Doug Burks
e54ece06a2
Merge pull request #7106 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-03 16:25:04 -05:00
Mike Reeves
cc986c8d7c
Merge pull request #7105 from Security-Onion-Solutions/23100hotfix2
...
2.3.100 Hotfix 2
2022-02-03 16:04:06 -05:00
Mike Reeves
b7732fb14a
2.3.100 Hotfix 2
2022-02-03 15:58:26 -05:00
Mike Reeves
6f03662120
Merge pull request #7102 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update HOTFIX
2022-02-03 15:08:52 -05:00
Mike Reeves
4f2952105e
Update HOTFIX
2022-02-03 15:06:18 -05:00
Josh Patterson
b34d0d7f7a
Merge pull request #7100 from Security-Onion-Solutions/100_hotfix_2
...
100 hotfix 2
2022-02-03 13:15:37 -05:00
m0duspwnens
797d769661
use actual hostname in logstash:nodes pillar
2022-02-03 10:36:18 -05:00
Mike Reeves
bbd2f0da2b
Merge pull request #7094 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update distributed-airgap-manager
2022-02-03 10:36:09 -05:00
Mike Reeves
5c39162aef
Update distributed-airgap-sensor
2022-02-03 10:34:55 -05:00
Mike Reeves
d8a4301533
Update distributed-airgap-manager
2022-02-03 10:34:12 -05:00
Doug Burks
c39047666b
Merge pull request #7082 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-02 16:38:27 -05:00
Mike Reeves
5c75bb8e7a
Merge pull request #7080 from Security-Onion-Solutions/23100hotfix
...
2.3.100 Hotfix
2022-02-02 16:30:46 -05:00
Mike Reeves
83683ec27e
2.3.100 Hotfix
2022-02-02 16:23:51 -05:00
Mike Reeves
b94cae0176
2.3.100 Hotfix
2022-02-02 16:22:44 -05:00
Mike Reeves
fc0824ceb0
2.3.100 Hotfix
2022-02-02 16:20:49 -05:00
Mike Reeves
73a43f3816
Merge pull request #7069 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-02-02 09:57:26 -05:00
Mike Reeves
8152aec22e
Update HOTFIX
2022-02-02 09:49:19 -05:00
Mike Reeves
0e28e1e4cb
Merge pull request #7066 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2022-02-02 09:22:00 -05:00
Josh Patterson
13f87e4654
Merge pull request #7067 from Security-Onion-Solutions/m0duspwnens-patch-2.3.100
...
FIX: ssl state and manager hostname with uppercase
2022-02-02 09:21:54 -05:00
Josh Patterson
a02fb37493
Update init.sls
2022-02-02 09:18:02 -05:00
Mike Reeves
eaeed07fd4
Update acng.conf
2022-02-02 09:12:29 -05:00
Mike Reeves
943edd0303
Merge pull request #7042 from Security-Onion-Solutions/dev
...
2.3.100 Release
2022-01-31 16:29:57 -05:00
Mike Reeves
b49524a293
Merge pull request #7041 from Security-Onion-Solutions/23100release
...
2.3.100 Release
2022-01-31 14:07:02 -05:00
Mike Reeves
6dc8415af5
2.3.100 Release
2022-01-31 14:05:22 -05:00
Doug Burks
7927534279
Merge pull request #7040 from Security-Onion-Solutions/dougburks-patch-1
...
Update version from 2.3.91 to 2.3.100
2022-01-31 13:32:05 -05:00
Doug Burks
e0f6b9af3a
Update version from 2.3.91 to 2.3.100
2022-01-31 13:27:45 -05:00
weslambert
6a2111c2ae
Merge pull request #7037 from Security-Onion-Solutions/fix/revert_zeek_dns_answers
...
Revert back to dns.answers for now
2022-01-31 09:55:22 -05:00
weslambert
367b59188b
Revert back to dns.answers for now
2022-01-31 09:54:39 -05:00
Josh Patterson
d3fc61e557
Merge pull request #7035 from Security-Onion-Solutions/soup_salt_repo
...
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager…
2022-01-31 09:05:45 -05:00
m0duspwnens
4dd0ce9f2c
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager and managerupdates is enabled
2022-01-31 09:01:18 -05:00
Josh Patterson
0c5b4c6070
Merge pull request #7033 from Security-Onion-Solutions/receiver_grafana
...
Receiver grafana
2022-01-31 08:41:56 -05:00
Josh Patterson
a8983dd895
Merge pull request #7028 from Security-Onion-Solutions/soup_salt_repo
...
Soup salt repo
2022-01-31 08:21:17 -05:00
m0duspwnens
e189f10a1b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into soup_salt_repo
2022-01-29 11:04:07 -05:00
m0duspwnens
a90660c07b
ensure salt-latest.repo is absent, salt.minion state include repo.client
2022-01-29 11:04:03 -05:00
Mike Reeves
bb87c85e07
Merge pull request #7027 from Security-Onion-Solutions/fix/soup-kibana
...
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 10:07:36 -05:00
Doug Burks
bc0a362b39
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 08:02:56 -05:00
m0duspwnens
3aee8656d4
fix %} - add redis to receiver telegraf
2022-01-28 17:45:12 -05:00
m0duspwnens
980a1a0c3d
add redis to receiver telegraf
2022-01-28 17:44:04 -05:00
m0duspwnens
bf26ae8e41
add receiver to allowed dashboards
2022-01-28 17:32:53 -05:00
m0duspwnens
da3e1e402a
add receiver dashboard grafana
2022-01-28 17:27:58 -05:00
m0duspwnens
1cd1ad9214
add inputs for so-receiver to telegraf conf
2022-01-28 17:18:31 -05:00
Josh Patterson
ddba4a5fe5
Merge pull request #7024 from Security-Onion-Solutions/soup_receiver
...
Soup receiver
2022-01-28 17:01:04 -05:00
m0duspwnens
c8b1e6f501
remove -X from UPGRADECOMMAND so salt-minion starts after upgrade
2022-01-28 15:49:53 -05:00
m0duspwnens
c45efebc7f
Merge remote-tracking branch 'remotes/origin/dev' into soup_receiver
2022-01-28 15:27:27 -05:00
m0duspwnens
014696f62f
fix receiver append to assigned_hostgroups.local.map.yaml
2022-01-28 15:26:37 -05:00
m0duspwnens
6b18551dd1
skip applying repo.client if airgap and saltupgrade prior to yum clean all
2022-01-28 14:39:10 -05:00
weslambert
4ecf4ab253
Merge pull request #7020 from Security-Onion-Solutions/feature/dash_updates
...
EG and HL Dashboard Updates
2022-01-28 13:19:02 -05:00
m0duspwnens
75b8d6a0c5
ensure /etc/yum.repos.d/securityonioncache.repo is absent if global:managerupdate = 0
2022-01-28 13:09:48 -05:00
weslambert
5142e6ccc7
Update so-kibana-config-load
2022-01-28 13:01:33 -05:00
Wes Lambert
3b76c2421c
Update to allow for passing HL saved objects
2022-01-28 17:59:34 +00:00
m0duspwnens
e82c6a2393
default for managerupdate should be int not a string
2022-01-28 12:50:58 -05:00
m0duspwnens
905ca35e93
use sed instead of echo
2022-01-28 11:19:54 -05:00
m0duspwnens
3977146a16
add receiver to firewall files during soup
2022-01-28 10:36:30 -05:00
Josh Patterson
5a37b14809
Merge pull request #7017 from Security-Onion-Solutions/issue/7016
...
dont apply wazuh state on sensors if it is disabled globally
2022-01-28 09:33:34 -05:00
m0duspwnens
15c29bda74
dont apply wazuh state on sensors if it is disabled globally - https://github.com/Security-Onion-Solutions/securityonion/issues/7016
2022-01-28 09:31:02 -05:00
Josh Patterson
d0186c8c1b
Merge pull request #7011 from Security-Onion-Solutions/fix/reinstall
...
https://github.com/Security-Onion-Solutions/securityonion/issues/7010
2022-01-27 16:40:37 -05:00
Jason Ertel
ac21bd1e29
Merge pull request #7009 from Security-Onion-Solutions/kilo
...
Add new abbreviated result limit param
2022-01-27 15:55:42 -05:00
Jason Ertel
14c587fca2
Add new abbreviated result limit param
2022-01-27 15:51:02 -05:00
m0duspwnens
6cc8e4355e
exclude salt ERROR seen during reinstall
2022-01-27 15:31:42 -05:00
m0duspwnens
e63f35a223
change to test
2022-01-27 15:19:33 -05:00
weslambert
69689b470b
Merge pull request #7005 from Security-Onion-Solutions/fix/revert_cases_field_limit
...
Revert field limit from testing
2022-01-27 11:33:31 -05:00
weslambert
fc0a5bce86
Revert field limit from testing
2022-01-27 11:18:35 -05:00
weslambert
39257df396
Merge pull request #7004 from Security-Onion-Solutions/fix/revert_dtc
...
Revert changes to common template
2022-01-27 11:15:50 -05:00
weslambert
60a0204975
Revert changes to common template
2022-01-27 11:02:47 -05:00
William Wernert
c6b11f4e05
Merge pull request #7001 from Security-Onion-Solutions/fix/so-rule-string-split
...
Fix error message printing in so-rule
2022-01-26 16:08:00 -05:00
William Wernert
4532de368a
Fix error message printing in so-rule
2022-01-26 16:04:45 -05:00
m0duspwnens
9e2278a199
Merge remote-tracking branch 'remotes/origin/dev' into fix/reinstall
2022-01-26 15:48:46 -05:00
weslambert
e303fb12cf
Merge pull request #7000 from Security-Onion-Solutions/fix/zeek_dns_answers_pipeline
...
Fix Zeek field name so it doesn't conflict with mapping of other dns.…
2022-01-26 15:04:12 -05:00
weslambert
8f0a327cb5
Fix Zeek field name so it doesn't conflict with mapping of other dns.answers fields
2022-01-26 15:02:59 -05:00
weslambert
bdc5e89822
Merge pull request #6999 from Security-Onion-Solutions/fix/case_mapping_changes_temp
...
Mapping changes for case index
2022-01-26 14:59:45 -05:00
weslambert
1b3e7f9d79
Temp changes while adjusting mapping
2022-01-26 14:57:16 -05:00
Josh Patterson
4f30d43611
Merge pull request #6998 from Security-Onion-Solutions/es_binds
...
mount repo dir in container same as defined on host
2022-01-26 13:59:17 -05:00
m0duspwnens
c80adc0430
mount repo dir in container same as defined on host
2022-01-26 13:42:56 -05:00
weslambert
e77648c475
Merge pull request #6994 from Security-Onion-Solutions/feature/dtc
...
Additional DTC changes
2022-01-26 12:22:48 -05:00
Jason Ertel
c2636036ee
Merge pull request #6995 from Security-Onion-Solutions/kilo
...
store related event data as a flattened object blob
2022-01-26 12:21:02 -05:00
Wes Lambert
e10749a495
Additional changes to template to accomodate default fields and keyword subfield
2022-01-26 17:16:29 +00:00
Jason Ertel
ed9b74dc33
store related event data as a flattened object blob
2022-01-26 12:16:05 -05:00
m0duspwnens
2aa19b78da
dont remove ca-certificates.crt
2022-01-26 11:27:35 -05:00
m0duspwnens
1337af9d69
more dupes
2022-01-26 11:07:06 -05:00
m0duspwnens
a0e493a186
remove dupe ids
2022-01-26 10:50:35 -05:00
m0duspwnens
a43fb293fc
remove role logic
2022-01-26 10:26:52 -05:00
m0duspwnens
8aa002b82e
add states to remove ca and ssl keys and certs and call them during reinstall.
2022-01-26 09:33:19 -05:00
m0duspwnens
8ce0f5b7be
log removal of root cron
2022-01-26 08:31:37 -05:00
Josh Patterson
26e03ccad2
Merge pull request #6978 from Security-Onion-Solutions/es_binds
...
allow for path.repo mounts for elasticsearch
2022-01-25 16:13:49 -05:00
m0duspwnens
dd00e3babc
use .get since repo may not exist
2022-01-25 13:18:21 -05:00
m0duspwnens
5d2b3992e2
dont need to set ES_PATH_REPO
2022-01-25 13:11:53 -05:00
m0duspwnens
7b6eeac03f
dnt mount under /repo in the container
2022-01-25 13:08:46 -05:00
m0duspwnens
00e17d5c78
put repos in /repo in es container
2022-01-25 13:03:54 -05:00
m0duspwnens
a17e1aa87a
930 for group
2022-01-25 13:00:04 -05:00
m0duspwnens
4423e93880
prevent path.repo from being put in elasticsearch.yml if the symlink doesnt exist
2022-01-25 12:57:05 -05:00
m0duspwnens
e62de2934c
fix test for es repo
2022-01-25 12:24:03 -05:00
m0duspwnens
a92e2a917b
change repos to repo
2022-01-25 10:53:28 -05:00
m0duspwnens
a72f12c4c7
add path.repo mount if symlink exists
2022-01-25 10:50:00 -05:00
Josh Patterson
9a45a9799b
Merge pull request #6974 from Security-Onion-Solutions/issue/6599
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6599
2022-01-25 09:11:33 -05:00
weslambert
ba52bd3835
Update template with syntax fixes
2022-01-25 08:56:03 -05:00
m0duspwnens
edd8709cdd
remove export LC_CTYPE="en_US.UTF-8" from soup
2022-01-24 19:42:56 -05:00
m0duspwnens
d6fc436d49
copy files to default salt base
2022-01-24 19:30:34 -05:00
m0duspwnens
82e2b2b611
dont escape raw and endraw
2022-01-24 17:03:25 -05:00
m0duspwnens
d083338350
adding --local
2022-01-24 16:46:29 -05:00
m0duspwnens
e3f1b456e6
add raw end raw back
2022-01-24 16:09:15 -05:00
m0duspwnens
268e07e2a2
remove jinja from soup scripts
2022-01-24 15:49:55 -05:00
Doug Burks
80b7487d45
Merge pull request #6968 from Security-Onion-Solutions/dougburks-patch-1
...
Update CONTRIBUTING.md with warning about more involved PRs
2022-01-24 10:39:40 -05:00
Jason Ertel
4ab7a6a079
Merge pull request #6967 from Security-Onion-Solutions/kilo
...
Copyright year and format update
2022-01-24 10:39:31 -05:00
Doug Burks
5f67dfd432
Update CONTRIBUTING.md
2022-01-24 10:36:22 -05:00
Jason Ertel
eefcc929c2
Update copyright pattern to match other repos
2022-01-24 10:09:23 -05:00
Jason Ertel
a4d2807fbb
Switch to httpcase for consistency
2022-01-24 09:45:07 -05:00
Doug Burks
fb5bff3913
Merge pull request #6956 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typos in ssh_warning
2022-01-24 09:39:40 -05:00
Jason Ertel
7c22f46a55
Update copyright year for 2022
2022-01-24 09:35:29 -05:00
Doug Burks
b103420100
fix typo in so-setup
2022-01-22 10:25:37 -05:00
Doug Burks
304ef64bc8
fix another typo in ssh_warning
2022-01-22 10:24:36 -05:00
Doug Burks
1e14e2977f
Fix typo in ssh_warning
2022-01-22 10:21:14 -05:00
Josh Patterson
86cfa07af9
Merge pull request #6955 from Security-Onion-Solutions/issue/6810
...
Issue/6810
2022-01-21 17:37:59 -05:00
m0duspwnens
32080b02e4
dont use logCmd for moving repo files after centos-release update
2022-01-21 17:28:40 -05:00
m0duspwnens
58c5db3bf6
reorder process in securityonion_repo function
2022-01-21 15:15:48 -05:00
m0duspwnens
9e5fb458b4
update saltstack repo location for securityonioncache.repo / managerupdates=1
2022-01-21 14:38:42 -05:00
weslambert
f7a4cc20f2
Update so-common-template.json.jinja
2022-01-21 12:36:38 -05:00
Josh Patterson
36fc25f78e
Merge pull request #6953 from Security-Onion-Solutions/issue/6492
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 12:09:13 -05:00
m0duspwnens
e7852d7700
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 11:59:27 -05:00
Josh Patterson
0257d09cf8
Merge pull request #6949 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-21 08:46:54 -05:00
m0duspwnens
878c3fe6d9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-21 08:09:24 -05:00
m0duspwnens
281e5d9b25
remove salt.enable_higstate state
2022-01-21 08:09:04 -05:00
m0duspwnens
baa93301b5
enable cron at the end of soup
2022-01-20 16:53:33 -05:00
m0duspwnens
00d0eb1ce5
fix setting var
2022-01-20 16:37:33 -05:00
m0duspwnens
01cb505338
start cron and enable highstate if soup exits on error
2022-01-20 16:31:01 -05:00
William Wernert
ec023f8f7c
Merge pull request #6937 from Security-Onion-Solutions/fix/fail-preflight-early
...
Correctly handle failure to install curl in so-preflight
2022-01-20 16:03:20 -05:00
m0duspwnens
e1757926cf
start cron and reenable highstate on soup exit
2022-01-20 15:26:03 -05:00
William Wernert
357cd059aa
Use ret_code in prereq function to return failures
2022-01-20 13:53:59 -05:00
weslambert
1b860e11e7
Merge pull request #6936 from Security-Onion-Solutions/fix/field_conflicts
...
Remove dynamic keyword template to prevent field conflicts with mappi…
2022-01-20 12:48:15 -05:00
weslambert
d1efa71c57
Remove dynamic keyword template to prevent field conflicts with mappings defined in common template
2022-01-20 12:34:32 -05:00
Josh Patterson
c57b2d005e
Merge pull request #6933 from Security-Onion-Solutions/issue/6810
...
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:57:56 -05:00
m0duspwnens
9b2459d8ba
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:52:48 -05:00
weslambert
d0c8dd0626
Merge pull request #6931 from Security-Onion-Solutions/fix/cases_dynamic_disable
...
Disable dynamic mapping and increase order to reduce potential field …
2022-01-20 09:48:01 -05:00
weslambert
e137ad60c5
Disable dynamic mapping and increase order to reduce potential field conflicts
2022-01-20 09:44:41 -05:00
Josh Patterson
93236738de
Merge pull request #6930 from Security-Onion-Solutions/issue/6810
...
upgrade salt to 3004
2022-01-20 08:28:20 -05:00
m0duspwnens
fc65f7bb84
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 15:35:28 -05:00
m0duspwnens
67e34b2402
reorder yum operations in securityonion_repo function
2022-01-19 15:35:04 -05:00
Jason Ertel
e984b0b9c4
Merge pull request #6921 from Security-Onion-Solutions/kilo
...
remove unused fields object from related case schema
2022-01-19 14:42:05 -05:00
Jason Ertel
dc44a91398
Prefix all SO fields to avoid potential conflicts with future ECS changes
2022-01-19 14:26:22 -05:00
m0duspwnens
a861801a24
more logCmd
2022-01-19 13:38:10 -05:00
m0duspwnens
fbe54b9ee8
yum clean all needs to happen before repo files are moved or the clean doesnt clean anything
2022-01-19 12:33:58 -05:00
m0duspwnens
7ebba1f325
use show_changes: False to prevent es pw from being shown when running the state
2022-01-19 12:11:38 -05:00
m0duspwnens
f8ac37c101
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 11:57:37 -05:00
m0duspwnens
4d078046d6
quote ES_PASS due to new characters in random string for elasticsearch:auth pw generation
2022-01-19 11:55:25 -05:00
William Wernert
13dbd0034f
Merge pull request #6924 from Security-Onion-Solutions/fix/whiptail-height
...
Fix height of node whiptail menu
2022-01-19 11:18:44 -05:00
William Wernert
c10ab712d5
Fix height of node whiptail menu
2022-01-19 11:05:34 -05:00
Jason Ertel
d7ba1cedff
remove unused fields object from related case schema
2022-01-19 08:39:21 -05:00
m0duspwnens
55a262646c
use logCmd
2022-01-19 08:34:54 -05:00
William Wernert
a3925d231c
Merge pull request #6909 from Security-Onion-Solutions/fix/preflight-curl
...
Install curl in preflight script to avoid error on Ubuntu
2022-01-18 13:39:44 -05:00
William Wernert
c0c42c3574
Install curl in preflight script to avoid error on Ubuntu
...
Also add check for already installed curl later in setup
2022-01-18 13:17:56 -05:00
m0duspwnens
f006d1a22c
logCmd commands in securityonion_repo function
2022-01-18 12:34:23 -05:00
m0duspwnens
a2ed9a86ff
remove influixdb salt state files and update patch files for influxdb salt modules/state
2022-01-18 11:33:36 -05:00
Josh Brower
19ccd5f8e9
Merge pull request #6904 from Security-Onion-Solutions/fix/fleetdm-disable-vuln-feature
...
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:48:06 -05:00
Josh Brower
c4babf22d6
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:38:55 -05:00
Mike Reeves
7eb564db14
Merge pull request #6901 from Security-Onion-Solutions/elasticupdate
...
Elastic 7.16.3
2022-01-18 09:47:36 -05:00
Mike Reeves
2e4e59bbe8
Elastic 7.16.3
2022-01-18 09:42:06 -05:00
m0duspwnens
87999453f2
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-18 09:13:10 -05:00
m0duspwnens
3bd26f05d4
account for salt 3004 adding new chars to random.get_str
2022-01-14 18:02:18 -05:00
m0duspwnens
a46a740170
account for salt 3004 adding new chars to random.get_str
2022-01-14 17:23:29 -05:00
Mike Reeves
71da74fd00
Merge pull request #6878 from Security-Onion-Solutions/fix/scan_pe_sections_entropy
...
Fix/scan pe sections entropy
2022-01-14 17:02:32 -05:00
weslambert
c512351dd6
Add mapping for scan.exiftool and scan.pe.sections.entropy
2022-01-14 17:01:13 -05:00
weslambert
a90bc9dba9
Add mapping for scan.pe.sections.entropy
2022-01-14 16:58:53 -05:00
m0duspwnens
02ce5c3236
update install salt to 3004
2022-01-14 13:47:16 -05:00
m0duspwnens
b6b2e06fbc
change module to cmd for onchanges_in
2022-01-14 12:44:58 -05:00
m0duspwnens
f5fe466410
repo update
2022-01-14 12:02:35 -05:00
Jason Ertel
a63787daba
Merge pull request #6864 from Security-Onion-Solutions/kilo
...
Add default queries for cases to show user's assigned cases
2022-01-13 17:15:02 -05:00
Jason Ertel
6b0b7245f0
Add default queries for cases to show user's assigned cases
2022-01-13 17:10:08 -05:00
m0duspwnens
bda9221d6f
upgrade salt to 3004 and update bootstrap-salt.sh
2022-01-13 13:26:11 -05:00
Josh Patterson
b2434faf10
Merge pull request #6862 from Security-Onion-Solutions/issue/6811
...
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:06:43 -05:00
m0duspwnens
82db3fa3c0
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:02:01 -05:00
Josh Patterson
78bb6e4176
Merge pull request #6856 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-13 11:03:51 -05:00
m0duspwnens
06c0cebb26
merge with dev
2022-01-13 09:44:26 -05:00
m0duspwnens
389ff1a46d
create enable_highstate state to reenable highstate following minion restart if it was previously disabled. same with cron
2022-01-13 09:39:46 -05:00
m0duspwnens
a28bb23d20
fix os_family for cron state map
2022-01-12 17:27:47 -05:00
m0duspwnens
443dc6ebaa
move branch echo to main so it is in the log
2022-01-12 16:14:49 -05:00
m0duspwnens
03b9b74ace
stop cron before soup upgrades the manager, start cron at the end. add cron state that is in included in common
2022-01-12 16:04:10 -05:00
Mike Reeves
e123dd4bb2
Merge pull request #6844 from Security-Onion-Solutions/highlanderml
...
Add additional highlander settings
2022-01-12 13:34:22 -05:00
Josh Patterson
5889ce02cd
Merge pull request #6845 from Security-Onion-Solutions/23100soup_jpp
...
remove mine push from 2.3.100 function
2022-01-12 13:34:06 -05:00
Josh Patterson
776e4c6e12
Update soup
2022-01-12 13:32:46 -05:00
Josh Patterson
035984569b
Merge branch 'dev' into 23100soup_jpp
2022-01-12 13:31:46 -05:00
Josh Patterson
da30f66096
remove mine push from 2.3.100 function
2022-01-12 13:29:34 -05:00
Mike Reeves
c525bf310d
Add additional highlander settings
2022-01-12 13:19:40 -05:00
Mike Reeves
ee44edfe75
Add additional highlander settings
2022-01-12 13:18:44 -05:00
m0duspwnens
0cf877f169
kill any possible queued salt jobs before stopping salt-master
2022-01-12 12:27:19 -05:00
Mike Reeves
f836d3ad16
Merge pull request #6843 from Security-Onion-Solutions/23100soup_jpp
...
push ips of mainint to salt mine
2022-01-12 12:25:51 -05:00
Josh Patterson
5b347600e9
push ips of mainint to salt mine
2022-01-12 12:24:52 -05:00
m0duspwnens
0388912ba7
kill all salt jobs across grid before stopping salt-master. kill all salt jobs on manager before stopping salt-minion.
2022-01-12 11:05:47 -05:00
m0duspwnens
494737549d
move some es script to src elasticsearch/tools/sbin and dst /usr/sbin. set requires
2022-01-12 10:20:05 -05:00
Mike Reeves
22096174bb
Merge pull request #6841 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix some formatting
2022-01-12 09:39:15 -05:00
Mike Reeves
1d94e3ac69
Fix some formatting
2022-01-12 09:38:22 -05:00
m0duspwnens
abf3a9401b
listen instead to not start service if not running then restart if changes to files
2022-01-11 18:31:35 -05:00
m0duspwnens
ae0f392035
wait for salt-master and salt-minin to exit. disable highstate before stopping salt-minion. apply salt-minion state before first highstate to update configs
2022-01-11 16:57:29 -05:00
Mike Reeves
53d2e20e48
Merge pull request #6834 from Security-Onion-Solutions/nohive
...
Remove hive install option
2022-01-11 16:50:18 -05:00
Mike Reeves
4ff5fc3b38
Remove hive install option
2022-01-11 14:38:38 -05:00
m0duspwnens
5ade8193f0
move highstate messages for more accurate final highstate message
2022-01-11 13:41:51 -05:00
m0duspwnens
0ef130bd38
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:12:07 -05:00
m0duspwnens
e33a9eb45c
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:11:25 -05:00
m0duspwnens
9d19cba600
log time when salt services stopped and started
2022-01-11 13:09:05 -05:00
m0duspwnens
baf297ab0a
merge with dev, resolve conflict
2022-01-11 11:24:10 -05:00
m0duspwnens
14eed8e5b9
redirect to setup_log
2022-01-11 11:20:30 -05:00
Josh Brower
5083be4ce7
Merge pull request #6816 from Security-Onion-Solutions/fix/wazuh-parsing-v2
...
Fix Wazuh WEL Parsing
2022-01-11 11:17:24 -05:00
Doug Burks
a3c8335130
Merge pull request #6827 from Security-Onion-Solutions/dougburks-patch-1
...
Remove unnecessary word
2022-01-11 11:06:40 -05:00
Doug Burks
29d8dbe371
Remove unnecessary word
2022-01-11 11:05:30 -05:00
m0duspwnens
91ef9b9366
update salt mine before salt-master and salt-minion get stopped
2022-01-11 10:57:48 -05:00
m0duspwnens
328d6cdeb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 10:02:18 -05:00
Mike Reeves
a9e58e2aba
Merge pull request #6826 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2022-01-11 10:01:49 -05:00
Mike Reeves
8ad36fc7b9
Update init.sls
2022-01-11 10:01:14 -05:00
m0duspwnens
87756cdbc9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:57:31 -05:00
Mike Reeves
7937487ee9
Merge pull request #6825 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update init.sls
2022-01-11 09:57:10 -05:00
Mike Reeves
770a389410
Update init.sls
2022-01-11 09:56:22 -05:00
m0duspwnens
b5c274de10
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:48:31 -05:00
m0duspwnens
a8d1b9eb90
restart salt-minion at end of run if mine_functions changes
2022-01-11 09:29:12 -05:00
m0duspwnens
86c8fc6c1c
need to update mine after salt-master starts
2022-01-11 08:56:38 -05:00
weslambert
17509a9231
Merge pull request #6822 from Security-Onion-Solutions/fix/event_fields
...
Add event.acknowledged and event.escalated mappings
2022-01-10 16:14:45 -05:00
weslambert
84f7c6b13b
Add event.acknowledged and event.escalated mappings
2022-01-10 16:08:35 -05:00
m0duspwnens
716c98ec61
requires and ordering for socusersroles state
2022-01-10 14:39:00 -05:00
Josh Brower
56aa24d874
Fix Wazuh WEL Parsing
2022-01-10 13:55:38 -05:00
Mike Reeves
b7a90a88f9
Merge pull request #6815 from Security-Onion-Solutions/esbackup
...
Add ability to specify local backup dir
2022-01-10 13:31:24 -05:00
weslambert
1dc363138a
Merge pull request #6814 from Security-Onion-Solutions/fix/template_typo
...
Fix typo -- replace period with comma
2022-01-10 13:30:13 -05:00
weslambert
1c3eeb5a34
Fix typo -- replace period with comma
2022-01-10 13:29:06 -05:00
m0duspwnens
beb9a33628
only include curl.config if elasticsearch:auth is enabled
2022-01-10 11:48:16 -05:00
Mike Reeves
dbba7d7226
Add ability to specify local backup dir
2022-01-10 11:31:41 -05:00
m0duspwnens
291ac7d361
https://github.com/Security-Onion-Solutions/securityonion/issues/6811
2022-01-10 10:36:42 -05:00
Josh Patterson
43eda0c5a3
Merge pull request #6796 from Security-Onion-Solutions/fix/wazuh_register_agent
...
dont try to register if state file exists
2022-01-07 16:07:56 -05:00
m0duspwnens
715d3f0e7e
dont try to register if state file exists
2022-01-07 16:05:55 -05:00
Jason Ertel
db04646735
Merge pull request #6794 from Security-Onion-Solutions/kilo
...
Update field mappings based on Wes' feedback
2022-01-07 16:03:05 -05:00
Jason Ertel
66c9e20c6a
Add wilcards for CCS compatibility
2022-01-07 15:57:08 -05:00
Josh Patterson
ed97fe0b65
Merge pull request #6795 from Security-Onion-Solutions/fix/wazuh_register_agent
...
Fix/wazuh register agent
2022-01-07 15:52:17 -05:00
m0duspwnens
3a86af8de2
quote $API_RESULT
2022-01-07 15:49:53 -05:00
m0duspwnens
7ee913eb1f
if /opt/so/conf/wazuh/initial_agent_registration.log doesnt exist, and agent is already registered, touch file and exit 0 to prevent salt error
2022-01-07 15:46:47 -05:00
Jason Ertel
d3656a7777
Merge branch 'dev' into kilo
2022-01-07 13:41:35 -05:00
Josh Patterson
3c44f6fd41
Merge pull request #6793 from Security-Onion-Solutions/23100soup_jpp
...
23100soup
2022-01-07 13:32:33 -05:00
Jason Ertel
391db568b0
Update field mappings based on Wes' feedback
2022-01-07 13:28:36 -05:00
Jason Ertel
a4f01d4412
Merge pull request #6792 from Security-Onion-Solutions/kilo
...
Add case exclusion toggle to Hunt to avoid hunt results getting case …
2022-01-07 13:02:27 -05:00
Jason Ertel
9ef83da23f
Add case exclusion toggle to Hunt to avoid hunt results getting case data hits unintentionally
2022-01-07 12:58:35 -05:00
m0duspwnens
871fd115ae
put so-firewalll in /usr/sbin since salt-master isnt running at this time
2022-01-07 12:04:19 -05:00
weslambert
218f7f3a13
Merge pull request #6790 from Security-Onion-Solutions/fix/dtc_severity_label
...
Add event.severity_label
2022-01-07 11:44:30 -05:00
weslambert
770e53d914
Add keyword subfield for event.severity_label
2022-01-07 11:21:57 -05:00
weslambert
c69e1353d9
Add event.severity_label
2022-01-07 11:19:54 -05:00
m0duspwnens
fd0e5d7d29
make sure so-firewall is up to date
2022-01-07 11:10:48 -05:00
Josh Brower
ae6aa0dafd
Merge pull request #6789 from Security-Onion-Solutions/fix/wazuh-parsing-revert
...
Revert Wazuh parser update
2022-01-07 10:53:53 -05:00
Josh Brower
5d4ea2ba3a
Revert Wazuh parser update
2022-01-07 10:51:24 -05:00
weslambert
a7e7566532
Merge pull request #6780 from Security-Onion-Solutions/feature/datatype_compliance
...
Initial commit for data type compliance
2022-01-06 16:38:17 -05:00
m0duspwnens
5ecb63f5cf
prevent exit if minion doesnt respond
2022-01-06 16:17:51 -05:00
Josh Brower
ca4aaae47c
Merge pull request #6778 from Security-Onion-Solutions/fix/wazuh-parsing
...
Uppercase first char in Wazuh WEL
2022-01-06 16:01:09 -05:00
Josh Brower
277c7f1ef8
Uppercase first char in Wazuh WEL
2022-01-06 14:58:50 -05:00
m0duspwnens
cd590b894a
check that ossec.conf exists
2022-01-06 12:39:48 -05:00
weslambert
3f02003ea2
Merge pull request #6777 from Security-Onion-Solutions/fix/deprecation_ecs_compatibility_logstash
...
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:31:51 -05:00
weslambert
8e2f500b9c
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:24:04 -05:00
weslambert
099e3e1ceb
Merge pull request #6775 from Security-Onion-Solutions/fix/deprecation_warning_suppress
...
Add logger stanza to suppress ES deprecation warning messages
2022-01-06 10:45:37 -05:00
weslambert
900d12b556
Add logger stanza to suppress deprecation warning messages for now due to current system index access warning messages flooding the ES log
2022-01-06 10:35:50 -05:00
Jason Ertel
8cf7ea8b87
Merge pull request #6772 from Security-Onion-Solutions/kilo
...
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 19:15:02 -05:00
Josh Patterson
eaa6597cd7
Merge pull request #6773 from Security-Onion-Solutions/issue/6765
...
Issue/6765
2022-01-05 18:11:06 -05:00
m0duspwnens
6338ba2e45
remove /var/cache/salt/ for reinstall
2022-01-05 16:54:56 -05:00
m0duspwnens
8af74e8bb3
remove more salt configs for reinstall
2022-01-05 16:53:54 -05:00
m0duspwnens
9357995bfa
remove root cron and restore yeselastic.txt
2022-01-05 16:04:32 -05:00
weslambert
2fb488f768
Merge pull request #6769 from Security-Onion-Solutions/fix/id_fielddata_deprecation
...
