Mike Reeves
b2a2dc5aea
Merge pull request #10037 from Security-Onion-Solutions/2.4/dev
...
2.4.0 Beta 1
2023-03-28 16:08:01 -04:00
Josh Patterson
72078848d3
Merge pull request #10041 from Security-Onion-Solutions/firsthighstatecronfix
...
add path to first highstate cron
2023-03-28 14:38:19 -04:00
Josh Patterson
af4acd5597
add path to first highstate cron
2023-03-28 14:37:28 -04:00
weslambert
de902ebd02
Merge pull request #10024 from Security-Onion-Solutions/esspace
...
Manage disk-based index deletion via so-curator-cluster-delete
2023-03-28 12:25:19 -04:00
Wes
6099a04e41
Change how the size is determined, in case there a decimal value is provided
2023-03-28 16:04:54 +00:00
Jason Ertel
44c696a495
Merge pull request #10036 from Security-Onion-Solutions/commonprofile
...
ensure scripts are run as root, have copyright, and path is correct
2023-03-28 11:59:10 -04:00
Josh Patterson
16606c1aaa
Merge pull request #10038 from Security-Onion-Solutions/addbangs
...
change #/bin/bash to #!/bin/bash
2023-03-28 11:58:09 -04:00
Jason Ertel
4efe22efb3
Update so-elasticsearch-cluster-settings
2023-03-28 11:57:41 -04:00
Jason Ertel
591129b98c
Update so-elasticsearch-pipelines
2023-03-28 11:57:22 -04:00
Jason Ertel
60d770411a
Update so-elasticsearch-roles-load
2023-03-28 11:57:07 -04:00
Jason Ertel
5f49a120de
Update so-elasticsearch-templates-load
2023-03-28 11:56:51 -04:00
m0duspwnens
64446f585c
change #/bin/bash to #!/bin/bash
2023-03-28 11:55:47 -04:00
Wes
ed8f944638
Fix typo in GLOBALS reference
2023-03-28 15:55:33 +00:00
Mike Reeves
74840264d7
Update so-elasticsearch-cluster-space-used
2023-03-28 11:49:05 -04:00
Jason Ertel
492fe1fc85
Ensure /usr/sbin is in path
2023-03-28 11:48:31 -04:00
Mike Reeves
e77e645a36
Update so-elasticsearch-cluster-space-total
2023-03-28 11:45:57 -04:00
Mike Reeves
636505ef98
Add license and common
2023-03-28 11:18:56 -04:00
weslambert
942182e826
Remove additional copyright in so-curator-cluster-delete-delete
2023-03-28 11:00:14 -04:00
weslambert
303fec6302
Fix verbiage for so-curator-cluster-delete-delete
2023-03-28 10:59:39 -04:00
weslambert
9411f5ca79
Fix closed index function and check
2023-03-28 10:54:21 -04:00
Wes
d494381e9d
Update verbiage for so-curator-cluster-delete
2023-03-28 14:18:49 +00:00
Wes
e1bda5acfd
Update verbiage for so-curator-cluster-delete-delete
2023-03-28 14:18:27 +00:00
Wes
138b312705
Fix script name
2023-03-28 13:52:59 +00:00
Wes
82efce0b31
Ensure so-curator-cluster-delete is run to manage so-curator-cluster-delete-delete
2023-03-28 13:23:23 +00:00
Wes
1ab253b8c3
Use explicit path to so-elasticsearch-query
2023-03-28 13:18:14 +00:00
Wes
a1394b9102
Use explicit path to so-elasticsearch-query
2023-03-28 13:18:00 +00:00
Wes
b3b030958c
Use explicit path to so-elasticsearch-query
2023-03-28 13:17:23 +00:00
Josh Patterson
ebdd74a420
Merge pull request #10032 from Security-Onion-Solutions/evalelasticfleet
...
add elasticfleet state to top for eval node
2023-03-28 09:03:16 -04:00
m0duspwnens
d886265211
add elasticfleet state to top for eval node
2023-03-28 09:01:41 -04:00
Wes
adbc9df222
Changes for LOG_SIZE_LIMIT
2023-03-28 12:54:32 +00:00
Doug Burks
1ad65f6326
Merge pull request #10030 from Security-Onion-Solutions/dougburks-patch-1
...
Update soc_idh.yaml
2023-03-28 08:54:12 -04:00
Doug Burks
46d9e0b804
Update soc_idh.yaml
2023-03-28 08:53:05 -04:00
Wes
f854d92cab
Remove the cluster space configuration script reference from the Elasticsearch state
2023-03-28 12:27:45 +00:00
Wes
22e8e3be28
Remove the cluster space configuration script
2023-03-28 12:27:12 +00:00
Wes
4352825ceb
Calculate log size limit every time so-curator-cluster-delete-delete runs
2023-03-28 12:25:49 +00:00
Wes
e2290d8a8e
Remove unncessary Salt logic for Elasticsearch
2023-03-28 12:19:36 +00:00
Wes
c68235c169
Fix Curator script name
2023-03-28 02:27:27 +00:00
Wes
a38aa903ac
Configure cluster space settings
2023-03-28 01:36:52 +00:00
Wes
fc0b9fa47c
Remove Curator closed index deletion scripts
2023-03-28 00:57:45 +00:00
Wes
32e92d10ad
Add new cluster space management scripts
2023-03-28 00:55:56 +00:00
Wes
7030f35561
Update Curator state
2023-03-28 00:54:36 +00:00
Wes
934b8894e2
Update Curator scripts
2023-03-28 00:54:04 +00:00
Jason Ertel
100d9f14e9
Merge pull request #10023 from Security-Onion-Solutions/kilo
...
fix role
2023-03-27 19:31:06 -04:00
Jason Ertel
34cd823cd4
fix role
2023-03-27 18:59:32 -04:00
Josh Patterson
a86da24bde
Merge pull request #10021 from Security-Onion-Solutions/bpffix
...
remove default zeek bpf
2023-03-27 17:01:36 -04:00
m0duspwnens
fcb6f3eaf1
remove default zeek bpf
2023-03-27 16:59:27 -04:00
Mike Reeves
6cc510d51b
Merge pull request #10020 from Security-Onion-Solutions/kilo
...
add minion CIDR to search also
2023-03-27 16:56:56 -04:00
Jason Ertel
2b1576249a
add minion CIDR to search also
2023-03-27 16:44:21 -04:00
Josh Brower
2dd48c6f0b
Merge pull request #10019 from Security-Onion-Solutions/2.4/idhfix
...
Add annotations
2023-03-27 15:19:15 -04:00
Josh Brower
d22a5b2eb3
Add annotations
2023-03-27 15:16:47 -04:00
Josh Patterson
8b626d2c67
Merge pull request #10018 from Security-Onion-Solutions/managersaltrestart
...
Managersaltrestart
2023-03-27 13:37:04 -04:00
m0duspwnens
0d87a5d739
import sensor vars in import vars
2023-03-27 12:51:29 -04:00
Mike Reeves
6c3c5730c5
Add curator settings
2023-03-27 12:33:34 -04:00
Mike Reeves
2cb6f0f1e6
Add curator settings
2023-03-27 12:30:39 -04:00
m0duspwnens
42cc419e00
restart salt master and minion after manager install completes
2023-03-27 11:30:03 -04:00
Mike Reeves
7752529b42
Merge pull request #10015 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-common
2023-03-27 10:51:26 -04:00
Mike Reeves
7f395c4c1e
Update so-common
2023-03-27 10:49:36 -04:00
Mike Reeves
94ae7469e3
Merge pull request #10012 from Security-Onion-Solutions/pkg
...
Modify reposync useragent
2023-03-27 10:21:35 -04:00
Mike Reeves
2a288c7e4a
Update so-functions
2023-03-27 10:18:57 -04:00
Mike Reeves
1602551295
Modify reposync useragent
2023-03-27 10:14:32 -04:00
Mike Reeves
72d01b13ed
Modify reposync useragent
2023-03-27 10:12:13 -04:00
Mike Reeves
f34bb40025
Merge pull request #10011 from Security-Onion-Solutions/pkg
...
Add unzip
2023-03-27 09:28:05 -04:00
Mike Reeves
8246293983
Add unzip
2023-03-27 08:40:36 -04:00
Josh Patterson
80043d154a
Merge pull request #10004 from Security-Onion-Solutions/guifixes
...
Guifixes
2023-03-24 16:58:19 -04:00
m0duspwnens
aa66a6471a
Merge remote-tracking branch 'origin/2.4/dev' into guifixes
2023-03-24 16:16:32 -04:00
m0duspwnens
1a6d887b5f
idh setup changes
2023-03-24 16:16:22 -04:00
Mike Reeves
3fed3b3f3e
Merge pull request #10003 from Security-Onion-Solutions/mirrorz
...
Add additional mirror
2023-03-24 15:13:03 -04:00
Mike Reeves
cb2fdae368
Switch Repos
2023-03-24 14:40:59 -04:00
Josh Brower
d9e1a54479
Merge pull request #10001 from Security-Onion-Solutions/2.4/playbookfix
...
Fix errors
2023-03-24 14:31:43 -04:00
Mike Reeves
afe4d75d91
Switch Repos
2023-03-24 14:13:48 -04:00
Doug Burks
7ced7488c7
Merge pull request #10000 from Security-Onion-Solutions/dougburks-patch-1
...
Add four new GeoIP dashboards
2023-03-24 14:11:58 -04:00
Doug Burks
5be5466efe
fix GeoIP queries
2023-03-24 14:03:12 -04:00
Mike Reeves
b2c2e1574f
Switch Repos
2023-03-24 14:02:13 -04:00
Doug Burks
a9dc7a14cb
fix GeoIP queries
2023-03-24 13:56:51 -04:00
m0duspwnens
627b243cac
Merge remote-tracking branch 'origin/2.4/dev' into guifixes
2023-03-24 13:52:38 -04:00
m0duspwnens
462b2b23b9
rework idh for web ui
2023-03-24 13:52:21 -04:00
Doug Burks
aa9d44ab09
Add four new GeoIP dashboards
2023-03-24 13:51:13 -04:00
Jason Ertel
890e1897af
Merge pull request #9999 from Security-Onion-Solutions/kilo
...
prune system volumes during upgrade
2023-03-24 13:30:57 -04:00
Jason Ertel
0be57e686e
prune system volumes during upgrade
2023-03-24 13:22:21 -04:00
Josh Brower
16bc63233f
Fix errors
2023-03-24 09:33:12 -04:00
Mike Reeves
e38b0313c7
Merge pull request #9994 from Security-Onion-Solutions/hotones
...
Switch up elastic roles
2023-03-23 16:59:49 -04:00
Josh Brower
c6f6f306a7
Merge pull request #9993 from Security-Onion-Solutions/2.4/ingestsoclogs
...
SOC Logs & Hunt Query
2023-03-23 16:25:32 -04:00
Josh Brower
bad905f54c
SOC Logs & Hunt Query
2023-03-23 16:22:59 -04:00
Mike Reeves
90159f4bcd
Switch up elastic roles
2023-03-23 15:09:40 -04:00
weslambert
0f66645a89
Merge pull request #9990 from Security-Onion-Solutions/fix/elasticsearch_node_attrs_remove
...
Remove node attrs configuration since node roles will be used
2023-03-23 13:48:00 -04:00
weslambert
0a9a064648
Remove node attrs configuration since node roles will be used
2023-03-23 13:45:51 -04:00
weslambert
d6bc20a2b8
Merge pull request #9986 from Security-Onion-Solutions/fix/elastic_agent_template_changes
...
Elastic Agent template changes
2023-03-23 13:07:22 -04:00
Mike Reeves
886bcda38c
Merge pull request #9988 from Security-Onion-Solutions/repofun
...
Add Repo Sync
2023-03-23 12:49:06 -04:00
Mike Reeves
3b671efa8e
Fix cache location
2023-03-23 12:47:48 -04:00
Mike Reeves
0a096712cb
Fix cache location
2023-03-23 12:39:31 -04:00
Mike Reeves
c977f38a58
Change repo conf permissions
2023-03-23 11:56:40 -04:00
Mike Reeves
8f4076ccd6
Change repo conf permissions
2023-03-23 11:46:32 -04:00
Mike Reeves
3756c93518
Change repo download script location
2023-03-23 11:05:48 -04:00
Mike Reeves
b68cf85392
Change repo download script location
2023-03-23 11:04:26 -04:00
Mike Reeves
e52087b742
Saltify it up
2023-03-23 10:54:01 -04:00
Mike Reeves
02aa8662f7
Saltify it up
2023-03-23 10:52:05 -04:00
Mike Reeves
f8d5acd37d
Saltify it up
2023-03-23 10:43:47 -04:00
Mike Reeves
b3ea4194dd
Only allow reposync to run on managers
2023-03-23 09:49:02 -04:00
Wes
84360aa9bf
Set replicas for Osquery manager indices to 0
2023-03-22 21:47:49 +00:00
Josh Patterson
c64987e756
Merge pull request #9985 from Security-Onion-Solutions/m0duspwnens-patch-1
...
ensure highstate schedule added sooner in highstate
2023-03-22 17:24:23 -04:00
Josh Patterson
c8e93f0388
Update top.sls
2023-03-22 17:22:21 -04:00
Wes
3fba27a0d4
Ensure component template files are in the correct directory
2023-03-22 20:45:33 +00:00
Wes
28f5dcd43b
Add managed generic Elastic Agent log component templates
2023-03-22 19:57:46 +00:00
Wes
eaaa028999
Update Elastic Agent template settings
2023-03-22 19:52:13 +00:00
Mike Reeves
f8e59478f4
Merge pull request #9984 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update config.map.jinja
2023-03-22 15:49:35 -04:00
Mike Reeves
d2bc5e4af2
Update config.map.jinja
2023-03-22 15:45:51 -04:00
Josh Patterson
4f995c1c7e
Merge pull request #9983 from Security-Onion-Solutions/2.4/zeekbpf
...
add sensor vars to eval
2023-03-22 12:23:07 -04:00
weslambert
bc2a84c631
Merge pull request #9982 from Security-Onion-Solutions/fix/elastic_integration_and_pipeline_strelka
...
Change data stream name and 'event.dataset' value for Strelka events
2023-03-22 11:08:58 -04:00
weslambert
6d87620c6a
Explicitly set 'event.dataset' as 'file'
2023-03-22 11:04:18 -04:00
weslambert
68380d7ecb
Change data_stream.dataset from 'file' to 'strelka'
2023-03-22 11:02:38 -04:00
m0duspwnens
5a2ef21ce4
add sensor vars to eval
2023-03-22 09:55:30 -04:00
m0duspwnens
fdaf8e8c68
idh changes for web ui
2023-03-22 09:38:40 -04:00
Mike Reeves
00b1ecb7d9
Merge pull request #9979 from Security-Onion-Solutions/esfun
...
Elastic Fixes
2023-03-22 08:51:24 -04:00
Mike Reeves
007e2baf41
Change Elastic Logic
2023-03-21 17:46:52 -04:00
Mike Reeves
5fc297b8c1
Change Elastic Logic
2023-03-21 16:52:08 -04:00
Mike Reeves
07f303205a
Merge pull request #9977 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Update so-minion
2023-03-21 15:50:52 -04:00
Mike Reeves
aeb6d47637
Update so-minion
2023-03-21 13:39:24 -04:00
Josh Brower
a247d1cc50
Merge pull request #9978 from Security-Onion-Solutions/2.4/updateEA
...
2.4/update ea
2023-03-21 13:27:59 -04:00
Mike Reeves
30fc74ac09
Update so-minion
2023-03-21 12:53:35 -04:00
Josh Brower
cd6bf0fe78
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/updateEA
2023-03-21 12:48:30 -04:00
Josh Brower
d87060b56e
Update Elastic Agent to 8.6.2
2023-03-21 12:48:02 -04:00
Mike Reeves
1526a7de11
Rework IDH phase 1
2023-03-21 11:26:30 -04:00
Mike Reeves
d89310e479
Rework IDH phase 1
2023-03-21 11:25:06 -04:00
Mike Reeves
bd17121834
Rework IDH phase 1
2023-03-21 11:23:31 -04:00
Jason Ertel
ca363053e6
Merge pull request #9975 from Security-Onion-Solutions/kilo
...
catch errors and exit with proper exit code
2023-03-21 10:51:36 -04:00
Josh Patterson
a0eea10a1d
Merge pull request #9974 from Security-Onion-Solutions/saltlogging
...
use saltversion grain to determine installed version
2023-03-21 10:46:57 -04:00
Jason Ertel
efd5f7b8a2
catch errors and exit with proper exit code
2023-03-21 10:44:21 -04:00
m0duspwnens
05b1a445d3
use saltversion grain to determine installed version
2023-03-21 10:12:10 -04:00
Josh Patterson
cdb714f331
Merge pull request #9973 from Security-Onion-Solutions/2.4/zeekbpf
...
2.4/zeekbpf
2023-03-21 09:54:39 -04:00
Mike Reeves
9ca9b9d4da
Rework IDH phase 1
2023-03-21 09:53:06 -04:00
Mike Reeves
a3d38dd2e7
Rework IDH phase 1
2023-03-21 09:49:28 -04:00
Mike Reeves
41554e8311
Merge pull request #9969 from Security-Onion-Solutions/guifixes
...
Add several annotations
2023-03-21 08:51:53 -04:00
Mike Reeves
444988f287
Adjust annotations
2023-03-21 08:48:02 -04:00
m0duspwnens
02c79463e1
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/zeekbpf
2023-03-21 08:45:07 -04:00
Mike Reeves
64904406b6
Adjust annotations
2023-03-21 08:41:48 -04:00
Josh Brower
1f23e4aafe
Merge pull request #9966 from Security-Onion-Solutions/2.4/kratosfix
...
Fix Kratos parsing
2023-03-21 07:12:49 -04:00
Mike Reeves
bc7261acfe
Adjust patch annotations
2023-03-20 20:16:43 -04:00
Mike Reeves
01d470a426
Adjust patch annotations
2023-03-20 20:13:29 -04:00
Mike Reeves
f810f9cbf0
Adjust patch annotations
2023-03-20 20:12:26 -04:00
Mike Reeves
507142cde4
Adjust patch annotations
2023-03-20 20:02:23 -04:00
Jason Ertel
331d4833b1
Merge pull request #9967 from Security-Onion-Solutions/kilo
...
Kilo
2023-03-20 18:27:35 -04:00
Jason Ertel
2e6fa1eff0
Merge branch '2.4/dev' into kilo
2023-03-20 18:15:00 -04:00
m0duspwnens
0fff3a5a11
suricata bpf
2023-03-20 17:31:56 -04:00
Mike Reeves
eb61b0c98f
Adjust sensor annotations
2023-03-20 17:10:36 -04:00
m0duspwnens
252afa8499
bpf for pcap
2023-03-20 17:10:34 -04:00
Mike Reeves
a6e34ae1d7
Adjust manager annotations
2023-03-20 16:54:57 -04:00
Josh Brower
df036206a8
Fix Kratos parsing
2023-03-20 16:53:25 -04:00
Mike Reeves
27fdad4a25
Adjust manager annotations
2023-03-20 16:52:22 -04:00
Mike Reeves
0bb2fd7d45
Adjust manager annotations
2023-03-20 16:50:18 -04:00
Mike Reeves
bb3480cd76
Adjust host annotations
2023-03-20 16:20:22 -04:00
Mike Reeves
22c3a4d398
Adjust elasticsearch annotations
2023-03-20 16:08:26 -04:00
Mike Reeves
8c2a43c073
Adjust docker annotations
2023-03-20 15:51:48 -04:00
Mike Reeves
fe13f90394
Adjust docker annotations
2023-03-20 15:33:22 -04:00
m0duspwnens
903ad530fe
move zeek bpf from zeek pillar to bpf pillar
2023-03-20 15:28:33 -04:00
Mike Reeves
9a43cd71e0
Adjust docker annotations
2023-03-20 15:19:54 -04:00
Jason Ertel
c43194665e
add sudo prefix
2023-03-20 12:57:13 -04:00
Mike Reeves
a22af96403
Merge branch '2.4/dev' of https://github.com/Security-Onion-Solutions/securityonion into guifixes
2023-03-20 12:26:48 -04:00
Josh Brower
03393a95d9
Merge pull request #9963 from Security-Onion-Solutions/2.4/fixidh
...
Remove hosts file edit
2023-03-20 12:15:12 -04:00
Josh Brower
325e767587
Remove hosts file edit
2023-03-20 12:11:45 -04:00
Jason Ertel
1771a3123f
Merge pull request #9961 from Security-Onion-Solutions/kilo
...
Backup old setup logs earlier in setup
2023-03-20 11:24:08 -04:00
Mike Reeves
823dde2856
Adjust repo sync
2023-03-20 11:17:15 -04:00
Jason Ertel
6b8b7df3c2
Move old setup/error logs before any logs are written on a subsequent setup invocation
2023-03-20 11:04:28 -04:00
Jason Ertel
da1c501cf7
Move old setup/error logs before any logs are written on a subsequent setup invocation
2023-03-20 11:01:07 -04:00
Jason Ertel
604db7534c
Merge branch '2.4/dev' into kilo
2023-03-20 10:46:37 -04:00
Jason Ertel
43712182a0
update help for clarity
2023-03-20 10:46:23 -04:00
Mike Reeves
9487dbffdf
Merge pull request #9960 from Security-Onion-Solutions/guifixes
...
Add gui components for fleet
2023-03-20 09:54:50 -04:00
Mike Reeves
cdbbc8e64c
Add gui components for fleet
2023-03-20 09:46:57 -04:00
Mike Reeves
1a70a6eb30
Merge pull request #9949 from Security-Onion-Solutions/guifixes
...
Change the salt dir for elastic fleet
2023-03-20 08:59:09 -04:00
Mike Reeves
da3fa31439
Merge branch '2.4/dev' into guifixes
2023-03-20 08:57:42 -04:00
Josh Brower
542eb19cdc
Merge pull request #9954 from Security-Onion-Solutions/2.4/whiptailsummary
...
Dist vs. non-Dist Install Summary
2023-03-20 08:37:10 -04:00
Josh Brower
c89bae7319
Wording tweaks
2023-03-20 07:51:44 -04:00
Josh Brower
3073b752bd
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/whiptailsummary
2023-03-20 07:48:40 -04:00
Josh Brower
d23c09a2ee
Merge pull request #9956 from Security-Onion-Solutions/2.4/kibanaui
...
Setup Kibana default space
2023-03-20 07:39:43 -04:00
Josh Brower
b59466139a
Merge pull request #9959 from Security-Onion-Solutions/2.4/curlquiet
...
2.4/wgetquiet
2023-03-20 07:37:30 -04:00
Josh Brower
cbf7b66729
Set wget to be quiet
2023-03-20 07:29:10 -04:00
Josh Brower
5b9ff06a85
Setup Kibana default space
2023-03-19 09:17:12 -04:00
Josh Brower
792732a8cf
summary changes
2023-03-18 13:09:46 -04:00
Josh Brower
536391bb3b
rename elasticfleet state
2023-03-17 16:14:29 -04:00
Mike Reeves
caa08e9cf0
Change the salt dir for elastic fleet
2023-03-17 11:44:56 -04:00
Mike Reeves
460f84d80f
Merge pull request #9950 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update so-functions
2023-03-17 11:36:31 -04:00
Mike Reeves
d7b0ed93c9
Update so-functions
2023-03-17 11:27:29 -04:00
Mike Reeves
4944365341
Change the salt dir for elastic fleet
2023-03-17 11:02:02 -04:00
Doug Burks
8a9bc8aefa
Merge pull request #9948 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typo and improve formatting in so-whiptail
2023-03-17 10:25:48 -04:00
Doug Burks
c5b16494d7
Fix typo and improve formatting in so-whiptail
2023-03-17 10:21:21 -04:00
Josh Brower
b9c4e647c4
Merge pull request #9946 from Security-Onion-Solutions/2.4/whiptailchanges
...
Add next steps to install summary
2023-03-17 10:16:05 -04:00
Josh Brower
8f5daa785b
Add next steps to install summary
2023-03-17 10:14:44 -04:00
Josh Patterson
9893fce105
Merge pull request #9945 from Security-Onion-Solutions/2.4/strelka
...
2.4/strelka
2023-03-17 09:55:45 -04:00
m0duspwnens
91da3fd797
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/strelka
2023-03-17 08:39:10 -04:00
m0duspwnens
924d598a8a
add filecheck_runas
2023-03-17 08:38:56 -04:00
Mike Reeves
c7099280da
Merge pull request #9944 from Security-Onion-Solutions/guifixes
...
Change yum to dnf
2023-03-17 08:28:26 -04:00
Mike Reeves
bd1eb9c7df
Change yum to dnf
2023-03-16 18:05:38 -04:00
m0duspwnens
dd4461daf4
remove other filecheck map import
2023-03-16 17:50:19 -04:00
m0duspwnens
a9b8877268
remove filecheckdefaults from strelka init
2023-03-16 17:15:52 -04:00
m0duspwnens
7950f692a8
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/strelka
2023-03-16 16:41:24 -04:00
m0duspwnens
0dfbbfcf8e
fix spacing on filecheck config
2023-03-16 16:37:38 -04:00
m0duspwnens
2056ce37c6
strelka ui things
2023-03-16 16:32:41 -04:00
Mike Reeves
e88d459ef4
Merge pull request #9942 from Security-Onion-Solutions/guifixes
...
Fix Repo Issues and Change curl to check for Salt ports
2023-03-16 15:59:47 -04:00
Mike Reeves
d12367ed75
Force package update before syncing the repo
2023-03-16 15:54:00 -04:00
Mike Reeves
ef4882198a
Force package update before syncing the repo
2023-03-16 15:48:57 -04:00
Mike Reeves
2b65c1498d
Force package update before syncing the repo
2023-03-16 15:45:04 -04:00
Mike Reeves
957467eae0
Force package update before syncing the repo
2023-03-16 15:41:29 -04:00
Mike Reeves
849e82e39f
Force package updates and curl check fix
2023-03-16 15:36:43 -04:00
Mike Reeves
6e3194486c
Force package update before syncing the repo
2023-03-16 13:50:22 -04:00
Josh Brower
336cf3ccf8
Merge pull request #9940 from Security-Onion-Solutions/2.4/idh-logs
...
Add IDH log ingest
2023-03-16 13:16:17 -04:00
Josh Brower
d78128dbf4
Formatting
2023-03-16 13:11:12 -04:00
Josh Brower
a96473554d
Add IDH log ingest
2023-03-16 12:56:04 -04:00
Mike Reeves
53e93f01c6
Force an update after repo is configured
2023-03-16 09:49:57 -04:00
Mike Reeves
d0955b3e91
Merge pull request #9937 from Security-Onion-Solutions/guifixes
...
Re-Work Backups
2023-03-16 09:42:07 -04:00
Jason Ertel
ad2616900c
Merge pull request #9939 from Security-Onion-Solutions/kilo
...
automated testing support; removal of nonexistent ScanRuby strelka scanner
2023-03-16 09:30:05 -04:00
Jason Ertel
3ab3e4712c
remove kilo for merge
2023-03-16 09:16:28 -04:00
Jason Ertel
49df376bcc
Remove non-existant Ruby scanner
2023-03-15 19:24:03 -04:00
Mike Reeves
f288d0dd61
Re-Work Backups
2023-03-15 17:58:15 -04:00
Mike Reeves
3156b1ed0c
Re-Work Backups
2023-03-15 17:53:14 -04:00
Mike Reeves
c355e6eaf0
Merge pull request #9935 from Security-Onion-Solutions/guifixes
...
Fix IDS tools
2023-03-15 17:27:07 -04:00
Mike Reeves
d4f5209e39
Re-Work IDSTOOLS
2023-03-15 17:22:54 -04:00
Mike Reeves
afcd1155bf
Re-Work IDSTOOLS
2023-03-15 17:19:33 -04:00
Mike Reeves
28dc490775
Re-Work IDSTOOLS
2023-03-15 16:58:52 -04:00
Mike Reeves
02d013c0cc
Re-Work IDSTOOLS
2023-03-15 16:47:43 -04:00
Mike Reeves
b56baf900c
Re-Work IDSTOOLS
2023-03-15 16:44:53 -04:00
Jason Ertel
49a9affe2a
Merge branch '2.4/dev' into kilo
2023-03-15 16:39:26 -04:00
Mike Reeves
0d30c14561
Re-Work IDSTOOLS
2023-03-15 16:33:33 -04:00
Jason Ertel
fbefe229c1
add test support to so-minion
2023-03-15 15:27:26 -04:00
Mike Reeves
a36a6d5659
Strelka UI components
2023-03-15 10:40:16 -04:00
Josh Patterson
b809b22566
Merge pull request #9931 from Security-Onion-Solutions/2.4/strelka
...
2.4/strelka
2023-03-14 16:16:53 -04:00
m0duspwnens
f9b8c78d74
move repos to rules dir
2023-03-14 14:43:13 -04:00
m0duspwnens
7cf4e6b03b
add rules dir, change so-yar-update to save to local/salt/strelka/rules
2023-03-14 13:59:31 -04:00
m0duspwnens
5f7256c826
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/strelka
2023-03-14 13:26:15 -04:00
m0duspwnens
b38d5df684
set default mime_db
2023-03-14 13:25:51 -04:00
weslambert
4e0390963b
Merge pull request #9928 from Security-Onion-Solutions/fix/curator_elastic_agent_filebeat_actions_close
...
Fix Curator Action Files
2023-03-14 10:58:53 -04:00
weslambert
8eba3426be
Remove extra dash for 'logs-elastic_agent-metricbeat-default' key
2023-03-14 10:51:50 -04:00
weslambert
7c39938e14
Change 'elastic_agent.filebeat' to 'elastic_agent-filebeat'
2023-03-14 10:48:50 -04:00
weslambert
123275ca35
Merge pull request #9926 from Security-Onion-Solutions/fix/curator_additional_elastic_agent_indices
...
Add more Elastic Agent Curator actions
2023-03-14 09:59:47 -04:00
Wes
766e6a7974
Add 'logs-windows-sysmon_operational-delete' for Windows Sysmon operational indices
2023-03-14 13:51:49 +00:00
Wes
f0d4c16b2b
Add more Elastic Agent index keys for Curator
2023-03-14 13:49:13 +00:00
Wes
412e5c0402
Add more Elastic Agent Curator action files
2023-03-14 13:46:08 +00:00
Josh Brower
fbac23c28d
Merge pull request #9925 from Security-Onion-Solutions/2.4/fiedfix
...
Removes Suricata host.* fields
2023-03-14 07:38:05 -04:00
weslambert
ebc943fcab
Merge pull request #9924 from Security-Onion-Solutions/fix/curator_action_file_system_syslog_delete
...
Fix Elastic Agent system syslog default delete file configuration
2023-03-13 17:28:38 -04:00
weslambert
486de12ca5
Delete logs-system-auth-syslog-close.yaml
2023-03-13 17:27:52 -04:00
weslambert
f4112b30c0
Fix index reference for system auth default
2023-03-13 17:27:06 -04:00
weslambert
bab40de58d
Fix system auth default key value
2023-03-13 17:26:05 -04:00
weslambert
785f100132
Fix system auth default key value
2023-03-13 17:25:33 -04:00
weslambert
8ade7b85fc
Fix system syslog default key value
2023-03-13 17:24:40 -04:00
weslambert
c2701f1835
Fix system syslog default key value
2023-03-13 17:24:12 -04:00
weslambert
d5bb223235
Fix system syslog delete file configuration
2023-03-13 17:10:52 -04:00
weslambert
bb711a2a15
Merge pull request #9923 from Security-Onion-Solutions/fix/curator_default_elastic_agent_logs
...
Add Elastic Agent default indices to be managed by Curator
2023-03-13 16:59:40 -04:00
Wes
efc5832499
Add Elastic Agent default log action files
2023-03-13 20:54:38 +00:00
Wes
8d395dc465
Add Elastic Agent default data stream backing indices for management by Curator
2023-03-13 20:54:13 +00:00
m0duspwnens
9d4e1cc149
jinja for strelka
2023-03-13 16:48:21 -04:00
Josh Brower
f7be4ba31c
Remove host field from NIDS logs
2023-03-13 14:07:17 -04:00
Josh Brower
126add7ddd
Merge pull request #9922 from Security-Onion-Solutions/2.4/fieldfixes
...
auto-apply firewall rules
2023-03-13 12:00:28 -04:00
Josh Brower
b3a2680847
auto-apply firewall rules
2023-03-13 11:41:36 -04:00
weslambert
1774d16d9a
Merge pull request #9921 from Security-Onion-Solutions/fix/elasticsearch_template_data_stream_configuration
...
Move data stream configuration outside of ILM policy definition
2023-03-13 09:29:42 -04:00
Wes
e105e56fac
Move data stream configuration outside of ILM policy definition
2023-03-13 13:27:02 +00:00
m0duspwnens
58343e39fa
2.4 strelka
2023-03-10 17:32:14 -05:00
weslambert
a844819261
Merge pull request #9919 from Security-Onion-Solutions/fix/elasticsearch_ilm_policy_elastic_agent_default
...
Add index lifecycle management policy definitions for default Elastic Agent data streams
2023-03-10 17:02:27 -05:00
weslambert
16d9478196
Add index lifecycle management policy definitions for default Elastic Agent data streams
2023-03-10 16:54:47 -05:00
Jason Ertel
5804409fcf
Merge branch '2.4/dev' into kilo
2023-03-10 15:13:57 -05:00
Jason Ertel
5301f442f9
distributed testing
2023-03-09 19:31:04 -05:00
Jason Ertel
ed8a23cedc
distributed testing
2023-03-09 17:01:38 -05:00
Jason Ertel
0ee870a199
cleanup unnecessary code
2023-03-09 15:40:51 -05:00
Jason Ertel
23b344bf14
distributed testing
2023-03-09 15:04:42 -05:00
Josh Brower
2fe8668f1b
Merge pull request #9891 from Security-Onion-Solutions/2.4/huntqueries
...
Initial updates for 2.4 fieldnames
2023-03-09 14:37:50 -05:00
Josh Brower
73abf8dbfd
Generic host dashboard
2023-03-09 14:32:52 -05:00
Jason Ertel
894a20b3ad
autodetect manager IP
2023-03-09 12:58:51 -05:00
Jason Ertel
ecc300197d
autodetect manager IP
2023-03-09 12:11:27 -05:00
Jason Ertel
b1f201ca87
autodetect manager IP
2023-03-09 12:05:42 -05:00
Jason Ertel
a4409b2979
autodetect manager IP
2023-03-09 11:47:35 -05:00
Jason Ertel
b6ce9f489a
autodetect manager IP
2023-03-09 11:02:01 -05:00
Josh Brower
1493806040
Change host dashboard titles
2023-03-08 17:03:02 -05:00
Josh Brower
a5c89bfaa1
update sysmon dashboards
2023-03-08 16:49:34 -05:00
Jason Ertel
b9e3024521
fix user sync issue after setup finishes
2023-03-08 15:10:31 -05:00
Josh Patterson
d75866caec
Merge pull request #9912 from Security-Onion-Solutions/2.4/heavynode
...
2.4/heavynode
2023-03-08 14:11:43 -05:00
m0duspwnens
61879a8d33
merge with dev and resolve conflicts in salt/top
2023-03-08 09:04:09 -05:00
Jason Ertel
0f456e6ecd
Merge branch '2.4/dev' into kilo
2023-03-07 16:18:30 -05:00
weslambert
7ad34ee8d7
Merge pull request #9910 from Security-Onion-Solutions/fix/curator_so_curator_cluster_warm
...
Remove reference to 'so-curator-cluster-warm' script since it has been removed
2023-03-07 16:18:05 -05:00
weslambert
2d7ce41a70
Remove reference to 'so-curator-cluster-warm' script since it has been removed
2023-03-07 16:16:55 -05:00
weslambert
a738c7c36d
Merge pull request #9907 from Security-Onion-Solutions/fix/curator_global_delete_action
...
Add the new Security Onion index format to the global delete action file for Curator
2023-03-07 16:03:28 -05:00
Josh Brower
6f82cf3807
Merge pull request #9906 from Security-Onion-Solutions/2.4/setupfix
...
Remove EA install from manager highstates
2023-03-07 15:33:34 -05:00
Jason Ertel
a3e05d782e
Merge branch '2.4/dev' into kilo
2023-03-07 15:26:01 -05:00
weslambert
e93c052d34
Add the new index format to the global delete action file for Curator
2023-03-07 15:21:53 -05:00
Josh Brower
fd2312a2ac
Remove EA install from manager highstates
2023-03-07 15:13:35 -05:00
Jason Ertel
4f3cb2eb3d
Clarify playbook load time log message
2023-03-07 14:42:10 -05:00
weslambert
8c79d7e40d
Merge pull request #9905 from Security-Onion-Solutions/fix/curator_new_action_files
...
Add New Curator Action Files
2023-03-07 12:44:25 -05:00
Wes
f50639d2d2
Fix import and syslog actions
2023-03-07 17:41:48 +00:00
Wes
26c9813276
Add keys for new Curator actions to defaults.yaml
2023-03-07 17:29:07 +00:00
Wes
88d98af243
Add new Curator action files to Curator close and delete scripts
2023-03-07 17:21:03 +00:00
Wes
d636546871
Add new Curator action files
2023-03-07 17:15:25 +00:00
weslambert
f0b7a75ae8
Merge pull request #9904 from Security-Onion-Solutions/fix/curator_clean_up_action_files
...
Clean Up Old Curator Action Files
2023-03-07 11:52:28 -05:00
Wes
073054b447
Remove 'so-curator-cluster-warm' and remove unncessary Curator default values
2023-03-07 16:21:55 +00:00
Wes
df94e830c5
Remove unnecessary Curator action files
2023-03-07 16:15:41 +00:00
m0duspwnens
2767d4bee3
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-07 10:36:12 -05:00
m0duspwnens
14aa9ac5c9
apply elastic-fleet state to managers
2023-03-07 10:35:49 -05:00
weslambert
deda0fa279
Merge pull request #9902 from Security-Onion-Solutions/fix/so-status_curator
...
Add Curator to so-status Output
2023-03-07 10:17:14 -05:00
Wes
086b3bf528
Add Curator to so-status output
2023-03-07 15:14:53 +00:00
Jason Ertel
66bb829505
if -i, either success or failure must be present
2023-03-06 22:18:08 -05:00
Jason Ertel
b641dc37b6
use high error code to flag an unrecoverable error
2023-03-06 18:56:04 -05:00
Jason Ertel
f77068f73f
setup and so-verify/so-status interop
2023-03-06 18:37:37 -05:00
m0duspwnens
691080de88
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-06 16:04:14 -05:00
Jason Ertel
1998c66073
Merge branch '2.4/dev' into kilo
2023-03-06 15:59:21 -05:00
Jason Ertel
1945659369
Error is too common, found even in dashboard titles
2023-03-06 15:59:08 -05:00
Josh Brower
3eb839bd21
Merge pull request #9897 from Security-Onion-Solutions/2.4/dev-fleet
...
Fleet - setup ES output for all Managers
2023-03-06 15:54:03 -05:00
Josh Brower
a6db2d4502
Fleet - setup ES output for all Managers
2023-03-06 15:50:09 -05:00
m0duspwnens
0f9803120e
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-06 13:55:09 -05:00
m0duspwnens
b6d55bedc8
make influxdb token accessible to all nodes
2023-03-06 13:50:17 -05:00
Josh Brower
8fae826a3a
Merge pull request #9890 from Security-Onion-Solutions/2.4/fixosquerylink
...
Fixup osquery SO Hunt link
2023-03-06 07:25:00 -05:00
Doug Burks
1e31966d8d
Merge pull request #9893 from Security-Onion-Solutions/2.4/enable-zeek-vlan
...
2.4/enable zeek vlan
2023-03-06 07:20:45 -05:00
Doug Burks
a2bda07820
add VLAN dashboard
2023-03-05 15:24:11 -05:00
Doug Burks
19ab2a5a46
rename suricata vlan field to network.vlan.id
2023-03-05 05:57:52 -05:00
Josh Brower
9db6df0f14
Initial updates for 2.4 fieldnames
2023-03-04 15:19:19 -05:00
Josh Brower
f0db5cf657
Fixup osquery SO Hunt link
2023-03-04 11:50:01 -05:00
Doug Burks
4a2e75dd8c
fix formatting
2023-03-03 17:16:45 -05:00
Jason Ertel
a45763f9a2
Merge branch '2.4/dev' into kilo
2023-03-03 16:01:06 -05:00
Doug Burks
e24296d536
add SOC Dashboards groupby for Zeek conn vlan field
2023-03-03 15:23:43 -05:00
Doug Burks
9940a36722
update Elasticsearch ingest for Zeek conn vlan field
2023-03-03 15:22:43 -05:00
Doug Burks
adb925b4d6
enable zeek vlan script
2023-03-03 12:48:42 -05:00
m0duspwnens
e3f9b5297a
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-03-02 16:58:56 -05:00
Jason Ertel
fd2068be88
Switch back to kilo images
2023-03-02 15:23:53 -05:00
m0duspwnens
e6167dc34a
heavynode changes
2023-03-02 15:09:59 -05:00
Mike Reeves
26dbaeb7ac
Merge pull request #9882 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-functions
2023-03-02 11:36:24 -05:00
Mike Reeves
2b0ea8eb8b
Update so-functions
2023-03-02 11:34:36 -05:00
weslambert
196a6ce984
Merge pull request #9881 from Security-Onion-Solutions/fix/curator_configuration_update_8.0.x
...
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-02 08:51:14 -05:00
weslambert
06d1f0f913
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-02 08:46:52 -05:00
Mike Reeves
204f423051
Merge pull request #9878 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2023-03-01 21:37:17 -05:00
Mike Reeves
af284b9aae
Update init.sls
2023-03-01 16:38:48 -05:00
Jason Ertel
41bc1cd36f
Merge branch '2.4/dev' into kilo
2023-03-01 09:53:59 -05:00
Mike Reeves
2091806f1f
Merge pull request #9864 from Security-Onion-Solutions/setuperrors
...
Fix some errors in setup
2023-03-01 09:48:20 -05:00
m0duspwnens
704365c6eb
only stdout redirect
2023-03-01 09:44:48 -05:00
m0duspwnens
a79c380e2b
use cmd.run to populate metrics_link
2023-03-01 09:18:58 -05:00
weslambert
a5c2c0fb20
Merge pull request #9866 from Security-Onion-Solutions/fix/soc_elasticsearch_ilm_annotations_verbiage
...
Various adjustments to descriptions
2023-02-28 16:46:53 -05:00
m0duspwnens
c4e1ec781e
apply influxdb before highstate in setup
2023-02-28 16:31:35 -05:00
Jason Ertel
13182fcda2
refactor automated testing inputs due to streamlined setup process
2023-02-28 16:31:17 -05:00
weslambert
134caa7f58
Various adjustments to descriptions
2023-02-28 16:31:16 -05:00
m0duspwnens
8772dcaa10
ensure influxdb is running
2023-02-28 15:57:54 -05:00
Jason Ertel
205e344034
dynamically choose test NICs in alphanumeric sort order
2023-02-28 15:40:08 -05:00
Jason Ertel
749c299ed2
refactor automated testing inputs due to streamlined setup process
2023-02-28 15:34:09 -05:00
Josh Brower
96467f0bd8
Merge pull request #9865 from Security-Onion-Solutions/2.4/fleet-esoutput
...
Move Output to ES
2023-02-28 15:20:46 -05:00
m0duspwnens
052e0dea2e
create and manage metrics_link in a file for soc
2023-02-28 14:47:44 -05:00
Jason Ertel
d456f681f1
refactor automated testing inputs due to streamlined setup process
2023-02-28 14:45:21 -05:00
Jason Ertel
8f20e2bcb9
refactor automated testing inputs due to streamlined setup process
2023-02-28 14:29:22 -05:00
Jason Ertel
9c3cc17153
refactor automated testing inputs due to streamlined setup process
2023-02-28 13:44:38 -05:00
Jason Ertel
d5df1a106a
refactor automated testing inputs due to streamlined setup process
2023-02-28 13:43:52 -05:00
Mike Reeves
ff495cb20e
fix formatting issue
2023-02-28 10:41:44 -05:00
Mike Reeves
34f5dbeba0
Merge branch 'setuperrors' of https://github.com/Security-Onion-Solutions/securityonion into setuperrors
2023-02-28 09:41:10 -05:00
Mike Reeves
c00d671098
backup influx dir
2023-02-28 09:40:57 -05:00
Josh Patterson
cbcd3c9dd9
Update defaults.map.jinja
2023-02-27 15:39:03 -05:00
Josh Patterson
8632606a24
Update defaults.map.jinja
2023-02-27 15:37:35 -05:00
Mike Reeves
1692970789
back out verify changes since underlying errors should be fixed
2023-02-27 15:22:08 -05:00
Josh Patterson
8d33f01936
Update defaults.map.jinja
2023-02-27 15:01:31 -05:00
Mike Reeves
aa7b05d639
small cleanup
2023-02-27 14:12:26 -05:00
Mike Reeves
9967e91825
remove mysql check
2023-02-27 13:42:11 -05:00
Josh Patterson
fb5aad34e0
Merge pull request #9861 from Security-Onion-Solutions/somefixes2
...
Somefixes2
2023-02-27 13:14:08 -05:00
m0duspwnens
44ed48033c
move requirement
2023-02-27 13:04:23 -05:00
m0duspwnens
068d383442
change to service.running
2023-02-27 12:44:46 -05:00
m0duspwnens
b4015ac73e
add sensor to node_containers
2023-02-27 10:05:08 -05:00
Josh Brower
f7176f9989
Move Output to ES
2023-02-27 09:58:43 -05:00
Josh Patterson
dd8f6a460b
Merge pull request #9853 from Security-Onion-Solutions/somefixes2
...
custom hostgroups in soc ui
2023-02-24 16:25:48 -05:00
m0duspwnens
d12ea041bf
capitalize
2023-02-24 16:20:16 -05:00
m0duspwnens
6b486d9604
move to default
2023-02-24 15:55:27 -05:00
m0duspwnens
fa5b9799f5
add firewall.soc to top for managers
2023-02-24 15:26:39 -05:00
m0duspwnens
d502d95dba
changes for soc firewall
2023-02-24 15:24:02 -05:00
m0duspwnens
29c68c1273
fix bracket, add output to template
2023-02-24 14:32:35 -05:00
m0duspwnens
3e2e68fbd0
custom hostgroups in soc
2023-02-24 14:24:47 -05:00
Jason Ertel
aed41404fc
Merge pull request #9852 from Security-Onion-Solutions/kilo
...
Remove FleetDM tool from SOC instead of deactivating it; generate SRV key during setup
2023-02-24 13:05:58 -05:00
Mike Reeves
2b683b09e1
Merge pull request #9851 from Security-Onion-Solutions/somefixes2
...
Fix install
2023-02-24 12:24:43 -05:00
Mike Reeves
afccd3f820
comment out minion installs for now
2023-02-24 12:21:14 -05:00
Mike Reeves
a25acb4558
comment out minion installs for now
2023-02-24 12:19:57 -05:00
Mike Reeves
a0eb505db0
Add fireall custom groups
2023-02-24 11:12:17 -05:00
Mike Reeves
99105c7563
Add fireall custom groups
2023-02-24 10:43:41 -05:00
Jason Ertel
316db85584
Generate SOC SRVKey during setup
2023-02-24 10:20:23 -05:00
Jason Ertel
d3c5d0569a
Remove FleetDM tool instead of deactivating it
2023-02-24 10:20:02 -05:00
Mike Reeves
57a02396de
Merge pull request #9849 from Security-Onion-Solutions/somefixes2
...
Playbook fix
2023-02-24 10:08:58 -05:00
Mike Reeves
29cf95d6eb
remove yum versionlock
2023-02-24 10:06:43 -05:00
Mike Reeves
39361c2ab0
unfix playbook fix
2023-02-24 10:01:27 -05:00
Mike Reeves
1289500e03
unfix playbook fix
2023-02-24 09:55:49 -05:00
Mike Reeves
663af7935b
Merge pull request #9847 from Security-Onion-Solutions/somefixes
2023-02-23 20:05:51 -05:00
Mike Reeves
cd56d3a799
unfix playbook fix
2023-02-23 16:18:22 -05:00
Mike Reeves
bf512d56ec
unfix playbook fix
2023-02-23 16:12:57 -05:00
Mike Reeves
b206b23fe1
unfix playbook fix
2023-02-23 16:09:54 -05:00
Mike Reeves
6141906b76
Merge pull request #9840 from Security-Onion-Solutions/reposync
...
Rocky 9 support
2023-02-23 12:30:38 -05:00
m0duspwnens
8f46e4aa30
set docker extra_hosts for soc
2023-02-23 12:26:58 -05:00
Jason Ertel
4222b09970
Merge branch '2.4/dev' into reposync
2023-02-23 12:15:03 -05:00
Jason Ertel
b62a0c5d5c
Merge pull request #9846 from Security-Onion-Solutions/kilo
...
Kilo
2023-02-23 12:12:06 -05:00
Jason Ertel
7067f9cd9c
allow the rpm gpg key filename
2023-02-23 12:09:55 -05:00
Jason Ertel
265447801e
allow the rpm gpg key filename
2023-02-23 12:08:43 -05:00
Jason Ertel
52f0ccf00d
Merge branch '2.4/dev' into kilo
2023-02-23 12:03:34 -05:00
Mike Reeves
2ebd9b3598
use hostnames please
2023-02-23 11:19:13 -05:00
Mike Reeves
4896452245
use hostnames please
2023-02-23 11:13:54 -05:00
Mike Reeves
9441d47c6a
Merge branch 'reposync' of https://github.com/Security-Onion-Solutions/securityonion into reposync
2023-02-23 11:11:38 -05:00
Mike Reeves
148b0b1c4c
use hostnames please
2023-02-23 11:11:29 -05:00
m0duspwnens
399e4de73c
stop and disable firewalld
2023-02-23 11:04:23 -05:00
m0duspwnens
96b1fb4782
change to eval
2023-02-23 10:51:14 -05:00
Mike Reeves
7f2d263046
fix nginx config
2023-02-23 10:16:34 -05:00
Mike Reeves
3fed04a532
fix nginx config
2023-02-23 09:52:24 -05:00
Mike Reeves
95f254dc63
Change elastalert ip
2023-02-23 09:37:20 -05:00
Mike Reeves
dc2fed5b04
Change elastalert ip
2023-02-23 09:34:16 -05:00
Mike Reeves
6927e28def
Change kibana IP
2023-02-23 09:25:16 -05:00
m0duspwnens
4db404b6f5
remove jinja from kibana defaults
2023-02-23 09:21:19 -05:00
Mike Reeves
7b30064d86
Chane Elastalert to use hosntame
2023-02-23 09:10:20 -05:00
Mike Reeves
0ec0983d7b
Chane Elastalert to use hosntame
2023-02-23 08:57:30 -05:00
weslambert
ee311de9c8
Merge pull request #9841 from Security-Onion-Solutions/fix/soc_analyzers_analyzerNodeId
...
Change 'GLOBALS.minion_id' to 'GLOBALS.hostname' for 'analyzerNodeId' value to ensure SOC creates analyzer jobs in the correct directory
2023-02-22 16:26:03 -05:00
Mike Reeves
7987cde668
Merge branch 'reposync' of https://github.com/Security-Onion-Solutions/securityonion into reposync
2023-02-22 16:25:04 -05:00
Mike Reeves
8e83407974
change playbook to use hostname
2023-02-22 16:24:35 -05:00
weslambert
ecf70847fd
Change 'GLOBALS.minion_id' to 'GLOBALS.hostname' for 'analyzerNodeId' value to ensure SOC creates analyzer jobs in the correct directory
2023-02-22 16:23:48 -05:00
m0duspwnens
0d0a61bd4a
remove so-grafana from node containers
2023-02-22 15:29:30 -05:00
Mike Reeves
5bc1dc9567
change playbook to use hostname
2023-02-22 15:19:27 -05:00
Mike Reeves
45434b06a4
change playbook to use hostname
2023-02-22 15:08:56 -05:00
Mike Reeves
6e59cc3409
change playbook to use hostname
2023-02-22 14:56:53 -05:00
Mike Reeves
417fff924d
change playbook to use hostname
2023-02-22 14:53:02 -05:00
Mike Reeves
1c1e613351
change playbook to use hostname
2023-02-22 14:48:55 -05:00
m0duspwnens
bf8e6c64d6
add sobip to global vars
2023-02-22 14:41:14 -05:00
Mike Reeves
68708accde
change playbook to use hostname
2023-02-22 14:32:49 -05:00
Mike Reeves
59c700ad10
change playbook to use hostname
2023-02-22 14:15:10 -05:00
Mike Reeves
c6a46d1eb3
change playbook to use hostname
2023-02-22 14:14:27 -05:00
Mike Reeves
c20a7e6cf9
fix yaml
2023-02-22 13:48:40 -05:00
Mike Reeves
3deb619737
add watchdog
2023-02-22 12:58:39 -05:00
Mike Reeves
7c64dad95b
add mysql
2023-02-22 11:28:46 -05:00
m0duspwnens
6dd09fb2c5
remove filebeat
2023-02-22 10:42:45 -05:00
m0duspwnens
b8966aa33a
fix role match
2023-02-22 10:24:51 -05:00
Mike Reeves
76011c96d6
fix conflict
2023-02-22 10:20:14 -05:00
Mike Reeves
c3784fe548
remove grafana
2023-02-22 10:09:52 -05:00
m0duspwnens
db3a46b6a1
fix indent
2023-02-22 10:07:04 -05:00
m0duspwnens
d0bb7dc475
repo for rocky
2023-02-22 10:04:43 -05:00
m0duspwnens
53b58d532a
apply docker state during setup
2023-02-22 09:35:37 -05:00
Mike Reeves
327855b0af
add docker
2023-02-22 09:28:51 -05:00
m0duspwnens
56ccf5c504
remove podman
2023-02-22 09:13:16 -05:00
Mike Reeves
7b6db5d95a
add docker
2023-02-22 09:08:39 -05:00
Mike Reeves
8645cd0c3b
add docker
2023-02-22 08:57:00 -05:00
m0duspwnens
cc654fda9f
fw 2.4 update
2023-02-21 15:43:41 -05:00
m0duspwnens
f2b0d67d8b
update fw rules
2023-02-21 15:20:49 -05:00
m0duspwnens
de499ead0c
update fw rules
2023-02-21 15:11:14 -05:00
m0duspwnens
a3bda9b322
podman changes to disable mgmt of iptables
2023-02-21 13:48:25 -05:00
Josh Brower
3a2ec8e8bf
Merge pull request #9830 from Security-Onion-Solutions/2.4/IDHMerge
...
Initial support for IDH
2023-02-21 12:19:53 -05:00
Josh Brower
b62cc32b1a
Initial support for IDH
2023-02-21 11:52:37 -05:00
Mike Reeves
bc054a15d3
add createrepo
2023-02-21 10:15:47 -05:00
Mike Reeves
c4a5470454
fix reposync
2023-02-21 10:06:01 -05:00
Mike Reeves
b402b84d11
fix reposync
2023-02-21 10:04:56 -05:00
Mike Reeves
f34e144629
removes filebeat
2023-02-21 10:01:27 -05:00
Mike Reeves
6cfa16c251
fix reposync script
2023-02-21 10:00:09 -05:00
Mike Reeves
173b15b46e
Add python3-rich for sostatus
2023-02-21 09:58:07 -05:00
m0duspwnens
653062b7c9
run podman state early
2023-02-21 09:46:52 -05:00
Jason Ertel
2b6685c887
restore kilo version
2023-02-21 09:27:02 -05:00
Jason Ertel
f00c7169ce
update test scenarios
2023-02-21 09:24:55 -05:00
m0duspwnens
5fff06602a
change symlink
2023-02-17 15:41:49 -05:00
Mike Reeves
4bafb40894
fix registry from restart
2023-02-17 15:38:54 -05:00
m0duspwnens
03cd67431d
start and enable podman services
2023-02-17 15:36:45 -05:00
m0duspwnens
160ed46d96
podman and remove filebeat
2023-02-17 14:59:39 -05:00
Mike Reeves
6fd68351ec
fix more python depends
2023-02-17 14:30:55 -05:00
m0duspwnens
49549c3d61
remove unneedfuls from podman state
2023-02-17 14:24:55 -05:00
m0duspwnens
9d4e4830dd
add podman state
2023-02-17 14:19:57 -05:00
Mike Reeves
b53aa08eeb
remove grafana and filebeat
2023-02-17 13:58:45 -05:00
Mike Reeves
c6266e9f91
add m2crypto
2023-02-17 13:54:46 -05:00
Mike Reeves
c6cbb4857d
add rsync
2023-02-17 13:53:36 -05:00
Mike Reeves
bcf1fe8dad
fix reposync script
2023-02-17 13:48:10 -05:00
Mike Reeves
12398bdf24
add m2crypto
2023-02-17 13:34:21 -05:00
Josh Patterson
ba5b125952
Update minion.defaults.yaml
2023-02-17 13:25:01 -05:00
Mike Reeves
e3e8d30161
fix python docker name
2023-02-17 13:17:57 -05:00
Mike Reeves
4bb49ad617
add some deps
2023-02-17 13:11:13 -05:00
Mike Reeves
e7f35673e0
replace centos
2023-02-17 11:38:50 -05:00
Mike Reeves
ba9c52db37
replace centos
2023-02-17 11:37:28 -05:00
Mike Reeves
43c177727c
replace centos
2023-02-17 11:32:05 -05:00
Mike Reeves
c6919a09da
replace centos
2023-02-17 11:26:11 -05:00
m0duspwnens
d8e85cbc28
change salt version
2023-02-17 11:20:16 -05:00
Mike Reeves
0a7ad4d211
yum-utils
2023-02-17 11:16:02 -05:00
Mike Reeves
54fc07b5b8
yum-utils
2023-02-17 11:07:44 -05:00
m0duspwnens
8b680693f4
remove patch pkg and patching of influx
2023-02-17 11:01:17 -05:00
Mike Reeves
353b77cd59
add minions.d dir
2023-02-17 10:40:43 -05:00
Doug Burks
eef81fdd1b
Merge pull request #9805 from Security-Onion-Solutions/2.4/upgrade-elastic-8.6.2
...
2.4/upgrade elastic 8.6.2
2023-02-17 08:03:09 -05:00
Doug Burks
ef3abe158c
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:07:20 -05:00
Doug Burks
dfa5503e41
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:06:36 -05:00
Mike Reeves
405060674c
Salt 3006 temp
2023-02-16 17:49:07 -05:00
Jason Ertel
1f37af0e57
Merge pull request #9800 from Security-Onion-Solutions/kilo
...
influx upgrade
2023-02-16 13:51:53 -05:00
Jason Ertel
59b1af15db
correct top order for import
2023-02-16 13:49:19 -05:00
Jason Ertel
79041d091e
influx upgrade
2023-02-16 13:22:13 -05:00
Jason Ertel
e4de89c960
Merge pull request #9798 from Security-Onion-Solutions/jertel-remove-kilo-from-ver
...
Update VERSION
2023-02-16 10:57:19 -05:00
Jason Ertel
dcbf5a2fa6
Update VERSION
2023-02-16 10:55:32 -05:00
Jason Ertel
6e9d1f7c2c
Merge pull request #9797 from Security-Onion-Solutions/kilo
...
Influx upgrade
2023-02-16 10:46:57 -05:00
weslambert
5e94a2cd74
Merge pull request #9790 from Security-Onion-Solutions/fix/kibana_default_data_view
...
Change default data view from '*:so-*' to 'logs-*'
2023-02-15 14:21:55 -05:00
weslambert
b7ad4e0570
Change default data view from 'so-*' to 'logs-*'
2023-02-15 14:19:29 -05:00
weslambert
967440f49f
Merge pull request #9789 from Security-Onion-Solutions/fix/kibana_visualization_index-pattern_reference
...
Replace 'so-*' index-pattern reference with 'logs-*' for Kibana dashboard visualizations
2023-02-15 11:33:44 -05:00
Wes
790b3c5635
Replace 'so-*' index-pattern reference with 'logs-*' for Kibana dashboard visualizations
2023-02-15 16:30:56 +00:00
Mike Reeves
01edb5dc00
Update repo URL
2023-02-15 11:09:37 -05:00
Jason Ertel
c43ccb7ed2
influx upgrade
2023-02-15 09:47:18 -05:00
Jason Ertel
a9b3594b35
merge
2023-02-15 08:06:41 -05:00
Jason Ertel
8746f55834
influx upgrade
2023-02-15 08:03:22 -05:00
Mike Reeves
577e3c27fe
Update repo URL
2023-02-14 13:52:21 -05:00
Mike Reeves
2cddcc8b8d
Change some order in repo sync
2023-02-14 13:38:28 -05:00
Mike Reeves
4c2142b181
add key for so packages
2023-02-14 13:21:37 -05:00
Mike Reeves
4dcdea58d7
add key for so packages
2023-02-14 13:16:13 -05:00
Mike Reeves
0f51e7bb98
fix key locations for rocky
2023-02-14 13:14:21 -05:00
Jason Ertel
1fa526cd0e
influx upgrade
2023-02-14 11:22:54 -05:00
Mike Reeves
4741038a41
fix function
2023-02-14 10:15:35 -05:00
Mike Reeves
89bd9163fb
reposync attempt for reocky
2023-02-14 10:08:34 -05:00
Mike Reeves
b2d85b843f
reposync
2023-02-14 09:00:10 -05:00
Jason Ertel
d15158e77a
influx upgrade
2023-02-13 20:52:12 -05:00
Jason Ertel
0890129c69
influx upgrade
2023-02-13 19:30:10 -05:00
Jason Ertel
e3ca0345a8
upgrade influx
2023-02-13 15:41:37 -05:00
Jason Ertel
1fa8294ee6
influx upgrade
2023-02-13 14:56:51 -05:00
weslambert
689ba5f341
Merge pull request #9778 from Security-Onion-Solutions/fix/filebeat_remove_docker_image
...
Remove 'so-filebeat' from list of trusted containers
2023-02-13 10:00:36 -05:00
weslambert
40d3269db3
Remove 'so-filebeat' from list of trusted containers
2023-02-13 09:58:39 -05:00
Jason Ertel
7b3acd53a1
upgrade influx
2023-02-13 09:55:45 -05:00
Jason Ertel
47af14c265
upgrade influx
2023-02-13 09:51:48 -05:00
Jason Ertel
34d19e308f
influx upgrade
2023-02-10 19:42:25 -05:00
Jason Ertel
e5c26032c4
influx upgrade
2023-02-10 19:37:59 -05:00
Jason Ertel
4f0af9ac6b
influx upgrade
2023-02-10 18:41:29 -05:00
Jason Ertel
0056b8f703
influx upgrade
2023-02-10 18:35:18 -05:00
Jason Ertel
39009ce938
influx upgrade
2023-02-10 18:32:01 -05:00
Jason Ertel
7dee2686ac
influx upgrade
2023-02-10 18:19:31 -05:00
Jason Ertel
cd27ae89cc
influx upgrade
2023-02-10 16:34:06 -05:00
weslambert
21ca8a9c50
Merge pull request #9770 from Security-Onion-Solutions/fix/elasticsearch_ilm_soc_annotations_settings
...
Add SOC annotation settings for Elasticsearch's ILM feature
2023-02-10 15:51:29 -05:00
weslambert
acda03ce40
Add annotation settings for Elasticsearch's ILM feature, and remove various index keys
2023-02-10 14:57:11 -05:00
weslambert
f2f318982e
Merge pull request #9768 from Security-Onion-Solutions/fix/elasticsearch_ilm_policy_load_additions
...
Manage Elasticsearch index lifecycle management policies in Elasticsearch state
2023-02-10 14:16:32 -05:00
Wes
1255c60317
Move policy load script into Elasticsearch state script directory
2023-02-10 18:59:45 +00:00
Wes
994eabae1b
Manage policy loading in Elasticsearch state
2023-02-10 18:57:19 +00:00
weslambert
82119b0247
Merge pull request #9765 from Security-Onion-Solutions/fix/elastic_utility_scripts_permissions
...
Ensure Elastic utility scripts have the correct permissions
2023-02-10 10:30:14 -05:00
Wes
1d0e09bdf7
Ensure Elastic utility scripts have the correct permissions
2023-02-10 15:26:46 +00:00
weslambert
7564a82b52
Merge pull request #9764 from Security-Onion-Solutions/fix/elasticsearch_ilm_dynamic_policy_loadiing
...
ILM Policy Changes
2023-02-10 10:17:14 -05:00
Wes
c9118699a9
Add index management lifecycle policy defintion and reference in index template
2023-02-10 15:10:30 +00:00
Wes
d17cf89c68
Fix Bash shebang
2023-02-10 15:01:09 +00:00
Wes
7b7461ef01
Dynamically load index management lifecycle policies based on pillar values
2023-02-10 14:59:29 +00:00
Jason Ertel
e77813a173
influx upgrade
2023-02-09 19:14:58 -05:00
Jason Ertel
0eec8b22a2
influx upgrade
2023-02-09 18:27:14 -05:00
Jason Ertel
0e50d36da6
upgrade influx
2023-02-09 16:18:04 -05:00
Jason Ertel
067b6bacd1
merge from 2.4/dev
2023-02-09 11:57:51 -05:00
weslambert
84c5d2fee9
Merge pull request #9753 from Security-Onion-Solutions/fix/elasticsearch_ilm_policy_load_additional_policies
...
