Compare commits

..

52 Commits

Author SHA1 Message Date
Mike Reeves
b31d38e734 Merge pull request #12463 from Security-Onion-Solutions/dev
2.3.290
2024-02-29 14:07:11 -05:00
Mike Reeves
b1db4137d0 Merge pull request #12462 from Security-Onion-Solutions/2.3.290
2.3.290
2024-02-29 09:15:41 -05:00
Mike Reeves
44ef164713 2.3.290 2024-02-29 09:08:37 -05:00
Jason Ertel
43f7dce297 Merge pull request #12407 from Security-Onion-Solutions/jertel/mergem
Jertel/mergem
2024-02-21 13:18:08 -05:00
Jason Ertel
4e4a4686f1 Merge branch 'master' into jertel/mergem 2024-02-21 13:14:29 -05:00
Jason Ertel
b5f44e48ab Merge pull request #12403 from Security-Onion-Solutions/jertel/disctemplate
add message at top for clickable link
2024-02-21 12:42:04 -05:00
Jason Ertel
a44448519b add message at top for clickable link 2024-02-21 10:53:50 -05:00
Jason Ertel
6245ee9a5b Merge branch 'master' into jertel/disctemplate 2024-02-21 10:43:28 -05:00
Jason Ertel
49ca970076 add message at top for clickable link 2024-02-21 10:41:28 -05:00
Jason Ertel
f49fb7cbae Merge pull request #12401 from Security-Onion-Solutions/jertel/disctemplate
template improvements
2024-02-21 10:39:03 -05:00
Jason Ertel
7692c9be53 template improvements 2024-02-21 10:36:07 -05:00
Jason Ertel
25ef12cdc5 Merge pull request #12395 from Security-Onion-Solutions/jertel/mergemaster
Jertel/mergemaster
2024-02-21 07:18:22 -05:00
Jason Ertel
2967adca90 Merge branch 'master' into jertel/mergemaster 2024-02-20 16:56:14 -05:00
Jason Ertel
d198458366 Merge pull request #12392 from Security-Onion-Solutions/jertel/glm_master
thread locking
2024-02-20 16:55:16 -05:00
Jason Ertel
9e98b409a5 thread locking 2024-02-20 16:00:41 -05:00
Doug Burks
ba8f729976 Merge pull request #12335 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.290
2024-02-09 11:18:59 -05:00
Doug Burks
5b67795c23 Update soup for 2.3.290 2024-02-09 11:12:43 -05:00
Jason Ertel
483bf60ae3 Merge pull request #12233 from Security-Onion-Solutions/jertel/23guidelines
Update 2-4.yml
2024-01-23 10:07:35 -05:00
Doug Burks
1a9350f60b Update 2-4.yml 2024-01-23 10:05:59 -05:00
Doug Burks
f4afda0975 Merge pull request #12232 from Security-Onion-Solutions/dougburks-patch-1
Improve Github Discussions template for 2.4 category
2024-01-23 09:57:40 -05:00
Doug Burks
137372337c Update 2-4.yml 2024-01-23 09:51:45 -05:00
Mike Reeves
1521532c60 Merge pull request #11880 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update VERSION
2023-11-28 15:33:48 -05:00
Mike Reeves
ada32967dc Update VERSION 2023-11-28 15:30:49 -05:00
Mike Reeves
d5d2b5fbc7 Merge pull request #11879 from Security-Onion-Solutions/dev
2.3.280
2023-11-28 15:21:56 -05:00
Mike Reeves
84d6fcb752 Merge pull request #11878 from Security-Onion-Solutions/2.3.280
2.3.280
2023-11-28 15:00:34 -05:00
Mike Reeves
de9e9a2716 2.3.280 2023-11-28 14:58:25 -05:00
Josh Patterson
