Mike Reeves
85cf096322
Merge pull request #6541 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-13 12:41:24 -05:00
Mike Reeves
4eaf3f8d8b
Merge pull request #6540 from Security-Onion-Solutions/2390hotfix3
...
2.3.90-20211213 Hotfix
2021-12-13 12:12:03 -05:00
Mike Reeves
d90904b4d4
2.3.90-20211213 Hotfix
2021-12-13 12:09:09 -05:00
Mike Reeves
65cc9930e7
Merge pull request #6537 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-12-13 11:13:40 -05:00
Mike Reeves
7f982d2824
Update HOTFIX
2021-12-13 11:12:18 -05:00
Mike Reeves
d3ac1f7994
Merge pull request #6533 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Add missing logstash lib
2021-12-13 09:30:32 -05:00
Jason Ertel
c94d5fa9dc
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:27:13 -05:00
Mike Reeves
83d1cdad90
Merge pull request #6532 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:05:30 -05:00
Jason Ertel
8365b5f140
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:02:41 -05:00
Mike Reeves
4d6cd66d9d
Merge pull request #6521 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-10 16:20:29 -05:00
Mike Reeves
1946965c5f
Merge pull request #6520 from Security-Onion-Solutions/2390hotfix0day
...
2.3.90-20211210 Hotfix
2021-12-10 15:49:38 -05:00
Mike Reeves
c9a14788ed
2.3.90-20211210 Hotfix
2021-12-10 15:42:53 -05:00
Mike Reeves
ce963a02d9
Merge pull request #6517 from Security-Onion-Solutions/ES0day2
...
Add JVM Options for logstash
2021-12-10 14:25:52 -05:00
Mike Reeves
dcd56de890
Update log4j2.properties
2021-12-10 14:23:38 -05:00
Mike Reeves
3d7b963912
Update log4j2.properties
2021-12-10 14:16:16 -05:00
Mike Reeves
09253b637e
Create jvm.options
2021-12-10 14:12:43 -05:00
Mike Reeves
c81ce48bff
Update log4j2.properties
2021-12-10 14:10:35 -05:00
Mike Reeves
73ec595baa
Update init.sls
2021-12-10 14:10:05 -05:00
Mike Reeves
04862fcc06
Merge pull request #6514 from Security-Onion-Solutions/ES0day2
...
Throw the log4j into the java options
2021-12-10 12:04:31 -05:00
Mike Reeves
45346b6318
Update log4j2.properties
2021-12-10 12:01:39 -05:00
Mike Reeves
e48de18480
Update init.sls
2021-12-10 12:00:12 -05:00
Mike Reeves
66c8cc6e86
Update init.sls
2021-12-10 11:59:12 -05:00
Mike Reeves
8dcb64d87c
Update init.sls
2021-12-10 11:56:33 -05:00
Mike Reeves
ae3e980852
Merge pull request #6513 from Security-Onion-Solutions/EShotfix
...
Update log4j2.properties
2021-12-10 10:35:43 -05:00
Mike Reeves
11f1fe7ab1
Update HOTFIX
2021-12-10 10:21:50 -05:00
Mike Reeves
4561e13871
Update log4j2.properties
2021-12-10 10:19:58 -05:00
Mike Reeves
ea26e402c8
Update log4j2.properties
2021-12-10 10:17:49 -05:00
Mike Reeves
9f41df641e
Merge pull request #6470 from Security-Onion-Solutions/hotfix/2.3.90
...
HOTFIX: 2.3.90-20211206
2021-12-07 09:51:01 -05:00
Mike Reeves
9f94ecfab7
Merge pull request #6466 from Security-Onion-Solutions/2390updates3
...
2.3.90 hotfix 20211206
2021-12-06 11:07:14 -05:00
Mike Reeves
4188282724
2.3.90 hotfix 20211206
2021-12-06 11:03:49 -05:00
Mike Reeves
3945933dec
Merge pull request #6446 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-12-06 09:38:02 -05:00
Mike Reeves
73a1a3878f
Update HOTFIX
2021-12-06 09:37:07 -05:00
weslambert
ff25d6f80b
Merge pull request #6447 from Security-Onion-Solutions/eg_dashes
...
Add initial EG dashboards
2021-12-03 18:05:22 -05:00
Wes Lambert
0571612ea1
Add initial EG dashes
2021-12-03 22:38:30 +00:00
Mike Reeves
f697d88090
Update HOTFIX
2021-12-03 15:36:16 -05:00
Mike Reeves
ad03241910
Merge pull request #6445 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Apply hotfix to all 2.3.90 installs
2021-12-03 15:24:33 -05:00
Mike Reeves
f82d204c0e
Update soup
2021-12-03 15:20:33 -05:00
Mike Reeves
780daf8aa7
Apply hotfix to all 2.3.90 installs
2021-12-03 15:15:45 -05:00
Josh Patterson
5008b647b0
Merge pull request #6441 from Security-Onion-Solutions/hf/soc_append2.3.90
...
export LC_CTYPE="en_US.UTF-8" in soup
2021-12-03 15:10:12 -05:00
m0duspwnens
65b1ab833d
run salt-call locally as if no Salt master were present during reinstall - https://github.com/Security-Onion-Solutions/securityonion/discussions/6435
2021-12-03 12:00:29 -05:00
m0duspwnens
c6773a0bbc
move "Preparing soup" to main so shows in soup.log
2021-12-03 10:26:22 -05:00
m0duspwnens
ff2d2c7c04
export LC_CTYPE="en_US.UTF-8" - https://github.com/Security-Onion-Solutions/securityonion/discussions/6431
2021-12-02 16:39:32 -05:00
Mike Reeves
6c7a1f23f5
Merge pull request #6440 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Fix for the clustername used in wrong context
2021-12-02 15:35:26 -05:00
Mike Reeves
f5761c73a5
Fix for the clustername used in wrong context
2021-12-02 15:30:35 -05:00
Mike Reeves
8448778ecd
Merge pull request #6438 from Security-Onion-Solutions/hf/soc_append2.3.90
...
hf/soc append2.3.90
2021-12-02 15:10:51 -05:00
m0duspwnens
8d667795a7
only add soc:es_index_patterns to pillar if not already present
2021-12-02 10:28:17 -05:00
m0duspwnens
7a664ab8f7
more error proof up_to_2.3.90 function
2021-12-02 10:02:26 -05:00
m0duspwnens
5e0ac89841
merge with master
2021-12-01 14:27:58 -05:00
Mike Reeves
8990a09d92
Merge pull request #6418 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-01 13:24:19 -05:00
Mike Reeves
946673dc3b
Merge pull request #6417 from Security-Onion-Solutions/2390updates2
...
2.3.90 hotfix airgap
2021-12-01 13:20:41 -05:00
m0duspwnens
c571b2c499
handle redirect if more than 1 match from compgen
2021-12-01 13:17:14 -05:00
Mike Reeves
80c569317f
2.3.90 hotfix airgap
2021-12-01 13:16:13 -05:00
Mike Reeves
5f121f3b99
Merge pull request #6411 from Security-Onion-Solutions/m0duspwnens-patch-1/hotfix/2.3.90
...
remove redirect to /dev/null for compgen
2021-12-01 10:17:29 -05:00
Josh Patterson
63cb486698
remove redirect to /dev/null for compgen
2021-12-01 10:16:04 -05:00
William Wernert
1a31e60e47
Merge pull request #6402 from Security-Onion-Solutions/fix/airgap-check
...
Fix/airgap check
2021-11-30 15:57:02 -05:00
William Wernert
168f860c87
Add hotfix string to HOTFIX
2021-11-30 15:49:41 -05:00
William Wernert
8d87fae6a8
Remove airgap repo file if it shouldn't exist
2021-11-30 15:46:22 -05:00
William Wernert
739efc22d2
Fix airgap check logic
2021-11-30 15:46:18 -05:00
Mike Reeves
4c6786a412
Merge pull request #6335 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-11-23 16:51:27 -05:00
Mike Reeves
5062e910e2
Merge pull request #6334 from Security-Onion-Solutions/2390updates
...
2.3.90 hotfix soup
2021-11-23 15:41:21 -05:00
Mike Reeves
1f9dc0db1f
2.3.90 hotfix soup
2021-11-23 15:40:04 -05:00
Mike Reeves
c536e11383
2.3.90 hotfix soup
2021-11-23 15:32:41 -05:00
Mike Reeves
faa8464b60
Merge pull request #6333 from Security-Onion-Solutions/kilo
...
Correct if check to inline the command instead of checking for emptin…
2021-11-23 14:53:24 -05:00
Jason Ertel
4f283c2d86
Suppres grep output
2021-11-23 14:52:40 -05:00
Jason Ertel
801d42ed20
Correct if check to inline the command instead of checking for emptiness of a variable
2021-11-23 14:51:06 -05:00
Mike Reeves
30a1ffc1c7
Merge pull request #6329 from Security-Onion-Solutions/kilo
...
2.3.90 WAZUH
2021-11-23 13:37:41 -05:00
Jason Ertel
59fc122eec
Force restart of wazuh since conf file is changing
2021-11-23 13:29:04 -05:00
Jason Ertel
52ffa27eda
Update hotfix file
2021-11-23 13:22:47 -05:00
Jason Ertel
bd59d65f02
Strip trailing newlines from version and hotfix files
2021-11-23 13:12:27 -05:00
Jason Ertel
01ceded223
Handle CRs in hotfix
2021-11-23 13:03:40 -05:00
Jason Ertel
3c37bd61ab
Add debug logging
2021-11-23 12:46:59 -05:00
Jason Ertel
a35670c889
Merge branch 'hotfix/1.3.90' into kilo
2021-11-23 12:38:57 -05:00
Jason Ertel
7627d37386
Add 2.3.90 WAZUH hotfix corrective function
2021-11-23 12:21:28 -05:00
Jason Ertel
273842eb43
Merge pull request #6328 from Security-Onion-Solutions/kilo
...
WAZUH hotfix
2021-11-23 12:06:34 -05:00
Jason Ertel
0dd251e2a9
Fix typo in whiptail prompt
2021-11-23 11:19:53 -05:00
Josh Patterson
c67b2b6936
Update soup
...
only check if salt was upgraded if upgrade_salt function was called
2021-11-23 11:14:10 -05:00
Jason Ertel
af4c04be59
Fix #6325 - Prevent XML header from outputting to ossec.conf
2021-11-23 10:57:21 -05:00
Jason Ertel
4672b0c15c
Fix #6317 - Do not attempt to whitelist when wazuh isn't enabled
2021-11-23 10:06:14 -05:00
Jason Ertel
9737a4088c
Merge pull request #6327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-11-23 09:25:43 -05:00
Mike Reeves
d8d429c71a
Update HOTFIX
2021-11-23 09:19:41 -05:00
Mike Reeves
3bfc3b8943
Merge pull request #6301 from Security-Onion-Solutions/dev
...
2.3.90
2021-11-22 13:15:23 -05:00
Mike Reeves
4ad6d616ae
Merge pull request #6313 from Security-Onion-Solutions/2390update
...
2390update
2021-11-22 09:04:16 -05:00
Mike Reeves
759c0b858a
2.3.90
2021-11-22 09:01:12 -05:00
Mike Reeves
c17a49a730
Merge pull request #6302 from Security-Onion-Solutions/fix/md5soup
...
Fix/md5soup
2021-11-19 16:45:02 -05:00
m0duspwnens
c0f183fb5e
add comment
2021-11-19 16:37:27 -05:00
m0duspwnens
d602339c45
render and md5sum soup and so-common
2021-11-19 16:32:59 -05:00
Mike Reeves
0122e62920
Merge pull request #6300 from Security-Onion-Solutions/2390
...
2.3.90
2021-11-19 14:09:02 -05:00
Mike Reeves
1634105780
2.3.90
2021-11-19 14:07:03 -05:00
Josh Patterson
198a690ba1
Merge pull request #6298 from Security-Onion-Solutions/fix/soup-script-check
...
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:24:48 -05:00
William Wernert
bebd62187d
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:23:32 -05:00
Mike Reeves
a91564605c
Merge pull request #6297 from Security-Onion-Solutions/fix/soup-playbook-secrets
...
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:28:11 -05:00
William Wernert
23b91ee7e5
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:27:11 -05:00
Mike Reeves
d3f25f8d74
Merge pull request #6293 from Security-Onion-Solutions/fix/fleet-stats
...
Fix FleetDM - disable stats
2021-11-19 09:53:26 -05:00
Josh Brower
8bd4ba3acd
Fix FleetDM - disable stats
2021-11-19 09:49:34 -05:00
Josh Patterson
e5927d0bf7
Merge pull request #6290 from Security-Onion-Solutions/fleet_startup_eval
...
run redis state before fleet state for eval highstate
2021-11-18 17:54:26 -05:00
m0duspwnens
9dd89f6be7
run redis state before fleet state for eval highstate
2021-11-18 17:41:56 -05:00
Mike Reeves
796eb59dc6
Merge pull request #6288 from Security-Onion-Solutions/syncesusers_so-kratos
...
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:42:18 -05:00
m0duspwnens
55fed43469
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:35:35 -05:00
William Wernert
af83019427
Merge pull request #6287 from Security-Onion-Solutions/feat/cidr-extra-validation
...
Check for more invalid cidr syntax
2021-11-18 15:21:58 -05:00
William Wernert
4149236cda
Check for more invalid cidr syntax
2021-11-18 15:18:12 -05:00
Josh Patterson
825106d074
Merge pull request #6286 from Security-Onion-Solutions/fix/docker-upgrade
...
Prevent downgrade of docker, containerd, and docker-cli
2021-11-18 15:15:37 -05:00
William Wernert
1a3324868a
Specify version of docker-ce-rootless-extras
2021-11-18 15:12:47 -05:00
William Wernert
bc87bb4770
Specify docker cli version as well
2021-11-18 14:51:26 -05:00
William Wernert
6aae48bdae
Don't upgrade docker or containerd before versionlock is applied
2021-11-18 14:14:18 -05:00
Mike Reeves
a0425a48e6
Merge pull request #6282 from Security-Onion-Solutions/syncesusers_so-kratos
...
remove restart policy for kratos container
2021-11-18 11:43:16 -05:00
m0duspwnens
4b89bf7bbc
remove restart policy for kratos container
2021-11-18 11:41:07 -05:00
Mike Reeves
5fc5afa9ea
Merge pull request #6281 from Security-Onion-Solutions/syncesusers_so-kratos
...
install specific docker verison
2021-11-18 11:32:38 -05:00
m0duspwnens
ddec8e4da0
install specific docker verison
2021-11-18 11:29:22 -05:00
Jason Ertel
9c0e8cedba
Merge pull request #6279 from Security-Onion-Solutions/syncesusers_so-kratos
...
restart kratos if failure
2021-11-18 10:49:12 -05:00
m0duspwnens
5054da0027
restart kratos if failure
2021-11-18 10:48:06 -05:00
Jason Ertel
96f1f0174b
Merge pull request #6275 from Security-Onion-Solutions/syncesusers_so-kratos
...
break kratos state out from soc state
2021-11-18 09:13:10 -05:00
m0duspwnens
cd1f0c0440
break kratos state out from soc state
2021-11-18 09:10:00 -05:00
Mike Reeves
12546a8efa
Merge pull request #6271 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 19:48:15 -05:00
Josh Brower
3f5956b56d
Fix soup - fleetdm SA user
2021-11-17 19:47:16 -05:00
Mike Reeves
6e49ab0558
Merge pull request #6270 from Security-Onion-Solutions/fix/whiptail-text
...
Fix text cutoff
2021-11-17 19:18:46 -05:00
William Wernert
c52df32f05
Fix text cutoff
2021-11-17 19:08:10 -05:00
Josh Patterson
c0602f4222
Merge pull request #6269 from Security-Onion-Solutions/syncesusers_so-kratos
...
run elasticsearch.auth state and so-elastic-auth true before manager …
2021-11-17 18:41:18 -05:00
m0duspwnens
d4b412bcbe
run elasticsearch.auth state and so-elastic-auth true before manager in setup for syncesusers in manager state
2021-11-17 18:38:13 -05:00
Josh Brower
66e2de0934
Merge pull request #6268 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 18:26:11 -05:00
Josh Brower
c93794a402
Fix soup - fleetdm SA user
2021-11-17 18:22:34 -05:00
Josh Patterson
98efc6f2ed
Merge pull request #6267 from Security-Onion-Solutions/syncesusers_so-kratos
...
syncesusers require so-kratos
2021-11-17 18:20:53 -05:00
m0duspwnens
59ef734064
syncesusers require so-kratos
2021-11-17 18:16:06 -05:00
Josh Brower
922657afbc
Merge pull request #6266 from Security-Onion-Solutions/fix/fleet-users
...
Unset pw reset for new Fleet users
2021-11-17 17:10:27 -05:00
Josh Brower
5f3601ac78
Unset pw reset for new Fleet users
2021-11-17 17:06:01 -05:00
Josh Brower
2fe4fa06a6
Merge pull request #6265 from Security-Onion-Solutions/fix/fleet-users
...
Fix FleetDM SA Creation for SOUP
2021-11-17 14:09:59 -05:00
Josh Brower
773c580e77
Fix FleetDM SA Creation for SOUP
2021-11-17 14:08:34 -05:00
Mike Reeves
aca684d55a
Merge pull request #6264 from Security-Onion-Solutions/fix/fleet-users
...
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:16:05 -05:00
Josh Brower
6f391dbe50
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:13:25 -05:00
William Wernert
8d033264e7
Merge pull request #6262 from Security-Onion-Solutions/fix/new-cidr-test
...
Add new ipv4 address w/ cidr mask validator
2021-11-17 13:09:04 -05:00
William Wernert
262d2023b5
Add new ipv4 address w/ cidr mask validator
2021-11-17 12:41:25 -05:00
Josh Patterson
d143a309a1
Merge pull request #6261 from Security-Onion-Solutions/soup_soc_endgame
...
change how soc endgame added to manager pillar in soup
2021-11-17 11:12:17 -05:00
m0duspwnens
ac400f1c41
change how soc endgame added to manager pillar in soup
2021-11-17 11:07:12 -05:00
William Wernert
df495c0017
Merge pull request #6258 from Security-Onion-Solutions/fix/nm-conf
...
Run `check_network_manager_conf()` later in setup
2021-11-17 08:44:25 -05:00
William Wernert
8c454973ad
Run check_network_manager_conf() later in setup
...
The directory was being overwritten when network-manager was installed later
2021-11-17 08:42:27 -05:00
Josh Patterson
a16e6aca22
Merge pull request #6257 from Security-Onion-Solutions/es_soup_ingest
...
escape raw and endraw
2021-11-17 07:56:01 -05:00
m0duspwnens
ce21ae11f5
escape raw and endraw
2021-11-17 07:53:15 -05:00
Mike Reeves
fdd9706669
Merge pull request #6255 from Security-Onion-Solutions/kilo
2021-11-16 18:09:40 -05:00
Jason Ertel
8fa9a180b2
Refactor upgrade and post-upgrade version to function mappings; fix missing version upgrades from older 2.3.61 releases and earlier; Drop support for upgrading ancient RC releases
2021-11-16 18:08:28 -05:00
Josh Patterson
6288365a50
Merge pull request #6254 from Security-Onion-Solutions/es_soup_ingest
...