Add index lifecycle policy templates for other logs
2023-02-09 10:59:24 -05:00
Wes
ee7f299e6d
Fix typo - 'Kratos' to 'Kibana'
2023-02-09 15:56:36 +00:00
Wes
bb6fc8da19
Add policy templates for other logs
2023-02-09 15:51:58 +00:00
weslambert
364799dcc5
Merge pull request #9751 from Security-Onion-Solutions/fix/elastic_fleet_output_temp_change
...
Temporarily use Elasticsearch output for standalone installations
2023-02-09 09:37:14 -05:00
weslambert
b744dc0641
Add so-eval to list of modes using the Elasticsearch output for Elastic Agent and Fleet
2023-02-09 09:35:29 -05:00
weslambert
613793ad9b
Temporarily use Elasticsearch output for Standalone installations
2023-02-09 09:32:04 -05:00
Jason Ertel
28eee48a7c
influx upgrade
2023-02-08 20:38:29 -05:00
Jason Ertel
849e53e1eb
upgrade influx
2023-02-08 17:40:27 -05:00
Josh Patterson
131d9b5898
Merge pull request #9747 from Security-Onion-Solutions/2.4/firewall
...
ensure node_data is populated with self
2023-02-08 17:29:07 -05:00
m0duspwnens
8a00521092
ensure node_data is populated with self if logstash:nodes data doesnt exist, ie import node
2023-02-08 17:19:20 -05:00
weslambert
32823ef640
Merge pull request #9746 from Security-Onion-Solutions/feature/elasticsearch_ilm_utility_scripts
...
Add Elasticsearch ILM utility scripts
2023-02-08 16:43:44 -05:00
Wes
b319b50fa1
Add initial ILM status script
2023-02-08 21:39:33 +00:00
Wes
1d6c03feb1
Rename initial ILM lifecycle status explanation script
2023-02-08 21:34:39 +00:00
Wes
91d24d36f9
Add initial ILM lifecycle status explanation script
2023-02-08 21:34:15 +00:00
Wes
3e31bda285
Fix typo in Elasticsearch portion of script names
2023-02-08 21:32:17 +00:00
Wes
1de3871ee9
Add initial ILM service restart script
2023-02-08 21:30:25 +00:00
Wes
03849b0659
Add initial ILM service start script
2023-02-08 21:29:38 +00:00
Wes
b38f4ca766
Add initial ILM service stop script
2023-02-08 21:29:16 +00:00
Wes
8027055086
Add initial ILM policy delete script
2023-02-08 21:09:42 +00:00
Jason Ertel
8ff0cf21cd
influx upgrade
2023-02-08 16:03:10 -05:00
Wes
d6d01f8542
Add initial ILM policy view script
2023-02-08 21:01:02 +00:00
Jason Ertel
c43e69ad93
influx upgrade
2023-02-08 15:57:14 -05:00
Jason Ertel
abbc92a58d
upgrade influx
2023-02-08 15:14:46 -05:00
Wes
713e9ee215
Create initial template for ILM policy load script
2023-02-08 20:10:41 +00:00
Jason Ertel
22eaeb1462
upgrade influx
2023-02-08 15:00:44 -05:00
Jason Ertel
2fddcc1e99
upgrade influx
2023-02-08 14:57:57 -05:00
Jason Ertel
67c8f6ba69
avoid cr/lr
2023-02-08 14:25:36 -05:00
Jason Ertel
44e60f1e57
upgrade influx
2023-02-08 14:03:27 -05:00
Jason Ertel
51674b3a5b
upgrade influx
2023-02-08 13:50:32 -05:00
Jason Ertel
4c42671a21
Merge branch '2.4/dev' into kilo
2023-02-08 13:49:07 -05:00
Jason Ertel
a1ac1785d3
upgrade influx
2023-02-08 13:40:27 -05:00
Josh Patterson
3b9bdecab8
Merge pull request #9745 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-02-08 13:26:40 -05:00
Jason Ertel
ea0c3db8e1
upgrade influxdb
2023-02-08 13:23:45 -05:00
m0duspwnens
3d34a49e44
change to new local ports file
2023-02-08 13:21:48 -05:00
m0duspwnens
19f49dde75
recusivly copy the firewall files for setup
2023-02-08 13:14:08 -05:00
Josh Patterson
d6fb0598df
Merge pull request #9743 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-02-08 11:37:05 -05:00
m0duspwnens
31daeef30d
2.4 fw changes
2023-02-08 11:01:26 -05:00
m0duspwnens
342b9619b0
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-08 09:18:21 -05:00
m0duspwnens
fb7ebcac7e
2.4 fw changes
2023-02-08 09:18:05 -05:00
Doug Burks
291bdc0d82
Merge pull request #9726 from Security-Onion-Solutions/2.4/change-radio-to-menu
...
FIX: Minimize keystrokes and errors in Setup by changing radio lists to menus where appropriate #9725
2023-02-06 12:11:21 -05:00
Doug Burks
cd38ecb300
change whiptail selections from radiolist to menu where appropriate
2023-02-06 11:52:42 -05:00
Josh Patterson
22a18d8855
Merge pull request #9717 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-02-03 11:04:36 -05:00
m0duspwnens
e8a1e164aa
add so.version module
2023-02-03 10:58:08 -05:00
m0duspwnens
e0e094cd95
rename sosbip and sosrange to sobip and sorange
2023-02-03 10:10:51 -05:00
m0duspwnens
a37f0fd0c0
rename sosbridge to sobridge
2023-02-03 10:07:07 -05:00
m0duspwnens
6e45f1b6e1
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-03 09:55:50 -05:00
m0duspwnens
df9ef9ffc7
add managersearch
2023-02-03 09:55:33 -05:00
weslambert
bee5a1e9e8
Merge pull request #9711 from Security-Onion-Solutions/fix/so_import_pcap_suricata_metadata_disable_zeek
...
Only run Zeek if it is defined as the metadata engine
2023-02-02 13:27:35 -05:00
m0duspwnens
3e808a70fa
allow managersearch. comment out localhost allow in setup
2023-02-02 12:11:03 -05:00
Wes
bc082dff99
Only run Zeek if it is defined as 'mdengine'
2023-02-02 16:22:42 +00:00
m0duspwnens
33787d345b
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-02 10:04:01 -05:00
m0duspwnens
9eae31e488
add managersearch to allowed roles for so-firewall. fix setup error from so-firewall "Please specify a role with --role="
2023-02-02 10:03:22 -05:00
weslambert
395cbf330a
Merge pull request #9706 from Security-Onion-Solutions/fix/suricata_metadata
...
Add Suricata metadata configuration
2023-02-02 09:54:49 -05:00
Wes
5fba3c5872
Add Suricata metadata configuration
2023-02-02 14:48:01 +00:00
m0duspwnens
3ba64f7545
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-02 09:31:40 -05:00
weslambert
eb7b6e78b9
Merge pull request #9702 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_disable
...
Disable loading of Kibana and Logstash integration policies
2023-02-01 16:02:56 -05:00
weslambert
d242050627
Disable loading of Kibana and Logstash logs for now since there are issues with the packages from the registry
2023-02-01 15:59:35 -05:00
weslambert
3dfa7959b3
Merge pull request #9698 from Security-Onion-Solutions/fix/strelka_yara_exclusion_2_4
...
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:38:38 -05:00
weslambert
2101ca60e9
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:25:46 -05:00
m0duspwnens
33668105a5
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-02-01 11:32:02 -05:00
m0duspwnens
d2dd68eb44
add global vars for managersearch
2023-02-01 11:31:36 -05:00
Josh Patterson
77749adc8f
Merge pull request #9691 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-31 17:11:57 -05:00
m0duspwnens
6ec086e24a
add influxdb as extra_hosts for grafana container
2023-01-31 17:10:11 -05:00
m0duspwnens
6f1438148f
allow elastic agent access
2023-01-31 16:54:46 -05:00
m0duspwnens
12bede5e77
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-31 16:10:50 -05:00
weslambert
056bcd0121
Merge pull request #9683 from Security-Onion-Solutions/fix/kibana_osquery_live_query_link_remove
...
Remove OSQuery live query link
2023-01-31 13:38:07 -05:00
m0duspwnens
8cbafb52d8
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-31 13:32:51 -05:00
m0duspwnens
16e1e297a0
allow elasticsearch_rest
2023-01-31 13:32:33 -05:00
weslambert
98bea0322e
Merge pull request #9688 from Security-Onion-Solutions/fix/elastic_agent_elasticsearch_output_typo_fix
...
Fix Elastic Agent Elasticsearch output typo
2023-01-31 12:57:38 -05:00
weslambert
74eed31eec
Change Elasticsearch output name from 'so-manager_elasticsearch2' to 'so-manager_elasticsearch'
2023-01-31 12:55:03 -05:00
m0duspwnens
aa411e2682
allow influxdb on manager and managersearch
2023-01-31 12:42:46 -05:00
weslambert
cbf2bd1373
Remove OSQuery live query link
2023-01-31 10:59:17 -05:00
m0duspwnens
0ba193c7a4
allow docker_registry fw
2023-01-31 10:55:14 -05:00
m0duspwnens
e09a86dc30
2.4 searchnode es config
2023-01-31 10:54:40 -05:00
m0duspwnens
8dc7a9da9e
add searchnode global vars
2023-01-31 10:52:35 -05:00
Doug Burks
acffc5ee07
Merge pull request #9682 from Security-Onion-Solutions/fix/suricata-dhcp-parsing-2.4
...
2.4: Improve Suricata DHCP parsing and dashboard
2023-01-31 10:18:41 -05:00
Doug Burks
a44d83d69b
Improve Suricata DHCP parsing and dashboard
2023-01-31 08:33:38 -05:00
weslambert
bde828cd4f
Merge pull request #9676 from Security-Onion-Solutions/fix/so-import-evtx_updates
...
Updates to so-import-evtx
2023-01-31 08:17:02 -05:00
weslambert
0436f885b8
Set values for '@timestamp' and 'event.ingested'
2023-01-31 08:04:49 -05:00
Wes
5472f53c9f
Remove bind mount and reference the correctly named entrypoint script
2023-01-30 21:24:30 +00:00
Wes
0156784687
Add EVTX integration policy for 'so-import-evtx'
2023-01-30 21:22:37 +00:00
Wes
cc100e50cd
Update so-import-evtx to convert EVTX to a JSON file instead of streaming to Elasticsearch
2023-01-30 21:09:58 +00:00
weslambert
b1eb16d3a2
Merge pull request #9670 from Security-Onion-Solutions/fix/elastic_agent_integration_policies_zeek_exclude_files
...
Remove 'prospector.scanner' prefix from 'exclude_files' configuration
2023-01-27 16:53:02 -05:00
weslambert
8240e5b20d
Remove 'prospector.scanner' prefix from 'exclude_files' configuration
2023-01-27 16:46:43 -05:00
Doug Burks
a13baf7bb8
Merge pull request #9669 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typos in so-elastic-fleet-integration-policy-load
2023-01-27 15:52:47 -05:00
Doug Burks
b160d0add5
Fix typos in so-elastic-fleet-integration-policy-load
2023-01-27 15:45:58 -05:00
Doug Burks
209f732176
Merge pull request #9668 from Security-Onion-Solutions/fix/elastic_agent_integration_policies_zeek
...
Fix syntax for Zeek Elastic Agent integration policies
2023-01-27 15:30:50 -05:00
weslambert
68fac4488e
Fix syntax for Zeek integration policies
2023-01-27 15:27:15 -05:00
weslambert
fa9e62a816
Merge pull request #9665 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_import_suricata_event.category
...
Change event.category from 'file' to 'network' in Import Suricata integration policy
2023-01-27 12:03:34 -05:00
weslambert
e47f64bd04
Change event.category from 'file' to 'network'
2023-01-27 12:00:30 -05:00
weslambert
6d2f379ba5
Merge pull request #9664 from Security-Onion-Solutions/fix/elastic_agent_integration_policies_zeek_exclude_files
...
Update Zeek file exclusions and add a minor output formatting change
2023-01-27 11:58:19 -05:00
weslambert
f49627cec1
Update Zeek file exclusions and add a minor output formatting change
2023-01-27 11:47:14 -05:00
weslambert
5ab3d1e8f1
Merge pull request #9663 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_zeek_import_ics_tag
...
Change 'pipeline' to 'import.file' so that ICS tag conditional is applied to the correct field
2023-01-27 11:34:28 -05:00
weslambert
6b251a2596
Change 'pipeline' to 'import.file' so that ICS tag conditional is applied to the correct field
2023-01-27 11:30:06 -05:00
weslambert
5468aa82b0
Merge pull request #9662 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_event.dataset_rename
...
Change event.dataset value for zeek.files and zeek.tunnels ingest pipelines
2023-01-27 11:19:45 -05:00
weslambert
2772b03dca
Change event.dataset value from 'tunnels' to 'tunnel'
2023-01-27 11:03:49 -05:00
weslambert
716ec7f936
Change event.dataset value from 'files' to 'file'
2023-01-27 11:02:44 -05:00
Doug Burks
83aad48e3a
Merge pull request #9657 from Security-Onion-Solutions/2.4/elastic-8.6.1
...
UPGRADE: Elastic 8.6.1 #9594 (2.4)
2023-01-26 16:24:42 -05:00
Doug Burks
86ca51ff99
Update to Elastic 8.6.1
2023-01-26 16:18:06 -05:00
Doug Burks
a27fc5c768
Update to Elastic 8.6.1
2023-01-26 16:17:36 -05:00
m0duspwnens
d5b5a36f28
remove data.nodestab from searchnodes pillar
2023-01-26 16:17:33 -05:00
m0duspwnens
75d73e4620
add yum portgroups for amnager
2023-01-26 15:35:22 -05:00
m0duspwnens
2fed977692
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-26 13:55:09 -05:00
m0duspwnens
f2d3298f14
allow nodes to connect to salt for manager and managersearch
2023-01-26 13:54:52 -05:00
weslambert
27b1f1bd07
Merge pull request #9654 from Security-Onion-Solutions/fix/logstash_cleanup
...
FIX: Logstash Pipeline Cleanup
2023-01-26 13:19:50 -05:00
Wes
e4271043c6
Remove unnecessary Logstash pipelines
2023-01-26 18:05:14 +00:00
Wes
b3123f7895
Remove unnecessary Logstash pipelines from the pillar
2023-01-26 17:57:07 +00:00
Mike Reeves
282d0f88db
Merge pull request #9652 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-verify
2023-01-26 12:33:46 -05:00
Mike Reeves
25a6eba166
Update so-verify
2023-01-26 12:30:35 -05:00
weslambert
a8d2631d75
Merge pull request #9650 from Security-Onion-Solutions/fix/elastic_agent_add_import_mode
...
Elastic Agent - Import Mode
2023-01-26 11:33:20 -05:00
Josh Patterson
881c8337a3
Merge pull request #9641 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-26 11:21:30 -05:00
Wes
b381c5424e
Remove extra whitespace after 'so-elastic-agent-builder' line in 'so-image-common'
2023-01-26 16:13:23 +00:00
Mike Reeves
a9919e7547
Merge pull request #9648 from Security-Onion-Solutions/mkr24
...
Enable Proxy Support
2023-01-26 11:12:35 -05:00
Wes
f1db1bc273
Ensure Kratos events are sent to a data stream instead of an index
2023-01-26 16:12:06 +00:00
Wes
7d68ef0e8b
Add Elastic Agent and Fleet to firewall configuration for Import Mode
2023-01-26 16:07:31 +00:00
Wes
43ffcb1d63
Allow setup to set up Elastic Fleet for Import Mode
2023-01-26 16:05:16 +00:00
Wes
8051fc70eb
Temporarily disable the loading of the RITA package policy
2023-01-26 16:03:59 +00:00
Wes
a9a119f1ab
Add Elasticsearch output to 'so-elastic-fleet-setup' for Import Mode
2023-01-26 16:02:27 +00:00
Wes
6a803dfe35
Add Elastic Fleet to top file configuration for Import Mode
2023-01-26 16:01:03 +00:00
Wes
1fb6cf7bfe
Add Elastic Fleet to allowed states for Import Mode
2023-01-26 15:59:49 +00:00
m0duspwnens
1d2f491084
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-26 10:49:00 -05:00
m0duspwnens
aafbdf6afc
adjust retry and timeout for wait_for_influxdb
2023-01-26 10:12:37 -05:00
Mike Reeves
2456aac311
Proxy Stuff
2023-01-26 09:57:44 -05:00
m0duspwnens
08750154b4
add missing quotes in check_web_pass
2023-01-26 09:11:28 -05:00
Mike Reeves
9e146184d6
Proxy Stuff
2023-01-25 17:43:02 -05:00
Mike Reeves
c57d390bac
Proxy Stuff
2023-01-25 17:40:40 -05:00
weslambert
211b87e7ae
Merge pull request #9644 from Security-Onion-Solutions/revert-9640-fix/elastic_agent_import_mode
...
Revert "Elastic Agent and Fleet - Import Mode"
2023-01-25 17:23:27 -05:00
weslambert
6ee66a34bc
Revert "Elastic Agent and Fleet - Import Mode"
2023-01-25 17:12:03 -05:00
weslambert
6785e0ec9e
Merge pull request #9640 from Security-Onion-Solutions/fix/elastic_agent_import_mode
...
Elastic Agent and Fleet - Import Mode
2023-01-25 17:01:33 -05:00
weslambert
c73cd78f08
Merge pull request #9643 from Security-Onion-Solutions/2.4/dev
...
Merge Dev
2023-01-25 16:59:47 -05:00
m0duspwnens
790aa6b684
add logstash pillar items for minions
2023-01-25 15:18:56 -05:00
Wes
5c58cda872
Move certificate configuration outside of conditional logic
2023-01-25 19:29:50 +00:00
m0duspwnens
b7a5937dc1
add soc_logstash and adv_logstash to nodes in pillar/top
2023-01-25 14:04:36 -05:00
Mike Reeves
31f591a098
Merge pull request #9635 from Security-Onion-Solutions/mkr24
...
Ubuntu support changes
2023-01-25 13:34:44 -05:00
Wes
c3717dae67
Add Elastic Fleet firewall configuration for Import Mode
2023-01-25 18:27:00 +00:00
Mike Reeves
498301b111
Salt for Ubuntu
2023-01-25 12:00:19 -05:00
Mike Reeves
704d99e757
Salt for Ubuntu
2023-01-25 11:50:19 -05:00
Mike Reeves
9243b01cbb
Salt for Ubuntu
2023-01-25 11:44:22 -05:00
Jason Ertel
c9f18891b2
Merge pull request #9639 from Security-Onion-Solutions/kilo
...
auto extract source/dest IP on case related event attachments; improve so-verify stream to console
2023-01-25 11:37:16 -05:00
Wes
86a925e1c7
Download Elastic Agent images for Import Mode
2023-01-25 16:09:12 +00:00
Jason Ertel
31d7e05c45
refactor so-verify to ensure output streams to console
2023-01-25 10:59:50 -05:00
Wes
838beabae5
Add missing single quote for Elastic Agent Elasticsearch output
2023-01-25 15:58:06 +00:00
m0duspwnens
3f99e3402e
add elasticsearch pillar files to manager and adv_elasticsearch to those that had soc_elasticsearch
2023-01-25 10:53:58 -05:00
Wes
c46b5e734b
Add 'elastic-fleet' to the list of allowed states for Import Mode
2023-01-25 14:38:23 +00:00
m0duspwnens
1b3f50a463
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-25 09:22:17 -05:00
Wes
1414b75e01
Allow 'elastic-fleet' state to be applied for Import Mode
2023-01-25 14:07:25 +00:00
Wes
506baa854d
Configure Elasticsearch output if running Import Mode
2023-01-25 13:52:54 +00:00
weslambert
4868bd8f5e
Merge pull request #9638 from Security-Onion-Solutions/fix/elastic_agent_integration_kratos_data_stream_rename
...
Rename Kratos Data Stream
2023-01-25 08:45:37 -05:00
weslambert
c9f458e1e2
Set event.dataset for all Kratos logs to 'access' for now
2023-01-25 08:19:50 -05:00
weslambert
7bf9d77962
Rename Kratos data stream
2023-01-25 08:18:21 -05:00
m0duspwnens
d1460ae01f
add node_data.ips pillar. grab influx host ip for soc extra_hosts
2023-01-24 17:05:40 -05:00
Mike Reeves
161881efbb
Salt for Ubuntu
2023-01-24 16:25:26 -05:00
Mike Reeves
d5f8ea8661
Salt for Ubuntu
2023-01-24 16:05:16 -05:00
Mike Reeves
53d6823ba7
Salt for Ubuntu
2023-01-24 16:00:03 -05:00
Mike Reeves
5a223981ca
Salt for Ubuntu
2023-01-24 15:57:05 -05:00
Mike Reeves
177ddc1183
Salt for Ubuntu
2023-01-24 15:48:48 -05:00
Mike Reeves
20f7a77886
Salt for Ubuntu
2023-01-24 15:43:12 -05:00
Mike Reeves
b89e7efeea
Salt for Ubuntu
2023-01-24 15:30:46 -05:00
weslambert
3f9764d22d
Merge pull request #9633 from Security-Onion-Solutions/fix/elastic_agent_more_improvements
...
More Elastic Agent Integration Improvements
2023-01-24 15:16:52 -05:00
Mike Reeves
a048034f16
Salt for Ubuntu
2023-01-24 13:38:39 -05:00
Jason Ertel
7b1f867ac3
Add defaults for auto extracted observables
2023-01-24 13:17:50 -05:00
Wes
4b9c92c53d
Set RITA event.dataset value explicitly
2023-01-24 18:00:34 +00:00
Wes
38ead7cb82
Remove import tag for now
2023-01-24 17:58:19 +00:00
Wes
44d149b1c3
Allow imported data to use a tag of 'import'
2023-01-24 17:01:52 +00:00
Wes
1e5377c78a
Condense RITA integration policies, add ICS tags, and improve output readability
2023-01-24 16:56:20 +00:00
m0duspwnens
b23575d85e
add global vars for manager
2023-01-24 11:03:03 -05:00
Jason Ertel
b0709e93fa
test workflow
2023-01-24 10:50:52 -05:00
Jason Ertel
fd7d51a59b
Merge pull request #9630 from Security-Onion-Solutions/kilo
...
Kilo
2023-01-24 10:45:12 -05:00
Jason Ertel
0dc5e7e714
try paths with wildcard
2023-01-24 10:38:59 -05:00
Jason Ertel
62b96c3698
rework filter for action
2023-01-24 10:31:02 -05:00
Jason Ertel
ec2e923530
Add proper spacing between headers and content
2023-01-24 10:28:39 -05:00
Jason Ertel
2bffd9b473
Merge pull request #9628 from Security-Onion-Solutions/kilo
...
try paths filter on both even though docs only mention support for push
2023-01-24 10:27:30 -05:00
Jason Ertel
cfc232eafa
try paths filter on both even though docs only mention support for push
2023-01-24 10:23:42 -05:00
m0duspwnens
6d3f57d648
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-24 10:17:24 -05:00
m0duspwnens
50895ee304
need to set_minion_info in setup for each node type
2023-01-24 10:16:58 -05:00
weslambert
7e0e5071d9
Merge pull request #9627 from Security-Onion-Solutions/fix/elastic_agent_integration_improvements
...
Elastic Agent Integration Improvements
2023-01-24 10:10:01 -05:00
Mike Reeves
2da30f42d4
Check for Ubuntu
2023-01-24 10:07:32 -05:00
Wes
7b4d8a47f0
Add copyright header to 'so-elastic-fleet-*' scripts
2023-01-24 15:07:00 +00:00
Josh Patterson
095ca29aca
Merge pull request #9626 from Security-Onion-Solutions/2.4/firewall
...
change MASTER to MANAGER in so-minion
2023-01-24 09:46:17 -05:00
Wes
f19cf75311
Change how event.dataset is determined for Suricata events
2023-01-24 14:45:00 +00:00
m0duspwnens
ee98e0684e
change MASTER to MANAGER
2023-01-24 09:44:01 -05:00
Josh Patterson
b797e356b4
Merge pull request #9624 from Security-Onion-Solutions/2.4/firewall
...
remove filebeat and redis(commented out) from telegraf config
2023-01-24 09:01:59 -05:00
m0duspwnens
88107fe0df
remove filebeat and redis(commented out) from telegraf config
2023-01-24 08:59:51 -05:00
Wes
51692ac66c
Update index pattern in various template definitions to match new data stream naming convention
2023-01-23 21:52:44 +00:00
Wes
40c6b380df
Update Import and Zeek integration policies; also update Zeek ingest node pipelines to set event.dataset.
2023-01-23 21:44:46 +00:00
Wes
d342f3c4b8
Add 'so-elastic-fleet-integration-policy-bulk-delete' to perform bulk deletion of integration policies
2023-01-23 21:38:13 +00:00
Josh Patterson
a503632f30
Merge pull request #9620 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-23 15:56:53 -05:00
m0duspwnens
d1ec7c8ace
remove to match with 2.4/dev
2023-01-23 15:50:53 -05:00
Jason Ertel
5da1b03d9b
Merge pull request #9619 from Security-Onion-Solutions/kilo
...
switch MySQL 8 to use native password for playbook compat; fix so-verify mail inspection
2023-01-23 15:14:00 -05:00
Jason Ertel
5a016312f6
switch MySQL 8 to use native password to avoid playbook incompatibility
2023-01-23 14:53:39 -05:00
m0duspwnens
90a224793e
merge with 2.4dev and fix conflict
2023-01-23 14:49:32 -05:00
m0duspwnens
22fbb953ea
create cronjob to run highstate after setup
2023-01-23 14:46:26 -05:00
Jason Ertel
d421aa82a2
do not treat all installs as ISO; fix check for non-empty mail files
2023-01-23 14:04:26 -05:00
Josh Patterson
1039e77550
Merge pull request #9617 from Security-Onion-Solutions/2.4/firewall
...
allow elastic agent on sensors to connect to managers
2023-01-23 13:19:49 -05:00
Mike Reeves
f077b5c96d
Remove 18.04
2023-01-23 13:11:50 -05:00
Josh Brower
f811223ba7
Merge pull request #9614 from Security-Onion-Solutions/playbookfixup
...
Playbookfixup
2023-01-23 08:20:06 -05:00
Josh Brower
d3cb57bba2
Rerun the playbook state
2023-01-23 08:16:28 -05:00
m0duspwnens
a1fa4e3ef2
revert reload_modules since bugged
2023-01-20 15:43:57 -05:00
Josh Brower
1ab8c712e4
remove exit condition
2023-01-20 15:17:04 -05:00
Jason Ertel
a613d960b9
Merge pull request #9608 from Security-Onion-Solutions/kilo
...
setup improvements
2023-01-20 13:11:11 -05:00
Jason Ertel
9541214073
logCmd with tee is eating the exit code
2023-01-20 12:26:52 -05:00
Jason Ertel
56478da0b2
eliminate find/exec issue altogether to keep it simple
2023-01-20 11:58:29 -05:00
Jason Ertel
c3384d8381
further improvements
2023-01-20 11:23:13 -05:00
Jason Ertel
1e4f9c9f26
use newer find syntax to allow the exec to work inside a quoted string
2023-01-20 11:01:02 -05:00
Jason Ertel
fea4a1b33d
Merge branch '2.4/dev' into kilo
2023-01-20 10:33:17 -05:00
Jason Ertel
ece63b72e2
Ensure so-verify output is logged
2023-01-20 07:38:58 -05:00
Jason Ertel
46aa7ebdf3
correct find/exec syntax
2023-01-20 06:48:33 -05:00
weslambert
9c83b775ee
Merge pull request #9604 from Security-Onion-Solutions/feature/sensoroni_scripts
...
Add scripts for starting, stopping, and restarting Sensoroni
2023-01-19 16:59:29 -05:00
Wes
739c174898
Add scripts for starting, stopping, and restarting Sensoroni
2023-01-19 21:50:10 +00:00
Jason Ertel
4044706cd9
Merge pull request #9603 from Security-Onion-Solutions/kilo
...
Handle setup failures
2023-01-19 15:49:41 -05:00
Jason Ertel
79fb5dc525
prevent false success occurring when deleting the grafana dashboard
2023-01-19 14:19:55 -05:00
Jason Ertel
59177288ef
correct grep patterns
2023-01-19 13:56:14 -05:00
Jason Ertel
85b5d1b317
Merge branch '2.4/dev' into kilo
2023-01-19 12:53:36 -05:00
Jason Ertel
6b7a8e1fcd
fix verify path
2023-01-19 12:53:24 -05:00
Josh Brower
027c83b5ea
Merge pull request #9601 from Security-Onion-Solutions/disablecontainer
...
Fixup
2023-01-19 11:47:04 -05:00
Josh Brower
4369d2385b
Temp disable Elastic Registry Repo
2023-01-19 11:45:13 -05:00
Jason Ertel
c5260e4787
verify setup
2023-01-19 11:25:59 -05:00
Jason Ertel
35835edf96
Merge branch '2.4/dev' into kilo
2023-01-19 11:04:32 -05:00
weslambert
8c4e00cfbd
Merge pull request #9600 from Security-Onion-Solutions/fix/elasticsearch_template_logs_default_remove
...
Remove default "logs-*" template settings for now
2023-01-19 10:30:44 -05:00
weslambert
7d3f6121eb
Remove default "logs-*" template settings for now
2023-01-19 10:29:10 -05:00
Jason Ertel
05c7999df3
merge
2023-01-19 10:06:58 -05:00
Jason Ertel
05a6d702b0
Add logic to determine if setup succeeded and provide relevant output
2023-01-19 10:03:03 -05:00
Josh Brower
8ce96942c1
Merge pull request #9599 from Security-Onion-Solutions/disablecontainer
...
Temp disable Elastic Registry Repo
2023-01-19 07:27:51 -05:00
Josh Brower
e83e54936e
Temp disable Elastic Registry Repo
2023-01-19 07:25:25 -05:00
weslambert
90f3e33cc6
Merge pull request #9597 from Security-Onion-Solutions/fix/elasticsearch_template_logs_default_priority_modification
...
Modify default 'logs-*' Elasticsearch template priority
2023-01-18 17:30:52 -05:00
weslambert
7a499c9051
Modify default 'logs-*' template priority
2023-01-18 17:24:07 -05:00
m0duspwnens
1eafb8d62a
reload salt modules when docker is installed
2023-01-18 13:46:06 -05:00
m0duspwnens
d501b0fac9
add elastic agent to assigned hostgroups
2023-01-18 09:46:55 -05:00
weslambert
1bf088e976
Merge pull request #9591 from Security-Onion-Solutions/fix/kibana_basepath_rewrite_disable
...
Disable Kibana's native base path rewrite and add publicBaseUrl
2023-01-17 16:59:06 -05:00
weslambert
1fed3cf474
Disable Kibana's native base path rewrite and add publicBaseUrl
2023-01-17 16:54:31 -05:00
Josh Patterson
e0f8315d27
Merge pull request #9590 from Security-Onion-Solutions/2.4/firewall
...
create /opt/so/ for non manager nodes during setup
2023-01-17 15:36:34 -05:00
m0duspwnens
dbfe176b45
create /opt/so/ for non manager nodes during setup
2023-01-17 14:15:44 -05:00
Josh Patterson
2842178396
Merge pull request #9588 from Security-Onion-Solutions/2.4/firewall
...
fix iptables
2023-01-17 13:50:16 -05:00
m0duspwnens
aa858bab45
fix iptables
2023-01-17 13:48:39 -05:00
weslambert
1723f58c04
Merge pull request #9579 from Security-Onion-Solutions/fix/elasticsearch_templates_so-ids
...
Remove so-ids since the data stream is now 'logs-suricata-*'
2023-01-13 16:17:38 -05:00
weslambert
ca80548bf0
Remove so-ids since the data stream is now 'logs-suricata-*'
2023-01-13 16:15:58 -05:00
weslambert
3e5127810d
Merge pull request #9577 from Security-Onion-Solutions/fix/elasticsearch_elastic_agent_templates
...
Make sure Elastic Agent data streams do not use replicas
2023-01-13 16:12:09 -05:00
weslambert
73a4dae28e
Make sure Elastic Agent data streams do not use replicas
2023-01-13 16:10:44 -05:00
Josh Patterson
3efca0010a
Merge pull request #9573 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-13 12:41:58 -05:00
m0duspwnens
3653df4d5f
spell it right
2023-01-13 10:18:13 -05:00
m0duspwnens
6033e9a0de
use port_bindings from docker defaults in docker states
2023-01-13 10:15:10 -05:00
weslambert
7cba5626b7
Merge pull request #9570 from Security-Onion-Solutions/fix/elasticsearch_templates_elastic_agent
...
Change priority for Elastic Agent Elasticsearch index templates
2023-01-12 16:48:12 -05:00
m0duspwnens
a69b0951d3
add strelka containers
2023-01-12 16:47:34 -05:00
weslambert
654d869e3e
Change priority from 500 to 200 for Elastic Agent index templates to avoid collisions with other templates
2023-01-12 16:46:08 -05:00
m0duspwnens
d163d834d4
allow for binding ip and ports to different port number
2023-01-12 16:42:45 -05:00
weslambert
be6b42494c
Merge pull request #9569 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_kratos
...
Kratos Index Changes
2023-01-12 15:33:51 -05:00
weslambert
fb8d8ea972
Update Elasticsearch index template for Kratos
2023-01-12 15:31:41 -05:00
weslambert
9416552338
Don't set the Kratos index explicitly
2023-01-12 15:25:35 -05:00
Mike Reeves
6c8b17d4d1
Merge pull request #9567 from Security-Onion-Solutions/mkr24
...
Fix nsm
2023-01-12 10:43:42 -05:00
Mike Reeves
8c5a060a80
Fix nsm
2023-01-12 10:41:54 -05:00
weslambert
66f9a06458
Merge pull request #9566 from Security-Onion-Solutions/fix/elastic_fleet_integration_policy_load
...
Fix Zeek import policies and remove unnecessary dash in RITAENABLED statement
2023-01-11 16:17:40 -05:00
Wes
0e437f84e7
Add back echo statement to print the import policy being loaded
2023-01-11 21:13:30 +00:00
Wes
ea01e68846
Fix Zeek import policies and remove unnecessary dash in RITAENABLED statement
2023-01-11 21:01:31 +00:00
Josh Patterson
add71cbdee
Merge pull request #9565 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-11 15:04:25 -05:00
Mike Reeves
60d476457a
Merge pull request #9564 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update 0900_input_redis.conf.jinja
2023-01-11 14:54:40 -05:00
m0duspwnens
80f65fcd62
remove 514/tcp from filebeat for now
2023-01-11 14:54:05 -05:00
Mike Reeves
66924b63a7
Update 9999_output_redis.conf.jinja
2023-01-11 14:53:16 -05:00
Mike Reeves
bdaed849ea
Update 0900_input_redis.conf.jinja
2023-01-11 14:52:32 -05:00
m0duspwnens
0d45c1583e
add so-filebeat docker container ports and add to standalone
2023-01-11 14:48:20 -05:00
m0duspwnens
81e07997f0
add so-elastic-fleet docker container ports and add to standalone
2023-01-11 14:28:35 -05:00
Mike Reeves
4923fb1c35
Merge pull request #9563 from Security-Onion-Solutions/mkr24
...
Optimize reinstall process
2023-01-11 12:44:52 -05:00
Mike Reeves
8fa8b89d9c
Fix reinstall logic
2023-01-11 12:43:22 -05:00
Mike Reeves
bab010a109
Fix reinstall logic
2023-01-11 12:40:18 -05:00
Mike Reeves
c07821a612
Fix reinstall logic
2023-01-11 12:32:43 -05:00
weslambert
acad7acc4a
Merge pull request #9562 from Security-Onion-Solutions/fix/elastic_agent_integration_policy_load_suricata_import
...
Move Suricata import policy definition so that it does not get caught in the for loop for Zeek policies
2023-01-11 12:27:37 -05:00
Mike Reeves
b36f1bc79e
Fix reinstall logic
2023-01-11 12:26:50 -05:00
weslambert
4391c22335
Move Suricata import policy definition so that it does not get caught in the for loop for Zeek policies
2023-01-11 12:23:50 -05:00
weslambert
39d1f07fab
Merge pull request #9561 from Security-Onion-Solutions/fix/filebeat_remove_module_setup
...
Remove pipeline.load from top.sls so that Filebeat module loading is not attempted
2023-01-11 12:21:39 -05:00
Mike Reeves
35e0a78cad
Fix reinstall logic
2023-01-11 12:20:57 -05:00
weslambert
b3e0183e39
Remove pipeline.load from top.sls so that Filebeat module loading is not attempted
2023-01-11 12:19:06 -05:00
Mike Reeves
708ba13721
Fix reinstall logic
2023-01-11 12:18:02 -05:00
Mike Reeves
eee433e8c4
Fix reinstall logic
2023-01-11 12:17:13 -05:00
Mike Reeves
cd57ff9820
Fix reinstall logic
2023-01-11 12:16:18 -05:00
Mike Reeves
6d1e6fc358
Fix reinstall logic
2023-01-11 12:15:21 -05:00
Mike Reeves
0531d369aa
Fix reinstall logic
2023-01-11 11:09:06 -05:00
Mike Reeves
55911ef649
Fix reinstall logic
2023-01-11 11:05:01 -05:00
weslambert
355953427c
Merge pull request #9553 from Security-Onion-Solutions/feature/filebeat_to_elastic_agent_conversion
...
Initial Conversion of Filebeat Inputs to Elastic Agent Inputs
2023-01-11 09:22:40 -05:00
Wes
52b620b137
Add additional conditional logic for Filebeat and disable Filebeat
2023-01-11 14:10:11 +00:00
Wes
33e2affb1d
Remove newlines from end of Syslog processor definitions
2023-01-11 14:08:28 +00:00
Wes
c3b83f1fc8
Update template settings to use data streams
2023-01-11 14:03:11 +00:00
Wes
5062dd2873
Suricata Elasticsearch ingest node pipeline changes - set 'alert' dataset
2023-01-11 14:02:09 +00:00
Wes
2e886d0c55
Remove data_index_name processor since we are using data streams
2023-01-11 13:58:38 +00:00
Wes
5d86edeed4
Modify Logstash Elastic Agent output to accomodate for events with and without 'metadata.pipeline'
2023-01-11 13:57:32 +00:00
Wes
caf0ea6b53
Add Elastic Agent policy view script
2023-01-11 13:56:21 +00:00
Wes
a146f1134e
Add Elastic Agent utility scripts
2023-01-11 13:54:42 +00:00
Mike Reeves
7cecc910d5
Merge pull request #9458 from Security-Onion-Solutions/2.4/firewall
...
2.4/firewall
2023-01-11 08:49:15 -05:00
Doug Burks
668fe10fc0
Merge pull request #9552 from Security-Onion-Solutions/fix/import-unnecessary-processes
...
Prevent unnecessary processes in Import Mode
2023-01-11 08:07:40 -05:00
m0duspwnens
76fff1b1e0
add logstash ports
2023-01-10 17:02:54 -05:00
Josh Patterson
5993d06896
Merge pull request #9548 from Security-Onion-Solutions/2.4minefunctionsconf
...
Update so-functions
2023-01-10 16:58:09 -05:00
Josh Patterson
64af393f40
Update so-functions
...
change MAININT to MNIC
2023-01-10 16:57:17 -05:00
Doug Burks
c15db73561
Avoid unnecessary Zeek processes in Import Mode
2023-01-10 16:48:47 -05:00
Doug Burks
554754421c
Avoid unecessary Suricata processes in Import Mode
2023-01-10 16:48:06 -05:00
Doug Burks
322efa304a
Avoid unnecessary processes in Import Mode
2023-01-10 16:47:18 -05:00
Mike Reeves
9995d06626
Merge branch '2.4/firewall' of https://github.com/Security-Onion-Solutions/securityonion into 2.4/firewall
2023-01-10 16:09:04 -05:00
Mike Reeves
ab3a7abcc7
run restore each time
2023-01-10 16:08:44 -05:00
Josh Patterson
f039ecb5ce
Merge pull request #9547 from Security-Onion-Solutions/2.4/dev
...
2.4/dev
2023-01-10 13:42:44 -05:00
Mike Reeves
38962520ac
Merge pull request #9546 from Security-Onion-Solutions/2.4minefunctionsconf
...
Update so-functions
2023-01-10 13:39:56 -05:00
Josh Patterson
0151830c85
Update so-functions
2023-01-10 13:37:56 -05:00
Mike Reeves
85978180c2
Merge pull request #9545 from Security-Onion-Solutions/revert-9544-2.4createrepoinstall
...
Revert "ensure yum-utils and createrepo are installed from so remote repo"
2023-01-10 13:13:31 -05:00
Mike Reeves
d3b8fbaafc
Revert "ensure yum-utils and createrepo are installed from so remote repo"
2023-01-10 13:13:13 -05:00
Josh Patterson
745387a756
Merge pull request #9544 from Security-Onion-Solutions/2.4createrepoinstall
...
ensure yum-utils and createrepo are installed from so remote repo
2023-01-10 11:53:36 -05:00
m0duspwnens
39d808cb8f
resolve conflict
2023-01-10 11:50:58 -05:00
Josh Patterson
ab8f41ecb5
Merge branch '2.4/firewall' into 2.4createrepoinstall
2023-01-10 11:38:31 -05:00
m0duspwnens
d2e623747d
ensure yum-utils and createrepo are installed from so remote repo
2023-01-10 11:34:50 -05:00
Mike Reeves
3e9bddcd11
Changes to iptables.jinja
2023-01-09 15:36:23 -05:00
Mike Reeves
302bf28b6c
Merge branch '2.4/firewall' of https://github.com/Security-Onion-Solutions/securityonion into 2.4/firewall
2023-01-09 15:00:05 -05:00
Mike Reeves
5058210bbb
Changes to iptables.jinja
2023-01-09 14:59:55 -05:00
m0duspwnens
ac157432de
include docker
2023-01-09 14:58:36 -05:00
m0duspwnens
ec5c565cec
put elastalert on sosbridge
2023-01-09 14:49:33 -05:00
m0duspwnens
dbbcea0009
look for True
2023-01-09 11:53:32 -05:00
m0duspwnens
c313b19b50
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/firewall
2023-01-09 11:18:08 -05:00
Mike Reeves
73ae48d28e
Merge pull request #9539 from Security-Onion-Solutions/mkr24
...
Changes to accept minion
2023-01-09 11:17:45 -05:00
Mike Reeves
0e1e9ff343
Changes to accept minion
2023-01-09 11:15:29 -05:00
Doug Burks
c3a5a02010
Merge pull request #9529 from Security-Onion-Solutions/dougburks-patch-1
...
Add missing Zeek log to filebeat defaults.yaml
2023-01-06 14:34:02 -05:00
Doug Burks
c1dfb9f935
Add missing Zeek log to filebeat defaults.yaml
2023-01-06 14:27:40 -05:00
Doug Burks
54e554eb3b
Merge pull request #9528 from Security-Onion-Solutions/dougburks-patch-1
...
Remove line numbers from vi
2023-01-06 14:25:19 -05:00
Doug Burks
10e82c5f1c
Remove line numbers from vi
2023-01-06 14:23:54 -05:00
m0duspwnens
d4c6834cd0
merge with 2.4/dev
2023-01-06 14:01:58 -05:00
m0duspwnens
4aacc6d1db
change role names in so-firewall-minion
2023-01-06 11:09:09 -05:00
m0duspwnens
cb1822a62d
change ref to DOCKER.sosrange
2023-01-05 15:57:06 -05:00
m0duspwnens
f10238da42
fw changes
2023-01-04 16:06:14 -05:00
Mike Reeves
2e53476a06
Merge pull request #9516 from Security-Onion-Solutions/mkr24
...
Add PW auth for Redis
2023-01-04 14:50:27 -05:00
Mike Reeves
275aead5b9
Allow auth for redis check for tgraf
2023-01-04 14:30:28 -05:00
Mike Reeves
e52b54720a
Allow auth for redis check for tgraf
2023-01-04 14:26:24 -05:00
Mike Reeves
5afad52b3f
Allow auth for redis check for tgraf
2023-01-04 14:18:08 -05:00
Mike Reeves
9bc08661c5
Allow auth for redis check for tgraf
2023-01-04 14:15:53 -05:00
Mike Reeves
48a3f4e261
Allow auth for redis check for tgraf
2023-01-04 14:14:10 -05:00
Doug Burks
723362e685
Merge pull request #9514 from Security-Onion-Solutions/fix/jinja-whitespace-2.4
...
fix jinja whitespace 2.4
2023-01-04 13:56:24 -05:00
doug
7ba4bdd87b
fix jinja whitespace
2023-01-04 13:50:25 -05:00
Mike Reeves
831300b540
Require password auth for redis access
2023-01-04 11:02:40 -05:00
Doug Burks
4c1fc4c679
Merge pull request #9511 from Security-Onion-Solutions/fix/sysmon-fields-2.4
...
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:58:16 -05:00
Doug Burks
5754365c6d
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:42:24 -05:00
Mike Reeves
761fbd0edf
Merge pull request #9504 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soc_global.yaml
2023-01-03 12:24:58 -05:00
Mike Reeves
08d7b24fb4
Update soc_global.yaml
2023-01-03 12:17:51 -05:00
Mike Reeves
df89445ab5
Update soc_global.yaml
2023-01-03 12:17:14 -05:00
m0duspwnens
203e612452
enable icc and hostbinding on sosbridge
2023-01-03 11:21:05 -05:00
weslambert
2c3bd6e3fd
Merge pull request #9502 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_rita_beacon_2_4
...
Update RITA beacon parsing
2023-01-03 11:14:04 -05:00
m0duspwnens
c35a3e122f
add ip to container.add containers to sosbridge
2023-01-03 11:13:50 -05:00
Wes
c8ff2c7a06
Update RITA beacon parsing
2023-01-03 16:03:49 +00:00
Doug Burks
3c91d842f5
Merge pull request #9499 from Security-Onion-Solutions/fix/sysmon-parsing-2.4
...
FIX: Sysmon logs are missing event.category and event.dataset #8194
2023-01-03 09:05:55 -05:00
doug
4e5d1d587e
update sysmon ingest parser and Sysmon File dashboard
2023-01-03 09:02:17 -05:00
Jason Ertel
8d797ad9df
Merge pull request #9490 from Security-Onion-Solutions/kilo
...
Ensure create/update dates are both reset when an admin sets a user pass
2022-12-30 11:47:01 -05:00
Jason Ertel
a89976779d
Ensure create/update dates are both reset when an admin sets a user's password
2022-12-30 11:30:09 -05:00
Mike Reeves
058b4013aa
Merge pull request #9470 from Security-Onion-Solutions/kilo
...
Kilo
2022-12-23 10:37:22 -05:00
Jason Ertel
136867c96a
ensure zombie pipe is destroyed before SOC restarts
2022-12-23 10:27:49 -05:00
Mike Reeves
1b946ced7f
Merge pull request #9469 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soc_global.yaml
2022-12-23 08:58:07 -05:00
Mike Reeves
75ffd1f56b
Update soc_global.yaml
2022-12-23 08:55:19 -05:00
Doug Burks
f335e7e477
Merge pull request #9466 from Security-Onion-Solutions/2.4/fix-grafana-playbook-links
...
Remove Grafana and Playbook links for Import mode
2022-12-22 16:09:46 -05:00
Doug Burks
5be074bbea
Remove Grafana and Playbook links for Import mode
2022-12-22 15:45:25 -05:00
m0duspwnens
24876eecd9
change refs from sosnet to sosbridge
2022-12-22 14:02:40 -05:00
Mike Reeves
3f0ded0638
Merge pull request #9464 from Security-Onion-Solutions/mkr24
...
Add global annotation and influx support
2022-12-22 13:57:56 -05:00
Mike Reeves
cd77e71d8d
Create annotation file for global settings
2022-12-22 13:37:41 -05:00
Mike Reeves
78f851e6c2
Create annotation file for global settings
2022-12-22 13:35:37 -05:00
Doug Burks
b02ba7edf7
Merge pull request #9463 from Security-Onion-Solutions/2.4/fix-grafana-eval
...
Enable Grafana in EVAL mode
2022-12-22 13:30:54 -05:00
m0duspwnens
90882ce1db
disable docker from managing iptables
2022-12-22 13:26:10 -05:00
Mike Reeves
a924d48408
Specify Influxdb host
2022-12-22 13:12:19 -05:00
Mike Reeves
308228620a
Specify Influxdb host
2022-12-22 13:05:33 -05:00
Mike Reeves
4620cd5edf
Merge pull request #9462 from Security-Onion-Solutions/mkr24
...
Modify manager for repo
2022-12-22 13:01:58 -05:00
Doug Burks
2df4755fef
Enable Grafana in EVAL mode
2022-12-22 12:54:57 -05:00
Mike Reeves
cf02b8e191
Modify manager for repo
2022-12-22 10:34:33 -05:00
Jason Ertel
a077645bb4
Merge branch '2.4/dev' into kilo
2022-12-22 10:27:13 -05:00
Jason Ertel
b6f37f8499
Correct indentation of client section
2022-12-22 10:26:51 -05:00
Doug Burks
f1d31a0c41
Merge pull request #9459 from Security-Onion-Solutions/2.4/fix-influxdb-telegraf
...
Make influxdb and telegraf consistent across import and eval modes
2022-12-22 10:26:36 -05:00
Doug Burks
e95034886e
add influxdb and telegraf to import mode
2022-12-22 09:49:57 -05:00
Doug Burks
9352854fe4
enable influxdb for eval and import modes
2022-12-22 09:48:38 -05:00
Doug Burks
75e16963c8
add influxdb and telegraf to import mode
2022-12-22 09:47:47 -05:00
Doug Burks
dfd5947051
add influxdb and telegraf to import mode
2022-12-22 09:46:27 -05:00
m0duspwnens
b4908e2bb9
add iptables.jinja
2022-12-22 09:31:45 -05:00
Jason Ertel
ba13ad7151
Merge pull request #9454 from Security-Onion-Solutions/kilo
...
fix redis defaults to force string keys instead of numeric
2022-12-21 18:16:40 -05:00
Jason Ertel
38634fde17
fix redis defaults to force string keys instead of numeric
2022-12-21 18:15:17 -05:00
Jason Ertel
8b6006e9c3
fix redis defaults to force string keys instead of numeric
2022-12-21 18:14:18 -05:00
Jason Ertel
3fd210463e
fix redis defaults to force string keys instead of numeric
2022-12-21 18:11:39 -05:00
Doug Burks
f99279ca24
Merge pull request #9453 from Security-Onion-Solutions/feature/improve-dashboards-2.4
...
FEATURE: Improve SOC Dashboards #9450 2.4
2022-12-21 15:46:11 -05:00
Doug Burks
69415a0d8d
Improve Strelka dashboard
2022-12-21 15:34:35 -05:00
Doug Burks
506556f0d2
Improve Firewall dashboard
2022-12-21 15:29:09 -05:00
Doug Burks
d7b2c88201
Improve Software dashboard
2022-12-21 15:24:58 -05:00
Doug Burks
4519c533a2
Improve Intel dashboard
2022-12-21 15:20:27 -05:00
Josh Patterson
8d35e0120e
Merge pull request #9451 from Security-Onion-Solutions/2.4/so-kibana-config-load
...
need space between curl.config and -X
2022-12-21 15:11:54 -05:00
m0duspwnens
6d6fa4c1e3
need space between curl.config and -X
2022-12-21 15:06:56 -05:00
m0duspwnens
accc293c8a
2.4 firewall changes
2022-12-21 15:03:45 -05:00
Doug Burks
3a367d69f4
Improve FTP dashboard
2022-12-21 14:37:17 -05:00
Doug Burks
a4f1f75306
Improve NIDS Alerts dashboard
2022-12-21 14:33:01 -05:00
Jason Ertel
5a5c565fae
Merge pull request #9449 from Security-Onion-Solutions/kilo
...
Ensure user/pass values are quoted due to symbol chars appearing in values
2022-12-21 14:02:38 -05:00
Jason Ertel
0889d49025
Ensure user/pass values are quoted due to symbol chars appearing in the values
2022-12-21 14:00:10 -05:00
Doug Burks
3d1ce4ef10
Improve SOC dashboards
2022-12-21 13:26:04 -05:00
Jason Ertel
33a1aea729
Merge pull request #9448 from Security-Onion-Solutions/kilo
...
improve so-status rendering on terminals that only support 8 colors
2022-12-21 10:14:47 -05:00
Jason Ertel
8e63909edf
improve so-status rendering on terminals that only support 8 colors
2022-12-21 10:11:38 -05:00
Mike Reeves
ab9edd4e6b
Merge pull request #9421 from Security-Onion-Solutions/mkr24
...
Redis defaults.yaml
2022-12-21 09:15:49 -05:00
Mike Reeves
aa7690864a
Modify redis config defaults
2022-12-20 22:05:04 -05:00
Mike Reeves
e1d0f99a14
Modify redis config defaults
2022-12-20 22:00:10 -05:00
Mike Reeves
38e23a0110
Modify Kratos config defaults
2022-12-20 21:21:18 -05:00
Mike Reeves
3768c0fee2
Fix Redis
2022-12-20 21:16:53 -05:00
Mike Reeves
8c6a2ce83a
Fix Kratos mode
2022-12-20 21:00:06 -05:00
Mike Reeves
9428949c79
Fix Kratos top
2022-12-20 20:56:06 -05:00
Mike Reeves
90061e2683
Fix Kratos top
2022-12-20 20:54:43 -05:00
Mike Reeves
c3917a373c
Fix Kratos top
2022-12-20 20:52:01 -05:00
m0duspwnens
318aac880e
file.managed for kratos schema
2022-12-20 17:40:29 -05:00
m0duspwnens
16b882a10e
new states for kratos config and schema
2022-12-20 15:34:58 -05:00
Mike Reeves
eaa705ee3e
Fix Kratos Pillar entry
2022-12-20 14:38:17 -05:00
Jason Ertel
2edc3cac11
Clarify Kratos annotations
2022-12-20 14:08:49 -05:00
Mike Reeves
13e5fa7544
SOC files for Kratos
2022-12-20 13:30:51 -05:00
m0duspwnens
a2d0de7e49
kratos config jinja
2022-12-20 12:15:33 -05:00
Josh Brower
f7150d423c
Merge pull request #9440 from Security-Onion-Solutions/fleet-setup-fixes
...
Make Fleet setup less fragile
2022-12-20 11:55:14 -05:00
Josh Brower
73a9c3bb38
Make Fleet setup less fragile
2022-12-20 11:52:56 -05:00
Doug Burks
03f682dbec
Merge pull request #9439 from Security-Onion-Solutions/2.4/remove-old-whiptail
...
Remove whiptail_network_init_notice
2022-12-20 11:16:24 -05:00
Mike Reeves
c0c2d28d19
SOC files for Redis
2022-12-20 11:09:49 -05:00
Doug Burks
1371c4d01f
remove whiptail_network_init_notice from so-whiptail
2022-12-20 10:46:14 -05:00
Doug Burks
388e0a08ae
remove old whiptail reference from so-functions
2022-12-20 10:45:30 -05:00
Doug Burks
6487e6e1f0
remove old whiptail reference from so-setup
2022-12-20 10:44:37 -05:00
Doug Burks
d4c54ce161
Merge pull request #9438 from Security-Onion-Solutions/dougburks-patch-1
...
so-status should ignore commented entries in so-status.conf
2022-12-20 09:16:21 -05:00
Doug Burks
894434715b
so-status should ignore commented entries in so-status.conf
...
Import mode comments out so-steno, so-suricata, and so-zeek in so-status.conf, so so-status should ignore these lines.
2022-12-20 09:05:07 -05:00
Doug Burks
86fc0e11b0
Merge pull request #9436 from Security-Onion-Solutions/2.4/improve-import
...
Import mode does not need Elastic Fleet or Playbook
2022-12-20 07:32:24 -05:00
Doug Burks
69811b4d74
Import mode does not need Elastic Fleet or Playbook
2022-12-20 06:46:01 -05:00
Doug Burks
316d2cd9a5
Merge pull request #9435 from Security-Onion-Solutions/2.4/fix-import
...
Fix Import Mode in 2.4
2022-12-20 06:13:37 -05:00
doug
cd55be2f83
move IMPORT to top of list
2022-12-19 16:58:43 -05:00
doug
9d8951ceb8
fix import
2022-12-19 16:55:16 -05:00
Doug Burks
7168c4f91a
fix import in so-setup
2022-12-19 16:48:35 -05:00
Mike Reeves
aea91cc776
Merge branch 'mkr24' of https://github.com/Security-Onion-Solutions/securityonion into mkr24
2022-12-19 16:21:47 -05:00
Mike Reeves
74af54a200
SOC file for influx
2022-12-19 16:16:48 -05:00
m0duspwnens
6a4718ec0f
merge defaults with pillar
2022-12-19 15:55:35 -05:00
m0duspwnens
30419e5b2b
fix import and jinja spacing
2022-12-19 14:51:12 -05:00
m0duspwnens
ce0b920195
jinja conf for influxdb
2022-12-19 14:44:52 -05:00
m0duspwnens
e5d38255fa
jinja conf for influxdb
2022-12-19 14:42:48 -05:00
Josh Brower
b901efc90d
Merge pull request #9434 from Security-Onion-Solutions/2.4/allow-editing-efpolicies
...
Unmanage default policies
2022-12-19 14:33:16 -05:00
Josh Brower
6d07ab0c40
Unmanage default policies
2022-12-19 14:27:36 -05:00
Mike Reeves
c20f8c230b
Initial SOC file for influx
2022-12-19 14:02:01 -05:00
Doug Burks
cf884c68a7
Merge pull request #9433 from Security-Onion-Solutions/dougburks-patch-1
...
Remove another hardcoded docs URL
2022-12-19 13:16:42 -05:00
Doug Burks
0494efaea0
remove temporary message
2022-12-19 13:15:02 -05:00
Mike Reeves
149038d08e
pillar tops
2022-12-19 12:06:45 -05:00
Mike Reeves
fde65db021
Add influx pillars during setup
2022-12-19 12:03:00 -05:00
Mike Reeves
61bfeb82d9
fix defaults for influx
2022-12-19 11:01:19 -05:00
Mike Reeves
56f326d123
fix defaults for influx
2022-12-19 10:46:39 -05:00
Doug Burks
d7b47814dc
Merge pull request #9432 from Security-Onion-Solutions/2.4/refactor-docs-url
...
2.4: Refactor docs URL
2022-12-19 10:43:22 -05:00
Mike Reeves
d9343d8450
fix defaults for redis
2022-12-19 10:38:11 -05:00
Mike Reeves
42157ff2b1
fix defaults for redis
2022-12-19 10:36:35 -05:00
Doug Burks
df1b564d17
Replace hardcoded URL in so-analyst-install with new $DOC_BASE_URL variable from so-common
2022-12-19 10:30:29 -05:00
Doug Burks
73f2789c95
Replace hardcoded URLs in soup with new $DOC_BASE_URL variable from so-common
2022-12-19 10:28:20 -05:00
m0duspwnens
3c00d67879
fix redis defaults
2022-12-19 10:24:28 -05:00
Doug Burks
a28f804f7f
Replace hardcoded URLs with new $DOC_BASE_URL variable from so-common
2022-12-19 10:24:03 -05:00
Doug Burks
042693895a
add new DOC_BASE_URL variable to so-common
2022-12-19 10:21:54 -05:00
m0duspwnens
01d6b2b1f1
jinja the redis config
2022-12-19 10:14:48 -05:00
weslambert
c220c322ef
Merge pull request #9431 from Security-Onion-Solutions/fix/elasticsearch_templates_elastic_agent
...
Remove 'so-' prefix for Elastic Agent/Fleet component templates
2022-12-19 10:14:39 -05:00
weslambert
fd1be0ab2c
Remove 'so-' prefix for Elastic Agent/Fleet component templates
2022-12-19 10:11:26 -05:00
Mike Reeves
4c90c1af12
Add defaults for redis
2022-12-18 18:07:02 -05:00
Doug Burks
c25a828dd2
Merge pull request #9417 from Security-Onion-Solutions/2.4/eval
...
Fix EVAL mode in 2.4
2022-12-16 16:39:46 -05:00
Doug Burks
0fa6ca3880
init.sls needs to import GLOBALS
2022-12-16 15:59:17 -05:00
Jason Ertel
1b42965a6d
Merge pull request #9416 from Security-Onion-Solutions/jertel/lic
...
license key format change and eventFields dedup
2022-12-16 15:58:08 -05:00
Jason Ertel
fa7488effb
change format of license key for compat with config alignment
2022-12-16 15:56:02 -05:00
Mike Reeves
93a8b76070
Add defaults for influxdb
2022-12-16 15:17:25 -05:00
Doug Burks
490e97b49f
Merge pull request #9415 from Security-Onion-Solutions/2.4/dev
...
2.4/dev
2022-12-16 15:07:39 -05:00
Doug Burks
4384b83b65
Merge pull request #9412 from Security-Onion-Solutions/dougburks-patch-1
...
fix telegraf_pillar
2022-12-16 13:51:32 -05:00
Doug Burks
9c4d441b4d
fix telegraf_pillar
2022-12-16 13:36:26 -05:00
doug
b9e51fc7cf
first round of fixes for eval mode
2022-12-16 13:24:02 -05:00
Doug Burks
93056e802f
remove old comment
2022-12-16 13:17:27 -05:00
Mike Reeves
3f4ad8b983
Merge pull request #9411 from Security-Onion-Solutions/mkr24
...
Change telegraf to match config map standard
2022-12-16 13:10:15 -05:00
Jason Ertel
b37697e95d
Switch license key to single line to avoid multiline/list conflicts
2022-12-16 12:50:22 -05:00
Mike Reeves
676aec7576
Add config map
2022-12-16 11:22:53 -05:00
Mike Reeves
b5cc5a023d
Merge pull request #9410 from Security-Onion-Solutions/mkr24
...
Add Telegraf to the GUI for 2.4
2022-12-16 08:44:57 -05:00
Mike Reeves
5badfb9cf5
Fix pillar
2022-12-16 08:38:31 -05:00
Jason Ertel
7853d972b6
Set default key to empty string to ensure new keys are type aligned correctly
2022-12-15 18:31:47 -05:00
Mike Reeves
8a0991afd0
Fix pillar
2022-12-15 15:05:57 -05:00
Jason Ertel
f84ceca03e
consolidate eventFields from hunt and dashbaords into a single setting
2022-12-15 14:22:23 -05:00
Mike Reeves
6b3149f4e9
Fix the pillar top
2022-12-15 14:03:21 -05:00
Mike Reeves
175f413beb
Minor gui tweak
2022-12-15 13:36:00 -05:00
Mike Reeves
121d07733f
Merge the defaults and pillar for telegraf
2022-12-15 13:29:31 -05:00
Mike Reeves
e55086230d
Merge the defaults and pillar for telegraf
2022-12-15 13:28:29 -05:00
Mike Reeves
d37a4b14ca
Spelling error
2022-12-15 12:02:01 -05:00
Mike Reeves
fd27044471
Spelling error
2022-12-15 11:57:06 -05:00
Mike Reeves
ed87b08fc1
Spelling error
2022-12-15 10:59:07 -05:00
Mike Reeves
5d732872d6
Add soc gui info for telegraf
2022-12-15 10:51:22 -05:00
Mike Reeves
28e8c54443
Wire telegraf initial commit
2022-12-15 10:43:58 -05:00
Jason Ertel
6a73410be9
Merge pull request #9394 from Security-Onion-Solutions/jertel/mvkr
...
move Kratos DB to /nsm
2022-12-14 15:00:44 -05:00
Jason Ertel
52c4553ea6
move Kratos DB to /nsm
2022-12-14 14:28:34 -05:00
Jason Ertel
9885f418fa
move Kratos DB to /nsm
2022-12-14 14:22:55 -05:00
Mike Reeves
c79457b41d
Merge pull request #9386 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update config.map.jinja
2022-12-13 13:56:14 -05:00
Mike Reeves
6352b3fd53
Update config.map.jinja
2022-12-13 13:55:09 -05:00
Doug Burks
61c976f8a6
Merge pull request #9384 from Security-Onion-Solutions/2.4/streamline-setup
...
miscellaneous improvements for 2.4
2022-12-13 13:43:31 -05:00
Doug Burks
07df9ad0e0
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:30:38 -05:00
Doug Burks
ca3c99ac99
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:29:59 -05:00
doug
6eedae601f
improve welcome screen
2022-12-13 12:35:43 -05:00
doug
d58579d916
improve grammar
2022-12-13 12:05:02 -05:00
weslambert
09b012ad4e
Merge pull request #9372 from Security-Onion-Solutions/fix/sensoroni_analyzers_configuration_check_2_4
...