Fix issue with _id field fielddata/deprecation
2022-01-05 15:40:25 -05:00
Wes Lambert
1cafacfa51
Update saved objects to reflect removal of TheHive scripted field and replacement of PCAP pivot with Hunt pivot
2022-01-05 20:36:23 +00:00
weslambert
c1a88977cf
Disable fielddata for _id field by default (since it is deprecated and can be memory-intensive)
2022-01-05 15:23:52 -05:00
m0duspwnens
0ff5e3cf6f
require so-elasticsearch container to be running to run the scripts
2022-01-05 14:48:41 -05:00
m0duspwnens
8950f94fb0
restore state files so python3-influxdb state doesnt try to patch during a restinstall
2022-01-05 12:02:53 -05:00
Wes Lambert
b60837e71a
Initial commit for data type compliance
2022-01-05 16:38:56 +00:00
Jason Ertel
4f8524e0ac
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 11:13:12 -05:00
weslambert
2f9672d3ea
Merge pull request #6764 from Security-Onion-Solutions/feature/soup_branch
...
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:54:29 -05:00
weslambert
db43e21378
Fix indentation
2022-01-05 10:46:41 -05:00
weslambert
4d8b417fc9
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:41:27 -05:00
Jason Ertel
89415b12ce
Merge pull request #6762 from Security-Onion-Solutions/kilo
...
Switch soc.json to use lowercase labels in default queries; Also enab…
2022-01-05 09:59:39 -05:00
Jason Ertel
4bfdfffe21
Switch soc.json to use lowercase labels in default queries; Also enable the 'Add Case' feature
2022-01-05 09:54:13 -05:00
Mike Reeves
1adc4c5346
Merge pull request #6752 from Security-Onion-Solutions/ubufix
...
Fix docker holds so re-install will work properly
2022-01-04 18:56:06 -05:00
Mike Reeves
3ca0ce9eea
Update so-functions
2022-01-04 18:47:35 -05:00
Mike Reeves
e869013057
Remove docker the reinstall it
2022-01-04 15:24:10 -05:00
Mike Reeves
dd104c9490
Add holds for ubuntu
2022-01-04 13:07:09 -05:00
m0duspwnens
7bb9b6efa9
populate mine with network.ip_addrs pillar.host.mainint for each host prior to highstate
2022-01-04 10:27:45 -05:00
Mike Reeves
288389c93e
Soup changes for 2.3.100
2022-01-04 08:38:14 -05:00
Josh Patterson
4247a3a816
Merge pull request #6730 from Security-Onion-Solutions/fix/ub1804ssl
...
more detailed logging for the retry command
2021-12-30 13:19:58 -05:00
m0duspwnens
cc2f6e23ca
more detailed logging for the retry command
2021-12-30 13:09:29 -05:00
Josh Patterson
064355dfb5
Merge pull request #6729 from Security-Onion-Solutions/fix/ub1804ssl
...
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 11:38:32 -05:00
m0duspwnens
d274615376
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 10:45:30 -05:00
Josh Patterson
78eda75c0f
Merge pull request #6725 from Security-Onion-Solutions/fix/ub1804ssl
...
add option to look for failed outout in retry function in so-common. …
2021-12-29 18:18:12 -05:00
m0duspwnens
200736a118
add option to look for failed outout in retry function in so-common. look for Err: when running soapt-get update in setup
2021-12-29 18:15:16 -05:00
Jason Ertel
1d136b611a
Merge pull request #6723 from Security-Onion-Solutions/kilo
...
Uniform presets
2021-12-29 16:49:41 -05:00
Jason Ertel
e6051cb653
Switch all presets to lowercase for uniformity
2021-12-29 16:42:34 -05:00
Jason Ertel
74dbc4bf67
Merge pull request #6720 from Security-Onion-Solutions/kilo
...
Add case template to eval install types; also improve clarity of case queries
2021-12-29 11:41:06 -05:00
Josh Patterson
a2f1f52450
Merge pull request #6719 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-29 11:39:10 -05:00
Jason Ertel
1d885a5419
Add case template to eval installs
2021-12-29 11:38:38 -05:00
m0duspwnens
b414e22e95
remove spaces in function
2021-12-29 11:37:22 -05:00
m0duspwnens
4c54d45681
some echos for logging
2021-12-29 11:36:12 -05:00
m0duspwnens
c6e9b00488
Merge remote-tracking branch 'remotes/origin/dev' into fix/ub1804ssl
2021-12-29 11:22:25 -05:00
m0duspwnens
b027da6378
wait for the salt-minion service to be ready for requests prior to running ssl state
2021-12-29 11:18:38 -05:00
Jason Ertel
fb02d0d35c
clarify case filters
2021-12-29 11:07:36 -05:00
Jason Ertel
d4f3615cae
Merge pull request #6717 from Security-Onion-Solutions/kilo
...
Support CCS in CM
2021-12-29 09:12:13 -05:00
Jason Ertel
e5110ac4e8
Use CCS compatible index
2021-12-29 09:08:10 -05:00
Jason Ertel
e87cbc37a4
Add case template
2021-12-28 19:17:15 -05:00
Josh Patterson
3b130ab202
Merge pull request #6712 from Security-Onion-Solutions/fix/ub1804ssl
...
all run ssl state during setup
2021-12-28 16:34:58 -05:00
m0duspwnens
22afe99719
all run ssl state during setup
2021-12-28 16:24:17 -05:00
Doug Burks
e56a9a5f22
Merge pull request #6711 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-analyst-install
2021-12-28 15:24:19 -05:00
Josh Patterson
7655920068
Merge pull request #6710 from Security-Onion-Solutions/fix/ub1804ssl
...
add mine function to signing_policies.conf
2021-12-28 15:23:36 -05:00
Doug Burks
463925686d
fix typo in so-analyst-install
2021-12-28 15:23:17 -05:00
m0duspwnens
2a5b4ef276
add mine function to signing_policies.conf. no longer need to check if mine in ca during manager install
2021-12-28 15:19:06 -05:00
Josh Patterson
7029c3a94a
Merge pull request #6707 from Security-Onion-Solutions/fix/ub1804ssl
...
put x509 signing policies in place when minion is configured
2021-12-28 12:05:20 -05:00
m0duspwnens
67a9f4d22e
put x509 signing policies in place when minion is configured
2021-12-28 12:03:10 -05:00
Josh Patterson
a5746d4919
Merge pull request #6706 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-28 11:27:15 -05:00
m0duspwnens
487ac24306
revert back to getting ca from mine
2021-12-28 11:16:01 -05:00
m0duspwnens
2405de4b82
fix require
2021-12-28 11:00:35 -05:00
m0duspwnens
9e3c289562
remove restarting salt in ssl generation. sperate ca and ssl generation into seperate functions
2021-12-28 10:43:45 -05:00
m0duspwnens
f2adcf4ca5
ensure /etc/pki is created and simplify ca logic for non manager in ssl state
2021-12-28 10:41:57 -05:00
Jason Ertel
0072ae253b
Merge pull request #6705 from Security-Onion-Solutions/kilo
...
Initial CM Impl; Improve so-user script
2021-12-28 08:36:59 -05:00
Jason Ertel
5a4473ecd6
fix indent
2021-12-28 08:33:31 -05:00
Jason Ertel
f335670b3f
Add new client-side param for cases
2021-12-27 21:53:30 -05:00
Jason Ertel
194e4119f0
Correct missing json vars
2021-12-27 20:36:28 -05:00
Jason Ertel
09626deb05
Correct var names for jinja
2021-12-27 18:01:15 -05:00
Jason Ertel
ae7a4b6528
More syntax corrections
2021-12-27 16:18:12 -05:00
Jason Ertel
0a255e5765
Resolve syntax error
2021-12-27 15:15:33 -05:00
Jason Ertel
789719d25e
Correct preset file syntax
2021-12-27 13:21:13 -05:00
Jason Ertel
7140255d95
Add missing presets file
2021-12-27 12:27:04 -05:00
Jason Ertel
ab3319b472
Add artifact support
2021-12-27 10:49:10 -05:00
Jason Ertel
b0d36f2ed2
Ensure update timestamp is updated when changing passwords; this ensures the sync will automatically follow
2021-12-21 13:38:35 -05:00
Jason Ertel
62e5914ab8
Merge branch 'dev' into kilo
2021-12-21 13:37:37 -05:00
Jason Ertel
2f88f08be2
Merge pull request #6649 from Security-Onion-Solutions/2.3.91-merge
...
2.3.91 merge
2021-12-21 09:39:14 -05:00
Jason Ertel
9aeaa1fccc
resolved merge conflicts
2021-12-21 09:35:57 -05:00
Jason Ertel
2c9062efb7
resolved merge conflicts
2021-12-21 09:34:39 -05:00
Doug Burks
c8de36d467
Merge pull request #6646 from Security-Onion-Solutions/patch/2.3.91
...
Patch/2.3.91
2021-12-21 09:27:14 -05:00
doug
284e0e9108
fix hashes in VERIFY_ISO.md
2021-12-20 17:27:19 -05:00
doug
e66b023c9c
update README.md for 2.3.91
2021-12-20 17:23:52 -05:00
doug
9f47522591
add sig for 2.3.91 ISO and update VERIFY_ISO.md
2021-12-20 17:21:53 -05:00
Jason Ertel
35617acaeb
Update cacerts to reflect new path; this changed due to ES 7.16.2
2021-12-20 12:12:00 -05:00
Jason Ertel
6f116a2d01
Switch to new Ubuntu SSL dir
2021-12-20 09:43:59 -05:00
Jason Ertel
d6c651af1c
Remove old patch dir from previously-patched installations
2021-12-20 09:42:27 -05:00
Jason Ertel
203e8a7873
Bump version to 2.3.91
2021-12-20 09:33:20 -05:00
Jason Ertel
b8fcec04b8
Remove patched jar due to upgrade of Elastic images to 7.16.2
2021-12-20 09:27:03 -05:00
Jason Ertel
6556a37869
Merge branch 'master' into patch/1.3.91
2021-12-20 09:20:03 -05:00
Jason Ertel
5af2bd8fa4
Upgrade to Elastic 7.16.2
2021-12-20 09:16:28 -05:00
Josh Patterson
d33cf19e3d
Merge pull request #6612 from Security-Onion-Solutions/issue/6469
...
add managersearch to list
2021-12-16 13:57:53 -05:00
m0duspwnens
a46a876ec6
add managersearch to list
2021-12-16 13:48:41 -05:00
Josh Brower
affe5b9ac0
Merge pull request #6605 from Security-Onion-Solutions/fix/fleet-ips
...
Fix cidr for fleet custom docker range
2021-12-16 11:55:11 -05:00
Josh Patterson
e0c8e03882
Merge pull request #6604 from Security-Onion-Solutions/issue/6469
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6469
2021-12-16 11:54:05 -05:00
Josh Brower
a23824e199
Fix cidr for fleet custom docker range
2021-12-16 11:53:26 -05:00
m0duspwnens
ae342ab673
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-16 11:33:09 -05:00
m0duspwnens
b4b8b91ccd
simplify ip logic wazuh-register-agent, mine_interval to 35 minutes
2021-12-16 11:24:35 -05:00
m0duspwnens
2e4ed8062e
simplify wazuh agent ip logic
2021-12-16 11:11:01 -05:00
m0duspwnens
bd7ef1cc59
fix whitespace control
2021-12-16 09:19:20 -05:00
Jason Ertel
8ec671422f
Merge pull request #6593 from Security-Onion-Solutions/esup
...
Finish upgrade of ES to 7.16.1
2021-12-16 07:59:34 -05:00
Jason Ertel
1268f8f92b
Upgrade ES to 7.16.1
2021-12-16 07:57:42 -05:00
Jason Ertel
d4f395b7f4
Fix query name for open cases
2021-12-15 20:02:35 -05:00
Jason Ertel
c68efd56c2
Merge branch 'dev' into kilo
2021-12-15 20:01:55 -05:00
m0duspwnens
a7600f7f43
update scripts to use their own ip
2021-12-15 17:31:39 -05:00
Mike Reeves
0f76227631
Merge pull request #6585 from Security-Onion-Solutions/unhotfix
...
Unhotfix
2021-12-15 17:23:02 -05:00
m0duspwnens
d0b0970353
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-15 17:08:56 -05:00
Mike Reeves
465ba1b7d3
Change CA certs location
2021-12-15 17:08:36 -05:00
m0duspwnens
f9b04ab96a
add node's own ip to FILEBEAT_EXTRA_HOSTS
2021-12-15 16:53:22 -05:00
m0duspwnens
522bc1d2b8
fix loadbalance logic and whitespace for filebeat.yml
2021-12-15 16:21:08 -05:00
m0duspwnens
cf2f4bad09
have standalone and managersearch pull from redis nodes
2021-12-15 15:27:23 -05:00
Mike Reeves
61955b7928
Change CA certs location
2021-12-15 13:50:19 -05:00
Jason Ertel
ffa8ca57a7
Merge pull request #6579 from Security-Onion-Solutions/unhotfix
...
Remove some previous hotfix code
2021-12-15 12:34:00 -05:00
Mike Reeves
7cd1b1c482
Remove some previous hotfix code
2021-12-15 12:26:53 -05:00
m0duspwnens
6ab2bdef0c
add sensoroni state to receiver node
2021-12-15 10:45:54 -05:00
m0duspwnens
ce0a39db4b
remove old EXTRAHOSTNAME EXTRAHOSTIP from being set for logstash
2021-12-15 09:43:46 -05:00
m0duspwnens
ea89d2074b
remove ca from allowed_hosts on so-receiver
2021-12-15 09:32:12 -05:00
m0duspwnens
759bf9837e
pillar top clean up for receiver and logstash.nodes
2021-12-15 09:31:03 -05:00
m0duspwnens
d9a384cc29
remove global:pipeline pillar call from logstash pipeline pillars
2021-12-15 09:30:15 -05:00
m0duspwnens
176ef852c8
clean up assinged hostgroups for receiver
2021-12-15 08:28:40 -05:00
Doug Burks
09f0bdba91
Merge pull request #6574 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-image-common
2021-12-15 07:45:24 -05:00
Doug Burks
7d1f9c51e8
fix typo in so-image-common
2021-12-15 07:24:30 -05:00
m0duspwnens
024860d0ae
rename EXTRA_NODES to LOGSTASH_NODES AND REDIS_NODES
2021-12-14 23:43:06 -05:00
m0duspwnens
0c6aba16ec
fix redis input
2021-12-14 23:42:37 -05:00
m0duspwnens
15b8d80b71
fix host for input_redis
2021-12-14 18:51:43 -05:00
m0duspwnens
55b74abcc5
extra_hosts and redis_input for logstash
2021-12-14 18:49:30 -05:00
m0duspwnens
4da017d61c
change extra_hosts for docker container
2021-12-14 17:05:30 -05:00
m0duspwnens
a31d61e151
handle ca for redis
2021-12-14 16:43:04 -05:00
m0duspwnens
841b91e052
exclude elasticsearch and managerssl keys and certs from receiver
2021-12-14 16:05:47 -05:00
m0duspwnens
d0b6d5bba6
remove so-eval from lists since it doesnt run logstash
2021-12-14 15:33:06 -05:00
m0duspwnens
a31f034f2e
remove receiver add node for cacerts and tls-ca-bundle for logstash bind
2021-12-14 15:02:59 -05:00
m0duspwnens
6962e3f9b3
fix logstash certs mapped into container
2021-12-14 14:52:15 -05:00
m0duspwnens
c490a3be36
move node_data pillar to logstash:nodes, set extra hosts for filebeat docker
2021-12-14 13:32:42 -05:00
Mike Reeves
5006e34208
Merge pull request #6560 from Security-Onion-Solutions/mergerz
...
Merge latest hotfix
2021-12-14 10:57:49 -05:00
Mike Reeves
30344ba0ef
Fix conflicts
2021-12-14 10:55:19 -05:00
m0duspwnens
6518691c55
sort the items
2021-12-13 18:16:25 -05:00
m0duspwnens
067e79894f
fix loop for node_data
2021-12-13 16:26:38 -05:00
m0duspwnens
6de2f5bd03
fix node_data
2021-12-13 15:55:09 -05:00
m0duspwnens
8d0872bce5
create node_data pillar from mine data, use node_data pillar for filebeat config
2021-12-13 15:48:30 -05:00
Mike Reeves
85cf096322
Merge pull request #6541 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-13 12:41:24 -05:00
Mike Reeves
4eaf3f8d8b
Merge pull request #6540 from Security-Onion-Solutions/2390hotfix3
...
2.3.90-20211213 Hotfix
2021-12-13 12:12:03 -05:00
Mike Reeves
d90904b4d4
2.3.90-20211213 Hotfix
2021-12-13 12:09:09 -05:00
Mike Reeves
65cc9930e7
Merge pull request #6537 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-12-13 11:13:40 -05:00
Mike Reeves
7f982d2824
Update HOTFIX
2021-12-13 11:12:18 -05:00
Mike Reeves
d3ac1f7994
Merge pull request #6533 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Add missing logstash lib
2021-12-13 09:30:32 -05:00
Jason Ertel
c94d5fa9dc
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:27:13 -05:00
Mike Reeves
83d1cdad90
Merge pull request #6532 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:05:30 -05:00
Jason Ertel
8365b5f140
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:02:41 -05:00
m0duspwnens
86f67198bf
loadbalance filebeat if across managers and receivers
2021-12-10 17:43:06 -05:00
Mike Reeves
4d6cd66d9d
Merge pull request #6521 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-10 16:20:29 -05:00
Mike Reeves
1946965c5f
Merge pull request #6520 from Security-Onion-Solutions/2390hotfix0day
...
2.3.90-20211210 Hotfix
2021-12-10 15:49:38 -05:00
Mike Reeves
c9a14788ed
2.3.90-20211210 Hotfix
2021-12-10 15:42:53 -05:00
m0duspwnens
fe7247f876
update fw for receiver and add mine_functions for ip_addr
2021-12-10 15:28:40 -05:00
Mike Reeves
ce963a02d9
Merge pull request #6517 from Security-Onion-Solutions/ES0day2
...
Add JVM Options for logstash
2021-12-10 14:25:52 -05:00
Mike Reeves
dcd56de890
Update log4j2.properties
2021-12-10 14:23:38 -05:00
Mike Reeves
3d7b963912
Update log4j2.properties
2021-12-10 14:16:16 -05:00
Mike Reeves
09253b637e
Create jvm.options
2021-12-10 14:12:43 -05:00
Mike Reeves
c81ce48bff
Update log4j2.properties
2021-12-10 14:10:35 -05:00
Mike Reeves
73ec595baa
Update init.sls
2021-12-10 14:10:05 -05:00
Mike Reeves
04862fcc06
Merge pull request #6514 from Security-Onion-Solutions/ES0day2
...
Throw the log4j into the java options
2021-12-10 12:04:31 -05:00
Mike Reeves
45346b6318
Update log4j2.properties
2021-12-10 12:01:39 -05:00
Mike Reeves
e48de18480
Update init.sls
2021-12-10 12:00:12 -05:00
Mike Reeves
66c8cc6e86
Update init.sls
2021-12-10 11:59:12 -05:00
Mike Reeves
8dcb64d87c
Update init.sls
2021-12-10 11:56:33 -05:00
Mike Reeves
ae3e980852
Merge pull request #6513 from Security-Onion-Solutions/EShotfix
...
Update log4j2.properties
2021-12-10 10:35:43 -05:00
Mike Reeves
11f1fe7ab1
Update HOTFIX
2021-12-10 10:21:50 -05:00
Mike Reeves
4561e13871
Update log4j2.properties
2021-12-10 10:19:58 -05:00
Mike Reeves
ea26e402c8
Update log4j2.properties
2021-12-10 10:17:49 -05:00
m0duspwnens
54c32acdbf
dont call logstash_pillar if manager or helix
2021-12-09 15:26:00 -05:00
Jason Ertel
83d86aebb1
Perform full email match
2021-12-09 15:04:00 -05:00
m0duspwnens
d94496bb90
remove minio_key and add missing endif
2021-12-09 13:24:20 -05:00
m0duspwnens
c2a952796c
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:13:18 -05:00
Mike Reeves
b92cbb01b3
SSL modifications
2021-12-09 13:13:01 -05:00
m0duspwnens
5b70d5510f
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:12:00 -05:00
Jason Ertel
2761662eb9
Add status presets
2021-12-09 13:09:56 -05:00
Mike Reeves
a7f0d81555
SSL modifications
2021-12-09 13:07:00 -05:00
Josh Brower
d3bbae23ca
Merge pull request #6499 from Security-Onion-Solutions/fix/beats-logstash
...
Use id for doc id if it exists
2021-12-09 09:47:14 -05:00
Josh Brower
656ea974dc
Use id for doc id if it exists
2021-12-09 09:16:58 -05:00
Jason Ertel
a9b7b9ee92
Jinjafy case params
2021-12-08 17:41:48 -05:00
m0duspwnens
7390b03dc1
dont show es options in final whiptail setup confirmation
2021-12-08 14:58:34 -05:00
m0duspwnens
b4bc32d3ca
set logstash pillar and enable avanced ls menu for so-receiver
2021-12-08 14:33:15 -05:00
m0duspwnens
ecc8594d44
prevent so-receiver from getting extra keys/certs
2021-12-08 13:32:56 -05:00
m0duspwnens
59464af10c
filebeat certs for logstash on so-receiver
2021-12-08 09:41:17 -05:00
m0duspwnens
1ef63f3a23
ssl things for so-receiver
2021-12-08 09:08:46 -05:00
m0duspwnens
c80059efb0
change from || to &&
2021-12-07 17:11:15 -05:00
m0duspwnens
8c95d0f36b
set ip for wazuh-register-agent and dont apply nginx in setup for receiver
2021-12-07 16:50:41 -05:00
m0duspwnens
429b9cab2f
set ip for ossec.conf
2021-12-07 16:22:07 -05:00
m0duspwnens
f8da5c7fe9
start of fw rules for receiver
2021-12-07 15:59:11 -05:00
m0duspwnens
06010bd157
add so-receiver to allowed_states
2021-12-07 13:34:06 -05:00
Jason Ertel
b73eb76c94
Make case module dynamic
2021-12-07 11:51:02 -05:00
m0duspwnens
f3ec5df447
add receiver node
2021-12-07 11:13:51 -05:00
m0duspwnens
7549e34881
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-07 10:57:12 -05:00
m0duspwnens
ba30c59ec7
add receiver node
2021-12-07 10:56:35 -05:00
Mike Reeves
892899b7f9
Merge pull request #6477 from Security-Onion-Solutions/merge-202112071526
...
Merge hotfix
2021-12-07 10:30:13 -05:00
Jason Ertel
702d95c63a
Merge branch 'master' into merge-202112071527
2021-12-07 10:28:00 -05:00
m0duspwnens
96666ab307
add receiver node
2021-12-07 10:19:32 -05:00
Mike Reeves
9f41df641e
Merge pull request #6470 from Security-Onion-Solutions/hotfix/2.3.90
...
HOTFIX: 2.3.90-20211206
2021-12-07 09:51:01 -05:00
Mike Reeves
9f94ecfab7
Merge pull request #6466 from Security-Onion-Solutions/2390updates3
...
2.3.90 hotfix 20211206
2021-12-06 11:07:14 -05:00
Mike Reeves
4188282724
2.3.90 hotfix 20211206
2021-12-06 11:03:49 -05:00
Mike Reeves
3945933dec
Merge pull request #6446 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-12-06 09:38:02 -05:00
Mike Reeves
73a1a3878f
Update HOTFIX
2021-12-06 09:37:07 -05:00
weslambert
ff25d6f80b
Merge pull request #6447 from Security-Onion-Solutions/eg_dashes
...
Add initial EG dashboards
2021-12-03 18:05:22 -05:00
Wes Lambert
0571612ea1
Add initial EG dashes
2021-12-03 22:38:30 +00:00
Mike Reeves
f697d88090
Update HOTFIX
2021-12-03 15:36:16 -05:00
Mike Reeves
ad03241910
Merge pull request #6445 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Apply hotfix to all 2.3.90 installs
2021-12-03 15:24:33 -05:00
Mike Reeves
f82d204c0e
Update soup
2021-12-03 15:20:33 -05:00
Mike Reeves
780daf8aa7
Apply hotfix to all 2.3.90 installs
2021-12-03 15:15:45 -05:00
Josh Patterson
5008b647b0
Merge pull request #6441 from Security-Onion-Solutions/hf/soc_append2.3.90
...
export LC_CTYPE="en_US.UTF-8" in soup
2021-12-03 15:10:12 -05:00
m0duspwnens
65b1ab833d
run salt-call locally as if no Salt master were present during reinstall - https://github.com/Security-Onion-Solutions/securityonion/discussions/6435
2021-12-03 12:00:29 -05:00
m0duspwnens
c6773a0bbc
move "Preparing soup" to main so shows in soup.log
2021-12-03 10:26:22 -05:00
m0duspwnens
ff2d2c7c04
export LC_CTYPE="en_US.UTF-8" - https://github.com/Security-Onion-Solutions/securityonion/discussions/6431
2021-12-02 16:39:32 -05:00
Mike Reeves
6c7a1f23f5
Merge pull request #6440 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Fix for the clustername used in wrong context
2021-12-02 15:35:26 -05:00
Mike Reeves
f5761c73a5
Fix for the clustername used in wrong context
2021-12-02 15:30:35 -05:00
Mike Reeves
8448778ecd
Merge pull request #6438 from Security-Onion-Solutions/hf/soc_append2.3.90
...
hf/soc append2.3.90
2021-12-02 15:10:51 -05:00
m0duspwnens
8d667795a7
only add soc:es_index_patterns to pillar if not already present
2021-12-02 10:28:17 -05:00
m0duspwnens
7a664ab8f7
more error proof up_to_2.3.90 function
2021-12-02 10:02:26 -05:00
Jason Ertel
83fab42b6e
Merge pull request #6433 from Security-Onion-Solutions/kilo
...
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:39:14 -05:00
Jason Ertel
e549cfdf82
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:35:13 -05:00
Josh Brower
c7a9fb1fa3
Merge pull request #6432 from Security-Onion-Solutions/fix/fleet-nginx
...
Fix FleetDM nginx errors
2021-12-02 08:30:28 -05:00
Josh Brower
97cd679d74
Fix FleetDM nginx errors
2021-12-02 08:17:01 -05:00
William Wernert
3bd8bcba12
Merge pull request #6421 from Security-Onion-Solutions/hotfix-merge
...
Hotfix merge
2021-12-01 14:49:05 -05:00
William Wernert
6e7188b4d8
Merge branch 'hotfix/2.3.90' into hotfix-merge
...
# Conflicts:
# HOTFIX
2021-12-01 14:40:34 -05:00
m0duspwnens
5e0ac89841
merge with master
2021-12-01 14:27:58 -05:00
Mike Reeves
8990a09d92
Merge pull request #6418 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-01 13:24:19 -05:00
Mike Reeves
946673dc3b
Merge pull request #6417 from Security-Onion-Solutions/2390updates2
...
2.3.90 hotfix airgap
2021-12-01 13:20:41 -05:00
m0duspwnens
c571b2c499
handle redirect if more than 1 match from compgen
2021-12-01 13:17:14 -05:00
Mike Reeves
80c569317f
2.3.90 hotfix airgap
2021-12-01 13:16:13 -05:00
Mike Reeves
84b91c547d
Merge pull request #6403 from Security-Onion-Solutions/dlee35-patch-1
...
add subjectAltName to filebeat.crt
2021-12-01 11:54:05 -05:00
Mike Reeves
5f121f3b99
Merge pull request #6411 from Security-Onion-Solutions/m0duspwnens-patch-1/hotfix/2.3.90
...
remove redirect to /dev/null for compgen
2021-12-01 10:17:29 -05:00
Josh Patterson
63cb486698
remove redirect to /dev/null for compgen
2021-12-01 10:16:04 -05:00
Dustin Lee
8a394380cb
add subjectAltName to filebeat.crt
...
IP SAN is required for Endgame integration w/Logstash when DNS resolution is unavailable
2021-11-30 16:24:08 -05:00
William Wernert
1a31e60e47
Merge pull request #6402 from Security-Onion-Solutions/fix/airgap-check
...
Fix/airgap check
2021-11-30 15:57:02 -05:00
William Wernert
168f860c87
Add hotfix string to HOTFIX
2021-11-30 15:49:41 -05:00
William Wernert
8d87fae6a8
Remove airgap repo file if it shouldn't exist
2021-11-30 15:46:22 -05:00
William Wernert
739efc22d2
Fix airgap check logic
2021-11-30 15:46:18 -05:00
Jason Ertel
1272de3058
Merge pull request #6378 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
bump version to 2.3.100
2021-11-29 09:57:29 -05:00
Mike Reeves
2beb69f495
Update HOTFIX
2021-11-29 09:55:32 -05:00
Mike Reeves
5a447c53d9
bump version to 2.3.100
2021-11-29 09:55:01 -05:00
Jason Ertel
31ffd6c4ec
Merge pull request #6339 from Security-Onion-Solutions/kilo
...
Merge 2.3.90 WAZUH hotfix into dev
2021-11-23 19:33:18 -05:00
Mike Reeves
4c6786a412
Merge pull request #6335 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-11-23 16:51:27 -05:00
Mike Reeves
5062e910e2
Merge pull request #6334 from Security-Onion-Solutions/2390updates
...
2.3.90 hotfix soup
2021-11-23 15:41:21 -05:00
Mike Reeves
1f9dc0db1f
2.3.90 hotfix soup
2021-11-23 15:40:04 -05:00
Mike Reeves
c536e11383
2.3.90 hotfix soup
2021-11-23 15:32:41 -05:00
Mike Reeves
faa8464b60
Merge pull request #6333 from Security-Onion-Solutions/kilo
...
Correct if check to inline the command instead of checking for emptin…
2021-11-23 14:53:24 -05:00
Jason Ertel
4f283c2d86
Suppres grep output
2021-11-23 14:52:40 -05:00
Jason Ertel
801d42ed20
Correct if check to inline the command instead of checking for emptiness of a variable
2021-11-23 14:51:06 -05:00
Mike Reeves
30a1ffc1c7
Merge pull request #6329 from Security-Onion-Solutions/kilo
...
2.3.90 WAZUH
2021-11-23 13:37:41 -05:00
Jason Ertel
59fc122eec
Force restart of wazuh since conf file is changing
2021-11-23 13:29:04 -05:00
Jason Ertel
52ffa27eda
Update hotfix file
2021-11-23 13:22:47 -05:00
Jason Ertel
bd59d65f02
Strip trailing newlines from version and hotfix files
2021-11-23 13:12:27 -05:00
Jason Ertel
01ceded223
Handle CRs in hotfix
2021-11-23 13:03:40 -05:00
Jason Ertel
3c37bd61ab
Add debug logging
2021-11-23 12:46:59 -05:00
Jason Ertel
a35670c889
Merge branch 'hotfix/1.3.90' into kilo
2021-11-23 12:38:57 -05:00
Jason Ertel
7627d37386
Add 2.3.90 WAZUH hotfix corrective function
2021-11-23 12:21:28 -05:00
Jason Ertel
273842eb43
Merge pull request #6328 from Security-Onion-Solutions/kilo
...
WAZUH hotfix
2021-11-23 12:06:34 -05:00
Jason Ertel
0dd251e2a9
Fix typo in whiptail prompt
2021-11-23 11:19:53 -05:00
Josh Patterson
c67b2b6936
Update soup
...
only check if salt was upgraded if upgrade_salt function was called
2021-11-23 11:14:10 -05:00
Jason Ertel
af4c04be59
Fix #6325 - Prevent XML header from outputting to ossec.conf
2021-11-23 10:57:21 -05:00
Jason Ertel
4672b0c15c
Fix #6317 - Do not attempt to whitelist when wazuh isn't enabled
2021-11-23 10:06:14 -05:00
Jason Ertel
9737a4088c
Merge pull request #6327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-11-23 09:25:43 -05:00
Mike Reeves
d8d429c71a
Update HOTFIX
2021-11-23 09:19:41 -05:00
Mike Reeves
3bfc3b8943
Merge pull request #6301 from Security-Onion-Solutions/dev
...
2.3.90
2021-11-22 13:15:23 -05:00
Mike Reeves
4ad6d616ae
Merge pull request #6313 from Security-Onion-Solutions/2390update
...
2390update
2021-11-22 09:04:16 -05:00
Mike Reeves
759c0b858a
2.3.90
2021-11-22 09:01:12 -05:00
Mike Reeves
c17a49a730
Merge pull request #6302 from Security-Onion-Solutions/fix/md5soup
...
Fix/md5soup
2021-11-19 16:45:02 -05:00
m0duspwnens
c0f183fb5e
add comment
2021-11-19 16:37:27 -05:00
m0duspwnens
d602339c45
render and md5sum soup and so-common
2021-11-19 16:32:59 -05:00
Mike Reeves
0122e62920
Merge pull request #6300 from Security-Onion-Solutions/2390
...
2.3.90
2021-11-19 14:09:02 -05:00
Mike Reeves
1634105780
2.3.90
2021-11-19 14:07:03 -05:00
Josh Patterson
198a690ba1
Merge pull request #6298 from Security-Onion-Solutions/fix/soup-script-check
...
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:24:48 -05:00
William Wernert
bebd62187d
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:23:32 -05:00
Mike Reeves
a91564605c
Merge pull request #6297 from Security-Onion-Solutions/fix/soup-playbook-secrets
...
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:28:11 -05:00
William Wernert
23b91ee7e5
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:27:11 -05:00
Mike Reeves
d3f25f8d74
Merge pull request #6293 from Security-Onion-Solutions/fix/fleet-stats
...
Fix FleetDM - disable stats
2021-11-19 09:53:26 -05:00
Josh Brower
8bd4ba3acd
Fix FleetDM - disable stats
2021-11-19 09:49:34 -05:00
Josh Patterson
e5927d0bf7
Merge pull request #6290 from Security-Onion-Solutions/fleet_startup_eval
...
run redis state before fleet state for eval highstate
2021-11-18 17:54:26 -05:00
m0duspwnens
9dd89f6be7
run redis state before fleet state for eval highstate
2021-11-18 17:41:56 -05:00
Mike Reeves
796eb59dc6
Merge pull request #6288 from Security-Onion-Solutions/syncesusers_so-kratos
...
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:42:18 -05:00
m0duspwnens
55fed43469
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:35:35 -05:00
William Wernert
af83019427
Merge pull request #6287 from Security-Onion-Solutions/feat/cidr-extra-validation
...
Check for more invalid cidr syntax
2021-11-18 15:21:58 -05:00
William Wernert
4149236cda
Check for more invalid cidr syntax
2021-11-18 15:18:12 -05:00
Josh Patterson
825106d074
Merge pull request #6286 from Security-Onion-Solutions/fix/docker-upgrade
...
