Mike Reeves
0bc3d5d757
Merge pull request #7741 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110 20220407
2022-04-07 16:30:50 -04:00
Mike Reeves
6d88a5b541
Merge pull request #7740 from Security-Onion-Solutions/hfix0407
...
2.3.110 hotfix 0407
2022-04-07 16:11:58 -04:00
Mike Reeves
6a28e752f0
2.3.110 hotfix 0407
2022-04-07 16:03:13 -04:00
Mike Reeves
2ad3f63cb5
Merge pull request #7739 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-04-07 14:46:20 -04:00
Mike Reeves
93e04850c4
Update HOTFIX
2022-04-07 14:40:54 -04:00
Josh Patterson
09e7b5a8bf
Merge pull request #7733 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-07 09:05:51 -04:00
m0duspwnens
8fbd16f75d
ensure salt.list is absent
2022-04-07 09:03:51 -04:00
m0duspwnens
722b200e16
add retry to apt_update incase running in background
2022-04-07 08:58:07 -04:00
m0duspwnens
b2a98af18b
proper formatting
2022-04-07 08:55:30 -04:00
m0duspwnens
be3769fd7c
run apt-get update if saltstack.list changes
2022-04-07 08:53:44 -04:00
m0duspwnens
08ac696f14
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-06 17:38:06 -04:00
Josh Patterson
0c1ac729e1
Merge pull request #7731 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update the centos repo for airgap prior to applying hotfix
2022-04-06 17:00:09 -04:00
m0duspwnens
833106775f
update the centos repo for airgap prior to applying hotfix or standard soup run
2022-04-06 16:53:55 -04:00
Mike Reeves
fbd417b09e
Merge pull request #7720 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-05 20:29:17 -04:00
Mike Reeves
4224d1f258
Merge pull request #7719 from Security-Onion-Solutions/hfix0405
...
2.3.110 hotfix 0405
2022-04-05 19:17:42 -04:00
Mike Reeves
79175b57fa
2.3.110 hotfix 0405
2022-04-05 19:15:20 -04:00
Josh Patterson
5717382340
Merge pull request #7717 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
use -r for bootstrap-salt for ubuntu
2022-04-05 17:37:22 -04:00
m0duspwnens
cf68aeb36e
use -r for bootstrap-salt for ubuntu
2022-04-05 17:35:03 -04:00
Josh Patterson
882eb83fee
Merge pull request #7716 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
point to so repo
2022-04-05 17:30:10 -04:00
m0duspwnens
89c7f5b356
point to so repo
2022-04-05 17:28:47 -04:00
Mike Reeves
bed9a20025
Merge pull request #7714 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
proper salt format
2022-04-05 15:45:36 -04:00
m0duspwnens
89518b5939
proper salt format
2022-04-05 15:44:06 -04:00
Mike Reeves
07b14d7fa7
Merge pull request #7713 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update update_repo function
2022-04-05 15:42:45 -04:00
m0duspwnens
1248ba8924
update update_repo function
2022-04-05 15:40:39 -04:00
Josh Patterson
cbbe3b9248
Merge pull request #7712 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
add deb to saltstack.list
2022-04-05 14:45:46 -04:00
m0duspwnens
b467cde9ad
add deb to saltstack.list
2022-04-05 14:42:36 -04:00
Josh Patterson
6d6f328cad
Merge pull request #7711 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
manage repo conf for ubuntu
2022-04-05 13:50:32 -04:00
m0duspwnens
020871ef61
update hotfix version
2022-04-05 13:49:28 -04:00
m0duspwnens
e08b13629a
manage repo conf for ubuntu
2022-04-05 13:41:26 -04:00
Doug Burks
1e187f0c44
Merge pull request #7703 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-04 23:37:28 -04:00
Mike Reeves
f5073243f9
Merge pull request #7702 from Security-Onion-Solutions/hfix0401
...
2.3.110 hotfix 0401
2022-04-04 16:13:08 -04:00
Mike Reeves
04370a04ce
2.3.110 hotfix 0401
2022-04-04 16:06:20 -04:00
Josh Patterson
809bc1858c
Merge pull request #7700 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
salt 3004.1 hotfix
2022-04-04 13:32:34 -04:00
m0duspwnens
f9563b2dc4
patch influxdb modules
2022-04-04 12:57:36 -04:00
m0duspwnens
b7aff4f4df
remove influxdb state files
2022-04-04 12:28:23 -04:00
m0duspwnens
1e955e0d38
enable highstate before highstate run for hotfix
2022-04-04 11:28:03 -04:00
m0duspwnens
127420b472
hotfix function for 2.3.10 hotfix 1
2022-04-04 10:39:44 -04:00
Josh Patterson
7f4c2687cf
Merge pull request #7691 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove influx patch state files
2022-04-01 15:58:03 -04:00
m0duspwnens
48e40513ff
remove influx patch state files
2022-04-01 15:53:48 -04:00
Josh Patterson
c429423dae
Merge pull request #7683 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
Update to salt 3004.1
2022-04-01 11:19:31 -04:00
m0duspwnens
45dd7d4758
salt 3004.1 in setup
2022-04-01 11:17:38 -04:00
Josh Patterson
f71fcdaed7
salt 3004.1
2022-04-01 09:55:55 -04:00
Josh Patterson
d95391505f
Update minion.defaults.yaml
2022-04-01 09:55:03 -04:00
Mike Reeves
0b80dad2c0
Merge pull request #7682 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-04-01 09:53:57 -04:00
Mike Reeves
02a96c409e
Update HOTFIX
2022-04-01 09:52:57 -04:00
Mike Reeves
3725130128
Merge pull request #7481 from Security-Onion-Solutions/dev
...
2.3.110
2022-03-09 14:44:40 -05:00
Mike Reeves
2c66fa1883
Merge pull request #7482 from Security-Onion-Solutions/kilo
...
Merge master with .100 hotfix #3 into dev
2022-03-09 12:24:04 -05:00
Jason Ertel
61a3155dfa
merge from master
2022-03-09 12:22:24 -05:00
Mike Reeves
99f25deb80
Merge pull request #7480 from Security-Onion-Solutions/2.3.110rel
...
2.3.110
2022-03-09 12:16:31 -05:00
Mike Reeves
0cb628f565
2.3.110
2022-03-09 12:12:32 -05:00
weslambert
262e68cb75
Merge pull request #7469 from Security-Onion-Solutions/fix/kibana_config_load_template
...
Add .template extension to ensure we are loading the template and not the resultant file
2022-03-08 21:12:29 -05:00
weslambert
c83b63d0d8
Add .template extension to load template file
2022-03-08 20:53:16 -05:00
weslambert
8d9ddf5f1b
Add .template extension to load template
2022-03-08 20:52:13 -05:00
weslambert
8115da358f
Add .template extension to load template file
2022-03-08 20:51:50 -05:00
Doug Burks
06efef7b81
Merge pull request #7467 from Security-Onion-Solutions/dougburks-patch-1
...
Revert security_opt addition in telegraf init.sls
2022-03-08 18:51:52 -05:00
Doug Burks
b76c01ef53
Revert security_opt addition in telegraf init.sls
2022-03-08 18:27:15 -05:00
weslambert
5f3c29b7f8
Merge pull request #7466 from Security-Onion-Solutions/fix/process_name_keyword
...
Add process.name.keyword
2022-03-08 12:47:31 -05:00
weslambert
65f998d6f7
Remove process.name.keyword for future-proofing
2022-03-08 12:44:51 -05:00
weslambert
406267a892
Add process.name.keyword
2022-03-08 12:42:34 -05:00
weslambert
d9c3160fbf
Merge pull request #7465 from Security-Onion-Solutions/fix/kibana_saved_objects_load
...
Kibana dashboard/saved objects loading improvements
2022-03-08 12:22:55 -05:00
Wes Lambert
d392cb258c
Switch Kibana state to kibana.so_savedobjects_defaults in top file
2022-03-08 16:59:48 +00:00
Wes Lambert
86e228b200
Add .template extension for future-proofing config files
2022-03-08 16:58:37 +00:00
Wes Lambert
a6fd1023b4
Fix criteria for successful execution
2022-03-08 16:57:26 +00:00
Wes Lambert
3f31f7fd41
Add .template extension to fix script behavior and not modify watched file
2022-03-08 16:43:43 +00:00
Jason Ertel
f64da9632f
Merge pull request #7461 from Security-Onion-Solutions/kilo
...
Gracefully handle situations where another process is using the Kratos DB while so-user executes
2022-03-08 11:02:14 -05:00
Jason Ertel
0cec5879bb
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:55:26 -05:00
Jason Ertel
d8ca4976be
Merge branch 'dev' into kilo
2022-03-08 10:41:40 -05:00
Jason Ertel
914d81ca07
Revert "Gracefully handle situations when another process is using the Kratos DB"
...
This reverts commit f2865d8b7f .
2022-03-08 10:40:20 -05:00
Jason Ertel
f2865d8b7f
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:38:05 -05:00
Wes Lambert
28554164cd
Remove drop file when securitySolution saved objects change
2022-03-08 14:39:23 +00:00
Wes Lambert
14dddd8649
Remove drop file when config saved objects change
2022-03-08 14:37:15 +00:00
Wes Lambert
c0f49f6fb0
Remove drop file when dashbaord saved objects change
2022-03-08 14:35:04 +00:00
Wes Lambert
d10d4acf9f
Modify Kibana config load script to drop file if successfully executed
2022-03-08 14:33:15 +00:00
Doug Burks
da8e885ede
Merge pull request #7451 from Security-Onion-Solutions/fix/docker-apparmor
...
Update init.sls to avoid telegraf apparmor issues
2022-03-07 17:06:42 -05:00
Doug Burks
104de2a3c9
Update init.sls to avoid telegraf apparmor issues
...
See #2560
2022-03-07 16:11:22 -05:00
Mike Reeves
fb59421f5b
Merge pull request #7446 from Security-Onion-Solutions/fixpipelineload
...
Only load pipelines on change
2022-03-07 15:17:32 -05:00
weslambert
e2bda255cc
Merge pull request #7447 from Security-Onion-Solutions/fix/es_templates_soup
...
Remove old Elasticsearch index templates during SOUP
2022-03-07 15:10:44 -05:00
Mike Reeves
4eb37fd5a9
Update init.sls
2022-03-07 15:09:36 -05:00
Wes Lambert
fa9be58b23
Specify index templates
2022-03-07 20:04:23 +00:00
Wes Lambert
647b316a96
Remove old ES index templates
...
Signed-off-by: Wes Lambert <wlambertts@gmail.com >
2022-03-07 20:02:45 +00:00
Mike Reeves
d33db6fb23
Only load pipelines on change
2022-03-07 14:25:46 -05:00
weslambert
eac120f4c2
Merge pull request #7444 from Security-Onion-Solutions/fix/dtc_client_override
...
Add DTC client mappings
2022-03-07 13:38:19 -05:00
Wes Lambert
c549b20221
Add DTC client mappings
2022-03-07 18:36:26 +00:00
Mike Reeves
e6132be4e6
Merge pull request #7443 from Security-Onion-Solutions/fixtemplates
...
Only load templates on change
2022-03-07 10:42:51 -05:00
Mike Reeves
c67604590d
Only load templates on change
2022-03-07 09:52:18 -05:00
weslambert
5600b55f05
Merge pull request #7427 from Security-Onion-Solutions/fix/syslog_kibana_viz
...
Replace syslog facility and severity with label fields in Kibana syslog dashboard
2022-03-07 08:14:35 -05:00
Doug Burks
a59779905f
Merge pull request #7437 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo
2022-03-07 08:05:07 -05:00
Doug Burks
848a5c6350
fix typo
2022-03-07 08:03:41 -05:00
Wes Lambert
33ba45472f
Replace syslog facility and severity with label fields
2022-03-04 21:40:41 +00:00
weslambert
ee4035f022
Merge pull request #7426 from Security-Onion-Solutions/fix/syslog_zeek
...
Change to label fields for syslog facility and severity
2022-03-04 16:31:45 -05:00
weslambert
f71ccadb8a
Change to label fields for Zeek syslog
2022-03-04 16:29:55 -05:00
weslambert
fc3273fa49
Change to label fields to comply with what's defined in Filebeat template
2022-03-04 16:29:01 -05:00
weslambert
3148fa0e06
Merge pull request #7422 from Security-Onion-Solutions/fix/syslog_dot_keyword
...
.keyword additions and increase max_clause_count
2022-03-04 15:32:29 -05:00
weslambert
254cf53c2f
Increase clause count to 3500
2022-03-04 10:36:37 -05:00
Wes Lambert
ffae22beef
Add DTC syslog mappings for .keyword and add refs to defaults.yml
2022-03-04 13:04:11 +00:00
weslambert
93c2f82345
Merge pull request #7413 from Security-Onion-Solutions/fix/add_keyword_subfield
...
Add .keyword subfield for more mappings
2022-03-03 10:42:38 -05:00
Wes Lambert
1f71816ad7
Add keyword subfield for DTC winlog mappings
2022-03-03 14:54:30 +00:00
Wes Lambert
1c086e36da
Add missing comma for file mappings
2022-03-03 13:49:54 +00:00
Wes Lambert
aa8d24b6cd
Add DTC destination, source, and winlog mapping references to templates in defaults file
2022-03-03 13:42:20 +00:00
Wes Lambert
85979cbce8
Add file, process, and winlog mapping changes
2022-03-03 13:37:27 +00:00
Wes Lambert
8f97f09c9c
Additional .keyword changes for host.hostname client.address, and event.action
2022-03-02 21:54:46 +00:00
Wes Lambert
3ee46e4c29
Add .keyword for destination/source geo.country_name
2022-03-02 21:50:03 +00:00
weslambert
a21060306c
Merge pull request #7404 from Security-Onion-Solutions/fix/field_limit_adjustment
...
