m0duspwnens
d91dd0dd3c
watch some values
2024-04-29 17:14:00 -04:00
m0duspwnens
a0388fd568
engines config for valueWatch
2024-04-29 14:02:10 -04:00
m0duspwnens
05244cfd75
watch files change engine
2024-04-24 13:19:39 -04:00
m0duspwnens
6c5e0579cf
logging changes. ensure salt master has pillarWatch engine
2024-04-19 09:32:32 -04:00
m0duspwnens
1f6eb9cdc3
match keys better. go through files reverse first found is prio
2024-04-18 13:50:37 -04:00
m0duspwnens
610dd2c08d
improve it
2024-04-18 11:11:14 -04:00
m0duspwnens
506bbd314d
more comments, better logging
2024-04-18 10:26:10 -04:00
m0duspwnens
4caa6a10b5
watch a pillar in files and take action
2024-04-17 18:09:04 -04:00
m0duspwnens
4b79623ce3
watch pillar files for changes and do something
2024-04-16 16:51:35 -04:00
m0duspwnens
c4994a208b
restart salt minion if a manager and signing policies change
2024-04-15 11:37:21 -04:00
m0duspwnens
bb983d4ba2
just broker as default process
2024-04-12 16:16:03 -04:00
m0duspwnens
c014508519
need /opt/so/conf/ca/cacerts on receiver for kafka to run
2024-04-12 13:50:25 -04:00
reyesj2
fcfbb1e857
Merge kaffytaffy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 12:50:56 -04:00
reyesj2
911ee579a9
Typo
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 12:16:20 -04:00
reyesj2
a6ff92b099
Note to remove so-kafka-clusterid. Update soup and setup to generate needed kafka pillar values
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 12:11:18 -04:00
m0duspwnens
d73ba7dd3e
order kafka pillar assignment
2024-04-12 11:55:26 -04:00
m0duspwnens
04ddcd5c93
add receiver managersearch and standalone to kafka.nodes pillar
2024-04-12 11:52:57 -04:00
reyesj2
af29ae1968
Merge kaffytaffy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 11:43:46 -04:00
reyesj2
fbd3cff90d
Make global.pipeline use GLOBALMERGED value
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 11:21:19 -04:00
m0duspwnens
0ed9894b7e
create kratos local pillar dirs during setup
2024-04-12 11:19:46 -04:00
m0duspwnens
a54a72c269
move kafka_cluster_id to kafka:cluster_id
2024-04-12 11:19:20 -04:00
m0duspwnens
f514e5e9bb
add kafka to receiver
2024-04-11 16:23:05 -04:00
reyesj2
3955587372
Use global.pipeline for redis / kafka states
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 16:20:09 -04:00
reyesj2
6b28dc72e8
Update annotation for global.pipeline
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:38:33 -04:00
reyesj2
ca7253a589
Run kafka-clusterid script when pillar values are missing
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:38:03 -04:00
reyesj2
af53dcda1b
Remove references to kafkanode
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:32:00 -04:00
m0duspwnens
d3bd56b131
disable logstash and redis if kafka enabled
2024-04-10 14:13:27 -04:00
m0duspwnens
e9e61ea2d8
Merge remote-tracking branch 'origin/2.4/dev' into kaffytaffy
2024-04-10 13:14:13 -04:00
m0duspwnens
86b984001d
annotations and enable/disable from ui
2024-04-10 10:39:06 -04:00
m0duspwnens
fa7f8104c8
Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy
2024-04-09 11:13:02 -04:00
m0duspwnens
bd5fe43285
jinja config files
2024-04-09 11:07:53 -04:00
m0duspwnens
d38051e806
fix client and server properties formatting
2024-04-09 10:36:37 -04:00
m0duspwnens
daa5342986
items not keys in for loop
2024-04-09 10:22:05 -04:00
m0duspwnens
c48436ccbf
fix dict update
2024-04-09 10:19:17 -04:00
m0duspwnens
7aa00faa6c
fix var
2024-04-09 09:31:54 -04:00
m0duspwnens
6217a7b9a9
add defaults and jijafy kafka config
2024-04-09 09:27:21 -04:00
reyesj2
d67ebabc95
Remove logstash output to kafka pipeline. Add additional topics for searchnodes to ingest and add partition/offset info to event
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-08 16:38:03 -04:00
Josh Brower
b9474b9352
Merge pull request #12766 from Security-Onion-Solutions/2.4/sigma-pipeline
...
Ship Defender logs + more
2024-04-08 16:35:24 -04:00
DefensiveDepth
376efab40c
Ship Defender logs
2024-04-08 14:01:38 -04:00
reyesj2
65274e89d7
Add client_id to logstash pipeline. To identify which searchnode is pulling messages
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-05 15:38:00 -04:00
coreyogburn
acf29a6c9c
Merge pull request #12760 from Security-Onion-Solutions/cogburn/detection-author-remap
...
Detection Author as a Keyword instead of Text
2024-04-05 11:39:53 -06:00
reyesj2
721e04f793
initial logstash input from kafka over ssl
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-05 13:37:14 -04:00
Corey Ogburn
00cea6fb80
Detection Author as a Keyword instead of Text
...
With Quick Actions added to Detections, as many fields should be usable as possible.
2024-04-05 11:22:47 -06:00
reyesj2
433309ef1a
Generate kafka cluster id if it doesn't exist
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-05 09:35:12 -04:00
Mike Reeves
cbc95d0b30
Merge pull request #12759 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-log-check
2024-04-05 08:17:50 -04:00
Mike Reeves
21f86be8ee
Update so-log-check
2024-04-05 08:03:42 -04:00
Josh Brower
8e38c3763e
Merge pull request #12756 from Security-Onion-Solutions/2.4/detections-defaults
...
Use list not string
2024-04-04 17:00:38 -04:00
DefensiveDepth
ca807bd6bd
Use list not string
2024-04-04 16:58:39 -04:00
reyesj2
735cfb4c29
Autogenerate kafka topics when a message it sent to non-existing topic
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-04 16:45:58 -04:00
reyesj2
6202090836
Merge remote-tracking branch 'origin/kaffytaffy' into reyesj2/kafka
2024-04-04 16:27:06 -04:00
reyesj2
436cbc1f06
Add kafka signing_policy for client/server auth. Add kafka-client cert on manager so manager can interact with kafka using its own cert
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-04 16:21:29 -04:00
reyesj2
40b08d737c
Generate kafka keystore on changes to kafka.key
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-04 16:16:53 -04:00
m0duspwnens
4c5b42b898
restart container on server config changes
2024-04-04 15:47:01 -04:00
m0duspwnens
7a6b72ebac
add so-kafka to manager for firewall
2024-04-04 15:46:11 -04:00
Josh Brower
f72cbd5f23
Merge pull request #12755 from Security-Onion-Solutions/2.4/detections-defaults
...
2.4/detections defaults
2024-04-04 11:33:59 -04:00
Josh Brower
1d7e47f589
Merge pull request #12682 from Security-Onion-Solutions/2.4/soup-playbook
...
2.4/soup playbook
2024-04-04 11:28:09 -04:00
DefensiveDepth
49d5fa95a2
Detections tweaks
2024-04-04 11:26:44 -04:00
Jason Ertel
204f44449a
Merge pull request #12754 from Security-Onion-Solutions/jertel/ana
...
skip telemetry summary in airgap mode
2024-04-04 10:39:07 -04:00
Jason Ertel
6046848ee7
skip telemetry summary in airgap mode
2024-04-04 10:25:32 -04:00
Doug Burks
b0aee238b1
Merge pull request #12753 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add dashboards specific to Elastic Agent #12746
2024-04-04 09:35:21 -04:00
Doug Burks
d8ac3f1292
FEATURE: Add dashboards specific to Elastic Agent #12746
2024-04-04 09:30:05 -04:00
Mike Reeves
8788b34c8a
Merge pull request #12752 from Security-Onion-Solutions/updates23
...
Allow 2.3 to update
2024-04-04 09:25:41 -04:00
Mike Reeves
784ec54795
2.3 updates
2024-04-04 09:24:17 -04:00
Mike Reeves
54fce4bf8f
2.3 updates
2024-04-04 09:21:16 -04:00
Mike Reeves
c4ebe25bab
Attempt to fix 2.3 when main repo changes
2024-04-04 09:18:37 -04:00
Doug Burks
7b4e207329
Merge pull request #12751 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module sigma #12743
2024-04-04 09:13:53 -04:00
Doug Burks
5ec3b834fb
FEATURE: Add Events table columns for event.module sigma #12743
2024-04-04 09:11:41 -04:00
Mike Reeves
7668fa1396
Attempt to fix 2.3 when main repo changes
2024-04-04 09:03:29 -04:00
Mike Reeves
470b0e4bf6
Attempt to fix 2.3 when main repo changes
2024-04-04 08:55:13 -04:00
Mike Reeves
d3f163bf9e
Attempt to fix 2.3 when main repo changes
2024-04-04 08:54:04 -04:00
Mike Reeves
4b31632dfc
Attempt to fix 2.3 when main repo changes
2024-04-04 08:52:37 -04:00
DefensiveDepth
c2f7f7e3a5
Remove dup line
2024-04-04 08:52:30 -04:00
DefensiveDepth
07cb0c7d46
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/soup-playbook
2024-04-04 08:51:09 -04:00
Mike Reeves
14c824143b
Attempt to fix 2.3 when main repo changes
2024-04-04 08:48:44 -04:00
Jason Ertel
c75c411426
Merge pull request #12749 from Security-Onion-Solutions/jertel/ana
...
Clarify annotation description re: Airgap
2024-04-04 07:53:18 -04:00
Jason Ertel
a7fab380b4
clarify telemetry annotation
2024-04-04 07:51:23 -04:00
Jason Ertel
a9517e1291
clarify telemetry annotation
2024-04-04 07:49:30 -04:00
Josh Brower
1017838cfc
Merge pull request #12748 from Security-Onion-Solutions/2.4/exclude-elastalert
...
Exclude Elastalert EQL errors
2024-04-04 06:57:22 -04:00
DefensiveDepth
1d221a574b
Exclude Elastalert EQL errors
2024-04-04 06:48:25 -04:00
Jason Ertel
a35bfc4822
Merge pull request #12747 from Security-Onion-Solutions/jertel/ana
...
do not prompt about telemetry on airgap installs
2024-04-03 21:50:38 -04:00
Jason Ertel
7c64fc8c05
do not prompt about telemetry on airgap installs
2024-04-03 18:08:42 -04:00
DefensiveDepth
f66cca96ce
YARA casing
2024-04-03 16:17:29 -04:00
Mike Reeves
12da7db22c
Attempt to fix 2.3 when main repo changes
2024-04-03 15:38:23 -04:00
m0duspwnens
1b8584d4bb
allow manager to manager on kafka ports
2024-04-03 15:36:35 -04:00
Mike Reeves
9c59f42c16
Attempt to fix 2.3 when main repo changes
2024-04-03 15:23:09 -04:00
coreyogburn
fb5eea8284
Merge pull request #12744 from Security-Onion-Solutions/cogburn/detection-state
...
Update SOC Config with State File Paths
2024-04-03 13:19:26 -06:00
Mike Reeves
9db9af27ae
Attempt to fix 2.3 when main repo changes
2024-04-03 15:14:50 -04:00
Corey Ogburn
0f50a265cf
Update SOC Config with State File Paths
...
Each detection engine is getting a state file to help manage the timer over restarts. By default, the files will go in soc's config folder inside a fingerprints folder.
2024-04-03 13:12:18 -06:00
Jason Ertel
3e05c04aa1
Merge pull request #12731 from Security-Onion-Solutions/jertel/ana
...
SOC Telemetry
2024-04-03 14:51:41 -04:00
Jason Ertel
8f8896c505
fix link
2024-04-03 14:45:39 -04:00
Jason Ertel
941a841da0
fix link
2024-04-03 14:41:57 -04:00
reyesj2
13105c4ab3
Generate certs for use with elasticfleet kafka output policy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-03 14:34:07 -04:00
reyesj2
dc27bbb01d
Set kafka heap size. To be later configured from SOC
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-03 14:30:52 -04:00
Jason Ertel
2b8a051525
fix link
2024-04-03 14:30:09 -04:00
Mike Reeves
1c7cc8dd3b
Merge pull request #12741 from Security-Onion-Solutions/metrics
...
Change code to allow for non root
2024-04-03 12:56:17 -04:00
Doug Burks
58d081eed1
Merge pull request #12742 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module kratos #12740
2024-04-03 12:48:24 -04:00
Doug Burks
9078b2bad2
FEATURE: Add Events table columns for event.module kratos #12740
2024-04-03 12:46:29 -04:00
Mike Reeves
8889c974b8
Change code to allow for non root
2024-04-03 12:38:59 -04:00
Doug Burks
f615a73120
Merge pull request #12739 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add dashboard for SOC Login Failures #12738
2024-04-03 12:01:08 -04:00
Doug Burks
66844af1c2
FEATURE: Add dashboard for SOC Login Failures #12738
2024-04-03 11:54:53 -04:00
Mike Reeves
a0b7d89eb6
Merge pull request #12734 from Security-Onion-Solutions/metrics
...
Add Elastic Agent Status Metrics
2024-04-03 11:12:53 -04:00
Mike Reeves
c31e459c2b
Change metrics reporting order
2024-04-03 11:06:00 -04:00
m0duspwnens
b863060df1
kafka broker and listener on 0.0.0.0
2024-04-03 11:05:24 -04:00
weslambert
d96d696c35
Merge pull request #12735 from Security-Onion-Solutions/feature/cef
...
Add cef
2024-04-03 10:49:44 -04:00
Wes
105eadf111
Add cef
2024-04-03 14:40:41 +00:00
Jason Ertel
ca57c20691
suppress soup update output for cleaner console
2024-04-03 10:31:24 -04:00
Jason Ertel
c4767bfdc8
suppress soup update output for cleaner console
2024-04-03 10:28:43 -04:00
Mike Reeves
0de1f76139
add agent count to reposync
2024-04-03 10:26:59 -04:00
Jason Ertel
5f4a0fdfad
suppress soup update output for cleaner console
2024-04-03 10:26:48 -04:00
m0duspwnens
18f95e867f
port 9093 for kafka docker
2024-04-03 10:24:53 -04:00
m0duspwnens
ed6137a76a
allow sensor and searchnode to connect to manager kafka ports
2024-04-03 10:24:10 -04:00
m0duspwnens
c3f02a698e
add kafka nodes as extra hosts for the container
2024-04-03 10:23:36 -04:00
m0duspwnens
db106f8ca1
listen on 0.0.0.0 for CONTROLLER
2024-04-03 10:22:47 -04:00
Jason Ertel
c712529cf6
suppress soup update output for cleaner console
2024-04-03 10:21:35 -04:00
Mike Reeves
976ddd3982
add agentstatus to telegraf
2024-04-03 10:06:08 -04:00
Mike Reeves
64748b98ad
add agentstatus to telegraf
2024-04-03 09:56:12 -04:00
Mike Reeves
3335612365
add agentstatus to telegraf
2024-04-03 09:54:16 -04:00
Mike Reeves
513273c8c3
add agentstatus to telegraf
2024-04-03 09:43:55 -04:00
Mike Reeves
0dfde3c9f2
add agentstatus to telegraf
2024-04-03 09:40:14 -04:00
Mike Reeves
0efdcfcb52
add agentstatus to telegraf
2024-04-03 09:36:02 -04:00
Josh Brower
fbdcc53fe0
Merge pull request #12732 from Security-Onion-Solutions/2.4/detections-defaults
...
Feature - auto-enabled Sigma rules
2024-04-03 09:01:09 -04:00
m0duspwnens
8e47cc73a5
kafka.nodes pillar to lf
2024-04-03 08:54:17 -04:00
m0duspwnens
639bf05081
add so-manager to kafka.nodes pillar
2024-04-03 08:52:26 -04:00
Jason Ertel
c1b5ef0891
ensure so-yaml.py is updated during soup
2024-04-03 08:44:40 -04:00
DefensiveDepth
a8f25150f6
Feature - auto-enabled Sigma rules
2024-04-03 08:21:50 -04:00
Jason Ertel
1ee2a6d37b
Improve wording for Airgap annotation
2024-04-03 08:21:30 -04:00
Mike Reeves
f64d9224fb
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into metrics
2024-04-02 17:22:20 -04:00
m0duspwnens
4e142e0212
put alphabetical
2024-04-02 16:47:35 -04:00
m0duspwnens
c9bf1c86c6
Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy
2024-04-02 16:40:47 -04:00
reyesj2
82830c8173
Fix typos and fix error related to elasticsearch saltstate being called from logstash state. Logstash will be removed from kafkanodes in future
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:37:39 -04:00
reyesj2
7f5741c43b
Fix kafka storage setup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:36:22 -04:00
reyesj2
643d4831c1
CRLF -> LF
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:35:14 -04:00
reyesj2
b032eed22a
Update kafka to use manager docker registry
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:34:06 -04:00
reyesj2
1b49c8540e
Fix kafka keystore script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:32:15 -04:00
m0duspwnens
f7534a0ae3
make manager download so-kafka container
2024-04-02 16:01:12 -04:00
Jason Ertel
b6187ab769
Improve wording for Airgap annotation
2024-04-02 15:54:39 -04:00
m0duspwnens
780ad9eb10
add kafka to manager nodes
2024-04-02 15:50:25 -04:00
Mike Reeves
283939b18a
Gather metrics from elastic agent to influx
2024-04-02 15:36:01 -04:00
m0duspwnens
e25bc8efe4
Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy
2024-04-02 13:36:47 -04:00
Jason Ertel
3b112e20e3
fix syntax error
2024-04-02 12:32:33 -04:00
reyesj2
26abe90671
Removed duplicate kafka setup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 12:19:46 -04:00
Doug Burks
23a6c4adb6
Merge pull request #12725 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:54:15 -04:00
Doug Burks
2f03cbf115
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:42:20 -04:00
Doug Burks
a678a5a416
Merge pull request #12724 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:15:20 -04:00
Doug Burks
b2b54ccf60
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:11:16 -04:00
Doug Burks
55e71c867c
Merge pull request #12723 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module playbook #12703
2024-04-02 10:04:21 -04:00
Doug Burks
6c2437f8ef
FEATURE: Add Events table columns for event.module playbook #12703
2024-04-02 09:55:56 -04:00
Doug Burks
261f2cbaf7
Merge pull request #12722 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 09:43:15 -04:00
Jason Ertel
f083558666
break out into sep func
2024-04-02 09:42:43 -04:00
Doug Burks
505eeea66a
Update defaults.yaml
2024-04-02 09:39:54 -04:00
Josh Brower
1001aa665d
Merge pull request #12720 from Security-Onion-Solutions/2.4/detections-defaults
...
Add default columns
2024-04-02 09:21:06 -04:00
DefensiveDepth
7f488422b0
Add default columns
2024-04-02 09:13:27 -04:00
Jason Ertel
f17d8d3369
analytics
2024-04-01 10:59:44 -04:00
Jason Ertel
ff777560ac
limit col size
2024-04-01 10:35:15 -04:00
Jason Ertel
2c68fd6311
limit col size
2024-04-01 10:32:54 -04:00
Jason Ertel
c1bf710e46
limit col size
2024-04-01 10:32:25 -04:00
Jason Ertel
9d2b40f366
Merge branch '2.4/dev' into jertel/ana
2024-04-01 09:50:38 -04:00
Jason Ertel
3aea2dec85
analytics
2024-04-01 09:50:18 -04:00
coreyogburn
65f6b7022c
Merge pull request #12702 from Security-Onion-Solutions/cogburn/yaml-fix
...
Correct YAML
2024-03-29 15:59:34 -06:00
Corey Ogburn
e5a3a54aea
Proper YAML
2024-03-29 14:31:43 -06:00
Doug Burks
be88dbe181
Merge pull request #12700 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add individual dashboards for Zeek SSL and Suricata SSL logs…
2024-03-29 15:41:14 -04:00
Doug Burks
b64ed5535e
FEATURE: Add individual dashboards for Zeek SSL and Suricata SSL logs #12699
2024-03-29 15:29:38 -04:00
Doug Burks
5be56703e9
Merge pull request #12698 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for zeek ssl and suricata ssl #12697
2024-03-29 14:46:39 -04:00
Doug Burks
0c7ba62867
FEATURE: Add Events table columns for zeek ssl and suricata ssl #12697
2024-03-29 14:44:29 -04:00
coreyogburn
d9d851040c
Merge pull request #12696 from Security-Onion-Solutions/cogburn/manual-sync
...
New Settings for Manual Sync in Detections
2024-03-29 12:43:08 -06:00
Corey Ogburn
e747a4e3fe
New Settings for Manual Sync in Detections
2024-03-29 12:25:03 -06:00
Doug Burks
cc2164221c
Merge pull request #12695 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add process.command_line to Process Info and Process Ancestry dashboards #12694
2024-03-29 13:04:09 -04:00
Doug Burks
102c3271d1
FEATURE: Add process.command_line to Process Info and Process Ancestry dashboards #12694
2024-03-29 12:04:47 -04:00
DefensiveDepth
32b8649c77
Add more error checking
2024-03-28 14:31:02 -04:00
DefensiveDepth
9c5ba92589
Check if container is running first
2024-03-28 13:23:40 -04:00
DefensiveDepth
d2c9e0ea4a
Cleanup
2024-03-28 13:04:48 -04:00
Jason Ertel
2928b71616
Merge pull request #12683 from Security-Onion-Solutions/jertel/lc
...
disregard errors in removed applications that occurred before th…
2024-03-28 09:48:26 -04:00
Jason Ertel
216b8c01bf
disregard errors that in removed applications that occurred before the upgrade
2024-03-28 09:31:39 -04:00
DefensiveDepth
ce0c9f846d
Remove containers from so-status
2024-03-27 16:13:52 -04:00
DefensiveDepth
ba262ee01a
Check to see if Playbook is enabled
2024-03-27 15:43:25 -04:00
DefensiveDepth
b571eeb8e6
Initial cut of .70 soup changes
2024-03-27 14:58:16 -04:00
Mike Reeves
7fe377f899
Merge pull request #12674 from Security-Onion-Solutions/ipv6fix
...
Fix Input Validation to allow for IPv6
2024-03-27 09:48:01 -04:00
Mike Reeves
d57f773072
Fix regex to allow ipv6 in bpfs
2024-03-27 09:36:42 -04:00
Doug Burks
389357ad2b
Merge pull request #12667 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module elastic_agent #12666
2024-03-26 16:11:46 -04:00
Doug Burks
e2caf4668e
FEATURE: Add Events table columns for event.module elastic_agent #12666
2024-03-26 16:08:41 -04:00
Josh Brower
63a58efba4
Merge pull request #12656 from Security-Onion-Solutions/2.4/detections-fixes
...
Add bindings for sigma repos
2024-03-26 09:33:38 -04:00
DefensiveDepth
bbcd3116f7
Fixes
2024-03-26 09:31:46 -04:00
Josh Brower
9c12aa261e
Merge pull request #12660 from Security-Onion-Solutions/kilo
...
Initial cut to remove Playbook and deps
2024-03-26 08:31:11 -04:00
DefensiveDepth
cc0f4847ba
Casing and validation
2024-03-26 08:10:57 -04:00
Doug Burks
923b80ba60
Merge pull request #12663 from Security-Onion-Solutions/feature/improve-soc-dashboards
...
FEATURE: Include additional groupby fields in Dashboards relating to sankey diagrams #12657
2024-03-26 07:52:54 -04:00
DefensiveDepth
7c4ea8a58e
Add Detections SOC Config
2024-03-26 07:39:39 -04:00
Doug Burks
20bd9a9701
FEATURE: Include additional groupby fields in Dashboards relating to sankey diagrams #12657
2024-03-26 07:39:24 -04:00
Josh Brower
f0cb30a649
Merge pull request #12659 from Security-Onion-Solutions/2.4/remove-playbook
...
Remove Playbook ref
2024-03-25 21:12:22 -04:00
DefensiveDepth
94ee761207
Remove Playbook ref
2024-03-25 21:11:47 -04:00
Josh Brower
0a5dc411d0
Merge pull request #12658 from Security-Onion-Solutions/2.4/remove-playbook
...
Initial cut to remove Playbook and deps
2024-03-25 19:45:51 -04:00
DefensiveDepth
d7ecad4333
Initial cut to remove Playbook and deps
2024-03-25 19:42:31 -04:00
DefensiveDepth
49fa800b2b
Add bindings for sigma repos
2024-03-25 14:45:50 -04:00
reyesj2
446f1ffdf5
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-03-25 13:55:48 -04:00
weslambert
57553bc1e5
Merge pull request #12652 from Security-Onion-Solutions/feature/pfsense_suricata
...
