Mike Reeves
1b5cd4f53a
Merge pull request #11532 from Security-Onion-Solutions/hotfix/2.4.20
...
Hotfix 2.4.20
2023-10-12 16:16:49 -04:00
Mike Reeves
acc6715f90
Merge pull request #11531 from Security-Onion-Solutions/2.4.20hf
...
2.4.20 hotfix
2023-10-12 15:52:44 -04:00
Mike Reeves
b6af59d9b0
2.4.20 hotfix
2023-10-12 15:47:53 -04:00
Josh Brower
8ce70e1f18
Merge pull request #11525 from Security-Onion-Solutions/hotfixfunctions
...
Apply named state
2023-10-12 11:05:32 -04:00
defensivedepth
98eab906af
Apply named state
2023-10-12 11:00:24 -04:00
Josh Brower
d558f20715
Merge pull request #11524 from Security-Onion-Solutions/hotfixfunctions
...
Apply state correctly
2023-10-12 10:56:43 -04:00
defensivedepth
967138cdff
Apply state correctly
2023-10-12 10:54:26 -04:00
Josh Brower
c76ac717f2
Merge pull request #11522 from Security-Onion-Solutions/hotfixfunctions
...
Add hotfix changes
2023-10-12 09:52:55 -04:00
defensivedepth
a671ac387a
Add hotfix changes
2023-10-12 09:45:20 -04:00
defensivedepth
1043315e6b
Manage Elastic Defend Integration manually
2023-10-12 09:22:26 -04:00
Mike Reeves
fc0e3c0124
Merge pull request #11476 from Security-Onion-Solutions/2.4/dev
...
2.4.20
2023-10-06 16:45:11 -04:00
Mike Reeves
32c1d6f95c
Merge pull request #11475 from Security-Onion-Solutions/2.4.20
...
2.4.20
2023-10-05 11:41:55 -04:00
Mike Reeves
c25aed9a2b
Update DOWNLOAD_AND_VERIFY_ISO.md
2023-10-05 11:37:49 -04:00
Mike Reeves
d79e27774c
2.4.20
2023-10-05 11:27:48 -04:00
Mike Reeves
194178a250
Merge pull request #11465 from Security-Onion-Solutions/fix/pkgs
...
Fix/pkgs
2023-10-03 10:17:37 -04:00
m0duspwnens
d78b55873d
remove mariadb-devel
2023-10-03 10:15:28 -04:00
Mike Reeves
f3ba28062b
Remove MySQL
2023-10-03 10:05:56 -04:00
m0duspwnens
2434ce14d3
remove removing mariadb-devel
2023-10-03 10:01:07 -04:00
m0duspwnens
66be04e78a
remove mariadb
2023-10-03 09:53:40 -04:00
Jason Ertel
62e9472f1a
Merge pull request #11464 from Security-Onion-Solutions/jertel/lc
...
exclude known issues
2023-10-03 09:46:18 -04:00
Jason Ertel
c699c2fe2a
exclude known issues
2023-10-03 09:43:29 -04:00
Mike Reeves
a35889ebdc
Merge pull request #11461 from Security-Onion-Solutions/fix/pkgs
2023-10-02 17:38:38 -04:00
m0duspwnens
8995752c27
let openssl-devel be installed with mariadb
2023-10-02 16:17:26 -04:00
m0duspwnens
57e76232ec
openssl pkgs in own state
2023-10-02 15:48:53 -04:00
m0duspwnens
d7a14d9e00
update holds
2023-10-02 15:08:22 -04:00
m0duspwnens
6b90961e87
openssl-libs
2023-10-02 14:26:28 -04:00
m0duspwnens
6547afe6c0
dont hold openssl-devel
2023-10-02 13:35:00 -04:00
m0duspwnens
3a5c6ee43a
install version lock before we try to hold pkgs
2023-10-02 12:09:13 -04:00
m0duspwnens
0f08d5d640
install openssl version 1:3.0.7-16.0.1.el9_2
2023-10-02 11:43:03 -04:00
m0duspwnens
f85dd910a3
hold openssl from update during setup
2023-10-02 11:13:08 -04:00
m0duspwnens
c1ab8952eb
hold openssl-devel
2023-10-02 10:59:51 -04:00
m0duspwnens
dfe399291f
hold openssl-libs
2023-10-02 10:54:41 -04:00
m0duspwnens
70a36bafa5
remove -
2023-10-02 10:38:54 -04:00
m0duspwnens
381d95e032
Merge remote-tracking branch 'origin/2.4/dev' into fix/pkgs
2023-10-02 10:37:12 -04:00
m0duspwnens
cd8a74290b
hold openssl version
2023-10-02 10:36:17 -04:00
Jason Ertel
d91eaa9ae5
Merge pull request #11448 from Security-Onion-Solutions/jertel/lc
...
fix exclusion
2023-09-30 18:16:23 -04:00
Jason Ertel
8c7933cd60
fix exclusion
2023-09-30 18:11:29 -04:00
Jason Ertel
88f461042d
Merge pull request #11442 from Security-Onion-Solutions/jertel/lc
...
more known errors
2023-09-29 21:43:51 -04:00
Jason Ertel
ea085c5ff6
more known errors
2023-09-29 21:38:13 -04:00
Jason Ertel
19232124f2
Merge pull request #11441 from Security-Onion-Solutions/jertel/lc
...
exclude oom error from cmd line
2023-09-29 14:21:05 -04:00
Jason Ertel
e8b67da08b
exclude oom error from cmd line
2023-09-29 14:20:20 -04:00
Jason Ertel
b5d19bd561
Merge pull request #11440 from Security-Onion-Solutions/jertel/lc
...
exclude logstash errors
2023-09-29 14:13:34 -04:00
Jason Ertel
d546d52069
exclude logstash
2023-09-29 14:08:44 -04:00
Josh Patterson
13cc8c4258
Merge pull request #11437 from Security-Onion-Solutions/telegraf/redis
...
remove redis from eval
2023-09-29 11:12:24 -04:00
m0duspwnens
9d3f6059ee
remove redis from eval
2023-09-29 11:10:08 -04:00
Jason Ertel
43855b8ca2
Merge pull request #11436 from Security-Onion-Solutions/jertel/lc
...
exclude all playbook logs
2023-09-29 11:04:48 -04:00
Jason Ertel
ec3cc7a854
exclude all playbook logs
2023-09-29 10:49:36 -04:00
Mike Reeves
63be7ef6ca
Merge pull request #11432 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update defaults.yaml
2023-09-28 19:48:14 -04:00
Mike Reeves
b8aad7f5e6
Update defaults.yaml
2023-09-28 19:44:49 -04:00
weslambert
c02e491609
Merge pull request #11430 from Security-Onion-Solutions/fix/elastic_packages
...
Upgrade packages and load integrations when packages change
2023-09-28 14:10:39 -04:00
Wes
670cd19051
Exclude package upgrade script
2023-09-28 18:04:07 +00:00
Wes
8c44481ee1
Load templates after package changes
2023-09-28 17:57:31 +00:00
Mike Reeves
a8c94a891b
Merge pull request #11426 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Fix Yara crontab
2023-09-28 13:09:11 -04:00
Mike Reeves
ff35946050
Fix manager cron logic
2023-09-28 13:06:21 -04:00
Mike Reeves
95d32cb076
Fix manager cron logic
2023-09-28 12:49:46 -04:00
Wes
018186ccbd
Upgrade packages and load integrations when packages change
2023-09-28 16:43:56 +00:00
Mike Reeves
5040df7551
Fix manager cron logic
2023-09-28 12:32:40 -04:00
Jason Ertel
c3604f6e80
Merge pull request #11422 from Security-Onion-Solutions/jertel/lc
...
exclude known issues
2023-09-28 11:47:13 -04:00
Mike Reeves
7a21b7903d
Fix manager cron logic
2023-09-28 11:46:43 -04:00
Mike Reeves
a77a53f20b
Update init.sls
2023-09-28 11:10:17 -04:00
Mike Reeves
ee45fc31a2
Delete salt/strelka/tools/sbin_jinja/so-yara-download
2023-09-28 11:04:16 -04:00
weslambert
ceae22adab
Merge pull request #11423 from Security-Onion-Solutions/fix/elastic_known_certs
...
Exclude known_certs
2023-09-28 09:20:38 -04:00
weslambert
202eb7e876
Exclude known_certs
2023-09-28 09:16:56 -04:00
Jason Ertel
89a9c30cc8
exclude known issues
2023-09-28 08:27:31 -04:00
Jason Ertel
7012ff6609
Merge pull request #11418 from Security-Onion-Solutions/jertel/lc
...
more exclusions
2023-09-28 08:02:29 -04:00
Jason Ertel
621da9e7e3
more exclusions
2023-09-27 22:20:54 -04:00
Jason Ertel
26bb0d064f
Merge pull request #11417 from Security-Onion-Solutions/jertel/lc
...
logcheck improvements
2023-09-27 20:35:06 -04:00
Jason Ertel
9ee64f93ca
logcheck improvements
2023-09-27 20:17:59 -04:00
Jason Ertel
641ff95f41
Merge pull request #11416 from Security-Onion-Solutions/jertel/lc
...
Jertel/lc
2023-09-27 20:03:58 -04:00
Jason Ertel
49115cde55
logcheck improvements
2023-09-27 19:55:46 -04:00
Josh Patterson
7d0e1c92a3
Merge pull request #11415 from Security-Onion-Solutions/issue/11390
...
Issue/11390
2023-09-27 19:39:36 -04:00
m0duspwnens
419acab48a
revert up_to_2.4.20
2023-09-27 19:17:13 -04:00
m0duspwnens
528572c15b
Merge remote-tracking branch 'origin/2.4/dev' into issue/11390
2023-09-27 18:42:07 -04:00
Jason Ertel
d72e4ae97d
ignore soctopus errors
2023-09-27 18:39:23 -04:00
m0duspwnens
76c0b881ff
exclude import from snapshotting previous version pillars and states
2023-09-27 18:20:50 -04:00
Jason Ertel
836c49b755
Merge pull request #11414 from Security-Onion-Solutions/jertel/lc
...
ignore generic python stack trace log lines of code, rely on actual e…
2023-09-27 16:59:34 -04:00
Jason Ertel
24def3a196
ignore generic python stack trace log lines of code, rely on actual error messages
2023-09-27 16:50:01 -04:00
Mike Reeves
b6d58b2fb8
Merge pull request #11411 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
FIX: Remove telegraf beats EPS script
2023-09-27 16:14:51 -04:00
Mike Reeves
770a74c83d
Merge pull request #11409 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Fix zeek from creating summary files
2023-09-27 16:14:34 -04:00
Mike Reeves
039d5ae9aa
Delete salt/telegraf/scripts/beatseps.sh
2023-09-27 16:09:27 -04:00
Mike Reeves
2fb73cd516
Update defaults.yaml
2023-09-27 16:07:38 -04:00
Mike Reeves
2427344dca
Update defaults.yaml
2023-09-27 15:58:58 -04:00
Mike Reeves
62cb661bab
Merge pull request #11408 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix sendmail errors in zeek
2023-09-27 15:53:50 -04:00
Jason Ertel
1e04199ea6
Merge pull request #11406 from Security-Onion-Solutions/jertel/lc
...
ignore generic python stack trace log lines of code, rely on actual e…
2023-09-27 15:52:48 -04:00
Jason Ertel
4666916077
ignore generic python stack trace log lines of code, rely on actual error messages
2023-09-27 15:48:52 -04:00
Mike Reeves
f094b1162d
Update defaults.yaml
2023-09-27 15:48:05 -04:00
Jason Ertel
ae9619f0c3
Merge pull request #11405 from Security-Onion-Solutions/jertel/lc
...
deb OS doesn't use /var/log/cron, skip
2023-09-27 15:42:10 -04:00
Jason Ertel
87cc389088
deb OS doesn't use /var/log/cron, skip
2023-09-27 15:36:13 -04:00
Josh Patterson
ec046a6943
Merge pull request #11404 from Security-Onion-Solutions/fix/filecheckcron
...
Fix/filecheckcron
2023-09-27 12:51:25 -04:00
Mike Reeves
7eefe7b79c
Merge pull request #11403 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update nginx.conf to use user nobody
2023-09-27 12:38:58 -04:00
Mike Reeves
c4fea9cb9d
Update nginx.conf
2023-09-27 11:03:58 -04:00
m0duspwnens
3fded86aa1
Merge remote-tracking branch 'origin/2.4/dev' into fix/filecheckcron
2023-09-27 10:08:17 -04:00
m0duspwnens
05e7c32cf9
remove duplicate filecheck_run cron
2023-09-27 10:08:08 -04:00
Jason Ertel
af2ff2b07c
Merge pull request #11399 from Security-Onion-Solutions/jertel/lc
...
don't inspect imported zeek output
2023-09-27 09:45:39 -04:00
Jason Ertel
b47d915cb6
don't inspect imported zeek output
2023-09-27 09:30:19 -04:00
Jason Ertel
376d525ad7
Merge pull request #11398 from Security-Onion-Solutions/jertel/lc
...
skip zeek spool logs due to test data false positives
2023-09-26 22:01:50 -04:00
Jason Ertel
9c854a13cc
skip zeek spool logs due to test data false positives
2023-09-26 21:41:44 -04:00
Jason Ertel
ff780738fd
Merge pull request #11397 from Security-Onion-Solutions/jertel/lc
...
log check tool initial
2023-09-26 18:23:41 -04:00
Jason Ertel
2c8d413f16
log check tool initial
2023-09-26 18:14:37 -04:00
Jason Ertel
48801da44e
log check tool initial
2023-09-26 18:12:20 -04:00
Josh Patterson
641b8ef0b6
Merge pull request #11393 from Security-Onion-Solutions/issue/11390
...
Issue/11390
2023-09-26 13:26:42 -04:00
m0duspwnens
036a21ff17
Merge remote-tracking branch 'origin/2.4/dev' into issue/11390
2023-09-26 11:01:44 -04:00
m0duspwnens
2abf434ebe
create snapshots of default, local salt and pillars during soup. rsync soup with --delete
2023-09-26 10:56:20 -04:00
weslambert
4dc477cc1d
Merge pull request #11391 from Security-Onion-Solutions/fix/elasticsearch_strelka_image_version
...
Make scan.pe.image_version type of 'float'
2023-09-26 10:21:17 -04:00
Wes
0bba68769b
Make scan.pe.image_version type of 'float'
2023-09-26 14:05:12 +00:00
m0duspwnens
e25d1c0ff3
so-salt-minion-check is jinja template
2023-09-26 10:01:21 -04:00
weslambert
f9ace4791f
Merge pull request #11384 from Security-Onion-Solutions/fix/analyzers_testing
...
Add a note about testing analyzers outside of the Sensoroni Docker container
2023-09-25 14:48:45 -04:00
weslambert
7cb9b5f257
Add the blank line that was removed from the previous commit
2023-09-25 14:41:20 -04:00
weslambert
c95af6b992
Add a note about testing analyzers outside of the Sensoroni Docker container
2023-09-25 14:39:33 -04:00
weslambert
2fc4d2923d
Merge pull request #11289 from Security-Onion-Solutions/fix/elastic_agent_404
...
/app/dashboards to /kibana/app/dashboards
2023-09-25 09:11:50 -04:00
Wes
eeeae08ec8
/app/ to /app/dashboards/
2023-09-21 18:39:06 +00:00
Jason Ertel
220f25e206
Merge pull request #11369 from Security-Onion-Solutions/jertel-patch-1
...
Update soup to prune in background
2023-09-21 09:42:28 -04:00
Jason Ertel
fa3a79a787
Update soup to prune in background
2023-09-21 09:41:44 -04:00
Doug Burks
ca71add51b
Merge pull request #11363 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Config sensoroni doc links should point to correct docs #11362
2023-09-20 08:29:30 -04:00
Doug Burks
3fa3f83007
Update soc_sensoroni.yaml
2023-09-20 08:22:52 -04:00
weslambert
377802410e
Merge pull request #11352 from Security-Onion-Solutions/fix/import_evtx_exists
...
Fix EVTX Imports
2023-09-19 16:11:22 -04:00
Wes
2e0ea3f374
Set final pipeline
2023-09-19 13:33:12 +00:00
Wes
508260bd46
Use event.created for timestamp
2023-09-19 13:32:03 +00:00
Wes
a1e963f834
Reverse timestamps where necessary
2023-09-19 13:28:20 +00:00
Jason Ertel
8a98040008
Merge pull request #11351 from Security-Onion-Solutions/jertel/auto
...
ignore debian apt update output
2023-09-19 09:26:31 -04:00
Jason Ertel
47e611682a
ignore debian apt update output
2023-09-19 09:24:12 -04:00
Wes
5bac1e4d15
Show correct dates and Kibana URL for already processed EVTX files
2023-09-18 21:31:15 +00:00
Jason Ertel
ad025b9683
Merge pull request #11345 from Security-Onion-Solutions/jertel/auto
...
ensure all binds are present to avoid volume sprawl
2023-09-18 15:34:57 -04:00
Josh Patterson
3e97ddc22d
Merge pull request #11344 from Security-Onion-Solutions/fix/idstoolextra_env
...
fix idstool extra_env for container
2023-09-18 15:29:33 -04:00
m0duspwnens
151e8bfc4e
fix idstool extra_env for container
2023-09-18 15:21:45 -04:00
Jason Ertel
a914a02273
prune unused volumes during upgrade
2023-09-18 14:43:02 -04:00
Jason Ertel
bb3632d1b2
fix bind if statement
2023-09-18 14:38:15 -04:00
Jason Ertel
66bb1272ae
avoid volume sprawl
2023-09-18 13:39:56 -04:00
Jason Ertel
bbef96ac25
use unique name
2023-09-18 12:12:57 -04:00
Jason Ertel
f9cbde10a6
avoid volume sprawl
2023-09-18 11:19:21 -04:00
weslambert
fe1bae96ed
Merge pull request #11297 from Security-Onion-Solutions/fix/soc_idh
...
Change description to indicate that opencanary modules only apply to IDH nodes
2023-09-15 11:16:06 -04:00
weslambert
eab6173a31
Merge pull request #11329 from Security-Onion-Solutions/fix/elastic_templates_clean
...
Clean component template directory
2023-09-15 11:00:17 -04:00
Wes
98499c3963
Clean component template directory
2023-09-15 13:51:46 +00:00
Josh Patterson
26da525ebe
Merge pull request #11328 from Security-Onion-Solutions/fix/checkreq
...
improvents for checking system requirements
2023-09-15 09:17:04 -04:00
m0duspwnens
c65c9777bd
improvents for checking system requirements
2023-09-14 17:42:25 -04:00
Josh Brower
af68af7f18
Merge pull request #11317 from Security-Onion-Solutions/2.4/fixes
...