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:47:53 -05:00
m0duspwnens
5448107310
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:43:33 -05:00
Mike Reeves
adaf3faf90
Merge pull request #6253 from Security-Onion-Solutions/kilo
2021-11-16 16:13:31 -05:00
Jason Ertel
1bd8e226b4
Force DB migration since installations on 2.3.50 or earlier will skip the Kratos 0.6 version
2021-11-16 15:58:04 -05:00
Josh Patterson
f60f0b5b6d
Merge pull request #6246 from Security-Onion-Solutions/es_soup_ingest
...
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:05:15 -05:00
William Wernert
adc867846c
Merge pull request #6245 from Security-Onion-Solutions/fix/ubuntu-nic-unmanaged
...
Modify network-manager conf earlier in setup
2021-11-16 14:00:58 -05:00
m0duspwnens
5945326817
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:00:41 -05:00
William Wernert
90cbb5d00e
Modify network-manager conf earlier in setup
2021-11-16 13:30:09 -05:00
Josh Brower
8bb2789c6f
Merge pull request #6237 from Security-Onion-Solutions/kilo
...
Migrate to email field instead of username due to breaking change in …
2021-11-16 12:06:08 -05:00
Jason Ertel
11fc0da971
Migrate to email field instead of username due to breaking change in FleetDM 4.x
2021-11-16 12:03:46 -05:00
William Wernert
76a1d767f2
Merge pull request #6235 from Security-Onion-Solutions/feature/preflight-retry
...
Retry failed URLs in so-preflight + improve logging clarity
2021-11-16 11:11:02 -05:00
William Wernert
a2152446ea
Pad count string to align text
2021-11-16 11:08:13 -05:00
William Wernert
d4d9032bfc
Remove confusing punctuation
2021-11-16 10:56:49 -05:00
William Wernert
4e3f43bee4
Fix variable name
2021-11-16 10:53:22 -05:00
William Wernert
57377e0a0e
Add retry support + more precise logging to so-preflight
2021-11-16 10:46:48 -05:00
Mike Reeves
2514d36ccd
Merge pull request #6232 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2021-11-15 17:11:08 -05:00
Mike Reeves
809dbc0a48
Merge pull request #6233 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2021-11-15 17:10:52 -05:00
Mike Reeves
b51405d5e8
Update soup
2021-11-15 17:04:46 -05:00
Mike Reeves
d1cfc4a8dc
Merge pull request #6231 from Security-Onion-Solutions/fix/whiptail-cutoff
...
Fix whiptail description text
2021-11-15 17:02:00 -05:00
Mike Reeves
731bbabe4c
Update init.sls
2021-11-15 17:00:34 -05:00
William Wernert
d4509ff4d8
Fix whiptail description text
2021-11-15 16:29:26 -05:00
Mike Reeves
85c0b0818b
Merge pull request #6230 from Security-Onion-Solutions/fix/cidr-full-validation-bash
...
Check CIDR validity completely
2021-11-15 15:43:58 -05:00
William Wernert
f674555290
Check CIDR validity completely
2021-11-15 15:43:05 -05:00
Josh Patterson
a8aae544d5
Merge pull request #6229 from Security-Onion-Solutions/kibana_json_logging
...
change kibana logging to json
2021-11-15 14:27:04 -05:00
m0duspwnens
6f9db25ea7
change kibana logging to json
2021-11-15 14:23:47 -05:00
Mike Reeves
405e78858a
Merge pull request #6228 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2021-11-15 14:07:23 -05:00
Mike Reeves
146e1f4297
Update soup
2021-11-15 14:05:29 -05:00
Mike Reeves
f78e0fb7b9
Merge pull request #6227 from Security-Onion-Solutions/fix/fleetlogging
...
Fix env var for logging
2021-11-15 14:00:31 -05:00
Josh Brower
6e6d2d1949
Fix env var for logging
2021-11-15 13:52:35 -05:00
Josh Patterson
ca5d20fecb
Merge pull request #6225 from Security-Onion-Solutions/clean_meta_data
...
clean metadata with cmd.run instead of pkg module due to False return…
2021-11-15 11:03:41 -05:00
m0duspwnens
dcfaece8b1
clean metadata with cmd.run instead of pkg module due to False return from module
2021-11-15 11:00:31 -05:00
Mike Reeves
af0e062193
Merge pull request #6221 from Security-Onion-Solutions/fix/var-reference
...
Fix variable reference in so-functions
2021-11-15 09:49:07 -05:00
Mike Reeves
56acedfbf7
Merge pull request #6220 from Security-Onion-Solutions/fix/revert-python-validation
...
Fix/revert python validation
2021-11-15 09:44:31 -05:00
William Wernert
4b0a5c3a17
Un-revert validation test script
2021-11-15 09:43:43 -05:00
William Wernert
052192e1d6
Revert "Use python lib to make cidr validation more strict"
...
This reverts commit 569cb24861 .
2021-11-15 09:43:18 -05:00
weslambert
92131d4bb7
Merge pull request #6215 from Security-Onion-Solutions/fix/eg_spelling
...
Fix spelling
2021-11-12 21:13:28 -05:00
weslambert
9ac1cb0e76
Fix spelling
2021-11-12 21:12:09 -05:00
Josh Patterson
ffbb04bb5a
Merge pull request #6213 from Security-Onion-Solutions/issue/5809
...
Issue/5809
2021-11-12 15:07:54 -05:00
m0duspwnens
cc1dea446c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/5809
2021-11-12 15:02:22 -05:00
m0duspwnens
7f3379e034
verify manager pillars can be rendered before proceeding with soup - https://github.com/Security-Onion-Solutions/securityonion/issues/5809
2021-11-12 15:02:16 -05:00
weslambert
8c46a2d1db
Merge pull request #6210 from Security-Onion-Solutions/fix/soc_pillar_soup
...
Add SOC pillar entry
2021-11-12 13:35:46 -05:00
William Wernert
ba621639bd
Merge pull request #6201 from Security-Onion-Solutions/fix/cidr-ip-validation
...
Improve cidr validation in setup and match ip validation to similar method
2021-11-12 13:34:19 -05:00
Wes Lambert
2fb9196604
Move logic above version declaration
2021-11-12 18:26:21 +00:00
Wes Lambert
48c71c8b12
Add soc pillar entry
2021-11-12 18:23:09 +00:00
weslambert
8d185ced61
Merge pull request #6209 from Security-Onion-Solutions/fix/endgame_setup
...
Adjust manager pillar config for Endgame and defaults
2021-11-12 12:27:55 -05:00
William Wernert
9141c271f0
Fix indent
2021-11-12 12:25:32 -05:00
weslambert
bc2e470da9
Fix indentation
2021-11-12 12:20:00 -05:00
weslambert
0f817cd735
Merge pull request #6208 from Security-Onion-Solutions/fix/endgame_pivot
...
Make Endgame pivot independent
2021-11-12 12:17:24 -05:00
weslambert
df5901a65d
Adjust how manager pillar is populated for ENDGAME and default SOC config
2021-11-12 12:16:26 -05:00
weslambert
3cd1b5687e
Make pivot condition independent for ENDGAMEHOST
2021-11-12 12:06:39 -05:00
Josh Patterson
86a42addf0
Merge pull request #6207 from Security-Onion-Solutions/so_elastic_auth_password_reset
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:43:31 -05:00
m0duspwnens
6bf4d5a576
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:37:55 -05:00
William Wernert
efa5eb9f7f
Merge pull request #6184 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-11 13:57:07 -05:00
Josh Patterson
22959f0260
Merge pull request #6195 from Security-Onion-Solutions/issue/6146
...
Issue/6146
2021-11-11 11:47:33 -05:00
m0duspwnens
8da2133cff
give kibana.secrets pillar to import node
2021-11-11 11:31:07 -05:00
William Wernert
1472af4fc3
Merge branch 'dev' into foxtrot
2021-11-11 09:03:05 -05:00
Josh Brower
f91a6d3cb6
Merge pull request #6194 from Security-Onion-Solutions/fix/fleetstandalone
...
Add Fleet Standalone Node to manager ssl
2021-11-11 08:52:29 -05:00
Josh Brower
96f427d924
Add so-fleet to cert requirements
2021-11-11 08:45:22 -05:00
Josh Brower
184356618c
Add Fleet Standalone Node to manager ssl
2021-11-11 08:28:22 -05:00
William Wernert
ed3b2e4569
Put entire ref to doc page on new line
2021-11-10 17:46:35 -05:00
William Wernert
62b41af069
Fix docs link being cut off
2021-11-10 17:17:19 -05:00
William Wernert
569cb24861
Use python lib to make cidr validation more strict
...
Also update ipv4 validation to match the method used to validate cidr strings
2021-11-10 16:53:01 -05:00
William Wernert
ac22df8381
Merge branch 'dev' into foxtrot
2021-11-10 16:51:31 -05:00
Mike Reeves
446d6bd532
Merge pull request #6189 from Security-Onion-Solutions/soup2390
...
Soup2390
2021-11-10 16:49:46 -05:00
Mike Reeves
fcf889be2f
Add soup to 2.3.90
2021-11-10 16:46:24 -05:00
Mike Reeves
8168f19b31
Add soup to 2.3.90
2021-11-10 16:37:54 -05:00
Mike Reeves
ba553d971c
Add soup to 2.3.90
2021-11-10 16:31:44 -05:00
Mike Reeves
9137454a25
Add soup placeholders
2021-11-10 16:08:07 -05:00
m0duspwnens
7ebd861e32
enable secureCookies, security.encryptionKey and reporting.encryptionKey - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-10 16:05:40 -05:00
William Wernert
d110b63050
Merge pull request #6187 from Security-Onion-Solutions/fix/so-rule-modify-example
...
Fix `so-rule modify` example
2021-11-10 14:31:28 -05:00
William Wernert
3806f10f8b
Fix so-rule modify example
2021-11-10 14:18:32 -05:00
Jason Ertel
83bd314a63
Merge pull request #6186 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.2
2021-11-10 14:06:08 -05:00
Jason Ertel
6cd7b252df
Upgrade to ES 7.15.2
2021-11-10 13:59:55 -05:00
Jason Ertel
dea03bbf5e
Upgrade to ES 7.15.2
2021-11-10 13:44:20 -05:00
Josh Brower
9edc543262
Merge pull request #6183 from Security-Onion-Solutions/delta
...
Upgrade FleetDM to 4.5
2021-11-10 11:35:12 -05:00
Josh Brower
d3dc5ffc5a
Fix salt syntax
2021-11-10 11:28:48 -05:00
William Wernert
2c296e832f
Remove references to CURCLOSEDAYS in setup
...
Curator is configured differently now so the variable set during setup is no longer in use
2021-11-10 11:25:51 -05:00
Josh Brower
b350174df1
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-11-10 11:08:36 -05:00
Josh Brower
67ebfeab16
Disable FleetDM usage stats
2021-11-10 10:49:56 -05:00
Josh Brower
435f430747
Fix enroll secret parsing
2021-11-10 10:24:53 -05:00
Josh Patterson
aa9e1701f0
Merge pull request #6180 from Security-Onion-Solutions/issue/5794
...
timeout wazuh-register-agent faster
2021-11-10 09:58:05 -05:00
m0duspwnens
02d9b87f66
https://github.com/Security-Onion-Solutions/securityonion/issues/5794
2021-11-10 09:54:51 -05:00
Josh Patterson
cfd46c1e58
Merge pull request #6176 from Security-Onion-Solutions/bravo
...
Grafana improvements, pillarize kibana
2021-11-10 09:18:47 -05:00
m0duspwnens
392305e4ed
add engame changes that were missing from merge somehow
2021-11-10 09:01:42 -05:00
m0duspwnens
5ff14ab652
Merge remote-tracking branch 'origin/issue/6007' into bravo
2021-11-09 18:31:56 -05:00
m0duspwnens
1890c7244a
set elasticsearch:auth to persist through user pw change
2021-11-09 18:25:17 -05:00
m0duspwnens
a8c4ed7bbf
set elasticsearch:auth:enabled True in auth pillar
2021-11-09 18:05:05 -05:00
m0duspwnens
91f54537d7
handle elasticsearch.auth state like kibana.secrets
2021-11-09 17:52:38 -05:00
m0duspwnens
7e3a4656aa
change xpack update
2021-11-09 17:33:09 -05:00
m0duspwnens
8a04fcd919
change how key is added
2021-11-09 17:07:20 -05:00
m0duspwnens
409ab623a5
ensure kibana pillar dir exists
2021-11-09 16:49:45 -05:00
m0duspwnens
ac85d1598e
dont show changes
2021-11-09 16:44:54 -05:00
m0duspwnens
4c8e68e014
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-11-09 16:42:47 -05:00
m0duspwnens
57c6e26634
encrypt kibana saved objects - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-09 16:41:25 -05:00
m0duspwnens
b6a1d7418e
fix typo, dont show changes for kibana.yaml or dashboard so
2021-11-09 16:14:48 -05:00
weslambert
6eb1a0b0ae
Merge pull request #6169 from Security-Onion-Solutions/fix/ingest_dynamic_ref
...
Add dynamic conf to config change check
2021-11-09 16:11:38 -05:00
weslambert
9301b8f5b9
Add dynamic conf to config change check
2021-11-09 15:56:52 -05:00
m0duspwnens
202977a323
create so script to load saved object defaults
2021-11-09 15:54:15 -05:00
weslambert
9597373e4a
Merge pull request #6167 from Security-Onion-Solutions/ecs_pipeline_common
...
Add config for dynamically formatted ingest pipelines
2021-11-09 15:41:43 -05:00
Wes Lambert
f80b70e008
Add config for dynamically formatted ingest pipelines
2021-11-09 20:07:53 +00:00
William Wernert
04d2b52306
Fix IP route whiptail error
2021-11-09 14:03:32 -05:00
m0duspwnens
af7830c2be
remove reference to saved_objects in defaults
2021-11-09 13:52:47 -05:00
m0duspwnens
3c3cb47b88
merge with dev
2021-11-09 13:07:35 -05:00
m0duspwnens
da4e92a7a3
change config id
2021-11-09 12:13:28 -05:00
Mike Reeves
3afb0bd263
Merge pull request #6161 from Security-Onion-Solutions/sslchange
...
Enable Subject Alt Name for registry
2021-11-09 10:53:38 -05:00
Josh Brower
f6e6b20392
Add Name and OrgName to Fleet setup
2021-11-09 09:20:47 -05:00
William Wernert
3835a4401e
Merge pull request #6157 from Security-Onion-Solutions/foxtrot
...
Fix preflight script on centos
2021-11-09 08:49:46 -05:00
William Wernert
4bae57d994
Fix preflight printing to log
2021-11-09 08:34:02 -05:00
William Wernert
ea7289d92e
Fix preflight script on centos
2021-11-09 08:20:19 -05:00
m0duspwnens
48eaf190e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6007
2021-11-08 17:00:06 -05:00
m0duspwnens
497de0fede
hide vars on pipeline overview
2021-11-08 16:54:39 -05:00
m0duspwnens
70e3bc7eb8
hide vars on pipeline overview
2021-11-08 16:52:15 -05:00
Mike Reeves
eefc9cfcb6
Enable Subject Alt Name for registry
2021-11-08 16:50:43 -05:00
m0duspwnens
42b8955883
panel cleanup
2021-11-08 16:33:57 -05:00
m0duspwnens
f6b753b805
panel cleanup
2021-11-08 16:26:41 -05:00
m0duspwnens
17fc03a553
pipleine overview tc changes
2021-11-08 16:15:42 -05:00
weslambert
8bf88043ac
Merge pull request #6149 from Security-Onion-Solutions/add_test_pipeline
...
Add ECS testing pipeline
2021-11-08 15:43:03 -05:00
m0duspwnens
79640342f2
update redis queue query
2021-11-08 15:20:28 -05:00
Mike Reeves
3ad47742bd
Merge pull request #6150 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2021-11-08 15:18:35 -05:00
Mike Reeves
a8c02252dc
Update acng.conf
2021-11-08 15:16:05 -05:00
m0duspwnens
fbef420155
update redis queue query
2021-11-08 15:15:53 -05:00
m0duspwnens
ccd84e441d
add redis queue to pipeline overview
2021-11-08 15:09:46 -05:00
Wes Lambert
46d3eb452d
Add ECS testing pipeline
2021-11-08 20:08:56 +00:00
Josh Brower
083d467aa9
Update to FleetDM 4.5
2021-11-08 15:05:58 -05:00
m0duspwnens
f026ac1b41
pipeline overview tc changes
2021-11-08 15:02:52 -05:00
m0duspwnens
9ea292b11e
fix query
2021-11-08 13:48:33 -05:00
m0duspwnens
e2ee460fdd
fix gridPos
2021-11-08 12:39:23 -05:00
m0duspwnens
5b70ff61d1
fix gridPos
2021-11-08 12:37:03 -05:00
m0duspwnens
3b2ca89852
use endif not fi
2021-11-08 12:20:07 -05:00
m0duspwnens
199c97684c
fix nontc name in defaults
2021-11-08 12:10:23 -05:00
m0duspwnens
d67e34dac4
add pipeline overview for true cluster
2021-11-08 12:09:35 -05:00
William Wernert
49a573074e
Merge pull request #6142 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-08 11:29:58 -05:00
William Wernert
6c16d6d222
Update invalid hostname message
2021-11-08 11:15:28 -05:00
William Wernert
acba82d194
Update dist install menus' top text
2021-11-08 11:04:51 -05:00
William Wernert
f66d915f5d
Normal hostname check already checks for localhost
2021-11-08 10:38:30 -05:00
William Wernert
ee2dd75dfd
Fix variable ref
2021-11-08 10:36:36 -05:00
William Wernert
50b7779d6e
Make manager hostname error more specific
2021-11-08 10:35:28 -05:00
William Wernert
ad71485361
Fix whiptail height
2021-11-08 10:21:55 -05:00
William Wernert
8b2cccdf4a
More whiptail formatting
2021-11-08 10:21:17 -05:00
William Wernert
dbe4a7de63
Fix new whiptail layouts
2021-11-08 10:19:38 -05:00
William Wernert
9c4bba9ac9
Fix variable reference
2021-11-08 10:08:23 -05:00
Doug Burks
b3fd7c548c
Merge pull request #6135 from Security-Onion-Solutions/dougburks-patch-1
...
Improve clarity in CONTRIBUTING.md
2021-11-08 08:53:50 -05:00
Doug Burks
dcf6dfb676
Improve clarity
2021-11-08 06:38:16 -05:00
William Wernert
246d41c552
Add additional checks for manager hostname + ip
...
Check for current hostname, ip, and localhost (ip + string) when setting the manager ip and hostname
2021-11-05 15:56:08 -04:00
William Wernert
988932293f
Whiptail changes
...
* Ask whether to join to or create new dist install
* Also add links to architecture on install type prompts
2021-11-05 15:54:17 -04:00
m0duspwnens
0b28e89f3c
change how telegraf script determine if there is already and instance of the script already running
2021-11-04 23:22:13 -04:00
m0duspwnens
665732bd32
dont show points
2021-11-04 14:23:11 -04:00
m0duspwnens
b599b49630
enable beat input plugin for telegraf
2021-11-04 13:52:45 -04:00
m0duspwnens
edb3b602a9
pipeline overview dashboard changs
2021-11-04 10:59:01 -04:00
William Wernert
a4289b7ab9
Merge pull request #6107 from Security-Onion-Solutions/foxtrot
...
