Wernert
002fa99055
Fix whiptail order
2021-04-19 13:47:50 -04:00
William Wernert
59247b4579
Add exit check to new menu
2021-04-19 13:45:01 -04:00
Josh Patterson
a70b631b2c
Merge pull request #3911 from Security-Onion-Solutions/issue/3501
...
Issue/3501
2021-04-19 13:43:34 -04:00
Mike Reeves
0c0edbaac8
Change EPS for Telegraf
2021-04-19 13:29:46 -04:00
Mike Reeves
54322f5e9d
Change EPS for Telegraf
2021-04-19 13:17:02 -04:00
Mike Reeves
f5b0411772
Change EPS for Telegraf
2021-04-19 13:11:19 -04:00
Mike Reeves
31f193c397
Change EPS for Telegraf
2021-04-19 12:36:46 -04:00
William Wernert
c907d416df
Set proxy for apt cacher too
2021-04-19 11:27:17 -04:00
William Wernert
e8553162a5
[refactor] Change how whiptail asks for proxy settings
2021-04-19 10:51:39 -04:00
Mike Reeves
af7b6af32f
Merge pull request #3901 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix beat script location
2021-04-19 09:44:59 -04:00
m0duspwnens
9e57fd2df0
cant pipe to grep without , python_shell=True
2021-04-19 09:00:30 -04:00
Mike Reeves
ef0669aabb
Fix beat script location
2021-04-17 18:24:33 -04:00
William Wernert
58febe7955
[fix] so-docker-prune breaks when multiple "so-" images share a version
2021-04-16 16:04:07 -04:00
m0duspwnens
1b15f01874
fix salt.master state
2021-04-16 13:09:01 -04:00
m0duspwnens
24b263c812
only hold/unhold packages if not already unheld/held
2021-04-16 11:37:18 -04:00
m0duspwnens
9d676efada
move salt_minion_service state outside jinja if
2021-04-15 12:45:34 -04:00
m0duspwnens
9d01387a04
remove references to the common salt package
2021-04-15 11:57:25 -04:00
m0duspwnens
22edbcc111
can use SPLITCHAR before defined
2021-04-15 11:29:01 -04:00
m0duspwnens
2f198ed9fb
change how salt is held and unheld from updates
2021-04-15 09:42:00 -04:00
weslambert
427dd31fcb
Merge pull request #3876 from Security-Onion-Solutions/delta
...
FIX:Remove ESUSER/ESPASS for now to prevent issues with attempting Elasti…
2021-04-15 08:11:15 -04:00
Wes Lambert
f61bf73f97
Remove ESUSER/ESPASS for now to prevent issues with attempting Elastic Auth when connecting to ES.
2021-04-15 11:59:34 +00:00
Josh Patterson
923d50d91e
Merge pull request #3875 from Security-Onion-Solutions/issue/3543
...
add delay for salt-minion service starting
2021-04-14 16:34:21 -04:00
m0duspwnens
71d7ca8958
only manage service file if the right salt version is installed
2021-04-14 15:48:33 -04:00
m0duspwnens
d42cd52ae1
Merge remote-tracking branch 'remotes/origin/dev' into issue/3543
2021-04-14 15:23:51 -04:00
Mike Reeves
f177819e4f
Merge pull request #3871 from Security-Onion-Solutions/beatstats
...
Beatstats
2021-04-14 15:03:13 -04:00
m0duspwnens
f60da54ff0
remove extra lines at end
2021-04-14 11:11:13 -04:00
m0duspwnens
d003d4941b
fix bad typing
2021-04-14 11:10:19 -04:00
m0duspwnens
48c531bc2c
fix file defaults def
2021-04-14 11:09:13 -04:00
m0duspwnens
47aa66876d
fix import
2021-04-14 11:07:16 -04:00
m0duspwnens
9bfdae9cd5
fix import
2021-04-14 11:06:06 -04:00
m0duspwnens
a50b3e8475
add delay to salt-minion service starting - https://github.com/Security-Onion-Solutions/securityonion/issues/3543
2021-04-14 10:22:06 -04:00
Mike Reeves
6fc7ed1a25
Add telegraf scripts to track eps and failures for beats
2021-04-13 20:51:27 -04:00
Mike Reeves
904d34977f
Add telegraf scripts to track eps and failures for beats
2021-04-13 20:48:53 -04:00
Mike Reeves
aa66b6226f
Add hostname to the listener
2021-04-13 20:22:51 -04:00
Mike Reeves
db7dcd76cd
Add hostname to the listener
2021-04-13 20:21:32 -04:00
Mike Reeves
7153f58a03
Add Firewall for Beats port
2021-04-13 20:17:26 -04:00
Mike Reeves
621e5c1cf8
Enable Filebeat Stats
2021-04-13 19:18:10 -04:00
Mike Reeves
26547f4e96
Merge pull request #3864 from Security-Onion-Solutions/agauto
...
Fix Airgap Automation
2021-04-13 15:36:08 -04:00
Mike Reeves
989c2b23b1
Fix Airgap Automation
2021-04-13 15:34:03 -04:00
Josh Patterson
e16875da0c
Merge pull request #3855 from Security-Onion-Solutions/salt3003
...
Salt3003
2021-04-13 13:23:21 -04:00
Josh Brower
2b06223d7c
Merge pull request #3856 from Security-Onion-Solutions/feature/osquery-ingest-timestamp
...
Differentiate between event & ingest timestamp
2021-04-13 13:00:52 -04:00
Josh Brower
7cbeed985a
Differentiate between event & ingest timestamp
2021-04-13 12:55:40 -04:00
m0duspwnens
78ff84f968
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-13 12:05:58 -04:00
m0duspwnens
eb94c011e2
update location of yum keys and repo files for setup
2021-04-13 11:15:15 -04:00
m0duspwnens
325264dafd
point to new repo location
2021-04-12 17:44:50 -04:00
William Wernert
2392c0e2d4
Merge pull request #3846 from Security-Onion-Solutions/foxtrot
...
Setup changes/fixes
2021-04-12 16:39:08 -04:00
m0duspwnens
eb7bf58f30
fix issues with repo.client state
2021-04-12 16:33:32 -04:00
William Wernert
9d09e7bec3
Fix sostatus log cron job
2021-04-12 16:25:17 -04:00
William Wernert
25637b74db
Add back removed testing skip
2021-04-12 16:14:47 -04:00
William Wernert
cc344d921a
Skip whiptail during testing, echo error message to setup log
2021-04-12 16:13:32 -04:00
Josh Brower
2fa01c9386
Merge pull request #3845 from Security-Onion-Solutions/fix/wazuh-wel-alerts
...
Fix Wazuh WEL Shipping
2021-04-12 15:22:57 -04:00
Josh Brower
cf4de255ec
Fix Wazuh WEL Shipping
2021-04-12 15:18:18 -04:00
m0duspwnens
9240d376f3
combine client repo management into 1 state
2021-04-12 14:31:41 -04:00
William Wernert
8cb4a75eb1
Merge branch 'dev' into feature/setup-check-manager
2021-04-12 13:14:51 -04:00
William Wernert
73a1bdd885
Send stdout to log, and actually populate error message
2021-04-12 12:59:45 -04:00
William Wernert
5d98c896a3
/opt/so/log needs 755 permissions for soremote to read sostatus log
2021-04-12 12:53:17 -04:00
Mike Reeves
03abf4d4ee
Merge pull request #3828 from Security-Onion-Solutions/kilo
...
Do not set influxdb hostUrl if import node since import nodes don't r…
2021-04-09 21:43:25 -04:00
Jason Ertel
8facbcf18c
Do not set influxdb hostUrl if import node since import nodes don't run influxdb
2021-04-09 20:40:44 -04:00
Jason Ertel
280958e298
Merge pull request #3826 from Security-Onion-Solutions/kilo
...
Add raid/process status to Grid
2021-04-09 16:33:14 -04:00
Jason Ertel
5cb73ced36
Add Influx module to SOC config
2021-04-09 14:58:15 -04:00
Jason Ertel
21d922c640
Merge branch 'dev' into kilo
2021-04-09 10:24:27 -04:00
William Wernert
4db20a00ff
Add quotes around description, since it can contain spaces
2021-04-09 10:16:19 -04:00
William Wernert
026ce76966
Change airgap prompt to menu
2021-04-09 10:11:00 -04:00
William Wernert
764307bfa0
Reformat airgap whiptail prompt
2021-04-09 10:09:28 -04:00
William Wernert
fc9df2bbae
Update airgap question to ask during minion installs too
2021-04-09 10:00:50 -04:00
William Wernert
9b5276f1ab
Remove bad || statement
2021-04-09 09:59:54 -04:00
William Wernert
b2fcd438c2
Initial support for checking state of manager during setup
2021-04-09 09:39:33 -04:00
m0duspwnens
ecda46c04b
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-09 09:37:35 -04:00
Josh Patterson
69ad3ad491
Merge pull request #3817 from Security-Onion-Solutions/saltver
...
Do not upgrade salt on ISO installs
2021-04-09 08:50:08 -04:00
Mike Reeves
c9feda1168
Do not upgrade salt on ISO installs
2021-04-09 08:48:29 -04:00
Jason Ertel
d5bc7ec627
Merge branch 'dev' into kilo
2021-04-08 18:43:37 -04:00
m0duspwnens
6650ad5cdd
make the -r for all
2021-04-08 14:04:30 -04:00
William Wernert
0ea57b4848
Merge pull request #3805 from Security-Onion-Solutions/foxtrot
...
Setup option summary + proxy test fix
2021-04-08 12:00:23 -04:00
Mike Reeves
ea9103ad53
Merge pull request #3806 from Security-Onion-Solutions/saltfix
...
Fix Telegraf sostatus
2021-04-08 11:51:24 -04:00
Mike Reeves
b53815d04a
Fix Telegraf sostatus
2021-04-08 11:42:41 -04:00
Jason Ertel
5ef336fed2
Merge branch 'dev' into kilo
2021-04-08 11:23:07 -04:00
Jason Ertel
f7f95b6c54
Add model to sensoroni agent config
2021-04-08 11:22:54 -04:00
Mike Reeves
28666e0db2
Merge pull request #3804 from Security-Onion-Solutions/saltfix
...
Fix Repos by forcing removal
2021-04-08 11:08:35 -04:00
Mike Reeves
09b14e6a86
Fix Repo Logic
2021-04-08 10:38:50 -04:00
Mike Reeves
4c5f373ffa
Fix Repo Logic
2021-04-08 10:37:44 -04:00
Mike Reeves
fdaf251ba0
Fix Repo Logic
2021-04-08 10:36:52 -04:00
Mike Reeves
951369c2d6
Fix Repo Logic
2021-04-08 10:25:36 -04:00
Mike Reeves
ce9f781d81
Fix Repo Logic
2021-04-08 10:24:04 -04:00
Mike Reeves
725320ebc8
Fix Repo Logic
2021-04-08 10:02:11 -04:00
m0duspwnens
dce476b604
change back to saltstack3003 repo
2021-04-08 09:54:41 -04:00
Mike Reeves
b609f250c3
Merge pull request #3798 from Security-Onion-Solutions/saltfix
...
Fix so repo for salt
2021-04-08 08:48:57 -04:00
Mike Reeves
d4a3bc4550
Fix so repo for salt
2021-04-08 08:43:20 -04:00
William Wernert
a5f5888913
Summary order change
2021-04-07 17:03:08 -04:00
Mike Reeves
9a7a7a3b12
Merge pull request #3795 from Security-Onion-Solutions/telemetric
...
Add raid bind
2021-04-07 16:33:14 -04:00
Mike Reeves
3caaf06820
Add sostatus for telegraf
2021-04-07 16:30:16 -04:00
Mike Reeves
8ab4dd10d4
Add sostatus for telegraf
2021-04-07 16:29:44 -04:00
Mike Reeves
9baa9767ca
Add raid bind
2021-04-07 16:12:51 -04:00
William Wernert
3c69c0c24c
Correct patch schedule name logic in summary
2021-04-07 14:15:02 -04:00
William Wernert
3a4cf8aa26
Add proxy url/user to summary
2021-04-07 13:54:01 -04:00
m0duspwnens
c4f0119276
fix check if repo file exists
2021-04-07 13:51:40 -04:00
William Wernert
ec076bba4a
MTU is not always set by the user, so don't always show in summary
2021-04-07 13:42:18 -04:00
William Wernert
f83ac5a278
Print install summary to file and setup log after user confirms
2021-04-07 13:38:47 -04:00
m0duspwnens
425e5bc4c3
add some quotes
2021-04-07 13:31:43 -04:00
William Wernert
5e5df4d65a
Merge branch 'feature/setup-end-screen' into foxtrot
2021-04-07 13:23:45 -04:00
William Wernert
377b14ccb1
ESCLUSTERNAME is empty for standalone, so check if it's set before listing
2021-04-07 13:20:55 -04:00
William Wernert
ceb1ea61dc
Summary screen changes
2021-04-07 13:15:49 -04:00
m0duspwnens
249fa06fc7
echo when performing the repo actions for 2.3.50
2021-04-07 13:03:27 -04:00
m0duspwnens
5578206bf1
need to make the repo changes before we try to upgrade sa;t
2021-04-07 12:41:01 -04:00
Josh Patterson
ceb4d4ace4
Merge pull request #3790 from Security-Onion-Solutions/airgapfix
...
Fix Logic for Airgap distributed
2021-04-07 12:37:11 -04:00
Mike Reeves
c8c1553247
Fix Logic for Airgap distributed
2021-04-07 12:36:50 -04:00
Mike Reeves
ed0cd97de5
Fix Logic for Airgap distributed
2021-04-07 12:34:23 -04:00
m0duspwnens
b7aa9ddaa3
run preupgrade changes if 2.3.40
2021-04-07 11:37:55 -04:00
m0duspwnens
54e0394776
change from saltstack3003 to just saltstack for repo
2021-04-07 10:57:09 -04:00
m0duspwnens
080ecba8e6
change delrepos
2021-04-07 10:54:46 -04:00
William Wernert
5b3014496b
Proxy fixes
...
* Adjust proxy test timeout
* Don't show proxy on error
* Add echo statement so user knows what setup is doing
2021-04-07 10:35:59 -04:00
Mike Reeves
95b440de43
Merge pull request #3783 from Security-Onion-Solutions/airgapfix
...
Fix Logic for Airgap distributed
2021-04-07 10:18:07 -04:00
William Wernert
88c565feae
Fix proxy test logic
2021-04-07 10:14:16 -04:00
Mike Reeves
5cd7d65b3f
Fix Logic for Airgap distributed
2021-04-07 10:03:33 -04:00
m0duspwnens
8f208728dd
change delete repos
2021-04-07 09:10:16 -04:00
William Wernert
099ac2ff19
Minor formatting changes to whiptail end screen
2021-04-07 09:06:22 -04:00
Jason Ertel
fb02a10bfb
Merge pull request #3781 from Security-Onion-Solutions/waagent
...
Detect if running in an Azure VM
2021-04-07 08:35:36 -04:00
Jason Ertel
ee079f1132
Merge from dev
2021-04-07 08:09:24 -04:00
m0duspwnens
9b19f93ad0
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 16:46:12 -04:00
Mike Reeves
6f7e6cee80
Force it
2021-04-06 16:43:42 -04:00
m0duspwnens
a95ead1ec8
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 16:31:16 -04:00
Mike Reeves
51bf988d31
Add .repo extension
2021-04-06 16:21:19 -04:00
m0duspwnens
73e00dbe30
change salt upgrade in soup
2021-04-06 16:07:08 -04:00
m0duspwnens
f522799b36
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 15:58:21 -04:00
Mike Reeves
b50700114c
Add the do
2021-04-06 15:58:08 -04:00
m0duspwnens
9c7309797a
Merge remote-tracking branch 'remotes/origin/soup2350' into salt3003.1
2021-04-06 15:48:36 -04:00
Mike Reeves
92768ecd08
Add upgrade function
2021-04-06 15:47:50 -04:00
Mike Reeves
af6403f874
soup salt and repos ohh my
2021-04-06 15:45:05 -04:00
William Wernert
6d6829ba34
Remove duplicate variable assignment
2021-04-06 13:21:07 -04:00
William Wernert
b70d9c0892
Add end summary and warning about SSH host key change
2021-04-06 13:20:56 -04:00
m0duspwnens
80509fbbc6
fix -R repo option
2021-04-06 12:23:11 -04:00
m0duspwnens
914a01e321
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-06 12:02:22 -04:00
m0duspwnens
6da84c7c87
strip trailing /
2021-04-06 12:00:36 -04:00
m0duspwnens
521dbbd90a
change repo path
2021-04-06 11:45:59 -04:00
m0duspwnens
01f95c846c
remove trailing /
2021-04-06 11:41:06 -04:00
m0duspwnens
049001d572
set repo url for salt upgrade for centos
2021-04-06 09:48:21 -04:00
m0duspwnens
1ea0be0097
remove references to 3003.1 change to 3003
2021-04-06 09:15:22 -04:00
William Wernert
b6dba26e2c
Merge pull request #3767 from Security-Onion-Solutions/foxtrot
...
Move function call using nmcli to prevent error during setup
2021-04-06 09:11:23 -04:00
m0duspwnens
5525b9e97d
point to new salt repo
2021-04-06 08:30:57 -04:00
Jason Ertel
919eec497d
Merge branch 'dev' into waagent
2021-04-05 20:19:30 -04:00
Josh Patterson
8dc915e965
Merge pull request #3770 from Security-Onion-Solutions/newrepo
...
Fix Spelling issue
2021-04-05 18:53:19 -04:00
Mike Reeves
168d0bcaf4
Fix Spelling issue
2021-04-05 18:30:07 -04:00
Mike Reeves
08a857239c
Merge pull request #3769 from Security-Onion-Solutions/newrepo
...
Add some manager logic
2021-04-05 17:50:05 -04:00
Mike Reeves
a38015bd98
Add some manager logic
2021-04-05 17:28:04 -04:00
m0duspwnens
3a1c478d9a
compare the new var
2021-04-05 16:56:34 -04:00
Jason Ertel
5f6770925d
speculative commit
2021-04-05 16:52:12 -04:00
m0duspwnens
89f72bb6ed
check if . in new version, append .1 if not
2021-04-05 16:44:51 -04:00
Jason Ertel
4d9f928aed
Merge branch 'dev' into kilo
2021-04-05 15:57:59 -04:00
m0duspwnens
83bf709290
use -r for salt boostrap in soup as well
2021-04-05 15:12:53 -04:00
Mike Reeves
d62ab60d48
Merge pull request #3768 from Security-Onion-Solutions/newrepo
...
Newrepo
2021-04-05 15:03:44 -04:00
Mike Reeves
fc88634159
Set the Repo for airgap during install
2021-04-05 15:01:21 -04:00
m0duspwnens
ae83fa61f3
Merge remote-tracking branch 'remotes/origin/dev' into salt3003.1
2021-04-05 14:36:21 -04:00
Josh Patterson
3adc2a8e63
Merge pull request #3766 from Security-Onion-Solutions/newrepo
...
Newrepo
2021-04-05 14:35:46 -04:00
Mike Reeves
97503bc35d
Merge pull request #3761 from Security-Onion-Solutions/newraid
...
Newraid
2021-04-05 14:31:51 -04:00
m0duspwnens
9b8b5e6173
use -r by default to disable salt bootstrap from doing repo things
2021-04-05 14:12:24 -04:00
m0duspwnens
ba3c65d49f
Merge remote-tracking branch 'remotes/origin/issue/3501' into salt3003.1
2021-04-05 12:52:48 -04:00
William Wernert
1dc45541eb
Merge branch 'dev' into foxtrot
2021-04-05 12:41:08 -04:00
William Wernert
6f784565d4
Merge branch 'fix/nmcli-ami-error' into foxtrot
2021-04-05 12:41:02 -04:00
William Wernert
c864936c15
Merge pull request #3762 from Security-Onion-Solutions/foxtrot
...