cec6cff19d Merge pull request #11874 from Security-Onion-Solutions/23souphs
so-nginx watch managerssl to restart if changed
2023-11-27 12:48:06 -05:00
m0duspwnens
7311d6480c so-nginx watch managerssl to restart if changed 2023-11-27 12:15:09 -05:00
Josh Patterson
f967c8e362 Merge pull request #11873 from Security-Onion-Solutions/23souphs
enable highstate after starting minion
2023-11-27 11:12:45 -05:00
m0duspwnens
cfad6414d2 enable highstate after starting minion 2023-11-27 11:10:39 -05:00
Josh Patterson
0fdaed9cf7 Merge pull request #11864 from Security-Onion-Solutions/import/suriinterface
suricata interface None if so-import
2023-11-22 10:42:43 -05:00
m0duspwnens
1dc88781f1 suricata interface None if so-import 2023-11-22 10:11:34 -05:00
Mike Reeves
0cfb8b0816 Merge pull request #11834 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update signing_policies.conf
2023-11-20 15:59:21 -05:00
Mike Reeves
c0968d3843 Update signing_policies.conf 2023-11-20 15:57:29 -05:00
Mike Reeves
3b133e87cd Merge pull request #11831 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update signing_policies.conf
2023-11-20 15:19:42 -05:00
Mike Reeves
fee9b61ce9 Update soup 2023-11-20 15:14:25 -05:00
Mike Reeves
57612c69fe Update signing_policies.conf 2023-11-20 15:11:50 -05:00
Mike Reeves
94accb0e8c Update signing_policies.conf 2023-11-20 15:09:13 -05:00
Josh Patterson
3b8d1d470e Merge pull request #11798 from Security-Onion-Solutions/m0duspwnens-patch-1
Update soup
2023-11-15 15:23:46 -05:00
Josh Patterson
c624a44b0e Update soup
add quote
2023-11-15 15:19:54 -05:00
weslambert
bc509a0aa9 Merge pull request #11772 from Security-Onion-Solutions/upgrade/elastic_8_10_4
Elastic 8.10.4
2023-11-13 09:36:49 -05:00
Doug Burks
ee0ef3217f Merge pull request #11771 from Security-Onion-Solutions/dougburks-patch-1
Add EOL warning to README.md
2023-11-13 09:18:50 -05:00
weslambert
18e319cbe3 Elastic 8.10.4 2023-11-13 09:17:33 -05:00
Doug Burks
3316e1261d Add EOL warning to README.md 2023-11-13 09:16:25 -05:00
weslambert
b7cf44466c Elastic 8.10.4 2023-11-13 09:16:23 -05:00
Mike Reeves
e321aa52a5 Merge pull request #11749 from Security-Onion-Solutions/TOoSmOotH-patch-6
Update soup
2023-11-09 10:49:34 -05:00
Mike Reeves
07df045e79 Update soup 2023-11-09 10:38:53 -05:00
Mike Reeves
7b11ddb032 Update soup 2023-11-09 10:25:16 -05:00
Jorge Reyes
ac4428940e Merge pull request #11561 from Security-Onion-Solutions/2.3/zeek6
Zeek 6 upgrade
2023-10-23 09:25:21 -04:00
reyesj2
a9457d5f53 Remove external community-id replaced with Zeek 6 built in community-id.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
2023-10-17 16:02:16 -04:00
Jason Ertel
3672701dde Merge pull request #11506 from Security-Onion-Solutions/jertel-patch-1
Update VERSION
2023-10-11 09:26:32 -04:00
Jason Ertel
07ed2cb3da Update VERSION 2023-10-10 21:35:48 -04:00
14 changed files with 121 additions and 51 deletions