FEATURE: pfSense Suricata logs
2024-03-25 10:10:13 -04:00
weslambert
df058b3f4a
Merge branch '2.4/dev' into feature/pfsense_suricata
2024-03-25 10:08:03 -04:00
Wes
5e21da443f
Minor verbiage updates
2024-03-25 13:58:32 +00:00
Josh Patterson
7898277a9b
Merge pull request #12651 from Security-Onion-Solutions/issue/12637
...
Allow for additional af-packet tuning options for Suricata
2024-03-25 09:37:52 -04:00
m0duspwnens
029d8a0e8f
handle yes/no on checksum-checks
2024-03-25 09:30:41 -04:00
Josh Brower
b8d33ab983
Merge pull request #12639 from Security-Onion-Solutions/2.4/enable-detections
...
Enable Detections
2024-03-25 09:30:01 -04:00
weslambert
e124791d5d
Merge pull request #12650 from Security-Onion-Solutions/fix/soc_template
...
FIX: http.response.status_code
2024-03-25 09:29:19 -04:00
coreyogburn
8ae30d0a77
Merge pull request #12640 from Security-Onion-Solutions/cogburn/sigma-repo-support
...
Update ElastAlert Config with Default Repos
2024-03-22 14:24:18 -06:00
m0duspwnens
81f3d69eb9
remove mmap-locked.
2024-03-22 15:55:59 -04:00
Corey Ogburn
237946e916
Specify Folder in Rule Repo
2024-03-22 13:52:20 -06:00
Corey Ogburn
3d04d37030
Update ElastAlert Config with Default Repos
2024-03-22 13:52:20 -06:00
m0duspwnens
bb0da2a5c5
add additional suricata af-packet config items
2024-03-22 14:34:14 -04:00
Doug Burks
d6ce3851ec
Merge pull request #12644 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Specify that static IP address is recommended #12643
2024-03-22 13:47:33 -04:00
Doug Burks
9c6f3f4808
FIX: Specify that static IP address is recommended #12643
2024-03-22 13:41:44 -04:00
Doug Burks
1ab56033a2
Merge pull request #12642 from Security-Onion-Solutions/fix/add-event.dataset
...
FEATURE: Add event.dataset to all Events column layouts #12641
2024-03-22 13:22:57 -04:00
Doug Burks
a78a304d4f
FEATURE: Add event.dataset to all Events column layouts #12641
2024-03-22 13:19:31 -04:00
DefensiveDepth
5ca9ec4b17
Enable Detections
2024-03-22 10:12:26 -04:00
weslambert
4e1543b6a8
Get only code
2024-03-22 09:56:21 -04:00
Jason Ertel
0e7d08b957
Merge pull request #12638 from Security-Onion-Solutions/jertel/logs
...
disregard benign telegraf error
2024-03-22 09:53:52 -04:00
Jason Ertel
f889a089bf
disregard benign telegraf error
2024-03-22 09:48:27 -04:00
Doug Burks
2b019ec8fe
Merge pull request #12634 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events column layout for event.module system #12628
2024-03-22 05:52:23 -04:00
Wes
5934829e0d
Include pfsense config
2024-03-21 20:08:33 +00:00
Wes
486a633dfe
Add pfsense Suricata config
2024-03-21 20:07:59 +00:00
weslambert
77ac342786
Merge pull request #12632 from Security-Onion-Solutions/fix/remove_temp_yara
...
Remove temp YARA
2024-03-21 10:11:32 -04:00
weslambert
8429a364dc
Remove Strelka rules watch
2024-03-21 10:09:36 -04:00
weslambert
1568f57096
Remove Strelka config
2024-03-21 10:07:27 -04:00
weslambert
f431e9ae08
Remove Strelka config
2024-03-21 10:06:25 -04:00
Josh Brower
4b03d088c3
Merge pull request #12611 from Security-Onion-Solutions/2.4/enable-detections
...
Change Detections defaults
2024-03-21 08:04:03 -04:00
DefensiveDepth
4a33234c34
Default update to 24 hours
2024-03-21 07:26:19 -04:00
Doug Burks
778997bed4
FEATURE: Add Events column layout for event.module system #12628
2024-03-20 17:07:37 -04:00
Doug Burks
655d3e349c
Merge pull request #12627 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 16:11:33 -04:00
Doug Burks
f3b921342e
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 16:06:25 -04:00
Doug Burks
fff4d20e39
Update soc_suricata.yaml
2024-03-20 16:03:45 -04:00
Doug Burks
d2fb067110
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 15:57:32 -04:00
Doug Burks
876690a9f6
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 15:49:46 -04:00
Jason Ertel
4c2f2759d4
Merge pull request #12601 from Security-Onion-Solutions/jertel/suripcap
...
reschedule close/lock jobs
2024-03-20 12:11:15 -04:00
Mike Reeves
dd603934bc
Merge pull request #12619 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-03-20 11:06:05 -04:00
Mike Reeves
d4d17e1835
Update VERSION
2024-03-20 11:04:40 -04:00
Mike Reeves
7779a95341
Merge pull request #12617 from Security-Onion-Solutions/2.4/main
...
fix merges
2024-03-20 10:53:09 -04:00
Mike Reeves
68ea2836dd
Merge pull request #12615 from Security-Onion-Solutions/2.4.60
...
2.4.260
2024-03-20 10:43:08 -04:00
Mike Reeves
bb3bbd749c
2.4.260
2024-03-20 10:20:04 -04:00
DefensiveDepth
d84af803a6
Enable Autoupdates
2024-03-20 08:48:31 -04:00
DefensiveDepth
020eb47026
Change Detections defaults
2024-03-19 13:53:37 -04:00
Wes
c6df805556
Add SOC template
2024-03-18 14:53:36 +00:00
Jason Ertel
47d447eadd
Merge branch '2.4/dev' into jertel/suripcap
2024-03-18 07:34:43 -04:00
Jason Ertel
af5b3feb96
re-schedule lock jobs
2024-03-18 07:34:18 -04:00
Mike Reeves
4237210f0b
Merge pull request #12587 from Security-Onion-Solutions/TOoSmOotH-patch-10
...
Update soc_suricata.yaml
2024-03-14 11:37:35 -04:00
Mike Reeves
fd835f6394
Update soc_suricata.yaml
2024-03-14 11:36:45 -04:00
Mike Reeves
284e0d8435
Update soc_suricata.yaml
2024-03-14 11:33:47 -04:00
Jason Ertel
09bff01d79
Merge pull request #12584 from Security-Onion-Solutions/jertel/suripcap
...
handle airgap when detections not enabled
2024-03-13 21:35:06 -04:00
Jason Ertel
844cfe55cd
handle airgap when detections not enabled
2024-03-13 20:52:17 -04:00
Jason Ertel
927fe9039d
handle airgap when detections not enabled
2024-03-13 20:50:03 -04:00
Jason Ertel
cc1356c823
Merge pull request #12581 from Security-Onion-Solutions/jertel/suripcap
...
removed unused property
2024-03-13 14:20:22 -04:00
Jason Ertel
275a678fa1
removed unused property
2024-03-13 13:49:44 -04:00
Josh Patterson
3d33c99f53
Merge pull request #12579 from Security-Onion-Solutions/m0duspwnens-patch-1-dontshowchanges
...
Update init.sls
2024-03-13 11:26:20 -04:00
Josh Patterson
b9702d02db
Update init.sls
2024-03-13 11:24:26 -04:00
Josh Patterson
292ab0e378
Merge pull request #12577 from Security-Onion-Solutions/jppsocerino
...
remove modules if detections disabled
2024-03-13 10:30:00 -04:00
m0duspwnens
1a829190ac
remove modules if detections disabled
2024-03-13 09:46:44 -04:00
Josh Brower
dc3eace718
Merge pull request #12576 from Security-Onion-Solutions/2.4/regenpackages
...
Gen packages post-SOUP
2024-03-13 07:53:08 -04:00
DefensiveDepth
06013e2c6f
Gen packages post-SOUP
2024-03-13 07:23:43 -04:00
Mike Reeves
603483148d
Merge pull request #12567 from Security-Onion-Solutions/TOoSmOotH-patch-9
...
Update so-saltstack-update to use 2.4/main
2024-03-12 10:20:41 -04:00
Mike Reeves
3e0fb3f8bb
Update so-saltstack-update
2024-03-12 10:18:27 -04:00
Mike Reeves
5deebe07d8
Merge pull request #12564 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update soc_suricata.yaml
2024-03-12 09:24:56 -04:00
Josh Brower
197791f8ed
Merge pull request #12565 from Security-Onion-Solutions/2.4/detections-defaults
...
2.4/detections defaults
2024-03-12 06:17:30 -04:00
Mike Reeves
72acb11925
Update soc_suricata.yaml
2024-03-11 19:04:51 -04:00
DefensiveDepth
0f41f07dc9
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/detections-defaults
2024-03-11 16:41:26 -04:00
Josh Brower
47ab1f5b95
Merge pull request #12563 from Security-Onion-Solutions/kilo
...
Add yara update back
2024-03-11 16:39:31 -04:00
Josh Patterson
b7f058a8ca
Merge pull request #12561 from Security-Onion-Solutions/jppnocap
...
transitional pcap
2024-03-11 15:57:16 -04:00
DefensiveDepth
61a183b7fc
Add regex defaults
2024-03-11 15:55:39 -04:00
m0duspwnens
ba32b3e6e9
fix bpf for transition
2024-03-11 14:07:45 -04:00
Jason Ertel
8c54a19698
Merge pull request #12560 from Security-Onion-Solutions/jertel/email
...
auto-convert email addresses to lowercase during setup
2024-03-11 14:06:52 -04:00
Jason Ertel
cd28c00d67
auto-convert email addresses to lowercase during setup
2024-03-11 13:47:31 -04:00
Jason Ertel
b5d8df7fb2
auto-convert email addresses to lowercase during setup
2024-03-11 13:45:57 -04:00
m0duspwnens
907cf9f992
transition pcap
2024-03-11 12:20:28 -04:00
Josh Patterson
4355d5b659
Merge pull request #12544 from Security-Onion-Solutions/jertel/status
...
pcap improvements
2024-03-11 10:29:33 -04:00
Jorge Reyes
2ca96c7f4c
Merge pull request #12555 from Security-Onion-Solutions/reyesj2-patch-osc
...
Create local salt directory
2024-03-11 09:40:20 -04:00
reyesj2
a8403c63c7
Create local salt dir for stig
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-03-11 09:35:54 -04:00
weslambert
34d5954e16
Fix indent
2024-03-11 09:12:05 -04:00
Jorge Reyes
f4725bf6d4
Merge pull request #12553 from Security-Onion-Solutions/reyesj2-patch-osc
...
Run scan against default scap security guide so that resulting score is accurate
2024-03-11 07:52:07 -04:00
Doug Burks
b622cf8d23
Merge pull request #12545 from Security-Onion-Solutions/dougburks-patch-1
...
Update soc_pcap.yaml
2024-03-08 16:45:29 -05:00
Doug Burks
a892352b61
Update soc_pcap.yaml
2024-03-08 16:43:29 -05:00
Jason Ertel
a55e04e64a
pcap improvements
2024-03-08 15:48:53 -05:00
Josh Brower
4a9e8265ce
Merge remote-tracking branch 'origin/2.4/dev' into kilo
2024-03-08 14:48:04 -05:00
coreyogburn
68ba9a89cf
Merge pull request #12542 from Security-Onion-Solutions/cogburn/yara-license
...
Updated RulesRepo for New Strelka Structure
2024-03-08 11:42:49 -07:00
Corey Ogburn
6f05c3976b
Updated RulesRepo for New Strelka Structure
2024-03-08 11:29:46 -07:00
Doug Burks
b6b6fc45e7
Merge pull request #12527 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Fix Space Free for Steno
2024-03-08 12:40:15 -05:00
Doug Burks
e1b27a930e
Merge pull request #12540 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Update SOC annotations for Stenographer PCAP #12539
2024-03-08 12:32:15 -05:00
Doug Burks
6680e023e4
Update soc_pcap.yaml
2024-03-08 12:16:59 -05:00
Wes
e8ae609012
Add Strelka rules watch back
2024-03-08 16:27:17 +00:00
Wes
fc66a54902
Add Strelka download and update scripts back
2024-03-08 16:26:14 +00:00
Wes
4e32935991
Add Strelka config back
2024-03-08 16:24:37 +00:00
Josh Patterson
7ec887a327
Merge pull request #12537 from Security-Onion-Solutions/issue/12535
...
allow managersearch to receiver redis and 5644
2024-03-08 10:13:27 -05:00
m0duspwnens
3eb6fe2df9
allow managersearch to receiver redis and 5644
2024-03-08 09:52:12 -05:00
Jason Ertel
6d06aa8ed6
Merge pull request #12526 from Security-Onion-Solutions/jertel/status
...
unswap files
2024-03-07 14:49:17 -05:00
Mike Reeves
06257b9c4a
Update so-minion
2024-03-07 14:32:46 -05:00
Jason Ertel
40574982e4
unswap files
2024-03-07 14:25:43 -05:00
Jason Ertel
e2567dcf8d
Merge pull request #12521 from Security-Onion-Solutions/jertel/status
...
gracefully handle status check failure on ubuntu
2024-03-07 13:29:48 -05:00
Jason Ertel
fffef9b621
gracefully handle status check failure on ubuntu
2024-03-07 12:31:51 -05:00
weslambert
1633527695
Merge pull request #12519 from Security-Onion-Solutions/fix/error_message_system_syslog
...
Add error.message mapping for system.syslog
2024-03-07 10:47:33 -05:00
Wes
005930f7fd
Add error.message mapping for system.syslog
2024-03-07 15:41:23 +00:00
Mike Reeves
b5f1733e97
Merge pull request #12513 from Security-Onion-Solutions/newsuripcap
...
Change Factoring for so-minion pcap disk space
2024-03-07 10:14:34 -05:00
m0duspwnens
70f3ce0536
change how maxfiles is calculated
2024-03-06 17:32:06 -05:00
reyesj2
17a75d5bd2
Run stig post remediate scan against default ol9 scap-security-guide.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-03-06 17:19:01 -05:00
m0duspwnens
583227290f
fix max-files calc
2024-03-06 15:18:22 -05:00
m0duspwnens
cf232534ca
move suricata.pcap to suricata.config.outputs.pcap-log
2024-03-06 14:42:07 -05:00
Mike Reeves
7f1e786e3d
Consolidate PCAP settings
2024-03-06 12:56:09 -05:00
Mike Reeves
9a413a2e31
Fix location of repo
2024-03-06 12:42:22 -05:00
Jason Ertel
8f36a8a4b6
Merge pull request #12514 from Security-Onion-Solutions/jertel/annotations
...
detections annotations
2024-03-06 11:10:21 -05:00
Jason Ertel
1cbac11fae
detections annotations
2024-03-06 11:08:03 -05:00
Mike Reeves
ad12093429
Fix percent calc
2024-03-06 11:05:06 -05:00
Jason Ertel
167aff24f6
detections annotations
2024-03-06 11:03:52 -05:00
Josh Brower
9e671621db
Merge pull request #12510 from Security-Onion-Solutions/2.4/excludedetections
...
Add Exclusion toggle
2024-03-06 10:56:29 -05:00
Mike Reeves
4dfa1a5626
Move Suricata around
2024-03-06 10:35:10 -05:00
Mike Reeves
f836d6a61d
Update so-minion
2024-03-06 10:06:17 -05:00
Mike Reeves
a63fca727c
Update soc_suricata.yaml
2024-03-06 10:02:06 -05:00
Mike Reeves
f58c104d89
Update so-minion
2024-03-06 09:51:56 -05:00
Jason Ertel
5acefb5d18
Merge pull request #12511 from Security-Onion-Solutions/jertel/annotations
...
PCAP annotations
2024-03-06 08:40:24 -05:00
Jason Ertel
0f12297f50
add new pcap annotations
2024-03-06 08:19:42 -05:00
Jason Ertel
12653eec8c
add new pcap annotations
2024-03-06 08:14:33 -05:00
Josh Brower
1b47537a3f
Add Exclusion toggle
2024-03-06 07:16:50 -05:00
Josh Patterson
73b45cfaf8
Merge pull request #12508 from Security-Onion-Solutions/jppsensoroni
...
fix pcapspace function
2024-03-05 17:53:28 -05:00
Josh Patterson
eaef076eba
Update so-minion
2024-03-05 17:52:24 -05:00
Josh Patterson
ac9db8a392
Merge branch '2.4/dev' into jppsensoroni
2024-03-05 17:51:32 -05:00
m0duspwnens
5687fdcf57
fix pcapspace function
2024-03-05 17:46:43 -05:00
Jason Ertel
d5b08142a0
Merge pull request #12507 from Security-Onion-Solutions/jertel/annotations
...
fix oinkcodes with leading zeros
2024-03-05 16:44:56 -05:00
Jason Ertel
4b5f00cef4
fix oinkcodes with leading zeros
2024-03-05 16:42:20 -05:00
weslambert
185a160df0
Merge pull request #12500 from Security-Onion-Solutions/feature/additional_integrations_5
...
Additional Integrations #5
2024-03-05 16:12:05 -05:00
Mike Reeves
b9707fc8ea
Merge pull request #12502 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-minion
2024-03-05 15:10:02 -05:00
Mike Reeves
a686d46322
Update so-minion
2024-03-05 15:09:02 -05:00
Mike Reeves
6eb608c3f5
Update so-minion
2024-03-05 15:05:03 -05:00
weslambert
b9ebe6c40b
Update VERSION
2024-03-05 12:58:34 -05:00
Josh Patterson
781f96a74e
Merge pull request #12497 from Security-Onion-Solutions/jppsensoroni
...
fix sensoroni for non sensor
2024-03-05 10:36:12 -05:00
m0duspwnens
c0d19e11b9
fix } placement
2024-03-05 10:07:32 -05:00
m0duspwnens
1a58aa61a0
only import pcap and suricata if sensor
2024-03-05 09:54:40 -05:00
m0duspwnens
08f2b8251b
add GLOBALS.is_sensor
2024-03-05 09:53:35 -05:00
weslambert
bed42208b1
Add journald integration
2024-03-05 09:49:55 -05:00
weslambert
2a7e5b096f
Change version for foxtrot
2024-03-05 09:48:59 -05:00
weslambert
d8e8933ea0
Add AWS Security Hub template
2024-03-05 09:25:41 -05:00
weslambert
d85ac39e28
Add AWS Inspector template
2024-03-05 09:23:17 -05:00
weslambert
1514f1291e
Add AWS GuardDuty template
2024-03-05 09:21:48 -05:00
weslambert
b64d61065a
Add AWS Cloudfront template
2024-03-05 09:19:43 -05:00
Mike Reeves
58d222284e
Merge pull request #12271 from Security-Onion-Solutions/suripcap
...
Suricata PCAP
2024-03-04 17:27:38 -05:00
Mike Reeves
fe238755e9
Fix df
2024-03-04 16:52:51 -05:00
Mike Reeves
018e099111
Modify setup
2024-03-04 14:53:15 -05:00
Josh Brower
9fd1653914
Merge pull request #12487 from Security-Onion-Solutions/2.4/elastic-agent-fim
...
Fix FIM
2024-03-04 07:41:36 -05:00
Josh Brower
f28f269bb1
Fix FIM
2024-03-04 07:38:32 -05:00
Josh Brower
f3dce66f03
Merge pull request #12482 from Security-Onion-Solutions/2.4/sigma-pipeline
...
2.4/sigma pipeline
2024-03-01 15:29:13 -05:00
Josh Brower
d832158cc5
Drop Hashes field
2024-03-01 15:26:02 -05:00
Josh Brower
b017157d21
Add antivirus mapping
2024-03-01 14:04:56 -05:00
Jorge Reyes
d911b7bfc4
Merge pull request #12469 from Security-Onion-Solutions/reyesj2-patch-4
...
FIX: EA installers not downloadable from SOC & fix logging
2024-02-29 16:21:44 -05:00
reyesj2
53761d4dba
FIX: EA installers not downloadable from SOC + fix stg logging
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-02-29 16:15:26 -05:00
Mike Reeves
1fe8f3d9e4
Merge pull request #12405 from Security-Onion-Solutions/repochange
...
Manage the repo files
2024-02-29 14:01:48 -05:00
Josh Brower
aa3b917368
Merge pull request #12456 from Security-Onion-Solutions/feature/detections-airgap
...
Feature/detections airgap
2024-02-28 09:41:13 -05:00
Josh Brower
e2dd0f8cf1
Only update rule files if AG
2024-02-28 09:39:23 -05:00
weslambert
d1e55d5ab7
Merge pull request #12450 from Security-Onion-Solutions/fix/suricata_max_age
...
Roll Suricata logs daily to prevent alerts from being deleted when not meeting size threshold
2024-02-27 17:28:07 -05:00
weslambert
df3943b465
Daily rollover
2024-02-27 17:24:27 -05:00
Josh Patterson
d5fc6ddd2c
Merge pull request #12449 from Security-Onion-Solutions/issue/12391
...
Issue/12391
2024-02-27 15:38:33 -05:00
m0duspwnens
fcc0f9d14f
redo classifications
2024-02-27 13:20:58 -05:00
Josh Brower
59af547838
Fix download location
2024-02-27 09:49:54 -05:00
Josh Brower
a817bae1e5
Merge pull request #12437 from Security-Onion-Solutions/feature/detections-airgap
...
Airgap Support - Detections module
2024-02-26 16:47:26 -05:00
Josh Brower
c6baa4be1b
Airgap Support - Detections module
2024-02-26 16:19:32 -05:00
m0duspwnens
8b7f7933bd
suricata container watch classification.config
2024-02-26 15:29:13 -05:00
m0duspwnens
466dac30bb
soup for classifications
2024-02-26 12:15:17 -05:00
Doug Burks
52580fb8c4
Merge pull request #12434 from Security-Onion-Solutions/feature/improve-endpoint-columns
...
Add multiple endpoint features
2024-02-26 12:05:30 -05:00
weslambert
acf7dbdabe
Merge pull request #12432 from Security-Onion-Solutions/fix/endpoint_diag_template
...
Update pattern for endpoint diagnostic template
2024-02-26 12:01:29 -05:00
weslambert
1d099f97d2
Update pattern for endpoint diagnostic template
2024-02-26 11:27:56 -05:00
Doug Burks
f8424f3dad
Update defaults.yaml
2024-02-26 11:22:09 -05:00
m0duspwnens
9a7e2153ee
add classification.config
2024-02-26 11:01:53 -05:00
Doug Burks
c8a95a8706
FEATURE: Add new endpoint dashboards #12428
2024-02-26 09:59:07 -05:00
Doug Burks
4df21148fc
FEATURE: Add default columns for endpoint.events datasets #12425
2024-02-26 09:40:51 -05:00
Doug Burks
ca249312ba
FEATURE: Add new SOC action for Process Info #12421
2024-02-26 09:38:14 -05:00
Josh Brower
66b815d4b2
Merge pull request #12431 from Security-Onion-Solutions/feature/brower-detections
...
Add Detection AutoUpdate config
2024-02-26 08:43:33 -05:00
Josh Brower
a6bb7216f9
Add Detection AutoUpdate config
2024-02-26 08:18:42 -05:00
Josh Brower
77cb5748f6
Merge pull request #12430 from Security-Onion-Solutions/feature/sigma-pipeline
...
Feature/sigma pipeline
2024-02-26 08:00:00 -05:00
Doug Burks
d6cb8ab928
update events_x_process in defaults.yaml
2024-02-23 17:09:40 -05:00
Doug Burks
daf96d7934
fix new eventFields in merged.map.jinja
2024-02-23 17:07:48 -05:00
Doug Burks
58f4fb87d0
fix new eventFields in soc_soc.yaml
2024-02-23 17:06:29 -05:00
Doug Burks
b7ef1e8af1
add more endpoint.events.x fields to soc_soc.yaml
2024-02-23 15:38:53 -05:00
Doug Burks
7da0ccf5a6
add more endpoint.events.x entries to merged.map.jinja
2024-02-23 15:35:53 -05:00
Doug Burks
65cdc1dc86
Merge pull request #12423 from Security-Onion-Solutions/jppfiec
...
convert _x_ to . for soc ui to config
2024-02-23 15:22:16 -05:00
m0duspwnens
573d565976
convert _x_ to . for soc ui to config
2024-02-23 15:03:44 -05:00
Doug Burks
b8baca417b
add endpoint_x_events_x_process to defaults.yaml
2024-02-23 14:03:04 -05:00
Josh Brower
d04aa06455
Fix source.ip
2024-02-22 14:01:02 -05:00
Mike Reeves
1824d7b36d
Merge pull request #12416 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Fix Loss Calculation for Stenographer
2024-02-22 12:52:36 -05:00
Mike Reeves
e7914fc5a1
Update stenoloss.sh
2024-02-22 12:49:06 -05:00
Mike Reeves
759b2ff59e
Manage the repos
2024-02-22 10:03:51 -05:00
Josh Brower
c886e72793
Imphash mappings
2024-02-22 08:59:33 -05:00
Josh Brower
0a9022ba6a
Add hash mappings
2024-02-21 17:07:08 -05:00
Josh Patterson
d2f7946377
Merge pull request #12411 from Security-Onion-Solutions/issue/12382
...
nest under policy
2024-02-21 16:28:04 -05:00
coreyogburn
eb3432fb8b
Merge pull request #12412 from Security-Onion-Solutions/kilo
...