Regex & Transform Role
2023-09-14 10:59:56 -04:00
defensivedepth
0c11a9b733
Add transform role
2023-09-14 09:33:17 -04:00
defensivedepth
59d077f3ff
Fix regex
2023-09-14 08:32:17 -04:00
Jason Ertel
6383712731
Merge pull request #11315 from Security-Onion-Solutions/jertel/auto
...
exclude docker pull unauth errors from failing setup
2023-09-14 07:41:59 -04:00
Jason Ertel
e067b7134e
exclude docker pull unauth errors from failing setup since they'll be retried
2023-09-14 07:38:07 -04:00
Mike Reeves
183c530c82
Merge pull request #11308 from Security-Onion-Solutions/pcapfree
...
Update so-minion
2023-09-13 13:47:21 -04:00
Mike Reeves
33d68478b6
Update so-minion
2023-09-13 11:48:16 -04:00
Mike Reeves
22c0323bda
Update so-minion
2023-09-13 10:57:45 -04:00
Doug Burks
19114c1a26
Merge pull request #11303 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Config pcap doc links should point to steno docs #11302
2023-09-13 07:50:43 -04:00
Doug Burks
11b8e13418
FIX: SOC Config pcap doc links should point to steno docs #11302
2023-09-13 07:37:54 -04:00
Josh Patterson
6fdd7b3751
Merge pull request #11295 from Security-Onion-Solutions/issue/11229
...
dont manage sorules
2023-09-12 09:30:29 -04:00
m0duspwnens
30c3255cb2
dont manage sorules
2023-09-12 08:39:42 -04:00
Wes
35ebbc974c
Change description to indicate that opencanary modules only apply to IDH nodes
2023-09-11 13:52:16 +00:00
Wes
f1d0db8171
/app to /kibana/app
2023-09-11 13:30:11 +00:00
Josh Patterson
9968d697f3
Merge pull request #11288 from Security-Onion-Solutions/issue/11229
...
Issue/11229
2023-09-11 09:19:31 -04:00
m0duspwnens
02c54a264d
Merge remote-tracking branch 'origin/2.4/dev' into issue/11229
2023-09-08 15:29:04 -04:00
m0duspwnens
e814a3409f
fix rule location for rulecat.conf. run so-rule-update if rules change in /opt/so/rules/nids
2023-09-08 15:28:24 -04:00
Jason Ertel
55847c7bdc
Merge pull request #11276 from Security-Onion-Solutions/jertel/auto
...
give priority to presets
2023-09-08 09:26:27 -04:00
Jason Ertel
598515e5b4
give priority to presets
2023-09-08 09:21:13 -04:00
Jason Ertel
692625f8cd
Merge pull request #11271 from Security-Onion-Solutions/jertel/auto
...
addl node types
2023-09-07 17:25:08 -04:00
Jason Ertel
f8ae3f12e6
addl node types
2023-09-07 17:22:10 -04:00
Josh Patterson
3780ed1b4f
Merge pull request #11269 from Security-Onion-Solutions/issue/11210
...
Issue/11210
2023-09-07 16:54:16 -04:00
m0duspwnens
8d269fee30
Merge remote-tracking branch 'origin/2.4/dev' into issue/11210
2023-09-07 15:46:25 -04:00
m0duspwnens
35157f2e8b
add comment
2023-09-07 15:46:04 -04:00
m0duspwnens
60f1947eb4
prevent endgame_dict from being added to standard_actions if it is already present
2023-09-07 14:01:19 -04:00
m0duspwnens
ffaab4a1b4
only add endgame to action if it is populated
2023-09-06 14:19:53 -04:00
weslambert
70e1309c9f
Merge pull request #11261 from Security-Onion-Solutions/fix/remove_default_templates
...
Remove templates
2023-09-06 10:57:09 -04:00
Jason Ertel
5c0045f9f8
Merge pull request #11256 from Security-Onion-Solutions/jertel/sod
...
only ingest pfsense on sensor nodes
2023-09-05 12:50:47 -04:00
Jason Ertel
b66be9c226
only ingest pfsense on sensor nodes
2023-09-05 12:46:49 -04:00
Josh Patterson
651393988a
Merge pull request #11255 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-09-05 11:57:58 -04:00
Wes
cf19c8f8c2
Remove templates
2023-09-05 13:43:41 +00:00
Mike Reeves
ba3ae92702
Merge pull request #11249 from Security-Onion-Solutions/jertel/sod
2023-09-03 22:23:55 -04:00
Jason Ertel
8e2bed7f91
MS testing
2023-09-03 19:56:40 -04:00
Jason Ertel
028b69c7d4
Merge pull request #11245 from Security-Onion-Solutions/jertel/sod
...
ensure hostname is set
2023-09-02 13:49:49 -04:00
Jason Ertel
0cf913a7c1
ensure hostname is set
2023-09-02 06:05:37 -04:00
Jason Ertel
13fbcd712b
Merge pull request #11243 from Security-Onion-Solutions/jertel/sod
...
ensure hostname is set
2023-09-01 20:43:35 -04:00
Jason Ertel
0aae107155
ensure hostname is set
2023-09-01 20:30:53 -04:00
Mike Reeves
d2dcf7e7c1
Merge pull request #11241 from Security-Onion-Solutions/jertel/sod
2023-09-01 18:22:38 -04:00
Jason Ertel
6efdf1b9d0
add additional test modes
2023-09-01 17:24:12 -04:00
Jason Ertel
a11259c683
add additional test modes
2023-09-01 17:08:27 -04:00
Jason Ertel
863db14b61
add additional test modes
2023-09-01 16:27:02 -04:00
Jason Ertel
335aaa5594
add additional test modes
2023-09-01 15:30:53 -04:00
m0duspwnens
07ed93de19
add elastic agent to desktop
2023-09-01 14:33:32 -04:00
Jason Ertel
8093e5ce7c
use IP to avoid host issues
2023-09-01 13:01:17 -04:00
m0duspwnens
585fba4bc6
add functions salt_install_module_deps and salt_patch_x509_v2
2023-09-01 12:40:01 -04:00
weslambert
b8f69b5008
Merge pull request #11239 from Security-Onion-Solutions/fix/syslog_heavynode
...
Add so-elastic-agent
2023-09-01 12:20:44 -04:00
m0duspwnens
aebfb19ab7
add sostatus.sh to desktop for telegraf scripts
2023-09-01 12:05:28 -04:00
m0duspwnens
490669d378
add ssl to desktop for allowed_states
2023-09-01 12:03:01 -04:00
m0duspwnens
3434d0f200
add sensoroni and telegraf back to individual nodes. add seperate block for desktop
2023-09-01 12:02:30 -04:00
weslambert
765a22e6f0
Add so-elastic-agent
2023-09-01 11:31:23 -04:00
Jason Ertel
546c562ef0
expose standard relay timeout in config UI; up default to 45s to accommodate sluggish pillar.get calls
2023-09-01 10:31:02 -04:00
m0duspwnens
b64d4e3658
add telegraf pillar to desktop
2023-09-01 09:53:26 -04:00
m0duspwnens
0fb00d569e
allow states for desktop. give all nodes docker_clean, order it last
2023-09-01 09:39:39 -04:00
m0duspwnens
b64fa51268
give desktop docker state and pillars
2023-09-01 09:16:24 -04:00
Jason Ertel
1871d48f7f
remove unnecesary OTHER submenu
2023-08-31 20:42:00 -04:00
m0duspwnens
b010919099
add sensoroni, telegraf, common states to desktop. allow docker_registry connection to managers for desktop
2023-08-31 13:21:32 -04:00
weslambert
ce2a7135cb
Merge pull request #11232 from Security-Onion-Solutions/fix/strelka_entropy
...
Strelka entropy mapping
2023-08-31 11:21:00 -04:00
Wes
0fed757b11
Add entropy mapping
2023-08-31 15:10:27 +00:00
Wes
1a3b3b21fb
Change entropy value syntax
2023-08-31 15:09:19 +00:00
Josh Patterson
d86e21c751
Merge pull request #11231 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-08-31 10:54:30 -04:00
m0duspwnens
e408718230
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-31 09:56:02 -04:00
m0duspwnens
ee848b8a8c
comments for desktop install
2023-08-31 09:51:55 -04:00
m0duspwnens
a60c34d548
exclude unnecessary pillars from desktop nodes
2023-08-31 09:40:54 -04:00
Doug Burks
8a2fc5d62b
Merge pull request #11226 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md
2023-08-31 09:18:19 -04:00
Doug Burks
da56a421e5
Update motd.md
2023-08-31 09:17:33 -04:00
m0duspwnens
bfb0d0ddb5
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-31 08:58:28 -04:00
m0duspwnens
c812c3991e
we dont need to run convert-gnome-classic script
2023-08-31 08:54:13 -04:00
coreyogburn
ca9dad396f
Merge pull request #11222 from Security-Onion-Solutions/cogburn/11143
...
New Config Default: longRelayTimeoutMs
2023-08-30 15:47:01 -06:00
Corey Ogburn
a615fc8e47
New Config Default: longRelayTimeoutMs
...
Salt is getting a second timeout for operations known to take a long time such as sending and importing files. There's also an entry in soc_soc.yaml so the value can be changed in SOC's config page.
2023-08-30 15:33:01 -06:00
weslambert
ac38f32e32
Merge pull request #11218 from Security-Onion-Solutions/feature/soc_administration_analyzers
...
Analyzer SOC Administration
2023-08-30 16:54:02 -04:00
Josh Patterson
f2d1b9ac95
Merge pull request #11221 from Security-Onion-Solutions/issue/10975
...
iso desktop join grid - set install_type and minion_type
2023-08-30 16:50:46 -04:00
m0duspwnens
14a6280531
iso desktop join grid - set install_type and minion_type
2023-08-30 16:49:17 -04:00
weslambert
41300af944
Set global to false
2023-08-30 16:30:32 -04:00
weslambert
21e91a7537
Fix api_version
2023-08-30 16:10:38 -04:00
weslambert
4127e0fc53
Merge pull request #11219 from Security-Onion-Solutions/fix/elastic_fortigate
...
Correct Fortigate Integration
2023-08-30 15:54:39 -04:00
weslambert
d090852895
Correct fortigate template name
2023-08-30 15:40:40 -04:00
weslambert
78915f900b
Add fortigate package
2023-08-30 15:37:30 -04:00
Wes
8cc19b0748
Add analyzer configuration description
2023-08-30 19:16:38 +00:00
Wes
fe690922de
Add analyzer configuration to the defaults file
2023-08-30 19:16:05 +00:00
Josh Patterson
257a471383
Merge pull request #11217 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-08-30 12:28:34 -04:00
weslambert
bee83a320b
Merge pull request #11212 from Security-Onion-Solutions/fix/elastic_heavynode_syslog
...
Add syslog to heavynode
2023-08-30 10:48:03 -04:00
m0duspwnens
b45e114ef2
cant use GLOBALS var due to desktop nongrid install
2023-08-30 10:41:34 -04:00
m0duspwnens
b14614ae53
need $ for vars
2023-08-30 10:32:13 -04:00
m0duspwnens
8381fa1d42
cant import globals because of nongrid desktop install~
2023-08-30 10:26:24 -04:00
m0duspwnens
a3eeba4761
do networking_needful for nongrid desktop network install
2023-08-30 09:51:09 -04:00
m0duspwnens
97587064f8
remove packages from nongrid desktop install
2023-08-30 09:48:52 -04:00
m0duspwnens
ae01da780e
desktop network install nongrid
2023-08-30 09:10:59 -04:00
Wes
60b0af5ab7
Allow external syslog
2023-08-30 13:05:30 +00:00
Wes
0e22acc255
Add tcp and udp integration
2023-08-30 13:04:32 +00:00
Wes
655eea2b00
Add port_bindings
2023-08-30 13:03:56 +00:00
Wes
ce05f29dc4
Add port_bindings for port 514
2023-08-30 13:03:28 +00:00
weslambert
7e12167b52
Merge pull request #11208 from Security-Onion-Solutions/fix/elasticsearch_syslog
...
Make sure a data stream is created for syslog
2023-08-30 08:37:39 -04:00
weslambert
706a6e2d56
Make sure a data stream is created for syslog
2023-08-30 08:34:04 -04:00
m0duspwnens
a4dc482372
add is_desktop_grid var
2023-08-29 13:10:06 -04:00
weslambert
f4191fb7fa
Merge pull request #11197 from Security-Onion-Solutions/feature/elastic_integration_apache
...
Add Apache package and templates
2023-08-29 11:27:08 -04:00
weslambert
d2063c7e11
Add auditd reference back
2023-08-29 11:14:49 -04:00
weslambert
c01a9006a6
Add Apache package
2023-08-29 11:01:22 -04:00
weslambert
f118e25e8c
Add Apache references
2023-08-29 11:00:31 -04:00
weslambert
d40bbf6b09
Add Apache templates
2023-08-29 10:59:40 -04:00
m0duspwnens
0455063a39
edit other/desktop install whiptail
2023-08-29 10:26:29 -04:00
m0duspwnens
532b2c222a
edit other/desktop install whiptail
2023-08-29 10:16:51 -04:00
m0duspwnens
67ea7d31e1
dont exec so-setup desktop
2023-08-29 09:32:10 -04:00
m0duspwnens
a1b1294247
desktop doesnt need docker state
2023-08-29 09:05:01 -04:00
m0duspwnens
1c3d3d703c
add desktop.map.jinja for global vars
2023-08-29 08:56:01 -04:00
m0duspwnens
9c3e3f8e06
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-28 15:42:04 -04:00
Mike Reeves
48e5cf7e67
Merge pull request #11193 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Heavy Node for acks
2023-08-28 14:42:10 -04:00
Mike Reeves
bd61ee22be
Update defaults.map.jinja
2023-08-28 14:41:06 -04:00
Josh Patterson
4f8a0c4173
Merge pull request #11190 from Security-Onion-Solutions/failreposync
...
Failreposync
2023-08-28 12:01:44 -04:00
m0duspwnens
6b0fbe4634
include so-repo-sync in soup_manager_scripts state
2023-08-28 11:53:45 -04:00
Jason Ertel
2616a2bba3
Merge pull request #11186 from Security-Onion-Solutions/jertel/alts
...
fix path to intermediate ca cert on heavy nodes
2023-08-28 11:10:04 -04:00
Jason Ertel
c10e686ec6
fix path to intermediate ca cert on heavy nodes
2023-08-28 11:07:28 -04:00
m0duspwnens
a8ec3717c4
fail soup if so-repo-sync fails
2023-08-28 10:20:53 -04:00
Josh Patterson
7dc855bbbe
Merge pull request #11184 from Security-Onion-Solutions/wheelwatchdog
...
dont need to repo_sync rocky or centos
2023-08-28 09:53:34 -04:00
m0duspwnens
1ef4d2cde1
dont need to repo_sync rocky or centos
2023-08-28 09:37:45 -04:00
Jason Ertel
8c5aa4a0e6
Merge pull request #11178 from Security-Onion-Solutions/jertel/alts
...
ingest pfsense sample data
2023-08-25 16:53:41 -04:00
Jason Ertel
5879eeabfa
ingest pfsense sample data
2023-08-25 16:45:31 -04:00
Jason Ertel
022ee36bca
ingest pfsense sample data
2023-08-25 16:44:03 -04:00
Josh Patterson
aacd689bae
Merge pull request #11177 from Security-Onion-Solutions/wheelwatchdog
...
new python watchdog
2023-08-25 15:32:52 -04:00
m0duspwnens
388c90f641
add oel to set_os
2023-08-25 14:56:42 -04:00
m0duspwnens
c22f9687fb
sync local repo in soup
2023-08-25 13:40:34 -04:00
m0duspwnens
0a88c812e8
differnet watchdog package names for debian vs redhat fams
2023-08-25 13:03:33 -04:00
m0duspwnens
e28ff38d39
Merge remote-tracking branch 'origin/2.4/dev' into wheelwatchdog
2023-08-25 09:40:16 -04:00
m0duspwnens
ab1d97c985
restart filecheck if watchdog pkg changes
2023-08-25 09:39:16 -04:00
m0duspwnens
4a489afb89
remove old and install new watchdog package
2023-08-25 08:55:00 -04:00
Jason Ertel
c957c6ce14
Merge pull request #11169 from Security-Onion-Solutions/jertel/alts
...
fix centos install
2023-08-24 15:06:10 -04:00
Jason Ertel
e57cc03084
fix centos install
2023-08-24 14:41:04 -04:00
Jason Ertel
3a0590f950
Merge pull request #11166 from Security-Onion-Solutions/jertel/alts
...
use the correct var
2023-08-24 13:08:35 -04:00
Jason Ertel
43e4cf632a
use the correct var
2023-08-24 12:57:35 -04:00
Jason Ertel
92c6229e00
Merge pull request #11165 from Security-Onion-Solutions/jertel/alts
...
allow testing runs to proceed with unsupported os
2023-08-24 12:30:07 -04:00
Jason Ertel
8252924203
allow testing runs to proceed with unsupported os
2023-08-24 12:16:25 -04:00
Jason Ertel
bdb88cc87b
Merge pull request #11161 from Security-Onion-Solutions/jertel/alts
...
use consistent cert dir and reduce jinja complexity
2023-08-24 11:18:34 -04:00
Jason Ertel
f4be5641da
cert work
2023-08-23 20:49:37 -04:00
Jason Ertel
4484e2d031
cert work
2023-08-23 18:16:49 -04:00
Jason Ertel
b8dc9ea560
cert work
2023-08-23 17:50:08 -04:00
weslambert
d4bffba736
Merge pull request #11153 from Security-Onion-Solutions/fix/elastic_fleet_integrations
...
Add more Elastic Fleet integrations
2023-08-23 16:22:14 -04:00
Wes
d2d0d53eef
Change order
2023-08-23 20:20:44 +00:00
Wes
31a49268cb
Add o365 and okta
2023-08-23 20:20:06 +00:00
Wes
2f51349ff8
Add SOC configuration
2023-08-23 20:07:42 +00:00
m0duspwnens
a885baf960
add desktop to grid
2023-08-23 15:24:32 -04:00
Wes
3f2793088a
Add templates
2023-08-23 19:02:50 +00:00
Wes
0f24c8e8bb
Add packages
2023-08-23 19:02:32 +00:00
Jason Ertel
8a751e097d
cert path refactor
2023-08-23 14:32:05 -04:00
weslambert
4a582804b0
Merge pull request #11139 from Security-Onion-Solutions/fix/soc_event_fields
...
Update SOC event fields
2023-08-22 10:46:38 -04:00
Mike Reeves
f278056493
Merge pull request #11129 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update HOTFIX
2023-08-21 16:30:34 -04:00
Mike Reeves
f2c665e4fa
Update HOTFIX
2023-08-21 16:30:02 -04:00
Mike Reeves
ce32a0081e
Merge pull request #11128 from Security-Onion-Solutions/2.4/main
...
Merge in hotfix
2023-08-21 16:29:40 -04:00
Mike Reeves
658d132c38
Merge pull request #11127 from Security-Onion-Solutions/hotfix/2.4.10
...
Hotfix/2.4.10
2023-08-21 16:26:27 -04:00
Mike Reeves
7d2f39a06f
Merge pull request #11126 from Security-Onion-Solutions/2410hf
...