Manage docker gid and run preflight check during setup
2021-11-04 10:07:05 -04:00
Mike Reeves
9b0ce8b395
Merge pull request #6090 from Security-Onion-Solutions/commonupdate
...
Make common template honor replicas
2021-11-03 14:04:19 -04:00
m0duspwnens
05456b38d1
update panel
2021-11-03 13:54:05 -04:00
m0duspwnens
4fc58e7a5a
update panel
2021-11-03 13:51:57 -04:00
Mike Reeves
dc07aba63d
Update so-common-template.json.jinja
2021-11-03 13:50:31 -04:00
m0duspwnens
f1d66e2d51
change searchnode var
2021-11-03 13:40:09 -04:00
m0duspwnens
fab0dd2bad
add repeating es ingest panel for nontc
2021-11-03 13:25:42 -04:00
Mike Reeves
747f14d60e
Make common template honor replicas
2021-11-03 13:11:38 -04:00
William Wernert
fb35ff40b4
Just hide whiptail cancel message on test installs
2021-11-03 10:41:44 -04:00
m0duspwnens
2cb31a4c05
fix query
2021-11-03 09:27:02 -04:00
m0duspwnens
32f986c505
change panel
2021-11-03 09:23:21 -04:00
m0duspwnens
c8ee67f354
update panel for pipeline_overview
2021-11-03 09:12:32 -04:00
m0duspwnens
db80315c06
rename panel
2021-11-03 08:37:33 -04:00
m0duspwnens
8e3b08a831
start of pipeline dashboard
2021-11-03 08:33:20 -04:00
m0duspwnens
677f62ebd1
dont show changes for telegraf conf
2021-11-02 18:22:37 -04:00
William Wernert
d927e79154
Exit on failed preflight check during testing
2021-11-02 16:17:08 -04:00
William Wernert
8670aa6cd8
Run check-update in preflight instead of update
2021-11-02 14:29:58 -04:00
William Wernert
7c7c225a41
Fix tmp file check
2021-11-02 14:01:21 -04:00
m0duspwnens
54b034b537
fix spacing on es input
2021-11-02 13:43:59 -04:00
m0duspwnens
2232759fa4
rename file
2021-11-02 12:21:54 -04:00
m0duspwnens
f65eea6a03
rename file
2021-11-02 12:09:32 -04:00
William Wernert
e4a77acfe6
Move whiptail menus outside of progress func
2021-11-02 12:03:42 -04:00
William Wernert
9671dab2a3
Make so-preflight executable
2021-11-02 11:48:24 -04:00
William Wernert
e6adb46364
Run so-preflight during setup
2021-11-02 11:18:23 -04:00
m0duspwnens
7abb2e5935
monitor interface graph total
2021-11-02 11:07:29 -04:00
m0duspwnens
561f86eac8
change eps graphs to use logstash data and not consumptioneps script
2021-11-02 11:06:29 -04:00
William Wernert
9a9d1480de
Manage docker group's gid to prevent gid overlap
2021-11-02 10:41:36 -04:00
Josh Brower
8b52f87a60
Merge pull request #6066 from Security-Onion-Solutions/fix/evtx-import-elastic-creds
...
Fix/evtx import elastic creds
2021-11-02 09:25:25 -04:00
Josh Brower
a6f399acf4
Fix evtx import logging
2021-11-02 09:19:32 -04:00
Josh Brower
3534256517
Add evtx import logging
2021-11-02 09:03:52 -04:00
m0duspwnens
b109d95d6f
add max to zeek capture loss legend
2021-11-02 09:02:48 -04:00
Josh Brower
b756c0cd38
Pull ES Creds at Runtime
2021-11-02 08:57:11 -04:00
m0duspwnens
3517ea3f2a
select last value for cpucount var
2021-11-02 08:41:57 -04:00
m0duspwnens
5d414c8bdd
remove logstash row from manager
2021-11-02 08:36:13 -04:00
Josh Brower
2b56b53c15
Merge pull request #6064 from Security-Onion-Solutions/feature/support_non-wel_beats
...
Support non-WEL Beats
2021-11-02 08:29:48 -04:00
Josh Brower
2ba619144c
Support non-WEL Beats
2021-11-02 08:23:29 -04:00
m0duspwnens
a9be0a0409
create and add mon traffic combined graph to sensor dash
2021-11-02 07:55:39 -04:00
m0duspwnens
bf116d210e
mostly overview dash panel changes
2021-11-01 17:48:02 -04:00
William Wernert
f8b62b63f9
Merge pull request #6061 from Security-Onion-Solutions/foxtrot
...
Fix NIC string values for VLAN tagged interfaces
2021-11-01 16:43:52 -04:00
m0duspwnens
f4d9455872
revert to b63b50d98c
2021-11-01 16:10:13 -04:00
m0duspwnens
936c796b9d
Revert "graph changes"
...
This reverts commit 8857fca797 .
2021-11-01 15:19:50 -04:00
m0duspwnens
8ff122262c
Revert "update many panels"
...
This reverts commit b63b50d98c .
2021-11-01 14:50:57 -04:00
m0duspwnens
c4a1fbd82a
remove old json
2021-11-01 14:39:03 -04:00
m0duspwnens
8857fca797
graph changes
2021-11-01 14:36:41 -04:00
m0duspwnens
b63b50d98c
update many panels
2021-11-01 14:06:01 -04:00
William Wernert
c17187708e
Merge branch 'dev' into foxtrot
2021-11-01 12:46:43 -04:00
Mike Reeves
095e6bd48c
Merge pull request #6044 from Burak-PLT/patch-1
...
Update auth.sls
2021-11-01 10:22:16 -04:00
m0duspwnens
c4b9244f9a
add gridPos
2021-10-29 17:24:50 -04:00
m0duspwnens
2ba548fcfc
grafana bug fixes and improvements - https://github.com/Security-Onion-Solutions/securityonion/issues/6007
2021-10-29 17:11:51 -04:00
William Wernert
f76a52b2ee
Fix NIC string values for VLAN tagged interfaces
2021-10-29 13:34:23 -04:00
William Wernert
b555ad16da
Merge pull request #6052 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-10-29 10:52:51 -04:00
William Wernert
b1c67f696e
Re-order logic to maintain backwards compatibility
2021-10-29 10:47:05 -04:00
William Wernert
d08149f728
Don't set INTERWEBS variable on automated minions
2021-10-29 10:11:47 -04:00
William Wernert
a5cba5ecf8
Merge branch 'dev' into foxtrot
2021-10-29 10:01:46 -04:00
Burak-PLT
f081938be5
Update auth.sls
...
Change default password lengths to 72 characters from 20.
2021-10-28 16:00:58 -04:00
William Wernert
c2b18efdbb
Minions still need to be ISO installs to be airgap
2021-10-28 11:59:42 -04:00
William Wernert
6b480a5ba4
Change airgap check to something that doesn't require root
2021-10-28 11:51:50 -04:00
William Wernert
d6eeb0b735
Gen ssh key sooner
2021-10-28 10:04:03 -04:00
Josh Patterson
3000c57428
Merge pull request #6039 from Security-Onion-Solutions/issue/5759
...
Issue/5759
2021-10-28 09:24:44 -04:00
m0duspwnens
5c5b4004e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/5759
2021-10-28 08:52:04 -04:00
Josh Patterson
05e0f92ec5
Merge pull request #6036 from Security-Onion-Solutions/issue/5955
...
include ssl state in telegraf state
2021-10-28 08:50:57 -04:00
m0duspwnens
0cea5e8f22
include ssl state in telegraf state
2021-10-28 08:46:27 -04:00
m0duspwnens
7eb42fa6bd
change boolean
2021-10-28 08:43:03 -04:00
m0duspwnens
18ce9c7819
disable zeekpacketlosscron and telegraf checks if zeek is diabled via pillar
2021-10-28 07:46:02 -04:00
Mike Reeves
b3e5319806
Merge pull request #6028 from Security-Onion-Solutions/telecluster
...
Enable cluster stats
2021-10-27 16:37:42 -04:00
Mike Reeves
c8c8cf203f
Enable cluster stats
2021-10-27 15:44:52 -04:00
Josh Patterson
19056b9177
Merge pull request #6027 from Security-Onion-Solutions/issue/5955
...
Issue/5955
2021-10-27 15:07:22 -04:00
William Wernert
75490a2536
Fix typo
2021-10-27 14:59:24 -04:00
William Wernert
eee612e73d
Make folder/file states explicit
...
Rather than using /nsm/zeek (max_depth: 1) create explicit states for /nsm/zeek/spool and /nsm/zeek/spool/state.db that set correct ownership
2021-10-27 11:43:09 -04:00
William Wernert
9e9079f9cb
Reorder airgap prompt and add additional logic
...
Setup should now only ask the user whether to setup as airgap on manager-type installs. For all distributed minions setup will now inherit the airgap boolean from the manager.
2021-10-27 11:03:00 -04:00
William Wernert
331801eec2
Merge branch 'dev' into foxtrot
2021-10-27 10:58:16 -04:00
William Wernert
a0216cea57
Merge pull request #6021 from Security-Onion-Solutions/fix/update-mysql-root-user
...
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:55:11 -04:00
m0duspwnens
e7f43cff5e
limit nodes that bind filebeat certs in so-logstash
2021-10-27 10:45:10 -04:00
William Wernert
90d473f2d6
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:42:33 -04:00
m0duspwnens
bf403a8307
only manager nodes get cert, key and att&ck binds
2021-10-27 09:47:12 -04:00
m0duspwnens
58d62f29ea
include ssl state in registry state
2021-10-26 11:55:47 -04:00
Mike Reeves
bcf03773c0
Merge pull request #6009 from Security-Onion-Solutions/stenoports
...
Remove port bindings for steno
2021-10-26 10:58:11 -04:00
m0duspwnens
c0dd9efd9b
change so-thehive-es binds and requires
2021-10-26 10:50:16 -04:00
m0duspwnens
36ae07b78e
change timeout from 60 to 120
2021-10-26 10:49:50 -04:00
Mike Reeves
d77328608e
Remove port bindings for steno
...
Steno runs in host mode so port bindings are not required
2021-10-26 10:23:33 -04:00
m0duspwnens
682cbfd223
remove the mode
2021-10-26 09:23:24 -04:00
m0duspwnens
fa2edb2b59
make cortex_init and hive_init time out after 1 minutes vs 5 minutes
2021-10-26 08:39:30 -04:00
m0duspwnens
0c679b62b2
Merge remote-tracking branch 'remotes/origin/dev' into issue/5955
2021-10-25 16:29:41 -04:00
m0duspwnens
7e8d74e770
just use mode
2021-10-25 15:50:27 -04:00
m0duspwnens
9a78d13bee
change perms on mysql
2021-10-25 15:37:23 -04:00
Jason Ertel
c469d12a49
Merge pull request #6002 from Security-Onion-Solutions/kilo
...
Update whiptail links to use latest docs
2021-10-25 15:08:31 -04:00
Jason Ertel
d5f42e0d7c
Update whiptail links to use latest docs
2021-10-25 15:06:42 -04:00
weslambert
926551d398
Merge pull request #5998 from Security-Onion-Solutions/fix/hl_host_name
...
Rename HTTP client headers and host
2021-10-25 13:21:11 -04:00
weslambert
3be0d05eea
Update field removal based on HTTP input changes
2021-10-25 13:16:30 -04:00
weslambert
7fa43a276a
Rename default headers and host for HTTP input
2021-10-25 13:15:20 -04:00
William Wernert
2bfedbd581
Merge pull request #5996 from Security-Onion-Solutions/fix/escape-node-desc
...
Escape single quotes and allow for any character in node description
2021-10-25 10:53:36 -04:00
William Wernert
dca30146ab
Merge branch 'dev' into foxtrot
2021-10-25 10:50:25 -04:00
William Wernert
6e34905b42
Escape single quotes and allow for any character in node description
2021-10-25 10:48:09 -04:00
m0duspwnens
ee7e714f43
change to file_mode
2021-10-22 16:55:23 -04:00
m0duspwnens
d7e5377a44
more requires
2021-10-22 16:46:45 -04:00
William Wernert
38b16a507b
Update ip for root user in mysql when running so-ip-update
2021-10-22 15:29:32 -04:00
William Wernert
17af513692
Escape single quotes and allow for any character in node description
2021-10-22 15:28:37 -04:00
m0duspwnens
283f7296bc
fix require
2021-10-22 14:45:22 -04:00
m0duspwnens
9f6407fcb0
fix dupe ids
2021-10-22 14:26:04 -04:00
m0duspwnens
f61400680d
fix dupe ids
2021-10-22 14:22:15 -04:00
m0duspwnens
fed8bfac67
more requires on docker containers
2021-10-22 14:10:59 -04:00
William Wernert
62971d8c15
Add Fleet custom hostname to end summary
2021-10-22 11:57:47 -04:00
William Wernert
352e30f9e1
Add CUSTOM_FLEET_HOSTNAME to subjectAltName of fleet.key
...
Resolves #4319
2021-10-22 11:16:29 -04:00
m0duspwnens
451b19dc4d
change from file to x509
2021-10-22 09:53:20 -04:00
William Wernert
d5d970672d
Merge pull request #5974 from Security-Onion-Solutions/foxtrot
...
Add so-deny script + rewrite so-allow to match
2021-10-21 16:37:05 -04:00
m0duspwnens
f93c6146f5
docker binds requires
2021-10-21 15:24:55 -04:00
weslambert
40dd33affe
Merge pull request #5971 from Security-Onion-Solutions/feature/es_templates
...
Add .keyword subfield for conflict fields
2021-10-21 15:07:00 -04:00
William Wernert
f374dcbb58
Check for IP environment variable in so-allow and so-deny
2021-10-21 13:54:06 -04:00
weslambert
77ee1db44c
Add .keyword subfield for conflict fields
2021-10-21 12:56:03 -04:00
Josh Patterson
8784d65023
Merge pull request #5967 from Security-Onion-Solutions/issue/5954
...
require files before starting soc or kratos
2021-10-21 11:15:36 -04:00
William Wernert
15fe7512b7
Install lxml during setup and in common state
2021-10-21 10:49:41 -04:00
William Wernert
0beeeb94bf
Actually add new so-allow script
2021-10-21 10:48:17 -04:00
m0duspwnens
928aed27c5
require files before starting soc or kratos
2021-10-20 17:04:02 -04:00
William Wernert
387d4d6ad5
Add so-deny script + rewrite so-allow to match so-deny
2021-10-20 16:44:57 -04:00
William Wernert
adf6cb4b3c
Merge branch 'dev' into foxtrot
2021-10-20 16:44:50 -04:00
William Wernert
0ed2ce0766
Fix validation.sh tests
2021-10-20 16:44:09 -04:00
William Wernert
b5cb47e066
Fix sbin perms
2021-10-20 16:43:55 -04:00
Josh Patterson
8061508330
Merge pull request #5961 from Security-Onion-Solutions/issue/5960
...
Issue/5960
2021-10-20 16:08:50 -04:00
m0duspwnens
adffb11800
fix redis port
2021-10-20 15:39:21 -04:00
m0duspwnens
8619af59cc
servers to list format
2021-10-20 15:02:33 -04:00
m0duspwnens
7ecfb55b70
fix pillar call
2021-10-20 14:50:50 -04:00
m0duspwnens
b496810b63
add redis and logstash input plugins to telegraf
2021-10-20 14:46:47 -04:00
Mike Reeves
e1ad02c28d
Merge pull request #5949 from Security-Onion-Solutions/kilo
...
Fix Docker-created corruption of SOC user roles file
2021-10-19 18:37:37 -04:00
Jason Ertel
2f8bb5a2a6
Fix Docker-created corruption of SOC user roles file
2021-10-19 16:04:10 -04:00
weslambert
6f3e441bf7
Merge pull request #5945 from Security-Onion-Solutions/fix/soc_index_pattern
...
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:05:40 -04:00
Mike Reeves
7f1585dcc0
Merge pull request #5942 from Security-Onion-Solutions/tunesteno
...
Fix Steno Math for PL
2021-10-19 13:03:50 -04:00
weslambert
9453ed7fa1
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:01:40 -04:00
Mike Reeves
64f25961b0
Fix Steno Math for PL
2021-10-19 11:15:58 -04:00
Mike Reeves
b9a3d3a6a9
Fix Steno Math for PL
2021-10-19 11:14:02 -04:00
m0duspwnens
36cb0d6c42
remove space
2021-10-18 14:34:33 -04:00
m0duspwnens
1b2268dfe5
load kibana configs during setup
2021-10-18 14:30:47 -04:00
Mike Reeves
00e5b54dda
Merge pull request #5911 from Security-Onion-Solutions/tunesteno
...
Add Steno Tuning Options
2021-10-18 09:01:14 -04:00
Mike Reeves
4016b416ec
Merge pull request #5923 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.1
2021-10-16 09:15:06 -04:00
weslambert
7590728a0b
Merge pull request #5915 from Security-Onion-Solutions/feature/ti_module
...
Add TI module
2021-10-15 17:17:33 -04:00
weslambert
bb36fc1ed8
Add TI module defaults
2021-10-15 17:16:38 -04:00
weslambert
d0a6dafc8b
Add TI module
2021-10-15 17:09:59 -04:00
m0duspwnens
76097476d3
remove includes
2021-10-15 16:57:38 -04:00
m0duspwnens
8b3b0bf160
fix opts
2021-10-15 16:51:11 -04:00
m0duspwnens
f19680b3e6
fix opts
2021-10-15 16:50:03 -04:00
m0duspwnens
7e1bbe3cc2
define MAANGER
2021-10-15 16:14:14 -04:00
m0duspwnens
947285e932
update cmd.run amd s_o files
2021-10-15 16:06:25 -04:00
m0duspwnens
1741f5068a
update config-load to do an update or import
2021-10-15 15:35:30 -04:00
Mike Reeves
a9f6c84d7c
Add Steno Tuning Options
2021-10-15 14:17:54 -04:00
weslambert
59852841ff
Add keyword subfield for event.module
2021-10-15 13:29:50 -04:00
weslambert
6f1f7d2a63
Merge pull request #5905 from Security-Onion-Solutions/feature/soc_es_index_pattern
...
Allow setting ES index patterns for SOC in pillar
2021-10-15 13:28:04 -04:00
Jason Ertel
8de8d58155
Upgrade to ES 7.15.1
2021-10-15 13:27:08 -04:00
Wes Lambert
8feeff97b5
Add EG index pattern during setup (if enabled)
2021-10-15 16:19:19 +00:00
Wes Lambert
032373187c
Allow setting ES index patterns for SOC in pillar
2021-10-15 16:02:53 +00:00
William Wernert
db2b70f655
Merge pull request #5900 from Security-Onion-Solutions/foxtrot
...