Adjust field limit for now due to component template errors
2022-03-02 11:41:35 -05:00
Wes Lambert
c5b16fdf3b
Adjust field limit for now
2022-03-02 16:33:39 +00:00
weslambert
b80e82aaf6
Merge pull request #7396 from Security-Onion-Solutions/fix/dot_security
...
Revert back to usage of .security field
2022-03-02 10:42:29 -05:00
Josh Brower
2ba72791aa
Remove sigma regen cron
2022-03-02 10:31:15 -05:00
Mike Reeves
d570b56c55
Merge pull request #7392 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix 2.3.100 20220301
2022-03-02 10:24:50 -05:00
Mike Reeves
ff4345d3aa
Merge pull request #7393 from Security-Onion-Solutions/jertelhf
...
Jertelhf
2022-03-02 10:20:29 -05:00
Jason Ertel
e59f0d69d9
Merge branch 'master' into jertelhf
2022-03-02 10:18:14 -05:00
Mike Reeves
ad2b69c9de
Merge pull request #7391 from Security-Onion-Solutions/hf0301
...
Hotfix 2.3.100 20220301
2022-03-02 10:08:27 -05:00
Mike Reeves
e874c32c08
Hotfix 2.3.100-20220301
2022-03-02 10:05:41 -05:00
Wes Lambert
ab9b81ea39
Change match_only_text to text for mac in host mappings
2022-03-02 15:01:05 +00:00
Wes Lambert
ed620b93b7
Add custom analyzer definition to all SO/DTC mappings
2022-03-02 14:43:19 +00:00
Wes Lambert
27c8eaa630
Update all other mappings for .security where applicable
2022-03-02 14:39:23 +00:00
Wes Lambert
e925d435ff
Update event, file, and host mappings to include .security
2022-03-02 14:33:52 +00:00
Wes Lambert
496b161253
Update ECS mappings to include .security
2022-03-02 14:27:36 +00:00
Wes Lambert
aae2fd1fbb
Update DNS mappings to include .security
2022-03-02 14:27:15 +00:00
Wes Lambert
0b45cf7ae1
Update base mappings to include .security
2022-03-02 14:25:57 +00:00
Wes Lambert
d89af5f04f
Update agent mappings to include .security
2022-03-02 14:25:14 +00:00
Wes Lambert
2d2ec45029
Modify base ECS mappings to include .security where possible, as well as custom analyzer definition
2022-03-02 14:19:36 +00:00
weslambert
93386f4620
Merge pull request #7389 from Security-Onion-Solutions/fix/revert_text
...
Fix/revert text
2022-03-02 09:17:46 -05:00
Mike Reeves
c0649a863b
Merge pull request #7376 from Security-Onion-Solutions/hfnew
...
Curator Fixes
2022-03-01 14:38:31 -05:00
Mike Reeves
e93dbb5347
Update Hotfix
2022-03-01 14:37:03 -05:00
doug
bbced5b52f
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:52 -05:00
Doug Burks
f134c74585
FIX: curator should exclude so-case* indices #7270
2022-03-01 14:34:41 -05:00
Wes Lambert
5489b8559d
Revert "Switch from .security to match_only_text"
...
This reverts commit f7862af934 .
2022-03-01 18:44:00 +00:00
Wes Lambert
2a9caccc7c
Revert "Add additional .text subfield mappings"
...
This reverts commit 61dadc6249 .
2022-03-01 18:43:24 +00:00
Doug Burks
adf3dc0cf6
Merge pull request #7370 from Security-Onion-Solutions/fix/syslog
...
Revert syslog pipeline updates from Abe's PR for now
2022-03-01 11:13:13 -05:00
Wes Lambert
a290602a70
Revert syslog pipeline updates from Abe' PR for now
2022-03-01 15:31:07 +00:00
weslambert
4201ee45c6
Merge pull request #7369 from Security-Onion-Solutions/fix/ingest_timestamp
...
Rename ingest timestamp to event.ingested
2022-03-01 10:11:16 -05:00
Wes Lambert
038dc49098
Temporarily increase field limit before trimming efforts
2022-03-01 15:06:28 +00:00
Wes Lambert
dc07adca63
Rename ingest.timestamp to event.ingested
2022-03-01 15:05:08 +00:00
Josh Brower
39718561ce
Merge pull request #7366 from Security-Onion-Solutions/delta
...
Enable state tracking for sigma refresh
2022-03-01 05:53:14 -05:00
Josh Brower
e960d99901
Enable state tracking for sigma refresh
2022-02-28 21:18:41 -05:00
Josh Brower
09f1a5025d
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-28 21:18:07 -05:00
Josh Brower
41a58b791a
Enable state tracking for sigma refresh
2022-02-28 21:17:59 -05:00
Jason Ertel
73b2a36e89
Merge pull request #7365 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.17.1
2022-02-28 18:26:31 -05:00
Jason Ertel
f147bb33ed
Upgrade to ES 7.17.1
2022-02-28 18:18:09 -05:00
Josh Patterson
6b3b5e9a1f
Merge pull request #7363 from Security-Onion-Solutions/soup_singlenode_30
...
allow for check_log_size_limit to work without salt-master running
2022-02-28 17:13:42 -05:00
Josh Brower
f824717094
Merge pull request #7364 from Security-Onion-Solutions/delta
...
IDH Node verbiage
2022-02-28 17:09:08 -05:00
Josh Brower
0cee0d5dea
IDH Node verbiage
2022-02-28 16:47:24 -05:00
Josh Brower
d71bde0e38
Merge pull request #7362 from Security-Onion-Solutions/delta
...
Navigator - include attack json for airgap
2022-02-28 16:33:10 -05:00
Josh Brower
2075412ca2
Navigator - include attack json for airgap
2022-02-28 16:15:30 -05:00
m0duspwnens
a51f833f36
output only the value for log_size_limit
2022-02-28 16:13:43 -05:00
Jason Ertel
04a99a0adc
Merge pull request #7361 from Security-Onion-Solutions/kilo
...
Clear out hotfix file
2022-02-28 16:04:30 -05:00
Jason Ertel
166ac0d194
Clear out hotfix file
2022-02-28 16:01:42 -05:00
m0duspwnens
8d12e136f2
Merge remote-tracking branch 'remotes/origin/dev' into soup_singlenode_30
2022-02-28 15:43:37 -05:00
m0duspwnens
710059211d
remove debug echo, mkdir verbose
2022-02-28 14:54:39 -05:00
weslambert
a1c0ae4aab
Merge pull request #7356 from Security-Onion-Solutions/fix/es_config_load_order
...
Run template load first to prevent issues with pipeline changes that …
2022-02-28 14:50:22 -05:00
m0duspwnens
80e5198f9e
combine local and default pillars to get pillar values locally
2022-02-28 14:35:16 -05:00
m0duspwnens
dc24cb711d
need local to be --local
2022-02-28 13:50:08 -05:00
m0duspwnens
c5bf818049
debug messages and pass local to lookup_salt_value
2022-02-28 13:39:50 -05:00
weslambert
414b9dcd59
Run template load first to prevent issues with pipeline changes that generate new indices
2022-02-28 12:33:18 -05:00
m0duspwnens
cd981fa2ae
forgot then for if
2022-02-28 12:25:06 -05:00
m0duspwnens
278235b0ca
update so-common lookup_salt_value to accept local option. soup get minion id from grains with local option
2022-02-28 12:15:23 -05:00
weslambert
a9caef9596
Merge pull request #7338 from Security-Onion-Solutions/fix/endgame_template
...
Revert Endgame index name changes
2022-02-28 08:13:09 -05:00
Doug Burks
e0b3635318
Merge pull request #7339 from Security-Onion-Solutions/fix/zeek_dns-import
...
Avoid changing _index for imported logs
2022-02-27 05:09:00 -05:00
Doug Burks
32b71fdcac
Avoid changing _index for imported logs
2022-02-26 10:36:09 -05:00
Wes Lambert
bd1b21a5b6
Revert Endgame index name changes
2022-02-26 02:53:57 +00:00
weslambert
56cb8d62ab
Merge pull request #7337 from Security-Onion-Solutions/fix/pb_overrides
...
Fix formatting for PB overrides
2022-02-25 20:48:38 -05:00
weslambert
e942d81433
Ensure correct formatting for source override
2022-02-25 19:14:58 -05:00
weslambert
a511fd33e9
Ensure correct formatting for destination override
2022-02-25 19:14:21 -05:00
Doug Burks
74037e6f00
Merge pull request #7335 from Security-Onion-Solutions/fix/soup-postversion
...
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 15:27:31 -05:00
Josh Brower
25b0069353
Merge pull request #7334 from Security-Onion-Solutions/delta
...
IDH Setup - dont show ssh fix screen
2022-02-25 15:01:25 -05:00
Josh Brower
6a270eb8b3
IDH Setup - dont show ssh fix screen - fix
2022-02-25 14:58:30 -05:00
Josh Brower
ee39ec1882
IDH Setup - dont show ssh fix screen
2022-02-25 14:55:28 -05:00
Doug Burks
8df47e809d
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 14:30:59 -05:00
Mike Reeves
fa15a2e012
Merge pull request #7333 from Security-Onion-Solutions/endgamecurator
...
Fix endgame index name
2022-02-25 13:31:29 -05:00
Mike Reeves
15924ebe0f
Fix endgame index name
2022-02-25 13:29:29 -05:00
weslambert
c95f48e49a
Merge pull request #7330 from Security-Onion-Solutions/fix/pb-override
...
Override destination/source mappings with .keyword for Playbook
2022-02-25 13:07:31 -05:00
Wes Lambert
a8bdff89ae
Move files into SO component template directory
2022-02-25 18:00:16 +00:00
Wes Lambert
08097fe9ec
Add Playbook override mappings
2022-02-25 17:58:51 +00:00
Josh Brower
ce4c859f3a
Merge pull request #7328 from Security-Onion-Solutions/fix/soup-sigma-refresh
...
.110 Post processing - sigma refresh
2022-02-25 12:24:19 -05:00
Josh Patterson
9de9d92b2b
Merge pull request #7329 from Security-Onion-Solutions/delta
...
add extra hosts for filebeat on idh node
2022-02-25 12:23:37 -05:00
m0duspwnens
d76facb1bb
add extra hosts for idh node
2022-02-25 12:21:43 -05:00
Josh Brower
1abf27873d
.110 Post processing - sigma refresh
2022-02-25 12:19:59 -05:00
weslambert
a6ab09501e
Merge pull request #7326 from Security-Onion-Solutions/fix/additional_text_subfield_mappings
...
Add additional .text subfield mappings
2022-02-25 11:29:26 -05:00
Wes Lambert
61dadc6249
Add additional .text subfield mappings
2022-02-25 16:27:37 +00:00
Josh Brower
be80f0530c
Merge pull request #7321 from Security-Onion-Solutions/delta
...
IDH Improvements
2022-02-24 21:27:36 -05:00
Josh Brower
96ed3cb158
IDH - Setup Summary new lines
2022-02-24 20:59:47 -05:00
Josh Brower
4a597b9f0e
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-24 19:58:10 -05:00
Josh Brower
cf7325a546
IDH - Play tweaks, Setup summary, log rotate
2022-02-24 19:57:11 -05:00
Josh Patterson
8302c45059
Merge pull request #7320 from Security-Onion-Solutions/delta_ssh
...
default to false if local role doesnt exist
2022-02-24 18:06:19 -05:00
m0duspwnens
0970bbc983
default to false if local role doesnt exist
2022-02-24 17:55:50 -05:00
Josh Brower
e8e683c2e9
Merge pull request #7319 from Security-Onion-Solutions/delta
...
Add and Update IDH Plays
2022-02-24 15:48:38 -05:00
Josh Brower
fbc702375c
Add and Update IDH Plays
2022-02-24 15:06:04 -05:00
Josh Patterson
5c747fbb4c
Merge pull request #7318 from Security-Onion-Solutions/delta_ssh
...
change name of selinux policy state for idh node
2022-02-24 14:49:55 -05:00
m0duspwnens
8b61d4818d
change name of selinux policy state for idh node
2022-02-24 14:47:14 -05:00
weslambert
22b01dab1e
Merge pull request #7317 from Security-Onion-Solutions/fix/add_text_subfield_to_dtc_mappings
...
Add .text subfield mappings for DTC where fields are defined
2022-02-24 14:47:11 -05:00
Wes Lambert
0f8a39002f
Add .text subfield mappings for DTC where fields are defined
2022-02-24 19:39:52 +00:00
weslambert
5e29c71381
Merge pull request #7315 from Security-Onion-Solutions/fix/split_zeek_dns
...
Split Zeek DNS records into a separate index
2022-02-24 13:21:52 -05:00
weslambert
23fb62c0d6
Split Zeek DNS records into a separate index
2022-02-24 12:52:25 -05:00
weslambert
313487a887
Merge pull request #7313 from Security-Onion-Solutions/fix/kibana_dashboard_load
...
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:48:28 -05:00
weslambert
bc1794e437
Fix function name
2022-02-24 09:42:14 -05:00
Josh Patterson
d7aa413c46
Merge pull request #7314 from Security-Onion-Solutions/delta
...
default port 2222 for ssh idh node
2022-02-24 09:37:11 -05:00
weslambert
45ccfc5ad4
Add back post to .100 and call for .110
2022-02-24 09:35:43 -05:00
weslambert
582bf4c64c
Remove dashboard updates for .100 so we don't run twice
2022-02-24 09:25:59 -05:00
weslambert
7f08ecdcbe
Add function reference for .110 post changes
2022-02-24 09:25:15 -05:00
weslambert
a22e470038
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:20:44 -05:00
weslambert
bc2c1b4ccc
Merge pull request #6935 from abesinger/issue/6912
...