Fix localfile analyzer 'file_path' check and add new list value verification function for helpers
2022-12-13 11:47:18 -05:00
doug
0072cc42db
add extra newline
2022-12-13 11:34:29 -05:00
doug
0f84f419b2
fix sizing
2022-12-13 11:31:12 -05:00
Wes
3ab8a0be60
Update tests to account for change in 'file_path' value verification
2022-12-13 16:29:18 +00:00
Wes
eae05e83e6
Use new list verification function for 'file_path'
2022-12-13 16:28:50 +00:00
Wes
117d230b9d
Add new test for list value verification function
2022-12-13 16:28:22 +00:00
Wes
5422c5b3e2
Add new function to verify list value
2022-12-13 16:27:58 +00:00
doug
d3a8bdff52
setup improvements
2022-12-13 11:20:00 -05:00
Doug Burks
f94eb243e4
Merge pull request #9367 from Security-Onion-Solutions/dougburks-patch-1
...
Upgrade to Elastic 8.5.3
2022-12-13 10:14:41 -05:00
Doug Burks
3dd4e31f49
Upgrade to Elastic 8.5.3 in config_saved_objects.ndjson
2022-12-13 10:07:52 -05:00
Doug Burks
2004184b72
Upgrade to Elastic 8.5.3 in so-kibana-config-load
2022-12-13 10:06:23 -05:00
Doug Burks
ed8bf884eb
Merge pull request #9355 from Security-Onion-Solutions/fix/2.4-ics
...
Fix ICS and other issues in 2.4
2022-12-12 09:18:14 -05:00
Doug Burks
e1d200e6ce
Remove duplicate TDS dashboard from defaults.yaml
2022-12-11 14:39:08 -05:00
Doug Burks
72f71ba695
Fix TDS dashboard in defaults.yaml
2022-12-11 14:36:27 -05:00
Doug Burks
be75062612
Update so-import-pcap
2022-12-10 15:17:02 -05:00
Doug Burks
da8e098655
update so-import-evtx
2022-12-10 15:16:32 -05:00
Doug Burks
cb16bd36fb
fix descriptions in defaults.yaml
2022-12-10 14:31:59 -05:00
Doug Burks
cf7d8076e9
remove old Wazuh Hunt queries in defaults.yaml
2022-12-10 14:21:58 -05:00
Doug Burks
cd664b2d39
remove old Modbus dashboard from defaults.yaml
2022-12-10 14:16:39 -05:00
Doug Burks
7f07a94a98
remove old DNP3 and Wazuh dashboards from defaults.yaml
2022-12-10 14:14:24 -05:00
Doug Burks
8a0f94f8df
increase window width to accommodate extra text in so-whiptail
2022-12-10 11:24:11 -05:00
Doug Burks
66ad10cf77
fix airgap text in so-whiptail
2022-12-10 10:41:30 -05:00
Doug Burks
de2427cabe
add -p option to mkdir in so-elastic-fleet-setup
2022-12-10 08:20:38 -05:00
Doug Burks
187ca4c453
Update soc defaults.yaml to include dnp3_control and dnp3_objects eventfields
2022-12-10 07:33:09 -05:00
Doug Burks
c4ea39d1ba
Merge pull request #9349 from Security-Onion-Solutions/fix/2.4-ics
...
2.4: Fix multiple ICS issues and keep import indices open as in 2.3
2022-12-09 15:09:49 -05:00
doug
c2e10a4359
remove duplicate import iteration from so-functions
2022-12-09 11:00:06 -05:00
doug
90093395b6
keep so-import indices open as in 2.3
2022-12-09 10:23:09 -05:00
doug
565ca4e94f
keep so-import indices open as in 2.3
2022-12-09 08:49:25 -05:00
weslambert
69c7bb11c6
Merge pull request #9343 from Security-Onion-Solutions/fix/analyzers_localfile_file_path
...
FIX: Ensure file path is ascertainable by localfile.py for localfile analyzer
2022-12-08 17:08:19 -05:00
weslambert
9477f29432
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 17:06:43 -05:00
doug
5c00ab7b7f
correct order in defaults.yaml
2022-12-08 16:50:34 -05:00
doug
07a4919cd3
remove old opcua files
2022-12-08 16:43:11 -05:00
doug
7cfb688890
update defaults.yaml
2022-12-08 16:32:04 -05:00
Doug Burks
cf53242cf8
Merge pull request #9334 from Security-Onion-Solutions/dougburks-patch-1
...
update wording in so-whiptail
2022-12-08 10:43:22 -05:00
Doug Burks
c01486b009
update wording in so-whiptail
2022-12-08 10:32:03 -05:00
Mike Reeves
8af9dddd2e
Merge pull request #9326 from Security-Onion-Solutions/config
...
Switch back to older style redirect due to incompatibility with Ubuntu 18
2022-12-07 14:10:23 -05:00
Jason Ertel
0bbc68edae
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:08:11 -05:00
Jason Ertel
ef3def156d
Switch back to older style redirect due to incompatibility with Ubuntu 18
2022-12-07 14:03:31 -05:00
Mike Reeves
71e0d7c499
Merge pull request #9325 from Security-Onion-Solutions/config
...
Switch back to grep instead of pgrep
2022-12-07 12:13:27 -05:00
Jason Ertel
9f72cfa1fc
roll back to grep instead of pgrep due to cron issue
2022-12-07 12:08:31 -05:00
Jason Ertel
fde33de030
Use original style due to pgrep conflict with cron
2022-12-07 11:51:49 -05:00
Jason Ertel
d1f554723a
Merge pull request #9317 from Security-Onion-Solutions/config
...
Reduce cron noise; ensure filecheck is restarted if modified
2022-12-07 08:41:04 -05:00
Jason Ertel
e849783a86
Reduce cron noise; ensure filecheck is restarted if modified
2022-12-07 08:36:56 -05:00
weslambert
2240283457
Merge pull request #9316 from Security-Onion-Solutions/fix/ics_scada_filebeat_disable_ecat_arp_info
...
Disable Filebeat input for 'ecat_arp_info' Zeek logs
2022-12-07 08:08:42 -05:00
weslambert
def0c85349
Disable Filebeat input for 'ecat_arp_info' Zeek logs
2022-12-07 08:00:21 -05:00
weslambert
31832ae150
Merge pull request #9309 from Security-Onion-Solutions/fix/ignore_additional_strelka_rules_causing_compilation_errors
...
Ignore additional rules causing YARA compilation errors
2022-12-06 14:01:14 -05:00
weslambert
7ce0924382
Ignore additional rules causing compilation errors
2022-12-06 13:59:21 -05:00
weslambert
73304e049c
Merge pull request #9304 from Security-Onion-Solutions/feature/ics_scada_additions
...
Port STUN, TDS, WireGuard, and ICS/SCADA Changes from 2.3 to 2.4
2022-12-06 13:14:47 -05:00
weslambert
a626acced0
Add new ICS/SCADA event fields to the dashboards section of the configuration and remove extra space in key names.
2022-12-06 13:11:55 -05:00
Jason Ertel
6443e702a5
Merge pull request #9305 from Security-Onion-Solutions/config
...
Filecheck support for Suricata
2022-12-06 12:53:19 -05:00
Jason Ertel
88410bc8f8
Merge branch '2.4/dev' into config
2022-12-06 12:38:43 -05:00
Jason Ertel
168cd00e1b
Handle suricata extracted with filecheck
2022-12-06 12:34:02 -05:00
Wes
1b5c1fecd4
Revert SOC default 'alerts' event fields and specify additional event fields for ICS/SCADA events
2022-12-06 17:28:30 +00:00
Wes
b048eec3c0
Add STUN, TDS, WireGuard, and ICS/SCADA dashboard queries
2022-12-06 17:17:49 +00:00
Wes
f44eee134a
Add default queries and ICS/SCADA queries
2022-12-06 16:52:20 +00:00
Wes
c741fe6b4d
Ensure ICS/SCADA plugins/scripts are enabled
2022-12-06 16:23:26 +00:00
Wes
be5775e4a0
Ensure Filebeat defaults file is updated with ICS/SCADA log references
2022-12-06 16:15:09 +00:00
Wes
499b5d95f2
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-12-06 16:01:57 +00:00
Wes
14af1d36cb
Ensure ICS/SCADA pipelines are present
2022-12-06 15:58:47 +00:00
Jason Ertel
fd13c7ccc0
Additional metadata for soc
2022-12-05 09:03:22 -05:00
Mike Reeves
7e102949a6
Merge pull request #9268 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update init.sls
2022-12-02 12:58:12 -05:00
Mike Reeves
f083b3867b
Update init.sls
2022-12-02 09:40:35 -05:00
Mike Reeves
55444288bc
Merge pull request #9254 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update filecheck
2022-11-30 11:04:18 -05:00
Mike Reeves
f83545c556
Update filecheck
2022-11-30 11:02:56 -05:00
weslambert
117a3d486a
Merge pull request #9210 from Security-Onion-Solutions/fix/add_missing_opcua_activate_session_pipelines_2_4
...
Add Missing OPCUA Activate Session Pipelines
2022-11-22 16:01:45 -05:00
Wes
7f324bc47e
Remove extra space used during testing
2022-11-22 20:52:08 +00:00
Wes
a6bc5b108f
Add missing OPCUA 'activate_session' pipelines
2022-11-22 20:51:44 +00:00
weslambert
090f8309c2
Merge pull request #9207 from Security-Onion-Solutions/fix/ingest_typos_2_4
...
Fix spelling of 'wireguard.responses' field name
2022-11-22 15:36:04 -05:00
m0duspwnens
b95a83b016
Merge remote-tracking branch 'remotes/origin/2.4/dev' into dockerips
2022-11-22 14:17:19 -05:00
m0duspwnens
b05839bb93
use single quote
2022-11-22 13:07:58 -05:00
weslambert
356904f751
Fix spelling of 'wireguard.responses' field name
2022-11-22 13:03:04 -05:00
weslambert
f9cc7888f4
Merge pull request #9204 from Security-Onion-Solutions/fix/ics_ingest_field_names_2_4
...
Fix ICS Ingest Field Names
2022-11-22 12:30:17 -05:00
weslambert
6b77843e52
Fix format/speliing for 'enip.status_code' field name
2022-11-22 12:07:55 -05:00
weslambert
13faf63770
Fix spelling for 'stun.class' field name
2022-11-22 12:07:15 -05:00
m0duspwnens
6d89d58c50
ensure createrepo and yum-utils is installed from so repo
2022-11-22 11:10:30 -05:00
m0duspwnens
4b6b42f9b9
dont try to add sosnet if it exists
2022-11-22 10:19:18 -05:00
weslambert
b801997709
Merge pull request #9196 from Security-Onion-Solutions/fix/missing_ics_pipelines_2_4
...
Add COTP and TDS ingest pipelines
2022-11-22 08:44:19 -05:00
Wes
a38e312df4
Add COTP and TDS ingest pipelines
2022-11-22 13:36:27 +00:00
weslambert
bde899e7cb
Merge pull request #9194 from Security-Onion-Solutions/fix/ics_tag_syntax_error_2_4
...
Fix syntax error for 'ics' tag logic
2022-11-22 07:32:54 -05:00
weslambert
d2bc1a5523
Fix syntax error for 'ics' tag logic
2022-11-22 07:24:54 -05:00
weslambert
68efd817e0
Merge pull request #9189 from Security-Onion-Solutions/feature/filebeat_config_ics_event_tag_2_4
...
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 17:06:14 -05:00
weslambert
fe180d5657
Fix indentation
2022-11-21 17:02:17 -05:00
weslambert
9994d47a43
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 16:46:47 -05:00
Doug Burks
6e1e6e15e8
Merge pull request #9186 from Security-Onion-Solutions/dougburks-patch-2
...
Add ICS/SCADA logs to filebeat defaults.yaml
2022-11-21 13:30:35 -05:00
Doug Burks
febb781428
Add ICS/SCADA logs to filebeat defaults.yaml
2022-11-21 12:10:55 -05:00
weslambert
061f0b0595
Merge pull request #9159 from Security-Onion-Solutions/feature/additional_ics_scada_ingest_pipelines_2_4
...
Add additional ICS/SCADA ingest node pipelines
2022-11-21 10:32:00 -05:00
Doug Burks
5a0fe6050b
Merge pull request #9179 from Security-Onion-Solutions/dougburks-patch-2
...
Simplify version in README.md to just 2.4
2022-11-21 08:46:33 -05:00
Doug Burks
778ee4b00f
Simplify version in README.md to just 2.4
2022-11-21 08:39:18 -05:00
Jason Ertel
5f59ae52d5
Merge pull request #9162 from Security-Onion-Solutions/config
...
Config
2022-11-17 11:50:35 -05:00
Wes
05b9a067fd
Add additional ICS/SCADA ingest node pipelines
2022-11-17 16:03:21 +00:00
Jason Ertel
ed9aa5b73f
Ensure filecheck is up by checking every minute
2022-11-17 10:48:53 -05:00
Jason Ertel
7f7e5474ed
Add more logging for filecheck monitoring, and ensure scripts are accessible to salt-relay
2022-11-17 10:43:05 -05:00
Jason Ertel
0ffef75d7b
Move background jobs to cron
2022-11-17 09:50:41 -05:00
Jason Ertel
c572848ece
temporarily remove filecheck for debug purposes
2022-11-17 08:06:24 -05:00
Jason Ertel
7cd5d625d1
temporarily remove salt-pipe for debug purposes
2022-11-16 20:45:50 -05:00
Jason Ertel
4497037442
Use bg:True to send cmd to background
2022-11-16 20:03:54 -05:00
weslambert
c14c8c1306
Merge pull request #9154 from Security-Onion-Solutions/fix/ics_scada_ingest_pipeline_updates_2_4
...
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 16:17:19 -05:00
Wes
638a3568b0
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 21:11:21 +00:00
m0duspwnens
d97e13b473
add /24 back to default bip, rever daemon.json
2022-11-16 14:47:40 -05:00
m0duspwnens
a3b505971b
remove /24 from docker bip
2022-11-16 12:51:43 -05:00
Josh Brower
98af16055c
Merge pull request #9151 from Security-Onion-Solutions/2.4/elasticfleet-ag
...
Initial support for Elastic Fleet Package Registry
2022-11-16 08:45:29 -05:00
Josh Brower
8db49feb32
Use our docker image
2022-11-16 08:24:25 -05:00
m0duspwnens
9ffde8bff5
ensure options are strings
2022-11-15 17:46:08 -05:00
m0duspwnens
19f043cfe2
add some options for sosnet
2022-11-15 17:39:08 -05:00
m0duspwnens
54e4749ddf
remove comma
2022-11-15 17:30:55 -05:00
m0duspwnens
d246aa6a80
we dont need default network config
2022-11-15 17:14:33 -05:00
m0duspwnens
75825617da
add soc to sosnet
2022-11-15 17:13:25 -05:00
m0duspwnens
edd993fd82
change dupe soc to elastalert
2022-11-15 16:02:17 -05:00
Mike Reeves
813e59aa61
Add statics
2022-11-15 13:23:35 -05:00
Josh Brower
48d191b656
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/elasticfleet-ag
2022-11-15 12:13:05 -05:00
Josh Patterson
a371c89f38
Update top.sls
2022-11-15 11:52:51 -05:00
Josh Patterson
1c242fb7f3
Update top.sls
2022-11-15 11:52:25 -05:00
Josh Patterson
c0afcca87a
Update init.sls
2022-11-15 11:16:18 -05:00
Mike Reeves
591616fe5b
Add statics to all containers
2022-11-15 11:05:17 -05:00
Mike Reeves
efc8621524
Fix some settings and add all defaults
2022-11-15 10:31:37 -05:00
Mike Reeves
6016b0e38a
Add dynamic ability for IP range for sosnet
2022-11-14 20:20:38 -05:00
Mike Reeves
e41361e127
Add Docker IP Skeleton
2022-11-14 17:43:14 -05:00
Mike Reeves
a40e10da83
Add Docker IP Skeleton
2022-11-14 17:41:38 -05:00
Mike Reeves
3378f58300
Add Docker IP Skeleton
2022-11-14 17:07:42 -05:00
Mike Reeves
a2d3b95e92
Add Docker IP Skeleton
2022-11-14 13:04:31 -05:00
Mike Reeves
5c50fdb74c
Add Docker IP Skeleton
2022-11-14 13:00:56 -05:00
Mike Reeves
f1135342a9
Add Docker IP Skeleton
2022-11-14 11:17:48 -05:00
Doug Burks
a2da8e5e08
Merge pull request #9129 from Security-Onion-Solutions/dougburks-patch-1
...
fix descriptions in files related to analyzers
2022-11-12 19:26:34 +00:00
Doug Burks
632464335f
fix descriptions in files related to analyzers
2022-11-12 13:14:02 -05:00
Doug Burks
f77db78219
fix descriptions in files related to analyzers
2022-11-12 13:13:30 -05:00
Doug Burks
2f4ce91678
fix descriptions in files related to analyzers
2022-11-12 13:12:58 -05:00
Doug Burks
154dff98de
fix descriptions in files related to analyzers
2022-11-12 13:12:23 -05:00
Doug Burks
a15ca3cc49
fix descriptions in files related to analyzers
2022-11-12 13:11:38 -05:00
Doug Burks
a6ad7fa3ac
Merge pull request #9125 from Security-Onion-Solutions/dougburks-patch-2
...
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 21:33:43 +00:00
Doug Burks
40f5bb25ef
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 16:28:23 -05:00
Josh Patterson
7420c31411
Merge pull request #9096 from Security-Onion-Solutions/salt3005.1_2.4
...
roll back to salt 3004.2
2022-11-08 15:47:00 -05:00
m0duspwnens
00cb0f5abb
roll back to salt 3004.2
2022-11-08 15:45:18 -05:00
Mike Reeves
bf31b593ed
Merge pull request #9055 from Security-Onion-Solutions/strelkastuff
...
Strelkastuff
2022-11-08 13:45:42 -05:00
Josh Patterson
4870b4b91f
Merge pull request #9095 from Security-Onion-Solutions/salt3005.1_2.4
...
upgrade to salt 3005.1
2022-11-08 13:45:24 -05:00
m0duspwnens
1a678064dc
upgrade to salt 3005.1
2022-11-08 13:42:24 -05:00
Josh Brower
c389944e5c
Initial support for Elastic Package Registry
2022-11-08 09:56:53 -05:00
Mike Reeves
de19a4dc53
Add Strelka Filecheck
2022-11-02 10:04:33 -04:00
Mike Reeves
d97de9fd0d
Add Strelka Filecheck
2022-11-02 10:02:21 -04:00
Mike Reeves
bf5df1ac51
Add Strelka Filecheck
2022-11-02 09:57:07 -04:00
Mike Reeves
225c33e5c9
Add Strelka Filecheck
2022-11-02 09:46:23 -04:00
Mike Reeves
4187363451
Add Strelka Filecheck
2022-11-02 09:44:08 -04:00
Doug Burks
f3fc52dd2c
Merge pull request #9041 from Security-Onion-Solutions/dougburks-patch-1
...
https://github.com/Security-Onion-Solutions/securityonion/pull/8952
2022-11-01 13:40:51 +00:00
Doug Burks
2030f08b54
https://github.com/Security-Onion-Solutions/securityonion/pull/8952
2022-11-01 09:35:53 -04:00
Jason Ertel
55f22af758
Merge pull request #9017 from Security-Onion-Solutions/config
...
Retry so-user commands if another process is currently using so-user
2022-10-27 15:41:37 -04:00
Jason Ertel
35fab05bdd
Retry so-user commands if another process is currently using so-user
2022-10-27 15:25:08 -04:00
Jason Ertel
d7b370e31b
Merge pull request #9010 from Security-Onion-Solutions/config
...
regex should match entire input against allowed logLevel values
2022-10-27 13:17:51 -04:00
Josh Patterson
c6ebe5c8dd
Merge pull request #9016 from Security-Onion-Solutions/patch2.4
...
Patch2.4
2022-10-27 13:07:54 -04:00
m0duspwnens
8af0334c3c
Merge remote-tracking branch 'remotes/origin/2.4/dev' into patch2.4
2022-10-27 11:08:32 -04:00
m0duspwnens
6525e0f201
setup no longer add patch pillar to minion
2022-10-27 10:56:29 -04:00
m0duspwnens
a95c2a690a
add defaults and map for patch state
2022-10-27 10:54:29 -04:00
Jason Ertel
6347532dd8
regex should match entire input against allowed logLevel values
2022-10-26 18:48:20 -04:00
weslambert
8b0ea7104f
Merge pull request #9003 from Security-Onion-Solutions/fix/remove_ja3er_references
...
Remove JA3er references
2022-10-26 10:37:45 -04:00
weslambert
0ede5a7313
Remove JA3er references
2022-10-26 10:24:25 -04:00
weslambert
409b8c276e
Merge pull request #8999 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Fix PyYAML .whl file name and remove JA3er analyzer
2022-10-25 15:32:20 -04:00
Wes
803d2d4d75
Add PyYAML .whl files back since they were 'deleted' in the previous commit
2022-10-25 19:15:54 +00:00
Wes
0267ece4bf
Fix PyYAML .whl file name and remove JA3er analyzer
2022-10-25 19:11:52 +00:00
Josh Patterson
d148febc99
Merge pull request #8967 from Security-Onion-Solutions/curator2.4
...
add line space
2022-10-21 11:56:01 -04:00
m0duspwnens
8c5197c2ea
add line space
2022-10-21 11:49:01 -04:00
Josh Patterson
8197017b6c
Merge pull request #8966 from Security-Onion-Solutions/curator2.4
...
Curator2.4
2022-10-21 11:26:51 -04:00
m0duspwnens
8b5c79fb39
add so-kratos and so-ossec to curator defaults
2022-10-21 11:21:03 -04:00
m0duspwnens
71eaa715b6
update jinja
2022-10-21 11:09:52 -04:00
m0duspwnens
c880be8d45
use curator defaults.yaml merged with pillar for actions
2022-10-21 10:38:32 -04:00
Josh Patterson
3af271a13c
Merge pull request #8930 from Security-Onion-Solutions/statesglobals
...
Statesglobals
2022-10-17 16:06:42 -04:00
m0duspwnens
998870ac87
Merge remote-tracking branch 'remotes/origin/2.4/dev' into statesglobals
2022-10-17 15:58:44 -04:00
m0duspwnens
b089a58243
use registry_host instead of manager
2022-10-17 15:53:29 -04:00
m0duspwnens
09b7af2998
fix typo
2022-10-17 15:50:48 -04:00
m0duspwnens
deba743ef0
fix elasticsearch auth globals
2022-10-13 13:54:52 -04:00
m0duspwnens
04b4030eb6
only add elasticsearch.auth to elasticsearch global var if auth exists
2022-10-13 12:31:41 -04:00
Doug Burks
7ede0c3c76
Merge pull request #8915 from Security-Onion-Solutions/dougburks-patch-2
...
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 13:04:23 +00:00
Doug Burks
f6151b3895
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 09:03:10 -04:00
Jason Ertel
fd6bea92da
Merge pull request #8913 from Security-Onion-Solutions/config
...
retry up to 25 minutes if APT is locked by an unattended upgrade. This is an increase from 8 minutes.
2022-10-13 07:01:00 -04:00
Jason Ertel
1c23d91a3b
retry up to 25 minutes if APT is locked by an unattended upgrade. This is an increase from 8 minutes.
2022-10-13 06:57:17 -04:00
m0duspwnens
78b496a689
fix mine_functions.conf
2022-10-12 16:03:44 -04:00
m0duspwnens
95f7cb6bcd
change file_mode to mode
2022-10-12 14:21:55 -04:00
m0duspwnens
eed3746ebc
fix some globals
2022-10-12 13:39:37 -04:00
m0duspwnens
6a17f201a2
changes for backup state
2022-10-12 11:31:42 -04:00
weslambert
078213ddb3
Merge pull request #8898 from Security-Onion-Solutions/feature/elastic-agent-configuration-log-package
...
Add log package for Fleet to allow for custom log ingestion
2022-10-11 12:14:15 -04:00
weslambert
dd09ce7aab
Add log package for Fleet to allow for custom log ingestion
2022-10-11 12:00:57 -04:00
m0duspwnens
b526532ab6
use global vars in states
2022-10-11 11:57:15 -04:00
Doug Burks
2c5038aa9c
Merge pull request #8879 from Security-Onion-Solutions/2.4/improve-sysmon-dashboards
...
improve sysmon dashboards
2022-10-07 16:46:51 +00:00
doug
d65fde9536
improve sysmon dashboards
2022-10-07 12:23:40 -04:00
weslambert
8437592bb5
Merge pull request #8869 from Security-Onion-Solutions/feature/elastic-8.4.3
...
Elastic 8.4.3
2022-10-06 16:03:36 -04:00
weslambert
bee1b06f76
Update to Kibana 8.4.3
2022-10-06 15:14:43 -04:00
weslambert
985e1728d7
Update to Kibana 8.4.3
2022-10-06 15:13:27 -04:00
Mike Reeves
46bdd1acad
Merge pull request #8837 from Security-Onion-Solutions/config
...
Add SOC annotations
2022-10-03 08:46:46 -04:00
Jason Ertel
0fdec03fa9
use yaml anchor to avoid duplicated annotations
2022-09-30 15:15:35 -04:00
Jason Ertel
30a23a4cd0
Add SOC annotations
2022-09-30 15:00:08 -04:00
Jason Ertel
fe62744c05
Merge pull request #8825 from Security-Onion-Solutions/config
...
resolve inode issue with soc_users_roles when deleting a user; other minor improvements
2022-09-27 17:38:20 -04:00
Jason Ertel
5708f3595e
Avoid overwriting the file inode since it's mapped into a running container
2022-09-27 17:27:28 -04:00
Jason Ertel
e519548557
add logLevel default and annotation for quick access to enabling debug logs
2022-09-27 16:55:28 -04:00
Jason Ertel
981371c72f
log salt-relay responses for troubleshooting assistance
2022-09-27 16:48:47 -04:00
Jason Ertel
16d24d4bc9
Merge pull request #8822 from Security-Onion-Solutions/config
...
user management / sync
2022-09-27 11:14:32 -04:00
Jason Ertel
53b4f01921
replace quotes on minion arg
2022-09-27 10:54:08 -04:00
Jason Ertel
851e44e5fa
ensure salt-relay is restarted when SOC is manually restarted
2022-09-27 10:31:14 -04:00
Jason Ertel
7f7f2c15d0
add support for querying active salt jobs (future use)
2022-09-27 10:29:21 -04:00
Josh Patterson
004fa8167e
Merge pull request #8821 from Security-Onion-Solutions/fix/soc2.4
...
Fix/soc2.4
2022-09-27 10:15:04 -04:00
m0duspwnens
6bd4860f19
fix path
2022-09-27 09:57:01 -04:00
m0duspwnens
42b03ca6df
add missing soc things
2022-09-27 09:53:48 -04:00
Jason Ertel
556ddc2ee4
sync in background
2022-09-27 09:24:34 -04:00
Jason Ertel
8e175b2d3f
add manual sync
2022-09-27 07:05:04 -04:00
Mike Reeves
e032a9f449
Merge pull request #8816 from Security-Onion-Solutions/funstuff
2022-09-26 18:15:14 -04:00
Mike Reeves
2066efcabf
Add Rules to sync
2022-09-26 17:18:28 -04:00
Mike Reeves
37c98c14cd
Fix zeek logs in filebeat
2022-09-26 17:11:10 -04:00
Mike Reeves
aa7dd47b00
Fix zeek logs in filebeat
2022-09-26 17:01:44 -04:00
Doug Burks
ea8d9362ae
Merge pull request #8813 from Security-Onion-Solutions/dougburks-patch-1
...
Change managing-rules.html to rules.html in soc_idstools.yaml
2022-09-26 19:00:41 +00:00
Doug Burks
80201f1465
Change managing-rules.html to rules.html in soc_idstools.yaml
2022-09-26 14:58:51 -04:00
Jason Ertel
0ad1a1a262
so-user and salt-relay updates for user management
2022-09-26 14:57:33 -04:00
Doug Burks
1b13e454f8
Merge pull request #8812 from Security-Onion-Solutions/2.4/dev-fix-screenshots
...
fix screenshots in README.md
2022-09-26 17:49:10 +00:00
doug
97a6b3c2f3
fix screenshots
2022-09-26 13:46:46 -04:00
Josh Brower
97f42dcce5
Merge pull request #8811 from Security-Onion-Solutions/2.4/elastic-fleet
...
Live Query - View in Hunt fix
2022-09-26 09:35:12 -04:00
Josh Brower
a0b579019f
Live Query - View in Hunt fix
2022-09-26 09:27:09 -04:00
Doug Burks
4e5eb1cbb8
Merge pull request #8807 from Security-Onion-Solutions/2.4/dev-ocd
...
initial quick OCD pass
2022-09-23 20:39:54 +00:00
doug
fee5a7bea9
initial quick OCD pass
2022-09-23 16:29:55 -04:00
Josh Brower
d698238ed1
Merge pull request #8799 from Security-Onion-Solutions/2.4/elastic-fleet
...
Live Query - View in Hunt link
2022-09-23 15:00:32 -04:00
Mike Reeves
e3f4a58989
Merge pull request #8804 from Security-Onion-Solutions/funstuff
...
Firewall and More
2022-09-23 14:00:51 -04:00
Mike Reeves
d26be44df1
update soc_firewall.yaml
2022-09-23 13:09:46 -04:00
Mike Reeves
3e2be096be
update soc_firewall.yaml
2022-09-23 13:08:03 -04:00
Mike Reeves
2b9322b823
Helps if you add the IP address
2022-09-23 08:52:58 -04:00
Josh Patterson
02f1d24ea6
remove minion hg
2022-09-23 08:40:25 -04:00
Josh Patterson
975c7fabcc
remove minion hg
2022-09-23 08:39:48 -04:00
Josh Patterson
5e32e333c4
remove minion hg
2022-09-23 08:37:59 -04:00
Josh Brower
c7eccfd0c5
Live Query - View in Hunt link
2022-09-22 20:17:57 -04:00
Mike Reeves
a7872234ab
Remove NTP from setup
2022-09-22 17:07:00 -04:00
Mike Reeves
4b059ce7fb
Firewall Changes
2022-09-22 17:04:18 -04:00
Mike Reeves
75b058c37f
Firewall Changes
2022-09-22 17:03:03 -04:00
Mike Reeves
f9c77900ae
Firewall Changes
2022-09-22 16:54:57 -04:00
Mike Reeves
81f79c3a02
Firewall Changes
2022-09-22 16:33:08 -04:00
Josh Patterson
3100efc954
fix syntax
2022-09-22 16:03:12 -04:00
Mike Reeves
4eebd855ac
Firewall Changes
2022-09-22 15:47:16 -04:00
m0duspwnens
abee5afd7b
adjust standalone firewall assigned_hostgroups
2022-09-22 15:40:52 -04:00
m0duspwnens
06d3681cec
2.4/firewall
2022-09-22 13:39:10 -04:00
weslambert
49dace66de
Merge pull request #8796 from Security-Onion-Solutions/fix/elasticsearch_fleet_component_template_syntax
...
Fix syntax for Fleet component templates
2022-09-22 11:14:16 -04:00
Wes
0fd5fee868
Fix syntax for Fleet component templates
2022-09-22 15:07:43 +00:00
m0duspwnens
c77fcc74c1
merge in 2.4./firewall changes
2022-09-22 10:55:39 -04:00
m0duspwnens
2995ae32bd
2.4 fw changes
2022-09-22 10:49:26 -04:00
weslambert
e35c77be62
Merge pull request #8785 from Security-Onion-Solutions/fix/elasticsearch_component_templates_fleet_main
...
Add additional component templates for Fleet and fix references for Elastic Agent index templates in defaults.yaml
2022-09-20 17:02:02 -04:00
Wes
46dd4c2749
Rename component mappings and references for Security Onion
2022-09-20 20:33:06 +00:00
Josh Patterson
f0ddfecd42
Merge pull request #8784 from Security-Onion-Solutions/2.4/zeek
...
2.4/zeek
2022-09-20 16:28:40 -04:00
Wes
7f2c5bc757
Add component templates for Fleet
2022-09-20 20:27:26 +00:00
m0duspwnens
e1ea3c2031
soc for zeek
2022-09-20 16:22:54 -04:00
Mike Reeves
85339d7cb1
Add helpLinks to everything
2022-09-20 15:43:34 -04:00
Doug Burks
8a537204d6
Merge pull request #8783 from Security-Onion-Solutions/2.4/fix-docs-links
...
fix docs links
2022-09-20 19:34:01 +00:00
m0duspwnens
1685e0e6db
few more
2022-09-20 15:25:50 -04:00
Doug Burks
0137004344
Fix releaseNotesUrl in defaults.yaml
2022-09-20 15:16:53 -04:00
Doug Burks
530c497800
Update motd.md
2022-09-20 15:16:04 -04:00
Doug Burks
0eafed32a4
Update docs links in README.md
2022-09-20 15:13:14 -04:00
Mike Reeves
097c05b114
Cleanup on aisle 4
2022-09-20 13:49:26 -04:00
Mike Reeves
0ade4d7847
Adjust portgroup yaml
2022-09-20 13:45:29 -04:00
Mike Reeves
b622940f3f
Remvoe NTP from setup
2022-09-20 13:32:41 -04:00
Mike Reeves
555bd678fb
Change Firewall Pillar Structure
2022-09-20 13:28:32 -04:00
Mike Reeves
27a9edbef7
Change Firewall Pillar Structure
2022-09-20 13:20:16 -04:00
m0duspwnens
75aa121b2d
fix some things
2022-09-20 13:19:15 -04:00
Doug Burks
bc57a74ac8
Merge pull request #8782 from Security-Onion-Solutions/dougburks-patch-1
...
change version to 2.4.0
2022-09-20 16:52:39 +00:00
Doug Burks
aadce055d1
change version to 2.4.0
2022-09-20 12:49:14 -04:00
Mike Reeves
678d5c5c9c
Replace so-firewall
2022-09-20 11:22:20 -04:00
m0duspwnens
29285b8fb1
fix conflixt in zeek/init.sls
2022-09-20 11:12:44 -04:00
m0duspwnens
d1ee3a7d04
zeek 2.4
2022-09-20 11:11:29 -04:00
Mike Reeves
9fffe1b5fa
Replace so-firewall
2022-09-20 11:11:19 -04:00
Doug Burks
8c88285365
Merge pull request #8780 from Security-Onion-Solutions/2.4/sysmon-fix-bryant
...
2.4/sysmon fix bryant
2022-09-20 14:32:35 +00:00
Doug Burks
df18f8f886
Merge pull request #8779 from Security-Onion-Solutions/2.4/dev
...
2.4/dev
2022-09-20 13:32:54 +00:00
Josh Brower
0815b607e6
Merge pull request #8778 from Security-Onion-Solutions/2.4/elastic-fleet
...
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-20 08:29:47 -04:00
Josh Brower
120fdef173
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-20 08:27:47 -04:00
Josh Brower
da8d09713f
Merge pull request #8776 from Security-Onion-Solutions/2.4/elastic-fleet
...
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-20 06:20:51 -04:00
Josh Brower
3eb4adc5c3
Hunt Query - Elastic Agent Live Osquery Logs
2022-09-19 20:12:47 -04:00
Mike Reeves
512c044d80
Thresholding
2022-09-19 16:53:51 -04:00
weslambert
d4fb78fe3b
Merge pull request #8775 from Security-Onion-Solutions/fix/elasticsearch_elastic_agent_index_templates_load
...
Update so-elasticsearch-templates-load to allow for proper loading of differently formatted Elastic Agent index templates
2022-09-19 16:44:21 -04:00
weslambert
509c32482f
Update so-elasticsearch-templates-load to allow for proper loading of differently formatted Elastic Agent index templates
2022-09-19 16:39:49 -04:00
Mike Reeves
a1aae627a2
Merge pull request #8771 from Security-Onion-Solutions/funstuff
...
Add NTP and NGINX
2022-09-19 16:33:05 -04:00
Mike Reeves
e72eae2e8a
NGINX fun
2022-09-19 16:23:46 -04:00
Mike Reeves
fad0e0a145
NGINX fun
2022-09-19 16:14:37 -04:00
Mike Reeves
cb2e46f275
NGINX fun
2022-09-19 16:11:49 -04:00
Josh Brower
b38804840d
Merge pull request #8772 from Security-Onion-Solutions/2.4/grafana-ids
...
Grafana SOC Redirect
2022-09-19 16:02:41 -04:00
Josh Brower
80919827c6
Fixup index patterns
2022-09-19 15:55:23 -04:00
Josh Patterson
0367365225
Merge pull request #8773 from Security-Onion-Solutions/fix/soc2.4
...
fix some soc defaults
2022-09-19 15:54:25 -04:00
m0duspwnens
30afc88322
fix some soc defaults
2022-09-19 15:51:29 -04:00
Josh Brower
ea7979cfdd
Add Elastic Agent datastreams to SOC index
2022-09-19 15:33:15 -04:00
m0duspwnens
79785fc053
zeek jinja
2022-09-19 15:26:32 -04:00
Mike Reeves
22e8c7ef3e
Add NTP
2022-09-19 15:10:11 -04:00
Mike Reeves
2abfcdc042
Add NTP
2022-09-19 14:48:40 -04:00
doug
fdffac83e1
sysmon fix by bryant
2022-09-19 14:47:45 -04:00
Mike Reeves
17cbe38c25
Add NTP
2022-09-19 14:32:29 -04:00
Mike Reeves
74ccf333e0
Add NTP
2022-09-19 14:30:23 -04:00
Mike Reeves
44be7b4969
Add NTP
2022-09-19 14:26:16 -04:00
Mike Reeves
03ea714dc1
Add NTP
2022-09-19 14:06:46 -04:00
Mike Reeves
f7e614f358
Add NTP
2022-09-19 14:06:30 -04:00
Josh Brower
d28a9ecec2
Set Dashboard UUID
2022-09-19 13:32:04 -04:00
weslambert
4c2ac9dd93
Merge pull request #8770 from Security-Onion-Solutions/fix/elasticsearch_cluster_settings
...
Re-establish Elasticsearch cluster (search) settings
2022-09-19 12:10:55 -04:00
Wes
9095bc2205
Re-establish Elasticsearch cluster (search) settings
2022-09-19 15:41:54 +00:00
Mike Reeves
0a885221e8
Merge pull request #8769 from Security-Onion-Solutions/funstuff
...
Firewall and Sensoroni Fix
2022-09-19 11:05:46 -04:00
Mike Reeves
32034078fa
Fix sensoroni Agent
2022-09-19 10:48:36 -04:00
Mike Reeves
aa8ce074f7
Fix sensoroni Agent
2022-09-19 10:43:05 -04:00
Mike Reeves
04a0be8247
Merge branch '2.4/dev' into funstuff
2022-09-19 10:41:53 -04:00
Mike Reeves
e3e6e7b4e8
Fix sensoroni Agent
2022-09-19 10:41:01 -04:00
Jason Ertel
21f8b3b61c
Merge pull request #8768 from Security-Onion-Solutions/config
...
refactor sostatus telegraf input script
2022-09-19 10:35:22 -04:00
Jason Ertel
ae6fbab45d
refactor sostatus telegraf input script
2022-09-19 10:27:20 -04:00
Mike Reeves
f4508aa534
Fix sensoroni Agent
2022-09-19 10:22:32 -04:00
Mike Reeves
61f3479d92
Merge branch '2.4/dev' into funstuff
2022-09-19 09:40:27 -04:00
Mike Reeves
9bdb364122
Firewall Fun
2022-09-19 09:39:42 -04:00
Jason Ertel
f2b09c84d4
Merge pull request #8767 from Security-Onion-Solutions/config
...
Config
2022-09-19 09:18:10 -04:00
Jason Ertel
7d965b5cda
Ensure so-status does not get jinjafied
2022-09-19 09:17:06 -04:00
Jason Ertel
b4add5ebb3
Merge pull request #8766 from Security-Onion-Solutions/config
...
complete rewrite of so-status
2022-09-19 07:40:51 -04:00
Mike Reeves
d7585e1b3d
Firewall Fun
2022-09-17 10:03:18 -04:00
Mike Reeves
4a68a5e054
Firewall Fun
2022-09-17 09:57:43 -04:00
Mike Reeves
98ae6149dc
Firewall Fun
2022-09-17 09:54:20 -04:00
Mike Reeves
e717579113
Firewall Fun
2022-09-17 09:51:26 -04:00
Mike Reeves
8a26b3fa04
Firewall Fun
2022-09-17 09:47:15 -04:00
Mike Reeves
724d5d952a
Firewall Fun
2022-09-17 09:46:07 -04:00
Mike Reeves
b6a1040090
Firewall Fun
2022-09-17 09:42:35 -04:00
Mike Reeves
f3056c7057
Firewall Fun
2022-09-17 09:39:49 -04:00
Mike Reeves
4b1031efa4
Firewall Fun
2022-09-17 09:34:35 -04:00
Jason Ertel
9542a5ada2
complete rewrite of so-status
2022-09-16 17:46:52 -04:00
weslambert
0a8aae8180
Merge pull request #8757 from Security-Onion-Solutions/fix/elastic_agent_templates_managed_by_securityonion
...
Change managed_by value from 'fleet' to 'security_onion' for Elastic Agent templates in defaults.yaml
2022-09-16 17:20:03 -04:00
Wes
12e940f809
Change managed_by value from 'fleet' to 'security_onion' for Elastic Agent templates in defaults.yaml
2022-09-16 20:55:49 +00:00
Mike Reeves
d02c6808a4
Firewall Fun
2022-09-16 13:44:54 -04:00
Mike Reeves
1c9069690f
Firewall Fun
2022-09-16 13:38:07 -04:00
Mike Reeves
0eb6388ea3
Firewall Fun
2022-09-16 13:34:11 -04:00
Mike Reeves
6649ffd8b5
Firewall Fun
2022-09-16 13:33:26 -04:00
Mike Reeves
70c95c7c7b
Firewall Fun
2022-09-16 13:31:23 -04:00
Mike Reeves
bc1921bd0e
Firewall Fun
2022-09-16 13:30:07 -04:00
Josh Brower
eba82553a1
Merge pull request #8755 from Security-Onion-Solutions/2.4/tls
...
Change ssl_ecdh_curve
2022-09-16 13:28:35 -04:00
Mike Reeves
384478836a
Firewall Fun
2022-09-16 13:02:11 -04:00
Mike Reeves
f14a8f3d01
Firewall Fun
2022-09-16 12:55:56 -04:00
Mike Reeves
943b98f091
IDS Tools rule management
2022-09-16 11:16:05 -04:00
Mike Reeves
f9e9e4ce1d
IDS Tools rule management
2022-09-16 11:14:09 -04:00
Mike Reeves
ae5eea6e3a
IDS Tools rule management
2022-09-16 11:12:03 -04:00
Mike Reeves
5e151a9fed
Fix minion pillar for remote sensors
2022-09-16 10:43:36 -04:00
Mike Reeves
958d2494a8
Zeek Test
2022-09-16 10:27:42 -04:00
Mike Reeves
2a51ecb1ac
Zeek Test
2022-09-16 09:10:09 -04:00
Josh Brower
d5debd9b6b
Change ssl_ecdh_curve
2022-09-16 09:06:09 -04:00
Mike Reeves
f02db7a815
Zeek Test
2022-09-16 09:05:16 -04:00
Mike Reeves
58ab91ea84
Add BPF
2022-09-16 08:50:17 -04:00
Mike Reeves
9a6fe3e8de
Add BPF
2022-09-16 08:36:44 -04:00
Mike Reeves
2c0d90bea4
Make test ping retry
2022-09-15 17:07:02 -04:00
Mike Reeves
c50a1608af
Make test ping retry
2022-09-15 17:01:53 -04:00
weslambert
6212a288e4
Merge pull request #8752 from Security-Onion-Solutions/fix/logstash_remove_osquery_livequery_output_configuration
...
Remove Osquery live query Logstash output configuration
2022-09-15 15:53:49 -04:00
Mike Reeves
e6c0c2ce19
Modify Steno Config
2022-09-15 15:46:28 -04:00
Wes
1a90eeb1b1
Remove Osquery live query Logstash output configuration
2022-09-15 19:45:28 +00:00
m0duspwnens
5a9b3f6821
fix diskfreepercantage
2022-09-15 15:39:31 -04:00
m0duspwnens
62f5ee04a4
fix source for steno config
2022-09-15 15:13:40 -04:00
m0duspwnens
52b58ad6ae
jinja for steno/pcap
2022-09-15 15:12:40 -04:00
Mike Reeves
9a75d939b4
Modify Steno Config
2022-09-15 13:55:39 -04:00
Mike Reeves
3286d55ef2
Modify Steno Config
2022-09-15 13:46:14 -04:00
Mike Reeves
c49c7348ff
Merge pull request #8751 from Security-Onion-Solutions/funstuff
...
Funstuff
2022-09-15 13:15:51 -04:00
Mike Reeves
7d6e847f86
Fix Zeek PIllar
2022-09-15 13:11:03 -04:00
Mike Reeves
73d45bd9fc
Update defaults for Steno
2022-09-15 12:56:02 -04:00
Mike Reeves
383714ec06
Fix pcap error
2022-09-15 12:38:55 -04:00
Mike Reeves
4357f013f0
Merge pull request #8748 from Security-Onion-Solutions/funstuff
...
Fix setup error
2022-09-15 11:12:21 -04:00
Mike Reeves
2e4f122e57
Fix setup error
2022-09-15 11:10:33 -04:00
Mike Reeves
b93c38759b
Merge pull request #8747 from Security-Onion-Solutions/funstuff
...
Fix setup error
2022-09-15 10:58:59 -04:00
Mike Reeves
8e99e02787
Fix setup error
2022-09-15 10:57:52 -04:00
Mike Reeves
1c00344327
Merge pull request #8746 from Security-Onion-Solutions/funstuff
...
Fix for Suricata
2022-09-15 10:53:22 -04:00
Mike Reeves
0351ef4ff5
Fix Suricata analyzers list
2022-09-15 10:48:08 -04:00
m0duspwnens
845d2e33bd
remove dupe afpacket
2022-09-15 10:44:39 -04:00
m0duspwnens
4cb955fe8d
jinja for the suricata outputs
2022-09-15 10:35:59 -04:00
Josh Brower
99f54acef1
Merge pull request #8742 from Security-Onion-Solutions/2.4/elastic-fleet
...
2.4/elastic fleet
2022-09-15 07:16:37 -04:00
Josh Brower
bdfde669f3
remove outdated scripts
2022-09-14 18:38:08 -04:00
Josh Brower
798b39ec09
elastic-fleet so-status & restart scripts
2022-09-14 18:36:26 -04:00
Mike Reeves
8528645c2c
Update suricata_config.map.jinja
2022-09-14 15:02:55 -04:00
Mike Reeves
f8c1571a91
Update suricata_config.map.jinja
2022-09-14 14:43:04 -04:00
Mike Reeves
30a469ea63
Update afpacket.map.jinja
2022-09-14 14:36:13 -04:00
Josh Brower
0c1f9eaa37
Merge pull request #8739 from Security-Onion-Solutions/2.4/elastic-fleet
...
EA Certs & image
2022-09-14 14:20:17 -04:00
Mike Reeves
90ed4fd4cb
Fix Suricata
2022-09-14 14:18:10 -04:00
Josh Brower
1c671b47d7
Run container as elastic-fleet user
2022-09-14 14:17:54 -04:00
Mike Reeves
ee59822097
Fix Suricata
2022-09-14 14:15:50 -04:00
Mike Reeves
74a8bd17ea
Fix Suricata
2022-09-14 13:56:17 -04:00
Mike Reeves
c60afba450
Fix core count
2022-09-14 12:30:22 -04:00
Mike Reeves
8049f9b9e4
Fix so-minion error for setup
2022-09-14 12:22:10 -04:00
Mike Reeves
8a5a58c647
Fix so-minion error for setup
2022-09-14 12:21:21 -04:00
Mike Reeves
547abb0fe1
Remove learn
2022-09-14 12:12:33 -04:00
Mike Reeves
be4c15877a
Improve pcap defaults
2022-09-14 11:11:21 -04:00
Mike Reeves
0a40bfcb88
Change how pcap is written to the minion file
2022-09-14 11:00:22 -04:00
Josh Brower
b7b92c73a3
add so-elastic-agent to container list
2022-09-14 11:00:16 -04:00
Josh Brower
334a0d7b1c
Start using so-elastic-agent container
2022-09-14 10:33:27 -04:00
weslambert
39c7c8cf80
Merge pull request #8738 from Security-Onion-Solutions/fix/remove_old_pipeline_config
...
Remove old Logstash pipeline configuration - initial cleanup
2022-09-14 10:30:37 -04:00
Wes
926a1e0189
Remove Snort output configuration
2022-09-14 14:22:00 +00:00
Wes
ce3ea456b6
Remove flow output configuration
2022-09-14 14:21:21 +00:00
Wes
d1a8b88eb9
Remove postprocess configuration
2022-09-14 14:20:24 +00:00
Wes
e3cd8a9c6a
Remove main pipeline configuration
2022-09-14 14:20:08 +00:00
Wes
43f89adbd4
Remove preprocess configuration
2022-09-14 14:19:07 +00:00
Mike Reeves
a4dc63f3a4
Change how zeek and suri are populated in the minion file
2022-09-14 09:53:57 -04:00
Josh Brower
6945596eee
Tweak elastic agent ssl gen
2022-09-14 08:10:42 -04:00
Josh Brower
bf14612258
Change out Elastic Fleet certs
2022-09-13 15:58:53 -04:00
Jason Ertel
0d32cc38d6
Merge pull request #8733 from Security-Onion-Solutions/config
...
Always use local docs
2022-09-13 14:40:10 -04:00
Mike Reeves
d36f2f642f
Merge pull request #8734 from Security-Onion-Solutions/funstuff
...
Updates for grafana
2022-09-13 14:39:49 -04:00
Jason Ertel
deb19d24b8
Always use local docs
2022-09-13 14:24:35 -04:00
Jason Ertel
d1eb7ef849
Always use local docs
2022-09-13 14:23:50 -04:00
Mike Reeves
064b64f68a
Add Grafana annotation
2022-09-13 14:00:04 -04:00
Mike Reeves
de047cea8e
Add Grafana annotation
2022-09-13 13:56:37 -04:00
Jason Ertel
810d89eb6c
Merge pull request #8731 from Security-Onion-Solutions/config
...
Remove comments to avoid confusing config viewers within SOC
2022-09-13 12:16:38 -04:00
Mike Reeves
8e8223b767
Merge pull request #8732 from Security-Onion-Solutions/funstuff
...
Update watermark settings
2022-09-13 12:16:17 -04:00
Mike Reeves
b38f0fa996
Update watermark settings
2022-09-13 12:13:45 -04:00
Jason Ertel
d12ff79af0
Remove comments to avoid confusing config viewers within SOC
2022-09-13 12:08:19 -04:00
Jason Ertel
8c5cba58aa
Merge pull request #8730 from Security-Onion-Solutions/config
...
Config
2022-09-13 11:52:05 -04:00
Mike Reeves
8144588534
Merge pull request #8729 from Security-Onion-Solutions/funstuff
...
Fix advanced view
2022-09-13 11:50:43 -04:00
Jason Ertel
d2fc712400
Initial SOC annotations
2022-09-13 11:49:19 -04:00
Jason Ertel
21c7f940d7
Update copyrights
2022-09-13 11:48:25 -04:00
Mike Reeves
df1a64b5e0
Modify more defaults
2022-09-13 11:45:59 -04:00
Mike Reeves
a32ff6f403
Modify Suricata defaults
2022-09-13 11:29:31 -04:00
Mike Reeves
bc2aced20d
Merge pull request #8726 from Security-Onion-Solutions/funstuff
...
Fix Typeo
2022-09-13 07:22:06 -04:00
Josh Brower
0c7ee56ee3
Merge pull request #8725 from Security-Onion-Solutions/2.4/elastic-fleet
...
Fix elastic agent gen script
2022-09-13 07:18:47 -04:00
Mike Reeves
74d991da45
Fix Typeo
2022-09-13 07:17:03 -04:00
Josh Brower
4a28841a7c
Fix elastic agent gen script
2022-09-13 06:38:05 -04:00
Mike Reeves
85e74485e7
Merge pull request #8723 from Security-Onion-Solutions/funstuff
...
Fix Dev
2022-09-12 17:43:34 -04:00
Mike Reeves
ec187e9d85
Pull in dev
2022-09-12 17:35:42 -04:00
Mike Reeves
6e052a3063
Pull in dev
2022-09-12 17:17:14 -04:00
Mike Reeves
440861998c
Merge pull request #8722 from Security-Onion-Solutions/funstuff
...
Add More Logging
2022-09-12 16:50:28 -04:00
Mike Reeves
a01fadd067
Add more logging to setup process
2022-09-12 15:56:08 -04:00
Mike Reeves
7ec66d1cd1
Add more logging to setup process
2022-09-12 15:46:33 -04:00
Mike Reeves
ea7c8e1fd9
Add more logging to setup process
2022-09-12 15:43:18 -04:00
weslambert
94f47a847d
Merge pull request #8721 from Security-Onion-Solutions/fix/elasticsearch_elastic_agent_template_defaults
...
Add back Elastic Agent default templates
2022-09-12 15:23:23 -04:00
Mike Reeves
17239ac6e4
Add more logging to setup process
2022-09-12 15:18:09 -04:00
weslambert
030f4d228a
Add back Elastic Agent default templates
2022-09-12 15:10:24 -04:00
Mike Reeves
f555846544
Add more logging to setup process
2022-09-12 15:06:29 -04:00
Mike Reeves
a168aa8b81
Add more logging to setup process
2022-09-12 14:53:34 -04:00
Mike Reeves
181e94a69d
Add more logging to setup process
2022-09-12 14:35:32 -04:00
Mike Reeves
2de2b0eb23
Add more logging to setup process
2022-09-12 14:31:10 -04:00
Mike Reeves
07263e03cb
Add more logging to setup process
2022-09-12 14:30:28 -04:00
Mike Reeves
c8a9fc2f26
Add more logging to setup process
2022-09-12 14:27:35 -04:00
Mike Reeves
9ca2e6e871
Add more logging to setup process
2022-09-12 14:20:59 -04:00
Josh Brower
905068f7bf
Merge pull request #8720 from Security-Onion-Solutions/2.4/elastic-fleet
...
Add so-elastic-agent-builder
2022-09-12 13:40:28 -04:00
Mike Reeves
2254512a2a
Add more logging to setup process
2022-09-12 12:48:02 -04:00
Josh Brower
0df7d0249a
Add so-elastic-agent-builder
2022-09-12 12:22:35 -04:00
Josh Brower
3708c9b4d9
Merge pull request #8715 from Security-Onion-Solutions/2.4/elastic-fleet
...
Add links to tools menu
2022-09-12 09:34:17 -04:00
Josh Brower
9f99939bda
Add links to tools menu
2022-09-12 09:28:10 -04:00
Josh Brower
e700a43a40
Merge pull request #8714 from Security-Onion-Solutions/2.4/elastic-fleet
...
2.4/elastic fleet
2022-09-12 08:34:28 -04:00
Mike Reeves
8b9fdef25c
Merge pull request #8708 from Security-Onion-Solutions/funstuff
2022-09-11 07:35:35 -04:00
Mike Reeves
3de4e56db9
Fix ES merge
2022-09-10 19:25:01 -04:00
Mike Reeves
a3d9b1d83b
Merge pull request #8707 from Security-Onion-Solutions/funstuff
...
Funstuff
2022-09-09 16:32:32 -04:00
Mike Reeves
f2ff8ca4e2
Create advanced files
2022-09-09 16:29:50 -04:00
Mike Reeves
9df2aaacb0
Create advanced files
2022-09-09 16:26:59 -04:00
Mike Reeves
8a7b194f2b
Create advanced files
2022-09-09 16:24:41 -04:00
Mike Reeves
57c303b9ca
Create advanced files
2022-09-09 16:23:32 -04:00
Mike Reeves
f8c6b82ed9
Merge pull request #8706 from Security-Onion-Solutions/funstuff
...
Fix yaml for idh,es,kib,esalert
2022-09-09 15:57:04 -04:00
Mike Reeves
037d5d1c46
Fix yaml for idh,es,kib,esalert
2022-09-09 15:55:51 -04:00
Mike Reeves
aa17837936
Merge pull request #8705 from Security-Onion-Solutions/funstuff
...
Fix yaml for idh,es,kib,esalert
2022-09-09 15:47:59 -04:00
Mike Reeves
16f2059f17
Fix yaml for idh,es,kib,esalert
2022-09-09 15:46:48 -04:00
Mike Reeves
e2eaefab6e
Fix yaml for idh,es,kib,esalert
2022-09-09 15:45:13 -04:00
Josh Patterson
c6421275f7
Merge pull request #8704 from Security-Onion-Solutions/influx/defaults
...
remove jinja from influxdb defaults.yaml
2022-09-09 15:42:46 -04:00
m0duspwnens
9a08decadb
remove jinja from influxdb defaults.yaml
2022-09-09 15:41:20 -04:00
Mike Reeves
cc08e5a42c
Merge pull request #8703 from Security-Onion-Solutions/funstuff
...
Fix yaml for idh,es,kib,esalert
2022-09-09 15:38:07 -04:00
Mike Reeves
1f3b170213
Fix yaml for idh,es,kib,esalert
2022-09-09 15:36:57 -04:00
Mike Reeves
74ef6c0ed0
Fix yaml for idh,es,kib,esalert
2022-09-09 15:30:28 -04:00
Josh Brower
09a1032f77
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/elastic-fleet
2022-09-09 15:08:25 -04:00
Josh Brower
921d644a0b
Elastic Fleet wrapper
2022-09-09 15:05:31 -04:00
Josh Patterson
54f7cefa28
Merge pull request #8702 from Security-Onion-Solutions/fix/soc2.4
...
add salt bind for soc
2022-09-09 14:45:31 -04:00
m0duspwnens
b5fb7596b0
add salt bind for soc
2022-09-09 14:44:41 -04:00
Josh Patterson
7dd65909f2
Merge pull request #8701 from Security-Onion-Solutions/fix/soc2.4
...
add saltPipe
2022-09-09 14:40:08 -04:00
m0duspwnens
0f2e9764ab
add saltPipe
2022-09-09 14:39:20 -04:00
Josh Patterson
deaecad8fd
Merge pull request #8700 from Security-Onion-Solutions/fix/soc2.4
...
Fix/soc2.4
2022-09-09 14:32:41 -04:00
m0duspwnens
5ccc103083
fix soc dashboards and things
2022-09-09 14:31:04 -04:00
m0duspwnens
5bb001281b
soc defaults changes - client child of server
2022-09-08 15:57:18 -04:00
Mike Reeves
ce59a8a225
Merge pull request #8697 from Security-Onion-Solutions/funstuff
...
move endgamehost
2022-09-08 14:12:43 -04:00
Mike Reeves
8c12b26847
touch the soc file
2022-09-08 14:08:24 -04:00
Mike Reeves
9c9509594a
move endgamehost
2022-09-08 13:55:35 -04:00
Jason Ertel
cfb3893c2b
Merge pull request #8694 from Security-Onion-Solutions/salt-relay
...
Salt relay
2022-09-08 10:31:28 -04:00
Jason Ertel
b7bbe7d69f
Add copyright notice
2022-09-08 10:27:56 -04:00
Jason Ertel
193c3fc4cd
Add salt relay
2022-09-08 10:26:39 -04:00
Mike Reeves
6ab9cc6d53
Merge pull request #8693 from Security-Onion-Solutions/funstuff
...
Add an older version of so-status
2022-09-08 09:04:41 -04:00
Mike Reeves
3785b97d95
so-status
2022-09-08 08:48:49 -04:00
weslambert
c25b981c50
Merge pull request #8688 from Security-Onion-Solutions/elastic_agent_security_subfield_additions
...
Elastic Agent .security subfield additions
2022-09-08 08:05:16 -04:00
Wes
86d60e444d
Add Elastic Agent index/template configuration to defaults file
2022-09-08 00:20:22 +00:00
Josh Brower
d9ae646ef2
Merge pull request #8682 from Security-Onion-Solutions/2.4/elastic-fleet
...
2.4/elastic fleet
2022-09-07 18:53:35 -04:00
Wes
b39a5061ca
Load Elastic Agent component templates (managed by Security Onion)
2022-09-07 21:26:43 +00:00
Wes
eeffded248
Remove duplicate security subfield configuration from component templates
2022-09-07 21:23:04 +00:00
Josh Brower
f00aafdfb2
Elastic Agent - move gen installers
2022-09-07 16:57:11 -04:00
Josh Brower
e8af315e40
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/elastic-fleet
2022-09-07 16:32:31 -04:00
Jason Ertel
df6ba5cbe9
initial salt relay script for comms with soc
2022-09-07 16:19:16 -04:00
Josh Brower
e3e0e4c6ed
Merge pull request #8681 from Security-Onion-Solutions/playbookfix
...
Update so-playbook-reset
2022-09-07 16:01:37 -04:00
Josh Brower
39ed582a72
Update so-playbook-reset
2022-09-07 15:59:54 -04:00
Mike Reeves
40131daeed
Merge pull request #8680 from Security-Onion-Solutions/funstuff
...
Funstuff
2022-09-07 15:46:48 -04:00
Mike Reeves
5b65fdcc1c
Remove crossthestreams
2022-09-07 15:42:22 -04:00
Mike Reeves
6d1bc78f7b
Remove crossthestreams
2022-09-07 15:41:21 -04:00
Mike Reeves
6adcb4c968
Remove crossthestreams
2022-09-07 15:38:55 -04:00
Wes
3c50072690
Add Elastic Agent component templates
2022-09-07 18:51:57 +00:00
Josh Brower
ce688cfb91
Elastic Agent setup changes
2022-09-07 10:23:26 -04:00
Mike Reeves
f7f5d414c4
Merge pull request #8677 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2022-09-07 09:56:26 -04:00
Mike Reeves
2fb1f14d09
Update VERSION
2022-09-07 09:55:41 -04:00
Josh Patterson
de456a402c
Merge pull request #8676 from Security-Onion-Solutions/index_settings_False
...
Update so-functions
2022-09-07 09:40:12 -04:00
Josh Patterson
dfd505dfaa
Update so-functions
2022-09-07 09:38:22 -04:00
Mike Reeves
b76bf0a6e0
Merge pull request #8675 from Security-Onion-Solutions/gitfoo
...
Move In Day
2022-09-07 09:21:03 -04:00
Mike Reeves
c9dd2beaaa
Move In Day
2022-09-07 09:15:58 -04:00
Mike Reeves
2bd9dd80e2
Move In Day
2022-09-07 09:06:25 -04:00
Josh Patterson
dcb7b49dbe
Merge pull request #8451 from Security-Onion-Solutions/issue/8441_3
...
manage salt-minion start delay with systemd drop-in file -
2022-08-02 16:39:45 -04:00
m0duspwnens
a965301b2e
manage salt-minion start delay with systemd drop-in file - https://github.com/Security-Onion-Solutions/securityonion/issues/8441
2022-08-02 16:37:27 -04:00
Mike Reeves
fbcbfaf7c3
Merge pull request #8310 from Security-Onion-Solutions/dev
...
2.3.140
2022-07-18 11:23:54 -04:00
Mike Reeves
497110d6cd
Merge pull request #8320 from Security-Onion-Solutions/2.3.140-2
...
2.3.140
2022-07-18 10:57:53 -04:00
Mike Reeves
3711eb52b8
2.3.140
2022-07-18 10:54:50 -04:00
weslambert
8099b1688b
Merge pull request #8319 from Security-Onion-Solutions/fix/elasticsearch_query_missing_query_path
...
Fix missing query path for so-elasticsearch-query
2022-07-18 09:47:16 -04:00
weslambert
2914007393
Add forward slash to fix issue with missing query path
2022-07-18 09:07:34 -04:00
weslambert
f5e10430ed
Add forward slash to fix issue with missing query path
2022-07-18 09:07:13 -04:00
Mike Reeves
b5a78d4577
Merge pull request #8309 from Security-Onion-Solutions/2.3.140
...
2.3.140
2022-07-15 13:36:31 -04:00
Mike Reeves
0a14dad849
Update VERIFY_ISO.md
2022-07-15 13:31:51 -04:00
Mike Reeves
3430df6a20
2.3.140
2022-07-15 13:26:25 -04:00
Mike Reeves
881915f871
Merge pull request #8306 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update defaults.yaml
2022-07-14 16:20:29 -04:00
Mike Reeves
cf8c6a6e94
Update defaults.yaml
2022-07-14 15:17:27 -04:00
weslambert
52ebbf8ff3
Merge pull request #8304 from Security-Onion-Solutions/fix/kibana_space_defaults_web_response_url
...
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:08:02 -04:00
weslambert
2443e8b97e
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:04:56 -04:00
weslambert
4241eb4b29
Merge pull request #8298 from Security-Onion-Solutions/fix/kibana_space_defaults_shebang
...