Replace rather than append to Kibana misc log
2021-10-15 10:27:25 -04:00
Jason Ertel
1800ec4570
Upgrade to Elastalert 2 v2.2.2
2021-10-15 09:25:44 -04:00
Mike Reeves
8a5960c220
Merge pull request #5896 from Security-Onion-Solutions/kilo
2021-10-14 18:05:33 -04:00
Jason Ertel
9797a15218
Fix issue with 'so-user delete' resetting all user roles - note that this function is not technically supported or published since it's not intended for production use
2021-10-14 17:23:18 -04:00
William Wernert
c7b15a9b1f
Replace rather than append to Kibana misc log
2021-10-14 15:13:55 -04:00
William Wernert
cba97802fe
Fix indent
2021-10-14 15:13:34 -04:00
William Wernert
025256aeaf
Merge pull request #5890 from Security-Onion-Solutions/foxtrot
...
Misc setup changes
2021-10-14 14:55:24 -04:00
weslambert
490f7eaf81
Merge pull request #5886 from Security-Onion-Solutions/feature/eg_pivot
...
Add EG pivot
2021-10-14 14:49:38 -04:00
m0duspwnens
6a2bf11a75
change format of file
2021-10-14 13:43:39 -04:00
m0duspwnens
78d30285b1
seperate securitySolutions load
2021-10-14 13:24:51 -04:00
Wes Lambert
f1fafa015e
Add EG to list of groups to include 127.0.0.1
2021-10-14 16:27:28 +00:00
Wes Lambert
6cdc214582
Add pillar in setup and change name of EG variable
2021-10-14 15:33:37 +00:00
Wes Lambert
15049f44b9
Add EG pivot
2021-10-14 15:15:23 +00:00
Doug Burks
42a642b85c
Merge pull request #5873 from petiepooo/enh-rediscount-tty
...
featreq: remove tty flag in redis-count script
2021-10-14 10:07:07 -04:00
weslambert
3b45e68ead
Merge pull request #5885 from Security-Onion-Solutions/feature/jinjafy_soc_actions
...
Allow SOC actions to use Jinja
2021-10-14 10:03:12 -04:00
Wes Lambert
5ee0ea3fe7
Allow SOC actions to use Jinja
2021-10-14 13:59:55 +00:00
weslambert
55c60f485c
Merge pull request #5884 from Security-Onion-Solutions/feature/hl_eg
...
Add EG firewall allowance via setup
2021-10-14 09:55:07 -04:00
Wes Lambert
78e88e0765
Add EG firewall allowance via setup
2021-10-13 21:42:54 +00:00
Wes Lambert
a9b250c0f4
Add EG firewall config
2021-10-13 21:37:59 +00:00
m0duspwnens
ae9753326a
fix var, quote vars
2021-10-13 16:38:01 -04:00
m0duspwnens
c8fb504ee0
Revert "Merge remote-tracking branch 'remotes/origin/dev' into issue/3933"
...
This reverts commit 54eec92621 , reversing
changes made to 7832e59629 .
2021-10-13 15:22:46 -04:00
m0duspwnens
54eec92621
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 15:19:33 -04:00
m0duspwnens
7832e59629
only load default kibana saved_objects during setup
2021-10-13 15:19:20 -04:00
weslambert
f9001654bb
Merge pull request #5871 from Security-Onion-Solutions/feature/hl_eg
...
Initial EG stuff
2021-10-13 15:07:03 -04:00
Wes Lambert
2a504a061b
Add Curator action files for EG indices
2021-10-13 18:40:34 +00:00
m0duspwnens
bb9c6446e4
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 14:01:36 -04:00
Pete
e7581036f7
remove tty/interactive flags
...
This call to docker exec simply returns a number. No interaction (stdin) or tty is required. Specifically, having the -t option prevents running via salt using a command such as:
> salt '*' cmd.run 'so-redis-count'
2021-10-13 13:51:05 -04:00
Wes Lambert
e1629d7ec4
Initial EG stuff
2021-10-13 17:13:07 +00:00
Josh Patterson
b4873bd296
Merge pull request #5868 from Security-Onion-Solutions/issue/5818
...
Issue/5818
2021-10-13 12:52:48 -04:00
m0duspwnens
3044edb104
update comment
2021-10-13 12:38:58 -04:00
m0duspwnens
a495779552
only 3 attempts with 120s max attemps
2021-10-13 12:34:56 -04:00
m0duspwnens
880c1b97b0
remove $ from var
2021-10-13 12:25:11 -04:00
m0duspwnens
7a4fa8879c
change count, attempts and timeout
2021-10-13 12:13:24 -04:00
m0duspwnens
adb8292814
add missing )
2021-10-13 10:37:18 -04:00
m0duspwnens
6e7a5fa326
add timeouts to check_salt_minion_status and check_salt_master_status - https://github.com/Security-Onion-Solutions/securityonion/issues/5818
2021-10-13 09:45:15 -04:00
m0duspwnens
23ea53248d
single line format
2021-10-12 14:15:37 -04:00
m0duspwnens
f1a5991699
add securitySolution.defaultIndex to defaults
2021-10-12 12:35:13 -04:00
m0duspwnens
c69ad091f7
update saved_objects config
2021-10-12 12:02:30 -04:00
William Wernert
b97361fab9
Remove references to xenial in setup
...
Resolves #4292
2021-10-12 10:23:39 -04:00
William Wernert
36e1795295
Add end of setup log messages per #5032
2021-10-12 10:19:47 -04:00
m0duspwnens
498e385484
change name to SAVED_OBJECTS
2021-10-12 10:15:39 -04:00
William Wernert
af687b0706
Remove all holds on Ubuntu reinstall
2021-10-12 10:10:34 -04:00
m0duspwnens
19489f3626
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-12 10:07:40 -04:00
m0duspwnens
89d1df8a1d
change name to SAVED_OBJECTS
2021-10-12 10:07:26 -04:00
William Wernert
946cf81a27
If ANALYST is selected immediately quit setup
2021-10-12 09:48:38 -04:00
Mike Reeves
2561480371
Merge pull request #5850 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.7.6-alpha.1
2021-10-12 08:19:25 -04:00
Jason Ertel
d21dee162d
Add Note field to user traits; Enforce max length restrictions on email, firstname, lastname, and note fields
2021-10-08 12:39:17 -04:00
Mike Reeves
444d067112
Merge pull request #5813 from Security-Onion-Solutions/macleod
...
Highlander changes
2021-10-08 10:06:18 -04:00
Mike Reeves
2a82373051
highlander fixes
2021-10-08 09:32:13 -04:00
Mike Reeves
64758a534c
Set ml to true
2021-10-08 08:42:26 -04:00
m0duspwnens
7517a63008
disabled ml
2021-10-07 13:06:52 -04:00
m0duspwnens
b2facdf31c
add securitySolutions advanced setting
2021-10-07 12:57:28 -04:00
m0duspwnens
4c54d6309c
change host to 0.0.0.0
2021-10-07 09:59:29 -04:00
Jason Ertel
62c3afc81d
Migrate users from locked to inactive during soup
2021-10-06 15:45:35 -04:00
Jason Ertel
7d8c8144b0
Drop obsolete status trait
2021-10-06 12:52:41 -04:00
Jason Ertel
a2c4fce1ef
Switch to use state attribute in identities for enabling/disabling users
2021-10-06 11:53:10 -04:00
m0duspwnens
599aba43d9
restart so-kibaba if config changes
2021-10-06 09:51:16 -04:00
m0duspwnens
fa4f92cdda
change defaults
2021-10-05 17:35:44 -04:00
m0duspwnens
5d98c0d14c
fix dict update
2021-10-05 15:57:57 -04:00
Mike Reeves
27614569e3
Fix set
2021-10-05 14:32:02 -04:00
m0duspwnens
ec357cca3c
fix cars
2021-10-05 12:57:30 -04:00
m0duspwnens
26681ac98a
var for dash saved objevs
2021-10-05 12:46:21 -04:00
m0duspwnens
748f0f2a1d
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-05 12:12:56 -04:00
Mike Reeves
869af548af
Fix spaces for highlander
2021-10-05 11:06:13 -04:00
Mike Reeves
2fd344822d
Add additional roles for highlander
2021-10-05 10:40:40 -04:00
Mike Reeves
a3e0fb127a
Merge pull request #5069 from datlife/datlife/asn-annotation
...
Add ASN annotation for IP
2021-10-05 06:50:31 -04:00
Dat
9569e73bd0
Added ASN annotation for IP
2021-10-04 12:41:20 -07:00
m0duspwnens
96d783b158
merge with dev
2021-10-04 10:39:48 -04:00
m0duspwnens
e0c097c270
add dashboard theme defaults
2021-10-04 10:36:58 -04:00
Mike Reeves
e6fce4cf3e
Merge pull request #5749 from Security-Onion-Solutions/kilo
...
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:55:53 -04:00
Jason Ertel
6ef9a5c95d
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:53:25 -04:00
Mike Reeves
727613b6e1
Merge pull request #5601 from Security-Onion-Solutions/special
...
Ubuntu 20.04 Beta
2021-10-04 08:51:01 -04:00
Mike Reeves
5013aa8490
Merge pull request #5748 from Security-Onion-Solutions/kilo
...
Merge ES Upgrade, Version Bump into dev
2021-10-04 08:48:07 -04:00
Jason Ertel
72a1b299ac
Bump to 2.3.90
2021-10-04 08:44:51 -04:00
Mike Reeves
cfaa0e679c
Merge pull request #5739 from Security-Onion-Solutions/dev
...
2.3.80
2021-10-01 15:15:54 -04:00
Mike Reeves
4ddf2b49ce
Merge pull request #5669 from Security-Onion-Solutions/2.3.80
...
2.3.80
2021-10-01 15:11:03 -04:00
m0duspwnens
bb95963d73
add missing {{}}
2021-09-30 14:40:13 -04:00
m0duspwnens
dfa9afde0e
change to mode
2021-09-30 14:33:52 -04:00
m0duspwnens
fa2333b9ef
change t file.managed
2021-09-30 14:32:28 -04:00
m0duspwnens
8b9c43915d
fix source
2021-09-30 14:30:00 -04:00
m0duspwnens
36832139b2
pillarize kibana
2021-09-30 14:28:31 -04:00
m0duspwnens
c3bf835566
kibana config
2021-09-30 14:23:49 -04:00
m0duspwnens
39d3c7c6ed
begin pillarization of kibana
2021-09-30 11:48:42 -04:00
Jason Ertel
b1a5527e82
Update ElastAlert to use ElastAlert 2
2021-09-28 07:01:47 -04:00
Jason Ertel
d0592c4293
Update ElastAlert to use ElastAlert 2
2021-09-28 00:51:29 -04:00
Mike Reeves
b1d0e3e93f
2.3.80
2021-09-27 12:32:45 -04:00
Mike Reeves
b069377c8a
2.3.80
2021-09-27 10:13:42 -04:00
Jason Ertel
e9a44c6e1b
Merge pull request #5662 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update README.md
2021-09-27 09:28:46 -04:00
Mike Reeves
275163f85d
Update README.md
2021-09-27 07:36:54 -04:00
William Wernert
98f74c25ba
Fix variable reference in so-functions
2021-09-24 12:32:56 -04:00
William Wernert
3064800820
Merge pull request #5636 from Security-Onion-Solutions/fix/soup-2.3.80
...
Misc. soup fixes
2021-09-23 13:03:43 -04:00
William Wernert
f8bea82430
Make redirect consistent with setup
2021-09-23 12:57:08 -04:00
William Wernert
8b905b585d
Fix redirect to append
2021-09-23 12:55:06 -04:00
William Wernert
b44358fc26
Add set +e after final upgrade steps and before post-upgrade checks
2021-09-23 12:49:42 -04:00
William Wernert
8a9dcb7fdb
Fix "upgrade to" message
...
Only specify "to" version and change when the upgrade message occurs
2021-09-23 12:47:22 -04:00
William Wernert
a01d49981c
Redirect thehive/cortex migrate curl output to soup log
2021-09-23 12:45:44 -04:00
William Wernert
b8b1867e52
Tell user what soup is doing at end of upgrade
2021-09-23 12:43:23 -04:00
William Wernert
292ce37ce4
Merge pull request #5632 from Security-Onion-Solutions/fix/logscan-soup
...
Add logscan to images for pull during soup if it's enabled
2021-09-23 10:13:20 -04:00
William Wernert
73dacdcbff
Add logscan to images for pull during soup if it's enabled
2021-09-23 09:52:23 -04:00
Josh Patterson
bea7555464
Merge pull request #5631 from Security-Onion-Solutions/80soup
...
80soup
2021-09-22 16:01:45 -04:00
m0duspwnens
52c1298b9b
notify of custom es config
2021-09-22 15:16:07 -04:00
m0duspwnens
cdb9dcbaec
notify of custom es config
2021-09-22 15:07:36 -04:00
Mike Reeves
37153288e8
Merge pull request #5627 from Security-Onion-Solutions/80soup
...
ignore manager pillar file for noderoutetype
2021-09-22 12:03:55 -04:00
m0duspwnens
edf75255cf
ignore manager pillar file for noderoutetype
2021-09-22 12:01:32 -04:00
Jason Ertel
9eb6f5942e
Merge pull request #5623 from Security-Onion-Solutions/kilo
...
Prevent email addresses from having uppercase characters
2021-09-22 09:10:38 -04:00
Jason Ertel
dae41d279a
Prevent emails addresses from having uppercase characters
2021-09-22 08:25:55 -04:00
Mike Reeves
07288367cf
Merge pull request #5611 from Security-Onion-Solutions/80soup
...
match elasticsearch at beginning of line
2021-09-21 15:42:09 -04:00
m0duspwnens
f4186feffa
move node_route_type
2021-09-21 15:40:49 -04:00
m0duspwnens
d82e91f69e
match elasticsearch at beginning of line
2021-09-21 13:54:45 -04:00
Josh Patterson
a2680fad0a
Merge pull request #5605 from Security-Onion-Solutions/80soup
...
fi xquotes
2021-09-21 13:02:58 -04:00
m0duspwnens
5c2be487f5
fi xquotes
2021-09-21 13:01:40 -04:00
Mike Reeves
531c9de488
Merge pull request #5600 from petiepooo/petiepooo-raidstat-fix
...
missing dollarsign
2021-09-21 11:35:57 -04:00
Pete
19efa493ad
missing dollarsign
2021-09-21 11:21:07 -04:00
Mike Reeves
0db3f14261
Merge pull request #5598 from Security-Onion-Solutions/80soup
...
Soup Changes for True Clusters
2021-09-21 09:57:12 -04:00
Mike Reeves
ed28e4d000
Soup Changes for True Clusters
2021-09-21 09:55:49 -04:00
Mike Reeves
2c8cbf0db1
Soup Changes for True Clusters
2021-09-21 09:53:09 -04:00
Mike Reeves
c1537335b1
Fix Python Problem
2021-09-20 19:05:01 -04:00
Mike Reeves
5f475ff9cb
Fix Python Problem
2021-09-20 18:46:43 -04:00
Mike Reeves
481ffb1cda
Fix Grain
2021-09-20 18:12:18 -04:00
Mike Reeves
50b78681f2
Ubuntu 20.04 Support
2021-09-20 17:24:47 -04:00
Jason Ertel
3924b8f5db
Merge pull request #5586 from Security-Onion-Solutions/kilo
...
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:56:30 -04:00
Jason Ertel
a9049eccd4
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:30:05 -04:00
Mike Reeves
1a7237bcdf
Merge pull request #5583 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2021-09-20 10:44:20 -04:00
Mike Reeves
1e5e1c9ef0
Update soup
2021-09-20 10:42:55 -04:00
Josh Patterson
47cd1ddc0a
Merge pull request #5580 from Security-Onion-Solutions/issue/1257
...
Issue/1257 - Pillarize ES
2021-09-20 09:31:03 -04:00
m0duspwnens
aed73511e4
file cleanup, comment cleanup
2021-09-20 09:24:03 -04:00
Jason Ertel
a3f62c81c3
Merge pull request #5577 from Security-Onion-Solutions/kilo
...
Continuation of auth enhancements
2021-09-20 06:30:36 -04:00
Jason Ertel
730503b69c
Ensure highstate migrates user roles
2021-09-18 23:17:49 -04:00
Jason Ertel
3508f3d8c1
Ensure ES user/role files are generated even if the primary admin user isn't yet created, since the system users are necessary for other installation functions
2021-09-18 19:20:43 -04:00
Jason Ertel
5704906b11
Create empty files for Docker to mount while installation continues
2021-09-18 15:49:05 -04:00
Jason Ertel
357c1db445
Recover from situation where roles file is corrupted
2021-09-18 11:08:35 -04:00
Jason Ertel
5377a1a85e
Recover from situation where roles file is corrupted
2021-09-18 11:06:54 -04:00
Jason Ertel
7f2d7eb038
Continue migration of user emails to IDs
2021-09-18 07:20:34 -04:00
Jason Ertel
30e781d076
Use user ID instead of email as role master
2021-09-17 17:54:38 -04:00
m0duspwnens
01323cc192
fix clustername redirect
2021-09-17 15:44:54 -04:00
m0duspwnens
109c83d8c3
move custom es cluster name pillar location
2021-09-17 15:29:41 -04:00
m0duspwnens
e864bc5404
move custom es cluster name pillar location
2021-09-17 15:28:35 -04:00
Josh Brower
22eb82e950
Merge pull request #5566 from Security-Onion-Solutions/feature/disable_services
...
Add support for disabling Zeek and Suricata
2021-09-17 14:18:03 -04:00
m0duspwnens
b877aa44bc
update dict
2021-09-17 14:10:45 -04:00
Josh Brower
4d307c53e8
Add support for disabling Zeek and Suricata
2021-09-17 13:01:50 -04:00
m0duspwnens
d0c87cd317
allow for pillar override of defaults
2021-09-17 12:11:12 -04:00
m0duspwnens
0d074dafd4
add missing defaults
2021-09-17 09:52:50 -04:00
m0duspwnens
5b77dc109f
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-16 16:54:23 -04:00
m0duspwnens
3ce48acadd
change cluster_settings to config
2021-09-16 16:44:31 -04:00
Jason Ertel
fbd9bab2f1
Split apart roles and users into separate maps
2021-09-16 16:08:55 -04:00
m0duspwnens
5526a2bc3a
reduce defaults.yaml
2021-09-16 15:32:08 -04:00
weslambert
18d81352c6
Merge pull request #5537 from Security-Onion-Solutions/delta
...
Add improved ignore functionality for YARA rules used by Strelka and add default ignored rules that break compilation
2021-09-16 10:38:49 -04:00
m0duspwnens
889d235c45
no box type more manager in true cluster
2021-09-16 09:15:24 -04:00
Jason Ertel
3fc26312e0
Remove x-user-id header from unauthenticated proxied requests
2021-09-16 08:52:31 -04:00
Jason Ertel
b81d38e392
Merge branch 'dev' into kilo
2021-09-16 07:44:35 -04:00
Jason Ertel
82da0041a4
Add limited roles with restricted visibility
2021-09-16 07:44:15 -04:00
m0duspwnens
782b01e76f
seed_hosts to list
2021-09-15 17:07:52 -04:00
m0duspwnens
3bf9685df8
fix seed_hosts append
2021-09-15 17:00:16 -04:00
m0duspwnens
4cf91f6c86
fix dict update
2021-09-15 15:51:00 -04:00
m0duspwnens
a43b37f234
fix dict update
2021-09-15 15:49:18 -04:00
m0duspwnens
e0dc62b6e9
fix dict update
2021-09-15 15:43:47 -04:00
m0duspwnens
c213834316
update the dict
2021-09-15 15:24:40 -04:00
Josh Brower
c06668c68e
Merge pull request #5527 from Security-Onion-Solutions/feature/so-import-evtx
...