Updated syslog pipeline, resolves #6912 .
2022-02-24 08:33:55 -05:00
Josh Brower
5779e40401
Merge pull request #7308 from Security-Onion-Solutions/defensivedepth-patch-1
...
UC true
2022-02-24 07:48:39 -05:00
Josh Brower
585c275df6
UC true
2022-02-23 19:35:10 -05:00
Josh Brower
babc114d27
Merge branch 'delta' of https://github.com/Security-Onion-Solutions/securityonion into delta
2022-02-23 19:33:18 -05:00
Josh Brower
2bf20bd1f0
UC true
2022-02-23 19:33:10 -05:00
Josh Patterson
a9c6dc32ab
Merge pull request #7305 from Security-Onion-Solutions/delta_ssh
...
allow only manager to connect to ssh port for idh node
2022-02-23 15:17:31 -05:00
m0duspwnens
61ae61953f
allow only manager to connect to ssh port for idh node
2022-02-23 15:14:11 -05:00
weslambert
2aa811dcd2
Merge pull request #7300 from Security-Onion-Solutions/fix/new_es_template_config
...
Add IDH and Kratos index templates
2022-02-23 12:24:38 -05:00
weslambert
6a0ecb9e9c
Add IDH and Kratos index templates
2022-02-23 12:13:46 -05:00
Josh Brower
b7b2183c15
Merge pull request #7296 from Security-Onion-Solutions/delta
...
IDH - Import & Enables Plays
2022-02-23 10:52:37 -05:00
weslambert
00dbf54a5f
Merge pull request #7295 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-functions
2022-02-23 10:50:32 -05:00
Josh Brower
83aa261d88
IDH - Import & Enables Plays
2022-02-23 10:50:13 -05:00
Mike Reeves
c4cc3fa35f
Update so-functions
2022-02-23 10:47:37 -05:00
Josh Brower
0121eda536
Merge pull request #7282 from Security-Onion-Solutions/delta
...
Initial Support - IDH Node
2022-02-23 08:49:40 -05:00
Doug Burks
aadc2a844b
Merge pull request #7284 from Security-Onion-Solutions/fix/so-curator-closed-delete
...
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:40:23 -05:00
doug
1392fc37e8
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:00:52 -05:00
weslambert
9f7612b599
Merge pull request #7283 from Security-Onion-Solutions/fix/match_only_text
...
Switch from .security to using match_only_text with .text
2022-02-22 15:41:29 -05:00
Wes Lambert
f7862af934
Switch from .security to match_only_text
2022-02-22 20:33:49 +00:00
Josh Brower
1d95aca4de
IDH - VNC default port
2022-02-22 14:16:45 -05:00
Josh Brower
99554d5db8
IDH - UDP vs TCP support
2022-02-22 14:10:05 -05:00
Josh Brower
df9fc807a3
IDH - restart scripts, filebeat fix
2022-02-22 08:05:53 -05:00
Josh Brower
3610b0cd30
merge in dev
2022-02-21 16:52:53 -05:00
Josh Brower
eea2b9ccfd
IDH - Play - ssh
2022-02-21 16:43:26 -05:00
Josh Brower
05be776f4b
IDH - so-status
2022-02-21 16:41:36 -05:00
Doug Burks
5b46d19b13
Merge pull request #7273 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:25:58 -05:00
Doug Burks
1abd824c5f
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:00:05 -05:00
Josh Brower
2203e2fedd
IDH - Final setup fixes
2022-02-19 21:01:48 -05:00
Josh Brower
780cd38adf
IDH - setup tweaks
2022-02-19 12:28:45 -05:00
Mike Reeves
fc0e27a7ae
Merge pull request #7261 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update networks.cfg.jinja
2022-02-18 20:03:47 -05:00
Mike Reeves
0d1da5d1dc
Update networks.cfg.jinja
2022-02-18 20:02:50 -05:00
Josh Brower
bf477a1c19
IDH - Initial whiptail
2022-02-18 17:21:04 -05:00
weslambert
3124f2bd12
Merge pull request #7255 from Security-Onion-Solutions/fix/remove_old_templates
...
Remove old index templates
2022-02-18 15:23:07 -05:00
Jason Ertel
380f0ef93a
Merge pull request #7256 from Security-Onion-Solutions/kilo
...
Update password len requirements; clarify password update help
2022-02-18 15:19:08 -05:00
Jason Ertel
93e9548eaf
Require a minimum of 8 characters for passwords, to match Kratos min requirements
2022-02-18 15:14:48 -05:00
Wes Lambert
4d1533537b
Remove old index templates
2022-02-18 20:08:13 +00:00
Josh Brower
0362afb260
IDH - Finalize Firewall config
2022-02-18 13:23:48 -05:00
Josh Patterson
d14967dd45
Merge pull request #7251 from Security-Onion-Solutions/issue/7233
...
dont allow $ to be used for elasticsearch:auth or kibana:secrets
2022-02-18 13:22:22 -05:00
m0duspwnens
cb55af4c1c
dont allow $ to be used for elasticsearch:auth or kibana:secrets - https://github.com/Security-Onion-Solutions/securityonion/issues/7233
2022-02-18 13:13:56 -05:00
weslambert
87a5e64f12
Merge pull request #7249 from Security-Onion-Solutions/fix/component_index_association
...
Update component -> index association for file/scan mappings for Strelka
2022-02-18 12:19:41 -05:00
Josh Brower
8de5a054d4
Merge pull request #7248 from Security-Onion-Solutions/feature/kratos-log-ingest
...
Ingest Kratos logs
2022-02-18 11:56:20 -05:00
William Wernert
786b01c85a
Merge pull request #6496 from JamesMConroy/so-staus-tty
...
so-staus detects tty
2022-02-18 11:52:18 -05:00
Josh Brower
118277ebc5
Ingest Kratos logs
2022-02-18 11:49:02 -05:00
Mike Reeves
27299cbe1b
Merge pull request #7247 from christopherwoodall/patch-7
...
Update so-setup
2022-02-18 11:47:19 -05:00
Christopher Woodall
118266bf5f
Update so-setup
...
Patch so setup to ignore deprecation warnings.
2022-02-18 11:38:56 -05:00
Mike Reeves
5d949de146
Merge pull request #7246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update networks.cfg.jinja
2022-02-18 11:28:57 -05:00
Mike Reeves
6f4ee4123a
Update networks.cfg.jinja
2022-02-18 11:26:58 -05:00
Mike Reeves
e4148818d8
Merge pull request #7226 from Security-Onion-Solutions/zeekhn
...
Add Zeek Homenet in networks.cfg
2022-02-18 11:11:56 -05:00
Mike Reeves
becdc34677
Merge pull request #7227 from hacker0ni/patch-1
...
Allow downgrades in docker_install
2022-02-18 11:10:26 -05:00
Mike Reeves
95eab61615
Rename to the .jinja standard
2022-02-18 11:06:33 -05:00
Mike Reeves
9341669a15
Merge pull request #7244 from christopherwoodall/patch-6
...
Update config.map.jinja
2022-02-18 09:57:33 -05:00
Jason Ertel
fdc63b5816
Clarify so-user update usage/help
2022-02-18 09:41:09 -05:00
Christopher Woodall
eaff6a12de
Update config.map.jinja
...
Extend the array instead of appending.
2022-02-18 08:50:28 -05:00
weslambert
6ee3287d2d
Update component -> index association for file/scan mappings for Strelka
2022-02-18 08:12:34 -05:00
James Conroy
91c207cd38
Update salt/common/tools/sbin/so-status
...
Removed # {% raw %} from line 170
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:43 -06:00
James Conroy
b774e62dfa
Update salt/common/tools/sbin/so-status
...
Add salt raw directive
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:25 -06:00
Josh Brower
f995d0768f
IDH - Initial firewall support
2022-02-17 15:54:20 -05:00
Doug Burks
3b887c7b1a
Merge pull request #7239 from Security-Onion-Solutions/dougburks-patch-1
...
so-ip-update needs to queue the Kibana dashboard update
2022-02-17 15:54:10 -05:00
Doug Burks
b4b7938ce2
so-ip-update needs to queue the Kibana dashboard update in case a salt operation is already running
2022-02-17 15:47:33 -05:00
Doug Burks
e5d7c1c77a
Merge pull request #7238 from Security-Onion-Solutions/dougburks-patch-1-1
...
so-ip-update needs to update Kibana dashboards
2022-02-17 14:53:31 -05:00
Doug Burks
1a96162966
so-ip-update needs to update Kibana dashboards
2022-02-17 14:49:55 -05:00
hacker0ni
bc72b3da91
Allow downgrades in docker_install
...
When running the installer again on a new node, it tries to pull the docker packages but since the installer ran again before, the install command fails on Ubuntu 18.04 stating that the `--allow-downgrades` is not specified in the command. This change adds that to circumvent the issue.
2022-02-17 11:47:36 -05:00
Mike Reeves
3e194c9b4b
Walk the homenet for zeek
2022-02-17 11:33:22 -05:00
Josh Brower
6c124733b5
IDH - Enable default states
2022-02-17 10:50:26 -05:00
weslambert
6842099e11
Merge pull request #7224 from Security-Onion-Solutions/fix/zeek_viz
...
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 10:05:46 -05:00
Wes Lambert
5c1f61bda8
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 15:03:46 +00:00
weslambert
53c7ad6041
Merge pull request #7223 from Security-Onion-Solutions/fix/shard_settings_setup
...
Ensure setup configures pillar correctly for index settings
2022-02-17 09:48:11 -05:00
Josh Brower
ef4df58510
IDH - Jinjafy hostname
2022-02-17 09:00:57 -05:00
weslambert
c0f9cb188b
Add missing colon
2022-02-17 07:58:05 -05:00
weslambert
d309c4fc0a
Update pillar structure for index_settings/shards
2022-02-17 07:10:29 -05:00
Jason Ertel
cb9712aa08
Merge pull request #7217 from Security-Onion-Solutions/kilo
...
MFA
2022-02-16 16:47:40 -05:00
weslambert
d084625ee0
Merge pull request #7218 from Security-Onion-Solutions/fix/composable_templates_soup
...
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:24:57 -05:00
weslambert
e71b606dd6
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:22:06 -05:00
weslambert
f1f9322bee
Merge pull request #7216 from Security-Onion-Solutions/fix/es_template_netflow_mappings_indent
...
Fix indent for so-netflow component template references
2022-02-16 14:47:31 -05:00
weslambert
185ea2fd99
Fix indent for so-netflow component template references
2022-02-16 14:46:12 -05:00
Mike Reeves
89eb2d0a8b
Add netowrks.cfg to Zeek
2022-02-16 14:24:58 -05:00
Jason Ertel
2c4ba75c0c
Merge branch 'dev' into kilo
2022-02-15 17:05:24 -05:00
weslambert
9e222b1464
Merge pull request #7206 from Security-Onion-Solutions/feature/template-reorg
...
Re-organize Elasticsearch Index Templates
2022-02-15 16:50:14 -05:00
Josh Brower
3ccef12df7
IDH - Pillarize OpenCanary Config
2022-02-15 13:57:31 -05:00
Wes Lambert
4fa3749418
Remove bind or ES templates
2022-02-15 18:08:03 +00:00
Wes Lambert
786a189f65
Merge branch 'feature/template-reorg' of https://github.com/security-onion-solutions/securityonion into feature/template-reorg
2022-02-15 17:06:02 +00:00
Wes Lambert
de731fc05d
Remove default templates from ES template pillar since they are now managed in the defaults file.
2022-02-15 17:04:57 +00:00
Wes Lambert
3df58eadd1
Modify logic to include custom templates
2022-02-15 17:00:24 +00:00
weslambert
1a53ec4372
Fix malformed copy/paste
2022-02-15 11:14:10 -05:00
Wes Lambert
dce3b7a874
Update defaults file to include ES index templates
2022-02-15 15:53:07 +00:00
Jason Ertel
377fe1987d
Merge branch 'dev' into kilo
2022-02-15 07:49:26 -05:00
Jason Ertel
d97423e9f8
Enable MFA support
2022-02-15 07:49:12 -05:00
Wes Lambert
8e389bf6e5
Add ES template map file
2022-02-14 15:38:32 +00:00
Wes Lambert
ebce67060f
Initial template refactor
2022-02-14 15:20:33 +00:00
James Conroy
a43ac2aea2
Move the jinja endraw directive below is_tty
...
This will prevent jninja from interpreting the shell string length
expansion as the start of jninja comments
2022-02-12 12:25:24 -06:00
James Conroy
95b4f7b4ef
Update the PADDING_CONSTENT to 15
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3046e811f0
Use spaces to define centerd justification output
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
6a1e586b8c
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
01346cbb06
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3adb6c1389
Renamed colors to attributes
...
Also correctly used tput to assign blue color
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dabae3888f
Renamed colors to attributes
...
As suggested by rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
c69e968790
Renamed Colors to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dfcabb5722
Seperate bold attribute from colors
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
b9b3876069
Exit with an error code if the user isn't root
2022-02-12 12:25:23 -06:00
James Conroy
bfcfad2e7d
Check for tty in main
...
So that the value is set every time it is checked
2022-02-12 12:25:23 -06:00
James Conroy
163182c858
Don't set the padding constant if not in a tty
...
This will preserve the original width from before my changes
2022-02-12 12:25:23 -06:00
James Conroy
6b4549499d
Don't split lines after standalone tests
...
This is to make the formatting consistent with the rest of the scripts
2022-02-12 12:25:23 -06:00
James Conroy
68a5826d70
Always print a line of '-'
...
Even when not printing to a tty
This is behavior preferred by the team
2022-02-12 12:25:22 -06:00
James Conroy
daa73c8845
Removed MYNAME variable
...