Initial Support for Detections Module
2024-02-21 14:08:11 -07:00
Josh Brower
927ea0c9ec
Update VERSION
2024-02-21 15:56:12 -05:00
m0duspwnens
162785575c
nest under policy
2024-02-21 15:28:24 -05:00
Jason Ertel
152e7937db
Merge pull request #12408 from Security-Onion-Solutions/jertel/24template
...
add missing template
2024-02-21 13:24:34 -05:00
Jason Ertel
25570e6ec2
add missing template
2024-02-21 13:18:39 -05:00
Josh Brower
1952f0f232
Merge remote-tracking branch 'origin/2.4/dev' into kilo
2024-02-21 13:11:49 -05:00
Mike Reeves
9ca0f586ae
Manage the repos
2024-02-21 11:45:02 -05:00
Jason Ertel
29778438f0
Merge pull request #12396 from Security-Onion-Solutions/jertel/glm
...
add lock threads
2024-02-21 07:18:05 -05:00
Jason Ertel
6c6a362fcc
add lock threads
2024-02-20 19:14:18 -05:00
Mike Reeves
89010dacab
Merge pull request #12348 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2024-02-20 12:10:09 -05:00
Jason Ertel
78d41c5342
Merge pull request #12386 from Security-Onion-Solutions/jertel/corricon
...
replace correlate icon to avoid confusion with searcheng.in
2024-02-20 10:39:38 -05:00
Jason Ertel
4b314c8715
replace correlate icon to avoid confusion with searcheng.in
2024-02-20 10:30:09 -05:00
Mike Reeves
ed0773604c
Merge pull request #12385 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-02-20 10:14:45 -05:00
Mike Reeves
07fcfab7ec
Update VERSION
2024-02-20 10:14:11 -05:00
Mike Reeves
84c5fa6a58
Merge pull request #12353 from Security-Onion-Solutions/2.4/dev
...
2.4.50
2024-02-20 10:04:01 -05:00
Mike Reeves
5c96e30087
Merge pull request #12383 from Security-Onion-Solutions/2.4.50
...
2.4.50
2024-02-20 09:50:09 -05:00
Mike Reeves
18b4fcca75
2.4.50
2024-02-20 09:47:05 -05:00
Josh Brower
ffb3cc87b7
Default ruleset; Descriptions
2024-02-16 11:55:10 -05:00
Josh Brower
e4dcb4a8dd
Merge remote-tracking branch 'origin/cogburn/detection_playbooks' into kilo
2024-02-15 17:50:37 -05:00
Corey Ogburn
c64f37ab67
sigmaRulePackages is now a string array
2024-02-15 10:34:07 -07:00
Josh Brower
686304f24a
Merge remote-tracking branch 'origin/2.4/dev' into kilo
2024-02-15 09:47:51 -05:00
Josh Patterson
0765320839
Merge pull request #12360 from Security-Onion-Solutions/2450soup
...
`2450soup
2024-02-14 14:37:28 -05:00
m0duspwnens
a2b17d2348
move jinja to top
2024-02-14 14:27:41 -05:00
m0duspwnens
c1f467a068
handle airgap
2024-02-14 14:22:18 -05:00
m0duspwnens
7d5932ee5e
Merge remote-tracking branch 'origin/2.4/dev' into 2450soup
2024-02-14 13:29:39 -05:00
m0duspwnens
79e98e508f
pass in UPDATE_DIR as a pillar
2024-02-14 13:28:12 -05:00
Josh Patterson
cf6266a92b
Merge pull request #12354 from Security-Onion-Solutions/2450soup
...
modify soup to update soup scripts using salt
2024-02-13 16:23:57 -05:00
m0duspwnens
2e9fa2438b
add back comment
2024-02-13 16:19:50 -05:00
Corey Ogburn
a5db9f87dd
Merge branch 'kilo' into cogburn/detection_playbooks
2024-02-13 14:08:44 -07:00
Corey Ogburn
f321e734eb
Added so-detection mapping in elasticsearch
2024-02-13 14:05:27 -07:00
Corey Ogburn
8800b7e878
WIP: Detections Changes
...
Removed some strelka/yara rules from salt.
Removed yara scripts for downloading and updating rules. This will be managed by SOC.
Added a new compile_yara.py script.
Added the strelka repos folder.
2024-02-13 14:05:27 -07:00
Corey Ogburn
031ee078c5
socsigmarepo
...
Need write permissions on the /opt/so/rules dir so I can clone the sigma repo there.
2024-02-13 14:05:27 -07:00
m0duspwnens
00f2374582
fix path for so-firewall
2024-02-13 15:43:02 -05:00
m0duspwnens
468eedfaeb
add soup script update retru
2024-02-13 15:30:24 -05:00
m0duspwnens
88786e8342
use file.copy to preserve perms
2024-02-13 15:05:09 -05:00
Corey Ogburn
c933627a71
Merge branch 'kilo' of github.com:security-onion-solutions/securityonion into kilo
2024-02-13 12:53:29 -07:00
Corey Ogburn
0d297274c8
DetectionComment Mapping Defined
2024-02-13 12:53:18 -07:00
m0duspwnens
141fd49f02
use rsync
2024-02-13 14:27:22 -05:00
m0duspwnens
7112337c85
fix copy
2024-02-13 13:52:14 -05:00
Josh Brower
0c6c6ba2d5
Various UI tweaks
2024-02-13 13:38:43 -05:00
m0duspwnens
d6ac7a3286
fix the jinja
2024-02-13 13:31:34 -05:00
m0duspwnens
9175a73456
dont need $ for vars
2024-02-13 13:08:09 -05:00
Doug Burks
14209ad99d
Merge pull request #12355 from Security-Onion-Solutions/dougburks-patch-1
...
Add table columns to process dashboard in defaults.yaml
2024-02-13 12:59:34 -05:00
m0duspwnens
1bde002f20
update case
2024-02-13 12:51:53 -05:00
Doug Burks
0741ae370a
Update defaults.yaml
2024-02-13 12:51:26 -05:00
m0duspwnens
d7f853b5b2
comment out script copy in soup
2024-02-13 12:50:22 -05:00
m0duspwnens
5c9b1ab38b
copy with cp
2024-02-13 12:48:31 -05:00
m0duspwnens
b713771494
add back common soup_scripts state
2024-02-13 12:30:36 -05:00
Doug Burks
8060751a66
Add table columns to process dashboard in defaults.yaml
2024-02-13 12:24:33 -05:00
m0duspwnens
c1258f9a92
Merge remote-tracking branch 'origin/2.4/dev' into 2450soup
2024-02-13 11:09:24 -05:00
m0duspwnens
92634724c4
move rm
2024-02-13 11:09:08 -05:00
m0duspwnens
3efaba1104
modify soup to update soup scripts without using salt
2024-02-13 11:04:26 -05:00
Doug Burks
d072d431b3
Merge pull request #12350 from Security-Onion-Solutions/feature/process-ancestry-action
...
FEATURE: Add new SOC action to show process ancestry #12345
2024-02-13 08:51:38 -05:00
Josh Brower
ea80469c2d
Detection Default queries
2024-02-12 19:39:55 -05:00
Doug Burks
0ad39a7e32
FEATURE: Add new SOC action to show process ancestry #12345
2024-02-12 19:18:29 -05:00
Doug Burks
20d2f3b97e
Update Sublime action in defaults.yaml to use i18n
2024-02-12 19:13:32 -05:00
Josh Brower
64726a2785
Merge pull request #12349 from Security-Onion-Solutions/2.4/conflictingfix
...
Fix conflicting id
2024-02-12 19:07:07 -05:00
Josh Brower
ccb14485a3
Fix conflicting id
2024-02-12 19:06:19 -05:00
Josh Brower
5102269440
Update defaults
2024-02-12 16:44:54 -05:00
Mike Reeves
5a4e11b2f8
Update soup
...
Remove a function that isn't used any more
2024-02-12 16:09:47 -05:00
Mike Reeves
e713b4c660
Merge pull request #12346 from Security-Onion-Solutions/reyesj2-patch-1
...
Remove unused file
2024-02-12 16:07:31 -05:00
Mike Reeves
2db5f4dd41
Merge pull request #12308 from petiepooo/feat-es-ownfs
...
FEATURE: Check for mountpoint during Elastic size limit calculations
2024-02-12 16:03:36 -05:00
Mike Reeves
f91cb5b81f
Merge pull request #12290 from petiepooo/fix-remove-intca-symlink
...
fix: also remove intca symlink
2024-02-12 12:33:13 -05:00
Jorge Reyes
4b697b2406
Remove unused file
2024-02-12 09:28:48 -05:00
Josh Brower
c04f5a3f0f
Merge pull request #12268 from Security-Onion-Solutions/feature/fleet-artifacts
...
Feature/fleet artifacts
2024-02-12 08:58:14 -05:00
Josh Brower
b1de6abc17
Merge pull request #12343 from Security-Onion-Solutions/fix/anothercheck
...
Wait for ES to be ready
2024-02-12 08:58:05 -05:00
Josh Brower
cc0f25a4f7
Wait for ES to be ready
2024-02-11 13:30:20 -05:00
Josh Brower
eafb5cf15e
Change to file_root
2024-02-11 13:18:20 -05:00
Jorge Reyes
2b2aa30ac1
Merge pull request #12332 from Security-Onion-Solutions/reyesj2/sod-putty
...
Add putty to SOD
2024-02-10 20:41:03 -05:00
Josh Brower
66ac36a944
Update soup
2024-02-10 11:07:26 -05:00
Josh Brower
feabb7c51f
Merge remote-tracking branch 'origin/2.4/dev' into feature/fleet-artifacts
2024-02-10 10:57:46 -05:00
Corey Ogburn
64f6d0fba9
Updated Detection's ES Mappings
...
Detection's now have a License field and the Comment model is defined now.
2024-02-09 14:20:07 -07:00
Josh Patterson
94b6e781bb
Merge pull request #12337 from Security-Onion-Solutions/salt3006.6v2
...
Salt3006.6v2
2024-02-09 15:45:39 -05:00
m0duspwnens
304ae49251
fix source
2024-02-09 12:41:23 -05:00
m0duspwnens
213ac822a8
create dir and chown
2024-02-09 10:54:07 -05:00
m0duspwnens
2143881c0b
specify *.rules
2024-02-09 10:22:25 -05:00
m0duspwnens
5903ae596c
move suricata rules to /opt/so/rules/nids/suri
2024-02-09 09:47:23 -05:00
Josh Brower
0c423c9329
Merge pull request #12333 from Security-Onion-Solutions/fix/shell
...
Fixup shell
2024-02-09 09:31:47 -05:00
Josh Brower
654602bf80
Fixup shell
2024-02-09 09:30:18 -05:00
reyesj2
3c9d6da1d8
add putty to sod packages.sls
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-02-08 22:05:37 -05:00
Josh Brower
683abf0179
Rework naming
2024-02-08 13:24:25 -05:00
Corey Ogburn
29174566f3
WIP: Updated Detection Mappings, Changed Engine to Language
...
Detection mappings updated to include the removal of Note and the addition of Tags, Ruleset, and Language.
SOC defaults updated to use language based queries rather than engine and show the language column instead of the engine column in results.
2024-02-08 09:44:56 -07:00
Josh Brower
8d0e8789bd
Use salt file roots
2024-02-08 09:54:51 -05:00
Josh Brower
503a09f150
Merge remote-tracking branch 'origin/2.4/dev' into feature/fleet-artifacts
2024-02-08 09:45:21 -05:00
Josh Brower
81a3e95914
Fixup sigma pipelines
2024-02-07 16:42:16 -05:00
Josh Patterson
f02f61c6dd
Merge pull request #12325 from Security-Onion-Solutions/salt3006.6
...
Salt3006.6
2024-02-07 16:33:56 -05:00
Doug Burks
8c5dafa058
Merge pull request #12324 from Security-Onion-Solutions/feature/dashboards-communityid-firewall
...
FEATURE: Add new dashboards for community_id and firewall auth #12323
2024-02-07 16:15:21 -05:00
Doug Burks
d3d2305f00
FEATURE: Add new dashboards for community_id and firewall auth #12323
2024-02-07 16:08:27 -05:00
Josh Brower
7e3187c0b8
Fixup sigma pipelines
2024-02-07 15:35:31 -05:00
Josh Brower
b7b501d289
Add Sigma pipelines
2024-02-07 15:02:52 -05:00
m0duspwnens
6534f392a9
update backup filename
2024-02-07 14:25:28 -05:00
m0duspwnens
478fb6261e
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.6
2024-02-07 14:15:11 -05:00
m0duspwnens
e42e07b245
update salt mine after salt-master restarts
2024-02-07 13:05:45 -05:00
m0duspwnens
f97d0f2f36
add /opt/so/rules/ to files_roots
2024-02-07 09:25:56 -05:00
m0duspwnens
24fd3ef8cc
uopdate error message
2024-02-06 16:22:13 -05:00
m0duspwnens
b3f6153667
update so-yaml tests
2024-02-06 16:15:54 -05:00
Doug Burks
d800d59304
Merge pull request #12316 from Security-Onion-Solutions/feature/improve-soc-actions
...
FEATURE: Improve Correlate and Hunt actions on SOC Actions menu #12315
2024-02-06 15:46:31 -05:00
Doug Burks
7106095128
FEATURE: Improve Correlate and Hunt actions on SOC Actions menu #12315
2024-02-06 15:39:23 -05:00
m0duspwnens
9d62ade32e
update so-yaml tests
2024-02-06 11:14:27 -05:00
m0duspwnens
2643ae08a7
add append to list
2024-02-05 17:54:30 -05:00
Josh Brower
378c99ae88
Fix bindings
2024-02-02 18:27:49 -05:00
Corey Ogburn
8f81c9eb68
Updating config for Detection(s)
2024-02-02 11:49:58 -07:00
Pete
cf83d1cb86
feat: use mountpoint for Elastic log limit
...
Instead of just existence, this checks if the directories are separate mountpoints when determining disk size and log_size_limit calculations.
It also sets the percentage to 80 if /nsm/elasticsearch is a separate mountpoint. This allows for better disk utilization on server configurations where /nsm is based on large slow HDDs for increased PCAP retention but /nsm/elasticsearch is based on SSDs for faster Elasticsearch performance.
2024-02-02 12:25:16 -05:00
Pete
7a29b3a529
call salt before stopping salt services
...
salt-call does not work when the salt-master is not running. If these calls are to succeed, they should occur before the salt services are stopped.
2024-02-02 08:45:01 -05:00
Josh Brower
fe196b5661
Add SOC Config for Detections
2024-02-01 12:22:50 -05:00
m0duspwnens
61ee41e431
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.6
2024-02-01 11:07:06 -05:00
m0duspwnens
0d5db58c86
upgrade salt3006.6
2024-02-01 10:32:41 -05:00
Josh Brower
3d478b92b2
Merge pull request #12294 from Security-Onion-Solutions/jppffa
...
Jppffa
2024-02-01 09:47:18 -05:00
Josh Brower
e090518b59
Refactor script
2024-02-01 09:46:53 -05:00
weslambert
91c1e595ef
Merge pull request #12297 from Security-Onion-Solutions/feature/pipeline_config_ui
...
Manage custom Elasticsearch and Logstash pipelines in UI
2024-02-01 09:18:30 -05:00
Wes
1818e134ca
Change numbers for Logstash
2024-02-01 14:01:55 +00:00
Wes
182667bafb
Change numbers for Elasticsearch
2024-02-01 13:59:23 +00:00
Josh Brower
49b5788ac1
add bindings
2024-02-01 07:21:49 -05:00
Josh Brower
881d6b313e
Update VERSION - kilo
2024-01-31 17:04:11 -05:00
Josh Brower
db057b4dfa
Merge pull request #12296 from Security-Onion-Solutions/cogburn/detection_playbooks
...
Cogburn/detection playbooks
2024-01-31 16:48:51 -05:00
Wes
136097f981
Custom Logstash pipeline annotations
2024-01-31 21:47:09 +00:00
Wes
bc502cc065
Custom Elasticserach pipeline annotations
2024-01-31 21:46:33 +00:00
m0duspwnens
ae32ac40c2
add fleet node nginx to docker annotations
2024-01-31 16:28:45 -05:00
m0duspwnens
2f03248612
use different nginx defaults for so-fleet node hosting artifacts
2024-01-31 16:25:09 -05:00
Mike Reeves
a094d1007b
Merge pull request #12293 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
fix salt lock for airgap version mismatches
2024-01-31 16:21:16 -05:00
Mike Reeves
341ff5b564
Update so-functions
2024-01-31 16:18:51 -05:00
Josh Brower
0fe96bfc2d
switch to symlink
2024-01-31 16:17:40 -05:00
Wes
4672a5b8eb
Custom pipeline configuration in UI
2024-01-31 20:18:17 +00:00
Wes
1853dc398b
Custom pipeline configuration
2024-01-31 20:17:33 +00:00
Wes
bc75be9402
Custom pipelines in UI
2024-01-31 20:16:48 +00:00
Wes
cd4bd6460a
Custom pipelines
2024-01-31 20:16:18 +00:00
Corey Ogburn
585147d1de
Added so-detection mapping in elasticsearch
2024-01-31 10:39:47 -07:00
Mike Reeves
0d01d09d2e
fix pcap paths
2024-01-31 09:15:35 -05:00
Pete
1192dbd530
also remove intca symlink
...
The symlink is created in init.sls; it should be removed here.
2024-01-31 09:01:56 -05:00
Mike Reeves
00289c201e
fix pcap paths
2024-01-31 08:58:57 -05:00
Corey Ogburn
858166bcae
WIP: Detections Changes
...
Removed some strelka/yara rules from salt.
Removed yara scripts for downloading and updating rules. This will be managed by SOC.
Added a new compile_yara.py script.
Added the strelka repos folder.
2024-01-30 15:43:51 -07:00
m0duspwnens
4be1214bab
pcap engine logic for sensoroni
2024-01-30 16:53:57 -05:00
Corey Ogburn
0fa4d92f8f
socsigmarepo
...
Need write permissions on the /opt/so/rules dir so I can clone the sigma repo there.
2024-01-30 14:49:05 -07:00
m0duspwnens
8a25748e33
grammar
2024-01-30 16:06:24 -05:00
m0duspwnens
8b503e2ffa
telegraf dont run stenoloss script if suricata is pcap engine
2024-01-30 15:58:11 -05:00
Jorge Reyes
4dd0b4a4fd
Merge pull request #12283 from Security-Onion-Solutions/reyesj2-patch-6
...
Remove remediate from initial oscap scan
2024-01-30 15:56:13 -05:00
reyesj2
b5ffa186fb
Remove remediate from initial oscap scan
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-30 15:54:23 -05:00
m0duspwnens
f32cb1f115
fix find to work with steno and suri pcap
2024-01-30 15:48:10 -05:00
m0duspwnens
8ed66ea468
disable stenographer if suricata is pcap engine
2024-01-30 15:22:32 -05:00
m0duspwnens
0522dc180a
map pcap dir to container. enable pcap-log in map
2024-01-30 13:39:35 -05:00
m0duspwnens
37dcb84a09
add missing comma
2024-01-30 10:50:01 -05:00
m0duspwnens
d118ff4728
add GLOBALS.pcap_engine
2024-01-29 16:54:08 -05:00
Mike Reeves
88d2ddba8b
add placeholder for telegraf
2024-01-29 15:53:54 -05:00
Mike Reeves
ab551a747d
Threads placeholder logic
2024-01-29 15:44:57 -05:00
Mike Reeves
88c01a22d6
Add annotation logic
2024-01-29 15:27:28 -05:00
Mike Reeves
0c969312e2
Add Globals
2024-01-29 15:22:20 -05:00
Mike Reeves
5b05aec96a
Target sspecific minion
2024-01-29 14:56:51 -05:00
Mike Reeves
1a2245a1ed
Add so-minion modifications
2024-01-29 13:44:53 -05:00
Josh Brower
0d08bb0a91
Finalize script
2024-01-29 11:37:28 -05:00
Jorge Reyes
cb5e111a00
Merge pull request #12267 from Security-Onion-Solutions/reyesj2-patch-6
...
Update soup
2024-01-29 10:22:35 -05:00
reyesj2
7c08b348aa
Add comment for soup update w/ STIGs enabled
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-29 10:16:34 -05:00
Josh Brower
afa98fa147
update artifacts URL automatically
2024-01-28 14:20:52 -05:00
Josh Brower
1847e5c3c0
Enable nginx on Fleet Node
2024-01-28 11:37:18 -05:00
Josh Brower
cfc33b1a34
Sync Elastic Agent Artifacts
2024-01-28 10:12:25 -05:00
weslambert
dc5ea89255
Merge pull request #12260 from Security-Onion-Solutions/fix/endpoint_diagnostic
...
Add template for endpoint.diagnostic.collection
2024-01-26 16:13:30 -05:00
reyesj2
c4301d7cc1
Soup script update locations
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:51:06 -05:00
reyesj2
91c7b8144d
soup logic
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:43:42 -05:00
reyesj2
2e026b637d
Update soup to retry modified salt command on failure to update soup scripts.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 11:36:33 -05:00
reyesj2
cd6e387bcb
remove --local from soup common.soup_scripts update.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-25 16:15:53 -05:00
Wes
12ab6338db
Add diagnostic
2024-01-25 20:16:52 +00:00
weslambert
cd54d4becb
Fix indent
2024-01-25 13:57:02 -05:00
Mike Reeves
762a3bea17
Defaults and Annotations
2024-01-25 09:59:26 -05:00
weslambert
5f1c76f6ec
endpoint.diagnostic.collection
2024-01-25 09:46:25 -05:00
weslambert
d2d70d1c5b
Merge pull request #12250 from Security-Onion-Solutions/fix/scan_pe_flags
...
Fix PE Flags
2024-01-24 14:29:23 -05:00
Jason Ertel
e53030feef
Merge pull request #12248 from Security-Onion-Solutions/jertel/pfeat
...
standardize feature names
2024-01-24 12:12:16 -05:00
Jason Ertel
9f17bd2255
lks/fps
2024-01-24 11:17:32 -05:00
Wes
8426aad56d
Text mapping for scan.pe.flags
2024-01-24 15:10:42 +00:00
Wes
d23d367058
Make scan.pe.flags a string
2024-01-24 15:08:38 +00:00
weslambert
cbdaf2e9a1
Merge pull request #12242 from Security-Onion-Solutions/upgrade/strelka_0.24.01.18
...
Fix quote
2024-01-23 14:02:35 -05:00
weslambert
4d7af21dd5
Fix quote
2024-01-23 13:55:37 -05:00
weslambert
8348506acc
Merge pull request #12240 from Security-Onion-Solutions/upgrade/strelka_0.24.01.18
...
UPGRADE: Strelka 0.24.01.18
2024-01-23 13:50:15 -05:00
weslambert
1698d95efe
Use PLACEHOLDER for key values
2024-01-23 13:45:26 -05:00
weslambert
b1052ddcce
Merge pull request #12241 from Security-Onion-Solutions/fix/leak_test
...
Exclude specific Strelka key values
2024-01-23 13:43:18 -05:00
weslambert
0cb36bb0aa
Exclude StrelkaHexDump and PLACEHOLDER values
2024-01-23 13:39:59 -05:00
weslambert
0ccdfcb07c
Exclude only offset_meta_key
2024-01-23 13:11:43 -05:00
weslambert
63ba97306c
Exclude Strelka defaults
2024-01-23 13:05:58 -05:00
weslambert
72319e33db
Avoid leak test triggering
2024-01-23 12:38:09 -05:00
weslambert
34bb37e415
Merge pull request #12227 from Security-Onion-Solutions/feature/rita_logs
...
RITA Logs
2024-01-23 12:32:32 -05:00
Wes
3bcb0bc132
Update defaults
2024-01-23 17:18:54 +00:00
Jorge Reyes
d25a2d4c30
Merge pull request #12230 from Security-Onion-Solutions/reyesj2-patch-sl
...