Refactor so-ssh-harden
2021-04-05 12:39:51 -04:00
Mike Reeves
a824813cdb
Add model to sensoroni config
2021-04-05 12:10:29 -04:00
Mike Reeves
bad22ab541
Add model to sensoroni config
2021-04-05 12:08:38 -04:00
Mike Reeves
f41ee1457b
Merge pull request #3755 from Security-Onion-Solutions/issue/3753
...
FIX: Hunt query for HTTP EXE downloads should work for both Zeek and …
2021-04-05 11:42:45 -04:00
Mike Reeves
5aefa2a024
Fix Raid for Jertel compliance
2021-04-05 11:41:19 -04:00
Mike Reeves
f9dc040c7f
Fix Raid
2021-04-05 11:38:39 -04:00
m0duspwnens
1c3a7094bd
upgrade salt to 3003.1
2021-04-05 11:05:48 -04:00
Mike Reeves
d43cb3e133
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-04-05 10:48:01 -04:00
m0duspwnens
534dbf9761
change the upgrade command - https://github.com/Security-Onion-Solutions/securityonion/issues/3501
2021-04-05 09:07:00 -04:00
Doug Burks
8ca0626387
FIX: Hunt query for HTTP EXE downloads should work for both Zeek and Suricata #3753
2021-04-05 06:55:40 -04:00
Jason Ertel
e430be1017
Enable Flux compatibility mode to prepare for eventual migration to 2.0
2021-04-02 16:36:29 -04:00
William Wernert
d19c03efef
Refactor search of config lines
...
* Create arrays for each line and loop through them for better code readability
* Add more host key algorithms for removal
* Update regex to look for a comma or EOL at the end of the search term, to avoid missing last item in list
2021-04-02 14:49:22 -04:00
William Wernert
8b8086b91a
Update wording, as the new key tends to be ED25519, not ECDSA
2021-04-02 10:20:28 -04:00
William Wernert
fd57996bc6
Change behavior of adding lines to sshd config
...
* Replace existing lines in cases where a change has already been made
2021-04-02 10:00:27 -04:00
William Wernert
43c31b4e66
Fix script so changes are actually made
2021-04-01 14:56:05 -04:00
William Wernert
fa373e9db0
Merge branch 'fix/ssh-harden-setup' into foxtrot
2021-04-01 11:04:10 -04:00
William Wernert
58989398e0
Merge pull request #3721 from Security-Onion-Solutions/foxtrot
...
Allow user to enter a description during setup
2021-04-01 11:02:23 -04:00
Mike Reeves
c60d4aca16
Merge pull request #3724 from Masaya-A/Fix-https
...
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 10:36:02 -04:00
Mike Reeves
234dec3f63
Merge pull request #3734 from Security-Onion-Solutions/zeekports
...
Reserve ports for Zeek
2021-04-01 10:35:16 -04:00
Mike Reeves
7d489ea34f
Merge pull request #3735 from Security-Onion-Solutions/kilo
...
For hunt quick actions, pipe value to 'escape' operator to escape bac…
2021-04-01 10:35:01 -04:00
Mike Reeves
7c6b037ae5
Reserve ports for Zeek
2021-04-01 10:30:52 -04:00
Mike Reeves
40313fc2f5
Reserve ports for Zeek
2021-04-01 10:29:58 -04:00
Mike Reeves
0d05612393
Reserve ports for Zeek
2021-04-01 10:00:55 -04:00
Masaya-A
bc04cae918
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 16:59:47 +09:00
Masaya-A
908c5f8ef6
Merge pull request #8 from Security-Onion-Solutions/dev
...
Dev Sync 20210401
2021-04-01 16:55:41 +09:00
Mike Reeves
88eab86528
Manage the repo files
2021-03-31 17:07:30 -04:00
Mike Reeves
9645988555
Manage the repo files
2021-03-31 17:06:26 -04:00
Mike Reeves
1509722185
Manage the repo files
2021-03-31 17:04:56 -04:00
Mike Reeves
bfc5bb011f
Manage the repo files
2021-03-31 17:03:52 -04:00
Mike Reeves
13421bb04b
Manage the repo files
2021-03-31 16:59:15 -04:00
Josh Patterson
6cebc41353
Merge pull request #3720 from Security-Onion-Solutions/issue/3709
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 16:54:15 -04:00
Mike Reeves
f387c4327a
Manage the repo files
2021-03-31 16:53:20 -04:00
Mike Reeves
358f397535
Manage the repo files
2021-03-31 16:50:43 -04:00
Mike Reeves
9b84a92ced
Manage the repo files
2021-03-31 16:47:04 -04:00
William Wernert
a8483cb30e
Merge branch 'dev' into foxtrot
2021-03-31 16:02:26 -04:00
William Wernert
dfe5e73608
Merge branch 'feature/node-description' into foxtrot
2021-03-31 16:02:12 -04:00
William Wernert
3de980e4a1
Move function call to run after Network Manager is installed
2021-03-31 16:00:37 -04:00
Josh Brower
2b86241450
Merge pull request #3717 from Security-Onion-Solutions/fix/playbook-timestamps
...
Fix Playbook Alert timestamps
2021-03-31 15:47:11 -04:00
Josh Brower
ef98445560
Fix Playbook Alert timestamps
2021-03-31 15:44:41 -04:00
m0duspwnens
f7e99b4961
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 15:17:15 -04:00
Jason Ertel
820b01405f
For hunt quick actions, pipe value to 'escape' operator to escape backslashes and double quotes
2021-03-31 14:57:36 -04:00
William Wernert
2a595f03b7
Merge pull request #3630 from Security-Onion-Solutions/foxtrot
...
Add option to configure chrony as an ntp service
2021-03-31 13:41:06 -04:00
William Wernert
761a12ebbb
Fix variable name
2021-03-31 13:32:49 -04:00
William Wernert
1c4ba28336
[fix] host_pillar overwrites the file, so run ntp_pillar after it
2021-03-31 13:28:42 -04:00
Mike Reeves
f8d7241354
Fix repo file path
2021-03-31 12:55:46 -04:00
Mike Reeves
89922a439e
Move repo files
2021-03-31 12:37:33 -04:00
Josh Brower
209d348108
Merge pull request #3688 from Security-Onion-Solutions/fix/playbook-sync
...
Fix sensor cleanup & playbook sync scripts
2021-03-31 11:59:27 -04:00
Jason Ertel
cdf3254485
Merge pull request #3708 from Security-Onion-Solutions/newrepo
...
Add Wazuh 4 repo
2021-03-31 09:29:50 -04:00
Mike Reeves
5e25d762c4
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-31 09:28:18 -04:00
Mike Reeves
46865809ed
Fix Automation Testing round 2
2021-03-31 09:28:02 -04:00
Mike Reeves
bb39ccc1aa
Fix Automation Testing
2021-03-31 09:25:21 -04:00
Mike Reeves
0d077b0d49
Merge pull request #3704 from gebhard73/patch-2
...
Update so-index-list
2021-03-31 09:18:29 -04:00
William Wernert
04920dcbed
Merge branch 'dev' into foxtrot
2021-03-31 09:15:17 -04:00
William Wernert
c03e2b2c11
Move ntp server array to its own pillar in the minion sls file
2021-03-31 09:14:40 -04:00
Mike Reeves
5203c25971
Add Wazuh 4 Repo
2021-03-31 09:13:38 -04:00
Mike Reeves
b485531bd8
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-31 09:12:56 -04:00
weslambert
5eb0137c21
Merge pull request #3705 from Security-Onion-Solutions/delta
...
Enforce date type for ingest.timestamp
2021-03-31 08:40:41 -04:00
Wes Lambert
942de130ca
Enforce date type for ingest.timestamp
2021-03-31 12:24:51 +00:00
gebhard73
0b9cf57b5f
Update so-index-list
...
Sort by index name.
2021-03-31 14:22:06 +02:00
Mike Reeves
e92f5c122c
Merge pull request #3689 from Security-Onion-Solutions/kilo
...
Remove incompatible example
2021-03-30 16:08:16 -04:00
William Wernert
177989269f
Better formatting of chrony.conf
2021-03-30 15:50:37 -04:00
William Wernert
fd51b327ee
Add messaging to explain chronyc output to log
2021-03-30 15:23:57 -04:00
William Wernert
be6eb3ed6c
Restart chrony in case it's already running
2021-03-30 14:17:05 -04:00
Josh Brower
679925ebd9
Fix sensor cleanup & playbook sync scripts
2021-03-30 13:29:56 -04:00
weslambert
ff317cdcf1
Merge pull request #3684 from Security-Onion-Solutions/delta
...
Add Elastic scripts
2021-03-30 12:06:00 -04:00
Wes Lambert
7049383ba6
Add Elastic scripts
2021-03-30 15:47:05 +00:00
Mike Reeves
2534ca7eb7
Merge pull request #3633 from Security-Onion-Solutions/newrepo
...
Attempt to use so repo for network install
2021-03-30 11:37:46 -04:00
Mike Reeves
b2138045c0
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-30 11:29:22 -04:00
Mike Reeves
fc3fd00216
Fix formatting
2021-03-30 11:28:47 -04:00
Mike Reeves
09064baf71
Update so-common
2021-03-30 11:21:19 -04:00
Mike Reeves
5f5a53b8bb
Push repolist to dev null
2021-03-30 11:14:58 -04:00
William Wernert
25eca39428
Always ask for ntp setup on iso installs, don't ask on network installs
2021-03-30 09:54:21 -04:00
William Wernert
0e9ffe033d
Show message about setting up network earlier during setup
2021-03-30 09:30:06 -04:00
Jason Ertel
e98f3e54c0
Merge branch 'dev' into kilo
2021-03-29 17:37:18 -04:00
Mike Reeves
3fce63e0c5
Fix Repo Again
2021-03-29 16:43:44 -04:00
Mike Reeves
f73bf947bc
Fix repo url
2021-03-29 15:42:26 -04:00
Mike Reeves
1a58479f39
Fix acng passthrough
2021-03-29 15:15:34 -04:00
William Wernert
d81d4e7474
Merge branch 'dev' into foxtrot
2021-03-29 09:36:38 -04:00
William Wernert
2ff790699f
[fix] Set ntp_string to empty, not ntp_servers
2021-03-29 09:36:24 -04:00
Jason Ertel
6bce8e8e2c
Remove incompatible example
2021-03-29 07:30:26 -04:00
Mike Reeves
d889bd2694
Fix Security Onio Pub Key
2021-03-28 22:32:03 -04:00
Mike Reeves
5882642c32
fixpath for GPG Keys for real
2021-03-28 22:10:02 -04:00
Mike Reeves
362bf55526
fixpath for GPG keys
2021-03-28 22:01:58 -04:00
Jason Ertel
0945747a70
Merge pull request #3649 from Security-Onion-Solutions/kilo
...
Support custom login banner
2021-03-26 22:33:36 -04:00
Mike Reeves
bab062e52b
Fix acng to actually cache
2021-03-26 16:21:03 -04:00
Mike Reeves
955d41abde
Fix acng to actually cache
2021-03-26 16:18:49 -04:00
Mike Reeves
26f8ae87c5
Fix acng to actually cache
2021-03-26 16:10:00 -04:00
Mike Reeves
8819cc1371
Fix acng to actually cache
2021-03-26 16:01:22 -04:00
Jason Ertel
9d6c2a5f15
Merge branch 'dev' into kilo
2021-03-26 15:58:05 -04:00
Jason Ertel
0195d366cc
Add custom banner to login page
2021-03-26 14:44:31 -04:00
William Wernert
eb674b3b93
Validate list of ntp servers (ip4, hostname, or fqdn)
2021-03-25 14:45:33 -04:00
William Wernert
150e724a4a
Fix chrony install logic + add sleep for chrony to finish sync
2021-03-25 13:37:54 -04:00
Mike Reeves
af3951e1ad
Attempt to use so repo for network install
2021-03-25 11:51:55 -04:00
Masaya-A
16f88c38de
Merge pull request #7 from Security-Onion-Solutions/dev
...
Dev Sync
2021-03-25 09:09:38 +09:00
Jason Ertel
909a1badcb
Merge pull request #3622 from Security-Onion-Solutions/kilo
...
Correct local online docs link to release notes
2021-03-24 15:01:35 -04:00
Jason Ertel
7fc2467951
Correct local online docs link to release notes
2021-03-24 15:00:02 -04:00
William Wernert
c6a257bc50
Merge branch 'dev' into feature/ntp-service
2021-03-24 11:50:47 -04:00
Mike Reeves
f0c19cf2af
Merge pull request #3616 from Security-Onion-Solutions/kilo
2021-03-24 11:48:31 -04:00
Jason Ertel
08f46a779a
Remove freqserver, minio, and domainstats from image list
2021-03-24 11:32:29 -04:00
William Wernert
982f2de33c
[fix] Refactor so-ssh-harden
...
* Create a temp file to make changes, and only copy back over if any changes are made
* Test changes as they're made, and exit if the test fails
* Only add lines if they don't already exist in the config
2021-03-24 09:48:00 -04:00
Jason Ertel
79ad87f83c
Remove freqserver, minio, and domainstats from image list
2021-03-23 21:16:17 -04:00
Jason Ertel
887920e7c5
Implement customizable overview page
2021-03-23 16:44:08 -04:00
Jason Ertel
2d8c73d317
Merge branch 'dev' into kilo
2021-03-23 16:31:44 -04:00
Jason Ertel
5ade0b9f40
Implement customizable overview page
2021-03-23 16:31:41 -04:00
William Wernert
23cd006724
so-ssh-harden fixes
...
* Change when script is run during setup
* Add newlines to sshd config for legibility
2021-03-23 14:06:10 -04:00
William Wernert
3287a777a2
[fix] Pre-fill hostname re-enter on default
2021-03-23 11:41:12 -04:00
William Wernert
9f0afd90f1
[fix] Add missing backslash
2021-03-23 11:27:37 -04:00
William Wernert
2d873b92fa
Fix ntp logic elsewhere
2021-03-23 10:22:41 -04:00
William Wernert
0e9c81c145
Fix logic around ntp prompt
2021-03-23 09:44:44 -04:00
William Wernert
884343b299
Merge branch 'dev' into feature/ntp-service
2021-03-23 09:36:41 -04:00
William Wernert
184c763b02
[fix] Export correct variable to check later in setup
2021-03-23 09:36:08 -04:00
William Wernert
ace30c07ea
[fix] Also sync time before updating system clock
2021-03-23 09:22:09 -04:00
William Wernert
b3f558a1f8
[fix] Also check if proxy is set before asking for ntp servers
2021-03-23 09:14:34 -04:00
Masaya-A
151376a18f
Merge pull request #5 from Security-Onion-Solutions/dev
...
Dev Sync
2021-03-23 14:27:29 +09:00
Jason Ertel
197693df4e
Merge pull request #3580 from Security-Onion-Solutions/kilo
...
Upgrade to version 2.3.50
2021-03-22 21:10:05 -04:00
William Wernert
449e0d853c
Initial support for ntp service via chronyd
2021-03-22 15:52:51 -04:00
Jason Ertel
8448588809
Upgrade to version 2.3.50
2021-03-22 15:04:02 -04:00
Mike Reeves
cdb16e3e5a
Merge pull request #3579 from Security-Onion-Solutions/kilo
...
Revert upgrade to version 2.3.50
2021-03-22 14:55:21 -04:00
Jason Ertel
86cb59d5ae
Revert upgrade to version 2.3.50
2021-03-22 14:53:36 -04:00
Mike Reeves
b4172565e8
Merge pull request #3578 from Security-Onion-Solutions/kilo
...
Upgrade to version 2.3.50
2021-03-22 14:50:27 -04:00
Jason Ertel
b83ae4bded
Upgrade to version 2.3.50
2021-03-22 14:49:14 -04:00
Mike Reeves
afed0b70eb
Merge pull request #3572 from Security-Onion-Solutions/dev
...
2.3.40
2021-03-22 14:43:34 -04:00
William Wernert
50fa0dc81a
Allow user to enter a description during setup
...
Resolves #2404
2021-03-22 11:32:37 -04:00
Jason Ertel
e9bd3888c4
Merge pull request #3571 from Security-Onion-Solutions/2340sigrtd
...
Verify ISO and update gpg
2021-03-22 10:03:42 -04:00
Mike Reeves
ea5624b4bf
Update date
2021-03-22 10:02:04 -04:00
Mike Reeves
11cb843fb4
Verify ISO and update gpg
2021-03-22 09:59:48 -04:00
Mike Reeves
57664a3c8a
Merge pull request #3570 from Security-Onion-Solutions/Update-Readme
...
Update README.md
2021-03-22 09:14:34 -04:00
Mike Reeves
71d4d7ee8f
Update README.md
2021-03-22 09:03:47 -04:00
Mike Reeves
25c9e70658
Merge pull request #3564 from Security-Onion-Solutions/fix/dash
...
Fix Dashboard Placeholder
2021-03-20 16:10:07 -04:00
Mike Reeves
e06e023d8e
Fix Dashboard Placeholder
2021-03-20 14:05:55 -04:00
Mike Reeves
4fe14dbfd8
Merge pull request #3558 from Security-Onion-Solutions/fix/https-playbook-alerter
...
Fix https Playbook Alerter
2021-03-19 16:39:35 -04:00
Josh Brower
2425355680
Fix https Playbook Alerter
2021-03-19 16:38:33 -04:00
Josh Patterson
30b948f6b8
Merge pull request #3557 from Security-Onion-Solutions/suri-eve-file-mode
...
prevent salt warning about file mode
2021-03-19 16:24:26 -04:00
m0duspwnens
e87fb013dc
prevent salt warning - The 'file_mode' argument will be ignored. Please use 'mode' instead to set file permissions.
2021-03-19 16:21:18 -04:00
Mike Reeves
908a9c2c06
Merge pull request #3550 from Security-Onion-Solutions/issue/3493
...
fix docker-ce holds
2021-03-19 15:18:45 -04:00
m0duspwnens
d0f938a600
fix docker-ce holds
2021-03-19 15:16:58 -04:00
Mike Reeves
ee2a6f8be9
Merge pull request #3549 from Security-Onion-Solutions/saved_objects
...
Update saved objects and remove index patterns because this is now handled by Field Caps API
2021-03-19 14:32:55 -04:00
Wes Lambert
b481cf885b
Update saved objects and remove index patterns because this is now handled by Field Caps API
2021-03-19 18:30:42 +00:00
Mike Reeves
890c0da81a
Merge pull request #3546 from Security-Onion-Solutions/kilo
...
Update release notes for 2.3.40
2021-03-19 11:25:15 -04:00
Jason Ertel
e69f6270f9
Merge branch 'dev' into kilo
2021-03-19 11:15:47 -04:00
Jason Ertel
83a3488a06
Update changes.json to reflect 2.3.40 changes
2021-03-19 11:15:27 -04:00
Mike Reeves
de61886441
Merge pull request #3544 from Security-Onion-Solutions/feature/setup-kibana-space
...
Configure default Space in Kibana during setup
2021-03-19 09:02:18 -04:00
Josh Brower
9d533e5db0
Merge pull request #3542 from Security-Onion-Solutions/fix/fleet-custom-hostname
...