Preferring to just use the value of $0 instead
2022-02-12 12:25:22 -06:00
James Conroy
7f694c17ed
Revert improvements to usage function
...
Made to make it more consistent with the rest of the scripts in
Security Onion
2022-02-12 12:25:22 -06:00
James Conroy
fd9a03a77f
Added Changes Suggested by Reviewer
...
Added a missing semi colon between a local variable's declaration and
assignment
Removed an unused return value
Made a TODO more descriptive
2022-02-12 12:25:22 -06:00
James Conroy
2993a20947
Moved line declaration out of tty conditional
...
This way it will always be set to ""
2022-02-12 12:25:22 -06:00
James Conroy
ac5527e1ab
Added Comments for future enhancements
2022-02-12 12:25:22 -06:00
James Conroy
715f9da6e2
Reworked tty detection and status printing
...
I was able to reduce the line count and make the script more reliable
2022-02-12 12:25:22 -06:00
James Conroy
caa06b026f
Refactored to reduce length and number of lines
2022-02-12 12:25:21 -06:00
James Conroy
a048de65ca
Print help message if not running as root
2022-02-12 12:25:21 -06:00
James Conroy
f807471a17
Only print color codes if we're printing to a tty
...
If we're not printing to a tty the escape sequences can only clutter the
screen.
Also removed a redundant function to print lines if not printing to a
tty. It was only called if docker wasn't running, not if the output
wasn't a tty.
2022-02-12 12:25:21 -06:00
James Conroy
81122d0693
Updated the useage function to use printf
...
Using a hear doc means we have to exactly specify the formatting. Useing
printf handles formatting for us
2022-02-12 12:25:21 -06:00
Josh Brower
1e5b9ef0bf
IDH - Enable Filebeat
2022-02-10 11:37:10 -05:00
Josh Brower
b66472eced
IDH - disable nginx
2022-02-09 14:56:56 -05:00
Josh Brower
f31fbbf1ed
IDH - states allowed
2022-02-09 13:57:18 -05:00
William Wernert
1fee5e6a60
Merge pull request #7162 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Also merge CONTRIBUTING.md changes to dev
2022-02-09 11:59:00 -05:00
William Wernert
bc5fa55ecd
Merge pull request #7160 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Update CONTRIBUTING.md
2022-02-09 11:49:52 -05:00
William Wernert
2e2eed9f42
PR's -> pull requests
2022-02-09 11:45:12 -05:00
William Wernert
3f83191083
Update CONTRIBUTING.md
2022-02-09 11:34:39 -05:00
Josh Brower
30c40ed3d7
IDH Initial Support
2022-02-09 10:37:47 -05:00
Mike Reeves
d63fe73c90
Merge pull request #7157 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update to 7.17.0
2022-02-09 09:46:25 -05:00
Mike Reeves
51bd266717
Update to 7.17.0
2022-02-09 09:44:28 -05:00
weslambert
380fa7d0c8
Merge pull request #7153 from Security-Onion-Solutions/fix/dtc_event_mappings
...
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 16:36:49 -05:00
Wes Lambert
9b841fd872
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 21:34:32 +00:00
weslambert
c216457a3e
Merge pull request #7147 from Security-Onion-Solutions/fix/ct_snyk
...
Add Snyk component template
2022-02-08 10:25:27 -05:00
Wes Lambert
c2c4e4df17
Add Snyk component template
2022-02-08 15:23:43 +00:00
weslambert
7be1549d41
Merge pull request #7146 from Security-Onion-Solutions/feature/additional_dtc_ct
...
Additional component templates
2022-02-08 10:12:31 -05:00
Josh Brower
ac8e06e79b
Initial support - IDH Node
2022-02-08 09:08:52 -05:00
Josh Brower
a3602c9eb9
Initial support - IDH Node
2022-02-08 08:24:15 -05:00
Wes Lambert
f9a50d33c3
Add new templates
2022-02-08 13:17:23 +00:00
Wes Lambert
2951e12c96
Remove snyk component template for now and fix folder structure
2022-02-08 13:16:59 +00:00
Wes Lambert
6d0ca6fcbb
Fix mangled key name/typo
2022-02-08 12:59:07 +00:00
Wes Lambert
2dd5db15b6
Add component and index template listing scripts
2022-02-08 03:40:42 +00:00
Wes Lambert
5090854d4d
Add additional component templates and index template references
2022-02-08 03:03:55 +00:00
Josh Brower
37b17b8821
Initial support - IDH Node
2022-02-07 19:27:51 -05:00
Josh Brower
f590bc43a6
Initial support - IDH Node
2022-02-07 19:09:27 -05:00
Josh Brower
7a9cb6d110
Initial support - IDH Node
2022-02-07 16:49:11 -05:00
weslambert
b41c5439c6
Merge pull request #7141 from Security-Onion-Solutions/fix/index_template_mapping_reference
...
Add mapping references for new component templates to index templates
2022-02-07 15:06:19 -05:00
Wes Lambert
1366e5288e
Add mappings references for new component templates to index templates
2022-02-07 19:54:23 +00:00
weslambert
f9196a8228
Merge pull request #7140 from Security-Onion-Solutions/feature/dtc_new_mappings
...
New DTC/Component Template Mappings
2022-02-07 14:47:07 -05:00
Wes Lambert
03bfb052ed
Add component templates for Elasticsearch, Kibana, Logstash, Netflow, Suricata, and Zeek
2022-02-07 19:42:24 +00:00
Josh Brower
9b1fac8417
Initial support - IDH Node
2022-02-07 14:36:40 -05:00
weslambert
c9b40d8569
Merge pull request #7136 from Security-Onion-Solutions/feature/so_es_indices_list_sort
...
Sort index listing alphabetically and add header
2022-02-07 09:34:58 -05:00
Wes Lambert
50215c550b
Sort index listing alphabetically and add header (@gebhard73)
2022-02-07 14:31:42 +00:00
Josh Patterson
ee17064585
Merge pull request #7122 from Security-Onion-Solutions/soup_docker_iso
...
Soup docker iso
2022-02-07 09:29:35 -05:00
Josh Patterson
e0c0eba24e
Update soup
2022-02-07 09:23:30 -05:00
Josh Patterson
7d09d1f7e2
Update soup
2022-02-07 09:22:43 -05:00
Mike Reeves
77fc9df448
Merge pull request #7134 from Security-Onion-Solutions/mastermerger
...
Mastermerger
2022-02-07 08:38:27 -05:00
Mike Reeves
abd121733f
Merge branch 'master' into mastermerger
2022-02-07 08:34:17 -05:00
m0duspwnens
7c31eb1288
mount iso at different point
2022-02-04 16:07:06 -05:00
m0duspwnens
780aace854
set AGDOCKER
2022-02-04 15:44:25 -05:00
m0duspwnens
eb0696b425
update dockers if -f used
2022-02-04 15:36:44 -05:00
m0duspwnens
267ef354c2
unmount iso after updating dockers
2022-02-04 15:09:35 -05:00
m0duspwnens
23fbf140ba
soup with dockers from iso
2022-02-04 15:06:42 -05:00
weslambert
d0b54a3a34
Merge pull request #7119 from Security-Onion-Solutions/feature/dtc_additional
...
Add additional scan and rule fileset mappings
2022-02-04 14:14:20 -05:00
Wes Lambert
317f6471d8
Add additional scan and rule filset mappings
2022-02-04 19:05:09 +00:00
weslambert
08c7181f1a
Merge pull request #7118 from Security-Onion-Solutions/fix/dtc_file_mappings
...
Fix/dtc file mappings
2022-02-04 13:22:11 -05:00
Wes Lambert
1ce8bb3523
Fix winlog mapping reference reversion
2022-02-04 18:14:01 +00:00
Wes Lambert
5e03b1a5de
Fix reference for file mappings in template
2022-02-04 18:11:03 +00:00
weslambert
898db542bf
Merge pull request #7117 from Security-Onion-Solutions/feature/winlog_dtc_mappings
...
Add winlog mappings
2022-02-04 12:16:16 -05:00
weslambert
66452b14ef
Merge pull request #7116 from Security-Onion-Solutions/fix/endgame_mappings
...
Fix EG template and mappings
2022-02-04 12:16:07 -05:00
Wes Lambert
69cb83cac9
Add winlog mappings
2022-02-04 17:08:26 +00:00
Wes Lambert
f3902cf77d
Fix EG template and mappings
2022-02-04 16:00:16 +00:00
weslambert
1af63edc6b
Merge pull request #7115 from Security-Onion-Solutions/feature/additional_dtc_mappings
...
Additional DTC mapping changes
2022-02-04 10:46:47 -05:00
Wes Lambert
a3031b2b5c
Additional DTC mapping changes
2022-02-04 15:38:51 +00:00
Doug Burks
e54ece06a2
Merge pull request #7106 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-03 16:25:04 -05:00
Mike Reeves
cc986c8d7c
Merge pull request #7105 from Security-Onion-Solutions/23100hotfix2
...
2.3.100 Hotfix 2
2022-02-03 16:04:06 -05:00
Mike Reeves
b7732fb14a
2.3.100 Hotfix 2
2022-02-03 15:58:26 -05:00
Mike Reeves
6f03662120
Merge pull request #7102 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update HOTFIX
2022-02-03 15:08:52 -05:00
Mike Reeves
4f2952105e
Update HOTFIX
2022-02-03 15:06:18 -05:00
Josh Patterson
b34d0d7f7a
Merge pull request #7100 from Security-Onion-Solutions/100_hotfix_2
...
100 hotfix 2
2022-02-03 13:15:37 -05:00
weslambert
1edc1dd842
Merge pull request #7096 from Security-Onion-Solutions/fix/dtc-ct-keyword-subfield
...
Add more DTC transition mappings
2022-02-03 12:35:34 -05:00
Wes Lambert
1ce386bb7f
Add more DTC transition mappings
2022-02-03 17:33:05 +00:00
weslambert
c7d23df000
Merge pull request #7076 from Security-Onion-Solutions/fix/zeek_dns_answers_name
...
Rename dns.answers to prevent field conflict
2022-02-03 12:22:26 -05:00
m0duspwnens
797d769661
use actual hostname in logstash:nodes pillar
2022-02-03 10:36:18 -05:00
Mike Reeves
bbd2f0da2b
Merge pull request #7094 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update distributed-airgap-manager
2022-02-03 10:36:09 -05:00
Mike Reeves
5c39162aef
Update distributed-airgap-sensor
2022-02-03 10:34:55 -05:00
Mike Reeves
d8a4301533
Update distributed-airgap-manager
2022-02-03 10:34:12 -05:00
Doug Burks
c39047666b
Merge pull request #7082 from Security-Onion-Solutions/hotfix/2.3.100
...
Hotfix/2.3.100
2022-02-02 16:38:27 -05:00
Mike Reeves
5c75bb8e7a
Merge pull request #7080 from Security-Onion-Solutions/23100hotfix
...
2.3.100 Hotfix
2022-02-02 16:30:46 -05:00
Mike Reeves
83683ec27e
2.3.100 Hotfix
2022-02-02 16:23:51 -05:00
Mike Reeves
b94cae0176
2.3.100 Hotfix
2022-02-02 16:22:44 -05:00
Mike Reeves
fc0824ceb0
2.3.100 Hotfix
2022-02-02 16:20:49 -05:00
weslambert
c5b5c5858e
Rename to prevent field conflict
2022-02-02 14:31:46 -05:00
weslambert
5e9e0d971b
Merge pull request #7070 from Security-Onion-Solutions/feature/composable_templates
...
Initial composable template configuration and base mappings
2022-02-02 10:25:15 -05:00
Mike Reeves
73a43f3816
Merge pull request #7069 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-02-02 09:57:26 -05:00
Mike Reeves
8152aec22e
Update HOTFIX
2022-02-02 09:49:19 -05:00
Mike Reeves
0e28e1e4cb
Merge pull request #7066 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update acng.conf
2022-02-02 09:22:00 -05:00
Josh Patterson
13f87e4654
Merge pull request #7067 from Security-Onion-Solutions/m0duspwnens-patch-2.3.100
...
FIX: ssl state and manager hostname with uppercase
2022-02-02 09:21:54 -05:00
Josh Patterson
a02fb37493
Update init.sls
2022-02-02 09:18:02 -05:00
Mike Reeves
eaeed07fd4
Update acng.conf
2022-02-02 09:12:29 -05:00
Wes Lambert
9db1510b0e
Initial composable template configuration and base mappings
2022-02-02 02:08:31 +00:00
Jason Ertel
1bac031975
Merge pull request #7058 from Security-Onion-Solutions/kilo
...
Bump to 2.3.110
2022-02-01 15:04:48 -05:00
Jason Ertel
c5d6f09320
Bump to 2.3.110
2022-02-01 15:03:41 -05:00
Mike Reeves
943edd0303
Merge pull request #7042 from Security-Onion-Solutions/dev
...
2.3.100 Release
2022-01-31 16:29:57 -05:00
Mike Reeves
b49524a293
Merge pull request #7041 from Security-Onion-Solutions/23100release
...
2.3.100 Release
2022-01-31 14:07:02 -05:00
Mike Reeves
6dc8415af5
2.3.100 Release
2022-01-31 14:05:22 -05:00
Doug Burks
7927534279
Merge pull request #7040 from Security-Onion-Solutions/dougburks-patch-1
...
Update version from 2.3.91 to 2.3.100
2022-01-31 13:32:05 -05:00
Doug Burks
e0f6b9af3a
Update version from 2.3.91 to 2.3.100
2022-01-31 13:27:45 -05:00
weslambert
6a2111c2ae
Merge pull request #7037 from Security-Onion-Solutions/fix/revert_zeek_dns_answers
...