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:50:21 -04:00
weslambert
0fd4f34b5b
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:48:39 -04:00
Josh Patterson
37df49d4f3
Merge pull request #8296 from Security-Onion-Solutions/elastalert_esversion_check
...
use onlyif requisite instead
2022-07-13 15:22:40 -04:00
m0duspwnens
7d7cf42d9a
use onlyif requisite instead
2022-07-13 15:21:34 -04:00
Doug Burks
de0a7d3bcd
Merge pull request #8293 from Security-Onion-Solutions/dougburks-patch-1
...
change hyperlink for Elastic 8 issues
2022-07-13 12:41:50 -04:00
Doug Burks
c67a58a5b1
change hyperlink for Elastic 8 issues
2022-07-13 12:40:03 -04:00
Josh Patterson
e79ca4bb9b
Merge pull request #8291 from Security-Onion-Solutions/elastalert_esversion_check
...
do not start elastalert if elasticsearch is not v8
2022-07-13 11:24:12 -04:00
m0duspwnens
086cf3996d
do not start elastalert if elasticsearch is not v8
2022-07-13 11:21:27 -04:00
Doug Burks
7ae5d49a4a
Merge pull request #8290 from Security-Onion-Solutions/dougburks-patch-1
...
increment version to 2.3.140
2022-07-13 09:33:37 -04:00
Doug Burks
34d3c6a882
increment version to 2.3.140
2022-07-13 09:32:28 -04:00
weslambert
4a5664db7b
Merge pull request #8289 from Security-Onion-Solutions/fix/soup_unsupported_indices_check
...
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:15:22 -04:00
weslambert
513c7ae56c
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:13:28 -04:00
weslambert
fa894cf83b
Merge pull request #8288 from Security-Onion-Solutions/fix/soup_elastalert_indices_deletion_check
...
Ensure Elastalert indices are deleted before continuing with SOUP
2022-07-13 08:44:04 -04:00
weslambert
8e92060c29
Ensure Elastalert indices are deleted before continuing with SOUP -- if they are not, generate a failure condition
2022-07-13 08:38:55 -04:00
weslambert
d7eb8b9bcb
Merge pull request #8281 from Security-Onion-Solutions/fix/soup_elasticsearch8_index_compatibility
...
SOUP - Check for indices created by Elasticsearch 6
2022-07-12 16:20:47 -04:00
weslambert
d0a0ca8458
Update exit code for ES checks
2022-07-12 16:15:44 -04:00
Josh Patterson
57b79421d8
Merge pull request #8280 from Security-Onion-Solutions/fix_filebeat
...
move port bindings back under port bindings
2022-07-12 16:12:49 -04:00
weslambert
4502182b53
Typo - Ensure Elasticsearch version 6 indices are checked
2022-07-12 15:35:46 -04:00
weslambert
0fc6f7b022
Add check for Elasticsearch 6 indices
2022-07-12 15:34:24 -04:00
m0duspwnens
ec451c19f8
move port bindings back under port bindings
2022-07-12 15:17:25 -04:00
weslambert
e9a22d0aff
Merge pull request #8275 from Security-Onion-Solutions/fix/filebeat_es_output_additions
...
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
2022-07-11 19:03:07 -04:00
weslambert
11d3ed36b7
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
...
Add outputs for Elasticsearch and Kibana for Eval/Import Mode, since Logstash is not used in Eval Mode or Import Mode. Otherwise, logs from these inputs end up in a filebeat-prefixed index.
2022-07-11 17:22:09 -04:00
weslambert
d828bbfe47
Merge pull request #8273 from Security-Onion-Solutions/fix/kibana_space_defaults_cases
...
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:39:30 -04:00
weslambert
bd32394560
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:38:05 -04:00
weslambert
6f4f050a96
Merge pull request #8272 from Security-Onion-Solutions/fix/soup_kibana_space_defaults
...
Run so-kibana-space-defaults when upgrading to 2.3.140
2022-07-11 14:47:11 -04:00
weslambert
f77edaa5c9
Run so-kibana-space-defaults to re-establish the default enabled features since Fleet feature name changed
2022-07-11 14:41:23 -04:00
Jason Ertel
15124b6ad7
Merge pull request #8271 from Security-Onion-Solutions/kilo
...
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:47:28 -04:00
Jason Ertel
077053afbd
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:43:41 -04:00
weslambert
dd1d5b1a83
Merge pull request #8270 from Security-Onion-Solutions/fix/curator_actions_delete_kratos
...
Add delete and warm action for Kratos indices in applicable Curator delete/warm scripts
2022-07-11 11:39:43 -04:00
weslambert
e82b6fcdec
Typo - Change 'delete' to 'warm'
2022-07-11 11:34:53 -04:00
weslambert
8c8ac41b36
Add action for Kratos indices
2022-07-11 11:32:03 -04:00
weslambert
b611dda143
Add delete action for Kratos indices
2022-07-11 11:31:22 -04:00
weslambert
3f5b98d14d
Merge pull request #8269 from Security-Onion-Solutions/fix/curator_actions_kratos
...
Add Curator actions and adjust Curator close scripts to account for so-kibana and so-kratos indices
2022-07-11 11:21:20 -04:00
Wes Lambert
0b6219d95f
Adjust Curator close scripts to include Kibana and Kratos indices
2022-07-11 14:51:33 +00:00
Wes Lambert
2f729e24d9
Add Curator action files for Kratos indices
2022-07-11 14:34:10 +00:00
weslambert
992b6e14de
Merge pull request #8268 from Security-Onion-Solutions/fix/kibana_disable_fleetv2
...
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:09:12 -04:00
weslambert
09a1d8c549
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:06:24 -04:00
Jason Ertel
f28c6d590a
Merge pull request #8263 from Security-Onion-Solutions/kilo
...
Remove Jinja from yaml files before parsing
2022-07-08 20:32:22 -04:00
Jason Ertel
4f8bb6049b
Future proof the jinja check to ensure the script does not silently overwrite jinja templates
2022-07-08 17:30:00 -04:00
Jason Ertel
a8e6b26406
Remove Jinja from yaml files before parsing
2022-07-08 17:07:24 -04:00
weslambert
2903bdbc7e
Merge pull request #8260 from Security-Onion-Solutions/fix/kratos_dedicated_index_and_filestream_id_additions
...
Add dedicated index for Kratos and IDs for all filestream inputs
2022-07-08 12:04:40 -04:00
Wes Lambert
5c90fce3a1
Add Kratos Logstash output to search pipeline for Logstash
2022-07-08 15:58:00 +00:00
Wes Lambert
26698cfd07
Add Logstash output for dedicated Kratos index
2022-07-08 15:55:55 +00:00
Wes Lambert
764e8688b1
Modify Kratos input to use dedicated index and add filestream ID for all applicable inputs
2022-07-08 15:53:55 +00:00
Wes Lambert
b06c16f750
Add ingest node pipeline for Kratos
2022-07-08 15:53:00 +00:00
weslambert
42cfab4544
Merge pull request #8256 from Security-Onion-Solutions/fix/kibana_restart_after_role_sync
...
Restart Kibana in case it times out before being able to read role update
2022-07-07 17:44:47 -04:00
weslambert
4bbc901860
Restart Kibana in case it times out before being able to read in new role configuration
2022-07-07 17:19:02 -04:00
weslambert
a343f8ced0
Merge pull request #8255 from Security-Onion-Solutions/fix/so_kibana_user_role
...
Force so-user to sync roles to ensure so_kibana role change
2022-07-07 16:19:30 -04:00
weslambert
85be2f4f99
Force so-user to sync roles to ensure so_kibana role change from superuser to kibana_system
2022-07-07 15:55:44 -04:00
weslambert
8b3fa0c4c6
Merge pull request #8252 from Security-Onion-Solutions/feature/elastic_8_3_2
...
Update to Elastic 8.3.2
2022-07-07 11:14:14 -04:00
weslambert
ede845ce00
Update to Kibana 8.3.2
2022-07-07 11:05:44 -04:00
weslambert
42c96553c5
Update to Kibana 8.3.2
2022-07-07 11:04:43 -04:00
Mike Reeves
41d5cdd78c
Merge pull request #8246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2022-07-06 16:39:38 -04:00
Mike Reeves
c819d3a558
Update soup
2022-07-06 16:36:57 -04:00
Mike Reeves
c00d33632a
Update soup
2022-07-06 16:23:02 -04:00
Mike Reeves
a1ee793607
Merge pull request #8242 from Security-Onion-Solutions/fixsoup
...
Move soup order
2022-07-06 09:18:16 -04:00
Mike Reeves
1589107b97
Move soup order
2022-07-06 08:59:21 -04:00
Mike Reeves
31688ee898
Merge pull request #8238 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Make soup enforce versions
2022-07-05 16:56:14 -04:00
Mike Reeves
f1d188a46d
Update soup
2022-07-05 16:50:20 -04:00
Mike Reeves
5f0c3aa7ae
Update soup
2022-07-05 16:49:20 -04:00
weslambert
2b73cd1156
Merge pull request #8236 from Security-Onion-Solutions/fix/localfile_analyzer
...
Strip quotes and ensure file_path is typed as a list (localfile analyzer)
2022-07-05 16:28:56 -04:00
Mike Reeves
c6fac28804
Update soup
2022-07-05 16:26:44 -04:00
Jason Ertel
9d43b7ec89
Rollback string manipulation in favor of fixed unit tests
2022-07-05 16:21:27 -04:00
Jason Ertel
f6266b19cc
Fix unit test issues
2022-07-05 16:20:24 -04:00
Mike Reeves
df0a774ffd
Make soup enforce versions
2022-07-05 16:17:32 -04:00
weslambert
77ee30f31a
Merge pull request #8237 from Security-Onion-Solutions/feature/elastic_8_3_1
...
Bump Elastic to 8.3.1
2022-07-05 14:50:24 -04:00
weslambert
2938464501
Update to Kibana 8.3.1
2022-07-05 14:46:02 -04:00
weslambert
79e88c9ca3
Update to Kibana 8.3.1
2022-07-05 14:45:30 -04:00
Wes Lambert
e96206d065
Strip quotes and ensure file_path is typed as a list
2022-07-05 14:25:54 +00:00
Josh Brower
7fa9ca8fc6
Merge pull request #8233 from Security-Onion-Solutions/fix/remove-sudo-bpf
...
Remove unneeded sudo
2022-07-05 09:23:48 -04:00
Josh Brower
a1d1779126
Remove unneeded sudo
2022-07-05 09:21:05 -04:00
Josh Patterson
fb365739ae
Merge pull request #8225 from Security-Onion-Solutions/salltupdate
...
bootstrap-salt can now update to minor version with -r
2022-07-01 08:53:59 -04:00
m0duspwnens
5f898ae569
change to egrep
2022-07-01 08:47:46 -04:00
m0duspwnens
f0ff0d51f7
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 16:59:54 -04:00
m0duspwnens
7524ea2c05
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 15:10:13 -04:00
Mike Reeves
6bb979e2b6
Merge pull request #8219 from Security-Onion-Solutions/salty
...
Salty
2022-06-30 13:34:03 -04:00
Mike Reeves
8b3d5e808e
Fix repo location
2022-06-30 13:30:56 -04:00
Mike Reeves
e86b7bff84
Fix repo location
2022-06-30 13:29:21 -04:00
Josh Patterson
69ce3613ff
Merge pull request #8217 from Security-Onion-Solutions/salltupdate
...
point to salt3004.2
2022-06-30 11:29:35 -04:00
m0duspwnens
0ebd957308
point to salt3004.2
2022-06-30 11:26:03 -04:00
Josh Patterson
c3979f5a32
Merge pull request #8207 from Security-Onion-Solutions/salltupdate
...
Saltupdate 3004.2
2022-06-28 11:20:53 -04:00
m0duspwnens
8fccd4598a
update saltstack.list for 3004.2
2022-06-27 16:23:01 -04:00
weslambert
3552dfac03
Merge pull request #8199 from Security-Onion-Solutions/fix/filebeat_filestream_elastic8
...
Change type from 'log' to 'filestream' to ensure compatibility with E…
2022-06-27 14:58:54 -04:00
Josh Patterson
fba5592f62
Update minion.defaults.yaml
2022-06-27 12:10:18 -04:00
Josh Patterson
05e84699d1
Update master.defaults.yaml
2022-06-27 12:09:39 -04:00
Mike Reeves
f36c8da1fe
Update so-functions
2022-06-27 12:04:33 -04:00
Mike Reeves
080daee1d8
Update so-functions
2022-06-27 11:43:01 -04:00
Mike Reeves
909e876509
Update ubuntu.sls
2022-06-27 11:41:49 -04:00
Jason Ertel
ac68fa822b
Merge pull request #8200 from Security-Onion-Solutions/contrib
...
Add gh action for contrib check
2022-06-27 11:25:10 -04:00
Jason Ertel
675ace21f5
Add gh action for contrib check
2022-06-27 11:11:15 -04:00
weslambert
85f790b28a
Change type from 'log' to 'filestream' to ensure compatibility with Elastic 8
2022-06-27 10:39:58 -04:00
weslambert
d0818e83c9
Merge pull request #8197 from Security-Onion-Solutions/fix/localfile_analyzer_csv_path
...
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:36:59 -04:00
weslambert
568b43d0af
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:10:13 -04:00
Jason Ertel
2e123b7a4f
Merge pull request #8175 from Security-Onion-Solutions/kilo
...
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 08:16:39 -04:00
Jason Ertel
ba6f716e4a
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 06:09:04 -04:00
weslambert
10bcc43e85
Merge pull request #8167 from Security-Onion-Solutions/feature/update_es_8_2_3
...
Update to Elastic 8.2.3
2022-06-21 16:11:39 -04:00
weslambert
af687fb2b5
Update config_saved_objects.ndjson
2022-06-21 16:06:28 -04:00
weslambert
776cc30a8e
Update to ES 8.2.3
2022-06-21 16:06:01 -04:00
Doug Burks
00cf0b38d0
Merge pull request #8165 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve default dashboards #8136
2022-06-21 12:57:46 -04:00
Doug Burks
94c637449d
FIX: Improve default dashboards #8136
2022-06-21 12:53:06 -04:00
Josh Brower
0a203add3b
Merge pull request #8145 from Security-Onion-Solutions/defensivedepth-patch-1
...
pin v1.6.0
2022-06-17 13:14:58 -04:00
Josh Brower
b8ee896f8a
pin v1.6.0
2022-06-17 12:38:54 -04:00
Josh Brower
238e671f34
Merge pull request #8129 from Security-Onion-Solutions/fix/curator-cron
...
Change curator to daily for true cluster
2022-06-15 11:40:53 -04:00
Josh Brower
072cb3cca2
Change curator to daily for true cluster
2022-06-15 11:38:38 -04:00
weslambert
44595cb333
Merge pull request #8123 from Security-Onion-Solutions/foxtrot
...
Merge foxtrot into dev
2022-06-14 15:44:13 -04:00
weslambert
959cec1845
Delete Elastalert indices before upgrading to Elastic 8
2022-06-14 11:40:11 -04:00
Doug Burks
286909af4b
Merge pull request #8113 from Security-Onion-Solutions/fix/pfsense-category
...
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:08:00 -04:00
doug
025993407e
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:03:44 -04:00
weslambert
151a42734c
Update Elastic version to 8.2.2
2022-06-08 15:07:45 -04:00
weslambert
11e3576e0d
Update Elastic version to 8.2.2
2022-06-08 15:07:07 -04:00
weslambert
adeccd0e7f
Merge pull request #8097 from Security-Onion-Solutions/dev
...
Merge latest dev into foxtrot
2022-06-08 15:01:09 -04:00
weslambert
aadf391e5a
Temporarily downgrade version for merge
2022-06-08 14:59:01 -04:00
weslambert
47f74fa5c6
Temporarily downgrade version for merge
2022-06-08 14:58:05 -04:00
Jason Ertel
e405750d26
Merge pull request #8095 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.140
2022-06-08 09:07:56 -04:00
Jason Ertel
e36c33485d
Bump version to 2.3.140
2022-06-08 09:04:57 -04:00
Mike Reeves
65165e52f4
Merge pull request #8086 from Security-Onion-Solutions/dev
...
2.3.130
2022-06-07 15:51:12 -04:00
Mike Reeves
2cceae54df
Merge pull request #8087 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 13:44:38 -04:00
Mike Reeves
8912e241aa
2.3.130
2022-06-07 13:41:51 -04:00
Mike Reeves
7357f157ec
Merge pull request #8085 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 12:04:47 -04:00
Mike Reeves
37881bd4b6
2.3.130
2022-06-07 11:34:10 -04:00
Josh Brower
2574f0e23d
Merge pull request #8081 from Security-Onion-Solutions/fix/fleetdm-websockets
...
Allow websockets for fleetdm
2022-06-06 19:15:02 -04:00
Josh Brower
c9d9804c3a
Allow websockets for fleetdm
2022-06-06 17:26:24 -04:00
Doug Burks
73baa1d2f0
Merge pull request #8073 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md to include links to Dashboards and Cases
2022-06-04 08:53:54 -04:00
Doug Burks
dce415297c
improve readability in motd.md
2022-06-04 06:59:09 -04:00
Doug Burks
de126647f8
Update motd.md to include links to Dashboards and Cases
2022-06-04 06:55:08 -04:00
Doug Burks
c34f456151
Merge pull request #8069 from Security-Onion-Solutions/dougburks-patch-1
...
add bar and pie examples to overview dashboard in dashboards.queries.…
2022-06-03 15:04:16 -04:00
Doug Burks
83bff5ee87
add bar and pie examples to overview dashboard in dashboards.queries.json
2022-06-03 15:02:40 -04:00
Doug Burks
918f431728
Merge pull request #8065 from Security-Onion-Solutions/dougburks-patch-1
...
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:13:39 -04:00
Doug Burks
4a886338c8
fix description field for default dashboard in dashboards.queries.json
2022-06-03 11:10:01 -04:00
Doug Burks
7da1802eae
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:03:48 -04:00
Mike Reeves
ff92b524c2
Merge pull request #8062 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2022-06-02 11:51:42 -04:00
Mike Reeves
395eaa39b4
Update soup
2022-06-02 11:45:37 -04:00
Mike Reeves
2867a32931
Merge pull request #8061 from Security-Onion-Solutions/soup130
...
soup for 130
2022-06-02 10:42:17 -04:00
Mike Reeves
fce43cf390
soup for 130
2022-06-02 10:33:18 -04:00
Josh Patterson
e5c9b91529
Merge pull request #8054 from Security-Onion-Solutions/dmz_receiver
...
Dmz receiver
2022-06-01 15:31:42 -04:00
m0duspwnens
e5b74bcb78
remove podman state
2022-06-01 15:26:25 -04:00
Doug Burks
91f8d3e5e9
Merge pull request #8050 from Security-Onion-Solutions/fix/elastalert-query
...
FIX: Elastalert query in Hunt #8049
2022-05-31 16:54:34 -04:00
Doug Burks
269b16bbfd
https://github.com/Security-Onion-Solutions/securityonion/issues/8049
2022-05-31 16:51:05 -04:00
Doug Burks
cd382a1b25
FIX: Elastalert query in Hunt #8049
2022-05-31 16:50:32 -04:00
Doug Burks
e1c9b0d108
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:52 -04:00
Doug Burks
9a98667e85
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:11 -04:00
weslambert
494ce0756d
Merge pull request #8045 from Security-Onion-Solutions/fix/mhr_naming
...
Fix naming for Malware Hash Registry analyzer
2022-05-31 07:52:48 -04:00
Wes Lambert
7f30a364ee
Make sure everything is added back after renaming mhr to malwarehashregistry
2022-05-31 11:44:35 +00:00
Wes Lambert
c82aa89497
Fix Malware Hash Registry naming so it's more descriptive in SOC
2022-05-31 11:41:48 +00:00
Josh Brower
025677a1e6
Merge pull request #8034 from Security-Onion-Solutions/feature/sigmafp
...
Feature/SigmaCustomFilters
2022-05-31 07:25:44 -04:00
Josh Brower
a5361fb745
Change Target_log name
2022-05-28 18:07:05 -04:00
Mike Reeves
30d7801ae1
Merge pull request #8033 from Security-Onion-Solutions/kilo
2022-05-28 11:38:35 -04:00
Jason Ertel
210bc556db
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:29:04 -04:00
Jason Ertel
e87e672b9e
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:28:20 -04:00
Jason Ertel
a70da41f20
Merge pull request #8032 from Security-Onion-Solutions/kilo
...
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:34:40 -04:00
Jason Ertel
8bb02763dc
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:28:10 -04:00
weslambert
a59ada695b
Merge pull request #8031 from Security-Onion-Solutions/fix/screenshots
...
Fix/screenshots
2022-05-27 17:05:51 -04:00
doug
b93a108386
update Cases screenshot in README
2022-05-27 16:33:08 -04:00
doug
6089f3906d
update screenshots and README
2022-05-27 16:32:00 -04:00
Josh Brower
94ee45ac63
Merge pull request #8029 from Security-Onion-Solutions/upgrade/navigator
...
Upgrade Navigator to 4.6.4
2022-05-27 14:46:59 -04:00
Josh Brower
43cb78a6a8
Upgrade Navigator
2022-05-27 14:21:11 -04:00
Josh Patterson
76bb1fbbcc
Merge pull request #8014 from Security-Onion-Solutions/issue/7918
...
manage suricata classifications.config
2022-05-26 13:13:03 -04:00
m0duspwnens
53d6e1d30d
simplfy
2022-05-26 11:51:17 -04:00
m0duspwnens
1bfde852f5
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:43:31 -04:00
m0duspwnens
53883e4ade
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:40:33 -04:00
weslambert
1a0ac4d253
Merge pull request #8007 from Security-Onion-Solutions/fix/filestream-id
...
Add filestream input ID for RITA logs
2022-05-25 10:11:36 -04:00
weslambert
44622350ea
Add ID for RITA filestream inputs
2022-05-25 10:09:01 -04:00
weslambert
99864f4787
Merge pull request #8001 from Security-Onion-Solutions/feature/analyzer_readme
...
Add configuration requirements for various analyzers
2022-05-25 09:33:07 -04:00
Doug Burks
6bd02c0b99
Merge pull request #8003 from Security-Onion-Solutions/feature/elastic-7.17.4
...
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:24:13 -04:00
Doug Burks
1d0bb21908
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:30 -04:00
Doug Burks
bde06e7ec5
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:01 -04:00
Wes Lambert
b93512eb01
Adjust verbiage around pillar configuration
2022-05-24 12:36:32 +00:00
Wes Lambert
92dee14ee8
Add configuration requirements for various analyzers
2022-05-24 12:29:14 +00:00
weslambert
3e6dfcfaca
Merge pull request #7996 from Security-Onion-Solutions/weslambert-patch-2
...
Create Virustotal README
2022-05-23 11:43:43 -04:00
weslambert
a6f1bf3aef
Create Virustotal README
2022-05-23 11:39:44 -04:00
Jason Ertel
88f17f037e
Merge pull request #7982 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.9.0-alpha.3
2022-05-19 13:28:58 -04:00
Jason Ertel
c20859f8c3
Upgrade to Kratos 0.9.0-alpha.3
2022-05-18 17:05:21 -04:00
Jason Ertel
c95bafd521
Merge pull request #7969 from Security-Onion-Solutions/fix/helpers-analyzers
...
Only import yaml module when config is loaded
2022-05-18 07:15:32 -04:00
Wes Lambert
429ccb2dcc
Only import yaml module when config is loaded
2022-05-18 02:07:39 +00:00
weslambert
94ca3ddbda
Merge pull request #7961 from Security-Onion-Solutions/weslambert-patch-1
...
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 13:33:24 -04:00
weslambert
d3206a048f
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 12:49:16 -04:00
weslambert
ff855eb8f7
Merge pull request #7958 from Security-Onion-Solutions/feature/mhr_analyzer
...
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 12:42:01 -04:00
Wes Lambert
8af1f19ac3
Another no_results change
2022-05-17 16:12:43 +00:00
Wes Lambert
e4a7e3cba6
Change 'No results found.' to 'no_results'
2022-05-17 16:11:58 +00:00
weslambert
2688083ff1
Merge pull request #7959 from Security-Onion-Solutions/feature/whoislookup-analyzer
...
Add Whoislookup RDAP-based analyzer
2022-05-17 12:09:06 -04:00
Wes Lambert
766e9748c5
Add Whoislookup RDAP-based analyzer
2022-05-17 15:52:12 +00:00
weslambert
3761b491c0
Remove whitespace
2022-05-17 10:50:33 -04:00
Wes Lambert
e8fc3ccdf4
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 14:44:53 +00:00
Doug Burks
eb9597217c
Merge pull request #7949 from Security-Onion-Solutions/fix/dashboards-hunt-queries
...
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:47:06 -04:00
doug
5cbb50a781
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:33:48 -04:00
Jason Ertel
685789de33
Merge pull request #7936 from Security-Onion-Solutions/kilo
...
Improved unit test coverage of new analyzers; Utilize localized summa…
2022-05-12 16:47:18 -04:00
Jason Ertel
b45b6b198b
Improved unit test coverage of new analyzers; Utilize localized summaries; Require 100% code coverage on analyzers
2022-05-12 16:32:47 -04:00
weslambert
6c506bbab0
Merge pull request #7935 from Security-Onion-Solutions/fix/pulsedive
...
Fix Pulsedive analyzer logic
2022-05-12 15:20:15 -04:00
Wes Lambert
3dc266cfa9
Add test for when indicator is not found
2022-05-12 19:02:41 +00:00
Wes Lambert
a233c08830
Update logic to handle indicators that are not present in database.
2022-05-12 19:02:02 +00:00
Doug Burks
58b049257d
Merge pull request #7932 from Security-Onion-Solutions/dougburks-patch-1
...
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:24:18 -04:00
Doug Burks
6ed3f42449
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:23:00 -04:00
m0duspwnens
d8abc0a195
if in dmz_nodes dont add to filebeta
2022-05-11 11:51:18 -04:00
m0duspwnens
a641346c02
prevent nodes with logstash:dmz:true from being added to logstash:nodes pillar
2022-05-10 17:28:19 -04:00
Jason Ertel
60b55acd6f
Merge pull request #7926 from Security-Onion-Solutions/kilo
...
Add support for analyzers in airgapped environments
2022-05-10 17:12:18 -04:00
Jason Ertel
35e47c8c3e
Add support for analyzers in airgapped environments
2022-05-10 16:51:00 -04:00
weslambert
7f797a11f8
Merge pull request #7924 from Security-Onion-Solutions/analyzer-docs
...
Update analyzer docs with information about analyzers that require au…
2022-05-10 09:40:50 -04:00
Jason Ertel
91a7f25d3a
Corrected brand name capitalization
2022-05-10 09:39:19 -04:00
weslambert
34d57c386b
Update analyzer docs with information about analyzers that require authentication
2022-05-10 09:32:18 -04:00
weslambert
000e813fbb
Merge pull request #7921 from Security-Onion-Solutions/fix/analyzer-packages
...
Update analyzer packages to those downloaded by Alpine and add additional build script option
2022-05-09 16:43:31 -04:00
Wes Lambert
555ca2e277
Update analyzer build/testing script to download necessary Python packages
2022-05-09 20:06:39 +00:00
Wes Lambert
32adba6141
Update analyzer packages with those built from native (Alpine) Docker image
2022-05-09 20:04:41 +00:00
Jason Ertel
e19635e44a
Merge pull request #7920 from Security-Onion-Solutions/kilo
...
Disable MRU queries on dashboards
2022-05-09 15:08:55 -04:00
Jason Ertel
31c04aabdd
Disable MRU queries on dashboards
2022-05-09 15:06:43 -04:00
Jason Ertel
dc209a37cd
Merge pull request #7916 from Security-Onion-Solutions/kilo
...
Disable actions on dashboards group-by tables
2022-05-09 11:52:22 -04:00
Jason Ertel
3f35dc54d2
Disable actions on dashboards group-by tables
2022-05-09 11:44:39 -04:00
Josh Brower
8e368bdebe
Merge in upstream dev
2022-05-06 20:01:07 -04:00
Jason Ertel
0e64a9e5c3
Merge pull request #7912 from Security-Onion-Solutions/kilo
...
Add dashboard ref to soc.json
2022-05-06 15:18:05 -04:00
Jason Ertel
0786191fc9
Add dashboard ref to soc.json
2022-05-06 15:16:27 -04:00
Jason Ertel
60763c38db
Merge pull request #7911 from Security-Onion-Solutions/kilo
...
Analyzers + Dashboards
2022-05-06 13:50:54 -04:00
weslambert
9800f59ed7
Add Urlscan to observable support matrix
2022-05-06 13:11:43 -04:00
Wes Lambert
ccac71f649
Fix formatting/whitespace
2022-05-06 17:08:40 +00:00
Wes Lambert
1990ba0cf0
Fix formatting/whitespace
2022-05-06 17:08:33 +00:00
Wes Lambert
8ff5778569
Add Urlscan analyzer and tests
2022-05-06 17:01:06 +00:00
Jason Ertel
bee4cf4c52
Fix typo in analyzer desc
2022-05-06 09:20:03 -04:00
Jason Ertel
105c95909c
Dashboard queries
2022-05-04 19:32:06 -04:00
Jason Ertel
890bcd58f9
Merge branch 'dev' into kilo
2022-05-04 19:25:08 -04:00
weslambert
a96c665d04
Change test name for EmailRep
2022-05-03 14:13:25 -04:00
weslambert
f3a91d9fcd
Add EmailRep analyzer to observable support matrix
2022-05-03 10:10:57 -04:00
Wes Lambert
5a9acb3857
Add EmailRep analyzer and tests
2022-05-03 14:06:32 +00:00
Wes Lambert
8b5666b238
Ensure API key is used
2022-05-03 12:48:06 +00:00
weslambert
efb229cfcb
Update to match configuration in analyzer dir
2022-05-02 16:35:21 -04:00
weslambert
2fcb2b081d
Update allowed complexity to 12
2022-05-02 16:14:43 -04:00
weslambert
25f17a5efd
Update allowed complexity to 11
2022-04-29 09:42:57 -04:00
weslambert
66b4fe9f58
Add additional information around URI and User Agent
2022-04-28 17:14:36 -04:00
Wes Lambert
c001708707
Add Pulsedive analyzer and tests
2022-04-28 20:56:03 +00:00
weslambert
4edd729596
Add initial supported observable matrix/table
2022-04-27 08:58:34 -04:00
Wes Lambert
76f183b112
Add Greynoise analyzer and tests
2022-04-26 17:25:35 +00:00
Wes Lambert
bd63753d80
Update analyzer name/description
2022-04-25 19:27:10 +00:00
Wes Lambert
15fcaa7030
Add localfile analyzer and tests
2022-04-25 19:23:35 +00:00
Jason Ertel
71a86b0a3c
Merge pull request #7856 from Security-Onion-Solutions/bumpver
...
Bump version
2022-04-25 13:01:19 -04:00
Jason Ertel
e2145720bd
Bump version
2022-04-25 12:10:29 -04:00
Mike Reeves
b4aa59c619
Merge pull request #7853 from Security-Onion-Solutions/dev
...
2.3.120
2022-04-25 11:33:05 -04:00
Mike Reeves
6975153cf4
Merge pull request #7852 from Security-Onion-Solutions/2.3.120
...
2.3.120
2022-04-25 08:59:52 -04:00
Mike Reeves
0935f51667
2.3.120
2022-04-25 08:57:35 -04:00
Mike Reeves
f92d65737b
2.3.120
2022-04-25 08:53:04 -04:00
Josh Patterson
8f5967911b
Merge pull request #7847 from Security-Onion-Solutions/m0duspwnens-patch-1
...
add eval
2022-04-22 16:06:01 -04:00
Josh Patterson
80eb31368a
add eval
2022-04-22 16:04:29 -04:00
Jason Ertel
d8fdf2b701
Merge branch 'dev' into kilo
2022-04-22 15:11:24 -04:00
Jason Ertel
459d388614
Only override nameservers if the first nameserver given is non empty
2022-04-22 15:08:56 -04:00
Wes Lambert
fbf6e64e67
Add initial OTX analyzer and tests
2022-04-22 17:13:40 +00:00
weslambert
677db7c563
Merge pull request #7841 from Security-Onion-Solutions/weslambert-patch-2
...
Update shard count for Zeek in setup
2022-04-21 17:27:57 -04:00
weslambert
1bb216954c
Merge pull request #7840 from Security-Onion-Solutions/weslambert-patch-1
...
Update shards for Zeek
2022-04-21 17:26:57 -04:00
weslambert
c81988ab00
Update shard count for Zeek in setup
2022-04-21 17:26:30 -04:00
weslambert
542db5b7f5
Update defaults.yaml
2022-04-21 17:24:24 -04:00
Wes Lambert
b2db32a2c7
Add function/test for non-existent VT api_key
2022-04-21 17:33:24 +00:00
Wes Lambert
9287d6adf7
Reduce size of test output for test
2022-04-21 16:56:22 +00:00
Wes Lambert
c8e189f35a
Add source-packages for JA3er
2022-04-21 16:46:45 +00:00
Wes Lambert
5afcc8de4f
Add JA3er analyzer and associated test
2022-04-21 16:42:46 +00:00
weslambert
d7eed52fae
Change -f to -r
2022-04-21 09:46:44 -04:00
Doug Burks
2910b56ea1
Merge pull request #7835 from Security-Onion-Solutions/elastic-7.17.3
...
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 09:02:51 -04:00
Doug Burks
e608285341
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:57:08 -04:00
Doug Burks
04856540dc
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:54:09 -04:00
Doug Burks
feb7eeeb8e
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:47:40 -04:00
Doug Burks
44f4b1da7f
Merge pull request #7832 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-04-20 17:00:09 -04:00
Doug Burks
1edb443c5d
so-playbook-sync pgrep should be more strict to avoid multiple matches on Ubuntu
2022-04-20 16:48:26 -04:00
Doug Burks
8fc03afdc0
so-sensor-clean pgrep should be more strict to avoid matching multiples on Ubuntu
2022-04-20 16:47:18 -04:00
Mike Reeves
fe09b5b0d1
Merge pull request #7831 from Security-Onion-Solutions/awlocal
...
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:42:58 -04:00
Mike Reeves
c3952e94c8
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:36:38 -04:00
Doug Burks
3aac644da5
Merge pull request #7830 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve Zeek file extraction #7829
2022-04-20 14:13:13 -04:00
Doug Burks
15ef0968d9
FIX: Improve Zeek file extraction #7829
2022-04-20 14:01:46 -04:00
Jason Ertel
aeb70dad8f
Doc updates
2022-04-19 14:31:21 -04:00
Jason Ertel
4129cef9fb
Add new spamhaus analyzer
2022-04-19 12:12:52 -04:00
Josh Patterson
40d9335573
Merge pull request #7822 from Security-Onion-Solutions/workstation_state
...
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:21:35 -04:00
m0duspwnens
807f6adf1e
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:19:09 -04:00
Doug Burks
6339ee3bf3
Merge pull request #7818 from Security-Onion-Solutions/dougburks-patch-1
...
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:35:22 -04:00
Doug Burks
5d62ece03b
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:33:54 -04:00
Doug Burks
6905ca276a
Merge pull request #7816 from Security-Onion-Solutions/dougburks-patch-1
...
remove old comments from so-whiptail
2022-04-18 11:30:43 -04:00
Doug Burks
3682754399
remove old comments from so-whiptail
2022-04-18 11:29:46 -04:00
Jason Ertel
0cb73d8f6a
Merge branch 'dev' into kilo
2022-04-18 11:04:32 -04:00
Mike Reeves
186258687e
Merge pull request #7815 from Security-Onion-Solutions/awlocal
...
Fix Analyst Install Loop
2022-04-18 11:04:10 -04:00
Mike Reeves
012ff3e1bc
Fix Analyst Install Loop
2022-04-18 11:02:19 -04:00
Josh Brower
891a197a6a
Merge pull request #7814 from Security-Onion-Solutions/defensivedepth-patch-2
...
Fix ES/LS Log Pruning
2022-04-18 10:45:27 -04:00
Josh Brower
b35b505f0a
Fix pattern matching
2022-04-18 10:39:04 -04:00
Josh Brower
2b39570b08
Fix matching logic
2022-04-18 10:37:38 -04:00
Jason Ertel
159122b52c
Merge branch 'dev' into kilo
2022-04-18 10:11:37 -04:00
Doug Burks
3fb7399000
Merge pull request #7813 from Security-Onion-Solutions/dougburks-patch-1
...
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 08:24:52 -04:00
Doug Burks
400879c079
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 07:53:57 -04:00
Doug Burks
62f3f13bbc
Merge pull request #7803 from Security-Onion-Solutions/dougburks-patch-1
...
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:48:12 -04:00
Doug Burks
0eda9a3bd7
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:45:01 -04:00
Doug Burks
ee00678362
Merge pull request #7802 from Security-Onion-Solutions/dougburks-patch-1
...
Replace old saltstack repo in so-preflight
2022-04-15 13:17:14 -04:00
Doug Burks
ce192c2526
Update so-preflight
2022-04-15 13:11:15 -04:00
Josh Brower
d60d31f723
Merge pull request #7801 from Security-Onion-Solutions/defensivedepth-patch-1
...
Remove thehive entries from so-status
2022-04-15 12:25:21 -04:00
Josh Brower
bd19da1878
Remove thehive entries from so-status
2022-04-15 12:21:56 -04:00
Doug Burks
f461d01961
Merge pull request #7800 from Security-Onion-Solutions/dougburks-patch-1
...
Improve grammar in so-whiptail
2022-04-15 10:52:29 -04:00
Doug Burks
a69d361d1b
Improve grammar in so-whiptail
2022-04-15 10:45:34 -04:00
Josh Brower
19cba9dca9
Merge pull request #7798 from Security-Onion-Solutions/awlocal
...
Make analyst iso install init management interface
2022-04-15 07:26:53 -04:00
Mike Reeves
5081a81a6c
Make analyst iso install init management interface
2022-04-14 20:00:58 -04:00
Josh Patterson
ba61057433
Merge pull request #7796 from Security-Onion-Solutions/fix_analyst_setup
...
Fix analyst setup
2022-04-14 16:12:53 -04:00
m0duspwnens
b8a80f76cf
change words
2022-04-14 16:09:39 -04:00
Josh Patterson
be2573bb7d
Merge pull request #7794 from Security-Onion-Solutions/soup_salt_influx
...
remove influxdb module patched state files when salt is upgraded
2022-04-14 16:08:10 -04:00
m0duspwnens
36aef87a3c
remove cd before running so-setup analyst
2022-04-14 16:03:43 -04:00
m0duspwnens
02c19da3c4
remove influxdb module patched state files when salt is upgraded
2022-04-14 15:00:14 -04:00
Josh Patterson
2d094a3bfc
Merge pull request #7784 from Security-Onion-Solutions/workstation_script
...
modify so-analyst-install to work with new states and install on managers
2022-04-13 14:37:24 -04:00
m0duspwnens
371fda09db
fix copy paste fail
2022-04-13 14:28:05 -04:00
m0duspwnens
149375115e
warn about required reboot and prompt if reboot desired at completion of install
2022-04-13 14:26:14 -04:00
m0duspwnens
4728bea633
fix typo
2022-04-13 14:03:09 -04:00
m0duspwnens
3ee09db752
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:48 -04:00
m0duspwnens
6477e6c5a2
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:39 -04:00
m0duspwnens
2389d3fac9
modify so-analyst-install to work with new states and install on managers
2022-04-13 12:32:05 -04:00
Mike Reeves
ecc29b586d
Merge pull request #7772 from Security-Onion-Solutions/awlocal
2022-04-12 15:45:56 -04:00
Mike Reeves
2977604d96
Merge branch 'awlocal' of https://github.com/Security-Onion-Solutions/securityonion into awlocal
2022-04-12 15:39:45 -04:00
Mike Reeves
5253cb5d25
Remove keys at the end of an install
2022-04-12 15:33:17 -04:00
Josh Brower
1cb5a791ca
Add idh req_storage elif
2022-04-12 14:29:07 -04:00
Mike Reeves
8408628b03
Stop thehive on soup
2022-04-12 13:54:08 -04:00
Mike Reeves
02f4cd9926
Replace salt code on a saltstack update
2022-04-12 12:15:22 -04:00
Mike Reeves
c1824e9f17
Replace salt code on a saltstack update
2022-04-12 11:55:45 -04:00
Mike Reeves
081d7e3a09
Replace salt code on a saltstack update
2022-04-12 11:20:26 -04:00
Mike Reeves
a7221ba2b4
Remove summary for thins the workstation doesnt care about
2022-04-12 11:06:12 -04:00
Mike Reeves
aa90a016d7
Change disk requirements for IDH
2022-04-12 10:44:45 -04:00
Josh Patterson
dbddff7be7
Merge pull request #7766 from Security-Onion-Solutions/issue/7763
...
Issue/7763
2022-04-11 16:44:04 -04:00
Josh Brower
f1574de827
Merge pull request #7765 from Security-Onion-Solutions/fix/compress-clean-elastic-logs
...
Compress + Clean ES & Logstash App Logs
2022-04-11 16:43:03 -04:00
Josh Brower
886d69fb38
Compress + Clean ES & Logstash App Logs
2022-04-11 16:09:24 -04:00
m0duspwnens
d68b6e7c9a
only start if exit code != 0
2022-04-11 16:03:00 -04:00
m0duspwnens
d102ca298d
move messages about starting services on soup failure before exit message
2022-04-11 16:01:36 -04:00
m0duspwnens
9914148441
more verbose
2022-04-11 15:51:11 -04:00
m0duspwnens
464772d7d3
start salt-master and salt-minion service is soup fails and exits
2022-04-11 15:43:09 -04:00
Mike Reeves
13f6957ae8
Merge pull request #7764 from Security-Onion-Solutions/awlocal
2022-04-11 15:40:06 -04:00
m0duspwnens
2a18059ad9
use quotes
2022-04-11 15:37:07 -04:00
m0duspwnens
01510c184a
set_os and set_cron_service_name sooner
2022-04-11 15:36:02 -04:00
Mike Reeves
eb2d759bf8
Add more whiptail menus
2022-04-11 15:14:29 -04:00
Mike Reeves
5ed7361e3a
Add more whiptail menus
2022-04-11 15:14:06 -04:00
m0duspwnens
6ed8694008
dont need to pass -t
2022-04-11 15:11:57 -04:00
m0duspwnens
79dc2374e0
check that salt-master is running before requiring manager
2022-04-11 15:09:00 -04:00
m0duspwnens
a2180a6721
ensure salt-master service is running before proceeding with soup
2022-04-11 15:01:41 -04:00
Mike Reeves
f9633e7287
Add more whiptail menus
2022-04-11 14:51:17 -04:00
Mike Reeves
0b2745b342
Sending things to the screen
2022-04-11 11:49:24 -04:00
Mike Reeves
ea34b69795
Sending things to the screen
2022-04-11 11:46:42 -04:00
Mike Reeves
97e691c321
Sending things to the screen
2022-04-11 11:43:13 -04:00
Mike Reeves
a3bf904e2d
Import GPG
2022-04-11 11:32:08 -04:00
Mike Reeves
9ed49ef318
Import GPG
2022-04-11 11:29:56 -04:00
Mike Reeves
f7760394a1
Import GPG
2022-04-11 11:25:54 -04:00
Mike Reeves
d9416f3828
Salt local install of Analyst Workstation
2022-04-11 11:04:25 -04:00
Jason Ertel
2d025e944c
Add yaml since helpers module uses it
2022-04-09 17:48:21 -04:00
Jason Ertel
202ca34c6f
Remove obsolete source/site pkg dirs
2022-04-09 14:36:21 -04:00
Jason Ertel
f9568626f2
Merge branch 'dev' into kilo
2022-04-09 09:02:55 -04:00
Jason Ertel
224e30c0ee
Change localized table layout
2022-04-08 17:31:15 -04:00
Jason Ertel
ebcfbaa06d
Analyzer improvements
2022-04-08 16:57:40 -04:00
Josh Patterson
365866c9cc
Merge pull request #7750 from Security-Onion-Solutions/issue_7730
...
ensure bash is used for influx query
2022-04-08 15:26:24 -04:00
m0duspwnens
59d5be682a
ensure bash is used for influx query
2022-04-08 15:01:38 -04:00
Mike Reeves
7805311ea2
Merge pull request #7748 from Security-Onion-Solutions/bravo
...
Bravo
2022-04-08 14:48:54 -04:00
Josh Patterson
8757ca0dfb
Merge pull request #7749 from Security-Onion-Solutions/issue/7113
...
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:10:54 -04:00
m0duspwnens
3e8c687d61
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:05:38 -04:00
Jason Ertel
13c9af5a5a
Clearing hotfix
2022-04-08 10:23:44 -04:00
Mike Reeves
a5313b330f
Merge master into dev
2022-04-08 09:07:46 -04:00
Mike Reeves
0bc3d5d757
Merge pull request #7741 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110 20220407
2022-04-07 16:30:50 -04:00
Mike Reeves
6d88a5b541
Merge pull request #7740 from Security-Onion-Solutions/hfix0407
...
2.3.110 hotfix 0407
2022-04-07 16:11:58 -04:00
Mike Reeves
6a28e752f0
2.3.110 hotfix 0407
2022-04-07 16:03:13 -04:00
Josh Brower
ae8d300567
Merge pull request #7738 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Include firewall state
2022-04-07 14:52:31 -04:00
Mike Reeves
2ad3f63cb5
Merge pull request #7739 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-04-07 14:46:20 -04:00
Mike Reeves
93e04850c4
Update HOTFIX
2022-04-07 14:40:54 -04:00
Josh Brower
36b2d78dfe
Include firewall state
2022-04-07 14:02:21 -04:00
Jason Ertel
44e318e046
Provide CLI feedback for missing input
2022-04-07 10:16:44 -04:00
Josh Patterson
09e7b5a8bf
Merge pull request #7733 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-07 09:05:51 -04:00
m0duspwnens
8fbd16f75d
ensure salt.list is absent
2022-04-07 09:03:51 -04:00
m0duspwnens
722b200e16
add retry to apt_update incase running in background
2022-04-07 08:58:07 -04:00
m0duspwnens
b2a98af18b
proper formatting
2022-04-07 08:55:30 -04:00
m0duspwnens
be3769fd7c
run apt-get update if saltstack.list changes
2022-04-07 08:53:44 -04:00
m0duspwnens
08ac696f14
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-06 17:38:06 -04:00
Josh Brower
86771e1fe6
Merge pull request #7732 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Feature/idh allow multiple int
2022-04-06 17:21:30 -04:00
Josh Brower
f5e539a05c
Initial support for restricting IDH services on MGT IP
2022-04-06 17:16:38 -04:00
Josh Patterson
0c1ac729e1
Merge pull request #7731 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update the centos repo for airgap prior to applying hotfix
2022-04-06 17:00:09 -04:00
m0duspwnens
833106775f
update the centos repo for airgap prior to applying hotfix or standard soup run
2022-04-06 16:53:55 -04:00
Mike Reeves
fbd417b09e
Merge pull request #7720 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-05 20:29:17 -04:00
Mike Reeves
4224d1f258
Merge pull request #7719 from Security-Onion-Solutions/hfix0405
...
2.3.110 hotfix 0405
2022-04-05 19:17:42 -04:00
Mike Reeves
79175b57fa
2.3.110 hotfix 0405
2022-04-05 19:15:20 -04:00
Josh Patterson
5717382340
Merge pull request #7717 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
use -r for bootstrap-salt for ubuntu
2022-04-05 17:37:22 -04:00
m0duspwnens
cf68aeb36e
use -r for bootstrap-salt for ubuntu
2022-04-05 17:35:03 -04:00
Josh Patterson
882eb83fee
Merge pull request #7716 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
point to so repo
2022-04-05 17:30:10 -04:00
m0duspwnens
89c7f5b356
point to so repo
2022-04-05 17:28:47 -04:00
Mike Reeves
bed9a20025
Merge pull request #7714 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
proper salt format
2022-04-05 15:45:36 -04:00
m0duspwnens
89518b5939
proper salt format
2022-04-05 15:44:06 -04:00
Mike Reeves
07b14d7fa7
Merge pull request #7713 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update update_repo function
2022-04-05 15:42:45 -04:00
m0duspwnens
1248ba8924
update update_repo function
2022-04-05 15:40:39 -04:00
Josh Patterson
cbbe3b9248
Merge pull request #7712 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
add deb to saltstack.list
2022-04-05 14:45:46 -04:00
m0duspwnens
b467cde9ad
add deb to saltstack.list
2022-04-05 14:42:36 -04:00
Josh Patterson
6d6f328cad
Merge pull request #7711 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
manage repo conf for ubuntu
2022-04-05 13:50:32 -04:00
m0duspwnens
020871ef61
update hotfix version
2022-04-05 13:49:28 -04:00
m0duspwnens
e08b13629a
manage repo conf for ubuntu
2022-04-05 13:41:26 -04:00
Jason Ertel
d8defdd7b0
Improve unit test stability
2022-04-05 07:36:25 -04:00
Jason Ertel
d2fa80e48a
Update status codes to match SOC
2022-04-05 07:20:23 -04:00
Doug Burks
1e187f0c44
Merge pull request #7703 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-04 23:37:28 -04:00
Josh Brower
7906c053b1
Initial support for restricting IDH services on MGT IP
2022-04-04 16:46:05 -04:00
Mike Reeves
f5073243f9
Merge pull request #7702 from Security-Onion-Solutions/hfix0401
...
2.3.110 hotfix 0401
2022-04-04 16:13:08 -04:00
Mike Reeves
0c7a07f5c0
Merge pull request #7667 from Security-Onion-Solutions/analystsetup
...
Analyst Setup
2022-04-04 16:09:13 -04:00
Mike Reeves
04370a04ce
2.3.110 hotfix 0401
2022-04-04 16:06:20 -04:00
Jason Ertel
04eef0d31f
Merge branch 'dev' into kilo
2022-04-04 15:59:09 -04:00
Jason Ertel
7df6833568
Add unit tests for Urlhaus; remove placeholder whois analyzer
2022-04-04 15:58:53 -04:00
Josh Patterson
809bc1858c
Merge pull request #7700 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
salt 3004.1 hotfix
2022-04-04 13:32:34 -04:00
m0duspwnens
f9563b2dc4
patch influxdb modules
2022-04-04 12:57:36 -04:00
m0duspwnens
b7aff4f4df
remove influxdb state files
2022-04-04 12:28:23 -04:00
m0duspwnens
1e955e0d38
enable highstate before highstate run for hotfix
2022-04-04 11:28:03 -04:00
m0duspwnens
127420b472
hotfix function for 2.3.10 hotfix 1
2022-04-04 10:39:44 -04:00
Wes Lambert
07cf3469a0
Remove pyyaml for requirements file
2022-04-04 11:40:02 +00:00
Wes Lambert
39101cafd1
Add UrlHaus analyzer and helpers script
2022-04-01 21:11:57 +00:00
Mike Reeves
5387caf6f4
fix formatting
2022-04-01 16:50:55 -04:00
Mike Reeves
07783713e6
fix formatting
2022-04-01 16:22:40 -04:00
Mike Reeves
5974279ed7
fix formatting
2022-04-01 16:17:22 -04:00
Mike Reeves
277c7d9d33
fix formatting
2022-04-01 16:05:37 -04:00
Mike Reeves
d20a07bb5f
fix formatting
2022-04-01 16:00:44 -04:00
Josh Patterson
7f4c2687cf
Merge pull request #7691 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove influx patch state files
2022-04-01 15:58:03 -04:00
m0duspwnens
48e40513ff
remove influx patch state files
2022-04-01 15:53:48 -04:00
Mike Reeves
a449a91f38
fix formatting
2022-04-01 15:52:38 -04:00
Mike Reeves
76f43380d9
fix so salt master gets installed
2022-04-01 14:29:24 -04:00
Mike Reeves
7c39559787
fix so salt master gets installed
2022-04-01 14:19:17 -04:00
Jason Ertel
cedb23f4bc
Merge pull request #7689 from Security-Onion-Solutions/esup
...
Upgrade to ES 7.17.2
2022-04-01 13:57:04 -04:00
Jason Ertel
6e7b2ccedc
Upgrade to ES 7.17.2
2022-04-01 13:50:57 -04:00
Mike Reeves
8e9386fcd4
fix the yum commands
2022-04-01 13:17:13 -04:00
Mike Reeves
97fc652a97
fix the yum commands
2022-04-01 11:54:55 -04:00
Mike Reeves
2782c9b464
Update salt versions
2022-04-01 11:26:58 -04:00
Josh Patterson
c429423dae
Merge pull request #7683 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
Update to salt 3004.1
2022-04-01 11:19:31 -04:00
m0duspwnens
45dd7d4758
salt 3004.1 in setup
2022-04-01 11:17:38 -04:00
Josh Patterson
b5ce8756e9
Merge pull request #7686 from Security-Onion-Solutions/workstation_state
...
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:06:53 -04:00
m0duspwnens
e14463c0ab
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:05:34 -04:00
Mike Reeves
d524f3833b
Let the patch pillar do its work
2022-04-01 10:09:55 -04:00
Josh Patterson
f71fcdaed7
salt 3004.1
2022-04-01 09:55:55 -04:00
Josh Patterson
d95391505f
Update minion.defaults.yaml
2022-04-01 09:55:03 -04:00
Mike Reeves
0b80dad2c0
Merge pull request #7682 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-04-01 09:53:57 -04:00
Mike Reeves
02a96c409e
Update HOTFIX
2022-04-01 09:52:57 -04:00
Mike Reeves
cb2044cee9
Fix the analyst pillar
2022-04-01 09:29:29 -04:00
Mike Reeves
64e480714a
Fix the analyst pillar
2022-04-01 09:10:38 -04:00
Jason Ertel
2dc370c8b6
Add source packages to salt state
2022-03-31 18:56:38 -04:00
Jason Ertel
57dc848792
Support analyzer deps
2022-03-31 16:48:13 -04:00
Jason Ertel
9947ba6e43
Support CentOS paths
2022-03-31 16:47:56 -04:00
Jason Ertel
48fbc2290f
Add dep support for analyzers
2022-03-31 13:59:35 -04:00
Mike Reeves
edc6a461ec
Fix analyst pillar
2022-03-31 13:57:37 -04:00
Mike Reeves
63eb15aa6d
Run anayst Pillar
2022-03-31 13:35:30 -04:00
Mike Reeves
5264526ff1
Fix salt master declaration
2022-03-31 12:05:59 -04:00
Mike Reeves
c9eb188a79
Only run specific states during install for AW
2022-03-31 12:01:55 -04:00
Mike Reeves
ad833965a0
Fix extra space
2022-03-31 11:12:10 -04:00
Mike Reeves
179aa5e29c
Add firewall rules for Analyst workstation
2022-03-31 10:49:38 -04:00
Josh Patterson
86b311c468
Merge pull request #7675 from Security-Onion-Solutions/issue/7203
...
different systemd unit files for ubuntu and centos
2022-03-31 10:18:10 -04:00
m0duspwnens
fc60f64ddb
different systemd unit files for ubuntu and centos
2022-03-31 10:11:43 -04:00
Jason Ertel
1aba4da2bb
Correct analyzer path
2022-03-30 21:01:07 -04:00
Mike Reeves
a049e458c6
Add workstation to the salt config
2022-03-30 14:03:52 -04:00
Jason Ertel
45f511caab
Remove extra comma
2022-03-30 13:21:35 -04:00
Mike Reeves
f43a6757e0
Add analyst install network stack
2022-03-30 11:16:00 -04:00
Mike Reeves
c3d3806f65
Add analyst install network stack
2022-03-30 11:14:35 -04:00
Mike Reeves
dceb46888f
Add analyst install network stack
2022-03-30 11:06:59 -04:00
Jason Ertel
e667bb1e59
merge
2022-03-30 10:57:40 -04:00
Mike Reeves
816d0b1075
Don't prompt for install type since we know its analyst
2022-03-29 17:35:13 -04:00
Mike Reeves
c4a4e9737b
Set standalone to load Xwindows
2022-03-29 17:31:53 -04:00
Josh Patterson
1cb48fc6a8
Merge pull request #7668 from Security-Onion-Solutions/issue/7203
...
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 17:30:32 -04:00
Mike Reeves
45161b2a39
Set standalone to load Xwindows
2022-03-29 17:28:32 -04:00
Mike Reeves
67582be575
Set standalone to load Xwindows
2022-03-29 17:23:38 -04:00
Mike Reeves
86e32f3e6c
Set standalone to load Xwindows
2022-03-29 17:13:47 -04:00
Mike Reeves
053ec81285
Set standalone to load Xwindows
2022-03-29 17:12:25 -04:00
Mike Reeves
853235ca9b
Set standalone to load Xwindows
2022-03-29 17:11:19 -04:00
Mike Reeves
afb918d79c
Set standalone to load Xwindows
2022-03-29 17:08:03 -04:00
m0duspwnens
7a4d93f09b
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 15:44:05 -04:00
Jason Ertel
b2a96fab7e
merge
2022-03-29 14:07:20 -04:00
Jason Ertel
d2bf6d5618
Add build script to help pre-validate analyzers before pushing
2022-03-29 14:04:23 -04:00
Jason Ertel
484ef4bc31
Ensure generated python files are not pushed to version control
2022-03-29 13:51:12 -04:00
Jason Ertel
cb491630ae
Analyzer CI
2022-03-29 13:40:56 -04:00
Jason Ertel
0a8d24a225
Add automated CI for analyzers
2022-03-29 13:10:04 -04:00
Mike Reeves
3ace55dfe5
Add initial analyst install code
2022-03-29 12:49:30 -04:00
Mike Reeves
102d2507cb
Add initial analyst install code
2022-03-29 12:48:52 -04:00
Mike Reeves
0d23688aa0
Add initial analyst install code
2022-03-29 12:46:45 -04:00
Mike Reeves
80af497f95
Add initial analyst install code
2022-03-29 12:43:20 -04:00
Mike Reeves
990470a765
Add initial analyst install option to so-setup
2022-03-29 10:41:45 -04:00
Josh Patterson
f5095b273d
Merge pull request #7665 from Security-Onion-Solutions/workstation_state
...
Workstation state
2022-03-29 10:27:07 -04:00
m0duspwnens
e3f3af52e1
fix spacing
2022-03-29 10:19:29 -04:00
m0duspwnens
2f489895ef
top match and remove_gui state
2022-03-29 10:17:21 -04:00
weslambert
7f7eaf173b
Merge pull request #7663 from Security-Onion-Solutions/fix/strelka_fw
...
Add strelka_frontend to heavynode, sensor, and standalone role FW por…
2022-03-28 16:14:25 -04:00
weslambert
6004dde54a
Add strelka_frontend to heavynode, sensor, and standalone role FW portgroups
2022-03-28 16:05:07 -04:00
Jason Ertel
c23b87965f
Merge branch 'dev' into kilo
2022-03-28 15:53:33 -04:00
Jason Ertel
deb9b0e5ef
Add analyze feature
2022-03-28 15:53:24 -04:00
m0duspwnens
0ddfaf8d74
changes for workstation
2022-03-28 15:34:15 -04:00
weslambert
fb7160cba5
Merge pull request #7644 from Security-Onion-Solutions/fix/syslog_pr_adjustment
...
Update with changes from Abe's PR and other fixes
2022-03-25 13:59:20 -04:00
weslambert
e6599cd10e
Update with changes from Abe's PR and other fixes
2022-03-25 13:57:44 -04:00
weslambert
c02d7fab50
Merge pull request #7636 from Security-Onion-Solutions/feature/rita
...
Parsing of RITA Logs
2022-03-24 13:05:22 -04:00
weslambert
fbc86f43ec
Add exclude filter for logs for when there are no results from analysis
2022-03-24 13:03:03 -04:00
weslambert
4c93217aac
Merge pull request #7635 from Security-Onion-Solutions/fix/process_mappings_keyword
...
Additional .keyword shims for process mappings
2022-03-24 12:53:16 -04:00
Wes Lambert
fe1b72655b
Additional .keyword shims for process mappings
2022-03-24 16:45:06 +00:00
m0duspwnens
293de159db
fix package names
2022-03-24 11:33:16 -04:00
m0duspwnens
7cfc52da8a
fix include
2022-03-24 10:02:25 -04:00
m0duspwnens
a0841ee7a7
workstation state
2022-03-24 09:57:58 -04:00
weslambert
5160a55dcf
Merge pull request #7629 from Security-Onion-Solutions/fix/roles_load_check_cluster_health
...
Check ES cluster health before trying to load roles
2022-03-23 11:07:24 -04:00
weslambert
1f2bca599f
Check cluster health before trying to load roles for ES
2022-03-23 11:00:26 -04:00
Wes Lambert
8a56c88773
Adjust log file paths
2022-03-22 17:51:17 +00:00
Wes Lambert
57f01c70ec
Remove extra forward slash in log path
2022-03-22 17:45:23 +00:00
Wes Lambert
2487d468ab
Add RITA Elasticsearch ingest pipeline config
2022-03-22 17:38:22 +00:00
Wes Lambert
f613d8ad86
Add RITA Logstash config
2022-03-22 17:36:18 +00:00
weslambert
bb9d6673ec
Fix casing
2022-03-21 12:38:50 -04:00
weslambert
9afa949623
Don't rotate Filebeat log on startup
2022-03-21 12:38:12 -04:00
weslambert
b2c26807a3
Add xpack.reporting.kibanaServer.hostname to defaults file
2022-03-21 09:30:25 -04:00
Wes Lambert
faeaa948c8
Remove extra Salt logic and clean up output format of resultant script
2022-03-19 04:31:48 +00:00
Wes Lambert
1a6ef0cc6b
Re-enable FB module load
2022-03-19 03:55:40 +00:00
Wes Lambert
a18b38de4d
Update so-filebeat-module-setup to use new load style to avoid having to explicitly enabled filesets
2022-03-19 03:54:41 +00:00
Wes Lambert
2e7d314650
Remove Cyberark module
2022-03-19 03:43:55 +00:00
Wes Lambert
c97847f0e2
Remove Threat Intel Recored Future fileset
2022-03-19 03:43:34 +00:00
Wes Lambert
59a2ac38f5
Disable FB module load for now
2022-03-18 22:12:09 +00:00
Wes Lambert
543bf9a7a7
Update Kibana version to 8
2022-03-18 22:07:21 +00:00
Wes Lambert
d111c08fb3
Update Curator commands with new Filebeat module variables
2022-03-18 21:45:33 +00:00
Doug Burks
a3f8a10eb9
Merge pull request #7608 from Security-Onion-Solutions/fix/telegraf-non-root
...
FIX: Run telegraf as non-root #7468
2022-03-18 15:17:28 -04:00
weslambert
a9ea99daa8
Switch from so_elastic user to so_kibana user for Elastic 8
2022-03-18 15:09:50 -04:00
weslambert
cb0d4acd57
Remove X-Pack ML entry for Elastic 8
2022-03-18 14:46:28 -04:00
Doug Burks
eda7a8d7ea
FIX: Update telegraf influxdbsize.sh to collect influxdb size from influxdb_size.log #7468
2022-03-18 13:15:43 -04:00
Doug Burks
f7dc5588ae
FIX: Update common init.sls to create cron job to write influxdb size for telegraf #7468
2022-03-18 13:13:46 -04:00
Doug Burks
c13994994b
FIX: Update telegraf init.sls to run telegraf as non-root #7468
2022-03-18 13:11:56 -04:00
weslambert
e0374be4aa
Update version from 7.16.2 to 8.1.0 for Kibana config
2022-03-18 11:57:33 -04:00
weslambert
6f294cc0c2
Change Kibana user role from superuser to kibana_system for Elastic 8
2022-03-18 11:54:08 -04:00
weslambert
5ec5b9a2ee
Remove older module config files
2022-03-18 10:14:13 -04:00
weslambert
c659a443b0
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:25:10 -04:00
weslambert
99430fddeb
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:24:39 -04:00
weslambert
7128b04636
Remove indices.query.bool.max_clause_count because it is dynamically allocated in Elastic 8
2022-03-17 21:20:41 -04:00
weslambert
712a92aa39
Switch from log input to filestream input
2022-03-17 21:18:03 -04:00
Wes Lambert
6e2aaa0098
Clean up original map file
2022-03-17 21:08:57 +00:00
Wes Lambert
09892a815b
Add back bind mounts and remove THIRDPARTY
2022-03-17 21:06:07 +00:00
Wes Lambert
a60ef33930
Reorganize FB module management
2022-03-17 21:01:03 +00:00
Josh Patterson
949365c636
Merge pull request #7602 from Security-Onion-Solutions/issue/7601
...
prevent so-setup iso from running on ubuntu
2022-03-17 11:37:53 -04:00
m0duspwnens
a896348743
prevent so-setup iso from running on ubuntu - https://github.com/Security-Onion-Solutions/securityonion/issues/7601
2022-03-17 11:31:16 -04:00
Josh Brower
5b9c82a434
Merge pull request #7494 from Security-Onion-Solutions/fix/fleetdm-custom-hostname
...
Force regen of ssl cert
2022-03-16 15:17:05 -04:00
Doug Burks
50477071b8
Merge pull request #7588 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-03-16 13:54:00 -04:00
Doug Burks
e65f2a5513
FIX: Prevent multiple instances of so-sensor-clean #6622
2022-03-16 13:28:39 -04:00
Doug Burks
e56f90d83c
FIX: Prevent multiple instances of so-playbook-sync #6622
2022-03-16 13:27:37 -04:00
weslambert
aaded58131
Merge pull request #7565 from Security-Onion-Solutions/fix/es_template_fix
...