Handle non-zero
2024-01-23 08:31:48 -05:00
reyesj2
350b0df3bf
Handle non-zero
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-22 22:48:15 -05:00
Wes
5542db0aac
Leave package version null
2024-01-22 21:07:46 +00:00
Wes
b08db3e05a
Add RITA policy
2024-01-22 20:16:43 +00:00
Wes
80a3942245
Rename RITA pipelines
2024-01-22 20:15:48 +00:00
weslambert
de6151fbe2
Merge pull request #12221 from Security-Onion-Solutions/feature/additional_integrations_4
...
Additional integrations #4 - Part 1
2024-01-19 17:32:37 -05:00
Wes
7118cc8dee
Add additional integration SOC configuration
2024-01-19 22:04:07 +00:00
Wes
05aa8b013a
Add additional integration to templates
2024-01-19 22:02:39 +00:00
Wes
d0457cb61e
Add additional integrations to defaults
2024-01-19 22:00:38 +00:00
Jorge Reyes
c2b44985c7
Merge pull request #12220 from Security-Onion-Solutions/reyesj2-patch-sl
...
Disable stigs setting/verifying umask is set to 077. Known issue with …
2024-01-19 16:06:10 -05:00
reyesj2
8f8c250ed3
Disable stigs setting/verifing umask is set to 077. Known issue with running SOUP
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 16:04:21 -05:00
Mike Reeves
6db32885eb
Merge pull request #12216 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update suricata.common
2024-01-19 13:56:48 -05:00
Mike Reeves
efe8cfda95
Update suricata.common
2024-01-19 13:39:28 -05:00
Mike Reeves
08486e279c
Update suricata.common
2024-01-19 13:36:43 -05:00
Jorge Reyes
40d0411441
Merge pull request #12214 from Security-Onion-Solutions/reyesj2-patch-sl
...
Add stig pillar dir during soup
2024-01-19 10:55:13 -05:00
reyesj2
2b6927da82
Add stig pillar dir during soup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 09:55:23 -05:00
Jorge Reyes
0786806f8f
Merge pull request #12213 from Security-Onion-Solutions/reyesj2-patch-sl
...
Update soup
2024-01-19 08:59:34 -05:00
reyesj2
ca4f2f1dd6
Add creation of additional pillars to soup for stig state
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 08:31:20 -05:00
Jorge Reyes
97e2721754
Merge pull request #12208 from Security-Onion-Solutions/reyesj2-patch-sl
2024-01-18 16:53:14 -05:00
reyesj2
07602076f1
Update telegraf script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 16:48:16 -05:00
reyesj2
caf4036dbf
Update features check
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 16:06:53 -05:00
Jorge Reyes
4a898619a6
Merge pull request #12206 from Security-Onion-Solutions/reyesj2-patch-sl
...
Remove need for stig script
2024-01-18 12:49:28 -05:00
reyesj2
65d46ea27d
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2-patch-sl
2024-01-18 12:24:35 -05:00
reyesj2
67445de4ee
Remove need for stig script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 12:24:01 -05:00
Jorge Reyes
6a8bf0b953
Merge pull request #12202 from Security-Onion-Solutions/reyesj2-patch-sl
...
Add stig state
2024-01-18 09:25:21 -05:00
weslambert
33d74098bd
Merge pull request #12201 from Security-Onion-Solutions/fix/suricata_ike
...
Add Suricata IKE pipeline
2024-01-17 16:50:19 -05:00
reyesj2
3173f9a26f
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2-patch-sl
2024-01-17 16:28:13 -05:00
reyesj2
df921892a3
Remove post scan from remediate log.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 16:23:20 -05:00
reyesj2
739feb25a4
Add telegraf script to import featuresdetected
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 15:55:00 -05:00
reyesj2
4e6924610d
Add additional status checks to so-common-status-check for telegraf
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 15:37:52 -05:00
Mike Reeves
880f2a3e1b
Merge pull request #12197 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-01-17 14:19:30 -05:00
Mike Reeves
958c827fd5
Update VERSION
2024-01-17 14:18:37 -05:00
Mike Reeves
aa294a7f41
Merge pull request #12195 from Security-Onion-Solutions/2.4/dev
...
2.4.40
2024-01-17 14:04:27 -05:00
Mike Reeves
049d0b53c2
Merge pull request #12194 from Security-Onion-Solutions/2.4.40
...
2.4.40
2024-01-17 12:02:14 -05:00
Mike Reeves
dff6d299a1
2.4.40
2024-01-17 11:59:27 -05:00
Wes
e70ce50912
Change description
2024-01-17 14:06:16 +00:00
Jason Ertel
38965ccab5
Merge pull request #12192 from Security-Onion-Solutions/needsrestarted
...
Needsrestarted
2024-01-16 18:49:22 -05:00
m0duspwnens
eeb249e00d
look for needs_restarted file
2024-01-16 17:22:09 -05:00
m0duspwnens
dff06cb085
changes for telegraf os.sh
2024-01-16 17:03:36 -05:00
m0duspwnens
8c1d1c95db
check needs_restarting rework
2024-01-16 17:02:27 -05:00
Wes
f6590ac0bf
Remove Suricata IKEv2 pipeline
2024-01-16 18:10:00 +00:00
Wes
ea64ce92d3
Add Suricata IKE pipeline
2024-01-16 18:09:46 +00:00
Wes
8a92b023b2
Add interface name
2024-01-16 18:09:16 +00:00
reyesj2
6cf0b365e6
Modify yum.conf.jinja to include localpkg_gpgcheck rather than modifying it with so-stig
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-15 21:30:31 -05:00
reyesj2
4bffd8e27c
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2-patch-sl
2024-01-15 21:19:37 -05:00
reyesj2
a73d78300a
Add initial stig state
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-15 21:17:17 -05:00
weslambert
790f5171a6
Merge pull request #12176 from Security-Onion-Solutions/fix/otx_pulses_template
...
FIX: OTX pulses template
2024-01-12 16:55:58 -05:00
weslambert
252c51dafb
Change order of names
2024-01-12 16:45:18 -05:00
weslambert
a07e6e1058
OTX pulses
2024-01-12 16:43:33 -05:00
weslambert
3f9678056d
OTX pulses template
2024-01-12 16:42:32 -05:00
weslambert
c895b6a274
Merge pull request #12173 from Security-Onion-Solutions/fix/endpoint_metrics_templates
...
Add endpoint metrics templates
2024-01-12 11:26:09 -05:00
Wes
418f41c7e4
Add SOC configuration for metrics
2024-01-12 15:03:18 +00:00
weslambert
05679e79fc
Merge pull request #12171 from Security-Onion-Solutions/2.4/dev
...
Merge 2.4 dev
2024-01-12 08:50:15 -05:00
Josh Brower
af3aa53612
Merge pull request #12170 from Security-Onion-Solutions/fix/nav
...
Remove old nav layers
2024-01-12 08:48:29 -05:00
Wes
5eae349938
Add endpoint metrics templates
2024-01-12 13:47:35 +00:00
Josh Brower
2f8ce33cf7
formatting
2024-01-12 08:47:09 -05:00
Josh Brower
61b2a76a09
Remove old nav layers-rev2
2024-01-12 08:46:23 -05:00
Josh Brower
b89b7cab59
Remove old nav layers
2024-01-12 08:37:32 -05:00
weslambert
71c5e34e03
Merge pull request #12164 from Security-Onion-Solutions/fix/optional_integration_pillar_merge
...
Make sure optional integration pillar values are merged with defaults
2024-01-11 16:14:46 -05:00
weslambert
880300d644
Move ELASTICFLEETMERGED import under allowed states
2024-01-11 14:58:21 -05:00
weslambert
f5b59cacec
Move ELASTICFLEETMERGED import
2024-01-11 14:56:01 -05:00
weslambert
ea5097f1b4
Add back curly brace
2024-01-11 14:51:01 -05:00
weslambert
cc66daba1a
Make sure optional integration pillar values are merged with defaults
2024-01-11 14:49:39 -05:00
Josh Brower
ea54aafa86
Merge pull request #12161 from Security-Onion-Solutions/fix/kibana-restart
...
Check Kibana API not Web
2024-01-11 12:32:19 -05:00
Josh Brower
03f140161c
Check Kibana API not Web
2024-01-11 12:30:23 -05:00
weslambert
7bdc306ad4
Merge pull request #12160 from Security-Onion-Solutions/feature/additional_integrations_3
...
Additional Supported Integrations #3
2024-01-11 12:26:14 -05:00
weslambert
5e1e685ce0
Exclude Cisco failed_attempts pipeline
2024-01-11 10:52:30 -05:00
Wes
c89d674a92
Add settings for integrations
2024-01-11 14:18:06 +00:00
Wes
9b1ddcacb4
Add additional templates for integrations
2024-01-11 14:00:09 +00:00
Wes
5703023008
Add additional packages
2024-01-11 13:59:38 +00:00
Josh Brower
59fe9a0587
Merge pull request #12156 from Security-Onion-Solutions/fix/navigator
...
Upgrade Navigator and fix Playbook layer
2024-01-11 08:48:34 -05:00
Josh Brower
b8e555e913
Upgrade Navigator and fix Playbook layer
2024-01-10 21:16:59 -05:00
Mike Reeves
16b15c786b
Merge pull request #12155 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2024-01-10 14:44:51 -05:00
Mike Reeves
3e13ea5c7a
Update soup
2024-01-10 14:36:49 -05:00
Josh Brower
9159eab9fd
Merge pull request #12151 from Security-Onion-Solutions/fix/so-playbook-reset
...
Fix reinstall & reset stability
2024-01-10 14:23:53 -05:00
Mike Reeves
0519812866
Merge pull request #12154 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-functions
2024-01-10 14:21:49 -05:00
Mike Reeves
fc2f02c0a0
Update so-functions
2024-01-10 14:19:47 -05:00
Mike Reeves
1e3a00a833
Update so-functions
2024-01-10 14:16:55 -05:00
Josh Brower
f21f0a9a96
Replace sed for so-yaml
2024-01-10 11:15:51 -05:00
Josh Brower
6ff764e6a1
refactor for reinstall stability
2024-01-10 10:22:50 -05:00
Jason Ertel
f5568995ac
Merge pull request #12149 from Security-Onion-Solutions/jertel/logs
...
exempt transient license check errors
2024-01-10 09:12:46 -05:00
Jason Ertel
47eea80d03
exempt transient license check errors
2024-01-10 09:07:17 -05:00
Josh Patterson
0b919ff0fa
Merge pull request #12144 from Security-Onion-Solutions/salt3006.5
...
Salt3006.5
2024-01-09 12:09:36 -05:00
m0duspwnens
c9f2038990
remove outdated comment
2024-01-09 11:36:44 -05:00
Josh Brower
bf05efa59f
Merge pull request #12141 from Security-Onion-Solutions/fix/fleet-reset
...
Fix/fleet reset
2024-01-09 10:38:07 -05:00
Josh Brower
b058bc8c05
Move to non-destructive
2024-01-09 10:22:43 -05:00
Josh Brower
7ddda03ee9
Merge pull request #12138 from Security-Onion-Solutions/fix/fim
...
Fix/fim
2024-01-09 08:26:55 -05:00
Josh Brower
5513e74807
comma
2024-01-09 08:12:33 -05:00
Josh Brower
31ee365a91
Fixup FIM events
2024-01-09 08:11:05 -05:00
m0duspwnens
f46ac6b9d7
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.5
2024-01-08 14:02:02 -05:00
m0duspwnens
31f314504e
salt 3006.5
2024-01-08 14:01:40 -05:00
Mike Reeves
0d76ddd49f
Merge pull request #12120 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-raid-status for SM based appliances
2024-01-05 10:27:21 -05:00
Mike Reeves
b0447a9af5
Update so-raid-status for SM based appliances
2024-01-05 09:28:04 -05:00
Josh Patterson
ef6eafeff1
Merge pull request #12118 from Security-Onion-Solutions/startupstates
...
enable startup_states: highstate on managers during setup and not wit…
2024-01-04 17:37:27 -05:00
m0duspwnens
ccfdafea0a
enable startup_states: highstate on managers during setup and not with salt
2024-01-04 16:24:48 -05:00
Josh Patterson
93cdac592e
Merge pull request #12116 from Security-Onion-Solutions/issue/12033
...
Issue/12033
2024-01-04 09:54:29 -05:00
m0duspwnens
2eaf0e812a
declare NEW_LIST outside jinja logic
2024-01-03 16:49:28 -05:00
Jorge Reyes
cab7c9d573
Merge pull request #12109 from Security-Onion-Solutions/reyesj2-patch-1
...
Add brasero to packages list for SOD
2024-01-03 14:45:07 -05:00
Jorge Reyes
8c792a8cfa
Add brasero to packages list for SOD
2024-01-03 12:17:57 -05:00
m0duspwnens
c091a0845c
allow user to disable elastic agent sending to manager
2024-01-03 11:48:16 -05:00
Mike Reeves
cf23723c54
Merge pull request #12102 from Security-Onion-Solutions/2.4/main
...
2.4/main
2024-01-02 11:18:07 -05:00
Mike Reeves
30bc02178a
Merge pull request #12100 from Security-Onion-Solutions/mkrtemp
...
2.4.30 hotfix
2024-01-02 11:16:13 -05:00
Mike Reeves
84e8013e46
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-01-02 10:31:14 -05:00
Mike Reeves
80ec4cecec
Merge pull request #12099 from Security-Onion-Solutions/2.4.30hf5
...
2.4.30 hotfix
2024-01-02 10:29:45 -05:00
Mike Reeves
82482d309a
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-01-02 10:09:13 -05:00
Mike Reeves
d437a2856a
2.4.30 hotfix
2024-01-02 09:48:45 -05:00
Josh Patterson
f0b44ad56c
Merge pull request #12095 from Security-Onion-Solutions/startupstates
...
Change salt-minion startup_states
2024-01-02 09:18:21 -05:00
Jason Ertel
cffc3353bc
Merge pull request #12090 from Security-Onion-Solutions/jertel/lasths
...
show last highstate date/time on grid metrics screen; expose maxUploa…
2023-12-29 14:51:09 -05:00
Jason Ertel
e075d07f5c
show last highstate date/time on grid metrics screen; expose maxUploadSize and staleMetricsMs settings on config screen
2023-12-29 11:38:42 -05:00
Jason Ertel
fe8f57c43b
Merge pull request #12071 from Security-Onion-Solutions/jertel/influxerr
...
exclude transient influxdb error
2023-12-22 07:22:45 -05:00
Jason Ertel
3456de3a30
exclude transient influxdb error
2023-12-22 07:16:45 -05:00
Jason Ertel
14767dd8b5
Merge pull request #12067 from Security-Onion-Solutions/jertel/fixcurator
...
only run the file.absent state if there are files to delete
2023-12-21 09:41:46 -05:00
Jason Ertel
8189f46a03
only run the file.absent state if there are files to delete
2023-12-21 09:36:47 -05:00
weslambert
cfb5c1c9d2
Merge pull request #12063 from Security-Onion-Solutions/fix/curator_log_check
...
Ignore Curator logs
2023-12-20 17:47:17 -05:00
weslambert
244968ce23
Remove unnecessary blank lines
2023-12-20 17:30:15 -05:00
weslambert
65f89b22b2
Ignore Curator logs
2023-12-20 17:28:55 -05:00
weslambert
7684aadb87
Merge pull request #12062 from Security-Onion-Solutions/fix/curator_remove
...
Curator Remove Changes
2023-12-20 15:16:47 -05:00
Wes
188744357f
Remove post since function doesn't exist
2023-12-20 19:14:14 +00:00
Wes
4baf4657f6
Curator cleanup
2023-12-20 19:10:22 +00:00
Wes
1006710226
Change Curator disable config
2023-12-20 18:26:27 +00:00
weslambert
cd661027a6
Remove post for 2.4.40
2023-12-20 12:23:20 -05:00
m0duspwnens
28fdf15304
remove comment
2023-12-19 16:37:32 -05:00
Mike Reeves
90edf7e8f1
Merge pull request #12053 from Security-Onion-Solutions/2.4/main
...
2.4/main
2023-12-19 14:40:21 -05:00
Mike Reeves
552e4c0d1c
Merge pull request #12050 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-12-19 14:37:35 -05:00
weslambert
ba2c51bee2
Merge pull request #12052 from Security-Onion-Solutions/fix/analyzer_images
...
Fix analyzer images
2023-12-19 14:30:19 -05:00
m0duspwnens
7b9ac7ae6d
remove checkin_at_boot function
2023-12-19 14:05:19 -05:00
Wes
62708ac97d
Add new image
2023-12-19 18:58:17 +00:00
Wes
f8fdc6d14e
Remove old image
2023-12-19 18:57:54 +00:00
Mike Reeves
72fbf386eb
Merge pull request #12051 from Security-Onion-Solutions/jertel/hotfixm
...
Jertel/hotfixm
2023-12-19 13:48:21 -05:00
Wes
15773bae34
Fix analyzer image links
2023-12-19 18:42:59 +00:00
Jason Ertel
ce8a774129
Merge branch '2.4/main' into jertel/hotfixm
2023-12-19 13:42:13 -05:00
Wes
c06de33318
Test EchoTrail image
2023-12-19 18:36:55 +00:00
Wes
41dc9df7cd
Add images for analyzers
2023-12-19 18:35:10 +00:00
Mike Reeves
cb956fb399
Merge pull request #12049 from Security-Onion-Solutions/2.4.30hf4
...
2.4.30 hotfix
2023-12-19 13:10:51 -05:00
Mike Reeves
5c34cdd943
2.4.30 hotfix
2023-12-19 13:07:25 -05:00
Doug Burks
5e8613f38b
Merge pull request #12048 from Security-Onion-Solutions/2.4/improve-filterlog-parser
...
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-19 12:57:37 -05:00
weslambert
69472e70b4
Merge pull request #12003 from HoangLongVu/2.4/dev
...
2.4/dev Analyzers for Threatfox, MalwareBazaar, Echotrail, Elasticsearch
2023-12-19 12:09:16 -05:00
m0duspwnens
090f3a3e02
only run if in file
2023-12-19 12:08:17 -05:00
Wes
85242651b2
Add Sublime image to assets and change link
2023-12-19 15:49:57 +00:00
Jason Ertel
80cd9920b2
Merge pull request #12047 from Security-Onion-Solutions/jertel/eslogerror
...
exclude log false positives
2023-12-19 10:49:42 -05:00
Jason Ertel
ca21e32d83
log false positives
2023-12-19 10:47:39 -05:00
Wes
6ab12ceec4
Add Elasticsearch image to assets and change link
2023-12-19 15:46:02 +00:00
Wes
bfcf7d4668
Add EchoTrail image to assets and change link
2023-12-19 15:42:23 +00:00
Wes
4a23832267
Don't require advanced options for required values
2023-12-19 15:14:33 +00:00
m0duspwnens
b3be999aea
dont enable startup_states during setup. use salt to add it
2023-12-19 09:00:32 -05:00
Doug Burks
ab5de4c104
update soc defaults.yaml
2023-12-19 07:27:07 -05:00
Wes
614589153b
Update Malwarebazaar test and comply with flake8
2023-12-19 02:57:35 +00:00
Ryan Hoang
5e715036fb
Update malwarebazaar_test.py
2023-12-18 19:54:14 -05:00
Ryan Hoang
748a67314f
Update malwarebazaar_test.py
2023-12-18 19:27:13 -05:00
Ryan Hoang
a561f8c783
Update malwarebazaar_test.py Removed Whitespace
2023-12-18 19:18:26 -05:00
Elijah Gibson
fb5ee6b9e9
Flake8 linting + isInJson tail recursion update
2023-12-18 15:58:16 -05:00
Elijah Gibson
7d6f8d922b
Update malwarebazaar_test.py
...
Flake8 linting
2023-12-18 15:57:41 -05:00
Elijah Gibson
f86adf8053
Merge branch 'Security-Onion-Solutions:2.4/dev' into 2.4/dev
2023-12-18 15:57:00 -05:00
Wes
8f6b1a07b7
Don't use soup for removing Curator files
2023-12-18 20:54:24 +00:00
Wes
6c92672566
Remove Curator configuration and scripts
2023-12-18 20:53:56 +00:00
Wes
aba5893965
Add disabled state for Curator
2023-12-18 20:50:49 +00:00
Josh Patterson
866c9988a0
Merge pull request #12037 from Security-Onion-Solutions/fix/receiver
...
Fix receivers
https://github.com/Security-Onion-Solutions/securityonion/issues/12038
2023-12-18 13:56:33 -05:00
Josh Patterson
f032ff40a2
Merge branch '2.4/dev' into fix/receiver
2023-12-18 13:55:23 -05:00
Semphorin
03421c1bcd
added isInJson tests
2023-12-18 13:54:38 -05:00
Doug Burks
4d8661d2e0
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-18 13:38:04 -05:00
Doug Burks
6a1073b616
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-18 12:57:40 -05:00
Wes
6a4e05d60f
Remove control characters
2023-12-15 20:53:51 +00:00
Wes
981f3642a0
Update tests
2023-12-15 20:53:19 +00:00
m0duspwnens
33a9ac5701
use logstash nodes for logstash extra_hosts
2023-12-15 15:42:49 -05:00
Wes
020472085b
ThreatFox test
2023-12-15 15:16:44 +00:00
Wes
8aaeee20b9
Fix import
2023-12-15 14:40:25 +00:00
Wes
e32de6893b
Remove control characters
2023-12-15 14:27:27 +00:00
Wes
f05eb742dd
Fix patch
2023-12-15 14:26:33 +00:00
Wes
cd3a661dd6
Set malwarebazaar.py to be executable
2023-12-15 14:17:33 +00:00
weslambert
55c957170d
Reduce complexity
2023-12-15 09:00:31 -05:00
Jackson
d41daa37f1
malwarebazaar
2023-12-15 03:00:43 -05:00
Jackson
b59896bb47
ThreatFox and EchoTrail
2023-12-15 02:47:54 -05:00
Jackson
c59a6516fc
fix Elasticsearch lint
2023-12-15 02:34:45 -05:00
Doug Burks
88684a6c19
Merge pull request #12023 from Security-Onion-Solutions/2.4/fix-firewall-queries
...
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-14 14:56:42 -05:00
weslambert
d0d671a828
Merge pull request #12020 from Security-Onion-Solutions/fix/integration_force
...
Add force option to integrations
2023-12-14 13:44:32 -05:00
Doug Burks
8779fb8cbc
Update defaults.yaml
2023-12-14 13:30:52 -05:00
Doug Burks
042e5ae9f0
https://github.com/Security-Onion-Solutions/securityonion/issues/12021
2023-12-14 12:46:28 -05:00
Josh Patterson
45f50cc121
Merge pull request #12019 from Security-Onion-Solutions/fix/extrahosts
...
fix extra_hosts
2023-12-14 12:03:07 -05:00
Wes
22fcccef1c
Add force option
2023-12-14 16:53:19 +00:00
Jackson
977081b6e7
update Readme.md
2023-12-14 10:37:04 -05:00
m0duspwnens
3dbf97944d
fix extra_hosts. https://github.com/Security-Onion-Solutions/securityonion/issues/12015
2023-12-14 10:26:29 -05:00
m0duspwnens
03b2a7d2de
change 9805 pipeline to send to self. fix extra_hosts for logstash
2023-12-14 10:01:03 -05:00
Jason Ertel
395da2cca0
Merge pull request #12012 from Security-Onion-Solutions/jertel/eslogerror
...
more log false alarms
2023-12-14 08:59:12 -05:00
Jason Ertel
997d323763
more log false alarms
2023-12-14 08:55:18 -05:00
Elijah Gibson
d5edf57ccb
Update elasticsearch.py
2023-12-13 23:04:44 -05:00
Elijah Gibson
94b9089b79
Update elasticsearch.json
2023-12-13 23:03:42 -05:00
Jackson
81e4fe78e7
pushing everything at once
2023-12-13 13:45:48 -05:00
weslambert
5d3f2298b6
Merge pull request #12000 from Security-Onion-Solutions/feature/additional_integrations
...
Additional Integrations #2
2023-12-13 13:23:34 -05:00
Doug Burks
b17e4006a1
Merge pull request #12001 from Security-Onion-Solutions/2.4/update-clear-scripts
...
FIX: Update clear scripts #11991
2023-12-13 12:01:11 -05:00
weslambert
8cf5d9c1a6
Annotations
2023-12-13 11:55:40 -05:00
weslambert
cdac2bfa16
Add Anomali, Cybersixgill, Snort, and ThreatQuotient
2023-12-13 11:03:25 -05:00
weslambert
b0a69d30c9
Add Anomali, Cybersixgill, Snort, and ThreatQuotient packages
2023-12-13 10:44:03 -05:00
Jason Ertel
196d59869a
Merge pull request #11998 from Security-Onion-Solutions/kilo
...
upgrade cla action
2023-12-13 10:18:39 -05:00
Jason Ertel
c0ab8f24e9
upgrade cla action
2023-12-13 10:10:51 -05:00
Jason Ertel
bd26a52227
upgrade cla action
2023-12-13 10:10:23 -05:00
Jason Ertel
03279732b7
upgrade cla action
2023-12-13 10:09:36 -05:00
Doug Burks
2c4d0a0d71
Update so-elastic-fleet-reset
2023-12-12 16:37:50 -05:00
Doug Burks
d49d13289e
Update so-elastic-clear
2023-12-12 16:37:06 -05:00
Doug Burks
aaf60bea87
Update so-nsm-clear
2023-12-12 16:30:17 -05:00
weslambert
e95932f28c
Merge pull request #11990 from Security-Onion-Solutions/fix/remove_curator
...