2.4.10 Hotfix
2023-08-21 15:39:07 -04:00
Mike Reeves
84d5d52ec8
2.4.10 Hotfix
2023-08-21 15:36:57 -04:00
weslambert
563a495725
Add Playbook
2023-08-21 11:24:07 -04:00
weslambert
9e18fe64cf
Remove OSSEC configuration
2023-08-21 11:20:47 -04:00
weslambert
708a681ed9
Merge pull request #11123 from Security-Onion-Solutions/fix/elastic_fleet_zeek_console
...
Exclude console log
2023-08-21 10:31:32 -04:00
Josh Patterson
a40937409a
Merge pull request #11124 from Security-Onion-Solutions/issue/11122
...
add missing containers to soc_docker.yaml. force port bindings to []string
2023-08-21 10:28:32 -04:00
m0duspwnens
b8d374b2af
add missing containers to soc_docker.yaml. force port bindings to []string
2023-08-21 09:45:23 -04:00
weslambert
fa31bd4bf7
Exclude console log
2023-08-21 09:20:49 -04:00
Mike Reeves
847aab2712
Merge pull request #11120 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update config.sls
2023-08-21 09:17:11 -04:00
Mike Reeves
710b800bc2
Update config.sls
2023-08-21 09:00:11 -04:00
Josh Brower
c92b359b79
Merge pull request #11116 from Security-Onion-Solutions/2.4/hotfixcerts
...
Fix certs on Rec and Heavy
2023-08-21 07:30:44 -04:00
Josh Brower
e2fd371886
Fix certs on Rec and Heavy
2023-08-21 07:26:37 -04:00
Josh Brower
5b453ca972
Merge pull request #11113 from Security-Onion-Solutions/2.4/rec-certs-fix
...
Fix certs for Rec & Heavy
2023-08-21 07:03:58 -04:00
Josh Brower
6784bdcb54
Fix certs for Rec & Heavy
2023-08-20 15:46:07 -04:00
Mike Reeves
7e4036f2a5
Merge pull request #11101 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix Hotfix
2023-08-18 15:45:08 -04:00
Mike Reeves
421cfc46ad
Update soup
2023-08-18 15:39:58 -04:00
Mike Reeves
0d4a49a0ff
Update so-setup
2023-08-18 15:34:36 -04:00
Mike Reeves
6453a86c2a
Merge pull request #11098 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2023-08-18 10:10:48 -04:00
Mike Reeves
d657bbdc18
Merge pull request #11100 from Security-Onion-Solutions/jertel/souptest
...
force soup docker output to log
2023-08-18 09:59:24 -04:00
Jason Ertel
8aeb4706e1
force soup docker output to log
2023-08-18 09:57:51 -04:00
Mike Reeves
e04ec1042a
Update soup
2023-08-18 09:12:19 -04:00
Josh Patterson
e77e5c3cea
Merge pull request #11090 from Security-Onion-Solutions/issue/10998
...
Issue/10998
2023-08-17 17:27:45 -04:00
Jason Ertel
222352b4b3
fix typo
2023-08-17 17:26:35 -04:00
m0duspwnens
4ac95447eb
pop sort settings if index_sorting is false
2023-08-17 16:15:27 -04:00
m0duspwnens
9cba9d9ae0
allow to override number_of_replicas from one place in soc ui
2023-08-17 15:00:01 -04:00
Mike Reeves
056072af7d
Merge pull request #11088 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2023-08-17 14:51:25 -04:00
Mike Reeves
fb3fee5d4b
Update HOTFIX
2023-08-17 14:43:35 -04:00
Jason Ertel
e7be8991f1
Merge pull request #11083 from Security-Onion-Solutions/jertel/souptty
...
force image pulls to go into soup log
2023-08-17 13:47:37 -04:00
Jason Ertel
09dd3f529b
force image pulls to go into soup log
2023-08-17 13:45:51 -04:00
weslambert
488c4d5000
Merge pull request #11079 from Security-Onion-Solutions/fix/import_evtx_pcap
...
Assign pipeline to import
2023-08-17 12:29:01 -04:00
Mike Reeves
abad833c5e
Merge pull request #11075 from Security-Onion-Solutions/2.4/soupmods
...
Add soup for 2.4.20
2023-08-17 10:53:52 -04:00
Mike Reeves
4363e71e80
Add soup for 2.4.20
2023-08-17 10:51:59 -04:00
Wes
7971d9749a
Assign pipeline to import
2023-08-17 14:08:48 +00:00
weslambert
5ebe33d45f
Merge pull request #11068 from Security-Onion-Solutions/fix/elastic_fleet_package_force_2
...
Fix so-elastic-fleet-package-load
2023-08-17 08:20:24 -04:00
weslambert
4887eb4957
Update so-elastic-fleet-package-load
2023-08-16 22:31:14 -04:00
weslambert
0620919241
Merge pull request #11064 from Security-Onion-Solutions/fix/elasticfleet_package_force
...
Force package installation
2023-08-16 16:37:39 -04:00
Wes
e84d624d23
Force package installation
2023-08-16 20:10:20 +00:00
Josh Patterson
45bc2ec380
Merge pull request #11060 from Security-Onion-Solutions/issue/10922
...
set timezone during setup. set salt log levels to info
2023-08-16 10:47:13 -04:00
m0duspwnens
9bf7b9bda5
set the timezone earlier in setup
2023-08-16 10:02:47 -04:00
m0duspwnens
ab19fa9ece
set salt log levels to info
2023-08-16 09:21:06 -04:00
m0duspwnens
53d7d69135
update salt docs url in service file
2023-08-16 08:46:24 -04:00
m0duspwnens
b22776dc5a
set timezone to etc/utc during setup
2023-08-15 16:22:02 -04:00
Mike Reeves
dc6d9d4ba2
Merge pull request #11047 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-08-15 07:29:34 -04:00
Mike Reeves
075ef5e02c
Update VERSION
2023-08-15 07:27:48 -04:00
Mike Reeves
16da0b469a
Merge pull request #11040 from Security-Onion-Solutions/2.4/dev
...
2.4.10
2023-08-15 07:14:03 -04:00
Mike Reeves
5c2c2908b8
Merge pull request #11044 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update DOWNLOAD_AND_VERIFY_ISO.md
2023-08-14 16:52:53 -04:00
Mike Reeves
ad9da07de1
Update DOWNLOAD_AND_VERIFY_ISO.md
2023-08-14 16:51:24 -04:00
Jason Ertel
d1210e946c
Merge pull request #11043 from Security-Onion-Solutions/jertel/up
...
Jertel/up
2023-08-14 16:46:21 -04:00
Jason Ertel
5d6fe4d9ae
Merge branch '2.4/main' into jertel/up
2023-08-14 16:44:13 -04:00
Mike Reeves
193f9c08fb
Merge pull request #11042 from Security-Onion-Solutions/2.4.10
...
2.4.10
2023-08-14 16:41:21 -04:00
Mike Reeves
4808c21cf4
2.4.10
2023-08-14 16:34:32 -04:00
Mike Reeves
4106d1f69d
2.4.10
2023-08-14 16:33:08 -04:00
Jason Ertel
007720132b
Merge pull request #11034 from Security-Onion-Solutions/dougburks-patch-1
...
soup should respect current indentation in soc_global.sls
2023-08-13 16:56:50 -04:00
Doug Burks
f3a58cd336
soup should respect current indentation in soc_global.sls
2023-08-13 16:46:32 -04:00
Josh Brower
faca36e74c
Merge pull request #11021 from Security-Onion-Solutions/2.4/esurlfixup
...
Set default for import and eval only
2023-08-12 08:41:54 -04:00
Josh Brower
f38b77892b
Move back
2023-08-11 17:14:48 -04:00
Josh Brower
00297cd864
Move from post to pre
2023-08-11 16:10:16 -04:00
Josh Brower
ce63e47fcd
Enable forced update
2023-08-11 14:47:33 -04:00
Jason Ertel
d53489d674
Merge pull request #11023 from Security-Onion-Solutions/jertel/fixann
...
add missing annotations to avoid soc crash
2023-08-11 13:58:40 -04:00
Jason Ertel
1fb3a59573
add missing annotations to avoid soc crash
2023-08-11 13:41:58 -04:00
Jason Ertel
a5e60363cf
add missing annotations to avoid soc crash
2023-08-11 13:38:16 -04:00
Josh Brower
3f054031a0
Set default for import and eval only
2023-08-11 13:32:22 -04:00
Josh Patterson
4a54febf38
Merge pull request #11016 from Security-Onion-Solutions/issue/10957
...
set SO desktop wallpaper for iso install
2023-08-11 09:22:05 -04:00
m0duspwnens
fdb2ca4167
set SO desktop wallpaper for iso install
2023-08-11 09:15:41 -04:00
Josh Brower
7112d53d4d
Merge pull request #11014 from Security-Onion-Solutions/2.4/templateloadfix
...
Upgrade integration packages
2023-08-10 20:00:57 -04:00
Josh Brower
1d83b2f2e6
Add elasticsearch integration
2023-08-10 19:51:12 -04:00
Josh Brower
a724b95441
Merge branch '2.4/dev' into 2.4/templateloadfix
2023-08-10 19:01:24 -04:00
Josh Brower
0d894b7f52
Upgrade integration packages
2023-08-10 18:57:17 -04:00
Josh Patterson
e32d7eb127
Merge pull request #11012 from Security-Onion-Solutions/issue/10957
...
set desktop background
2023-08-10 16:27:56 -04:00
m0duspwnens
caced64d11
set desktop background
2023-08-10 16:10:39 -04:00
Doug Burks
3ec3f8bcd8
Merge pull request #11011 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md
2023-08-10 15:17:20 -04:00
Doug Burks
4426437ad3
Update motd.md
2023-08-10 15:04:31 -04:00
Josh Patterson
1f0f74ff04
Merge pull request #11009 from Security-Onion-Solutions/fix/soruleupdate
...
ensure only 1 instance of so-rule-update runs. execute the cmd at the end of state run
2023-08-10 12:04:42 -04:00
m0duspwnens
e43900074a
ensure only 1 instance of so-rule-update runs. execute the cmd at the end of state run
2023-08-10 11:54:49 -04:00
Josh Patterson
732d2605a7
Merge pull request #11008 from Security-Onion-Solutions/fix/esanno
...
Fix/esanno
2023-08-10 11:32:14 -04:00
m0duspwnens
4d497022db
replace . with _x_ for soc ui compat
2023-08-10 09:52:18 -04:00
Josh Brower
2680a50927
Merge pull request #11004 from Security-Onion-Solutions/2.4/esurlfix
...
Unset defaults
2023-08-10 08:50:56 -04:00
Josh Brower
874dab7535
Unset defaults
2023-08-09 19:02:53 -04:00
Josh Brower
fe9917ef1c
Merge pull request #11002 from Security-Onion-Solutions/2.4/fixfqdn
...
Move base_url to cert SAN
2023-08-09 16:41:09 -04:00
Josh Brower
e844cf11db
Move base_url to cert SAN
2023-08-09 16:38:27 -04:00
m0duspwnens
f9e272dd8f
add additional annotations for elasticsearch index settings
2023-08-09 16:09:23 -04:00
m0duspwnens
dfe916d7c8
add annotation for so-logs index
2023-08-09 15:19:17 -04:00
Josh Patterson
c3c769922d
Merge pull request #11000 from Security-Onion-Solutions/issue/10954
...
Issue/10954
2023-08-09 11:31:55 -04:00
m0duspwnens
30e3fbb41c
remove extra )
2023-08-09 11:21:16 -04:00
m0duspwnens
78694807ff
Merge remote-tracking branch 'origin/2.4/dev' into issue/10954
2023-08-09 11:19:19 -04:00
m0duspwnens
8844e305ab
use sensor.interface for suricata. make af-packet.interface ro in soc ui
2023-08-09 11:18:47 -04:00
Josh Brower
1a37c43c98
Merge pull request #10997 from Security-Onion-Solutions/2.4/autoupgrade
...
Enable Agent Upgrade Check during highstate
2023-08-09 10:58:26 -04:00
Josh Brower
bf78faa0f0
Enable upgrade check during state run
2023-08-09 10:43:34 -04:00
Josh Brower
204ef7e68f
Merge pull request #10994 from Security-Onion-Solutions/2.4/autoupgrade
...
RC2 Fixes
2023-08-09 09:47:57 -04:00
Josh Patterson
176608d2f9
Merge pull request #10995 from Security-Onion-Solutions/fix/desktop
...
Fix/desktop
2023-08-09 09:34:44 -04:00
m0duspwnens
28dfdbf06d
securityonion_desktop is just desktop
2023-08-09 08:51:39 -04:00
m0duspwnens
a443c654e5
fix desktop pillar in setup
2023-08-09 08:48:00 -04:00
m0duspwnens
6413050f2e
set doc_desktop_url before jinja
2023-08-09 08:39:46 -04:00
m0duspwnens
fe7a940082
add details for enabling in soc gui
2023-08-09 08:31:54 -04:00
Josh Brower
e586d6b967
Extract Elastic Agent tarball for airgap soup
2023-08-09 08:30:19 -04:00
m0duspwnens
2d25e352d4
write to adv_ pillar file since that is where it would be stored from using the soc ui
2023-08-09 08:18:13 -04:00
Josh Brower
4297d51a2d
Refactor for multiple agents
2023-08-09 08:14:52 -04:00
m0duspwnens
1440c72559
changes for desktop referencing Rocky/CentOS to OEL
2023-08-09 08:06:51 -04:00
m0duspwnens
00efc2f88f
rename workstation to desktop for firewall
2023-08-09 07:31:31 -04:00
Josh Patterson
d55c2f889c
Merge pull request #10989 from Security-Onion-Solutions/issue/10973
...
Issue/10973
2023-08-08 19:35:02 -04:00
Josh Brower
e1e535b009
Retry if exit code is error
2023-08-08 18:38:18 -04:00
m0duspwnens
789fff561e
ensure ownership of /opt/so/log/strelka/filecheck.log
2023-08-08 17:55:30 -04:00
m0duspwnens
58fe25623b
ensure ownership of /opt/so/log/strelka/filecheck_stdout.log
2023-08-08 17:48:34 -04:00
m0duspwnens
553b758c61
update cronjobs first, the kill filecheck
2023-08-08 17:28:14 -04:00
m0duspwnens
6da2f117f2
change which user runs filecheck cron based on md engine
2023-08-08 17:25:08 -04:00
Doug Burks
6ad22edf8e
Merge pull request #10987 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.4.10
2023-08-08 17:18:38 -04:00
m0duspwnens
2dbe679849
force restart of filecheck if the config changes
2023-08-08 17:05:03 -04:00
Doug Burks
2f74b69cc3
Update soup for 2.4.10
2023-08-08 16:27:11 -04:00
bryant-treacle
4320dab856
Merge pull request #10986 from Security-Onion-Solutions/fix/windows_event_table
...
Fix/windows event table
2023-08-08 16:23:14 -04:00
bryant-treacle
036b81707b
Update defaults.yaml
2023-08-08 16:10:54 -04:00
Josh Brower
8455d3da6f
Merge pull request #10977 from Security-Onion-Solutions/2.4/squashbug
...
Set as default
2023-08-08 15:55:58 -04:00
bryant-treacle
3d4fd08547
Update defaults.yaml
2023-08-08 15:28:06 -04:00
m0duspwnens
21c80e4953
run so-rule-update after idstools container restart
2023-08-08 15:27:23 -04:00
m0duspwnens
5c704d7e58
run so-rule-update if idstools configs change
2023-08-08 15:20:44 -04:00
m0duspwnens
230f5868f9
sync sorules
2023-08-08 15:14:27 -04:00
m0duspwnens
20dedab4b2
remove previously add rules files
2023-08-08 15:03:06 -04:00
m0duspwnens
9118ac2b56
filter.rules to filters.rules
2023-08-08 13:59:43 -04:00
m0duspwnens
aab89d2483
rule-files does not go under profiling
2023-08-08 13:54:58 -04:00
m0duspwnens
b2e75e77e8
add local.rules and filter.rules to suricata defaults. add extraction.rules, local.rules and filter.rules for suricata metadata
2023-08-08 13:50:19 -04:00
Josh Patterson
bcd1ccd91b
Merge pull request #10983 from Security-Onion-Solutions/fix/tgrafzeekcloss
...
Fix/tgrafzeekcloss
2023-08-08 10:19:46 -04:00
m0duspwnens
673b45af09
import ZEEKMERGED
2023-08-08 09:41:42 -04:00
m0duspwnens
a06040c035
add WORKERS calculation back to zeekcaptureloss script
2023-08-08 09:37:37 -04:00
m0duspwnens
e286b8f2ba
Merge remote-tracking branch 'origin/2.4/dev' into fix/tgrafzeekcloss
2023-08-08 09:36:12 -04:00
m0duspwnens
69553f9017
removes spaces from zeekcaptureloss script
2023-08-08 09:34:59 -04:00
m0duspwnens
609a2bf32e
only import ZEEKMERGED if a sensor type node
2023-08-08 09:27:03 -04:00
Jason Ertel
dad541423d
Merge pull request #10978 from Security-Onion-Solutions/jertel/bumpver
...
update version
2023-08-07 16:36:10 -04:00
Jason Ertel
b9d0d03223
update version
2023-08-07 16:35:05 -04:00
Josh Brower
8611d1848c
Set as default
2023-08-07 15:55:53 -04:00
m0duspwnens
5278601e5d
manage telegraf scripts with a defaults file assigned per node type
2023-08-07 11:18:35 -04:00
Doug Burks
a13b3f305a
Merge pull request #10970 from Security-Onion-Solutions/2.4/dev
...
2.4.5 RC2
2023-08-07 10:21:29 -04:00
Doug Burks
38089c6662
Merge pull request #10971 from Security-Onion-Solutions/2.4/main
...
2.4/main to 2.4/dev
2023-08-07 10:17:51 -04:00
Doug Burks
2d863f09eb
Merge pull request #10969 from Security-Onion-Solutions/dougburks-patch-1
...
add spaces for proper rendering DOWNLOAD_AND_VERIFY_ISO.md
2023-08-07 09:31:33 -04:00
Doug Burks
37b98ba188
add spaces for proper rendering DOWNLOAD_AND_VERIFY_ISO.md
2023-08-07 09:29:34 -04:00
Doug Burks
65d1e57ccd
Merge pull request #10968 from Security-Onion-Solutions/dougburks-patch-1
...
prepare for 2.4.5 ISO image release
2023-08-07 09:15:53 -04:00
Doug Burks
9ae32e2bd6
create sigs directory and add sig for 2.4.5
2023-08-07 09:02:52 -04:00
Doug Burks
6e8f31e083
Delete sigs
2023-08-07 08:59:24 -04:00
Doug Burks
3c5cd941c7
Update DOWNLOAD_AND_VERIFY_ISO.md for 2.4.5
2023-08-07 08:45:30 -04:00
Doug Burks
2ea2a4d0a7
Merge pull request #10964 from Security-Onion-Solutions/dougburks-patch-1
...