Custom ES template fixes
2022-03-15 11:09:46 -04:00
Doug Burks
9bf0265cea
Merge pull request #7566 from Security-Onion-Solutions/feature/hunt-soc-auth
...
FEATURE: Add new Hunt query for SOC logins #7327
2022-03-15 10:58:40 -04:00
Mike Reeves
e01c1398d5
Merge pull request #7564 from Security-Onion-Solutions/removethehive
...
Removethehive
2022-03-15 10:56:08 -04:00
Wes Lambert
42d6c3a956
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
2022-03-15 14:55:04 +00:00
Doug Burks
eec44a6b02
Add a SOC Auth query to hunt.queries.json
2022-03-15 10:38:46 -04:00
Doug Burks
d1e1887e36
Add support for Kratos audit logs in hunt.eventfields.json
2022-03-15 10:37:58 -04:00
Wes Lambert
5f56c7a261
Replace ELASTICCURL with so-elasticsearch-query
2022-03-15 14:32:00 +00:00
weslambert
d46620ea2a
Merge pull request #7561 from Security-Onion-Solutions/es_template_map_fix
...
Custom ES Template Fixes
2022-03-15 10:01:42 -04:00
Jason Ertel
408f9d6695
Update .gitleaks.toml
2022-03-15 09:53:27 -04:00
Jason Ertel
b810f14428
Update .gitleaks.toml
2022-03-15 09:53:11 -04:00
Jason Ertel
cec9cba40e
Create .gitleaks.toml
2022-03-15 09:47:57 -04:00
Jason Ertel
8ebeeb497f
add configuration to override leak detector defaults
2022-03-15 09:43:09 -04:00
Mike Reeves
9c80ff4f65
Remove hive from more files
2022-03-15 09:37:58 -04:00
Mike Reeves
81f0aa58b8
Remove hive from more files
2022-03-15 08:28:03 -04:00
Doug Burks
63cef4daff
Merge pull request #7557 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: surilogcompress cron job not running
2022-03-15 07:41:05 -04:00
Doug Burks
db4f138a78
FIX: surilogcompress cron job not running
...
The suricata user was originally created with `/opt/so/conf/suricata` as its home directory. I think at some point we changed permissions on `/opt/so/conf` and at that point the `surilogcompress` cron job stopped working. Changing the home directory to `/nsm/suricata` works on all of my PROD systems (including Ubuntu and CentOS).
For more information, please see:
https://github.com/Security-Onion-Solutions/securityonion/issues/7133
2022-03-15 07:10:02 -04:00
Mike Reeves
b5b60af16f
Remove hive from so-user
2022-03-14 15:06:07 -04:00
Mike Reeves
b83fec6fd2
More hive remova
2022-03-14 14:51:39 -04:00
Mike Reeves
ff30f572d7
Remove thehive from image common
2022-03-14 10:40:41 -04:00
Mike Reeves
95195c07fc
Disable hive in automation files
2022-03-14 10:36:23 -04:00
Jason Ertel
16f673d956
Merge pull request #7541 from Security-Onion-Solutions/kilo
...
Add assignee field to case list
2022-03-14 08:49:46 -04:00
Jason Ertel
5a28725def
Add assignee to case list
2022-03-14 08:45:28 -04:00
Wes Lambert
ba24f75893
Fix index typo
2022-03-11 18:11:16 +00:00
Wes Lambert
70ed20f691
Add new sls file for custom ES index templates
2022-03-11 18:07:23 +00:00
Wes Lambert
d12ff503c2
Chage role loading verbiage
2022-03-11 16:23:19 +00:00
Wes Lambert
dc258cf043
Load custom component templates in so-elasticsearch-templates-load
2022-03-11 16:22:55 +00:00
Wes Lambert
8e43a6e571
Don't generate index template if index_template definition is not present in pillar
2022-03-11 16:22:06 +00:00
m0duspwnens
e1e8a20e11
make sure values exist in data structure
2022-03-10 17:09:00 -05:00
Josh Brower
f0e44827a5
rm extra line
2022-03-10 08:48:46 -05:00
Josh Brower
814e16ba95
Force regen of ssl cert
2022-03-10 08:47:26 -05:00
Mike Reeves
7ca06df66f
Merge pull request #7484 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-03-09 14:50:52 -05:00
Mike Reeves
6f15acd2f9
Update VERSION
2022-03-09 14:50:14 -05:00
Mike Reeves
3725130128
Merge pull request #7481 from Security-Onion-Solutions/dev
...
2.3.110
2022-03-09 14:44:40 -05:00
Mike Reeves
2c66fa1883
Merge pull request #7482 from Security-Onion-Solutions/kilo
...
Merge master with .100 hotfix #3 into dev
2022-03-09 12:24:04 -05:00
Jason Ertel
61a3155dfa
merge from master
2022-03-09 12:22:24 -05:00
Mike Reeves
99f25deb80
Merge pull request #7480 from Security-Onion-Solutions/2.3.110rel
...
2.3.110
2022-03-09 12:16:31 -05:00
Mike Reeves
0cb628f565
2.3.110
2022-03-09 12:12:32 -05:00
weslambert
262e68cb75
Merge pull request #7469 from Security-Onion-Solutions/fix/kibana_config_load_template
...
Add .template extension to ensure we are loading the template and not the resultant file
2022-03-08 21:12:29 -05:00
weslambert
c83b63d0d8
Add .template extension to load template file
2022-03-08 20:53:16 -05:00
weslambert
8d9ddf5f1b
Add .template extension to load template
2022-03-08 20:52:13 -05:00
weslambert
8115da358f
Add .template extension to load template file
2022-03-08 20:51:50 -05:00
Doug Burks
06efef7b81
Merge pull request #7467 from Security-Onion-Solutions/dougburks-patch-1
...
Revert security_opt addition in telegraf init.sls
2022-03-08 18:51:52 -05:00
Doug Burks
b76c01ef53
Revert security_opt addition in telegraf init.sls
2022-03-08 18:27:15 -05:00
weslambert
5f3c29b7f8
Merge pull request #7466 from Security-Onion-Solutions/fix/process_name_keyword
...
Add process.name.keyword
2022-03-08 12:47:31 -05:00
weslambert
65f998d6f7
Remove process.name.keyword for future-proofing
2022-03-08 12:44:51 -05:00
weslambert
406267a892
Add process.name.keyword
2022-03-08 12:42:34 -05:00
weslambert
d9c3160fbf
Merge pull request #7465 from Security-Onion-Solutions/fix/kibana_saved_objects_load
...
Kibana dashboard/saved objects loading improvements
2022-03-08 12:22:55 -05:00
Wes Lambert
d392cb258c
Switch Kibana state to kibana.so_savedobjects_defaults in top file
2022-03-08 16:59:48 +00:00
Wes Lambert
86e228b200
Add .template extension for future-proofing config files
2022-03-08 16:58:37 +00:00
Wes Lambert
a6fd1023b4
Fix criteria for successful execution
2022-03-08 16:57:26 +00:00
Wes Lambert
3f31f7fd41
Add .template extension to fix script behavior and not modify watched file
2022-03-08 16:43:43 +00:00
Jason Ertel
f64da9632f
Merge pull request #7461 from Security-Onion-Solutions/kilo
...
Gracefully handle situations where another process is using the Kratos DB while so-user executes
2022-03-08 11:02:14 -05:00
Jason Ertel
0cec5879bb
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:55:26 -05:00
Jason Ertel
d8ca4976be
Merge branch 'dev' into kilo
2022-03-08 10:41:40 -05:00
Jason Ertel
914d81ca07
Revert "Gracefully handle situations when another process is using the Kratos DB"
...
This reverts commit f2865d8b7f .
2022-03-08 10:40:20 -05:00
Jason Ertel
f2865d8b7f
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:38:05 -05:00
Wes Lambert
28554164cd
Remove drop file when securitySolution saved objects change
2022-03-08 14:39:23 +00:00
Wes Lambert
14dddd8649
Remove drop file when config saved objects change
2022-03-08 14:37:15 +00:00
Wes Lambert
c0f49f6fb0
Remove drop file when dashbaord saved objects change
2022-03-08 14:35:04 +00:00
Wes Lambert
d10d4acf9f
Modify Kibana config load script to drop file if successfully executed
2022-03-08 14:33:15 +00:00
Doug Burks
da8e885ede
Merge pull request #7451 from Security-Onion-Solutions/fix/docker-apparmor
...
Update init.sls to avoid telegraf apparmor issues
2022-03-07 17:06:42 -05:00
Doug Burks
104de2a3c9
Update init.sls to avoid telegraf apparmor issues
...
See #2560
2022-03-07 16:11:22 -05:00
Mike Reeves
fb59421f5b
Merge pull request #7446 from Security-Onion-Solutions/fixpipelineload
...
Only load pipelines on change
2022-03-07 15:17:32 -05:00
weslambert
e2bda255cc
Merge pull request #7447 from Security-Onion-Solutions/fix/es_templates_soup
...
Remove old Elasticsearch index templates during SOUP
2022-03-07 15:10:44 -05:00
Mike Reeves
4eb37fd5a9
Update init.sls
2022-03-07 15:09:36 -05:00
Wes Lambert
fa9be58b23
Specify index templates
2022-03-07 20:04:23 +00:00
Wes Lambert
647b316a96
Remove old ES index templates
...
Signed-off-by: Wes Lambert <wlambertts@gmail.com >
2022-03-07 20:02:45 +00:00
Mike Reeves
d33db6fb23
Only load pipelines on change
2022-03-07 14:25:46 -05:00
weslambert
eac120f4c2
Merge pull request #7444 from Security-Onion-Solutions/fix/dtc_client_override
...
Add DTC client mappings
2022-03-07 13:38:19 -05:00
Wes Lambert
c549b20221
Add DTC client mappings
2022-03-07 18:36:26 +00:00
Mike Reeves
e6132be4e6
Merge pull request #7443 from Security-Onion-Solutions/fixtemplates
...
Only load templates on change
2022-03-07 10:42:51 -05:00
Mike Reeves
c67604590d
Only load templates on change
2022-03-07 09:52:18 -05:00
weslambert
5600b55f05
Merge pull request #7427 from Security-Onion-Solutions/fix/syslog_kibana_viz
...
Replace syslog facility and severity with label fields in Kibana syslog dashboard
2022-03-07 08:14:35 -05:00
Doug Burks
a59779905f
Merge pull request #7437 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo
2022-03-07 08:05:07 -05:00
Doug Burks
848a5c6350
fix typo
2022-03-07 08:03:41 -05:00
Wes Lambert
33ba45472f
Replace syslog facility and severity with label fields
2022-03-04 21:40:41 +00:00
weslambert
ee4035f022
Merge pull request #7426 from Security-Onion-Solutions/fix/syslog_zeek
...
Change to label fields for syslog facility and severity
2022-03-04 16:31:45 -05:00
weslambert
f71ccadb8a
Change to label fields for Zeek syslog
2022-03-04 16:29:55 -05:00
weslambert
fc3273fa49
Change to label fields to comply with what's defined in Filebeat template
2022-03-04 16:29:01 -05:00
weslambert
3148fa0e06
Merge pull request #7422 from Security-Onion-Solutions/fix/syslog_dot_keyword
...
.keyword additions and increase max_clause_count
2022-03-04 15:32:29 -05:00
weslambert
254cf53c2f
Increase clause count to 3500
2022-03-04 10:36:37 -05:00
Wes Lambert
ffae22beef
Add DTC syslog mappings for .keyword and add refs to defaults.yml
2022-03-04 13:04:11 +00:00
weslambert
93c2f82345
Merge pull request #7413 from Security-Onion-Solutions/fix/add_keyword_subfield
...
Add .keyword subfield for more mappings
2022-03-03 10:42:38 -05:00
Wes Lambert
1f71816ad7
Add keyword subfield for DTC winlog mappings
2022-03-03 14:54:30 +00:00
Wes Lambert
1c086e36da
Add missing comma for file mappings
2022-03-03 13:49:54 +00:00
Wes Lambert
aa8d24b6cd
Add DTC destination, source, and winlog mapping references to templates in defaults file
2022-03-03 13:42:20 +00:00
Wes Lambert
85979cbce8
Add file, process, and winlog mapping changes
2022-03-03 13:37:27 +00:00
Wes Lambert
8f97f09c9c
Additional .keyword changes for host.hostname client.address, and event.action
2022-03-02 21:54:46 +00:00
Wes Lambert
3ee46e4c29
Add .keyword for destination/source geo.country_name
2022-03-02 21:50:03 +00:00
weslambert
a21060306c
Merge pull request #7404 from Security-Onion-Solutions/fix/field_limit_adjustment
...
Adjust field limit for now due to component template errors
2022-03-02 11:41:35 -05:00
Wes Lambert
c5b16fdf3b
Adjust field limit for now
2022-03-02 16:33:39 +00:00
weslambert
b80e82aaf6
Merge pull request #7396 from Security-Onion-Solutions/fix/dot_security
...
Revert back to usage of .security field
2022-03-02 10:42:29 -05:00
Josh Brower
2ba72791aa
Remove sigma regen cron
2022-03-02 10:31:15 -05:00
Mike Reeves
d570b56c55
Merge pull request #7392 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix 2.3.100 20220301
2022-03-02 10:24:50 -05:00
Mike Reeves
ff4345d3aa
Merge pull request #7393 from Security-Onion-Solutions/jertelhf
...
Jertelhf
2022-03-02 10:20:29 -05:00
Jason Ertel
e59f0d69d9
Merge branch 'master' into jertelhf
2022-03-02 10:18:14 -05:00
Mike Reeves
ad2b69c9de
Merge pull request #7391 from Security-Onion-Solutions/hf0301
...
Hotfix 2.3.100 20220301
2022-03-02 10:08:27 -05:00
Mike Reeves
e874c32c08
Hotfix 2.3.100-20220301
2022-03-02 10:05:41 -05:00
Wes Lambert
ab9b81ea39
Change match_only_text to text for mac in host mappings
2022-03-02 15:01:05 +00:00
Wes Lambert
ed620b93b7
Add custom analyzer definition to all SO/DTC mappings
2022-03-02 14:43:19 +00:00
Wes Lambert
27c8eaa630
Update all other mappings for .security where applicable
2022-03-02 14:39:23 +00:00
Wes Lambert
e925d435ff
Update event, file, and host mappings to include .security
2022-03-02 14:33:52 +00:00
Wes Lambert
496b161253
Update ECS mappings to include .security
2022-03-02 14:27:36 +00:00
Wes Lambert
aae2fd1fbb
Update DNS mappings to include .security
2022-03-02 14:27:15 +00:00
Wes Lambert
0b45cf7ae1
Update base mappings to include .security
2022-03-02 14:25:57 +00:00
Wes Lambert
d89af5f04f
Update agent mappings to include .security
2022-03-02 14:25:14 +00:00
Wes Lambert
2d2ec45029
Modify base ECS mappings to include .security where possible, as well as custom analyzer definition
2022-03-02 14:19:36 +00:00
weslambert
93386f4620
Merge pull request #7389 from Security-Onion-Solutions/fix/revert_text
...
Fix/revert text
2022-03-02 09:17:46 -05:00
Mike Reeves
c0649a863b
Merge pull request #7376 from Security-Onion-Solutions/hfnew
...
Curator Fixes
2022-03-01 14:38:31 -05:00
Mike Reeves
e93dbb5347
Update Hotfix
2022-03-01 14:37:03 -05:00
doug
bbced5b52f
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:52 -05:00
Doug Burks
f134c74585
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:41 -05:00
Wes Lambert
5489b8559d
Revert "Switch from .security to match_only_text"
...
This reverts commit f7862af934 .
2022-03-01 18:44:00 +00:00
Wes Lambert
2a9caccc7c
Revert "Add additional .text subfield mappings"
...
This reverts commit 61dadc6249 .
2022-03-01 18:43:24 +00:00
Doug Burks
adf3dc0cf6
Merge pull request #7370 from Security-Onion-Solutions/fix/syslog
...
Revert syslog pipeline updates from Abe's PR for now
2022-03-01 11:13:13 -05:00
Wes Lambert
a290602a70
Revert syslog pipeline updates from Abe' PR for now
2022-03-01 15:31:07 +00:00
weslambert
4201ee45c6
Merge pull request #7369 from Security-Onion-Solutions/fix/ingest_timestamp
...
Rename ingest timestamp to event.ingested
2022-03-01 10:11:16 -05:00
Wes Lambert
038dc49098
Temporarily increase field limit before trimming efforts
2022-03-01 15:06:28 +00:00
Wes Lambert
dc07adca63
Rename ingest.timestamp to event.ingested
2022-03-01 15:05:08 +00:00
Josh Brower
39718561ce
Merge pull request #7366 from Security-Onion-Solutions/delta
...
Enable state tracking for sigma refresh
2022-03-01 05:53:14 -05:00
Josh Brower
e960d99901
Enable state tracking for sigma refresh
2022-02-28 21:18:41 -05:00
Josh Brower
09f1a5025d
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-28 21:18:07 -05:00
Josh Brower
41a58b791a
Enable state tracking for sigma refresh
2022-02-28 21:17:59 -05:00
Jason Ertel
73b2a36e89
Merge pull request #7365 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.17.1
2022-02-28 18:26:31 -05:00
Jason Ertel
f147bb33ed
Upgrade to ES 7.17.1
2022-02-28 18:18:09 -05:00
Josh Patterson
6b3b5e9a1f
Merge pull request #7363 from Security-Onion-Solutions/soup_singlenode_30
...
allow for check_log_size_limit to work without salt-master running
2022-02-28 17:13:42 -05:00
Josh Brower
f824717094
Merge pull request #7364 from Security-Onion-Solutions/delta
...
IDH Node verbiage
2022-02-28 17:09:08 -05:00
Josh Brower
0cee0d5dea
IDH Node verbiage
2022-02-28 16:47:24 -05:00
Josh Brower
d71bde0e38
Merge pull request #7362 from Security-Onion-Solutions/delta
...
Navigator - include attack json for airgap
2022-02-28 16:33:10 -05:00
Josh Brower
2075412ca2
Navigator - include attack json for airgap
2022-02-28 16:15:30 -05:00
m0duspwnens
a51f833f36
output only the value for log_size_limit
2022-02-28 16:13:43 -05:00
Jason Ertel
04a99a0adc
Merge pull request #7361 from Security-Onion-Solutions/kilo
...
Clear out hotfix file
2022-02-28 16:04:30 -05:00
Jason Ertel
166ac0d194
Clear out hotfix file
2022-02-28 16:01:42 -05:00
m0duspwnens
8d12e136f2
Merge remote-tracking branch 'remotes/origin/dev' into soup_singlenode_30
2022-02-28 15:43:37 -05:00
m0duspwnens
710059211d
remove debug echo, mkdir verbose
2022-02-28 14:54:39 -05:00
weslambert
a1c0ae4aab
Merge pull request #7356 from Security-Onion-Solutions/fix/es_config_load_order
...
Run template load first to prevent issues with pipeline changes that …
2022-02-28 14:50:22 -05:00
m0duspwnens
80e5198f9e
combine local and default pillars to get pillar values locally
2022-02-28 14:35:16 -05:00
m0duspwnens
dc24cb711d
need local to be --local
2022-02-28 13:50:08 -05:00
m0duspwnens
c5bf818049
debug messages and pass local to lookup_salt_value
2022-02-28 13:39:50 -05:00
weslambert
414b9dcd59
Run template load first to prevent issues with pipeline changes that generate new indices
2022-02-28 12:33:18 -05:00
m0duspwnens
cd981fa2ae
forgot then for if
2022-02-28 12:25:06 -05:00
m0duspwnens
278235b0ca
update so-common lookup_salt_value to accept local option. soup get minion id from grains with local option
2022-02-28 12:15:23 -05:00
weslambert
a9caef9596
Merge pull request #7338 from Security-Onion-Solutions/fix/endgame_template
...
Revert Endgame index name changes
2022-02-28 08:13:09 -05:00
Doug Burks
e0b3635318
Merge pull request #7339 from Security-Onion-Solutions/fix/zeek_dns-import
...
Avoid changing _index for imported logs
2022-02-27 05:09:00 -05:00
Doug Burks
32b71fdcac
Avoid changing _index for imported logs
2022-02-26 10:36:09 -05:00
Wes Lambert
bd1b21a5b6
Revert Endgame index name changes
2022-02-26 02:53:57 +00:00
weslambert
56cb8d62ab
Merge pull request #7337 from Security-Onion-Solutions/fix/pb_overrides
...
Fix formatting for PB overrides
2022-02-25 20:48:38 -05:00
weslambert
e942d81433
Ensure correct formatting for source override
2022-02-25 19:14:58 -05:00
weslambert
a511fd33e9
Ensure correct formatting for destination override
2022-02-25 19:14:21 -05:00
Doug Burks
74037e6f00
Merge pull request #7335 from Security-Onion-Solutions/fix/soup-postversion
...
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 15:27:31 -05:00
Josh Brower
25b0069353
Merge pull request #7334 from Security-Onion-Solutions/delta
...
IDH Setup - dont show ssh fix screen
2022-02-25 15:01:25 -05:00
Josh Brower
6a270eb8b3
IDH Setup - dont show ssh fix screen - fix
2022-02-25 14:58:30 -05:00
Josh Brower
ee39ec1882
IDH Setup - dont show ssh fix screen
2022-02-25 14:55:28 -05:00
Doug Burks
8df47e809d
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 14:30:59 -05:00
Mike Reeves
fa15a2e012
Merge pull request #7333 from Security-Onion-Solutions/endgamecurator
...
Fix endgame index name
2022-02-25 13:31:29 -05:00
Mike Reeves
15924ebe0f
Fix endgame index name
2022-02-25 13:29:29 -05:00
weslambert
c95f48e49a
Merge pull request #7330 from Security-Onion-Solutions/fix/pb-override
...
Override destination/source mappings with .keyword for Playbook
2022-02-25 13:07:31 -05:00
Wes Lambert
a8bdff89ae
Move files into SO component template directory
2022-02-25 18:00:16 +00:00
Wes Lambert
08097fe9ec
Add Playbook override mappings
2022-02-25 17:58:51 +00:00
Josh Brower
ce4c859f3a
Merge pull request #7328 from Security-Onion-Solutions/fix/soup-sigma-refresh
...
.110 Post processing - sigma refresh
2022-02-25 12:24:19 -05:00
Josh Patterson
9de9d92b2b
Merge pull request #7329 from Security-Onion-Solutions/delta
...
add extra hosts for filebeat on idh node
2022-02-25 12:23:37 -05:00
m0duspwnens
d76facb1bb
add extra hosts for idh node
2022-02-25 12:21:43 -05:00
Josh Brower
1abf27873d
.110 Post processing - sigma refresh
2022-02-25 12:19:59 -05:00
weslambert
a6ab09501e
Merge pull request #7326 from Security-Onion-Solutions/fix/additional_text_subfield_mappings
...
Add additional .text subfield mappings
2022-02-25 11:29:26 -05:00
Wes Lambert
61dadc6249
Add additional .text subfield mappings
2022-02-25 16:27:37 +00:00
Josh Brower
be80f0530c
Merge pull request #7321 from Security-Onion-Solutions/delta
...
IDH Improvements
2022-02-24 21:27:36 -05:00
Josh Brower
96ed3cb158
IDH - Setup Summary new lines
2022-02-24 20:59:47 -05:00
Josh Brower
4a597b9f0e
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-24 19:58:10 -05:00
Josh Brower
cf7325a546
IDH - Play tweaks, Setup summary, log rotate
2022-02-24 19:57:11 -05:00
Josh Patterson
8302c45059
Merge pull request #7320 from Security-Onion-Solutions/delta_ssh
...
default to false if local role doesnt exist
2022-02-24 18:06:19 -05:00
m0duspwnens
0970bbc983
default to false if local role doesnt exist
2022-02-24 17:55:50 -05:00
Josh Brower
e8e683c2e9
Merge pull request #7319 from Security-Onion-Solutions/delta
...
Add and Update IDH Plays
2022-02-24 15:48:38 -05:00
Josh Brower
fbc702375c
Add and Update IDH Plays
2022-02-24 15:06:04 -05:00
Josh Patterson
5c747fbb4c
Merge pull request #7318 from Security-Onion-Solutions/delta_ssh
...
change name of selinux policy state for idh node
2022-02-24 14:49:55 -05:00
m0duspwnens
8b61d4818d
change name of selinux policy state for idh node
2022-02-24 14:47:14 -05:00
weslambert
22b01dab1e
Merge pull request #7317 from Security-Onion-Solutions/fix/add_text_subfield_to_dtc_mappings
...
Add .text subfield mappings for DTC where fields are defined
2022-02-24 14:47:11 -05:00
Wes Lambert
0f8a39002f
Add .text subfield mappings for DTC where fields are defined
2022-02-24 19:39:52 +00:00
weslambert
5e29c71381
Merge pull request #7315 from Security-Onion-Solutions/fix/split_zeek_dns
...
Split Zeek DNS records into a separate index
2022-02-24 13:21:52 -05:00
weslambert
23fb62c0d6
Split Zeek DNS records into a separate index
2022-02-24 12:52:25 -05:00
weslambert
313487a887
Merge pull request #7313 from Security-Onion-Solutions/fix/kibana_dashboard_load
...
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:48:28 -05:00
weslambert
bc1794e437
Fix function name
2022-02-24 09:42:14 -05:00
Josh Patterson
d7aa413c46
Merge pull request #7314 from Security-Onion-Solutions/delta
...
default port 2222 for ssh idh node
2022-02-24 09:37:11 -05:00
weslambert
45ccfc5ad4
Add back post to .100 and call for .110
2022-02-24 09:35:43 -05:00
weslambert
582bf4c64c
Remove dashboard updates for .100 so we don't run twice
2022-02-24 09:25:59 -05:00
weslambert
7f08ecdcbe
Add function reference for .110 post changes
2022-02-24 09:25:15 -05:00
weslambert
a22e470038
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:20:44 -05:00
weslambert
bc2c1b4ccc
Merge pull request #6935 from abesinger/issue/6912
...
Updated syslog pipeline, resolves #6912 .
2022-02-24 08:33:55 -05:00
Josh Brower
5779e40401
Merge pull request #7308 from Security-Onion-Solutions/defensivedepth-patch-1
...
UC true
2022-02-24 07:48:39 -05:00
Josh Brower
585c275df6
UC true
2022-02-23 19:35:10 -05:00
Josh Brower
babc114d27
Merge branch 'delta' of https://github.com/Security-Onion-Solutions/securityonion into delta
2022-02-23 19:33:18 -05:00
Josh Brower
2bf20bd1f0
UC true
2022-02-23 19:33:10 -05:00
Josh Patterson
a9c6dc32ab
Merge pull request #7305 from Security-Onion-Solutions/delta_ssh
...
allow only manager to connect to ssh port for idh node
2022-02-23 15:17:31 -05:00
m0duspwnens
61ae61953f
allow only manager to connect to ssh port for idh node
2022-02-23 15:14:11 -05:00
weslambert
2aa811dcd2
Merge pull request #7300 from Security-Onion-Solutions/fix/new_es_template_config
...
Add IDH and Kratos index templates
2022-02-23 12:24:38 -05:00
weslambert
6a0ecb9e9c
Add IDH and Kratos index templates
2022-02-23 12:13:46 -05:00
Josh Brower
b7b2183c15
Merge pull request #7296 from Security-Onion-Solutions/delta
...
IDH - Import & Enables Plays
2022-02-23 10:52:37 -05:00
weslambert
00dbf54a5f
Merge pull request #7295 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-functions
2022-02-23 10:50:32 -05:00
Josh Brower
83aa261d88
IDH - Import & Enables Plays
2022-02-23 10:50:13 -05:00
Mike Reeves
c4cc3fa35f
Update so-functions
2022-02-23 10:47:37 -05:00
Josh Brower
0121eda536
Merge pull request #7282 from Security-Onion-Solutions/delta
...
Initial Support - IDH Node
2022-02-23 08:49:40 -05:00
Doug Burks
aadc2a844b
Merge pull request #7284 from Security-Onion-Solutions/fix/so-curator-closed-delete
...
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:40:23 -05:00
doug
1392fc37e8
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:00:52 -05:00
weslambert
9f7612b599
Merge pull request #7283 from Security-Onion-Solutions/fix/match_only_text
...
Switch from .security to using match_only_text with .text
2022-02-22 15:41:29 -05:00
Wes Lambert
f7862af934
Switch from .security to match_only_text
2022-02-22 20:33:49 +00:00
Josh Brower
1d95aca4de
IDH - VNC default port
2022-02-22 14:16:45 -05:00
Josh Brower
99554d5db8
IDH - UDP vs TCP support
2022-02-22 14:10:05 -05:00
Josh Brower
df9fc807a3
IDH - restart scripts, filebeat fix
2022-02-22 08:05:53 -05:00
Josh Brower
3610b0cd30
merge in dev
2022-02-21 16:52:53 -05:00
Josh Brower
eea2b9ccfd
IDH - Play - ssh
2022-02-21 16:43:26 -05:00
Josh Brower
05be776f4b
IDH - so-status
2022-02-21 16:41:36 -05:00
Doug Burks
5b46d19b13
Merge pull request #7273 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:25:58 -05:00
Doug Burks
1abd824c5f
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:00:05 -05:00
Josh Brower
2203e2fedd
IDH - Final setup fixes
2022-02-19 21:01:48 -05:00
Josh Brower
780cd38adf
IDH - setup tweaks
2022-02-19 12:28:45 -05:00
Mike Reeves
fc0e27a7ae
Merge pull request #7261 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update networks.cfg.jinja
2022-02-18 20:03:47 -05:00
Mike Reeves
0d1da5d1dc
Update networks.cfg.jinja
2022-02-18 20:02:50 -05:00
Josh Brower
bf477a1c19
IDH - Initial whiptail
2022-02-18 17:21:04 -05:00
weslambert
3124f2bd12
Merge pull request #7255 from Security-Onion-Solutions/fix/remove_old_templates
...
Remove old index templates
2022-02-18 15:23:07 -05:00
Jason Ertel
380f0ef93a
Merge pull request #7256 from Security-Onion-Solutions/kilo
...
Update password len requirements; clarify password update help
2022-02-18 15:19:08 -05:00
Jason Ertel
93e9548eaf
Require a minimum of 8 characters for passwords, to match Kratos min requirements
2022-02-18 15:14:48 -05:00
Wes Lambert
4d1533537b
Remove old index templates
2022-02-18 20:08:13 +00:00
Josh Brower
0362afb260
IDH - Finalize Firewall config
2022-02-18 13:23:48 -05:00
Josh Patterson
d14967dd45
Merge pull request #7251 from Security-Onion-Solutions/issue/7233
...
dont allow $ to be used for elasticsearch:auth or kibana:secrets
2022-02-18 13:22:22 -05:00
m0duspwnens
cb55af4c1c
dont allow $ to be used for elasticsearch:auth or kibana:secrets - https://github.com/Security-Onion-Solutions/securityonion/issues/7233
2022-02-18 13:13:56 -05:00
weslambert
87a5e64f12
Merge pull request #7249 from Security-Onion-Solutions/fix/component_index_association
...
Update component -> index association for file/scan mappings for Strelka
2022-02-18 12:19:41 -05:00
Josh Brower
8de5a054d4
Merge pull request #7248 from Security-Onion-Solutions/feature/kratos-log-ingest
...
Ingest Kratos logs
2022-02-18 11:56:20 -05:00
William Wernert
786b01c85a
Merge pull request #6496 from JamesMConroy/so-staus-tty
...
so-staus detects tty
2022-02-18 11:52:18 -05:00
Josh Brower
118277ebc5
Ingest Kratos logs
2022-02-18 11:49:02 -05:00
Mike Reeves
27299cbe1b
Merge pull request #7247 from christopherwoodall/patch-7
...
Update so-setup
2022-02-18 11:47:19 -05:00
Christopher Woodall
118266bf5f
Update so-setup
...
Patch so setup to ignore deprecation warnings.
2022-02-18 11:38:56 -05:00
Mike Reeves
5d949de146
Merge pull request #7246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update networks.cfg.jinja
2022-02-18 11:28:57 -05:00
Mike Reeves
6f4ee4123a
Update networks.cfg.jinja
2022-02-18 11:26:58 -05:00
Mike Reeves
e4148818d8
Merge pull request #7226 from Security-Onion-Solutions/zeekhn
...
Add Zeek Homenet in networks.cfg
2022-02-18 11:11:56 -05:00
Mike Reeves
becdc34677
Merge pull request #7227 from hacker0ni/patch-1
...
Allow downgrades in docker_install
2022-02-18 11:10:26 -05:00
Mike Reeves
95eab61615
Rename to the .jinja standard
2022-02-18 11:06:33 -05:00
Mike Reeves
9341669a15
Merge pull request #7244 from christopherwoodall/patch-6
...
Update config.map.jinja
2022-02-18 09:57:33 -05:00
Jason Ertel
fdc63b5816
Clarify so-user update usage/help
2022-02-18 09:41:09 -05:00
Christopher Woodall
eaff6a12de
Update config.map.jinja
...
Extend the array instead of appending.
2022-02-18 08:50:28 -05:00
weslambert
6ee3287d2d
Update component -> index association for file/scan mappings for Strelka
2022-02-18 08:12:34 -05:00
James Conroy
91c207cd38
Update salt/common/tools/sbin/so-status
...
Removed # {% raw %} from line 170
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:43 -06:00
James Conroy
b774e62dfa
Update salt/common/tools/sbin/so-status
...
Add salt raw directive
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:25 -06:00
Josh Brower
f995d0768f
IDH - Initial firewall support
2022-02-17 15:54:20 -05:00
Doug Burks
3b887c7b1a
Merge pull request #7239 from Security-Onion-Solutions/dougburks-patch-1
...
so-ip-update needs to queue the Kibana dashboard update
2022-02-17 15:54:10 -05:00
Doug Burks
b4b7938ce2
so-ip-update needs to queue the Kibana dashboard update in case a salt operation is already running
2022-02-17 15:47:33 -05:00
Doug Burks
e5d7c1c77a
Merge pull request #7238 from Security-Onion-Solutions/dougburks-patch-1-1
...
so-ip-update needs to update Kibana dashboards
2022-02-17 14:53:31 -05:00
Doug Burks
1a96162966
so-ip-update needs to update Kibana dashboards
2022-02-17 14:49:55 -05:00
hacker0ni
bc72b3da91
Allow downgrades in docker_install
...
When running the installer again on a new node, it tries to pull the docker packages but since the installer ran again before, the install command fails on Ubuntu 18.04 stating that the `--allow-downgrades` is not specified in the command. This change adds that to circumvent the issue.
2022-02-17 11:47:36 -05:00
Mike Reeves
3e194c9b4b
Walk the homenet for zeek
2022-02-17 11:33:22 -05:00
Josh Brower
6c124733b5
IDH - Enable default states
2022-02-17 10:50:26 -05:00
weslambert
6842099e11
Merge pull request #7224 from Security-Onion-Solutions/fix/zeek_viz
...
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 10:05:46 -05:00
Wes Lambert
5c1f61bda8
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 15:03:46 +00:00
weslambert
53c7ad6041
Merge pull request #7223 from Security-Onion-Solutions/fix/shard_settings_setup
...
Ensure setup configures pillar correctly for index settings
2022-02-17 09:48:11 -05:00
Josh Brower
ef4df58510
IDH - Jinjafy hostname
2022-02-17 09:00:57 -05:00
weslambert
c0f9cb188b
Add missing colon
2022-02-17 07:58:05 -05:00
weslambert
d309c4fc0a
Update pillar structure for index_settings/shards
2022-02-17 07:10:29 -05:00
Jason Ertel
cb9712aa08
Merge pull request #7217 from Security-Onion-Solutions/kilo
...
MFA
2022-02-16 16:47:40 -05:00
weslambert
d084625ee0
Merge pull request #7218 from Security-Onion-Solutions/fix/composable_templates_soup
...
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:24:57 -05:00
weslambert
e71b606dd6
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:22:06 -05:00
weslambert
f1f9322bee
Merge pull request #7216 from Security-Onion-Solutions/fix/es_template_netflow_mappings_indent
...
Fix indent for so-netflow component template references
2022-02-16 14:47:31 -05:00
weslambert
185ea2fd99
Fix indent for so-netflow component template references
2022-02-16 14:46:12 -05:00
Mike Reeves
89eb2d0a8b
Add netowrks.cfg to Zeek
2022-02-16 14:24:58 -05:00
Jason Ertel
2c4ba75c0c
Merge branch 'dev' into kilo
2022-02-15 17:05:24 -05:00
weslambert
9e222b1464
Merge pull request #7206 from Security-Onion-Solutions/feature/template-reorg
...
Re-organize Elasticsearch Index Templates
2022-02-15 16:50:14 -05:00
Josh Brower
3ccef12df7
IDH - Pillarize OpenCanary Config
2022-02-15 13:57:31 -05:00
Wes Lambert
4fa3749418
Remove bind or ES templates
2022-02-15 18:08:03 +00:00
Wes Lambert
786a189f65
Merge branch 'feature/template-reorg' of https://github.com/security-onion-solutions/securityonion into feature/template-reorg
2022-02-15 17:06:02 +00:00
Wes Lambert
de731fc05d
Remove default templates from ES template pillar since they are now managed in the defaults file.
2022-02-15 17:04:57 +00:00
Wes Lambert
3df58eadd1
Modify logic to include custom templates
2022-02-15 17:00:24 +00:00
weslambert
1a53ec4372
Fix malformed copy/paste
2022-02-15 11:14:10 -05:00
Wes Lambert
dce3b7a874
Update defaults file to include ES index templates
2022-02-15 15:53:07 +00:00
Jason Ertel
377fe1987d
Merge branch 'dev' into kilo
2022-02-15 07:49:26 -05:00
Jason Ertel
d97423e9f8
Enable MFA support
2022-02-15 07:49:12 -05:00
Wes Lambert
8e389bf6e5
Add ES template map file
2022-02-14 15:38:32 +00:00
Wes Lambert
ebce67060f
Initial template refactor
2022-02-14 15:20:33 +00:00
James Conroy
a43ac2aea2
Move the jinja endraw directive below is_tty
...
This will prevent jninja from interpreting the shell string length
expansion as the start of jninja comments
2022-02-12 12:25:24 -06:00
James Conroy
95b4f7b4ef
Update the PADDING_CONSTENT to 15
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3046e811f0
Use spaces to define centerd justification output
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
6a1e586b8c
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
01346cbb06
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3adb6c1389
Renamed colors to attributes
...
Also correctly used tput to assign blue color
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dabae3888f
Renamed colors to attributes
...
As suggested by rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
c69e968790
Renamed Colors to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dfcabb5722
Seperate bold attribute from colors
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
b9b3876069
Exit with an error code if the user isn't root
2022-02-12 12:25:23 -06:00
James Conroy
bfcfad2e7d
Check for tty in main
...
So that the value is set every time it is checked
2022-02-12 12:25:23 -06:00
James Conroy
163182c858
Don't set the padding constant if not in a tty
...
This will preserve the original width from before my changes
2022-02-12 12:25:23 -06:00
James Conroy
6b4549499d
Don't split lines after standalone tests
...
This is to make the formatting consistent with the rest of the scripts
2022-02-12 12:25:23 -06:00
James Conroy
68a5826d70
Always print a line of '-'
...
Even when not printing to a tty
This is behavior preferred by the team
2022-02-12 12:25:22 -06:00
James Conroy
daa73c8845
Removed MYNAME variable
...
Preferring to just use the value of $0 instead
2022-02-12 12:25:22 -06:00
James Conroy
7f694c17ed
Revert improvements to usage function
...
Made to make it more consistent with the rest of the scripts in
Security Onion
2022-02-12 12:25:22 -06:00
James Conroy
fd9a03a77f
Added Changes Suggested by Reviewer
...
Added a missing semi colon between a local variable's declaration and
assignment
Removed an unused return value
Made a TODO more descriptive
2022-02-12 12:25:22 -06:00
James Conroy
2993a20947
Moved line declaration out of tty conditional
...
This way it will always be set to ""
2022-02-12 12:25:22 -06:00
James Conroy
ac5527e1ab
Added Comments for future enhancements
2022-02-12 12:25:22 -06:00
James Conroy
715f9da6e2
Reworked tty detection and status printing
...
I was able to reduce the line count and make the script more reliable
2022-02-12 12:25:22 -06:00
James Conroy
caa06b026f
Refactored to reduce length and number of lines
2022-02-12 12:25:21 -06:00
James Conroy
a048de65ca
Print help message if not running as root
2022-02-12 12:25:21 -06:00
James Conroy
f807471a17
Only print color codes if we're printing to a tty
...
If we're not printing to a tty the escape sequences can only clutter the
screen.
Also removed a redundant function to print lines if not printing to a
tty. It was only called if docker wasn't running, not if the output
wasn't a tty.
2022-02-12 12:25:21 -06:00
James Conroy
81122d0693
Updated the useage function to use printf
...
Using a hear doc means we have to exactly specify the formatting. Useing
printf handles formatting for us
2022-02-12 12:25:21 -06:00
Josh Brower
1e5b9ef0bf
IDH - Enable Filebeat
2022-02-10 11:37:10 -05:00
Josh Brower
b66472eced
IDH - disable nginx
2022-02-09 14:56:56 -05:00
Josh Brower
f31fbbf1ed
IDH - states allowed
2022-02-09 13:57:18 -05:00
William Wernert
1fee5e6a60
Merge pull request #7162 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Also merge CONTRIBUTING.md changes to dev
2022-02-09 11:59:00 -05:00
William Wernert
bc5fa55ecd
Merge pull request #7160 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Update CONTRIBUTING.md
2022-02-09 11:49:52 -05:00
William Wernert
2e2eed9f42
PR's -> pull requests
2022-02-09 11:45:12 -05:00
William Wernert
3f83191083
Update CONTRIBUTING.md
2022-02-09 11:34:39 -05:00
Josh Brower
30c40ed3d7
IDH Initial Support
2022-02-09 10:37:47 -05:00
Mike Reeves
d63fe73c90
Merge pull request #7157 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update to 7.17.0
2022-02-09 09:46:25 -05:00
Mike Reeves
51bd266717
Update to 7.17.0
2022-02-09 09:44:28 -05:00
weslambert
380fa7d0c8
Merge pull request #7153 from Security-Onion-Solutions/fix/dtc_event_mappings
...
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 16:36:49 -05:00
Wes Lambert
9b841fd872
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 21:34:32 +00:00
weslambert
c216457a3e
Merge pull request #7147 from Security-Onion-Solutions/fix/ct_snyk
...
Add Snyk component template
2022-02-08 10:25:27 -05:00
Wes Lambert
c2c4e4df17
Add Snyk component template
2022-02-08 15:23:43 +00:00
weslambert
7be1549d41
Merge pull request #7146 from Security-Onion-Solutions/feature/additional_dtc_ct
...
Additional component templates
2022-02-08 10:12:31 -05:00
Josh Brower
ac8e06e79b
Initial support - IDH Node
2022-02-08 09:08:52 -05:00
Josh Brower
a3602c9eb9
Initial support - IDH Node
2022-02-08 08:24:15 -05:00
Wes Lambert
f9a50d33c3
Add new templates
2022-02-08 13:17:23 +00:00
Wes Lambert
2951e12c96
Remove snyk component template for now and fix folder structure
2022-02-08 13:16:59 +00:00
Wes Lambert
6d0ca6fcbb
Fix mangled key name/typo
2022-02-08 12:59:07 +00:00
Wes Lambert
2dd5db15b6
Add component and index template listing scripts
2022-02-08 03:40:42 +00:00
Wes Lambert
5090854d4d
Add additional component templates and index template references
2022-02-08 03:03:55 +00:00
Josh Brower
37b17b8821
Initial support - IDH Node
2022-02-07 19:27:51 -05:00
Josh Brower
f590bc43a6
Initial support - IDH Node
2022-02-07 19:09:27 -05:00
Josh Brower
7a9cb6d110
Initial support - IDH Node
2022-02-07 16:49:11 -05:00
weslambert
b41c5439c6
Merge pull request #7141 from Security-Onion-Solutions/fix/index_template_mapping_reference
...
Add mapping references for new component templates to index templates
2022-02-07 15:06:19 -05:00
Wes Lambert
1366e5288e
Add mappings references for new component templates to index templates
2022-02-07 19:54:23 +00:00
weslambert
f9196a8228
Merge pull request #7140 from Security-Onion-Solutions/feature/dtc_new_mappings
...
New DTC/Component Template Mappings
2022-02-07 14:47:07 -05:00
Wes Lambert
03bfb052ed
Add component templates for Elasticsearch, Kibana, Logstash, Netflow, Suricata, and Zeek
2022-02-07 19:42:24 +00:00
Josh Brower
9b1fac8417
Initial support - IDH Node
2022-02-07 14:36:40 -05:00
weslambert
c9b40d8569
Merge pull request #7136 from Security-Onion-Solutions/feature/so_es_indices_list_sort
...
Sort index listing alphabetically and add header
2022-02-07 09:34:58 -05:00
Wes Lambert
50215c550b
Sort index listing alphabetically and add header (@gebhard73)
2022-02-07 14:31:42 +00:00
Josh Patterson
ee17064585
Merge pull request #7122 from Security-Onion-Solutions/soup_docker_iso
...
Soup docker iso
2022-02-07 09:29:35 -05:00
Josh Patterson
e0c0eba24e
Update soup
2022-02-07 09:23:30 -05:00
Josh Patterson
7d09d1f7e2
Update soup
2022-02-07 09:22:43 -05:00
Mike Reeves
77fc9df448
Merge pull request #7134 from Security-Onion-Solutions/mastermerger
...
Mastermerger
2022-02-07 08:38:27 -05:00
Mike Reeves
abd121733f
Merge branch 'master' into mastermerger
2022-02-07 08:34:17 -05:00
m0duspwnens
7c31eb1288
mount iso at different point
2022-02-04 16:07:06 -05:00
m0duspwnens
780aace854
set AGDOCKER
2022-02-04 15:44:25 -05:00
m0duspwnens
eb0696b425
update dockers if -f used
2022-02-04 15:36:44 -05:00
m0duspwnens
267ef354c2
unmount iso after updating dockers
2022-02-04 15:09:35 -05:00
m0duspwnens
23fbf140ba
soup with dockers from iso
2022-02-04 15:06:42 -05:00
weslambert
d0b54a3a34
Merge pull request #7119 from Security-Onion-Solutions/feature/dtc_additional
...
Add additional scan and rule fileset mappings
2022-02-04 14:14:20 -05:00
Wes Lambert
317f6471d8
Add additional scan and rule filset mappings
2022-02-04 19:05:09 +00:00
weslambert
08c7181f1a
Merge pull request #7118 from Security-Onion-Solutions/fix/dtc_file_mappings
...
Fix/dtc file mappings
2022-02-04 13:22:11 -05:00
Wes Lambert
1ce8bb3523
Fix winlog mapping reference reversion
2022-02-04 18:14:01 +00:00
Wes Lambert
5e03b1a5de
Fix reference for file mappings in template
2022-02-04 18:11:03 +00:00
weslambert
898db542bf
Merge pull request #7117 from Security-Onion-Solutions/feature/winlog_dtc_mappings
...
Add winlog mappings
2022-02-04 12:16:16 -05:00
weslambert
66452b14ef
Merge pull request #7116 from Security-Onion-Solutions/fix/endgame_mappings
...
Fix EG template and mappings
2022-02-04 12:16:07 -05:00
Wes Lambert
69cb83cac9
Add winlog mappings
2022-02-04 17:08:26 +00:00
Wes Lambert
f3902cf77d
Fix EG template and mappings
2022-02-04 16:00:16 +00:00
weslambert
1af63edc6b
Merge pull request #7115 from Security-Onion-Solutions/feature/additional_dtc_mappings
...
Additional DTC mapping changes
2022-02-04 10:46:47 -05:00
Wes Lambert
a3031b2b5c
Additional DTC mapping changes
2022-02-04 15:38:51 +00:00
Doug Burks
e54ece06a2
Merge pull request #7106 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-03 16:25:04 -05:00
Mike Reeves
cc986c8d7c
Merge pull request #7105 from Security-Onion-Solutions/23100hotfix2
...
2.3.100 Hotfix 2
2022-02-03 16:04:06 -05:00
Mike Reeves
b7732fb14a
2.3.100 Hotfix 2
2022-02-03 15:58:26 -05:00
Mike Reeves
6f03662120
Merge pull request #7102 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update HOTFIX
2022-02-03 15:08:52 -05:00
Mike Reeves
4f2952105e
Update HOTFIX
2022-02-03 15:06:18 -05:00
Josh Patterson
b34d0d7f7a
Merge pull request #7100 from Security-Onion-Solutions/100_hotfix_2
...
100 hotfix 2
2022-02-03 13:15:37 -05:00
weslambert
1edc1dd842
Merge pull request #7096 from Security-Onion-Solutions/fix/dtc-ct-keyword-subfield
...
Add more DTC transition mappings
2022-02-03 12:35:34 -05:00
Wes Lambert
1ce386bb7f
Add more DTC transition mappings
2022-02-03 17:33:05 +00:00
weslambert
c7d23df000
Merge pull request #7076 from Security-Onion-Solutions/fix/zeek_dns_answers_name
...
Rename dns.answers to prevent field conflict
2022-02-03 12:22:26 -05:00
m0duspwnens
797d769661
use actual hostname in logstash:nodes pillar
2022-02-03 10:36:18 -05:00
Mike Reeves
bbd2f0da2b
Merge pull request #7094 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update distributed-airgap-manager
2022-02-03 10:36:09 -05:00
Mike Reeves
5c39162aef
Update distributed-airgap-sensor
2022-02-03 10:34:55 -05:00
Mike Reeves
d8a4301533
Update distributed-airgap-manager
2022-02-03 10:34:12 -05:00
Doug Burks
c39047666b
Merge pull request #7082 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-02 16:38:27 -05:00
Mike Reeves
5c75bb8e7a
Merge pull request #7080 from Security-Onion-Solutions/23100hotfix
...
2.3.100 Hotfix
2022-02-02 16:30:46 -05:00
Mike Reeves
83683ec27e
2.3.100 Hotfix
2022-02-02 16:23:51 -05:00
Mike Reeves
b94cae0176
2.3.100 Hotfix
2022-02-02 16:22:44 -05:00
Mike Reeves
fc0824ceb0
2.3.100 Hotfix
2022-02-02 16:20:49 -05:00
weslambert
c5b5c5858e
Rename to prevent field conflict
2022-02-02 14:31:46 -05:00
weslambert
5e9e0d971b
Merge pull request #7070 from Security-Onion-Solutions/feature/composable_templates
...
Initial composable template configuration and base mappings
2022-02-02 10:25:15 -05:00
Mike Reeves
73a43f3816
Merge pull request #7069 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-02-02 09:57:26 -05:00
Mike Reeves
8152aec22e
Update HOTFIX
2022-02-02 09:49:19 -05:00
Mike Reeves
0e28e1e4cb
Merge pull request #7066 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2022-02-02 09:22:00 -05:00
Josh Patterson
13f87e4654
Merge pull request #7067 from Security-Onion-Solutions/m0duspwnens-patch-2.3.100
...
FIX: ssl state and manager hostname with uppercase
2022-02-02 09:21:54 -05:00
Josh Patterson
a02fb37493
Update init.sls
2022-02-02 09:18:02 -05:00
Mike Reeves
eaeed07fd4
Update acng.conf
2022-02-02 09:12:29 -05:00
Wes Lambert
9db1510b0e
Initial composable template configuration and base mappings
2022-02-02 02:08:31 +00:00
Jason Ertel
1bac031975
Merge pull request #7058 from Security-Onion-Solutions/kilo
...
Bump to 2.3.110
2022-02-01 15:04:48 -05:00
Jason Ertel
c5d6f09320
Bump to 2.3.110
2022-02-01 15:03:41 -05:00
Mike Reeves
943edd0303
Merge pull request #7042 from Security-Onion-Solutions/dev
...
2.3.100 Release
2022-01-31 16:29:57 -05:00
Mike Reeves
b49524a293
Merge pull request #7041 from Security-Onion-Solutions/23100release
...
2.3.100 Release
2022-01-31 14:07:02 -05:00
Mike Reeves
6dc8415af5
2.3.100 Release
2022-01-31 14:05:22 -05:00
Doug Burks
7927534279
Merge pull request #7040 from Security-Onion-Solutions/dougburks-patch-1
...
Update version from 2.3.91 to 2.3.100
2022-01-31 13:32:05 -05:00
Doug Burks
e0f6b9af3a
Update version from 2.3.91 to 2.3.100
2022-01-31 13:27:45 -05:00
weslambert
6a2111c2ae
Merge pull request #7037 from Security-Onion-Solutions/fix/revert_zeek_dns_answers
...
Revert back to dns.answers for now
2022-01-31 09:55:22 -05:00
weslambert
367b59188b
Revert back to dns.answers for now
2022-01-31 09:54:39 -05:00
Josh Patterson
d3fc61e557
Merge pull request #7035 from Security-Onion-Solutions/soup_salt_repo
...
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager…
2022-01-31 09:05:45 -05:00
m0duspwnens
4dd0ce9f2c
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager and managerupdates is enabled
2022-01-31 09:01:18 -05:00
Josh Patterson
0c5b4c6070
Merge pull request #7033 from Security-Onion-Solutions/receiver_grafana
...
Receiver grafana
2022-01-31 08:41:56 -05:00
Josh Patterson
a8983dd895
Merge pull request #7028 from Security-Onion-Solutions/soup_salt_repo
...
Soup salt repo
2022-01-31 08:21:17 -05:00
m0duspwnens
e189f10a1b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into soup_salt_repo
2022-01-29 11:04:07 -05:00
m0duspwnens
a90660c07b
ensure salt-latest.repo is absent, salt.minion state include repo.client
2022-01-29 11:04:03 -05:00
Mike Reeves
bb87c85e07
Merge pull request #7027 from Security-Onion-Solutions/fix/soup-kibana
...
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 10:07:36 -05:00
Doug Burks
bc0a362b39
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 08:02:56 -05:00
m0duspwnens
3aee8656d4
fix %} - add redis to receiver telegraf
2022-01-28 17:45:12 -05:00
m0duspwnens
980a1a0c3d
add redis to receiver telegraf
2022-01-28 17:44:04 -05:00
m0duspwnens
bf26ae8e41
add receiver to allowed dashboards
2022-01-28 17:32:53 -05:00
m0duspwnens
da3e1e402a
add receiver dashboard grafana
2022-01-28 17:27:58 -05:00
m0duspwnens
1cd1ad9214
add inputs for so-receiver to telegraf conf
2022-01-28 17:18:31 -05:00
Josh Patterson
ddba4a5fe5
Merge pull request #7024 from Security-Onion-Solutions/soup_receiver
...
Soup receiver
2022-01-28 17:01:04 -05:00
m0duspwnens
c8b1e6f501
remove -X from UPGRADECOMMAND so salt-minion starts after upgrade
2022-01-28 15:49:53 -05:00
m0duspwnens
c45efebc7f
Merge remote-tracking branch 'remotes/origin/dev' into soup_receiver
2022-01-28 15:27:27 -05:00
m0duspwnens
014696f62f
fix receiver append to assigned_hostgroups.local.map.yaml
2022-01-28 15:26:37 -05:00
m0duspwnens
6b18551dd1
skip applying repo.client if airgap and saltupgrade prior to yum clean all
2022-01-28 14:39:10 -05:00
weslambert
4ecf4ab253
Merge pull request #7020 from Security-Onion-Solutions/feature/dash_updates
...
EG and HL Dashboard Updates
2022-01-28 13:19:02 -05:00
m0duspwnens
75b8d6a0c5
ensure /etc/yum.repos.d/securityonioncache.repo is absent if global:managerupdate = 0
2022-01-28 13:09:48 -05:00
weslambert
5142e6ccc7
Update so-kibana-config-load
2022-01-28 13:01:33 -05:00
Wes Lambert
3b76c2421c
Update to allow for passing HL saved objects
2022-01-28 17:59:34 +00:00
m0duspwnens
e82c6a2393
default for managerupdate should be int not a string
2022-01-28 12:50:58 -05:00
m0duspwnens
905ca35e93
use sed instead of echo
2022-01-28 11:19:54 -05:00
m0duspwnens
3977146a16
add receiver to firewall files during soup
2022-01-28 10:36:30 -05:00
Josh Patterson
5a37b14809
Merge pull request #7017 from Security-Onion-Solutions/issue/7016
...
dont apply wazuh state on sensors if it is disabled globally
2022-01-28 09:33:34 -05:00
m0duspwnens
15c29bda74
dont apply wazuh state on sensors if it is disabled globally - https://github.com/Security-Onion-Solutions/securityonion/issues/7016
2022-01-28 09:31:02 -05:00
Josh Patterson
d0186c8c1b
Merge pull request #7011 from Security-Onion-Solutions/fix/reinstall
...
https://github.com/Security-Onion-Solutions/securityonion/issues/7010
2022-01-27 16:40:37 -05:00
Jason Ertel
ac21bd1e29
Merge pull request #7009 from Security-Onion-Solutions/kilo
...
Add new abbreviated result limit param
2022-01-27 15:55:42 -05:00
Jason Ertel
14c587fca2
Add new abbreviated result limit param
2022-01-27 15:51:02 -05:00
m0duspwnens
6cc8e4355e
exclude salt ERROR seen during reinstall
2022-01-27 15:31:42 -05:00
m0duspwnens
e63f35a223
change to test
2022-01-27 15:19:33 -05:00
weslambert
69689b470b
Merge pull request #7005 from Security-Onion-Solutions/fix/revert_cases_field_limit
...
Revert field limit from testing
2022-01-27 11:33:31 -05:00
weslambert
fc0a5bce86
Revert field limit from testing
2022-01-27 11:18:35 -05:00
weslambert
39257df396
Merge pull request #7004 from Security-Onion-Solutions/fix/revert_dtc
...
Revert changes to common template
2022-01-27 11:15:50 -05:00
weslambert
60a0204975
Revert changes to common template
2022-01-27 11:02:47 -05:00
William Wernert
c6b11f4e05
Merge pull request #7001 from Security-Onion-Solutions/fix/so-rule-string-split
...
Fix error message printing in so-rule
2022-01-26 16:08:00 -05:00
William Wernert
4532de368a
Fix error message printing in so-rule
2022-01-26 16:04:45 -05:00
m0duspwnens
9e2278a199
Merge remote-tracking branch 'remotes/origin/dev' into fix/reinstall
2022-01-26 15:48:46 -05:00
weslambert
e303fb12cf
Merge pull request #7000 from Security-Onion-Solutions/fix/zeek_dns_answers_pipeline
...
Fix Zeek field name so it doesn't conflict with mapping of other dns.…
2022-01-26 15:04:12 -05:00
weslambert
8f0a327cb5
Fix Zeek field name so it doesn't conflict with mapping of other dns.answers fields
2022-01-26 15:02:59 -05:00
weslambert
bdc5e89822
Merge pull request #6999 from Security-Onion-Solutions/fix/case_mapping_changes_temp
...
Mapping changes for case index
2022-01-26 14:59:45 -05:00
weslambert
1b3e7f9d79
Temp changes while adjusting mapping
2022-01-26 14:57:16 -05:00
Josh Patterson
4f30d43611
Merge pull request #6998 from Security-Onion-Solutions/es_binds
...
mount repo dir in container same as defined on host
2022-01-26 13:59:17 -05:00
m0duspwnens
c80adc0430
mount repo dir in container same as defined on host
2022-01-26 13:42:56 -05:00
weslambert
e77648c475
Merge pull request #6994 from Security-Onion-Solutions/feature/dtc
...
Additional DTC changes
2022-01-26 12:22:48 -05:00
Jason Ertel
c2636036ee
Merge pull request #6995 from Security-Onion-Solutions/kilo
...
store related event data as a flattened object blob
2022-01-26 12:21:02 -05:00
Wes Lambert
e10749a495
Additional changes to template to accomodate default fields and keyword subfield
2022-01-26 17:16:29 +00:00
Jason Ertel
ed9b74dc33
store related event data as a flattened object blob
2022-01-26 12:16:05 -05:00
m0duspwnens
2aa19b78da
dont remove ca-certificates.crt
2022-01-26 11:27:35 -05:00
m0duspwnens
1337af9d69
more dupes
2022-01-26 11:07:06 -05:00
m0duspwnens
a0e493a186
remove dupe ids
2022-01-26 10:50:35 -05:00
m0duspwnens
a43fb293fc
remove role logic
2022-01-26 10:26:52 -05:00
m0duspwnens
8aa002b82e
add states to remove ca and ssl keys and certs and call them during reinstall.
2022-01-26 09:33:19 -05:00
m0duspwnens
8ce0f5b7be
log removal of root cron
2022-01-26 08:31:37 -05:00
Josh Patterson
26e03ccad2
Merge pull request #6978 from Security-Onion-Solutions/es_binds
...
allow for path.repo mounts for elasticsearch
2022-01-25 16:13:49 -05:00
m0duspwnens
dd00e3babc
use .get since repo may not exist
2022-01-25 13:18:21 -05:00
m0duspwnens
5d2b3992e2
dont need to set ES_PATH_REPO
2022-01-25 13:11:53 -05:00
m0duspwnens
7b6eeac03f
dnt mount under /repo in the container
2022-01-25 13:08:46 -05:00
m0duspwnens
00e17d5c78
put repos in /repo in es container
2022-01-25 13:03:54 -05:00
m0duspwnens
a17e1aa87a
930 for group
2022-01-25 13:00:04 -05:00
m0duspwnens
4423e93880
prevent path.repo from being put in elasticsearch.yml if the symlink doesnt exist
2022-01-25 12:57:05 -05:00
m0duspwnens
e62de2934c
fix test for es repo
2022-01-25 12:24:03 -05:00
m0duspwnens
a92e2a917b
change repos to repo
2022-01-25 10:53:28 -05:00
m0duspwnens
a72f12c4c7
add path.repo mount if symlink exists
2022-01-25 10:50:00 -05:00
Josh Patterson
9a45a9799b
Merge pull request #6974 from Security-Onion-Solutions/issue/6599
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6599
2022-01-25 09:11:33 -05:00
weslambert
ba52bd3835
Update template with syntax fixes
2022-01-25 08:56:03 -05:00
m0duspwnens
edd8709cdd
remove export LC_CTYPE="en_US.UTF-8" from soup
2022-01-24 19:42:56 -05:00
m0duspwnens
d6fc436d49
copy files to default salt base
2022-01-24 19:30:34 -05:00
m0duspwnens
82e2b2b611
dont escape raw and endraw
2022-01-24 17:03:25 -05:00
m0duspwnens
d083338350
adding --local
2022-01-24 16:46:29 -05:00
m0duspwnens
e3f1b456e6
add raw end raw back
2022-01-24 16:09:15 -05:00
m0duspwnens
268e07e2a2
remove jinja from soup scripts
2022-01-24 15:49:55 -05:00
Doug Burks
80b7487d45
Merge pull request #6968 from Security-Onion-Solutions/dougburks-patch-1
...
Update CONTRIBUTING.md with warning about more involved PRs
2022-01-24 10:39:40 -05:00
Jason Ertel
4ab7a6a079
Merge pull request #6967 from Security-Onion-Solutions/kilo
...
Copyright year and format update
2022-01-24 10:39:31 -05:00
Doug Burks
5f67dfd432
Update CONTRIBUTING.md
2022-01-24 10:36:22 -05:00
Jason Ertel
eefcc929c2
Update copyright pattern to match other repos
2022-01-24 10:09:23 -05:00
Jason Ertel
a4d2807fbb
Switch to httpcase for consistency
2022-01-24 09:45:07 -05:00
Doug Burks
fb5bff3913
Merge pull request #6956 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typos in ssh_warning
2022-01-24 09:39:40 -05:00
Jason Ertel
7c22f46a55
Update copyright year for 2022
2022-01-24 09:35:29 -05:00
Doug Burks
b103420100
fix typo in so-setup
2022-01-22 10:25:37 -05:00
Doug Burks
304ef64bc8
fix another typo in ssh_warning
2022-01-22 10:24:36 -05:00
Doug Burks
1e14e2977f
Fix typo in ssh_warning
2022-01-22 10:21:14 -05:00
Josh Patterson
86cfa07af9
Merge pull request #6955 from Security-Onion-Solutions/issue/6810
...