Feature/so import evtx
2021-09-15 14:17:15 -04:00
Josh Brower
a75238bc3f
so-import-evtx - fix ingest formatting
2021-09-15 14:13:16 -04:00
Josh Brower
ac417867ed
so-import-evtx - final fixes
2021-09-15 14:06:08 -04:00
m0duspwnens
1614b70853
update cluster name if true cluster
2021-09-15 13:45:43 -04:00
Mike Reeves
0882158e03
Merge pull request #5525 from Security-Onion-Solutions/soup80
...
soup changes 2.3.80
2021-09-15 13:44:54 -04:00
m0duspwnens
1a03853a7c
fix extend
2021-09-15 13:38:29 -04:00
Mike Reeves
aff571faf2
soup changes 2.3.80
2021-09-15 13:32:52 -04:00
m0duspwnens
e0faa4c75b
Merge branch 'issue/1257' of https://github.com/Security-Onion-Solutions/securityonion into issue/1257
2021-09-15 13:09:35 -04:00
m0duspwnens
e3e2e1d851
logic for truecluster to map file
2021-09-15 13:09:04 -04:00
weslambert
2affaf07a2
Merge pull request #5521 from Security-Onion-Solutions/fix/strelka-yara
...
Fix/strelka yara
2021-09-15 11:33:44 -04:00
weslambert
39e5ded58d
Refactor ignore list and only ignore for signature-base for now
2021-09-15 11:32:29 -04:00
weslambert
4d41d3aee1
Ignore these rules by default because they are causing issues with YARA compilation with Strelka
2021-09-15 10:29:11 -04:00
weslambert
5c8067728e
Remove unnecessary logic
2021-09-15 10:22:17 -04:00
Josh Brower
1d905124d3
Merge pull request #5519 from Security-Onion-Solutions/fix/fleet-link
...
Fix Fleet Link Logic
2021-09-15 09:30:21 -04:00
Josh Brower
e0a289182f
Fix Fleet Link Logic
2021-09-15 09:28:23 -04:00
m0duspwnens
551dba955c
set roles empty list
2021-09-15 09:20:33 -04:00
Jason Ertel
9970e54081
Adjust custom_role examples to be more realistic
2021-09-14 14:03:22 -04:00
Jason Ertel
ff989b1c73
Include wording in so-user relating to optional role parameter
2021-09-14 14:03:00 -04:00
Mike Reeves
2ffb723bbd
Rename so-common-template.json to so-common-template.json.jinja
2021-09-14 13:58:45 -04:00
Mike Reeves
6ae2fba71f
Update search.sls
2021-09-14 13:57:26 -04:00
Mike Reeves
2cc25587d9
Update eval.sls
2021-09-14 13:57:04 -04:00
Mike Reeves
614a6dc9fe
Update manager.sls
2021-09-14 13:56:43 -04:00
Josh Brower
4b7667d87f
Merge pull request #5508 from Security-Onion-Solutions/fix/fleet-link
...
Fleet SA - SOC Link Fix
2021-09-14 13:29:20 -04:00
Josh Brower
74b0b365bd
Fleet SA - SOC Link Fix
2021-09-14 13:23:07 -04:00
Josh Brower
0b0d508585
so-import-evtx - tweaks
2021-09-14 12:01:14 -04:00
m0duspwnens
0534a2dda3
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-13 15:04:50 -04:00
m0duspwnens
f8ab0ac8a9
config changes
2021-09-13 15:04:39 -04:00
m0duspwnens
0ae09cc630
config changes
2021-09-13 09:49:56 -04:00
Mike Reeves
332c4dda22
Merge pull request #5469 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Allow so-rule-update to accept any number of args
2021-09-10 14:41:55 -04:00
William Wernert
679faddd52
Update so-rule-update to pass all args to docker exec
...
Instead of passing $1, build a string from all args and add that to the command string for the docker exec statement
2021-09-10 13:44:37 -04:00
William Wernert
0b42b19763
Update so-rule-update to source so-common
2021-09-10 13:41:58 -04:00
William Wernert
943bd3e902
Merge pull request #5468 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Add `--force` flag to idstools-rulecat under so-rule-update
2021-09-10 13:17:16 -04:00
Mike Reeves
4af6a901a1
Merge pull request #5461 from Security-Onion-Solutions/truclusterrator
...
Add new hunt fields
2021-09-10 13:17:01 -04:00
William Wernert
9c310de459
Add --force flag to idstools-rulecat under so-rule-update
...
This forces idstools to pull from the url each time, which prevents it from clearing all.rules if idstools-rulecat is run twice within 15 minutes by any method (either restarting the container or running so-rule-update)
2021-09-10 13:15:09 -04:00
Mike Reeves
4f6a3269cb
Add more detail to syscollector
2021-09-10 09:59:47 -04:00
Doug Burks
6a2e1df7d4
Merge pull request #5460 from Security-Onion-Solutions/feature/welcome-link-docs
...
FEATURE: Add docs link to Setup #5459
2021-09-10 07:27:48 -04:00
doug
db50ef71b4
FEATURE: Add docs link to Setup #5459
2021-09-10 06:19:16 -04:00
Jason Ertel
4e2d5018a2
Merge pull request #5455 from Security-Onion-Solutions/kilo
...
Consolidate whiptail screens
2021-09-09 14:57:28 -04:00
Jason Ertel
94688a9adb
Eliminate adv component popup
2021-09-09 14:29:09 -04:00
Jason Ertel
63f67b3500
Rephrase screen that warns about more RAM requirements
2021-09-09 14:16:05 -04:00
Mike Reeves
eaa5e41651
Merge pull request #5450 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Raid Status for cloud
2021-09-09 11:09:49 -04:00
Mike Reeves
c83f119cc0
Update so-raid-status
2021-09-09 10:59:35 -04:00
Mike Reeves
5d235e932c
Fix Raid Status for cloud
2021-09-09 10:46:28 -04:00
m0duspwnens
93f2cd75a4
add the jinja template
2021-09-09 10:19:46 -04:00
m0duspwnens
f06ab8b77d
testing defaults.yaml
2021-09-09 08:55:36 -04:00
weslambert
03b45512fa
Merge pull request #5436 from Security-Onion-Solutions/fix/kibana_server_url
...
Incude server.publicBaseUrl
2021-09-08 12:13:48 -04:00
weslambert
b8600be0f1
Incude server.publicBaseUrl
2021-09-08 12:12:09 -04:00
Jason Ertel
19a02baa7c
Merge pull request #5425 from Security-Onion-Solutions/kilo
...
Auth enhancements
2021-09-07 13:10:36 -04:00
Jason Ertel
3c59579f99
Add maintenance privilege for analysts to refresh indices
2021-09-07 13:03:30 -04:00
Mike Reeves
3f989590ad
Merge pull request #5402 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Enable index sorting by default but allow it to be disabled
2021-09-07 11:28:40 -04:00
Jason Ertel
72cff7ec7a
Merge branch 'dev' into kilo
2021-09-07 10:49:08 -04:00
Mike Reeves
e3900606dc
Enable index sorting by default but allow it to be disabled
2021-09-04 10:42:18 -04:00
Mike Reeves
a2fd8ae200
Merge pull request #5401 from rwaight/dev
...
Enable index sorting in `so-common-template.json`
2021-09-04 10:32:57 -04:00
Rob Waight
b7591093cf
Add index sorting to so-common-template.json
...
Add index sorting to so-common-template.json
2021-09-04 09:45:03 -04:00
Rob Waight
51439cd1ab
Merge pull request #1 from Security-Onion-Solutions/dev
...
sync with SO/Dev
2021-09-04 09:43:23 -04:00
Jason Ertel
94ea1f856b
Add auditor role; update analyst role with correct syntax
2021-09-03 15:59:48 -04:00
Jason Ertel
fbbb7f4e85
Add auditor role; update analyst role with correct syntax
2021-09-03 15:54:05 -04:00
Mike Reeves
7b3a0cd1e4
Merge pull request #5394 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Add maxfiles to the steno config
2021-09-03 10:49:59 -04:00
Mike Reeves
9fb28709d5
Add maxfiles to the steno config
2021-09-03 10:47:00 -04:00
Jason Ertel
649f339934
Correct typo
2021-09-02 20:30:48 -04:00
Jason Ertel
f659079542
Consolidate password validation messaging
2021-09-02 19:12:32 -04:00
Jason Ertel
ce70380f0f
resolve so-user errors from recent auth changes
2021-09-02 17:59:33 -04:00
Jason Ertel
c4d402d8b4
Ensure role file exists before ES state is run
2021-09-02 15:45:47 -04:00
Mike Reeves
9f5dafd560
More Event Fields
2021-09-02 13:48:18 -04:00
Mike Reeves
1cee603ee4
Squid event fields
2021-09-02 13:24:04 -04:00
William Wernert
a14854d56d
Merge pull request #5383 from Security-Onion-Solutions/feature/soup-y
...
Add logic to check unattended flag when checking OS updates
2021-09-02 11:50:45 -04:00
Mike Reeves
2bf471054b
Cloudtrail Event Fields
2021-09-02 11:46:18 -04:00
William Wernert
56894b9581
Add logic to check unattended flag when checking if updates are available
2021-09-02 11:15:32 -04:00
Jason Ertel
10126bb7ef
Auth enhancements
2021-09-02 09:44:57 -04:00
Jason Ertel
6dfc943e8c
Merge pull request #5382 from Security-Onion-Solutions/kilo
...
Correct invalid password message
2021-09-02 07:15:09 -04:00
Jason Ertel
84ecc3cba7
Merge branch 'dev' into kilo
2021-09-02 07:09:36 -04:00
Jason Ertel
0ad3d826eb
Invalid password message should also mention that dollar signs are not allowed
2021-09-02 07:07:36 -04:00
William Wernert
d785dafe2f
Merge pull request #5374 from Security-Onion-Solutions/feature/soup-y
...
Add unattended soup flag, and iso location argument for air gap
2021-09-01 16:48:55 -04:00
Mike Reeves
e3dffcc2cb
Merge pull request #5373 from Security-Onion-Solutions/truclusterrator
...
Add eventfields for new default logs
2021-09-01 16:48:51 -04:00
Mike Reeves
556bad6925
Add eventfields for new default logs
2021-09-01 15:13:43 -04:00
William Wernert
446821e9fd
Use exit code 0 when printing error message before exiting soup
2021-09-01 15:11:18 -04:00
William Wernert
576c893eb3
Exit on missing file argument
2021-09-01 15:08:53 -04:00
Mike Reeves
34a5d6e56a
Merge pull request #5367 from Security-Onion-Solutions/truclusterrator
...
Allow closing of fb module indices in global
2021-09-01 10:54:02 -04:00
Mike Reeves
324e6b12e2
Add jinja template
2021-09-01 09:32:32 -04:00
Mike Reeves
007b15979a
Non Cluster honor closed indices values
2021-09-01 09:25:14 -04:00
Mike Reeves
c168703e9f
Merge pull request #5362 from Security-Onion-Solutions/truclusterrator
...
True Cluster Curator Overhaul
2021-08-31 17:17:47 -04:00
Mike Reeves
527a793e94
Only enable curator on Manager in true cluster
2021-08-31 16:59:41 -04:00
Mike Reeves
61ebedc0e9
Only enable curator on Manager in true cluster
2021-08-31 16:56:08 -04:00
Mike Reeves
e09aa4e5d4
Only enable curator on Manager in true cluster
2021-08-31 16:35:19 -04:00
Mike Reeves
e7b04b862f
Only enable curator on Manager in true cluster
2021-08-31 16:21:48 -04:00
Mike Reeves
62edfd0b7f
Only enable curator on Manager in true cluster
2021-08-31 16:20:42 -04:00
Mike Reeves
958575c22a
Only enable curator on Manager in true cluster
2021-08-31 16:17:55 -04:00
Mike Reeves
0c8e11dc9f
Only enable curator on Manager in true cluster
2021-08-31 16:13:05 -04:00
Mike Reeves
5b9ef3bc0d
Only enable curator on Manager in true cluster
2021-08-31 15:55:44 -04:00
Mike Reeves
c12f380bc3
Only enable curator on Manager in true cluster
2021-08-31 15:51:34 -04:00
Mike Reeves
dc25ed2594
Add logic for cronjobs
2021-08-31 15:43:48 -04:00
Mike Reeves
9f51f02ab4
Add logic for cronjobs
2021-08-31 15:40:09 -04:00
Mike Reeves
f6f4375e13
Add logic for cronjobs
2021-08-31 15:34:26 -04:00
Mike Reeves
ed116cf850
Add Actions for warm indices
2021-08-31 15:09:26 -04:00
Mike Reeves
476ecccbc1
Add Actions for warm indices
2021-08-31 15:08:10 -04:00
Mike Reeves
c09cebbd6b
Add Actions for close and delete in cluster mode
2021-08-31 13:42:11 -04:00
Mike Reeves
0ed92fd9bd
Merge pull request #5359 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 Wazuh hotfix into dev
2021-08-31 13:39:21 -04:00
Jason Ertel
c3454c9e8a
Merge branch 'master' into kilo
2021-08-31 13:37:46 -04:00
Mike Reeves
3425a0fe78
Delete Curators for all modules
2021-08-31 11:12:21 -04:00
Mike Reeves
9605eda559
Close Curators for all modules
2021-08-31 10:49:39 -04:00
Mike Reeves
ff09d9ca58
Merge pull request #5355 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERIFY_ISO.md
2021-08-31 10:06:12 -04:00
Mike Reeves
77b82bf2c0
Update VERIFY_ISO.md
2021-08-31 10:01:32 -04:00
Mike Reeves
ccc8f9ff0a
Merge pull request #5353 from Security-Onion-Solutions/hotfix/2.3.70
2021-08-31 09:57:05 -04:00
Mike Reeves
43d20226a8
Merge pull request #5352 from Security-Onion-Solutions/wazhf
...
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:47:14 -04:00
Mike Reeves
4fe0a1d7b4
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:39:37 -04:00
Mike Reeves
7a48a94624
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-31 08:22:55 -04:00
Mike Reeves
1aacc27cd4
Merge pull request #5340 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-08-30 17:48:53 -04:00
Mike Reeves
92858cd13a
Update HOTFIX
2021-08-30 17:38:29 -04:00
Mike Reeves
99cb38362a
Merge pull request #5339 from Security-Onion-Solutions/hotfix/wazuh-update-exclude
...
wazuh-agent fix + pull in master
2021-08-30 17:37:47 -04:00
William Wernert
bfd632e20a
Add wazuh to exclude arg when running yum update
2021-08-30 14:21:13 -04:00
Mike Reeves
518f9fceb0
Merge pull request #5337 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2021-08-30 12:33:43 -04:00
Mike Reeves
2b34da0fee
Update HOTFIX
2021-08-30 12:32:44 -04:00
William Wernert
72859adb13
Fix typo in so-checkin
2021-08-27 15:23:01 -04:00
Mike Reeves
a27263435a
Add Templates for all filebeat modules
2021-08-27 14:41:04 -04:00
Mike Reeves
f8cdf5bca3
Add Templates for all filebeat modules
2021-08-27 14:39:02 -04:00
William Wernert
ca5339341f
Fix batch size regex to disallow 0
2021-08-27 11:34:28 -04:00
William Wernert
c5d120293d
Initial work to add unattended option to soup
2021-08-27 11:33:51 -04:00
Jason Ertel
12b5c0899b
merge
2021-08-27 08:20:23 -04:00
Jason Ertel
09d5097837
Remove unused automation files
2021-08-25 21:08:49 -04:00
Jason Ertel
de5f823abf
Add automation for deploy-vader env
2021-08-25 18:28:17 -04:00
Josh Brower
7b93f355e2
so-import-evtx - timestamp extraction
2021-08-25 15:17:19 -04:00
m0duspwnens
a27569f20b
remove source when contents provided
2021-08-25 12:32:17 -04:00
m0duspwnens
fd1e632386
cleanup yaml
2021-08-25 12:08:43 -04:00
m0duspwnens
0681d29bb0
starting es pillarization
2021-08-25 10:23:06 -04:00
Josh Brower
ef650c6ee6
Merge pull request #5235 from Security-Onion-Solutions/feature/so-playbook-import
...
Initial version so-playbook-import
2021-08-24 10:40:07 -04:00
Mike Reeves
24f36bb4c9
Merge pull request #5284 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 GRAFANA hotfix to dev
2021-08-24 10:27:09 -04:00
m0duspwnens
9783d13ea3
remove identifier from HOTFIX file
2021-08-24 10:22:01 -04:00
m0duspwnens
427ec98ce5
fix merge conflict in HOTFIX file
2021-08-24 10:20:42 -04:00
Josh Patterson
72ba29fb7b
Merge pull request #5282 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-24 10:15:33 -04:00
Josh Patterson
2859bff0e4
Merge pull request #5281 from Security-Onion-Solutions/grafana_fleet_hotfix
...
sig files and iso info
2021-08-24 10:01:10 -04:00
Mike Reeves
6e921415ea
sig files and iso info
2021-08-24 10:00:06 -04:00
Mike Reeves
2f8b68e67a
sig files and iso info
2021-08-24 09:58:28 -04:00
Mike Reeves
e762491039
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-24 09:50:41 -04:00
Mike Reeves
11381e304b
Merge pull request #5273 from Security-Onion-Solutions/kilo
...
Switch to new Curator auth params
2021-08-24 08:29:47 -04:00
Jason Ertel
6d49bca0ac
Switch to new auth params
2021-08-23 15:36:11 -04:00
Josh Patterson
8ea89932ae
Merge pull request #5270 from Security-Onion-Solutions/grafana_fleet_hotfix
...
Grafana fleet hotfix
2021-08-23 13:10:35 -04:00
m0duspwnens
f87cf123b0
fix typo - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:08:11 -04:00
m0duspwnens
80f4d03254
place unique identifier on same line for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:05:28 -04:00
m0duspwnens
a9cc68f89e
add unique identifier for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:02:49 -04:00
m0duspwnens
b053f29a89
only create dashboards for certain node types - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 12:58:52 -04:00
Mike Reeves
19cfce5e0b
Add curator delete yml files
2021-08-23 10:47:41 -04:00
Mike Reeves
c4a32ca631
Merge pull request #5259 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 CURATOR Hotfix to Dev
2021-08-23 09:37:50 -04:00
Jason Ertel
b78da5c237
Merge hotfix to dev; reset to .80
2021-08-23 09:36:20 -04:00
Mike Reeves
0abf7593ed
Merge pull request #5233 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-23 09:28:07 -04:00
Josh Brower
aa420b914b
Initial version so-playbook-import
2021-08-20 16:27:09 -04:00
Mike Reeves
f096b513b7
Merge pull request #5232 from Security-Onion-Solutions/cfixhfix
...