Fix Fleet Custom Hostname Reactor
2021-03-19 08:21:30 -04:00
Josh Brower
d020f1d1a1
Fix Fleet Custom Hostname Reactor
2021-03-19 08:15:47 -04:00
William Wernert
b595c6ddf7
Configure default Space in Kibana during setup
2021-03-18 16:00:13 -04:00
Mike Reeves
28999af493
Merge pull request #3539 from Security-Onion-Solutions/fix/postsoup
...
Fix/postsoup
2021-03-18 15:46:36 -04:00
Josh Brower
77b8aecfd9
add so-kibana-space-defaults
2021-03-18 15:40:12 -04:00
Mike Reeves
2e84af621e
Add postloop for 2.3.40
2021-03-18 15:14:10 -04:00
William Wernert
6b2947ca6a
Merge pull request #3535 from Security-Onion-Solutions/fix/cloud-var
...
Set is_cloud variable in the main shell process
2021-03-18 14:00:58 -04:00
Mike Reeves
2bd3a6418d
Merge pull request #3536 from Security-Onion-Solutions/kilo
...
Refresh fieldcaps every 5 minutes
2021-03-18 13:57:24 -04:00
Jason Ertel
cc30abfe1b
Refresh fieldcaps every 5 minutes
2021-03-18 13:48:57 -04:00
William Wernert
0edf419bcb
Remove redundant message
2021-03-18 13:16:45 -04:00
William Wernert
360f0d4dfd
Also print stdout message to log
2021-03-18 13:12:16 -04:00
William Wernert
27ff823bc0
[fix] Don't set is_cloud in a subshell
2021-03-18 13:09:46 -04:00
Mike Reeves
1f85506fb1
Merge pull request #3532 from Security-Onion-Solutions/fix/packaging
...
Also add python packaging lib package to common state
2021-03-18 11:30:56 -04:00
William Wernert
cb0fb93f77
Also add python packaging lib package to common state
2021-03-18 11:28:25 -04:00
William Wernert
fcf0417fbf
Merge pull request #3528 from Security-Onion-Solutions/fix/default-no-proxy
...
Change proxy prompt to default to no
2021-03-18 09:57:03 -04:00
William Wernert
c910a2d2a0
Change proxy prompt to default to no
2021-03-18 09:52:11 -04:00
William Wernert
066a8598a6
Merge pull request #3523 from Security-Onion-Solutions/issue/3493
...
fix docker versions in setup
2021-03-18 09:31:35 -04:00
William Wernert
b5770964c4
Merge pull request #3522 from Security-Onion-Solutions/fix/install-network-manager
...
[fix] CentOS ami does not include NetworkManager, so install it
2021-03-18 09:10:41 -04:00
William Wernert
31725ac627
[fix] Indent
2021-03-18 09:09:29 -04:00
m0duspwnens
dbe54708ef
fix docker versions in setup https://github.com/Security-Onion-Solutions/securityonion/issues/3493
2021-03-18 09:09:28 -04:00
William Wernert
163cb8f3ca
[fix] Typo
2021-03-18 09:08:31 -04:00
William Wernert
4f104c860e
[fix] CentOS ami does not include NetworkManager, so install it
2021-03-18 09:00:02 -04:00
Mike Reeves
db605adaf6
Merge pull request #3517 from Security-Onion-Solutions/fix/restarting-docker-message
2021-03-17 21:15:37 -04:00
Mike Reeves
308f10fbdd
Merge pull request #3510 from Security-Onion-Solutions/kilo
2021-03-17 21:14:45 -04:00
William Wernert
6e3d951b01
[fix] Show message in terminal when restarting Docker to avoid confusion
2021-03-17 20:17:23 -04:00
Mike Reeves
9a2b5fa301
Merge pull request #3516 from Security-Onion-Solutions/add_suricata_eve_clean
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3515
2021-03-17 18:50:23 -04:00
m0duspwnens
ec179f8e9b
https://github.com/Security-Onion-Solutions/securityonion/issues/3515
2021-03-17 18:44:25 -04:00
Jason Ertel
bc002cb9fb
Merge branch 'dev' into kilo
2021-03-17 18:29:52 -04:00
Jason Ertel
4e9f629231
Reformat inactiveTools list in JSON format
2021-03-17 18:25:05 -04:00
Mike Reeves
75f9138a40
Merge pull request #3514 from Security-Onion-Solutions/fix/accept-hostname-proxy
...
[fix] Also accept a hostname in the proxy URL
2021-03-17 17:51:59 -04:00
William Wernert
96ac742b69
[fix] Also accept a hostname in the proxy URL
2021-03-17 17:31:47 -04:00
Jason Ertel
42809083e8
Merge branch 'dev' into kilo
2021-03-17 17:14:29 -04:00
Mike Reeves
a3b7388aba
Merge pull request #3511 from Security-Onion-Solutions/fix/elastic-license-agree
...
Make the Elastic license prompt case insensitive
2021-03-17 16:57:32 -04:00
William Wernert
7da027abc1
Make the Elastic license prompt case insensitive
2021-03-17 16:55:34 -04:00
Jason Ertel
4de809ecbd
Automatically hide SOC tools that are not installed. Resolves #1643 .
2021-03-17 16:13:50 -04:00
Josh Brower
8fd3f102f1
Merge pull request #3509 from Security-Onion-Solutions/fix/kibana-space-defaults
...
Add space defaults script
2021-03-17 15:55:11 -04:00
Josh Brower
7583593152
Add space defaults scripot
2021-03-17 15:47:36 -04:00
Jason Ertel
dc0d989942
Merge pull request #3504 from Security-Onion-Solutions/issue/3493
...
UPGRADE: docker-ce, docker-ce-cli, containerd to latest
2021-03-17 13:51:31 -04:00
William Wernert
46d346aa62
Merge pull request #3503 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-03-17 12:07:40 -04:00
William Wernert
16d6e116fa
Merge branch 'dev' into foxtrot
...
# Conflicts:
# salt/idstools/init.sls
2021-03-17 11:52:54 -04:00
Mike Reeves
52b836d456
Merge pull request #3498 from Security-Onion-Solutions/fix/so-rule-apply
...
Fix so-rule apply - manually tested
2021-03-17 11:28:16 -04:00
William Wernert
8aac9d6bea
Reorder states in sync_files.sls
2021-03-17 10:46:17 -04:00
William Wernert
99a37a56a9
[fix] Change the commands so-rule uses to apply changes
2021-03-17 10:36:43 -04:00
m0duspwnens
f63cc10602
https://github.com/Security-Onion-Solutions/securityonion/issues/3493
2021-03-17 10:26:52 -04:00
William Wernert
c0163108ab
Merge branch 'dev' into foxtrot
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-03-17 10:23:51 -04:00
m0duspwnens
aa14dda155
https://github.com/Security-Onion-Solutions/securityonion/issues/3493
2021-03-17 10:20:20 -04:00
Mike Reeves
fbdb627ab7
Merge pull request #3488 from Security-Onion-Solutions/issue/3288
...
insert instead of append
2021-03-17 09:17:20 -04:00
m0duspwnens
68ce7a902d
insert instead of append
2021-03-17 09:14:19 -04:00
Doug Burks
2ba130b44c
Merge pull request #3487 from Security-Onion-Solutions/issue/3486
...
FEATURE: soup should provide some initial information and then prompt…
2021-03-17 09:02:29 -04:00
Doug Burks
d32c1de411
FEATURE: soup should provide some initial information and then prompt the user to continue #3486
2021-03-17 09:00:46 -04:00
Josh Brower
d21abd9693
Merge pull request #3482 from Security-Onion-Solutions/feature/revert-livequery-hunt
...
Temp revert Fleet Live Query to Hunt
2021-03-17 08:29:28 -04:00
Josh Brower
bba9913be1
Temp revert Fleet Live Query to Hunt
2021-03-17 08:25:25 -04:00
Jason Ertel
1b6f681ae1
Merge pull request #3477 from Security-Onion-Solutions/esheap
...
Esheap
2021-03-17 08:14:13 -04:00
Mike Reeves
137e1a699d
Fix the math
2021-03-16 19:01:10 -04:00
Mike Reeves
2f3488b134
Merge pull request #3476 from Security-Onion-Solutions/issue/3288
...
Issue/3288
2021-03-16 18:56:07 -04:00
Mike Reeves
7719a26a96
Change ES Heap calculation
2021-03-16 18:53:41 -04:00
m0duspwnens
53c3b19a08
Merge remote-tracking branch 'remotes/origin/dev' into issue/3288
2021-03-16 16:46:32 -04:00
Doug Burks
065f1c2927
Merge pull request #3473 from Security-Onion-Solutions/fix/shorten-elastic-license-url
...
Shorten Elastic License URL to avoid line wrap
2021-03-16 16:43:38 -04:00
Doug Burks
388524ec4e
Shorten Elastic License URL to avoid line wrap
2021-03-16 16:39:14 -04:00
m0duspwnens
38a497932c
https://github.com/Security-Onion-Solutions/securityonion/issues/3288
2021-03-16 16:36:35 -04:00
weslambert
8d29f757b1
Merge pull request #3471 from Security-Onion-Solutions/kilo
...
Reverse Zeek index close/delete count for Curator
2021-03-16 14:34:46 -04:00
Josh Brower
b56434aea1
Merge pull request #3470 from Security-Onion-Solutions/feature/disable-features-ui
...
Feature/disable certain features in Kibana UI
2021-03-16 14:00:21 -04:00
Josh Brower
abd4f92088
Cleanup curl output
2021-03-16 13:53:28 -04:00
Josh Brower
c855e0a55a
Disable certain Features within the default space
2021-03-16 13:48:13 -04:00
Wes Lambert
7a02150389
Reverse Zeek index close/delete count for Curator
2021-03-16 17:16:55 +00:00
weslambert
5fd483a99d
Merge pull request #3466 from Security-Onion-Solutions/soup2340
...
Soup for 2.3.40
2021-03-16 13:03:33 -04:00
Mike Reeves
d92c1c11aa
Merge pull request #3463 from Security-Onion-Solutions/kilo
...
Ignore TIME_WAIT when checking for Strelka frontend port reservation
2021-03-16 12:59:16 -04:00
Mike Reeves
71c6bb71c1
Merge remote-tracking branch 'remotes/origin/dev' into soup2340
2021-03-16 12:56:24 -04:00
Mike Reeves
e528d84ebe
Update Elastic License Text
2021-03-16 12:56:06 -04:00
William Wernert
129db23062
Move interface message to later in setup
2021-03-16 12:34:44 -04:00
William Wernert
1e7aaf9ffb
Collect manager info before showing message about copying ssh key
2021-03-16 12:32:37 -04:00
Mike Reeves
2851840e76
Fix Logging
2021-03-16 12:18:01 -04:00
Josh Brower
7b748128ea
Merge pull request #3462 from Security-Onion-Solutions/delta
...
Fixes IP & Port mappings
2021-03-16 12:05:23 -04:00
Josh Brower
4d6cac4a2a
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-03-16 11:57:17 -04:00
William Wernert
c8bbe078a6
Use more lines on proxy error message
2021-03-16 11:42:15 -04:00
William Wernert
6a48d7f478
Print curl error to populate variable
2021-03-16 11:34:36 -04:00
Wes Lambert
038c58f3d5
Ignore TIME_WAIT when checking for Strelka frontend port reservation
2021-03-16 14:51:16 +00:00
William Wernert
59c62393b5
Change back to validating proxy, show user error message from curl
2021-03-16 10:18:02 -04:00
Mike Reeves
00025e5c74
Fix Syntax Error
2021-03-16 09:34:53 -04:00
Josh Brower
71ae5b60ea
Update Sigmac mappings and config for IPs and ports
2021-03-16 09:32:40 -04:00
Josh Brower
44c75122ed
Update Sigmac mappings and config for IPs and ports
2021-03-16 09:05:35 -04:00
Mike Reeves
8d23518f90
Update Elastic Link
2021-03-15 17:50:06 -04:00
Mike Reeves
9a4c4448f3
Fix whiptail display
2021-03-15 17:45:44 -04:00
Mike Reeves
12501e0079
Add check license to its own logic
2021-03-15 17:41:45 -04:00
Mike Reeves
72759de97f
Fix so-common syntax
2021-03-15 17:37:44 -04:00
Mike Reeves
67e0d450e4
Add Elastic License Prompts
2021-03-15 17:32:36 -04:00
Mike Reeves
05ec7dba21
Merge pull request #3452 from Security-Onion-Solutions/Telegraf-Fix
...
Turn off SSL Verification in Telegraf
2021-03-15 16:47:27 -04:00
Mike Reeves
674bb342ea
Turn off SSL Verification in Telegraf
2021-03-15 16:39:43 -04:00
Josh Brower
5fe025318b
Update Sigmac mappings and config for IPs and ports
2021-03-15 15:53:00 -04:00
William Wernert
086f2b3437
Change when prereq packages are installed to follow new order
2021-03-15 14:59:24 -04:00
Mike Reeves
c93aab7a85
Merge pull request #3448 from Security-Onion-Solutions/kilo
...
Allow for moving Strelka files to processed directory after scanning
2021-03-15 14:51:04 -04:00
William Wernert
efc0463201
Change when proxy + variables are set so strings are built correctly
2021-03-15 14:45:23 -04:00
William Wernert
55aee69a74
Merge branch 'dev' into foxtrot
2021-03-15 12:34:24 -04:00
William Wernert
6ae3a26cbe
Revert all proxy changes on reinstall
2021-03-15 12:34:13 -04:00
Wes Lambert
f142b754dc
Add Strelka files.processed directory so files will be moved from staging to processed
2021-03-15 15:43:31 +00:00
Wes Lambert
b6a785395d
Add Strelka staging directory for state
2021-03-15 15:42:13 +00:00
Mike Reeves
ab75d0e563
soup for 2.3.40
2021-03-15 10:51:31 -04:00
Mike Reeves
79c7af9a31
soup for 2.3.40
2021-03-15 10:48:24 -04:00
Masaya-A
236373cda2
Merge pull request #2 from Security-Onion-Solutions/dev
...
Dev Sync
2021-03-14 20:27:50 +09:00
Mike Reeves
d931e57fd8
Merge pull request #3428 from Security-Onion-Solutions/kilo
2021-03-12 17:03:48 -05:00
Doug Burks
cfdf9703ab
Merge pull request #3427 from Security-Onion-Solutions/issue/3340
...
FEATURE: soup should output more guidance for distributed deployments at the end #3340
2021-03-12 15:27:26 -05:00
Doug Burks
da7adab566
FEATURE: soup should output more guidance for distributed deployments at the end #3340
2021-03-12 12:59:17 -05:00
William Wernert
f80dfda60b
Only run initial installer progress to 98 to avoid sitting at 100
2021-03-12 11:39:44 -05:00
William Wernert
302d6e03be
Merge branch 'dev' into foxtrot
2021-03-12 11:36:26 -05:00
Mike Reeves
4ac408ad38
Merge pull request #3423 from Security-Onion-Solutions/issue/3422
...
FIX: Improve Setup verbiage #3422
2021-03-12 11:04:25 -05:00
doug
edb88ac09a
FIX: Improve Setup verbiage #3422
2021-03-12 10:54:44 -05:00
Jason Ertel
747f387936
Replace salt's http.wait_for_successful_query with so-common's wait_for_web_response due to issues with salt
2021-03-12 10:42:18 -05:00
Jason Ertel
8cddfeb47d
Provide pillar for each client param
2021-03-12 07:42:10 -05:00
Doug Burks
555f9b5091
Merge pull request #3417 from Security-Onion-Solutions/issue/3413
...
FIX: SMTP shoud read SNMP on Kibana SNMP view #3413
2021-03-12 06:52:21 -05:00
doug
a5779a520c
FIX: SMTP shoud read SNMP on Kibana SNMP view #3413
2021-03-12 06:48:57 -05:00
Jason Ertel
a7ea0808c3
Merge pull request #3399 from Security-Onion-Solutions/kilo
...
feature: Show job owner/submitter. Resolves #2775
2021-03-12 06:45:34 -05:00
Jason Ertel
462f76e2bb
Remove client params block in favor in individual settings that will go into the pillar
2021-03-12 06:38:53 -05:00
Jason Ertel
b5cf9ae820
Merge branch 'dev' into kilo
2021-03-11 18:01:17 -05:00
Jason Ertel
80987dfd1d
Support overrides of client params
2021-03-11 18:01:04 -05:00
William Wernert
6842204981
Ask for hostname earlier in setup
2021-03-11 16:55:06 -05:00
Doug Burks
ab1c84afca
Merge pull request #3409 from Security-Onion-Solutions/issue/3408
...
FIX: Populate http.status_message field #3408
2021-03-11 16:45:53 -05:00
doug
adbc7436b6
FIX: Populate http.status_message field #3408
2021-03-11 16:42:20 -05:00
William Wernert
6d431c0bda
Add more info to comment
2021-03-11 16:36:56 -05:00
William Wernert
b14b9e8e17
[fix] Fix dependency install progress bar
2021-03-11 16:34:54 -05:00
William Wernert
b35e65190e
[fix] Fix dependency install progress bar
2021-03-11 16:30:14 -05:00
William Wernert
8e8bb1489b
Redirect output of kill command
2021-03-11 16:13:52 -05:00
William Wernert
e2fc1b0b39
Redirect output of kill command
2021-03-11 16:06:49 -05:00
William Wernert
3306ffa792
Only collect proxy once, include manager in no_proxy value on minions
2021-03-11 16:03:43 -05:00
William Wernert
a86b2ab653
[fix] Remove additional collect_proxy call
2021-03-11 15:54:46 -05:00
William Wernert
5612fc10d4
[feat] Remove setup dependency on bc
2021-03-11 15:53:04 -05:00
Jason Ertel
286351f424
Merge branch 'dev' into kilo
2021-03-11 15:32:38 -05:00
Jason Ertel
908720592a
Upgrade saved objects to 7.11.2
2021-03-11 15:32:22 -05:00
William Wernert
66da3e380f
[fix] Set percentage value when needed
2021-03-11 15:25:38 -05:00
William Wernert
e60bc87ffa
Install setup required packages later so that also uses the proxy
2021-03-11 15:20:39 -05:00
William Wernert
0d01f63e3b
[fix] Confirm proxy password
2021-03-11 11:46:46 -05:00
Jason Ertel
79dd0d1809
Fix indentation
2021-03-11 11:13:14 -05:00
Mike Reeves
cdd95986a8
Merge pull request #3398 from Security-Onion-Solutions/issue/3397
...
FIX: Improve Suricata DHCP logging and parsing #3397
2021-03-11 11:07:53 -05:00
doug
b4ad7e7359
FIX: Improve Suricata DHCP logging and parsing #3397
2021-03-11 11:01:51 -05:00
William Wernert
0434ffac38
Merge branch 'dev' into foxtrot
2021-03-11 10:52:36 -05:00
William Wernert
506162bfcc
Use auth for automated proxy test
2021-03-11 10:52:17 -05:00
Doug Burks
adb25d63d2
Merge pull request #3396 from Security-Onion-Solutions/issue/3295
...
FIX: Improve DHCP leases query in Hunt #3395
2021-03-11 08:22:48 -05:00
Doug Burks
85aaa71006
FIX: Improve DHCP leases query in Hunt #3395
2021-03-11 08:01:27 -05:00
William Wernert
750de6333d
[fix] Remove last bad usage of cortexkey
2021-03-10 16:24:21 -05:00
William Wernert
9ffbb9d37e
[fix] Use update so-cortex-user-enable with correct pillar
...
Fixes #3388
2021-03-10 16:17:10 -05:00
William Wernert
157badf448
[fix] Use correct pillar value for api key
...