Issue/6810
2022-01-21 17:37:59 -05:00
m0duspwnens
32080b02e4
dont use logCmd for moving repo files after centos-release update
2022-01-21 17:28:40 -05:00
m0duspwnens
58c5db3bf6
reorder process in securityonion_repo function
2022-01-21 15:15:48 -05:00
m0duspwnens
9e5fb458b4
update saltstack repo location for securityonioncache.repo / managerupdates=1
2022-01-21 14:38:42 -05:00
weslambert
f7a4cc20f2
Update so-common-template.json.jinja
2022-01-21 12:36:38 -05:00
Josh Patterson
36fc25f78e
Merge pull request #6953 from Security-Onion-Solutions/issue/6492
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 12:09:13 -05:00
m0duspwnens
e7852d7700
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 11:59:27 -05:00
Josh Patterson
0257d09cf8
Merge pull request #6949 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-21 08:46:54 -05:00
m0duspwnens
878c3fe6d9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-21 08:09:24 -05:00
m0duspwnens
281e5d9b25
remove salt.enable_higstate state
2022-01-21 08:09:04 -05:00
m0duspwnens
baa93301b5
enable cron at the end of soup
2022-01-20 16:53:33 -05:00
m0duspwnens
00d0eb1ce5
fix setting var
2022-01-20 16:37:33 -05:00
m0duspwnens
01cb505338
start cron and enable highstate if soup exits on error
2022-01-20 16:31:01 -05:00
William Wernert
ec023f8f7c
Merge pull request #6937 from Security-Onion-Solutions/fix/fail-preflight-early
...
Correctly handle failure to install curl in so-preflight
2022-01-20 16:03:20 -05:00
m0duspwnens
e1757926cf
start cron and reenable highstate on soup exit
2022-01-20 15:26:03 -05:00
William Wernert
357cd059aa
Use ret_code in prereq function to return failures
2022-01-20 13:53:59 -05:00
weslambert
1b860e11e7
Merge pull request #6936 from Security-Onion-Solutions/fix/field_conflicts
...
Remove dynamic keyword template to prevent field conflicts with mappi…
2022-01-20 12:48:15 -05:00
weslambert
d1efa71c57
Remove dynamic keyword template to prevent field conflicts with mappings defined in common template
2022-01-20 12:34:32 -05:00
Josh Patterson
c57b2d005e
Merge pull request #6933 from Security-Onion-Solutions/issue/6810
...
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:57:56 -05:00
m0duspwnens
9b2459d8ba
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:52:48 -05:00
weslambert
d0c8dd0626
Merge pull request #6931 from Security-Onion-Solutions/fix/cases_dynamic_disable
...
Disable dynamic mapping and increase order to reduce potential field …
2022-01-20 09:48:01 -05:00
weslambert
e137ad60c5
Disable dynamic mapping and increase order to reduce potential field conflicts
2022-01-20 09:44:41 -05:00
Josh Patterson
93236738de
Merge pull request #6930 from Security-Onion-Solutions/issue/6810
...
upgrade salt to 3004
2022-01-20 08:28:20 -05:00
abesinger
31d22e717d
Updated syslog pipeline, resolves #6912 . Also cleaned up formatting to make it more readable.
2022-01-19 18:45:26 -06:00
m0duspwnens
fc65f7bb84
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 15:35:28 -05:00
m0duspwnens
67e34b2402
reorder yum operations in securityonion_repo function
2022-01-19 15:35:04 -05:00
Jason Ertel
e984b0b9c4
Merge pull request #6921 from Security-Onion-Solutions/kilo
...
remove unused fields object from related case schema
2022-01-19 14:42:05 -05:00
Jason Ertel
dc44a91398
Prefix all SO fields to avoid potential conflicts with future ECS changes
2022-01-19 14:26:22 -05:00
m0duspwnens
a861801a24
more logCmd
2022-01-19 13:38:10 -05:00
m0duspwnens
fbe54b9ee8
yum clean all needs to happen before repo files are moved or the clean doesnt clean anything
2022-01-19 12:33:58 -05:00
m0duspwnens
7ebba1f325
use show_changes: False to prevent es pw from being shown when running the state
2022-01-19 12:11:38 -05:00
m0duspwnens
f8ac37c101
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 11:57:37 -05:00
m0duspwnens
4d078046d6
quote ES_PASS due to new characters in random string for elasticsearch:auth pw generation
2022-01-19 11:55:25 -05:00
William Wernert
13dbd0034f
Merge pull request #6924 from Security-Onion-Solutions/fix/whiptail-height
...
Fix height of node whiptail menu
2022-01-19 11:18:44 -05:00
William Wernert
c10ab712d5
Fix height of node whiptail menu
2022-01-19 11:05:34 -05:00
Jason Ertel
d7ba1cedff
remove unused fields object from related case schema
2022-01-19 08:39:21 -05:00
m0duspwnens
55a262646c
use logCmd
2022-01-19 08:34:54 -05:00
William Wernert
a3925d231c
Merge pull request #6909 from Security-Onion-Solutions/fix/preflight-curl
...
Install curl in preflight script to avoid error on Ubuntu
2022-01-18 13:39:44 -05:00
William Wernert
c0c42c3574
Install curl in preflight script to avoid error on Ubuntu
...
Also add check for already installed curl later in setup
2022-01-18 13:17:56 -05:00
m0duspwnens
f006d1a22c
logCmd commands in securityonion_repo function
2022-01-18 12:34:23 -05:00
m0duspwnens
a2ed9a86ff
remove influixdb salt state files and update patch files for influxdb salt modules/state
2022-01-18 11:33:36 -05:00
Josh Brower
19ccd5f8e9
Merge pull request #6904 from Security-Onion-Solutions/fix/fleetdm-disable-vuln-feature
...
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:48:06 -05:00
Josh Brower
c4babf22d6
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:38:55 -05:00
Mike Reeves
7eb564db14
Merge pull request #6901 from Security-Onion-Solutions/elasticupdate
...
Elastic 7.16.3
2022-01-18 09:47:36 -05:00
Mike Reeves
2e4e59bbe8
Elastic 7.16.3
2022-01-18 09:42:06 -05:00
m0duspwnens
87999453f2
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-18 09:13:10 -05:00
m0duspwnens
3bd26f05d4
account for salt 3004 adding new chars to random.get_str
2022-01-14 18:02:18 -05:00
m0duspwnens
a46a740170
account for salt 3004 adding new chars to random.get_str
2022-01-14 17:23:29 -05:00
Mike Reeves
71da74fd00
Merge pull request #6878 from Security-Onion-Solutions/fix/scan_pe_sections_entropy
...
Fix/scan pe sections entropy
2022-01-14 17:02:32 -05:00
weslambert
c512351dd6
Add mapping for scan.exiftool and scan.pe.sections.entropy
2022-01-14 17:01:13 -05:00
weslambert
a90bc9dba9
Add mapping for scan.pe.sections.entropy
2022-01-14 16:58:53 -05:00
m0duspwnens
02ce5c3236
update install salt to 3004
2022-01-14 13:47:16 -05:00
m0duspwnens
b6b2e06fbc
change module to cmd for onchanges_in
2022-01-14 12:44:58 -05:00
m0duspwnens
f5fe466410
repo update
2022-01-14 12:02:35 -05:00
Jason Ertel
a63787daba
Merge pull request #6864 from Security-Onion-Solutions/kilo
...
Add default queries for cases to show user's assigned cases
2022-01-13 17:15:02 -05:00
Jason Ertel
6b0b7245f0
Add default queries for cases to show user's assigned cases
2022-01-13 17:10:08 -05:00
m0duspwnens
bda9221d6f
upgrade salt to 3004 and update bootstrap-salt.sh
2022-01-13 13:26:11 -05:00
Josh Patterson
b2434faf10
Merge pull request #6862 from Security-Onion-Solutions/issue/6811
...
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:06:43 -05:00
m0duspwnens
82db3fa3c0
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:02:01 -05:00
Josh Patterson
78bb6e4176
Merge pull request #6856 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-13 11:03:51 -05:00
m0duspwnens
06c0cebb26
merge with dev
2022-01-13 09:44:26 -05:00
m0duspwnens
389ff1a46d
create enable_highstate state to reenable highstate following minion restart if it was previously disabled. same with cron
2022-01-13 09:39:46 -05:00
m0duspwnens
a28bb23d20
fix os_family for cron state map
2022-01-12 17:27:47 -05:00
m0duspwnens
443dc6ebaa
move branch echo to main so it is in the log
2022-01-12 16:14:49 -05:00
m0duspwnens
03b9b74ace
stop cron before soup upgrades the manager, start cron at the end. add cron state that is in included in common
2022-01-12 16:04:10 -05:00
Mike Reeves
e123dd4bb2
Merge pull request #6844 from Security-Onion-Solutions/highlanderml
...
Add additional highlander settings
2022-01-12 13:34:22 -05:00
Josh Patterson
5889ce02cd
Merge pull request #6845 from Security-Onion-Solutions/23100soup_jpp
...
remove mine push from 2.3.100 function
2022-01-12 13:34:06 -05:00
Josh Patterson
776e4c6e12
Update soup
2022-01-12 13:32:46 -05:00
Josh Patterson
035984569b
Merge branch 'dev' into 23100soup_jpp
2022-01-12 13:31:46 -05:00
Josh Patterson
da30f66096
remove mine push from 2.3.100 function
2022-01-12 13:29:34 -05:00
Mike Reeves
c525bf310d
Add additional highlander settings
2022-01-12 13:19:40 -05:00
Mike Reeves
ee44edfe75
Add additional highlander settings
2022-01-12 13:18:44 -05:00
m0duspwnens
0cf877f169
kill any possible queued salt jobs before stopping salt-master
2022-01-12 12:27:19 -05:00
Mike Reeves
f836d3ad16
Merge pull request #6843 from Security-Onion-Solutions/23100soup_jpp
...
push ips of mainint to salt mine
2022-01-12 12:25:51 -05:00
Josh Patterson
5b347600e9
push ips of mainint to salt mine
2022-01-12 12:24:52 -05:00
m0duspwnens
0388912ba7
kill all salt jobs across grid before stopping salt-master. kill all salt jobs on manager before stopping salt-minion.
2022-01-12 11:05:47 -05:00
m0duspwnens
494737549d
move some es script to src elasticsearch/tools/sbin and dst /usr/sbin. set requires
2022-01-12 10:20:05 -05:00
Mike Reeves
22096174bb
Merge pull request #6841 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix some formatting
2022-01-12 09:39:15 -05:00
Mike Reeves
1d94e3ac69
Fix some formatting
2022-01-12 09:38:22 -05:00
m0duspwnens
abf3a9401b
listen instead to not start service if not running then restart if changes to files
2022-01-11 18:31:35 -05:00
m0duspwnens
ae0f392035
wait for salt-master and salt-minin to exit. disable highstate before stopping salt-minion. apply salt-minion state before first highstate to update configs
2022-01-11 16:57:29 -05:00
Mike Reeves
53d2e20e48
Merge pull request #6834 from Security-Onion-Solutions/nohive
...
Remove hive install option
2022-01-11 16:50:18 -05:00
Mike Reeves
4ff5fc3b38
Remove hive install option
2022-01-11 14:38:38 -05:00
m0duspwnens
5ade8193f0
move highstate messages for more accurate final highstate message
2022-01-11 13:41:51 -05:00
m0duspwnens
0ef130bd38
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:12:07 -05:00
m0duspwnens
e33a9eb45c
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:11:25 -05:00
m0duspwnens
9d19cba600
log time when salt services stopped and started
2022-01-11 13:09:05 -05:00
m0duspwnens
baf297ab0a
merge with dev, resolve conflict
2022-01-11 11:24:10 -05:00
m0duspwnens
14eed8e5b9
redirect to setup_log
2022-01-11 11:20:30 -05:00
Josh Brower
5083be4ce7
Merge pull request #6816 from Security-Onion-Solutions/fix/wazuh-parsing-v2
...
Fix Wazuh WEL Parsing
2022-01-11 11:17:24 -05:00
Doug Burks
a3c8335130
Merge pull request #6827 from Security-Onion-Solutions/dougburks-patch-1
...
Remove unnecessary word
2022-01-11 11:06:40 -05:00
Doug Burks
29d8dbe371
Remove unnecessary word
2022-01-11 11:05:30 -05:00
m0duspwnens
91ef9b9366
update salt mine before salt-master and salt-minion get stopped
2022-01-11 10:57:48 -05:00
m0duspwnens
328d6cdeb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 10:02:18 -05:00
Mike Reeves
a9e58e2aba
Merge pull request #6826 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2022-01-11 10:01:49 -05:00
Mike Reeves
8ad36fc7b9
Update init.sls
2022-01-11 10:01:14 -05:00
m0duspwnens
87756cdbc9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:57:31 -05:00
Mike Reeves
7937487ee9
Merge pull request #6825 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update init.sls
2022-01-11 09:57:10 -05:00
Mike Reeves
770a389410
Update init.sls
2022-01-11 09:56:22 -05:00
m0duspwnens
b5c274de10
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:48:31 -05:00
m0duspwnens
a8d1b9eb90
restart salt-minion at end of run if mine_functions changes
2022-01-11 09:29:12 -05:00
m0duspwnens
86c8fc6c1c
need to update mine after salt-master starts
2022-01-11 08:56:38 -05:00
weslambert
17509a9231
Merge pull request #6822 from Security-Onion-Solutions/fix/event_fields
...
Add event.acknowledged and event.escalated mappings
2022-01-10 16:14:45 -05:00
weslambert
84f7c6b13b
Add event.acknowledged and event.escalated mappings
2022-01-10 16:08:35 -05:00
m0duspwnens
716c98ec61
requires and ordering for socusersroles state
2022-01-10 14:39:00 -05:00
Josh Brower
56aa24d874
Fix Wazuh WEL Parsing
2022-01-10 13:55:38 -05:00
Mike Reeves
b7a90a88f9
Merge pull request #6815 from Security-Onion-Solutions/esbackup
...
Add ability to specify local backup dir
2022-01-10 13:31:24 -05:00
weslambert
1dc363138a
Merge pull request #6814 from Security-Onion-Solutions/fix/template_typo
...
Fix typo -- replace period with comma
2022-01-10 13:30:13 -05:00
weslambert
1c3eeb5a34
Fix typo -- replace period with comma
2022-01-10 13:29:06 -05:00
m0duspwnens
beb9a33628
only include curl.config if elasticsearch:auth is enabled
2022-01-10 11:48:16 -05:00
Mike Reeves
dbba7d7226
Add ability to specify local backup dir
2022-01-10 11:31:41 -05:00
m0duspwnens
291ac7d361
https://github.com/Security-Onion-Solutions/securityonion/issues/6811
2022-01-10 10:36:42 -05:00
Josh Patterson
43eda0c5a3
Merge pull request #6796 from Security-Onion-Solutions/fix/wazuh_register_agent
...
dont try to register if state file exists
2022-01-07 16:07:56 -05:00
m0duspwnens
715d3f0e7e
dont try to register if state file exists
2022-01-07 16:05:55 -05:00
Jason Ertel
db04646735
Merge pull request #6794 from Security-Onion-Solutions/kilo
...
Update field mappings based on Wes' feedback
2022-01-07 16:03:05 -05:00
Jason Ertel
66c9e20c6a
Add wilcards for CCS compatibility
2022-01-07 15:57:08 -05:00
Josh Patterson
ed97fe0b65
Merge pull request #6795 from Security-Onion-Solutions/fix/wazuh_register_agent
...
Fix/wazuh register agent
2022-01-07 15:52:17 -05:00
m0duspwnens
3a86af8de2
quote $API_RESULT
2022-01-07 15:49:53 -05:00
m0duspwnens
7ee913eb1f
if /opt/so/conf/wazuh/initial_agent_registration.log doesnt exist, and agent is already registered, touch file and exit 0 to prevent salt error
2022-01-07 15:46:47 -05:00
Jason Ertel
d3656a7777
Merge branch 'dev' into kilo
2022-01-07 13:41:35 -05:00
Josh Patterson
3c44f6fd41
Merge pull request #6793 from Security-Onion-Solutions/23100soup_jpp
...
23100soup
2022-01-07 13:32:33 -05:00
Jason Ertel
391db568b0
Update field mappings based on Wes' feedback
2022-01-07 13:28:36 -05:00
Jason Ertel
a4f01d4412
Merge pull request #6792 from Security-Onion-Solutions/kilo
...
Add case exclusion toggle to Hunt to avoid hunt results getting case …
2022-01-07 13:02:27 -05:00
Jason Ertel
9ef83da23f
Add case exclusion toggle to Hunt to avoid hunt results getting case data hits unintentionally
2022-01-07 12:58:35 -05:00
m0duspwnens
871fd115ae
put so-firewalll in /usr/sbin since salt-master isnt running at this time
2022-01-07 12:04:19 -05:00
weslambert
218f7f3a13
Merge pull request #6790 from Security-Onion-Solutions/fix/dtc_severity_label
...
Add event.severity_label
2022-01-07 11:44:30 -05:00
weslambert
770e53d914
Add keyword subfield for event.severity_label
2022-01-07 11:21:57 -05:00
weslambert
c69e1353d9
Add event.severity_label
2022-01-07 11:19:54 -05:00
m0duspwnens
fd0e5d7d29
make sure so-firewall is up to date
2022-01-07 11:10:48 -05:00
Josh Brower
ae6aa0dafd
Merge pull request #6789 from Security-Onion-Solutions/fix/wazuh-parsing-revert
...
Revert Wazuh parser update
2022-01-07 10:53:53 -05:00
Josh Brower
5d4ea2ba3a
Revert Wazuh parser update
2022-01-07 10:51:24 -05:00
weslambert
a7e7566532
Merge pull request #6780 from Security-Onion-Solutions/feature/datatype_compliance
...
Initial commit for data type compliance
2022-01-06 16:38:17 -05:00
m0duspwnens
5ecb63f5cf
prevent exit if minion doesnt respond
2022-01-06 16:17:51 -05:00
Josh Brower
ca4aaae47c
Merge pull request #6778 from Security-Onion-Solutions/fix/wazuh-parsing
...
Uppercase first char in Wazuh WEL
2022-01-06 16:01:09 -05:00
Josh Brower
277c7f1ef8
Uppercase first char in Wazuh WEL
2022-01-06 14:58:50 -05:00
m0duspwnens
cd590b894a
check that ossec.conf exists
2022-01-06 12:39:48 -05:00
weslambert
3f02003ea2
Merge pull request #6777 from Security-Onion-Solutions/fix/deprecation_ecs_compatibility_logstash
...
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:31:51 -05:00
weslambert
8e2f500b9c
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:24:04 -05:00
weslambert
099e3e1ceb
Merge pull request #6775 from Security-Onion-Solutions/fix/deprecation_warning_suppress
...
Add logger stanza to suppress ES deprecation warning messages
2022-01-06 10:45:37 -05:00
weslambert
900d12b556
Add logger stanza to suppress deprecation warning messages for now due to current system index access warning messages flooding the ES log
2022-01-06 10:35:50 -05:00
Jason Ertel
8cf7ea8b87
Merge pull request #6772 from Security-Onion-Solutions/kilo
...
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 19:15:02 -05:00
Josh Patterson
eaa6597cd7
Merge pull request #6773 from Security-Onion-Solutions/issue/6765
...
Issue/6765
2022-01-05 18:11:06 -05:00
m0duspwnens
6338ba2e45
remove /var/cache/salt/ for reinstall
2022-01-05 16:54:56 -05:00
m0duspwnens
8af74e8bb3
remove more salt configs for reinstall
2022-01-05 16:53:54 -05:00
m0duspwnens
9357995bfa
remove root cron and restore yeselastic.txt
2022-01-05 16:04:32 -05:00
weslambert
2fb488f768
Merge pull request #6769 from Security-Onion-Solutions/fix/id_fielddata_deprecation
...
Fix issue with _id field fielddata/deprecation
2022-01-05 15:40:25 -05:00
Wes Lambert
1cafacfa51
Update saved objects to reflect removal of TheHive scripted field and replacement of PCAP pivot with Hunt pivot
2022-01-05 20:36:23 +00:00
weslambert
c1a88977cf
Disable fielddata for _id field by default (since it is deprecated and can be memory-intensive)
2022-01-05 15:23:52 -05:00
m0duspwnens
0ff5e3cf6f
require so-elasticsearch container to be running to run the scripts
2022-01-05 14:48:41 -05:00
m0duspwnens
8950f94fb0
restore state files so python3-influxdb state doesnt try to patch during a restinstall
2022-01-05 12:02:53 -05:00
Wes Lambert
b60837e71a
Initial commit for data type compliance
2022-01-05 16:38:56 +00:00
Jason Ertel
4f8524e0ac
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 11:13:12 -05:00
weslambert
2f9672d3ea
Merge pull request #6764 from Security-Onion-Solutions/feature/soup_branch
...
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:54:29 -05:00
weslambert
db43e21378
Fix indentation
2022-01-05 10:46:41 -05:00
weslambert
4d8b417fc9
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:41:27 -05:00
Jason Ertel
89415b12ce
Merge pull request #6762 from Security-Onion-Solutions/kilo
...
Switch soc.json to use lowercase labels in default queries; Also enab…
2022-01-05 09:59:39 -05:00
Jason Ertel
4bfdfffe21
Switch soc.json to use lowercase labels in default queries; Also enable the 'Add Case' feature
2022-01-05 09:54:13 -05:00
Mike Reeves
1adc4c5346
Merge pull request #6752 from Security-Onion-Solutions/ubufix
...
Fix docker holds so re-install will work properly
2022-01-04 18:56:06 -05:00
Mike Reeves
3ca0ce9eea
Update so-functions
2022-01-04 18:47:35 -05:00
Mike Reeves
e869013057
Remove docker the reinstall it
2022-01-04 15:24:10 -05:00
Mike Reeves
dd104c9490
Add holds for ubuntu
2022-01-04 13:07:09 -05:00
m0duspwnens
7bb9b6efa9
populate mine with network.ip_addrs pillar.host.mainint for each host prior to highstate
2022-01-04 10:27:45 -05:00
Mike Reeves
288389c93e
Soup changes for 2.3.100
2022-01-04 08:38:14 -05:00
Josh Patterson
4247a3a816
Merge pull request #6730 from Security-Onion-Solutions/fix/ub1804ssl
...
more detailed logging for the retry command
2021-12-30 13:19:58 -05:00
m0duspwnens
cc2f6e23ca
more detailed logging for the retry command
2021-12-30 13:09:29 -05:00
Josh Patterson
064355dfb5
Merge pull request #6729 from Security-Onion-Solutions/fix/ub1804ssl
...
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 11:38:32 -05:00
m0duspwnens
d274615376
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 10:45:30 -05:00
Josh Patterson
78eda75c0f
Merge pull request #6725 from Security-Onion-Solutions/fix/ub1804ssl
...
add option to look for failed outout in retry function in so-common. …
2021-12-29 18:18:12 -05:00
m0duspwnens
200736a118
add option to look for failed outout in retry function in so-common. look for Err: when running soapt-get update in setup
2021-12-29 18:15:16 -05:00
Jason Ertel
1d136b611a
Merge pull request #6723 from Security-Onion-Solutions/kilo
...
Uniform presets
2021-12-29 16:49:41 -05:00
Jason Ertel
e6051cb653
Switch all presets to lowercase for uniformity
2021-12-29 16:42:34 -05:00
Jason Ertel
74dbc4bf67
Merge pull request #6720 from Security-Onion-Solutions/kilo
...
Add case template to eval install types; also improve clarity of case queries
2021-12-29 11:41:06 -05:00
Josh Patterson
a2f1f52450
Merge pull request #6719 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-29 11:39:10 -05:00
Jason Ertel
1d885a5419
Add case template to eval installs
2021-12-29 11:38:38 -05:00
m0duspwnens
b414e22e95
remove spaces in function
2021-12-29 11:37:22 -05:00
m0duspwnens
4c54d45681
some echos for logging
2021-12-29 11:36:12 -05:00
m0duspwnens
c6e9b00488
Merge remote-tracking branch 'remotes/origin/dev' into fix/ub1804ssl
2021-12-29 11:22:25 -05:00
m0duspwnens
b027da6378
wait for the salt-minion service to be ready for requests prior to running ssl state
2021-12-29 11:18:38 -05:00
Jason Ertel
fb02d0d35c
clarify case filters
2021-12-29 11:07:36 -05:00
Jason Ertel
d4f3615cae
Merge pull request #6717 from Security-Onion-Solutions/kilo
...
Support CCS in CM
2021-12-29 09:12:13 -05:00
Jason Ertel
e5110ac4e8
Use CCS compatible index
2021-12-29 09:08:10 -05:00
Jason Ertel
e87cbc37a4
Add case template
2021-12-28 19:17:15 -05:00
Josh Patterson
3b130ab202
Merge pull request #6712 from Security-Onion-Solutions/fix/ub1804ssl
...
all run ssl state during setup
2021-12-28 16:34:58 -05:00
m0duspwnens
22afe99719
all run ssl state during setup
2021-12-28 16:24:17 -05:00
Doug Burks
e56a9a5f22
Merge pull request #6711 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-analyst-install
2021-12-28 15:24:19 -05:00
Josh Patterson
7655920068
Merge pull request #6710 from Security-Onion-Solutions/fix/ub1804ssl
...
add mine function to signing_policies.conf
2021-12-28 15:23:36 -05:00
Doug Burks
463925686d
fix typo in so-analyst-install
2021-12-28 15:23:17 -05:00
m0duspwnens
2a5b4ef276
add mine function to signing_policies.conf. no longer need to check if mine in ca during manager install
2021-12-28 15:19:06 -05:00
Josh Patterson
7029c3a94a
Merge pull request #6707 from Security-Onion-Solutions/fix/ub1804ssl
...
put x509 signing policies in place when minion is configured
2021-12-28 12:05:20 -05:00
m0duspwnens
67a9f4d22e
put x509 signing policies in place when minion is configured
2021-12-28 12:03:10 -05:00
Josh Patterson
a5746d4919
Merge pull request #6706 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-28 11:27:15 -05:00
m0duspwnens
487ac24306
revert back to getting ca from mine
2021-12-28 11:16:01 -05:00
m0duspwnens
2405de4b82
fix require
2021-12-28 11:00:35 -05:00
m0duspwnens
9e3c289562
remove restarting salt in ssl generation. sperate ca and ssl generation into seperate functions
2021-12-28 10:43:45 -05:00
m0duspwnens
f2adcf4ca5
ensure /etc/pki is created and simplify ca logic for non manager in ssl state
2021-12-28 10:41:57 -05:00
Jason Ertel
0072ae253b
Merge pull request #6705 from Security-Onion-Solutions/kilo
...
Initial CM Impl; Improve so-user script
2021-12-28 08:36:59 -05:00
Jason Ertel
5a4473ecd6
fix indent
2021-12-28 08:33:31 -05:00
Jason Ertel
f335670b3f
Add new client-side param for cases
2021-12-27 21:53:30 -05:00
Jason Ertel
194e4119f0
Correct missing json vars
2021-12-27 20:36:28 -05:00
Jason Ertel
09626deb05
Correct var names for jinja
2021-12-27 18:01:15 -05:00
Jason Ertel
ae7a4b6528
More syntax corrections
2021-12-27 16:18:12 -05:00
Jason Ertel
0a255e5765
Resolve syntax error
2021-12-27 15:15:33 -05:00
Jason Ertel
789719d25e
Correct preset file syntax
2021-12-27 13:21:13 -05:00
Jason Ertel
7140255d95
Add missing presets file
2021-12-27 12:27:04 -05:00
Jason Ertel
ab3319b472
Add artifact support
2021-12-27 10:49:10 -05:00
Jason Ertel
b0d36f2ed2
Ensure update timestamp is updated when changing passwords; this ensures the sync will automatically follow
2021-12-21 13:38:35 -05:00
Jason Ertel
62e5914ab8
Merge branch 'dev' into kilo
2021-12-21 13:37:37 -05:00
Jason Ertel
2f88f08be2
Merge pull request #6649 from Security-Onion-Solutions/2.3.91-merge
...
2.3.91 merge
2021-12-21 09:39:14 -05:00
Jason Ertel
9aeaa1fccc
resolved merge conflicts
2021-12-21 09:35:57 -05:00
Jason Ertel
2c9062efb7
resolved merge conflicts
2021-12-21 09:34:39 -05:00
Doug Burks
c8de36d467
Merge pull request #6646 from Security-Onion-Solutions/patch/2.3.91
...
Patch/2.3.91
2021-12-21 09:27:14 -05:00
doug
284e0e9108
fix hashes in VERIFY_ISO.md
2021-12-20 17:27:19 -05:00
doug
e66b023c9c
update README.md for 2.3.91
2021-12-20 17:23:52 -05:00
doug
9f47522591
add sig for 2.3.91 ISO and update VERIFY_ISO.md
2021-12-20 17:21:53 -05:00
Jason Ertel
35617acaeb
Update cacerts to reflect new path; this changed due to ES 7.16.2
2021-12-20 12:12:00 -05:00
Jason Ertel
6f116a2d01
Switch to new Ubuntu SSL dir
2021-12-20 09:43:59 -05:00
Jason Ertel
d6c651af1c
Remove old patch dir from previously-patched installations
2021-12-20 09:42:27 -05:00
Jason Ertel
203e8a7873
Bump version to 2.3.91
2021-12-20 09:33:20 -05:00
Jason Ertel
b8fcec04b8
Remove patched jar due to upgrade of Elastic images to 7.16.2
2021-12-20 09:27:03 -05:00
Jason Ertel
6556a37869
Merge branch 'master' into patch/1.3.91
2021-12-20 09:20:03 -05:00
Jason Ertel
5af2bd8fa4
Upgrade to Elastic 7.16.2
2021-12-20 09:16:28 -05:00
Josh Patterson
d33cf19e3d
Merge pull request #6612 from Security-Onion-Solutions/issue/6469
...
add managersearch to list
2021-12-16 13:57:53 -05:00
m0duspwnens
a46a876ec6
add managersearch to list
2021-12-16 13:48:41 -05:00
Josh Brower
affe5b9ac0
Merge pull request #6605 from Security-Onion-Solutions/fix/fleet-ips
...
Fix cidr for fleet custom docker range
2021-12-16 11:55:11 -05:00
Josh Patterson
e0c8e03882
Merge pull request #6604 from Security-Onion-Solutions/issue/6469
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6469
2021-12-16 11:54:05 -05:00
Josh Brower
a23824e199
Fix cidr for fleet custom docker range
2021-12-16 11:53:26 -05:00
m0duspwnens
ae342ab673
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-16 11:33:09 -05:00
m0duspwnens
b4b8b91ccd
simplify ip logic wazuh-register-agent, mine_interval to 35 minutes
2021-12-16 11:24:35 -05:00
m0duspwnens
2e4ed8062e
simplify wazuh agent ip logic
2021-12-16 11:11:01 -05:00
m0duspwnens
bd7ef1cc59
fix whitespace control
2021-12-16 09:19:20 -05:00
Jason Ertel
8ec671422f
Merge pull request #6593 from Security-Onion-Solutions/esup
...
Finish upgrade of ES to 7.16.1
2021-12-16 07:59:34 -05:00
Jason Ertel
1268f8f92b
Upgrade ES to 7.16.1
2021-12-16 07:57:42 -05:00
Jason Ertel
d4f395b7f4
Fix query name for open cases
2021-12-15 20:02:35 -05:00
Jason Ertel
c68efd56c2
Merge branch 'dev' into kilo
2021-12-15 20:01:55 -05:00
m0duspwnens
a7600f7f43
update scripts to use their own ip
2021-12-15 17:31:39 -05:00
Mike Reeves
0f76227631
Merge pull request #6585 from Security-Onion-Solutions/unhotfix
...
Unhotfix
2021-12-15 17:23:02 -05:00
m0duspwnens
d0b0970353
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-15 17:08:56 -05:00
Mike Reeves
465ba1b7d3
Change CA certs location
2021-12-15 17:08:36 -05:00
m0duspwnens
f9b04ab96a
add node's own ip to FILEBEAT_EXTRA_HOSTS
2021-12-15 16:53:22 -05:00
m0duspwnens
522bc1d2b8
fix loadbalance logic and whitespace for filebeat.yml
2021-12-15 16:21:08 -05:00
m0duspwnens
cf2f4bad09
have standalone and managersearch pull from redis nodes
2021-12-15 15:27:23 -05:00
Mike Reeves
61955b7928
Change CA certs location
2021-12-15 13:50:19 -05:00
Jason Ertel
ffa8ca57a7
Merge pull request #6579 from Security-Onion-Solutions/unhotfix
...
Remove some previous hotfix code
2021-12-15 12:34:00 -05:00
Mike Reeves
7cd1b1c482
Remove some previous hotfix code
2021-12-15 12:26:53 -05:00
m0duspwnens
6ab2bdef0c
add sensoroni state to receiver node
2021-12-15 10:45:54 -05:00
m0duspwnens
ce0a39db4b
remove old EXTRAHOSTNAME EXTRAHOSTIP from being set for logstash
2021-12-15 09:43:46 -05:00
m0duspwnens
ea89d2074b
remove ca from allowed_hosts on so-receiver
2021-12-15 09:32:12 -05:00
m0duspwnens
759bf9837e
pillar top clean up for receiver and logstash.nodes
2021-12-15 09:31:03 -05:00
m0duspwnens
d9a384cc29
remove global:pipeline pillar call from logstash pipeline pillars
2021-12-15 09:30:15 -05:00
m0duspwnens
176ef852c8
clean up assinged hostgroups for receiver
2021-12-15 08:28:40 -05:00
Doug Burks
09f0bdba91
Merge pull request #6574 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-image-common
2021-12-15 07:45:24 -05:00
Doug Burks
7d1f9c51e8
fix typo in so-image-common
2021-12-15 07:24:30 -05:00
m0duspwnens
024860d0ae
rename EXTRA_NODES to LOGSTASH_NODES AND REDIS_NODES
2021-12-14 23:43:06 -05:00
m0duspwnens
0c6aba16ec
fix redis input
2021-12-14 23:42:37 -05:00
m0duspwnens
15b8d80b71
fix host for input_redis
2021-12-14 18:51:43 -05:00
m0duspwnens
55b74abcc5
extra_hosts and redis_input for logstash
2021-12-14 18:49:30 -05:00
m0duspwnens
4da017d61c
change extra_hosts for docker container
2021-12-14 17:05:30 -05:00
m0duspwnens
a31d61e151
handle ca for redis
2021-12-14 16:43:04 -05:00
m0duspwnens
841b91e052
exclude elasticsearch and managerssl keys and certs from receiver
2021-12-14 16:05:47 -05:00
m0duspwnens
d0b6d5bba6
remove so-eval from lists since it doesnt run logstash
2021-12-14 15:33:06 -05:00
m0duspwnens
a31f034f2e
remove receiver add node for cacerts and tls-ca-bundle for logstash bind
2021-12-14 15:02:59 -05:00
m0duspwnens
6962e3f9b3
fix logstash certs mapped into container
2021-12-14 14:52:15 -05:00
m0duspwnens
c490a3be36
move node_data pillar to logstash:nodes, set extra hosts for filebeat docker
2021-12-14 13:32:42 -05:00
Mike Reeves
5006e34208
Merge pull request #6560 from Security-Onion-Solutions/mergerz
...
Merge latest hotfix
2021-12-14 10:57:49 -05:00
Mike Reeves
30344ba0ef
Fix conflicts
2021-12-14 10:55:19 -05:00
m0duspwnens
6518691c55
sort the items
2021-12-13 18:16:25 -05:00
m0duspwnens
067e79894f
fix loop for node_data
2021-12-13 16:26:38 -05:00
m0duspwnens
6de2f5bd03
fix node_data
2021-12-13 15:55:09 -05:00
m0duspwnens
8d0872bce5
create node_data pillar from mine data, use node_data pillar for filebeat config
2021-12-13 15:48:30 -05:00
Mike Reeves
85cf096322
Merge pull request #6541 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-13 12:41:24 -05:00
Mike Reeves
4eaf3f8d8b
Merge pull request #6540 from Security-Onion-Solutions/2390hotfix3
...
2.3.90-20211213 Hotfix
2021-12-13 12:12:03 -05:00
Mike Reeves
d90904b4d4
2.3.90-20211213 Hotfix
2021-12-13 12:09:09 -05:00
Mike Reeves
65cc9930e7
Merge pull request #6537 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-12-13 11:13:40 -05:00
Mike Reeves
7f982d2824
Update HOTFIX
2021-12-13 11:12:18 -05:00
Mike Reeves
d3ac1f7994
Merge pull request #6533 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Add missing logstash lib
2021-12-13 09:30:32 -05:00
Jason Ertel
c94d5fa9dc
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:27:13 -05:00
Mike Reeves
83d1cdad90
Merge pull request #6532 from Security-Onion-Solutions/jertel/hotfix-20211213
...
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:05:30 -05:00
Jason Ertel
8365b5f140
Strip JndiLookup.class from log4j-core jars, to match Elastic's mitigation approach
2021-12-13 09:02:41 -05:00
m0duspwnens
86f67198bf
loadbalance filebeat if across managers and receivers
2021-12-10 17:43:06 -05:00
Mike Reeves
4d6cd66d9d
Merge pull request #6521 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-10 16:20:29 -05:00
Mike Reeves
1946965c5f
Merge pull request #6520 from Security-Onion-Solutions/2390hotfix0day
...
2.3.90-20211210 Hotfix
2021-12-10 15:49:38 -05:00
Mike Reeves
c9a14788ed
2.3.90-20211210 Hotfix
2021-12-10 15:42:53 -05:00
m0duspwnens
fe7247f876
update fw for receiver and add mine_functions for ip_addr
2021-12-10 15:28:40 -05:00
Mike Reeves
ce963a02d9
Merge pull request #6517 from Security-Onion-Solutions/ES0day2
...
Add JVM Options for logstash
2021-12-10 14:25:52 -05:00
Mike Reeves
dcd56de890
Update log4j2.properties
2021-12-10 14:23:38 -05:00
Mike Reeves
3d7b963912
Update log4j2.properties
2021-12-10 14:16:16 -05:00
Mike Reeves
09253b637e
Create jvm.options
2021-12-10 14:12:43 -05:00
Mike Reeves
c81ce48bff
Update log4j2.properties
2021-12-10 14:10:35 -05:00
Mike Reeves
73ec595baa
Update init.sls
2021-12-10 14:10:05 -05:00
Mike Reeves
04862fcc06
Merge pull request #6514 from Security-Onion-Solutions/ES0day2
...
Throw the log4j into the java options
2021-12-10 12:04:31 -05:00
Mike Reeves
45346b6318
Update log4j2.properties
2021-12-10 12:01:39 -05:00
Mike Reeves
e48de18480
Update init.sls
2021-12-10 12:00:12 -05:00
Mike Reeves
66c8cc6e86
Update init.sls
2021-12-10 11:59:12 -05:00
Mike Reeves
8dcb64d87c
Update init.sls
2021-12-10 11:56:33 -05:00
Mike Reeves
ae3e980852
Merge pull request #6513 from Security-Onion-Solutions/EShotfix
...
Update log4j2.properties
2021-12-10 10:35:43 -05:00
Mike Reeves
11f1fe7ab1
Update HOTFIX
2021-12-10 10:21:50 -05:00
Mike Reeves
4561e13871
Update log4j2.properties
2021-12-10 10:19:58 -05:00
Mike Reeves
ea26e402c8
Update log4j2.properties
2021-12-10 10:17:49 -05:00
m0duspwnens
54c32acdbf
dont call logstash_pillar if manager or helix
2021-12-09 15:26:00 -05:00
Jason Ertel
83d86aebb1
Perform full email match
2021-12-09 15:04:00 -05:00
m0duspwnens
d94496bb90
remove minio_key and add missing endif
2021-12-09 13:24:20 -05:00
m0duspwnens
c2a952796c
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:13:18 -05:00
Mike Reeves
b92cbb01b3
SSL modifications
2021-12-09 13:13:01 -05:00
m0duspwnens
5b70d5510f
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:12:00 -05:00
Jason Ertel
2761662eb9
Add status presets
2021-12-09 13:09:56 -05:00
Mike Reeves
a7f0d81555
SSL modifications
2021-12-09 13:07:00 -05:00
Josh Brower
d3bbae23ca
Merge pull request #6499 from Security-Onion-Solutions/fix/beats-logstash
...
Use id for doc id if it exists
2021-12-09 09:47:14 -05:00
Josh Brower
656ea974dc
Use id for doc id if it exists
2021-12-09 09:16:58 -05:00
Jason Ertel
a9b7b9ee92
Jinjafy case params
2021-12-08 17:41:48 -05:00
m0duspwnens
7390b03dc1
dont show es options in final whiptail setup confirmation
2021-12-08 14:58:34 -05:00
m0duspwnens
b4bc32d3ca
set logstash pillar and enable avanced ls menu for so-receiver
2021-12-08 14:33:15 -05:00
m0duspwnens
ecc8594d44
prevent so-receiver from getting extra keys/certs
2021-12-08 13:32:56 -05:00
m0duspwnens
59464af10c
filebeat certs for logstash on so-receiver
2021-12-08 09:41:17 -05:00
m0duspwnens
1ef63f3a23
ssl things for so-receiver
2021-12-08 09:08:46 -05:00
m0duspwnens
c80059efb0
change from || to &&
2021-12-07 17:11:15 -05:00
m0duspwnens
8c95d0f36b
set ip for wazuh-register-agent and dont apply nginx in setup for receiver
2021-12-07 16:50:41 -05:00
m0duspwnens
429b9cab2f
set ip for ossec.conf
2021-12-07 16:22:07 -05:00
m0duspwnens
f8da5c7fe9
start of fw rules for receiver
2021-12-07 15:59:11 -05:00
m0duspwnens
06010bd157
add so-receiver to allowed_states
2021-12-07 13:34:06 -05:00
Jason Ertel
b73eb76c94
Make case module dynamic
2021-12-07 11:51:02 -05:00
m0duspwnens
f3ec5df447
add receiver node
2021-12-07 11:13:51 -05:00
m0duspwnens
7549e34881
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-07 10:57:12 -05:00
m0duspwnens
ba30c59ec7
add receiver node
2021-12-07 10:56:35 -05:00
Mike Reeves
892899b7f9
Merge pull request #6477 from Security-Onion-Solutions/merge-202112071526
...
Merge hotfix
2021-12-07 10:30:13 -05:00
Jason Ertel
702d95c63a
Merge branch 'master' into merge-202112071527
2021-12-07 10:28:00 -05:00
m0duspwnens
96666ab307
add receiver node
2021-12-07 10:19:32 -05:00
Mike Reeves
9f41df641e
Merge pull request #6470 from Security-Onion-Solutions/hotfix/2.3.90
...
HOTFIX: 2.3.90-20211206
2021-12-07 09:51:01 -05:00
Mike Reeves
9f94ecfab7
Merge pull request #6466 from Security-Onion-Solutions/2390updates3
...
2.3.90 hotfix 20211206
2021-12-06 11:07:14 -05:00
Mike Reeves
4188282724
2.3.90 hotfix 20211206
2021-12-06 11:03:49 -05:00
Mike Reeves
3945933dec
Merge pull request #6446 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-12-06 09:38:02 -05:00
Mike Reeves
73a1a3878f
Update HOTFIX
2021-12-06 09:37:07 -05:00
weslambert
ff25d6f80b
Merge pull request #6447 from Security-Onion-Solutions/eg_dashes
...
Add initial EG dashboards
2021-12-03 18:05:22 -05:00
Wes Lambert
0571612ea1
Add initial EG dashes
2021-12-03 22:38:30 +00:00
Mike Reeves
f697d88090
Update HOTFIX
2021-12-03 15:36:16 -05:00
Mike Reeves
ad03241910
Merge pull request #6445 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Apply hotfix to all 2.3.90 installs
2021-12-03 15:24:33 -05:00
Mike Reeves
f82d204c0e
Update soup
2021-12-03 15:20:33 -05:00
Mike Reeves
780daf8aa7
Apply hotfix to all 2.3.90 installs
2021-12-03 15:15:45 -05:00
Josh Patterson
5008b647b0
Merge pull request #6441 from Security-Onion-Solutions/hf/soc_append2.3.90
...
export LC_CTYPE="en_US.UTF-8" in soup
2021-12-03 15:10:12 -05:00
m0duspwnens
65b1ab833d
run salt-call locally as if no Salt master were present during reinstall - https://github.com/Security-Onion-Solutions/securityonion/discussions/6435
2021-12-03 12:00:29 -05:00
m0duspwnens
c6773a0bbc
move "Preparing soup" to main so shows in soup.log
2021-12-03 10:26:22 -05:00
m0duspwnens
ff2d2c7c04
export LC_CTYPE="en_US.UTF-8" - https://github.com/Security-Onion-Solutions/securityonion/discussions/6431
2021-12-02 16:39:32 -05:00
Mike Reeves
6c7a1f23f5
Merge pull request #6440 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Fix for the clustername used in wrong context
2021-12-02 15:35:26 -05:00
Mike Reeves
f5761c73a5
Fix for the clustername used in wrong context
2021-12-02 15:30:35 -05:00
Mike Reeves
8448778ecd
Merge pull request #6438 from Security-Onion-Solutions/hf/soc_append2.3.90
...
hf/soc append2.3.90
2021-12-02 15:10:51 -05:00
m0duspwnens
8d667795a7
only add soc:es_index_patterns to pillar if not already present
2021-12-02 10:28:17 -05:00
m0duspwnens
7a664ab8f7
more error proof up_to_2.3.90 function
2021-12-02 10:02:26 -05:00
Jason Ertel
83fab42b6e
Merge pull request #6433 from Security-Onion-Solutions/kilo
...
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:39:14 -05:00
Jason Ertel
e549cfdf82
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:35:13 -05:00
Josh Brower
c7a9fb1fa3
Merge pull request #6432 from Security-Onion-Solutions/fix/fleet-nginx
...
Fix FleetDM nginx errors
2021-12-02 08:30:28 -05:00
Josh Brower
97cd679d74
Fix FleetDM nginx errors
2021-12-02 08:17:01 -05:00
William Wernert
3bd8bcba12
Merge pull request #6421 from Security-Onion-Solutions/hotfix-merge
...
Hotfix merge
2021-12-01 14:49:05 -05:00
William Wernert
6e7188b4d8
Merge branch 'hotfix/2.3.90' into hotfix-merge
...
# Conflicts:
# HOTFIX
2021-12-01 14:40:34 -05:00
m0duspwnens
5e0ac89841
merge with master
2021-12-01 14:27:58 -05:00
Mike Reeves
8990a09d92
Merge pull request #6418 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-12-01 13:24:19 -05:00
Mike Reeves
946673dc3b
Merge pull request #6417 from Security-Onion-Solutions/2390updates2
...
2.3.90 hotfix airgap
2021-12-01 13:20:41 -05:00
m0duspwnens
c571b2c499
handle redirect if more than 1 match from compgen
2021-12-01 13:17:14 -05:00
Mike Reeves
80c569317f
2.3.90 hotfix airgap
2021-12-01 13:16:13 -05:00
Mike Reeves
84b91c547d
Merge pull request #6403 from Security-Onion-Solutions/dlee35-patch-1
...
add subjectAltName to filebeat.crt
2021-12-01 11:54:05 -05:00
Mike Reeves
5f121f3b99
Merge pull request #6411 from Security-Onion-Solutions/m0duspwnens-patch-1/hotfix/2.3.90
...
remove redirect to /dev/null for compgen
2021-12-01 10:17:29 -05:00
Josh Patterson
63cb486698
remove redirect to /dev/null for compgen
2021-12-01 10:16:04 -05:00
Dustin Lee
8a394380cb
add subjectAltName to filebeat.crt
...
IP SAN is required for Endgame integration w/Logstash when DNS resolution is unavailable
2021-11-30 16:24:08 -05:00
William Wernert
1a31e60e47
Merge pull request #6402 from Security-Onion-Solutions/fix/airgap-check
...
Fix/airgap check
2021-11-30 15:57:02 -05:00
William Wernert
168f860c87
Add hotfix string to HOTFIX
2021-11-30 15:49:41 -05:00
William Wernert
8d87fae6a8
Remove airgap repo file if it shouldn't exist
2021-11-30 15:46:22 -05:00
William Wernert
739efc22d2
Fix airgap check logic
2021-11-30 15:46:18 -05:00
Jason Ertel
1272de3058
Merge pull request #6378 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
bump version to 2.3.100
2021-11-29 09:57:29 -05:00
Mike Reeves
2beb69f495
Update HOTFIX
2021-11-29 09:55:32 -05:00
Mike Reeves
5a447c53d9
bump version to 2.3.100
2021-11-29 09:55:01 -05:00
Jason Ertel
31ffd6c4ec
Merge pull request #6339 from Security-Onion-Solutions/kilo
...
Merge 2.3.90 WAZUH hotfix into dev
2021-11-23 19:33:18 -05:00
Mike Reeves
4c6786a412
Merge pull request #6335 from Security-Onion-Solutions/hotfix/2.3.90
...
Hotfix/2.3.90
2021-11-23 16:51:27 -05:00
Mike Reeves
5062e910e2
Merge pull request #6334 from Security-Onion-Solutions/2390updates
...
2.3.90 hotfix soup
2021-11-23 15:41:21 -05:00
Mike Reeves
1f9dc0db1f
2.3.90 hotfix soup
2021-11-23 15:40:04 -05:00
Mike Reeves
c536e11383
2.3.90 hotfix soup
2021-11-23 15:32:41 -05:00
Mike Reeves
faa8464b60
Merge pull request #6333 from Security-Onion-Solutions/kilo
...
Correct if check to inline the command instead of checking for emptin…
2021-11-23 14:53:24 -05:00
Jason Ertel
4f283c2d86
Suppres grep output
2021-11-23 14:52:40 -05:00
Jason Ertel
801d42ed20
Correct if check to inline the command instead of checking for emptiness of a variable
2021-11-23 14:51:06 -05:00
Mike Reeves
30a1ffc1c7
Merge pull request #6329 from Security-Onion-Solutions/kilo
...
2.3.90 WAZUH
2021-11-23 13:37:41 -05:00
Jason Ertel
59fc122eec
Force restart of wazuh since conf file is changing
2021-11-23 13:29:04 -05:00
Jason Ertel
52ffa27eda
Update hotfix file
2021-11-23 13:22:47 -05:00
Jason Ertel
bd59d65f02
Strip trailing newlines from version and hotfix files
2021-11-23 13:12:27 -05:00
Jason Ertel
01ceded223
Handle CRs in hotfix
2021-11-23 13:03:40 -05:00
Jason Ertel
3c37bd61ab
Add debug logging
2021-11-23 12:46:59 -05:00
Jason Ertel
a35670c889
Merge branch 'hotfix/1.3.90' into kilo
2021-11-23 12:38:57 -05:00
Jason Ertel
7627d37386
Add 2.3.90 WAZUH hotfix corrective function
2021-11-23 12:21:28 -05:00
Jason Ertel
273842eb43
Merge pull request #6328 from Security-Onion-Solutions/kilo
...
WAZUH hotfix
2021-11-23 12:06:34 -05:00
Jason Ertel
0dd251e2a9
Fix typo in whiptail prompt
2021-11-23 11:19:53 -05:00
Josh Patterson
c67b2b6936
Update soup
...
only check if salt was upgraded if upgrade_salt function was called
2021-11-23 11:14:10 -05:00
Jason Ertel
af4c04be59
Fix #6325 - Prevent XML header from outputting to ossec.conf
2021-11-23 10:57:21 -05:00
Jason Ertel
4672b0c15c
Fix #6317 - Do not attempt to whitelist when wazuh isn't enabled
2021-11-23 10:06:14 -05:00
Jason Ertel
9737a4088c
Merge pull request #6327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-11-23 09:25:43 -05:00
Mike Reeves
d8d429c71a
Update HOTFIX
2021-11-23 09:19:41 -05:00
Mike Reeves
3bfc3b8943
Merge pull request #6301 from Security-Onion-Solutions/dev
...
2.3.90
2021-11-22 13:15:23 -05:00
Mike Reeves
4ad6d616ae
Merge pull request #6313 from Security-Onion-Solutions/2390update
...
2390update
2021-11-22 09:04:16 -05:00
Mike Reeves
759c0b858a
2.3.90
2021-11-22 09:01:12 -05:00
Mike Reeves
c17a49a730
Merge pull request #6302 from Security-Onion-Solutions/fix/md5soup
...
Fix/md5soup
2021-11-19 16:45:02 -05:00
m0duspwnens
c0f183fb5e
add comment
2021-11-19 16:37:27 -05:00
m0duspwnens
d602339c45
render and md5sum soup and so-common
2021-11-19 16:32:59 -05:00
Mike Reeves
0122e62920
Merge pull request #6300 from Security-Onion-Solutions/2390
...
2.3.90
2021-11-19 14:09:02 -05:00
Mike Reeves
1634105780
2.3.90
2021-11-19 14:07:03 -05:00
Josh Patterson
198a690ba1
Merge pull request #6298 from Security-Onion-Solutions/fix/soup-script-check
...
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:24:48 -05:00
William Wernert
bebd62187d
Check soup in /usr/sbin rather than the saltstack default dir
2021-11-19 11:23:32 -05:00
Mike Reeves
a91564605c
Merge pull request #6297 from Security-Onion-Solutions/fix/soup-playbook-secrets
...
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:28:11 -05:00
William Wernert
23b91ee7e5
Fix indent on playbook_admin and playbook_automation secrets
2021-11-19 10:27:11 -05:00
Mike Reeves
d3f25f8d74
Merge pull request #6293 from Security-Onion-Solutions/fix/fleet-stats
...
Fix FleetDM - disable stats
2021-11-19 09:53:26 -05:00
Josh Brower
8bd4ba3acd
Fix FleetDM - disable stats
2021-11-19 09:49:34 -05:00
Josh Patterson
e5927d0bf7
Merge pull request #6290 from Security-Onion-Solutions/fleet_startup_eval
...
run redis state before fleet state for eval highstate
2021-11-18 17:54:26 -05:00
m0duspwnens
9dd89f6be7
run redis state before fleet state for eval highstate
2021-11-18 17:41:56 -05:00
Mike Reeves
796eb59dc6
Merge pull request #6288 from Security-Onion-Solutions/syncesusers_so-kratos
...
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:42:18 -05:00
m0duspwnens
55fed43469
wait for up to 5 minutes for kratos to respond before proceeding
2021-11-18 16:35:35 -05:00
William Wernert
af83019427
Merge pull request #6287 from Security-Onion-Solutions/feat/cidr-extra-validation
...
Check for more invalid cidr syntax
2021-11-18 15:21:58 -05:00
William Wernert
4149236cda
Check for more invalid cidr syntax
2021-11-18 15:18:12 -05:00
Josh Patterson
825106d074
Merge pull request #6286 from Security-Onion-Solutions/fix/docker-upgrade
...
Prevent downgrade of docker, containerd, and docker-cli
2021-11-18 15:15:37 -05:00
William Wernert
1a3324868a
Specify version of docker-ce-rootless-extras
2021-11-18 15:12:47 -05:00
William Wernert
bc87bb4770
Specify docker cli version as well
2021-11-18 14:51:26 -05:00
William Wernert
6aae48bdae
Don't upgrade docker or containerd before versionlock is applied
2021-11-18 14:14:18 -05:00
Mike Reeves
a0425a48e6
Merge pull request #6282 from Security-Onion-Solutions/syncesusers_so-kratos
...
remove restart policy for kratos container
2021-11-18 11:43:16 -05:00
m0duspwnens
4b89bf7bbc
remove restart policy for kratos container
2021-11-18 11:41:07 -05:00
Mike Reeves
5fc5afa9ea
Merge pull request #6281 from Security-Onion-Solutions/syncesusers_so-kratos
...
install specific docker verison
2021-11-18 11:32:38 -05:00
m0duspwnens
ddec8e4da0
install specific docker verison
2021-11-18 11:29:22 -05:00
Jason Ertel
9c0e8cedba
Merge pull request #6279 from Security-Onion-Solutions/syncesusers_so-kratos
...
restart kratos if failure
2021-11-18 10:49:12 -05:00
m0duspwnens
5054da0027
restart kratos if failure
2021-11-18 10:48:06 -05:00
Jason Ertel
96f1f0174b
Merge pull request #6275 from Security-Onion-Solutions/syncesusers_so-kratos
...
break kratos state out from soc state
2021-11-18 09:13:10 -05:00
m0duspwnens
cd1f0c0440
break kratos state out from soc state
2021-11-18 09:10:00 -05:00
Mike Reeves
12546a8efa
Merge pull request #6271 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 19:48:15 -05:00
Josh Brower
3f5956b56d
Fix soup - fleetdm SA user
2021-11-17 19:47:16 -05:00
Mike Reeves
6e49ab0558
Merge pull request #6270 from Security-Onion-Solutions/fix/whiptail-text
...
Fix text cutoff
2021-11-17 19:18:46 -05:00
William Wernert
c52df32f05
Fix text cutoff
2021-11-17 19:08:10 -05:00
Josh Patterson
c0602f4222
Merge pull request #6269 from Security-Onion-Solutions/syncesusers_so-kratos
...
run elasticsearch.auth state and so-elastic-auth true before manager …
2021-11-17 18:41:18 -05:00
m0duspwnens
d4b412bcbe
run elasticsearch.auth state and so-elastic-auth true before manager in setup for syncesusers in manager state
2021-11-17 18:38:13 -05:00
Josh Brower
66e2de0934
Merge pull request #6268 from Security-Onion-Solutions/fix/fleet-users
...
Fix soup - fleetdm SA user
2021-11-17 18:26:11 -05:00
Josh Brower
c93794a402
Fix soup - fleetdm SA user
2021-11-17 18:22:34 -05:00
Josh Patterson
98efc6f2ed
Merge pull request #6267 from Security-Onion-Solutions/syncesusers_so-kratos
...
syncesusers require so-kratos
2021-11-17 18:20:53 -05:00
m0duspwnens
59ef734064
syncesusers require so-kratos
2021-11-17 18:16:06 -05:00
Josh Brower
922657afbc
Merge pull request #6266 from Security-Onion-Solutions/fix/fleet-users
...
Unset pw reset for new Fleet users
2021-11-17 17:10:27 -05:00
Josh Brower
5f3601ac78
Unset pw reset for new Fleet users
2021-11-17 17:06:01 -05:00
Josh Brower
2fe4fa06a6
Merge pull request #6265 from Security-Onion-Solutions/fix/fleet-users
...
Fix FleetDM SA Creation for SOUP
2021-11-17 14:09:59 -05:00
Josh Brower
773c580e77
Fix FleetDM SA Creation for SOUP
2021-11-17 14:08:34 -05:00
Mike Reeves
aca684d55a
Merge pull request #6264 from Security-Onion-Solutions/fix/fleet-users
...
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:16:05 -05:00
Josh Brower
6f391dbe50
Migrate FleetDM user mgt to fleetctl
2021-11-17 13:13:25 -05:00
William Wernert
8d033264e7
Merge pull request #6262 from Security-Onion-Solutions/fix/new-cidr-test
...
Add new ipv4 address w/ cidr mask validator
2021-11-17 13:09:04 -05:00
William Wernert
262d2023b5
Add new ipv4 address w/ cidr mask validator
2021-11-17 12:41:25 -05:00
Josh Patterson
d143a309a1
Merge pull request #6261 from Security-Onion-Solutions/soup_soc_endgame
...
change how soc endgame added to manager pillar in soup
2021-11-17 11:12:17 -05:00
m0duspwnens
ac400f1c41
change how soc endgame added to manager pillar in soup
2021-11-17 11:07:12 -05:00
William Wernert
df495c0017
Merge pull request #6258 from Security-Onion-Solutions/fix/nm-conf
...
Run `check_network_manager_conf()` later in setup
2021-11-17 08:44:25 -05:00
William Wernert
8c454973ad
Run check_network_manager_conf() later in setup
...
The directory was being overwritten when network-manager was installed later
2021-11-17 08:42:27 -05:00
Josh Patterson
a16e6aca22
Merge pull request #6257 from Security-Onion-Solutions/es_soup_ingest
...
escape raw and endraw
2021-11-17 07:56:01 -05:00
m0duspwnens
ce21ae11f5
escape raw and endraw
2021-11-17 07:53:15 -05:00
Mike Reeves
fdd9706669
Merge pull request #6255 from Security-Onion-Solutions/kilo
2021-11-16 18:09:40 -05:00
Jason Ertel
8fa9a180b2
Refactor upgrade and post-upgrade version to function mappings; fix missing version upgrades from older 2.3.61 releases and earlier; Drop support for upgrading ancient RC releases
2021-11-16 18:08:28 -05:00
Josh Patterson
6288365a50
Merge pull request #6254 from Security-Onion-Solutions/es_soup_ingest
...
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:47:53 -05:00
m0duspwnens
5448107310
wrap common ingest in raw endraw since json and no jinja
2021-11-16 16:43:33 -05:00
Mike Reeves
adaf3faf90
Merge pull request #6253 from Security-Onion-Solutions/kilo
2021-11-16 16:13:31 -05:00
Jason Ertel
1bd8e226b4
Force DB migration since installations on 2.3.50 or earlier will skip the Kratos 0.6 version
2021-11-16 15:58:04 -05:00
Josh Patterson
f60f0b5b6d
Merge pull request #6246 from Security-Onion-Solutions/es_soup_ingest
...
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:05:15 -05:00
William Wernert
adc867846c
Merge pull request #6245 from Security-Onion-Solutions/fix/ubuntu-nic-unmanaged
...
Modify network-manager conf earlier in setup
2021-11-16 14:00:58 -05:00
m0duspwnens
5945326817
soup for es ingest common and watch esingestdynamicconf for so-elastic docker
2021-11-16 14:00:41 -05:00
William Wernert
90cbb5d00e
Modify network-manager conf earlier in setup
2021-11-16 13:30:09 -05:00
Josh Brower
8bb2789c6f
Merge pull request #6237 from Security-Onion-Solutions/kilo
...
Migrate to email field instead of username due to breaking change in …
2021-11-16 12:06:08 -05:00
Jason Ertel
11fc0da971
Migrate to email field instead of username due to breaking change in FleetDM 4.x
2021-11-16 12:03:46 -05:00
William Wernert
76a1d767f2
Merge pull request #6235 from Security-Onion-Solutions/feature/preflight-retry
...
Retry failed URLs in so-preflight + improve logging clarity
2021-11-16 11:11:02 -05:00
William Wernert
a2152446ea
Pad count string to align text
2021-11-16 11:08:13 -05:00
William Wernert
d4d9032bfc
Remove confusing punctuation
2021-11-16 10:56:49 -05:00
William Wernert
4e3f43bee4
Fix variable name
2021-11-16 10:53:22 -05:00
William Wernert
57377e0a0e
Add retry support + more precise logging to so-preflight
2021-11-16 10:46:48 -05:00
Mike Reeves
2514d36ccd
Merge pull request #6232 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2021-11-15 17:11:08 -05:00
Mike Reeves
809dbc0a48
Merge pull request #6233 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2021-11-15 17:10:52 -05:00
Mike Reeves
b51405d5e8
Update soup
2021-11-15 17:04:46 -05:00
Mike Reeves
d1cfc4a8dc
Merge pull request #6231 from Security-Onion-Solutions/fix/whiptail-cutoff
...
Fix whiptail description text
2021-11-15 17:02:00 -05:00
Mike Reeves
731bbabe4c
Update init.sls
2021-11-15 17:00:34 -05:00
William Wernert
d4509ff4d8
Fix whiptail description text
2021-11-15 16:29:26 -05:00
Mike Reeves
85c0b0818b
Merge pull request #6230 from Security-Onion-Solutions/fix/cidr-full-validation-bash
...
Check CIDR validity completely
2021-11-15 15:43:58 -05:00
William Wernert
f674555290
Check CIDR validity completely
2021-11-15 15:43:05 -05:00
Josh Patterson
a8aae544d5
Merge pull request #6229 from Security-Onion-Solutions/kibana_json_logging
...
change kibana logging to json
2021-11-15 14:27:04 -05:00
m0duspwnens
6f9db25ea7
change kibana logging to json
2021-11-15 14:23:47 -05:00
Mike Reeves
405e78858a
Merge pull request #6228 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2021-11-15 14:07:23 -05:00
Mike Reeves
146e1f4297
Update soup
2021-11-15 14:05:29 -05:00
Mike Reeves
f78e0fb7b9
Merge pull request #6227 from Security-Onion-Solutions/fix/fleetlogging
...
Fix env var for logging
2021-11-15 14:00:31 -05:00
Josh Brower
6e6d2d1949
Fix env var for logging
2021-11-15 13:52:35 -05:00
Josh Patterson
ca5d20fecb
Merge pull request #6225 from Security-Onion-Solutions/clean_meta_data
...
clean metadata with cmd.run instead of pkg module due to False return…
2021-11-15 11:03:41 -05:00
m0duspwnens
dcfaece8b1
clean metadata with cmd.run instead of pkg module due to False return from module
2021-11-15 11:00:31 -05:00
Mike Reeves
af0e062193
Merge pull request #6221 from Security-Onion-Solutions/fix/var-reference
...
Fix variable reference in so-functions
2021-11-15 09:49:07 -05:00
Mike Reeves
56acedfbf7
Merge pull request #6220 from Security-Onion-Solutions/fix/revert-python-validation
...
Fix/revert python validation
2021-11-15 09:44:31 -05:00
William Wernert
4b0a5c3a17
Un-revert validation test script
2021-11-15 09:43:43 -05:00
William Wernert
052192e1d6
Revert "Use python lib to make cidr validation more strict"
...
This reverts commit 569cb24861 .
2021-11-15 09:43:18 -05:00
weslambert
92131d4bb7
Merge pull request #6215 from Security-Onion-Solutions/fix/eg_spelling
...