Revert yesterday's change to zeekcaptureloss.sh
2023-08-05 09:23:58 -04:00
Doug Burks
90102b1148
Finish reverting yesterday's change to zeekcaptureloss.sh
2023-08-05 09:23:27 -04:00
Doug Burks
ec81cbd70d
Revert yesterday's change to zeekcaptureloss.sh
2023-08-05 09:11:58 -04:00
Josh Patterson
59c0109c91
Merge pull request #10961 from Security-Onion-Solutions/fix/tgrafzeekcloss
...
fix count of WORKERS for zeekcaptureloss script for telegraf
2023-08-04 16:39:26 -04:00
m0duspwnens
9af2a731ca
fix count of WORKERS for zeekcaptureloss script for telegraf
2023-08-04 16:29:30 -04:00
Josh Brower
9b656ebbc0
Merge pull request #10960 from Security-Onion-Solutions/2.4/fleetcustomfqdn
...
Refactor to remove new line
2023-08-04 16:16:43 -04:00
Josh Brower
9d3744aa25
Refactor to remove new line
2023-08-04 16:05:28 -04:00
Josh Patterson
9fddd56c96
Merge pull request #10959 from Security-Onion-Solutions/desktopyummv
...
Desktopyummv
2023-08-04 16:03:20 -04:00
m0duspwnens
89c4f58296
fix indents
2023-08-04 15:41:10 -04:00
m0duspwnens
0ba1e7521a
set default session for preexisting users
2023-08-04 15:36:44 -04:00
m0duspwnens
36747cf940
add networkminer to desktop.packages
2023-08-04 13:52:01 -04:00
Doug Burks
118088c35f
Merge pull request #10953 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: soup should rotate its log file #10951
2023-08-04 12:38:21 -04:00
Doug Burks
63373710b4
Update soup to rotate log file
2023-08-04 12:26:36 -04:00
Doug Burks
209da766ba
Update soup to rotate log file
2023-08-04 12:16:14 -04:00
m0duspwnens
433cde0f9e
Merge remote-tracking branch 'origin/2.4/dev' into desktopyummv
2023-08-04 11:25:06 -04:00
Josh Patterson
9fe9256a0f
Merge pull request #10950 from Security-Onion-Solutions/fix/idhfirewall
...
Fix/idhfirewall
2023-08-04 11:00:58 -04:00
m0duspwnens
014aeffb2a
add analyst back
2023-08-04 09:56:33 -04:00
m0duspwnens
3b86b60207
Merge remote-tracking branch 'origin/2.4/dev' into fix/idhfirewall
2023-08-04 09:40:01 -04:00
m0duspwnens
0f52530d07
soc_firewall.yaml update adding idh and rename analyst to workstation
2023-08-04 09:37:58 -04:00
m0duspwnens
726ec72350
allow idh to connect to salt_manager ports on managres
2023-08-04 09:22:59 -04:00
Doug Burks
560ec9106d
Merge pull request #10948 from Security-Onion-Solutions/dougburks-patch-1
...
Update so-whiptail
2023-08-04 09:21:55 -04:00
m0duspwnens
a51acfc314
rename analyst to workstation for fw rules. allow workstation to connect to salt_manager port on managers
2023-08-04 09:17:22 -04:00
Doug Burks
78950ebfbb
Update so-whiptail
2023-08-04 09:16:58 -04:00
Josh Brower
d3ae2b03f0
Merge pull request #10947 from Security-Onion-Solutions/2.4/comm_id
...
Generate community_id for defend endpoint logs
2023-08-04 09:07:35 -04:00
Josh Brower
dd1fa51eb5
Generate community_id for defend endpoint logs
2023-08-04 09:03:17 -04:00
m0duspwnens
682289ef23
add sensoroni ports where missing
2023-08-04 09:01:09 -04:00
m0duspwnens
593cdbd060
add rules for idh to connect to managers, change idh from sensor to idh in so-firewall-minion
2023-08-04 08:50:06 -04:00
Josh Brower
4ed0ba5040
Merge pull request #10946 from Security-Onion-Solutions/2.4/logstashfix
...
Don't watch certs on search nodes
2023-08-03 19:01:13 -04:00
Josh Brower
2472d6a727
Don't watch certs on search nodes
2023-08-03 18:52:29 -04:00
Mike Reeves
18e31a4490
Merge pull request #10944 from Security-Onion-Solutions/raid
...
Raid refactor + yara and rule proxy
2023-08-03 17:18:19 -04:00
Mike Reeves
2caca92082
Raid refactor + yara and rule proxy
2023-08-03 17:11:43 -04:00
weslambert
abf74e0ae4
Merge pull request #10940 from Security-Onion-Solutions/foxtrot
...
Add time shift for so-import-evtx
2023-08-03 16:56:40 -04:00
Josh Brower
dc7ce5ba8f
Merge pull request #10941 from Security-Onion-Solutions/2.4/defendupdate
...
Update for 8.8.2
2023-08-03 16:28:56 -04:00
Josh Brower
6b5343f582
Update for 8.8.2
2023-08-03 16:25:02 -04:00
weslambert
ca6276b922
Update VERSION
2023-08-03 15:58:33 -04:00
weslambert
3e4136e641
Update help text
2023-08-03 15:56:05 -04:00
m0duspwnens
15b8e1a753
add convert-gnome-classic.sh
2023-08-03 15:37:26 -04:00
Doug Burks
b7197bbd16
Merge pull request #10939 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for airgap
2023-08-03 15:28:28 -04:00
Josh Brower
8966617508
Merge pull request #10926 from Security-Onion-Solutions/2.4/FleetEnhancments
...
2.4/fleet-Enhancements
2023-08-03 15:28:03 -04:00
Doug Burks
9319c3f2e1
Update soup for airgap
2023-08-03 15:27:24 -04:00
m0duspwnens
d4fbf7d6a6
convert to gnome classic
2023-08-03 15:26:43 -04:00
Josh Brower
e78fcbc6cb
Refactor for Jinja instead
2023-08-03 15:25:11 -04:00
Josh Brower
27b70cbf68
Use jinja instead
2023-08-03 15:21:20 -04:00
Josh Patterson
ffb54135d1
Merge pull request #10938 from Security-Onion-Solutions/desktopyummv
...
Desktopyummv
2023-08-03 14:54:29 -04:00
m0duspwnens
d40a8927c3
install salt version specified in master.defaults.yaml for desktop
2023-08-03 14:51:43 -04:00
m0duspwnens
9172e10dba
check if there are files in yum.repos.d before trying to move them
2023-08-03 14:47:53 -04:00
Doug Burks
1907ea805c
Merge pull request #10937 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for airgap
2023-08-03 14:39:53 -04:00
Doug Burks
80598d7f8d
Update soup for airgap
2023-08-03 14:36:47 -04:00
Josh Patterson
13c3e7f5ff
Merge pull request #10934 from Security-Onion-Solutions/fix/soupairgap
...
ensure AIRGAP is lowercase and check for true
2023-08-03 12:00:06 -04:00
m0duspwnens
d4389d5057
ensure AIRGAP is lowercase and check for true
2023-08-03 11:56:48 -04:00
weslambert
cf2233bbb6
Add help information for time shift
2023-08-03 08:54:54 -04:00
weslambert
3847863b3d
Add time shift
2023-08-03 08:51:23 -04:00
weslambert
3368789b43
Update VERSION
2023-08-03 08:49:45 -04:00
Josh Brower
1bc7bbc76e
Refactor custom_fqdn
2023-08-02 20:02:37 -04:00
Jason Ertel
e108bb9bcd
Merge pull request #10932 from Security-Onion-Solutions/jertel/agentcommon
...
remove unused vars
2023-08-02 19:29:03 -04:00
Jason Ertel
5414b0756c
remove unused vars
2023-08-02 19:25:07 -04:00
Jason Ertel
11c827927c
Merge pull request #10931 from Security-Onion-Solutions/jertel/agentcommon
...
refactor elastic-agent download for soup ctrl+c anomalies
2023-08-02 19:20:45 -04:00
Jason Ertel
3054b8dcb9
refactor elastic-agent download for soup ctrl+c anomalies
2023-08-02 18:57:46 -04:00
Josh Brower
399758cd5f
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/FleetEnhancments
2023-08-02 17:58:48 -04:00
Josh Brower
1c8a8c460c
Restart logstash when certs change
2023-08-02 17:53:29 -04:00
Josh Brower
ab28cee7cf
Allow multiple Custom Fleet FQDN
2023-08-02 17:45:37 -04:00
Mike Reeves
5a3c1f0373
Merge pull request #10930 from Security-Onion-Solutions/m0duspwnens-patch-2
...
add gtk2
2023-08-02 16:58:38 -04:00
Josh Patterson
435da77388
add gtk2
2023-08-02 16:53:45 -04:00
Mike Reeves
da2910e36f
Merge pull request #10927 from Security-Onion-Solutions/m0duspwnens-patch-1
...
add mono-devel
2023-08-02 16:22:09 -04:00
Josh Patterson
eb512d9aa2
add mono-devel
2023-08-02 16:21:23 -04:00
Mike Reeves
03f5e44be7
Merge pull request #10924 from Security-Onion-Solutions/2.4/regenagent
...
Regen Agent Installers
2023-08-02 15:28:29 -04:00
Josh Brower
f153c1125d
Allow multiple Custom Fleet FQDN
2023-08-02 15:23:18 -04:00
Jason Ertel
99b61b5e1d
Merge pull request #10925 from Security-Onion-Solutions/jertel/fiximportsuri
...
ensure suri rules are synced for import installs
2023-08-02 15:13:59 -04:00
Jason Ertel
8036df4b20
ensure suri rules are synced for import installs
2023-08-02 15:10:31 -04:00
Josh Brower
aab55c8cf6
Regen Agent Installers
2023-08-02 15:09:26 -04:00
Josh Patterson
f3c5d26a4e
Merge pull request #10923 from Security-Onion-Solutions/soupaloop
...
Soupaloop
2023-08-02 14:44:49 -04:00
m0duspwnens
64776936cc
no longer need so-user migrate in 2.4
2023-08-02 14:09:43 -04:00
m0duspwnens
c17b324108
dont count adv_ sls files for number of minions in deployment
2023-08-02 14:04:19 -04:00
weslambert
72e1cbbfb6
Merge pull request #10920 from Security-Onion-Solutions/fix/pfsense
...
Pfsense fix
2023-08-02 13:27:33 -04:00
weslambert
f102351052
Add event
2023-08-02 13:25:44 -04:00
weslambert
ac28f90af3
Remove override
2023-08-02 13:15:11 -04:00
m0duspwnens
f6c6204555
procps to procps-ng
2023-08-02 13:05:24 -04:00
m0duspwnens
9873121000
change pgrep for salt-minion PID
2023-08-02 12:54:31 -04:00
m0duspwnens
5630b353c4
change how pgrep finds salt-master PID
2023-08-02 11:20:51 -04:00
Josh Patterson
04ed5835ae
Merge pull request #10918 from Security-Onion-Solutions/issue/10917
...
force portgroups added to hostgroups in roles to be list of strings
2023-08-02 11:00:41 -04:00
m0duspwnens
407cb2a537
force portgroups added to hostgroups in roles to be list of strings
2023-08-02 10:56:41 -04:00
Josh Brower
b520c1abb7
Allow multiple Custom Fleet FQDN
2023-08-02 10:36:40 -04:00
weslambert
25b11c35fb
Merge pull request #10915 from Security-Onion-Solutions/fix/ea_elastic_defend
...
Set version for Elastic Defend and enable updates
2023-08-02 10:32:30 -04:00
weslambert
ef0301d364
Merge pull request #10914 from Security-Onion-Solutions/feature/package_list
...
Add package list
2023-08-02 10:03:38 -04:00
Wes
e694019027
Add package list
2023-08-02 13:50:14 +00:00
weslambert
22ebb2faf6
Merge pull request #10907 from Security-Onion-Solutions/fix/ea_container_logs
...
EA Container Logs
2023-08-02 09:26:53 -04:00
Wes
0d5ed2e835
Set version for Elastic Defend and enable updates
2023-08-02 13:21:03 +00:00
Josh Patterson
8ab1769d70
Merge pull request #10912 from Security-Onion-Solutions/mineerror
...
Mine error
2023-08-01 17:21:31 -04:00
Jason Ertel
6692fffb9b
Merge pull request #10910 from Security-Onion-Solutions/jertel/noautoredirforapi
...
Fix login flicker; so-status sluggishness
2023-08-01 17:05:48 -04:00
Jason Ertel
23414599ee
use simple json (w/o template) to resolve sluggishness
2023-08-01 16:53:26 -04:00
Jason Ertel
8b3a38f573
resolve login page flicker
2023-08-01 16:30:24 -04:00
m0duspwnens
9ec4322bf4
Merge remote-tracking branch 'origin/2.4/dev' into mineerror
2023-08-01 16:21:22 -04:00
m0duspwnens
7037fc52f8
sync all modules before running states
2023-08-01 16:21:06 -04:00
Wes
0e047cffad
Add to logrotate
2023-08-01 20:14:53 +00:00
Wes
44b086a028
Change path
2023-08-01 20:13:50 +00:00
Wes
4e2eb86b36
Move LOGS_PATH to environment vars
2023-08-01 20:11:51 +00:00
weslambert
1cbf60825d
Add log dir
2023-08-01 14:40:52 -04:00
weslambert
2d13bf1a61
Present logs to the host
2023-08-01 14:40:12 -04:00
Josh Brower
968fee3488
Regen Agent Installers when Fleet URLs change
2023-08-01 13:10:41 -04:00
Doug Burks
da51fd59a0
Merge pull request #10905 from Security-Onion-Solutions/dougburks-patch-1
...
Update verbiage and links in soc_sensor.yaml
2023-08-01 12:52:22 -04:00
Doug Burks
3fa0a98830
Update verbiage and links in soc_sensor.yaml
2023-08-01 12:45:09 -04:00
weslambert
e7bef745eb
Merge pull request #10904 from Security-Onion-Solutions/fix/syslog
...
Move syslog to the INPUT chain where needed
2023-08-01 12:14:48 -04:00
Mike Reeves
82b335ed04
Merge pull request #10899 from Security-Onion-Solutions/offload
...
Fix Offload
2023-08-01 10:32:53 -04:00
Mike Reeves
f35f42c83d
Sensor NIC offload
2023-08-01 10:23:45 -04:00
weslambert
4adaddf13f
Move syslog to the INPUT chain where needed
2023-08-01 10:14:59 -04:00
Mike Reeves
b6579d7d45
Sensor NIC offload
2023-08-01 10:13:44 -04:00
Mike Reeves
87a5d20ac9
Sensor NIC offload
2023-08-01 10:03:59 -04:00
Mike Reeves
2875a7a2e5
Sensor NIC offload
2023-08-01 09:48:44 -04:00
Josh Brower
f27ebc47c1
Merge pull request #10897 from Security-Onion-Solutions/2.4/heavyrc2
...
2.4/heavyrc2
2023-08-01 09:15:10 -04:00
Josh Brower
63b4bdcebe
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/heavyrc2
2023-08-01 08:53:07 -04:00
weslambert
ba3660d0da
Merge pull request #10894 from Security-Onion-Solutions/fix/soc_auth
...
SOC Auth msg fix
2023-08-01 08:35:41 -04:00
weslambert
83265d9d6c
Merge pull request #10893 from Security-Onion-Solutions/foxtrot
...
Elastic 8.2.2
2023-08-01 08:20:07 -04:00
weslambert
527a6ba454
Use asterisk when searching 'msg' since it is now a keyword
2023-07-31 23:52:38 -04:00
weslambert
f84b0a3219
Update VERSION
2023-07-31 23:16:46 -04:00
weslambert
ae6997a6b7
Merge pull request #10892 from Security-Onion-Solutions/feature/elastic_8.8.2
...
Elastic 8.8.2
2023-07-31 22:24:21 -04:00
weslambert
9d59e4250f
Update VERSION
2023-07-31 22:23:54 -04:00
Wes
48d9c14563
Enable log package by default
2023-08-01 02:20:43 +00:00
Wes
29b64eadd4
Change log.log to log.logs
2023-08-01 02:20:22 +00:00
weslambert
5dd5f9fc1c
Elastic 8.8.2
2023-07-31 22:18:43 -04:00
weslambert
44c926ba8d
Elastic 8.8.2
2023-07-31 22:18:07 -04:00
weslambert
6a55a8e5c0
Elastic 8.2.2
2023-07-31 22:17:22 -04:00
Josh Brower
64bad0a9cf
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/heavyrc2
2023-07-31 15:24:32 -04:00
Josh Brower
b6dd347eb8
Heavy Node add manager
2023-07-31 15:22:29 -04:00
Josh Brower
a89508f1ae
Heavy Node fixes
2023-07-31 15:17:24 -04:00
Josh Patterson
ed7b674fbb
Merge pull request #10891 from Security-Onion-Solutions/fix/idh
...
import DOCKER in idh.enabled
2023-07-31 15:06:26 -04:00
Josh Patterson
0c2a4cbaba
Merge pull request #10889 from Security-Onion-Solutions/searchnodefw
...
add managersearch and standlone fw rules for searchnode
2023-07-31 13:37:39 -04:00
m0duspwnens
57562ad5e3
add managersearch and standlone fw rules for searchnode
2023-07-31 13:34:08 -04:00
m0duspwnens
95581f505a
import DOCKER in idh.enabled
2023-07-31 13:18:57 -04:00
Mike Reeves
599de60dc8
Merge pull request #10888 from Security-Onion-Solutions/soups
...
Update Soup
2023-07-31 13:14:54 -04:00
Mike Reeves
77101fec12
Update Soup
2023-07-31 13:12:32 -04:00
Mike Reeves
069d32be1a
Merge pull request #10887 from Security-Onion-Solutions/soups
...
Soup
2023-07-31 13:10:02 -04:00
Mike Reeves
e78e6b74ed
Update Soup
2023-07-31 13:07:29 -04:00
Mike Reeves
16217912db
Update Soup
2023-07-31 13:04:33 -04:00
Josh Patterson
635ddc9b21
Merge pull request #10886 from Security-Onion-Solutions/iptables
...
Iptables
2023-07-31 11:36:22 -04:00
Mike Reeves
18d8f0d448
Merge pull request #10885 from Security-Onion-Solutions/sensorfix
...
Sensor Fix
2023-07-31 10:37:28 -04:00
Mike Reeves
1c42d70d30
Update soc_sensor.yaml
2023-07-31 10:36:00 -04:00
Mike Reeves
282f13a774
Merge pull request #10881 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-yara-download
2023-07-31 10:23:32 -04:00
Mike Reeves
f867be9e04
Fix no_proxy
2023-07-31 10:19:51 -04:00
Mike Reeves
4939447764
Update so-yara-download
2023-07-31 10:16:37 -04:00
Mike Reeves
5a59975cb8
Update so-yara-download
2023-07-31 10:14:31 -04:00
coreyogburn
20f3cedc01
Merge pull request #10842 from Security-Onion-Solutions/cogburn/7992
...
New Action "Add to Case"
2023-07-28 14:54:28 -06:00
Doug Burks
e563d71856
Merge pull request #10871 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md to 2.4 RC2
2023-07-28 16:33:06 -04:00
Doug Burks
1ca78fd297
Update README.md to 2.4 RC2
2023-07-28 16:29:46 -04:00
Mike Reeves
e76ee718e0
Merge pull request #10870 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-07-28 16:08:53 -04:00
Mike Reeves
5c90a5f27e
Update VERSION
2023-07-28 16:08:01 -04:00
Mike Reeves
bee429fe29
Merge pull request #10868 from Security-Onion-Solutions/2.4/dev
...