Prevent downgrade of docker, containerd, and docker-cli
2021-11-18 15:15:37 -05:00
William Wernert
1a3324868a
Specify version of docker-ce-rootless-extras
2021-11-18 15:12:47 -05:00
William Wernert
bc87bb4770
Specify docker cli version as well
2021-11-18 14:51:26 -05:00
William Wernert
6aae48bdae
Don't upgrade docker or containerd before versionlock is applied
2021-11-18 14:14:18 -05:00
Mike Reeves
a0425a48e6
Merge pull request #6282 from Security-Onion-Solutions/syncesusers_so-kratos
...
remove restart policy for kratos container
2021-11-18 11:43:16 -05:00
m0duspwnens
4b89bf7bbc
remove restart policy for kratos container
2021-11-18 11:41:07 -05:00
Mike Reeves
5fc5afa9ea
Merge pull request #6281 from Security-Onion-Solutions/syncesusers_so-kratos
...
install specific docker verison
2021-11-18 11:32:38 -05:00
m0duspwnens
ddec8e4da0
install specific docker verison
2021-11-18 11:29:22 -05:00
Jason Ertel
9c0e8cedba
Merge pull request #6279 from Security-Onion-Solutions/syncesusers_so-kratos
...
restart kratos if failure
2021-11-18 10:49:12 -05:00
m0duspwnens
5054da0027
restart kratos if failure
2021-11-18 10:48:06 -05:00
Jason Ertel
96f1f0174b
Merge pull request #6275 from Security-Onion-Solutions/syncesusers_so-kratos
...
break kratos state out from soc state
2021-11-18 09:13:10 -05:00
m0duspwnens
cd1f0c0440
break kratos state out from soc state
2021-11-18 09:10:00 -05:00
Mike Reeves
12546a8efa
Merge pull request #6271 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 19:48:15 -05:00
Josh Brower
3f5956b56d
Fix soup - fleetdm SA user
2021-11-17 19:47:16 -05:00
Mike Reeves
6e49ab0558
Merge pull request #6270 from Security-Onion-Solutions/fix/whiptail-text
...
Fix text cutoff
2021-11-17 19:18:46 -05:00
William Wernert
c52df32f05
Fix text cutoff
2021-11-17 19:08:10 -05:00
Josh Patterson
c0602f4222
Merge pull request #6269 from Security-Onion-Solutions/syncesusers_so-kratos
...
run elasticsearch.auth state and so-elastic-auth true before manager …
2021-11-17 18:41:18 -05:00
m0duspwnens
d4b412bcbe
run elasticsearch.auth state and so-elastic-auth true before manager in setup for syncesusers in manager state
2021-11-17 18:38:13 -05:00
Josh Brower
66e2de0934
Merge pull request #6268 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 18:26:11 -05:00
Josh Brower
c93794a402
Fix soup - fleetdm SA user
2021-11-17 18:22:34 -05:00
Josh Patterson
98efc6f2ed
Merge pull request #6267 from Security-Onion-Solutions/syncesusers_so-kratos
...
syncesusers require so-kratos
2021-11-17 18:20:53 -05:00
m0duspwnens
59ef734064
syncesusers require so-kratos
2021-11-17 18:16:06 -05:00
Josh Brower
922657afbc
Merge pull request #6266 from Security-Onion-Solutions/fix/fleet-users
...
Unset pw reset for new Fleet users
2021-11-17 17:10:27 -05:00
Josh Brower
5f3601ac78
Unset pw reset for new Fleet users
2021-11-17 17:06:01 -05:00
Josh Brower
2fe4fa06a6
Merge pull request #6265 from Security-Onion-Solutions/fix/fleet-users
...
Fix FleetDM SA Creation for SOUP
2021-11-17 14:09:59 -05:00
Josh Brower
773c580e77
Fix FleetDM SA Creation for SOUP
2021-11-17 14:08:34 -05:00
Mike Reeves
aca684d55a
Merge pull request #6264 from Security-Onion-Solutions/fix/fleet-users
...
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:16:05 -05:00
Josh Brower
6f391dbe50
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:13:25 -05:00
William Wernert
8d033264e7
Merge pull request #6262 from Security-Onion-Solutions/fix/new-cidr-test
...
Add new ipv4 address w/ cidr mask validator
2021-11-17 13:09:04 -05:00
William Wernert
262d2023b5
Add new ipv4 address w/ cidr mask validator
2021-11-17 12:41:25 -05:00
Josh Patterson
d143a309a1
Merge pull request #6261 from Security-Onion-Solutions/soup_soc_endgame
...
change how soc endgame added to manager pillar in soup
2021-11-17 11:12:17 -05:00
m0duspwnens
ac400f1c41
change how soc endgame added to manager pillar in soup
2021-11-17 11:07:12 -05:00
William Wernert
df495c0017
Merge pull request #6258 from Security-Onion-Solutions/fix/nm-conf
...
Run `check_network_manager_conf()` later in setup
2021-11-17 08:44:25 -05:00
William Wernert
8c454973ad
Run check_network_manager_conf() later in setup
...
The directory was being overwritten when network-manager was installed later
2021-11-17 08:42:27 -05:00
Josh Patterson
a16e6aca22
Merge pull request #6257 from Security-Onion-Solutions/es_soup_ingest
...
escape raw and endraw
2021-11-17 07:56:01 -05:00
m0duspwnens
ce21ae11f5
escape raw and endraw
2021-11-17 07:53:15 -05:00
Mike Reeves
fdd9706669
Merge pull request #6255 from Security-Onion-Solutions/kilo
2021-11-16 18:09:40 -05:00
Jason Ertel
8fa9a180b2
Refactor upgrade and post-upgrade version to function mappings; fix missing version upgrades from older 2.3.61 releases and earlier; Drop support for upgrading ancient RC releases
2021-11-16 18:08:28 -05:00
Josh Patterson
6288365a50
Merge pull request #6254 from Security-Onion-Solutions/es_soup_ingest
...
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:47:53 -05:00
m0duspwnens
5448107310
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:43:33 -05:00
Mike Reeves
adaf3faf90
Merge pull request #6253 from Security-Onion-Solutions/kilo
2021-11-16 16:13:31 -05:00
Jason Ertel
1bd8e226b4
Force DB migration since installations on 2.3.50 or earlier will skip the Kratos 0.6 version
2021-11-16 15:58:04 -05:00
Josh Patterson
f60f0b5b6d
Merge pull request #6246 from Security-Onion-Solutions/es_soup_ingest
...
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:05:15 -05:00
William Wernert
adc867846c
Merge pull request #6245 from Security-Onion-Solutions/fix/ubuntu-nic-unmanaged
...
Modify network-manager conf earlier in setup
2021-11-16 14:00:58 -05:00
m0duspwnens
5945326817
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:00:41 -05:00
William Wernert
90cbb5d00e
Modify network-manager conf earlier in setup
2021-11-16 13:30:09 -05:00
Josh Brower
8bb2789c6f
Merge pull request #6237 from Security-Onion-Solutions/kilo
...
Migrate to email field instead of username due to breaking change in …
2021-11-16 12:06:08 -05:00
Jason Ertel
11fc0da971
Migrate to email field instead of username due to breaking change in FleetDM 4.x
2021-11-16 12:03:46 -05:00
William Wernert
76a1d767f2
Merge pull request #6235 from Security-Onion-Solutions/feature/preflight-retry
...
Retry failed URLs in so-preflight + improve logging clarity
2021-11-16 11:11:02 -05:00
William Wernert
a2152446ea
Pad count string to align text
2021-11-16 11:08:13 -05:00
William Wernert
d4d9032bfc
Remove confusing punctuation
2021-11-16 10:56:49 -05:00
William Wernert
4e3f43bee4
Fix variable name
2021-11-16 10:53:22 -05:00
William Wernert
57377e0a0e
Add retry support + more precise logging to so-preflight
2021-11-16 10:46:48 -05:00
Mike Reeves
2514d36ccd
Merge pull request #6232 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2021-11-15 17:11:08 -05:00
Mike Reeves
809dbc0a48
Merge pull request #6233 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2021-11-15 17:10:52 -05:00
Mike Reeves
b51405d5e8
Update soup
2021-11-15 17:04:46 -05:00
Mike Reeves
d1cfc4a8dc
Merge pull request #6231 from Security-Onion-Solutions/fix/whiptail-cutoff
...
Fix whiptail description text
2021-11-15 17:02:00 -05:00
Mike Reeves
731bbabe4c
Update init.sls
2021-11-15 17:00:34 -05:00
William Wernert
d4509ff4d8
Fix whiptail description text
2021-11-15 16:29:26 -05:00
Mike Reeves
85c0b0818b
Merge pull request #6230 from Security-Onion-Solutions/fix/cidr-full-validation-bash
...
Check CIDR validity completely
2021-11-15 15:43:58 -05:00
William Wernert
f674555290
Check CIDR validity completely
2021-11-15 15:43:05 -05:00
Josh Patterson
a8aae544d5
Merge pull request #6229 from Security-Onion-Solutions/kibana_json_logging
...
change kibana logging to json
2021-11-15 14:27:04 -05:00
m0duspwnens
6f9db25ea7
change kibana logging to json
2021-11-15 14:23:47 -05:00
Mike Reeves
405e78858a
Merge pull request #6228 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2021-11-15 14:07:23 -05:00
Mike Reeves
146e1f4297
Update soup
2021-11-15 14:05:29 -05:00
Mike Reeves
f78e0fb7b9
Merge pull request #6227 from Security-Onion-Solutions/fix/fleetlogging
...
Fix env var for logging
2021-11-15 14:00:31 -05:00
Josh Brower
6e6d2d1949
Fix env var for logging
2021-11-15 13:52:35 -05:00
Josh Patterson
ca5d20fecb
Merge pull request #6225 from Security-Onion-Solutions/clean_meta_data
...
clean metadata with cmd.run instead of pkg module due to False return…
2021-11-15 11:03:41 -05:00
m0duspwnens
dcfaece8b1
clean metadata with cmd.run instead of pkg module due to False return from module
2021-11-15 11:00:31 -05:00
Mike Reeves
af0e062193
Merge pull request #6221 from Security-Onion-Solutions/fix/var-reference
...
Fix variable reference in so-functions
2021-11-15 09:49:07 -05:00
Mike Reeves
56acedfbf7
Merge pull request #6220 from Security-Onion-Solutions/fix/revert-python-validation
...
Fix/revert python validation
2021-11-15 09:44:31 -05:00
William Wernert
4b0a5c3a17
Un-revert validation test script
2021-11-15 09:43:43 -05:00
William Wernert
052192e1d6
Revert "Use python lib to make cidr validation more strict"
...
This reverts commit 569cb24861 .
2021-11-15 09:43:18 -05:00
weslambert
92131d4bb7
Merge pull request #6215 from Security-Onion-Solutions/fix/eg_spelling
...
Fix spelling
2021-11-12 21:13:28 -05:00
weslambert
9ac1cb0e76
Fix spelling
2021-11-12 21:12:09 -05:00
Josh Patterson
ffbb04bb5a
Merge pull request #6213 from Security-Onion-Solutions/issue/5809
...
Issue/5809
2021-11-12 15:07:54 -05:00
m0duspwnens
cc1dea446c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/5809
2021-11-12 15:02:22 -05:00
m0duspwnens
7f3379e034
verify manager pillars can be rendered before proceeding with soup - https://github.com/Security-Onion-Solutions/securityonion/issues/5809
2021-11-12 15:02:16 -05:00
weslambert
8c46a2d1db
Merge pull request #6210 from Security-Onion-Solutions/fix/soc_pillar_soup
...
Add SOC pillar entry
2021-11-12 13:35:46 -05:00
William Wernert
ba621639bd
Merge pull request #6201 from Security-Onion-Solutions/fix/cidr-ip-validation
...
Improve cidr validation in setup and match ip validation to similar method
2021-11-12 13:34:19 -05:00
Wes Lambert
2fb9196604
Move logic above version declaration
2021-11-12 18:26:21 +00:00
Wes Lambert
48c71c8b12
Add soc pillar entry
2021-11-12 18:23:09 +00:00
weslambert
8d185ced61
Merge pull request #6209 from Security-Onion-Solutions/fix/endgame_setup
...
Adjust manager pillar config for Endgame and defaults
2021-11-12 12:27:55 -05:00
William Wernert
9141c271f0
Fix indent
2021-11-12 12:25:32 -05:00
weslambert
bc2e470da9
Fix indentation
2021-11-12 12:20:00 -05:00
weslambert
0f817cd735
Merge pull request #6208 from Security-Onion-Solutions/fix/endgame_pivot
...
Make Endgame pivot independent
2021-11-12 12:17:24 -05:00
weslambert
df5901a65d
Adjust how manager pillar is populated for ENDGAME and default SOC config
2021-11-12 12:16:26 -05:00
weslambert
3cd1b5687e
Make pivot condition independent for ENDGAMEHOST
2021-11-12 12:06:39 -05:00
Josh Patterson
86a42addf0
Merge pull request #6207 from Security-Onion-Solutions/so_elastic_auth_password_reset
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:43:31 -05:00
m0duspwnens
6bf4d5a576
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:37:55 -05:00
William Wernert
efa5eb9f7f
Merge pull request #6184 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-11 13:57:07 -05:00
Josh Patterson
22959f0260
Merge pull request #6195 from Security-Onion-Solutions/issue/6146
...
Issue/6146
2021-11-11 11:47:33 -05:00
m0duspwnens
8da2133cff
give kibana.secrets pillar to import node
2021-11-11 11:31:07 -05:00
William Wernert
1472af4fc3
Merge branch 'dev' into foxtrot
2021-11-11 09:03:05 -05:00
Josh Brower
f91a6d3cb6
Merge pull request #6194 from Security-Onion-Solutions/fix/fleetstandalone
...
Add Fleet Standalone Node to manager ssl
2021-11-11 08:52:29 -05:00
Josh Brower
96f427d924
Add so-fleet to cert requirements
2021-11-11 08:45:22 -05:00
Josh Brower
184356618c
Add Fleet Standalone Node to manager ssl
2021-11-11 08:28:22 -05:00
William Wernert
ed3b2e4569
Put entire ref to doc page on new line
2021-11-10 17:46:35 -05:00
William Wernert
62b41af069
Fix docs link being cut off
2021-11-10 17:17:19 -05:00
William Wernert
569cb24861
Use python lib to make cidr validation more strict
...
Also update ipv4 validation to match the method used to validate cidr strings
2021-11-10 16:53:01 -05:00
William Wernert
ac22df8381
Merge branch 'dev' into foxtrot
2021-11-10 16:51:31 -05:00
Mike Reeves
446d6bd532
Merge pull request #6189 from Security-Onion-Solutions/soup2390
...
Soup2390
2021-11-10 16:49:46 -05:00
Mike Reeves
fcf889be2f
Add soup to 2.3.90
2021-11-10 16:46:24 -05:00
Mike Reeves
8168f19b31
Add soup to 2.3.90
2021-11-10 16:37:54 -05:00
Mike Reeves
ba553d971c
Add soup to 2.3.90
2021-11-10 16:31:44 -05:00
Mike Reeves
9137454a25
Add soup placeholders
2021-11-10 16:08:07 -05:00
m0duspwnens
7ebd861e32
enable secureCookies, security.encryptionKey and reporting.encryptionKey - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-10 16:05:40 -05:00
William Wernert
d110b63050
Merge pull request #6187 from Security-Onion-Solutions/fix/so-rule-modify-example
...
Fix `so-rule modify` example
2021-11-10 14:31:28 -05:00
William Wernert
3806f10f8b
Fix so-rule modify example
2021-11-10 14:18:32 -05:00
Jason Ertel
83bd314a63
Merge pull request #6186 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.2
2021-11-10 14:06:08 -05:00
Jason Ertel
6cd7b252df
Upgrade to ES 7.15.2
2021-11-10 13:59:55 -05:00
Jason Ertel
dea03bbf5e
Upgrade to ES 7.15.2
2021-11-10 13:44:20 -05:00
Josh Brower
9edc543262
Merge pull request #6183 from Security-Onion-Solutions/delta
...
Upgrade FleetDM to 4.5
2021-11-10 11:35:12 -05:00
Josh Brower
d3dc5ffc5a
Fix salt syntax
2021-11-10 11:28:48 -05:00
William Wernert
2c296e832f
Remove references to CURCLOSEDAYS in setup
...
Curator is configured differently now so the variable set during setup is no longer in use
2021-11-10 11:25:51 -05:00
Josh Brower
b350174df1
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-11-10 11:08:36 -05:00
Josh Brower
67ebfeab16
Disable FleetDM usage stats
2021-11-10 10:49:56 -05:00
Josh Brower
435f430747
Fix enroll secret parsing
2021-11-10 10:24:53 -05:00
Josh Patterson
aa9e1701f0
Merge pull request #6180 from Security-Onion-Solutions/issue/5794
...
timeout wazuh-register-agent faster
2021-11-10 09:58:05 -05:00
m0duspwnens
02d9b87f66
https://github.com/Security-Onion-Solutions/securityonion/issues/5794
2021-11-10 09:54:51 -05:00
Josh Patterson
cfd46c1e58
Merge pull request #6176 from Security-Onion-Solutions/bravo
...
Grafana improvements, pillarize kibana
2021-11-10 09:18:47 -05:00
m0duspwnens
392305e4ed
add engame changes that were missing from merge somehow
2021-11-10 09:01:42 -05:00
m0duspwnens
5ff14ab652
Merge remote-tracking branch 'origin/issue/6007' into bravo
2021-11-09 18:31:56 -05:00
m0duspwnens
1890c7244a
set elasticsearch:auth to persist through user pw change
2021-11-09 18:25:17 -05:00
m0duspwnens
a8c4ed7bbf
set elasticsearch:auth:enabled True in auth pillar
2021-11-09 18:05:05 -05:00
m0duspwnens
91f54537d7
handle elasticsearch.auth state like kibana.secrets
2021-11-09 17:52:38 -05:00
m0duspwnens
7e3a4656aa
change xpack update
2021-11-09 17:33:09 -05:00
m0duspwnens
8a04fcd919
change how key is added
2021-11-09 17:07:20 -05:00
m0duspwnens
409ab623a5
ensure kibana pillar dir exists
2021-11-09 16:49:45 -05:00
m0duspwnens
ac85d1598e
dont show changes
2021-11-09 16:44:54 -05:00
m0duspwnens
4c8e68e014
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-11-09 16:42:47 -05:00
m0duspwnens
57c6e26634
encrypt kibana saved objects - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-09 16:41:25 -05:00
m0duspwnens
b6a1d7418e
fix typo, dont show changes for kibana.yaml or dashboard so
2021-11-09 16:14:48 -05:00
weslambert
6eb1a0b0ae
Merge pull request #6169 from Security-Onion-Solutions/fix/ingest_dynamic_ref
...
Add dynamic conf to config change check
2021-11-09 16:11:38 -05:00
weslambert
9301b8f5b9
Add dynamic conf to config change check
2021-11-09 15:56:52 -05:00
m0duspwnens
202977a323
create so script to load saved object defaults
2021-11-09 15:54:15 -05:00
weslambert
9597373e4a
Merge pull request #6167 from Security-Onion-Solutions/ecs_pipeline_common
...
Add config for dynamically formatted ingest pipelines
2021-11-09 15:41:43 -05:00
Wes Lambert
f80b70e008
Add config for dynamically formatted ingest pipelines
2021-11-09 20:07:53 +00:00
William Wernert
04d2b52306
Fix IP route whiptail error
2021-11-09 14:03:32 -05:00
m0duspwnens
af7830c2be
remove reference to saved_objects in defaults
2021-11-09 13:52:47 -05:00
m0duspwnens
3c3cb47b88
merge with dev
2021-11-09 13:07:35 -05:00
m0duspwnens
da4e92a7a3
change config id
2021-11-09 12:13:28 -05:00
Mike Reeves
3afb0bd263
Merge pull request #6161 from Security-Onion-Solutions/sslchange
...
Enable Subject Alt Name for registry
2021-11-09 10:53:38 -05:00
Josh Brower
f6e6b20392
Add Name and OrgName to Fleet setup
2021-11-09 09:20:47 -05:00
William Wernert
3835a4401e
Merge pull request #6157 from Security-Onion-Solutions/foxtrot
...
Fix preflight script on centos
2021-11-09 08:49:46 -05:00
William Wernert
4bae57d994
Fix preflight printing to log
2021-11-09 08:34:02 -05:00
William Wernert
ea7289d92e
Fix preflight script on centos
2021-11-09 08:20:19 -05:00
m0duspwnens
48eaf190e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6007
2021-11-08 17:00:06 -05:00
m0duspwnens
497de0fede
hide vars on pipeline overview
2021-11-08 16:54:39 -05:00
m0duspwnens
70e3bc7eb8
hide vars on pipeline overview
2021-11-08 16:52:15 -05:00
Mike Reeves
eefc9cfcb6
Enable Subject Alt Name for registry
2021-11-08 16:50:43 -05:00
m0duspwnens
42b8955883
panel cleanup
2021-11-08 16:33:57 -05:00
m0duspwnens
f6b753b805
panel cleanup
2021-11-08 16:26:41 -05:00
m0duspwnens
17fc03a553
pipleine overview tc changes
2021-11-08 16:15:42 -05:00
weslambert
8bf88043ac
Merge pull request #6149 from Security-Onion-Solutions/add_test_pipeline
...
Add ECS testing pipeline
2021-11-08 15:43:03 -05:00
m0duspwnens
79640342f2
update redis queue query
2021-11-08 15:20:28 -05:00
Mike Reeves
3ad47742bd
Merge pull request #6150 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2021-11-08 15:18:35 -05:00
Mike Reeves
a8c02252dc
Update acng.conf
2021-11-08 15:16:05 -05:00
m0duspwnens
fbef420155
update redis queue query
2021-11-08 15:15:53 -05:00
m0duspwnens
ccd84e441d
add redis queue to pipeline overview
2021-11-08 15:09:46 -05:00
Wes Lambert
46d3eb452d
Add ECS testing pipeline
2021-11-08 20:08:56 +00:00
Josh Brower
083d467aa9
Update to FleetDM 4.5
2021-11-08 15:05:58 -05:00
m0duspwnens
f026ac1b41
pipeline overview tc changes
2021-11-08 15:02:52 -05:00
m0duspwnens
9ea292b11e
fix query
2021-11-08 13:48:33 -05:00
m0duspwnens
e2ee460fdd
fix gridPos
2021-11-08 12:39:23 -05:00
m0duspwnens
5b70ff61d1
fix gridPos
2021-11-08 12:37:03 -05:00
m0duspwnens
3b2ca89852
use endif not fi
2021-11-08 12:20:07 -05:00
m0duspwnens
199c97684c
fix nontc name in defaults
2021-11-08 12:10:23 -05:00
m0duspwnens
d67e34dac4
add pipeline overview for true cluster
2021-11-08 12:09:35 -05:00
William Wernert
49a573074e
Merge pull request #6142 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-08 11:29:58 -05:00
William Wernert
6c16d6d222
Update invalid hostname message
2021-11-08 11:15:28 -05:00
William Wernert
acba82d194
Update dist install menus' top text
2021-11-08 11:04:51 -05:00
William Wernert
f66d915f5d
Normal hostname check already checks for localhost
2021-11-08 10:38:30 -05:00
William Wernert
ee2dd75dfd
Fix variable ref
2021-11-08 10:36:36 -05:00
William Wernert
50b7779d6e
Make manager hostname error more specific
2021-11-08 10:35:28 -05:00
William Wernert
ad71485361
Fix whiptail height
2021-11-08 10:21:55 -05:00
William Wernert
8b2cccdf4a
More whiptail formatting
2021-11-08 10:21:17 -05:00
William Wernert
dbe4a7de63
Fix new whiptail layouts
2021-11-08 10:19:38 -05:00
William Wernert
9c4bba9ac9
Fix variable reference
2021-11-08 10:08:23 -05:00
Doug Burks
b3fd7c548c
Merge pull request #6135 from Security-Onion-Solutions/dougburks-patch-1
...
Improve clarity in CONTRIBUTING.md
2021-11-08 08:53:50 -05:00
Doug Burks
dcf6dfb676
Improve clarity
2021-11-08 06:38:16 -05:00
William Wernert
246d41c552
Add additional checks for manager hostname + ip
...
Check for current hostname, ip, and localhost (ip + string) when setting the manager ip and hostname
2021-11-05 15:56:08 -04:00
William Wernert
988932293f
Whiptail changes
...
* Ask whether to join to or create new dist install
* Also add links to architecture on install type prompts
2021-11-05 15:54:17 -04:00
m0duspwnens
0b28e89f3c
change how telegraf script determine if there is already and instance of the script already running
2021-11-04 23:22:13 -04:00
m0duspwnens
665732bd32
dont show points
2021-11-04 14:23:11 -04:00
m0duspwnens
b599b49630
enable beat input plugin for telegraf
2021-11-04 13:52:45 -04:00
m0duspwnens
edb3b602a9
pipeline overview dashboard changs
2021-11-04 10:59:01 -04:00
William Wernert
a4289b7ab9
Merge pull request #6107 from Security-Onion-Solutions/foxtrot
...
Manage docker gid and run preflight check during setup
2021-11-04 10:07:05 -04:00
Mike Reeves
9b0ce8b395
Merge pull request #6090 from Security-Onion-Solutions/commonupdate
...
Make common template honor replicas
2021-11-03 14:04:19 -04:00
m0duspwnens
05456b38d1
update panel
2021-11-03 13:54:05 -04:00
m0duspwnens
4fc58e7a5a
update panel
2021-11-03 13:51:57 -04:00
Mike Reeves
dc07aba63d
Update so-common-template.json.jinja
2021-11-03 13:50:31 -04:00
m0duspwnens
f1d66e2d51
change searchnode var
2021-11-03 13:40:09 -04:00
m0duspwnens
fab0dd2bad
add repeating es ingest panel for nontc
2021-11-03 13:25:42 -04:00
Mike Reeves
747f14d60e
Make common template honor replicas
2021-11-03 13:11:38 -04:00
William Wernert
fb35ff40b4
Just hide whiptail cancel message on test installs
2021-11-03 10:41:44 -04:00
m0duspwnens
2cb31a4c05
fix query
2021-11-03 09:27:02 -04:00
m0duspwnens
32f986c505
change panel
2021-11-03 09:23:21 -04:00
m0duspwnens
c8ee67f354
update panel for pipeline_overview
2021-11-03 09:12:32 -04:00
m0duspwnens
db80315c06
rename panel
2021-11-03 08:37:33 -04:00
m0duspwnens
8e3b08a831
start of pipeline dashboard
2021-11-03 08:33:20 -04:00
m0duspwnens
677f62ebd1
dont show changes for telegraf conf
2021-11-02 18:22:37 -04:00
William Wernert
d927e79154
Exit on failed preflight check during testing
2021-11-02 16:17:08 -04:00
William Wernert
8670aa6cd8
Run check-update in preflight instead of update
2021-11-02 14:29:58 -04:00
William Wernert
7c7c225a41
Fix tmp file check
2021-11-02 14:01:21 -04:00
m0duspwnens
54b034b537
fix spacing on es input
2021-11-02 13:43:59 -04:00
m0duspwnens
2232759fa4
rename file
2021-11-02 12:21:54 -04:00
m0duspwnens
f65eea6a03
rename file
2021-11-02 12:09:32 -04:00
William Wernert
e4a77acfe6
Move whiptail menus outside of progress func
2021-11-02 12:03:42 -04:00
William Wernert
9671dab2a3
Make so-preflight executable
2021-11-02 11:48:24 -04:00
William Wernert
e6adb46364
Run so-preflight during setup
2021-11-02 11:18:23 -04:00
m0duspwnens
7abb2e5935
monitor interface graph total
2021-11-02 11:07:29 -04:00
m0duspwnens
561f86eac8
change eps graphs to use logstash data and not consumptioneps script
2021-11-02 11:06:29 -04:00
William Wernert
9a9d1480de
Manage docker group's gid to prevent gid overlap
2021-11-02 10:41:36 -04:00
Josh Brower
8b52f87a60
Merge pull request #6066 from Security-Onion-Solutions/fix/evtx-import-elastic-creds
...
Fix/evtx import elastic creds
2021-11-02 09:25:25 -04:00
Josh Brower
a6f399acf4
Fix evtx import logging
2021-11-02 09:19:32 -04:00
Josh Brower
3534256517
Add evtx import logging
2021-11-02 09:03:52 -04:00
m0duspwnens
b109d95d6f
add max to zeek capture loss legend
2021-11-02 09:02:48 -04:00
Josh Brower
b756c0cd38
Pull ES Creds at Runtime
2021-11-02 08:57:11 -04:00
m0duspwnens
3517ea3f2a
select last value for cpucount var
2021-11-02 08:41:57 -04:00
m0duspwnens
5d414c8bdd
remove logstash row from manager
2021-11-02 08:36:13 -04:00
Josh Brower
2b56b53c15
Merge pull request #6064 from Security-Onion-Solutions/feature/support_non-wel_beats
...
Support non-WEL Beats
2021-11-02 08:29:48 -04:00
Josh Brower
2ba619144c
Support non-WEL Beats
2021-11-02 08:23:29 -04:00
m0duspwnens
a9be0a0409
create and add mon traffic combined graph to sensor dash
2021-11-02 07:55:39 -04:00
m0duspwnens
bf116d210e
mostly overview dash panel changes
2021-11-01 17:48:02 -04:00
William Wernert
f8b62b63f9
Merge pull request #6061 from Security-Onion-Solutions/foxtrot
...
Fix NIC string values for VLAN tagged interfaces
2021-11-01 16:43:52 -04:00
m0duspwnens
f4d9455872
revert to b63b50d98c
2021-11-01 16:10:13 -04:00
m0duspwnens
936c796b9d
Revert "graph changes"
...
This reverts commit 8857fca797 .
2021-11-01 15:19:50 -04:00
m0duspwnens
8ff122262c
Revert "update many panels"
...
This reverts commit b63b50d98c .
2021-11-01 14:50:57 -04:00
m0duspwnens
c4a1fbd82a
remove old json
2021-11-01 14:39:03 -04:00
m0duspwnens
8857fca797
graph changes
2021-11-01 14:36:41 -04:00
m0duspwnens
b63b50d98c
update many panels
2021-11-01 14:06:01 -04:00
William Wernert
c17187708e
Merge branch 'dev' into foxtrot
2021-11-01 12:46:43 -04:00
Mike Reeves
095e6bd48c
Merge pull request #6044 from Burak-PLT/patch-1
...
Update auth.sls
2021-11-01 10:22:16 -04:00
m0duspwnens
c4b9244f9a
add gridPos
2021-10-29 17:24:50 -04:00
m0duspwnens
2ba548fcfc
grafana bug fixes and improvements - https://github.com/Security-Onion-Solutions/securityonion/issues/6007
2021-10-29 17:11:51 -04:00
William Wernert
f76a52b2ee
Fix NIC string values for VLAN tagged interfaces
2021-10-29 13:34:23 -04:00
William Wernert
b555ad16da
Merge pull request #6052 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-10-29 10:52:51 -04:00
William Wernert
b1c67f696e
Re-order logic to maintain backwards compatibility
2021-10-29 10:47:05 -04:00
William Wernert
d08149f728
Don't set INTERWEBS variable on automated minions
2021-10-29 10:11:47 -04:00
William Wernert
a5cba5ecf8
Merge branch 'dev' into foxtrot
2021-10-29 10:01:46 -04:00
Burak-PLT
f081938be5
Update auth.sls
...
Change default password lengths to 72 characters from 20.
2021-10-28 16:00:58 -04:00
William Wernert
c2b18efdbb
Minions still need to be ISO installs to be airgap
2021-10-28 11:59:42 -04:00
William Wernert
6b480a5ba4
Change airgap check to something that doesn't require root
2021-10-28 11:51:50 -04:00
William Wernert
d6eeb0b735
Gen ssh key sooner
2021-10-28 10:04:03 -04:00
Josh Patterson
3000c57428
Merge pull request #6039 from Security-Onion-Solutions/issue/5759
...
Issue/5759
2021-10-28 09:24:44 -04:00
m0duspwnens
5c5b4004e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/5759
2021-10-28 08:52:04 -04:00
Josh Patterson
05e0f92ec5
Merge pull request #6036 from Security-Onion-Solutions/issue/5955
...
include ssl state in telegraf state
2021-10-28 08:50:57 -04:00
m0duspwnens
0cea5e8f22
include ssl state in telegraf state
2021-10-28 08:46:27 -04:00
m0duspwnens
7eb42fa6bd
change boolean
2021-10-28 08:43:03 -04:00
m0duspwnens
18ce9c7819
disable zeekpacketlosscron and telegraf checks if zeek is diabled via pillar
2021-10-28 07:46:02 -04:00
Mike Reeves
b3e5319806
Merge pull request #6028 from Security-Onion-Solutions/telecluster
...
Enable cluster stats
2021-10-27 16:37:42 -04:00
Mike Reeves
c8c8cf203f
Enable cluster stats
2021-10-27 15:44:52 -04:00
Josh Patterson
19056b9177
Merge pull request #6027 from Security-Onion-Solutions/issue/5955
...
Issue/5955
2021-10-27 15:07:22 -04:00
William Wernert
75490a2536
Fix typo
2021-10-27 14:59:24 -04:00
William Wernert
eee612e73d
Make folder/file states explicit
...
Rather than using /nsm/zeek (max_depth: 1) create explicit states for /nsm/zeek/spool and /nsm/zeek/spool/state.db that set correct ownership
2021-10-27 11:43:09 -04:00
William Wernert
9e9079f9cb
Reorder airgap prompt and add additional logic
...
Setup should now only ask the user whether to setup as airgap on manager-type installs. For all distributed minions setup will now inherit the airgap boolean from the manager.
2021-10-27 11:03:00 -04:00
William Wernert
331801eec2
Merge branch 'dev' into foxtrot
2021-10-27 10:58:16 -04:00
William Wernert
a0216cea57
Merge pull request #6021 from Security-Onion-Solutions/fix/update-mysql-root-user
...
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:55:11 -04:00
m0duspwnens
e7f43cff5e
limit nodes that bind filebeat certs in so-logstash
2021-10-27 10:45:10 -04:00
William Wernert
90d473f2d6
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:42:33 -04:00
m0duspwnens
bf403a8307
only manager nodes get cert, key and att&ck binds
2021-10-27 09:47:12 -04:00
m0duspwnens
58d62f29ea
include ssl state in registry state
2021-10-26 11:55:47 -04:00
Mike Reeves
bcf03773c0
Merge pull request #6009 from Security-Onion-Solutions/stenoports
...