View File

@@ -1,20 +1,17 @@
body:
- type: markdown
attributes:
value: >
value: |
⚠️ This category is solely for conversations related to Security Onion 2.4 ⚠️
If your organization needs more immediate, enterprise grade professional support, with one-on-one virtual meetings and screensharing, contact us via our website: https://securityonion.com/support
- type: dropdown
attributes:
label: Version
description: Which version of Security Onion 2.4.x are you asking about?
options:
-
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4 Pre-release (Beta, Release Candidate)
- 2.4.10
- 2.4.20
- 2.4.30
@@ -178,33 +175,16 @@ body:
- type: textarea
attributes:
label: Detail
description: Please read the placeholder and then provide detailed information to help us help you.
placeholder: >-
STOP! Please read these guidelines in their entirety before typing!
Community Support is considered best effort and there are no guarantees and no SLAs. If you need private, priority, or enterprise support, please consider purchasing support from Security Onion Solutions.
Please review the Github Community Guidelines (see link on the right side of the page).
Please be patient, courteous, and respectful. Disrespectful messages can result in being banned.
Before posting for help, check the Help, FAQ, and other sections of the documentation (https://docs.securityonion.net/) to see if your question has already been answered there.
Please do not tag an individual in a discussion unless that individual has already volunteered to help you in that discussion.
When creating your discussion, please put a relevant and descriptive title in the Title field and avoid generic titles like Help. When copying text from your Security Onion deployment to the discussion, please copy as plain text when possible rather than taking a screenshot of the text. This allows others to search for and find your text.
Avoid typing in ALL CAPS as this looks like YELLING!
If you need to include a large section of output, please do so as an attached file or Github gist rather than including the output directly in the reply itself.
If you attach files, please make sure they are plain text format. No Word docs or PDFs please.
description: Please read our discussion guidelines at https://github.com/Security-Onion-Solutions/securityonion/discussions/1720 and then provide detailed information to help us help you.
placeholder: |-
STOP! Before typing, please read our discussion guidelines at https://github.com/Security-Onion-Solutions/securityonion/discussions/1720 in their entirety!
If your organization needs more immediate, enterprise grade professional support, with one-on-one virtual meetings and screensharing, contact us via our website: https://securityonion.com/support
validations:
required: true
- type: checkboxes
attributes:
label: Guidelines
options:
- label: I have read the above statement and can confirm my post is relevant to Security Onion 2.4.
- label: I have read the discussion guidelines at https://github.com/Security-Onion-Solutions/securityonion/discussions/1720 and assert that I have followed the guidelines.
required: true

42
.github/workflows/lock-threads.yml vendored Normal file
View File

@@ -0,0 +1,42 @@
name: 'Lock Threads'
on:
schedule:
- cron: '50 1 * * *'
workflow_dispatch:
permissions:
issues: write
pull-requests: write
discussions: write
concurrency:
group: lock-threads
jobs:
close-threads:
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
steps:
- uses: actions/stale@v5
with:
days-before-issue-stale: -1
days-before-issue-close: 60
stale-issue-message: "This issue is stale because it has been inactive for an extended period. Stale issues convey that the issue, while important to someone, is not critical enough for the author, or other community members to work on, sponsor, or otherwise shepherd the issue through to a resolution."
close-issue-message: "This issue was closed because it has been stale for an extended period. It will be automatically locked in 30 days, after which no further commenting will be available."
days-before-pr-stale: 45
days-before-pr-close: 60
stale-pr-message: "This PR is stale because it has been inactive for an extended period. The longer a PR remains stale the more out of date with the main branch it becomes."
close-pr-message: "This PR was closed because it has been stale for an extended period. It will be automatically locked in 30 days. If there is still a commitment to finishing this PR re-open it before it is locked."
lock-threads:
runs-on: ubuntu-latest
steps:
- uses: jertel/lock-threads@main
with:
include-discussion-currently-open: true
discussion-inactive-days: 90
issue-inactive-days: 30
pr-inactive-days: 30

View File

@@ -2,6 +2,20 @@
Security Onion 2.3 is here!
## End Of Life Warning
Security Onion 2.3 reaches End Of Life (EOL) on April 6, 2024:
https://blog.securityonion.net/2023/10/6-month-eol-notice-for-security-onion-23.html
For new installations, please see the 2.4 branch of this repo:
https://github.com/Security-Onion-Solutions/securityonion/tree/2.4/main
If you have an existing 2.3 installation and would like to migrate to 2.4, please see:
https://docs.securityonion.net/en/2.4/appendix.html
## Screenshots
Alerts