Fixes #3388
2021-03-10 16:12:59 -05:00
Jason Ertel
eefa6bb949
feature: Show job owner/submitter. Resolves #2775
2021-03-10 14:44:21 -05:00
William Wernert
19ccd0c9a2
Merge branch 'dev' into foxtrot
2021-03-10 09:33:42 -05:00
Mike Reeves
6bbcc7a5e9
Merge pull request #3382 from Security-Onion-Solutions/kilo
...
Ensure MTU is defined for advanced sensor automation
2021-03-10 09:27:20 -05:00
Jason Ertel
3eb4a37c76
Expose zeek and suri pins for automation
2021-03-10 09:26:46 -05:00
Jason Ertel
180bba782e
Expose zeek and suri pins for automation
2021-03-10 09:26:11 -05:00
Jason Ertel
b1531cc75e
Merge pull request #3384 from Security-Onion-Solutions/Eval/Import-Fix
...
Update cert location for eval.import
2021-03-10 09:15:53 -05:00
Mike Reeves
18203513ab
Update cert location for eval.import
2021-03-10 09:14:14 -05:00
Jason Ertel
46af6a5c84
Ensure MTU is defined for advanced sensor automation
2021-03-10 08:14:25 -05:00
Mike Reeves
2e74cb6abf
Merge pull request #3377 from Security-Onion-Solutions/kilo
2021-03-09 21:40:43 -05:00
Jason Ertel
a496b03de7
Add missing MTU var for automation of advanced sensor
2021-03-09 20:52:34 -05:00
William Wernert
60f40163aa
Merge branch 'dev' into foxtrot
2021-03-09 13:51:13 -05:00
Jason Ertel
46288802d1
Merge pull request #3368 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update 9101_output_osquery_livequery.conf.jinja
2021-03-09 13:16:17 -05:00
Mike Reeves
2e01330e1b
Update 9101_output_osquery_livequery.conf.jinja
2021-03-09 13:15:04 -05:00
William Wernert
f0e089b6bf
Merge branch 'dev' into foxtrot
2021-03-09 10:11:04 -05:00
Mike Reeves
734d25b1ac
Merge pull request #3361 from Security-Onion-Solutions/nomorefeatures
...
Make saved objects less hacky
2021-03-09 10:05:23 -05:00
Mike Reeves
49258a13a3
Make saved objects less hacky
2021-03-09 10:03:29 -05:00
Josh Brower
00da549430
Merge pull request #3358 from Security-Onion-Solutions/delta
...
FEATURE: Initial support for viewing Osquery Live Query results in Hunt
2021-03-09 09:18:57 -05:00
Jason Ertel
b1777ff10f
Merge pull request #3357 from Security-Onion-Solutions/nomorefeatures
...
SSL with Elastic Security
2021-03-08 21:22:30 -05:00
Mike Reeves
3967e581cf
Merge pull request #3356 from Security-Onion-Solutions/kilo
...
fix: Sensors can temporarily show offline while processing large PCAP…
2021-03-08 19:14:54 -05:00
William Wernert
ba71b2fbc8
Change proxy Jinja logic (none and empty string are falsy)
2021-03-08 17:36:34 -05:00
Mike Reeves
1ecb079066
Fix Kibana Script for loading dashboards
2021-03-08 17:36:07 -05:00
William Wernert
f85f86ccdd
[fix] Check for empty proxy string everywhere
2021-03-08 17:25:23 -05:00
William Wernert
8c4e66f7bb
[fix] Print error to stderr
2021-03-08 15:52:21 -05:00
William Wernert
5ee6856a07
Strip the last substring following a hyphen for automated branches
...
Also don't show the user a stack trace on invalid version strings, just alert on the bad string and exit
2021-03-08 15:43:54 -05:00
William Wernert
ed4f8025be
[fix] Also check for proxy to be empty string
2021-03-08 13:57:24 -05:00
Josh Brower
fe8788c09a
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-03-08 12:56:47 -05:00
William Wernert
5c7d3656dd
[fix] Don't try to create so_proxy during automated installs, just set it
2021-03-08 12:26:17 -05:00
Jason Ertel
84c152e233
fix: Sensors can temporarily show offline while processing large PCAP jobs. Resolves #3279 .
2021-03-08 12:05:44 -05:00
Mike Reeves
bf4ac2a312
Fix some merge conflicts
2021-03-08 11:43:24 -05:00
William Wernert
368b04b24e
Add back accidentally removed code
2021-03-08 09:04:17 -05:00
William Wernert
ca2766511b
Revert "[wip] Change when proxy is set up so main ip is known"
...
This reverts commit 1ea3cb1c61 .
# Conflicts:
# setup/so-functions
2021-03-08 09:02:53 -05:00
William Wernert
06c584910c
Merge branch 'dev' into foxtrot
2021-03-08 08:58:31 -05:00
Josh Brower
19b3c7bb07
Merge pull request #3339 from Security-Onion-Solutions/feature/live_query-hunt
...
Feature/live query hunt
2021-03-08 08:31:25 -05:00
William Wernert
49db2a016a
Merge pull request #3341 from Security-Onion-Solutions/kilo
...
Kilo
2021-03-08 08:17:29 -05:00
Jason Ertel
94610307b3
Merge branch 'dev' into kilo
2021-03-08 07:56:48 -05:00
William Wernert
35ae9363f5
[fix] Log gateway error, and don't show whiptail msg on automated installs
2021-03-05 20:15:37 -05:00
William Wernert
9c49cef2de
Merge branch 'feature/docker-prune-rework' into foxtrot
2021-03-05 14:18:57 -05:00
William Wernert
f537b3c7f7
Merge branch 'feature/setup-ssh-harden' into foxtrot
2021-03-05 14:18:35 -05:00
William Wernert
e5110dc3fc
[fix] None -> none
2021-03-05 14:08:03 -05:00
William Wernert
50fcdb65a6
[fix] Modify the proxy automated test
...
* It makes more sense to test the proxy using a network install, not via the iso
2021-03-05 13:53:48 -05:00
William Wernert
32e7afdc5f
Merge branch 'feature/setup' into foxtrot
2021-03-05 12:53:31 -05:00
William Wernert
245902326f
[wip] Add automation support for proxy settings
2021-03-05 12:53:20 -05:00
Jason Ertel
7234353476
Merge pull request #3319 from Security-Onion-Solutions/foxtrot
...
fix: syntax error in reserved ports configuration #3308
2021-03-05 12:51:50 -05:00
William Wernert
ec04145d15
[fix] Set proxy for idstools container manually
2021-03-05 11:34:31 -05:00
Jason Ertel
61a7efeeab
fix: syntax error in reserved ports configuration; ensure ports are reserved prior to setup
2021-03-05 10:54:01 -05:00
Josh Brower
548f67ca6f
Initial support for Live Queries in Hunt
2021-03-04 18:21:13 -05:00
William Wernert
33b2bd33fe
[fix] Also create config.json so containers use proxy
2021-03-04 17:12:10 -05:00
William Wernert
e0d0baafcc
[fix] Permanently set proxy for yum using template
2021-03-04 16:40:32 -05:00
William Wernert
b3c7760ad4
[fix] Use correct variable in so-proxy.sh
2021-03-04 14:08:21 -05:00
Mike Reeves
39d4f077b4
Merge pull request #3290 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-03-04 13:44:00 -05:00
William Wernert
a435ea77e8
[fix] Also add hostname to no_proxy list
2021-03-04 12:43:42 -05:00
William Wernert
2ee8c7ad1c
[fix] Always pass $proxy_addr since we retry the surrounding function
2021-03-04 12:16:23 -05:00
William Wernert
ac0a4f4a13
Merge branch 'dev' into feature/setup
2021-03-04 12:11:17 -05:00
William Wernert
b265854644
[wip] Move proxy config to separate file
2021-03-04 12:10:42 -05:00
William Wernert
4339ded17f
[wip][fix] Don't add logic to so-setup, create wrapper function in so-functions
2021-03-04 12:10:14 -05:00
William Wernert
d19ca943cc
[fix][wip] Only setup proxy early on configure network setup
2021-03-04 11:57:16 -05:00
William Wernert
2e56252f54
[wip] Syntax fixes
2021-03-04 11:54:21 -05:00
William Wernert
13dc822197
[wip] Ask user if they want to re-enter the proxy
2021-03-04 11:53:08 -05:00
William Wernert
5a97341d33
[wip] Fix how collect_proxy function works on retry
2021-03-04 11:41:36 -05:00
William Wernert
7ee0fd6375
[wip] Specify setup log location to user when directing them to it
2021-03-04 11:31:22 -05:00
Mike Reeves
05c7bd5789
Merge pull request #3285 from Security-Onion-Solutions/elastic
...
Elastic
2021-03-04 10:57:06 -05:00
Mike Reeves
c2b347e4bb
Security Enable for only nodes and heavy
2021-03-04 10:52:01 -05:00
Mike Reeves
a0a8d12526
Enable SSL and Features
2021-03-04 10:08:28 -05:00
Mike Reeves
8c474cc7df
Merge pull request #3268 from Security-Onion-Solutions/issue/3254
...
FIX: Custom Kibana settings are not being applied properly on upgrades #3254
2021-03-04 08:39:50 -05:00
William Wernert
3d5cf128ae
[wip] Test proxy before using it
2021-03-03 15:02:21 -05:00
Mike Reeves
49371a1d6a
fix elastic output for ssl
2021-03-03 14:30:45 -05:00
William Wernert
1ea3cb1c61
[wip] Change when proxy is set up so main ip is known
...
* Also only restart docker if the command exists (i.e. docker is installed)
2021-03-03 14:20:26 -05:00
Mike Reeves
bf4249d28b
fix elastalert verification
2021-03-03 14:16:10 -05:00
William Wernert
4ffa0fbc13
[wip] Fix proxy validation
2021-03-03 14:09:59 -05:00
Mike Reeves
e0538417f1
fix http.wait
2021-03-03 14:06:35 -05:00
doug
d39b3280c8
FIX: Custom Kibana settings are not being applied properly on upgrades #3254
2021-03-03 14:04:32 -05:00
Mike Reeves
6c7111cd0a
turn off verification mode for ES
2021-03-03 13:42:04 -05:00
Mike Reeves
4de62c878c
turn on elastic security
2021-03-03 12:51:29 -05:00
William Wernert
e951e9d9c5
[wip] Further proxy changes
...
* Remove unused docker.conf template
* Rename proxy variable to avoid name collision
* Reword address prompt to specify users should not include user:pass in their input
* Actually call the collect_proxy function
2021-03-03 12:19:14 -05:00
William Wernert
26b1da744c
[wip] Reword proxy yesno prompt
2021-03-03 12:01:15 -05:00
William Wernert
83791d87c7
[wip][fix] Use passwordbox for proxy password
2021-03-03 11:58:45 -05:00
William Wernert
279a5b60b8
Soup indent fixes
2021-03-03 11:58:10 -05:00
Mike Reeves
4f34eca5b9
remove unused script
2021-03-03 10:32:23 -05:00
Mike Reeves
07b5cc3d1d
Fix https for rw indicies script
2021-03-03 10:29:41 -05:00
Mike Reeves
d7451dcd75
Merge remote-tracking branch 'origin/foxtrot' into nomorefeatures
2021-03-03 10:04:38 -05:00
Mike Reeves
4f867e5375
Fix all scripts for ssl elastic
2021-03-03 10:02:23 -05:00
William Wernert
82018a206c
[wip] Don't validate user+pass for proxy, use new variable
2021-03-03 09:56:14 -05:00
William Wernert
2b94fa366e
[wip] Add auth inputs for proxy settings, fix some broken logic
2021-03-03 09:51:38 -05:00
William Wernert
de77d3ebc9
[wip] Initial work for setting up proxy on manager
2021-03-02 17:41:49 -05:00
William Wernert
4df53b3c70
Unify log_size_limit variable value in so-curator-closed-delete-delete
2021-03-02 17:38:17 -05:00
William Wernert
497938460a
[fix] manager:log_size_limit is no longer used, remove generation
2021-03-02 16:47:49 -05:00
Mike Reeves
e0d9212e55
Make https default for all things
2021-03-02 14:01:05 -05:00
Mike Reeves
80574d3c20
Make https default for all things
2021-03-02 13:59:43 -05:00
Mike Reeves
bfd05a8cfc
Change to https for elastic connections
2021-03-02 11:32:29 -05:00
Mike Reeves
3219f4cd12
Remove Features Option
2021-03-02 11:04:50 -05:00
William Wernert
a18dd869c4
Merge branch 'dev' into feature/setup
2021-03-02 10:23:33 -05:00
William Wernert
61611b8de2
Fix Elasticsearch disk space prompt
...
Resolves #3205
2021-03-02 10:23:04 -05:00
William Wernert
0db9991307
Reword/remove some comments
2021-03-02 10:20:33 -05:00
Jason Ertel
4014dbbc3d
Revert "Move version to 2.3.31"
...
This reverts commit cf21200a36 .
2021-03-02 10:14:45 -05:00
William Wernert
35f5c7fb4b
Merge branch 'dev' into feature/docker-prune-rework
2021-03-02 09:48:41 -05:00
Jason Ertel
cf21200a36
Move version to 2.3.31
2021-03-02 09:11:49 -05:00
Mike Reeves
bff446543a
Merge pull request #3215 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-03-01 15:58:41 -05:00
Jason Ertel
53a45e1c97
Merge branch 'dev' into foxtrot
2021-03-01 15:54:41 -05:00
Jason Ertel
b37d5ae15f
Enable advanced setup for some search/sensor installs
2021-03-01 15:54:29 -05:00
Mike Reeves
85204dbb14
Merge pull request #3210 from Security-Onion-Solutions/dev2340
...
Update VERSION
2021-03-01 15:28:45 -05:00
Mike Reeves
2c75cb74db
Update VERSION
2021-03-01 15:17:38 -05:00
Mike Reeves
d99acdb72c
Merge pull request #3209 from Security-Onion-Solutions/dev
...
2.3.30
2021-03-01 15:09:29 -05:00
Mike Reeves
0d70d2e6f8
Merge pull request #3208 from Security-Onion-Solutions/sigs
...
Update Signatures
2021-03-01 14:48:04 -05:00
Mike Reeves
64b37cedc7
Update Signatures
2021-03-01 14:45:51 -05:00
Mike Reeves
852f588512
Merge pull request #3207 from Security-Onion-Solutions/telegraf_suri_meta
...
Telegraf suri meta
2021-03-01 13:59:36 -05:00
m0duspwnens
a197d5addf
revert version to 2.3.30 https://github.com/Security-Onion-Solutions/securityonion/issues/3206
2021-03-01 13:58:04 -05:00
m0duspwnens
3983e08fe5
exclude zeekcaptureloss when suricata metadata selected https://github.com/Security-Onion-Solutions/securityonion/issues/3206
2021-03-01 13:31:05 -05:00
Mike Reeves
8f8651c52c
Merge pull request #3204 from Security-Onion-Solutions/foxtrot
...
Update VERSION file to 2.3.40
2021-03-01 12:18:50 -05:00
Jason Ertel
85e059a766
Update VERSION file to 2.3.40
2021-03-01 12:16:46 -05:00
Mike Reeves
2df871adcd
Merge pull request #3199 from Security-Onion-Solutions/dev
...
2.3.30 Release
2021-03-01 12:11:19 -05:00
William Wernert
3e1a31c0b0
Merge pull request #3201 from Security-Onion-Solutions/sigs
...
Release 2.3.30 sig
2021-03-01 10:49:55 -05:00
Mike Reeves
4e9bfbefda
Merge pull request #3200 from Security-Onion-Solutions/release-merge-fix
...
Release merge fix
2021-03-01 10:49:41 -05:00
Mike Reeves
1a1e3caec8
Release 2.3.30 sig
2021-03-01 10:48:22 -05:00
William Wernert
be7dcdb442
Merge branch 'master' into release-merge-fix
...
# Conflicts:
# README.md
# VERIFY_ISO.md
# VERSION
# salt/docker_clean/init.sls
# salt/soc/files/soc/changes.json
2021-03-01 10:45:51 -05:00
Mike Reeves
8a9c7fa279
Merge pull request #3198 from Security-Onion-Solutions/sigs
...
Add Signature Files
2021-03-01 10:42:15 -05:00
Mike Reeves
bfa7c85e27
Release 2.3.30
2021-03-01 10:40:41 -05:00
Mike Reeves
ed2c836250
Merge pull request #3196 from Security-Onion-Solutions/foxtrot
...
Update changes for 2.3.30
2021-03-01 10:00:12 -05:00
Jason Ertel
1ae46b82ec
Update changes for 2.3.30
2021-03-01 09:58:39 -05:00
Mike Reeves
6e8777b9d6
Merge pull request #3193 from Security-Onion-Solutions/bugfix/revert-default-route-msg
...
Revert "[refactor] Make default route message a warning"
2021-03-01 09:49:58 -05:00
William Wernert
def3637bf6
Revert "[refactor] Make default route message a warning"
...
This reverts commit be1f641bf0 .
2021-03-01 09:46:28 -05:00
William Wernert
1834e07aad
Merge branch 'dev' into feature/docker-prune-rework
2021-03-01 09:37:47 -05:00
Mike Reeves
64cc894948
Merge pull request #3192 from Security-Onion-Solutions/bugfix/input-validation-fixes
...
Bugfix/input validation fixes
2021-03-01 09:27:48 -05:00
Mike Reeves
55b6efba7b
Merge pull request #3189 from Security-Onion-Solutions/bugfix/mtu-input
...
Add max to MTU input validation to encompass default + jumbo frames
2021-03-01 09:26:54 -05:00
William Wernert
cf9be3521d
[fix] Don't validate LS/ES heap sizes
...
* Also remove comments + fix indent
2021-03-01 09:17:36 -05:00
William Wernert
6113bcc261
[fix] Increase max integer value
2021-03-01 09:16:51 -05:00
William Wernert
810ffbdaf5
Add max to MTU input validation to encompass default + jumbo frames
2021-03-01 08:41:19 -05:00
Mike Reeves
c1a8e1971b
Merge pull request #3174 from Security-Onion-Solutions/foxtrot
2021-02-27 09:49:46 -05:00
Jason Ertel
7451aa990b
Improve formatting of changes list
2021-02-27 08:14:44 -05:00
Jason Ertel
839ab30b2c
Merge pull request #3171 from Security-Onion-Solutions/foxtrot
...
Add changes.json for 2.3.30
2021-02-26 18:16:20 -05:00
Jason Ertel
9631327c71
Add changes.json for 2.3.30
2021-02-26 18:11:13 -05:00
William Wernert
33696398eb
Add new so-docker-prune script
...
* Script will pull list of so- images and prune any older than most recent + last version
2021-02-26 18:06:07 -05:00
Josh Patterson
b6fe8dec3b
Merge pull request #3170 from Security-Onion-Solutions/bugfix/setup-configure-network
...
Fix logic for configure network option in setup
2021-02-26 15:43:38 -05:00
William Wernert
fd877a2256
Fix logic for configure network option in setup
2021-02-26 15:40:20 -05:00
Mike Reeves
26a22b8e3b
Merge pull request #3169 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-02-26 14:37:09 -05:00
Jason Ertel
cc15e9a0b1
Merge branch 'dev' into foxtrot
2021-02-26 14:26:48 -05:00
Jason Ertel
4a03862fc4
Add suricata distributed automations
2021-02-26 14:26:28 -05:00
William Wernert
069f6eccbf
Merge pull request #3157 from Security-Onion-Solutions/feature/default-route-warn
...