Remove port bindings for steno
2021-10-26 10:58:11 -04:00
m0duspwnens
c0dd9efd9b
change so-thehive-es binds and requires
2021-10-26 10:50:16 -04:00
m0duspwnens
36ae07b78e
change timeout from 60 to 120
2021-10-26 10:49:50 -04:00
Mike Reeves
d77328608e
Remove port bindings for steno
...
Steno runs in host mode so port bindings are not required
2021-10-26 10:23:33 -04:00
m0duspwnens
682cbfd223
remove the mode
2021-10-26 09:23:24 -04:00
m0duspwnens
fa2edb2b59
make cortex_init and hive_init time out after 1 minutes vs 5 minutes
2021-10-26 08:39:30 -04:00
m0duspwnens
0c679b62b2
Merge remote-tracking branch 'remotes/origin/dev' into issue/5955
2021-10-25 16:29:41 -04:00
m0duspwnens
7e8d74e770
just use mode
2021-10-25 15:50:27 -04:00
m0duspwnens
9a78d13bee
change perms on mysql
2021-10-25 15:37:23 -04:00
Jason Ertel
c469d12a49
Merge pull request #6002 from Security-Onion-Solutions/kilo
...
Update whiptail links to use latest docs
2021-10-25 15:08:31 -04:00
Jason Ertel
d5f42e0d7c
Update whiptail links to use latest docs
2021-10-25 15:06:42 -04:00
weslambert
926551d398
Merge pull request #5998 from Security-Onion-Solutions/fix/hl_host_name
...
Rename HTTP client headers and host
2021-10-25 13:21:11 -04:00
weslambert
3be0d05eea
Update field removal based on HTTP input changes
2021-10-25 13:16:30 -04:00
weslambert
7fa43a276a
Rename default headers and host for HTTP input
2021-10-25 13:15:20 -04:00
William Wernert
2bfedbd581
Merge pull request #5996 from Security-Onion-Solutions/fix/escape-node-desc
...
Escape single quotes and allow for any character in node description
2021-10-25 10:53:36 -04:00
William Wernert
dca30146ab
Merge branch 'dev' into foxtrot
2021-10-25 10:50:25 -04:00
William Wernert
6e34905b42
Escape single quotes and allow for any character in node description
2021-10-25 10:48:09 -04:00
m0duspwnens
ee7e714f43
change to file_mode
2021-10-22 16:55:23 -04:00
m0duspwnens
d7e5377a44
more requires
2021-10-22 16:46:45 -04:00
William Wernert
38b16a507b
Update ip for root user in mysql when running so-ip-update
2021-10-22 15:29:32 -04:00
William Wernert
17af513692
Escape single quotes and allow for any character in node description
2021-10-22 15:28:37 -04:00
m0duspwnens
283f7296bc
fix require
2021-10-22 14:45:22 -04:00
m0duspwnens
9f6407fcb0
fix dupe ids
2021-10-22 14:26:04 -04:00
m0duspwnens
f61400680d
fix dupe ids
2021-10-22 14:22:15 -04:00
m0duspwnens
fed8bfac67
more requires on docker containers
2021-10-22 14:10:59 -04:00
William Wernert
62971d8c15
Add Fleet custom hostname to end summary
2021-10-22 11:57:47 -04:00
William Wernert
352e30f9e1
Add CUSTOM_FLEET_HOSTNAME to subjectAltName of fleet.key
...
Resolves #4319
2021-10-22 11:16:29 -04:00
m0duspwnens
451b19dc4d
change from file to x509
2021-10-22 09:53:20 -04:00
William Wernert
d5d970672d
Merge pull request #5974 from Security-Onion-Solutions/foxtrot
...
Add so-deny script + rewrite so-allow to match
2021-10-21 16:37:05 -04:00
m0duspwnens
f93c6146f5
docker binds requires
2021-10-21 15:24:55 -04:00
weslambert
40dd33affe
Merge pull request #5971 from Security-Onion-Solutions/feature/es_templates
...
Add .keyword subfield for conflict fields
2021-10-21 15:07:00 -04:00
William Wernert
f374dcbb58
Check for IP environment variable in so-allow and so-deny
2021-10-21 13:54:06 -04:00
weslambert
77ee1db44c
Add .keyword subfield for conflict fields
2021-10-21 12:56:03 -04:00
Josh Patterson
8784d65023
Merge pull request #5967 from Security-Onion-Solutions/issue/5954
...
require files before starting soc or kratos
2021-10-21 11:15:36 -04:00
William Wernert
15fe7512b7
Install lxml during setup and in common state
2021-10-21 10:49:41 -04:00
William Wernert
0beeeb94bf
Actually add new so-allow script
2021-10-21 10:48:17 -04:00
m0duspwnens
928aed27c5
require files before starting soc or kratos
2021-10-20 17:04:02 -04:00
William Wernert
387d4d6ad5
Add so-deny script + rewrite so-allow to match so-deny
2021-10-20 16:44:57 -04:00
William Wernert
adf6cb4b3c
Merge branch 'dev' into foxtrot
2021-10-20 16:44:50 -04:00
William Wernert
0ed2ce0766
Fix validation.sh tests
2021-10-20 16:44:09 -04:00
William Wernert
b5cb47e066
Fix sbin perms
2021-10-20 16:43:55 -04:00
Josh Patterson
8061508330
Merge pull request #5961 from Security-Onion-Solutions/issue/5960
...
Issue/5960
2021-10-20 16:08:50 -04:00
m0duspwnens
adffb11800
fix redis port
2021-10-20 15:39:21 -04:00
m0duspwnens
8619af59cc
servers to list format
2021-10-20 15:02:33 -04:00
m0duspwnens
7ecfb55b70
fix pillar call
2021-10-20 14:50:50 -04:00
m0duspwnens
b496810b63
add redis and logstash input plugins to telegraf
2021-10-20 14:46:47 -04:00
Mike Reeves
e1ad02c28d
Merge pull request #5949 from Security-Onion-Solutions/kilo
...
Fix Docker-created corruption of SOC user roles file
2021-10-19 18:37:37 -04:00
Jason Ertel
2f8bb5a2a6
Fix Docker-created corruption of SOC user roles file
2021-10-19 16:04:10 -04:00
weslambert
6f3e441bf7
Merge pull request #5945 from Security-Onion-Solutions/fix/soc_index_pattern
...
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:05:40 -04:00
Mike Reeves
7f1585dcc0
Merge pull request #5942 from Security-Onion-Solutions/tunesteno
...
Fix Steno Math for PL
2021-10-19 13:03:50 -04:00
weslambert
9453ed7fa1
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:01:40 -04:00
Mike Reeves
64f25961b0
Fix Steno Math for PL
2021-10-19 11:15:58 -04:00
Mike Reeves
b9a3d3a6a9
Fix Steno Math for PL
2021-10-19 11:14:02 -04:00
m0duspwnens
36cb0d6c42
remove space
2021-10-18 14:34:33 -04:00
m0duspwnens
1b2268dfe5
load kibana configs during setup
2021-10-18 14:30:47 -04:00
Mike Reeves
00e5b54dda
Merge pull request #5911 from Security-Onion-Solutions/tunesteno
...
Add Steno Tuning Options
2021-10-18 09:01:14 -04:00
Mike Reeves
4016b416ec
Merge pull request #5923 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.1
2021-10-16 09:15:06 -04:00
weslambert
7590728a0b
Merge pull request #5915 from Security-Onion-Solutions/feature/ti_module
...
Add TI module
2021-10-15 17:17:33 -04:00
weslambert
bb36fc1ed8
Add TI module defaults
2021-10-15 17:16:38 -04:00
weslambert
d0a6dafc8b
Add TI module
2021-10-15 17:09:59 -04:00
m0duspwnens
76097476d3
remove includes
2021-10-15 16:57:38 -04:00
m0duspwnens
8b3b0bf160
fix opts
2021-10-15 16:51:11 -04:00
m0duspwnens
f19680b3e6
fix opts
2021-10-15 16:50:03 -04:00
m0duspwnens
7e1bbe3cc2
define MAANGER
2021-10-15 16:14:14 -04:00
m0duspwnens
947285e932
update cmd.run amd s_o files
2021-10-15 16:06:25 -04:00
m0duspwnens
1741f5068a
update config-load to do an update or import
2021-10-15 15:35:30 -04:00
Mike Reeves
a9f6c84d7c
Add Steno Tuning Options
2021-10-15 14:17:54 -04:00
weslambert
59852841ff
Add keyword subfield for event.module
2021-10-15 13:29:50 -04:00
weslambert
6f1f7d2a63
Merge pull request #5905 from Security-Onion-Solutions/feature/soc_es_index_pattern
...
Allow setting ES index patterns for SOC in pillar
2021-10-15 13:28:04 -04:00
Jason Ertel
8de8d58155
Upgrade to ES 7.15.1
2021-10-15 13:27:08 -04:00
Wes Lambert
8feeff97b5
Add EG index pattern during setup (if enabled)
2021-10-15 16:19:19 +00:00
Wes Lambert
032373187c
Allow setting ES index patterns for SOC in pillar
2021-10-15 16:02:53 +00:00
William Wernert
db2b70f655
Merge pull request #5900 from Security-Onion-Solutions/foxtrot
...
Replace rather than append to Kibana misc log
2021-10-15 10:27:25 -04:00
Jason Ertel
1800ec4570
Upgrade to Elastalert 2 v2.2.2
2021-10-15 09:25:44 -04:00
Mike Reeves
8a5960c220
Merge pull request #5896 from Security-Onion-Solutions/kilo
2021-10-14 18:05:33 -04:00
Jason Ertel
9797a15218
Fix issue with 'so-user delete' resetting all user roles - note that this function is not technically supported or published since it's not intended for production use
2021-10-14 17:23:18 -04:00
William Wernert
c7b15a9b1f
Replace rather than append to Kibana misc log
2021-10-14 15:13:55 -04:00
William Wernert
cba97802fe
Fix indent
2021-10-14 15:13:34 -04:00
William Wernert
025256aeaf
Merge pull request #5890 from Security-Onion-Solutions/foxtrot
...
Misc setup changes
2021-10-14 14:55:24 -04:00
weslambert
490f7eaf81
Merge pull request #5886 from Security-Onion-Solutions/feature/eg_pivot
...
Add EG pivot
2021-10-14 14:49:38 -04:00
m0duspwnens
6a2bf11a75
change format of file
2021-10-14 13:43:39 -04:00
m0duspwnens
78d30285b1
seperate securitySolutions load
2021-10-14 13:24:51 -04:00
Wes Lambert
f1fafa015e
Add EG to list of groups to include 127.0.0.1
2021-10-14 16:27:28 +00:00
Wes Lambert
6cdc214582
Add pillar in setup and change name of EG variable
2021-10-14 15:33:37 +00:00
Wes Lambert
15049f44b9
Add EG pivot
2021-10-14 15:15:23 +00:00
Doug Burks
42a642b85c
Merge pull request #5873 from petiepooo/enh-rediscount-tty
...
featreq: remove tty flag in redis-count script
2021-10-14 10:07:07 -04:00
weslambert
3b45e68ead
Merge pull request #5885 from Security-Onion-Solutions/feature/jinjafy_soc_actions
...
Allow SOC actions to use Jinja
2021-10-14 10:03:12 -04:00
Wes Lambert
5ee0ea3fe7
Allow SOC actions to use Jinja
2021-10-14 13:59:55 +00:00
weslambert
55c60f485c
Merge pull request #5884 from Security-Onion-Solutions/feature/hl_eg
...
Add EG firewall allowance via setup
2021-10-14 09:55:07 -04:00
Wes Lambert
78e88e0765
Add EG firewall allowance via setup
2021-10-13 21:42:54 +00:00
Wes Lambert
a9b250c0f4
Add EG firewall config
2021-10-13 21:37:59 +00:00
m0duspwnens
ae9753326a
fix var, quote vars
2021-10-13 16:38:01 -04:00
m0duspwnens
c8fb504ee0
Revert "Merge remote-tracking branch 'remotes/origin/dev' into issue/3933"
...
This reverts commit 54eec92621 , reversing
changes made to 7832e59629 .
2021-10-13 15:22:46 -04:00
m0duspwnens
54eec92621
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 15:19:33 -04:00
m0duspwnens
7832e59629
only load default kibana saved_objects during setup
2021-10-13 15:19:20 -04:00
weslambert
f9001654bb
Merge pull request #5871 from Security-Onion-Solutions/feature/hl_eg
...
Initial EG stuff
2021-10-13 15:07:03 -04:00
Wes Lambert
2a504a061b
Add Curator action files for EG indices
2021-10-13 18:40:34 +00:00
m0duspwnens
bb9c6446e4
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 14:01:36 -04:00
Pete
e7581036f7
remove tty/interactive flags
...
This call to docker exec simply returns a number. No interaction (stdin) or tty is required. Specifically, having the -t option prevents running via salt using a command such as:
> salt '*' cmd.run 'so-redis-count'
2021-10-13 13:51:05 -04:00
Wes Lambert
e1629d7ec4
Initial EG stuff
2021-10-13 17:13:07 +00:00
Josh Patterson
b4873bd296
Merge pull request #5868 from Security-Onion-Solutions/issue/5818
...
Issue/5818
2021-10-13 12:52:48 -04:00
m0duspwnens
3044edb104
update comment
2021-10-13 12:38:58 -04:00
m0duspwnens
a495779552
only 3 attempts with 120s max attemps
2021-10-13 12:34:56 -04:00
m0duspwnens
880c1b97b0
remove $ from var
2021-10-13 12:25:11 -04:00
m0duspwnens
7a4fa8879c
change count, attempts and timeout
2021-10-13 12:13:24 -04:00
m0duspwnens
adb8292814
add missing )
2021-10-13 10:37:18 -04:00
m0duspwnens
6e7a5fa326
add timeouts to check_salt_minion_status and check_salt_master_status - https://github.com/Security-Onion-Solutions/securityonion/issues/5818
2021-10-13 09:45:15 -04:00
m0duspwnens
23ea53248d
single line format
2021-10-12 14:15:37 -04:00
m0duspwnens
f1a5991699
add securitySolution.defaultIndex to defaults
2021-10-12 12:35:13 -04:00
m0duspwnens
c69ad091f7
update saved_objects config
2021-10-12 12:02:30 -04:00
William Wernert
b97361fab9
Remove references to xenial in setup
...
Resolves #4292
2021-10-12 10:23:39 -04:00
William Wernert
36e1795295
Add end of setup log messages per #5032
2021-10-12 10:19:47 -04:00
m0duspwnens
498e385484
change name to SAVED_OBJECTS
2021-10-12 10:15:39 -04:00
William Wernert
af687b0706
Remove all holds on Ubuntu reinstall
2021-10-12 10:10:34 -04:00
m0duspwnens
19489f3626
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-12 10:07:40 -04:00
m0duspwnens
89d1df8a1d
change name to SAVED_OBJECTS
2021-10-12 10:07:26 -04:00
William Wernert
946cf81a27
If ANALYST is selected immediately quit setup
2021-10-12 09:48:38 -04:00
Mike Reeves
2561480371
Merge pull request #5850 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.7.6-alpha.1
2021-10-12 08:19:25 -04:00
Jason Ertel
d21dee162d
Add Note field to user traits; Enforce max length restrictions on email, firstname, lastname, and note fields
2021-10-08 12:39:17 -04:00
Mike Reeves
444d067112
Merge pull request #5813 from Security-Onion-Solutions/macleod
...
Highlander changes
2021-10-08 10:06:18 -04:00
Mike Reeves
2a82373051
highlander fixes
2021-10-08 09:32:13 -04:00
Mike Reeves
64758a534c
Set ml to true
2021-10-08 08:42:26 -04:00
m0duspwnens
7517a63008
disabled ml
2021-10-07 13:06:52 -04:00
m0duspwnens
b2facdf31c
add securitySolutions advanced setting
2021-10-07 12:57:28 -04:00
m0duspwnens
4c54d6309c
change host to 0.0.0.0
2021-10-07 09:59:29 -04:00
Jason Ertel
62c3afc81d
Migrate users from locked to inactive during soup
2021-10-06 15:45:35 -04:00
Jason Ertel
7d8c8144b0
Drop obsolete status trait
2021-10-06 12:52:41 -04:00
Jason Ertel
a2c4fce1ef
Switch to use state attribute in identities for enabling/disabling users
2021-10-06 11:53:10 -04:00
m0duspwnens
599aba43d9
restart so-kibaba if config changes
2021-10-06 09:51:16 -04:00
m0duspwnens
fa4f92cdda
change defaults
2021-10-05 17:35:44 -04:00
m0duspwnens
5d98c0d14c
fix dict update
2021-10-05 15:57:57 -04:00
Mike Reeves
27614569e3
Fix set
2021-10-05 14:32:02 -04:00
m0duspwnens
ec357cca3c
fix cars
2021-10-05 12:57:30 -04:00
m0duspwnens
26681ac98a
var for dash saved objevs
2021-10-05 12:46:21 -04:00
m0duspwnens
748f0f2a1d
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-05 12:12:56 -04:00
Mike Reeves
869af548af
Fix spaces for highlander
2021-10-05 11:06:13 -04:00
Mike Reeves
2fd344822d
Add additional roles for highlander
2021-10-05 10:40:40 -04:00
Mike Reeves
a3e0fb127a
Merge pull request #5069 from datlife/datlife/asn-annotation
...
Add ASN annotation for IP
2021-10-05 06:50:31 -04:00
Dat
9569e73bd0
Added ASN annotation for IP
2021-10-04 12:41:20 -07:00
m0duspwnens
96d783b158
merge with dev
2021-10-04 10:39:48 -04:00
m0duspwnens
e0c097c270
add dashboard theme defaults
2021-10-04 10:36:58 -04:00
Mike Reeves
e6fce4cf3e
Merge pull request #5749 from Security-Onion-Solutions/kilo
...
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:55:53 -04:00
Jason Ertel
6ef9a5c95d
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:53:25 -04:00
Mike Reeves
727613b6e1
Merge pull request #5601 from Security-Onion-Solutions/special
...
Ubuntu 20.04 Beta
2021-10-04 08:51:01 -04:00
Mike Reeves
5013aa8490
Merge pull request #5748 from Security-Onion-Solutions/kilo
...
Merge ES Upgrade, Version Bump into dev
2021-10-04 08:48:07 -04:00
Jason Ertel
72a1b299ac
Bump to 2.3.90
2021-10-04 08:44:51 -04:00
Mike Reeves
cfaa0e679c
Merge pull request #5739 from Security-Onion-Solutions/dev
...
2.3.80
2021-10-01 15:15:54 -04:00
Mike Reeves
4ddf2b49ce
Merge pull request #5669 from Security-Onion-Solutions/2.3.80
...
2.3.80
2021-10-01 15:11:03 -04:00
m0duspwnens
bb95963d73
add missing {{}}
2021-09-30 14:40:13 -04:00
m0duspwnens
dfa9afde0e
change to mode
2021-09-30 14:33:52 -04:00
m0duspwnens
fa2333b9ef
change t file.managed
2021-09-30 14:32:28 -04:00
m0duspwnens
8b9c43915d
fix source
2021-09-30 14:30:00 -04:00
m0duspwnens
36832139b2
pillarize kibana
2021-09-30 14:28:31 -04:00
m0duspwnens
c3bf835566
kibana config
2021-09-30 14:23:49 -04:00
m0duspwnens
39d3c7c6ed
begin pillarization of kibana
2021-09-30 11:48:42 -04:00
Jason Ertel
b1a5527e82
Update ElastAlert to use ElastAlert 2
2021-09-28 07:01:47 -04:00
Jason Ertel
d0592c4293
Update ElastAlert to use ElastAlert 2
2021-09-28 00:51:29 -04:00
Mike Reeves
b1d0e3e93f
2.3.80
2021-09-27 12:32:45 -04:00
Mike Reeves
b069377c8a
2.3.80
2021-09-27 10:13:42 -04:00
Jason Ertel
e9a44c6e1b
Merge pull request #5662 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update README.md
2021-09-27 09:28:46 -04:00
Mike Reeves
275163f85d
Update README.md
2021-09-27 07:36:54 -04:00
William Wernert
98f74c25ba
Fix variable reference in so-functions
2021-09-24 12:32:56 -04:00
William Wernert
3064800820
Merge pull request #5636 from Security-Onion-Solutions/fix/soup-2.3.80
...
Misc. soup fixes
2021-09-23 13:03:43 -04:00
William Wernert
f8bea82430
Make redirect consistent with setup
2021-09-23 12:57:08 -04:00
William Wernert
8b905b585d
Fix redirect to append
2021-09-23 12:55:06 -04:00
William Wernert
b44358fc26
Add set +e after final upgrade steps and before post-upgrade checks
2021-09-23 12:49:42 -04:00
William Wernert
8a9dcb7fdb
Fix "upgrade to" message
...
Only specify "to" version and change when the upgrade message occurs
2021-09-23 12:47:22 -04:00
William Wernert
a01d49981c
Redirect thehive/cortex migrate curl output to soup log
2021-09-23 12:45:44 -04:00
William Wernert
b8b1867e52
Tell user what soup is doing at end of upgrade
2021-09-23 12:43:23 -04:00
William Wernert
292ce37ce4
Merge pull request #5632 from Security-Onion-Solutions/fix/logscan-soup
...
Add logscan to images for pull during soup if it's enabled
2021-09-23 10:13:20 -04:00
William Wernert
73dacdcbff
Add logscan to images for pull during soup if it's enabled
2021-09-23 09:52:23 -04:00
Josh Patterson
bea7555464
Merge pull request #5631 from Security-Onion-Solutions/80soup
...
80soup
2021-09-22 16:01:45 -04:00
m0duspwnens
52c1298b9b
notify of custom es config
2021-09-22 15:16:07 -04:00
m0duspwnens
cdb9dcbaec
notify of custom es config
2021-09-22 15:07:36 -04:00
Mike Reeves
37153288e8
Merge pull request #5627 from Security-Onion-Solutions/80soup
...
ignore manager pillar file for noderoutetype
2021-09-22 12:03:55 -04:00
m0duspwnens
edf75255cf
ignore manager pillar file for noderoutetype
2021-09-22 12:01:32 -04:00
Jason Ertel
9eb6f5942e
Merge pull request #5623 from Security-Onion-Solutions/kilo
...
Prevent email addresses from having uppercase characters
2021-09-22 09:10:38 -04:00
Jason Ertel
dae41d279a
Prevent emails addresses from having uppercase characters
2021-09-22 08:25:55 -04:00
Mike Reeves
07288367cf
Merge pull request #5611 from Security-Onion-Solutions/80soup
...
match elasticsearch at beginning of line
2021-09-21 15:42:09 -04:00
m0duspwnens
f4186feffa
move node_route_type
2021-09-21 15:40:49 -04:00
m0duspwnens
d82e91f69e
match elasticsearch at beginning of line
2021-09-21 13:54:45 -04:00
Josh Patterson
a2680fad0a
Merge pull request #5605 from Security-Onion-Solutions/80soup
...
fi xquotes
2021-09-21 13:02:58 -04:00
m0duspwnens
5c2be487f5
fi xquotes
2021-09-21 13:01:40 -04:00
Mike Reeves
531c9de488
Merge pull request #5600 from petiepooo/petiepooo-raidstat-fix
...
missing dollarsign
2021-09-21 11:35:57 -04:00
Pete
19efa493ad
missing dollarsign
2021-09-21 11:21:07 -04:00
Mike Reeves
0db3f14261
Merge pull request #5598 from Security-Onion-Solutions/80soup
...
Soup Changes for True Clusters
2021-09-21 09:57:12 -04:00
Mike Reeves
ed28e4d000
Soup Changes for True Clusters
2021-09-21 09:55:49 -04:00
Mike Reeves
2c8cbf0db1
Soup Changes for True Clusters
2021-09-21 09:53:09 -04:00
Mike Reeves
c1537335b1
Fix Python Problem
2021-09-20 19:05:01 -04:00
Mike Reeves
5f475ff9cb
Fix Python Problem
2021-09-20 18:46:43 -04:00
Mike Reeves
481ffb1cda
Fix Grain
2021-09-20 18:12:18 -04:00
Mike Reeves
50b78681f2
Ubuntu 20.04 Support
2021-09-20 17:24:47 -04:00
Jason Ertel
3924b8f5db
Merge pull request #5586 from Security-Onion-Solutions/kilo
...
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:56:30 -04:00
Jason Ertel
a9049eccd4
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:30:05 -04:00
Mike Reeves
1a7237bcdf
Merge pull request #5583 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2021-09-20 10:44:20 -04:00
Mike Reeves
1e5e1c9ef0
Update soup
2021-09-20 10:42:55 -04:00
Josh Patterson
47cd1ddc0a
Merge pull request #5580 from Security-Onion-Solutions/issue/1257
...
Issue/1257 - Pillarize ES
2021-09-20 09:31:03 -04:00
m0duspwnens
aed73511e4
file cleanup, comment cleanup
2021-09-20 09:24:03 -04:00
Jason Ertel
a3f62c81c3
Merge pull request #5577 from Security-Onion-Solutions/kilo
...
Continuation of auth enhancements
2021-09-20 06:30:36 -04:00
Jason Ertel
730503b69c
Ensure highstate migrates user roles
2021-09-18 23:17:49 -04:00
Jason Ertel
3508f3d8c1
Ensure ES user/role files are generated even if the primary admin user isn't yet created, since the system users are necessary for other installation functions
2021-09-18 19:20:43 -04:00
Jason Ertel
5704906b11
Create empty files for Docker to mount while installation continues
2021-09-18 15:49:05 -04:00
Jason Ertel
357c1db445
Recover from situation where roles file is corrupted
2021-09-18 11:08:35 -04:00
Jason Ertel
5377a1a85e
Recover from situation where roles file is corrupted
2021-09-18 11:06:54 -04:00
Jason Ertel
7f2d7eb038
Continue migration of user emails to IDs
2021-09-18 07:20:34 -04:00
Jason Ertel
30e781d076
Use user ID instead of email as role master
2021-09-17 17:54:38 -04:00
m0duspwnens
01323cc192
fix clustername redirect
2021-09-17 15:44:54 -04:00
m0duspwnens
109c83d8c3
move custom es cluster name pillar location
2021-09-17 15:29:41 -04:00
m0duspwnens
e864bc5404
move custom es cluster name pillar location
2021-09-17 15:28:35 -04:00
Josh Brower
22eb82e950
Merge pull request #5566 from Security-Onion-Solutions/feature/disable_services
...
Add support for disabling Zeek and Suricata
2021-09-17 14:18:03 -04:00
m0duspwnens
b877aa44bc
update dict
2021-09-17 14:10:45 -04:00
Josh Brower
4d307c53e8
Add support for disabling Zeek and Suricata
2021-09-17 13:01:50 -04:00
m0duspwnens
d0c87cd317
allow for pillar override of defaults
2021-09-17 12:11:12 -04:00
m0duspwnens
0d074dafd4
add missing defaults
2021-09-17 09:52:50 -04:00
m0duspwnens
5b77dc109f
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-16 16:54:23 -04:00
m0duspwnens
3ce48acadd
change cluster_settings to config
2021-09-16 16:44:31 -04:00
Jason Ertel
fbd9bab2f1
Split apart roles and users into separate maps
2021-09-16 16:08:55 -04:00
m0duspwnens
5526a2bc3a
reduce defaults.yaml
2021-09-16 15:32:08 -04:00
weslambert
18d81352c6
Merge pull request #5537 from Security-Onion-Solutions/delta
...
Add improved ignore functionality for YARA rules used by Strelka and add default ignored rules that break compilation
2021-09-16 10:38:49 -04:00
m0duspwnens
889d235c45
no box type more manager in true cluster
2021-09-16 09:15:24 -04:00
Jason Ertel
3fc26312e0
Remove x-user-id header from unauthenticated proxied requests
2021-09-16 08:52:31 -04:00
Jason Ertel
b81d38e392
Merge branch 'dev' into kilo
2021-09-16 07:44:35 -04:00
Jason Ertel
82da0041a4
Add limited roles with restricted visibility
2021-09-16 07:44:15 -04:00
m0duspwnens
782b01e76f
seed_hosts to list
2021-09-15 17:07:52 -04:00
m0duspwnens
3bf9685df8
fix seed_hosts append
2021-09-15 17:00:16 -04:00
m0duspwnens
4cf91f6c86
fix dict update
2021-09-15 15:51:00 -04:00
m0duspwnens
a43b37f234
fix dict update
2021-09-15 15:49:18 -04:00
m0duspwnens
e0dc62b6e9
fix dict update
2021-09-15 15:43:47 -04:00
m0duspwnens
c213834316
update the dict
2021-09-15 15:24:40 -04:00
Josh Brower
c06668c68e
Merge pull request #5527 from Security-Onion-Solutions/feature/so-import-evtx
...
Feature/so import evtx
2021-09-15 14:17:15 -04:00
Josh Brower
a75238bc3f
so-import-evtx - fix ingest formatting
2021-09-15 14:13:16 -04:00
Josh Brower
ac417867ed
so-import-evtx - final fixes
2021-09-15 14:06:08 -04:00
m0duspwnens
1614b70853
update cluster name if true cluster
2021-09-15 13:45:43 -04:00
Mike Reeves
0882158e03
Merge pull request #5525 from Security-Onion-Solutions/soup80
...
soup changes 2.3.80
2021-09-15 13:44:54 -04:00
m0duspwnens
1a03853a7c
fix extend
2021-09-15 13:38:29 -04:00
Mike Reeves
aff571faf2
soup changes 2.3.80
2021-09-15 13:32:52 -04:00
m0duspwnens
e0faa4c75b
Merge branch 'issue/1257' of https://github.com/Security-Onion-Solutions/securityonion into issue/1257
2021-09-15 13:09:35 -04:00
m0duspwnens
e3e2e1d851
logic for truecluster to map file
2021-09-15 13:09:04 -04:00
weslambert
2affaf07a2
Merge pull request #5521 from Security-Onion-Solutions/fix/strelka-yara
...
Fix/strelka yara
2021-09-15 11:33:44 -04:00
weslambert
39e5ded58d
Refactor ignore list and only ignore for signature-base for now
2021-09-15 11:32:29 -04:00
weslambert
4d41d3aee1
Ignore these rules by default because they are causing issues with YARA compilation with Strelka
2021-09-15 10:29:11 -04:00
weslambert
5c8067728e
Remove unnecessary logic
2021-09-15 10:22:17 -04:00
Josh Brower
1d905124d3
Merge pull request #5519 from Security-Onion-Solutions/fix/fleet-link
...
Fix Fleet Link Logic
2021-09-15 09:30:21 -04:00
Josh Brower
e0a289182f
Fix Fleet Link Logic
2021-09-15 09:28:23 -04:00
m0duspwnens
551dba955c
set roles empty list
2021-09-15 09:20:33 -04:00
Jason Ertel
9970e54081
Adjust custom_role examples to be more realistic
2021-09-14 14:03:22 -04:00
Jason Ertel
ff989b1c73
Include wording in so-user relating to optional role parameter
2021-09-14 14:03:00 -04:00
Mike Reeves
2ffb723bbd
Rename so-common-template.json to so-common-template.json.jinja
2021-09-14 13:58:45 -04:00
Mike Reeves
6ae2fba71f
Update search.sls
2021-09-14 13:57:26 -04:00
Mike Reeves
2cc25587d9
Update eval.sls
2021-09-14 13:57:04 -04:00
Mike Reeves
614a6dc9fe
Update manager.sls
2021-09-14 13:56:43 -04:00
Josh Brower
4b7667d87f
Merge pull request #5508 from Security-Onion-Solutions/fix/fleet-link
...
Fleet SA - SOC Link Fix
2021-09-14 13:29:20 -04:00
Josh Brower
74b0b365bd
Fleet SA - SOC Link Fix
2021-09-14 13:23:07 -04:00
Josh Brower
0b0d508585
so-import-evtx - tweaks
2021-09-14 12:01:14 -04:00
m0duspwnens
0534a2dda3
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-13 15:04:50 -04:00
m0duspwnens
f8ab0ac8a9
config changes
2021-09-13 15:04:39 -04:00
m0duspwnens
0ae09cc630
config changes
2021-09-13 09:49:56 -04:00
Mike Reeves
332c4dda22
Merge pull request #5469 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Allow so-rule-update to accept any number of args
2021-09-10 14:41:55 -04:00
William Wernert
679faddd52
Update so-rule-update to pass all args to docker exec
...
Instead of passing $1, build a string from all args and add that to the command string for the docker exec statement
2021-09-10 13:44:37 -04:00
William Wernert
0b42b19763
Update so-rule-update to source so-common
2021-09-10 13:41:58 -04:00
William Wernert
943bd3e902
Merge pull request #5468 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Add `--force` flag to idstools-rulecat under so-rule-update
2021-09-10 13:17:16 -04:00
Mike Reeves
4af6a901a1
Merge pull request #5461 from Security-Onion-Solutions/truclusterrator
...
Add new hunt fields
2021-09-10 13:17:01 -04:00
William Wernert
9c310de459
Add --force flag to idstools-rulecat under so-rule-update
...
This forces idstools to pull from the url each time, which prevents it from clearing all.rules if idstools-rulecat is run twice within 15 minutes by any method (either restarting the container or running so-rule-update)
2021-09-10 13:15:09 -04:00
Mike Reeves
4f6a3269cb
Add more detail to syscollector
2021-09-10 09:59:47 -04:00
Doug Burks
6a2e1df7d4
Merge pull request #5460 from Security-Onion-Solutions/feature/welcome-link-docs
...
FEATURE: Add docs link to Setup #5459
2021-09-10 07:27:48 -04:00
doug
db50ef71b4
FEATURE: Add docs link to Setup #5459
2021-09-10 06:19:16 -04:00
Jason Ertel
4e2d5018a2
Merge pull request #5455 from Security-Onion-Solutions/kilo
...
Consolidate whiptail screens
2021-09-09 14:57:28 -04:00
Jason Ertel
94688a9adb
Eliminate adv component popup
2021-09-09 14:29:09 -04:00
Jason Ertel
63f67b3500
Rephrase screen that warns about more RAM requirements
2021-09-09 14:16:05 -04:00
Mike Reeves
eaa5e41651
Merge pull request #5450 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Raid Status for cloud
2021-09-09 11:09:49 -04:00
Mike Reeves
c83f119cc0
Update so-raid-status
2021-09-09 10:59:35 -04:00
Mike Reeves
5d235e932c
Fix Raid Status for cloud
2021-09-09 10:46:28 -04:00
m0duspwnens
93f2cd75a4
add the jinja template
2021-09-09 10:19:46 -04:00
m0duspwnens
f06ab8b77d
testing defaults.yaml
2021-09-09 08:55:36 -04:00
weslambert
03b45512fa
Merge pull request #5436 from Security-Onion-Solutions/fix/kibana_server_url
...