Revert back to dns.answers for now
2022-01-31 09:55:22 -05:00
weslambert
367b59188b
Revert back to dns.answers for now
2022-01-31 09:54:39 -05:00
Josh Patterson
d3fc61e557
Merge pull request #7035 from Security-Onion-Solutions/soup_salt_repo
...
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager…
2022-01-31 09:05:45 -05:00
m0duspwnens
4dd0ce9f2c
ensure /etc/yum.repos.d/securityonion.repo is absent if not a manager and managerupdates is enabled
2022-01-31 09:01:18 -05:00
Josh Patterson
0c5b4c6070
Merge pull request #7033 from Security-Onion-Solutions/receiver_grafana
...
Receiver grafana
2022-01-31 08:41:56 -05:00
Josh Patterson
a8983dd895
Merge pull request #7028 from Security-Onion-Solutions/soup_salt_repo
...
Soup salt repo
2022-01-31 08:21:17 -05:00
m0duspwnens
e189f10a1b
Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into soup_salt_repo
2022-01-29 11:04:07 -05:00
m0duspwnens
a90660c07b
ensure salt-latest.repo is absent, salt.minion state include repo.client
2022-01-29 11:04:03 -05:00
Mike Reeves
bb87c85e07
Merge pull request #7027 from Security-Onion-Solutions/fix/soup-kibana
...
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 10:07:36 -05:00
Doug Burks
bc0a362b39
Move Kibana dashboard update from post_to_2.3.90() to post_to_2.3.100()
2022-01-29 08:02:56 -05:00
m0duspwnens
3aee8656d4
fix %} - add redis to receiver telegraf
2022-01-28 17:45:12 -05:00
m0duspwnens
980a1a0c3d
add redis to receiver telegraf
2022-01-28 17:44:04 -05:00
m0duspwnens
bf26ae8e41
add receiver to allowed dashboards
2022-01-28 17:32:53 -05:00
m0duspwnens
da3e1e402a
add receiver dashboard grafana
2022-01-28 17:27:58 -05:00
m0duspwnens
1cd1ad9214
add inputs for so-receiver to telegraf conf
2022-01-28 17:18:31 -05:00
Josh Patterson
ddba4a5fe5
Merge pull request #7024 from Security-Onion-Solutions/soup_receiver
...
Soup receiver
2022-01-28 17:01:04 -05:00
m0duspwnens
c8b1e6f501
remove -X from UPGRADECOMMAND so salt-minion starts after upgrade
2022-01-28 15:49:53 -05:00
m0duspwnens
c45efebc7f
Merge remote-tracking branch 'remotes/origin/dev' into soup_receiver
2022-01-28 15:27:27 -05:00
m0duspwnens
014696f62f
fix receiver append to assigned_hostgroups.local.map.yaml
2022-01-28 15:26:37 -05:00
m0duspwnens
6b18551dd1
skip applying repo.client if airgap and saltupgrade prior to yum clean all
2022-01-28 14:39:10 -05:00
weslambert
4ecf4ab253
Merge pull request #7020 from Security-Onion-Solutions/feature/dash_updates
...
EG and HL Dashboard Updates
2022-01-28 13:19:02 -05:00
m0duspwnens
75b8d6a0c5
ensure /etc/yum.repos.d/securityonioncache.repo is absent if global:managerupdate = 0
2022-01-28 13:09:48 -05:00
weslambert
5142e6ccc7
Update so-kibana-config-load
2022-01-28 13:01:33 -05:00
Wes Lambert
3b76c2421c
Update to allow for passing HL saved objects
2022-01-28 17:59:34 +00:00
m0duspwnens
e82c6a2393
default for managerupdate should be int not a string
2022-01-28 12:50:58 -05:00
m0duspwnens
905ca35e93
use sed instead of echo
2022-01-28 11:19:54 -05:00
m0duspwnens
3977146a16
add receiver to firewall files during soup
2022-01-28 10:36:30 -05:00
Josh Patterson
5a37b14809
Merge pull request #7017 from Security-Onion-Solutions/issue/7016
...
dont apply wazuh state on sensors if it is disabled globally
2022-01-28 09:33:34 -05:00
m0duspwnens
15c29bda74
dont apply wazuh state on sensors if it is disabled globally - https://github.com/Security-Onion-Solutions/securityonion/issues/7016
2022-01-28 09:31:02 -05:00
Josh Patterson
d0186c8c1b
Merge pull request #7011 from Security-Onion-Solutions/fix/reinstall
...
https://github.com/Security-Onion-Solutions/securityonion/issues/7010
2022-01-27 16:40:37 -05:00
Jason Ertel
ac21bd1e29
Merge pull request #7009 from Security-Onion-Solutions/kilo
...
Add new abbreviated result limit param
2022-01-27 15:55:42 -05:00
Jason Ertel
14c587fca2
Add new abbreviated result limit param
2022-01-27 15:51:02 -05:00
m0duspwnens
6cc8e4355e
exclude salt ERROR seen during reinstall
2022-01-27 15:31:42 -05:00
m0duspwnens
e63f35a223
change to test
2022-01-27 15:19:33 -05:00
weslambert
69689b470b
Merge pull request #7005 from Security-Onion-Solutions/fix/revert_cases_field_limit
...
Revert field limit from testing
2022-01-27 11:33:31 -05:00
weslambert
fc0a5bce86
Revert field limit from testing
2022-01-27 11:18:35 -05:00
weslambert
39257df396
Merge pull request #7004 from Security-Onion-Solutions/fix/revert_dtc
...
Revert changes to common template
2022-01-27 11:15:50 -05:00
weslambert
60a0204975
Revert changes to common template
2022-01-27 11:02:47 -05:00
William Wernert
c6b11f4e05
Merge pull request #7001 from Security-Onion-Solutions/fix/so-rule-string-split
...
Fix error message printing in so-rule
2022-01-26 16:08:00 -05:00
William Wernert
4532de368a
Fix error message printing in so-rule
2022-01-26 16:04:45 -05:00
m0duspwnens
9e2278a199
Merge remote-tracking branch 'remotes/origin/dev' into fix/reinstall
2022-01-26 15:48:46 -05:00
weslambert
e303fb12cf
Merge pull request #7000 from Security-Onion-Solutions/fix/zeek_dns_answers_pipeline
...
Fix Zeek field name so it doesn't conflict with mapping of other dns.…
2022-01-26 15:04:12 -05:00
weslambert
8f0a327cb5
Fix Zeek field name so it doesn't conflict with mapping of other dns.answers fields
2022-01-26 15:02:59 -05:00
weslambert
bdc5e89822
Merge pull request #6999 from Security-Onion-Solutions/fix/case_mapping_changes_temp
...
Mapping changes for case index
2022-01-26 14:59:45 -05:00
weslambert
1b3e7f9d79
Temp changes while adjusting mapping
2022-01-26 14:57:16 -05:00
Josh Patterson
4f30d43611
Merge pull request #6998 from Security-Onion-Solutions/es_binds
...
mount repo dir in container same as defined on host
2022-01-26 13:59:17 -05:00
m0duspwnens
c80adc0430
mount repo dir in container same as defined on host
2022-01-26 13:42:56 -05:00
weslambert
e77648c475
Merge pull request #6994 from Security-Onion-Solutions/feature/dtc
...
Additional DTC changes
2022-01-26 12:22:48 -05:00
Jason Ertel
c2636036ee
Merge pull request #6995 from Security-Onion-Solutions/kilo
...
store related event data as a flattened object blob
2022-01-26 12:21:02 -05:00
Wes Lambert
e10749a495
Additional changes to template to accomodate default fields and keyword subfield
2022-01-26 17:16:29 +00:00
Jason Ertel
ed9b74dc33
store related event data as a flattened object blob
2022-01-26 12:16:05 -05:00
m0duspwnens
2aa19b78da
dont remove ca-certificates.crt
2022-01-26 11:27:35 -05:00
m0duspwnens
1337af9d69
more dupes
2022-01-26 11:07:06 -05:00
m0duspwnens
a0e493a186
remove dupe ids
2022-01-26 10:50:35 -05:00
m0duspwnens
a43fb293fc
remove role logic
2022-01-26 10:26:52 -05:00
m0duspwnens
8aa002b82e
add states to remove ca and ssl keys and certs and call them during reinstall.
2022-01-26 09:33:19 -05:00
m0duspwnens
8ce0f5b7be
log removal of root cron
2022-01-26 08:31:37 -05:00
Josh Patterson
26e03ccad2
Merge pull request #6978 from Security-Onion-Solutions/es_binds
...
allow for path.repo mounts for elasticsearch
2022-01-25 16:13:49 -05:00
m0duspwnens
dd00e3babc
use .get since repo may not exist
2022-01-25 13:18:21 -05:00
m0duspwnens
5d2b3992e2
dont need to set ES_PATH_REPO
2022-01-25 13:11:53 -05:00
m0duspwnens
7b6eeac03f
dnt mount under /repo in the container
2022-01-25 13:08:46 -05:00
m0duspwnens
00e17d5c78
put repos in /repo in es container
2022-01-25 13:03:54 -05:00
m0duspwnens
a17e1aa87a
930 for group
2022-01-25 13:00:04 -05:00
m0duspwnens
4423e93880
prevent path.repo from being put in elasticsearch.yml if the symlink doesnt exist
2022-01-25 12:57:05 -05:00
m0duspwnens
e62de2934c
fix test for es repo
2022-01-25 12:24:03 -05:00
m0duspwnens
a92e2a917b
change repos to repo
2022-01-25 10:53:28 -05:00
m0duspwnens
a72f12c4c7
add path.repo mount if symlink exists
2022-01-25 10:50:00 -05:00
Josh Patterson
9a45a9799b
Merge pull request #6974 from Security-Onion-Solutions/issue/6599
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6599
2022-01-25 09:11:33 -05:00
weslambert
ba52bd3835
Update template with syntax fixes
2022-01-25 08:56:03 -05:00
m0duspwnens
edd8709cdd
remove export LC_CTYPE="en_US.UTF-8" from soup
2022-01-24 19:42:56 -05:00
m0duspwnens
d6fc436d49
copy files to default salt base
2022-01-24 19:30:34 -05:00
m0duspwnens
82e2b2b611
dont escape raw and endraw
2022-01-24 17:03:25 -05:00
m0duspwnens
d083338350
adding --local
2022-01-24 16:46:29 -05:00
m0duspwnens
e3f1b456e6
add raw end raw back
2022-01-24 16:09:15 -05:00
m0duspwnens
268e07e2a2
remove jinja from soup scripts
2022-01-24 15:49:55 -05:00
Doug Burks
80b7487d45
Merge pull request #6968 from Security-Onion-Solutions/dougburks-patch-1
...
Update CONTRIBUTING.md with warning about more involved PRs
2022-01-24 10:39:40 -05:00
Jason Ertel
4ab7a6a079
Merge pull request #6967 from Security-Onion-Solutions/kilo
...
Copyright year and format update
2022-01-24 10:39:31 -05:00
Doug Burks
5f67dfd432
Update CONTRIBUTING.md
2022-01-24 10:36:22 -05:00
Jason Ertel
eefcc929c2
Update copyright pattern to match other repos
2022-01-24 10:09:23 -05:00
Jason Ertel
a4d2807fbb
Switch to httpcase for consistency
2022-01-24 09:45:07 -05:00
Doug Burks
fb5bff3913
Merge pull request #6956 from Security-Onion-Solutions/dougburks-patch-1
...
Fix typos in ssh_warning
2022-01-24 09:39:40 -05:00
Jason Ertel
7c22f46a55
Update copyright year for 2022
2022-01-24 09:35:29 -05:00
Doug Burks
b103420100
fix typo in so-setup
2022-01-22 10:25:37 -05:00
Doug Burks
304ef64bc8
fix another typo in ssh_warning
2022-01-22 10:24:36 -05:00
Doug Burks
1e14e2977f
Fix typo in ssh_warning
2022-01-22 10:21:14 -05:00
Josh Patterson
86cfa07af9
Merge pull request #6955 from Security-Onion-Solutions/issue/6810
...
Issue/6810
2022-01-21 17:37:59 -05:00
m0duspwnens
32080b02e4
dont use logCmd for moving repo files after centos-release update
2022-01-21 17:28:40 -05:00
m0duspwnens
58c5db3bf6
reorder process in securityonion_repo function
2022-01-21 15:15:48 -05:00
m0duspwnens
9e5fb458b4
update saltstack repo location for securityonioncache.repo / managerupdates=1
2022-01-21 14:38:42 -05:00
weslambert
f7a4cc20f2
Update so-common-template.json.jinja
2022-01-21 12:36:38 -05:00
Josh Patterson
36fc25f78e
Merge pull request #6953 from Security-Onion-Solutions/issue/6492
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 12:09:13 -05:00
m0duspwnens
e7852d7700
https://github.com/Security-Onion-Solutions/securityonion/issues/6492
2022-01-21 11:59:27 -05:00
Josh Patterson
0257d09cf8
Merge pull request #6949 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-21 08:46:54 -05:00
m0duspwnens
878c3fe6d9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-21 08:09:24 -05:00
m0duspwnens
281e5d9b25
remove salt.enable_higstate state
2022-01-21 08:09:04 -05:00
m0duspwnens
baa93301b5
enable cron at the end of soup
2022-01-20 16:53:33 -05:00
m0duspwnens
00d0eb1ce5
fix setting var
2022-01-20 16:37:33 -05:00
m0duspwnens
01cb505338
start cron and enable highstate if soup exits on error
2022-01-20 16:31:01 -05:00
William Wernert
ec023f8f7c
Merge pull request #6937 from Security-Onion-Solutions/fix/fail-preflight-early
...
