Mike Reeves
84c5fa6a58
Merge pull request #12353 from Security-Onion-Solutions/2.4/dev
...
2.4.50
2024-02-20 10:04:01 -05:00
Mike Reeves
5c96e30087
Merge pull request #12383 from Security-Onion-Solutions/2.4.50
...
2.4.50
2024-02-20 09:50:09 -05:00
Mike Reeves
18b4fcca75
2.4.50
2024-02-20 09:47:05 -05:00
Josh Patterson
0765320839
Merge pull request #12360 from Security-Onion-Solutions/2450soup
...
`2450soup
2024-02-14 14:37:28 -05:00
m0duspwnens
a2b17d2348
move jinja to top
2024-02-14 14:27:41 -05:00
m0duspwnens
c1f467a068
handle airgap
2024-02-14 14:22:18 -05:00
m0duspwnens
7d5932ee5e
Merge remote-tracking branch 'origin/2.4/dev' into 2450soup
2024-02-14 13:29:39 -05:00
m0duspwnens
79e98e508f
pass in UPDATE_DIR as a pillar
2024-02-14 13:28:12 -05:00
Josh Patterson
cf6266a92b
Merge pull request #12354 from Security-Onion-Solutions/2450soup
...
modify soup to update soup scripts using salt
2024-02-13 16:23:57 -05:00
m0duspwnens
2e9fa2438b
add back comment
2024-02-13 16:19:50 -05:00
m0duspwnens
00f2374582
fix path for so-firewall
2024-02-13 15:43:02 -05:00
m0duspwnens
468eedfaeb
add soup script update retru
2024-02-13 15:30:24 -05:00
m0duspwnens
88786e8342
use file.copy to preserve perms
2024-02-13 15:05:09 -05:00
m0duspwnens
141fd49f02
use rsync
2024-02-13 14:27:22 -05:00
m0duspwnens
7112337c85
fix copy
2024-02-13 13:52:14 -05:00
m0duspwnens
d6ac7a3286
fix the jinja
2024-02-13 13:31:34 -05:00
m0duspwnens
9175a73456
dont need $ for vars
2024-02-13 13:08:09 -05:00
Doug Burks
14209ad99d
Merge pull request #12355 from Security-Onion-Solutions/dougburks-patch-1
...
Add table columns to process dashboard in defaults.yaml
2024-02-13 12:59:34 -05:00
m0duspwnens
1bde002f20
update case
2024-02-13 12:51:53 -05:00
Doug Burks
0741ae370a
Update defaults.yaml
2024-02-13 12:51:26 -05:00
m0duspwnens
d7f853b5b2
comment out script copy in soup
2024-02-13 12:50:22 -05:00
m0duspwnens
5c9b1ab38b
copy with cp
2024-02-13 12:48:31 -05:00
m0duspwnens
b713771494
add back common soup_scripts state
2024-02-13 12:30:36 -05:00
Doug Burks
8060751a66
Add table columns to process dashboard in defaults.yaml
2024-02-13 12:24:33 -05:00
m0duspwnens
c1258f9a92
Merge remote-tracking branch 'origin/2.4/dev' into 2450soup
2024-02-13 11:09:24 -05:00
m0duspwnens
92634724c4
move rm
2024-02-13 11:09:08 -05:00
m0duspwnens
3efaba1104
modify soup to update soup scripts without using salt
2024-02-13 11:04:26 -05:00
Doug Burks
d072d431b3
Merge pull request #12350 from Security-Onion-Solutions/feature/process-ancestry-action
...
FEATURE: Add new SOC action to show process ancestry #12345
2024-02-13 08:51:38 -05:00
Doug Burks
0ad39a7e32
FEATURE: Add new SOC action to show process ancestry #12345
2024-02-12 19:18:29 -05:00
Doug Burks
20d2f3b97e
Update Sublime action in defaults.yaml to use i18n
2024-02-12 19:13:32 -05:00
Josh Brower
64726a2785
Merge pull request #12349 from Security-Onion-Solutions/2.4/conflictingfix
...
Fix conflicting id
2024-02-12 19:07:07 -05:00
Josh Brower
ccb14485a3
Fix conflicting id
2024-02-12 19:06:19 -05:00
Mike Reeves
e713b4c660
Merge pull request #12346 from Security-Onion-Solutions/reyesj2-patch-1
...
Remove unused file
2024-02-12 16:07:31 -05:00
Mike Reeves
2db5f4dd41
Merge pull request #12308 from petiepooo/feat-es-ownfs
...
FEATURE: Check for mountpoint during Elastic size limit calculations
2024-02-12 16:03:36 -05:00
Mike Reeves
f91cb5b81f
Merge pull request #12290 from petiepooo/fix-remove-intca-symlink
...
fix: also remove intca symlink
2024-02-12 12:33:13 -05:00
Jorge Reyes
4b697b2406
Remove unused file
2024-02-12 09:28:48 -05:00
Josh Brower
c04f5a3f0f
Merge pull request #12268 from Security-Onion-Solutions/feature/fleet-artifacts
...
Feature/fleet artifacts
2024-02-12 08:58:14 -05:00
Josh Brower
b1de6abc17
Merge pull request #12343 from Security-Onion-Solutions/fix/anothercheck
...