Incude server.publicBaseUrl
2021-09-08 12:13:48 -04:00
weslambert
b8600be0f1
Incude server.publicBaseUrl
2021-09-08 12:12:09 -04:00
Jason Ertel
19a02baa7c
Merge pull request #5425 from Security-Onion-Solutions/kilo
...
Auth enhancements
2021-09-07 13:10:36 -04:00
Jason Ertel
3c59579f99
Add maintenance privilege for analysts to refresh indices
2021-09-07 13:03:30 -04:00
Mike Reeves
3f989590ad
Merge pull request #5402 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Enable index sorting by default but allow it to be disabled
2021-09-07 11:28:40 -04:00
Jason Ertel
72cff7ec7a
Merge branch 'dev' into kilo
2021-09-07 10:49:08 -04:00
Mike Reeves
e3900606dc
Enable index sorting by default but allow it to be disabled
2021-09-04 10:42:18 -04:00
Mike Reeves
a2fd8ae200
Merge pull request #5401 from rwaight/dev
...
Enable index sorting in `so-common-template.json`
2021-09-04 10:32:57 -04:00
Rob Waight
b7591093cf
Add index sorting to so-common-template.json
...
Add index sorting to so-common-template.json
2021-09-04 09:45:03 -04:00
Rob Waight
51439cd1ab
Merge pull request #1 from Security-Onion-Solutions/dev
...
sync with SO/Dev
2021-09-04 09:43:23 -04:00
Jason Ertel
94ea1f856b
Add auditor role; update analyst role with correct syntax
2021-09-03 15:59:48 -04:00
Jason Ertel
fbbb7f4e85
Add auditor role; update analyst role with correct syntax
2021-09-03 15:54:05 -04:00
Mike Reeves
7b3a0cd1e4
Merge pull request #5394 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Add maxfiles to the steno config
2021-09-03 10:49:59 -04:00
Mike Reeves
9fb28709d5
Add maxfiles to the steno config
2021-09-03 10:47:00 -04:00
Jason Ertel
649f339934
Correct typo
2021-09-02 20:30:48 -04:00
Jason Ertel
f659079542
Consolidate password validation messaging
2021-09-02 19:12:32 -04:00
Jason Ertel
ce70380f0f
resolve so-user errors from recent auth changes
2021-09-02 17:59:33 -04:00
Jason Ertel
c4d402d8b4
Ensure role file exists before ES state is run
2021-09-02 15:45:47 -04:00
Mike Reeves
9f5dafd560
More Event Fields
2021-09-02 13:48:18 -04:00
Mike Reeves
1cee603ee4
Squid event fields
2021-09-02 13:24:04 -04:00
William Wernert
a14854d56d
Merge pull request #5383 from Security-Onion-Solutions/feature/soup-y
...
Add logic to check unattended flag when checking OS updates
2021-09-02 11:50:45 -04:00
Mike Reeves
2bf471054b
Cloudtrail Event Fields
2021-09-02 11:46:18 -04:00
William Wernert
56894b9581
Add logic to check unattended flag when checking if updates are available
2021-09-02 11:15:32 -04:00
Jason Ertel
10126bb7ef
Auth enhancements
2021-09-02 09:44:57 -04:00
Jason Ertel
6dfc943e8c
Merge pull request #5382 from Security-Onion-Solutions/kilo
...
Correct invalid password message
2021-09-02 07:15:09 -04:00
Jason Ertel
84ecc3cba7
Merge branch 'dev' into kilo
2021-09-02 07:09:36 -04:00
Jason Ertel
0ad3d826eb
Invalid password message should also mention that dollar signs are not allowed
2021-09-02 07:07:36 -04:00
William Wernert
d785dafe2f
Merge pull request #5374 from Security-Onion-Solutions/feature/soup-y
...
Add unattended soup flag, and iso location argument for air gap
2021-09-01 16:48:55 -04:00
Mike Reeves
e3dffcc2cb
Merge pull request #5373 from Security-Onion-Solutions/truclusterrator
...
Add eventfields for new default logs
2021-09-01 16:48:51 -04:00
Mike Reeves
556bad6925
Add eventfields for new default logs
2021-09-01 15:13:43 -04:00
William Wernert
446821e9fd
Use exit code 0 when printing error message before exiting soup
2021-09-01 15:11:18 -04:00
William Wernert
576c893eb3
Exit on missing file argument
2021-09-01 15:08:53 -04:00
Mike Reeves
34a5d6e56a
Merge pull request #5367 from Security-Onion-Solutions/truclusterrator
...
Allow closing of fb module indices in global
2021-09-01 10:54:02 -04:00
Mike Reeves
324e6b12e2
Add jinja template
2021-09-01 09:32:32 -04:00
Mike Reeves
007b15979a
Non Cluster honor closed indices values
2021-09-01 09:25:14 -04:00
Mike Reeves
c168703e9f
Merge pull request #5362 from Security-Onion-Solutions/truclusterrator
...
True Cluster Curator Overhaul
2021-08-31 17:17:47 -04:00
Mike Reeves
527a793e94
Only enable curator on Manager in true cluster
2021-08-31 16:59:41 -04:00
Mike Reeves
61ebedc0e9
Only enable curator on Manager in true cluster
2021-08-31 16:56:08 -04:00
Mike Reeves
e09aa4e5d4
Only enable curator on Manager in true cluster
2021-08-31 16:35:19 -04:00
Mike Reeves
e7b04b862f
Only enable curator on Manager in true cluster
2021-08-31 16:21:48 -04:00
Mike Reeves
62edfd0b7f
Only enable curator on Manager in true cluster
2021-08-31 16:20:42 -04:00
Mike Reeves
958575c22a
Only enable curator on Manager in true cluster
2021-08-31 16:17:55 -04:00
Mike Reeves
0c8e11dc9f
Only enable curator on Manager in true cluster
2021-08-31 16:13:05 -04:00
Mike Reeves
5b9ef3bc0d
Only enable curator on Manager in true cluster
2021-08-31 15:55:44 -04:00
Mike Reeves
c12f380bc3
Only enable curator on Manager in true cluster
2021-08-31 15:51:34 -04:00
Mike Reeves
dc25ed2594
Add logic for cronjobs
2021-08-31 15:43:48 -04:00
Mike Reeves
9f51f02ab4
Add logic for cronjobs
2021-08-31 15:40:09 -04:00
Mike Reeves
f6f4375e13
Add logic for cronjobs
2021-08-31 15:34:26 -04:00
Mike Reeves
ed116cf850
Add Actions for warm indices
2021-08-31 15:09:26 -04:00
Mike Reeves
476ecccbc1
Add Actions for warm indices
2021-08-31 15:08:10 -04:00
Mike Reeves
c09cebbd6b
Add Actions for close and delete in cluster mode
2021-08-31 13:42:11 -04:00
Mike Reeves
0ed92fd9bd
Merge pull request #5359 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 Wazuh hotfix into dev
2021-08-31 13:39:21 -04:00
Jason Ertel
c3454c9e8a
Merge branch 'master' into kilo
2021-08-31 13:37:46 -04:00
Mike Reeves
3425a0fe78
Delete Curators for all modules
2021-08-31 11:12:21 -04:00
Mike Reeves
9605eda559
Close Curators for all modules
2021-08-31 10:49:39 -04:00
Mike Reeves
ff09d9ca58
Merge pull request #5355 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERIFY_ISO.md
2021-08-31 10:06:12 -04:00
Mike Reeves
77b82bf2c0
Update VERIFY_ISO.md
2021-08-31 10:01:32 -04:00
Mike Reeves
ccc8f9ff0a
Merge pull request #5353 from Security-Onion-Solutions/hotfix/2.3.70
2021-08-31 09:57:05 -04:00
Mike Reeves
43d20226a8
Merge pull request #5352 from Security-Onion-Solutions/wazhf
...
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:47:14 -04:00
Mike Reeves
4fe0a1d7b4
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:39:37 -04:00
Mike Reeves
7a48a94624
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-31 08:22:55 -04:00
Mike Reeves
1aacc27cd4
Merge pull request #5340 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-08-30 17:48:53 -04:00
Mike Reeves
92858cd13a
Update HOTFIX
2021-08-30 17:38:29 -04:00
Mike Reeves
99cb38362a
Merge pull request #5339 from Security-Onion-Solutions/hotfix/wazuh-update-exclude
...
wazuh-agent fix + pull in master
2021-08-30 17:37:47 -04:00
William Wernert
bfd632e20a
Add wazuh to exclude arg when running yum update
2021-08-30 14:21:13 -04:00
Mike Reeves
518f9fceb0
Merge pull request #5337 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2021-08-30 12:33:43 -04:00
Mike Reeves
2b34da0fee
Update HOTFIX
2021-08-30 12:32:44 -04:00
William Wernert
72859adb13
Fix typo in so-checkin
2021-08-27 15:23:01 -04:00
Mike Reeves
a27263435a
Add Templates for all filebeat modules
2021-08-27 14:41:04 -04:00
Mike Reeves
f8cdf5bca3
Add Templates for all filebeat modules
2021-08-27 14:39:02 -04:00
William Wernert
ca5339341f
Fix batch size regex to disallow 0
2021-08-27 11:34:28 -04:00
William Wernert
c5d120293d
Initial work to add unattended option to soup
2021-08-27 11:33:51 -04:00
Jason Ertel
12b5c0899b
merge
2021-08-27 08:20:23 -04:00
Jason Ertel
09d5097837
Remove unused automation files
2021-08-25 21:08:49 -04:00
Jason Ertel
de5f823abf
Add automation for deploy-vader env
2021-08-25 18:28:17 -04:00
Josh Brower
7b93f355e2
so-import-evtx - timestamp extraction
2021-08-25 15:17:19 -04:00
m0duspwnens
a27569f20b
remove source when contents provided
2021-08-25 12:32:17 -04:00
m0duspwnens
fd1e632386
cleanup yaml
2021-08-25 12:08:43 -04:00
m0duspwnens
0681d29bb0
starting es pillarization
2021-08-25 10:23:06 -04:00
Josh Brower
ef650c6ee6
Merge pull request #5235 from Security-Onion-Solutions/feature/so-playbook-import
...
Initial version so-playbook-import
2021-08-24 10:40:07 -04:00
Mike Reeves
24f36bb4c9
Merge pull request #5284 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 GRAFANA hotfix to dev
2021-08-24 10:27:09 -04:00
m0duspwnens
9783d13ea3
remove identifier from HOTFIX file
2021-08-24 10:22:01 -04:00
m0duspwnens
427ec98ce5
fix merge conflict in HOTFIX file
2021-08-24 10:20:42 -04:00
Josh Patterson
72ba29fb7b
Merge pull request #5282 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-24 10:15:33 -04:00
Josh Patterson
2859bff0e4
Merge pull request #5281 from Security-Onion-Solutions/grafana_fleet_hotfix
...
sig files and iso info
2021-08-24 10:01:10 -04:00
Mike Reeves
6e921415ea
sig files and iso info
2021-08-24 10:00:06 -04:00
Mike Reeves
2f8b68e67a
sig files and iso info
2021-08-24 09:58:28 -04:00
Mike Reeves
e762491039
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-24 09:50:41 -04:00
Mike Reeves
11381e304b
Merge pull request #5273 from Security-Onion-Solutions/kilo
...
Switch to new Curator auth params
2021-08-24 08:29:47 -04:00
Jason Ertel
6d49bca0ac
Switch to new auth params
2021-08-23 15:36:11 -04:00
Josh Patterson
8ea89932ae
Merge pull request #5270 from Security-Onion-Solutions/grafana_fleet_hotfix
...
Grafana fleet hotfix
2021-08-23 13:10:35 -04:00
m0duspwnens
f87cf123b0
fix typo - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:08:11 -04:00
m0duspwnens
80f4d03254
place unique identifier on same line for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:05:28 -04:00
m0duspwnens
a9cc68f89e
add unique identifier for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:02:49 -04:00
m0duspwnens
b053f29a89
only create dashboards for certain node types - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 12:58:52 -04:00
Mike Reeves
19cfce5e0b
Add curator delete yml files
2021-08-23 10:47:41 -04:00
Mike Reeves
c4a32ca631
Merge pull request #5259 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 CURATOR Hotfix to Dev
2021-08-23 09:37:50 -04:00
Jason Ertel
b78da5c237
Merge hotfix to dev; reset to .80
2021-08-23 09:36:20 -04:00
Mike Reeves
0abf7593ed
Merge pull request #5233 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-23 09:28:07 -04:00
Josh Brower
aa420b914b
Initial version so-playbook-import
2021-08-20 16:27:09 -04:00
Mike Reeves
f096b513b7
Merge pull request #5232 from Security-Onion-Solutions/cfixhfix
...
Cfixhfix
2021-08-20 15:40:44 -04:00
Mike Reeves
51b517581a
2.3.70 sigs
2021-08-20 15:38:56 -04:00
Mike Reeves
936c998ecb
CURATOR ISO info
2021-08-20 12:49:55 -04:00
Mike Reeves
02372d130a
Merge pull request #5224 from Security-Onion-Solutions/curator_cron
...
remove the curator cronjobs if it is disabled
2021-08-20 10:44:55 -04:00
m0duspwnens
6f9a263af3
remove the curator cronjobs if it is disabled
2021-08-20 10:40:15 -04:00
Mike Reeves
43ffaab82c
Merge pull request #5213 from Security-Onion-Solutions/hotfix/curator
...
stop curator and remove from so-status for manager
2021-08-19 15:45:17 -04:00
m0duspwnens
dccfdb14e4
stop curator and remove from so-status for manager
2021-08-19 15:40:17 -04:00
Josh Patterson
21f3b3d985
Merge pull request #5212 from Security-Onion-Solutions/hotfix/curator
...
just dont run curator on manager
2021-08-19 15:27:55 -04:00
m0duspwnens
e2d74b115f
just dont run curator on manager
2021-08-19 15:26:22 -04:00
Mike Reeves
13741400f1
Merge pull request #5210 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2021-08-19 15:02:52 -04:00
Mike Reeves
d0f587858c
Merge pull request #5211 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Curator
2021-08-19 15:02:28 -04:00
Mike Reeves
acca8cc5d2
Update HOTFIX
2021-08-19 15:01:21 -04:00
Mike Reeves
ef950955bd
Update VERSION
2021-08-19 15:00:51 -04:00
Josh Patterson
9a8ccef828
Merge pull request #5209 from Security-Onion-Solutions/issue/5195
...
fix error in telegraf log
2021-08-19 13:27:08 -04:00
m0duspwnens
7b8e23fadd
fix error in telegraf log - https://github.com/Security-Onion-Solutions/securityonion/issues/5195
2021-08-19 11:11:24 -04:00
Mike Reeves
18335afa7f
Merge pull request #5204 from Security-Onion-Solutions/kilo
...
Update 2.3.80
2021-08-19 08:55:44 -04:00
Jason Ertel
41e8be87b6
Update 2.3.80
2021-08-19 08:42:29 -04:00
Doug Burks
39f32a6e13
Merge pull request #5185 from Security-Onion-Solutions/dev
...
2.3.70
2021-08-19 06:22:57 -04:00
Mike Reeves
8e9f95652d
Merge pull request #5188 from Security-Onion-Solutions/2.3.70
...
2.3.70 sigs
2021-08-18 09:37:51 -04:00
Mike Reeves
30489e4117
2.3.70 sigs
2021-08-18 09:35:48 -04:00
Mike Reeves
9dc9f10003
Merge pull request #5174 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-functions
2021-08-17 10:46:17 -04:00
Mike Reeves
1ced05c1d2
Update so-functions
2021-08-17 10:44:44 -04:00
Mike Reeves
41b246b8b3
Merge pull request #5169 from Security-Onion-Solutions/agrepo
...
Fix repo creation in airgap
2021-08-16 13:08:21 -04:00
Mike Reeves
a12f19c533
Fix repo creation in airgap
2021-08-16 13:00:52 -04:00
Josh Patterson
f1c91555ae
Merge pull request #5166 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-16 09:08:27 -04:00
Jason Ertel
e39de8c7bc
Merge pull request #5089 from Ron89/feature/thehive-userupdate
...
add user password update command
2021-08-15 09:36:35 -04:00
Mike Reeves
d0e312ec42
Merge pull request #5149 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 18:42:34 -04:00
Mike Reeves
e492833453
Grid Fixes
2021-08-13 18:32:55 -04:00
Mike Reeves
9beacacd44
Grid Fixes
2021-08-13 18:26:17 -04:00
Mike Reeves
aad14b2461
Grid Fixes
2021-08-13 18:22:02 -04:00
m0duspwnens
4955b552df
remove -
2021-08-13 17:42:37 -04:00
Mike Reeves
55e8a777d4
Merge pull request #5147 from Security-Onion-Solutions/issue/4674
...
keep the list unique
2021-08-13 17:39:54 -04:00
m0duspwnens
a98ed282c0
keep the list unique
2021-08-13 17:38:45 -04:00
Mike Reeves
7504b1cb2e
Merge pull request #5146 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 16:25:31 -04:00
m0duspwnens
afab1cb1e6
Merge remote-tracking branch 'remotes/origin/dev' into issue/2806
2021-08-13 16:19:57 -04:00
m0duspwnens
cd0b9bbe4a
dont always add curator to so-status
2021-08-13 16:19:41 -04:00
Mike Reeves
3ea29e77a9
Merge pull request #5145 from Security-Onion-Solutions/bugfix/so-logscan-soup-pull
...
Remove so-logscan from so-image-common arrays
2021-08-13 13:59:10 -04:00
William Wernert
fb4c2c35e3
Remove so-logscan from so-image-common arrays
2021-08-13 13:58:08 -04:00
HE Chong
81ccce8659
negative case where username doesn't exist now report exception as expected
2021-08-13 23:00:11 +08:00
HE Chong
0d5e3771f5
modify user password update script for theHive, keep it in consistency with Fleet counterpart.
2021-08-13 21:52:19 +08:00
HE Chong
2030ef65f1
add user password update script for Fleet
2021-08-13 21:50:24 +08:00
HE Chong
b6c361f83d
add user password update script for The Hive
2021-08-13 20:54:35 +08:00
Mike Reeves
9404cb635d
Grid Fixes
2021-08-13 08:48:47 -04:00
William Wernert
da53b39c15
Merge pull request #5142 from Security-Onion-Solutions/foxtrot
...
Add image pull script to allow so-learn to pull missing images, update wording on several whiptail prompts
2021-08-12 16:09:55 -04:00
William Wernert
86569b0599
Make sbin script permissions consistent
2021-08-12 16:05:54 -04:00
William Wernert
45aa2f72cb
Merge branch 'dev' into foxtrot
2021-08-12 15:45:12 -04:00
Mike Reeves
06b7434ca2
Merge pull request #5141 from Security-Onion-Solutions/kilo
2021-08-12 15:05:14 -04:00
Jason Ertel
258cebda6e
Correct identity update payload to not have unsupported fields
2021-08-12 15:01:45 -04:00
Jason Ertel
0cca43c4bd
Merge branch 'dev' into kilo
2021-08-12 15:01:12 -04:00
William Wernert
bf40a1038e
Whiptail changes
...
* Update wording of ip mask prompt + so-allow question for clarity
* Remove old ip+mask prompts
2021-08-12 10:32:27 -04:00
William Wernert
3312a66e75
Fix indent
2021-08-11 16:37:22 -04:00
William Wernert
4a31d6b3bc
Specify images are also verified
2021-08-11 16:35:33 -04:00
William Wernert
64dfc6e191
Fix pull logic and properly hide output
2021-08-11 16:33:45 -04:00
William Wernert
95bd7f9861
Merge branch 'dev' into foxtrot
2021-08-11 13:47:38 -04:00
William Wernert
983549711c
Pull image if missing when enabling module in so-learn
2021-08-11 13:47:31 -04:00
Josh Patterson
5922dbdf22
Merge pull request #5120 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-08-10 12:29:51 -04:00
m0duspwnens
9e48a5b57b
fix the pillar.get
2021-08-10 10:29:29 -04:00
m0duspwnens
3c1114403e
fix the pillar.get
2021-08-10 10:25:05 -04:00
m0duspwnens
8d2f614af6
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-08-10 10:16:30 -04:00
m0duspwnens
1415de858c
delete old dashboard folders via api - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-10 10:16:14 -04:00
Josh Patterson
59e9fddf18
Merge pull request #5109 from Security-Onion-Solutions/issue/4674
...
remove old dashboard dirs
2021-08-09 13:37:45 -04:00
m0duspwnens
ad3b6cf629
remove old dashboard dirs - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-09 13:34:02 -04:00
William Wernert
b12e2eded5
Merge pull request #5086 from Security-Onion-Solutions/foxtrot
...
Add conditional check for logscan log + add log folder to logrotate config
2021-08-06 11:32:23 -04:00
William Wernert
26030d83eb
Merge branch 'dev' into foxtrot
2021-08-06 09:44:10 -04:00
William Wernert
3b01f6431e
Add logscan to logrotate config
2021-08-06 09:43:58 -04:00
Jason Ertel
a646867593
Merge branch 'dev' into kilo
2021-08-06 09:14:45 -04:00
Josh Patterson
768e61e11a
Merge pull request #5080 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-05 12:02:42 -04:00
m0duspwnens
e72ad9eb5a
allow curator
2021-08-05 11:54:49 -04:00
m0duspwnens
ac4faf673d
add so-manager to curator.yml
2021-08-05 11:11:59 -04:00
William Wernert
dd1769fbef
Only check for logscan on manager-type and import
2021-08-05 11:02:09 -04:00
m0duspwnens
853a986082
add reqs to docker add manager to so-curator-closed-delete-delte
2021-08-05 10:36:18 -04:00
m0duspwnens
727a3742f5
run only on manager if truecluster enabled
2021-08-05 09:50:51 -04:00
Doug Burks
478a0b6a3f
Merge pull request #5075 from Security-Onion-Solutions/fix/typo
...
fix typo
2021-08-05 07:43:46 -04:00
Doug Burks
771688a70f
fix typo
2021-08-05 07:34:07 -04:00
Josh Patterson
40fa549353
Merge pull request #5066 from Security-Onion-Solutions/issue/2806
...
dont run curator on searchnode if truecluster is enabled
2021-08-04 15:01:11 -04:00
Jason Ertel
84fdc1e690
Merge pull request #5057 from Security-Onion-Solutions/bravo
...
Several Suricata things
2021-08-04 12:26:11 -04:00
Mike Reeves
71bbb41b5f
Merge branch 'dev' into bravo
2021-08-04 10:57:10 -04:00
m0duspwnens
52cb72ba67
dont run curator on searchnode if truecluster is enabled - https://github.com/Security-Onion-Solutions/securityonion/issues/2806
2021-08-04 09:40:34 -04:00
William Wernert
54a3b754e0
Merge pull request #5050 from Security-Onion-Solutions/foxtrot
...
Add logscan state, related pipeline config, and initial so-learn script
2021-08-03 16:30:07 -04:00
William Wernert
2bc88e7750
Remove learn from allowed states for helixsensor
2021-08-03 15:29:37 -04:00
William Wernert
ef59cb47dd
Use print_err function
2021-08-03 15:26:57 -04:00
William Wernert
9e5d3aa286
Fix removed root check in so-rule
2021-08-03 15:25:53 -04:00
William Wernert
25bf25eae6
Allowed states remove typo'd logscan
2021-08-03 15:24:32 -04:00
William Wernert
24f5fa66f3
Merge branch 'dev' into foxtrot
2021-08-03 13:02:29 -04:00
Mike Reeves
1aeb2d7d4f
Merge pull request #5040 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-03 10:59:28 -04:00
Jason Ertel
ee176f5bfd
Condense cloud automations
2021-08-03 07:40:50 -04:00
Jason Ertel
eb093b8e6c
Condense cloud automations
2021-08-02 21:52:42 -04:00
Jason Ertel
f88fa6e3b2
Condense cloud automations
2021-08-02 21:51:26 -04:00
Jason Ertel
724f7d4f3d
Merge pull request #5036 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-02 18:04:05 -04:00
Jason Ertel
19816d8814
Condense cloud automations
2021-08-02 17:55:27 -04:00
William Wernert
d3b170c6df
Add logscan automation file + fix enable command in setup
2021-08-02 12:37:37 -04:00
William Wernert
757091beeb
Add log_level to logscan.conf
2021-08-02 10:35:39 -04:00
William Wernert
8a49039b85
Only append source.ip to logscan.source.ips if it's been created
2021-08-02 09:50:49 -04:00
William Wernert
4f39cd1d7f
Add logscan dynamic object to so-common template mappings
2021-07-30 16:02:02 -04:00
William Wernert
2a6277c0c3
Fix field names in logscan pipeline
2021-07-30 15:46:39 -04:00
William Wernert
33bd6aed20
Fix logscan pipeline on eval
...
* Rename logscan pipeline to logscan.alert
* Add module to indices array in filebeat.yml
2021-07-30 14:41:15 -04:00
William Wernert
b9980c9d30
Fix pipeline name
2021-07-30 13:09:09 -04:00
William Wernert
01bb94514c
Correct mod_so_status to only act on single string
2021-07-30 11:05:48 -04:00
William Wernert
d71967ea1d
Fix incorrect writing of so-status.conf
2021-07-30 10:28:39 -04:00
William Wernert
0b06d0bfdb
Merge branch 'dev' into foxtrot
2021-07-29 15:15:25 -04:00
William Wernert
b2a83018ba
Remove or run logscan based on enabled bool
2021-07-29 15:14:54 -04:00
William Wernert
ba265d94f4
Change default value in learn init to a dict where approriate
2021-07-29 15:14:28 -04:00
Mike Reeves
af7b314cfe
Merge pull request #4993 from Security-Onion-Solutions/kilo
...
Merge 2.3.61 MSEARCH Hotfix into dev
2021-07-29 15:02:51 -04:00
Jason Ertel
4c6447a3da
merge 2.3.61 MSEARCH hotfix into dev
2021-07-29 15:00:58 -04:00
William Wernert
b30f771fa2
Set write_needed flag correctly, include newline in so-status.conf string
2021-07-29 14:59:26 -04:00
Mike Reeves
837c0402a0
Merge pull request #4989 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-29 14:58:25 -04:00
William Wernert
e38219aa2e
Fix learn init.sls typo
2021-07-29 14:35:02 -04:00
William Wernert
9e92f6da3d
Add container to so-status when enabling/disabling ml module
2021-07-29 14:25:20 -04:00
William Wernert
44551ea9ee
Fix so-learn list
2021-07-29 13:31:48 -04:00
William Wernert
c53da9b1ff
Fix wrong variables in learn init.sls
2021-07-29 12:04:40 -04:00
William Wernert
e1785dbd9a
Fix typo
2021-07-29 12:00:53 -04:00
William Wernert
2560a9b78c
[wip] Change learn:modules to dictionary
2021-07-29 11:58:58 -04:00
William Wernert
d53e989c55
Add ability to set cpu_period per module
2021-07-29 11:52:10 -04:00
William Wernert
211a841cdb
Fix file path in bind mount for logscan
2021-07-29 11:40:19 -04:00
Josh Patterson
50e4365475
Merge pull request #4990 from Security-Onion-Solutions/issue/4985
...
Issue/4985
2021-07-29 11:14:54 -04:00
Jason Ertel
c524b54af1
Merge pull request #4988 from Security-Onion-Solutions/mkr2361
...
2.3.61-MSEARCH
2021-07-29 11:10:41 -04:00
Mike Reeves
7591bb115e
2.3.61-MSEARCH
2021-07-29 11:09:54 -04:00
Mike Reeves
3d2da303c8
2.3.61-MSEARCH
2021-07-29 11:09:27 -04:00
Mike Reeves
f585eb6e62
2.3.61-MSEARCH
2021-07-29 11:08:03 -04:00
m0duspwnens
4b6120a46b
fix the hours get
2021-07-29 10:59:33 -04:00
Mike Reeves
d946c6d5ed
Merge pull request #4987 from Security-Onion-Solutions/kilo
...
Do not prompt about uppercased hostname during testing
2021-07-29 10:57:56 -04:00
William Wernert
5894b85bd1
Remove broken yaml dump arg, rename metavars
2021-07-29 10:57:53 -04:00
m0duspwnens
3fc43f7d92
allow for adjustment to auto patch os schedule - https://github.com/Security-Onion-Solutions/securityonion/issues/4985
2021-07-29 10:48:24 -04:00
Jason Ertel
8ed264460f
Do not prompt about uppercased hostname during testing
2021-07-29 10:45:35 -04:00
William Wernert
811b32735e
Merge branch 'dev' into foxtrot
2021-07-29 09:52:29 -04:00
Mike Reeves
4b3db0c4d2
Merge pull request #4972 from Security-Onion-Solutions/mkr2361
...
Fix Manager Search
2021-07-28 17:08:40 -04:00
Mike Reeves
281ba21298
Merge pull request #4956 from Security-Onion-Solutions/kilo
...
Merge master to dev
2021-07-28 17:07:58 -04:00
Mike Reeves
d4a177949a
Fix Manager Search
2021-07-28 17:05:16 -04:00
Mike Reeves
a42d8c9229
Fix Manager Search
2021-07-28 17:03:14 -04:00
William Wernert
dd0e407935
Use correct container name
2021-07-28 15:06:38 -04:00
William Wernert
7ef5b39b04
[wip] Fix 'Nonetype' object is not callable error
2021-07-28 14:28:00 -04:00
William Wernert
cf9121dfc2
Actually download so-learn container
2021-07-28 14:13:16 -04:00
Josh Patterson
fcfc2a65a9
Merge pull request #4968 from Security-Onion-Solutions/issue/3933
...
allow for sampleSize adjustment in kibana
2021-07-28 11:13:49 -04:00
William Wernert
91accb0bc6
[wip] Fixing so-learn script
2021-07-28 10:12:32 -04:00
William Wernert
e2abe8840f
Fix directory in logscan state
2021-07-28 10:12:19 -04:00
m0duspwnens
ead9ae8cb5
fix merge and defaults passed
2021-07-28 09:58:38 -04:00
William Wernert
455719936b
Uncomment required lines in so-learn
2021-07-28 09:53:35 -04:00
William Wernert
8d56fc71fa
Fix jinja length calculation
2021-07-28 09:53:24 -04:00
William Wernert
833d154bf4
Merge branch 'dev' into foxtrot
2021-07-28 09:50:11 -04:00
William Wernert
f31dc5abc7
Add learn to allowed states
2021-07-28 09:49:59 -04:00
m0duspwnens
9a429230fe
wrap with raw due to {{value}}
2021-07-28 09:39:35 -04:00
m0duspwnens
b36d46b7f2
change to jinja tem,plate
2021-07-28 09:27:44 -04:00
m0duspwnens
fee89665fd
dict not list for defaults
2021-07-28 09:18:15 -04:00
m0duspwnens
d78a37f9e3
allow for control of kibana discover sampleSize - https://github.com/Security-Onion-Solutions/securityonion/issues/3933
2021-07-28 09:12:31 -04:00
Jason Ertel
28c5c02ef1
Merge pull request #4958 from Security-Onion-Solutions/issue/4024
...
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:21:13 -04:00
m0duspwnens
8ffeae38bc
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:16:48 -04:00
William Wernert
f4fae7938e
Merge branch 'dev' into foxtrot
2021-07-27 16:01:44 -04:00
Jason Ertel
22920bc9a1
clear out hotfix from merge
2021-07-27 14:42:11 -04:00
Jason Ertel
ceb82cb863
Merge branch 'master' into kilo
2021-07-27 14:40:31 -04:00
Mike Reeves
1caa361e22
Merge pull request #4955 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-27 14:33:31 -04:00
Mike Reeves
da20790238
Merge pull request #4954 from Security-Onion-Solutions/mkr2361
...
Steno ISO Details
2021-07-27 11:11:22 -04:00
Mike Reeves
f359dd0cd4
Steno ISO Details
2021-07-27 11:09:25 -04:00
Josh Patterson
bee442a21f
Merge pull request #4950 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-07-27 10:28:02 -04:00
m0duspwnens
a66765e99b
remove old dashboards, set default refresh to 5m
2021-07-27 10:23:35 -04:00
m0duspwnens
0db7f91eb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-27 08:53:31 -04:00
m0duspwnens
850315dc20
remove role conditional from all panel queiries
2021-07-27 08:47:44 -04:00
Mike Reeves
d35e4bea01
Merge pull request #4932 from Security-Onion-Solutions/issue/4922
...
Issue/4922
2021-07-26 16:18:22 -04:00
Jason Ertel
356b623148
Merge pull request #4937 from Security-Onion-Solutions/kilo
...
Add Azure automations
2021-07-26 16:13:57 -04:00
Jason Ertel
3a022e7a83
Add Azure automations
2021-07-26 15:50:15 -04:00
William Wernert
64945cec16
[wip] Initial work to enable/disable "learn" modules
2021-07-26 14:24:10 -04:00
Jason Ertel
26741bdb53
Add wss: to CSP for browsers that enforce wss distinctly from other protocols
2021-07-26 10:55:30 -04:00
m0duspwnens
7aa5e857ed
update hotfix file
2021-07-26 10:46:52 -04:00
m0duspwnens
2e277bf487
change container to abesent of pcap is disabled
2021-07-26 10:08:59 -04:00
m0duspwnens
e4f46c6e14
hide role template var from all dash except overview
2021-07-26 09:36:05 -04:00
m0duspwnens
e9d90644fd
fix query and allow for setting text and value of servername template var
2021-07-23 16:52:07 -04:00
m0duspwnens
5a06f0dce9
role template var now selects default role
2021-07-23 16:34:58 -04:00
m0duspwnens
08e9a58f2e
simply to one servername.json
2021-07-23 16:09:25 -04:00
m0duspwnens
e1f0c8e87c
add "list" bast to tempating defs for overview
2021-07-23 15:43:31 -04:00
m0duspwnens
17a532f7b5
add new templating defs to overview
2021-07-23 15:41:03 -04:00
m0duspwnens
c7306dda12
fix servername_eval template var, test using 1 servername template var
2021-07-23 15:38:45 -04:00
m0duspwnens
00d311cd6c
fix nodetype listing
2021-07-23 14:40:44 -04:00
m0duspwnens
f8d2a7f449
fix nodetype listing
2021-07-23 13:43:35 -04:00
m0duspwnens
a02a928996
add missing ]
2021-07-23 13:33:25 -04:00
m0duspwnens
eb661b7a24
add ability to set title for dashboards, only create dashboards/dirs if that node type exists
2021-07-23 13:31:44 -04:00
m0duspwnens
6aea607f21
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-23 11:12:48 -04:00
m0duspwnens
41e747dcc1
add servername_all template var
2021-07-23 10:55:15 -04:00
m0duspwnens
d3d02faa1c
remove detailed
2021-07-23 10:52:30 -04:00
m0duspwnens
7a85a3c7f7
move dashboard location
2021-07-23 10:20:57 -04:00
m0duspwnens
fceb2851ef
add eval dashboard
2021-07-23 09:02:40 -04:00
William Wernert
2f118781ea
Merge branch 'dev' into foxtrot
2021-07-23 08:54:08 -04:00
William Wernert
b8e3a45a7e
[wip] Add logscan state
...