2.4.4
2023-07-28 16:00:45 -04:00
m0duspwnens
ecbb353d68
Merge remote-tracking branch 'origin/2.4/dev' into iptables
2023-07-28 15:12:08 -04:00
Mike Reeves
ed21b94c28
Merge pull request #10867 from Security-Onion-Solutions/2.4.4
...
2.4.4
2023-07-28 14:53:23 -04:00
Mike Reeves
2a282a29c3
2.4.4
2023-07-28 14:49:50 -04:00
Mike Reeves
bc09b418ca
Merge pull request #10866 from Security-Onion-Solutions/rockyepel
...
Rockyepel
2023-07-28 14:06:36 -04:00
m0duspwnens
6f6db61a69
remove epel-next
2023-07-28 14:04:27 -04:00
m0duspwnens
9fce80dba3
install epel-next after epel-release
2023-07-28 14:01:14 -04:00
Mike Reeves
abfec85e28
Merge pull request #10863 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update so-functions
2023-07-28 12:21:20 -04:00
Mike Reeves
9aa655365b
Update so-functions
2023-07-28 12:20:15 -04:00
Corey Ogburn
aa56085758
New Action "Add to Case"
2023-07-28 09:55:44 -06:00
Mike Reeves
9a3760951a
Merge pull request #10861 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-functions
2023-07-28 11:35:49 -04:00
m0duspwnens
4c8373452d
change to iptables-nft-services
2023-07-28 11:35:34 -04:00
Mike Reeves
0bb5db2e72
Update so-functions
2023-07-28 11:34:30 -04:00
Mike Reeves
2dbc7d8485
Merge pull request #10859 from Security-Onion-Solutions/ordesk
...
Ordesk
2023-07-28 10:56:15 -04:00
Mike Reeves
858e884ec2
Fix Desktop ISO install
2023-07-28 10:52:37 -04:00
Mike Reeves
4672eeb99b
Fix Desktop ISO install
2023-07-28 10:51:45 -04:00
Mike Reeves
aa824e7b6c
Merge pull request #10857 from Security-Onion-Solutions/ordesk
...
Oracle Desktop
2023-07-28 09:58:46 -04:00
Mike Reeves
bb2a1b9521
Fix Desktop ISO install
2023-07-28 09:46:27 -04:00
m0duspwnens
3a22ef8e86
change iptables package name for redhat fam
2023-07-28 08:40:32 -04:00
m0duspwnens
54080c42fe
enable, not enabled
2023-07-27 17:01:19 -04:00
Mike Reeves
a1fa87c150
Merge pull request #10853 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Don't restart suricata if it doesn't exist
2023-07-27 16:38:45 -04:00
Mike Reeves
0c553633b1
Don't restart suricata if it doesn't exist
2023-07-27 16:16:46 -04:00
m0duspwnens
12486599e0
Merge remote-tracking branch 'origin/2.4/dev' into iptables
2023-07-27 16:13:58 -04:00
m0duspwnens
3c16218c5a
map services,pkg,config for firewall state
2023-07-27 15:45:18 -04:00
Josh Patterson
f9850025ea
Merge pull request #10852 from Security-Onion-Solutions/2.4/debian
...
2.4/debian
2023-07-27 15:05:23 -04:00
Mike Reeves
65b76d72ca
Merge pull request #10850 from Security-Onion-Solutions/ordesk
...
Fix packages for desktop
2023-07-27 14:44:44 -04:00
Mike Reeves
afca15f444
Fix packages for desktop
2023-07-27 14:17:43 -04:00
Mike Reeves
65b9843f14
Fix packages for desktop
2023-07-27 14:11:53 -04:00
m0duspwnens
653e2d8205
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/debian
2023-07-27 10:26:12 -04:00
Josh Patterson
bbaf6df914
Merge pull request #10849 from Security-Onion-Solutions/iptables
...
Iptables
2023-07-27 10:00:46 -04:00
m0duspwnens
bc182c1c43
only run firewalld states if os_family is RedHat
2023-07-27 09:24:41 -04:00
m0duspwnens
fe9b934af6
Merge remote-tracking branch 'origin/2.4/dev' into iptables
2023-07-26 16:32:03 -04:00
m0duspwnens
373298430b
only run iptables-restore if config file is valid
2023-07-26 16:31:22 -04:00
Mike Reeves
4a18eb02f3
Merge pull request #10847 from Security-Onion-Solutions/ordesk
...
SO Desktop
2023-07-26 15:53:40 -04:00
m0duspwnens
0aab3e185e
dont manage interfaces listed in /etc/network/interfaces for debian
2023-07-26 15:16:44 -04:00
Josh Brower
b1fb05dd28
Merge pull request #10841 from Security-Onion-Solutions/2.4/eqlfields
...
Fix formatting
2023-07-26 11:25:20 -04:00
Josh Brower
9437a47946
Fix formatting
2023-07-26 10:54:24 -04:00
Josh Brower
bdf4f6190d
Merge pull request #10829 from Security-Onion-Solutions/2.4/heavynoderedux
...
Heavy Node fixes
2023-07-26 10:41:42 -04:00
Josh Brower
f24a3a51ce
Heavy Node fixes
2023-07-25 18:28:41 -04:00
m0duspwnens
ba6043392c
reorder whiptail text
2023-07-25 16:18:01 -04:00
m0duspwnens
60eb1611ea
upgrade packages for debian and reboot prior to so installation
2023-07-25 16:06:38 -04:00
Josh Brower
3ef6ea9155
Merge pull request #10826 from Security-Onion-Solutions/2.4/navfix
...
Upgrade Nav
2023-07-25 12:26:07 -04:00
Josh Brower
2b38bc778d
Upgrade Nav
2023-07-25 12:24:23 -04:00
m0duspwnens
e334d44c95
need quotes for logCmd
2023-07-25 11:03:10 -04:00
m0duspwnens
39662ccf14
import rpm logic change
2023-07-25 10:21:44 -04:00
m0duspwnens
fd69d1c714
remove quotes so sed will work in logCmd
2023-07-25 09:59:02 -04:00
m0duspwnens
63eebdf6ac
installer_prereq_packages is run for debian during detect_os so not needed again
2023-07-25 09:58:26 -04:00
Josh Brower
e19845e41d
Merge pull request #10819 from Security-Onion-Solutions/fix/elasticsearch_endpoint
...
Add endpoint to defaults
2023-07-25 09:11:06 -04:00
Josh Patterson
c1190064ad
Merge pull request #10823 from Security-Onion-Solutions/2.4/dockerips
...
2.4/dockerips
2023-07-25 08:39:49 -04:00
Josh Brower
4f94d953c9
Merge remote-tracking branch 'origin/2.4/dev' into fix/elasticsearch_endpoint
2023-07-25 07:42:59 -04:00
Josh Brower
71a83c1fe9
Merge pull request #10815 from Security-Onion-Solutions/2.4/SigmaMappings
...
2.4/sigma mappings
2023-07-25 07:23:25 -04:00
Wes
5553be02ac
Change how tags are added
2023-07-24 21:31:28 +00:00
m0duspwnens
b20fad2839
add missing do
2023-07-24 17:08:01 -04:00
m0duspwnens
16edca7834
fix failed copy paste
2023-07-24 17:06:49 -04:00
m0duspwnens
2545f9907f
dont allow 172.17.0.0/24 for custom dockernet
2023-07-24 17:00:20 -04:00
Wes
4efc951eaf
Add tags
2023-07-24 20:57:39 +00:00
Doug Burks
d75191d679
Merge pull request #10820 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md
2023-07-24 15:35:34 -04:00
Doug Burks
ee667a48c9
Update README.md
2023-07-24 15:33:50 -04:00
Josh Brower
067a83a87c
Merge pull request #10818 from Security-Onion-Solutions/2.4/fixnavigator
...
Update & Fix Navigator
2023-07-24 15:13:09 -04:00
Wes
d84dbf9535
Add fleet
2023-07-24 18:53:52 +00:00
m0duspwnens
d71254ad29
only add custom docker net to pillar
2023-07-24 14:47:14 -04:00
Wes
de7b7ff989
Add endpoint
2023-07-24 18:35:02 +00:00
Josh Brower
510900e640
Update & Fix Navigator
2023-07-24 13:56:22 -04:00
m0duspwnens
00483018ca
change docker bip to gateway
2023-07-24 13:38:14 -04:00
Mike Reeves
9416a14971
Merge pull request #10816 from Security-Onion-Solutions/gpgoracle
...
add oracle key
2023-07-24 11:02:10 -04:00
Mike Reeves
c9faa1a340
Add gui
2023-07-24 11:00:26 -04:00
m0duspwnens
9bda01bd29
change ranges
2023-07-24 10:40:23 -04:00
Josh Brower
eead0c42d4
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/SigmaMappings
2023-07-24 09:27:14 -04:00
Josh Brower
741e6039c1
Cleanup for Sigma Rules
2023-07-24 09:25:58 -04:00
m0duspwnens
db09b465bd
change default docker net/range
2023-07-24 09:23:13 -04:00
Doug Burks
a59f2ded38
Merge pull request #10813 from Security-Onion-Solutions/2.4/fix-packages-sls
...
Update packages.sls
2023-07-24 08:08:11 -04:00
Doug Burks
e2fe04dadc
Update packages.sls
2023-07-24 07:10:48 -04:00
Doug Burks
563bf2ff3a
Merge pull request #10812 from Security-Onion-Solutions/fuse
...
Update packages.sls
2023-07-24 06:48:47 -04:00
Mike Reeves
07eeb4e2a0
Update packages.sls
2023-07-23 21:07:19 -04:00
Mike Reeves
5dc5b99b05
Add gui
2023-07-21 18:00:01 -04:00
Mike Reeves
ba69c67dc2
Add gui
2023-07-21 17:30:17 -04:00
Mike Reeves
d1d5f8a2b6
Add gui
2023-07-21 17:28:09 -04:00
Mike Reeves
48324911ce
Add gui
2023-07-21 17:18:03 -04:00
m0duspwnens
4b0126a2e7
fix split
2023-07-21 17:10:51 -04:00
Mike Reeves
8a3c2e7242
Add gui
2023-07-21 17:06:38 -04:00
m0duspwnens
f55c1a4078
DOCKERBIP change
2023-07-21 16:59:22 -04:00
m0duspwnens
c4d81a249a
remove /24 from DOCKERBIP
2023-07-21 16:36:03 -04:00
m0duspwnens
4c9d172721
sorange to range
2023-07-21 16:21:18 -04:00
m0duspwnens
36a936d3d6
docker ips changes
2023-07-21 16:06:52 -04:00
coreyogburn
d6164446c6
Merge pull request #10809 from Security-Onion-Solutions/cogburn/8655
...
Added ReverseLookup Option
2023-07-21 13:38:38 -06:00
Corey Ogburn
bb7a918a16
Added ReverseLookup Option
...
Defaults to false, has metadata to show up in the config section of soc.
2023-07-21 13:18:08 -06:00
weslambert
be254b15f2
Merge pull request #10804 from Security-Onion-Solutions/fix/fleet_logging
...
Fleet logging
2023-07-20 15:51:56 -04:00
weslambert
83e1e3efdc
Merge pull request #10788 from Security-Onion-Solutions/fix/elastic_mappings
...
Fix user name mapping and remove security subfield
2023-07-20 15:51:42 -04:00
Mike Reeves
7c48f9d6ec
Merge pull request #10806 from Security-Onion-Solutions/newrhel
...
For Phil
2023-07-20 14:41:05 -04:00
Mike Reeves
f2947de0ca
Add epel-next
2023-07-20 12:13:36 -04:00
Wes
d07c46f27e
Change playbook and sysmon
2023-07-20 16:08:50 +00:00
Mike Reeves
47e418a441
Add epel-next
2023-07-20 12:07:26 -04:00
Mike Reeves
87b1207ac0
Merge pull request #10805 from Security-Onion-Solutions/alma
...
Test Alma
2023-07-20 10:57:19 -04:00
Mike Reeves
a86cbaa6fa
Merge pull request #10803 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update needs_restarting.py
2023-07-20 10:55:11 -04:00
Wes
c68cd6cf33
Fix typo
2023-07-20 14:39:35 +00:00
Josh Patterson
3071a1de41
Update map.jinja
2023-07-20 08:42:27 -04:00
Josh Patterson
e75d0c8094
Update needs_restarting.py
2023-07-20 08:36:27 -04:00
Mike Reeves
14c685ab10
Update needs_restarting.py
2023-07-20 08:32:19 -04:00
Mike Reeves
54082858dc
Update needs_restarting.py
2023-07-20 08:25:13 -04:00
Wes
4b7e7978ef
Add final pipeline
2023-07-19 19:56:54 +00:00
Josh Patterson
066de70638
Merge pull request #10799 from Security-Onion-Solutions/2.4/mysql
...
whiptails for ubuntu focal
2023-07-19 15:55:32 -04:00
m0duspwnens
19c6796927
only allow existing deployment for focal
2023-07-19 15:38:18 -04:00
m0duspwnens
77c9b4fb54
remove OTHER
2023-07-19 15:35:28 -04:00
m0duspwnens
3104137190
install type whiptail for focal
2023-07-19 15:31:09 -04:00
Josh Patterson
c8b65ecca0
Merge pull request #10798 from Security-Onion-Solutions/2.4/mysql
...
2.4/mysql
2023-07-19 14:55:35 -04:00
Mike Reeves
555c881235
Test Alma
2023-07-19 14:48:12 -04:00
m0duspwnens
0ac9a1f9cc
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/mysql
2023-07-19 14:41:03 -04:00
m0duspwnens
3c0554a42c
queue states during so-playbook-reset
2023-07-19 14:40:29 -04:00
Wes
0b19179630
Add logrotate
2023-07-19 15:17:42 +00:00
Wes
30a14f8aaf
Add logging
2023-07-19 15:00:20 +00:00
Wes
877fc36013
Add log dir
2023-07-19 14:57:24 +00:00
Mike Reeves
a892adb66f
Merge pull request #10668 from Security-Onion-Solutions/centos
...
CentOS Stream Support
2023-07-19 10:41:38 -04:00
Mike Reeves
a49b05661d
Merge pull request #10794 from Security-Onion-Solutions/2.4/mysql
...
2.4/mysql
2023-07-19 10:40:37 -04:00
Jason Ertel
266fc4e866
Merge pull request #10792 from Security-Onion-Solutions/regup
...
upgrade registry version
2023-07-19 10:00:40 -04:00
Wes
b738325880
Remove keyword
2023-07-19 13:55:12 +00:00
m0duspwnens
ad7821391d
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/mysql
2023-07-19 09:54:54 -04:00
m0duspwnens
1b0c146b54
get rid of mysql error: mbind: Operation not permitted
2023-07-19 09:54:00 -04:00
Wes
1848a835f5
Remove keyword
2023-07-19 13:52:15 +00:00
Jason Ertel
23cc75c68d
upgrade registry version
2023-07-19 09:51:07 -04:00
weslambert
17fcf12608
Merge pull request #10791 from Security-Onion-Solutions/fix/elastic_clear
...
Set delete for interactive
2023-07-19 08:27:00 -04:00
Wes
6a8737e9a2
Set delete for interactive
2023-07-19 12:21:47 +00:00
m0duspwnens
9543058a2c
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/mysql
2023-07-18 16:51:52 -04:00
m0duspwnens
b66cd82110
fix depreciations
2023-07-18 16:50:34 -04:00
weslambert
41ebb403ca
Merge pull request #10787 from Security-Onion-Solutions/fix/elastic_clear
...
Use new agent scripts for Elastic clear command
2023-07-18 16:15:27 -04:00
Mike Reeves
c94436fcbd
fix other OS installs
2023-07-18 15:19:10 -04:00
Wes
a59eda319e
Remove security subfield
2023-07-18 19:00:50 +00:00
Wes
8a76975d8c
Use new agent scripts
2023-07-18 18:43:57 +00:00
Mike Reeves
737da45e7f
fix other OS installs
2023-07-18 14:02:13 -04:00
m0duspwnens
df1bf8e67b
restart mysql container if config or pass changes
2023-07-18 13:41:26 -04:00
Mike Reeves
f95757c551
fix other OS installs
2023-07-18 11:58:49 -04:00
Mike Reeves
5e46138961
fix other OS installs
2023-07-18 11:55:51 -04:00
Mike Reeves
dc8aa4d923
fix other OS installs
2023-07-18 11:53:55 -04:00
Wes
1d3e39b6bd
Map user name to keyword and remove security subfield generation
2023-07-18 14:46:47 +00:00
Mike Reeves
9ad7303cf2
fix other OS installs
2023-07-17 16:44:55 -04:00
Mike Reeves
b1daa22dfc
fix other OS installs
2023-07-17 16:40:35 -04:00
Mike Reeves
49c4edbcbe
fix other OS installs
2023-07-17 16:33:47 -04:00
Mike Reeves
f4c3103f84
fix other OS installs
2023-07-17 16:24:51 -04:00
Mike Reeves
a2aea5530b
Merge pull request #10779 from Security-Onion-Solutions/palletethings
...
Palletethings
2023-07-17 16:20:44 -04:00
Mike Reeves
01234f87f9
fix other OS installs
2023-07-17 16:20:32 -04:00
m0duspwnens
5d4186ac07
different whiptail warning if ubuntu 20.04
2023-07-17 15:56:29 -04:00
m0duspwnens
425ca35a22
Merge remote-tracking branch 'origin/centos' into palletethings
2023-07-17 13:58:00 -04:00
m0duspwnens
fe5ca3a0c8
set palette after detecting os and before whiptail
2023-07-17 13:51:14 -04:00
Mike Reeves
7fad710ca1
fix other OS installs
2023-07-17 13:51:01 -04:00
Mike Reeves
8d6c2600c9
fix other OS installs
2023-07-17 13:49:08 -04:00
Mike Reeves
38c7ea0801
fix other OS installs
2023-07-17 13:44:02 -04:00
Mike Reeves
abe0a9ec27
fix other OS installs
2023-07-17 11:03:28 -04:00
Mike Reeves
f0f8513370
fix other OS installs
2023-07-17 11:02:34 -04:00
Mike Reeves
bffd24e0d5
fix other OS installs
2023-07-17 10:55:04 -04:00
Mike Reeves
71cbab8fcc
fix other OS installs
2023-07-17 10:47:24 -04:00
weslambert
6816d06710
Merge pull request #10766 from Security-Onion-Solutions/fix/elastic-agent-scripts
...