[refactor] Make default route message a warning
2021-02-26 10:29:43 -05:00
William Wernert
be1f641bf0
[refactor] Make default route message a warning
...
Don't force users to exit setup if the default route and management NIC's IP don't match,
just warn them
2021-02-26 10:27:14 -05:00
William Wernert
8910b5c3a7
Merge pull request #3155 from Security-Onion-Solutions/bugfix/fleet-hostname-input
...
[fix] Change logic for collecting fleet custom hostname
2021-02-26 09:16:22 -05:00
William Wernert
333a7e6173
[fix] Change logic for collecting fleet custom hostname
2021-02-26 09:14:30 -05:00
Josh Patterson
b893a2b887
Merge pull request #3154 from Security-Onion-Solutions/salt-3002.5
...
upgrade to Salt 3002.5
2021-02-26 08:57:23 -05:00
m0duspwnens
b4c1c56e72
Merge remote-tracking branch 'remotes/origin/dev' into salt-3002.5
2021-02-26 08:38:02 -05:00
Josh Brower
45f626887d
Merge pull request #3153 from Security-Onion-Solutions/bugfix/so-playbook-sigmarefresh
...
Fix so-playbook-sigma-refresh
2021-02-26 08:36:36 -05:00
Josh Brower
5678e66b39
Fix so-playbook-sigma-refresh
2021-02-26 08:33:24 -05:00
Josh Brower
b8137214e4
Initial Support - Live Query to Hunt
2021-02-26 08:08:09 -05:00
Josh Patterson
dc673eef77
Merge pull request #3148 from Security-Onion-Solutions/salt-3002.5
...
Salt 3002.5
2021-02-25 23:00:35 -05:00
m0duspwnens
9fa625189f
upgrade to salt 3002.5 https://github.com/Security-Onion-Solutions/securityonion/issues/3147
2021-02-25 20:07:29 -05:00
Mike Reeves
e06ca75677
Merge pull request #3144 from Security-Onion-Solutions/interfaces
...
Don't disable NICs
2021-02-25 17:28:47 -05:00
Mike Reeves
a47a3d51c9
Merge pull request #3139 from Security-Onion-Solutions/feature/soup-log_size_limit
...
Show log_size_limit message at end of soup instead of during
2021-02-25 17:10:38 -05:00
William Wernert
b024dae72e
[fix] Don't call set_main_ip a second time
2021-02-25 15:19:28 -05:00
Josh Patterson
8a0e0e88e0
Merge pull request #3142 from Security-Onion-Solutions/issue/3130
...
stop zeek state.db from getting owned by root
2021-02-25 15:01:20 -05:00
Mike Reeves
2c8bc16c8f
Remove some nmcli business
2021-02-25 13:43:02 -05:00
Mike Reeves
37c13362df
Netowrk Manager needs to chill
2021-02-25 13:20:29 -05:00
Mike Reeves
51e8839daf
Inverse NIC offload
2021-02-25 11:46:00 -05:00
Josh Patterson
18365ed87d
Merge pull request #3140 from Security-Onion-Solutions/issue/3130
...
Issue/3130
2021-02-25 11:27:46 -05:00
m0duspwnens
fcd3f81400
fix quotes
2021-02-25 11:16:53 -05:00
m0duspwnens
c8213fa3d4
change docker exec
2021-02-25 11:07:54 -05:00
m0duspwnens
add66e750e
forgot to add -c
2021-02-25 10:49:09 -05:00
William Wernert
6a097beaff
Show log_size_limit message at end of soup instead of during
2021-02-25 10:47:29 -05:00
Doug Burks
79fefd83ef
Merge pull request #3134 from Security-Onion-Solutions/issue/3128
...
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 07:11:20 -08:00
m0duspwnens
d52abcbcbd
ensure zeekctl is run as user zeek https://github.com/Security-Onion-Solutions/securityonion/issues/3130
2021-02-25 09:58:07 -05:00
Doug Burks
c18c865764
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 09:23:19 -05:00
Doug Burks
ef1e296415
Improve Hunt queries for ssh and tunnel #3128
2021-02-25 08:52:34 -05:00
Mike Reeves
ae89260793
Merge pull request #3127 from Security-Onion-Solutions/foxtrot
...
Add automation files for Suricata metadata
2021-02-25 08:26:20 -05:00
Jason Ertel
34dab9009c
Ensure Zeek spool dir is owned by Zeek to allow Zeek to start correctly
2021-02-25 08:10:13 -05:00
Jason Ertel
ef7cdf27bf
Add automation files for Suricata metadata
2021-02-25 07:43:11 -05:00
Mike Reeves
c39b516f38
Merge pull request #3121 from Security-Onion-Solutions/strelkainstall
...
Fix Strelka Rule updates, repo fix
2021-02-24 17:13:41 -05:00
Mike Reeves
39860ea6bd
Merge pull request #3123 from Security-Onion-Solutions/kilo
...
Add function to soup to notify user of log_size_limit issues
2021-02-24 17:09:07 -05:00
Mike Reeves
701cfe7e9a
Merge branch 'dev' into strelkainstall
2021-02-24 17:07:26 -05:00
William Wernert
4ae34f928c
Merge branch 'dev' into kilo
...
# Conflicts:
# setup/so-functions
2021-02-24 17:05:53 -05:00
Mike Reeves
ff577cdf41
Merge pull request #3079 from petiepooo/feature/eslogsize
...
calculate log_size_limit based on /nsm/elasticsearch
2021-02-24 17:03:35 -05:00
William Wernert
4a6ad7c87e
Set MAINIP to MNIC_IP when using a VPN
2021-02-24 16:31:45 -05:00
Mike Reeves
b30f964974
Moving the wildcard
2021-02-24 16:09:37 -05:00
Mike Reeves
262bf03595
Testing capitals
2021-02-24 16:04:53 -05:00
Mike Reeves
ae17a3aeb8
Fix Syntax try 3
2021-02-24 16:02:36 -05:00
Mike Reeves
ab66f175c5
Fix Syntax
2021-02-24 16:01:18 -05:00
Mike Reeves
8f3ba7633c
Fix Syntax
2021-02-24 15:57:18 -05:00
Mike Reeves
5949119cb5
Bypass route check
2021-02-24 15:53:55 -05:00
Mike Reeves
6058400aad
Bypass route check
2021-02-24 15:52:50 -05:00
William Wernert
f042312aac
Merge branch 'dev' into kilo
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-02-24 15:42:10 -05:00
Mike Reeves
52fd3c0470
Merge pull request #3122 from Security-Onion-Solutions/strelka_repo_update
...
Modify soup to add Strelka rule repo in pillar
2021-02-24 15:35:35 -05:00
Wes Lambert
6ea8eab9af
Modify soup to add Strelka rule repo in pillar
2021-02-24 20:32:47 +00:00
William Wernert
775f274962
Also check /nsm/elasticsearch in soup log_size_limit check
...
Reflect changes from PR#3079
2021-02-24 14:36:41 -05:00
William Wernert
e500e24802
Only show log_size_limit warning on dist if heavynode pillars exist
2021-02-24 13:56:59 -05:00
William Wernert
298f7da90b
Fix indent in set_default_log_size
2021-02-24 13:56:33 -05:00
Mike Reeves
38d60752b7
Merge pull request #3110 from Security-Onion-Solutions/dockerclean
...
Docker Cleanup
2021-02-24 13:44:06 -05:00
Josh Patterson
25ca70efd8
Merge pull request #3120 from Security-Onion-Solutions/issue/3115
...
ensure log_level and log_level_logfile are set to info in /etc/salt/minion
2021-02-24 13:36:34 -05:00
Mike Reeves
bdfec5176d
Dont disable unused interfaces during setup
2021-02-24 13:22:06 -05:00
William Wernert
ece79379a5
Add file name/path to log_size_limit message
2021-02-24 12:54:14 -05:00
William Wernert
ac6f1df86f
[fix] Only check log_size_limit on .2X -> .30
...
* Since we're showing a message in the middle of soup, wait for keypress if it's shown
2021-02-24 12:35:17 -05:00
William Wernert
4507a89d95
tar arg fix (-x -> -z)
2021-02-24 12:24:54 -05:00
William Wernert
2be7ccac33
Add function to notify user that log_size_limit may be incorrect
2021-02-24 12:24:32 -05:00
Josh Patterson
81331264e7
Merge pull request #3117 from Security-Onion-Solutions/issue/3115
...
logfile is 1 word
2021-02-24 11:57:33 -05:00
m0duspwnens
eba5d271aa
logfile is 1 word https://github.com/Security-Onion-Solutions/securityonion/issues/3115
2021-02-24 11:56:43 -05:00
Josh Patterson
a9066f491d
Merge pull request #3116 from Security-Onion-Solutions/issue/3115
...
Issue/3115
2021-02-24 11:51:42 -05:00
m0duspwnens
3552abfca1
ensure info log level -
2021-02-24 11:50:08 -05:00
Mike Reeves
1d45472b48
Fix Strelka Rule updates, repo fix
2021-02-24 11:30:43 -05:00
Mike Reeves
68c683e3bf
Merge pull request #3114 from Security-Onion-Solutions/foxtrot
...
Add retry support for 'docker pull' command
2021-02-24 11:25:14 -05:00
Jason Ertel
050058a959
Add retry support for 'docker pull' command
2021-02-24 09:34:14 -05:00
Mike Reeves
09c94ddf95
Docker Cleanup
2021-02-24 08:57:25 -05:00
Mike Reeves
54367db99b
Merge pull request #3108 from Security-Onion-Solutions/issue/3056
...
add estimated EPS graphs to Grafana for manager, mastersearch and standalone nodes
2021-02-24 08:49:36 -05:00
Mike Reeves
56daae64be
Merge pull request #3097 from Security-Onion-Solutions/sometacleanup
...
Clean up on sid numbers
2021-02-24 08:24:48 -05:00
Mike Reeves
00deab9305
Merge pull request #3100 from Security-Onion-Solutions/kilo
...
Add so-preflight + usage to so-monitor-add, fix managersearch missing from so-rule
2021-02-23 17:32:41 -05:00
Mike Reeves
fa6fd20ff9
Merge pull request #3088 from Security-Onion-Solutions/soupairgap
...
Syn the latest rules on an airgap install
2021-02-23 17:31:29 -05:00
Mike Reeves
d195efa8e5
Merge pull request #3098 from Security-Onion-Solutions/feature/update-soup
...
Update SOUP with so-playbook-sigma-refresh
2021-02-23 15:46:48 -05:00
Josh Brower
a7eb3cd38d
Add so-playbook-sigma-refresh
2021-02-23 15:43:09 -05:00
Mike Reeves
5baa4cb6a5
Clean up on sid numbers
2021-02-23 15:42:58 -05:00
Josh Patterson
988ad5f8fc
Merge pull request #3086 from Security-Onion-Solutions/issue/3056
...
Issue/3056
2021-02-23 14:53:42 -05:00
William Wernert
a361ca0e19
[fix] Add managersearch node type to so-rule pillar search
2021-02-23 14:15:17 -05:00
William Wernert
9cf15cdae5
[fix] Reword so-monitor-add help message
2021-02-23 13:55:18 -05:00
William Wernert
d5477b4721
Add usage/help message to so-monitor-add
2021-02-23 13:48:54 -05:00
William Wernert
5a2fa26d72
Add ET OPEN/PRO URLs
2021-02-23 13:47:52 -05:00
William Wernert
61a23509a1
[fix] grep -q doesn't give output to parse, so remove the flag
2021-02-23 13:43:10 -05:00
William Wernert
25698dafe3
Add initial pre-flight check script
2021-02-23 13:25:54 -05:00
Mike Reeves
186710964b
Fix Airgap Rule Path
2021-02-23 13:07:23 -05:00
Mike Reeves
3b32eb539f
Copy latest rules when using airgaps
2021-02-23 11:21:23 -05:00
m0duspwnens
6ee69ff21b
Merge remote-tracking branch 'remotes/origin/dev' into issue/3056
2021-02-23 11:11:50 -05:00
m0duspwnens
00cc640224
add EPS to managersearch dashboard
2021-02-23 11:08:08 -05:00
Mike Reeves
40721d7dec
Merge pull request #3084 from Security-Onion-Solutions/feature/log-rotate
...
Configure fleet result.log to rotate
2021-02-23 10:20:53 -05:00
m0duspwnens
e76ee07932
add CPUS for cpu count
2021-02-23 10:10:58 -05:00
Josh Brower
122e34b69c
Configure fleet result.log to rotate
2021-02-23 10:06:24 -05:00
m0duspwnens
1f2475c1c5
add eps graph to manager
2021-02-23 10:06:11 -05:00
m0duspwnens
141fbaced1
add eps graph to standalone
2021-02-23 09:40:21 -05:00
William Wernert
fa9fe82046
Merge pull request #3082 from Security-Onion-Solutions/kilo
...
Add so-rule script + soup pillar changes
2021-02-23 08:56:49 -05:00
William Wernert
fad87a8789
Fix function name (.20 -> .2X)
2021-02-23 08:51:44 -05:00
William Wernert
9287209750
Merge branch 'soup2.3.30' into feature/so-rules
...
# Conflicts:
# salt/common/tools/sbin/soup
2021-02-22 16:07:15 -05:00
William Wernert
982967fdde
Merge branch 'dev' into feature/so-rules
2021-02-22 16:01:48 -05:00
William Wernert
fb3af255d9
Add more info to apply messaging
2021-02-22 15:50:07 -05:00
William Wernert
3e3c923ab9
Arrange missing pillar error message better
2021-02-22 15:44:29 -05:00
William Wernert
b00cc88801
[fix] Unreverse apply prompt actions
2021-02-22 15:43:56 -05:00
William Wernert
e9b85337ff
[fix] Only prompt if entry doesn't exist, deep compare arrays
2021-02-22 15:41:09 -05:00
William Wernert
fd33a6cebe
Rename script, prompt user to apply if they didn't pass --apply
2021-02-22 15:32:18 -05:00
William Wernert
cdf766eeae
explicitely -> explicitly
2021-02-22 14:30:26 -05:00
William Wernert
8fc82fa3ef
Fix minion pillar directory
2021-02-22 14:27:22 -05:00
Mike Reeves
6ed1cc3875
Add Soup Functions
2021-02-22 14:02:37 -05:00
Doug Burks
84f138772f
Merge pull request #3072 from Security-Onion-Solutions/kilo
...
Additional fine tuning of Suricata metadata support
2021-02-22 10:57:02 -08:00
doug
71c7ffae3e
Improve support for Suricata metadata #2200
2021-02-22 13:49:29 -05:00
doug
bcce205430
Improve support for Suricata metadata #2200
2021-02-22 13:00:14 -05:00
Jason Ertel
943cbdbf1f
Merge pull request #3073 from Security-Onion-Solutions/delta
...
Apply action on PR only now that PRs are mandatory
2021-02-22 12:50:38 -05:00
Jason Ertel
43e0c3a60b
Apply action on PR only now that PRs are mandatory
2021-02-22 12:35:17 -05:00
Mike Reeves
d5069d12cf
Merge pull request #3071 from Security-Onion-Solutions/delta
...
Add acng to import installs for consistency
2021-02-22 11:34:23 -05:00
William Wernert
e65c9e5c7c
Don't expect apply arg at beginning of command
2021-02-22 11:29:30 -05:00
William Wernert
4bcb7403a9
Add apply option to end of command
2021-02-22 11:27:03 -05:00
William Wernert
bef3a6921c
[fix] SID wildcards are not parsed by idstools, remove
2021-02-22 11:12:02 -05:00
William Wernert
f7bef9200b
[fix] Only look for manager-type pillars
...
* SID disabling is only managed globally for now, so don't give the option to edit a different pillar
2021-02-22 10:38:53 -05:00
William Wernert
bb6f3107bc
[fix] idstools can run on an import node as well
2021-02-22 10:29:40 -05:00
doug
3467f30603
Improve support for Suricata metadata #2200
2021-02-22 10:27:24 -05:00
Doug Burks
d4ee2b86e6
Merge pull request #3070 from Security-Onion-Solutions/dev
...
Dev to Kilo
2021-02-22 07:22:49 -08:00
William Wernert
f2a1e89633
Merge branch 'dev' into feature/so-rules
2021-02-22 10:03:14 -05:00
William Wernert
abae673568
Update help text to reflect arg requirement changes
2021-02-22 10:00:29 -05:00
Jason Ertel
747d62dae5
Add acng to import installs for consistency
2021-02-22 09:44:24 -05:00
Josh Brower
5ca3dc492c
Merge pull request #3061 from Security-Onion-Solutions/foxtrot
...
Fix Playbook Fields & Mappings
2021-02-21 09:40:59 -05:00
Doug Burks
85b9cac110
Merge pull request #3063 from Security-Onion-Solutions/dev
...
Dev to kilo
2021-02-21 03:40:05 -08:00
Mike Reeves
40780f192e
Merge pull request #3062 from Security-Onion-Solutions/delta
...
fix merge issue
2021-02-20 19:15:16 -05:00
Jason Ertel
7222f1faa5
fix merge issue
2021-02-20 16:41:12 -05:00
Mike Reeves
e07e0b201d
Merge pull request #3058 from Security-Onion-Solutions/delta
...
Fix intermittent Suricata rules load issue
2021-02-20 10:27:13 -05:00
Jason Ertel
9d3c82a589
Disable unused features for import installations
2021-02-19 20:14:55 -05:00
Jason Ertel
04b3a20e22
Merge branch 'dev' into delta
2021-02-19 20:12:07 -05:00
Mike Reeves
cb6fe75ddb
Merge pull request #3055 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Rename filter.rules to filters.rules
2021-02-19 15:36:01 -05:00
Mike Reeves
8ab12c71a1
Rename filter.rules to filters.rules
2021-02-19 15:34:45 -05:00
Josh Brower
046cc0fbb0
Merge pull request #3052 from Security-Onion-Solutions/feature/sigma-tweaks
...
Feature/sigma tweaks
2021-02-19 15:16:34 -05:00
Josh Brower
8c69e19419
Add sigma refresh script
2021-02-19 15:14:37 -05:00
Josh Brower
2a324eac32
Add sigma refresh script
2021-02-19 15:12:55 -05:00
Mike Reeves
8db3602679
Merge pull request #3049 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix name and update examples
2021-02-19 15:01:04 -05:00
Mike Reeves
08abad747d
Fix name and update examples
2021-02-19 14:59:27 -05:00
William Wernert
c73970620d
[fix] Correct indent
2021-02-19 14:38:43 -05:00
William Wernert
34174a3290
Print relevant help if no/partial command passed
2021-02-19 14:34:32 -05:00
Mike Reeves
0ea29144a8
Merge pull request #3047 from Security-Onion-Solutions/surifile2
...
Suricata as Meta Data, File Extraction, And Parsing changes
2021-02-19 14:09:38 -05:00
Doug Burks
3ea1ec99d5
Merge pull request #3048 from Security-Onion-Solutions/kilo
...
Update syslog ingest parser to accomodate pfSense filterlog changes #3033
2021-02-19 11:02:56 -08:00
William Wernert
d205fff3ba
Run ssh-harden in setup per #1932
2021-02-19 13:45:23 -05:00
Jason Ertel
9302b9302b
Clear salt fileserver cache to ensure the new local.rules file gets picked up on the filesync
2021-02-19 11:13:31 -05:00
Mike Reeves
b4b449aa14
Pull in Suricata changes
2021-02-19 11:01:15 -05:00
William Wernert
4689e32ce4
Add sed for curly braces in minion pillars to soup
2021-02-19 10:18:06 -05:00
William Wernert
2184c6d59f
[fix] Create dict value if it doesn't exist
2021-02-19 09:31:22 -05:00
William Wernert
9183c0a92c
[feat] Initial so-rules script
...