Cfixhfix
2021-08-20 15:40:44 -04:00
Mike Reeves
51b517581a
2.3.70 sigs
2021-08-20 15:38:56 -04:00
Mike Reeves
936c998ecb
CURATOR ISO info
2021-08-20 12:49:55 -04:00
Mike Reeves
02372d130a
Merge pull request #5224 from Security-Onion-Solutions/curator_cron
...
remove the curator cronjobs if it is disabled
2021-08-20 10:44:55 -04:00
m0duspwnens
6f9a263af3
remove the curator cronjobs if it is disabled
2021-08-20 10:40:15 -04:00
Mike Reeves
43ffaab82c
Merge pull request #5213 from Security-Onion-Solutions/hotfix/curator
...
stop curator and remove from so-status for manager
2021-08-19 15:45:17 -04:00
m0duspwnens
dccfdb14e4
stop curator and remove from so-status for manager
2021-08-19 15:40:17 -04:00
Josh Patterson
21f3b3d985
Merge pull request #5212 from Security-Onion-Solutions/hotfix/curator
...
just dont run curator on manager
2021-08-19 15:27:55 -04:00
m0duspwnens
e2d74b115f
just dont run curator on manager
2021-08-19 15:26:22 -04:00
Mike Reeves
13741400f1
Merge pull request #5210 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2021-08-19 15:02:52 -04:00
Mike Reeves
d0f587858c
Merge pull request #5211 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Curator
2021-08-19 15:02:28 -04:00
Mike Reeves
acca8cc5d2
Update HOTFIX
2021-08-19 15:01:21 -04:00
Mike Reeves
ef950955bd
Update VERSION
2021-08-19 15:00:51 -04:00
Josh Patterson
9a8ccef828
Merge pull request #5209 from Security-Onion-Solutions/issue/5195
...
fix error in telegraf log
2021-08-19 13:27:08 -04:00
m0duspwnens
7b8e23fadd
fix error in telegraf log - https://github.com/Security-Onion-Solutions/securityonion/issues/5195
2021-08-19 11:11:24 -04:00
Mike Reeves
18335afa7f
Merge pull request #5204 from Security-Onion-Solutions/kilo
...
Update 2.3.80
2021-08-19 08:55:44 -04:00
Jason Ertel
41e8be87b6
Update 2.3.80
2021-08-19 08:42:29 -04:00
Doug Burks
39f32a6e13
Merge pull request #5185 from Security-Onion-Solutions/dev
...
2.3.70
2021-08-19 06:22:57 -04:00
Mike Reeves
8e9f95652d
Merge pull request #5188 from Security-Onion-Solutions/2.3.70
...
2.3.70 sigs
2021-08-18 09:37:51 -04:00
Mike Reeves
30489e4117
2.3.70 sigs
2021-08-18 09:35:48 -04:00
Mike Reeves
9dc9f10003
Merge pull request #5174 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-functions
2021-08-17 10:46:17 -04:00
Mike Reeves
1ced05c1d2
Update so-functions
2021-08-17 10:44:44 -04:00
Mike Reeves
41b246b8b3
Merge pull request #5169 from Security-Onion-Solutions/agrepo
...
Fix repo creation in airgap
2021-08-16 13:08:21 -04:00
Mike Reeves
a12f19c533
Fix repo creation in airgap
2021-08-16 13:00:52 -04:00
Josh Patterson
f1c91555ae
Merge pull request #5166 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-16 09:08:27 -04:00
Jason Ertel
e39de8c7bc
Merge pull request #5089 from Ron89/feature/thehive-userupdate
...
add user password update command
2021-08-15 09:36:35 -04:00
Mike Reeves
d0e312ec42
Merge pull request #5149 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 18:42:34 -04:00
Mike Reeves
e492833453
Grid Fixes
2021-08-13 18:32:55 -04:00
Mike Reeves
9beacacd44
Grid Fixes
2021-08-13 18:26:17 -04:00
Mike Reeves
aad14b2461
Grid Fixes
2021-08-13 18:22:02 -04:00
m0duspwnens
4955b552df
remove -
2021-08-13 17:42:37 -04:00
Mike Reeves
55e8a777d4
Merge pull request #5147 from Security-Onion-Solutions/issue/4674
...
keep the list unique
2021-08-13 17:39:54 -04:00
m0duspwnens
a98ed282c0
keep the list unique
2021-08-13 17:38:45 -04:00
Mike Reeves
7504b1cb2e
Merge pull request #5146 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 16:25:31 -04:00
m0duspwnens
afab1cb1e6
Merge remote-tracking branch 'remotes/origin/dev' into issue/2806
2021-08-13 16:19:57 -04:00
m0duspwnens
cd0b9bbe4a
dont always add curator to so-status
2021-08-13 16:19:41 -04:00
Mike Reeves
3ea29e77a9
Merge pull request #5145 from Security-Onion-Solutions/bugfix/so-logscan-soup-pull
...
Remove so-logscan from so-image-common arrays
2021-08-13 13:59:10 -04:00
William Wernert
fb4c2c35e3
Remove so-logscan from so-image-common arrays
2021-08-13 13:58:08 -04:00
HE Chong
81ccce8659
negative case where username doesn't exist now report exception as expected
2021-08-13 23:00:11 +08:00
HE Chong
0d5e3771f5
modify user password update script for theHive, keep it in consistency with Fleet counterpart.
2021-08-13 21:52:19 +08:00
HE Chong
2030ef65f1
add user password update script for Fleet
2021-08-13 21:50:24 +08:00
HE Chong
b6c361f83d
add user password update script for The Hive
2021-08-13 20:54:35 +08:00
Mike Reeves
9404cb635d
Grid Fixes
2021-08-13 08:48:47 -04:00
William Wernert
da53b39c15
Merge pull request #5142 from Security-Onion-Solutions/foxtrot
...
Add image pull script to allow so-learn to pull missing images, update wording on several whiptail prompts
2021-08-12 16:09:55 -04:00
William Wernert
86569b0599
Make sbin script permissions consistent
2021-08-12 16:05:54 -04:00
William Wernert
45aa2f72cb
Merge branch 'dev' into foxtrot
2021-08-12 15:45:12 -04:00
Mike Reeves
06b7434ca2
Merge pull request #5141 from Security-Onion-Solutions/kilo
2021-08-12 15:05:14 -04:00
Jason Ertel
258cebda6e
Correct identity update payload to not have unsupported fields
2021-08-12 15:01:45 -04:00
Jason Ertel
0cca43c4bd
Merge branch 'dev' into kilo
2021-08-12 15:01:12 -04:00
William Wernert
bf40a1038e
Whiptail changes
...
* Update wording of ip mask prompt + so-allow question for clarity
* Remove old ip+mask prompts
2021-08-12 10:32:27 -04:00
William Wernert
3312a66e75
Fix indent
2021-08-11 16:37:22 -04:00
William Wernert
4a31d6b3bc
Specify images are also verified
2021-08-11 16:35:33 -04:00
William Wernert
64dfc6e191
Fix pull logic and properly hide output
2021-08-11 16:33:45 -04:00
William Wernert
95bd7f9861
Merge branch 'dev' into foxtrot
2021-08-11 13:47:38 -04:00
William Wernert
983549711c
Pull image if missing when enabling module in so-learn
2021-08-11 13:47:31 -04:00
Josh Patterson
5922dbdf22
Merge pull request #5120 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-08-10 12:29:51 -04:00
m0duspwnens
9e48a5b57b
fix the pillar.get
2021-08-10 10:29:29 -04:00
m0duspwnens
3c1114403e
fix the pillar.get
2021-08-10 10:25:05 -04:00
m0duspwnens
8d2f614af6
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-08-10 10:16:30 -04:00
m0duspwnens
1415de858c
delete old dashboard folders via api - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-10 10:16:14 -04:00
Josh Patterson
59e9fddf18
Merge pull request #5109 from Security-Onion-Solutions/issue/4674
...
remove old dashboard dirs
2021-08-09 13:37:45 -04:00
m0duspwnens
ad3b6cf629
remove old dashboard dirs - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-09 13:34:02 -04:00
William Wernert
b12e2eded5
Merge pull request #5086 from Security-Onion-Solutions/foxtrot
...
Add conditional check for logscan log + add log folder to logrotate config
2021-08-06 11:32:23 -04:00
William Wernert
26030d83eb
Merge branch 'dev' into foxtrot
2021-08-06 09:44:10 -04:00
William Wernert
3b01f6431e
Add logscan to logrotate config
2021-08-06 09:43:58 -04:00
Jason Ertel
a646867593
Merge branch 'dev' into kilo
2021-08-06 09:14:45 -04:00
Josh Patterson
768e61e11a
Merge pull request #5080 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-05 12:02:42 -04:00
m0duspwnens
e72ad9eb5a
allow curator
2021-08-05 11:54:49 -04:00
m0duspwnens
ac4faf673d
add so-manager to curator.yml
2021-08-05 11:11:59 -04:00
William Wernert
dd1769fbef
Only check for logscan on manager-type and import
2021-08-05 11:02:09 -04:00
m0duspwnens
853a986082
add reqs to docker add manager to so-curator-closed-delete-delte
2021-08-05 10:36:18 -04:00
m0duspwnens
727a3742f5
run only on manager if truecluster enabled
2021-08-05 09:50:51 -04:00
Doug Burks
478a0b6a3f
Merge pull request #5075 from Security-Onion-Solutions/fix/typo
...
fix typo
2021-08-05 07:43:46 -04:00
Doug Burks
771688a70f
fix typo
2021-08-05 07:34:07 -04:00
Josh Patterson
40fa549353
Merge pull request #5066 from Security-Onion-Solutions/issue/2806
...
dont run curator on searchnode if truecluster is enabled
2021-08-04 15:01:11 -04:00
Jason Ertel
84fdc1e690
Merge pull request #5057 from Security-Onion-Solutions/bravo
...
Several Suricata things
2021-08-04 12:26:11 -04:00
Mike Reeves
71bbb41b5f
Merge branch 'dev' into bravo
2021-08-04 10:57:10 -04:00
m0duspwnens
52cb72ba67
dont run curator on searchnode if truecluster is enabled - https://github.com/Security-Onion-Solutions/securityonion/issues/2806
2021-08-04 09:40:34 -04:00
William Wernert
54a3b754e0
Merge pull request #5050 from Security-Onion-Solutions/foxtrot
...
Add logscan state, related pipeline config, and initial so-learn script
2021-08-03 16:30:07 -04:00
William Wernert
2bc88e7750
Remove learn from allowed states for helixsensor
2021-08-03 15:29:37 -04:00
William Wernert
ef59cb47dd
Use print_err function
2021-08-03 15:26:57 -04:00
William Wernert
9e5d3aa286
Fix removed root check in so-rule
2021-08-03 15:25:53 -04:00
William Wernert
25bf25eae6
Allowed states remove typo'd logscan
2021-08-03 15:24:32 -04:00
William Wernert
24f5fa66f3
Merge branch 'dev' into foxtrot
2021-08-03 13:02:29 -04:00
Mike Reeves
1aeb2d7d4f
Merge pull request #5040 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-03 10:59:28 -04:00
Jason Ertel
ee176f5bfd
Condense cloud automations
2021-08-03 07:40:50 -04:00
Jason Ertel
eb093b8e6c
Condense cloud automations
2021-08-02 21:52:42 -04:00
Jason Ertel
f88fa6e3b2
Condense cloud automations
2021-08-02 21:51:26 -04:00
Jason Ertel
724f7d4f3d
Merge pull request #5036 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-02 18:04:05 -04:00
Jason Ertel
19816d8814
Condense cloud automations
2021-08-02 17:55:27 -04:00
William Wernert
d3b170c6df
Add logscan automation file + fix enable command in setup
2021-08-02 12:37:37 -04:00
William Wernert
757091beeb
Add log_level to logscan.conf
2021-08-02 10:35:39 -04:00
William Wernert
8a49039b85
Only append source.ip to logscan.source.ips if it's been created
2021-08-02 09:50:49 -04:00
William Wernert
4f39cd1d7f
Add logscan dynamic object to so-common template mappings
2021-07-30 16:02:02 -04:00
William Wernert
2a6277c0c3
Fix field names in logscan pipeline
2021-07-30 15:46:39 -04:00
William Wernert
33bd6aed20
Fix logscan pipeline on eval
...
* Rename logscan pipeline to logscan.alert
* Add module to indices array in filebeat.yml
2021-07-30 14:41:15 -04:00
William Wernert
b9980c9d30
Fix pipeline name
2021-07-30 13:09:09 -04:00
William Wernert
01bb94514c
Correct mod_so_status to only act on single string
2021-07-30 11:05:48 -04:00
William Wernert
d71967ea1d
Fix incorrect writing of so-status.conf
2021-07-30 10:28:39 -04:00
William Wernert
0b06d0bfdb
Merge branch 'dev' into foxtrot
2021-07-29 15:15:25 -04:00
William Wernert
b2a83018ba
Remove or run logscan based on enabled bool
2021-07-29 15:14:54 -04:00
William Wernert
ba265d94f4
Change default value in learn init to a dict where approriate
2021-07-29 15:14:28 -04:00
Mike Reeves
af7b314cfe
Merge pull request #4993 from Security-Onion-Solutions/kilo
...
Merge 2.3.61 MSEARCH Hotfix into dev
2021-07-29 15:02:51 -04:00
Jason Ertel
4c6447a3da
merge 2.3.61 MSEARCH hotfix into dev
2021-07-29 15:00:58 -04:00
William Wernert
b30f771fa2
Set write_needed flag correctly, include newline in so-status.conf string
2021-07-29 14:59:26 -04:00
Mike Reeves
837c0402a0
Merge pull request #4989 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-29 14:58:25 -04:00
William Wernert
e38219aa2e
Fix learn init.sls typo
2021-07-29 14:35:02 -04:00
William Wernert
9e92f6da3d
Add container to so-status when enabling/disabling ml module
2021-07-29 14:25:20 -04:00
William Wernert
44551ea9ee
Fix so-learn list
2021-07-29 13:31:48 -04:00
William Wernert
c53da9b1ff
Fix wrong variables in learn init.sls
2021-07-29 12:04:40 -04:00
William Wernert
e1785dbd9a
Fix typo
2021-07-29 12:00:53 -04:00
William Wernert
2560a9b78c
[wip] Change learn:modules to dictionary
2021-07-29 11:58:58 -04:00
William Wernert
d53e989c55
Add ability to set cpu_period per module
2021-07-29 11:52:10 -04:00
William Wernert
211a841cdb
Fix file path in bind mount for logscan
2021-07-29 11:40:19 -04:00
Josh Patterson
50e4365475
Merge pull request #4990 from Security-Onion-Solutions/issue/4985
...
Issue/4985
2021-07-29 11:14:54 -04:00
Jason Ertel
c524b54af1
Merge pull request #4988 from Security-Onion-Solutions/mkr2361
...
2.3.61-MSEARCH
2021-07-29 11:10:41 -04:00
Mike Reeves
7591bb115e
2.3.61-MSEARCH
2021-07-29 11:09:54 -04:00
Mike Reeves
3d2da303c8
2.3.61-MSEARCH
2021-07-29 11:09:27 -04:00
Mike Reeves
f585eb6e62
2.3.61-MSEARCH
2021-07-29 11:08:03 -04:00
m0duspwnens
4b6120a46b
fix the hours get
2021-07-29 10:59:33 -04:00
Mike Reeves
d946c6d5ed
Merge pull request #4987 from Security-Onion-Solutions/kilo
...
Do not prompt about uppercased hostname during testing
2021-07-29 10:57:56 -04:00
William Wernert
5894b85bd1
Remove broken yaml dump arg, rename metavars
2021-07-29 10:57:53 -04:00
m0duspwnens
3fc43f7d92
allow for adjustment to auto patch os schedule - https://github.com/Security-Onion-Solutions/securityonion/issues/4985
2021-07-29 10:48:24 -04:00
Jason Ertel
8ed264460f
Do not prompt about uppercased hostname during testing
2021-07-29 10:45:35 -04:00
William Wernert
811b32735e
Merge branch 'dev' into foxtrot
2021-07-29 09:52:29 -04:00
Mike Reeves
4b3db0c4d2
Merge pull request #4972 from Security-Onion-Solutions/mkr2361
...
Fix Manager Search
2021-07-28 17:08:40 -04:00
Mike Reeves
281ba21298
Merge pull request #4956 from Security-Onion-Solutions/kilo
...
Merge master to dev
2021-07-28 17:07:58 -04:00
Mike Reeves
d4a177949a
Fix Manager Search
2021-07-28 17:05:16 -04:00
Mike Reeves
a42d8c9229
Fix Manager Search
2021-07-28 17:03:14 -04:00
William Wernert
dd0e407935
Use correct container name
2021-07-28 15:06:38 -04:00
William Wernert
7ef5b39b04
[wip] Fix 'Nonetype' object is not callable error
2021-07-28 14:28:00 -04:00
William Wernert
cf9121dfc2
Actually download so-learn container
2021-07-28 14:13:16 -04:00
Josh Patterson
fcfc2a65a9
Merge pull request #4968 from Security-Onion-Solutions/issue/3933
...
allow for sampleSize adjustment in kibana
2021-07-28 11:13:49 -04:00
William Wernert
91accb0bc6
[wip] Fixing so-learn script
2021-07-28 10:12:32 -04:00
William Wernert
e2abe8840f
Fix directory in logscan state
2021-07-28 10:12:19 -04:00
m0duspwnens
ead9ae8cb5
fix merge and defaults passed
2021-07-28 09:58:38 -04:00
William Wernert
455719936b
Uncomment required lines in so-learn
2021-07-28 09:53:35 -04:00
William Wernert
8d56fc71fa
Fix jinja length calculation
2021-07-28 09:53:24 -04:00
William Wernert
833d154bf4
Merge branch 'dev' into foxtrot
2021-07-28 09:50:11 -04:00
William Wernert
f31dc5abc7
Add learn to allowed states
2021-07-28 09:49:59 -04:00
m0duspwnens
9a429230fe
wrap with raw due to {{value}}
2021-07-28 09:39:35 -04:00
m0duspwnens
b36d46b7f2
change to jinja tem,plate
2021-07-28 09:27:44 -04:00
m0duspwnens
fee89665fd
dict not list for defaults
2021-07-28 09:18:15 -04:00
m0duspwnens
d78a37f9e3
allow for control of kibana discover sampleSize - https://github.com/Security-Onion-Solutions/securityonion/issues/3933
2021-07-28 09:12:31 -04:00
Jason Ertel
28c5c02ef1
Merge pull request #4958 from Security-Onion-Solutions/issue/4024
...
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:21:13 -04:00
m0duspwnens
8ffeae38bc
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:16:48 -04:00
William Wernert
f4fae7938e
Merge branch 'dev' into foxtrot
2021-07-27 16:01:44 -04:00
Jason Ertel
22920bc9a1
clear out hotfix from merge
2021-07-27 14:42:11 -04:00
Jason Ertel
ceb82cb863
Merge branch 'master' into kilo
2021-07-27 14:40:31 -04:00
Mike Reeves
1caa361e22
Merge pull request #4955 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-27 14:33:31 -04:00
Mike Reeves
da20790238
Merge pull request #4954 from Security-Onion-Solutions/mkr2361
...