Do not add state to top file or setup yet, script will be written to enable the feature shortly
2021-07-23 08:53:45 -04:00
m0duspwnens
61312397e1
update container uptime panel
2021-07-23 08:25:43 -04:00
m0duspwnens
8ea4682aab
add docker container uptime to overview dash
2021-07-23 07:34:01 -04:00
m0duspwnens
3b6befdb97
adjust gridpos
2021-07-22 15:05:37 -04:00
m0duspwnens
613979ea3f
remove extra comma
2021-07-22 15:03:58 -04:00
m0duspwnens
191def686b
add packet loss panels
2021-07-22 15:02:06 -04:00
Mike Reeves
f986e0dc78
Merge pull request #4892 from Security-Onion-Solutions/kilo
...
Merge master back to dev
2021-07-22 14:37:40 -04:00
Jason Ertel
08e75567d4
merge master to kilo
2021-07-22 14:34:24 -04:00
Mike Reeves
668199f1a8
Merge pull request #4889 from Security-Onion-Solutions/2361update
...
2.3.61
2021-07-22 14:29:13 -04:00
Jason Ertel
7a753a56ec
Update README with 2.3.61
2021-07-22 13:54:04 -04:00
m0duspwnens
7b38b4e280
fix {{}}
2021-07-22 13:36:44 -04:00
m0duspwnens
7dc2e2ca73
add option to hide trend on zeek packet loss graph
2021-07-22 13:35:25 -04:00
m0duspwnens
44eb23615a
change to packet_loss
2021-07-22 13:20:19 -04:00
m0duspwnens
d47566f667
remove monitor inbound graph
2021-07-22 13:18:31 -04:00
m0duspwnens
9ae84c8108
add network and tool packetloss panels to overview
2021-07-22 13:16:39 -04:00
Mike Reeves
578c7aac35
2.3.61
2021-07-22 13:06:26 -04:00
m0duspwnens
1c460cc19c
fix traffic overview graphs
2021-07-22 10:31:47 -04:00
m0duspwnens
ff436aea93
allow multi and all for manint and monint vars
2021-07-22 10:06:31 -04:00
m0duspwnens
aa333794f7
add disk usage percent graphs
2021-07-22 09:54:17 -04:00
doug
3d3593a1a9
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-22 09:50:21 -04:00
Jason Ertel
257062e20c
Update release notes link to match top right menu for airgap
2021-07-22 09:48:34 -04:00
doug
fa9d7afb46
FIX: Airgap link to Release Notes #4685
2021-07-22 09:42:37 -04:00
m0duspwnens
ae5f351e1a
change row name
2021-07-22 09:31:17 -04:00
m0duspwnens
257a88ec8e
change row name
2021-07-22 09:30:43 -04:00
m0duspwnens
e1e6304a8a
rename
2021-07-22 09:29:37 -04:00
m0duspwnens
a81ef0017c
rename panels source, reorg overview
2021-07-22 09:15:22 -04:00
m0duspwnens
b89162e086
change id
2021-07-22 08:01:54 -04:00
m0duspwnens
a6630540a4
add system uptime graph to overview dash
2021-07-21 18:11:42 -04:00
m0duspwnens
a528c5d54b
role first var for overview
2021-07-21 17:41:53 -04:00
m0duspwnens
690699ddf7
update template vars to use regex for $servername
2021-07-21 17:17:23 -04:00
m0duspwnens
cd8d9c657e
add mgmt interface traffic graphs to overview
2021-07-21 16:24:16 -04:00
m0duspwnens
f732b80b92
add swap usage percent to overview dash
2021-07-21 15:48:04 -04:00
Jason Ertel
ad8c12afa5
Upgrade ES to 7.13.4
2021-07-21 15:07:02 -04:00
m0duspwnens
479fcb6c46
add panel for memory usage percent
2021-07-21 15:00:05 -04:00
Jason Ertel
74874dfff2
Allow web pages to load blob data
2021-07-21 14:59:33 -04:00
m0duspwnens
ceb108a5fe
set min yaxes to 0
2021-07-21 14:47:57 -04:00
m0duspwnens
235d8b7cf0
ensure role matches
2021-07-21 14:44:07 -04:00
Mike Reeves
7c9df2d75a
Update HOTFIX
2021-07-21 14:40:53 -04:00
Mike Reeves
43bf75217f
Update VERSION
2021-07-21 14:40:23 -04:00
m0duspwnens
9bf6d478c5
remove $col var
2021-07-21 14:36:08 -04:00
m0duspwnens
e2baa93270
remove role from node_config for telegraf
2021-07-21 14:32:01 -04:00
m0duspwnens
37fcda3817
add cpu row and panels to overview dashboard
2021-07-21 14:30:41 -04:00
m0duspwnens
457ae54341
role var
2021-07-21 11:50:06 -04:00
m0duspwnens
4cc3c5ada9
add role template var to overview dashboard
2021-07-21 11:35:02 -04:00
m0duspwnens
07d5736d61
change sort of legend
2021-07-21 11:33:48 -04:00
m0duspwnens
a7551a44e5
allow multi and all on servername_all template var
2021-07-21 11:29:30 -04:00
m0duspwnens
f4d3e13c7f
begin overview dashboard
2021-07-21 11:26:02 -04:00
m0duspwnens
47d82b3d35
sort desc remaining tooltips
2021-07-21 10:36:07 -04:00
m0duspwnens
9d06aff1d1
add manager dashboard
2021-07-21 10:23:39 -04:00
m0duspwnens
5ea8c978a0
add managersearch
2021-07-21 10:16:40 -04:00
m0duspwnens
6809c3a9f6
add mastersearch dashboard
2021-07-21 10:13:43 -04:00
m0duspwnens
761108964e
remove panels from searchnode dashboard
2021-07-21 10:05:43 -04:00
m0duspwnens
e3e74a84f2
test sort tooltip descending
2021-07-21 10:00:14 -04:00
m0duspwnens
1fee4e87c4
add searchnode dashboard
2021-07-21 09:51:49 -04:00
m0duspwnens
0c4c59375d
sort container uptime ascending
2021-07-21 09:11:39 -04:00
Mike Reeves
09165daab8
Several Suricata things
2021-07-21 09:10:33 -04:00
m0duspwnens
3393b77535
add sensor dashboard
2021-07-21 08:54:26 -04:00
m0duspwnens
d050bc02e2
dont show legend for docker uptime trend
2021-07-20 16:29:49 -04:00
m0duspwnens
af60ddf404
add docker container uptime graph
2021-07-20 16:28:07 -04:00
m0duspwnens
1bb92f63d1
add docker details
2021-07-20 15:21:59 -04:00
m0duspwnens
a405ca39fa
add redis.sh for telegraf on heavynodes
2021-07-20 14:31:09 -04:00
m0duspwnens
852b686d81
add servername vars for each role
2021-07-20 14:25:56 -04:00
m0duspwnens
608d5d3c26
change uid logic
2021-07-20 14:10:26 -04:00
m0duspwnens
6038ebb705
handle multile nodetpes and uid
2021-07-20 14:04:28 -04:00
m0duspwnens
4bb350d37d
add heavynode
2021-07-20 13:55:52 -04:00
m0duspwnens
d01ac55db1
add heavynode
2021-07-20 13:55:18 -04:00
Jason Ertel
fcde5c3c18
Merge pull request #4865 from Security-Onion-Solutions/kilo
...
Merge curator hotfix into dev
2021-07-20 11:47:49 -04:00
Jason Ertel
dbf19e134f
Merge branch 'master' into kilo
2021-07-20 11:44:10 -04:00
Mike Reeves
b13c5a3b8b
Merge pull request #4863 from Security-Onion-Solutions/hotfix/2.3.60
...
Hotfix/2.3.60 CuratorFix
2021-07-20 11:02:34 -04:00
m0duspwnens
b0c5a352c1
remove old panaels
2021-07-20 10:53:47 -04:00
m0duspwnens
d0b3cd5f66
add the detailed dash dir
2021-07-20 10:50:40 -04:00
m0duspwnens
24efdec9ea
cap the var
2021-07-20 10:48:46 -04:00
m0duspwnens
1bed818a8e
fix jinja
2021-07-20 10:47:10 -04:00
m0duspwnens
3c4c52567d
fix jinja
2021-07-20 10:46:41 -04:00
m0duspwnens
87ae14d11c
fix jinja
2021-07-20 10:44:32 -04:00
m0duspwnens
258d303e7f
change how dashboards are deployed
2021-07-20 10:43:00 -04:00
m0duspwnens
458350e1a8
new redis queue stat panel, change to lastnotnull
2021-07-20 09:45:28 -04:00
Mike Reeves
fe7ee1e2c7
Merge pull request #4862 from Security-Onion-Solutions/curatorfix
...
Curator Fix
2021-07-20 09:26:54 -04:00
m0duspwnens
d8910a0097
add redis queue to overview, reposition overview panels
2021-07-20 09:22:43 -04:00
Mike Reeves
3b6e683d37
Curator Fix
2021-07-20 09:21:22 -04:00
m0duspwnens
90f6bad6ce
panel title change
2021-07-20 08:54:39 -04:00
m0duspwnens
fcc6802f86
convert all singlestat to stat
2021-07-20 08:51:53 -04:00
m0duspwnens
3b9bc77ecc
remove scopedvars
2021-07-19 17:51:43 -04:00
m0duspwnens
0fb4500fcc
add legends
2021-07-19 17:39:32 -04:00
m0duspwnens
93ca00c7fe
change min y
2021-07-19 17:29:57 -04:00
m0duspwnens
522f2a3f9f
maxdatapoints and min interval
2021-07-19 17:19:56 -04:00
m0duspwnens
40ddf5f49c
fix cords
2021-07-19 16:30:02 -04:00
m0duspwnens
60356eacce
make the ids unique
2021-07-19 16:26:09 -04:00
m0duspwnens
158f3bf092
add row_stenographer
2021-07-19 16:18:02 -04:00
m0duspwnens
ebf3c65bed
add many more panels
2021-07-19 16:02:40 -04:00
William Wernert
df6d1d72e2
Merge branch 'dev' into feature/logscan
2021-07-19 15:19:59 -04:00
weslambert
72542322ca
Merge pull request #4857 from Security-Onion-Solutions/fix/beats_output_fb_modules
...
Check if Filebeat modules are being used for incoming (external) Beats
2021-07-19 13:11:06 -04:00
weslambert
fea4f3f973
Check if Filebeat modules are being used for incoming Beats
2021-07-19 12:57:42 -04:00
Mike Reeves
7878180f54
Merge pull request #4854 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2021-07-19 12:50:23 -04:00
Mike Reeves
0669aa6bbd
Update HOTFIX
2021-07-19 12:49:43 -04:00
Mike Reeves
2c4924a602
Merge pull request #4853 from Security-Onion-Solutions/fix/curator_http_auth
...
Use http_auth instead of username/password until Curator is updated to latest version
2021-07-19 12:45:29 -04:00
weslambert
bde86e0383
Use http_auth instead of username/password until Curator is upgraded to next version
2021-07-19 12:42:46 -04:00
Jason Ertel
bab18275bc
Merge pull request #4836 from Security-Onion-Solutions/fix/airgap-release-notes
...
FIX: Airgap link to Release Notes #4685
2021-07-17 11:05:33 -04:00
doug
7e86681509
FIX: Airgap link to Release Notes #4685
2021-07-16 16:50:49 -04:00
William Wernert
c2fc2df54c
Merge pull request #4835 from Security-Onion-Solutions/feature/uppercase-warning
...
Show warning to user when trying to use uppercase characters in hostname or domain name
2021-07-16 15:44:47 -04:00
William Wernert
0deb77468f
Change uppercase regex
...
Check for any uppercase characters rather than revalidating input sans uppercase
2021-07-16 15:39:09 -04:00
William Wernert
9bf1d3e0c6
Misc fixes
2021-07-16 14:59:44 -04:00
William Wernert
3a12d28d20
Merge branch 'dev' into feature/logscan
2021-07-16 14:13:19 -04:00
William Wernert
e8ba4bdc6c
Add quotes to string
2021-07-16 14:07:23 -04:00
William Wernert
b552973e00
Add logic to show uppercase warning message when appropriate
2021-07-15 16:36:46 -04:00
William Wernert
ac98e1fd0f
Remove testing default values, change wording, set default option to no
2021-07-15 16:36:24 -04:00
m0duspwnens
4246aac51b
unhide disk var
2021-07-15 13:57:43 -04:00
William Wernert
33f396bdae
Add uppercase warning function
2021-07-15 13:53:57 -04:00
William Wernert
ff25cecd54
Remove unused function
2021-07-15 13:53:31 -04:00
m0duspwnens
e88b258208
add maxDataPoints and min interval to more panels
2021-07-15 11:53:24 -04:00
m0duspwnens
1cbf895e0e
add missing ,
2021-07-15 11:27:19 -04:00
m0duspwnens
7dc1f5c445
add maxDataPoints and min interval to some panels for testing
2021-07-15 11:25:20 -04:00
m0duspwnens
439e049948
revert to $__interval
2021-07-15 10:17:21 -04:00
m0duspwnens
fbf26bef8d
test new groupby interval for trend on monitor packets
2021-07-15 08:42:53 -04:00
m0duspwnens
c1f550382c
remove interval var
2021-07-15 08:31:42 -04:00
m0duspwnens
23fb6a5c02
rename
2021-07-14 18:04:33 -04:00
m0duspwnens
d632266092
fix jinja
2021-07-14 18:01:56 -04:00
m0duspwnens
4ea3ab9538
add disk iops graphs
2021-07-14 17:58:49 -04:00
m0duspwnens
725161ea6e
fix datasource
2021-07-14 16:07:14 -04:00
m0duspwnens
fccd86f676
add disk var to standalone
2021-07-14 16:04:55 -04:00
m0duspwnens
0f0a977ed9
add disk var
2021-07-14 16:04:17 -04:00
Jason Ertel
7f9d0b59b8
Merge pull request #4808 from Security-Onion-Solutions/kilo
...
Merge hotfix from master into dev; add `so-firewall apply` feature to dev
2021-07-14 15:49:12 -04:00
m0duspwnens
b0d510167c
change title
2021-07-14 15:36:26 -04:00
m0duspwnens
4971933201
rename file
2021-07-14 15:34:39 -04:00
m0duspwnens
693a9b30ae
add swap, adjust cords
2021-07-14 15:33:28 -04:00
Jason Ertel
76c285158a
Merge branch 'master' into kilo
2021-07-14 15:24:35 -04:00
Jason Ertel
08517e3732
Merge branch 'dev' into kilo
2021-07-14 15:24:29 -04:00
m0duspwnens
59530f4263
cahnge nullPointMode
2021-07-14 14:54:48 -04:00
Mike Reeves
5d48fb41ba
Merge pull request #4800 from Security-Onion-Solutions/hotfix/2.3.60
2021-07-14 14:54:00 -04:00
m0duspwnens
4acebe7f59
replace $interval with $__interval
2021-07-14 14:47:02 -04:00
m0duspwnens
a44a7b7161
change title
2021-07-14 14:45:17 -04:00
m0duspwnens
be13f0a066
change id
2021-07-14 14:31:25 -04:00
m0duspwnens
98ce77c2b1
add disk usage graphs
2021-07-14 14:28:25 -04:00
m0duspwnens
275a491cac
cords
2021-07-14 13:44:47 -04:00
m0duspwnens
1c868f85c4
fix cords;
2021-07-14 13:25:17 -04:00
m0duspwnens
b6deacf86d
cords
2021-07-14 13:11:48 -04:00
Mike Reeves
ebe5ef6535
Merge pull request #4799 from Security-Onion-Solutions/agsoupupdate
...
Update ISO info
2021-07-14 12:07:35 -04:00
m0duspwnens
294f91473c
fix packets legend
2021-07-14 11:49:24 -04:00
m0duspwnens
902f04efb4
set 0 as min
2021-07-14 11:44:14 -04:00
m0duspwnens
ca2989c0e5
fix network cords
2021-07-14 11:42:01 -04:00
m0duspwnens
2d9697cd66
fix network cords
2021-07-14 11:40:31 -04:00
m0duspwnens
b4111a9f79
fix network cords
2021-07-14 11:38:16 -04:00
m0duspwnens
7f8212fdba
add trend, add network graphs
2021-07-14 11:31:48 -04:00
weslambert
7e1be8a3a4
Merge pull request #4798 from Security-Onion-Solutions/fix/strelka_filepath_mapping
...
Replace staging with processed in Strelka file path mapping
2021-07-14 11:16:15 -04:00
Wes Lambert
05aad07bfc
Replace staging path with processed path for analyzed files
2021-07-14 15:04:46 +00:00
Mike Reeves
92a80f9a58
Update ISO info
2021-07-14 10:30:10 -04:00
m0duspwnens
4b4ceb525a
trends for load and process status
2021-07-14 10:29:35 -04:00
weslambert
42ba9888d7
Merge pull request #4797 from Security-Onion-Solutions/fix/wazuh_data_port
...
Change field name and mapping for Wazuh's data.port
2021-07-14 10:14:53 -04:00
William Wernert
818f912a90
[fix] Remove indent
2021-07-14 10:13:14 -04:00
m0duspwnens
dae64b82ff
add trend to cpu
2021-07-14 10:09:34 -04:00
m0duspwnens
53c6edcbdb
add trends memory usage and network graphs
2021-07-14 09:57:43 -04:00
Wes Lambert
723172bc1f
Add path_unmatch for data.port so it is not mapped as integer
2021-07-14 13:45:09 +00:00
Wes Lambert
323b5d6694
Add dynamic mapping for wazuh
2021-07-14 13:43:34 +00:00
Wes Lambert
441cd3fc59
Move Wazuh-specific data to wazuh.data
2021-07-14 13:42:51 +00:00
m0duspwnens
1d23d1b2e2
start network row
2021-07-14 09:21:46 -04:00
Jason Ertel
1dd81b6d49
Merge pull request #4790 from Security-Onion-Solutions/agsoupupdate
...
Remove old airgap scripts
2021-07-13 15:45:45 -04:00
Mike Reeves
741e825ab9
Remove old airgap scripts
2021-07-13 15:44:26 -04:00
William Wernert
e41811fbd0
[fix] Typo
2021-07-13 15:14:13 -04:00
m0duspwnens
f111106a9f
fix cords
2021-07-13 14:13:19 -04:00
m0duspwnens
f9e29eaede
update memory usage graph panel
2021-07-13 14:09:23 -04:00
William Wernert
e7a6172d7e
[fix] Add single quotes to strings
2021-07-13 14:07:27 -04:00
m0duspwnens
ec8f9228e8
add memory and docker container rows
2021-07-13 14:01:42 -04:00
m0duspwnens
6c12e26632
add mem usage, add docker graphs back, update nsm usage thresh
2021-07-13 13:55:01 -04:00
m0duspwnens
9a6ac7bd20
change panels
2021-07-13 12:30:45 -04:00
m0duspwnens
5b3751da70
new load averages panel
2021-07-13 12:24:32 -04:00
m0duspwnens
65127eb226
fix servername var
2021-07-13 12:04:52 -04:00
William Wernert
115e0a6fee
[fix] Add missing comma
2021-07-13 12:04:10 -04:00
m0duspwnens
ddfab44883
new id
2021-07-13 11:59:01 -04:00
Mike Reeves
6eab390962
Merge pull request #4788 from Security-Onion-Solutions/fix/fbpipeline
...
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:40:58 -04:00
Mike Reeves
35388056d3
Merge pull request #4789 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-07-13 11:40:44 -04:00
Mike Reeves
e2c5967191
Update HOTFIX
2021-07-13 11:38:20 -04:00
weslambert
7cdb967810
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:36:18 -04:00
m0duspwnens
8900d52c33
change y
2021-07-13 11:30:14 -04:00
m0duspwnens
bab72393e6
query and id changes
2021-07-13 11:23:06 -04:00
William Wernert
e059c25ebc
[fix][wip] Fix pipeline parsing errors
2021-07-13 11:05:05 -04:00
m0duspwnens
c87ca8f5dc
spacing
2021-07-13 10:42:33 -04:00
m0duspwnens
e01e3cdd43
change file name
2021-07-13 10:25:26 -04:00
m0duspwnens
2ab9ade761
add missing gridPos
2021-07-13 10:22:48 -04:00
m0duspwnens
0b35b8f6d6
add cpu row
2021-07-13 10:19:20 -04:00
William Wernert
9ff95f66dd
Merge branch 'dev' into feature/logscan
2021-07-13 10:02:58 -04:00
William Wernert
c1523c4936
Merge pull request #4782 from Security-Onion-Solutions/feature/check-local-mods
...
Add jinja raw tag
2021-07-13 08:58:25 -04:00
m0duspwnens
b6e31278a7
move old panels into old for organization
2021-07-13 08:57:01 -04:00
William Wernert
ca2b24f735
Add jinja raw tag
2021-07-13 08:46:57 -04:00
William Wernert
2b0bca8e55
Merge branch 'dev' into feature/logscan
2021-07-12 14:58:30 -04:00
m0duspwnens
98fe7e8700
fix mean
2021-07-12 14:37:17 -04:00
m0duspwnens
0acc3cc537
rename
2021-07-12 14:32:37 -04:00
m0duspwnens
8491ffde07
add docker container network usage graphs
2021-07-12 14:18:54 -04:00
Doug Burks
2ea3989497
Merge pull request #4775 from Security-Onion-Solutions/fix/suricata-dns-response-code
...
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:40:14 -04:00
doug
e6f9592cde
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:24:21 -04:00
William Wernert
222d79bf53
Merge pull request #4774 from Security-Onion-Solutions/feature/check-local-mods
...
Compare local files to their defaults to check for potentially breaking changes
2021-07-12 12:00:18 -04:00
m0duspwnens
19d9258717
add postfix , change color
2021-07-12 11:22:48 -04:00
m0duspwnens
b46456b78e
move math, add 2 decimal spot
2021-07-12 11:16:33 -04:00
m0duspwnens
cebc2ef09d
add missing ,
2021-07-12 11:13:32 -04:00
m0duspwnens
c4ff8f6876
convert seconds to days
2021-07-12 11:12:28 -04:00
m0duspwnens
619022ef7f
2 new panels to overview
2021-07-12 11:09:23 -04:00
weslambert
c0f3c5b3db
Merge pull request #4773 from Security-Onion-Solutions/feature/filebeat-logging-level
...
Allow setting Filebeat logging level in pillar
2021-07-12 10:55:43 -04:00
m0duspwnens
860b8bf945
panel changes
2021-07-12 10:34:39 -04:00
m0duspwnens
694db81b80
fix locations and panel ids
2021-07-12 10:29:09 -04:00
weslambert
a895270bc8
Allow setting Filebeat logging level in pillar
2021-07-12 10:27:43 -04:00
m0duspwnens
7474b451ca
rename file
2021-07-12 10:24:12 -04:00
m0duspwnens
e8eecc8bc1
rename file
2021-07-12 10:22:25 -04:00
m0duspwnens
28e33b413c
add more panels for overview
2021-07-12 10:17:23 -04:00
Jason Ertel
78c58e61ea
Resolves #4765
2021-07-12 09:38:01 -04:00
William Wernert
f3ecdf21bf
Revert "Add newline to local modifications warning"
...
This reverts commit ff656365d2 .
2021-07-12 09:28:24 -04:00
William Wernert
ff656365d2
Add newline to local modifications warning
2021-07-12 09:22:22 -04:00
William Wernert
ea7c09bb00
Merge branch 'dev' into feature/check-local-mods
2021-07-12 09:20:10 -04:00
Jason Ertel
e23f7cd3e7
Merge pull request #4766 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.70
2021-07-10 13:01:54 -04:00
Jason Ertel
c6bb32b862
Bump version to 2.3.70
2021-07-10 07:34:52 -04:00
m0duspwnens
0bde69b441
update panel
2021-07-09 16:47:39 -04:00
m0duspwnens
6fbafb74bd
update panel
2021-07-09 16:45:02 -04:00
m0duspwnens
9572c1f663
fix var
2021-07-09 16:33:09 -04:00
m0duspwnens
0fedb0f2c5
add 5 minute load avg panel
2021-07-09 16:29:48 -04:00
m0duspwnens
33d3aef9f5
yamlize gridpos
2021-07-09 16:14:25 -04:00
m0duspwnens
fb8ccedf66
reduce height by 2
2021-07-09 16:04:55 -04:00
m0duspwnens
efcf0accc1
change IDs
2021-07-09 16:01:57 -04:00
m0duspwnens
f556d5c07d
change row id
2021-07-09 15:58:45 -04:00
m0duspwnens
6c1f424c0b
fix row_overview
2021-07-09 15:56:27 -04:00
William Wernert
90970f97e8
Add function to check if files copied to local have been changed in default
2021-07-09 15:44:27 -04:00
m0duspwnens
d3137dc6b9
add row panels
2021-07-09 15:43:51 -04:00
m0duspwnens
efaf53f2f7
add a panel header, change memeory usage panel
2021-07-09 15:13:50 -04:00
m0duspwnens
beb7b89275
yamlize the gridpos for panels
2021-07-09 14:13:00 -04:00
Jason Ertel
8c15fa1627
Merge pull request #4758 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.13.3; Use nginx reverse proxy for access to Playbook and Soctopus
2021-07-09 12:40:33 -04:00
m0duspwnens
bc814c9be6
new panels, add containers var, hide manint and monint var from dash
2021-07-09 11:21:06 -04:00
William Wernert
bac7ef71d8
Add logscan.source.ips field
2021-07-09 10:55:11 -04:00
m0duspwnens
dd199ea30f
remove quotes if pillar doesnt exist
2021-07-09 10:00:47 -04:00
m0duspwnens
fc8acac1a5
change id
2021-07-08 17:39:34 -04:00
m0duspwnens
fec269c3e7
add combined container mem panel
2021-07-08 17:28:18 -04:00
m0duspwnens
8e366fd633
add combined container mem panel
2021-07-08 17:27:51 -04:00
m0duspwnens
f7d54186dd
remove all panels from standalone
2021-07-08 17:11:33 -04:00
m0duspwnens
ab92fb3910
add cpucount to standalone
2021-07-08 17:08:45 -04:00
m0duspwnens
6783e2e28b
dont hide cpucount on dashboard
2021-07-08 17:06:21 -04:00
m0duspwnens
4e47d3f458
remove single quotes
2021-07-08 17:04:41 -04:00
m0duspwnens
b265c7dcb7
single quote cpucount
2021-07-08 17:00:17 -04:00
m0duspwnens
f4fae89b8e
fix copy paste error
2021-07-08 16:50:25 -04:00
m0duspwnens
45f0b4c85f
manint and monint
2021-07-08 16:43:53 -04:00
m0duspwnens
7c80483f6e
change CPUS to $cpucount
2021-07-08 16:39:14 -04:00
Jason Ertel
08ba4fdbee
Update Kibana saved objects to 7.13.3
2021-07-08 16:34:16 -04:00
m0duspwnens
7085796601
replace SERVERNAME with $servername
2021-07-08 16:33:21 -04:00
m0duspwnens
091b5f73b1
update var
2021-07-08 14:43:38 -04:00
Jason Ertel
0c079edc1a
Reverse proxy requests to playbook, soctopus, and nodered
2021-07-08 14:27:16 -04:00
m0duspwnens
54cdfb89f6
remove common_standalone.json.jinja
2021-07-08 14:14:40 -04:00
m0duspwnens
f56514ed7d
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-08 14:12:26 -04:00
m0duspwnens
56697fde19
create common dashboard and define templates/dashbaord vars
2021-07-08 14:10:22 -04:00
William Wernert
80525ee736
[wip] Add logscan pipeline
2021-07-08 12:29:50 -04:00
Jason Ertel
a43bdd9aad
Merge pull request #4723 from Security-Onion-Solutions/dev
...
HEAVYNODE_REDIS hotfix
2021-07-08 11:42:22 -04:00
m0duspwnens
20360d0bb0
create node_config measurement for nodes to be used for grafana dashboard vars
2021-07-08 11:18:25 -04:00
Josh Patterson
70d7513f84
Merge pull request #4729 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 14:49:38 -04:00
Josh Patterson
12b7fd3ab4
whitespace
2021-07-07 14:48:07 -04:00
Josh Patterson
c32b5b5429
whitespace
2021-07-07 14:47:16 -04:00
Josh Patterson
ea2a748dba
whitespace
2021-07-07 14:44:44 -04:00
Josh Patterson
c1d7d8c55a
add new line
2021-07-07 14:43:20 -04:00
Josh Patterson
a3c58d8445
remove heavy soup
2021-07-07 14:42:38 -04:00
Josh Patterson
cfc5c2aef6
do ; instead of &&
2021-07-07 14:32:57 -04:00
Josh Patterson
313260a0c5
add heavy action in soup for ssl redis, es, ls, fb
2021-07-07 14:22:45 -04:00
Josh Patterson
ee548aaf83
Merge pull request #4728 from Security-Onion-Solutions/fix/heavyfix
...
remove soup control of heavy
2021-07-07 14:01:32 -04:00
m0duspwnens
5eab57e500
remove soup control of heavy
2021-07-07 13:58:52 -04:00
Josh Patterson
6f48fdad42
Merge pull request #4727 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 12:15:50 -04:00
m0duspwnens
98fb5109d7
tell heavys to update ssl and restart containers for HEAVYNODE_SSL_LOGSTASH_REDIS_PIPELINES hotfix
2021-07-07 12:05:38 -04:00
m0duspwnens
9c2ead16cc
common name changes, allow cert to be managed regardless of expire date for heavy node
2021-07-07 10:22:37 -04:00
Jason Ertel
c4293c6119
Merge pull request #4724 from Security-Onion-Solutions/kilo
...
Merge master into dev via kilo
2021-07-07 07:21:21 -04:00
Jason Ertel
13c392d758
Merge branch 'master' into kilo
2021-07-07 06:40:30 -04:00
m0duspwnens
35f10518b2
map file into container
2021-07-06 17:12:21 -04:00
m0duspwnens
03066c4674
rename file
2021-07-06 17:08:29 -04:00
m0duspwnens
e33a6892b3
point to new location
2021-07-06 16:58:15 -04:00
m0duspwnens
87bb3f4a6b
quote the 5m
2021-07-06 16:45:10 -04:00
m0duspwnens
62bfaa4e45
send node_config data into telegraf for dashboard queries
2021-07-06 16:30:35 -04:00
Josh Patterson
9e94e605ee
Merge pull request #4715 from Security-Onion-Solutions/fix/heavyfix
...
add to HOTFIX file
2021-07-06 16:01:11 -04:00
m0duspwnens
f8dc647b1f
add to HOTFIX file
2021-07-06 15:59:35 -04:00
Josh Patterson
fc727d6909
Merge pull request #4711 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-06 15:56:02 -04:00
m0duspwnens
c1d61dc624
add to HOTFIX file
2021-07-06 15:54:15 -04:00
m0duspwnens
0627ca2fc2
use heavynode hostname for certs if heavynode. changes to logstash pipeline for redis if heavynode
2021-07-06 15:32:39 -04:00
weslambert
ce0b064972
Add conditional for heavynode for redis and elasticsearch
2021-07-06 14:21:29 -04:00
weslambert
2f3f04e4ca
Change from nodename to host
2021-07-06 14:18:39 -04:00
weslambert
2e91f27336
Add conditional for heavynode
2021-07-06 14:17:49 -04:00
weslambert
10b1829830
Add conditional for heavynode
2021-07-06 14:16:34 -04:00
weslambert
4946f32d88
Add extra_hosts entry for local instance when running as heavy node
2021-07-06 14:14:58 -04:00
m0duspwnens
dc1363aaf5
create file for telegraf to read node config details
2021-07-06 13:06:03 -04:00
m0duspwnens
a5067718d2
comma control
2021-07-06 11:06:35 -04:00
m0duspwnens
98505a9a3f
beginning of managing individual panels in grafana
2021-07-06 10:08:36 -04:00
Mike Reeves
e054fdb464
Merge pull request #4680 from Security-Onion-Solutions/dev
...
ECSFIX HOTFIX
2021-07-02 11:16:49 -04:00
Mike Reeves
3c8ad18693
Merge pull request #4683 from Security-Onion-Solutions/2.3.60ecs
...
2.3.60 ECSFIX
2021-07-02 11:05:17 -04:00
Mike Reeves
0a91f571c1
2.3.60 ECSFIX
2021-07-02 10:41:15 -04:00
Mike Reeves
8db5284f6e
Merge pull request #4679 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update telegraf.conf
2021-07-02 09:48:33 -04:00
Mike Reeves
22aa695508
Update telegraf.conf
2021-07-02 09:47:31 -04:00
m0duspwnens
a16f733622
add individual panels
2021-07-02 09:35:04 -04:00
Mike Reeves
af7d6c8cb5
Merge pull request #4678 from Security-Onion-Solutions/ecsfix1
...
ECS Hotfix
2021-07-02 09:14:42 -04:00
Mike Reeves
693f455862
ECS hotfix
2021-07-02 08:55:49 -04:00
Mike Reeves
b0abd290a9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-02 08:47:02 -04:00
Mike Reeves
0a9686f584
Merge pull request #4669 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
2.3.70
2021-07-01 14:39:01 -04:00
Mike Reeves
0b11bf6266
Update VERSION
2021-07-01 14:37:56 -04:00
Mike Reeves
d26056d272
Merge pull request #4655 from Security-Onion-Solutions/dev
...
2.3.60
2021-07-01 14:31:04 -04:00
Mike Reeves
724f9ec76f
Merge pull request #4667 from Security-Onion-Solutions/2.3.60v2
...
2.3.60
2021-07-01 13:11:10 -04:00
Mike Reeves
d583c79936
2.3.60
2021-07-01 13:09:09 -04:00
Mike Reeves
73b47716bc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-01 13:00:30 -04:00
Josh Patterson
4eaef94454
Merge pull request #4664 from Security-Onion-Solutions/influx_scripts
...
so-influxdb-downsample script improvements
2021-07-01 10:28:21 -04:00
m0duspwnens
21c9c7b8f4
only render main script if a manager type node
2021-07-01 07:56:45 -04:00
m0duspwnens
108fb12612
s/Migrating/Downsampling
2021-06-30 17:53:09 -04:00
m0duspwnens
eb8a030966
reset vars in jinja loop
2021-06-30 17:41:38 -04:00
m0duspwnens
9235bb35a1
fix jinja whatspace and add defaults
2021-06-30 17:30:33 -04:00
m0duspwnens
7b281abf0c
migrate script now goes through each day and measurement
2021-06-30 17:21:18 -04:00
Mike Reeves
b5fecd30cf
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 17:05:17 -04:00
Mike Reeves
26ff50f85c
Merge pull request #4659 from Security-Onion-Solutions/kilo
2021-06-30 16:34:16 -04:00
Mike Reeves
2eb1ba565f
Merge pull request #4658 from Security-Onion-Solutions/fix/so-docker-prune
2021-06-30 16:34:05 -04:00
William Wernert
4dbb869952
Fix typo
2021-06-30 16:21:09 -04:00
Jason Ertel
f3041a8d7e
Ensure all curl's to Kibana are properly sessioned and/or authenticated depending on elastic auth toggle
2021-06-30 16:09:08 -04:00
William Wernert
4109cdec53
Refactor so-docker-prune to prevent exceptions when removing images
...