Fix spelling
2021-11-12 21:13:28 -05:00
weslambert
9ac1cb0e76
Fix spelling
2021-11-12 21:12:09 -05:00
Josh Patterson
ffbb04bb5a
Merge pull request #6213 from Security-Onion-Solutions/issue/5809
...
Issue/5809
2021-11-12 15:07:54 -05:00
m0duspwnens
cc1dea446c
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/5809
2021-11-12 15:02:22 -05:00
m0duspwnens
7f3379e034
verify manager pillars can be rendered before proceeding with soup - https://github.com/Security-Onion-Solutions/securityonion/issues/5809
2021-11-12 15:02:16 -05:00
weslambert
8c46a2d1db
Merge pull request #6210 from Security-Onion-Solutions/fix/soc_pillar_soup
...
Add SOC pillar entry
2021-11-12 13:35:46 -05:00
William Wernert
ba621639bd
Merge pull request #6201 from Security-Onion-Solutions/fix/cidr-ip-validation
...
Improve cidr validation in setup and match ip validation to similar method
2021-11-12 13:34:19 -05:00
Wes Lambert
2fb9196604
Move logic above version declaration
2021-11-12 18:26:21 +00:00
Wes Lambert
48c71c8b12
Add soc pillar entry
2021-11-12 18:23:09 +00:00
weslambert
8d185ced61
Merge pull request #6209 from Security-Onion-Solutions/fix/endgame_setup
...
Adjust manager pillar config for Endgame and defaults
2021-11-12 12:27:55 -05:00
William Wernert
9141c271f0
Fix indent
2021-11-12 12:25:32 -05:00
weslambert
bc2e470da9
Fix indentation
2021-11-12 12:20:00 -05:00
weslambert
0f817cd735
Merge pull request #6208 from Security-Onion-Solutions/fix/endgame_pivot
...
Make Endgame pivot independent
2021-11-12 12:17:24 -05:00
weslambert
df5901a65d
Adjust how manager pillar is populated for ENDGAME and default SOC config
2021-11-12 12:16:26 -05:00
weslambert
3cd1b5687e
Make pivot condition independent for ENDGAMEHOST
2021-11-12 12:06:39 -05:00
Josh Patterson
86a42addf0
Merge pull request #6207 from Security-Onion-Solutions/so_elastic_auth_password_reset
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:43:31 -05:00
m0duspwnens
6bf4d5a576
https://github.com/Security-Onion-Solutions/securityonion/issues/6206
2021-11-12 11:37:55 -05:00
William Wernert
efa5eb9f7f
Merge pull request #6184 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-11 13:57:07 -05:00
Josh Patterson
22959f0260
Merge pull request #6195 from Security-Onion-Solutions/issue/6146
...
Issue/6146
2021-11-11 11:47:33 -05:00
m0duspwnens
8da2133cff
give kibana.secrets pillar to import node
2021-11-11 11:31:07 -05:00
William Wernert
1472af4fc3
Merge branch 'dev' into foxtrot
2021-11-11 09:03:05 -05:00
Josh Brower
f91a6d3cb6
Merge pull request #6194 from Security-Onion-Solutions/fix/fleetstandalone
...
Add Fleet Standalone Node to manager ssl
2021-11-11 08:52:29 -05:00
Josh Brower
96f427d924
Add so-fleet to cert requirements
2021-11-11 08:45:22 -05:00
Josh Brower
184356618c
Add Fleet Standalone Node to manager ssl
2021-11-11 08:28:22 -05:00
William Wernert
ed3b2e4569
Put entire ref to doc page on new line
2021-11-10 17:46:35 -05:00
William Wernert
62b41af069
Fix docs link being cut off
2021-11-10 17:17:19 -05:00
William Wernert
569cb24861
Use python lib to make cidr validation more strict
...
Also update ipv4 validation to match the method used to validate cidr strings
2021-11-10 16:53:01 -05:00
William Wernert
ac22df8381
Merge branch 'dev' into foxtrot
2021-11-10 16:51:31 -05:00
Mike Reeves
446d6bd532
Merge pull request #6189 from Security-Onion-Solutions/soup2390
...
Soup2390
2021-11-10 16:49:46 -05:00
Mike Reeves
fcf889be2f
Add soup to 2.3.90
2021-11-10 16:46:24 -05:00
Mike Reeves
8168f19b31
Add soup to 2.3.90
2021-11-10 16:37:54 -05:00
Mike Reeves
ba553d971c
Add soup to 2.3.90
2021-11-10 16:31:44 -05:00
Mike Reeves
9137454a25
Add soup placeholders
2021-11-10 16:08:07 -05:00
m0duspwnens
7ebd861e32
enable secureCookies, security.encryptionKey and reporting.encryptionKey - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-10 16:05:40 -05:00
William Wernert
d110b63050
Merge pull request #6187 from Security-Onion-Solutions/fix/so-rule-modify-example
...
Fix `so-rule modify` example
2021-11-10 14:31:28 -05:00
William Wernert
3806f10f8b
Fix so-rule modify example
2021-11-10 14:18:32 -05:00
Jason Ertel
83bd314a63
Merge pull request #6186 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.2
2021-11-10 14:06:08 -05:00
Jason Ertel
6cd7b252df
Upgrade to ES 7.15.2
2021-11-10 13:59:55 -05:00
Jason Ertel
dea03bbf5e
Upgrade to ES 7.15.2
2021-11-10 13:44:20 -05:00
Josh Brower
9edc543262
Merge pull request #6183 from Security-Onion-Solutions/delta
...
Upgrade FleetDM to 4.5
2021-11-10 11:35:12 -05:00
Josh Brower
d3dc5ffc5a
Fix salt syntax
2021-11-10 11:28:48 -05:00
William Wernert
2c296e832f
Remove references to CURCLOSEDAYS in setup
...
Curator is configured differently now so the variable set during setup is no longer in use
2021-11-10 11:25:51 -05:00
Josh Brower
b350174df1
Merge remote-tracking branch 'remotes/origin/dev' into delta
2021-11-10 11:08:36 -05:00
Josh Brower
67ebfeab16
Disable FleetDM usage stats
2021-11-10 10:49:56 -05:00
Josh Brower
435f430747
Fix enroll secret parsing
2021-11-10 10:24:53 -05:00
Josh Patterson
aa9e1701f0
Merge pull request #6180 from Security-Onion-Solutions/issue/5794
...
timeout wazuh-register-agent faster
2021-11-10 09:58:05 -05:00
m0duspwnens
02d9b87f66
https://github.com/Security-Onion-Solutions/securityonion/issues/5794
2021-11-10 09:54:51 -05:00
Josh Patterson
cfd46c1e58
Merge pull request #6176 from Security-Onion-Solutions/bravo
...
Grafana improvements, pillarize kibana
2021-11-10 09:18:47 -05:00
m0duspwnens
392305e4ed
add engame changes that were missing from merge somehow
2021-11-10 09:01:42 -05:00
m0duspwnens
5ff14ab652
Merge remote-tracking branch 'origin/issue/6007' into bravo
2021-11-09 18:31:56 -05:00
m0duspwnens
1890c7244a
set elasticsearch:auth to persist through user pw change
2021-11-09 18:25:17 -05:00
m0duspwnens
a8c4ed7bbf
set elasticsearch:auth:enabled True in auth pillar
2021-11-09 18:05:05 -05:00
m0duspwnens
91f54537d7
handle elasticsearch.auth state like kibana.secrets
2021-11-09 17:52:38 -05:00
m0duspwnens
7e3a4656aa
change xpack update
2021-11-09 17:33:09 -05:00
m0duspwnens
8a04fcd919
change how key is added
2021-11-09 17:07:20 -05:00
m0duspwnens
409ab623a5
ensure kibana pillar dir exists
2021-11-09 16:49:45 -05:00
m0duspwnens
ac85d1598e
dont show changes
2021-11-09 16:44:54 -05:00
m0duspwnens
4c8e68e014
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-11-09 16:42:47 -05:00
m0duspwnens
57c6e26634
encrypt kibana saved objects - https://github.com/Security-Onion-Solutions/securityonion/issues/6146
2021-11-09 16:41:25 -05:00
m0duspwnens
b6a1d7418e
fix typo, dont show changes for kibana.yaml or dashboard so
2021-11-09 16:14:48 -05:00
weslambert
6eb1a0b0ae
Merge pull request #6169 from Security-Onion-Solutions/fix/ingest_dynamic_ref
...
Add dynamic conf to config change check
2021-11-09 16:11:38 -05:00
weslambert
9301b8f5b9
Add dynamic conf to config change check
2021-11-09 15:56:52 -05:00
m0duspwnens
202977a323
create so script to load saved object defaults
2021-11-09 15:54:15 -05:00
weslambert
9597373e4a
Merge pull request #6167 from Security-Onion-Solutions/ecs_pipeline_common
...
Add config for dynamically formatted ingest pipelines
2021-11-09 15:41:43 -05:00
Wes Lambert
f80b70e008
Add config for dynamically formatted ingest pipelines
2021-11-09 20:07:53 +00:00
William Wernert
04d2b52306
Fix IP route whiptail error
2021-11-09 14:03:32 -05:00
m0duspwnens
af7830c2be
remove reference to saved_objects in defaults
2021-11-09 13:52:47 -05:00
m0duspwnens
3c3cb47b88
merge with dev
2021-11-09 13:07:35 -05:00
m0duspwnens
da4e92a7a3
change config id
2021-11-09 12:13:28 -05:00
Mike Reeves
3afb0bd263
Merge pull request #6161 from Security-Onion-Solutions/sslchange
...
Enable Subject Alt Name for registry
2021-11-09 10:53:38 -05:00
Josh Brower
f6e6b20392
Add Name and OrgName to Fleet setup
2021-11-09 09:20:47 -05:00
William Wernert
3835a4401e
Merge pull request #6157 from Security-Onion-Solutions/foxtrot
...
Fix preflight script on centos
2021-11-09 08:49:46 -05:00
William Wernert
4bae57d994
Fix preflight printing to log
2021-11-09 08:34:02 -05:00
William Wernert
ea7289d92e
Fix preflight script on centos
2021-11-09 08:20:19 -05:00
m0duspwnens
48eaf190e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6007
2021-11-08 17:00:06 -05:00
m0duspwnens
497de0fede
hide vars on pipeline overview
2021-11-08 16:54:39 -05:00
m0duspwnens
70e3bc7eb8
hide vars on pipeline overview
2021-11-08 16:52:15 -05:00
Mike Reeves
eefc9cfcb6
Enable Subject Alt Name for registry
2021-11-08 16:50:43 -05:00
m0duspwnens
42b8955883
panel cleanup
2021-11-08 16:33:57 -05:00
m0duspwnens
f6b753b805
panel cleanup
2021-11-08 16:26:41 -05:00
m0duspwnens
17fc03a553
pipleine overview tc changes
2021-11-08 16:15:42 -05:00
weslambert
8bf88043ac
Merge pull request #6149 from Security-Onion-Solutions/add_test_pipeline
...
Add ECS testing pipeline
2021-11-08 15:43:03 -05:00
m0duspwnens
79640342f2
update redis queue query
2021-11-08 15:20:28 -05:00
Mike Reeves
3ad47742bd
Merge pull request #6150 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2021-11-08 15:18:35 -05:00
Mike Reeves
a8c02252dc
Update acng.conf
2021-11-08 15:16:05 -05:00
m0duspwnens
fbef420155
update redis queue query
2021-11-08 15:15:53 -05:00
m0duspwnens
ccd84e441d
add redis queue to pipeline overview
2021-11-08 15:09:46 -05:00
Wes Lambert
46d3eb452d
Add ECS testing pipeline
2021-11-08 20:08:56 +00:00
Josh Brower
083d467aa9
Update to FleetDM 4.5
2021-11-08 15:05:58 -05:00
m0duspwnens
f026ac1b41
pipeline overview tc changes
2021-11-08 15:02:52 -05:00
m0duspwnens
9ea292b11e
fix query
2021-11-08 13:48:33 -05:00
m0duspwnens
e2ee460fdd
fix gridPos
2021-11-08 12:39:23 -05:00
m0duspwnens
5b70ff61d1
fix gridPos
2021-11-08 12:37:03 -05:00
m0duspwnens
3b2ca89852
use endif not fi
2021-11-08 12:20:07 -05:00
m0duspwnens
199c97684c
fix nontc name in defaults
2021-11-08 12:10:23 -05:00
m0duspwnens
d67e34dac4
add pipeline overview for true cluster
2021-11-08 12:09:35 -05:00
William Wernert
49a573074e
Merge pull request #6142 from Security-Onion-Solutions/foxtrot
...
Whiptail changes
2021-11-08 11:29:58 -05:00
William Wernert
6c16d6d222
Update invalid hostname message
2021-11-08 11:15:28 -05:00
William Wernert
acba82d194
Update dist install menus' top text
2021-11-08 11:04:51 -05:00
William Wernert
f66d915f5d
Normal hostname check already checks for localhost
2021-11-08 10:38:30 -05:00
William Wernert
ee2dd75dfd
Fix variable ref
2021-11-08 10:36:36 -05:00
William Wernert
50b7779d6e
Make manager hostname error more specific
2021-11-08 10:35:28 -05:00
William Wernert
ad71485361
Fix whiptail height
2021-11-08 10:21:55 -05:00
William Wernert
8b2cccdf4a
More whiptail formatting
2021-11-08 10:21:17 -05:00
William Wernert
dbe4a7de63
Fix new whiptail layouts
2021-11-08 10:19:38 -05:00
William Wernert
9c4bba9ac9
Fix variable reference
2021-11-08 10:08:23 -05:00
Doug Burks
b3fd7c548c
Merge pull request #6135 from Security-Onion-Solutions/dougburks-patch-1
...
Improve clarity in CONTRIBUTING.md
2021-11-08 08:53:50 -05:00
Doug Burks
dcf6dfb676
Improve clarity
2021-11-08 06:38:16 -05:00
William Wernert
246d41c552
Add additional checks for manager hostname + ip
...
Check for current hostname, ip, and localhost (ip + string) when setting the manager ip and hostname
2021-11-05 15:56:08 -04:00
William Wernert
988932293f
Whiptail changes
...
* Ask whether to join to or create new dist install
* Also add links to architecture on install type prompts
2021-11-05 15:54:17 -04:00
m0duspwnens
0b28e89f3c
change how telegraf script determine if there is already and instance of the script already running
2021-11-04 23:22:13 -04:00
m0duspwnens
665732bd32
dont show points
2021-11-04 14:23:11 -04:00
m0duspwnens
b599b49630
enable beat input plugin for telegraf
2021-11-04 13:52:45 -04:00
m0duspwnens
edb3b602a9
pipeline overview dashboard changs
2021-11-04 10:59:01 -04:00
William Wernert
a4289b7ab9
Merge pull request #6107 from Security-Onion-Solutions/foxtrot
...
Manage docker gid and run preflight check during setup
2021-11-04 10:07:05 -04:00
Mike Reeves
9b0ce8b395
Merge pull request #6090 from Security-Onion-Solutions/commonupdate
...
Make common template honor replicas
2021-11-03 14:04:19 -04:00
m0duspwnens
05456b38d1
update panel
2021-11-03 13:54:05 -04:00
m0duspwnens
4fc58e7a5a
update panel
2021-11-03 13:51:57 -04:00
Mike Reeves
dc07aba63d
Update so-common-template.json.jinja
2021-11-03 13:50:31 -04:00
m0duspwnens
f1d66e2d51
change searchnode var
2021-11-03 13:40:09 -04:00
m0duspwnens
fab0dd2bad
add repeating es ingest panel for nontc
2021-11-03 13:25:42 -04:00
Mike Reeves
747f14d60e
Make common template honor replicas
2021-11-03 13:11:38 -04:00
William Wernert
fb35ff40b4
Just hide whiptail cancel message on test installs
2021-11-03 10:41:44 -04:00
m0duspwnens
2cb31a4c05
fix query
2021-11-03 09:27:02 -04:00
m0duspwnens
32f986c505
change panel
2021-11-03 09:23:21 -04:00
m0duspwnens
c8ee67f354
update panel for pipeline_overview
2021-11-03 09:12:32 -04:00
m0duspwnens
db80315c06
rename panel
2021-11-03 08:37:33 -04:00
m0duspwnens
8e3b08a831
start of pipeline dashboard
2021-11-03 08:33:20 -04:00
m0duspwnens
677f62ebd1
dont show changes for telegraf conf
2021-11-02 18:22:37 -04:00
William Wernert
d927e79154
Exit on failed preflight check during testing
2021-11-02 16:17:08 -04:00
William Wernert
8670aa6cd8
Run check-update in preflight instead of update
2021-11-02 14:29:58 -04:00
William Wernert
7c7c225a41
Fix tmp file check
2021-11-02 14:01:21 -04:00
m0duspwnens
54b034b537
fix spacing on es input
2021-11-02 13:43:59 -04:00
m0duspwnens
2232759fa4
rename file
2021-11-02 12:21:54 -04:00
m0duspwnens
f65eea6a03
rename file
2021-11-02 12:09:32 -04:00
William Wernert
e4a77acfe6
Move whiptail menus outside of progress func
2021-11-02 12:03:42 -04:00
William Wernert
9671dab2a3
Make so-preflight executable
2021-11-02 11:48:24 -04:00
William Wernert
e6adb46364
Run so-preflight during setup
2021-11-02 11:18:23 -04:00
m0duspwnens
7abb2e5935
monitor interface graph total
2021-11-02 11:07:29 -04:00
m0duspwnens
561f86eac8
change eps graphs to use logstash data and not consumptioneps script
2021-11-02 11:06:29 -04:00
William Wernert
9a9d1480de
Manage docker group's gid to prevent gid overlap
2021-11-02 10:41:36 -04:00
Josh Brower
8b52f87a60
Merge pull request #6066 from Security-Onion-Solutions/fix/evtx-import-elastic-creds
...
Fix/evtx import elastic creds
2021-11-02 09:25:25 -04:00
Josh Brower
a6f399acf4
Fix evtx import logging
2021-11-02 09:19:32 -04:00
Josh Brower
3534256517
Add evtx import logging
2021-11-02 09:03:52 -04:00
m0duspwnens
b109d95d6f
add max to zeek capture loss legend
2021-11-02 09:02:48 -04:00
Josh Brower
b756c0cd38
Pull ES Creds at Runtime
2021-11-02 08:57:11 -04:00
m0duspwnens
3517ea3f2a
select last value for cpucount var
2021-11-02 08:41:57 -04:00
m0duspwnens
5d414c8bdd
remove logstash row from manager
2021-11-02 08:36:13 -04:00
Josh Brower
2b56b53c15
Merge pull request #6064 from Security-Onion-Solutions/feature/support_non-wel_beats
...
Support non-WEL Beats
2021-11-02 08:29:48 -04:00
Josh Brower
2ba619144c
Support non-WEL Beats
2021-11-02 08:23:29 -04:00
m0duspwnens
a9be0a0409
create and add mon traffic combined graph to sensor dash
2021-11-02 07:55:39 -04:00
m0duspwnens
bf116d210e
mostly overview dash panel changes
2021-11-01 17:48:02 -04:00
William Wernert
f8b62b63f9
Merge pull request #6061 from Security-Onion-Solutions/foxtrot
...
Fix NIC string values for VLAN tagged interfaces
2021-11-01 16:43:52 -04:00
m0duspwnens
f4d9455872
revert to b63b50d98c
2021-11-01 16:10:13 -04:00
m0duspwnens
936c796b9d
Revert "graph changes"
...
This reverts commit 8857fca797 .
2021-11-01 15:19:50 -04:00
m0duspwnens
8ff122262c
Revert "update many panels"
...
This reverts commit b63b50d98c .
2021-11-01 14:50:57 -04:00
m0duspwnens
c4a1fbd82a
remove old json
2021-11-01 14:39:03 -04:00
m0duspwnens
8857fca797
graph changes
2021-11-01 14:36:41 -04:00
m0duspwnens
b63b50d98c
update many panels
2021-11-01 14:06:01 -04:00
William Wernert
c17187708e
Merge branch 'dev' into foxtrot
2021-11-01 12:46:43 -04:00
Mike Reeves
095e6bd48c
Merge pull request #6044 from Burak-PLT/patch-1
...
Update auth.sls
2021-11-01 10:22:16 -04:00
m0duspwnens
c4b9244f9a
add gridPos
2021-10-29 17:24:50 -04:00
m0duspwnens
2ba548fcfc
grafana bug fixes and improvements - https://github.com/Security-Onion-Solutions/securityonion/issues/6007
2021-10-29 17:11:51 -04:00
William Wernert
f76a52b2ee
Fix NIC string values for VLAN tagged interfaces
2021-10-29 13:34:23 -04:00
William Wernert
b555ad16da
Merge pull request #6052 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2021-10-29 10:52:51 -04:00
William Wernert
b1c67f696e
Re-order logic to maintain backwards compatibility
2021-10-29 10:47:05 -04:00
William Wernert
d08149f728
Don't set INTERWEBS variable on automated minions
2021-10-29 10:11:47 -04:00
William Wernert
a5cba5ecf8
Merge branch 'dev' into foxtrot
2021-10-29 10:01:46 -04:00
Burak-PLT
f081938be5
Update auth.sls
...
Change default password lengths to 72 characters from 20.
2021-10-28 16:00:58 -04:00
William Wernert
c2b18efdbb
Minions still need to be ISO installs to be airgap
2021-10-28 11:59:42 -04:00
William Wernert
6b480a5ba4
Change airgap check to something that doesn't require root
2021-10-28 11:51:50 -04:00
William Wernert
d6eeb0b735
Gen ssh key sooner
2021-10-28 10:04:03 -04:00
Josh Patterson
3000c57428
Merge pull request #6039 from Security-Onion-Solutions/issue/5759
...
Issue/5759
2021-10-28 09:24:44 -04:00
m0duspwnens
5c5b4004e9
Merge remote-tracking branch 'remotes/origin/dev' into issue/5759
2021-10-28 08:52:04 -04:00
Josh Patterson
05e0f92ec5
Merge pull request #6036 from Security-Onion-Solutions/issue/5955
...
include ssl state in telegraf state
2021-10-28 08:50:57 -04:00
m0duspwnens
0cea5e8f22
include ssl state in telegraf state
2021-10-28 08:46:27 -04:00
m0duspwnens
7eb42fa6bd
change boolean
2021-10-28 08:43:03 -04:00
m0duspwnens
18ce9c7819
disable zeekpacketlosscron and telegraf checks if zeek is diabled via pillar
2021-10-28 07:46:02 -04:00
Mike Reeves
b3e5319806
Merge pull request #6028 from Security-Onion-Solutions/telecluster
...
Enable cluster stats
2021-10-27 16:37:42 -04:00
Mike Reeves
c8c8cf203f
Enable cluster stats
2021-10-27 15:44:52 -04:00
Josh Patterson
19056b9177
Merge pull request #6027 from Security-Onion-Solutions/issue/5955
...
Issue/5955
2021-10-27 15:07:22 -04:00
William Wernert
75490a2536
Fix typo
2021-10-27 14:59:24 -04:00
William Wernert
eee612e73d
Make folder/file states explicit
...
Rather than using /nsm/zeek (max_depth: 1) create explicit states for /nsm/zeek/spool and /nsm/zeek/spool/state.db that set correct ownership
2021-10-27 11:43:09 -04:00
William Wernert
9e9079f9cb
Reorder airgap prompt and add additional logic
...
Setup should now only ask the user whether to setup as airgap on manager-type installs. For all distributed minions setup will now inherit the airgap boolean from the manager.
2021-10-27 11:03:00 -04:00
William Wernert
331801eec2
Merge branch 'dev' into foxtrot
2021-10-27 10:58:16 -04:00
William Wernert
a0216cea57
Merge pull request #6021 from Security-Onion-Solutions/fix/update-mysql-root-user
...
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:55:11 -04:00
m0duspwnens
e7f43cff5e
limit nodes that bind filebeat certs in so-logstash
2021-10-27 10:45:10 -04:00
William Wernert
90d473f2d6
Update ip for root user in mysql when running so-ip-update
2021-10-27 10:42:33 -04:00
m0duspwnens
bf403a8307
only manager nodes get cert, key and att&ck binds
2021-10-27 09:47:12 -04:00
m0duspwnens
58d62f29ea
include ssl state in registry state
2021-10-26 11:55:47 -04:00
Mike Reeves
bcf03773c0
Merge pull request #6009 from Security-Onion-Solutions/stenoports
...
Remove port bindings for steno
2021-10-26 10:58:11 -04:00
m0duspwnens
c0dd9efd9b
change so-thehive-es binds and requires
2021-10-26 10:50:16 -04:00
m0duspwnens
36ae07b78e
change timeout from 60 to 120
2021-10-26 10:49:50 -04:00
Mike Reeves
d77328608e
Remove port bindings for steno
...
Steno runs in host mode so port bindings are not required
2021-10-26 10:23:33 -04:00
m0duspwnens
682cbfd223
remove the mode
2021-10-26 09:23:24 -04:00
m0duspwnens
fa2edb2b59
make cortex_init and hive_init time out after 1 minutes vs 5 minutes
2021-10-26 08:39:30 -04:00
m0duspwnens
0c679b62b2
Merge remote-tracking branch 'remotes/origin/dev' into issue/5955
2021-10-25 16:29:41 -04:00
m0duspwnens
7e8d74e770
just use mode
2021-10-25 15:50:27 -04:00
m0duspwnens
9a78d13bee
change perms on mysql
2021-10-25 15:37:23 -04:00
Jason Ertel
c469d12a49
Merge pull request #6002 from Security-Onion-Solutions/kilo
...
Update whiptail links to use latest docs
2021-10-25 15:08:31 -04:00
Jason Ertel
d5f42e0d7c
Update whiptail links to use latest docs
2021-10-25 15:06:42 -04:00
weslambert
926551d398
Merge pull request #5998 from Security-Onion-Solutions/fix/hl_host_name
...
Rename HTTP client headers and host
2021-10-25 13:21:11 -04:00
weslambert
3be0d05eea
Update field removal based on HTTP input changes
2021-10-25 13:16:30 -04:00
weslambert
7fa43a276a
Rename default headers and host for HTTP input
2021-10-25 13:15:20 -04:00
William Wernert
2bfedbd581
Merge pull request #5996 from Security-Onion-Solutions/fix/escape-node-desc
...
Escape single quotes and allow for any character in node description
2021-10-25 10:53:36 -04:00
William Wernert
dca30146ab
Merge branch 'dev' into foxtrot
2021-10-25 10:50:25 -04:00
William Wernert
6e34905b42
Escape single quotes and allow for any character in node description
2021-10-25 10:48:09 -04:00
m0duspwnens
ee7e714f43
change to file_mode
2021-10-22 16:55:23 -04:00
m0duspwnens
d7e5377a44
more requires
2021-10-22 16:46:45 -04:00
William Wernert
38b16a507b
Update ip for root user in mysql when running so-ip-update
2021-10-22 15:29:32 -04:00
William Wernert
17af513692
Escape single quotes and allow for any character in node description
2021-10-22 15:28:37 -04:00
m0duspwnens
283f7296bc
fix require
2021-10-22 14:45:22 -04:00
m0duspwnens
9f6407fcb0
fix dupe ids
2021-10-22 14:26:04 -04:00
m0duspwnens
f61400680d
fix dupe ids
2021-10-22 14:22:15 -04:00
m0duspwnens
fed8bfac67
more requires on docker containers
2021-10-22 14:10:59 -04:00
William Wernert
62971d8c15
Add Fleet custom hostname to end summary
2021-10-22 11:57:47 -04:00
William Wernert
352e30f9e1
Add CUSTOM_FLEET_HOSTNAME to subjectAltName of fleet.key
...
Resolves #4319
2021-10-22 11:16:29 -04:00
m0duspwnens
451b19dc4d
change from file to x509
2021-10-22 09:53:20 -04:00
William Wernert
d5d970672d
Merge pull request #5974 from Security-Onion-Solutions/foxtrot
...
Add so-deny script + rewrite so-allow to match
2021-10-21 16:37:05 -04:00
m0duspwnens
f93c6146f5
docker binds requires
2021-10-21 15:24:55 -04:00
weslambert
40dd33affe
Merge pull request #5971 from Security-Onion-Solutions/feature/es_templates
...
Add .keyword subfield for conflict fields
2021-10-21 15:07:00 -04:00
William Wernert
f374dcbb58
Check for IP environment variable in so-allow and so-deny
2021-10-21 13:54:06 -04:00
weslambert
77ee1db44c
Add .keyword subfield for conflict fields
2021-10-21 12:56:03 -04:00
Josh Patterson
8784d65023
Merge pull request #5967 from Security-Onion-Solutions/issue/5954
...
require files before starting soc or kratos
2021-10-21 11:15:36 -04:00
William Wernert
15fe7512b7
Install lxml during setup and in common state
2021-10-21 10:49:41 -04:00
William Wernert
0beeeb94bf
Actually add new so-allow script
2021-10-21 10:48:17 -04:00
m0duspwnens
928aed27c5
require files before starting soc or kratos
2021-10-20 17:04:02 -04:00
William Wernert
387d4d6ad5
Add so-deny script + rewrite so-allow to match so-deny
2021-10-20 16:44:57 -04:00
William Wernert
adf6cb4b3c
Merge branch 'dev' into foxtrot
2021-10-20 16:44:50 -04:00
William Wernert
0ed2ce0766
Fix validation.sh tests
2021-10-20 16:44:09 -04:00
William Wernert
b5cb47e066
Fix sbin perms
2021-10-20 16:43:55 -04:00
Josh Patterson
8061508330
Merge pull request #5961 from Security-Onion-Solutions/issue/5960
...
Issue/5960
2021-10-20 16:08:50 -04:00
m0duspwnens
adffb11800
fix redis port
2021-10-20 15:39:21 -04:00
m0duspwnens
8619af59cc
servers to list format
2021-10-20 15:02:33 -04:00
m0duspwnens
7ecfb55b70
fix pillar call
2021-10-20 14:50:50 -04:00
m0duspwnens
b496810b63
add redis and logstash input plugins to telegraf
2021-10-20 14:46:47 -04:00
Mike Reeves
e1ad02c28d
Merge pull request #5949 from Security-Onion-Solutions/kilo
...
Fix Docker-created corruption of SOC user roles file
2021-10-19 18:37:37 -04:00
Jason Ertel
2f8bb5a2a6
Fix Docker-created corruption of SOC user roles file
2021-10-19 16:04:10 -04:00
weslambert
6f3e441bf7
Merge pull request #5945 from Security-Onion-Solutions/fix/soc_index_pattern
...
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:05:40 -04:00
Mike Reeves
7f1585dcc0
Merge pull request #5942 from Security-Onion-Solutions/tunesteno
...
Fix Steno Math for PL
2021-10-19 13:03:50 -04:00
weslambert
9453ed7fa1
Remove space to allow pattern(s) to be correctly interpreted
2021-10-19 13:01:40 -04:00
Mike Reeves
64f25961b0
Fix Steno Math for PL
2021-10-19 11:15:58 -04:00
Mike Reeves
b9a3d3a6a9
Fix Steno Math for PL
2021-10-19 11:14:02 -04:00
m0duspwnens
36cb0d6c42
remove space
2021-10-18 14:34:33 -04:00
m0duspwnens
1b2268dfe5
load kibana configs during setup
2021-10-18 14:30:47 -04:00
Mike Reeves
00e5b54dda
Merge pull request #5911 from Security-Onion-Solutions/tunesteno
...
Add Steno Tuning Options
2021-10-18 09:01:14 -04:00
Mike Reeves
4016b416ec
Merge pull request #5923 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.15.1
2021-10-16 09:15:06 -04:00
weslambert
7590728a0b
Merge pull request #5915 from Security-Onion-Solutions/feature/ti_module
...
Add TI module
2021-10-15 17:17:33 -04:00
weslambert
bb36fc1ed8
Add TI module defaults
2021-10-15 17:16:38 -04:00
weslambert
d0a6dafc8b
Add TI module
2021-10-15 17:09:59 -04:00
m0duspwnens
76097476d3
remove includes
2021-10-15 16:57:38 -04:00
m0duspwnens
8b3b0bf160
fix opts
2021-10-15 16:51:11 -04:00
m0duspwnens
f19680b3e6
fix opts
2021-10-15 16:50:03 -04:00
m0duspwnens
7e1bbe3cc2
define MAANGER
2021-10-15 16:14:14 -04:00
m0duspwnens
947285e932
update cmd.run amd s_o files
2021-10-15 16:06:25 -04:00
m0duspwnens
1741f5068a
update config-load to do an update or import
2021-10-15 15:35:30 -04:00
Mike Reeves
a9f6c84d7c
Add Steno Tuning Options
2021-10-15 14:17:54 -04:00
weslambert
59852841ff
Add keyword subfield for event.module
2021-10-15 13:29:50 -04:00
weslambert
6f1f7d2a63
Merge pull request #5905 from Security-Onion-Solutions/feature/soc_es_index_pattern
...
Allow setting ES index patterns for SOC in pillar
2021-10-15 13:28:04 -04:00
Jason Ertel
8de8d58155
Upgrade to ES 7.15.1
2021-10-15 13:27:08 -04:00
Wes Lambert
8feeff97b5
Add EG index pattern during setup (if enabled)
2021-10-15 16:19:19 +00:00
Wes Lambert
032373187c
Allow setting ES index patterns for SOC in pillar
2021-10-15 16:02:53 +00:00
William Wernert
db2b70f655
Merge pull request #5900 from Security-Onion-Solutions/foxtrot
...
Replace rather than append to Kibana misc log
2021-10-15 10:27:25 -04:00
Jason Ertel
1800ec4570
Upgrade to Elastalert 2 v2.2.2
2021-10-15 09:25:44 -04:00
Mike Reeves
8a5960c220
Merge pull request #5896 from Security-Onion-Solutions/kilo
2021-10-14 18:05:33 -04:00
Jason Ertel
9797a15218
Fix issue with 'so-user delete' resetting all user roles - note that this function is not technically supported or published since it's not intended for production use
2021-10-14 17:23:18 -04:00
William Wernert
c7b15a9b1f
Replace rather than append to Kibana misc log
2021-10-14 15:13:55 -04:00
William Wernert
cba97802fe
Fix indent
2021-10-14 15:13:34 -04:00
William Wernert
025256aeaf
Merge pull request #5890 from Security-Onion-Solutions/foxtrot
...
Misc setup changes
2021-10-14 14:55:24 -04:00
weslambert
490f7eaf81
Merge pull request #5886 from Security-Onion-Solutions/feature/eg_pivot
...
Add EG pivot
2021-10-14 14:49:38 -04:00
m0duspwnens
6a2bf11a75
change format of file
2021-10-14 13:43:39 -04:00
m0duspwnens
78d30285b1
seperate securitySolutions load
2021-10-14 13:24:51 -04:00
Wes Lambert
f1fafa015e
Add EG to list of groups to include 127.0.0.1
2021-10-14 16:27:28 +00:00
Wes Lambert
6cdc214582
Add pillar in setup and change name of EG variable
2021-10-14 15:33:37 +00:00
Wes Lambert
15049f44b9
Add EG pivot
2021-10-14 15:15:23 +00:00
Doug Burks
42a642b85c
Merge pull request #5873 from petiepooo/enh-rediscount-tty
...
featreq: remove tty flag in redis-count script
2021-10-14 10:07:07 -04:00
weslambert
3b45e68ead
Merge pull request #5885 from Security-Onion-Solutions/feature/jinjafy_soc_actions
...
Allow SOC actions to use Jinja
2021-10-14 10:03:12 -04:00
Wes Lambert
5ee0ea3fe7
Allow SOC actions to use Jinja
2021-10-14 13:59:55 +00:00
weslambert
55c60f485c
Merge pull request #5884 from Security-Onion-Solutions/feature/hl_eg
...
Add EG firewall allowance via setup
2021-10-14 09:55:07 -04:00
Wes Lambert
78e88e0765
Add EG firewall allowance via setup
2021-10-13 21:42:54 +00:00
Wes Lambert
a9b250c0f4
Add EG firewall config
2021-10-13 21:37:59 +00:00
m0duspwnens
ae9753326a
fix var, quote vars
2021-10-13 16:38:01 -04:00
m0duspwnens
c8fb504ee0
Revert "Merge remote-tracking branch 'remotes/origin/dev' into issue/3933"
...
This reverts commit 54eec92621 , reversing
changes made to 7832e59629 .
2021-10-13 15:22:46 -04:00
m0duspwnens
54eec92621
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 15:19:33 -04:00
m0duspwnens
7832e59629
only load default kibana saved_objects during setup
2021-10-13 15:19:20 -04:00
weslambert
f9001654bb
Merge pull request #5871 from Security-Onion-Solutions/feature/hl_eg
...
Initial EG stuff
2021-10-13 15:07:03 -04:00
Wes Lambert
2a504a061b
Add Curator action files for EG indices
2021-10-13 18:40:34 +00:00
m0duspwnens
bb9c6446e4
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-13 14:01:36 -04:00
Pete
e7581036f7
remove tty/interactive flags
...
This call to docker exec simply returns a number. No interaction (stdin) or tty is required. Specifically, having the -t option prevents running via salt using a command such as:
> salt '*' cmd.run 'so-redis-count'
2021-10-13 13:51:05 -04:00
Wes Lambert
e1629d7ec4
Initial EG stuff
2021-10-13 17:13:07 +00:00
Josh Patterson
b4873bd296
Merge pull request #5868 from Security-Onion-Solutions/issue/5818
...
Issue/5818
2021-10-13 12:52:48 -04:00
m0duspwnens
3044edb104
update comment
2021-10-13 12:38:58 -04:00
m0duspwnens
a495779552
only 3 attempts with 120s max attemps
2021-10-13 12:34:56 -04:00
m0duspwnens
880c1b97b0
remove $ from var
2021-10-13 12:25:11 -04:00
m0duspwnens
7a4fa8879c
change count, attempts and timeout
2021-10-13 12:13:24 -04:00
m0duspwnens
adb8292814
add missing )
2021-10-13 10:37:18 -04:00
m0duspwnens
6e7a5fa326
add timeouts to check_salt_minion_status and check_salt_master_status - https://github.com/Security-Onion-Solutions/securityonion/issues/5818
2021-10-13 09:45:15 -04:00
m0duspwnens
23ea53248d
single line format
2021-10-12 14:15:37 -04:00
m0duspwnens
f1a5991699
add securitySolution.defaultIndex to defaults
2021-10-12 12:35:13 -04:00
m0duspwnens
c69ad091f7
update saved_objects config
2021-10-12 12:02:30 -04:00
William Wernert
b97361fab9
Remove references to xenial in setup
...
Resolves #4292
2021-10-12 10:23:39 -04:00
William Wernert
36e1795295
Add end of setup log messages per #5032
2021-10-12 10:19:47 -04:00
m0duspwnens
498e385484
change name to SAVED_OBJECTS
2021-10-12 10:15:39 -04:00
William Wernert
af687b0706
Remove all holds on Ubuntu reinstall
2021-10-12 10:10:34 -04:00
m0duspwnens
19489f3626
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-12 10:07:40 -04:00
m0duspwnens
89d1df8a1d
change name to SAVED_OBJECTS
2021-10-12 10:07:26 -04:00
William Wernert
946cf81a27
If ANALYST is selected immediately quit setup
2021-10-12 09:48:38 -04:00
Mike Reeves
2561480371
Merge pull request #5850 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.7.6-alpha.1
2021-10-12 08:19:25 -04:00
Jason Ertel
d21dee162d
Add Note field to user traits; Enforce max length restrictions on email, firstname, lastname, and note fields
2021-10-08 12:39:17 -04:00
Mike Reeves
444d067112
Merge pull request #5813 from Security-Onion-Solutions/macleod
...
Highlander changes
2021-10-08 10:06:18 -04:00
Mike Reeves
2a82373051
highlander fixes
2021-10-08 09:32:13 -04:00
Mike Reeves
64758a534c
Set ml to true
2021-10-08 08:42:26 -04:00
m0duspwnens
7517a63008
disabled ml
2021-10-07 13:06:52 -04:00
m0duspwnens
b2facdf31c
add securitySolutions advanced setting
2021-10-07 12:57:28 -04:00
m0duspwnens
4c54d6309c
change host to 0.0.0.0
2021-10-07 09:59:29 -04:00
Jason Ertel
62c3afc81d
Migrate users from locked to inactive during soup
2021-10-06 15:45:35 -04:00
Jason Ertel
7d8c8144b0
Drop obsolete status trait
2021-10-06 12:52:41 -04:00
Jason Ertel
a2c4fce1ef
Switch to use state attribute in identities for enabling/disabling users
2021-10-06 11:53:10 -04:00
m0duspwnens
599aba43d9
restart so-kibaba if config changes
2021-10-06 09:51:16 -04:00
m0duspwnens
fa4f92cdda
change defaults
2021-10-05 17:35:44 -04:00
m0duspwnens
5d98c0d14c
fix dict update
2021-10-05 15:57:57 -04:00
Mike Reeves
27614569e3
Fix set
2021-10-05 14:32:02 -04:00
m0duspwnens
ec357cca3c
fix cars
2021-10-05 12:57:30 -04:00
m0duspwnens
26681ac98a
var for dash saved objevs
2021-10-05 12:46:21 -04:00
m0duspwnens
748f0f2a1d
Merge remote-tracking branch 'remotes/origin/dev' into issue/3933
2021-10-05 12:12:56 -04:00
Mike Reeves
869af548af
Fix spaces for highlander
2021-10-05 11:06:13 -04:00
Mike Reeves
2fd344822d
Add additional roles for highlander
2021-10-05 10:40:40 -04:00
Mike Reeves
a3e0fb127a
Merge pull request #5069 from datlife/datlife/asn-annotation
...
Add ASN annotation for IP
2021-10-05 06:50:31 -04:00
Dat
9569e73bd0
Added ASN annotation for IP
2021-10-04 12:41:20 -07:00
m0duspwnens
96d783b158
merge with dev
2021-10-04 10:39:48 -04:00
m0duspwnens
e0c097c270
add dashboard theme defaults
2021-10-04 10:36:58 -04:00
Mike Reeves
e6fce4cf3e
Merge pull request #5749 from Security-Onion-Solutions/kilo
...
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:55:53 -04:00
Jason Ertel
6ef9a5c95d
Use safe_load to avoid warnings - credit to @clairmont32
2021-10-04 08:53:25 -04:00
Mike Reeves
727613b6e1
Merge pull request #5601 from Security-Onion-Solutions/special
...
Ubuntu 20.04 Beta
2021-10-04 08:51:01 -04:00
Mike Reeves
5013aa8490
Merge pull request #5748 from Security-Onion-Solutions/kilo
...
Merge ES Upgrade, Version Bump into dev
2021-10-04 08:48:07 -04:00
Jason Ertel
72a1b299ac
Bump to 2.3.90
2021-10-04 08:44:51 -04:00
Mike Reeves
cfaa0e679c
Merge pull request #5739 from Security-Onion-Solutions/dev
...
2.3.80
2021-10-01 15:15:54 -04:00
Mike Reeves
4ddf2b49ce
Merge pull request #5669 from Security-Onion-Solutions/2.3.80
...
2.3.80
2021-10-01 15:11:03 -04:00
m0duspwnens
bb95963d73
add missing {{}}
2021-09-30 14:40:13 -04:00
m0duspwnens
dfa9afde0e
change to mode
2021-09-30 14:33:52 -04:00
m0duspwnens
fa2333b9ef
change t file.managed
2021-09-30 14:32:28 -04:00
m0duspwnens
8b9c43915d
fix source
2021-09-30 14:30:00 -04:00
m0duspwnens
36832139b2
pillarize kibana
2021-09-30 14:28:31 -04:00
m0duspwnens
c3bf835566
kibana config
2021-09-30 14:23:49 -04:00
m0duspwnens
39d3c7c6ed
begin pillarization of kibana
2021-09-30 11:48:42 -04:00
Jason Ertel
b1a5527e82
Update ElastAlert to use ElastAlert 2
2021-09-28 07:01:47 -04:00
Jason Ertel
d0592c4293
Update ElastAlert to use ElastAlert 2
2021-09-28 00:51:29 -04:00
Mike Reeves
b1d0e3e93f
2.3.80
2021-09-27 12:32:45 -04:00
Mike Reeves
b069377c8a
2.3.80
2021-09-27 10:13:42 -04:00
Jason Ertel
e9a44c6e1b
Merge pull request #5662 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update README.md
2021-09-27 09:28:46 -04:00
Mike Reeves
275163f85d
Update README.md
2021-09-27 07:36:54 -04:00
William Wernert
98f74c25ba
Fix variable reference in so-functions
2021-09-24 12:32:56 -04:00
William Wernert
3064800820
Merge pull request #5636 from Security-Onion-Solutions/fix/soup-2.3.80
...
Misc. soup fixes
2021-09-23 13:03:43 -04:00
William Wernert
f8bea82430
Make redirect consistent with setup
2021-09-23 12:57:08 -04:00
William Wernert
8b905b585d
Fix redirect to append
2021-09-23 12:55:06 -04:00
William Wernert
b44358fc26
Add set +e after final upgrade steps and before post-upgrade checks
2021-09-23 12:49:42 -04:00
William Wernert
8a9dcb7fdb
Fix "upgrade to" message
...
Only specify "to" version and change when the upgrade message occurs
2021-09-23 12:47:22 -04:00
William Wernert
a01d49981c
Redirect thehive/cortex migrate curl output to soup log
2021-09-23 12:45:44 -04:00
William Wernert
b8b1867e52
Tell user what soup is doing at end of upgrade
2021-09-23 12:43:23 -04:00
William Wernert
292ce37ce4
Merge pull request #5632 from Security-Onion-Solutions/fix/logscan-soup
...
Add logscan to images for pull during soup if it's enabled
2021-09-23 10:13:20 -04:00
William Wernert
73dacdcbff
Add logscan to images for pull during soup if it's enabled
2021-09-23 09:52:23 -04:00
Josh Patterson
bea7555464
Merge pull request #5631 from Security-Onion-Solutions/80soup
...
80soup
2021-09-22 16:01:45 -04:00
m0duspwnens
52c1298b9b
notify of custom es config
2021-09-22 15:16:07 -04:00
m0duspwnens
cdb9dcbaec
notify of custom es config
2021-09-22 15:07:36 -04:00
Mike Reeves
37153288e8
Merge pull request #5627 from Security-Onion-Solutions/80soup
...
ignore manager pillar file for noderoutetype
2021-09-22 12:03:55 -04:00
m0duspwnens
edf75255cf
ignore manager pillar file for noderoutetype
2021-09-22 12:01:32 -04:00
Jason Ertel
9eb6f5942e
Merge pull request #5623 from Security-Onion-Solutions/kilo
...
Prevent email addresses from having uppercase characters
2021-09-22 09:10:38 -04:00
Jason Ertel
dae41d279a
Prevent emails addresses from having uppercase characters
2021-09-22 08:25:55 -04:00
Mike Reeves
07288367cf
Merge pull request #5611 from Security-Onion-Solutions/80soup
...
match elasticsearch at beginning of line
2021-09-21 15:42:09 -04:00
m0duspwnens
f4186feffa
move node_route_type
2021-09-21 15:40:49 -04:00
m0duspwnens
d82e91f69e
match elasticsearch at beginning of line
2021-09-21 13:54:45 -04:00
Josh Patterson
a2680fad0a
Merge pull request #5605 from Security-Onion-Solutions/80soup
...
fi xquotes
2021-09-21 13:02:58 -04:00
m0duspwnens
5c2be487f5
fi xquotes
2021-09-21 13:01:40 -04:00
Mike Reeves
531c9de488
Merge pull request #5600 from petiepooo/petiepooo-raidstat-fix
...
missing dollarsign
2021-09-21 11:35:57 -04:00
Pete
19efa493ad
missing dollarsign
2021-09-21 11:21:07 -04:00
Mike Reeves
0db3f14261
Merge pull request #5598 from Security-Onion-Solutions/80soup
...
Soup Changes for True Clusters
2021-09-21 09:57:12 -04:00
Mike Reeves
ed28e4d000
Soup Changes for True Clusters
2021-09-21 09:55:49 -04:00
Mike Reeves
2c8cbf0db1
Soup Changes for True Clusters
2021-09-21 09:53:09 -04:00
Mike Reeves
c1537335b1
Fix Python Problem
2021-09-20 19:05:01 -04:00
Mike Reeves
5f475ff9cb
Fix Python Problem
2021-09-20 18:46:43 -04:00
Mike Reeves
481ffb1cda
Fix Grain
2021-09-20 18:12:18 -04:00
Mike Reeves
50b78681f2
Ubuntu 20.04 Support
2021-09-20 17:24:47 -04:00
Jason Ertel
3924b8f5db
Merge pull request #5586 from Security-Onion-Solutions/kilo
...
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:56:30 -04:00
Jason Ertel
a9049eccd4
Ensure identity ID parm is quoted now that it doesn't have embedded quotes in the value
2021-09-20 13:30:05 -04:00
Mike Reeves
1a7237bcdf
Merge pull request #5583 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2021-09-20 10:44:20 -04:00
Mike Reeves
1e5e1c9ef0
Update soup
2021-09-20 10:42:55 -04:00
Josh Patterson
47cd1ddc0a
Merge pull request #5580 from Security-Onion-Solutions/issue/1257
...
Issue/1257 - Pillarize ES
2021-09-20 09:31:03 -04:00
m0duspwnens
aed73511e4
file cleanup, comment cleanup
2021-09-20 09:24:03 -04:00
Jason Ertel
a3f62c81c3
Merge pull request #5577 from Security-Onion-Solutions/kilo
...
Continuation of auth enhancements
2021-09-20 06:30:36 -04:00
Jason Ertel
730503b69c
Ensure highstate migrates user roles
2021-09-18 23:17:49 -04:00
Jason Ertel
3508f3d8c1
Ensure ES user/role files are generated even if the primary admin user isn't yet created, since the system users are necessary for other installation functions
2021-09-18 19:20:43 -04:00
Jason Ertel
5704906b11
Create empty files for Docker to mount while installation continues
2021-09-18 15:49:05 -04:00
Jason Ertel
357c1db445
Recover from situation where roles file is corrupted
2021-09-18 11:08:35 -04:00
Jason Ertel
5377a1a85e
Recover from situation where roles file is corrupted
2021-09-18 11:06:54 -04:00
Jason Ertel
7f2d7eb038
Continue migration of user emails to IDs
2021-09-18 07:20:34 -04:00
Jason Ertel
30e781d076
Use user ID instead of email as role master
2021-09-17 17:54:38 -04:00
m0duspwnens
01323cc192
fix clustername redirect
2021-09-17 15:44:54 -04:00
m0duspwnens
109c83d8c3
move custom es cluster name pillar location
2021-09-17 15:29:41 -04:00
m0duspwnens
e864bc5404
move custom es cluster name pillar location
2021-09-17 15:28:35 -04:00
Josh Brower
22eb82e950
Merge pull request #5566 from Security-Onion-Solutions/feature/disable_services
...
Add support for disabling Zeek and Suricata
2021-09-17 14:18:03 -04:00
m0duspwnens
b877aa44bc
update dict
2021-09-17 14:10:45 -04:00
Josh Brower
4d307c53e8
Add support for disabling Zeek and Suricata
2021-09-17 13:01:50 -04:00
m0duspwnens
d0c87cd317
allow for pillar override of defaults
2021-09-17 12:11:12 -04:00
m0duspwnens
0d074dafd4
add missing defaults
2021-09-17 09:52:50 -04:00
m0duspwnens
5b77dc109f
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-16 16:54:23 -04:00
m0duspwnens
3ce48acadd
change cluster_settings to config
2021-09-16 16:44:31 -04:00
Jason Ertel
fbd9bab2f1
Split apart roles and users into separate maps
2021-09-16 16:08:55 -04:00
m0duspwnens
5526a2bc3a
reduce defaults.yaml
2021-09-16 15:32:08 -04:00
weslambert
18d81352c6
Merge pull request #5537 from Security-Onion-Solutions/delta
...
Add improved ignore functionality for YARA rules used by Strelka and add default ignored rules that break compilation
2021-09-16 10:38:49 -04:00
m0duspwnens
889d235c45
no box type more manager in true cluster
2021-09-16 09:15:24 -04:00
Jason Ertel
3fc26312e0
Remove x-user-id header from unauthenticated proxied requests
2021-09-16 08:52:31 -04:00
Jason Ertel
b81d38e392
Merge branch 'dev' into kilo
2021-09-16 07:44:35 -04:00
Jason Ertel
82da0041a4
Add limited roles with restricted visibility
2021-09-16 07:44:15 -04:00
m0duspwnens
782b01e76f
seed_hosts to list
2021-09-15 17:07:52 -04:00
m0duspwnens
3bf9685df8
fix seed_hosts append
2021-09-15 17:00:16 -04:00
m0duspwnens
4cf91f6c86
fix dict update
2021-09-15 15:51:00 -04:00
m0duspwnens
a43b37f234
fix dict update
2021-09-15 15:49:18 -04:00
m0duspwnens
e0dc62b6e9
fix dict update
2021-09-15 15:43:47 -04:00
m0duspwnens
c213834316
update the dict
2021-09-15 15:24:40 -04:00
Josh Brower
c06668c68e
Merge pull request #5527 from Security-Onion-Solutions/feature/so-import-evtx
...
Feature/so import evtx
2021-09-15 14:17:15 -04:00
Josh Brower
a75238bc3f
so-import-evtx - fix ingest formatting
2021-09-15 14:13:16 -04:00
Josh Brower
ac417867ed
so-import-evtx - final fixes
2021-09-15 14:06:08 -04:00
m0duspwnens
1614b70853
update cluster name if true cluster
2021-09-15 13:45:43 -04:00
Mike Reeves
0882158e03
Merge pull request #5525 from Security-Onion-Solutions/soup80
...
soup changes 2.3.80
2021-09-15 13:44:54 -04:00
m0duspwnens
1a03853a7c
fix extend
2021-09-15 13:38:29 -04:00
Mike Reeves
aff571faf2
soup changes 2.3.80
2021-09-15 13:32:52 -04:00
m0duspwnens
e0faa4c75b
Merge branch 'issue/1257' of https://github.com/Security-Onion-Solutions/securityonion into issue/1257
2021-09-15 13:09:35 -04:00
m0duspwnens
e3e2e1d851
logic for truecluster to map file
2021-09-15 13:09:04 -04:00
weslambert
2affaf07a2
Merge pull request #5521 from Security-Onion-Solutions/fix/strelka-yara
...
Fix/strelka yara
2021-09-15 11:33:44 -04:00
weslambert
39e5ded58d
Refactor ignore list and only ignore for signature-base for now
2021-09-15 11:32:29 -04:00
weslambert
4d41d3aee1
Ignore these rules by default because they are causing issues with YARA compilation with Strelka
2021-09-15 10:29:11 -04:00
weslambert
5c8067728e
Remove unnecessary logic
2021-09-15 10:22:17 -04:00
Josh Brower
1d905124d3
Merge pull request #5519 from Security-Onion-Solutions/fix/fleet-link
...
Fix Fleet Link Logic
2021-09-15 09:30:21 -04:00
Josh Brower
e0a289182f
Fix Fleet Link Logic
2021-09-15 09:28:23 -04:00
m0duspwnens
551dba955c
set roles empty list
2021-09-15 09:20:33 -04:00
Jason Ertel
9970e54081
Adjust custom_role examples to be more realistic
2021-09-14 14:03:22 -04:00
Jason Ertel
ff989b1c73
Include wording in so-user relating to optional role parameter
2021-09-14 14:03:00 -04:00
Mike Reeves
2ffb723bbd
Rename so-common-template.json to so-common-template.json.jinja
2021-09-14 13:58:45 -04:00
Mike Reeves
6ae2fba71f
Update search.sls
2021-09-14 13:57:26 -04:00
Mike Reeves
2cc25587d9
Update eval.sls
2021-09-14 13:57:04 -04:00
Mike Reeves
614a6dc9fe
Update manager.sls
2021-09-14 13:56:43 -04:00
Josh Brower
4b7667d87f
Merge pull request #5508 from Security-Onion-Solutions/fix/fleet-link
...
Fleet SA - SOC Link Fix
2021-09-14 13:29:20 -04:00
Josh Brower
74b0b365bd
Fleet SA - SOC Link Fix
2021-09-14 13:23:07 -04:00
Josh Brower
0b0d508585
so-import-evtx - tweaks
2021-09-14 12:01:14 -04:00
m0duspwnens
0534a2dda3
Merge remote-tracking branch 'remotes/origin/dev' into issue/1257
2021-09-13 15:04:50 -04:00
m0duspwnens
f8ab0ac8a9
config changes
2021-09-13 15:04:39 -04:00
m0duspwnens
0ae09cc630
config changes
2021-09-13 09:49:56 -04:00
Mike Reeves
332c4dda22
Merge pull request #5469 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Allow so-rule-update to accept any number of args
2021-09-10 14:41:55 -04:00
William Wernert
679faddd52
Update so-rule-update to pass all args to docker exec
...
Instead of passing $1, build a string from all args and add that to the command string for the docker exec statement
2021-09-10 13:44:37 -04:00
William Wernert
0b42b19763
Update so-rule-update to source so-common
2021-09-10 13:41:58 -04:00
William Wernert
943bd3e902
Merge pull request #5468 from Security-Onion-Solutions/fix/idstools-rule-clear
...
Add `--force` flag to idstools-rulecat under so-rule-update
2021-09-10 13:17:16 -04:00
Mike Reeves
4af6a901a1
Merge pull request #5461 from Security-Onion-Solutions/truclusterrator
...
Add new hunt fields
2021-09-10 13:17:01 -04:00
William Wernert
9c310de459
Add --force flag to idstools-rulecat under so-rule-update
...
This forces idstools to pull from the url each time, which prevents it from clearing all.rules if idstools-rulecat is run twice within 15 minutes by any method (either restarting the container or running so-rule-update)
2021-09-10 13:15:09 -04:00
Mike Reeves
4f6a3269cb
Add more detail to syscollector
2021-09-10 09:59:47 -04:00
Doug Burks
6a2e1df7d4
Merge pull request #5460 from Security-Onion-Solutions/feature/welcome-link-docs
...
FEATURE: Add docs link to Setup #5459
2021-09-10 07:27:48 -04:00
doug
db50ef71b4
FEATURE: Add docs link to Setup #5459
2021-09-10 06:19:16 -04:00
Jason Ertel
4e2d5018a2
Merge pull request #5455 from Security-Onion-Solutions/kilo
...
Consolidate whiptail screens
2021-09-09 14:57:28 -04:00
Jason Ertel
94688a9adb
Eliminate adv component popup
2021-09-09 14:29:09 -04:00
Jason Ertel
63f67b3500
Rephrase screen that warns about more RAM requirements
2021-09-09 14:16:05 -04:00
Mike Reeves
eaa5e41651
Merge pull request #5450 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Raid Status for cloud
2021-09-09 11:09:49 -04:00
Mike Reeves
c83f119cc0
Update so-raid-status
2021-09-09 10:59:35 -04:00
Mike Reeves
5d235e932c
Fix Raid Status for cloud
2021-09-09 10:46:28 -04:00
m0duspwnens
93f2cd75a4
add the jinja template
2021-09-09 10:19:46 -04:00
m0duspwnens
f06ab8b77d
testing defaults.yaml
2021-09-09 08:55:36 -04:00
weslambert
03b45512fa
Merge pull request #5436 from Security-Onion-Solutions/fix/kibana_server_url
...
Incude server.publicBaseUrl
2021-09-08 12:13:48 -04:00
weslambert
b8600be0f1
Incude server.publicBaseUrl
2021-09-08 12:12:09 -04:00
Jason Ertel
19a02baa7c
Merge pull request #5425 from Security-Onion-Solutions/kilo
...
Auth enhancements
2021-09-07 13:10:36 -04:00
Jason Ertel
3c59579f99
Add maintenance privilege for analysts to refresh indices
2021-09-07 13:03:30 -04:00
Mike Reeves
3f989590ad
Merge pull request #5402 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Enable index sorting by default but allow it to be disabled
2021-09-07 11:28:40 -04:00
Jason Ertel
72cff7ec7a
Merge branch 'dev' into kilo
2021-09-07 10:49:08 -04:00
Mike Reeves
e3900606dc
Enable index sorting by default but allow it to be disabled
2021-09-04 10:42:18 -04:00
Mike Reeves
a2fd8ae200
Merge pull request #5401 from rwaight/dev
...
Enable index sorting in `so-common-template.json`
2021-09-04 10:32:57 -04:00
Rob Waight
b7591093cf
Add index sorting to so-common-template.json
...
Add index sorting to so-common-template.json
2021-09-04 09:45:03 -04:00
Rob Waight
51439cd1ab
Merge pull request #1 from Security-Onion-Solutions/dev
...
sync with SO/Dev
2021-09-04 09:43:23 -04:00
Jason Ertel
94ea1f856b
Add auditor role; update analyst role with correct syntax
2021-09-03 15:59:48 -04:00
Jason Ertel
fbbb7f4e85
Add auditor role; update analyst role with correct syntax
2021-09-03 15:54:05 -04:00
Mike Reeves
7b3a0cd1e4
Merge pull request #5394 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Add maxfiles to the steno config
2021-09-03 10:49:59 -04:00
Mike Reeves
9fb28709d5
Add maxfiles to the steno config
2021-09-03 10:47:00 -04:00
Jason Ertel
649f339934
Correct typo
2021-09-02 20:30:48 -04:00
Jason Ertel
f659079542
Consolidate password validation messaging
2021-09-02 19:12:32 -04:00
Jason Ertel
ce70380f0f
resolve so-user errors from recent auth changes
2021-09-02 17:59:33 -04:00
Jason Ertel
c4d402d8b4
Ensure role file exists before ES state is run
2021-09-02 15:45:47 -04:00
Mike Reeves
9f5dafd560
More Event Fields
2021-09-02 13:48:18 -04:00
Mike Reeves
1cee603ee4
Squid event fields
2021-09-02 13:24:04 -04:00
William Wernert
a14854d56d
Merge pull request #5383 from Security-Onion-Solutions/feature/soup-y
...
Add logic to check unattended flag when checking OS updates
2021-09-02 11:50:45 -04:00
Mike Reeves
2bf471054b
Cloudtrail Event Fields
2021-09-02 11:46:18 -04:00
William Wernert
56894b9581
Add logic to check unattended flag when checking if updates are available
2021-09-02 11:15:32 -04:00
Jason Ertel
10126bb7ef
Auth enhancements
2021-09-02 09:44:57 -04:00
Jason Ertel
6dfc943e8c
Merge pull request #5382 from Security-Onion-Solutions/kilo
...
Correct invalid password message
2021-09-02 07:15:09 -04:00
Jason Ertel
84ecc3cba7
Merge branch 'dev' into kilo
2021-09-02 07:09:36 -04:00
Jason Ertel
0ad3d826eb
Invalid password message should also mention that dollar signs are not allowed
2021-09-02 07:07:36 -04:00
William Wernert
d785dafe2f
Merge pull request #5374 from Security-Onion-Solutions/feature/soup-y
...
Add unattended soup flag, and iso location argument for air gap
2021-09-01 16:48:55 -04:00
Mike Reeves
e3dffcc2cb
Merge pull request #5373 from Security-Onion-Solutions/truclusterrator
...
Add eventfields for new default logs
2021-09-01 16:48:51 -04:00
Mike Reeves
556bad6925
Add eventfields for new default logs
2021-09-01 15:13:43 -04:00
William Wernert
446821e9fd
Use exit code 0 when printing error message before exiting soup
2021-09-01 15:11:18 -04:00
William Wernert
576c893eb3
Exit on missing file argument
2021-09-01 15:08:53 -04:00
Mike Reeves
34a5d6e56a
Merge pull request #5367 from Security-Onion-Solutions/truclusterrator
...
Allow closing of fb module indices in global
2021-09-01 10:54:02 -04:00
Mike Reeves
324e6b12e2
Add jinja template
2021-09-01 09:32:32 -04:00
Mike Reeves
007b15979a
Non Cluster honor closed indices values
2021-09-01 09:25:14 -04:00
Mike Reeves
c168703e9f
Merge pull request #5362 from Security-Onion-Solutions/truclusterrator
...