Steno ISO Details
2021-07-27 11:11:22 -04:00
Mike Reeves
f359dd0cd4
Steno ISO Details
2021-07-27 11:09:25 -04:00
Josh Patterson
bee442a21f
Merge pull request #4950 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-07-27 10:28:02 -04:00
m0duspwnens
a66765e99b
remove old dashboards, set default refresh to 5m
2021-07-27 10:23:35 -04:00
m0duspwnens
0db7f91eb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-27 08:53:31 -04:00
m0duspwnens
850315dc20
remove role conditional from all panel queiries
2021-07-27 08:47:44 -04:00
Mike Reeves
d35e4bea01
Merge pull request #4932 from Security-Onion-Solutions/issue/4922
...
Issue/4922
2021-07-26 16:18:22 -04:00
Jason Ertel
356b623148
Merge pull request #4937 from Security-Onion-Solutions/kilo
...
Add Azure automations
2021-07-26 16:13:57 -04:00
Jason Ertel
3a022e7a83
Add Azure automations
2021-07-26 15:50:15 -04:00
William Wernert
64945cec16
[wip] Initial work to enable/disable "learn" modules
2021-07-26 14:24:10 -04:00
Jason Ertel
26741bdb53
Add wss: to CSP for browsers that enforce wss distinctly from other protocols
2021-07-26 10:55:30 -04:00
m0duspwnens
7aa5e857ed
update hotfix file
2021-07-26 10:46:52 -04:00
m0duspwnens
2e277bf487
change container to abesent of pcap is disabled
2021-07-26 10:08:59 -04:00
m0duspwnens
e4f46c6e14
hide role template var from all dash except overview
2021-07-26 09:36:05 -04:00
m0duspwnens
e9d90644fd
fix query and allow for setting text and value of servername template var
2021-07-23 16:52:07 -04:00
m0duspwnens
5a06f0dce9
role template var now selects default role
2021-07-23 16:34:58 -04:00
m0duspwnens
08e9a58f2e
simply to one servername.json
2021-07-23 16:09:25 -04:00
m0duspwnens
e1f0c8e87c
add "list" bast to tempating defs for overview
2021-07-23 15:43:31 -04:00
m0duspwnens
17a532f7b5
add new templating defs to overview
2021-07-23 15:41:03 -04:00
m0duspwnens
c7306dda12
fix servername_eval template var, test using 1 servername template var
2021-07-23 15:38:45 -04:00
m0duspwnens
00d311cd6c
fix nodetype listing
2021-07-23 14:40:44 -04:00
m0duspwnens
f8d2a7f449
fix nodetype listing
2021-07-23 13:43:35 -04:00
m0duspwnens
a02a928996
add missing ]
2021-07-23 13:33:25 -04:00
m0duspwnens
eb661b7a24
add ability to set title for dashboards, only create dashboards/dirs if that node type exists
2021-07-23 13:31:44 -04:00
m0duspwnens
6aea607f21
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-23 11:12:48 -04:00
m0duspwnens
41e747dcc1
add servername_all template var
2021-07-23 10:55:15 -04:00
m0duspwnens
d3d02faa1c
remove detailed
2021-07-23 10:52:30 -04:00
m0duspwnens
7a85a3c7f7
move dashboard location
2021-07-23 10:20:57 -04:00
m0duspwnens
fceb2851ef
add eval dashboard
2021-07-23 09:02:40 -04:00
William Wernert
2f118781ea
Merge branch 'dev' into foxtrot
2021-07-23 08:54:08 -04:00
William Wernert
b8e3a45a7e
[wip] Add logscan state
...
Do not add state to top file or setup yet, script will be written to enable the feature shortly
2021-07-23 08:53:45 -04:00
m0duspwnens
61312397e1
update container uptime panel
2021-07-23 08:25:43 -04:00
m0duspwnens
8ea4682aab
add docker container uptime to overview dash
2021-07-23 07:34:01 -04:00
m0duspwnens
3b6befdb97
adjust gridpos
2021-07-22 15:05:37 -04:00
m0duspwnens
613979ea3f
remove extra comma
2021-07-22 15:03:58 -04:00
m0duspwnens
191def686b
add packet loss panels
2021-07-22 15:02:06 -04:00
Mike Reeves
f986e0dc78
Merge pull request #4892 from Security-Onion-Solutions/kilo
...
Merge master back to dev
2021-07-22 14:37:40 -04:00
Jason Ertel
08e75567d4
merge master to kilo
2021-07-22 14:34:24 -04:00
Mike Reeves
668199f1a8
Merge pull request #4889 from Security-Onion-Solutions/2361update
...
2.3.61
2021-07-22 14:29:13 -04:00
Jason Ertel
7a753a56ec
Update README with 2.3.61
2021-07-22 13:54:04 -04:00
m0duspwnens
7b38b4e280
fix {{}}
2021-07-22 13:36:44 -04:00
m0duspwnens
7dc2e2ca73
add option to hide trend on zeek packet loss graph
2021-07-22 13:35:25 -04:00
m0duspwnens
44eb23615a
change to packet_loss
2021-07-22 13:20:19 -04:00
m0duspwnens
d47566f667
remove monitor inbound graph
2021-07-22 13:18:31 -04:00
m0duspwnens
9ae84c8108
add network and tool packetloss panels to overview
2021-07-22 13:16:39 -04:00
Mike Reeves
578c7aac35
2.3.61
2021-07-22 13:06:26 -04:00
m0duspwnens
1c460cc19c
fix traffic overview graphs
2021-07-22 10:31:47 -04:00
m0duspwnens
ff436aea93
allow multi and all for manint and monint vars
2021-07-22 10:06:31 -04:00
m0duspwnens
aa333794f7
add disk usage percent graphs
2021-07-22 09:54:17 -04:00
doug
3d3593a1a9
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-22 09:50:21 -04:00
Jason Ertel
257062e20c
Update release notes link to match top right menu for airgap
2021-07-22 09:48:34 -04:00
doug
fa9d7afb46
FIX: Airgap link to Release Notes #4685
2021-07-22 09:42:37 -04:00
m0duspwnens
ae5f351e1a
change row name
2021-07-22 09:31:17 -04:00
m0duspwnens
257a88ec8e
change row name
2021-07-22 09:30:43 -04:00
m0duspwnens
e1e6304a8a
rename
2021-07-22 09:29:37 -04:00
m0duspwnens
a81ef0017c
rename panels source, reorg overview
2021-07-22 09:15:22 -04:00
m0duspwnens
b89162e086
change id
2021-07-22 08:01:54 -04:00
m0duspwnens
a6630540a4
add system uptime graph to overview dash
2021-07-21 18:11:42 -04:00
m0duspwnens
a528c5d54b
role first var for overview
2021-07-21 17:41:53 -04:00
m0duspwnens
690699ddf7
update template vars to use regex for $servername
2021-07-21 17:17:23 -04:00
m0duspwnens
cd8d9c657e
add mgmt interface traffic graphs to overview
2021-07-21 16:24:16 -04:00
m0duspwnens
f732b80b92
add swap usage percent to overview dash
2021-07-21 15:48:04 -04:00
Jason Ertel
ad8c12afa5
Upgrade ES to 7.13.4
2021-07-21 15:07:02 -04:00
m0duspwnens
479fcb6c46
add panel for memory usage percent
2021-07-21 15:00:05 -04:00
Jason Ertel
74874dfff2
Allow web pages to load blob data
2021-07-21 14:59:33 -04:00
m0duspwnens
ceb108a5fe
set min yaxes to 0
2021-07-21 14:47:57 -04:00
m0duspwnens
235d8b7cf0
ensure role matches
2021-07-21 14:44:07 -04:00
Mike Reeves
7c9df2d75a
Update HOTFIX
2021-07-21 14:40:53 -04:00
Mike Reeves
43bf75217f
Update VERSION
2021-07-21 14:40:23 -04:00
m0duspwnens
9bf6d478c5
remove $col var
2021-07-21 14:36:08 -04:00
m0duspwnens
e2baa93270
remove role from node_config for telegraf
2021-07-21 14:32:01 -04:00
m0duspwnens
37fcda3817
add cpu row and panels to overview dashboard
2021-07-21 14:30:41 -04:00
m0duspwnens
457ae54341
role var
2021-07-21 11:50:06 -04:00
m0duspwnens
4cc3c5ada9
add role template var to overview dashboard
2021-07-21 11:35:02 -04:00
m0duspwnens
07d5736d61
change sort of legend
2021-07-21 11:33:48 -04:00
m0duspwnens
a7551a44e5
allow multi and all on servername_all template var
2021-07-21 11:29:30 -04:00
m0duspwnens
f4d3e13c7f
begin overview dashboard
2021-07-21 11:26:02 -04:00
m0duspwnens
47d82b3d35
sort desc remaining tooltips
2021-07-21 10:36:07 -04:00
m0duspwnens
9d06aff1d1
add manager dashboard
2021-07-21 10:23:39 -04:00
m0duspwnens
5ea8c978a0
add managersearch
2021-07-21 10:16:40 -04:00
m0duspwnens
6809c3a9f6
add mastersearch dashboard
2021-07-21 10:13:43 -04:00
m0duspwnens
761108964e
remove panels from searchnode dashboard
2021-07-21 10:05:43 -04:00
m0duspwnens
e3e74a84f2
test sort tooltip descending
2021-07-21 10:00:14 -04:00
m0duspwnens
1fee4e87c4
add searchnode dashboard
2021-07-21 09:51:49 -04:00
m0duspwnens
0c4c59375d
sort container uptime ascending
2021-07-21 09:11:39 -04:00
Mike Reeves
09165daab8
Several Suricata things
2021-07-21 09:10:33 -04:00
m0duspwnens
3393b77535
add sensor dashboard
2021-07-21 08:54:26 -04:00
m0duspwnens
d050bc02e2
dont show legend for docker uptime trend
2021-07-20 16:29:49 -04:00
m0duspwnens
af60ddf404
add docker container uptime graph
2021-07-20 16:28:07 -04:00
m0duspwnens
1bb92f63d1
add docker details
2021-07-20 15:21:59 -04:00
m0duspwnens
a405ca39fa
add redis.sh for telegraf on heavynodes
2021-07-20 14:31:09 -04:00
m0duspwnens
852b686d81
add servername vars for each role
2021-07-20 14:25:56 -04:00
m0duspwnens
608d5d3c26
change uid logic
2021-07-20 14:10:26 -04:00
m0duspwnens
6038ebb705
handle multile nodetpes and uid
2021-07-20 14:04:28 -04:00
m0duspwnens
4bb350d37d
add heavynode
2021-07-20 13:55:52 -04:00
m0duspwnens
d01ac55db1
add heavynode
2021-07-20 13:55:18 -04:00
Jason Ertel
fcde5c3c18
Merge pull request #4865 from Security-Onion-Solutions/kilo
...
Merge curator hotfix into dev
2021-07-20 11:47:49 -04:00
Jason Ertel
dbf19e134f
Merge branch 'master' into kilo
2021-07-20 11:44:10 -04:00
Mike Reeves
b13c5a3b8b
Merge pull request #4863 from Security-Onion-Solutions/hotfix/2.3.60
...
Hotfix/2.3.60 CuratorFix
2021-07-20 11:02:34 -04:00
m0duspwnens
b0c5a352c1
remove old panaels
2021-07-20 10:53:47 -04:00
m0duspwnens
d0b3cd5f66
add the detailed dash dir
2021-07-20 10:50:40 -04:00
m0duspwnens
24efdec9ea
cap the var
2021-07-20 10:48:46 -04:00
m0duspwnens
1bed818a8e
fix jinja
2021-07-20 10:47:10 -04:00
m0duspwnens
3c4c52567d
fix jinja
2021-07-20 10:46:41 -04:00
m0duspwnens
87ae14d11c
fix jinja
2021-07-20 10:44:32 -04:00
m0duspwnens
258d303e7f
change how dashboards are deployed
2021-07-20 10:43:00 -04:00
m0duspwnens
458350e1a8
new redis queue stat panel, change to lastnotnull
2021-07-20 09:45:28 -04:00
Mike Reeves
fe7ee1e2c7
Merge pull request #4862 from Security-Onion-Solutions/curatorfix
...
Curator Fix
2021-07-20 09:26:54 -04:00
m0duspwnens
d8910a0097
add redis queue to overview, reposition overview panels
2021-07-20 09:22:43 -04:00
Mike Reeves
3b6e683d37
Curator Fix
2021-07-20 09:21:22 -04:00
m0duspwnens
90f6bad6ce
panel title change
2021-07-20 08:54:39 -04:00
m0duspwnens
fcc6802f86
convert all singlestat to stat
2021-07-20 08:51:53 -04:00
m0duspwnens
3b9bc77ecc
remove scopedvars
2021-07-19 17:51:43 -04:00
m0duspwnens
0fb4500fcc
add legends
2021-07-19 17:39:32 -04:00
m0duspwnens
93ca00c7fe
change min y
2021-07-19 17:29:57 -04:00
m0duspwnens
522f2a3f9f
maxdatapoints and min interval
2021-07-19 17:19:56 -04:00
m0duspwnens
40ddf5f49c
fix cords
2021-07-19 16:30:02 -04:00
m0duspwnens
60356eacce
make the ids unique
2021-07-19 16:26:09 -04:00
m0duspwnens
158f3bf092
add row_stenographer
2021-07-19 16:18:02 -04:00
m0duspwnens
ebf3c65bed
add many more panels
2021-07-19 16:02:40 -04:00
William Wernert
df6d1d72e2
Merge branch 'dev' into feature/logscan
2021-07-19 15:19:59 -04:00
weslambert
72542322ca
Merge pull request #4857 from Security-Onion-Solutions/fix/beats_output_fb_modules
...
Check if Filebeat modules are being used for incoming (external) Beats
2021-07-19 13:11:06 -04:00
weslambert
fea4f3f973
Check if Filebeat modules are being used for incoming Beats
2021-07-19 12:57:42 -04:00
Mike Reeves
7878180f54
Merge pull request #4854 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2021-07-19 12:50:23 -04:00
Mike Reeves
0669aa6bbd
Update HOTFIX
2021-07-19 12:49:43 -04:00
Mike Reeves
2c4924a602
Merge pull request #4853 from Security-Onion-Solutions/fix/curator_http_auth
...
Use http_auth instead of username/password until Curator is updated to latest version
2021-07-19 12:45:29 -04:00
weslambert
bde86e0383
Use http_auth instead of username/password until Curator is upgraded to next version
2021-07-19 12:42:46 -04:00
Jason Ertel
bab18275bc
Merge pull request #4836 from Security-Onion-Solutions/fix/airgap-release-notes
...
FIX: Airgap link to Release Notes #4685
2021-07-17 11:05:33 -04:00
doug
7e86681509
FIX: Airgap link to Release Notes #4685
2021-07-16 16:50:49 -04:00
William Wernert
c2fc2df54c
Merge pull request #4835 from Security-Onion-Solutions/feature/uppercase-warning
...
Show warning to user when trying to use uppercase characters in hostname or domain name
2021-07-16 15:44:47 -04:00
William Wernert
0deb77468f
Change uppercase regex
...
Check for any uppercase characters rather than revalidating input sans uppercase
2021-07-16 15:39:09 -04:00
William Wernert
9bf1d3e0c6
Misc fixes
2021-07-16 14:59:44 -04:00
William Wernert
3a12d28d20
Merge branch 'dev' into feature/logscan
2021-07-16 14:13:19 -04:00
William Wernert
e8ba4bdc6c
Add quotes to string
2021-07-16 14:07:23 -04:00
William Wernert
b552973e00
Add logic to show uppercase warning message when appropriate
2021-07-15 16:36:46 -04:00
William Wernert
ac98e1fd0f
Remove testing default values, change wording, set default option to no
2021-07-15 16:36:24 -04:00
m0duspwnens
4246aac51b
unhide disk var
2021-07-15 13:57:43 -04:00
William Wernert
33f396bdae
Add uppercase warning function
2021-07-15 13:53:57 -04:00
William Wernert
ff25cecd54
Remove unused function
2021-07-15 13:53:31 -04:00
m0duspwnens
e88b258208
add maxDataPoints and min interval to more panels
2021-07-15 11:53:24 -04:00
m0duspwnens
1cbf895e0e
add missing ,
2021-07-15 11:27:19 -04:00
m0duspwnens
7dc1f5c445
add maxDataPoints and min interval to some panels for testing
2021-07-15 11:25:20 -04:00
m0duspwnens
439e049948
revert to $__interval
2021-07-15 10:17:21 -04:00
m0duspwnens
fbf26bef8d
test new groupby interval for trend on monitor packets
2021-07-15 08:42:53 -04:00
m0duspwnens
c1f550382c
remove interval var
2021-07-15 08:31:42 -04:00
m0duspwnens
23fb6a5c02
rename
2021-07-14 18:04:33 -04:00
m0duspwnens
d632266092
fix jinja
2021-07-14 18:01:56 -04:00
m0duspwnens
4ea3ab9538
add disk iops graphs
2021-07-14 17:58:49 -04:00
m0duspwnens
725161ea6e
fix datasource
2021-07-14 16:07:14 -04:00
m0duspwnens
fccd86f676
add disk var to standalone
2021-07-14 16:04:55 -04:00
m0duspwnens
0f0a977ed9
add disk var
2021-07-14 16:04:17 -04:00
Jason Ertel
7f9d0b59b8
Merge pull request #4808 from Security-Onion-Solutions/kilo
...
Merge hotfix from master into dev; add `so-firewall apply` feature to dev
2021-07-14 15:49:12 -04:00
m0duspwnens
b0d510167c
change title
2021-07-14 15:36:26 -04:00
m0duspwnens
4971933201
rename file
2021-07-14 15:34:39 -04:00
m0duspwnens
693a9b30ae
add swap, adjust cords
2021-07-14 15:33:28 -04:00
Jason Ertel
76c285158a
Merge branch 'master' into kilo
2021-07-14 15:24:35 -04:00
Jason Ertel
08517e3732
Merge branch 'dev' into kilo
2021-07-14 15:24:29 -04:00
m0duspwnens
59530f4263
cahnge nullPointMode
2021-07-14 14:54:48 -04:00
Mike Reeves
5d48fb41ba
Merge pull request #4800 from Security-Onion-Solutions/hotfix/2.3.60
2021-07-14 14:54:00 -04:00
m0duspwnens
4acebe7f59
replace $interval with $__interval
2021-07-14 14:47:02 -04:00
m0duspwnens
a44a7b7161
change title
2021-07-14 14:45:17 -04:00
m0duspwnens
be13f0a066
change id
2021-07-14 14:31:25 -04:00
m0duspwnens
98ce77c2b1
add disk usage graphs
2021-07-14 14:28:25 -04:00
m0duspwnens
275a491cac
cords
2021-07-14 13:44:47 -04:00
m0duspwnens
1c868f85c4
fix cords;
2021-07-14 13:25:17 -04:00
m0duspwnens
b6deacf86d
cords
2021-07-14 13:11:48 -04:00
Mike Reeves
ebe5ef6535
Merge pull request #4799 from Security-Onion-Solutions/agsoupupdate
...