Remove Curator
2023-12-12 12:31:16 -05:00
Wes
bbe091fa14
Fix accidental change
2023-12-12 15:08:47 +00:00
Wes
54c3167b10
Delete data streams when necessary
2023-12-12 05:25:50 +00:00
Wes
b1721b6467
Fix directory
2023-12-11 21:43:25 +00:00
Jason Ertel
214404265a
Merge pull request #11981 from Security-Onion-Solutions/jertel/importlogs
...
fix import stats
2023-12-11 14:54:29 -05:00
Jason Ertel
25c39540c8
fix import stats
2023-12-11 14:48:46 -05:00
Wes
f7373ed79c
Stop Curator, remove scripts and status
2023-12-11 19:20:52 +00:00
Wes
d203aec44a
Remove Curator
2023-12-08 19:37:06 +00:00
Jason Ertel
be8ed1e1d8
Merge pull request #11970 from Security-Onion-Solutions/jertel/hfm
...
grid page enhancements
2023-12-08 09:56:39 -05:00
Jason Ertel
a732985351
grid page enhancements
2023-12-08 08:38:42 -05:00
Jason Ertel
98947f3906
grid page enhancements
2023-12-08 08:37:42 -05:00
weslambert
b80d7fd610
Merge pull request #11967 from Security-Onion-Solutions/fix/close_remove
...
Remove Curator close configuration
2023-12-07 15:05:38 -05:00
Wes
849e9e14ad
Change soup to remove delete actions and run post_to_2.4.40
2023-12-07 16:49:44 +00:00
Wes
0ebc8c7beb
Change path
2023-12-07 15:17:51 +00:00
Wes
e0801282eb
Remove files
2023-12-07 14:07:26 +00:00
Wes
bdf4b2c68d
Remove settings
2023-12-07 14:03:45 +00:00
Wes
e49fc0dd27
Remove more settings
2023-12-07 14:03:09 +00:00
Wes
f52da4a933
Remove close settings and cron
2023-12-07 13:58:39 +00:00
Wes
f38758a9c7
Remove close scripts
2023-12-07 13:52:25 +00:00
Wes
1ac3a2d2f1
Remove delete files and allow deletion of indices managed by ILM
2023-12-07 13:51:24 +00:00
Wes
965ced94c4
Remove close files
2023-12-07 13:48:08 +00:00
Doug Burks
bc3634b13d
Merge pull request #11960 from Security-Onion-Solutions/2.4/fix-config-links
...
FIX: Documentation links under SOC - Administration - Configuration need updating #11828
2023-12-06 16:04:11 -05:00
Doug Burks
5c50060857
add description for soc_patch.yaml
2023-12-06 15:51:00 -05:00
Doug Burks
00fa75869b
add description for http_x_skin
2023-12-06 15:44:36 -05:00
Doug Burks
ab0e6f9bec
update broken help links in SOC Config
2023-12-06 14:35:51 -05:00
Doug Burks
213cdb479d
Update soc_manager.yaml
2023-12-06 14:19:15 -05:00
Mike Reeves
8da96e93c8
Merge pull request #11957 from Security-Onion-Solutions/mergeback
...
Merge Main into Dev
2023-12-06 13:40:30 -05:00
Mike Reeves
0160cae7d7
Merge branch '2.4/dev' into mergeback
2023-12-06 13:38:53 -05:00
Mike Reeves
d7bf52de76
Merge pull request #11918 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-12-06 13:31:33 -05:00
weslambert
fea5a3026d
Merge pull request #11955 from Security-Onion-Solutions/fix/sublime_analyzer_documentation
...
Sublime Analyzer Documentation
2023-12-06 13:27:03 -05:00
weslambert
7f21bee0d4
Add README
2023-12-06 13:14:17 -05:00
weslambert
ade3a46a9a
Add LocalFile link
2023-12-06 12:58:44 -05:00
weslambert
e6a2e49d37
Add Sublime Platform
2023-12-06 12:57:59 -05:00
weslambert
1438913f6a
Merge pull request #11954 from Security-Onion-Solutions/fix/sublime_analyzer_indentation
...
Fix indentation for rule_results
2023-12-06 12:50:44 -05:00
Wes
51fa4922b9
Fix indentation for rule_results
2023-12-06 17:37:07 +00:00
Mike Reeves
b878728882
Merge pull request #11951 from Security-Onion-Solutions/2.4.30hf3
...
2.4.30 hotfix
2023-12-06 08:36:13 -05:00
Mike Reeves
386e9214fc
2.4.30 hotfix
2023-12-06 08:34:46 -05:00
weslambert
4becf3e20f
Merge pull request #11950 from Security-Onion-Solutions/fix/eml_observable
...
Add eml observable type
2023-12-06 08:30:27 -05:00
weslambert
0334ef9677
Add eml observable type
2023-12-05 19:10:16 -05:00
weslambert
0537e1b3f6
Merge pull request #11945 from Security-Onion-Solutions/feature/sublime_platform_analyzer
...
Sublime Platform Analyzer
2023-12-05 16:51:03 -05:00
Wes
6fff05b444
Remove pytest.ini
2023-12-05 20:14:17 +00:00
Wes
01a37df7fc
Add extra line
2023-12-05 20:02:12 +00:00
Wes
b3e78c9cc3
Update live flow option
2023-12-05 19:55:23 +00:00
Wes
d871b61150
Change author
2023-12-05 18:36:25 +00:00
Wes
b2536a64d8
Remove extra space
2023-12-05 18:33:00 +00:00
Wes
3d1eecfad6
Add Sublime Platform analyzer
2023-12-05 18:31:50 +00:00
Mike Reeves
8eaa07a186
Merge pull request #11942 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2023-12-05 11:26:42 -05:00
Mike Reeves
9446b750c0
Update soup
2023-12-05 11:25:25 -05:00
Mike Reeves
fdd4173632
Update soup
2023-12-05 11:20:56 -05:00
Mike Reeves
b7227e15eb
Merge pull request #11939 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2023-12-05 10:26:56 -05:00
Mike Reeves
90d9e5b927
Update soup
2023-12-05 10:24:31 -05:00
Mike Reeves
802bf9ce27
Merge pull request #11931 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-12-04 14:00:40 -05:00
Mike Reeves
0b6ba6d2f2
Update soup
2023-12-04 13:51:12 -05:00
Mike Reeves
55a8b1064d
Update soup
2023-12-04 13:36:04 -05:00
Josh Patterson
11a3e12e94
Merge pull request #11929 from Security-Onion-Solutions/hf_soup
...
avoid exiting salt when ca state applied in post for 2.4.30
2023-12-04 11:46:27 -05:00
m0duspwnens
38868af08a
avoid exiting salt when ca state applied in post for 2.4.30
2023-12-04 10:11:38 -05:00
Josh Patterson
ace5dff351
Merge pull request #11923 from Security-Onion-Solutions/hf_soup
...
move wait_for_salt_minion for hotfix
2023-12-01 15:37:35 -05:00
m0duspwnens
265cde5296
move wait_for_salt_minion for hotfix
2023-12-01 15:31:15 -05:00
weslambert
55052c4811
Merge pull request #11919 from Security-Onion-Solutions/fix/remove_curator_changes
...
Remove Curator Changes
2023-12-01 11:15:23 -05:00
Wes
e36044e164
Remove close changes
2023-12-01 16:10:56 +00:00
Wes
6fa4a69753
Remove action changes
2023-12-01 16:10:07 +00:00
Doug Burks
4fc3c852a1
Merge pull request #11890 from chateaulav/chateaulav-import-evtx-logs-11889
...
Update import-evtx-logs.json
2023-11-30 13:57:59 -05:00
weslambert
32b03f514e
Merge pull request #11907 from Security-Onion-Solutions/fix/curator_close
...
Curator close fixes
2023-11-30 11:05:49 -05:00
Wes
a605c5c62c
Ensure indices managed by ILM can be managed by Curator
2023-11-29 22:13:20 +00:00
Wes
2368e8b793
Fix action file names
2023-11-29 22:06:11 +00:00
weslambert
317b6cb614
Merge pull request #11902 from Security-Onion-Solutions/fix/hotfix_version
...
Update HOTFIX
2023-11-29 17:03:59 -05:00
weslambert
a6d20bdc71
Update HOTFIX
2023-11-29 17:01:29 -05:00
reyesj2
8cf29682bb
Update to merge in 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-11-29 13:41:23 -05:00
reyesj2
86dc7cc804
Kafka init
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-11-29 13:34:25 -05:00
Doug Burks
93fb10de86
Merge pull request #11897 from Security-Onion-Solutions/2.4/nids-rule-reference
...
FIX: Update NIDS rule.reference in common.nids pipeline #11846
2023-11-29 12:19:12 -05:00
weslambert
1a4d009b7f
Merge pull request #11896 from Security-Onion-Solutions/feature/elastic_certificate_fingerprints
...
Add certificate fingerprints
2023-11-29 12:07:50 -05:00
weslambert
9d63a47792
Certificate hash
2023-11-29 12:01:43 -05:00
weslambert
7001e90667
Client and server fingerprints
2023-11-29 12:00:46 -05:00
weslambert
a0573212c0
Merge pull request #11891 from Security-Onion-Solutions/fix/elastic_ignore_analyzer
...
Ignore analyzer log
2023-11-29 10:05:01 -05:00
weslambert
5f79644aef
Ignore analyzer log
2023-11-29 10:02:13 -05:00
Doug Burks
0603e96c08
FIX: Update NIDS rule.reference in common.nids pipeline #11846
2023-11-29 09:46:11 -05:00
Jonathan Race
ece3c367b5
Update import-evtx-logs.json
...
version updates to match 2.4 release pipelines
2023-11-29 09:20:37 -05:00
Jason Ertel
8953ffcc49
Merge pull request #11855 from Security-Onion-Solutions/jertel/hfm
...
Jertel/hfm
2023-11-21 16:43:28 -05:00
Jason Ertel
9ee3423b32
Merge branch '2.4/dev' into jertel/hfm
2023-11-21 16:42:50 -05:00
Jason Ertel
7d759a99fe
remove hotfix
2023-11-21 16:40:54 -05:00
Mike Reeves
d3802c1668
Merge pull request #11854 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-11-21 16:39:40 -05:00
Mike Reeves
874618d512
Merge pull request #11853 from Security-Onion-Solutions/2.4.30hf2
...
2.4.30 hotfix
2023-11-21 14:32:53 -05:00
Mike Reeves
fa9032b323
2.4.30 hotfix
2023-11-21 14:28:23 -05:00
Mike Reeves
17942676c6
Merge pull request #11844 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soup
2023-11-21 10:32:24 -05:00
Mike Reeves
458c6de39d
Update soup
2023-11-21 10:30:21 -05:00
Mike Reeves
a39f696a34
Merge pull request #11843 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2023-11-21 10:19:21 -05:00
Mike Reeves
9aa193af3b
Update soup
2023-11-21 10:18:02 -05:00
Mike Reeves
3f1f256748
Merge pull request #11842 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2023-11-21 10:01:13 -05:00
Mike Reeves
c78ea0183f
Update HOTFIX
2023-11-21 09:59:51 -05:00
Mike Reeves
e9417dd437
Merge pull request #11841 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-11-21 09:56:45 -05:00
Mike Reeves
14b5aa476e
Update soup
2023-11-21 09:55:44 -05:00
Jason Ertel
861e850f9a
Merge pull request #11835 from Security-Onion-Solutions/jertel/yaml
...
add support for nested keys
2023-11-20 16:33:17 -05:00
Jason Ertel
6356a0bf95
add support for nested keys
2023-11-20 16:18:30 -05:00
Jason Ertel
f31e288005
Merge pull request #11832 from Security-Onion-Solutions/jertel/hfm
...
Merge hoftix back to 2.4/dev
2023-11-20 15:32:40 -05:00
Jason Ertel
b2ea7138f3
remove hotfix
2023-11-20 15:28:56 -05:00
Jason Ertel
f29a91ea4c
Merge branch '2.4/main' into jertel/hfm
2023-11-20 15:28:27 -05:00
Mike Reeves
4b0033c60a
Merge pull request #11827 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix 2.4.30
2023-11-20 15:26:16 -05:00
Mike Reeves
c20004c210
Merge pull request #11826 from Security-Onion-Solutions/2.4.30hf
...
2.4.30 hotfix
2023-11-20 11:35:11 -05:00
Mike Reeves
45dc1ce036
2.4.30 hotfix
2023-11-20 11:32:21 -05:00
Jason Ertel
0cc10fbf80
Merge pull request #11823 from Security-Onion-Solutions/jertel/igwarn
...
ignore libwbclient upgrade warning
2023-11-19 19:46:19 -05:00
Jason Ertel
e71ee97717
ignore libwbclient upgrade warning
2023-11-19 19:03:23 -05:00
Mike Reeves
77d0a7277a
Merge pull request #11818 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-11-17 17:07:54 -05:00
Mike Reeves
2ae87de409
Merge branch 'hotfix/2.4.30' into TOoSmOotH-patch-2
2023-11-17 17:05:11 -05:00
Josh Brower
a69a65c44f
Merge pull request #11819 from Security-Onion-Solutions/hftesting
...
Remove state file
2023-11-17 16:54:08 -05:00
Mike Reeves
d89beefc8c
Update soup
2023-11-17 16:53:11 -05:00
Josh Brower
9c371fc374
Remove state file
2023-11-17 16:52:34 -05:00
Mike Reeves
4fb9cce41c
Update signing_policies.conf
2023-11-17 16:38:50 -05:00
Mike Reeves
e226efa799
Update soup
2023-11-17 16:35:12 -05:00
Josh Brower
82a41894f3
Merge pull request #11817 from Security-Onion-Solutions/hftesting
...
Hftesting
2023-11-17 13:12:06 -05:00
Josh Brower
7aadc3851f
Remove state file
2023-11-17 13:08:15 -05:00
Josh Brower
ca1498fca1
Dont update Defend Integration
2023-11-17 12:19:22 -05:00
Josh Brower
15fc4f2655
Merge pull request #11815 from Security-Onion-Solutions/hftesting
...
use updated code
2023-11-17 11:23:45 -05:00
Josh Brower
089a111ae8
use updated code
2023-11-17 11:20:13 -05:00
Josh Brower
33bd04b797
Merge pull request #11811 from Security-Onion-Solutions/hftesting
...
Move API check logic
2023-11-17 06:02:26 -05:00
Josh Brower
5920a14478
Move API check logic
2023-11-16 20:34:01 -05:00
Jason Ertel
67f116daed
Merge pull request #11809 from Security-Onion-Solutions/jertel/srtmp
...
improve timing of responses
2023-11-16 16:00:27 -05:00
Jason Ertel
c09e8f0d71
improve timing of responses
2023-11-16 15:58:48 -05:00
Jason Ertel
de99cda766
improve timing of responses
2023-11-16 15:51:17 -05:00
Josh Brower
3ede19a106
Merge pull request #11808 from Security-Onion-Solutions/2.4/defendhotfix2
...
Update HOTFIX
2023-11-16 15:25:24 -05:00
weslambert
b6e2df45c7
Update HOTFIX
2023-11-16 14:48:00 -05:00
Josh Brower
af98c8e2da
Merge pull request #11805 from Security-Onion-Solutions/2.4/defendhotfix2
...
.30 hotfix
2023-11-16 11:42:49 -05:00
Josh Brower
6b8e48c973
Remove highstate
2023-11-16 11:41:20 -05:00
Josh Brower
109ee55d8c
Add to pre for .30 soup
2023-11-16 11:37:38 -05:00
Josh Brower
ff8cd194f1
Make sure kibana API is up
2023-11-16 11:21:34 -05:00
Josh Brower
d5dd0d88ed
.30 hotfix
2023-11-16 10:58:23 -05:00
weslambert
46c5bf40e0
Merge pull request #11804 from Security-Onion-Solutions/fix/kibana_corrupt_integration
...
Discard corrupt integration
2023-11-16 10:49:39 -05:00
Wes
3ed7b36865
Discard corrupt integration
2023-11-16 15:45:38 +00:00
Jason Ertel
85649da2cb
Merge pull request #11792 from Security-Onion-Solutions/jertel/auto
...
avoid startup error
2023-11-14 15:42:26 -05:00
Jason Ertel
f7fa4d05fb
avoid startup error
2023-11-14 15:40:52 -05:00
Doug Burks
96b456cd76
Merge pull request #11785 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Hunt HTTP EXE query #11784
2023-11-14 10:03:46 -05:00
Doug Burks
4666b993e5
Update defaults.yaml
2023-11-14 09:58:45 -05:00
Mike Reeves
4fa6b265a0
Merge pull request #11778 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-11-13 15:38:53 -05:00
Mike Reeves
567e19e5d7
Update VERSION
2023-11-13 15:38:23 -05:00
Mike Reeves
f036623d55
Merge pull request #11777 from Security-Onion-Solutions/2.4/dev
...
2.4.30
2023-11-13 15:27:24 -05:00
Mike Reeves
1204ce96f3
Merge pull request #11776 from Security-Onion-Solutions/2.4.30
...
2.4.30
2023-11-13 13:13:29 -05:00
Mike Reeves
bc178a9784
2.4.30
2023-11-13 13:11:49 -05:00
Mike Reeves
c338daabce
Merge pull request #11769 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Update soup
2023-11-13 08:51:40 -05:00
Mike Reeves
fe7af49a82
Update soup
2023-11-13 08:37:46 -05:00
weslambert
aeb09b16db
Merge pull request #11760 from Security-Onion-Solutions/fix/elastic_packages
...
Add Elastic Agent package and upgrade packages when elasticfleet.packages list changes
2023-11-10 10:20:17 -05:00
weslambert
583ec5176e
Add package check
2023-11-10 10:15:52 -05:00
weslambert
4bb1dabb89
Add elastic_agent
2023-11-10 10:14:59 -05:00
Josh Brower
89c3d45abe
Merge pull request #11751 from Security-Onion-Solutions/2.4/fleetresetfix2
...
Remove unneeded datastreams
2023-11-09 15:04:02 -05:00
Josh Brower
551f7831de
Add more clarity to message
2023-11-09 15:01:56 -05:00
Josh Brower
193c9d202e
Remove unneeded datastreams
2023-11-09 14:30:00 -05:00
Josh Brower
b5912fc1e4
Merge pull request #11750 from Security-Onion-Solutions/2.4/defendpolicy
...
Upgrade Defend Integration policy
2023-11-09 12:48:57 -05:00
Josh Brower
33f538b73e
Upgrade Defend Integration policy
2023-11-09 11:52:06 -05:00
Josh Brower
d3ea5def69
Merge pull request #11747 from Security-Onion-Solutions/2.4/resetscriptfix
...
remove state file
2023-11-09 09:12:52 -05:00
Josh Brower
d1b6ef411b
remove state file
2023-11-09 09:01:57 -05:00
Jason Ertel
8ca825b9a1
Merge pull request #11745 from Security-Onion-Solutions/jertel/yaml
...
re-add source pkgs from accidental commit
2023-11-09 07:19:22 -05:00
Jason Ertel
209e237d0d
re-add source pkgs from accidental commit
2023-11-09 00:34:52 -05:00
Jason Ertel
325dceb01b
Merge pull request #11743 from Security-Onion-Solutions/fix/elastic_template_check
...
Additional fixes for index template check
2023-11-09 00:15:14 -05:00
weslambert
02baa18502
Add metrics
2023-11-08 22:41:24 -05:00
Jason Ertel
268dc03131
Merge pull request #11742 from Security-Onion-Solutions/jertel/yaml
...
add yaml helper script; refactor python testing
2023-11-08 21:06:04 -05:00
weslambert
e39edab00d
Exclude osquery and display failed name
2023-11-08 20:55:08 -05:00
weslambert
acb6e84248
Don't load index template if component template doesn't exist
2023-11-08 20:34:08 -05:00
Jason Ertel
9231c8d2f2
replace reset sed with new script
2023-11-08 19:17:32 -05:00
Jason Ertel
bc044fa2d5
more coverage
2023-11-08 18:42:06 -05:00
Jason Ertel
84b815c2ef
add yaml helper script; refactor python testing
2023-11-08 18:30:05 -05:00
Jason Ertel
1ab44a40d3
add yaml helper script; refactor python testing
2023-11-08 18:29:06 -05:00
Jason Ertel
9317e51f20
add yaml helper script; refactor python testing
2023-11-08 18:26:37 -05:00
Jason Ertel
33a8ef1568
add yaml helper script; refactor python testing
2023-11-08 18:24:23 -05:00
Josh Patterson
01e846ba22
Merge pull request #11741 from Security-Onion-Solutions/issue/11738
...
remove comments from BPFs
2023-11-08 15:25:02 -05:00
weslambert
9df3a8fc18
Merge pull request #11740 from Security-Onion-Solutions/fix/elastic_templates
...
Remove template files
2023-11-08 15:20:01 -05:00
weslambert
36098e6314
Remove template files
2023-11-08 14:32:58 -05:00
Jason Ertel
32079a7bce
Merge pull request #11734 from Security-Onion-Solutions/fix/elastic_scripts
...
Improve error handling and add retry logic
2023-11-08 12:19:00 -05:00
Jason Ertel
3701c1d847
ignore retry logging
2023-11-08 11:50:56 -05:00
m0duspwnens
f46aef1611
remove comments from BPFs
2023-11-08 11:23:19 -05:00
Jason Ertel
d256be3eb3
allow template loads to partially succeed only on the initial attempt
2023-11-08 10:32:11 -05:00
Wes
653fda124f
Check expected with retry
2023-11-08 13:02:17 +00:00
Wes
b46e86c39b
Extend index template loading to 60 attempts and a total of ~5 minutes
2023-11-08 02:29:09 +00:00
Wes
de9f9549af
Extend template loading to 24 attempts and a total of ~2 minutes
2023-11-07 23:55:03 +00:00
weslambert
749e22e4b9
Fix if statement
2023-11-07 17:29:38 -05:00
weslambert
69ec1987af
Fix if statement
2023-11-07 17:28:37 -05:00
Wes
570624da7e
Remove RETURN_CODE
2023-11-07 21:09:29 +00:00
Wes
7772657b4b
Remove RETURN_CODE
2023-11-07 21:06:35 +00:00
Jason Ertel
6d97667634
Merge branch '2.4/dev' into kilo
2023-11-07 15:59:52 -05:00
Wes
1676c84f9c
Use the retry function so-elasticsearch-query
2023-11-07 19:56:50 +00:00
Jason Ertel
e665899e4d
Merge pull request #11735 from Security-Onion-Solutions/fix/elastic_agent_template
...
Change pipeline to 1.13.1
2023-11-07 14:11:47 -05:00
weslambert
1dcca0bfd3
Change pipeline to 1.13.1
2023-11-07 12:17:51 -05:00
Wes
0b4a246ddb
State file changes and retry logic
2023-11-07 16:44:42 +00:00
weslambert
f97dc70fcb
Merge pull request #11732 from Security-Onion-Solutions/fix/elastic_agent_template
...
Change pipeline to 1.8.0
2023-11-07 09:08:25 -05:00
weslambert
cce80eb2fb
Change pipeline to 1.8.0
2023-11-07 09:02:48 -05:00
Jason Ertel
2f95512199
Merge branch '2.4/dev' into kilo
2023-11-06 11:27:58 -05:00
Jason Ertel
b008661b6b
Merge pull request #11726 from Security-Onion-Solutions/jertel/auto
...
improve verbosity of setup logs
2023-11-06 11:27:33 -05:00
Jason Ertel
b99c7ce76e
improve verbosity of setup logs
2023-11-06 11:22:35 -05:00
Wes
c30a0d5b5b
Better error handling and state file management
2023-11-06 14:29:01 +00:00
Wes
74eda68d84
Exit if unable to communicate with Elasticsearch
2023-11-06 13:16:35 +00:00
Josh Brower
ef1dfc3152
Merge pull request #11722 from Security-Onion-Solutions/2.4/packageupgrade
...