* Quote curly braces in minion pillar, need to add sed function in soup
2021-02-19 09:24:12 -05:00
doug
88eb5b1d61
Update syslog ingest parser to accomodate pfSense filterlog changes #3033
2021-02-19 08:02:32 -05:00
Doug Burks
5493b3ef91
Merge pull request #3032 from Security-Onion-Solutions/dev
...
Update kilo to latest dev
2021-02-19 04:53:23 -08:00
Josh Patterson
4a510df205
Merge pull request #3026 from Security-Onion-Solutions/delta
...
Delta
2021-02-18 16:31:18 -05:00
Jason Ertel
faa78c0e26
Salt doesn't like a name starting with a non alpha-numeric char. Switch back to long if/then format
2021-02-18 14:51:09 -05:00
Josh Patterson
79e7b1da4d
Merge pull request #3021 from Security-Onion-Solutions/issue/2989
...
change suricata clean cron to run once a day
2021-02-18 14:07:40 -05:00
m0duspwnens
03487c2a31
change suricata clean cron to run once a day
2021-02-18 14:06:45 -05:00
Jason Ertel
e912b2fd96
Move idstools to run after nginx runs
2021-02-18 12:50:00 -05:00
Josh Patterson
0ab9577863
Merge pull request #3018 from Security-Onion-Solutions/all_rules_dont_show_changes
...
dont show changes since file can be large
2021-02-18 12:23:54 -05:00
m0duspwnens
bf100a2310
dont show changes since file can be large
2021-02-18 12:23:22 -05:00
Josh Patterson
2092044335
Merge pull request #3017 from Security-Onion-Solutions/issue/1237
...
load templates all the time
2021-02-18 12:13:49 -05:00
m0duspwnens
e730efb4ec
load templates all the time
2021-02-18 12:12:18 -05:00
Josh Patterson
76cdc45fad
Merge pull request #3016 from Security-Onion-Solutions/all_rules_dont_show_changes
...
Don't show changes because all.rules can be large
2021-02-18 12:00:08 -05:00
m0duspwnens
069997a65c
Don't show changes because all.rules can be large
2021-02-18 11:56:25 -05:00
Jason Ertel
6f7bc650a0
Apply reserved ports if the existing file is 0 bytes
2021-02-18 11:20:13 -05:00
Josh Patterson
a9da761fab
Merge pull request #3012 from Security-Onion-Solutions/issue/2989
...
Issue/2989
2021-02-18 10:52:23 -05:00
m0duspwnens
95df18c545
limit eve logs and gz files based on days
2021-02-18 10:45:20 -05:00
m0duspwnens
a4d5f58256
fix surilogcompress
2021-02-18 10:33:47 -05:00
Josh Patterson
3f7cdb933f
Merge pull request #3010 from Security-Onion-Solutions/issue/2989
...
Issue/2989
2021-02-18 09:58:35 -05:00
m0duspwnens
74ca4487de
ensure at least 2 eve files are kept https://github.com/Security-Onion-Solutions/securityonion/issues/2989
2021-02-18 09:51:40 -05:00
m0duspwnens
4b07d5e457
add identifier to eve clean cron
2021-02-18 09:39:54 -05:00
m0duspwnens
041d193f2d
fix brackets
2021-02-18 09:37:37 -05:00
m0duspwnens
0bef8b6662
limit number of eve.json files for suricata https://github.com/Security-Onion-Solutions/securityonion/issues/2989
2021-02-18 09:26:59 -05:00
Josh Brower
b5087b815a
Merge pull request #3002 from Security-Onion-Solutions/feature/sigma-tweaks
...
Update .security analyzer
2021-02-17 16:38:22 -05:00
Josh Brower
d2a74c80e2
Update .security analyzer
2021-02-17 16:37:31 -05:00
Josh Brower
741f674a4c
Merge pull request #3001 from Security-Onion-Solutions/dev
...
Dev
2021-02-17 16:36:49 -05:00
Pete
29c5f3212f
make log_size_limit calculation more specific
...
Extend the directory traversal into /nsm/elasticsearch in case that's a separate mountpoint from /nsm/.
2021-02-17 16:53:31 +00:00
Josh Patterson
174ed84750
Merge pull request #2993 from Security-Onion-Solutions/issue/2736
...
logrotate strelka
2021-02-17 11:47:52 -05:00
m0duspwnens
7a595df5b6
strelka logrotate - https://github.com/Security-Onion-Solutions/securityonion/issues/2736
2021-02-17 11:17:41 -05:00
m0duspwnens
2b07d89b5a
error: /opt/so/conf/sensor-rotate.conf:8 unknown option 'endscript' -- ignoring line
2021-02-17 11:01:18 -05:00
m0duspwnens
e6ae1af85f
test rotating strelka log at 100k
2021-02-17 10:47:06 -05:00
Josh Patterson
ce313d8dc4
Merge pull request #2992 from Security-Onion-Solutions/issue/2737
...
fix logic for log_size_limit
2021-02-17 10:09:54 -05:00
Josh Patterson
fddef1a6f4
Merge pull request #2985 from Security-Onion-Solutions/issue/2915
...
remove old backup files
2021-02-17 09:43:58 -05:00
William Wernert
cda36f178b
Merge pull request #2979 from Security-Onion-Solutions/foxtrot
...
Setup fixes/improvements
2021-02-16 17:14:59 -05:00
Josh Patterson
bec437c2cf
Merge pull request #2984 from Security-Onion-Solutions/issue/2737
...
Issue/2737
2021-02-16 15:41:46 -05:00
m0duspwnens
996bf0768b
fix logic for log_size_limit https://github.com/Security-Onion-Solutions/securityonion/issues/2737
2021-02-16 15:40:01 -05:00
William Wernert
0bd5ddf6a6
Grammar + misc fixes per PR review
...
* Remove unnecessary `apt-get update` commands
* Change `if ! (command); then exit 1; fi` to `command || exit 1` to avoid subshell
2021-02-16 14:17:41 -05:00
Doug Burks
8016511414
Merge pull request #2981 from Security-Onion-Solutions/kilo
...
Hunt: improve Wazuh queries #2383
2021-02-16 10:38:53 -08:00
Josh Patterson
eb18ec552c
Merge pull request #2980 from Security-Onion-Solutions/issue/2915
...
Issue/2915
2021-02-16 12:01:37 -05:00
doug
fabe3c87f2
Hunt: improve Wazuh queries #2383
2021-02-16 11:56:14 -05:00
m0duspwnens
7099ed4bf5
delete many backup files
2021-02-16 11:55:49 -05:00
m0duspwnens
1ccc5480e1
remove oldest backup
2021-02-16 11:40:45 -05:00
Doug Burks
d6fa54b606
Merge pull request #2975 from Security-Onion-Solutions/kilo
...
Issues 2954 and 2361 - Kibana config
2021-02-16 08:30:46 -08:00
William Wernert
3323e900ef
[fix] Fix indent (pt 2)
2021-02-16 11:17:36 -05:00
William Wernert
7a9f801eb1
[fix] Add more apt-get update commands
...
Fixes #2962
2021-02-16 10:24:58 -05:00
William Wernert
38a5b86813
Make apt-get syntax consistent
2021-02-16 10:24:07 -05:00
William Wernert
23221065eb
Preset MANAGERUPDATES var for airgap since we don't prompt now
2021-02-16 09:43:54 -05:00
William Wernert
5e8d09be51
[fix] Fix indent
2021-02-16 09:42:35 -05:00
doug
397d8d0964
Kibana 7.10.2 config changes #2954
2021-02-14 07:04:51 -05:00
doug
3248edea8b
Update Kibana dashboard hyperlinks to new url format #2361
2021-02-12 17:25:42 -05:00
Josh Patterson
bf3b609a44
Merge pull request #2955 from Security-Onion-Solutions/issue/1237
...
Issue/1237
2021-02-12 16:04:58 -05:00
m0duspwnens
100601c452
only laod templates if they change https://github.com/Security-Onion-Solutions/securityonion/issues/1237
2021-02-12 16:03:45 -05:00
doug
31a0c2bc82
Update Kibana dashboard hyperlinks to new url format #2361
2021-02-12 15:37:25 -05:00
doug
797d2c4dba
Kibana 7.10.2 config changes #2954
2021-02-12 15:35:06 -05:00
Doug Burks
fd4cb0b7a8
Kibana 7.10.2 config changes #2954
2021-02-12 14:05:29 -05:00
Doug Burks
c717773fc3
Kibana 7.10.2 config changes #2954
2021-02-12 14:04:00 -05:00
Josh Patterson
ce04b109fe
Merge pull request #2950 from Security-Onion-Solutions/delta
...
Disable ICMP timestamps by default
2021-02-12 13:54:59 -05:00
William Wernert
4affb20b27
Give context to metadata tool choice
2021-02-12 13:42:14 -05:00
William Wernert
724f5cad78
Warn user if using "securityonion" as hostname
2021-02-12 12:55:55 -05:00
William Wernert
8323f3f57a
[fix] Fix logic to correctly hide prompt
2021-02-12 12:23:45 -05:00
Josh Patterson
a8598a50e4
Merge pull request #2953 from Security-Onion-Solutions/issue/2756
...
remove /etc/yum.repos.d/salt-2019-2-5.repo if present
2021-02-12 12:05:21 -05:00
m0duspwnens
3b0c2b3e91
remove /etc/yum.repos.d/salt-2019-2-5.repo if present https://github.com/Security-Onion-Solutions/securityonion/issues/2756
2021-02-12 12:04:08 -05:00
William Wernert
1ffa7afefa
eval-net answerfile corrections
...
* HOSTNAME: standalone -> eval
* install_type: STANDALONE -> EVAL
2021-02-11 16:20:29 -05:00
William Wernert
188d844d27
Redirect stderr of minion grep to /dev/null
2021-02-11 13:49:39 -05:00
m0duspwnens
b4e9a44572
Merge remote-tracking branch 'remotes/origin/dev' into issue/1704
2021-02-11 11:10:06 -05:00
m0duspwnens
7e4d7a6985
drop icmp timestamp replies https://github.com/Security-Onion-Solutions/securityonion/issues/1704
2021-02-11 11:09:21 -05:00
William Wernert
d9b4c09cf0
[fix] Don't show irrelevant prompts during airgap setup
2021-02-11 10:52:18 -05:00
William Wernert
ce8db8abdb
[fix] Only run salt commands during reinstall if master is configured
2021-02-11 10:51:04 -05:00
Josh Patterson
bf8ca590d0
Merge pull request #2932 from Security-Onion-Solutions/delta
...
only save at the end
2021-02-11 09:25:31 -05:00
Mike Reeves
97594f84cb
Merge pull request #2930 from Security-Onion-Solutions/vpn
...
VPN Configuration
2021-02-11 09:21:17 -05:00
Mike Reeves
f8903c2554
Fix extra character
2021-02-10 12:58:02 -05:00
Mike Reeves
9eb1e6a448
Prevent the tun interface from being disabled
2021-02-10 12:51:26 -05:00
m0duspwnens
3cfbc61f4e
only save at the end
2021-02-10 11:15:39 -05:00
Mike Reeves
10553938b5
Merge pull request #2901 from Security-Onion-Solutions/curatorwarm
...
add warm node action for hot/warm
2021-02-08 12:08:23 -05:00
Mike Reeves
125f7d6262
add warm node action for hot/warm
2021-02-08 11:49:49 -05:00
Mike Reeves
940bac3634
Merge pull request #2889 from Security-Onion-Solutions/backupsfix
...
Backupsfix
2021-02-08 10:40:20 -05:00
Mike Reeves
5043b970ef
Fix tar syntax
2021-02-06 19:14:44 -05:00
Mike Reeves
a3ca84db66
Fix backupdir name state
2021-02-06 15:32:42 -05:00
Mike Reeves
bf79c92456
Lock down Backups folder permissions
2021-02-05 22:31:08 -05:00
Mike Reeves
8f97973fac
Lock down Backups folder permissions
2021-02-05 22:17:31 -05:00
Jason Ertel
4d6d2edd17
Merge pull request #2872 from Security-Onion-Solutions/automation/ami
...
Add locking to so-firewall
2021-02-04 16:14:16 -05:00
Jason Ertel
e427f8178d
Implement locking to so-firewall script
2021-02-04 16:06:11 -05:00
Jason Ertel
a13b31fbcc
Merge branch 'dev' into automation/ami
2021-02-04 16:05:39 -05:00
Mike Reeves
d4e5ab477f
Merge pull request #2854 from Security-Onion-Solutions/revert-2830-filebeatlimits
...
Revert "Make filebeat retry forever"
2021-02-03 22:26:03 -05:00
Jason Ertel
58e4205602
Revert "Make filebeat retry forever"
2021-02-03 21:46:29 -05:00
Jason Ertel
6b54a29ac7
Remove 'new user' references from so-user
2021-02-03 15:23:58 -05:00
Jason Ertel
3ebedcd4e8
Merge pull request #2830 from Security-Onion-Solutions/filebeatlimits
...
Make filebeat retry forever
2021-02-03 11:32:05 -05:00
Mike Reeves
179efa3a51
Merge pull request #2833 from Security-Onion-Solutions/automation/ami
...
Adjust AMI test network
2021-02-02 21:05:34 -05:00
Jason Ertel
91480abaa0
Adjust AMI test network
2021-02-02 17:41:41 -05:00
Mike Reeves
55a8f6aa7a
Make filebeat retry forever
2021-02-02 16:41:52 -05:00
William Wernert
8f0b0ac936
Merge pull request #2825 from Security-Onion-Solutions/foxtrot
...
Setup: dpkg retry, whiptail changes, fix zeek state condition
2021-02-02 14:41:48 -05:00
Josh Patterson
ef2fe2bb61
Merge pull request #2828 from Security-Onion-Solutions/delta
...
adjust timeout for ssl states and pillarize ElastAlert
2021-02-02 13:35:28 -05:00
William Wernert
46581c0528
[fix] Don't use ZEEKVERSION var, check pillar value
2021-02-02 12:45:56 -05:00
William Wernert
2253603544
[fix] Don't try to inherit home net on standalone
2021-02-02 12:11:47 -05:00
Jason Ertel
e7e1f4c155
Merge pull request #2820 from Security-Onion-Solutions/automation/ami
...
Adjust automation files for distributed AMI
2021-02-01 15:33:53 -05:00
m0duspwnens
b3c08229db
Merge remote-tracking branch 'remotes/origin/sslstate/timeouts_retry' into delta
2021-02-01 15:33:31 -05:00
Jason Ertel
f736d9f8dd
Adjust automation files for distributed AMI
2021-02-01 15:27:53 -05:00
m0duspwnens
8cf0a3da98
remove seconds
2021-02-01 15:19:47 -05:00
William Wernert
8d01b87ab5
Merge branch 'dev' into foxtrot
2021-02-01 13:56:33 -05:00
William Wernert
8f476bbbdd
[fix] Add back removed if statement
2021-02-01 13:11:51 -05:00
m0duspwnens
8ff6d1639a
Merge remote-tracking branch 'remotes/origin/dev' into issue/1191
2021-02-01 12:51:00 -05:00
William Wernert
daebe90b6e
[fix] fix retry command handling
...
* use eval "$cmd" to handle strings correctly
* add-apt-repo doesn't need dpkg lock so don't use retry for those lines
2021-02-01 12:06:19 -05:00
William Wernert
44617fdddf
[fix] Run command being retried within quotes
2021-02-01 11:28:28 -05:00
William Wernert
02f0ef989b
[fix] <cmd> || <fail_reactor>; exit 1 will always exit, fix this
2021-02-01 11:11:01 -05:00
William Wernert
36ce389202
Remove wait_for_apt, use common retry function to run apt commands
2021-02-01 10:55:14 -05:00
Jason Ertel
1c8a8f6b7b
Merge pull request #2805 from Security-Onion-Solutions/elasticrollback
...
Add features option back
2021-01-30 21:00:10 -05:00
Mike Reeves
160d307f4a
Disable ML for features #2788
2021-01-30 20:00:41 -05:00
Mike Reeves
4212afe0c9
Add features option back
2021-01-30 19:57:18 -05:00
m0duspwnens
0ea504c16a
remove space
2021-01-29 17:32:48 -05:00
m0duspwnens
8ca15a6679
Merge remote-tracking branch 'remotes/origin/dev' into issue/1191
2021-01-29 16:54:26 -05:00
Mike Reeves
929896c191
Merge pull request #2797 from Security-Onion-Solutions/raid2
...
Raid Setup for Appliances
2021-01-29 16:30:43 -05:00
Mike Reeves
22e6e45667
Remove other changes
2021-01-29 16:14:14 -05:00
William Wernert
edfd985353
Merge branch 'bugfix/zeek-prompts' into foxtrot
2021-01-29 16:04:56 -05:00
Mike Reeves
18f2c7b482
Raid Setup for Appliances
2021-01-29 16:03:18 -05:00
Mike Reeves
aa93e2b48f
Merge pull request #2794 from Security-Onion-Solutions/foxtrot
...
Add retry capabilities to image/sig pulls
2021-01-29 15:57:41 -05:00
William Wernert
7a3c7322fc
[fix] Only check for ZEEKVERSION on manager installs
2021-01-29 15:36:50 -05:00
m0duspwnens
618b94b9b6
add newline
2021-01-29 15:31:05 -05:00
m0duspwnens
f50a89a0cf
watch elastalert config and restart docker if chagnes
2021-01-29 15:28:59 -05:00
m0duspwnens
482b6eb699
Merge remote-tracking branch 'remotes/origin/dev' into sslstate/timeouts_retry
2021-01-29 13:44:27 -05:00
m0duspwnens
e6ecd609cc
change timeouts to 30s
2021-01-29 13:44:11 -05:00
Jason Ertel
2926527ad0
Place sig keys in same dir as other sig files
2021-01-29 13:21:58 -05:00
Jason Ertel
73909c4dea
Place sig keys in same dir as other sig files
2021-01-29 13:00:56 -05:00
Jason Ertel
c055427e40
Add support for image key/sig retries
2021-01-29 11:18:06 -05:00
Jason Ertel
194f480017
Airgap fix for import nodes missing rules
2021-01-28 13:03:47 -05:00
m0duspwnens
0936dbdb1c
add timeouts and retries to ca/ssl states
2021-01-28 11:40:31 -05:00
Jason Ertel
f12947362b
Adjust test network IPs
2021-01-28 11:35:10 -05:00
Jason Ertel
bfa6aabc4b
Correct automation for airgap import to avoid infinite loop during setup
2021-01-28 10:38:03 -05:00
Jason Ertel
34c2116669
Adjust test network allocation
2021-01-27 16:02:36 -05:00
m0duspwnens
b7aef32eeb
fix missing }
2021-01-27 15:50:23 -05:00
m0duspwnens
8df9e020ac
pillarize elastalert https://github.com/Security-Onion-Solutions/securityonion/issues/1191
2021-01-27 15:35:29 -05:00
m0duspwnens
0ac19142c4
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-27 10:52:05 -05:00
Josh Brower
d277bf6d05
Merge pull request #2749 from Security-Onion-Solutions/bugfix/osquery-wel-parsing
...
Update Osquery Windows Eventlog Parsing
2021-01-27 09:17:17 -05:00
Josh Brower
13ab4c66eb
Update Osquery Windows Eventlog Parsing
2021-01-27 09:15:54 -05:00
William Wernert
f5c044e3e3
[fix] Log directory fixes
...