Update ISO info
2021-07-14 12:07:35 -04:00
m0duspwnens
294f91473c
fix packets legend
2021-07-14 11:49:24 -04:00
m0duspwnens
902f04efb4
set 0 as min
2021-07-14 11:44:14 -04:00
m0duspwnens
ca2989c0e5
fix network cords
2021-07-14 11:42:01 -04:00
m0duspwnens
2d9697cd66
fix network cords
2021-07-14 11:40:31 -04:00
m0duspwnens
b4111a9f79
fix network cords
2021-07-14 11:38:16 -04:00
m0duspwnens
7f8212fdba
add trend, add network graphs
2021-07-14 11:31:48 -04:00
weslambert
7e1be8a3a4
Merge pull request #4798 from Security-Onion-Solutions/fix/strelka_filepath_mapping
...
Replace staging with processed in Strelka file path mapping
2021-07-14 11:16:15 -04:00
Wes Lambert
05aad07bfc
Replace staging path with processed path for analyzed files
2021-07-14 15:04:46 +00:00
Mike Reeves
92a80f9a58
Update ISO info
2021-07-14 10:30:10 -04:00
m0duspwnens
4b4ceb525a
trends for load and process status
2021-07-14 10:29:35 -04:00
weslambert
42ba9888d7
Merge pull request #4797 from Security-Onion-Solutions/fix/wazuh_data_port
...
Change field name and mapping for Wazuh's data.port
2021-07-14 10:14:53 -04:00
William Wernert
818f912a90
[fix] Remove indent
2021-07-14 10:13:14 -04:00
m0duspwnens
dae64b82ff
add trend to cpu
2021-07-14 10:09:34 -04:00
m0duspwnens
53c6edcbdb
add trends memory usage and network graphs
2021-07-14 09:57:43 -04:00
Wes Lambert
723172bc1f
Add path_unmatch for data.port so it is not mapped as integer
2021-07-14 13:45:09 +00:00
Wes Lambert
323b5d6694
Add dynamic mapping for wazuh
2021-07-14 13:43:34 +00:00
Wes Lambert
441cd3fc59
Move Wazuh-specific data to wazuh.data
2021-07-14 13:42:51 +00:00
m0duspwnens
1d23d1b2e2
start network row
2021-07-14 09:21:46 -04:00
Jason Ertel
1dd81b6d49
Merge pull request #4790 from Security-Onion-Solutions/agsoupupdate
...
Remove old airgap scripts
2021-07-13 15:45:45 -04:00
Mike Reeves
741e825ab9
Remove old airgap scripts
2021-07-13 15:44:26 -04:00
William Wernert
e41811fbd0
[fix] Typo
2021-07-13 15:14:13 -04:00
m0duspwnens
f111106a9f
fix cords
2021-07-13 14:13:19 -04:00
m0duspwnens
f9e29eaede
update memory usage graph panel
2021-07-13 14:09:23 -04:00
William Wernert
e7a6172d7e
[fix] Add single quotes to strings
2021-07-13 14:07:27 -04:00
m0duspwnens
ec8f9228e8
add memory and docker container rows
2021-07-13 14:01:42 -04:00
m0duspwnens
6c12e26632
add mem usage, add docker graphs back, update nsm usage thresh
2021-07-13 13:55:01 -04:00
m0duspwnens
9a6ac7bd20
change panels
2021-07-13 12:30:45 -04:00
m0duspwnens
5b3751da70
new load averages panel
2021-07-13 12:24:32 -04:00
m0duspwnens
65127eb226
fix servername var
2021-07-13 12:04:52 -04:00
William Wernert
115e0a6fee
[fix] Add missing comma
2021-07-13 12:04:10 -04:00
m0duspwnens
ddfab44883
new id
2021-07-13 11:59:01 -04:00
Mike Reeves
6eab390962
Merge pull request #4788 from Security-Onion-Solutions/fix/fbpipeline
...
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:40:58 -04:00
Mike Reeves
35388056d3
Merge pull request #4789 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-07-13 11:40:44 -04:00
Mike Reeves
e2c5967191
Update HOTFIX
2021-07-13 11:38:20 -04:00
weslambert
7cdb967810
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:36:18 -04:00
m0duspwnens
8900d52c33
change y
2021-07-13 11:30:14 -04:00
m0duspwnens
bab72393e6
query and id changes
2021-07-13 11:23:06 -04:00
William Wernert
e059c25ebc
[fix][wip] Fix pipeline parsing errors
2021-07-13 11:05:05 -04:00
m0duspwnens
c87ca8f5dc
spacing
2021-07-13 10:42:33 -04:00
m0duspwnens
e01e3cdd43
change file name
2021-07-13 10:25:26 -04:00
m0duspwnens
2ab9ade761
add missing gridPos
2021-07-13 10:22:48 -04:00
m0duspwnens
0b35b8f6d6
add cpu row
2021-07-13 10:19:20 -04:00
William Wernert
9ff95f66dd
Merge branch 'dev' into feature/logscan
2021-07-13 10:02:58 -04:00
William Wernert
c1523c4936
Merge pull request #4782 from Security-Onion-Solutions/feature/check-local-mods
...
Add jinja raw tag
2021-07-13 08:58:25 -04:00
m0duspwnens
b6e31278a7
move old panels into old for organization
2021-07-13 08:57:01 -04:00
William Wernert
ca2b24f735
Add jinja raw tag
2021-07-13 08:46:57 -04:00
William Wernert
2b0bca8e55
Merge branch 'dev' into feature/logscan
2021-07-12 14:58:30 -04:00
m0duspwnens
98fe7e8700
fix mean
2021-07-12 14:37:17 -04:00
m0duspwnens
0acc3cc537
rename
2021-07-12 14:32:37 -04:00
m0duspwnens
8491ffde07
add docker container network usage graphs
2021-07-12 14:18:54 -04:00
Doug Burks
2ea3989497
Merge pull request #4775 from Security-Onion-Solutions/fix/suricata-dns-response-code
...
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:40:14 -04:00
doug
e6f9592cde
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:24:21 -04:00
William Wernert
222d79bf53
Merge pull request #4774 from Security-Onion-Solutions/feature/check-local-mods
...
Compare local files to their defaults to check for potentially breaking changes
2021-07-12 12:00:18 -04:00
m0duspwnens
19d9258717
add postfix , change color
2021-07-12 11:22:48 -04:00
m0duspwnens
b46456b78e
move math, add 2 decimal spot
2021-07-12 11:16:33 -04:00
m0duspwnens
cebc2ef09d
add missing ,
2021-07-12 11:13:32 -04:00
m0duspwnens
c4ff8f6876
convert seconds to days
2021-07-12 11:12:28 -04:00
m0duspwnens
619022ef7f
2 new panels to overview
2021-07-12 11:09:23 -04:00
weslambert
c0f3c5b3db
Merge pull request #4773 from Security-Onion-Solutions/feature/filebeat-logging-level
...
Allow setting Filebeat logging level in pillar
2021-07-12 10:55:43 -04:00
m0duspwnens
860b8bf945
panel changes
2021-07-12 10:34:39 -04:00
m0duspwnens
694db81b80
fix locations and panel ids
2021-07-12 10:29:09 -04:00
weslambert
a895270bc8
Allow setting Filebeat logging level in pillar
2021-07-12 10:27:43 -04:00
m0duspwnens
7474b451ca
rename file
2021-07-12 10:24:12 -04:00
m0duspwnens
e8eecc8bc1
rename file
2021-07-12 10:22:25 -04:00
m0duspwnens
28e33b413c
add more panels for overview
2021-07-12 10:17:23 -04:00
Jason Ertel
78c58e61ea
Resolves #4765
2021-07-12 09:38:01 -04:00
William Wernert
f3ecdf21bf
Revert "Add newline to local modifications warning"
...
This reverts commit ff656365d2 .
2021-07-12 09:28:24 -04:00
William Wernert
ff656365d2
Add newline to local modifications warning
2021-07-12 09:22:22 -04:00
William Wernert
ea7c09bb00
Merge branch 'dev' into feature/check-local-mods
2021-07-12 09:20:10 -04:00
Jason Ertel
e23f7cd3e7
Merge pull request #4766 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.70
2021-07-10 13:01:54 -04:00
Jason Ertel
c6bb32b862
Bump version to 2.3.70
2021-07-10 07:34:52 -04:00
m0duspwnens
0bde69b441
update panel
2021-07-09 16:47:39 -04:00
m0duspwnens
6fbafb74bd
update panel
2021-07-09 16:45:02 -04:00
m0duspwnens
9572c1f663
fix var
2021-07-09 16:33:09 -04:00
m0duspwnens
0fedb0f2c5
add 5 minute load avg panel
2021-07-09 16:29:48 -04:00
m0duspwnens
33d3aef9f5
yamlize gridpos
2021-07-09 16:14:25 -04:00
m0duspwnens
fb8ccedf66
reduce height by 2
2021-07-09 16:04:55 -04:00
m0duspwnens
efcf0accc1
change IDs
2021-07-09 16:01:57 -04:00
m0duspwnens
f556d5c07d
change row id
2021-07-09 15:58:45 -04:00
m0duspwnens
6c1f424c0b
fix row_overview
2021-07-09 15:56:27 -04:00
William Wernert
90970f97e8
Add function to check if files copied to local have been changed in default
2021-07-09 15:44:27 -04:00
m0duspwnens
d3137dc6b9
add row panels
2021-07-09 15:43:51 -04:00
m0duspwnens
efaf53f2f7
add a panel header, change memeory usage panel
2021-07-09 15:13:50 -04:00
m0duspwnens
beb7b89275
yamlize the gridpos for panels
2021-07-09 14:13:00 -04:00
Jason Ertel
8c15fa1627
Merge pull request #4758 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.13.3; Use nginx reverse proxy for access to Playbook and Soctopus
2021-07-09 12:40:33 -04:00
m0duspwnens
bc814c9be6
new panels, add containers var, hide manint and monint var from dash
2021-07-09 11:21:06 -04:00
William Wernert
bac7ef71d8
Add logscan.source.ips field
2021-07-09 10:55:11 -04:00
m0duspwnens
dd199ea30f
remove quotes if pillar doesnt exist
2021-07-09 10:00:47 -04:00
m0duspwnens
fc8acac1a5
change id
2021-07-08 17:39:34 -04:00
m0duspwnens
fec269c3e7
add combined container mem panel
2021-07-08 17:28:18 -04:00
m0duspwnens
8e366fd633
add combined container mem panel
2021-07-08 17:27:51 -04:00
m0duspwnens
f7d54186dd
remove all panels from standalone
2021-07-08 17:11:33 -04:00
m0duspwnens
ab92fb3910
add cpucount to standalone
2021-07-08 17:08:45 -04:00
m0duspwnens
6783e2e28b
dont hide cpucount on dashboard
2021-07-08 17:06:21 -04:00
m0duspwnens
4e47d3f458
remove single quotes
2021-07-08 17:04:41 -04:00
m0duspwnens
b265c7dcb7
single quote cpucount
2021-07-08 17:00:17 -04:00
m0duspwnens
f4fae89b8e
fix copy paste error
2021-07-08 16:50:25 -04:00
m0duspwnens
45f0b4c85f
manint and monint
2021-07-08 16:43:53 -04:00
m0duspwnens
7c80483f6e
change CPUS to $cpucount
2021-07-08 16:39:14 -04:00
Jason Ertel
08ba4fdbee
Update Kibana saved objects to 7.13.3
2021-07-08 16:34:16 -04:00
m0duspwnens
7085796601
replace SERVERNAME with $servername
2021-07-08 16:33:21 -04:00
m0duspwnens
091b5f73b1
update var
2021-07-08 14:43:38 -04:00
Jason Ertel
0c079edc1a
Reverse proxy requests to playbook, soctopus, and nodered
2021-07-08 14:27:16 -04:00
m0duspwnens
54cdfb89f6
remove common_standalone.json.jinja
2021-07-08 14:14:40 -04:00
m0duspwnens
f56514ed7d
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-08 14:12:26 -04:00
m0duspwnens
56697fde19
create common dashboard and define templates/dashbaord vars
2021-07-08 14:10:22 -04:00
William Wernert
80525ee736
[wip] Add logscan pipeline
2021-07-08 12:29:50 -04:00
Jason Ertel
a43bdd9aad
Merge pull request #4723 from Security-Onion-Solutions/dev
...
HEAVYNODE_REDIS hotfix
2021-07-08 11:42:22 -04:00
m0duspwnens
20360d0bb0
create node_config measurement for nodes to be used for grafana dashboard vars
2021-07-08 11:18:25 -04:00
Josh Patterson
70d7513f84
Merge pull request #4729 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 14:49:38 -04:00
Josh Patterson
12b7fd3ab4
whitespace
2021-07-07 14:48:07 -04:00
Josh Patterson
c32b5b5429
whitespace
2021-07-07 14:47:16 -04:00
Josh Patterson
ea2a748dba
whitespace
2021-07-07 14:44:44 -04:00
Josh Patterson
c1d7d8c55a
add new line
2021-07-07 14:43:20 -04:00
Josh Patterson
a3c58d8445
remove heavy soup
2021-07-07 14:42:38 -04:00
Josh Patterson
cfc5c2aef6
do ; instead of &&
2021-07-07 14:32:57 -04:00
Josh Patterson
313260a0c5
add heavy action in soup for ssl redis, es, ls, fb
2021-07-07 14:22:45 -04:00
Josh Patterson
ee548aaf83
Merge pull request #4728 from Security-Onion-Solutions/fix/heavyfix
...
remove soup control of heavy
2021-07-07 14:01:32 -04:00
m0duspwnens
5eab57e500
remove soup control of heavy
2021-07-07 13:58:52 -04:00
Josh Patterson
6f48fdad42
Merge pull request #4727 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 12:15:50 -04:00
m0duspwnens
98fb5109d7
tell heavys to update ssl and restart containers for HEAVYNODE_SSL_LOGSTASH_REDIS_PIPELINES hotfix
2021-07-07 12:05:38 -04:00
m0duspwnens
9c2ead16cc
common name changes, allow cert to be managed regardless of expire date for heavy node
2021-07-07 10:22:37 -04:00
Jason Ertel
c4293c6119
Merge pull request #4724 from Security-Onion-Solutions/kilo
...
Merge master into dev via kilo
2021-07-07 07:21:21 -04:00
Jason Ertel
13c392d758
Merge branch 'master' into kilo
2021-07-07 06:40:30 -04:00
m0duspwnens
35f10518b2
map file into container
2021-07-06 17:12:21 -04:00
m0duspwnens
03066c4674
rename file
2021-07-06 17:08:29 -04:00
m0duspwnens
e33a6892b3
point to new location
2021-07-06 16:58:15 -04:00
m0duspwnens
87bb3f4a6b
quote the 5m
2021-07-06 16:45:10 -04:00
m0duspwnens
62bfaa4e45
send node_config data into telegraf for dashboard queries
2021-07-06 16:30:35 -04:00
Josh Patterson
9e94e605ee
Merge pull request #4715 from Security-Onion-Solutions/fix/heavyfix
...
add to HOTFIX file
2021-07-06 16:01:11 -04:00
m0duspwnens
f8dc647b1f
add to HOTFIX file
2021-07-06 15:59:35 -04:00
Josh Patterson
fc727d6909
Merge pull request #4711 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-06 15:56:02 -04:00
m0duspwnens
c1d61dc624
add to HOTFIX file
2021-07-06 15:54:15 -04:00
m0duspwnens
0627ca2fc2
use heavynode hostname for certs if heavynode. changes to logstash pipeline for redis if heavynode
2021-07-06 15:32:39 -04:00
weslambert
ce0b064972
Add conditional for heavynode for redis and elasticsearch
2021-07-06 14:21:29 -04:00
weslambert
2f3f04e4ca
Change from nodename to host
2021-07-06 14:18:39 -04:00
weslambert
2e91f27336
Add conditional for heavynode
2021-07-06 14:17:49 -04:00
weslambert
10b1829830
Add conditional for heavynode
2021-07-06 14:16:34 -04:00
weslambert
4946f32d88
Add extra_hosts entry for local instance when running as heavy node
2021-07-06 14:14:58 -04:00
m0duspwnens
dc1363aaf5
create file for telegraf to read node config details
2021-07-06 13:06:03 -04:00
m0duspwnens
a5067718d2
comma control
2021-07-06 11:06:35 -04:00
m0duspwnens
98505a9a3f
beginning of managing individual panels in grafana
2021-07-06 10:08:36 -04:00
Mike Reeves
e054fdb464
Merge pull request #4680 from Security-Onion-Solutions/dev
...
ECSFIX HOTFIX
2021-07-02 11:16:49 -04:00
Mike Reeves
3c8ad18693
Merge pull request #4683 from Security-Onion-Solutions/2.3.60ecs
...
2.3.60 ECSFIX
2021-07-02 11:05:17 -04:00
Mike Reeves
0a91f571c1
2.3.60 ECSFIX
2021-07-02 10:41:15 -04:00
Mike Reeves
8db5284f6e
Merge pull request #4679 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update telegraf.conf
2021-07-02 09:48:33 -04:00
Mike Reeves
22aa695508
Update telegraf.conf
2021-07-02 09:47:31 -04:00
m0duspwnens
a16f733622
add individual panels
2021-07-02 09:35:04 -04:00
Mike Reeves
af7d6c8cb5
Merge pull request #4678 from Security-Onion-Solutions/ecsfix1
...
ECS Hotfix
2021-07-02 09:14:42 -04:00
Mike Reeves
693f455862
ECS hotfix
2021-07-02 08:55:49 -04:00
Mike Reeves
b0abd290a9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-02 08:47:02 -04:00
Mike Reeves
0a9686f584
Merge pull request #4669 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
2.3.70
2021-07-01 14:39:01 -04:00
Mike Reeves
0b11bf6266
Update VERSION
2021-07-01 14:37:56 -04:00
Mike Reeves
73b47716bc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-01 13:00:30 -04:00
Mike Reeves
b5fecd30cf
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 17:05:17 -04:00
Mike Reeves
a08166f27d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 11:38:15 -04:00
Mike Reeves
846aef1bd6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-24 14:54:51 -04:00
Mike Reeves
78fa4feac6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-23 15:38:38 -04:00
Mike Reeves
6e780164ea
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-22 09:52:44 -04:00
Mike Reeves
85d7e75fb1
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 16:09:11 -04:00
Mike Reeves
0dc4bc3cee
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 13:30:58 -04:00
Mike Reeves
8d6b0e23ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-16 13:23:44 -04:00
Mike Reeves
8aaf3e1052
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-04 10:44:13 -04:00
Mike Reeves
21b92ac077
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-02 13:06:29 -04:00
Mike Reeves
96eab86bc6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-29 11:19:19 -04:00
Mike Reeves
4c55e5a6cc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-28 10:27:55 -04:00
Mike Reeves
77533f7873
Repo Fix
2021-04-27 15:45:35 -04:00
Mike Reeves
a6b2eefee1
Prompt airgap to update
2021-04-27 15:33:52 -04:00
Mike Reeves
4cea08c080
Prompt airgap to update
2021-04-27 15:32:00 -04:00
Mike Reeves
d56e66917a
2.3.50 sig files
2021-04-26 09:18:15 -04:00