Set execute permissions
2023-11-06 08:06:13 -05:00
Josh Brower
f6cd35e143
Set execute permissions
2023-11-06 08:03:31 -05:00
Jason Ertel
d010af9a24
Merge pull request #11718 from Security-Onion-Solutions/jertel/auto
...
disregard false positives
2023-11-04 16:32:02 -04:00
Jason Ertel
7a0b21647f
disregard false positives
2023-11-04 10:05:37 -04:00
Josh Patterson
610374816d
Merge pull request #11714 from Security-Onion-Solutions/change/so-minion
...
apply es and soc states to manager if new search or hn are added
2023-11-03 16:43:16 -04:00
Josh Brower
3ff74948d8
Merge pull request #11713 from Security-Onion-Solutions/2.4/agentupdate
...
Upgrade Elastic Agent
2023-11-03 15:23:55 -04:00
Josh Brower
0086c24729
Upgrade Elastic Agent
2023-11-03 15:21:06 -04:00
m0duspwnens
9d2b84818f
apply es and soc states to manager if new search or hn are added
2023-11-03 15:00:13 -04:00
Mike Reeves
b74aa32deb
Merge pull request #11712 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soc_elasticsearch.yaml
2023-11-03 11:33:00 -04:00
Mike Reeves
3d8663db66
Update soc_elasticsearch.yaml
2023-11-03 11:29:45 -04:00
Josh Brower
65978a340f
Merge pull request #11710 from Security-Onion-Solutions/2.4/navlayerfix
...
exit 0
2023-11-03 11:07:10 -04:00
Josh Brower
a8b0e41dbe
exit 0
2023-11-03 11:04:52 -04:00
Jason Ertel
1bc4b44be7
Merge pull request #11709 from Security-Onion-Solutions/jertel/auto
...
ignore malformed open canary log lines
2023-11-03 09:17:23 -04:00
Jason Ertel
1a3d4a2051
ignore malformed open canary log lines
2023-11-03 09:14:26 -04:00
Josh Brower
9d639df882
Merge pull request #11708 from Security-Onion-Solutions/2.4/metadatafix2
...
Dont overwrite metadata
2023-11-03 08:47:48 -04:00
Josh Brower
8c7767b381
Dont overwrite metadata
2023-11-03 08:41:33 -04:00
weslambert
96582add5e
Merge pull request #11704 from Security-Onion-Solutions/feature/integrations_checkpoint_vsphere
...
Checkpoint and VSphere Integrations
2023-11-02 17:17:03 -04:00
Wes
5bfef3f527
Add checkpoint and vsphere templates
2023-11-02 21:10:01 +00:00
Wes
3875970dc5
Add checkpoint and vsphere packages
2023-11-02 21:09:37 +00:00
Jason Ertel
7aa4f28524
Merge pull request #11702 from Security-Onion-Solutions/jertel/auto
...
ignore connectivity problems to docker containers during startup
2023-11-02 16:48:09 -04:00
Jason Ertel
96fdfb3829
ignore connectivity problems to docker containers during startup
2023-11-02 16:46:41 -04:00
weslambert
ac593e4632
Merge pull request #11701 from Security-Onion-Solutions/fix/elastic_templates_common
...
Don't source so-elastic-fleet-common if not there
2023-11-02 16:43:27 -04:00
weslambert
51e7861757
Don't source so-elastic-fleet-common if not there
2023-11-02 16:41:34 -04:00
Jason Ertel
6332df04d1
Merge pull request #11695 from Security-Onion-Solutions/jertel/auto
...
Jertel/auto
2023-11-02 13:07:09 -04:00
Jason Ertel
32701b5941
more log bypass
2023-11-02 12:50:12 -04:00
Josh Brower
0dec6693dc
Merge pull request #11678 from Security-Onion-Solutions/2.4/fleetreset
...
Add Elastic Fleet reset script
2023-11-02 11:33:58 -04:00
Jason Ertel
41a6ab5b4f
Merge pull request #11691 from Security-Onion-Solutions/jertel/auto
...
more log bypass
2023-11-02 10:41:17 -04:00
Jason Ertel
e18e0fd69a
more log bypass
2023-11-02 10:39:14 -04:00
Josh Brower
2c0e287f8c
Fix name
2023-11-02 10:34:24 -04:00
Josh Patterson
9a76cfe3d3
Merge pull request #11690 from Security-Onion-Solutions/upgrade/salt3006.3v2
...
fix UPGRADECOMMAND used for distrib salt upgrade. remove unneeded vars
2023-11-02 10:28:29 -04:00
m0duspwnens
6c4dc7cc09
fix UPGRADECOMMAND used for distrib salt upgrade. remove unneeded vars
2023-11-02 10:23:03 -04:00
Josh Brower
5388b92865
Refactor & cleanup
2023-11-02 10:20:32 -04:00
Jason Ertel
f932444101
Merge pull request #11689 from Security-Onion-Solutions/jertel/auto
...
more log bypass
2023-11-02 10:02:13 -04:00
Jason Ertel
1d2518310d
more log bypass
2023-11-02 09:59:45 -04:00
weslambert
e10f043b1c
Merge pull request #11688 from Security-Onion-Solutions/fix/integrations_roles
...
Add eval and import roles
2023-11-02 09:58:40 -04:00
weslambert
65735fc4d3
Add eval and import roles
2023-11-02 09:54:01 -04:00
Jason Ertel
b7f516fca4
Merge pull request #11687 from Security-Onion-Solutions/jertel/auto
...
adjust log filter to include all hosts
2023-11-02 09:24:08 -04:00
Jason Ertel
c8d8997119
adjust log filter to include all hosts
2023-11-02 09:21:57 -04:00
Josh Brower
c230cf4eb7
Formatting
2023-11-01 17:00:32 -04:00
Josh Brower
344dd7d61f
Add Elastic Fleet reset script
2023-11-01 16:50:20 -04:00
Mike Reeves
cd8949d26b
Merge pull request #11677 from Security-Onion-Solutions/lowram
...
Allow 16GB of memory
2023-11-01 16:38:40 -04:00
weslambert
f9e2940181
Merge pull request #11676 from Security-Onion-Solutions/feature/sublime_platform_integration
...
Sublime Platform Integration
2023-11-01 16:13:57 -04:00
Wes
f33079f1e3
Make settings global
2023-11-01 20:09:56 +00:00
Mike Reeves
e6a0838e4c
Add memory restrictions
2023-11-01 15:26:24 -04:00
Mike Reeves
cc93976db9
Add memory restrictions
2023-11-01 15:17:23 -04:00
Mike Reeves
b3b67acf07
Add memory restrictions
2023-11-01 15:11:54 -04:00
Josh Patterson
64926941dc
Merge pull request #11674 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2023-11-01 15:03:30 -04:00
Wes
c32935e2e6
Remove optional integration from configuration if not enabled
2023-11-01 17:02:43 +00:00
Mike Reeves
4f98beaf9e
Merge pull request #11671 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Remove legacy pillar info
2023-11-01 13:00:34 -04:00
Wes
655c88cd09
Make sure enabled_nodes is populated
2023-11-01 16:47:51 +00:00
Mike Reeves
f62e02a477
Delete pillar/thresholding/pillar.example
2023-11-01 10:42:29 -04:00
Mike Reeves
2b3e405b2d
Delete pillar/thresholding/pillar.usage
2023-11-01 10:41:40 -04:00
Josh Patterson
59328d3909
Merge pull request #11670 from Security-Onion-Solutions/fix/soupagrepo
...
Fix/soupagrepo
2023-11-01 10:36:17 -04:00
m0duspwnens
4d7b1095b7
Merge remote-tracking branch 'origin/2.4/dev' into fix/soupagrepo
2023-11-01 10:31:59 -04:00
m0duspwnens
338146fedd
fix repo update during soup for airgap
2023-11-01 10:19:56 -04:00
Wes
bca1194a46
Sublime SOC Action
2023-11-01 14:01:55 +00:00
Wes
a0926b7b87
Load optional integrations
2023-11-01 13:59:24 +00:00
Wes
44e45843bf
Change optional integration Fleet configuration
2023-11-01 13:52:38 +00:00
Wes
9701d0ac20
Optional integration Fleet configuration
2023-11-01 13:47:20 +00:00
Wes
23ee9c2bb0
Sublime Platform integration
2023-11-01 13:41:40 +00:00
Wes
51247be6b9
Sublime Platform integration defaults
2023-11-01 13:37:52 +00:00
Wes
4dc64400c5
Support document_id
2023-11-01 13:36:32 +00:00
Wes
ae45d40eca
Add Sublime Platform ingest pipeline
2023-11-01 13:34:30 +00:00
Mike Reeves
ebf982bf86
Merge pull request #11666 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Remove unused scripts and functions
2023-10-31 15:18:23 -04:00
Mike Reeves
d07cfdd3fe
Update so-functions
2023-10-31 13:10:55 -04:00
Mike Reeves
497294c363
Delete salt/common/tools/sbin/so-zeek-logs
2023-10-31 12:57:10 -04:00
Mike Reeves
cc3a69683c
Delete salt/manager/tools/sbin/so-allow-view
2023-10-31 12:55:47 -04:00
Mike Reeves
0c98bd96c7
Delete salt/idstools/tools/sbin/so-rule
...
UI does this now
2023-10-31 12:52:00 -04:00
Jason Ertel
a6d456e108
Merge pull request #11665 from Security-Onion-Solutions/jertel/auto
...
ignore specific Suricata errors
2023-10-31 11:20:28 -04:00
Jason Ertel
c420e198fb
ignore specific Suricata errors
2023-10-31 11:18:39 -04:00
weslambert
5a85003952
Merge pull request #11664 from Security-Onion-Solutions/fix/elastic_import
...
Add import roles
2023-10-31 10:47:13 -04:00
weslambert
c354924b68
Add import roles
2023-10-31 10:05:29 -04:00
Jason Ertel
db0d687b87
Merge pull request #11661 from Security-Onion-Solutions/fix/elastic_eval_roles
...
Add roles for eval mode
2023-10-30 22:01:22 -04:00
weslambert
ed6473a34b
Add roles for eval mode
2023-10-30 20:41:49 -04:00
Josh Patterson
1b99d5081a
Merge pull request #11659 from Security-Onion-Solutions/issue/11457
...
ensure networkminer is latest version
2023-10-30 16:20:36 -04:00
m0duspwnens
07e51121ba
ensure networkminer is latest version
2023-10-30 16:11:36 -04:00
weslambert
9a1e95cd09
Merge pull request #11648 from Security-Onion-Solutions/fix/ilm_remove_policy
...
Remove ILM policies for Cases and OSQuery manager indices
2023-10-27 17:28:59 -04:00
weslambert
76dd6f07ab
Remove policy for OSQuery manager indices
2023-10-27 17:26:33 -04:00
weslambert
c955f9210a
Remove policy for Cases indices
2023-10-27 17:24:27 -04:00
Josh Patterson
d35483aa02
Merge pull request #11647 from Security-Onion-Solutions/upgrade/salt3006.3v2
...
Upgrade/salt3006.3v2
2023-10-27 14:37:16 -04:00
Jorge Reyes
a9284b35a2
Merge pull request #11644 from Security-Onion-Solutions/bravo
...
UPGRADE: influxdb 2.7.1 & telegraf 1.28.2
2023-10-27 12:16:48 -04:00
Jason Ertel
58cab35a4c
Merge pull request #11643 from Security-Onion-Solutions/kilo
...
oidc
2023-10-27 11:21:20 -04:00
Jason Ertel
6d7243038c
switch back to kilo version
2023-10-27 11:20:49 -04:00
Jason Ertel
3a83c52660
minor updates
2023-10-27 11:20:05 -04:00
Jason Ertel
d42b5ef901
remove unused url props to avoid kratos complaining about invalid urls when they're blank
2023-10-27 11:18:56 -04:00
m0duspwnens
2b511cef77
Merge branch 'upgrade/salt3006.3' into upgrade/salt3006.3v2
2023-10-27 10:58:09 -04:00
Josh Patterson
4bbcc5002a
Revert "Revert "Upgrade/salt3006.3""
...
This reverts commit c41e19ad0b .
2023-10-27 10:56:45 -04:00
Mike Reeves
f1dbea6e2d
Merge pull request #11623 from Security-Onion-Solutions/warmui
...
Warm Node UI Changes
2023-10-27 10:36:23 -04:00
Mike Reeves
25f1a0251f
Annotation changes for warm node
2023-10-27 09:08:07 -04:00
Mike Reeves
87494f64c7
Annotation changes for warm node
2023-10-27 09:06:12 -04:00
Mike Reeves
ce1858fe05
Annotation changes for warm node
2023-10-27 09:02:39 -04:00
Mike Reeves
9fc3a73035
Annotation changes for warm node
2023-10-27 08:58:08 -04:00
Josh Brower
0d52efafa8
Merge pull request #11637 from Security-Onion-Solutions/2.4/kibanauser
...
2.4/kibanauser
2023-10-27 08:43:12 -04:00
defensivedepth
3b63ef149a
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/kibanauser
2023-10-27 07:50:58 -04:00
defensivedepth
cc3ee43192
Make dirs as needed
2023-10-27 07:49:34 -04:00
Mike Reeves
b37e38e3c3
Update defaults.yaml
2023-10-26 16:03:58 -04:00
Jorge Reyes
25982b79ab
Merge pull request #11633 from Security-Onion-Solutions/reyesj2/influxdb_config
...
UPGRADE: Influxdb 2.7.1 & telegraf 1.28.2
2023-10-26 14:37:09 -04:00
Jason Ertel
cb9d72ebd7
switch back to kilo version
2023-10-26 14:19:59 -04:00
m0duspwnens
7e8f3b753f
add minion name to log, update comment
2023-10-26 13:19:04 -04:00
reyesj2
47373adad2
Specify config.yaml in config_path. Otherwise when no influxd.bolt exists influxdb will fail to read the config file and won't create a new db.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-26 13:15:40 -04:00
m0duspwnens
6891a95254
remove wait_for_salt_minion from so-functions
2023-10-26 13:02:39 -04:00
Mike Reeves
2e0100fd35
Update defaults.yaml
2023-10-26 12:37:55 -04:00
Jason Ertel
a969c319f5
Merge pull request #11631 from Security-Onion-Solutions/kilo
...
oidc
2023-10-26 12:30:06 -04:00
Jason Ertel
4942f83d4f
adjust version to match target branch
2023-10-26 11:45:39 -04:00
Josh Brower
6f4566c23e
Merge pull request #11609 from Security-Onion-Solutions/2.4/kibanauser
...
Add kibana curl config
2023-10-26 10:42:32 -04:00
Wes
891ea997e7
Add lifecycle policies and warm settings
2023-10-26 12:25:37 +00:00
Mike Reeves
01810a782c
Annotation changes for warm node
2023-10-25 16:46:30 -04:00
Mike Reeves
6d6292714f
Annotation changes for warm node
2023-10-25 16:21:47 -04:00
Mike Reeves
88fb7d06e6
Annotation changes for warm node
2023-10-25 16:20:28 -04:00
Josh Patterson
39abe19cfd
Update config.map.jinja
2023-10-25 16:17:06 -04:00
Josh Patterson
807b40019f
Update soc_elasticsearch.yaml
2023-10-25 16:16:48 -04:00
Josh Patterson
5f168a33ed
Update defaults.yaml
2023-10-25 16:16:01 -04:00
Mike Reeves
d1170cb69f
Update soc_elasticsearch.yaml
2023-10-25 16:05:20 -04:00
m0duspwnens
19fdc9319b
fix role update
2023-10-25 15:58:26 -04:00
Mike Reeves
dc53b49f15
Update soup
2023-10-25 15:53:39 -04:00
Josh Patterson
af4b34801f
Update defaults.yaml
2023-10-25 15:48:27 -04:00
Josh Patterson
1ae8896a05
Update config.map.jinja
2023-10-25 15:47:40 -04:00
Mike Reeves
6fb0c5dbfe
Annotation changes for warm node
2023-10-25 15:37:36 -04:00
Mike Reeves
58bf6d3eff
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into warmui
2023-10-25 15:37:14 -04:00
Mike Reeves
a887551dad
Annotation changes for warm node
2023-10-25 15:22:47 -04:00
Jason Ertel
b20177b0ef
Merge branch '2.4/dev' into kilo
2023-10-25 15:19:57 -04:00
defensivedepth
1e710a22ce
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/kibanauser
2023-10-25 11:33:38 -04:00
Josh Patterson
d562445686
Merge pull request #11619 from Security-Onion-Solutions/revert-11612-upgrade/salt3006.3
...
Revert "Upgrade/salt3006.3"
2023-10-25 11:28:14 -04:00
Josh Patterson
c41e19ad0b
Revert "Upgrade/salt3006.3"
2023-10-25 11:01:13 -04:00
m0duspwnens
a3e6b1ee1d
change generate_ssl wait_for_salt_minion
2023-10-25 09:26:36 -04:00
Jason Ertel
a28cc274ba
Merge branch '2.4/dev' into kilo
2023-10-25 09:04:36 -04:00
Jason Ertel
a66006c8a6
minor updates
2023-10-25 09:04:23 -04:00
defensivedepth
3ad480453a
Rename to remove dupe
2023-10-25 07:20:07 -04:00
Josh Patterson
205748e992
Merge pull request #11613 from Security-Onion-Solutions/issue/11610
...
fix issue/11610
2023-10-24 18:16:44 -04:00
m0duspwnens
dfe707ab64
fix issue/11610
2023-10-24 17:26:39 -04:00
Josh Patterson
308e5ea505
Merge pull request #11612 from Security-Onion-Solutions/upgrade/salt3006.3
...
Upgrade/salt3006.3
2023-10-24 16:45:12 -04:00
m0duspwnens
3e343bff84
fix line to log properly
2023-10-24 16:40:51 -04:00
m0duspwnens
1d6e32fbab
dont exit if salt isnt running
2023-10-24 15:08:50 -04:00
defensivedepth
310a6b4f27
Add kibana curl config
2023-10-24 14:21:01 -04:00
m0duspwnens
180ba3a958
if deb fam, stop salt-master and salt-minion after salt upgrade
2023-10-24 13:24:52 -04:00
m0duspwnens
6d3465626e
if deb fam, stop salt-master and salt-minion after salt upgrade
2023-10-24 12:52:25 -04:00
m0duspwnens
fab91edd2d
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-24 09:41:23 -04:00
m0duspwnens
752390be2e
merge with dev, fix confict
2023-10-24 09:40:09 -04:00
Mike Reeves
02639d3bc5
Merge pull request #11606 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Enable http2 for Suricata
2023-10-24 09:23:07 -04:00
Mike Reeves
4a3fc06a4d
Enable http2 for Suricata
2023-10-24 09:18:10 -04:00
weslambert
0c2b3f3c62
Merge pull request #11600 from Security-Onion-Solutions/fix/suricata_pkt_src
...
Parse pkt_src for Suricata logs
2023-10-23 15:51:30 -04:00
weslambert
660020cc76
Parse pkt_src for Suricata logs
2023-10-23 15:45:41 -04:00
Jorge Reyes
b59a95b72f
Merge pull request #11594 from Security-Onion-Solutions/fix/playbookrule
...
FIX: Add -watch to soctopus saltstate for file SOCtopus.conf. Makes contai…
2023-10-23 11:51:53 -04:00
reyesj2
030a667d26
Add -watch to soctopus saltstate for file SOCtopus.conf. Makes container restart @ highstate if file is updated.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-23 11:47:14 -04:00
Josh Patterson
a40760e601
Merge pull request #11592 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-23 10:37:05 -04:00
m0duspwnens
dc3ca99c12
ask the minion if it can see itself in the mine
2023-10-20 17:16:33 -04:00
m0duspwnens
7e3aa11a73
check mine is populated with ip before telling node to highstate
2023-10-20 16:27:20 -04:00
m0duspwnens
c409339446
change post setup highstate cron to 5 minutes since accepting minion runs a highstate
2023-10-20 13:46:24 -04:00
m0duspwnens
c588bf4395
update mine and highstate minion when added
2023-10-20 13:43:12 -04:00
m0duspwnens
6d77b1e4c3
continue loop if minion not in mine
2023-10-20 13:41:53 -04:00
m0duspwnens
99662c999f
log operation and minion target
2023-10-20 13:41:24 -04:00
m0duspwnens
ef2b89f5bf
fix attempts logic
2023-10-20 13:40:40 -04:00
Josh Patterson
2878f82754
Merge pull request #11582 from Security-Onion-Solutions/minechanges
...
handle a minion not being in the mine data return
2023-10-20 10:07:44 -04:00
m0duspwnens
2e16250c93
handle a minion not being in the mine data return
2023-10-20 10:00:39 -04:00
m0duspwnens
f03bbdbc09
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-19 17:01:12 -04:00
m0duspwnens
dbfccdfff8
fix logging when using wait_for_minion
2023-10-19 16:53:03 -04:00
m0duspwnens
dfcbbfd157
update call to wait_for_salt_minion with new options in so-functions
2023-10-19 15:58:50 -04:00
m0duspwnens
37e803917e
have soup wait_for_salt_minion() before running any highstate
2023-10-19 15:58:10 -04:00
m0duspwnens
66ee074795
add wait_for_salt_minion to so-common
2023-10-19 15:57:24 -04:00
m0duspwnens
90bde94371
handle debian family salt upgrade for soup
2023-10-19 13:46:48 -04:00
m0duspwnens
84f8e1cc92
debian family upgrade salt without -r flag
2023-10-19 13:46:07 -04:00
m0duspwnens
e3830fa286
all more os to set_os in so-common
2023-10-19 13:43:03 -04:00
m0duspwnens
13a5c8baa7
remove extra ||
2023-10-19 11:19:51 -04:00
m0duspwnens
c5610edd83
handle salt for r9 and c9
2023-10-19 11:12:20 -04:00
weslambert
5119e6c45a
Merge pull request #11570 from Security-Onion-Solutions/feature/additional_integrations
...
Additional integrations
2023-10-19 09:30:40 -04:00
m0duspwnens
02e22c87e8
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-19 09:15:31 -04:00
Mike Reeves
0772926992
Merge pull request #11573 from Security-Onion-Solutions/minechanges
2023-10-18 19:45:23 -04:00
m0duspwnens
b2bb92d413
remove extra space
2023-10-18 19:38:19 -04:00
Mike Reeves
19bebe44aa
Merge pull request #11572 from Security-Onion-Solutions/minechanges
2023-10-18 19:37:34 -04:00
m0duspwnens
f30a652e19
add back redirects
2023-10-18 19:31:45 -04:00
m0duspwnens
ff18b1f074
remove redirect
2023-10-18 18:45:14 -04:00
m0duspwnens
9eb682bc40
generate_ca after salt-master and salt-minion states run
2023-10-18 18:37:35 -04:00
Wes
c135f886a9
Remove Carbon Black Cloud integration
2023-10-18 20:41:34 +00:00
Wes
28b7a24cc1
Add templates for integrations
2023-10-18 20:36:04 +00:00
m0duspwnens
a52ee063e5
use generate_ca and generate_ssl functions and move them up
2023-10-18 16:35:33 -04:00
Wes
767a54c91b
Add pkgs
2023-10-18 20:07:26 +00:00
m0duspwnens
ac28e1b967
verify crt and key differently in checkmine
2023-10-18 15:53:12 -04:00
Jorge Reyes
5e10a0d9e2
Merge pull request #11568 from Security-Onion-Solutions/2.4/zeek6
...
Add back plugin-tds/ plugin-profinet. Using patched versions for Zeek 6
2023-10-18 15:39:30 -04:00
reyesj2
dd28dc6ddd
Add back plugin-tds/ plugin-profinet. Using patched versions for Zeek 6
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-18 15:30:32 -04:00
m0duspwnens
e58c1e189c
use x509 instead of file for onchanges
2023-10-18 15:10:17 -04:00
m0duspwnens
1c1b23c328
fix mine update for ca
2023-10-18 15:07:18 -04:00
m0duspwnens
2206cdb0fa
change soup comment
2023-10-18 15:04:39 -04:00
m0duspwnens
1999db0bb3
apply ca state early in setup
2023-10-18 15:02:22 -04:00
m0duspwnens
c3cde61202
docker service watches and requires the intca
2023-10-18 15:01:26 -04:00
m0duspwnens
8e68f96316
check that the manager has a ca in the mine and that it is valid
2023-10-18 13:59:15 -04:00
m0duspwnens
138aa9c554
update the mine with the ca when it is created or changed
2023-10-18 13:54:14 -04:00
weslambert
f0e380870d
Merge pull request #11567 from Security-Onion-Solutions/fix/mhr_docs
...