Add agent scripts
2023-07-17 10:46:54 -04:00
Wes
d19615f743
Fix typo
2023-07-17 14:42:27 +00:00
Mike Reeves
894e009b95
fix other OS installs
2023-07-17 10:34:14 -04:00
Wes
1a4515fc8a
Split restart into stop and start
2023-07-17 14:30:51 +00:00
Wes
31696803e1
Use correct name
2023-07-17 14:28:12 +00:00
Wes
e715dfa354
Remove sbin
2023-07-17 14:27:39 +00:00
Wes
c723a09107
Remove agent installer generation script
2023-07-14 21:45:25 +00:00
Wes
8cf3ceeb71
Update agent scripts
2023-07-14 21:43:03 +00:00
Mike Reeves
921fc95668
Fix logic
2023-07-14 14:35:51 -04:00
Doug Burks
9e42fb927d
Add RPM-GPG-KEY-oracle
2023-07-14 14:04:36 -04:00
Mike Reeves
87d72e852c
Fix logic
2023-07-14 13:45:31 -04:00
m0duspwnens
ba2782c5e7
patch x509_v2.py
2023-07-14 13:22:40 -04:00
Mike Reeves
9169fca9f8
Merge branch '2.4/dev' into centos
2023-07-14 13:17:52 -04:00
Mike Reeves
1028fb1346
Fix ISO install
2023-07-14 13:17:20 -04:00
Josh Brower
6846487909
Merge pull request #10765 from Security-Onion-Solutions/2.4/FleetEnhancements
...
Retry install
2023-07-14 13:07:25 -04:00
Josh Brower
2cc0c4c0ac
Automatically Update ES URLs
2023-07-14 12:07:32 -04:00
Mike Reeves
5a5b643155
Fix ISO install
2023-07-14 12:04:30 -04:00
Josh Patterson
e97bec2bc1
Merge pull request #10769 from Security-Onion-Solutions/wtinstalltype
...
Wtinstalltype
2023-07-14 09:22:40 -04:00
Josh Brower
78db64a419
Auto-managed Fleet Server URLs
2023-07-14 08:40:26 -04:00
m0duspwnens
55d32c5b98
merge and fix conflicts
2023-07-14 08:37:03 -04:00
Mike Reeves
333213d1dd
Multi OS Support
2023-07-13 18:40:48 -04:00
Mike Reeves
03b16a5582
Multi OS Support
2023-07-13 18:29:02 -04:00
Mike Reeves
20c76abac4
Multi OS Support
2023-07-13 18:27:21 -04:00
m0duspwnens
4158e18675
warn of unsupported os
2023-07-13 16:38:51 -04:00
Mike Reeves
f0c391e801
Multi OS Support
2023-07-13 15:05:51 -04:00
weslambert
922a77ac55
Merge pull request #10762 from Security-Onion-Solutions/fix/integration_elasticsearch
...
Allow Elasticsearch integration policy
2023-07-13 14:42:23 -04:00
weslambert
a62f96595c
Merge pull request #10763 from Security-Onion-Solutions/fix/strelka_pe
...
Strelka entropy and pe fixes
2023-07-13 14:42:12 -04:00
Josh Brower
fb8a79e112
Retry install
2023-07-13 13:15:01 -04:00
Mike Reeves
782a3eccfe
Initial Oracle support
2023-07-13 11:29:18 -04:00
Mike Reeves
2c996fe7ad
Initial Oracle support
2023-07-13 10:54:04 -04:00
weslambert
0c177ec923
Allow Elasticsearch integration policy
2023-07-13 10:46:59 -04:00
Wes
41f00c0aa1
Add agent scripts
2023-07-13 14:32:22 +00:00
Mike Reeves
05b30771c5
Initial Oracle support
2023-07-13 10:29:06 -04:00
Wes
e3249c8e4c
Wrap values in quotes for proper conversion
2023-07-13 14:18:57 +00:00
Mike Reeves
a0b6e1076f
Initial Oracle support
2023-07-13 10:04:55 -04:00
weslambert
85bb5a327c
Fix long vs float for pe version
2023-07-13 09:38:09 -04:00
Mike Reeves
68f5c9965a
Initial Oracle support
2023-07-13 09:24:01 -04:00
Mike Reeves
727d0443a2
Merge pull request #10757 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERSION
2023-07-13 08:53:35 -04:00
Mike Reeves
b915cea52f
Initial Oracle support
2023-07-13 08:44:20 -04:00
Mike Reeves
d98a1d5ae5
Initial Oracle support
2023-07-13 08:40:09 -04:00
Josh Brower
6f5bb136ff
Merge pull request #10753 from Security-Onion-Solutions/2.4/integrationfixes
...
Update Integration JSON
2023-07-13 07:34:32 -04:00
Mike Reeves
695ec149f1
Initial Oracle support
2023-07-12 15:07:26 -04:00
Mike Reeves
50103aebb3
Initial Oracle support
2023-07-12 14:59:36 -04:00
Mike Reeves
6f81e234cd
Initial Oracle support
2023-07-12 14:52:23 -04:00
Mike Reeves
7732435b64
Initial Oracle support
2023-07-12 14:49:59 -04:00
Mike Reeves
2cf36f1e8f
Initial Oracle support
2023-07-12 14:12:24 -04:00
Mike Reeves
43d63a3187
Update VERSION
2023-07-12 10:59:12 -04:00
Mike Reeves
37116a9bdd
Merge pull request #10755 from Security-Onion-Solutions/2.4/dev
...
2.4.3
2023-07-12 10:57:42 -04:00
Jason Ertel
6297a2632b
Merge pull request #10756 from Security-Onion-Solutions/kilo
...
catch up branch
2023-07-12 10:38:18 -04:00
Jason Ertel
5cc752f128
Merge branch '2.4/main' into 2.4/dev
2023-07-12 10:19:39 -04:00
Mike Reeves
68d95cd1cb
Merge pull request #10754 from Security-Onion-Solutions/2.4.3
...
2.4.3
2023-07-12 10:05:31 -04:00
Mike Reeves
1a68c3cd24
2.4.3
2023-07-12 10:02:19 -04:00
Josh Brower
40294e2762
Update Integration JSON
2023-07-12 08:49:36 -04:00
Josh Patterson
87eec4ae88
Merge pull request #10751 from Security-Onion-Solutions/yararules
...
Yararules
2023-07-11 15:55:00 -04:00
m0duspwnens
676696b24a
restart strelka backend if rules change
2023-07-11 15:48:22 -04:00
m0duspwnens
da27fce95f
run so-yara-download/update if scripts change
2023-07-11 13:48:26 -04:00
weslambert
8acc37a7d1
Merge pull request #10749 from Security-Onion-Solutions/fix/yara_update
...
Fix syntax for conditional
2023-07-11 13:41:38 -04:00
weslambert
5f1b467e64
Fix syntax for conditional
2023-07-11 13:37:50 -04:00
weslambert
fe7fb7f54d
Merge pull request #10748 from Security-Onion-Solutions/fix/elasticsearch_strelka
...
Update logic for YARA matches
2023-07-11 13:02:24 -04:00
Wes
577bfac886
Update logic for YARA matches
2023-07-11 17:00:13 +00:00
Josh Patterson
468b6e4831
Merge pull request #10741 from Security-Onion-Solutions/m0duspwnens-patch-1
...
import ELASTICFLEETMERGED
2023-07-11 11:04:26 -04:00
Josh Patterson
c75d209d7f
import ELASTICFLEETMERGED
2023-07-11 11:01:27 -04:00
Josh Brower
b29b264d5c
Merge pull request #10740 from Security-Onion-Solutions/2.4/removecomments
...
Remove Comments
2023-07-11 10:28:41 -04:00
Josh Brower
c99e7da5a7
Remove Comments
2023-07-11 10:26:18 -04:00
Josh Patterson
60d66b973c
Merge pull request #10739 from Security-Onion-Solutions/yararules
...
include *.yara
2023-07-11 10:21:35 -04:00
m0duspwnens
304830d2ee
remove old rules prior to copy
2023-07-11 10:20:04 -04:00
m0duspwnens
d7285d69a7
include *.yara
2023-07-11 09:59:13 -04:00
weslambert
7cdd1f89d7
Merge pull request #10736 from Security-Onion-Solutions/fix/strelka_path
...
Change path to old one
2023-07-11 09:13:36 -04:00
weslambert
b7cab1d118
Change path to old one
2023-07-11 09:10:20 -04:00
weslambert
f03a472ee5
Merge pull request #10731 from Security-Onion-Solutions/fix/kibana_file_search
...
Kibana dashboard changes
2023-07-11 08:50:03 -04:00
Mike Reeves
c7a0801eed
Merge pull request #10725 from Security-Onion-Solutions/yararules
...
Yararules
2023-07-11 08:49:20 -04:00
Josh Brower
5e0015e9ac
Merge pull request #10735 from Security-Onion-Solutions/2.4/TagPlaybookAlerts
...
2.4/tag playbook alerts
2023-07-11 08:37:37 -04:00
Josh Brower
5a72c558cb
Tag at top level
2023-07-11 08:35:47 -04:00
Josh Brower
a6e907f76c
Tag Playbook Alerts
2023-07-11 08:03:15 -04:00
Mike Reeves
a3f79850fe
Initial Oracle support
2023-07-10 20:31:49 -04:00
Josh Brower
2d3eb22057
Merge pull request #10732 from Security-Onion-Solutions/2.4/autogenfix
...
Exclude Import and Eval from autoupdate
2023-07-10 17:18:10 -04:00
Josh Brower
8437fcd94c
Exclude Import and Eval from autoupdate
2023-07-10 17:10:08 -04:00
Josh Brower
1b25db4573
Merge pull request #10680 from Security-Onion-Solutions/2.4/fleetautogen
...
Automatically manage Fleet Logstash Config
2023-07-10 16:26:20 -04:00
m0duspwnens
f8ed2e6e8e
make parent dirs
2023-07-10 16:11:45 -04:00
m0duspwnens
f22c61a0a2
use su instead of runuser since logCmd has issues with runuser
2023-07-10 15:19:41 -04:00
m0duspwnens
5069d1163c
only *.yar files
2023-07-10 14:36:34 -04:00
Josh Brower
31edf2e8ea
Tighten & Document Pipelines
2023-07-10 14:17:42 -04:00
Wes
6b8893ded5
Update saved objects
2023-07-10 18:13:34 +00:00
m0duspwnens
1f8b7bda89
fix output_dir var
2023-07-10 13:39:31 -04:00
Mike Reeves
b9204cbe99
Initial RHEL support
2023-07-10 12:57:59 -04:00
m0duspwnens
59233d6550
use full path
2023-07-10 11:43:56 -04:00
m0duspwnens
1ac72e5b24
ensure /nsm/rules/yara directory exists
2023-07-10 11:10:37 -04:00
Josh Brower
7805ca8beb
Add Failover Support
2023-07-10 10:38:14 -04:00
m0duspwnens
47b2481cdd
nothing in strelka/tools/sbin_jinja to file.recurse
2023-07-10 10:29:19 -04:00
m0duspwnens
fa933d3f53
use file_mode
2023-07-10 10:26:30 -04:00
Mike Reeves
6f7914f3c4
Initial RHEL support
2023-07-10 10:18:09 -04:00
Mike Reeves
0c9e230294
Initial RHEL support
2023-07-10 10:14:47 -04:00
m0duspwnens
f4dc73a206
yara download and update
2023-07-10 09:42:37 -04:00
Doug Burks
437c9cab68
Merge pull request #10726 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md
2023-07-10 09:07:11 -04:00
Wes
6da96a733f
Use tags instead of dataset
2023-07-10 13:06:38 +00:00
Doug Burks
82796370ce
Update README.md
2023-07-10 09:04:55 -04:00
Josh Brower
8c16feb772
Rename Fleet pipelines
2023-07-09 12:22:55 -04:00
Josh Brower
ce1f363424
Allow base_url
2023-07-08 13:30:19 -04:00
Josh Brower
e8860a7d2c
Fix perms
2023-07-08 09:04:55 -04:00
Josh Brower
beb26596fd
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/fleetautogen
2023-07-07 19:12:47 -04:00
m0duspwnens
6a5ff04804
remove unneeded function
2023-07-07 16:45:51 -04:00
Josh Brower
ff3bb11fbb
Elastic Fleet Certs Refactor
2023-07-07 16:44:16 -04:00
m0duspwnens
8be5082b60
yara scripts
2023-07-07 16:43:26 -04:00
coreyogburn
5faa4f0a30
Merge pull request #10720 from Security-Onion-Solutions/cogburn/8908
...
Allow an additional kratos endpoint through
2023-07-07 13:17:32 -06:00
Corey Ogburn
da7770a900
Allow an additional kratos endpoint through
...
The /auth/self-service/errors route is used to lookup auth issues so the route must also be proxied to kratos.
2023-07-07 12:47:55 -06:00
weslambert
8178338971
Merge pull request #10717 from Security-Onion-Solutions/fix/strelka_rules
...
Change path
2023-07-07 13:45:02 -04:00
weslambert
79ed17b506
Change path
2023-07-07 13:31:43 -04:00
Mike Reeves
fa1d53a309
Add Debian
2023-07-07 13:00:39 -04:00
Mike Reeves
a41b0dbfea
Add Debian
2023-07-07 12:59:41 -04:00
Mike Reeves
d28375b304
Add Debian
2023-07-07 12:54:47 -04:00
Mike Reeves
07c0b539d7
Add Debian
2023-07-07 12:53:23 -04:00
Mike Reeves
d18ebd6e36
Add Debian
2023-07-07 12:52:45 -04:00
Mike Reeves
5a642b151b
Add Debian
2023-07-07 12:51:17 -04:00
Mike Reeves
0aa4ea3e87
Add Debian
2023-07-07 12:49:11 -04:00
Mike Reeves
efcef90ead
Add Debian
2023-07-07 11:37:33 -04:00
Mike Reeves
af56aa4f16
Add Debian
2023-07-07 11:35:11 -04:00
Mike Reeves
d5257468eb
Add Debian
2023-07-07 11:31:18 -04:00
Mike Reeves
a3b0db7949
Add Debian
2023-07-07 11:27:42 -04:00
Mike Reeves
5f509eb2d8
Add Debian
2023-07-07 11:24:59 -04:00
Mike Reeves
a38d561684
Add Debian
2023-07-07 11:21:47 -04:00
Mike Reeves
4b559ec182
Add Debian
2023-07-07 11:19:36 -04:00
Mike Reeves
0b209d69e5
Add Debian
2023-07-07 11:02:26 -04:00
Josh Patterson
2785587840
Merge pull request #10714 from Security-Onion-Solutions/remove_so-logstash-get-unparsed
...
remove so-logstash-get-unparsed, use so-redis-count instead
2023-07-07 09:53:54 -04:00
weslambert
9f95306458
Merge pull request #10708 from Security-Onion-Solutions/fix/elasticsearch_templates_hn
...
Fix heavy node Elasticsearch template load
2023-07-07 09:52:54 -04:00
m0duspwnens
55bed0771b
remove so-logstash-get-unparsed, use so-redis-count instead
2023-07-07 09:52:21 -04:00
Wes
0b5ee49873
Fix inverted logic for component template
2023-07-06 20:46:35 +00:00
Jason Ertel
1646459052
Merge pull request #10707 from Security-Onion-Solutions/kilo
...
add default pillar file
2023-07-06 14:49:40 -04:00
Jason Ertel
8ec003d89f
add default pillar file
2023-07-06 14:47:21 -04:00
Jason Ertel
224f0606c2
Merge pull request #10706 from Security-Onion-Solutions/kilo
...
incorporate features pillar
2023-07-06 14:04:12 -04:00
Wes
910125f13a
Restructure logic
2023-07-06 17:49:06 +00:00
Jason Ertel
5eca1acbeb
incorporate features pillar
2023-07-06 13:24:45 -04:00
Wes
d551faeb16
Heavy node template considerations
2023-07-06 17:19:28 +00:00
Josh Patterson
6a6afeef75
Merge pull request #10704 from Security-Onion-Solutions/patch/x509_v2
...
Patch/x509 v2
2023-07-06 11:43:33 -04:00
m0duspwnens
869f60ccaa
cipher deprecated for x509_+v2
2023-07-06 10:51:44 -04:00
m0duspwnens
12c82d2812
bits deprecation to keysize
2023-07-06 10:49:32 -04:00
m0duspwnens
a2b50c6d40
remove quote
2023-07-06 10:25:19 -04:00
m0duspwnens
ab7ae6cddd
fix cp for x509_v2.py
2023-07-06 10:17:14 -04:00
m0duspwnens
7a9a12ae3d
fix cp for x509_v2.py
2023-07-06 10:03:12 -04:00
m0duspwnens
b49a296276
we can remove the unless in ssl state since x509_v2 is patched
2023-07-06 09:44:58 -04:00
Josh Patterson
9b9321d23a
Merge pull request #10698 from Security-Onion-Solutions/issue/10468
...
disable salt schedule after highstate then enable later in setup
2023-07-05 14:56:31 -04:00
m0duspwnens
1922ad95d5
disable salt schedule after highstate then enable later in setup
2023-07-05 13:43:54 -04:00
Josh Patterson
11493cb615
Merge pull request #10697 from Security-Onion-Solutions/jppcentos
...