* The playbook log dir is owned by the socore group, so we can use `su root socore`
* Addresses https://github.com/Security-Onion-Solutions/securityonion/pull/2681#issuecomment-767761670
---
* influxdb runs as root, so we can set the log directory permissions to 755 for this service
2021-01-26 16:07:34 -05:00
m0duspwnens
be0b2b99e9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-26 13:48:49 -05:00
William Wernert
1939fe85d7
[fix] Revert directory permission changes
2021-01-26 13:41:10 -05:00
Josh Patterson
f8242a931c
Merge pull request #2733 from Security-Onion-Solutions/automation/ssh_prompts
...
fix if statement for isntalling sshpass
2021-01-26 09:57:32 -05:00
m0duspwnens
ffd01d6975
fix if statement for isntalling sshpass
2021-01-26 09:49:19 -05:00
m0duspwnens
f1faab7b1a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-26 09:04:00 -05:00
William Wernert
7b2ec05dbf
[fix] Add missing fi
2021-01-25 19:57:34 -05:00
Mike Reeves
bcd5bdd82d
Merge pull request #2730 from Security-Onion-Solutions/telegraf3
...
Add EPS and RAID status collection for telegraf
2021-01-25 19:37:03 -05:00
Mike Reeves
3b1cea94d1
Merge branch 'dev' into telegraf3
2021-01-25 19:36:49 -05:00
Mike Reeves
88abd284a7
Fix Conflicts
2021-01-25 19:35:32 -05:00
Mike Reeves
891a7592d8
Fix Conflicts
2021-01-25 19:33:49 -05:00
Mike Reeves
e43a80b9c6
Add EPS and RAID status collection for telegraf
2021-01-25 19:28:30 -05:00
Mike Reeves
4ef38f8d04
Add EPS and RAID status collection for telegraf
2021-01-25 19:14:46 -05:00
Josh Patterson
049daa6701
Merge pull request #2725 from Security-Onion-Solutions/automation/ssh_prompts
...
Automation/ssh prompts
2021-01-25 17:21:55 -05:00
Jason Ertel
df21b28d5c
Update copyright year
2021-01-25 17:11:42 -05:00
Jason Ertel
b0c74cf38c
Add import automation files for other platforms
2021-01-25 16:46:52 -05:00
Jason Ertel
ae233b5757
Update AMI automation files for distributed install
2021-01-25 15:53:25 -05:00
Jason Ertel
8ec0b95f02
Rename AMI automation files for consistency with other files
2021-01-25 15:53:25 -05:00
m0duspwnens
2f8b5afe3e
Merge remote-tracking branch 'remotes/origin/issue/2722' into automation/ssh_prompts
2021-01-25 15:23:39 -05:00
m0duspwnens
944817732b
grep for the scrip to be running https://github.com/Security-Onion-Solutions/securityonion/issues/2722
2021-01-25 15:22:04 -05:00
m0duspwnens
17a1189e42
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-25 15:20:46 -05:00
m0duspwnens
50345628f0
Merge remote-tracking branch 'remotes/origin/dev' into automation/ssh_prompts
2021-01-25 13:48:08 -05:00
m0duspwnens
7dcca6f364
change when we detect os and wait_for_apt when installing sshpass
2021-01-25 13:47:51 -05:00
Mike Reeves
6e9bdde9e2
Merge pull request #2721 from Security-Onion-Solutions/sosappliance
...
Fix function for appliances
2021-01-25 13:26:28 -05:00
Mike Reeves
2e32b53158
Fix function for appliances
2021-01-25 13:20:46 -05:00
m0duspwnens
e1f7c090f3
detect os and cloud sooner
2021-01-25 10:25:41 -05:00
William Wernert
2a4eac74c4
Merge pull request #2681 from Masaya-A/logrotate-fix
...
Log Rotation Fix (common-rotate)
2021-01-25 10:14:39 -05:00
m0duspwnens
fe09479dde
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-25 09:55:52 -05:00
Masaya-A
995d618ff5
Add cron.absent to remove old cron job if present
2021-01-25 15:45:33 +09:00
Mike Reeves
560e510b44
Merge pull request #2715 from Security-Onion-Solutions/sosappliance
...
Sosappliance
2021-01-24 12:06:18 -05:00
Mike Reeves
b4c8b439a0
Detect if this is an SOS appliance
2021-01-24 12:02:34 -05:00
Mike Reeves
85e2a14f1e
Put functions in correct order
2021-01-24 11:52:45 -05:00
Jason Ertel
6f14f27ca0
Add automation files for distributed network variations
2021-01-23 11:04:07 -05:00
William Wernert
59a4b148bc
Merge branch 'dev' into logrotate-fix
2021-01-22 15:20:55 -05:00
William Wernert
2159914742
Merge pull request #2708 from Security-Onion-Solutions/bugfix/telegraf-zombie-procs
...
Bugfix/telegraf zombie procs
2021-01-22 15:20:09 -05:00
Jason Ertel
47d69bbc9e
Move from quay.io to ghcr.io
2021-01-22 13:53:49 -05:00
William Wernert
7273c8a066
[fix] Also rotate stenographer log as per #2681
2021-01-22 12:46:21 -05:00
William Wernert
4079f8a8e8
[fix] Telegraf doesn't clean up zombie processes, use init flag to fix this
2021-01-22 12:23:09 -05:00
William Wernert
f1781b1fde
[fix] Set timeout for scripts (15s, 3x default 5s)
2021-01-22 12:15:29 -05:00
Jason Ertel
537f7529f8
Increase Kibana wait from 3 minutes to 15 minutes due to the longer init time needed for Kibana to start (because of the recent ES changes)
2021-01-22 10:09:15 -05:00
Masaya-A
249651edc7
Delete suri-rotate.conf
2021-01-22 10:08:23 +09:00
Masaya-A
e0bbc8cc51
Delete surirotate
2021-01-22 10:08:07 +09:00
Masaya-A
f156106e57
Update salt/common/files/log-rotate.conf
...
Co-authored-by: William Wernert <william.wernert@gmail.com >
2021-01-22 09:29:08 +09:00
Masaya-A
bcdf826204
Update init.sls
2021-01-22 09:26:52 +09:00
Mike Reeves
636687ac59
Merge pull request #2702 from Security-Onion-Solutions/essecurity
...
SSL with Elastic Basic license. Remove features option.
2021-01-21 13:57:28 -05:00
Mike Reeves
9408d62c65
Remove features
2021-01-21 13:55:53 -05:00
Mike Reeves
f85ecf254e
Fix dupe
2021-01-21 13:21:08 -05:00
Mike Reeves
9f984036c5
Use the internmediate cert
2021-01-21 13:00:46 -05:00
Mike Reeves
b0914fa604
try .p12
2021-01-21 12:46:00 -05:00
Mike Reeves
9759990233
Switch to java key store
2021-01-21 12:29:45 -05:00
Mike Reeves
bb523c44e6
Enable features temporarily
2021-01-21 12:19:41 -05:00
Mike Reeves
013b706ce4
Enable http ssl
2021-01-21 12:13:23 -05:00
weslambert
583b65e952
Fix syntax
2021-01-21 11:52:23 -05:00
Mike Reeves
84b75a38a3
Fix error in init.sls for ES
2021-01-21 11:21:04 -05:00
Mike Reeves
6de70ec820
Update docker mappings for ES
2021-01-21 11:12:12 -05:00
weslambert
d6043d091b
Merge pull request #2701 from Security-Onion-Solutions/feature/filebeat_events
...
Allow for Filebeat queue/output adjustments via pillar
2021-01-21 10:36:33 -05:00
Wes Lambert
19d22e1f8a
Allow for Filebeat queue/output adjustments via pillar
2021-01-21 15:34:54 +00:00
Mike Reeves
35c741ae63
Turn on Xpack SSL
2021-01-21 09:49:31 -05:00
m0duspwnens
76aadbd04e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-21 09:30:03 -05:00
weslambert
a99246c600
Merge pull request #2698 from Security-Onion-Solutions/fix/reserved_ports
...
Fix/reserved ports
2021-01-21 08:39:35 -05:00
Wes Lambert
0039877779
Check for port availability for Wazuh and Strelka
2021-01-21 13:29:09 +00:00
Wes Lambert
9a91674688
Add reserved ports file for sysctl
2021-01-21 13:18:22 +00:00
Wes Lambert
74e315841a
Modify common to reserve Docker proxy ports
2021-01-21 13:17:16 +00:00
Masaya-A
cd5abf924c
To make log rotation working
2021-01-21 09:31:15 +09:00
Masaya-A
845ab92d36
To make log rotation working
2021-01-21 09:30:34 +09:00
Josh Patterson
516634ef8d
Merge pull request #2691 from Security-Onion-Solutions/issue/2679
...
Issue/2679
2021-01-20 17:41:43 -05:00
m0duspwnens
18217ba38b
change so-searchnode role to so-node https://github.com/Security-Onion-Solutions/securityonion/issues/2679
2021-01-20 17:40:02 -05:00
m0duspwnens
6e756b3586
allow heathcheck state for standalone and heavynode
2021-01-20 17:34:53 -05:00
Josh Patterson
e7e6243399
Merge pull request #2689 from Security-Onion-Solutions/issue/2679
...
Issue/2679
2021-01-20 15:14:38 -05:00
m0duspwnens
18278a97ac
fix salt top formatting
2021-01-20 15:13:55 -05:00
m0duspwnens
b693373d8d
change how we allow or disallow states to be run https://github.com/Security-Onion-Solutions/securityonion/issues/2679
2021-01-20 15:09:53 -05:00
Jason Ertel
58f922aac3
Skip image pull if so-tcpreplay image already exists and is current
2021-01-20 11:17:10 -05:00
m0duspwnens
b1c5b83fd5
removing old search node logic and managersensor from salt top
2021-01-20 09:53:42 -05:00
m0duspwnens
caaa8cc764
add schedule state to fleet node so it gets highstate schedule
2021-01-20 09:46:49 -05:00
Masaya-A
d53945888c
Add sensoroni dir
2021-01-20 14:54:55 +09:00
Masaya-A
d3d11ff67b
Delete some directories
...
Delete some directories that should not be handled by common-rotate.
2021-01-20 13:42:20 +09:00
Masaya-A
b2b221fa46
Specify the file name for Suricata
...
stats.log will be rotated by surirotate
2021-01-20 13:20:04 +09:00
Masaya-A
e20891ac44
Fix spacing
2021-01-20 13:10:33 +09:00
Masaya-A
8cca792a8f
To avoid lots of "[stenoloss.sh] <defunct>"
2021-01-20 12:16:17 +09:00
Masaya-A
5dad143c42
Need full path in order to work on cron
2021-01-20 12:14:09 +09:00
Masaya-A
9dd3199ec4
Merge pull request #1 from Security-Onion-Solutions/dev
...
Update Dev
2021-01-20 12:09:35 +09:00
Jason Ertel
71e0014115
Wrap parenthesis around correlation filter to allow additional filtering
2021-01-19 17:51:23 -05:00
m0duspwnens
0fec46505d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-19 14:35:53 -05:00
William Wernert
8023e79020
[fix] Don't remove answer file when checking version on manager, file does not yet exist
2021-01-19 11:28:33 -05:00
m0duspwnens
3ef8106d8d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-19 11:28:27 -05:00
William Wernert
650008e1e6
[fix] Replace leftover /root/install_opt strings with variable
2021-01-19 11:20:53 -05:00
Jason Ertel
d91913e58e
Redirect tcpreplay warnings to dev null when running so-test
2021-01-18 21:42:50 -05:00
Mike Reeves
12aa4033b6
Fix soup in case airgap is in the hostname
2021-01-18 18:08:34 -05:00
Jason Ertel
a795f0a487
Correct airgap IPs; Remove auto tcpreplay during post-setup phase
2021-01-16 12:01:49 -05:00
Jason Ertel
2006677a22
Add default customization file (Blank)
2021-01-15 20:08:27 -05:00
William Wernert
32839f8a53
[feat] Various input validation changes + fixes
...
* Keep invalid input in subsequent prompts
* Remove useless placeholder values
* Only set PROCS variable once
* Make input collection loops more consistent
2021-01-15 18:05:29 -05:00
Jason Ertel
0af6afa216
Add method for making adjustments to the SOC UI
2021-01-15 16:26:06 -05:00
William Wernert
8cb836a17a
[fix] Don't preset HOSTNAME var, interferes with automation
2021-01-15 16:22:07 -05:00
William Wernert
432d231a0e
[fix] Don't use set -e since we depend on non-zero exit codes for this function
2021-01-15 13:52:10 -05:00
William Wernert
9726ff9ce6
[fix] Correct logic for verbose flag
2021-01-15 13:39:12 -05:00
Mike Reeves
9cf63545bc
Merge pull request #2640 from Masaya-A/influxdb/strengthen
...
Disable weak cipher suites from influxdb
2021-01-15 10:50:21 -05:00
m0duspwnens
76c7c46887
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-15 10:48:19 -05:00
William Wernert
e440f6c44a
[fix] Set variables used by sensor pillar before generating the pillar
2021-01-15 10:29:51 -05:00
William Wernert
ed129bcf1f
[fix] Add verbose flag so that so-monitor-add only sees necessary information
2021-01-15 09:25:04 -05:00
William Wernert
f4de5e28bf
[fix] Padding 3->4 spaces, don't use lookup_pillar before salt is installed
2021-01-15 08:57:14 -05:00
Jason Ertel
07b5f1d23e
Rename functions to avoid naming conflict with setup vars
2021-01-15 08:55:30 -05:00
William Wernert
0f6805823e
[fix] Add spacing to whiptail menu + preset err
2021-01-15 08:35:37 -05:00
Masaya-A
0d93b15a63
Disable weak cipher suites from influxdb
...
The default config of influxdb enables use of some weak cipher suites such as RC4 and 3DES(SWEET32).
To disable them, a list of enabled ciphers added into influxdb.conf.
2021-01-15 11:47:04 +09:00
William Wernert
dbe22f901d
[fix] Add jinja raw block to so-common
2021-01-14 14:54:37 -05:00
William Wernert
ebc5a4314a
[feat] Add salt logs to log rotation config
2021-01-14 13:43:00 -05:00
William Wernert
df07cc578c
[fix] Only update err if return code is non-zero
2021-01-14 13:20:56 -05:00
William Wernert
2e23e0d690
[fix] Only update err if return code is non-zero
2021-01-14 13:20:29 -05:00
William Wernert
a7b9b565fd
[fix] Only return after all interfaces added to bond0
2021-01-14 13:19:29 -05:00
William Wernert
e7070ef217
Merge pull request #2630 from Security-Onion-Solutions/feature/setup
...
Input validation + so-monitor-add
2021-01-14 13:17:01 -05:00
William Wernert
8793965f4a
[fix] Capitalization
2021-01-14 13:12:12 -05:00
William Wernert
ddcd487edc
[fix] Remove files not in dev
2021-01-14 13:08:11 -05:00
William Wernert
0db439df1e
Merge branch 'dev' into feature/setup
2021-01-14 13:06:32 -05:00
William Wernert
82c7832d60
[fix] Fix indent in valid_hostname
2021-01-14 12:58:21 -05:00
m0duspwnens
a2b52a1a98
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-14 10:44:53 -05:00
William Wernert
3c22738ae1
[fix] Add example CIDR notation, remove placeholder X.X.X.X
2021-01-14 10:38:47 -05:00
Jason Ertel
9d0dca05b1
Adjusted logic on so-tcpreplay to handle init for standalone/eval nodes
2021-01-13 22:29:58 -05:00
Jason Ertel
2ccf77eaef
Rename network automation files
2021-01-13 17:29:48 -05:00
William Wernert
8245b25835
[fix] Move metadata function
2021-01-13 17:28:19 -05:00
William Wernert
b68685e00e
[fix] Correct metadata function name
2021-01-13 17:26:27 -05:00
William Wernert
90f085b2d7
[fix] Fail setup early if we can't determine version of manager
2021-01-13 15:57:21 -05:00
Jason Ertel
6d6779bba6
Added automation files for network eval/standalone installs; Reduced Zeek threads from 7 to 2 on all test nodes
2021-01-13 15:43:43 -05:00
Jason Ertel
0a1ab29d19
Add distributed airgap automation files
2021-01-13 14:28:54 -05:00
Jason Ertel
ea1ab75072
Refactored so-common node type checks for improved readability; Updated so-tcpreplay to support distributed grids
2021-01-13 12:42:54 -05:00
William Wernert
6ea3a651a4
[fix] Fix unit tests for dns list
2021-01-13 11:37:48 -05:00
William Wernert
4dc3a6aa35
[refactor] Standardize list inputs to comma separated
2021-01-13 11:36:20 -05:00
Josh Patterson
59b016695f
Merge pull request #2611 from Security-Onion-Solutions/issue/2095
...
pillarize disk freespace for steno
2021-01-13 11:11:27 -05:00
m0duspwnens
df590bfd23
pillarize disk freespace for steno https://github.com/Security-Onion-Solutions/securityonion/issues/2095
2021-01-13 11:09:38 -05:00
William Wernert
d254fd960a
[feat] Add message explaining strings cannot contain spaces
2021-01-13 11:04:35 -05:00
m0duspwnens
489f702e47
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-13 10:47:13 -05:00
William Wernert
0734998315
[fix] patch_schedule should not be local
2021-01-13 10:39:24 -05:00
Jason Ertel
9b060fb2d1
Adjust automation defaults for sensors and search nodes
2021-01-13 10:39:10 -05:00
Jason Ertel
bb386f9935
Allow passwordless sudo during tests for all nodes, not just manager; Only run so-test on sensor nodes during test runs
2021-01-13 10:39:05 -05:00
William Wernert
ebac17ce38
[wip] Attempting to fix missing patch schedule prompts
2021-01-13 10:29:36 -05:00
Mike Reeves
2950779d91
Fix stralka rule update
2021-01-13 09:57:12 -05:00
Josh Patterson
02d4813ef7
Merge pull request #2609 from Security-Onion-Solutions/issue/2590
...