Correctly handle failure to install curl in so-preflight
2022-01-20 16:03:20 -05:00
m0duspwnens
e1757926cf
start cron and reenable highstate on soup exit
2022-01-20 15:26:03 -05:00
William Wernert
357cd059aa
Use ret_code in prereq function to return failures
2022-01-20 13:53:59 -05:00
weslambert
1b860e11e7
Merge pull request #6936 from Security-Onion-Solutions/fix/field_conflicts
...
Remove dynamic keyword template to prevent field conflicts with mappi…
2022-01-20 12:48:15 -05:00
weslambert
d1efa71c57
Remove dynamic keyword template to prevent field conflicts with mappings defined in common template
2022-01-20 12:34:32 -05:00
Josh Patterson
c57b2d005e
Merge pull request #6933 from Security-Onion-Solutions/issue/6810
...
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:57:56 -05:00
m0duspwnens
9b2459d8ba
quote ES_PASS in SOCtopus.conf and remove % from random pw
2022-01-20 10:52:48 -05:00
weslambert
d0c8dd0626
Merge pull request #6931 from Security-Onion-Solutions/fix/cases_dynamic_disable
...
Disable dynamic mapping and increase order to reduce potential field …
2022-01-20 09:48:01 -05:00
weslambert
e137ad60c5
Disable dynamic mapping and increase order to reduce potential field conflicts
2022-01-20 09:44:41 -05:00
Josh Patterson
93236738de
Merge pull request #6930 from Security-Onion-Solutions/issue/6810
...
upgrade salt to 3004
2022-01-20 08:28:20 -05:00
abesinger
31d22e717d
Updated syslog pipeline, resolves #6912 . Also cleaned up formatting to make it more readable.
2022-01-19 18:45:26 -06:00
m0duspwnens
fc65f7bb84
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 15:35:28 -05:00
m0duspwnens
67e34b2402
reorder yum operations in securityonion_repo function
2022-01-19 15:35:04 -05:00
Jason Ertel
e984b0b9c4
Merge pull request #6921 from Security-Onion-Solutions/kilo
...
remove unused fields object from related case schema
2022-01-19 14:42:05 -05:00
Jason Ertel
dc44a91398
Prefix all SO fields to avoid potential conflicts with future ECS changes
2022-01-19 14:26:22 -05:00
m0duspwnens
a861801a24
more logCmd
2022-01-19 13:38:10 -05:00
m0duspwnens
fbe54b9ee8
yum clean all needs to happen before repo files are moved or the clean doesnt clean anything
2022-01-19 12:33:58 -05:00
m0duspwnens
7ebba1f325
use show_changes: False to prevent es pw from being shown when running the state
2022-01-19 12:11:38 -05:00
m0duspwnens
f8ac37c101
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-19 11:57:37 -05:00
m0duspwnens
4d078046d6
quote ES_PASS due to new characters in random string for elasticsearch:auth pw generation
2022-01-19 11:55:25 -05:00
William Wernert
13dbd0034f
Merge pull request #6924 from Security-Onion-Solutions/fix/whiptail-height
...
Fix height of node whiptail menu
2022-01-19 11:18:44 -05:00
William Wernert
c10ab712d5
Fix height of node whiptail menu
2022-01-19 11:05:34 -05:00
Jason Ertel
d7ba1cedff
remove unused fields object from related case schema
2022-01-19 08:39:21 -05:00
m0duspwnens
55a262646c
use logCmd
2022-01-19 08:34:54 -05:00
William Wernert
a3925d231c
Merge pull request #6909 from Security-Onion-Solutions/fix/preflight-curl
...
Install curl in preflight script to avoid error on Ubuntu
2022-01-18 13:39:44 -05:00
William Wernert
c0c42c3574
Install curl in preflight script to avoid error on Ubuntu
...
Also add check for already installed curl later in setup
2022-01-18 13:17:56 -05:00
m0duspwnens
f006d1a22c
logCmd commands in securityonion_repo function
2022-01-18 12:34:23 -05:00
m0duspwnens
a2ed9a86ff
remove influixdb salt state files and update patch files for influxdb salt modules/state
2022-01-18 11:33:36 -05:00
Josh Brower
19ccd5f8e9
Merge pull request #6904 from Security-Onion-Solutions/fix/fleetdm-disable-vuln-feature
...
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:48:06 -05:00
Josh Brower
c4babf22d6
FleetDM - Disable Vuln Proc Feature
2022-01-18 10:38:55 -05:00
Mike Reeves
7eb564db14
Merge pull request #6901 from Security-Onion-Solutions/elasticupdate
...
Elastic 7.16.3
2022-01-18 09:47:36 -05:00
Mike Reeves
2e4e59bbe8
Elastic 7.16.3
2022-01-18 09:42:06 -05:00
m0duspwnens
87999453f2
Merge remote-tracking branch 'remotes/origin/dev' into issue/6810
2022-01-18 09:13:10 -05:00
m0duspwnens
3bd26f05d4
account for salt 3004 adding new chars to random.get_str
2022-01-14 18:02:18 -05:00
m0duspwnens
a46a740170
account for salt 3004 adding new chars to random.get_str
2022-01-14 17:23:29 -05:00
Mike Reeves
71da74fd00
Merge pull request #6878 from Security-Onion-Solutions/fix/scan_pe_sections_entropy
...
Fix/scan pe sections entropy
2022-01-14 17:02:32 -05:00
weslambert
c512351dd6
Add mapping for scan.exiftool and scan.pe.sections.entropy
2022-01-14 17:01:13 -05:00
weslambert
a90bc9dba9
Add mapping for scan.pe.sections.entropy
2022-01-14 16:58:53 -05:00
m0duspwnens
02ce5c3236
update install salt to 3004
2022-01-14 13:47:16 -05:00
m0duspwnens
b6b2e06fbc
change module to cmd for onchanges_in
2022-01-14 12:44:58 -05:00
m0duspwnens
f5fe466410
repo update
2022-01-14 12:02:35 -05:00
Jason Ertel
a63787daba
Merge pull request #6864 from Security-Onion-Solutions/kilo
...
Add default queries for cases to show user's assigned cases
2022-01-13 17:15:02 -05:00
Jason Ertel
6b0b7245f0
Add default queries for cases to show user's assigned cases
2022-01-13 17:10:08 -05:00
m0duspwnens
bda9221d6f
upgrade salt to 3004 and update bootstrap-salt.sh
2022-01-13 13:26:11 -05:00
Josh Patterson
b2434faf10
Merge pull request #6862 from Security-Onion-Solutions/issue/6811
...
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:06:43 -05:00
m0duspwnens
82db3fa3c0
restart wazuh with docker restart vs so-wazuh-restart
2022-01-13 13:02:01 -05:00
Josh Patterson
78bb6e4176
Merge pull request #6856 from Security-Onion-Solutions/issue/6811
...
Issue/6811
2022-01-13 11:03:51 -05:00
m0duspwnens
06c0cebb26
merge with dev
2022-01-13 09:44:26 -05:00
m0duspwnens
389ff1a46d
create enable_highstate state to reenable highstate following minion restart if it was previously disabled. same with cron
2022-01-13 09:39:46 -05:00
m0duspwnens
a28bb23d20
fix os_family for cron state map
2022-01-12 17:27:47 -05:00
m0duspwnens
443dc6ebaa
move branch echo to main so it is in the log
2022-01-12 16:14:49 -05:00
m0duspwnens
03b9b74ace
stop cron before soup upgrades the manager, start cron at the end. add cron state that is in included in common
2022-01-12 16:04:10 -05:00
Mike Reeves
e123dd4bb2
Merge pull request #6844 from Security-Onion-Solutions/highlanderml
...
Add additional highlander settings
2022-01-12 13:34:22 -05:00
Josh Patterson
5889ce02cd
Merge pull request #6845 from Security-Onion-Solutions/23100soup_jpp
...
remove mine push from 2.3.100 function
2022-01-12 13:34:06 -05:00
Josh Patterson
776e4c6e12
Update soup
2022-01-12 13:32:46 -05:00
Josh Patterson
035984569b
Merge branch 'dev' into 23100soup_jpp
2022-01-12 13:31:46 -05:00
Josh Patterson
da30f66096
remove mine push from 2.3.100 function
2022-01-12 13:29:34 -05:00
Mike Reeves
c525bf310d
Add additional highlander settings
2022-01-12 13:19:40 -05:00
Mike Reeves
ee44edfe75
Add additional highlander settings
2022-01-12 13:18:44 -05:00
m0duspwnens
0cf877f169
kill any possible queued salt jobs before stopping salt-master
2022-01-12 12:27:19 -05:00
Mike Reeves
f836d3ad16
Merge pull request #6843 from Security-Onion-Solutions/23100soup_jpp
...
push ips of mainint to salt mine
2022-01-12 12:25:51 -05:00
Josh Patterson
5b347600e9
push ips of mainint to salt mine
2022-01-12 12:24:52 -05:00
m0duspwnens
0388912ba7
kill all salt jobs across grid before stopping salt-master. kill all salt jobs on manager before stopping salt-minion.
2022-01-12 11:05:47 -05:00
m0duspwnens
494737549d
move some es script to src elasticsearch/tools/sbin and dst /usr/sbin. set requires
2022-01-12 10:20:05 -05:00
Mike Reeves
22096174bb
Merge pull request #6841 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix some formatting
2022-01-12 09:39:15 -05:00
Mike Reeves
1d94e3ac69
Fix some formatting
2022-01-12 09:38:22 -05:00
m0duspwnens
abf3a9401b
listen instead to not start service if not running then restart if changes to files
2022-01-11 18:31:35 -05:00
m0duspwnens
ae0f392035
wait for salt-master and salt-minin to exit. disable highstate before stopping salt-minion. apply salt-minion state before first highstate to update configs
2022-01-11 16:57:29 -05:00
Mike Reeves
53d2e20e48
Merge pull request #6834 from Security-Onion-Solutions/nohive
...
Remove hive install option
2022-01-11 16:50:18 -05:00
Mike Reeves
4ff5fc3b38
Remove hive install option
2022-01-11 14:38:38 -05:00
m0duspwnens
5ade8193f0
move highstate messages for more accurate final highstate message
2022-01-11 13:41:51 -05:00
m0duspwnens
0ef130bd38
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:12:07 -05:00
m0duspwnens
e33a9eb45c
bootstrap.sh, dont start salt services after salt upgrade, allow soup to do it
2022-01-11 13:11:25 -05:00
m0duspwnens
9d19cba600
log time when salt services stopped and started
2022-01-11 13:09:05 -05:00
m0duspwnens
baf297ab0a
merge with dev, resolve conflict
2022-01-11 11:24:10 -05:00
m0duspwnens
14eed8e5b9
redirect to setup_log
2022-01-11 11:20:30 -05:00
Josh Brower
5083be4ce7
Merge pull request #6816 from Security-Onion-Solutions/fix/wazuh-parsing-v2
...
Fix Wazuh WEL Parsing
2022-01-11 11:17:24 -05:00
Doug Burks
a3c8335130
Merge pull request #6827 from Security-Onion-Solutions/dougburks-patch-1
...
Remove unnecessary word
2022-01-11 11:06:40 -05:00
Doug Burks
29d8dbe371
Remove unnecessary word
2022-01-11 11:05:30 -05:00
m0duspwnens
91ef9b9366
update salt mine before salt-master and salt-minion get stopped
2022-01-11 10:57:48 -05:00
m0duspwnens
328d6cdeb4
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 10:02:18 -05:00
Mike Reeves
a9e58e2aba
Merge pull request #6826 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2022-01-11 10:01:49 -05:00
Mike Reeves
8ad36fc7b9
Update init.sls
2022-01-11 10:01:14 -05:00
m0duspwnens
87756cdbc9
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:57:31 -05:00
Mike Reeves
7937487ee9
Merge pull request #6825 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update init.sls
2022-01-11 09:57:10 -05:00
Mike Reeves
770a389410
Update init.sls
2022-01-11 09:56:22 -05:00
m0duspwnens
b5c274de10
Merge remote-tracking branch 'remotes/origin/dev' into issue/6811
2022-01-11 09:48:31 -05:00
m0duspwnens
a8d1b9eb90
restart salt-minion at end of run if mine_functions changes
2022-01-11 09:29:12 -05:00
m0duspwnens
86c8fc6c1c
need to update mine after salt-master starts
2022-01-11 08:56:38 -05:00
weslambert
17509a9231
Merge pull request #6822 from Security-Onion-Solutions/fix/event_fields
...
Add event.acknowledged and event.escalated mappings
2022-01-10 16:14:45 -05:00
weslambert
84f7c6b13b
Add event.acknowledged and event.escalated mappings
2022-01-10 16:08:35 -05:00
m0duspwnens
716c98ec61
requires and ordering for socusersroles state
2022-01-10 14:39:00 -05:00
Josh Brower
56aa24d874
Fix Wazuh WEL Parsing
2022-01-10 13:55:38 -05:00
Mike Reeves
b7a90a88f9
Merge pull request #6815 from Security-Onion-Solutions/esbackup
...
Add ability to specify local backup dir
2022-01-10 13:31:24 -05:00
weslambert
1dc363138a
Merge pull request #6814 from Security-Onion-Solutions/fix/template_typo
...
Fix typo -- replace period with comma
2022-01-10 13:30:13 -05:00
weslambert
1c3eeb5a34
Fix typo -- replace period with comma
2022-01-10 13:29:06 -05:00
m0duspwnens
beb9a33628
only include curl.config if elasticsearch:auth is enabled
2022-01-10 11:48:16 -05:00
Mike Reeves
dbba7d7226
Add ability to specify local backup dir
2022-01-10 11:31:41 -05:00
m0duspwnens
291ac7d361
https://github.com/Security-Onion-Solutions/securityonion/issues/6811
2022-01-10 10:36:42 -05:00
Josh Patterson
43eda0c5a3
Merge pull request #6796 from Security-Onion-Solutions/fix/wazuh_register_agent
...
dont try to register if state file exists
2022-01-07 16:07:56 -05:00
m0duspwnens
715d3f0e7e
dont try to register if state file exists
2022-01-07 16:05:55 -05:00
Jason Ertel
db04646735
Merge pull request #6794 from Security-Onion-Solutions/kilo
...