View File

@@ -1,18 +1,18 @@
### 2.3.270-20231006 ISO image built on 2023/10/06
### 2.3.290-20240229 ISO image built on 2024/02/29
### Download and Verify
2.3.270-20231006 ISO image:
https://download.securityonion.net/file/securityonion/securityonion-2.3.270-20231006.iso
2.3.290-20240229 ISO image:
https://download.securityonion.net/file/securityonion/securityonion-2.3.290-20240229.iso
MD5: 3FC7A37EA402A5F0C6609D7431387575
SHA1: 979851603E431EE9670A1576E5DCCD838CEDA294
SHA256: 34F72EDEA9A62E1545347A31DEDEDD099D824466EC52B8674ACC7DB6D7E8B943
MD5: D2A7BBDA25F311B7944A95655CC439CE
SHA1: BAD2A67119C6F73B6472E1A31B9C157A60A074B5
SHA256: FD611421C3B41BA267BA7A57B8FAFB29B0B59435D0A796D686C0D3BDD36AFF7D
Signature for ISO image:
https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.270-20231006.iso.sig
https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.290-20240229.iso.sig
Signing key:
https://raw.githubusercontent.com/Security-Onion-Solutions/securityonion/master/KEYS
@@ -26,22 +26,22 @@ wget https://raw.githubusercontent.com/Security-Onion-Solutions/securityonion/ma
Download the signature file for the ISO:
```
wget https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.270-20231006.iso.sig
wget https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.290-20240229.iso.sig
```
Download the ISO image:
```
wget https://download.securityonion.net/file/securityonion/securityonion-2.3.270-20231006.iso
wget https://download.securityonion.net/file/securityonion/securityonion-2.3.290-20240229.iso
```
Verify the downloaded ISO image using the signature file:
```
gpg --verify securityonion-2.3.270-20231006.iso.sig securityonion-2.3.270-20231006.iso
gpg --verify securityonion-2.3.290-20240229.iso.sig securityonion-2.3.290-20240229.iso
```
The output should show "Good signature" and the Primary key fingerprint should match what's shown below:
```
gpg: Signature made Thu 21 Sep 2023 10:43:13 AM EDT using RSA key ID FE507013
gpg: Signature made Wed 28 Feb 2024 04:11:05 PM EST using RSA key ID FE507013
gpg: Good signature from "Security Onion Solutions, LLC <info@securityonionsolutions.com>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.

View File

@@ -1 +1 @@
2.3.270
2.3.290

View File

@@ -42,12 +42,13 @@ zeek:
- frameworks/files/hash-all-files
- frameworks/files/detect-MHR
- policy/frameworks/notice/extend-email/hostnames
- policy/frameworks/notice/community-id
- policy/protocols/conn/community-id-logging
- ja3
- hassh
- intel
- cve-2020-0601
- securityonion/bpfconf
- securityonion/communityid
- securityonion/file-extraction
- oui-logging
- icsnpp-modbus

View File

@@ -37,7 +37,7 @@ x509_signing_policies:
- ST: Utah
- L: Salt Lake City
- basicConstraints: "critical CA:false"
- keyUsage: "critical keyEncipherment"
- keyUsage: "critical keyEncipherment, digitalSignature"
- subjectKeyIdentifier: hash
- authorityKeyIdentifier: keyid,issuer:always
- extendedKeyUsage: serverAuth

View File

@@ -580,6 +580,8 @@ preupgrade_changes() {
[[ "$INSTALLEDVERSION" == 2.3.240 ]] && up_to_2.3.250
[[ "$INSTALLEDVERSION" == 2.3.250 ]] && up_to_2.3.260
[[ "$INSTALLEDVERSION" == 2.3.260 ]] && up_to_2.3.270
[[ "$INSTALLEDVERSION" == 2.3.270 ]] && up_to_2.3.280
[[ "$INSTALLEDVERSION" == 2.3.280 ]] && up_to_2.3.290
true
}
@@ -612,6 +614,8 @@ postupgrade_changes() {
[[ "$POSTVERSION" == 2.3.240 ]] && post_to_2.3.250
[[ "$POSTVERSION" == 2.3.250 ]] && post_to_2.3.260
[[ "$POSTVERSION" == 2.3.260 ]] && post_to_2.3.270
[[ "$POSTVERSION" == 2.3.270 ]] && post_to_2.3.280
[[ "$POSTVERSION" == 2.3.280 ]] && post_to_2.3.290
true
}
@@ -772,6 +776,21 @@ post_to_2.3.270() {
POSTVERSION=2.3.270
}
post_to_2.3.280() {
salt-call state.apply ca queue=True
stop_salt_minion