Issue/2590
2021-01-12 16:43:45 -05:00
m0duspwnens
225ed1c14a
change suriloss and zeekloss to be more similar code style
2021-01-12 16:39:19 -05:00
m0duspwnens
96dab31ab0
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/2590
2021-01-12 14:29:59 -05:00
Josh Patterson
aa8a14d74a
Merge pull request #2606 from Security-Onion-Solutions/automation/ssh_prompts
...
fix quotes
2021-01-12 14:08:08 -05:00
m0duspwnens
dbb9f90f00
fix quotes
2021-01-12 14:07:04 -05:00
William Wernert
dd20002fd5
[fix] Dockernet prompt is negative, continue on "no"
2021-01-12 11:28:24 -05:00
William Wernert
5c6f8f9d47
[fix] Correct function call (pt 2)
2021-01-12 11:27:03 -05:00
William Wernert
ff69d022b3
[fix] Correct function call
2021-01-12 11:26:20 -05:00
William Wernert
fb31b56c8b
[fix] Only check for network init file if iso
2021-01-12 11:22:52 -05:00
William Wernert
38e37a0385
[refactor] Remove whiptail shard count prompt
2021-01-12 11:04:40 -05:00
William Wernert
5d077d278e
[feat] Add input validation to inputbox whiptail prompts
2021-01-12 11:02:33 -05:00
William Wernert
0dc0780e28
[feat] Add unit tests for input validation
2021-01-12 11:02:00 -05:00
William Wernert
332c6877b8
[fix] Add extra arg to printf instead of using echo
2021-01-12 11:01:25 -05:00
William Wernert
ef7a934b9d
[feat] Add functions for input validation
2021-01-12 11:01:04 -05:00
m0duspwnens
cc0697cefa
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-12 10:29:49 -05:00
Josh Patterson
4f384991ba
Merge pull request #2601 from Security-Onion-Solutions/automation/ssh_prompts
...
remote quotes
2021-01-12 09:54:10 -05:00
m0duspwnens
9405990a2e
remote quotes
2021-01-12 09:50:08 -05:00
m0duspwnens
6ea1a83afe
resolve some issues with the zeekloss script https://github.com/Security-Onion-Solutions/securityonion/issues/2590
2021-01-11 14:10:08 -05:00
m0duspwnens
4d84b64056
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-11 12:43:37 -05:00
Jason Ertel
8b49876e26
First pass at distribute ISO automation files
2021-01-11 12:04:57 -05:00
Jason Ertel
bc8e200919
Continued retry implementation for salt-key acceptance; improve timestamp coverage in setup
2021-01-10 02:34:46 -05:00
Jason Ertel
63047b4b85
Add retry logic around salt key acceptance during setup
2021-01-10 00:57:43 -05:00
Josh Patterson
95a9d14832
Merge pull request #2578 from Security-Onion-Solutions/salt/info_logging
...
increase salt logging to info
2021-01-08 16:34:26 -05:00
m0duspwnens
f07e583013
increase salt logging to info
2021-01-08 16:33:38 -05:00
m0duspwnens
ae63b52e7a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-08 15:30:15 -05:00
Jason Ertel
9eedb874fb
Add eval and standalone airgap automations
2021-01-08 12:37:54 -05:00
Jason Ertel
a6f88b2843
Correct eval AMI automation vars
2021-01-07 15:22:34 -05:00
m0duspwnens
86cb1abad4
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-07 15:12:36 -05:00
Jason Ertel
567d80bb01
Update sed to disable sudo password prompt for automated testing
2021-01-07 11:33:59 -05:00
Josh Patterson
d2848b9985
Merge pull request #2561 from Security-Onion-Solutions/automation/so-status
...
add description for exit code 99
2021-01-07 11:24:14 -05:00
m0duspwnens
83e7493691
add description for exit code 99
2021-01-07 11:23:39 -05:00
William Wernert
1ec45fb4ae
[fix] Only show Zeek prompts if Zeek was selected as the MD tool
...
Resolves #900
2021-01-07 10:37:25 -05:00
William Wernert
c1e32ed680
[refactor] Rename MD tool function to be more clear
2021-01-07 10:36:32 -05:00
William Wernert
fa06a38a3b
[refactor] Remove duplicate function
2021-01-07 10:36:01 -05:00
Josh Patterson
d287dd2412
Merge pull request #2557 from Security-Onion-Solutions/automation/so-status
...
Automation/so status
2021-01-07 09:07:12 -05:00
Josh Patterson
8fa2b14c98
Merge pull request #2539 from Security-Onion-Solutions/automation/ssh_prompts
...
Automation/ssh prompts
2021-01-07 09:06:10 -05:00
Jason Ertel
948f900673
Drop password requirement for sudo access during automated tests
2021-01-06 20:39:44 -05:00
m0duspwnens
a5735e6654
return 99 if setup is running
2021-01-06 20:14:42 -05:00
m0duspwnens
ae7c0a26be
add a quiet mode to so-status for automation testing
2021-01-06 18:46:21 -05:00
Jason Ertel
bbdb47703d
Rename automation files to match environment names for consistency
2021-01-06 17:21:46 -05:00
Wes Lambert
7f64d57111
Reserve port for Wazuh API and check if port is already in use
2021-01-06 14:37:28 -05:00
Wes Lambert
e7db1a99bd
Set @timestamp to winlog.systemTime
2021-01-06 14:37:28 -05:00
Mike Reeves
7d25e8a08b
Remove ERSPAN so log doesn't show a warning
2021-01-06 14:37:28 -05:00
Masaya-A
d37023e0f5
Make yum removing unneeded packages
...
Reference: https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2020-09-03/finding/V-204452
2021-01-06 14:37:28 -05:00
William Wernert
9d8fb79d9f
[feat] Reorder network-only prompt
2021-01-06 14:37:27 -05:00
weslambert
c864cc607f
Remove multiple old so-yara-update cron jobs, if needed
2021-01-06 14:37:27 -05:00
William Wernert
80a3d8dcf8
[fix] Fix automation compatibility
2021-01-06 14:37:27 -05:00
William Wernert
ac35a345ff
[fix] Don't prompt to only set up network and then skip if network was previously configured
2021-01-06 14:37:27 -05:00
weslambert
958635b012
Remove old Strelka cron job
2021-01-06 14:37:27 -05:00
William Wernert
6ba11f835d
[fix] Remove condition for stopping SOC, since the parent condition covers what's tested
2021-01-06 14:37:27 -05:00
Jason Ertel
1cc8a78aa5
Only stop SOC if is_manager or is_import
2021-01-06 14:37:27 -05:00
Jason Ertel
7dcd934269
so-fleet-setup doesn't need an interactive terminal to run, remove 'it'
2021-01-06 14:37:27 -05:00
Jason Ertel
bedbd39b82
tcpreplay doesn't need an interactive terminal to run, remove 'it'
2021-01-06 14:37:27 -05:00
Jason Ertel
7d97e3590c
Redirect tcpreplay init output to file
2021-01-06 14:37:27 -05:00
Jason Ertel
bdbc637852
Stop SOC prior to opening the firewall for analysts, this ensures no outside requests can be processed prior to the server rebooting
2021-01-06 14:37:27 -05:00
Jason Ertel
10d04f760d
Use manager internal IP for intra-service comms
2021-01-06 14:37:26 -05:00
Jason Ertel
ebb0e615b9
Fix script typo to correctly run the so-test
2021-01-06 14:37:26 -05:00
Jason Ertel
f20feabda2
Reboot to ensure thehive falls in line before kicking off the test
2021-01-06 14:37:26 -05:00
Jason Ertel
9b40318bfe
Ensure so-test is logged
2021-01-06 14:37:26 -05:00
Jason Ertel
fc44474519
Add eval automation
2021-01-06 14:37:26 -05:00
Jason Ertel
229657f7d2
Use AMI's public IP for external access
2021-01-06 14:37:26 -05:00
Jason Ertel
fb28faa4e3
Monitor interface will not always be bond0 - pull correct value from pillar; Replay test data after automated test installations complete.
2021-01-06 14:37:26 -05:00
weslambert
36ae09ac4a
Merge pull request #2545 from Security-Onion-Solutions/fix/wazuh_port_reservation
...
Reserve port for Wazuh API and check if port is already in use
2021-01-06 11:49:23 -05:00
weslambert
55344725e7
Merge pull request #2544 from Security-Onion-Solutions/fix/winlog_timestamp
...
Set @timestamp to winlog.systemTime
2021-01-06 11:49:01 -05:00
Wes Lambert
875908dc90
Set @timestamp to winlog.systemTime
2021-01-06 16:47:35 +00:00
Wes Lambert
f2b677bfcb
Reserve port for Wazuh API and check if port is already in use
2021-01-06 15:52:10 +00:00
m0duspwnens
48f81d9ac6
reduce setting ssh commands down to 1 function and 1 function call
2021-01-06 08:58:33 -05:00
m0duspwnens
94fd79cd28
originally had sshpass package install reveresed, fixed it here
2021-01-06 08:51:33 -05:00
m0duspwnens
aecc0c025e
fix comment
2021-01-06 08:49:08 -05:00
m0duspwnens
91ad7f26bf
no longer need to pass $automated to compare_versions
2021-01-06 08:45:33 -05:00
m0duspwnens
c65e722164
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-06 08:39:56 -05:00
m0duspwnens
749b21e684
make sure ssh commands get set whether automated install or not
2021-01-05 14:12:43 -05:00
Mike Reeves
1154b533d6
Remove ERSPAN so log doesn't show a warning
2021-01-05 13:56:56 -05:00
m0duspwnens
0f9bf9deb6
make sshcmd, scpcmd, ssh_copy_id_cmd global to so-functions;
2021-01-05 13:49:51 -05:00
m0duspwnens
c93dfa7b33
hardcode automation pw
2021-01-05 11:47:22 -05:00
m0duspwnens
81c4d879eb
first round of testing for automated testing ssh/scp
2021-01-05 10:26:19 -05:00
Mike Reeves
dc429494ac
Merge pull request #2370 from Masaya-A/improve/yum
...
Make yum removing unneeded packages
2021-01-05 09:26:04 -05:00
William Wernert
294601ff64
[feat] Reorder network-only prompt
2021-01-04 16:40:16 -05:00
weslambert
707528d7e8
Merge pull request #2530 from Security-Onion-Solutions/fix/strelka_cron_2
...
Remove multiple old so-yara-update cron jobs, if needed
2021-01-04 16:30:22 -05:00
weslambert
c1e245043e
Remove multiple old so-yara-update cron jobs, if needed
2021-01-04 16:29:32 -05:00
William Wernert
f94e421f4e
[fix] Fix automation compatibility
2021-01-04 14:46:48 -05:00
m0duspwnens
38f985ae22
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-01-04 14:10:41 -05:00
William Wernert
9d674d6d3a
[feat] Add so-monitor-add script
2021-01-04 13:35:14 -05:00
William Wernert
7bfac1e8df
[fix] Don't prompt to only set up network and then skip if network was previously configured
2021-01-04 11:58:25 -05:00
William Wernert
65c3849c7b
Merge pull request #2527 from Security-Onion-Solutions/feature/setup
...
Feature/setup
2021-01-04 11:41:07 -05:00
William Wernert
f8c7413b15
[fix] Move is_iso variable assignment up
2021-01-04 10:37:07 -05:00
weslambert
e51f60f7fa
Merge pull request #2521 from Security-Onion-Solutions/fix/strelka_rule_cron
...
Remove old Strelka cron job
2021-01-04 10:19:50 -05:00
weslambert
535820bfa7
Remove old Strelka cron job
2021-01-04 10:18:32 -05:00
William Wernert
0fa001ed92
[fix] Add more logic to network-only process
2021-01-04 09:27:22 -05:00
William Wernert
a714d36b99
[fix] Remove condition for stopping SOC, since the parent condition covers what's tested
2021-01-02 21:03:15 -05:00
Jason Ertel
455da7ec5d
Only stop SOC if is_manager or is_import
2020-12-31 15:09:22 -05:00
Jason Ertel
4b244645ba
so-fleet-setup doesn't need an interactive terminal to run, remove 'it'
2020-12-31 10:52:59 -05:00
Jason Ertel
6b81419d38
tcpreplay doesn't need an interactive terminal to run, remove 'it'
2020-12-30 22:02:19 -05:00
Jason Ertel
e167bfed20
Redirect tcpreplay init output to file
2020-12-30 18:48:56 -05:00
Jason Ertel
df305c49a6
Stop SOC prior to opening the firewall for analysts, this ensures no outside requests can be processed prior to the server rebooting
2020-12-30 16:33:46 -05:00
William Wernert
3f3fe78322
[fix] Correct reversed logic
2020-12-30 14:01:20 -05:00
Jason Ertel
13f0ddabfc
Use manager internal IP for intra-service comms
2020-12-30 12:02:42 -05:00
Jason Ertel
19d14cf277
Fix script typo to correctly run the so-test
2020-12-30 10:31:04 -05:00
Jason Ertel
a49ddfb887
Reboot to ensure thehive falls in line before kicking off the test
2020-12-29 20:42:50 -05:00
Jason Ertel
827a571db8
Ensure so-test is logged
2020-12-29 17:25:53 -05:00
Jason Ertel
989e2b8b78
Add eval automation
2020-12-29 16:15:10 -05:00
William Wernert
0a57b78900
[feat] Add option to set up only network on an iso
2020-12-29 12:52:21 -05:00
Jason Ertel
74dd2187fb
Use AMI's public IP for external access
2020-12-29 11:16:57 -05:00
Jason Ertel
ea5e25c4a5
Monitor interface will not always be bond0 - pull correct value from pillar; Replay test data after automated test installations complete.
2020-12-29 10:34:31 -05:00
William Wernert
afe40fe87b
Merge pull request #2478 from Security-Onion-Solutions/feature/wait-for-apt
...
Feature/wait for apt
2020-12-28 18:29:20 -05:00
William Wernert
e9a6155e44
Merge branch 'dev' into feature/wait-for-apt
2020-12-28 18:26:38 -05:00
Jason Ertel
deb38844ba
Correct hive init urls
2020-12-28 16:20:33 -05:00
William Wernert
97466957a7
[fix] Fix text printed to whiptail progress bar
2020-12-28 15:06:03 -05:00
William Wernert
cdb6dfcea0
[fix][wip] Fix whiptail output
2020-12-28 14:55:15 -05:00
William Wernert
5059373485
[fix] Change text printed to whiptail progress bar
2020-12-28 14:43:33 -05:00
William Wernert
af62e64852
[fix] Message changes
2020-12-28 14:40:17 -05:00
William Wernert
b03408df6b
[fix] Add missing function
2020-12-28 14:30:34 -05:00
William Wernert
5836d22525
[fix] Change text printed to whiptail progress bar
2020-12-28 14:29:03 -05:00
William Wernert
a4239d7fe4
[fix] Clarify why dpkg lock is needed
2020-12-28 14:20:37 -05:00
William Wernert
5bd15b91ea
[fix] Message formatting changes
2020-12-28 14:18:43 -05:00
William Wernert
a0533dd6b5
[feat] Increase retry_count, decrease wait time, change wording
2020-12-28 14:17:27 -05:00
William Wernert
f7a60a011b
[fix] Message formatting
2020-12-28 14:06:33 -05:00
William Wernert
17160dcdbe
[fix] Don't repeat fail message on last attempt
2020-12-28 14:02:46 -05:00
William Wernert
0dd80a664f
[fix] Only call progress callback if arg passed
2020-12-28 14:00:09 -05:00
William Wernert
1e0525b1ad
[fix] Only call progress callback if arg passed
2020-12-28 13:57:44 -05:00
William Wernert
7050b1fce5
[fix] Don't use same variable for increment and limit
2020-12-28 13:55:03 -05:00
Jason Ertel
7fe0182ede
Refactor so-test and so-tcpreplay to be compatible with SO 2.3.20+; Change hive_init and cortex_init to initialize the cortex and fleet services directly on the manager IP instead of attempting to use the public URL
2020-12-28 11:26:56 -05:00
William Wernert
4d1cb37468
[feat] Add function to wait for dpkg lock
2020-12-28 09:35:51 -05:00
Jason Ertel
8f15d794bc
Silence curl progress output during hive/cortex init
2020-12-24 08:44:28 -05:00
Jason Ertel
baf5be1a3a
Return adequate exit code when init fails; Logs output of init scripts for troubleshooting failed installations
2020-12-23 20:14:46 -05:00
Jason Ertel
9cf150f988
Switch from Jinja syntax to bash
2020-12-23 15:11:43 -05:00
m0duspwnens
7800e90776
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-23 14:53:27 -05:00
Jason Ertel
2d44b69e8d
Refactor hive and cortex init to use wait loops instead of hardcoded sleeps
2020-12-23 12:12:38 -05:00
Jason Ertel
aa5c0a7351
Clarify prompt instructions for so-elastalert-test
2020-12-23 09:37:44 -05:00
Jason Ertel
eef1f49d09
Corrected cortex_init process which was incorrectly attempting to access ES via the external URL; Removing 1-2 minute sleeps during init to see if those are no longer needed
2020-12-22 22:56:01 -05:00
Jason Ertel
cfe5019f51
Add firewall listhogroups and listportgroups commands; Change AMI test defaults to use a custom hostname for cypress access
2020-12-22 17:59:59 -05:00
weslambert
f6a199156b
Merge pull request #2428 from Security-Onion-Solutions/feature/strelka_pillar_repos
...
Support setting rule repos via pillar
2020-12-22 10:38:01 -05:00
Wes Lambert
ac96ded2dc
Support setting rule repos via pillar
2020-12-22 15:36:15 +00:00
Mike Reeves
aa15f3ca4a
Merge pull request #2425 from Security-Onion-Solutions/patch/2.3.21
...
2.3.21 ISO sig
2020-12-22 08:39:00 -05:00
TOoSmOotH
3a3182a51f
2.3.21 ISO sig
2020-12-22 08:32:58 -05:00
Mike Reeves
36207d0440
Merge pull request #2417 from Security-Onion-Solutions/patch/2.3.21
...
2.3.21
2020-12-21 20:02:04 -05:00
Mike Reeves
88bfe7c49c
Update VERIFY_ISO.md
2020-12-21 19:52:31 -05:00
Mike Reeves
7116c2103b
Update Docker Clean
2020-12-21 17:06:14 -05:00
Mike Reeves
b49355d346
Update changes.json
2020-12-21 16:54:55 -05:00
Mike Reeves
aecde2dd54
Update README.md
2020-12-21 16:54:10 -05:00
Mike Reeves
f2d8c7f10d
Update VERSION
2020-12-21 16:53:30 -05:00
Mike Reeves
627d4da432
Merge pull request #2403 from Security-Onion-Solutions/fix/so-analyst-typo
...
fix typo in so-analyst-install warning
2020-12-21 11:48:25 -05:00
m0duspwnens
a18c89d804
fix typo in so-analyst-install warning
2020-12-21 11:42:03 -05:00
m0duspwnens
416d98071d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 11:39:23 -05:00
Mike Reeves
d73f3bb6f8
Update README.md
2020-12-21 10:53:41 -05:00
Mike Reeves
48931116ab
Update VERSION
2020-12-21 10:52:37 -05:00
m0duspwnens
544c473338
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 10:21:48 -05:00
m0duspwnens
5d0cef5e3d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-21 10:21:24 -05:00
m0duspwnens
7653ad56a9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 14:11:21 -05:00
m0duspwnens
1374ac0628
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 13:39:27 -05:00
m0duspwnens
b506f0455f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 12:38:44 -05:00
m0duspwnens
e7a833e890
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-18 10:57:18 -05:00
m0duspwnens
6e202f2ee0
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-17 17:21:01 -05:00
Masaya-A
59ae5f63cf
Make yum removing unneeded packages
...
Reference: https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2020-09-03/finding/V-204452
2020-12-17 22:14:03 +09:00
m0duspwnens
9fd2ab530e
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-16 10:53:35 -05:00
m0duspwnens
fffca7e0d8
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-16 08:59:39 -05:00
m0duspwnens
3a66af0b16
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-14 11:36:03 -05:00
m0duspwnens
32482710db
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-14 10:14:44 -05:00
m0duspwnens
95c068a37f
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-11 14:13:48 -05:00
m0duspwnens
2b412b6a48
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-08 10:41:28 -05:00
m0duspwnens
81e914ab23
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-07 09:38:04 -05:00
m0duspwnens
8983ff994c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-02 13:08:15 -05:00
m0duspwnens
3ee562a243
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-12-01 09:28:27 -05:00
m0duspwnens
ae464c38b2
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-30 11:04:34 -05:00
m0duspwnens
5f0f20918b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-24 14:33:05 -05:00
m0duspwnens
ae7672f395
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-23 13:44:38 -05:00
m0duspwnens
22ebb5af03
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-23 09:29:18 -05:00
m0duspwnens
d178a7c5f3
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-20 10:32:32 -05:00
m0duspwnens
762441fdda
merge
2020-11-20 08:57:48 -05:00
m0duspwnens
868286a58a
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2020-11-19 15:06:10 -05:00
m0duspwnens
146c1a4d75
fix typos of minon to minion
2020-11-19 15:06:06 -05:00