Add note regarding DNS resolver
2023-10-18 13:46:25 -04:00
weslambert
34717fb65e
Add note regarding DNS resolver
2023-10-18 13:44:09 -04:00
Josh Patterson
d81dfb99d0
Merge pull request #11563 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-17 17:36:46 -04:00
m0duspwnens
fb9a0ab8b6
endif not fi in jinja
2023-10-17 17:33:53 -04:00
m0duspwnens
928fb23e96
only add node to pillar if returned ip from mine
2023-10-17 17:28:28 -04:00
m0duspwnens
d9862aefcf
handle mine.p not being present. only check if mine_ip exists, dont compare to alived ip
2023-10-17 17:09:52 -04:00
m0duspwnens
496b97d706
handle the mine file not being present before checking the size
2023-10-17 15:42:42 -04:00
weslambert
830b5b9a21
Merge pull request #11560 from Security-Onion-Solutions/foxtrot
...
Elastic 8.10.4
2023-10-17 13:47:21 -04:00
weslambert
06e731c762
Update VERSION
2023-10-17 13:33:12 -04:00
weslambert
be2a829524
Elastic 8.10.4
2023-10-17 10:49:03 -04:00
weslambert
8cab242ad0
Elastic 8.10.4
2023-10-17 10:48:31 -04:00
weslambert
99054a2687
Elastic 8.10.4
2023-10-17 10:47:26 -04:00
weslambert
adcb7840bd
Elastic 8.10.3
2023-10-17 10:38:20 -04:00
weslambert
8db6fef92d
Elastic 8.10.3
2023-10-17 10:35:36 -04:00
weslambert
24329e3731
Update config_saved_objects.ndjson
2023-10-17 10:34:38 -04:00
weslambert
1db88bdbb5
Update so-common
2023-10-17 10:33:39 -04:00
weslambert
7c2cdb78e9
Update VERSION
2023-10-17 10:31:53 -04:00
Josh Patterson
e858a1211e
Merge pull request #11558 from Security-Onion-Solutions/excludelogfp
...
mark suricata 7 log line as fp fo so-log-check
2023-10-17 10:02:21 -04:00
m0duspwnens
01cb0fccb6
mark suricata 7 log line as fp fo so-log-check
2023-10-17 10:01:11 -04:00
Josh Patterson
86394dab01
Merge pull request #11555 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-16 17:32:16 -04:00
m0duspwnens
53fcafea50
redo how we check if salt-master is ready and accessible
2023-10-16 16:31:43 -04:00
Jorge Reyes
574a81da7f
Merge pull request #11554 from Security-Onion-Solutions/2.4/zeek6
...
Zeek 6 upgrade
2023-10-16 15:52:48 -04:00
reyesj2
ed693a7ae6
Remove commented lines in defaults.yaml to avoid UI issues.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-16 15:48:51 -04:00
reyesj2
e5c936e8cf
Replace external zeek-community-id with builtin community-id. Disable plugin-tds + plugin-profinet. Not updated for Zeek 6.x
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-16 15:18:26 -04:00
m0duspwnens
9f3a9dfab0
reorder salt.master state
2023-10-16 15:00:53 -04:00
m0duspwnens
c0030bc513
dont need to restart minion service when just adding sleep delay on service start
2023-10-16 15:00:07 -04:00
m0duspwnens
a637b0e61b
apply salt.master and minion state early in setup to prevent the services from restarting later in setup
2023-10-16 14:58:58 -04:00
Jason Ertel
2f0e673ec3
Merge pull request #11552 from Security-Onion-Solutions/jertel/auto
...
only add heavynodes to remoteHostUrls
2023-10-16 13:10:10 -04:00
Jason Ertel
84c39b5de7
only add heavynodes to remoteHostUrls
2023-10-16 13:01:13 -04:00
m0duspwnens
07902d17cc
display container dl status during soup
2023-10-16 11:20:19 -04:00
m0duspwnens
1a7761c531
display container dl status during soup
2023-10-16 11:00:31 -04:00
m0duspwnens
2773da5a12
run the checkmine engine under master instead of minion
2023-10-16 10:34:45 -04:00
m0duspwnens
e23b3a62f3
default interval of 60s
2023-10-13 16:24:11 -04:00
m0duspwnens
57684efddf
checkmine looks for 1 byte file and verify mine ip is correct
2023-10-13 16:23:16 -04:00
m0duspwnens
1641aa111b
add checkmine back
2023-10-13 13:46:31 -04:00
Jason Ertel
ca2530e07f
Merge pull request #11535 from Security-Onion-Solutions/jertel/auto
...
avoid rebooting when testing deb installs
2023-10-12 16:30:24 -04:00
Mike Reeves
104b53c6ec
Merge pull request #11534 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2023-10-12 16:20:37 -04:00
Mike Reeves
6c5f8e4e2d
Update HOTFIX
2023-10-12 16:19:59 -04:00
Mike Reeves
b8d586addd
Merge pull request #11533 from Security-Onion-Solutions/2.4/main
...
2.4/main
2023-10-12 16:19:29 -04:00
Mike Reeves
1b5cd4f53a
Merge pull request #11532 from Security-Onion-Solutions/hotfix/2.4.20
...
Hotfix 2.4.20
2023-10-12 16:16:49 -04:00
m0duspwnens
d2002a5158
add additional comments
2023-10-12 15:58:33 -04:00
m0duspwnens
5250292e95
only allow stable install type. require -r to be used
2023-10-12 15:54:22 -04:00
Mike Reeves
acc6715f90
Merge pull request #11531 from Security-Onion-Solutions/2.4.20hf
...
2.4.20 hotfix
2023-10-12 15:52:44 -04:00
Mike Reeves
b6af59d9b0
2.4.20 hotfix
2023-10-12 15:47:53 -04:00
Jason Ertel
49a651fd72
adjust var name
2023-10-12 15:43:22 -04:00
m0duspwnens
2d688331df
handle version install for stable and onedir install type
2023-10-12 15:32:04 -04:00
m0duspwnens
b12c4a96e9
remove files
2023-10-12 15:11:25 -04:00
m0duspwnens
6dd06c0fe9
change install_centos_onedir to install version provided from command line
2023-10-12 15:07:47 -04:00
Jason Ertel
17ae9b3349
avoid reboot during testing
2023-10-12 13:54:07 -04:00
m0duspwnens
8dc163f074
use script from develop branch
2023-10-12 13:09:07 -04:00
Josh Brower
8ce70e1f18
Merge pull request #11525 from Security-Onion-Solutions/hotfixfunctions
...
Apply named state
2023-10-12 11:05:32 -04:00
defensivedepth
98eab906af
Apply named state
2023-10-12 11:00:24 -04:00
Josh Brower
d558f20715
Merge pull request #11524 from Security-Onion-Solutions/hotfixfunctions
...
Apply state correctly
2023-10-12 10:56:43 -04:00
defensivedepth
967138cdff
Apply state correctly
2023-10-12 10:54:26 -04:00
Josh Brower
c76ac717f2
Merge pull request #11522 from Security-Onion-Solutions/hotfixfunctions
...
Add hotfix changes
2023-10-12 09:52:55 -04:00
defensivedepth
a671ac387a
Add hotfix changes
2023-10-12 09:45:20 -04:00
m0duspwnens
ab4c5acd0c
update bootstrap-salt.sh with stable branch
2023-10-12 09:28:07 -04:00
defensivedepth
1043315e6b
Manage Elastic Defend Integration manually
2023-10-12 09:22:26 -04:00
m0duspwnens
d357864d69
fix upgrade_salt function for oel
2023-10-11 15:32:11 -04:00
Jason Ertel
44b855dd93
merge 2.4/dev
2023-10-11 13:35:16 -04:00
m0duspwnens
2094b4f688
upgrade to salt 3006.3
2023-10-11 09:04:36 -04:00
Josh Patterson
5252482fe3
Merge pull request #11503 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-10 16:33:17 -04:00
m0duspwnens
abeebc7bc4
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-10-10 13:13:55 -04:00
m0duspwnens
4193130ed0
reduce salt mine interval to 25 minutes
2023-10-10 13:07:12 -04:00
m0duspwnens
89467adf9c
batch the salt mine update
2023-10-10 13:05:43 -04:00
m0duspwnens
a283e7ea0b
remove checkmine salt engine
2023-10-10 13:00:54 -04:00
Mike Reeves
a54479d603
Merge pull request #11497 from Security-Onion-Solutions/TOoSmOotH-patch-9
...
Update VERSION
2023-10-10 11:07:51 -04:00
Mike Reeves
49ebbf3232
Update VERSION
2023-10-10 11:05:39 -04:00
m0duspwnens
05da5c039c
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-10-10 11:02:19 -04:00
Josh Patterson
f3d0248ec5
Merge pull request #11496 from Security-Onion-Solutions/fix/ping
...
accept icmp on input chain
2023-10-10 10:59:05 -04:00
m0duspwnens
4dc24b22c7
accept icmp on input chain
2023-10-10 10:51:59 -04:00
Mike Reeves
fc0e3c0124
Merge pull request #11476 from Security-Onion-Solutions/2.4/dev
...
2.4.20
2023-10-06 16:45:11 -04:00
Mike Reeves
32c1d6f95c
Merge pull request #11475 from Security-Onion-Solutions/2.4.20
...
2.4.20
2023-10-05 11:41:55 -04:00
Mike Reeves
c25aed9a2b
Update DOWNLOAD_AND_VERIFY_ISO.md
2023-10-05 11:37:49 -04:00
Mike Reeves
d79e27774c
2.4.20
2023-10-05 11:27:48 -04:00
Mike Reeves
194178a250
Merge pull request #11465 from Security-Onion-Solutions/fix/pkgs
...
Fix/pkgs
2023-10-03 10:17:37 -04:00
m0duspwnens
d78b55873d
remove mariadb-devel
2023-10-03 10:15:28 -04:00
Mike Reeves
f3ba28062b
Remove MySQL
2023-10-03 10:05:56 -04:00
m0duspwnens
2434ce14d3
remove removing mariadb-devel
2023-10-03 10:01:07 -04:00
m0duspwnens
66be04e78a
remove mariadb
2023-10-03 09:53:40 -04:00
Jason Ertel
62e9472f1a
Merge pull request #11464 from Security-Onion-Solutions/jertel/lc
...
exclude known issues
2023-10-03 09:46:18 -04:00
Jason Ertel
c699c2fe2a
exclude known issues
2023-10-03 09:43:29 -04:00
Mike Reeves
a35889ebdc
Merge pull request #11461 from Security-Onion-Solutions/fix/pkgs
2023-10-02 17:38:38 -04:00
m0duspwnens
8995752c27
let openssl-devel be installed with mariadb
2023-10-02 16:17:26 -04:00
m0duspwnens
57e76232ec
openssl pkgs in own state
2023-10-02 15:48:53 -04:00
m0duspwnens
d7a14d9e00
update holds
2023-10-02 15:08:22 -04:00
m0duspwnens
6b90961e87
openssl-libs
2023-10-02 14:26:28 -04:00
m0duspwnens
6547afe6c0
dont hold openssl-devel
2023-10-02 13:35:00 -04:00
m0duspwnens
3a5c6ee43a
install version lock before we try to hold pkgs
2023-10-02 12:09:13 -04:00
m0duspwnens
0f08d5d640
install openssl version 1:3.0.7-16.0.1.el9_2
2023-10-02 11:43:03 -04:00
m0duspwnens
f85dd910a3
hold openssl from update during setup
2023-10-02 11:13:08 -04:00
m0duspwnens
c1ab8952eb
hold openssl-devel
2023-10-02 10:59:51 -04:00
m0duspwnens
dfe399291f
hold openssl-libs
2023-10-02 10:54:41 -04:00
m0duspwnens
70a36bafa5
remove -
2023-10-02 10:38:54 -04:00
m0duspwnens
381d95e032
Merge remote-tracking branch 'origin/2.4/dev' into fix/pkgs
2023-10-02 10:37:12 -04:00
m0duspwnens
cd8a74290b
hold openssl version
2023-10-02 10:36:17 -04:00
Jason Ertel
d91eaa9ae5
Merge pull request #11448 from Security-Onion-Solutions/jertel/lc
...
fix exclusion
2023-09-30 18:16:23 -04:00
Jason Ertel
8c7933cd60
fix exclusion
2023-09-30 18:11:29 -04:00
Jason Ertel
88f461042d
Merge pull request #11442 from Security-Onion-Solutions/jertel/lc
...
more known errors
2023-09-29 21:43:51 -04:00
Jason Ertel
ea085c5ff6
more known errors
2023-09-29 21:38:13 -04:00
m0duspwnens
39ea1d317d
add comment
2023-09-29 17:12:14 -04:00
m0duspwnens
827ed7b273
run salt.mine_function state locally and provide pillar info to it
2023-09-29 17:08:42 -04:00
m0duspwnens
8690304dff
change how mine_functions.conf is managed during setup
2023-09-29 16:17:19 -04:00
m0duspwnens
1e327c143c
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-09-29 15:11:06 -04:00
Jason Ertel
19232124f2
Merge pull request #11441 from Security-Onion-Solutions/jertel/lc
...
exclude oom error from cmd line
2023-09-29 14:21:05 -04:00
Jason Ertel
e8b67da08b
exclude oom error from cmd line
2023-09-29 14:20:20 -04:00
Jason Ertel
b5d19bd561
Merge pull request #11440 from Security-Onion-Solutions/jertel/lc
...
exclude logstash errors
2023-09-29 14:13:34 -04:00
m0duspwnens
ad01be66ea
remove checkmine engine. add x509.get_pem_entries to managers mine_functions. simplify mine update during soup
2023-09-29 14:09:04 -04:00
Jason Ertel
d546d52069
exclude logstash
2023-09-29 14:08:44 -04:00
Josh Patterson
13cc8c4258
Merge pull request #11437 from Security-Onion-Solutions/telegraf/redis
...
remove redis from eval
2023-09-29 11:12:24 -04:00
m0duspwnens
9d3f6059ee
remove redis from eval
2023-09-29 11:10:08 -04:00
Jason Ertel
43855b8ca2
Merge pull request #11436 from Security-Onion-Solutions/jertel/lc
...
exclude all playbook logs
2023-09-29 11:04:48 -04:00
Jason Ertel
ec3cc7a854
exclude all playbook logs
2023-09-29 10:49:36 -04:00
Mike Reeves
63be7ef6ca
Merge pull request #11432 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update defaults.yaml
2023-09-28 19:48:14 -04:00
Mike Reeves
b8aad7f5e6
Update defaults.yaml
2023-09-28 19:44:49 -04:00
weslambert
c02e491609
Merge pull request #11430 from Security-Onion-Solutions/fix/elastic_packages
...
Upgrade packages and load integrations when packages change
2023-09-28 14:10:39 -04:00
Wes
670cd19051
Exclude package upgrade script
2023-09-28 18:04:07 +00:00
Wes
8c44481ee1
Load templates after package changes
2023-09-28 17:57:31 +00:00
Mike Reeves
a8c94a891b
Merge pull request #11426 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Fix Yara crontab
2023-09-28 13:09:11 -04:00
Mike Reeves
ff35946050
Fix manager cron logic
2023-09-28 13:06:21 -04:00
Mike Reeves
95d32cb076
Fix manager cron logic
2023-09-28 12:49:46 -04:00
Wes
018186ccbd
Upgrade packages and load integrations when packages change
2023-09-28 16:43:56 +00:00
Mike Reeves
5040df7551
Fix manager cron logic
2023-09-28 12:32:40 -04:00
Jason Ertel
c3604f6e80
Merge pull request #11422 from Security-Onion-Solutions/jertel/lc
...
exclude known issues
2023-09-28 11:47:13 -04:00
Mike Reeves
7a21b7903d
Fix manager cron logic
2023-09-28 11:46:43 -04:00
Mike Reeves
a77a53f20b
Update init.sls
2023-09-28 11:10:17 -04:00
Mike Reeves
ee45fc31a2
Delete salt/strelka/tools/sbin_jinja/so-yara-download
2023-09-28 11:04:16 -04:00
weslambert
ceae22adab
Merge pull request #11423 from Security-Onion-Solutions/fix/elastic_known_certs
...
Exclude known_certs
2023-09-28 09:20:38 -04:00
weslambert
202eb7e876
Exclude known_certs
2023-09-28 09:16:56 -04:00
Jason Ertel
89a9c30cc8
exclude known issues
2023-09-28 08:27:31 -04:00
Jason Ertel
7012ff6609
Merge pull request #11418 from Security-Onion-Solutions/jertel/lc
...
more exclusions
2023-09-28 08:02:29 -04:00
Jason Ertel
621da9e7e3
more exclusions
2023-09-27 22:20:54 -04:00
Jason Ertel
26bb0d064f
Merge pull request #11417 from Security-Onion-Solutions/jertel/lc
...
logcheck improvements
2023-09-27 20:35:06 -04:00
Jason Ertel
9ee64f93ca
logcheck improvements
2023-09-27 20:17:59 -04:00
Jason Ertel
641ff95f41
Merge pull request #11416 from Security-Onion-Solutions/jertel/lc
...
Jertel/lc
2023-09-27 20:03:58 -04:00
Jason Ertel
49115cde55
logcheck improvements
2023-09-27 19:55:46 -04:00
Josh Patterson
7d0e1c92a3
Merge pull request #11415 from Security-Onion-Solutions/issue/11390
...
Issue/11390
2023-09-27 19:39:36 -04:00
m0duspwnens
419acab48a
revert up_to_2.4.20
2023-09-27 19:17:13 -04:00
m0duspwnens
528572c15b
Merge remote-tracking branch 'origin/2.4/dev' into issue/11390
2023-09-27 18:42:07 -04:00
Jason Ertel
d72e4ae97d
ignore soctopus errors
2023-09-27 18:39:23 -04:00
m0duspwnens
76c0b881ff
exclude import from snapshotting previous version pillars and states
2023-09-27 18:20:50 -04:00
Jason Ertel
836c49b755
Merge pull request #11414 from Security-Onion-Solutions/jertel/lc
...
ignore generic python stack trace log lines of code, rely on actual e…
2023-09-27 16:59:34 -04:00
Jason Ertel
24def3a196
ignore generic python stack trace log lines of code, rely on actual error messages
2023-09-27 16:50:01 -04:00
Mike Reeves
b6d58b2fb8
Merge pull request #11411 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
FIX: Remove telegraf beats EPS script
2023-09-27 16:14:51 -04:00
Mike Reeves
770a74c83d
Merge pull request #11409 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Fix zeek from creating summary files
2023-09-27 16:14:34 -04:00
Mike Reeves
039d5ae9aa
Delete salt/telegraf/scripts/beatseps.sh
2023-09-27 16:09:27 -04:00
Mike Reeves
2fb73cd516
Update defaults.yaml
2023-09-27 16:07:38 -04:00
Mike Reeves
2427344dca
Update defaults.yaml
2023-09-27 15:58:58 -04:00
Mike Reeves
62cb661bab
Merge pull request #11408 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix sendmail errors in zeek
2023-09-27 15:53:50 -04:00
Jason Ertel
1e04199ea6
Merge pull request #11406 from Security-Onion-Solutions/jertel/lc
...
ignore generic python stack trace log lines of code, rely on actual e…
2023-09-27 15:52:48 -04:00
Jason Ertel
4666916077
ignore generic python stack trace log lines of code, rely on actual error messages
2023-09-27 15:48:52 -04:00
Mike Reeves
f094b1162d
Update defaults.yaml
2023-09-27 15:48:05 -04:00
Jason Ertel
ae9619f0c3
Merge pull request #11405 from Security-Onion-Solutions/jertel/lc
...
deb OS doesn't use /var/log/cron, skip
2023-09-27 15:42:10 -04:00
Jason Ertel
87cc389088
deb OS doesn't use /var/log/cron, skip
2023-09-27 15:36:13 -04:00
Josh Patterson
ec046a6943
Merge pull request #11404 from Security-Onion-Solutions/fix/filecheckcron
...
Fix/filecheckcron
2023-09-27 12:51:25 -04:00
Mike Reeves
7eefe7b79c
Merge pull request #11403 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update nginx.conf to use user nobody
2023-09-27 12:38:58 -04:00
Mike Reeves
c4fea9cb9d
Update nginx.conf
2023-09-27 11:03:58 -04:00
m0duspwnens
3fded86aa1
Merge remote-tracking branch 'origin/2.4/dev' into fix/filecheckcron
2023-09-27 10:08:17 -04:00
m0duspwnens
05e7c32cf9
remove duplicate filecheck_run cron
2023-09-27 10:08:08 -04:00
Jason Ertel
af2ff2b07c
Merge pull request #11399 from Security-Onion-Solutions/jertel/lc
...
don't inspect imported zeek output
2023-09-27 09:45:39 -04:00
Jason Ertel
b47d915cb6
don't inspect imported zeek output
2023-09-27 09:30:19 -04:00
Jason Ertel
376d525ad7
Merge pull request #11398 from Security-Onion-Solutions/jertel/lc
...
skip zeek spool logs due to test data false positives
2023-09-26 22:01:50 -04:00
Jason Ertel
9c854a13cc
skip zeek spool logs due to test data false positives
2023-09-26 21:41:44 -04:00
Jason Ertel
ff780738fd
Merge pull request #11397 from Security-Onion-Solutions/jertel/lc
...
log check tool initial
2023-09-26 18:23:41 -04:00
Jason Ertel
2c8d413f16
log check tool initial
2023-09-26 18:14:37 -04:00
Jason Ertel
48801da44e
log check tool initial
2023-09-26 18:12:20 -04:00
Josh Patterson
641b8ef0b6
Merge pull request #11393 from Security-Onion-Solutions/issue/11390
...
Issue/11390
2023-09-26 13:26:42 -04:00
m0duspwnens
036a21ff17
Merge remote-tracking branch 'origin/2.4/dev' into issue/11390
2023-09-26 11:01:44 -04:00
m0duspwnens
2abf434ebe
create snapshots of default, local salt and pillars during soup. rsync soup with --delete
2023-09-26 10:56:20 -04:00
weslambert
4dc477cc1d
Merge pull request #11391 from Security-Onion-Solutions/fix/elasticsearch_strelka_image_version
...
Make scan.pe.image_version type of 'float'
2023-09-26 10:21:17 -04:00
Wes
0bba68769b
Make scan.pe.image_version type of 'float'
2023-09-26 14:05:12 +00:00
m0duspwnens
e25d1c0ff3
so-salt-minion-check is jinja template
2023-09-26 10:01:21 -04:00
weslambert
f9ace4791f
Merge pull request #11384 from Security-Onion-Solutions/fix/analyzers_testing
...
Add a note about testing analyzers outside of the Sensoroni Docker container
2023-09-25 14:48:45 -04:00
weslambert
7cb9b5f257
Add the blank line that was removed from the previous commit
2023-09-25 14:41:20 -04:00
weslambert
c95af6b992
Add a note about testing analyzers outside of the Sensoroni Docker container
2023-09-25 14:39:33 -04:00
weslambert
2fc4d2923d
Merge pull request #11289 from Security-Onion-Solutions/fix/elastic_agent_404
...
/app/dashboards to /kibana/app/dashboards
2023-09-25 09:11:50 -04:00
Wes
eeeae08ec8
/app/ to /app/dashboards/
2023-09-21 18:39:06 +00:00
Jason Ertel
220f25e206
Merge pull request #11369 from Security-Onion-Solutions/jertel-patch-1
...
Update soup to prune in background
2023-09-21 09:42:28 -04:00
Jason Ertel
fa3a79a787
Update soup to prune in background
2023-09-21 09:41:44 -04:00
Doug Burks
ca71add51b
Merge pull request #11363 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Config sensoroni doc links should point to correct docs #11362
2023-09-20 08:29:30 -04:00
Doug Burks
3fa3f83007
Update soc_sensoroni.yaml
2023-09-20 08:22:52 -04:00
weslambert
377802410e
Merge pull request #11352 from Security-Onion-Solutions/fix/import_evtx_exists
...
Fix EVTX Imports
2023-09-19 16:11:22 -04:00
Wes
2e0ea3f374
Set final pipeline
2023-09-19 13:33:12 +00:00
Wes
508260bd46
Use event.created for timestamp
2023-09-19 13:32:03 +00:00
Wes
a1e963f834
Reverse timestamps where necessary
2023-09-19 13:28:20 +00:00
Jason Ertel
8a98040008
Merge pull request #11351 from Security-Onion-Solutions/jertel/auto
...
ignore debian apt update output
2023-09-19 09:26:31 -04:00
Jason Ertel
47e611682a
ignore debian apt update output
2023-09-19 09:24:12 -04:00
Wes
5bac1e4d15
Show correct dates and Kibana URL for already processed EVTX files
2023-09-18 21:31:15 +00:00
Jason Ertel
ad025b9683
Merge pull request #11345 from Security-Onion-Solutions/jertel/auto
...
ensure all binds are present to avoid volume sprawl
2023-09-18 15:34:57 -04:00
Josh Patterson
3e97ddc22d
Merge pull request #11344 from Security-Onion-Solutions/fix/idstoolextra_env
...
fix idstool extra_env for container
2023-09-18 15:29:33 -04:00
m0duspwnens
151e8bfc4e
fix idstool extra_env for container
2023-09-18 15:21:45 -04:00
Jason Ertel
a914a02273
prune unused volumes during upgrade
2023-09-18 14:43:02 -04:00
Jason Ertel
bb3632d1b2
fix bind if statement
2023-09-18 14:38:15 -04:00
Jason Ertel
66bb1272ae
avoid volume sprawl
2023-09-18 13:39:56 -04:00
Jason Ertel
bbef96ac25
use unique name
2023-09-18 12:12:57 -04:00
Jason Ertel
f9cbde10a6
avoid volume sprawl
2023-09-18 11:19:21 -04:00
weslambert
fe1bae96ed
Merge pull request #11297 from Security-Onion-Solutions/fix/soc_idh
...