* Prune containers at beginning of script so stopped containers using old images are removed
* Add force=True arg to remove() call to ensure an image is still deleted on the off chance a container is still using that image
* Add exception handling to continue removing containers instead of exiting if the script fails to remove a container
2021-06-30 15:35:01 -04:00
Josh Patterson
cdced887d1
Merge pull request #4654 from Security-Onion-Solutions/2.3.60
...
2.3.60
2021-06-30 12:40:00 -04:00
Mike Reeves
77ca922f62
2.3.60
2021-06-30 12:37:30 -04:00
Mike Reeves
a08166f27d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 11:38:15 -04:00
Mike Reeves
b9c56d1885
Merge pull request #4647 from Security-Onion-Solutions/fb-module-template
2021-06-30 09:38:20 -04:00
weslambert
fcbacd473d
Add ELK, redis
2021-06-30 09:34:56 -04:00
weslambert
06d77d9972
Update so-common-template.json
2021-06-30 09:31:32 -04:00
Mike Reeves
ee9c4f130e
Merge pull request #4646 from Security-Onion-Solutions/influx_scripts
2021-06-30 08:58:33 -04:00
m0duspwnens
ada729087d
add script to drop autogen, rename so-influxdb-migrate to so-influxdb-downsample
2021-06-30 08:14:52 -04:00
m0duspwnens
aa47a72656
source common to require root
2021-06-30 07:25:51 -04:00
Jason Ertel
857ec70abb
Merge pull request #4639 from Security-Onion-Solutions/issue/4609
...
grafana dashboards with trends
2021-06-29 22:23:31 -04:00
m0duspwnens
149f837223
Merge remote-tracking branch 'remotes/origin/dev' into issue/4609
2021-06-29 22:20:28 -04:00
m0duspwnens
37d6529ae0
fix load panel for manager graf
2021-06-29 22:18:17 -04:00
m0duspwnens
8d3ae65e04
fix load graf standalone
2021-06-29 22:13:51 -04:00
m0duspwnens
649e539ca6
add trends to sensor dash
2021-06-29 22:08:29 -04:00
m0duspwnens
45e90750a0
add trends for searchnode grafs
2021-06-29 21:37:20 -04:00
Mike Reeves
ce2a8917a6
Merge pull request #4635 from Security-Onion-Solutions/kilo
2021-06-29 21:21:55 -04:00
m0duspwnens
b22cd2d27c
managersearch dash with trends
2021-06-29 21:07:02 -04:00
m0duspwnens
813ef7d81a
new eval dashboard with trends
2021-06-29 20:23:27 -04:00
m0duspwnens
88275cd968
remove trend zeek capture loss, turn on line and points for capture loss standalone graf
2021-06-29 19:50:53 -04:00
m0duspwnens
3a47563b27
remove queries manager dashboard
2021-06-29 19:26:40 -04:00
m0duspwnens
ebb45a866b
remove queries from standalone dashboard
2021-06-29 19:20:29 -04:00
Mike Reeves
1433822437
Merge pull request #4637 from Security-Onion-Solutions/influxdb_cqs
...
Influxdb cqs - fix the query groupby
2021-06-29 19:08:56 -04:00
m0duspwnens
4a5b416a0b
Merge remote-tracking branch 'remotes/origin/influxdb_cqs' into issue/4609
2021-06-29 18:55:38 -04:00
Jason Ertel
cad4efdded
Fixed PCAP files are readable by root only, which prevents Suricata from being able to scan the file during import
2021-06-29 17:51:04 -04:00
m0duspwnens
f73a8d4d80
Merge remote-tracking branch 'remotes/origin/dev' into influxdb_cqs
2021-06-29 17:15:14 -04:00
m0duspwnens
dac19d224f
update cq
2021-06-29 17:15:00 -04:00
m0duspwnens
fa3e5eebe2
update manager dashboard
2021-06-29 15:11:31 -04:00
Jason Ertel
b64749c9d7
Merge pull request #4630 from Security-Onion-Solutions/dougburks-patch-1
...
Move salt lines after shebang
2021-06-29 13:33:00 -04:00
Doug Burks
822165f168
Move salt lines after shebang
2021-06-29 13:32:02 -04:00
m0duspwnens
2d16463fc6
Merge remote-tracking branch 'remotes/origin/dev' into issue/4609
2021-06-29 12:05:12 -04:00
m0duspwnens
3d8cbe9427
add trend lines
2021-06-29 11:22:14 -04:00
m0duspwnens
f18b64faaf
new standalone dashboard
2021-06-29 11:11:23 -04:00
Jason Ertel
95c7a7e9de
Merge pull request #4629 from Security-Onion-Solutions/influxdb_cqs
...
Influxdb cqs
2021-06-29 10:01:07 -04:00
m0duspwnens
ca152ab04c
redefine measurements
2021-06-29 09:54:17 -04:00
m0duspwnens
bf8bba7b84
only set measurements if conditions are met
2021-06-29 08:57:51 -04:00
m0duspwnens
3f2f699449
Merge remote-tracking branch 'remotes/origin/dev' into influxdb_cqs
2021-06-29 07:46:42 -04:00
m0duspwnens
6b68a39cbe
handle senario where there are no measurements
2021-06-29 07:46:25 -04:00
Jason Ertel
8867840215
Merge pull request #4628 from Security-Onion-Solutions/influxdb_cqs
...
Influxdb cqs
2021-06-28 17:10:27 -04:00
m0duspwnens
1c516daa96
fix measurement list
2021-06-28 17:05:32 -04:00
m0duspwnens
21c9388ee6
generate measurement list and cq for each
2021-06-28 16:12:36 -04:00
m0duspwnens
c72146587a
standalone dashboard
2021-06-28 16:07:32 -04:00
m0duspwnens
0ba685d0e2
change time filter
2021-06-28 12:36:06 -04:00
m0duspwnens
ce98f46331
update standalone dashboard for new influx
2021-06-28 08:49:02 -04:00
m0duspwnens
d6aa672556
updating standalone dashboard
2021-06-25 17:30:25 -04:00
Jason Ertel
6d2761b155
Merge pull request #4625 from Security-Onion-Solutions/foxtrot
...
Add Elasticsearch and Kibana to list of services that use webuser creds
2021-06-25 15:58:56 -04:00
Doug Burks
127afe1582
Merge pull request #4624 from Security-Onion-Solutions/fix/soup-grammar
...
fix soup grammar
2021-06-25 11:19:22 -04:00
doug
a3d7f4e35d
fix grammar
2021-06-25 11:16:26 -04:00
Mike Reeves
8eb163532d
Merge pull request #4620 from Security-Onion-Solutions/modulefix
...
Fix filebeat modules
2021-06-24 15:59:16 -04:00
Mike Reeves
ea50023ca5
Fix filebeat modules
2021-06-24 15:53:14 -04:00
Mike Reeves
846aef1bd6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-24 14:54:51 -04:00
Mike Reeves
143f2eb1a8
Merge pull request #4616 from Security-Onion-Solutions/airsoup
...
remove some debug statements
2021-06-24 13:31:17 -04:00
Mike Reeves
3f8cb23cf6
remove some debug statements
2021-06-24 13:29:16 -04:00
Mike Reeves
f92709b03b
Merge pull request #4614 from Security-Onion-Solutions/airsoup
...
Airsoup
2021-06-24 11:37:16 -04:00
Mike Reeves
81bb7c6534
remove a net check
2021-06-24 11:32:01 -04:00
Mike Reeves
bdd1074be7
remove a net check
2021-06-24 11:24:12 -04:00
Mike Reeves
42a63f8ea5
remove a net check
2021-06-24 11:15:16 -04:00
Mike Reeves
3c85db1769
Fix regression
2021-06-24 11:04:56 -04:00
Mike Reeves
930d5b3627
Revert "Move up script verification"
...
This reverts commit 66e88cef42 .
2021-06-24 10:52:53 -04:00
Mike Reeves
a1ec40b547
Revert "Move up script verification"
...
This reverts commit 2681903c93 .
2021-06-24 10:52:27 -04:00
William Wernert
022f9ea76e
Add Elasticsearch and Kibana to list of services that use webuser creds
2021-06-24 10:45:12 -04:00
Mike Reeves
2681903c93
Move up script verification
2021-06-24 10:24:00 -04:00
Jason Ertel
403d10cc75
Merge pull request #4611 from Security-Onion-Solutions/airsoup
...
Move up script verification
2021-06-24 10:05:05 -04:00
Mike Reeves
66e88cef42
Move up script verification
2021-06-24 10:03:38 -04:00
Jason Ertel
8f9d1b99e2
Merge pull request #4610 from Security-Onion-Solutions/airsoup
...
Fix airgap check
2021-06-24 09:51:47 -04:00
Mike Reeves
4af2f6d84a
Fix airgap check
2021-06-24 09:49:57 -04:00
Mike Reeves
78fa4feac6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-23 15:38:38 -04:00
Jason Ertel
5189f38766
Merge pull request #4601 from Security-Onion-Solutions/kilo
...
Elastic auth related adjustments; Soup error handling corrections, ES pipeline load improvements
2021-06-23 14:46:05 -04:00
Jason Ertel
243e888717
Add queue=True -- needed for all salt commands, not just state changes
2021-06-23 14:41:38 -04:00
weslambert
c5b81f2f4b
Fix output so that it can be redirected to local file with appropriate syntax
2021-06-23 14:41:38 -04:00
Mike Reeves
caa14e0cad
Fix Retry Spam
2021-06-23 14:41:38 -04:00
weslambert
d411a9e1ff
Merge pull request #4597 from Security-Onion-Solutions/fix/pipeline-view-output
...
Fix output so that it can be redirected to local file with appropriat…
2021-06-23 09:24:41 -04:00
weslambert
3fbc850774
Fix output so that it can be redirected to local file with appropriate syntax
2021-06-23 09:17:37 -04:00
Jason Ertel
d16febcae1
Merge pull request #4591 from Security-Onion-Solutions/kilo
...
Require either true | false in parameter to so-elastic-auth and ensur…
2021-06-22 15:31:48 -04:00
Jason Ertel
26bb6cc011
Require either true | false in parameter to so-elastic-auth and ensure all minions are fully updated with the new auth setting
2021-06-22 15:29:48 -04:00
Jason Ertel
bc80ef9a80
Merge pull request #4590 from Security-Onion-Solutions/kilo
...
only attempt to upgrade salt on minions if the minion count it > 1
2021-06-22 11:36:37 -04:00
m0duspwnens
9fad0876c5
only attempt to upgrade salt on minions if the minion count it > 1
2021-06-22 11:31:31 -04:00
Jason Ertel
914e635b4a
Merge pull request #4589 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Retry Spam
2021-06-22 10:15:39 -04:00
Mike Reeves
85bb234cf9
Fix Retry Spam
2021-06-22 10:14:33 -04:00
Mike Reeves
f7675a5dea
Merge pull request #4588 from Security-Onion-Solutions/souperduper
...
let the first highstate pass
2021-06-22 09:58:00 -04:00
Josh Patterson
7b662055dd
Merge pull request #4587 from Security-Onion-Solutions/kilo
...
fix timeout for docker_container.running for so-dockerregistry
2021-06-22 09:56:24 -04:00
m0duspwnens
d78c6f1a74
Merge branch 'kilo' of https://github.com/Security-Onion-Solutions/securityonion into kilo
2021-06-22 09:54:35 -04:00
m0duspwnens
9fa83d1cee
change to client_timeout
2021-06-22 09:54:25 -04:00
Mike Reeves
6e780164ea
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-22 09:52:44 -04:00
Jason Ertel
2ca8da0710
Merge pull request #4585 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-22 08:38:39 -04:00
Jason Ertel
c3deabae36
Update init.sls
2021-06-22 08:30:54 -04:00
m0duspwnens
9cdbcb72ac
Merge branch 'kilo' of https://github.com/Security-Onion-Solutions/securityonion into kilo
2021-06-22 08:23:26 -04:00
m0duspwnens
bc86590411
only add sosyncuser cron if startup_states: highstate is set in minion config
2021-06-22 08:23:16 -04:00
Jason Ertel
cb167f3d74
Merge pull request #4584 from Security-Onion-Solutions/kilo
...
retry on so-dockerregistry
2021-06-22 08:08:28 -04:00
Jason Ertel
8ddc99e91f
Allow for adjusting SOC session timeout
2021-06-22 08:07:52 -04:00
Jason Ertel
dcc9af946a
Avoid logging when sync is unnecessary due to cronjob log output spam
2021-06-22 08:07:52 -04:00
m0duspwnens
e4e3b199fc
retry on so-dockerregistry
2021-06-22 08:05:08 -04:00
Josh Patterson
bf61c82cf2
Merge pull request #4581 from Security-Onion-Solutions/kilo
...
adding elasticsearch.auth to heavynode and searchnode
2021-06-21 14:48:32 -04:00
m0duspwnens
c9ee28ce01
adding elasticsearch.auth to heavynode and searchnode
2021-06-21 14:47:24 -04:00
Jason Ertel
5135beb036
Merge pull request #4579 from Security-Onion-Solutions/kilo
...
Improve user sync algorithm
2021-06-21 12:40:27 -04:00
Jason Ertel
f36ef86ccc
Improve algorithm for determining if a user sync is necessary; Apply salt state in foreground to avoid collisions with setup salt states.
2021-06-21 12:38:02 -04:00
Jason Ertel
5e042bf4b8
Improve algorithm for determining if a user sync is necessary; Apply salt state in foreground to avoid collisions with setup salt states.
2021-06-21 12:16:47 -04:00
Josh Brower
130ce34686
Merge pull request #4578 from Security-Onion-Solutions/fix/esAlerter
...
esalerter ES creds fix
2021-06-21 11:08:59 -04:00
Josh Brower
591ef540a6
esalerter ES creds fix
2021-06-21 10:50:09 -04:00
Josh Patterson
697f6ab538
Merge pull request #4577 from Security-Onion-Solutions/issue/1333
...
remove the salt-minion check for schedules
2021-06-21 09:05:18 -04:00
m0duspwnens
ba5b5db2c4
remove the salt-minion check for schedules
2021-06-21 08:56:24 -04:00
Jason Ertel
e7afbab6a1
Merge pull request #4576 from Security-Onion-Solutions/kilo
...
Fix intermittent 'like' failures; Ensure bash is on first line of loa…
2021-06-21 07:09:10 -04:00
Jason Ertel
5298cb8cfb
Update copyrights
2021-06-21 07:06:49 -04:00
Jason Ertel
777bece2eb
Fix intermittent 'like' failures; Ensure bash is on first line of load templates script
2021-06-20 22:14:13 -04:00
Mike Reeves
7daad1a52a
Merge pull request #4571 from Security-Onion-Solutions/kilo
...
Ensure htpasswd exists earlier in the install process
2021-06-18 21:45:29 -04:00
Jason Ertel
60fd3c6bd3
Ensure htpasswd exists earlier in the install process
2021-06-18 20:01:32 -04:00
Josh Patterson
dc1c82f347
Merge pull request #4567 from Security-Onion-Solutions/issue/1333
...
Issue/1333
2021-06-18 16:12:42 -04:00
m0duspwnens
c7a58816b6
move condition to avoid wrong notic about schedule not set in pillar
2021-06-18 15:30:51 -04:00
m0duspwnens
48c3cb4816
if the salt-minion service isnt running when the state is rendered, dont try to apply schedule - https://github.com/Security-Onion-Solutions/securityonion/issues/1333
2021-06-18 14:56:01 -04:00
Jason Ertel
6e7f2107cb
Merge pull request #4566 from Security-Onion-Solutions/kilo
...
Remove unused mode
2021-06-18 14:45:02 -04:00
Jason Ertel
101b835cf6
Remove unused mode
2021-06-18 14:34:42 -04:00
Jason Ertel
558a90aaf8
Merge pull request #4563 from Security-Onion-Solutions/kilo
...
Disable HaveIBeenPwned API (pwnedpasswords.com)
2021-06-18 08:41:23 -04:00
Jason Ertel
1d4161ba31
Disable HaveIBeenPwned API (pwnedpasswords.com)
2021-06-18 08:36:36 -04:00
Mike Reeves
78d53af27c
Merge pull request #4562 from Security-Onion-Solutions/kilo
...
Fix wrong grep file
2021-06-17 21:19:05 -04:00
Jason Ertel
188b4424e4
Fix wrong grep file
2021-06-17 21:00:56 -04:00
Mike Reeves
0615d635eb
let the first highstate pass
2021-06-17 16:12:39 -04:00
Mike Reeves
85d7e75fb1
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 16:09:11 -04:00
Jason Ertel
833559dde6
Merge pull request #4559 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-17 15:55:28 -04:00
Jason Ertel
b294cee278
Remove passwords from soctopus templates since these are the basis for elastalert rules, which will use the user/pass at the elastalert global config level
2021-06-17 15:53:07 -04:00
Jason Ertel
afe7ddb480
Remove passwords from soctopus templates since these are the basis for elastalert rules, which will use the user/pass at the elastalert global config level
2021-06-17 15:51:53 -04:00
Jason Ertel
98526af82a
Merge pull request #4558 from Security-Onion-Solutions/kilo
...
Lock so-user to avoid two processes from overwriting eachother
2021-06-17 15:23:42 -04:00
Jason Ertel
0cb4562254
Lock so-user to avoid two processes from overwriting eachother
2021-06-17 15:19:39 -04:00
Josh Patterson
70f0ee719c
Merge pull request #4557 from Security-Onion-Solutions/fix_soup_elasticcurl
...
Fix soup elasticcurl
2021-06-17 15:02:27 -04:00
m0duspwnens
63b120e9e2
use just curl for elastic in soup
2021-06-17 14:56:05 -04:00
m0duspwnens
d587120613
set ELASTICCUURL default as curl
2021-06-17 14:42:04 -04:00
Mike Reeves
0dc4bc3cee
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 13:30:58 -04:00
Josh Patterson
79aad225a4
Merge pull request #4552 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-17 09:38:41 -04:00
m0duspwnens
8cd2bc7c13
adding so-eval to ES_INCLUDED_NODES
2021-06-17 09:37:21 -04:00
m0duspwnens
2a5198cae4
change perms to resolve error about module-setup.yml being 660
2021-06-17 08:49:21 -04:00
Jason Ertel
b8c463db82
Merge pull request #4551 from Security-Onion-Solutions/kilo
...
Fix require statement
2021-06-16 21:49:47 -04:00
Jason Ertel
059b016c62
Fix require statement
2021-06-16 21:48:31 -04:00
Jason Ertel
f1429632d2
Merge pull request #4549 from Security-Onion-Solutions/kilo
...
Elastic auth: Fun with Salt
2021-06-16 17:57:58 -04:00
Jason Ertel
2d34208269
Elastic auth: Fun with Salt
2021-06-16 17:52:22 -04:00
Jason Ertel
36c9054744
Merge pull request #4547 from Security-Onion-Solutions/kilo
...
Kilo
2021-06-16 14:55:27 -04:00
William Wernert
5e11efb0b9
Merge pull request #4548 from Security-Onion-Solutions/fix/soup-merge-fix
...
Fix merge issue in soup
2021-06-16 14:36:24 -04:00
William Wernert
703988b376
Fix merge issue in soup
2021-06-16 14:28:20 -04:00
Jason Ertel
fefd2677fb
Only include so-common if available. It only is used for requiring root, but since this script is needed before common is installed, we can safely assume that it's being run as root already (during the install)
2021-06-16 14:26:26 -04:00
Jason Ertel
a323aeb8fa
Allow so-elastic-auth to run before common even though the script has dependency on a common-provided script (benign error). This is needed first since common will need to know if auth is enabled
2021-06-16 14:23:58 -04:00
Mike Reeves
8d6b0e23ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-16 13:23:44 -04:00
Jason Ertel
edac99e5a9
Merge pull request #4546 from Security-Onion-Solutions/kilo
...
Accept either 200 or 401 instead of wasting 3 minutes waiting for thi…
2021-06-16 11:41:23 -04:00
Jason Ertel
dd14235e31
Accept either 200 or 401 instead of wasting 3 minutes waiting for this to timeout
2021-06-16 11:39:21 -04:00
Jason Ertel
15eadd4f89
Merge pull request #4545 from Security-Onion-Solutions/kilo
...
Merge kilo to dev for additional ES Auth changes
2021-06-16 11:04:39 -04:00
Jason Ertel
09fbb045a1
If ES auth disabled ensure user/pass are blank
2021-06-16 09:59:57 -04:00
Josh Patterson
7bdd0d3bf1
Merge pull request #4543 from Security-Onion-Solutions/issue/2977
...
Issue/2977
2021-06-16 08:16:36 -04:00
m0duspwnens
ebea9a7198
remove space
2021-06-16 08:07:28 -04:00
m0duspwnens
ad9441bb60
prevent suricata state from running on manager and managersearch https://github.com/Security-Onion-Solutions/securityonion/issues/2977
2021-06-16 08:06:26 -04:00
Jason Ertel
989f9dce42
Ensure sqlite.db exists before querying it; Execute so-elastic-auth after common state has been applied and redirect output to setup log
2021-06-15 16:57:13 -04:00
Jason Ertel
b95437347e
Upgrade ES to 7.13.2
2021-06-15 12:50:57 -04:00
Jason Ertel
2d27e0d9a9
Merge pull request #4530 from Security-Onion-Solutions/kilo
...
Elastic auth
2021-06-15 11:15:19 -04:00
Jason Ertel
c3c078e5be
Merge pull request #4522 from Security-Onion-Solutions/feature/contributing-md
...
Add CONTRIBUTING.md
2021-06-15 10:25:07 -04:00
Jason Ertel
dd8eb29a18
Continue merge of ECS into Elastic Auth
2021-06-15 09:11:58 -04:00
William Wernert
2d5591a87f
Remove draft label
2021-06-14 16:33:52 -04:00
William Wernert
71b079eb54
Add bullet detailing linking pull request to issue
2021-06-14 16:04:22 -04:00
William Wernert
ca6f3807fc
Don't use idioms, and remove TBD lines
2021-06-14 15:58:21 -04:00
Doug Burks
c2f6a6983d
Merge pull request #4521 from Security-Onion-Solutions/feature/security-md
...
Create SECURITY.md
2021-06-14 15:51:55 -04:00
Jason Ertel
3891ca2929
Use correct mode param to file.recurse
2021-06-14 15:46:25 -04:00
Doug Burks
20437ef2c7
Create SECURITY.md
2021-06-14 15:42:18 -04:00
William Wernert
7de02d541f
Increase width of verified commit screenshot
2021-06-14 15:28:44 -04:00
William Wernert
68e4c5e469
Add CONTRIBUTING.md draft, move markdown images to assets/images
2021-06-14 15:21:46 -04:00
Jason Ertel
62187807f0
Specify elastic creds for playbook alert templates
2021-06-14 14:08:14 -04:00
Jason Ertel
37f4caf536
Make new ECS changes Elastic-auth compatible
2021-06-14 12:13:50 -04:00
Jason Ertel
fca1c6e957
Merge branch 'dev' into kilo
2021-06-14 10:40:04 -04:00
Josh Patterson
0de7e71fa0
Merge pull request #4517 from Security-Onion-Solutions/fix/filebeat
...
update roles that include es state
2021-06-14 10:02:50 -04:00
m0duspwnens
fd5d540c78
update roles that include es state
2021-06-14 10:00:19 -04:00
m0duspwnens
d2069dc5f2
update roles that include es state
2021-06-14 09:58:50 -04:00
Mike Reeves
2ac832678f
Merge pull request #4513 from Security-Onion-Solutions/fix/filebeat
...
fix two bugs
2021-06-14 08:53:13 -04:00
m0duspwnens
5941332d49
fix two bugs
2021-06-14 08:51:29 -04:00
Josh Patterson
45732bd87a
Merge pull request #4494 from Security-Onion-Solutions/fix_module_config_jinja
...
dont loop if modules arent defined for the node
2021-06-11 13:54:15 -04:00
m0duspwnens
f7600af89b
dont loop if modules arent defined for the node
2021-06-11 13:52:33 -04:00
Josh Patterson
5108121b59
Merge pull request #4489 from Security-Onion-Solutions/hotfix/soup_salt
...
Hotfix/soup salt
2021-06-10 16:04:27 -04:00
Josh Patterson
c2339c84e7
Merge branch 'dev' into hotfix/soup_salt
2021-06-10 15:48:00 -04:00
Jason Ertel
7205c5cb7b
Provide timestamp as arg to SOC PCAP pivots
2021-06-10 15:21:03 -04:00
m0duspwnens
ff807c9a6f
empty hotfix file for merge into dev
2021-06-10 14:06:24 -04:00
Mike Reeves
0341eb5d8f
Merge pull request #4479 from Security-Onion-Solutions/hotfix/soup_salt
...
Hotfix/soup salt
2021-06-10 13:44:10 -04:00
Mike Reeves
a2e1b1de3a
Merge pull request #4484 from Security-Onion-Solutions/pipeline
...
Pipeline
2021-06-10 13:41:14 -04:00
m0duspwnens
e64059bd7b
remove unneeded function
2021-06-10 09:31:10 -04:00
m0duspwnens
46b1de97f5
change function name
2021-06-10 09:30:03 -04:00
Mike Reeves
ca7d2c6d64
Merge branch 'pipeline' of https://github.com/Security-Onion-Solutions/securityonion into pipeline
2021-06-10 09:20:38 -04:00
Mike Reeves
12d4d4a4f7
Dynamix Pipelines take 2
2021-06-10 09:19:15 -04:00
m0duspwnens
7c92054f13
soup hotfix to updating repos for earlier versions of SO so salt will isntall
2021-06-10 09:13:15 -04:00
weslambert
1bef1d5652
Update to apply to any so-prefixed index
2021-06-10 08:16:00 -04:00
Jason Ertel
89a02383b8
Correct cronjob path issue for sysctl; suppress diff outputs from users/roles files; suppress salt state output during user sync
2021-06-09 16:31:32 -04:00
Mike Reeves
7fba904f75
Dynamix Pipelines take 1
2021-06-09 15:32:39 -04:00
Mike Reeves
1c7741fdbe
Add templates for SO logs
2021-06-09 12:38:19 -04:00
Mike Reeves
4c90a0ed7e
Add templates for SO logs
2021-06-09 12:04:32 -04:00
m0duspwnens
a82b174826
perform the repo changes for any upgrade
2021-06-09 11:53:10 -04:00
Mike Reeves
579ff8c0b4
Add verbosity to checkin
2021-06-09 11:40:17 -04:00
Mike Reeves
264080546c
Add log path
2021-06-09 11:37:27 -04:00
Jason Ertel
a0c65e2333
Ensure elastic minions also update their auth files
2021-06-09 09:38:50 -04:00
Jason Ertel
dd73ad544c
Rename PATH var to avoid collision with OS PATH var; wrapped password var in quotes to support spaces in Fleet/TheHive passwords
2021-06-09 09:06:29 -04:00
Mike Reeves
33db9023eb
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:50:39 -04:00
Mike Reeves
88eea03f97
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:36:50 -04:00
Mike Reeves
a959ec1eb1
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:23:31 -04:00
Mike Reeves
3e138cbc6d
Revert to SO taxonomy for zeek and suricata
2021-06-08 13:14:46 -04:00
Jason Ertel
9b61723194
Merge branch 'dev' into kilo
2021-06-08 11:04:09 -04:00
Jason Ertel
d2381b0209
Ensure empty/aborted users/roles files do not get copied onto final filenames
2021-06-08 11:03:56 -04:00
Mike Reeves
4972f69dd6
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-06-08 11:03:14 -04:00
Mike Reeves
56eb220ed6
Revert to SO taxonomy for zeek and suricata
2021-06-08 09:52:05 -04:00
Jason Ertel
343c47d67a
Add so-elasticsearch-query tool
2021-06-07 17:26:07 -04:00
Jason Ertel
e53f2217ec
Add so-elasticsearch-query tool
2021-06-07 17:24:22 -04:00
Mike Reeves
016a5a5914
Merge pull request #4432 from Security-Onion-Solutions/merge_2.3.52
...
Merge 2.3.52
2021-06-07 14:10:16 -04:00
William Wernert
9f2adfb67a
Merge branch 'master' into merge_2.3.52
...
# Conflicts:
# VERSION
2021-06-07 14:08:17 -04:00
Jason Ertel
14aa9805b4
Stop failing an install because salt is already running when a highstate is applied at 95%
2021-06-06 18:20:57 -04:00
Jason Ertel
fdab17a3b9
Due to dir ownership restrictions need to run crossthestreams and eval as root
2021-06-06 16:36:35 -04:00
Jason Ertel
bebba7d280
Switch ownership of curl config to socore
2021-06-06 07:43:53 -04:00
Jason Ertel
11b2b2a893
Switch ownership of curl config to socore
2021-06-06 05:42:34 -04:00
Jason Ertel
84141082ab
Avoid applying state when adding web user
2021-06-05 08:41:48 -04:00
Jason Ertel
ba29b5e036
Do not apply salt state if already applying a state
2021-06-04 21:56:41 -04:00
Jason Ertel
e22421ec99
Refactor users/roles management via salt due to Salt's clobbering of the inode which breaks Docker mounts
2021-06-04 20:01:30 -04:00
Jason Ertel
416b38fc71
Use cronjob to ensure user synchronization
2021-06-04 11:24:58 -04:00
William Wernert
fd5fcfeaae
Merge pull request #4402 from Security-Onion-Solutions/foxtrot
...
Use variable for whiptail title and make sure all menus in setup have the same title
2021-06-04 11:10:01 -04:00
Jason Ertel
316035910f
Remove inotify beacon due to it not functioning as documented; Add back so-user changes to sync upon so-user changes
2021-06-03 15:15:35 -04:00
William Wernert
d1d09d4aab
Remove useless variable assignment
2021-06-03 14:20:52 -04:00
William Wernert
3aff3ac7e4
Change logic to check for unmanaged nics
...
Resolves issue mentioned in #4327
2021-06-03 11:00:20 -04:00
William Wernert
d1a185aaae
Further standardize whiptail titles
2021-06-03 10:59:14 -04:00
William Wernert
bb5b805983
Merge branch 'fix/missing-version-string' into foxtrot
2021-06-03 10:45:02 -04:00
Jason Ertel
58ae3479dc
Fix mispelled db filename; ensure ELASTICCURL is used for loading config objects
2021-06-03 10:11:10 -04:00
William Wernert
d55e007032
Merge pull request #4386 from Security-Onion-Solutions/foxtrot
...
Update wording for iso location prompt in soup
2021-06-03 09:55:15 -04:00
Jason Ertel
2af43d62eb
Wrap curl param in quotes for function call
2021-06-03 08:53:59 -04:00
Jason Ertel
5c527b2c48
Rename username param to user since logstash is 'unique'
2021-06-03 07:51:43 -04:00
Jason Ertel
e6165f0046
Update kibana config load for auth changes
2021-06-03 07:47:32 -04:00
Jason Ertel
70427bc676
Merge branch 'dev' into kilo
2021-06-03 07:41:35 -04:00
Mike Reeves
9ec7cbef8e
Merge pull request #4391 from Security-Onion-Solutions/es-7.13.1
...
Es 7.13.1 saved objects update
2021-06-02 20:23:40 -04:00
Jason Ertel
719d841353
Update saved objects
2021-06-02 20:15:03 -04:00
Jason Ertel
fa6af06204
Avoid running highstate during setup when flipping auth flag
2021-06-02 17:13:59 -04:00
weslambert
cba719b3a0
Remove extra comma
2021-06-02 16:42:09 -04:00
weslambert
4241bb08b8
Add suricata/zeek until we migrate templates
2021-06-02 16:37:43 -04:00
Jason Ertel
901242f7e9
remove extra parenthesis
2021-06-02 16:23:45 -04:00
weslambert
4c74e7f308
Add event.kind and set name to module[dot]dataset
2021-06-02 15:35:26 -04:00
weslambert
db48c15f1d
Create event.kind field and rename dataset to be module[dot]dataset
2021-06-02 15:33:18 -04:00
weslambert
a1b34e7a88
Fix Suricata index name
2021-06-02 15:30:14 -04:00
Jason Ertel
fc6b3726a4
Fix missing colon for mode
2021-06-02 15:23:16 -04:00
Mike Reeves
9c9bcac61b
Update DNS queries
2021-06-02 15:01:14 -04:00
Jason Ertel
588da4d7dc
Resolve salt pillar/state/jinja race condition
2021-06-02 14:34:21 -04:00
Mike Reeves
e42db3cd2d
Fix some hunt queries
2021-06-02 14:05:02 -04:00
Mike Reeves
e8cc88174f
Fix some hunt queries
2021-06-02 13:55:05 -04:00
Mike Reeves
7b7111e12c
Fix some hunt queries
2021-06-02 13:53:39 -04:00
William Wernert
b3f2c60065
Whiptail title fixes
...
- Use a variable for the title
- Fix cases where the whiptail title wasn't changed previously
2021-06-02 12:38:32 -04:00
Jason Ertel
20e896cacf
Update all configs to pass user/pass to ES
2021-06-02 12:17:15 -04:00
William Wernert
afbf7de9e3
Remove empty lines in iso location prompt
2021-06-02 11:05:43 -04:00
Jason Ertel
4ff85ab0c4
Merge branch 'dev' into kilo
2021-06-02 10:39:51 -04:00
Jason Ertel
dd7388e577
Merge pull request #4382 from Security-Onion-Solutions/jertel/timeouts
...