Update field mappings based on Wes' feedback
2022-01-07 16:03:05 -05:00
Jason Ertel
66c9e20c6a
Add wilcards for CCS compatibility
2022-01-07 15:57:08 -05:00
Josh Patterson
ed97fe0b65
Merge pull request #6795 from Security-Onion-Solutions/fix/wazuh_register_agent
...
Fix/wazuh register agent
2022-01-07 15:52:17 -05:00
m0duspwnens
3a86af8de2
quote $API_RESULT
2022-01-07 15:49:53 -05:00
m0duspwnens
7ee913eb1f
if /opt/so/conf/wazuh/initial_agent_registration.log doesnt exist, and agent is already registered, touch file and exit 0 to prevent salt error
2022-01-07 15:46:47 -05:00
Jason Ertel
d3656a7777
Merge branch 'dev' into kilo
2022-01-07 13:41:35 -05:00
Josh Patterson
3c44f6fd41
Merge pull request #6793 from Security-Onion-Solutions/23100soup_jpp
...
23100soup
2022-01-07 13:32:33 -05:00
Jason Ertel
391db568b0
Update field mappings based on Wes' feedback
2022-01-07 13:28:36 -05:00
Jason Ertel
a4f01d4412
Merge pull request #6792 from Security-Onion-Solutions/kilo
...
Add case exclusion toggle to Hunt to avoid hunt results getting case …
2022-01-07 13:02:27 -05:00
Jason Ertel
9ef83da23f
Add case exclusion toggle to Hunt to avoid hunt results getting case data hits unintentionally
2022-01-07 12:58:35 -05:00
m0duspwnens
871fd115ae
put so-firewalll in /usr/sbin since salt-master isnt running at this time
2022-01-07 12:04:19 -05:00
weslambert
218f7f3a13
Merge pull request #6790 from Security-Onion-Solutions/fix/dtc_severity_label
...
Add event.severity_label
2022-01-07 11:44:30 -05:00
weslambert
770e53d914
Add keyword subfield for event.severity_label
2022-01-07 11:21:57 -05:00
weslambert
c69e1353d9
Add event.severity_label
2022-01-07 11:19:54 -05:00
m0duspwnens
fd0e5d7d29
make sure so-firewall is up to date
2022-01-07 11:10:48 -05:00
Josh Brower
ae6aa0dafd
Merge pull request #6789 from Security-Onion-Solutions/fix/wazuh-parsing-revert
...
Revert Wazuh parser update
2022-01-07 10:53:53 -05:00
Josh Brower
5d4ea2ba3a
Revert Wazuh parser update
2022-01-07 10:51:24 -05:00
weslambert
a7e7566532
Merge pull request #6780 from Security-Onion-Solutions/feature/datatype_compliance
...
Initial commit for data type compliance
2022-01-06 16:38:17 -05:00
m0duspwnens
5ecb63f5cf
prevent exit if minion doesnt respond
2022-01-06 16:17:51 -05:00
Josh Brower
ca4aaae47c
Merge pull request #6778 from Security-Onion-Solutions/fix/wazuh-parsing
...
Uppercase first char in Wazuh WEL
2022-01-06 16:01:09 -05:00
Josh Brower
277c7f1ef8
Uppercase first char in Wazuh WEL
2022-01-06 14:58:50 -05:00
m0duspwnens
cd590b894a
check that ossec.conf exists
2022-01-06 12:39:48 -05:00
weslambert
3f02003ea2
Merge pull request #6777 from Security-Onion-Solutions/fix/deprecation_ecs_compatibility_logstash
...
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:31:51 -05:00
weslambert
8e2f500b9c
Add config option for ECS compatibility (default of disabled)
2022-01-06 11:24:04 -05:00
weslambert
099e3e1ceb
Merge pull request #6775 from Security-Onion-Solutions/fix/deprecation_warning_suppress
...
Add logger stanza to suppress ES deprecation warning messages
2022-01-06 10:45:37 -05:00
weslambert
900d12b556
Add logger stanza to suppress deprecation warning messages for now due to current system index access warning messages flooding the ES log
2022-01-06 10:35:50 -05:00
Jason Ertel
8cf7ea8b87
Merge pull request #6772 from Security-Onion-Solutions/kilo
...
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 19:15:02 -05:00
Josh Patterson
eaa6597cd7
Merge pull request #6773 from Security-Onion-Solutions/issue/6765
...
Issue/6765
2022-01-05 18:11:06 -05:00
m0duspwnens
6338ba2e45
remove /var/cache/salt/ for reinstall
2022-01-05 16:54:56 -05:00
m0duspwnens
8af74e8bb3
remove more salt configs for reinstall
2022-01-05 16:53:54 -05:00
m0duspwnens
9357995bfa
remove root cron and restore yeselastic.txt
2022-01-05 16:04:32 -05:00
weslambert
2fb488f768
Merge pull request #6769 from Security-Onion-Solutions/fix/id_fielddata_deprecation
...
Fix issue with _id field fielddata/deprecation
2022-01-05 15:40:25 -05:00
Wes Lambert
1cafacfa51
Update saved objects to reflect removal of TheHive scripted field and replacement of PCAP pivot with Hunt pivot
2022-01-05 20:36:23 +00:00
weslambert
c1a88977cf
Disable fielddata for _id field by default (since it is deprecated and can be memory-intensive)
2022-01-05 15:23:52 -05:00
m0duspwnens
0ff5e3cf6f
require so-elasticsearch container to be running to run the scripts
2022-01-05 14:48:41 -05:00
m0duspwnens
8950f94fb0
restore state files so python3-influxdb state doesnt try to patch during a restinstall
2022-01-05 12:02:53 -05:00
Wes Lambert
b60837e71a
Initial commit for data type compliance
2022-01-05 16:38:56 +00:00
Jason Ertel
4f8524e0ac
Prevent PCAP action from showing up outside of hunt/alerts
2022-01-05 11:13:12 -05:00
weslambert
2f9672d3ea
Merge pull request #6764 from Security-Onion-Solutions/feature/soup_branch
...
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:54:29 -05:00
weslambert
db43e21378
Fix indentation
2022-01-05 10:46:41 -05:00
weslambert
4d8b417fc9
Denote which branch is being used in SOUP if BRANCH is specified
2022-01-05 10:41:27 -05:00
Jason Ertel
89415b12ce
Merge pull request #6762 from Security-Onion-Solutions/kilo
...
Switch soc.json to use lowercase labels in default queries; Also enab…
2022-01-05 09:59:39 -05:00
Jason Ertel
4bfdfffe21
Switch soc.json to use lowercase labels in default queries; Also enable the 'Add Case' feature
2022-01-05 09:54:13 -05:00
Mike Reeves
1adc4c5346
Merge pull request #6752 from Security-Onion-Solutions/ubufix
...
Fix docker holds so re-install will work properly
2022-01-04 18:56:06 -05:00
Mike Reeves
3ca0ce9eea
Update so-functions
2022-01-04 18:47:35 -05:00
Mike Reeves
e869013057
Remove docker the reinstall it
2022-01-04 15:24:10 -05:00
Mike Reeves
dd104c9490
Add holds for ubuntu
2022-01-04 13:07:09 -05:00
m0duspwnens
7bb9b6efa9
populate mine with network.ip_addrs pillar.host.mainint for each host prior to highstate
2022-01-04 10:27:45 -05:00
Mike Reeves
288389c93e
Soup changes for 2.3.100
2022-01-04 08:38:14 -05:00
Josh Patterson
4247a3a816
Merge pull request #6730 from Security-Onion-Solutions/fix/ub1804ssl
...
more detailed logging for the retry command
2021-12-30 13:19:58 -05:00
m0duspwnens
cc2f6e23ca
more detailed logging for the retry command
2021-12-30 13:09:29 -05:00
Josh Patterson
064355dfb5
Merge pull request #6729 from Security-Onion-Solutions/fix/ub1804ssl
...
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 11:38:32 -05:00
m0duspwnens
d274615376
change exitCode to exitcode. set exitcode to 1 if failed output found
2021-12-30 10:45:30 -05:00
Josh Patterson
78eda75c0f
Merge pull request #6725 from Security-Onion-Solutions/fix/ub1804ssl
...
add option to look for failed outout in retry function in so-common. …
2021-12-29 18:18:12 -05:00
m0duspwnens
200736a118
add option to look for failed outout in retry function in so-common. look for Err: when running soapt-get update in setup
2021-12-29 18:15:16 -05:00
Jason Ertel
1d136b611a
Merge pull request #6723 from Security-Onion-Solutions/kilo
...
Uniform presets
2021-12-29 16:49:41 -05:00
Jason Ertel
e6051cb653
Switch all presets to lowercase for uniformity
2021-12-29 16:42:34 -05:00
Jason Ertel
74dbc4bf67
Merge pull request #6720 from Security-Onion-Solutions/kilo
...
Add case template to eval install types; also improve clarity of case queries
2021-12-29 11:41:06 -05:00
Josh Patterson
a2f1f52450
Merge pull request #6719 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-29 11:39:10 -05:00
Jason Ertel
1d885a5419
Add case template to eval installs
2021-12-29 11:38:38 -05:00
m0duspwnens
b414e22e95
remove spaces in function
2021-12-29 11:37:22 -05:00
m0duspwnens
4c54d45681
some echos for logging
2021-12-29 11:36:12 -05:00
m0duspwnens
c6e9b00488
Merge remote-tracking branch 'remotes/origin/dev' into fix/ub1804ssl
2021-12-29 11:22:25 -05:00
m0duspwnens
b027da6378
wait for the salt-minion service to be ready for requests prior to running ssl state
2021-12-29 11:18:38 -05:00
Jason Ertel
fb02d0d35c
clarify case filters
2021-12-29 11:07:36 -05:00
Jason Ertel
d4f3615cae
Merge pull request #6717 from Security-Onion-Solutions/kilo
...
Support CCS in CM
2021-12-29 09:12:13 -05:00
Jason Ertel
e5110ac4e8
Use CCS compatible index
2021-12-29 09:08:10 -05:00
Jason Ertel
e87cbc37a4
Add case template
2021-12-28 19:17:15 -05:00
Josh Patterson
3b130ab202
Merge pull request #6712 from Security-Onion-Solutions/fix/ub1804ssl
...
all run ssl state during setup
2021-12-28 16:34:58 -05:00
m0duspwnens
22afe99719
all run ssl state during setup
2021-12-28 16:24:17 -05:00
Doug Burks
e56a9a5f22
Merge pull request #6711 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-analyst-install
2021-12-28 15:24:19 -05:00
Josh Patterson
7655920068
Merge pull request #6710 from Security-Onion-Solutions/fix/ub1804ssl
...
add mine function to signing_policies.conf
2021-12-28 15:23:36 -05:00
Doug Burks
463925686d
fix typo in so-analyst-install
2021-12-28 15:23:17 -05:00
m0duspwnens
2a5b4ef276
add mine function to signing_policies.conf. no longer need to check if mine in ca during manager install
2021-12-28 15:19:06 -05:00
Josh Patterson
7029c3a94a
Merge pull request #6707 from Security-Onion-Solutions/fix/ub1804ssl
...
put x509 signing policies in place when minion is configured
2021-12-28 12:05:20 -05:00
m0duspwnens
67a9f4d22e
put x509 signing policies in place when minion is configured
2021-12-28 12:03:10 -05:00
Josh Patterson
a5746d4919
Merge pull request #6706 from Security-Onion-Solutions/fix/ub1804ssl
...
Fix/ub1804ssl
2021-12-28 11:27:15 -05:00
m0duspwnens
487ac24306
revert back to getting ca from mine
2021-12-28 11:16:01 -05:00
m0duspwnens
2405de4b82
fix require
2021-12-28 11:00:35 -05:00
m0duspwnens
9e3c289562
remove restarting salt in ssl generation. sperate ca and ssl generation into seperate functions
2021-12-28 10:43:45 -05:00
m0duspwnens
f2adcf4ca5
ensure /etc/pki is created and simplify ca logic for non manager in ssl state
2021-12-28 10:41:57 -05:00
Jason Ertel
0072ae253b
Merge pull request #6705 from Security-Onion-Solutions/kilo
...
Initial CM Impl; Improve so-user script
2021-12-28 08:36:59 -05:00
Jason Ertel
5a4473ecd6
fix indent
2021-12-28 08:33:31 -05:00
Jason Ertel
f335670b3f
Add new client-side param for cases
2021-12-27 21:53:30 -05:00
Jason Ertel
194e4119f0
Correct missing json vars
2021-12-27 20:36:28 -05:00
Jason Ertel
09626deb05
Correct var names for jinja
2021-12-27 18:01:15 -05:00
Jason Ertel
ae7a4b6528
More syntax corrections
2021-12-27 16:18:12 -05:00
Jason Ertel
0a255e5765
Resolve syntax error
2021-12-27 15:15:33 -05:00
Jason Ertel
789719d25e
Correct preset file syntax
2021-12-27 13:21:13 -05:00
Jason Ertel
7140255d95
Add missing presets file
2021-12-27 12:27:04 -05:00
Jason Ertel
ab3319b472
Add artifact support
2021-12-27 10:49:10 -05:00
Jason Ertel
b0d36f2ed2
Ensure update timestamp is updated when changing passwords; this ensures the sync will automatically follow
2021-12-21 13:38:35 -05:00
Jason Ertel
62e5914ab8
Merge branch 'dev' into kilo
2021-12-21 13:37:37 -05:00
Jason Ertel
2f88f08be2
Merge pull request #6649 from Security-Onion-Solutions/2.3.91-merge
...