Change description to indicate that opencanary modules only apply to IDH nodes
2023-09-15 11:16:06 -04:00
weslambert
eab6173a31
Merge pull request #11329 from Security-Onion-Solutions/fix/elastic_templates_clean
...
Clean component template directory
2023-09-15 11:00:17 -04:00
Wes
98499c3963
Clean component template directory
2023-09-15 13:51:46 +00:00
Josh Patterson
26da525ebe
Merge pull request #11328 from Security-Onion-Solutions/fix/checkreq
...
improvents for checking system requirements
2023-09-15 09:17:04 -04:00
m0duspwnens
c65c9777bd
improvents for checking system requirements
2023-09-14 17:42:25 -04:00
Josh Brower
af68af7f18
Merge pull request #11317 from Security-Onion-Solutions/2.4/fixes
...
Regex & Transform Role
2023-09-14 10:59:56 -04:00
defensivedepth
0c11a9b733
Add transform role
2023-09-14 09:33:17 -04:00
defensivedepth
59d077f3ff
Fix regex
2023-09-14 08:32:17 -04:00
Jason Ertel
6383712731
Merge pull request #11315 from Security-Onion-Solutions/jertel/auto
...
exclude docker pull unauth errors from failing setup
2023-09-14 07:41:59 -04:00
Jason Ertel
e067b7134e
exclude docker pull unauth errors from failing setup since they'll be retried
2023-09-14 07:38:07 -04:00
Mike Reeves
183c530c82
Merge pull request #11308 from Security-Onion-Solutions/pcapfree
...
Update so-minion
2023-09-13 13:47:21 -04:00
Mike Reeves
33d68478b6
Update so-minion
2023-09-13 11:48:16 -04:00
Mike Reeves
22c0323bda
Update so-minion
2023-09-13 10:57:45 -04:00
Doug Burks
19114c1a26
Merge pull request #11303 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Config pcap doc links should point to steno docs #11302
2023-09-13 07:50:43 -04:00
Doug Burks
11b8e13418
FIX: SOC Config pcap doc links should point to steno docs #11302
2023-09-13 07:37:54 -04:00
Josh Patterson
6fdd7b3751
Merge pull request #11295 from Security-Onion-Solutions/issue/11229
...
dont manage sorules
2023-09-12 09:30:29 -04:00
m0duspwnens
30c3255cb2
dont manage sorules
2023-09-12 08:39:42 -04:00
Wes
35ebbc974c
Change description to indicate that opencanary modules only apply to IDH nodes
2023-09-11 13:52:16 +00:00
Wes
f1d0db8171
/app to /kibana/app
2023-09-11 13:30:11 +00:00
Josh Patterson
9968d697f3
Merge pull request #11288 from Security-Onion-Solutions/issue/11229
...
Issue/11229
2023-09-11 09:19:31 -04:00
m0duspwnens
02c54a264d
Merge remote-tracking branch 'origin/2.4/dev' into issue/11229
2023-09-08 15:29:04 -04:00
m0duspwnens
e814a3409f
fix rule location for rulecat.conf. run so-rule-update if rules change in /opt/so/rules/nids
2023-09-08 15:28:24 -04:00
Jason Ertel
55847c7bdc
Merge pull request #11276 from Security-Onion-Solutions/jertel/auto
...
give priority to presets
2023-09-08 09:26:27 -04:00
Jason Ertel
598515e5b4
give priority to presets
2023-09-08 09:21:13 -04:00
Jason Ertel
692625f8cd
Merge pull request #11271 from Security-Onion-Solutions/jertel/auto
...
addl node types
2023-09-07 17:25:08 -04:00
Jason Ertel
f8ae3f12e6
addl node types
2023-09-07 17:22:10 -04:00
Josh Patterson
3780ed1b4f
Merge pull request #11269 from Security-Onion-Solutions/issue/11210
...
Issue/11210
2023-09-07 16:54:16 -04:00
m0duspwnens
8d269fee30
Merge remote-tracking branch 'origin/2.4/dev' into issue/11210
2023-09-07 15:46:25 -04:00
m0duspwnens
35157f2e8b
add comment
2023-09-07 15:46:04 -04:00
m0duspwnens
60f1947eb4
prevent endgame_dict from being added to standard_actions if it is already present
2023-09-07 14:01:19 -04:00
m0duspwnens
ffaab4a1b4
only add endgame to action if it is populated
2023-09-06 14:19:53 -04:00
weslambert
70e1309c9f
Merge pull request #11261 from Security-Onion-Solutions/fix/remove_default_templates
...
Remove templates
2023-09-06 10:57:09 -04:00
Jason Ertel
5c0045f9f8
Merge pull request #11256 from Security-Onion-Solutions/jertel/sod
...
only ingest pfsense on sensor nodes
2023-09-05 12:50:47 -04:00
Jason Ertel
b66be9c226
only ingest pfsense on sensor nodes
2023-09-05 12:46:49 -04:00
Josh Patterson
651393988a
Merge pull request #11255 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-09-05 11:57:58 -04:00
Wes
cf19c8f8c2
Remove templates
2023-09-05 13:43:41 +00:00
Mike Reeves
ba3ae92702
Merge pull request #11249 from Security-Onion-Solutions/jertel/sod
2023-09-03 22:23:55 -04:00
Jason Ertel
8e2bed7f91
MS testing
2023-09-03 19:56:40 -04:00
Jason Ertel
028b69c7d4
Merge pull request #11245 from Security-Onion-Solutions/jertel/sod
...
ensure hostname is set
2023-09-02 13:49:49 -04:00
Jason Ertel
0cf913a7c1
ensure hostname is set
2023-09-02 06:05:37 -04:00
Jason Ertel
13fbcd712b
Merge pull request #11243 from Security-Onion-Solutions/jertel/sod
...
ensure hostname is set
2023-09-01 20:43:35 -04:00
Jason Ertel
0aae107155
ensure hostname is set
2023-09-01 20:30:53 -04:00
Mike Reeves
d2dcf7e7c1
Merge pull request #11241 from Security-Onion-Solutions/jertel/sod
2023-09-01 18:22:38 -04:00
Jason Ertel
6efdf1b9d0
add additional test modes
2023-09-01 17:24:12 -04:00
Jason Ertel
a11259c683
add additional test modes
2023-09-01 17:08:27 -04:00
Jason Ertel
863db14b61
add additional test modes
2023-09-01 16:27:02 -04:00
Jason Ertel
335aaa5594
add additional test modes
2023-09-01 15:30:53 -04:00
m0duspwnens
07ed93de19
add elastic agent to desktop
2023-09-01 14:33:32 -04:00
Jason Ertel
8093e5ce7c
use IP to avoid host issues
2023-09-01 13:01:17 -04:00
m0duspwnens
585fba4bc6
add functions salt_install_module_deps and salt_patch_x509_v2
2023-09-01 12:40:01 -04:00
weslambert
b8f69b5008
Merge pull request #11239 from Security-Onion-Solutions/fix/syslog_heavynode
...
Add so-elastic-agent
2023-09-01 12:20:44 -04:00
m0duspwnens
aebfb19ab7
add sostatus.sh to desktop for telegraf scripts
2023-09-01 12:05:28 -04:00
m0duspwnens
490669d378
add ssl to desktop for allowed_states
2023-09-01 12:03:01 -04:00
m0duspwnens
3434d0f200
add sensoroni and telegraf back to individual nodes. add seperate block for desktop
2023-09-01 12:02:30 -04:00
weslambert
765a22e6f0
Add so-elastic-agent
2023-09-01 11:31:23 -04:00
Jason Ertel
546c562ef0
expose standard relay timeout in config UI; up default to 45s to accommodate sluggish pillar.get calls
2023-09-01 10:31:02 -04:00
m0duspwnens
b64d4e3658
add telegraf pillar to desktop
2023-09-01 09:53:26 -04:00
m0duspwnens
0fb00d569e
allow states for desktop. give all nodes docker_clean, order it last
2023-09-01 09:39:39 -04:00
m0duspwnens
b64fa51268
give desktop docker state and pillars
2023-09-01 09:16:24 -04:00
Jason Ertel
1871d48f7f
remove unnecesary OTHER submenu
2023-08-31 20:42:00 -04:00
m0duspwnens
b010919099
add sensoroni, telegraf, common states to desktop. allow docker_registry connection to managers for desktop
2023-08-31 13:21:32 -04:00
weslambert
ce2a7135cb
Merge pull request #11232 from Security-Onion-Solutions/fix/strelka_entropy
...
Strelka entropy mapping
2023-08-31 11:21:00 -04:00
Wes
0fed757b11
Add entropy mapping
2023-08-31 15:10:27 +00:00
Wes
1a3b3b21fb
Change entropy value syntax
2023-08-31 15:09:19 +00:00
Josh Patterson
d86e21c751
Merge pull request #11231 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-08-31 10:54:30 -04:00
m0duspwnens
e408718230
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-31 09:56:02 -04:00
m0duspwnens
ee848b8a8c
comments for desktop install
2023-08-31 09:51:55 -04:00
m0duspwnens
a60c34d548
exclude unnecessary pillars from desktop nodes
2023-08-31 09:40:54 -04:00
Doug Burks
8a2fc5d62b
Merge pull request #11226 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md
2023-08-31 09:18:19 -04:00
Doug Burks
da56a421e5
Update motd.md
2023-08-31 09:17:33 -04:00
m0duspwnens
bfb0d0ddb5
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-31 08:58:28 -04:00
m0duspwnens
c812c3991e
we dont need to run convert-gnome-classic script
2023-08-31 08:54:13 -04:00
coreyogburn
ca9dad396f
Merge pull request #11222 from Security-Onion-Solutions/cogburn/11143
...
New Config Default: longRelayTimeoutMs
2023-08-30 15:47:01 -06:00
Corey Ogburn
a615fc8e47
New Config Default: longRelayTimeoutMs
...
Salt is getting a second timeout for operations known to take a long time such as sending and importing files. There's also an entry in soc_soc.yaml so the value can be changed in SOC's config page.
2023-08-30 15:33:01 -06:00
weslambert
ac38f32e32
Merge pull request #11218 from Security-Onion-Solutions/feature/soc_administration_analyzers
...
Analyzer SOC Administration
2023-08-30 16:54:02 -04:00
Josh Patterson
f2d1b9ac95
Merge pull request #11221 from Security-Onion-Solutions/issue/10975
...
iso desktop join grid - set install_type and minion_type
2023-08-30 16:50:46 -04:00
m0duspwnens
14a6280531
iso desktop join grid - set install_type and minion_type
2023-08-30 16:49:17 -04:00
weslambert
41300af944
Set global to false
2023-08-30 16:30:32 -04:00
weslambert
21e91a7537
Fix api_version
2023-08-30 16:10:38 -04:00
weslambert
4127e0fc53
Merge pull request #11219 from Security-Onion-Solutions/fix/elastic_fortigate
...
Correct Fortigate Integration
2023-08-30 15:54:39 -04:00
weslambert
d090852895
Correct fortigate template name
2023-08-30 15:40:40 -04:00
weslambert
78915f900b
Add fortigate package
2023-08-30 15:37:30 -04:00
Wes
8cc19b0748
Add analyzer configuration description
2023-08-30 19:16:38 +00:00
Wes
fe690922de
Add analyzer configuration to the defaults file
2023-08-30 19:16:05 +00:00
Josh Patterson
257a471383
Merge pull request #11217 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-08-30 12:28:34 -04:00
weslambert
bee83a320b
Merge pull request #11212 from Security-Onion-Solutions/fix/elastic_heavynode_syslog
...
Add syslog to heavynode
2023-08-30 10:48:03 -04:00
m0duspwnens
b45e114ef2
cant use GLOBALS var due to desktop nongrid install
2023-08-30 10:41:34 -04:00
m0duspwnens
b14614ae53
need $ for vars
2023-08-30 10:32:13 -04:00
m0duspwnens
8381fa1d42
cant import globals because of nongrid desktop install~
2023-08-30 10:26:24 -04:00
m0duspwnens
a3eeba4761
do networking_needful for nongrid desktop network install
2023-08-30 09:51:09 -04:00
m0duspwnens
97587064f8
remove packages from nongrid desktop install
2023-08-30 09:48:52 -04:00
m0duspwnens
ae01da780e
desktop network install nongrid
2023-08-30 09:10:59 -04:00
Wes
60b0af5ab7
Allow external syslog
2023-08-30 13:05:30 +00:00
Wes
0e22acc255
Add tcp and udp integration
2023-08-30 13:04:32 +00:00
Wes
655eea2b00
Add port_bindings
2023-08-30 13:03:56 +00:00
Wes
ce05f29dc4
Add port_bindings for port 514
2023-08-30 13:03:28 +00:00
weslambert
7e12167b52
Merge pull request #11208 from Security-Onion-Solutions/fix/elasticsearch_syslog
...
Make sure a data stream is created for syslog
2023-08-30 08:37:39 -04:00
weslambert
706a6e2d56
Make sure a data stream is created for syslog
2023-08-30 08:34:04 -04:00
m0duspwnens
a4dc482372
add is_desktop_grid var
2023-08-29 13:10:06 -04:00
weslambert
f4191fb7fa
Merge pull request #11197 from Security-Onion-Solutions/feature/elastic_integration_apache
...
Add Apache package and templates
2023-08-29 11:27:08 -04:00
weslambert
d2063c7e11
Add auditd reference back
2023-08-29 11:14:49 -04:00
weslambert
c01a9006a6
Add Apache package
2023-08-29 11:01:22 -04:00
weslambert
f118e25e8c
Add Apache references
2023-08-29 11:00:31 -04:00
weslambert
d40bbf6b09
Add Apache templates
2023-08-29 10:59:40 -04:00
m0duspwnens
0455063a39
edit other/desktop install whiptail
2023-08-29 10:26:29 -04:00
m0duspwnens
532b2c222a
edit other/desktop install whiptail
2023-08-29 10:16:51 -04:00
m0duspwnens
67ea7d31e1
dont exec so-setup desktop
2023-08-29 09:32:10 -04:00
m0duspwnens
a1b1294247
desktop doesnt need docker state
2023-08-29 09:05:01 -04:00
m0duspwnens
1c3d3d703c
add desktop.map.jinja for global vars
2023-08-29 08:56:01 -04:00
m0duspwnens
9c3e3f8e06
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-28 15:42:04 -04:00
Mike Reeves
48e5cf7e67
Merge pull request #11193 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Heavy Node for acks
2023-08-28 14:42:10 -04:00
Mike Reeves
bd61ee22be
Update defaults.map.jinja
2023-08-28 14:41:06 -04:00
Josh Patterson
4f8a0c4173
Merge pull request #11190 from Security-Onion-Solutions/failreposync
...
Failreposync
2023-08-28 12:01:44 -04:00
m0duspwnens
6b0fbe4634
include so-repo-sync in soup_manager_scripts state
2023-08-28 11:53:45 -04:00
Jason Ertel
2616a2bba3
Merge pull request #11186 from Security-Onion-Solutions/jertel/alts
...
fix path to intermediate ca cert on heavy nodes
2023-08-28 11:10:04 -04:00
Jason Ertel
c10e686ec6
fix path to intermediate ca cert on heavy nodes
2023-08-28 11:07:28 -04:00
m0duspwnens
a8ec3717c4
fail soup if so-repo-sync fails
2023-08-28 10:20:53 -04:00
Josh Patterson
7dc855bbbe
Merge pull request #11184 from Security-Onion-Solutions/wheelwatchdog
...
dont need to repo_sync rocky or centos
2023-08-28 09:53:34 -04:00
m0duspwnens
1ef4d2cde1
dont need to repo_sync rocky or centos
2023-08-28 09:37:45 -04:00
Jason Ertel
8c5aa4a0e6
Merge pull request #11178 from Security-Onion-Solutions/jertel/alts
...
ingest pfsense sample data
2023-08-25 16:53:41 -04:00
Jason Ertel
5879eeabfa
ingest pfsense sample data
2023-08-25 16:45:31 -04:00
Jason Ertel
022ee36bca
ingest pfsense sample data
2023-08-25 16:44:03 -04:00
Josh Patterson
aacd689bae
Merge pull request #11177 from Security-Onion-Solutions/wheelwatchdog
...
new python watchdog
2023-08-25 15:32:52 -04:00
m0duspwnens
388c90f641
add oel to set_os
2023-08-25 14:56:42 -04:00
m0duspwnens
c22f9687fb
sync local repo in soup
2023-08-25 13:40:34 -04:00
m0duspwnens
0a88c812e8
differnet watchdog package names for debian vs redhat fams
2023-08-25 13:03:33 -04:00
m0duspwnens
e28ff38d39
Merge remote-tracking branch 'origin/2.4/dev' into wheelwatchdog
2023-08-25 09:40:16 -04:00
m0duspwnens
ab1d97c985
restart filecheck if watchdog pkg changes
2023-08-25 09:39:16 -04:00
m0duspwnens
4a489afb89
remove old and install new watchdog package
2023-08-25 08:55:00 -04:00
Jason Ertel
c957c6ce14
Merge pull request #11169 from Security-Onion-Solutions/jertel/alts
...
fix centos install
2023-08-24 15:06:10 -04:00
Jason Ertel
e57cc03084
fix centos install
2023-08-24 14:41:04 -04:00
Jason Ertel
3a0590f950
Merge pull request #11166 from Security-Onion-Solutions/jertel/alts
...
use the correct var
2023-08-24 13:08:35 -04:00
Jason Ertel
43e4cf632a
use the correct var
2023-08-24 12:57:35 -04:00
Jason Ertel
92c6229e00
Merge pull request #11165 from Security-Onion-Solutions/jertel/alts
...
allow testing runs to proceed with unsupported os
2023-08-24 12:30:07 -04:00
Jason Ertel
8252924203
allow testing runs to proceed with unsupported os
2023-08-24 12:16:25 -04:00
Jason Ertel
bdb88cc87b
Merge pull request #11161 from Security-Onion-Solutions/jertel/alts
...
use consistent cert dir and reduce jinja complexity
2023-08-24 11:18:34 -04:00
Jason Ertel
f4be5641da
cert work
2023-08-23 20:49:37 -04:00
Jason Ertel
4484e2d031
cert work
2023-08-23 18:16:49 -04:00
Jason Ertel
b8dc9ea560
cert work
2023-08-23 17:50:08 -04:00
weslambert
d4bffba736
Merge pull request #11153 from Security-Onion-Solutions/fix/elastic_fleet_integrations
...
Add more Elastic Fleet integrations
2023-08-23 16:22:14 -04:00
Wes
d2d0d53eef
Change order
2023-08-23 20:20:44 +00:00
Wes
31a49268cb
Add o365 and okta
2023-08-23 20:20:06 +00:00
Wes
2f51349ff8
Add SOC configuration
2023-08-23 20:07:42 +00:00
m0duspwnens
a885baf960
add desktop to grid
2023-08-23 15:24:32 -04:00
Wes
3f2793088a
Add templates
2023-08-23 19:02:50 +00:00
Wes
0f24c8e8bb
Add packages
2023-08-23 19:02:32 +00:00
Jason Ertel
8a751e097d
cert path refactor
2023-08-23 14:32:05 -04:00
weslambert
4a582804b0
Merge pull request #11139 from Security-Onion-Solutions/fix/soc_event_fields
...
Update SOC event fields
2023-08-22 10:46:38 -04:00
Mike Reeves
f278056493
Merge pull request #11129 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update HOTFIX
2023-08-21 16:30:34 -04:00
Mike Reeves
f2c665e4fa
Update HOTFIX
2023-08-21 16:30:02 -04:00
Mike Reeves
ce32a0081e
Merge pull request #11128 from Security-Onion-Solutions/2.4/main
...
Merge in hotfix
2023-08-21 16:29:40 -04:00
weslambert
563a495725
Add Playbook
2023-08-21 11:24:07 -04:00
weslambert
9e18fe64cf
Remove OSSEC configuration
2023-08-21 11:20:47 -04:00
weslambert
708a681ed9
Merge pull request #11123 from Security-Onion-Solutions/fix/elastic_fleet_zeek_console
...
Exclude console log
2023-08-21 10:31:32 -04:00
Josh Patterson
a40937409a
Merge pull request #11124 from Security-Onion-Solutions/issue/11122
...
add missing containers to soc_docker.yaml. force port bindings to []string
2023-08-21 10:28:32 -04:00
m0duspwnens
b8d374b2af
add missing containers to soc_docker.yaml. force port bindings to []string
2023-08-21 09:45:23 -04:00
weslambert
fa31bd4bf7
Exclude console log
2023-08-21 09:20:49 -04:00
Josh Brower
5b453ca972
Merge pull request #11113 from Security-Onion-Solutions/2.4/rec-certs-fix
...
Fix certs for Rec & Heavy
2023-08-21 07:03:58 -04:00
Josh Brower
6784bdcb54
Fix certs for Rec & Heavy
2023-08-20 15:46:07 -04:00
Josh Patterson
e77e5c3cea
Merge pull request #11090 from Security-Onion-Solutions/issue/10998
...
Issue/10998
2023-08-17 17:27:45 -04:00
Jason Ertel
222352b4b3
fix typo
2023-08-17 17:26:35 -04:00
m0duspwnens
4ac95447eb
pop sort settings if index_sorting is false
2023-08-17 16:15:27 -04:00
m0duspwnens
9cba9d9ae0
allow to override number_of_replicas from one place in soc ui
2023-08-17 15:00:01 -04:00
Jason Ertel
e7be8991f1
Merge pull request #11083 from Security-Onion-Solutions/jertel/souptty
...
force image pulls to go into soup log
2023-08-17 13:47:37 -04:00
Jason Ertel
09dd3f529b
force image pulls to go into soup log
2023-08-17 13:45:51 -04:00
Mike Reeves
abad833c5e
Merge pull request #11075 from Security-Onion-Solutions/2.4/soupmods
...
Add soup for 2.4.20
2023-08-17 10:53:52 -04:00
Mike Reeves
4363e71e80
Add soup for 2.4.20
2023-08-17 10:51:59 -04:00
Josh Patterson
45bc2ec380
Merge pull request #11060 from Security-Onion-Solutions/issue/10922
...
set timezone during setup. set salt log levels to info
2023-08-16 10:47:13 -04:00
m0duspwnens
9bf7b9bda5
set the timezone earlier in setup
2023-08-16 10:02:47 -04:00
m0duspwnens
ab19fa9ece
set salt log levels to info
2023-08-16 09:21:06 -04:00
m0duspwnens
53d7d69135
update salt docs url in service file
2023-08-16 08:46:24 -04:00
m0duspwnens
b22776dc5a
set timezone to etc/utc during setup
2023-08-15 16:22:02 -04:00
Mike Reeves
dc6d9d4ba2
Merge pull request #11047 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-08-15 07:29:34 -04:00
Mike Reeves
075ef5e02c
Update VERSION
2023-08-15 07:27:48 -04:00
Jason Ertel
5c7c3fb996
avoid rare false positive when dasbhoard load completes during setup
2023-07-31 16:09:36 -04:00
Jason Ertel
f4907a5b5c
Merge branch '2.4/dev' into kilo
2023-07-28 14:15:14 -04:00
Jason Ertel
a5c4783564
oidc
2023-07-27 18:36:50 -04:00
Jason Ertel
d3e83d154b
Merge branch '2.4/t dev' into kilo
2023-07-27 10:20:22 -04:00
Jason Ertel
aa36e9a785
oidc
2023-07-27 08:40:27 -04:00
Jason Ertel
b712d505f2
update version to use kilo images
2023-07-26 09:21:23 -04:00
Jason Ertel
6d56deb2e4
oidc 1
2023-07-25 08:12:45 -04:00
Jason Ertel
101e2e8ba1
do not redirect to API URLs when not logged in
2023-07-24 17:05:52 -04:00
Jason Ertel
83bff72cd4
Merge branch '2.4/dev' into kilo
2023-07-18 10:49:12 -04:00
Jason Ertel
b24afac0f4
upgrade registry version
2023-07-18 10:48:42 -04:00
Jason Ertel
b129b4ceaa
prepare for alt login
2023-07-14 17:03:20 -04:00