Jppcentos
2023-07-05 09:52:01 -04:00
m0duspwnens
0def41f03c
Merge remote-tracking branch 'origin/centos' into jppcentos
2023-07-05 08:44:49 -04:00
Mike Reeves
1c191e426f
Add some Ubuntu
2023-07-03 16:20:44 -04:00
m0duspwnens
de98baaad4
Merge remote-tracking branch 'origin/centos' into jppcentos
2023-07-03 15:46:30 -04:00
m0duspwnens
df0e19ff80
update-alternatives for python3.10
2023-07-03 15:44:51 -04:00
Mike Reeves
d22d864ba6
Add some Ubuntu
2023-07-03 15:23:56 -04:00
Mike Reeves
898b352af9
Add some Ubuntu
2023-07-03 15:16:12 -04:00
Mike Reeves
76a8e315b7
Add some Ubuntu
2023-07-03 15:12:56 -04:00
Mike Reeves
edaf695463
Add some Ubuntu
2023-07-03 15:12:55 -04:00
Mike Reeves
53fcac4a02
Add some Ubuntu
2023-07-03 15:12:55 -04:00
Mike Reeves
44054ba95f
Add some Ubuntu
2023-07-03 15:12:54 -04:00
Mike Reeves
10aa77977e
Add some Ubuntu
2023-07-03 15:12:54 -04:00
Mike Reeves
8e90658856
Add some Ubuntu
2023-07-03 15:12:54 -04:00
Mike Reeves
965d0543f4
Add some Ubuntu
2023-07-03 15:12:53 -04:00
Mike Reeves
e353855855
Add some Ubuntu
2023-07-03 15:12:53 -04:00
Mike Reeves
c54217a8cb
Add some Ubuntu
2023-07-03 15:12:52 -04:00
Mike Reeves
710b3bac3d
fix repo state
2023-07-03 15:12:52 -04:00
Mike Reeves
8a90579df7
fix repo state
2023-07-03 15:12:51 -04:00
Mike Reeves
39c8766914
fix repo state
2023-07-03 15:12:51 -04:00
Mike Reeves
694ea743cc
add more OS logic
2023-07-03 15:12:51 -04:00
Mike Reeves
3d9e7d1e97
add fuse
2023-07-03 15:12:50 -04:00
Mike Reeves
ca71c00f1c
add fuse
2023-07-03 15:12:50 -04:00
Mike Reeves
2f2394dca2
add OS logic
2023-07-03 15:12:49 -04:00
Mike Reeves
fee4c20912
add OS logic
2023-07-03 15:12:49 -04:00
Mike Reeves
03342fd477
Add more packages
2023-07-03 15:12:49 -04:00
Mike Reeves
6dbff3b9df
Add more packages
2023-07-03 15:12:48 -04:00
Mike Reeves
2f375b89a8
Add more packages
2023-07-03 15:12:48 -04:00
Mike Reeves
f67ac80c56
Add more packages
2023-07-03 15:12:47 -04:00
Mike Reeves
b06a35099f
Add more packages
2023-07-03 15:12:47 -04:00
Mike Reeves
087099b9b6
Fix keys
2023-07-03 15:12:47 -04:00
Mike Reeves
04fe2ca996
Fix gpg things
2023-07-03 15:12:46 -04:00
Mike Reeves
bdb5748b44
Fix whiptail logic
2023-07-03 15:12:46 -04:00
Mike Reeves
1cbe5580a6
Fix whiptail logic
2023-07-03 15:12:45 -04:00
Mike Reeves
b57674a7cc
Fix syntax error
2023-07-03 15:12:45 -04:00
Mike Reeves
53bd7bcc29
Initial Support
2023-07-03 15:12:45 -04:00
Mike Reeves
6787b97c6a
Initial Support
2023-07-03 15:12:44 -04:00
m0duspwnens
0d43f9aaf4
add repo noninteractively
2023-07-03 14:23:24 -04:00
Mike Reeves
40540f47bf
Add some Ubuntu
2023-07-03 13:51:01 -04:00
Mike Reeves
24e05c9491
Add some Ubuntu
2023-07-03 13:45:04 -04:00
Mike Reeves
02c9465dfb
Add some Ubuntu
2023-07-03 12:30:53 -04:00
Mike Reeves
a4d484ea47
Add some Ubuntu
2023-07-03 12:00:57 -04:00
Mike Reeves
c9d650f4c8
Add some Ubuntu
2023-07-03 11:59:07 -04:00
Josh Patterson
9de8814412
Merge pull request #10692 from Security-Onion-Solutions/issue/10545
...
Issue/10545
2023-07-03 11:05:55 -04:00
Josh Brower
35e7659904
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/fleetautogen
2023-07-03 10:36:29 -04:00
Mike Reeves
ed1d2d0a8b
Add some Ubuntu
2023-07-03 10:06:16 -04:00
Mike Reeves
903de330c2
Add some Ubuntu
2023-07-03 09:49:24 -04:00
Mike Reeves
8621352701
Add some Ubuntu
2023-07-03 09:38:23 -04:00
Mike Reeves
564ab105ba
Add some Ubuntu
2023-07-02 09:34:14 -04:00
Mike Reeves
b637e27c8d
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into centos
2023-07-02 09:13:06 -04:00
weslambert
d31ea4097d
Merge pull request #10683 from Security-Onion-Solutions/fix/kibana_http_search
...
Kibana dashboard changes
2023-06-30 17:17:37 -04:00
Wes
c277b7acfa
Change Zeek file from evet dataset to tags
2023-06-30 20:24:10 +00:00
m0duspwnens
97a9e0989d
Merge remote-tracking branch 'origin/2.4/dev' into issue/10545
2023-06-30 15:46:41 -04:00
Wes
6bdccec6b1
Add asterisk back to Modbus search
2023-06-30 19:01:53 +00:00
m0duspwnens
35945ed224
create local logrotate pillar dir
2023-06-30 14:43:00 -04:00
m0duspwnens
7319d7ae9b
replace . with _x_
2023-06-30 14:18:20 -04:00
Wes
8b38cbe8cf
Fix Modbus since the previous fix was reverted
2023-06-30 17:38:05 +00:00
Wes
35ea084466
Update from exported saved objects again
2023-06-30 16:55:00 +00:00
Jason Ertel
c89582ffb6
Merge pull request #10685 from Security-Onion-Solutions/kilo
...
remove use of pipe
2023-06-30 12:23:48 -04:00
Jason Ertel
d6db94a4d4
reset ver
2023-06-30 12:11:32 -04:00
Wes
e2acf027a9
Update from exported saved objects
2023-06-30 16:01:50 +00:00
m0duspwnens
d6d8ba7479
Merge remote-tracking branch 'origin/2.4/dev' into issue/10545
2023-06-30 11:29:25 -04:00
m0duspwnens
41a4321b03
configure logrotate through soc
2023-06-30 11:26:55 -04:00
Jason Ertel
2ae049071d
Merge branch '2.4t/dev' into kilo
2023-06-30 11:10:01 -04:00
Jason Ertel
e82df53997
switch version to kilo
2023-06-30 11:08:42 -04:00
Wes
273e78da94
Modbus dashboard - use asterisk
2023-06-30 15:03:20 +00:00
Wes
446376395e
Modbus dashboard - use tags
2023-06-30 13:56:08 +00:00
Wes
a13001dce0
PE dashboard - use tags
2023-06-30 13:40:36 +00:00
Wes
8819e1d4d6
HTTP search - use tags
2023-06-30 13:02:00 +00:00
Josh Brower
1baea3bcd5
Add Fleet to Logstash Nodes
2023-06-29 17:24:52 -04:00
Josh Patterson
1c37c05824
Merge pull request #10682 from Security-Onion-Solutions/addbackunless
...
add back unless in ssl state
2023-06-29 16:13:39 -04:00
m0duspwnens
cd1db36c13
add back unless in ssl state
2023-06-29 15:26:16 -04:00
m0duspwnens
5898c9ef31
start of logrotate configurable via ui
2023-06-29 12:54:37 -04:00
Jason Ertel
951f04c265
remove use of pipe
2023-06-29 12:10:12 -04:00
Josh Brower
4b069d91ab
Check the correct pillar
2023-06-29 11:00:34 -04:00
Mike Reeves
34ab949dfc
fix repo state
2023-06-29 08:56:38 -04:00
Mike Reeves
59191008a0
fix repo state
2023-06-29 08:55:00 -04:00
Mike Reeves
17a04a75c9
fix repo state
2023-06-29 08:53:00 -04:00
Josh Brower
7561ec0512
Automatically manage Fleet Logstash Config
2023-06-29 08:52:51 -04:00
Mike Reeves
884d669ae9
add more OS logic
2023-06-29 08:48:46 -04:00
Mike Reeves
8a88b16b9e
add fuse
2023-06-28 16:16:59 -04:00
Mike Reeves
6545ae588d
add fuse
2023-06-28 16:10:23 -04:00
Mike Reeves
5ab54fcfc5
add OS logic
2023-06-28 16:02:25 -04:00
Mike Reeves
ae4befe377
add OS logic
2023-06-28 15:57:43 -04:00
Mike Reeves
0c320e3501
Add more packages
2023-06-28 15:46:29 -04:00
Mike Reeves
933f4fa6c8
Add more packages
2023-06-28 15:45:32 -04:00
Mike Reeves
d80c88f613
Add more packages
2023-06-28 15:43:56 -04:00
Mike Reeves
6d2e851a43
Add more packages
2023-06-28 15:36:51 -04:00
Mike Reeves
209aae50bc
Add more packages
2023-06-28 15:32:01 -04:00
Josh Patterson
eef1b40436
Merge pull request #10677 from Security-Onion-Solutions/issue/10533
...
Issue/10533
2023-06-28 15:17:42 -04:00
m0duspwnens
34db6fb823
dont need the unless for ssl since using x509v2 now
2023-06-28 15:06:13 -04:00
m0duspwnens
eeaf077baf
dont need the unless for ssl since using x509v2 now
2023-06-28 15:02:09 -04:00
m0duspwnens
120d21c0da
use minion id instead of hostname for ca_server in nginx state
2023-06-28 13:52:30 -04:00
Mike Reeves
6fc988740d
Fix keys
2023-06-28 13:46:25 -04:00
m0duspwnens
66457ad8f8
use watch_in instead of watch
2023-06-28 12:27:14 -04:00
m0duspwnens
69670c481d
fix require logic for nginx container
2023-06-28 11:32:08 -04:00
m0duspwnens
cae011babb
force bool for nginx ssl replace_cert
2023-06-28 11:30:36 -04:00
m0duspwnens
02ea939abc
watch crt and key for nginx container
2023-06-28 11:11:20 -04:00
m0duspwnens
be028aa23e
define ca_server for nginx.ssl
2023-06-28 10:58:13 -04:00
m0duspwnens
24b7f7a7ce
move replace_cert under ssl for nginx defaults
2023-06-28 10:32:16 -04:00
m0duspwnens
12cce111db
custom crt and key for nginx
2023-06-28 10:28:50 -04:00
weslambert
add72d7a5c
Merge pull request #10670 from Security-Onion-Solutions/fix/kibana_dashboards
...
Kibana Dashboards - Remove Wazuh reference and use tags
2023-06-28 09:41:19 -04:00
Josh Brower
c7a1d4758b
Merge pull request #10598 from Security-Onion-Solutions/2.4/fix-naming
...
Remove old var
2023-06-28 07:09:37 -04:00
Wes
8436b647dd
Remove Wazuh and use tags
2023-06-27 18:05:04 +00:00
Mike Reeves
387ce22385
Fix gpg things
2023-06-27 13:57:53 -04:00
Mike Reeves
cc3c28135d
Fix whiptail logic
2023-06-27 12:53:18 -04:00
Mike Reeves
6b6724afcf
Fix whiptail logic
2023-06-27 12:52:53 -04:00
Mike Reeves
c37a179a3c
Fix syntax error
2023-06-27 12:46:13 -04:00
Doug Burks
77e6ee3c36
Merge pull request #10669 from Security-Onion-Solutions/dougburks-patch-1
...
Update so-desktop-install
2023-06-27 09:26:44 -04:00
Doug Burks
3e71663669
Update so-desktop-install
2023-06-27 09:24:47 -04:00
Mike Reeves
d519369c6f
Initial Support
2023-06-26 19:22:33 -04:00
Mike Reeves
883d9560a0
Initial Support
2023-06-26 19:20:40 -04:00
Mike Reeves
984971c63c
Merge pull request #10667 from Security-Onion-Solutions/desktop
...
Fix some installs
2023-06-26 18:51:55 -04:00
Mike Reeves
6adef20a06
Fix the rest of the analyst entries
2023-06-26 16:26:55 -04:00
Mike Reeves
cb8faf7c5f
Fix the rest of the analyst entries
2023-06-26 16:14:04 -04:00
Mike Reeves
740723ecd6
Fix some installs
2023-06-26 16:01:58 -04:00
Mike Reeves
d70371c540
Merge pull request #10665 from Security-Onion-Solutions/desktop
...
Desktop Install
2023-06-26 15:42:14 -04:00
Mike Reeves
b6986d5c61
Merge branch '2.4/dev' into desktop
2023-06-26 15:36:48 -04:00
Mike Reeves
02e6e11be7
so-desktop-install
2023-06-26 15:34:48 -04:00
Mike Reeves
d26484fe1a
so-desktop-install
2023-06-26 15:27:18 -04:00
Mike Reeves
12d10d7d42
Merge branch '2.4/dev' into desktop
2023-06-26 15:20:43 -04:00
Mike Reeves
7ea37ac2dd
Merge pull request #10663 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update packages.sls
2023-06-26 11:25:14 -04:00
Mike Reeves
7aae72cfcf
Update packages.sls
2023-06-26 11:23:02 -04:00
Mike Reeves
ec427cde08
Merge pull request #10662 from Security-Onion-Solutions/desktop
...
Desktop State
2023-06-26 10:48:41 -04:00
weslambert
c2efd7ef64
Merge pull request #10655 from Security-Onion-Solutions/feature/supported_integrations
...
Restructure Elasticsearch templates for supported integrations
2023-06-26 09:43:10 -04:00
Mike Reeves
77c58e665e
Merge pull request #10654 from Security-Onion-Solutions/24soup
...
soup updates
2023-06-26 09:26:47 -04:00
Mike Reeves
9530901d1d
Remove local file check
2023-06-26 09:09:55 -04:00
Doug Burks
e83afa3e30
Merge pull request #10660 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md
2023-06-26 08:33:22 -04:00
Doug Burks
70fb28a8b3
Update README.md
2023-06-26 08:31:41 -04:00
Josh Brower
8355432356
Merge pull request #10657 from Security-Onion-Solutions/2.4/policy-name-fix
...
2.4/policy name fix
2023-06-24 19:00:00 -04:00
Josh Brower
2247cafe5f
Change policy name
2023-06-24 17:13:28 -04:00
Josh Brower
85a8da6331
Change policy name
2023-06-24 16:58:36 -04:00
Josh Brower
ddabab253c
Merge pull request #10653 from Security-Onion-Solutions/2.4/heavynode
...
2.4/heavynode
2023-06-23 19:55:24 -04:00
Jason Ertel
2e42eddbc2
Merge pull request #10656 from Security-Onion-Solutions/jertel/fix-import
...
fix agent extract error during install; simplify logic
2023-06-23 17:21:39 -04:00
Jason Ertel
07a590dda8
fix agent extract error during install; simplify logic
2023-06-23 17:17:59 -04:00
Mike Reeves
ec8eac3430
soup fix
2023-06-23 17:05:41 -04:00
weslambert
05b84327b8
Fix typo
2023-06-23 16:32:57 -04:00
Mike Reeves
0607532e4a
soup fix
2023-06-23 16:20:41 -04:00
Mike Reeves
3018886f72
soup fix
2023-06-23 16:13:04 -04:00
weslambert
e02bdffe34
Fix typos
2023-06-23 16:10:22 -04:00
Mike Reeves
5073d62ee8
soup fix
2023-06-23 16:09:57 -04:00
weslambert
e2ff48164b
Only load if so-elastic-fleet-common exists
2023-06-23 16:03:58 -04:00
Mike Reeves
43832f9c34
soup fix
2023-06-23 16:03:51 -04:00
Mike Reeves
5da5a04025
soup fix
2023-06-23 16:00:02 -04:00
Mike Reeves
25b51135fc
soup fix
2023-06-23 15:58:20 -04:00
weslambert
aa91c1fef2
Add empty object for index_settings
2023-06-23 15:57:30 -04:00
Mike Reeves
801a5a6824
soup fix
2023-06-23 15:56:15 -04:00
Mike Reeves
f63c26b7f2
soup fix
2023-06-23 15:50:54 -04:00
Josh Brower
336a40d646
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/heavynode
2023-06-23 15:50:14 -04:00
Josh Brower
bb0cfc5253
Create & assign Heavy Node Fleet Policy
2023-06-23 15:49:03 -04:00
coreyogburn
106aaa9c3e
Merge pull request #10652 from Security-Onion-Solutions/cogburn/10122
...
FIX: Exclude System logs from Hunt/Dashboard Queries.
2023-06-23 13:48:17 -06:00
weslambert
ff7db0be63
Remove old index settings
2023-06-23 15:31:11 -04:00
Wes
b96d3473f2
Fix indentation
2023-06-23 18:38:04 +00:00
Corey Ogburn
fb27e7c479
Also add to dashboard
...
Duplicate new queryToggleFilter from hunt to dashboard.
2023-06-23 11:30:26 -06:00
Corey Ogburn
261acee8a0
New Hunt queryToggleFilter
...
New filter to exclude soc logs from hunt results.
2023-06-23 11:30:26 -06:00
Josh Brower
a9585b2a7f
Fix Elastic Agent for Heavy
2023-06-23 10:45:58 -04:00
Wes
62fa15c63e
Add more templates
2023-06-23 14:43:15 +00:00
weslambert
e995576b1d
Remove extra templates
2023-06-23 09:41:49 -04:00
Jason Ertel
d247c9d704
Merge pull request #10648 from Security-Onion-Solutions/jertel/fix-import
...
use cluster-unique password for import encryption
2023-06-23 09:40:26 -04:00
Jason Ertel
b21b545756
use cluster-unique password for import encryption
2023-06-23 09:37:41 -04:00
Wes
5e8748c436
Load Elasticsearch templates
2023-06-23 13:28:01 +00:00
Wes
e2cca917c1
Add package load command to Fleet setup
2023-06-23 13:26:06 +00:00
Wes
d8700137d2
Add updated so-elasticsearch-templates-load
2023-06-23 13:23:29 +00:00
Wes
2c42d4b19e
Add package check to so-elasticsearch-templates-load
2023-06-23 13:22:51 +00:00
Wes
a3c7e40c40
Add package load command
2023-06-23 13:20:05 +00:00
Wes
94fe456e28
Add package functions
2023-06-23 13:19:20 +00:00
Wes
662db41857
Add default packages
2023-06-23 13:17:38 +00:00
Jason Ertel
7623dd20b9
Merge pull request #10644 from Security-Onion-Solutions/cogburn/salt-relay-fix
...
WIP: Fix `salt cmd.run` commands for importing
2023-06-22 20:31:19 -04:00
Corey Ogburn
2b323ab661
Fix salt cmd.run commands for importing
...
Functional and easy to read.
2023-06-22 17:30:56 -06:00
Josh Brower
8de01625a8
Add Elastic Agent container for Heavy Nodes
2023-06-22 16:02:42 -04:00
Josh Brower
d0d7ab57ca
Add Elastic Agent container for Heavy Nodes
2023-06-22 16:02:17 -04:00
Jason Ertel
f4cbe20ddf
Merge pull request #10641 from Security-Onion-Solutions/jertel/fix-import
...
fix quotations
2023-06-22 14:46:41 -04:00
Jason Ertel
0d92a1594a
fix quotations
2023-06-22 14:41:39 -04:00
m0duspwnens
daaead618e
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/heavynode
2023-06-22 13:26:56 -04:00
m0duspwnens
19469205e1
include eval and import in so-elasticsearch-cluster-settings
2023-06-22 13:12:47 -04:00
Jason Ertel
cae9e6230f
Merge pull request #10638 from Security-Onion-Solutions/cogburn/import-fix
...
Change upload path
2023-06-22 13:04:22 -04:00
m0duspwnens
6c4c815683
change so-elasticsearch-cluster settings to include heavynode, and only run on managers
2023-06-22 13:04:20 -04:00
Corey Ogburn
6769386c86
Change upload path
2023-06-22 10:59:24 -06:00
m0duspwnens
36272efda7
create ES_LOGSTASH_NODES which removes heavynodes
2023-06-22 09:46:42 -04:00
weslambert
6b97d07a89
Merge pull request #10629 from Security-Onion-Solutions/fix/elasticsearch_ingest_suricata_xff_ip
...
Parse xff
2023-06-22 08:45:58 -04:00
coreyogburn
da82395dcf
Merge pull request #10633 from Security-Onion-Solutions/cogburn/10413
...
Cogburn/10413
2023-06-21 15:48:53 -06:00
Corey Ogburn
b5e5bd57ad
Fix for Upload Import
...
Needed to mount /nsm/soc/uploads into soc container.
Made the upload route configurable.
Added gpg logging to salt-relay.