True Cluster Curator Overhaul
2021-08-31 17:17:47 -04:00
Mike Reeves
527a793e94
Only enable curator on Manager in true cluster
2021-08-31 16:59:41 -04:00
Mike Reeves
61ebedc0e9
Only enable curator on Manager in true cluster
2021-08-31 16:56:08 -04:00
Mike Reeves
e09aa4e5d4
Only enable curator on Manager in true cluster
2021-08-31 16:35:19 -04:00
Mike Reeves
e7b04b862f
Only enable curator on Manager in true cluster
2021-08-31 16:21:48 -04:00
Mike Reeves
62edfd0b7f
Only enable curator on Manager in true cluster
2021-08-31 16:20:42 -04:00
Mike Reeves
958575c22a
Only enable curator on Manager in true cluster
2021-08-31 16:17:55 -04:00
Mike Reeves
0c8e11dc9f
Only enable curator on Manager in true cluster
2021-08-31 16:13:05 -04:00
Mike Reeves
5b9ef3bc0d
Only enable curator on Manager in true cluster
2021-08-31 15:55:44 -04:00
Mike Reeves
c12f380bc3
Only enable curator on Manager in true cluster
2021-08-31 15:51:34 -04:00
Mike Reeves
dc25ed2594
Add logic for cronjobs
2021-08-31 15:43:48 -04:00
Mike Reeves
9f51f02ab4
Add logic for cronjobs
2021-08-31 15:40:09 -04:00
Mike Reeves
f6f4375e13
Add logic for cronjobs
2021-08-31 15:34:26 -04:00
Mike Reeves
ed116cf850
Add Actions for warm indices
2021-08-31 15:09:26 -04:00
Mike Reeves
476ecccbc1
Add Actions for warm indices
2021-08-31 15:08:10 -04:00
Mike Reeves
c09cebbd6b
Add Actions for close and delete in cluster mode
2021-08-31 13:42:11 -04:00
Mike Reeves
0ed92fd9bd
Merge pull request #5359 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 Wazuh hotfix into dev
2021-08-31 13:39:21 -04:00
Jason Ertel
c3454c9e8a
Merge branch 'master' into kilo
2021-08-31 13:37:46 -04:00
Mike Reeves
3425a0fe78
Delete Curators for all modules
2021-08-31 11:12:21 -04:00
Mike Reeves
9605eda559
Close Curators for all modules
2021-08-31 10:49:39 -04:00
Mike Reeves
ff09d9ca58
Merge pull request #5355 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERIFY_ISO.md
2021-08-31 10:06:12 -04:00
Mike Reeves
77b82bf2c0
Update VERIFY_ISO.md
2021-08-31 10:01:32 -04:00
Mike Reeves
ccc8f9ff0a
Merge pull request #5353 from Security-Onion-Solutions/hotfix/2.3.70
2021-08-31 09:57:05 -04:00
Mike Reeves
43d20226a8
Merge pull request #5352 from Security-Onion-Solutions/wazhf
...
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:47:14 -04:00
Mike Reeves
4fe0a1d7b4
2.3.70 WAZUH Hotfix sigs
2021-08-31 08:39:37 -04:00
Mike Reeves
7a48a94624
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-31 08:22:55 -04:00
Mike Reeves
1aacc27cd4
Merge pull request #5340 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update HOTFIX
2021-08-30 17:48:53 -04:00
Mike Reeves
92858cd13a
Update HOTFIX
2021-08-30 17:38:29 -04:00
Mike Reeves
99cb38362a
Merge pull request #5339 from Security-Onion-Solutions/hotfix/wazuh-update-exclude
...
wazuh-agent fix + pull in master
2021-08-30 17:37:47 -04:00
William Wernert
bfd632e20a
Add wazuh to exclude arg when running yum update
2021-08-30 14:21:13 -04:00
Mike Reeves
518f9fceb0
Merge pull request #5337 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2021-08-30 12:33:43 -04:00
Mike Reeves
2b34da0fee
Update HOTFIX
2021-08-30 12:32:44 -04:00
William Wernert
72859adb13
Fix typo in so-checkin
2021-08-27 15:23:01 -04:00
Mike Reeves
a27263435a
Add Templates for all filebeat modules
2021-08-27 14:41:04 -04:00
Mike Reeves
f8cdf5bca3
Add Templates for all filebeat modules
2021-08-27 14:39:02 -04:00
William Wernert
ca5339341f
Fix batch size regex to disallow 0
2021-08-27 11:34:28 -04:00
William Wernert
c5d120293d
Initial work to add unattended option to soup
2021-08-27 11:33:51 -04:00
Jason Ertel
12b5c0899b
merge
2021-08-27 08:20:23 -04:00
Jason Ertel
09d5097837
Remove unused automation files
2021-08-25 21:08:49 -04:00
Jason Ertel
de5f823abf
Add automation for deploy-vader env
2021-08-25 18:28:17 -04:00
Josh Brower
7b93f355e2
so-import-evtx - timestamp extraction
2021-08-25 15:17:19 -04:00
m0duspwnens
a27569f20b
remove source when contents provided
2021-08-25 12:32:17 -04:00
m0duspwnens
fd1e632386
cleanup yaml
2021-08-25 12:08:43 -04:00
m0duspwnens
0681d29bb0
starting es pillarization
2021-08-25 10:23:06 -04:00
Josh Brower
ef650c6ee6
Merge pull request #5235 from Security-Onion-Solutions/feature/so-playbook-import
...
Initial version so-playbook-import
2021-08-24 10:40:07 -04:00
Mike Reeves
24f36bb4c9
Merge pull request #5284 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 GRAFANA hotfix to dev
2021-08-24 10:27:09 -04:00
m0duspwnens
9783d13ea3
remove identifier from HOTFIX file
2021-08-24 10:22:01 -04:00
m0duspwnens
427ec98ce5
fix merge conflict in HOTFIX file
2021-08-24 10:20:42 -04:00
Josh Patterson
72ba29fb7b
Merge pull request #5282 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-24 10:15:33 -04:00
Josh Patterson
2859bff0e4
Merge pull request #5281 from Security-Onion-Solutions/grafana_fleet_hotfix
...
sig files and iso info
2021-08-24 10:01:10 -04:00
Mike Reeves
6e921415ea
sig files and iso info
2021-08-24 10:00:06 -04:00
Mike Reeves
2f8b68e67a
sig files and iso info
2021-08-24 09:58:28 -04:00
Mike Reeves
e762491039
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into truclusterrator
2021-08-24 09:50:41 -04:00
Mike Reeves
11381e304b
Merge pull request #5273 from Security-Onion-Solutions/kilo
...
Switch to new Curator auth params
2021-08-24 08:29:47 -04:00
Jason Ertel
6d49bca0ac
Switch to new auth params
2021-08-23 15:36:11 -04:00
Josh Patterson
8ea89932ae
Merge pull request #5270 from Security-Onion-Solutions/grafana_fleet_hotfix
...
Grafana fleet hotfix
2021-08-23 13:10:35 -04:00
m0duspwnens
f87cf123b0
fix typo - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:08:11 -04:00
m0duspwnens
80f4d03254
place unique identifier on same line for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:05:28 -04:00
m0duspwnens
a9cc68f89e
add unique identifier for hotfix - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 13:02:49 -04:00
m0duspwnens
b053f29a89
only create dashboards for certain node types - https://github.com/Security-Onion-Solutions/securityonion/issues/5268
2021-08-23 12:58:52 -04:00
Mike Reeves
19cfce5e0b
Add curator delete yml files
2021-08-23 10:47:41 -04:00
Mike Reeves
c4a32ca631
Merge pull request #5259 from Security-Onion-Solutions/kilo
...
Merge 2.3.70 CURATOR Hotfix to Dev
2021-08-23 09:37:50 -04:00
Jason Ertel
b78da5c237
Merge hotfix to dev; reset to .80
2021-08-23 09:36:20 -04:00
Mike Reeves
0abf7593ed
Merge pull request #5233 from Security-Onion-Solutions/hotfix/2.3.70
...
Hotfix/2.3.70
2021-08-23 09:28:07 -04:00
Josh Brower
aa420b914b
Initial version so-playbook-import
2021-08-20 16:27:09 -04:00
Mike Reeves
f096b513b7
Merge pull request #5232 from Security-Onion-Solutions/cfixhfix
...
Cfixhfix
2021-08-20 15:40:44 -04:00
Mike Reeves
51b517581a
2.3.70 sigs
2021-08-20 15:38:56 -04:00
Mike Reeves
936c998ecb
CURATOR ISO info
2021-08-20 12:49:55 -04:00
Mike Reeves
02372d130a
Merge pull request #5224 from Security-Onion-Solutions/curator_cron
...
remove the curator cronjobs if it is disabled
2021-08-20 10:44:55 -04:00
m0duspwnens
6f9a263af3
remove the curator cronjobs if it is disabled
2021-08-20 10:40:15 -04:00
Mike Reeves
43ffaab82c
Merge pull request #5213 from Security-Onion-Solutions/hotfix/curator
...
stop curator and remove from so-status for manager
2021-08-19 15:45:17 -04:00
m0duspwnens
dccfdb14e4
stop curator and remove from so-status for manager
2021-08-19 15:40:17 -04:00
Josh Patterson
21f3b3d985
Merge pull request #5212 from Security-Onion-Solutions/hotfix/curator
...
just dont run curator on manager
2021-08-19 15:27:55 -04:00
m0duspwnens
e2d74b115f
just dont run curator on manager
2021-08-19 15:26:22 -04:00
Mike Reeves
13741400f1
Merge pull request #5210 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2021-08-19 15:02:52 -04:00
Mike Reeves
d0f587858c
Merge pull request #5211 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Curator
2021-08-19 15:02:28 -04:00
Mike Reeves
acca8cc5d2
Update HOTFIX
2021-08-19 15:01:21 -04:00
Mike Reeves
ef950955bd
Update VERSION
2021-08-19 15:00:51 -04:00
Josh Patterson
9a8ccef828
Merge pull request #5209 from Security-Onion-Solutions/issue/5195
...
fix error in telegraf log
2021-08-19 13:27:08 -04:00
m0duspwnens
7b8e23fadd
fix error in telegraf log - https://github.com/Security-Onion-Solutions/securityonion/issues/5195
2021-08-19 11:11:24 -04:00
Mike Reeves
18335afa7f
Merge pull request #5204 from Security-Onion-Solutions/kilo
...
Update 2.3.80
2021-08-19 08:55:44 -04:00
Jason Ertel
41e8be87b6
Update 2.3.80
2021-08-19 08:42:29 -04:00
Doug Burks
39f32a6e13
Merge pull request #5185 from Security-Onion-Solutions/dev
...
2.3.70
2021-08-19 06:22:57 -04:00
Mike Reeves
8e9f95652d
Merge pull request #5188 from Security-Onion-Solutions/2.3.70
...
2.3.70 sigs
2021-08-18 09:37:51 -04:00
Mike Reeves
30489e4117
2.3.70 sigs
2021-08-18 09:35:48 -04:00
Mike Reeves
9dc9f10003
Merge pull request #5174 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-functions
2021-08-17 10:46:17 -04:00
Mike Reeves
1ced05c1d2
Update so-functions
2021-08-17 10:44:44 -04:00
Mike Reeves
41b246b8b3
Merge pull request #5169 from Security-Onion-Solutions/agrepo
...
Fix repo creation in airgap
2021-08-16 13:08:21 -04:00
Mike Reeves
a12f19c533
Fix repo creation in airgap
2021-08-16 13:00:52 -04:00
Josh Patterson
f1c91555ae
Merge pull request #5166 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-16 09:08:27 -04:00
Jason Ertel
e39de8c7bc
Merge pull request #5089 from Ron89/feature/thehive-userupdate
...
add user password update command
2021-08-15 09:36:35 -04:00
Mike Reeves
d0e312ec42
Merge pull request #5149 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 18:42:34 -04:00
Mike Reeves
e492833453
Grid Fixes
2021-08-13 18:32:55 -04:00
Mike Reeves
9beacacd44
Grid Fixes
2021-08-13 18:26:17 -04:00
Mike Reeves
aad14b2461
Grid Fixes
2021-08-13 18:22:02 -04:00
m0duspwnens
4955b552df
remove -
2021-08-13 17:42:37 -04:00
Mike Reeves
55e8a777d4
Merge pull request #5147 from Security-Onion-Solutions/issue/4674
...
keep the list unique
2021-08-13 17:39:54 -04:00
m0duspwnens
a98ed282c0
keep the list unique
2021-08-13 17:38:45 -04:00
Mike Reeves
7504b1cb2e
Merge pull request #5146 from Security-Onion-Solutions/gridraid
...
Grid Fixes
2021-08-13 16:25:31 -04:00
m0duspwnens
afab1cb1e6
Merge remote-tracking branch 'remotes/origin/dev' into issue/2806
2021-08-13 16:19:57 -04:00
m0duspwnens
cd0b9bbe4a
dont always add curator to so-status
2021-08-13 16:19:41 -04:00
Mike Reeves
3ea29e77a9
Merge pull request #5145 from Security-Onion-Solutions/bugfix/so-logscan-soup-pull
...
Remove so-logscan from so-image-common arrays
2021-08-13 13:59:10 -04:00
William Wernert
fb4c2c35e3
Remove so-logscan from so-image-common arrays
2021-08-13 13:58:08 -04:00
HE Chong
81ccce8659
negative case where username doesn't exist now report exception as expected
2021-08-13 23:00:11 +08:00
HE Chong
0d5e3771f5
modify user password update script for theHive, keep it in consistency with Fleet counterpart.
2021-08-13 21:52:19 +08:00
HE Chong
2030ef65f1
add user password update script for Fleet
2021-08-13 21:50:24 +08:00
HE Chong
b6c361f83d
add user password update script for The Hive
2021-08-13 20:54:35 +08:00
Mike Reeves
9404cb635d
Grid Fixes
2021-08-13 08:48:47 -04:00
William Wernert
da53b39c15
Merge pull request #5142 from Security-Onion-Solutions/foxtrot
...
Add image pull script to allow so-learn to pull missing images, update wording on several whiptail prompts
2021-08-12 16:09:55 -04:00
William Wernert
86569b0599
Make sbin script permissions consistent
2021-08-12 16:05:54 -04:00
William Wernert
45aa2f72cb
Merge branch 'dev' into foxtrot
2021-08-12 15:45:12 -04:00
Mike Reeves
06b7434ca2
Merge pull request #5141 from Security-Onion-Solutions/kilo
2021-08-12 15:05:14 -04:00
Jason Ertel
258cebda6e
Correct identity update payload to not have unsupported fields
2021-08-12 15:01:45 -04:00
Jason Ertel
0cca43c4bd
Merge branch 'dev' into kilo
2021-08-12 15:01:12 -04:00
William Wernert
bf40a1038e
Whiptail changes
...
* Update wording of ip mask prompt + so-allow question for clarity
* Remove old ip+mask prompts
2021-08-12 10:32:27 -04:00
William Wernert
3312a66e75
Fix indent
2021-08-11 16:37:22 -04:00
William Wernert
4a31d6b3bc
Specify images are also verified
2021-08-11 16:35:33 -04:00
William Wernert
64dfc6e191
Fix pull logic and properly hide output
2021-08-11 16:33:45 -04:00
William Wernert
95bd7f9861
Merge branch 'dev' into foxtrot
2021-08-11 13:47:38 -04:00
William Wernert
983549711c
Pull image if missing when enabling module in so-learn
2021-08-11 13:47:31 -04:00
Josh Patterson
5922dbdf22
Merge pull request #5120 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-08-10 12:29:51 -04:00
m0duspwnens
9e48a5b57b
fix the pillar.get
2021-08-10 10:29:29 -04:00
m0duspwnens
3c1114403e
fix the pillar.get
2021-08-10 10:25:05 -04:00
m0duspwnens
8d2f614af6
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-08-10 10:16:30 -04:00
m0duspwnens
1415de858c
delete old dashboard folders via api - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-10 10:16:14 -04:00
Josh Patterson
59e9fddf18
Merge pull request #5109 from Security-Onion-Solutions/issue/4674
...
remove old dashboard dirs
2021-08-09 13:37:45 -04:00
m0duspwnens
ad3b6cf629
remove old dashboard dirs - https://github.com/Security-Onion-Solutions/securityonion/issues/4674
2021-08-09 13:34:02 -04:00
William Wernert
b12e2eded5
Merge pull request #5086 from Security-Onion-Solutions/foxtrot
...
Add conditional check for logscan log + add log folder to logrotate config
2021-08-06 11:32:23 -04:00
William Wernert
26030d83eb
Merge branch 'dev' into foxtrot
2021-08-06 09:44:10 -04:00
William Wernert
3b01f6431e
Add logscan to logrotate config
2021-08-06 09:43:58 -04:00
Jason Ertel
a646867593
Merge branch 'dev' into kilo
2021-08-06 09:14:45 -04:00
Josh Patterson
768e61e11a
Merge pull request #5080 from Security-Onion-Solutions/issue/2806
...
Issue/2806
2021-08-05 12:02:42 -04:00
m0duspwnens
e72ad9eb5a
allow curator
2021-08-05 11:54:49 -04:00
m0duspwnens
ac4faf673d
add so-manager to curator.yml
2021-08-05 11:11:59 -04:00
William Wernert
dd1769fbef
Only check for logscan on manager-type and import
2021-08-05 11:02:09 -04:00
m0duspwnens
853a986082
add reqs to docker add manager to so-curator-closed-delete-delte
2021-08-05 10:36:18 -04:00
m0duspwnens
727a3742f5
run only on manager if truecluster enabled
2021-08-05 09:50:51 -04:00
Doug Burks
478a0b6a3f
Merge pull request #5075 from Security-Onion-Solutions/fix/typo
...
fix typo
2021-08-05 07:43:46 -04:00
Doug Burks
771688a70f
fix typo
2021-08-05 07:34:07 -04:00
Josh Patterson
40fa549353
Merge pull request #5066 from Security-Onion-Solutions/issue/2806
...
dont run curator on searchnode if truecluster is enabled
2021-08-04 15:01:11 -04:00
Jason Ertel
84fdc1e690
Merge pull request #5057 from Security-Onion-Solutions/bravo
...
Several Suricata things
2021-08-04 12:26:11 -04:00
Mike Reeves
71bbb41b5f
Merge branch 'dev' into bravo
2021-08-04 10:57:10 -04:00
m0duspwnens
52cb72ba67
dont run curator on searchnode if truecluster is enabled - https://github.com/Security-Onion-Solutions/securityonion/issues/2806
2021-08-04 09:40:34 -04:00
William Wernert
54a3b754e0
Merge pull request #5050 from Security-Onion-Solutions/foxtrot
...
Add logscan state, related pipeline config, and initial so-learn script
2021-08-03 16:30:07 -04:00
William Wernert
2bc88e7750
Remove learn from allowed states for helixsensor
2021-08-03 15:29:37 -04:00
William Wernert
ef59cb47dd
Use print_err function
2021-08-03 15:26:57 -04:00
William Wernert
9e5d3aa286
Fix removed root check in so-rule
2021-08-03 15:25:53 -04:00
William Wernert
25bf25eae6
Allowed states remove typo'd logscan
2021-08-03 15:24:32 -04:00
William Wernert
24f5fa66f3
Merge branch 'dev' into foxtrot
2021-08-03 13:02:29 -04:00
Mike Reeves
1aeb2d7d4f
Merge pull request #5040 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-03 10:59:28 -04:00
Jason Ertel
ee176f5bfd
Condense cloud automations
2021-08-03 07:40:50 -04:00
Jason Ertel
eb093b8e6c
Condense cloud automations
2021-08-02 21:52:42 -04:00
Jason Ertel
f88fa6e3b2
Condense cloud automations
2021-08-02 21:51:26 -04:00
Jason Ertel
724f7d4f3d
Merge pull request #5036 from Security-Onion-Solutions/kilo
...
Condense cloud automations
2021-08-02 18:04:05 -04:00
Jason Ertel
19816d8814
Condense cloud automations
2021-08-02 17:55:27 -04:00
William Wernert
d3b170c6df
Add logscan automation file + fix enable command in setup
2021-08-02 12:37:37 -04:00
William Wernert
757091beeb
Add log_level to logscan.conf
2021-08-02 10:35:39 -04:00
William Wernert
8a49039b85
Only append source.ip to logscan.source.ips if it's been created
2021-08-02 09:50:49 -04:00
William Wernert
4f39cd1d7f
Add logscan dynamic object to so-common template mappings
2021-07-30 16:02:02 -04:00
William Wernert
2a6277c0c3
Fix field names in logscan pipeline
2021-07-30 15:46:39 -04:00
William Wernert
33bd6aed20
Fix logscan pipeline on eval
...
* Rename logscan pipeline to logscan.alert
* Add module to indices array in filebeat.yml
2021-07-30 14:41:15 -04:00
William Wernert
b9980c9d30
Fix pipeline name
2021-07-30 13:09:09 -04:00
William Wernert
01bb94514c
Correct mod_so_status to only act on single string
2021-07-30 11:05:48 -04:00
William Wernert
d71967ea1d
Fix incorrect writing of so-status.conf
2021-07-30 10:28:39 -04:00
William Wernert
0b06d0bfdb
Merge branch 'dev' into foxtrot
2021-07-29 15:15:25 -04:00
William Wernert
b2a83018ba
Remove or run logscan based on enabled bool
2021-07-29 15:14:54 -04:00
William Wernert
ba265d94f4
Change default value in learn init to a dict where approriate
2021-07-29 15:14:28 -04:00
Mike Reeves
af7b314cfe
Merge pull request #4993 from Security-Onion-Solutions/kilo
...
Merge 2.3.61 MSEARCH Hotfix into dev
2021-07-29 15:02:51 -04:00
Jason Ertel
4c6447a3da
merge 2.3.61 MSEARCH hotfix into dev
2021-07-29 15:00:58 -04:00
William Wernert
b30f771fa2
Set write_needed flag correctly, include newline in so-status.conf string
2021-07-29 14:59:26 -04:00
Mike Reeves
837c0402a0
Merge pull request #4989 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-29 14:58:25 -04:00
William Wernert
e38219aa2e
Fix learn init.sls typo
2021-07-29 14:35:02 -04:00
William Wernert
9e92f6da3d
Add container to so-status when enabling/disabling ml module
2021-07-29 14:25:20 -04:00
William Wernert
44551ea9ee
Fix so-learn list
2021-07-29 13:31:48 -04:00
William Wernert
c53da9b1ff
Fix wrong variables in learn init.sls
2021-07-29 12:04:40 -04:00
William Wernert
e1785dbd9a
Fix typo
2021-07-29 12:00:53 -04:00
William Wernert
2560a9b78c
[wip] Change learn:modules to dictionary
2021-07-29 11:58:58 -04:00
William Wernert
d53e989c55
Add ability to set cpu_period per module
2021-07-29 11:52:10 -04:00
William Wernert
211a841cdb
Fix file path in bind mount for logscan
2021-07-29 11:40:19 -04:00
Josh Patterson
50e4365475
Merge pull request #4990 from Security-Onion-Solutions/issue/4985
...
Issue/4985
2021-07-29 11:14:54 -04:00
Jason Ertel
c524b54af1
Merge pull request #4988 from Security-Onion-Solutions/mkr2361
...
2.3.61-MSEARCH
2021-07-29 11:10:41 -04:00
Mike Reeves
7591bb115e
2.3.61-MSEARCH
2021-07-29 11:09:54 -04:00
Mike Reeves
3d2da303c8
2.3.61-MSEARCH
2021-07-29 11:09:27 -04:00
Mike Reeves
f585eb6e62
2.3.61-MSEARCH
2021-07-29 11:08:03 -04:00
m0duspwnens
4b6120a46b
fix the hours get
2021-07-29 10:59:33 -04:00
Mike Reeves
d946c6d5ed
Merge pull request #4987 from Security-Onion-Solutions/kilo
...
Do not prompt about uppercased hostname during testing
2021-07-29 10:57:56 -04:00
William Wernert
5894b85bd1
Remove broken yaml dump arg, rename metavars
2021-07-29 10:57:53 -04:00
m0duspwnens
3fc43f7d92
allow for adjustment to auto patch os schedule - https://github.com/Security-Onion-Solutions/securityonion/issues/4985
2021-07-29 10:48:24 -04:00
Jason Ertel
8ed264460f
Do not prompt about uppercased hostname during testing
2021-07-29 10:45:35 -04:00
William Wernert
811b32735e
Merge branch 'dev' into foxtrot
2021-07-29 09:52:29 -04:00
Mike Reeves
4b3db0c4d2
Merge pull request #4972 from Security-Onion-Solutions/mkr2361
...
Fix Manager Search
2021-07-28 17:08:40 -04:00
Mike Reeves
281ba21298
Merge pull request #4956 from Security-Onion-Solutions/kilo
...
Merge master to dev
2021-07-28 17:07:58 -04:00
Mike Reeves
d4a177949a
Fix Manager Search
2021-07-28 17:05:16 -04:00
Mike Reeves
a42d8c9229
Fix Manager Search
2021-07-28 17:03:14 -04:00
William Wernert
dd0e407935
Use correct container name
2021-07-28 15:06:38 -04:00
William Wernert
7ef5b39b04
[wip] Fix 'Nonetype' object is not callable error
2021-07-28 14:28:00 -04:00
William Wernert
cf9121dfc2
Actually download so-learn container
2021-07-28 14:13:16 -04:00
Josh Patterson
fcfc2a65a9
Merge pull request #4968 from Security-Onion-Solutions/issue/3933
...
allow for sampleSize adjustment in kibana
2021-07-28 11:13:49 -04:00
William Wernert
91accb0bc6
[wip] Fixing so-learn script
2021-07-28 10:12:32 -04:00
William Wernert
e2abe8840f
Fix directory in logscan state
2021-07-28 10:12:19 -04:00
m0duspwnens
ead9ae8cb5
fix merge and defaults passed
2021-07-28 09:58:38 -04:00
William Wernert
455719936b
Uncomment required lines in so-learn
2021-07-28 09:53:35 -04:00
William Wernert
8d56fc71fa
Fix jinja length calculation
2021-07-28 09:53:24 -04:00
William Wernert
833d154bf4
Merge branch 'dev' into foxtrot
2021-07-28 09:50:11 -04:00
William Wernert
f31dc5abc7
Add learn to allowed states
2021-07-28 09:49:59 -04:00
m0duspwnens
9a429230fe
wrap with raw due to {{value}}
2021-07-28 09:39:35 -04:00
m0duspwnens
b36d46b7f2
change to jinja tem,plate
2021-07-28 09:27:44 -04:00
m0duspwnens
fee89665fd
dict not list for defaults
2021-07-28 09:18:15 -04:00
m0duspwnens
d78a37f9e3
allow for control of kibana discover sampleSize - https://github.com/Security-Onion-Solutions/securityonion/issues/3933
2021-07-28 09:12:31 -04:00
Jason Ertel
28c5c02ef1
Merge pull request #4958 from Security-Onion-Solutions/issue/4024
...
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:21:13 -04:00
m0duspwnens
8ffeae38bc
https://github.com/Security-Onion-Solutions/securityonion/issues/4024
2021-07-27 16:16:48 -04:00
William Wernert
f4fae7938e
Merge branch 'dev' into foxtrot
2021-07-27 16:01:44 -04:00
Jason Ertel
22920bc9a1
clear out hotfix from merge
2021-07-27 14:42:11 -04:00
Jason Ertel
ceb82cb863
Merge branch 'master' into kilo
2021-07-27 14:40:31 -04:00
Mike Reeves
1caa361e22
Merge pull request #4955 from Security-Onion-Solutions/hotfix/2.3.61
...
Hotfix/2.3.61
2021-07-27 14:33:31 -04:00
Mike Reeves
da20790238
Merge pull request #4954 from Security-Onion-Solutions/mkr2361
...
Steno ISO Details
2021-07-27 11:11:22 -04:00
Mike Reeves
f359dd0cd4
Steno ISO Details
2021-07-27 11:09:25 -04:00
Josh Patterson
bee442a21f
Merge pull request #4950 from Security-Onion-Solutions/issue/4674
...
Issue/4674
2021-07-27 10:28:02 -04:00
m0duspwnens
a66765e99b
remove old dashboards, set default refresh to 5m
2021-07-27 10:23:35 -04:00
m0duspwnens
0db7f91eb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-27 08:53:31 -04:00
m0duspwnens
850315dc20
remove role conditional from all panel queiries
2021-07-27 08:47:44 -04:00
Mike Reeves
d35e4bea01
Merge pull request #4932 from Security-Onion-Solutions/issue/4922
...
Issue/4922
2021-07-26 16:18:22 -04:00
Jason Ertel
356b623148
Merge pull request #4937 from Security-Onion-Solutions/kilo
...
Add Azure automations
2021-07-26 16:13:57 -04:00
Jason Ertel
3a022e7a83
Add Azure automations
2021-07-26 15:50:15 -04:00
William Wernert
64945cec16
[wip] Initial work to enable/disable "learn" modules
2021-07-26 14:24:10 -04:00
Jason Ertel
26741bdb53
Add wss: to CSP for browsers that enforce wss distinctly from other protocols
2021-07-26 10:55:30 -04:00
m0duspwnens
7aa5e857ed
update hotfix file
2021-07-26 10:46:52 -04:00
m0duspwnens
2e277bf487
change container to abesent of pcap is disabled
2021-07-26 10:08:59 -04:00
m0duspwnens
e4f46c6e14
hide role template var from all dash except overview
2021-07-26 09:36:05 -04:00
m0duspwnens
e9d90644fd
fix query and allow for setting text and value of servername template var
2021-07-23 16:52:07 -04:00
m0duspwnens
5a06f0dce9
role template var now selects default role
2021-07-23 16:34:58 -04:00
m0duspwnens
08e9a58f2e
simply to one servername.json
2021-07-23 16:09:25 -04:00
m0duspwnens
e1f0c8e87c
add "list" bast to tempating defs for overview
2021-07-23 15:43:31 -04:00
m0duspwnens
17a532f7b5
add new templating defs to overview
2021-07-23 15:41:03 -04:00
m0duspwnens
c7306dda12
fix servername_eval template var, test using 1 servername template var
2021-07-23 15:38:45 -04:00
m0duspwnens
00d311cd6c
fix nodetype listing
2021-07-23 14:40:44 -04:00
m0duspwnens
f8d2a7f449
fix nodetype listing
2021-07-23 13:43:35 -04:00
m0duspwnens
a02a928996
add missing ]
2021-07-23 13:33:25 -04:00
m0duspwnens
eb661b7a24
add ability to set title for dashboards, only create dashboards/dirs if that node type exists
2021-07-23 13:31:44 -04:00
m0duspwnens
6aea607f21
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-23 11:12:48 -04:00
m0duspwnens
41e747dcc1
add servername_all template var
2021-07-23 10:55:15 -04:00
m0duspwnens
d3d02faa1c
remove detailed
2021-07-23 10:52:30 -04:00
m0duspwnens
7a85a3c7f7
move dashboard location
2021-07-23 10:20:57 -04:00
m0duspwnens
fceb2851ef
add eval dashboard
2021-07-23 09:02:40 -04:00
William Wernert
2f118781ea
Merge branch 'dev' into foxtrot
2021-07-23 08:54:08 -04:00
William Wernert
b8e3a45a7e
[wip] Add logscan state
...
Do not add state to top file or setup yet, script will be written to enable the feature shortly
2021-07-23 08:53:45 -04:00
m0duspwnens
61312397e1
update container uptime panel
2021-07-23 08:25:43 -04:00
m0duspwnens
8ea4682aab
add docker container uptime to overview dash
2021-07-23 07:34:01 -04:00
m0duspwnens
3b6befdb97
adjust gridpos
2021-07-22 15:05:37 -04:00
m0duspwnens
613979ea3f
remove extra comma
2021-07-22 15:03:58 -04:00
m0duspwnens
191def686b
add packet loss panels
2021-07-22 15:02:06 -04:00
Mike Reeves
f986e0dc78
Merge pull request #4892 from Security-Onion-Solutions/kilo
...
Merge master back to dev
2021-07-22 14:37:40 -04:00
Jason Ertel
08e75567d4
merge master to kilo
2021-07-22 14:34:24 -04:00
Mike Reeves
668199f1a8
Merge pull request #4889 from Security-Onion-Solutions/2361update
...
2.3.61
2021-07-22 14:29:13 -04:00
Jason Ertel
7a753a56ec
Update README with 2.3.61
2021-07-22 13:54:04 -04:00
m0duspwnens
7b38b4e280
fix {{}}
2021-07-22 13:36:44 -04:00
m0duspwnens
7dc2e2ca73
add option to hide trend on zeek packet loss graph
2021-07-22 13:35:25 -04:00
m0duspwnens
44eb23615a
change to packet_loss
2021-07-22 13:20:19 -04:00
m0duspwnens
d47566f667
remove monitor inbound graph
2021-07-22 13:18:31 -04:00
m0duspwnens
9ae84c8108
add network and tool packetloss panels to overview
2021-07-22 13:16:39 -04:00
Mike Reeves
578c7aac35
2.3.61
2021-07-22 13:06:26 -04:00
m0duspwnens
1c460cc19c
fix traffic overview graphs
2021-07-22 10:31:47 -04:00
m0duspwnens
ff436aea93
allow multi and all for manint and monint vars
2021-07-22 10:06:31 -04:00
m0duspwnens
aa333794f7
add disk usage percent graphs
2021-07-22 09:54:17 -04:00
doug
3d3593a1a9
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-22 09:50:21 -04:00
Jason Ertel
257062e20c
Update release notes link to match top right menu for airgap
2021-07-22 09:48:34 -04:00
doug
fa9d7afb46
FIX: Airgap link to Release Notes #4685
2021-07-22 09:42:37 -04:00
m0duspwnens
ae5f351e1a
change row name
2021-07-22 09:31:17 -04:00
m0duspwnens
257a88ec8e
change row name
2021-07-22 09:30:43 -04:00
m0duspwnens
e1e6304a8a
rename
2021-07-22 09:29:37 -04:00
m0duspwnens
a81ef0017c
rename panels source, reorg overview
2021-07-22 09:15:22 -04:00
m0duspwnens
b89162e086
change id
2021-07-22 08:01:54 -04:00
m0duspwnens
a6630540a4
add system uptime graph to overview dash
2021-07-21 18:11:42 -04:00
m0duspwnens
a528c5d54b
role first var for overview
2021-07-21 17:41:53 -04:00
m0duspwnens
690699ddf7
update template vars to use regex for $servername
2021-07-21 17:17:23 -04:00
m0duspwnens
cd8d9c657e
add mgmt interface traffic graphs to overview
2021-07-21 16:24:16 -04:00
m0duspwnens
f732b80b92
add swap usage percent to overview dash
2021-07-21 15:48:04 -04:00
Jason Ertel
ad8c12afa5
Upgrade ES to 7.13.4
2021-07-21 15:07:02 -04:00
m0duspwnens
479fcb6c46
add panel for memory usage percent
2021-07-21 15:00:05 -04:00
Jason Ertel
74874dfff2
Allow web pages to load blob data
2021-07-21 14:59:33 -04:00
m0duspwnens
ceb108a5fe
set min yaxes to 0
2021-07-21 14:47:57 -04:00
m0duspwnens
235d8b7cf0
ensure role matches
2021-07-21 14:44:07 -04:00
Mike Reeves
7c9df2d75a
Update HOTFIX
2021-07-21 14:40:53 -04:00
Mike Reeves
43bf75217f
Update VERSION
2021-07-21 14:40:23 -04:00
m0duspwnens
9bf6d478c5
remove $col var
2021-07-21 14:36:08 -04:00
m0duspwnens
e2baa93270
remove role from node_config for telegraf
2021-07-21 14:32:01 -04:00
m0duspwnens
37fcda3817
add cpu row and panels to overview dashboard
2021-07-21 14:30:41 -04:00
m0duspwnens
457ae54341
role var
2021-07-21 11:50:06 -04:00
m0duspwnens
4cc3c5ada9
add role template var to overview dashboard
2021-07-21 11:35:02 -04:00
m0duspwnens
07d5736d61
change sort of legend
2021-07-21 11:33:48 -04:00
m0duspwnens
a7551a44e5
allow multi and all on servername_all template var
2021-07-21 11:29:30 -04:00
m0duspwnens
f4d3e13c7f
begin overview dashboard
2021-07-21 11:26:02 -04:00
m0duspwnens
47d82b3d35
sort desc remaining tooltips
2021-07-21 10:36:07 -04:00
m0duspwnens
9d06aff1d1
add manager dashboard
2021-07-21 10:23:39 -04:00
m0duspwnens
5ea8c978a0
add managersearch
2021-07-21 10:16:40 -04:00
m0duspwnens
6809c3a9f6
add mastersearch dashboard
2021-07-21 10:13:43 -04:00
m0duspwnens
761108964e
remove panels from searchnode dashboard
2021-07-21 10:05:43 -04:00
m0duspwnens
e3e74a84f2
test sort tooltip descending
2021-07-21 10:00:14 -04:00
m0duspwnens
1fee4e87c4
add searchnode dashboard
2021-07-21 09:51:49 -04:00
m0duspwnens
0c4c59375d
sort container uptime ascending
2021-07-21 09:11:39 -04:00
Mike Reeves
09165daab8
Several Suricata things
2021-07-21 09:10:33 -04:00
m0duspwnens
3393b77535
add sensor dashboard
2021-07-21 08:54:26 -04:00
m0duspwnens
d050bc02e2
dont show legend for docker uptime trend
2021-07-20 16:29:49 -04:00
m0duspwnens
af60ddf404
add docker container uptime graph
2021-07-20 16:28:07 -04:00
m0duspwnens
1bb92f63d1
add docker details
2021-07-20 15:21:59 -04:00
m0duspwnens
a405ca39fa
add redis.sh for telegraf on heavynodes
2021-07-20 14:31:09 -04:00
m0duspwnens
852b686d81
add servername vars for each role
2021-07-20 14:25:56 -04:00
m0duspwnens
608d5d3c26
change uid logic
2021-07-20 14:10:26 -04:00
m0duspwnens
6038ebb705
handle multile nodetpes and uid
2021-07-20 14:04:28 -04:00
m0duspwnens
4bb350d37d
add heavynode
2021-07-20 13:55:52 -04:00
m0duspwnens
d01ac55db1
add heavynode
2021-07-20 13:55:18 -04:00
Jason Ertel
fcde5c3c18
Merge pull request #4865 from Security-Onion-Solutions/kilo
...
Merge curator hotfix into dev
2021-07-20 11:47:49 -04:00
Jason Ertel
dbf19e134f
Merge branch 'master' into kilo
2021-07-20 11:44:10 -04:00
Mike Reeves
b13c5a3b8b
Merge pull request #4863 from Security-Onion-Solutions/hotfix/2.3.60
...
Hotfix/2.3.60 CuratorFix
2021-07-20 11:02:34 -04:00
m0duspwnens
b0c5a352c1
remove old panaels
2021-07-20 10:53:47 -04:00
m0duspwnens
d0b3cd5f66
add the detailed dash dir
2021-07-20 10:50:40 -04:00
m0duspwnens
24efdec9ea
cap the var
2021-07-20 10:48:46 -04:00
m0duspwnens
1bed818a8e
fix jinja
2021-07-20 10:47:10 -04:00
m0duspwnens
3c4c52567d
fix jinja
2021-07-20 10:46:41 -04:00
m0duspwnens
87ae14d11c
fix jinja
2021-07-20 10:44:32 -04:00
m0duspwnens
258d303e7f
change how dashboards are deployed
2021-07-20 10:43:00 -04:00
m0duspwnens
458350e1a8
new redis queue stat panel, change to lastnotnull
2021-07-20 09:45:28 -04:00
Mike Reeves
fe7ee1e2c7
Merge pull request #4862 from Security-Onion-Solutions/curatorfix
...
Curator Fix
2021-07-20 09:26:54 -04:00
m0duspwnens
d8910a0097
add redis queue to overview, reposition overview panels
2021-07-20 09:22:43 -04:00
Mike Reeves
3b6e683d37
Curator Fix
2021-07-20 09:21:22 -04:00
m0duspwnens
90f6bad6ce
panel title change
2021-07-20 08:54:39 -04:00
m0duspwnens
fcc6802f86
convert all singlestat to stat
2021-07-20 08:51:53 -04:00
m0duspwnens
3b9bc77ecc
remove scopedvars
2021-07-19 17:51:43 -04:00
m0duspwnens
0fb4500fcc
add legends
2021-07-19 17:39:32 -04:00
m0duspwnens
93ca00c7fe
change min y
2021-07-19 17:29:57 -04:00
m0duspwnens
522f2a3f9f
maxdatapoints and min interval
2021-07-19 17:19:56 -04:00
m0duspwnens
40ddf5f49c
fix cords
2021-07-19 16:30:02 -04:00
m0duspwnens
60356eacce
make the ids unique
2021-07-19 16:26:09 -04:00
m0duspwnens
158f3bf092
add row_stenographer
2021-07-19 16:18:02 -04:00
m0duspwnens
ebf3c65bed
add many more panels
2021-07-19 16:02:40 -04:00
William Wernert
df6d1d72e2
Merge branch 'dev' into feature/logscan
2021-07-19 15:19:59 -04:00
weslambert
72542322ca
Merge pull request #4857 from Security-Onion-Solutions/fix/beats_output_fb_modules
...
Check if Filebeat modules are being used for incoming (external) Beats
2021-07-19 13:11:06 -04:00
weslambert
fea4f3f973
Check if Filebeat modules are being used for incoming Beats
2021-07-19 12:57:42 -04:00
Mike Reeves
7878180f54
Merge pull request #4854 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2021-07-19 12:50:23 -04:00
Mike Reeves
0669aa6bbd
Update HOTFIX
2021-07-19 12:49:43 -04:00
Mike Reeves
2c4924a602
Merge pull request #4853 from Security-Onion-Solutions/fix/curator_http_auth
...
Use http_auth instead of username/password until Curator is updated to latest version
2021-07-19 12:45:29 -04:00
weslambert
bde86e0383
Use http_auth instead of username/password until Curator is upgraded to next version
2021-07-19 12:42:46 -04:00
Jason Ertel
bab18275bc
Merge pull request #4836 from Security-Onion-Solutions/fix/airgap-release-notes
...
FIX: Airgap link to Release Notes #4685
2021-07-17 11:05:33 -04:00
doug
7e86681509
FIX: Airgap link to Release Notes #4685
2021-07-16 16:50:49 -04:00
William Wernert
c2fc2df54c
Merge pull request #4835 from Security-Onion-Solutions/feature/uppercase-warning
...
Show warning to user when trying to use uppercase characters in hostname or domain name
2021-07-16 15:44:47 -04:00
William Wernert
0deb77468f
Change uppercase regex
...
Check for any uppercase characters rather than revalidating input sans uppercase
2021-07-16 15:39:09 -04:00
William Wernert
9bf1d3e0c6
Misc fixes
2021-07-16 14:59:44 -04:00
William Wernert
3a12d28d20
Merge branch 'dev' into feature/logscan
2021-07-16 14:13:19 -04:00
William Wernert
e8ba4bdc6c
Add quotes to string
2021-07-16 14:07:23 -04:00
William Wernert
b552973e00
Add logic to show uppercase warning message when appropriate
2021-07-15 16:36:46 -04:00
William Wernert
ac98e1fd0f
Remove testing default values, change wording, set default option to no
2021-07-15 16:36:24 -04:00
m0duspwnens
4246aac51b
unhide disk var
2021-07-15 13:57:43 -04:00
William Wernert
33f396bdae
Add uppercase warning function
2021-07-15 13:53:57 -04:00
William Wernert
ff25cecd54
Remove unused function
2021-07-15 13:53:31 -04:00
m0duspwnens
e88b258208
add maxDataPoints and min interval to more panels
2021-07-15 11:53:24 -04:00
m0duspwnens
1cbf895e0e
add missing ,
2021-07-15 11:27:19 -04:00
m0duspwnens
7dc1f5c445
add maxDataPoints and min interval to some panels for testing
2021-07-15 11:25:20 -04:00
m0duspwnens
439e049948
revert to $__interval
2021-07-15 10:17:21 -04:00
m0duspwnens
fbf26bef8d
test new groupby interval for trend on monitor packets
2021-07-15 08:42:53 -04:00
m0duspwnens
c1f550382c
remove interval var
2021-07-15 08:31:42 -04:00
m0duspwnens
23fb6a5c02
rename
2021-07-14 18:04:33 -04:00
m0duspwnens
d632266092
fix jinja
2021-07-14 18:01:56 -04:00
m0duspwnens
4ea3ab9538
add disk iops graphs
2021-07-14 17:58:49 -04:00
m0duspwnens
725161ea6e
fix datasource
2021-07-14 16:07:14 -04:00
m0duspwnens
fccd86f676
add disk var to standalone
2021-07-14 16:04:55 -04:00
m0duspwnens
0f0a977ed9
add disk var
2021-07-14 16:04:17 -04:00
Jason Ertel
7f9d0b59b8
Merge pull request #4808 from Security-Onion-Solutions/kilo
...
Merge hotfix from master into dev; add `so-firewall apply` feature to dev
2021-07-14 15:49:12 -04:00
m0duspwnens
b0d510167c
change title
2021-07-14 15:36:26 -04:00
m0duspwnens
4971933201
rename file
2021-07-14 15:34:39 -04:00
m0duspwnens
693a9b30ae
add swap, adjust cords
2021-07-14 15:33:28 -04:00
Jason Ertel
76c285158a
Merge branch 'master' into kilo
2021-07-14 15:24:35 -04:00
Jason Ertel
08517e3732
Merge branch 'dev' into kilo
2021-07-14 15:24:29 -04:00
m0duspwnens
59530f4263
cahnge nullPointMode
2021-07-14 14:54:48 -04:00
Mike Reeves
5d48fb41ba
Merge pull request #4800 from Security-Onion-Solutions/hotfix/2.3.60
2021-07-14 14:54:00 -04:00
m0duspwnens
4acebe7f59
replace $interval with $__interval
2021-07-14 14:47:02 -04:00
m0duspwnens
a44a7b7161
change title
2021-07-14 14:45:17 -04:00
m0duspwnens
be13f0a066
change id
2021-07-14 14:31:25 -04:00
m0duspwnens
98ce77c2b1
add disk usage graphs
2021-07-14 14:28:25 -04:00
m0duspwnens
275a491cac
cords
2021-07-14 13:44:47 -04:00
m0duspwnens
1c868f85c4
fix cords;
2021-07-14 13:25:17 -04:00
m0duspwnens
b6deacf86d
cords
2021-07-14 13:11:48 -04:00
Mike Reeves
ebe5ef6535
Merge pull request #4799 from Security-Onion-Solutions/agsoupupdate
...
Update ISO info
2021-07-14 12:07:35 -04:00
m0duspwnens
294f91473c
fix packets legend
2021-07-14 11:49:24 -04:00
m0duspwnens
902f04efb4
set 0 as min
2021-07-14 11:44:14 -04:00
m0duspwnens
ca2989c0e5
fix network cords
2021-07-14 11:42:01 -04:00
m0duspwnens
2d9697cd66
fix network cords
2021-07-14 11:40:31 -04:00
m0duspwnens
b4111a9f79
fix network cords
2021-07-14 11:38:16 -04:00
m0duspwnens
7f8212fdba
add trend, add network graphs
2021-07-14 11:31:48 -04:00
weslambert
7e1be8a3a4
Merge pull request #4798 from Security-Onion-Solutions/fix/strelka_filepath_mapping
...
Replace staging with processed in Strelka file path mapping
2021-07-14 11:16:15 -04:00
Wes Lambert
05aad07bfc
Replace staging path with processed path for analyzed files
2021-07-14 15:04:46 +00:00
Mike Reeves
92a80f9a58
Update ISO info
2021-07-14 10:30:10 -04:00
m0duspwnens
4b4ceb525a
trends for load and process status
2021-07-14 10:29:35 -04:00
weslambert
42ba9888d7
Merge pull request #4797 from Security-Onion-Solutions/fix/wazuh_data_port
...
Change field name and mapping for Wazuh's data.port
2021-07-14 10:14:53 -04:00
William Wernert
818f912a90
[fix] Remove indent
2021-07-14 10:13:14 -04:00
m0duspwnens
dae64b82ff
add trend to cpu
2021-07-14 10:09:34 -04:00
m0duspwnens
53c6edcbdb
add trends memory usage and network graphs
2021-07-14 09:57:43 -04:00
Wes Lambert
723172bc1f
Add path_unmatch for data.port so it is not mapped as integer
2021-07-14 13:45:09 +00:00
Wes Lambert
323b5d6694
Add dynamic mapping for wazuh
2021-07-14 13:43:34 +00:00
Wes Lambert
441cd3fc59
Move Wazuh-specific data to wazuh.data
2021-07-14 13:42:51 +00:00
m0duspwnens
1d23d1b2e2
start network row
2021-07-14 09:21:46 -04:00
Jason Ertel
1dd81b6d49
Merge pull request #4790 from Security-Onion-Solutions/agsoupupdate
...
Remove old airgap scripts
2021-07-13 15:45:45 -04:00
Mike Reeves
741e825ab9
Remove old airgap scripts
2021-07-13 15:44:26 -04:00
William Wernert
e41811fbd0
[fix] Typo
2021-07-13 15:14:13 -04:00
m0duspwnens
f111106a9f
fix cords
2021-07-13 14:13:19 -04:00
m0duspwnens
f9e29eaede
update memory usage graph panel
2021-07-13 14:09:23 -04:00
William Wernert
e7a6172d7e
[fix] Add single quotes to strings
2021-07-13 14:07:27 -04:00
m0duspwnens
ec8f9228e8
add memory and docker container rows
2021-07-13 14:01:42 -04:00
m0duspwnens
6c12e26632
add mem usage, add docker graphs back, update nsm usage thresh
2021-07-13 13:55:01 -04:00
m0duspwnens
9a6ac7bd20
change panels
2021-07-13 12:30:45 -04:00
m0duspwnens
5b3751da70
new load averages panel
2021-07-13 12:24:32 -04:00
m0duspwnens
65127eb226
fix servername var
2021-07-13 12:04:52 -04:00
William Wernert
115e0a6fee
[fix] Add missing comma
2021-07-13 12:04:10 -04:00
m0duspwnens
ddfab44883
new id
2021-07-13 11:59:01 -04:00
Mike Reeves
6eab390962
Merge pull request #4788 from Security-Onion-Solutions/fix/fbpipeline
...
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:40:58 -04:00
Mike Reeves
35388056d3
Merge pull request #4789 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2021-07-13 11:40:44 -04:00
Mike Reeves
e2c5967191
Update HOTFIX
2021-07-13 11:38:20 -04:00
weslambert
7cdb967810
Only route to FB module pipeline if filebeat in metadata
2021-07-13 11:36:18 -04:00
m0duspwnens
8900d52c33
change y
2021-07-13 11:30:14 -04:00
m0duspwnens
bab72393e6
query and id changes
2021-07-13 11:23:06 -04:00
William Wernert
e059c25ebc
[fix][wip] Fix pipeline parsing errors
2021-07-13 11:05:05 -04:00
m0duspwnens
c87ca8f5dc
spacing
2021-07-13 10:42:33 -04:00
m0duspwnens
e01e3cdd43
change file name
2021-07-13 10:25:26 -04:00
m0duspwnens
2ab9ade761
add missing gridPos
2021-07-13 10:22:48 -04:00
m0duspwnens
0b35b8f6d6
add cpu row
2021-07-13 10:19:20 -04:00
William Wernert
9ff95f66dd
Merge branch 'dev' into feature/logscan
2021-07-13 10:02:58 -04:00
William Wernert
c1523c4936
Merge pull request #4782 from Security-Onion-Solutions/feature/check-local-mods
...
Add jinja raw tag
2021-07-13 08:58:25 -04:00
m0duspwnens
b6e31278a7
move old panels into old for organization
2021-07-13 08:57:01 -04:00
William Wernert
ca2b24f735
Add jinja raw tag
2021-07-13 08:46:57 -04:00
William Wernert
2b0bca8e55
Merge branch 'dev' into feature/logscan
2021-07-12 14:58:30 -04:00
m0duspwnens
98fe7e8700
fix mean
2021-07-12 14:37:17 -04:00
m0duspwnens
0acc3cc537
rename
2021-07-12 14:32:37 -04:00
m0duspwnens
8491ffde07
add docker container network usage graphs
2021-07-12 14:18:54 -04:00
Doug Burks
2ea3989497
Merge pull request #4775 from Security-Onion-Solutions/fix/suricata-dns-response-code
...
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:40:14 -04:00
doug
e6f9592cde
FIX: Suricata dns.response.code needs to be renamed to dns.response.code_name #4770
2021-07-12 13:24:21 -04:00
William Wernert
222d79bf53
Merge pull request #4774 from Security-Onion-Solutions/feature/check-local-mods
...
Compare local files to their defaults to check for potentially breaking changes
2021-07-12 12:00:18 -04:00
m0duspwnens
19d9258717
add postfix , change color
2021-07-12 11:22:48 -04:00
m0duspwnens
b46456b78e
move math, add 2 decimal spot
2021-07-12 11:16:33 -04:00
m0duspwnens
cebc2ef09d
add missing ,
2021-07-12 11:13:32 -04:00
m0duspwnens
c4ff8f6876
convert seconds to days
2021-07-12 11:12:28 -04:00
m0duspwnens
619022ef7f
2 new panels to overview
2021-07-12 11:09:23 -04:00
weslambert
c0f3c5b3db
Merge pull request #4773 from Security-Onion-Solutions/feature/filebeat-logging-level
...
Allow setting Filebeat logging level in pillar
2021-07-12 10:55:43 -04:00
m0duspwnens
860b8bf945
panel changes
2021-07-12 10:34:39 -04:00
m0duspwnens
694db81b80
fix locations and panel ids
2021-07-12 10:29:09 -04:00
weslambert
a895270bc8
Allow setting Filebeat logging level in pillar
2021-07-12 10:27:43 -04:00
m0duspwnens
7474b451ca
rename file
2021-07-12 10:24:12 -04:00
m0duspwnens
e8eecc8bc1
rename file
2021-07-12 10:22:25 -04:00
m0duspwnens
28e33b413c
add more panels for overview
2021-07-12 10:17:23 -04:00
Jason Ertel
78c58e61ea
Resolves #4765
2021-07-12 09:38:01 -04:00
William Wernert
f3ecdf21bf
Revert "Add newline to local modifications warning"
...
This reverts commit ff656365d2 .
2021-07-12 09:28:24 -04:00
William Wernert
ff656365d2
Add newline to local modifications warning
2021-07-12 09:22:22 -04:00
William Wernert
ea7c09bb00
Merge branch 'dev' into feature/check-local-mods
2021-07-12 09:20:10 -04:00
Jason Ertel
e23f7cd3e7
Merge pull request #4766 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.70
2021-07-10 13:01:54 -04:00
Jason Ertel
c6bb32b862
Bump version to 2.3.70
2021-07-10 07:34:52 -04:00
m0duspwnens
0bde69b441
update panel
2021-07-09 16:47:39 -04:00
m0duspwnens
6fbafb74bd
update panel
2021-07-09 16:45:02 -04:00
m0duspwnens
9572c1f663
fix var
2021-07-09 16:33:09 -04:00
m0duspwnens
0fedb0f2c5
add 5 minute load avg panel
2021-07-09 16:29:48 -04:00
m0duspwnens
33d3aef9f5
yamlize gridpos
2021-07-09 16:14:25 -04:00
m0duspwnens
fb8ccedf66
reduce height by 2
2021-07-09 16:04:55 -04:00
m0duspwnens
efcf0accc1
change IDs
2021-07-09 16:01:57 -04:00
m0duspwnens
f556d5c07d
change row id
2021-07-09 15:58:45 -04:00
m0duspwnens
6c1f424c0b
fix row_overview
2021-07-09 15:56:27 -04:00
William Wernert
90970f97e8
Add function to check if files copied to local have been changed in default
2021-07-09 15:44:27 -04:00
m0duspwnens
d3137dc6b9
add row panels
2021-07-09 15:43:51 -04:00
m0duspwnens
efaf53f2f7
add a panel header, change memeory usage panel
2021-07-09 15:13:50 -04:00
m0duspwnens
beb7b89275
yamlize the gridpos for panels
2021-07-09 14:13:00 -04:00
Jason Ertel
8c15fa1627
Merge pull request #4758 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.13.3; Use nginx reverse proxy for access to Playbook and Soctopus
2021-07-09 12:40:33 -04:00
m0duspwnens
bc814c9be6
new panels, add containers var, hide manint and monint var from dash
2021-07-09 11:21:06 -04:00
William Wernert
bac7ef71d8
Add logscan.source.ips field
2021-07-09 10:55:11 -04:00
m0duspwnens
dd199ea30f
remove quotes if pillar doesnt exist
2021-07-09 10:00:47 -04:00
m0duspwnens
fc8acac1a5
change id
2021-07-08 17:39:34 -04:00
m0duspwnens
fec269c3e7
add combined container mem panel
2021-07-08 17:28:18 -04:00
m0duspwnens
8e366fd633
add combined container mem panel
2021-07-08 17:27:51 -04:00
m0duspwnens
f7d54186dd
remove all panels from standalone
2021-07-08 17:11:33 -04:00
m0duspwnens
ab92fb3910
add cpucount to standalone
2021-07-08 17:08:45 -04:00
m0duspwnens
6783e2e28b
dont hide cpucount on dashboard
2021-07-08 17:06:21 -04:00
m0duspwnens
4e47d3f458
remove single quotes
2021-07-08 17:04:41 -04:00
m0duspwnens
b265c7dcb7
single quote cpucount
2021-07-08 17:00:17 -04:00
m0duspwnens
f4fae89b8e
fix copy paste error
2021-07-08 16:50:25 -04:00
m0duspwnens
45f0b4c85f
manint and monint
2021-07-08 16:43:53 -04:00
m0duspwnens
7c80483f6e
change CPUS to $cpucount
2021-07-08 16:39:14 -04:00
Jason Ertel
08ba4fdbee
Update Kibana saved objects to 7.13.3
2021-07-08 16:34:16 -04:00
m0duspwnens
7085796601
replace SERVERNAME with $servername
2021-07-08 16:33:21 -04:00
m0duspwnens
091b5f73b1
update var
2021-07-08 14:43:38 -04:00
Jason Ertel
0c079edc1a
Reverse proxy requests to playbook, soctopus, and nodered
2021-07-08 14:27:16 -04:00
m0duspwnens
54cdfb89f6
remove common_standalone.json.jinja
2021-07-08 14:14:40 -04:00
m0duspwnens
f56514ed7d
Merge remote-tracking branch 'remotes/origin/dev' into issue/4674
2021-07-08 14:12:26 -04:00
m0duspwnens
56697fde19
create common dashboard and define templates/dashbaord vars
2021-07-08 14:10:22 -04:00
William Wernert
80525ee736
[wip] Add logscan pipeline
2021-07-08 12:29:50 -04:00
Jason Ertel
a43bdd9aad
Merge pull request #4723 from Security-Onion-Solutions/dev
...
HEAVYNODE_REDIS hotfix
2021-07-08 11:42:22 -04:00
m0duspwnens
20360d0bb0
create node_config measurement for nodes to be used for grafana dashboard vars
2021-07-08 11:18:25 -04:00
Josh Patterson
70d7513f84
Merge pull request #4729 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 14:49:38 -04:00
Josh Patterson
12b7fd3ab4
whitespace
2021-07-07 14:48:07 -04:00
Josh Patterson
c32b5b5429
whitespace
2021-07-07 14:47:16 -04:00
Josh Patterson
ea2a748dba
whitespace
2021-07-07 14:44:44 -04:00
Josh Patterson
c1d7d8c55a
add new line
2021-07-07 14:43:20 -04:00
Josh Patterson
a3c58d8445
remove heavy soup
2021-07-07 14:42:38 -04:00
Josh Patterson
cfc5c2aef6
do ; instead of &&
2021-07-07 14:32:57 -04:00
Josh Patterson
313260a0c5
add heavy action in soup for ssl redis, es, ls, fb
2021-07-07 14:22:45 -04:00
Josh Patterson
ee548aaf83
Merge pull request #4728 from Security-Onion-Solutions/fix/heavyfix
...
remove soup control of heavy
2021-07-07 14:01:32 -04:00
m0duspwnens
5eab57e500
remove soup control of heavy
2021-07-07 13:58:52 -04:00
Josh Patterson
6f48fdad42
Merge pull request #4727 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-07 12:15:50 -04:00
m0duspwnens
98fb5109d7
tell heavys to update ssl and restart containers for HEAVYNODE_SSL_LOGSTASH_REDIS_PIPELINES hotfix
2021-07-07 12:05:38 -04:00
m0duspwnens
9c2ead16cc
common name changes, allow cert to be managed regardless of expire date for heavy node
2021-07-07 10:22:37 -04:00
Jason Ertel
c4293c6119
Merge pull request #4724 from Security-Onion-Solutions/kilo
...
Merge master into dev via kilo
2021-07-07 07:21:21 -04:00
Jason Ertel
13c392d758
Merge branch 'master' into kilo
2021-07-07 06:40:30 -04:00
m0duspwnens
35f10518b2
map file into container
2021-07-06 17:12:21 -04:00
m0duspwnens
03066c4674
rename file
2021-07-06 17:08:29 -04:00
m0duspwnens
e33a6892b3
point to new location
2021-07-06 16:58:15 -04:00
m0duspwnens
87bb3f4a6b
quote the 5m
2021-07-06 16:45:10 -04:00
m0duspwnens
62bfaa4e45
send node_config data into telegraf for dashboard queries
2021-07-06 16:30:35 -04:00
Josh Patterson
9e94e605ee
Merge pull request #4715 from Security-Onion-Solutions/fix/heavyfix
...
add to HOTFIX file
2021-07-06 16:01:11 -04:00
m0duspwnens
f8dc647b1f
add to HOTFIX file
2021-07-06 15:59:35 -04:00
Josh Patterson
fc727d6909
Merge pull request #4711 from Security-Onion-Solutions/fix/heavyfix
...
Fix/heavyfix
2021-07-06 15:56:02 -04:00
m0duspwnens
c1d61dc624
add to HOTFIX file
2021-07-06 15:54:15 -04:00
m0duspwnens
0627ca2fc2
use heavynode hostname for certs if heavynode. changes to logstash pipeline for redis if heavynode
2021-07-06 15:32:39 -04:00
weslambert
ce0b064972
Add conditional for heavynode for redis and elasticsearch
2021-07-06 14:21:29 -04:00
weslambert
2f3f04e4ca
Change from nodename to host
2021-07-06 14:18:39 -04:00
weslambert
2e91f27336
Add conditional for heavynode
2021-07-06 14:17:49 -04:00
weslambert
10b1829830
Add conditional for heavynode
2021-07-06 14:16:34 -04:00
weslambert
4946f32d88
Add extra_hosts entry for local instance when running as heavy node
2021-07-06 14:14:58 -04:00
m0duspwnens
dc1363aaf5
create file for telegraf to read node config details
2021-07-06 13:06:03 -04:00
m0duspwnens
a5067718d2
comma control
2021-07-06 11:06:35 -04:00
m0duspwnens
98505a9a3f
beginning of managing individual panels in grafana
2021-07-06 10:08:36 -04:00
Mike Reeves
e054fdb464
Merge pull request #4680 from Security-Onion-Solutions/dev
...
ECSFIX HOTFIX
2021-07-02 11:16:49 -04:00
Mike Reeves
3c8ad18693
Merge pull request #4683 from Security-Onion-Solutions/2.3.60ecs
...
2.3.60 ECSFIX
2021-07-02 11:05:17 -04:00
Mike Reeves
0a91f571c1
2.3.60 ECSFIX
2021-07-02 10:41:15 -04:00
Mike Reeves
8db5284f6e
Merge pull request #4679 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update telegraf.conf
2021-07-02 09:48:33 -04:00
Mike Reeves
22aa695508
Update telegraf.conf
2021-07-02 09:47:31 -04:00
m0duspwnens
a16f733622
add individual panels
2021-07-02 09:35:04 -04:00
Mike Reeves
af7d6c8cb5
Merge pull request #4678 from Security-Onion-Solutions/ecsfix1
...
ECS Hotfix
2021-07-02 09:14:42 -04:00
Mike Reeves
693f455862
ECS hotfix
2021-07-02 08:55:49 -04:00
Mike Reeves
b0abd290a9
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-02 08:47:02 -04:00
Mike Reeves
0a9686f584
Merge pull request #4669 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
2.3.70
2021-07-01 14:39:01 -04:00
Mike Reeves
0b11bf6266
Update VERSION
2021-07-01 14:37:56 -04:00
Mike Reeves
73b47716bc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-07-01 13:00:30 -04:00
Mike Reeves
b5fecd30cf
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 17:05:17 -04:00
Mike Reeves
a08166f27d
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-30 11:38:15 -04:00
Mike Reeves
846aef1bd6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-24 14:54:51 -04:00
Mike Reeves
78fa4feac6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-23 15:38:38 -04:00
Mike Reeves
6e780164ea
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-22 09:52:44 -04:00
Mike Reeves
85d7e75fb1
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 16:09:11 -04:00
Mike Reeves
0dc4bc3cee
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-17 13:30:58 -04:00
Mike Reeves
8d6b0e23ce
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-06-16 13:23:44 -04:00
Mike Reeves
8aaf3e1052
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-04 10:44:13 -04:00
Mike Reeves
21b92ac077
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-05-02 13:06:29 -04:00
Mike Reeves
96eab86bc6
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-29 11:19:19 -04:00
Mike Reeves
4c55e5a6cc
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into dev
2021-04-28 10:27:55 -04:00
Mike Reeves
77533f7873
Repo Fix
2021-04-27 15:45:35 -04:00
Mike Reeves
a6b2eefee1
Prompt airgap to update
2021-04-27 15:33:52 -04:00
Mike Reeves
4cea08c080
Prompt airgap to update
2021-04-27 15:32:00 -04:00
Mike Reeves
d56e66917a
2.3.50 sig files
2021-04-26 09:18:15 -04:00