mv /etc/pki/managerssl.crt /etc/pki/managerssl.crt.old
mv /etc/pki/managerssl.key /etc/pki/managerssl.key.old
systemctl_func "start" "salt-minion"
enable_highstate
POSTVERSION=2.3.280
}
post_to_2.3.290() {
echo "Nothing to do for .290"
POSTVERSION=2.3.290
}
stop_salt_master() {
# kill all salt jobs across the grid because the hang indefinitely if they are queued and salt-master restarts
set +e
@@ -1137,6 +1156,16 @@ up_to_2.3.270() {
INSTALLEDVERSION=2.3.270
}
up_to_2.3.280() {
echo "Upgrading to 2.3.280"
INSTALLEDVERSION=2.3.280
}
up_to_2.3.290() {
echo "Upgrading to 2.3.290"
INSTALLEDVERSION=2.3.290
}
verify_upgradespace() {
CURRENTSPACE=$(df -BG / | grep -v Avail | awk '{print $4}' | sed 's/.$//')
if [ "$CURRENTSPACE" -lt "10" ]; then
@@ -1720,8 +1749,12 @@ if [[ -z $UNATTENDED ]]; then
SOUP - Security Onion UPdater
**WARNING** Security Onion 2.3 reaches End Of Life (EOL) on April 6, 2024.
Please make plans to migrate to Security Onion 2.4:
https://blog.securityonion.net/2023/10/6-month-eol-notice-for-security-onion-23.html
Please review the following for more information about the update process and recent updates:
https://docs.securityonion.net/soup
https://docs.securityonion.net/en/2.3/soup.html
https://blog.securityonion.net
EOF

View File

@@ -59,7 +59,7 @@ update() {
IFS=$'\r\n' GLOBIGNORE='*' command eval 'LINES=($(cat $1))'
for i in "${LINES[@]}"; do
RESPONSE=$({{ ELASTICCURL }} -X PUT "localhost:5601/api/saved_objects/config/8.8.2" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d " $i ")
RESPONSE=$({{ ELASTICCURL }} -X PUT "localhost:5601/api/saved_objects/config/8.10.4" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d " $i ")
echo $RESPONSE; if [[ "$RESPONSE" != *"\"success\":true"* ]] && [[ "$RESPONSE" != *"updated_at"* ]] ; then RETURN_CODE=1;fi
done

View File

@@ -1 +1 @@
{"attributes": {"buildNum": 39457,"defaultIndex": "2289a0c0-6970-11ea-a0cd-ffa0f6a1bc29","defaultRoute": "/app/dashboards#/view/a8411b30-6d03-11ea-b301-3d6c35840645","discover:sampleSize": 100,"theme:darkMode": true,"timepicker:timeDefaults": "{\n \"from\": \"now-24h\",\n \"to\": \"now\"\n}"},"coreMigrationVersion": "8.8.2","id": "8.8.2","references": [],"type": "config","updated_at": "2021-10-10T10:10:10.105Z","version": "WzI5NzUsMl0="}
{"attributes": {"buildNum": 39457,"defaultIndex": "2289a0c0-6970-11ea-a0cd-ffa0f6a1bc29","defaultRoute": "/app/dashboards#/view/a8411b30-6d03-11ea-b301-3d6c35840645","discover:sampleSize": 100,"theme:darkMode": true,"timepicker:timeDefaults": "{\n \"from\": \"now-24h\",\n \"to\": \"now\"\n}"},"coreMigrationVersion": "8.10.4","id": "8.10.4","references": [],"type": "config","updated_at": "2021-10-10T10:10:10.105Z","version": "WzI5NzUsMl0="}

View File

@@ -118,6 +118,10 @@ so-nginx:
- watch:
- file: nginxconf
- file: nginxconfdir
{% if grains.role in ['so-manager', 'so-managersearch', 'so-eval', 'so-standalone', 'so-import', 'so-fleet'] %}
- x509: managerssl_key
- x509: managerssl_crt
{% endif %}
- require:
- file: nginxconf
{% if grains.role in ['so-manager', 'so-managersearch', 'so-eval', 'so-standalone', 'so-import', 'so-fleet'] %}

View File

@@ -1,6 +1,6 @@
{% load_yaml as afpacket %}
af-packet:
- interface: {{ salt['pillar.get']('sensor:interface', 'bond0') }}
- interface: {{ None if grains.role == 'so-import' else salt['pillar.get']('sensor:interface', 'bond0') }}
cluster-id: 59
cluster-type: cluster_flow
defrag: yes
@@ -8,8 +8,4 @@ af-packet:
threads: {{ salt['pillar.get']('sensor:suriprocs', salt['pillar.get']('sensor:suripins') | length) }}
tpacket-v3: yes
ring-size: {{ salt['pillar.get']('sensor:suriringsize', '5000') }}
- interface: default
#threads: auto
#use-mmap: no
#tpacket-v3: yes
{% endload %}

Binary file not shown.

Binary file not shown.