Increase SOC API timeouts and ES timeout from 2m to 5m
2021-06-02 10:28:36 -04:00
Mike Reeves
77f13961ad
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-06-02 10:12:17 -04:00
Mike Reeves
e00fe0a732
Enable for all modes
2021-06-02 10:02:11 -04:00
Jason Ertel
c757d21360
Increase default SOC API and ES timeouts from 2m to 5m
2021-06-02 09:38:59 -04:00
Jason Ertel
3a134cc706
fix merge conflicts
2021-06-02 09:16:28 -04:00
Jason Ertel
7aede4d058
Persist chown/chmod settings on users/roles files
2021-06-02 09:01:16 -04:00
Mike Reeves
5983eae3a8
fix filebeat module syntax
2021-06-01 17:47:13 -04:00
Josh Patterson
9d6dca9c64
Merge pull request #4372 from Security-Onion-Solutions/pipeline_userpass
...
fix typo
2021-06-01 17:46:41 -04:00
m0duspwnens
7b68c1bc9b
fix typo
2021-06-01 17:45:52 -04:00
Josh Patterson
9d905368ca
Merge pull request #4371 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-06-01 17:01:51 -04:00
m0duspwnens
867613669d
changes for syncing users
2021-06-01 17:01:03 -04:00
Mike Reeves
fd1de624c8
Disable TTY for filebeat script
2021-06-01 14:50:21 -04:00
Jason Ertel
2a2247e1da
Additional so-user sync adjustments
2021-06-01 14:45:01 -04:00
Jason Ertel
7a59bee315
Add so-elastic-auth script
2021-06-01 12:48:53 -04:00
Mike Reeves
73a0b31380
elastic pipeline enable
2021-06-01 12:12:20 -04:00
m0duspwnens
ef00695b07
fix typo
2021-06-01 11:31:50 -04:00
m0duspwnens
bfaffbc87e
add reactor and beacon for sqlite db
2021-06-01 11:15:28 -04:00
William Wernert
e800d62df4
Merge branch 'dev' into fix/update-iso-soup-wording
2021-06-01 11:12:17 -04:00
Josh Patterson
6fe765434e
Merge pull request #4362 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-06-01 10:56:29 -04:00
m0duspwnens
7e48740ea7
fix merge conflict
2021-06-01 10:56:02 -04:00
m0duspwnens
d25a439bd4
more changes
2021-06-01 10:53:58 -04:00
Jason Ertel
ed8c85df2b
Only sync web users if teh sqlite db exists
2021-06-01 10:26:33 -04:00
Josh Patterson
c4ae8c3418
Merge pull request #4359 from Security-Onion-Solutions/pipeline_userpass
...
generate pillar file if auth enabled or not
2021-06-01 09:38:34 -04:00
m0duspwnens
f87dce8ec1
generate pillar file if auth enabled or not
2021-06-01 09:38:07 -04:00
Josh Patterson
5d2f1c8e11
Merge pull request #4357 from Security-Onion-Solutions/pipeline_userpass
...
fix logic
2021-06-01 08:36:48 -04:00
m0duspwnens
1aa2852ed6
fix logic
2021-06-01 08:35:43 -04:00
Jason Ertel
a42a406f53
Remove extra users file mounts; disable elastic anon access when auth enabled
2021-05-29 07:52:08 -04:00
Jason Ertel
47b56e78b3
Fix missing endif
2021-05-28 20:07:51 -04:00
Josh Patterson
52db7b32ef
Merge pull request #4335 from Security-Onion-Solutions/pipeline_userpass
...
fix logic on password created in pillar and fix how me manage
2021-05-28 18:29:59 -04:00
m0duspwnens
3aad5a30e9
fix logic on password created in pillar and fix how me manage
2021-05-28 18:28:53 -04:00
Jason Ertel
b8a10f2e86
Support multiple elastic system users
2021-05-28 15:59:51 -04:00
Josh Patterson
4e8dc0e3b9
Merge pull request #4334 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-05-28 15:29:07 -04:00
m0duspwnens
edf60f80f7
manager and common states now require elasticsearch.auth state
2021-05-28 15:26:26 -04:00
William Wernert
a94c598d00
Merge pull request #4333 from Security-Onion-Solutions/feature/show-version-in-setup
...
Show version in setup
2021-05-28 15:15:43 -04:00
m0duspwnens
68abaa5e3c
update auth.map and curl.config to use new elasticsearch:auth pillar format
2021-05-28 14:03:21 -04:00
m0duspwnens
63b31de2b8
add additional users - manage file if user name isnt returned from grepping the file
2021-05-28 13:58:03 -04:00
Josh Patterson
35845440c6
Merge pull request #4330 from Security-Onion-Solutions/pipeline_userpass
...
remove unneeded curl.config template
2021-05-28 10:38:43 -04:00
m0duspwnens
18926009d3
remove unneeded curl.config template
2021-05-28 10:38:06 -04:00
William Wernert
d55a9e6274
Add version to all whiptail titles
2021-05-28 10:20:19 -04:00
William Wernert
ba011581ef
Add version to ending summary
2021-05-28 10:14:58 -04:00
Jason Ertel
1788ceccea
Merge pull request #4329 from Security-Onion-Solutions/fix/kibana_7.13.0
...
bump Kibana version to 7.13.0
2021-05-28 09:14:18 -04:00
doug
ada8255af0
bump version to 7.13.0
2021-05-28 08:59:40 -04:00
Josh Patterson
f1a6f66d49
Merge pull request #4317 from Security-Onion-Solutions/pipeline_userpass
...
remove vault pg from when i was testing
2021-05-27 13:55:01 -04:00
m0duspwnens
423793ecf9
remove vault pg from testing
2021-05-27 13:50:22 -04:00
Josh Patterson
94cfa3c9d0
Merge pull request #4314 from Security-Onion-Solutions/pipeline_userpass
...
Pipeline userpass
2021-05-27 11:34:34 -04:00
m0duspwnens
0134ceef16
merge and resolve conflict in elasticsearch state
2021-05-27 11:33:44 -04:00
m0duspwnens
b23ce7462e
add depenency
2021-05-27 11:26:25 -04:00
Doug Burks
cf3dda6869
Merge pull request #4300 from j-bernal/patch-1
...
Update so-whiptail
2021-05-27 07:58:16 -04:00
m0duspwnens
dc8520df42
user curl.config for curl and elasticscripts
2021-05-26 18:04:30 -04:00
Jason Ertel
d9c5976ed0
Merge pull request #4304 from Security-Onion-Solutions/feature/1596
...
add menu.actions.json and update soc.json
2021-05-26 16:41:30 -04:00
doug
aeea5701e4
completely disable both alerts.actions.json and hunt.actions.json
2021-05-26 16:34:05 -04:00
m0duspwnens
7263e35a89
happy little comment
2021-05-26 14:52:59 -04:00
m0duspwnens
4d991d3773
propogate users and users_roles
2021-05-26 14:52:10 -04:00
Mike Reeves
bfcde15a24
elastic pipeline test
2021-05-26 14:22:14 -04:00
doug
ee675546ac
add menu.actions.json and update soc.json
2021-05-26 14:09:00 -04:00
Jason Ertel
b43e6c5d6b
Salt will handle auto-sync
2021-05-26 13:51:24 -04:00
Jason Ertel
c531ef0773
Move user sync'd files to saltstack for grid propagation
2021-05-26 13:44:30 -04:00
Jason Ertel
a6a4c03029
Improve error scenarios for user sync; Ensure user sync runs before Elastic container starts
2021-05-26 12:08:10 -04:00
Mike Reeves
b525cfc787
Remove old modules
2021-05-26 11:07:53 -04:00
m0duspwnens
842aa97f7e
load filebeat modules when es container starts and if fb container is running
2021-05-26 11:00:18 -04:00
Mike Reeves
34d4eedf67
Remove old modules
2021-05-26 10:11:47 -04:00
Josh Brower
4a109d6af1
Merge pull request #4299 from Security-Onion-Solutions/feature/so-pcap-pull
...
Feature/so-pcap-export
2021-05-26 09:59:45 -04:00
John Bernal
cb40a76247
Update so-whiptail
...
Updated Zeek capitalization when prompting for the number of processes.
2021-05-26 09:55:14 -04:00
Josh Brower
ed249600d3
Merge remote-tracking branch 'remotes/origin/dev' into feature/so-pcap-pull
2021-05-26 09:52:58 -04:00
Josh Brower
0187c9d6df
Adds so-pcap-export
2021-05-26 09:51:37 -04:00
William Wernert
6da37966d9
Update wording for iso location prompt in soup
2021-05-26 09:32:25 -04:00
m0duspwnens
525d4325c7
define ZEEKLOGLOOKUP in the yaml
2021-05-25 17:18:58 -04:00
m0duspwnens
ecf7e25a51
fix merge conflict
2021-05-25 17:16:44 -04:00
Jason Ertel
ec2f8fe6c8
Synchronize SOC passwords with Elastic
2021-05-25 17:16:05 -04:00
m0duspwnens
dfaf40f583
add zeekloglookup to translate zeeklogs to filebeat filesets
2021-05-25 17:14:26 -04:00
Mike Reeves
543154f037
Remove old modules
2021-05-25 16:58:18 -04:00
Mike Reeves
cd3e355f84
Fix zeek depth
2021-05-25 16:54:20 -04:00
m0duspwnens
2eee6b45bc
Merge branch 'pipeline' of https://github.com/Security-Onion-Solutions/securityonion into pipeline
2021-05-25 16:52:08 -04:00
m0duspwnens
0de5c6f204
fix sodefault modules
2021-05-25 16:52:02 -04:00
Mike Reeves
9363fc153c
Fix pillar for module
2021-05-25 16:44:13 -04:00
m0duspwnens
2aacd5b9b6
so defaults filebeat modules
2021-05-25 16:40:50 -04:00
m0duspwnens
c3b2e1e8b2
dont show changes
2021-05-25 16:16:57 -04:00
m0duspwnens
e261c197f3
add elasticsearch.auth state to statnalone node
2021-05-25 13:46:18 -04:00
m0duspwnens
747dc77c92
comment out the hackery
2021-05-25 13:23:26 -04:00
m0duspwnens
35cc7b27e9
remove extra quote
2021-05-25 13:12:30 -04:00
William Wernert
67828a86c1
Merge pull request #4289 from Security-Onion-Solutions/foxtrot
...
Soup error handling, reorder sensoroni state
2021-05-25 12:42:01 -04:00
m0duspwnens
58ec31d6c7
pass ELASTICAUTH to script
2021-05-25 12:02:41 -04:00
m0duspwnens
6da0b57ce1
fix file.file_exists
2021-05-25 11:55:22 -04:00
m0duspwnens
8d9d5a267a
generate elasticsearch.auth pillar if it doesnt exist
2021-05-25 11:52:58 -04:00
William Wernert
94af55a951
Fix typo
2021-05-25 11:25:37 -04:00
William Wernert
192cec1825
Change how version with dashes are handled by so-docker-prune
2021-05-25 11:25:12 -04:00
Mike Reeves
1e564c2140
Fix zeek jinja
2021-05-25 10:22:36 -04:00
William Wernert
7e008378ba
Replace string with variable, remove unnecessary text
2021-05-25 09:23:44 -04:00
William Wernert
dbc4ffd69a
Fix typo
2021-05-25 09:20:45 -04:00
m0duspwnens
5a1e8d9fe9
update kibana scripts for elastic auth
2021-05-25 08:50:55 -04:00
Mike Reeves
5e5d30a377
Fix 3rd party modules
2021-05-25 08:26:25 -04:00
William Wernert
3bc0def02a
Add failure message to salt-master check
2021-05-24 16:45:05 -04:00
m0duspwnens
bd301880ad
define the default
2021-05-24 16:32:30 -04:00
m0duspwnens
2deb703272
map users_roles and users conf into docker container
2021-05-24 16:30:55 -04:00
Jason Ertel
8c6489a49a
Initial pass at synchronizing users file
2021-05-24 15:48:05 -04:00
m0duspwnens
87609ba5d1
fix elasticcurl if auth is enabled
2021-05-24 15:44:01 -04:00
m0duspwnens
ba3a51387c
set default to False
2021-05-24 15:31:46 -04:00
William Wernert
ffd5bfc480
Force images from automated branches to a very high semver
2021-05-24 15:25:03 -04:00
m0duspwnens
a4226cc39a
use elastic map file
2021-05-24 15:14:05 -04:00
William Wernert
dcb89b704a
Move sensoroni state out of the * block of top.sls
...
Resolves #3559
2021-05-24 13:45:12 -04:00
William Wernert
686c7c5a6c
Add exception handling for docker API error to so-docker-prune
2021-05-24 13:26:43 -04:00
Jason Ertel
409eea677d
Continue removal of argon hashing
2021-05-24 11:50:53 -04:00
William Wernert
99d41d1606
Add ending newline to soup
2021-05-24 11:29:40 -04:00
Jason Ertel
915b7aa2df
Switch Kratos config from argon2 to bcrypt12
2021-05-24 10:52:54 -04:00
m0duspwnens
e2d5102a0e
changes for script to auth to elastic
2021-05-24 10:13:29 -04:00
Mike Reeves
e5a41b60ef
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-05-24 09:14:03 -04:00
Jason Ertel
0572ea4095
Fail curl command if a failing status code is returned by the remote server
2021-05-21 17:27:11 -04:00
Jason Ertel
71032150c5
Add secure HTTP headers to all SO application responses to reduce exposure to browser and other HTTP-related vulnerabilities
2021-05-21 17:27:00 -04:00
Jason Ertel
36d13dd414
Merge branch 'dev' into kilo
2021-05-21 17:26:50 -04:00
William Wernert
946e369a44
Merge branch 'dev' into foxtrot
2021-05-21 15:26:24 -04:00
Mike Reeves
18922ed6f5
Merge pull request #4263 from Security-Onion-Solutions/feature/merge-2.3.51
...
Merge 2.3.51 into dev
2021-05-21 12:47:15 -04:00
William Wernert
c1dd4dafe4
Fix influx state
2021-05-21 12:41:10 -04:00
William Wernert
fe3aec173f
Merge branch 'master' into feature/merge-2.3.51
...
# Conflicts:
# VERSION
# salt/influxdb/init.sls
2021-05-21 12:31:54 -04:00
Mike Reeves
de4fde4ee3
Merge pull request #4248 from Masaya-A/MAC-Address
...
Showing Mac Address to select suitable NICs (Discussions #4214 )
2021-05-19 21:18:15 -04:00
Masaya-A
3450219bc7
Drop error to /dev/null
2021-05-20 09:33:14 +09:00
Masaya-A
6af126b872
Fix array
2021-05-19 10:02:19 +09:00
Masaya-A
ac42cba50b
Adding MAC Address for NIC List
2021-05-19 09:06:02 +09:00
Masaya-A
5d263f63cb
Merge pull request #10 from Security-Onion-Solutions/dev
...
Dev Sync
2021-05-19 08:59:49 +09:00
William Wernert
f445186f1e
Remove redundant error messages
2021-05-18 13:38:55 -04:00
William Wernert
bdd53ed5e3
Change retry delay + count
2021-05-18 12:23:40 -04:00
William Wernert
dbd5ef70c9
Change retry delay + count
2021-05-17 16:19:31 -04:00
William Wernert
ce9554281e
Fix backwards logic
2021-05-17 16:08:34 -04:00
William Wernert
4e1fba5b38
Only echo error code if not using retry
2021-05-17 16:04:13 -04:00
William Wernert
3f238f7a4a
Set flag so trap doesn't repeat info
2021-05-17 16:02:52 -04:00
William Wernert
b89091cc7d
Try retrying in curl instead of shell function
2021-05-17 15:58:25 -04:00
William Wernert
992b76a0f0
Remove debug lines
2021-05-17 15:38:10 -04:00
William Wernert
2bcd51b21c
Fix error message
2021-05-17 15:10:57 -04:00
William Wernert
3625453668
Don't unmount airgap directory if not airgap
2021-05-17 11:00:28 -04:00
William Wernert
5821a122cc
Merge branch 'dev' into issue/3220
2021-05-17 10:58:06 -04:00
Josh Patterson
891e414cb6
Merge pull request #4202 from Security-Onion-Solutions/issue/3264
...
Issue/3264
2021-05-14 16:30:16 -04:00
m0duspwnens
54f9e3ff9d
remove leading space on comment line
2021-05-14 16:24:16 -04:00
m0duspwnens
1c0cc15fdb
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-14 15:19:58 -04:00
m0duspwnens
231e07dbbd
circumvent file.patch putting ERROR in log if patch doesnt need applied
2021-05-14 15:19:45 -04:00
m0duspwnens
3859f6464a
dont be quiet on first grep
2021-05-14 08:56:42 -04:00
Mike Reeves
71a74a6656
Added updated script and core modules
2021-05-13 13:07:16 -04:00
Josh Patterson
3668d1aadf
Merge pull request #4188 from Security-Onion-Solutions/issue/3264
...
install influxdb and grafana during setup prior to final highstate
2021-05-13 11:46:57 -04:00
m0duspwnens
d3af06e7a4
handle exception if influxdb module doesnt exist
2021-05-13 11:00:42 -04:00
m0duspwnens
74f2a61b25
install influxdb and grafana during setup prior to final highstate
2021-05-13 09:06:47 -04:00
Mike Reeves
68a667ee7c
Add thirfpartydefaults.yml
2021-05-12 15:31:19 -04:00
William Wernert
192b5db25a
Add true to end of functions ending with shorthand comparison
...
Functions ending with test using [[ <false> ]] && <cmd> will trip set -e, so adding true to the last line of the function will prevent the function from returning a nonzero code
2021-05-12 15:26:39 -04:00
William Wernert
9ced391c11
Fix indent in main(), re-add trap, remove ERR_HANDLED variable
2021-05-12 13:20:59 -04:00
William Wernert
807b525c79
Temp remove exit on failure + bash trap
2021-05-12 11:19:33 -04:00
William Wernert
7bd04deae7
Unset exit on failure for pkill command
2021-05-12 10:45:03 -04:00
William Wernert
c379822bf0
Set variable to skip trap if error already handled
2021-05-11 12:59:49 -04:00
m0duspwnens
ad67167e97
remove whitespace control
2021-05-11 12:58:21 -04:00
m0duspwnens
4012a8276c
add template for module .yml file
2021-05-11 12:22:25 -04:00
m0duspwnens
efc028d0a5
handle the docker port bindings for filebeat modules
2021-05-10 18:08:47 -04:00
Mike Reeves
01a121e029
Add defaults.yml
2021-05-10 15:29:50 -04:00
William Wernert
f793450d97
Return actual exit code from retry
2021-05-10 13:22:13 -04:00
William Wernert
fec868432f
Try to fix bash trap
2021-05-10 11:59:22 -04:00
William Wernert
d3b08beb53
Only cat file if it exists
2021-05-10 11:11:54 -04:00
William Wernert
a75d4841d0
Add debug lines
2021-05-10 11:05:24 -04:00
William Wernert
8b3730748b
Add debug line and remove exit command on retry failure
2021-05-10 10:58:29 -04:00
William Wernert
de5552c91a
Merge branch 'dev' into issue/3220
2021-05-10 10:33:52 -04:00
m0duspwnens
a7e6dec51d
Merge remote-tracking branch 'remotes/origin/dev' into kilo
2021-05-10 09:57:50 -04:00
Josh Patterson
26335a9b42
Merge pull request #4140 from Security-Onion-Solutions/issue/3264
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-05-10 08:14:12 -04:00
William Wernert
f8dd6890b2
Unset/set exit on command fail for retries
2021-05-07 16:50:59 -04:00
m0duspwnens
1c103f92f2
Merge remote-tracking branch 'remotes/origin/issue/3264' into kilo
2021-05-07 14:48:42 -04:00
m0duspwnens
e3ce683970
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-07 14:48:16 -04:00
m0duspwnens
9eb63b17f9
exit if retry fails
2021-05-07 14:48:02 -04:00
m0duspwnens
755370eff0
Merge remote-tracking branch 'remotes/origin/dev' into kilo
2021-05-07 14:46:08 -04:00
Jason Ertel
407ad51244
Merge pull request #4139 from Security-Onion-Solutions/issue/4081
...
FEATURE: Pivot from Alerts/Hunt to CyberChef #4081
2021-05-07 13:31:21 -04:00
Doug Burks
293fb0a76d
FEATURE: Pivot from Alerts/Hunt to CyberChef #4081
2021-05-07 13:23:46 -04:00
Doug Burks
2e228c8355
FEATURE: Pivot from Alerts/Hunt to CyberChef #4081
2021-05-07 13:22:03 -04:00
m0duspwnens
009f7617c1
check salt-master is responding
2021-05-07 12:47:22 -04:00
m0duspwnens
b39c8c1f1f
exit after 50 tries if manager cant connect to iteself via salt
2021-05-07 11:02:23 -04:00
William Wernert
7b29c6427b
Add preliminary error handling in soup
2021-05-07 10:55:17 -04:00
m0duspwnens
d0e084b8ea
change command to test if salt-master is accepting connections
2021-05-07 10:20:04 -04:00
m0duspwnens
46223e0b30
add quotes around minionid
2021-05-07 08:59:47 -04:00
m0duspwnens
5d3b147b42
change retry command
2021-05-06 20:32:26 -04:00
m0duspwnens
6474c296e1
dont need to specify dest rp
2021-05-06 20:26:13 -04:00
m0duspwnens
b8ad80ae35
update comment
2021-05-06 17:49:40 -04:00
m0duspwnens
78240b4b52
change retry command
2021-05-06 17:49:02 -04:00
m0duspwnens
e7c716ede4
merge with dev, use retry to check if manager up instead of sleep in soup
2021-05-06 16:44:34 -04:00
m0duspwnens
da528e802f
ensure migration script doesnt migrate the current days data and fix downsample cq to move from so_short_term rp
2021-05-06 12:52:47 -04:00
Josh Brower
23b4327c28
Merge pull request #4072 from petiepooo/fix-sleep
...
fix 5-second sleep
2021-05-06 12:48:34 -04:00
William Wernert
9f6dfa4d2e
Merge pull request #4112 from Security-Onion-Solutions/master
...
Bring hotfix changes into dev
2021-05-06 10:44:25 -04:00
Wes Lambert
728d1f7540
Make Zeek and Suricata great again
2021-05-06 14:06:17 +00:00
Wes Lambert
ee92ba20b0
Add modules path reference
2021-05-06 13:56:39 +00:00
Wes Lambert
1b749cf004
Additional config
2021-05-06 13:55:07 +00:00
Wes Lambert
37929dbd7d
Add additional config for Filebeat modules
2021-05-06 13:54:28 +00:00
Wes Lambert
865ba912f8
Merge remote-tracking branch 'remotes/origin/dev' into pipeline
2021-05-06 13:19:31 +00:00
m0duspwnens
9dbb9f519b
create so_short_term rp as default so that autogen can just be dropped once data is downsampled
2021-05-06 09:14:49 -04:00
m0duspwnens
20188549f7
add the logic for so-influxdb-migrate
2021-05-05 19:28:16 -04:00
m0duspwnens
925be17d51
clean some commas in so-influxdb-clean
2021-05-05 15:59:18 -04:00
m0duspwnens
0ea4c99102
remove support for months as it isnt supported in InfluxQL
2021-05-05 15:32:53 -04:00
m0duspwnens
db98b7ed27
verify with user before proceedig to clean
2021-05-05 15:08:11 -04:00
m0duspwnens
44de611097
rename to so-influxdb-clean
2021-05-05 14:57:39 -04:00
m0duspwnens
a5ee8fb59d
fix the issues with so-influxdb-clear
2021-05-05 14:56:53 -04:00
m0duspwnens
e532804474
move to proper dir
2021-05-05 13:42:21 -04:00
m0duspwnens
ce24781446
first take at so-infludb-clean
2021-05-05 13:29:24 -04:00
weslambert
c867d6648a
Merge pull request #4098 from Security-Onion-Solutions/delta
...
Add ignore above for message keyword field
2021-05-05 08:53:39 -04:00
m0duspwnens
8ae5ae7e57
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-05 08:33:47 -04:00
m0duspwnens
6a639edb05
have cq created once again
2021-05-05 08:33:31 -04:00
Wes Lambert
a1a79719fc
Add ignore above for message keyword field
2021-05-05 12:07:30 +00:00
m0duspwnens
c5f99b012e
comment out creation of cq to test data migration
2021-05-04 13:58:53 -04:00
m0duspwnens
fcd1bea4a3
remove auto data migration, change duration from 0s to 0d
2021-05-04 12:06:03 -04:00
Mike Reeves
0622c77a7f
Add filebeat modules
2021-05-04 10:50:13 -04:00
Mike Reeves
8aaf3e1052
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-04 10:44:13 -04:00
m0duspwnens
3dcaa1f6fb
more logging for influxdb migration
2021-05-04 10:37:25 -04:00
m0duspwnens
2d91e509fa
update wording
2021-05-04 10:34:13 -04:00
m0duspwnens
a0f1839162
run in background
2021-05-04 09:59:16 -04:00
m0duspwnens
e2f52765e4
add newline
2021-05-04 09:34:42 -04:00
m0duspwnens
f186a3dde9
make sure user sees influxdb migration message by requiring enter to be pressed to continue
2021-05-04 09:30:38 -04:00
m0duspwnens
9b065155f4
log iunfluxdb migration to new log
2021-05-04 08:56:13 -04:00
m0duspwnens
12306368cf
add post upgrade function for 2.3.60 soup to migrate influxdb data
2021-05-04 08:37:52 -04:00
weslambert
d4e8ea8e72
Merge pull request #4079 from Security-Onion-Solutions/delta
...
Add event_data to common template so elastalert/playbook event_data f…
2021-05-03 13:45:17 -04:00
Wes Lambert
619402cc67
Add event_data to common template so elastalert/playbook event_data fields can be indexed and searchable
2021-05-03 17:03:30 +00:00
m0duspwnens
b01bfda862
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-05-03 11:49:09 -04:00
William Wernert
da19df5174
Merge pull request #4076 from Security-Onion-Solutions/issue/4004
...
Don't ask for node description on eval and import installs
2021-05-03 11:43:37 -04:00
William Wernert
19dd9b97d2
Don't ask for node description on eval and import installs
2021-05-03 09:40:53 -04:00
Mike Reeves
21b92ac077
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-02 13:06:29 -04:00
Pete
b80dd1ef3e
fix 5-second sleep
...
using wait here instead of sleep tries to wait until pid 5 exits and generates the error
> /usr/sbin/so-playbook-reset: line 25: wait: pid 5 is not a child of this shell
2021-04-30 20:21:50 +00:00
m0duspwnens
d6b9154a88
change how version to be installed is defined to work with centos
2021-04-30 14:48:51 -04:00
m0duspwnens
f9573f7972
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-30 13:33:47 -04:00
m0duspwnens
038cadeae8
change version to 2.3.60 to prepare to push to dev
2021-04-30 12:31:57 -04:00
m0duspwnens
e32ca284c5
ensure proper version of python3-influxdb is installed prior to running the states that require it
2021-04-30 11:10:31 -04:00
Mike Reeves
a56426010d
Merge pull request #4057 from Security-Onion-Solutions/kilo
2021-04-29 17:46:26 -04:00
Jason Ertel
dda07af4d4
Update Kibana config defaults
2021-04-29 17:44:15 -04:00
Mike Reeves
81bfb202f7
Merge pull request #4055 from Security-Onion-Solutions/kilo
2021-04-29 15:37:34 -04:00
Jason Ertel
b6561fd8e2
Update defaultRoute with new path structure
2021-04-29 15:35:22 -04:00
m0duspwnens
d475e50bef
add deps for ubuntu
2021-04-29 13:49:15 -04:00
m0duspwnens
689a01423f
fix deps
2021-04-29 13:28:31 -04:00
m0duspwnens
888d637b67
add %}
2021-04-29 13:26:24 -04:00
m0duspwnens
e7660d68cb
add %}
2021-04-29 13:25:29 -04:00
m0duspwnens
450a01784b
support installing via pip for ubuntu
2021-04-29 13:22:31 -04:00
Mike Reeves
5d8cb511be
Merge pull request #4046 from Security-Onion-Solutions/kilo
...
Switch to the ES-included community_id plugin
2021-04-29 12:11:44 -04:00
Jason Ertel
44ad8ce888
Switch to the ES-included community_id plugin
2021-04-29 12:08:07 -04:00
Jason Ertel
14572d9eab
Merge pull request #4045 from Security-Onion-Solutions/ktbackup
...
Add Grid nodeid fix and Kratos backup to include Kratos
2021-04-29 11:55:46 -04:00
Mike Reeves
76d735ff43
Add ID Fix to nodeID
2021-04-29 11:49:20 -04:00
Mike Reeves
02b621bd2c
Add Kratos to Backups
2021-04-29 11:29:07 -04:00
Mike Reeves
96eab86bc6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-29 11:19:19 -04:00
m0duspwnens
93ee96b1cd
Ignore "Status .* was not found" due to output from salt http.query or http.wait_for_successful_query states used with retry
2021-04-29 10:19:42 -04:00
m0duspwnens
907dbe6388
for for influx to be up so the reliant states dont fail
2021-04-29 08:47:33 -04:00
m0duspwnens
f8e01d5d53
let the state retry incase influxdb isnt fully up yet
2021-04-29 06:43:05 -04:00
m0duspwnens
454b541a2e
merge with dev, change version so test box doesnt try to upgrade to 2.3.60
2021-04-28 18:04:14 -04:00
m0duspwnens
2b9b22cd90
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-28 18:02:01 -04:00
m0duspwnens
5584c4f1ae
define and install the dependencies for python36-influxdb
2021-04-28 18:01:33 -04:00
Mike Reeves
9830f661c8
Merge pull request #4031 from Security-Onion-Solutions/kilo
...
Remove unused and incorrectly formatted osraid metric
2021-04-28 13:34:57 -04:00
Jason Ertel
7a21c44727
Remove unused and incorrectly formatted osraid metric
2021-04-28 13:27:11 -04:00
Mike Reeves
4c55e5a6cc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-28 10:27:55 -04:00
Mike Reeves
f0012015e6
Merge pull request #4018 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update raid.sh
2021-04-28 10:27:35 -04:00
Mike Reeves
14557983e1
Update raid.sh
2021-04-28 10:24:39 -04:00
Jason Ertel
865e5cb120
Merge pull request #4017 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2021-04-28 10:19:07 -04:00
m0duspwnens
d9cb018a7d
merge with dev, resolve conflicts
2021-04-28 10:19:01 -04:00
Mike Reeves
8dd9564171
Update VERSION
2021-04-28 10:17:37 -04:00
Mike Reeves
77533f7873
Repo Fix
2021-04-27 15:45:35 -04:00
Mike Reeves
a6b2eefee1
Prompt airgap to update
2021-04-27 15:33:52 -04:00
Mike Reeves
4cea08c080
Prompt airgap to update
2021-04-27 15:32:00 -04:00
Mike Reeves
d56e66917a
2.3.50 sig files
2021-04-26 09:18:15 -04:00
m0duspwnens
28982e0e0b
fix requirement
2021-04-21 19:22:07 -04:00
m0duspwnens
1fbf77d090
fix state name
2021-04-21 18:53:00 -04:00
m0duspwnens
6c8a2e68d9
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-21 18:24:07 -04:00
m0duspwnens
f5ddb084b6
create salt.helper-packages state, use it to install the patch package
2021-04-21 18:22:44 -04:00
m0duspwnens
21077ef26e
undo path change
2021-04-21 18:09:11 -04:00
m0duspwnens
5cedf98f55
change path
2021-04-21 18:05:52 -04:00
m0duspwnens
a7247e9812
update package name
2021-04-21 17:17:49 -04:00
m0duspwnens
c9298137b5
adding docker-ce.repo to delete list
2021-04-21 17:08:35 -04:00
m0duspwnens
17c95723ec
update package name
2021-04-21 16:44:40 -04:00
m0duspwnens
1f654d4444
fix the state apply
2021-04-21 12:04:58 -04:00
m0duspwnens
0a01d7b041
fix var
2021-04-21 11:14:13 -04:00
m0duspwnens
b53017ee87
ensure salt python modules are installed and patched during soup
2021-04-21 10:44:46 -04:00
m0duspwnens
af86a9dac0
handle different paths for salt states/modules based on os
2021-04-21 09:52:22 -04:00
m0duspwnens
d792c65ce3
change how influx is patch and python3-influxdb is installed
2021-04-21 09:25:25 -04:00
m0duspwnens
8eef574342
install python3-influxdb and create requires
2021-04-21 08:28:01 -04:00
m0duspwnens
2d0594398c
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-04-20 15:53:34 -04:00
m0duspwnens
115764ae38
merge with dev and fix merge conflict in so-functions https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-20 10:03:15 -04:00
m0duspwnens
5cda35db0a
change defaults for testing - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-01 10:45:54 -04:00
m0duspwnens
4f3b3a787c
change defaults for testing, remove measurements list since cq uses wildcard now - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-01 10:18:29 -04:00
m0duspwnens
8e55e0b994
start graphing data from so_long_term
2021-03-30 13:36:52 -04:00
m0duspwnens
30c6d4756a
change default long term resolution to 5m
2021-03-30 09:38:37 -04:00
m0duspwnens
d1150f150f
loop through the rps
2021-03-29 10:59:18 -04:00
m0duspwnens
e0f4abaa09
try to do it with just 1 cq, modify defaults for testing
2021-03-29 10:36:56 -04:00
m0duspwnens
889e624a8c
add shard_duration to state and defaults - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-03-25 09:33:10 -04:00
m0duspwnens
cd0ab5c709
add support for shard_duration to influxdb module and influxdb_retention_policy state - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-03-25 08:50:32 -04:00
m0duspwnens
d75fafb19c
add support for shard_duration to influxdb module and influxdb_retention_policy state - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-03-24 17:30:27 -04:00
m0duspwnens
11c3f14b42
end patch files with newline
2021-03-24 10:35:20 -04:00
m0duspwnens
53528d486c
remove minio
2021-03-24 09:44:56 -04:00
m0duspwnens
3a8aea0de6
removing domainstats and freqserver from so-image-common
2021-03-24 09:11:48 -04:00
m0duspwnens
a3e11f017b
merge with 2.3.40
2021-03-23 14:34:52 -04:00
m0duspwnens
c4da576030
ensure the presence of the telegraf database
2021-03-11 12:20:32 -05:00
m0duspwnens
465253a769
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-03-11 10:55:19 -05:00
m0duspwnens
3b74d987c1
fix retry in ca state. add subjectAltName to influxdb.crt
2021-03-11 10:49:15 -05:00
m0duspwnens
3385ba2ca2
verify ssl
2021-03-11 09:35:54 -05:00
m0duspwnens
6dba2879c5
change so_long_term rp to 6h for tetsing
2021-03-11 09:25:44 -05:00
m0duspwnens
8fc1656939
fix timeouts / retries in ssl state
2021-03-11 09:24:57 -05:00
m0duspwnens
75012cdcba
create rps and cqs
2021-03-10 15:20:11 -05:00
m0duspwnens
c1e4c4cb30
fix pip and python-influxdb install
2021-03-09 11:50:27 -05:00
m0duspwnens
a3a0af64ce
Merge remote-tracking branch 'remotes/origin/dev' into issue/3264
2021-03-09 10:34:39 -05:00
m0duspwnens
1f9e5ca3cc
install influxdb python module add test retention policies
2021-03-09 10:31:59 -05:00
m0duspwnens
7409f15752
update all grafana queries that were using autogen to use default
2021-03-05 13:59:29 -05:00