2023-06-21 15:41:16 -06:00
Josh Patterson
ad4fb52b81
Merge pull request #10631 from Security-Onion-Solutions/2.4/repos
...
2.4/repos
2023-06-21 16:06:30 -04:00
m0duspwnens
4e849ecc90
issues with exclude rocky-repos
2023-06-21 15:14:53 -04:00
weslambert
7e37cd0f05
Parse xff
2023-06-21 14:29:54 -04:00
Mike Reeves
3952c1a9b7
Fix desktop state
2023-06-21 13:52:10 -04:00
Mike Reeves
c13c37f406
Fix desktop state
2023-06-21 13:49:01 -04:00
Mike Reeves
9240c3c6f0
Fix desktop package list
2023-06-21 13:42:51 -04:00
Mike Reeves
2aa01280e7
Fix desktop package list
2023-06-21 13:34:47 -04:00
m0duspwnens
1675b787bf
exclude rocky-repos and remove files
2023-06-21 13:27:34 -04:00
Mike Reeves
4866eb2315
Fix desktop package list
2023-06-21 12:52:42 -04:00
Mike Reeves
f785fb2772
Fix desktop package list
2023-06-21 12:27:15 -04:00
Mike Reeves
8c9f863808
Fix desktop package list
2023-06-21 12:22:03 -04:00
Mike Reeves
1751e35121
Fix desktop package list
2023-06-21 12:20:57 -04:00
Mike Reeves
6676afc7de
Fix desktop package list
2023-06-21 12:19:48 -04:00
Mike Reeves
699ea1ac3e
Fix desktop package list
2023-06-21 11:48:37 -04:00
Mike Reeves
90fdb9c465
Update paths
2023-06-21 11:47:22 -04:00
Mike Reeves
48291f5271
Merge branch '2.4/dev' of https://github.com/Security-Onion-Solutions/securityonion into desktop
2023-06-21 11:43:05 -04:00
Mike Reeves
3a41b090c1
Update paths
2023-06-21 11:42:51 -04:00
Josh Brower
139b36b189
Merge pull request #10627 from Security-Onion-Solutions/2.4/import-evtx
...
Refactor EVTX Import
2023-06-21 11:42:10 -04:00
Josh Brower
6ddf887342
Refactor EVTX Import
2023-06-21 09:32:42 -04:00
Josh Brower
6ba9e057a9
Merge pull request #10600 from Security-Onion-Solutions/fix/dataset_tags
...
Change format of event dataset and assign dataset to tags
2023-06-21 09:22:40 -04:00
Mike Reeves
6600484f8e
Update Docker
2023-06-21 09:15:31 -04:00
Mike Reeves
b02c38175c
Merge pull request #10624 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Salt Defunct Workaround
2023-06-20 17:44:53 -04:00
Mike Reeves
4497f6561f
Salt Defunct Workaround
...
This can be removed once they patch salt
2023-06-20 17:27:02 -04:00
Mike Reeves
0fc03baf58
Desktop Packages
2023-06-20 13:41:10 -04:00
coreyogburn
fb81c6e2e3
Merge pull request #10601 from Security-Onion-Solutions/cogburn/10413
...
Cogburn/10413
2023-06-20 11:08:53 -06:00
Corey Ogburn
ad28ea275f
Better state management
...
When salt-cp runs it's course and finds it can't send a file, it outputs a report saying as much but the exit code will be zero. Now we remove the filename and node from the response and look for `True` to know if it succeeded. Also, respect the cleanup flag on success or failure.
Check the status of the decryption process before importing.
No longer decrypt locally, issue salt command for the remote client to do the decrypting.
2023-06-20 09:41:14 -06:00
Corey Ogburn
41951659ec
Use importer's new --json flag.
...
Using the new --json flag is not only more reliable than using a regex, the way the import script was written even re-imports will provide a url. This means that in more cases we can provide the results to the users (even if nothing changed).
2023-06-20 09:41:14 -06:00
Corey Ogburn
451a4784a1
send-file and import-file security
...
Encrypt the file with a passphrase before sending and decrypt the file with the same passphrase before importing.
2023-06-20 09:41:14 -06:00
Corey Ogburn
1b7095fa81
Improved import-file url regex
...
sed doesn't remove ALL whitespace, only newlines. It's better to stop at the first whitespace than to stop at a particular, maybe-not-last query string parameter.
2023-06-20 09:41:14 -06:00
Corey Ogburn
89d789fe0f
New folder for salt to maintain
...
This folder is where a manager will initially store uploaded PCAP/EVTX files before sending to sensors. Sensors will store uploads in this folder on their own system.
2023-06-20 09:41:14 -06:00
Corey Ogburn
49055e260f
salt-relay import-file reporting
...
On successful import, return dashboard URL
2023-06-20 09:41:14 -06:00
Corey Ogburn
a465039887
2 new capabilities: send-file and import-file
2023-06-20 09:41:14 -06:00
Doug Burks
b60cf29598
Merge pull request #10618 from Security-Onion-Solutions/dougburks-patch-1
...
Resolve conflicts with dataset PR
2023-06-20 07:42:30 -04:00
Doug Burks
0e09d73aa0
Resolve conflicts with dataset PR
2023-06-20 07:40:10 -04:00
Doug Burks
520a5671ca
Merge pull request #10617 from Security-Onion-Solutions/dougburks-patch-1
...
Fix SOC Auth queries in Dashboards and Hunt
2023-06-20 07:32:46 -04:00
Doug Burks
fc824359ed
Update default fields for kratos.audit
2023-06-20 07:30:56 -04:00
Doug Burks
7caa7cec6b
Fix SOC Auth queries in Dashboards and Hunt
...
Change `event.dataset:audit` to `event.dataset:kratos.audit`.
2023-06-20 07:13:33 -04:00
Josh Patterson
0695140f83
Merge pull request #10611 from Security-Onion-Solutions/2.4/ubuntu
...
2.4/ubuntu
2023-06-16 14:00:52 -04:00
m0duspwnens
ed1e2c8908
ignore failure notification for Ubuntu Failed to restart snapd
2023-06-16 13:58:45 -04:00
Jason Ertel
594900a8d4
Merge pull request #10609 from Security-Onion-Solutions/kilo
...
webauthn for SOC
2023-06-16 13:15:25 -04:00
Jason Ertel
6894fa4e4d
Update VERSION
2023-06-16 13:09:01 -04:00
m0duspwnens
2334d82d36
fix salt install for ubuntu
2023-06-16 11:13:34 -04:00
Josh Patterson
c0a2ea3138
Merge pull request #10604 from Security-Onion-Solutions/2.4/receiver
...
2.4/receiver
2023-06-15 15:42:34 -04:00
m0duspwnens
d4acb1a33a
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/receiver
2023-06-15 15:32:49 -04:00
m0duspwnens
5de9e5baf4
allow sensor to logstash on receiver
2023-06-15 14:46:46 -04:00
Wes
3a34da354f
Use append instead of set
2023-06-15 16:35:43 +00:00
m0duspwnens
469390696e
2.4 receiver changes
2023-06-15 11:04:16 -04:00
Josh Brower
0a4a48b61e
Remove old var
2023-06-15 10:24:50 -04:00
Wes
58a63e0765
Remove extra comma
2023-06-15 14:22:37 +00:00
Doug Burks
251bc6f45e
Merge pull request #10597 from Security-Onion-Solutions/dougburks-patch-1
...
Update so_motd.jinja
2023-06-15 09:59:25 -04:00
Doug Burks
b84d997f87
Update so_motd.jinja
2023-06-15 09:54:23 -04:00
Wes
b5bccc5e05
Use module in dataset name and add dataset tag
2023-06-15 13:06:57 +00:00
Jason Ertel
b4e5ac9796
Add note to advise against changing settings
2023-06-14 16:11:50 -04:00
m0duspwnens
2db95fe1b4
fw rules for receiver to managers
2023-06-14 15:24:14 -04:00
m0duspwnens
934b0f45a1
allow receiver to connect to salt manager
2023-06-14 15:08:07 -04:00
Jason Ertel
a88227d13f
Merge branch '2.4/dev' into kilo
2023-06-14 13:34:15 -04:00
Jason Ertel
21a7b76352
webauthn
2023-06-14 13:33:31 -04:00
weslambert
03082339ca
Merge pull request #10592 from Security-Onion-Solutions/fix/analyzer_dependencies
...
Update analyzer dependencies
2023-06-14 12:22:06 -04:00
m0duspwnens
8f6226b531
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/heavynode
2023-06-14 10:40:22 -04:00
m0duspwnens
2c4eccd7e0
2.4 heavynode changes
2023-06-14 10:40:05 -04:00
Josh Brower
fa57494694
Merge pull request #10584 from Security-Onion-Solutions/2.4/elasticagent-renaming
...
Change Elastic Fleet Tarball naming
2023-06-14 09:42:57 -04:00
weslambert
3f1741e75a
Merge pull request #10585 from Security-Onion-Solutions/fix/elasticsearch_templates
...
Update Elasticsearch templates for Fleet
2023-06-14 09:33:23 -04:00
Wes
48331ce35b
Add system.system component templates
2023-06-14 13:29:11 +00:00
Wes
c2ac60b82e
Add system.system template and add event-mappings
2023-06-14 13:28:00 +00:00
Josh Brower
fedfbe9fec
Fix tarball output name
2023-06-14 08:52:56 -04:00
Josh Brower
9947f9def4
Rework tarball naming schema
2023-06-14 07:38:03 -04:00
Wes
c205438771
Update dependencies
2023-06-14 02:35:29 +00:00
Wes
8cde05807c
Remove elastic-agent dir
2023-06-13 21:33:04 +00:00
Wes
2ac0aba916
Add osquery files
2023-06-13 21:32:02 +00:00
Wes
af003cc2a1
Add osquery templates
2023-06-13 20:43:39 +00:00
Josh Brower
0d4f6b4fe6
Change Elastic Fleet Tarball naming
2023-06-13 16:32:19 -04:00
Jason Ertel
7093254439
Merge pull request #10582 from Security-Onion-Solutions/jertel/pcap
...
ensure status line shows dates for new and existing imports
2023-06-13 15:16:43 -04:00
Wes
bd7644a557
Add another template
2023-06-13 19:13:20 +00:00
Jason Ertel
90b740a997
ensure status line shows dates for new and existing imports
2023-06-13 15:11:13 -04:00
Wes
5547a1b7ab
Add event mappings
2023-06-13 18:23:50 +00:00
Wes
1b90fd8581
Add custom component templates
2023-06-13 18:21:45 +00:00
Doug Burks
bbdf7bb5a7
Merge pull request #10580 from Security-Onion-Solutions/dougburks-patch-1
...
Set START and END variables earlier in so-import-pcap
2023-06-13 13:31:16 -04:00
Doug Burks
fb8ad71b27
Set START and END variables earlier in so-import-pcap
2023-06-13 13:19:18 -04:00
Wes
e43b7607bb
Add more component templates
2023-06-13 17:04:03 +00:00
Wes
a265c06e31
Add other component templates
2023-06-13 15:47:25 +00:00
Wes
2aa954cb0a
Add component templates
2023-06-13 15:25:23 +00:00
Wes
73812b11a3
Allow ingest node pipelines that start with a period
2023-06-13 13:37:56 +00:00
Wes
38ab426470
Add final Fleet pipeline
2023-06-13 13:36:26 +00:00
Wes
d0a6881c2c
Add event mappings and remove meta information for now
2023-06-13 13:35:46 +00:00
m0duspwnens
c7c4e65df1
single-node for heavynode
2023-06-13 09:22:17 -04:00
m0duspwnens
49b150797d
2.4 heavynode changes
2023-06-12 16:25:51 -04:00
Wes
57268ba934
Change priority of templates
2023-06-12 14:29:45 +00:00
Wes
1208915896
Remove Elastic Agent package templates
2023-06-12 14:24:59 +00:00
Wes
42f5ad9939
Add templates for system.auth and systen.syslog
2023-06-12 14:23:24 +00:00
Doug Burks
8e0d895afb
Merge pull request #10572 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Add more Zeek logs to excluded list #10569
2023-06-12 09:33:13 -04:00
Doug Burks
998c85e3f8
Update defaults.yaml
2023-06-12 09:31:19 -04:00
weslambert
32f3ee0b01
Merge pull request #10564 from Security-Onion-Solutions/fix/elasticsearch_templates
...
Update templates for integrations
2023-06-12 09:05:31 -04:00
Doug Burks
a90aed25fb
Merge pull request #10570 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Add Zeek ocsp.log to excluded list #10569
2023-06-12 08:46:49 -04:00
Doug Burks
ae14e4870d
Add ocsp to logging.zeek.exclued in defaults.yaml
2023-06-12 08:44:46 -04:00
Doug Burks
273a1d7e9c
Merge pull request #10568 from Security-Onion-Solutions/2.4/fix-suricata-dhcp
...
FIX: Suricata DHCP logs not ingesting #10565
2023-06-12 07:50:44 -04:00
Doug Burks
b3f8ed7dcd
FIX: Suricata DHCP logs not ingesting #10565
2023-06-10 11:42:41 -04:00
Wes
ad5a424c03
Update templates for integrations
2023-06-09 18:32:50 +00:00
Jason Ertel
e06787445c
Merge pull request #10561 from Security-Onion-Solutions/jertel/pcap
...
Node description config setting should not accept a grid-wide value
2023-06-09 12:02:51 -04:00
Jason Ertel
8a4f5d6dcb
Merge branch '2.4/dev' into jertel/pcap
2023-06-09 11:51:37 -04:00
Doug Burks
81dd951064
Merge pull request #10560 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Setup re-runs when SSH'ing into a successfully installed minion …
2023-06-09 11:49:54 -04:00
Doug Burks
c12f138899
FIX: Setup re-runs when SSH'ing into a successfully installed minion node #10498
2023-06-09 11:20:54 -04:00
Jason Ertel
884a7041af
Merge branch '2.4/dev' into jertel/pcap
2023-06-09 10:47:26 -04:00
Jason Ertel
023008c54c
do not allow node_description to be set at global grid-wide level
2023-06-09 10:46:56 -04:00
Jason Ertel
6f7de954d9
Merge pull request #10559 from Security-Onion-Solutions/jertel/pcap
...
Telegraf should monitor all mount points
2023-06-09 09:18:54 -04:00
Jason Ertel
46371aaaf5
Monitor all mount points for simplicity
2023-06-09 09:14:36 -04:00
Doug Burks
1fde2e2755
Merge pull request #10553 from Security-Onion-Solutions/2.4/update-readme
...
2.4/update readme
2023-06-08 13:44:39 -04:00
Doug Burks
1aad9d1b2f
Update README.md
2023-06-08 13:41:08 -04:00
Doug Burks
9703e70163
Update README.md
2023-06-08 13:38:11 -04:00
Doug Burks
f6735207d7
Merge pull request #10552 from Security-Onion-Solutions/2.4/fix-suricata-dataset
...
FIX: Suricata dataset values for certain types of metadata#10551
2023-06-08 13:33:53 -04:00
Doug Burks
e5f76a9c6e
change suricata parsers from dataset to event.dataset
2023-06-08 12:31:31 -04:00
weslambert
d1c86cb9ff
Merge pull request #10550 from Security-Onion-Solutions/kilo
...
Elastalert and EQL
2023-06-08 11:21:18 -04:00
weslambert
8ccb24dda2
Update version to 2.4.3
2023-06-08 11:05:05 -04:00
weslambert
932054e9da
Update version to 2.4.0
2023-06-08 11:04:45 -04:00
Josh Brower
8b35002169
EQL Refactor
2023-06-07 13:44:37 -04:00
weslambert
f68527d366
Merge pull request #10541 from Security-Onion-Solutions/fix/curator_action_ignore_empty_list
...
Use ignore_empty_list
2023-06-07 10:36:38 -04:00
Wes
81e3d26540
Ignore empty list
2023-06-07 13:14:52 +00:00
weslambert
96b60fa39a
Restore original URL syntax, but use data stream
2023-06-06 20:53:05 -04:00
weslambert
f172a74fbc
Remove EQL setting
2023-06-06 20:51:29 -04:00
weslambert
c4be56ec7b
Update host syntax
2023-06-06 20:51:03 -04:00
weslambert
96195806ab
Update version to 2.4.0-kilo
2023-06-06 20:50:10 -04:00
weslambert
88bbd3440d
Merge pull request #10522 from Security-Onion-Solutions/fix/playbook_index
...
Change Playbook index to a data stream and update mapping for event.severity_label
2023-06-06 09:03:49 -04:00
Wes
495a9c0783
Add mapping for event.severity_label
2023-06-05 21:19:37 +00:00
Wes
905bc564fc
Change data stream name
2023-06-05 21:18:47 +00:00
Wes
f6f387428f
Update Playbook alerter to write to a data stream
2023-06-05 21:17:10 +00:00
Jason Ertel
db5abcb3cf
Merge pull request #10503 from Security-Onion-Solutions/jertel/pcap
...
add ability to output PCAP import results in JSON format
2023-06-05 14:32:32 -04:00
Jason Ertel
27e310c2a1
add json output option to so-import-evtx; clean up other issues
2023-06-05 13:54:44 -04:00
weslambert
236eb0cbcc
Merge pull request #10515 from Security-Onion-Solutions/fix/analyzers
...
Update requests and whoisit
2023-06-05 12:12:59 -04:00
Wes
841d0b4b1f
Update dependencies after git add
2023-06-05 15:42:55 +00:00
Wes
272f97e2d7
Update dependencies
2023-06-05 15:42:38 +00:00
Wes
eac9a3fc86
Update requests and whoisit
2023-06-05 15:41:01 +00:00
Doug Burks
32dc26f2e7
Merge pull request #10514 from Security-Onion-Solutions/2.4/fix-VERIFY_ISO
...
Rename VERIFY_ISO.md to DOWNLOAD_AND_VERIFY_ISO.md
2023-06-05 10:12:43 -04:00
Doug Burks
1b14142e4c
Rename VERIFY_ISO.md to DOWNLOAD_AND_VERIFY_ISO.md
2023-06-05 10:08:20 -04:00
Jason Ertel
2fef1d5fa7
silence grep output
2023-06-02 15:43:48 -04:00
Jason Ertel
3bbfc3865d
use proper URL spacing
2023-06-02 15:26:14 -04:00
Jason Ertel
6947fd6414
add ability to output PCAP import results in JSON format
2023-06-02 15:21:41 -04:00
Doug Burks
d3e5be78fd
Merge pull request #10500 from Security-Onion-Solutions/dougburks-patch-1
...
Update soc_zeek.yaml
2023-06-02 07:54:11 -04:00
Doug Burks
09e005127e
Update soc_zeek.yaml
2023-06-02 07:41:55 -04:00
Mike Reeves
d3ea596deb
Merge pull request #10491 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-06-01 09:44:13 -04:00
Mike Reeves
d6d315e8d5
Update VERSION
2023-06-01 09:43:32 -04:00
Jason Ertel
162a32fd08
Merge branch '2.4/dev' into kilo
2023-05-30 11:51:57 -04:00
Jason Ertel
f765dc23ea
kilofy version
2023-05-26 09:54:50 -04:00