2.3.91 merge
2021-12-21 09:39:14 -05:00
Jason Ertel
9aeaa1fccc
resolved merge conflicts
2021-12-21 09:35:57 -05:00
Jason Ertel
2c9062efb7
resolved merge conflicts
2021-12-21 09:34:39 -05:00
Doug Burks
c8de36d467
Merge pull request #6646 from Security-Onion-Solutions/patch/2.3.91
...
Patch/2.3.91
2021-12-21 09:27:14 -05:00
doug
284e0e9108
fix hashes in VERIFY_ISO.md
2021-12-20 17:27:19 -05:00
doug
e66b023c9c
update README.md for 2.3.91
2021-12-20 17:23:52 -05:00
doug
9f47522591
add sig for 2.3.91 ISO and update VERIFY_ISO.md
2021-12-20 17:21:53 -05:00
Jason Ertel
35617acaeb
Update cacerts to reflect new path; this changed due to ES 7.16.2
2021-12-20 12:12:00 -05:00
Jason Ertel
6f116a2d01
Switch to new Ubuntu SSL dir
2021-12-20 09:43:59 -05:00
Jason Ertel
d6c651af1c
Remove old patch dir from previously-patched installations
2021-12-20 09:42:27 -05:00
Jason Ertel
203e8a7873
Bump version to 2.3.91
2021-12-20 09:33:20 -05:00
Jason Ertel
b8fcec04b8
Remove patched jar due to upgrade of Elastic images to 7.16.2
2021-12-20 09:27:03 -05:00
Jason Ertel
6556a37869
Merge branch 'master' into patch/1.3.91
2021-12-20 09:20:03 -05:00
Jason Ertel
5af2bd8fa4
Upgrade to Elastic 7.16.2
2021-12-20 09:16:28 -05:00
Josh Patterson
d33cf19e3d
Merge pull request #6612 from Security-Onion-Solutions/issue/6469
...
add managersearch to list
2021-12-16 13:57:53 -05:00
m0duspwnens
a46a876ec6
add managersearch to list
2021-12-16 13:48:41 -05:00
Josh Brower
affe5b9ac0
Merge pull request #6605 from Security-Onion-Solutions/fix/fleet-ips
...
Fix cidr for fleet custom docker range
2021-12-16 11:55:11 -05:00
Josh Patterson
e0c8e03882
Merge pull request #6604 from Security-Onion-Solutions/issue/6469
...
https://github.com/Security-Onion-Solutions/securityonion/issues/6469
2021-12-16 11:54:05 -05:00
Josh Brower
a23824e199
Fix cidr for fleet custom docker range
2021-12-16 11:53:26 -05:00
m0duspwnens
ae342ab673
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-16 11:33:09 -05:00
m0duspwnens
b4b8b91ccd
simplify ip logic wazuh-register-agent, mine_interval to 35 minutes
2021-12-16 11:24:35 -05:00
m0duspwnens
2e4ed8062e
simplify wazuh agent ip logic
2021-12-16 11:11:01 -05:00
m0duspwnens
bd7ef1cc59
fix whitespace control
2021-12-16 09:19:20 -05:00
Jason Ertel
8ec671422f
Merge pull request #6593 from Security-Onion-Solutions/esup
...
Finish upgrade of ES to 7.16.1
2021-12-16 07:59:34 -05:00
Jason Ertel
1268f8f92b
Upgrade ES to 7.16.1
2021-12-16 07:57:42 -05:00
Jason Ertel
d4f395b7f4
Fix query name for open cases
2021-12-15 20:02:35 -05:00
Jason Ertel
c68efd56c2
Merge branch 'dev' into kilo
2021-12-15 20:01:55 -05:00
m0duspwnens
a7600f7f43
update scripts to use their own ip
2021-12-15 17:31:39 -05:00
Mike Reeves
0f76227631
Merge pull request #6585 from Security-Onion-Solutions/unhotfix
...
Unhotfix
2021-12-15 17:23:02 -05:00
m0duspwnens
d0b0970353
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-15 17:08:56 -05:00
Mike Reeves
465ba1b7d3
Change CA certs location
2021-12-15 17:08:36 -05:00
m0duspwnens
f9b04ab96a
add node's own ip to FILEBEAT_EXTRA_HOSTS
2021-12-15 16:53:22 -05:00
m0duspwnens
522bc1d2b8
fix loadbalance logic and whitespace for filebeat.yml
2021-12-15 16:21:08 -05:00
m0duspwnens
cf2f4bad09
have standalone and managersearch pull from redis nodes
2021-12-15 15:27:23 -05:00
Mike Reeves
61955b7928
Change CA certs location
2021-12-15 13:50:19 -05:00
Jason Ertel
ffa8ca57a7
Merge pull request #6579 from Security-Onion-Solutions/unhotfix
...
Remove some previous hotfix code
2021-12-15 12:34:00 -05:00
Mike Reeves
7cd1b1c482
Remove some previous hotfix code
2021-12-15 12:26:53 -05:00
m0duspwnens
6ab2bdef0c
add sensoroni state to receiver node
2021-12-15 10:45:54 -05:00
m0duspwnens
ce0a39db4b
remove old EXTRAHOSTNAME EXTRAHOSTIP from being set for logstash
2021-12-15 09:43:46 -05:00
m0duspwnens
ea89d2074b
remove ca from allowed_hosts on so-receiver
2021-12-15 09:32:12 -05:00
m0duspwnens
759bf9837e
pillar top clean up for receiver and logstash.nodes
2021-12-15 09:31:03 -05:00
m0duspwnens
d9a384cc29
remove global:pipeline pillar call from logstash pipeline pillars
2021-12-15 09:30:15 -05:00
m0duspwnens
176ef852c8
clean up assinged hostgroups for receiver
2021-12-15 08:28:40 -05:00
Doug Burks
09f0bdba91
Merge pull request #6574 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in so-image-common
2021-12-15 07:45:24 -05:00
Doug Burks
7d1f9c51e8
fix typo in so-image-common
2021-12-15 07:24:30 -05:00
m0duspwnens
024860d0ae
rename EXTRA_NODES to LOGSTASH_NODES AND REDIS_NODES
2021-12-14 23:43:06 -05:00
m0duspwnens
0c6aba16ec
fix redis input
2021-12-14 23:42:37 -05:00
m0duspwnens
15b8d80b71
fix host for input_redis
2021-12-14 18:51:43 -05:00
m0duspwnens
55b74abcc5
extra_hosts and redis_input for logstash
2021-12-14 18:49:30 -05:00
m0duspwnens
4da017d61c
change extra_hosts for docker container
2021-12-14 17:05:30 -05:00
m0duspwnens
a31d61e151
handle ca for redis
2021-12-14 16:43:04 -05:00
m0duspwnens
841b91e052
exclude elasticsearch and managerssl keys and certs from receiver
2021-12-14 16:05:47 -05:00
m0duspwnens
d0b6d5bba6
remove so-eval from lists since it doesnt run logstash
2021-12-14 15:33:06 -05:00
m0duspwnens
a31f034f2e
remove receiver add node for cacerts and tls-ca-bundle for logstash bind
2021-12-14 15:02:59 -05:00
m0duspwnens
6962e3f9b3
fix logstash certs mapped into container
2021-12-14 14:52:15 -05:00
m0duspwnens
c490a3be36
move node_data pillar to logstash:nodes, set extra hosts for filebeat docker
2021-12-14 13:32:42 -05:00
Mike Reeves
5006e34208
Merge pull request #6560 from Security-Onion-Solutions/mergerz
...
Merge latest hotfix
2021-12-14 10:57:49 -05:00
Mike Reeves
30344ba0ef
Fix conflicts
2021-12-14 10:55:19 -05:00
m0duspwnens
6518691c55
sort the items
2021-12-13 18:16:25 -05:00
m0duspwnens
067e79894f
fix loop for node_data
2021-12-13 16:26:38 -05:00
m0duspwnens
6de2f5bd03
fix node_data
2021-12-13 15:55:09 -05:00
m0duspwnens
8d0872bce5
create node_data pillar from mine data, use node_data pillar for filebeat config
2021-12-13 15:48:30 -05:00
m0duspwnens
86f67198bf
loadbalance filebeat if across managers and receivers
2021-12-10 17:43:06 -05:00
m0duspwnens
fe7247f876
update fw for receiver and add mine_functions for ip_addr
2021-12-10 15:28:40 -05:00
m0duspwnens
54c32acdbf
dont call logstash_pillar if manager or helix
2021-12-09 15:26:00 -05:00
Jason Ertel
83d86aebb1
Perform full email match
2021-12-09 15:04:00 -05:00
m0duspwnens
d94496bb90
remove minio_key and add missing endif
2021-12-09 13:24:20 -05:00
m0duspwnens
c2a952796c
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:13:18 -05:00
Mike Reeves
b92cbb01b3
SSL modifications
2021-12-09 13:13:01 -05:00
m0duspwnens
5b70d5510f
Merge remote-tracking branch 'remotes/origin/sans' into issue/6469
2021-12-09 13:12:00 -05:00
Jason Ertel
2761662eb9
Add status presets
2021-12-09 13:09:56 -05:00
Mike Reeves
a7f0d81555
SSL modifications
2021-12-09 13:07:00 -05:00
Josh Brower
d3bbae23ca
Merge pull request #6499 from Security-Onion-Solutions/fix/beats-logstash
...
Use id for doc id if it exists
2021-12-09 09:47:14 -05:00
Josh Brower
656ea974dc
Use id for doc id if it exists
2021-12-09 09:16:58 -05:00
Jason Ertel
a9b7b9ee92
Jinjafy case params
2021-12-08 17:41:48 -05:00
m0duspwnens
7390b03dc1
dont show es options in final whiptail setup confirmation
2021-12-08 14:58:34 -05:00
m0duspwnens
b4bc32d3ca
set logstash pillar and enable avanced ls menu for so-receiver
2021-12-08 14:33:15 -05:00
m0duspwnens
ecc8594d44
prevent so-receiver from getting extra keys/certs
2021-12-08 13:32:56 -05:00
m0duspwnens
59464af10c
filebeat certs for logstash on so-receiver
2021-12-08 09:41:17 -05:00
m0duspwnens
1ef63f3a23
ssl things for so-receiver
2021-12-08 09:08:46 -05:00
m0duspwnens
c80059efb0
change from || to &&
2021-12-07 17:11:15 -05:00
m0duspwnens
8c95d0f36b
set ip for wazuh-register-agent and dont apply nginx in setup for receiver
2021-12-07 16:50:41 -05:00
m0duspwnens
429b9cab2f
set ip for ossec.conf
2021-12-07 16:22:07 -05:00
m0duspwnens
f8da5c7fe9
start of fw rules for receiver
2021-12-07 15:59:11 -05:00
m0duspwnens
06010bd157
add so-receiver to allowed_states
2021-12-07 13:34:06 -05:00
Jason Ertel
b73eb76c94
Make case module dynamic
2021-12-07 11:51:02 -05:00
m0duspwnens
f3ec5df447
add receiver node
2021-12-07 11:13:51 -05:00
m0duspwnens
7549e34881
Merge remote-tracking branch 'remotes/origin/dev' into issue/6469
2021-12-07 10:57:12 -05:00
m0duspwnens
ba30c59ec7
add receiver node
2021-12-07 10:56:35 -05:00
Mike Reeves
892899b7f9
Merge pull request #6477 from Security-Onion-Solutions/merge-202112071526
...
Merge hotfix
2021-12-07 10:30:13 -05:00
Jason Ertel
702d95c63a
Merge branch 'master' into merge-202112071527
2021-12-07 10:28:00 -05:00
m0duspwnens
96666ab307
add receiver node
2021-12-07 10:19:32 -05:00
Jason Ertel
83fab42b6e
Merge pull request #6433 from Security-Onion-Solutions/kilo
...
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:39:14 -05:00
Jason Ertel
e549cfdf82
Reign in the Wazuh port check to only complain if a non-Docker process is listening on 55000.
2021-12-02 09:35:13 -05:00
Josh Brower
c7a9fb1fa3
Merge pull request #6432 from Security-Onion-Solutions/fix/fleet-nginx
...
Fix FleetDM nginx errors
2021-12-02 08:30:28 -05:00
Josh Brower
97cd679d74
Fix FleetDM nginx errors
2021-12-02 08:17:01 -05:00
William Wernert
3bd8bcba12
Merge pull request #6421 from Security-Onion-Solutions/hotfix-merge
...
Hotfix merge
2021-12-01 14:49:05 -05:00
William Wernert
6e7188b4d8
Merge branch 'hotfix/2.3.90' into hotfix-merge
...
# Conflicts:
# HOTFIX
2021-12-01 14:40:34 -05:00
Mike Reeves
84b91c547d
Merge pull request #6403 from Security-Onion-Solutions/dlee35-patch-1
...
add subjectAltName to filebeat.crt
2021-12-01 11:54:05 -05:00
Dustin Lee
8a394380cb
add subjectAltName to filebeat.crt
...
IP SAN is required for Endgame integration w/Logstash when DNS resolution is unavailable
2021-11-30 16:24:08 -05:00
Jason Ertel
1272de3058
Merge pull request #6378 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
bump version to 2.3.100
2021-11-29 09:57:29 -05:00
Mike Reeves
2beb69f495
Update HOTFIX
2021-11-29 09:55:32 -05:00
Mike Reeves
5a447c53d9
bump version to 2.3.100
2021-11-29 09:55:01 -05:00
Jason Ertel
31ffd6c4ec
Merge pull request #6339 from Security-Onion-Solutions/kilo
...
Merge 2.3.90 WAZUH hotfix into dev
2021-11-23 19:33:18 -05:00