Wait for ES to be ready
2024-02-12 08:58:05 -05:00
Josh Brower
cc0f25a4f7
Wait for ES to be ready
2024-02-11 13:30:20 -05:00
Josh Brower
eafb5cf15e
Change to file_root
2024-02-11 13:18:20 -05:00
Jorge Reyes
2b2aa30ac1
Merge pull request #12332 from Security-Onion-Solutions/reyesj2/sod-putty
...
Add putty to SOD
2024-02-10 20:41:03 -05:00
Josh Brower
66ac36a944
Update soup
2024-02-10 11:07:26 -05:00
Josh Brower
feabb7c51f
Merge remote-tracking branch 'origin/2.4/dev' into feature/fleet-artifacts
2024-02-10 10:57:46 -05:00
Josh Patterson
94b6e781bb
Merge pull request #12337 from Security-Onion-Solutions/salt3006.6v2
...
Salt3006.6v2
2024-02-09 15:45:39 -05:00
m0duspwnens
304ae49251
fix source
2024-02-09 12:41:23 -05:00
m0duspwnens
213ac822a8
create dir and chown
2024-02-09 10:54:07 -05:00
m0duspwnens
2143881c0b
specify *.rules
2024-02-09 10:22:25 -05:00
m0duspwnens
5903ae596c
move suricata rules to /opt/so/rules/nids/suri
2024-02-09 09:47:23 -05:00
Josh Brower
0c423c9329
Merge pull request #12333 from Security-Onion-Solutions/fix/shell
...
Fixup shell
2024-02-09 09:31:47 -05:00
Josh Brower
654602bf80
Fixup shell
2024-02-09 09:30:18 -05:00
reyesj2
3c9d6da1d8
add putty to sod packages.sls
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-02-08 22:05:37 -05:00
Josh Brower
683abf0179
Rework naming
2024-02-08 13:24:25 -05:00
Josh Brower
8d0e8789bd
Use salt file roots
2024-02-08 09:54:51 -05:00
Josh Brower
503a09f150
Merge remote-tracking branch 'origin/2.4/dev' into feature/fleet-artifacts
2024-02-08 09:45:21 -05:00
Josh Patterson
f02f61c6dd
Merge pull request #12325 from Security-Onion-Solutions/salt3006.6
...
Salt3006.6
2024-02-07 16:33:56 -05:00
Doug Burks
8c5dafa058
Merge pull request #12324 from Security-Onion-Solutions/feature/dashboards-communityid-firewall
...
FEATURE: Add new dashboards for community_id and firewall auth #12323
2024-02-07 16:15:21 -05:00
Doug Burks
d3d2305f00
FEATURE: Add new dashboards for community_id and firewall auth #12323
2024-02-07 16:08:27 -05:00
m0duspwnens
6534f392a9
update backup filename
2024-02-07 14:25:28 -05:00
m0duspwnens
478fb6261e
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.6
2024-02-07 14:15:11 -05:00
m0duspwnens
e42e07b245
update salt mine after salt-master restarts
2024-02-07 13:05:45 -05:00
m0duspwnens
f97d0f2f36
add /opt/so/rules/ to files_roots
2024-02-07 09:25:56 -05:00
m0duspwnens
24fd3ef8cc
uopdate error message
2024-02-06 16:22:13 -05:00
m0duspwnens
b3f6153667
update so-yaml tests
2024-02-06 16:15:54 -05:00
Doug Burks
d800d59304
Merge pull request #12316 from Security-Onion-Solutions/feature/improve-soc-actions
...
FEATURE: Improve Correlate and Hunt actions on SOC Actions menu #12315
2024-02-06 15:46:31 -05:00
Doug Burks
7106095128
FEATURE: Improve Correlate and Hunt actions on SOC Actions menu #12315
2024-02-06 15:39:23 -05:00
m0duspwnens
9d62ade32e
update so-yaml tests
2024-02-06 11:14:27 -05:00
m0duspwnens
2643ae08a7
add append to list
2024-02-05 17:54:30 -05:00
Pete
cf83d1cb86
feat: use mountpoint for Elastic log limit
...
Instead of just existence, this checks if the directories are separate mountpoints when determining disk size and log_size_limit calculations.
It also sets the percentage to 80 if /nsm/elasticsearch is a separate mountpoint. This allows for better disk utilization on server configurations where /nsm is based on large slow HDDs for increased PCAP retention but /nsm/elasticsearch is based on SSDs for faster Elasticsearch performance.
2024-02-02 12:25:16 -05:00
Pete
7a29b3a529
call salt before stopping salt services
...
salt-call does not work when the salt-master is not running. If these calls are to succeed, they should occur before the salt services are stopped.
2024-02-02 08:45:01 -05:00
m0duspwnens
61ee41e431
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.6
2024-02-01 11:07:06 -05:00
m0duspwnens
0d5db58c86
upgrade salt3006.6
2024-02-01 10:32:41 -05:00
Josh Brower
3d478b92b2
Merge pull request #12294 from Security-Onion-Solutions/jppffa
...
Jppffa
2024-02-01 09:47:18 -05:00
Josh Brower
e090518b59
Refactor script
2024-02-01 09:46:53 -05:00
weslambert
91c1e595ef
Merge pull request #12297 from Security-Onion-Solutions/feature/pipeline_config_ui
...
Manage custom Elasticsearch and Logstash pipelines in UI
2024-02-01 09:18:30 -05:00
Wes
1818e134ca
Change numbers for Logstash
2024-02-01 14:01:55 +00:00
Wes
182667bafb
Change numbers for Elasticsearch
2024-02-01 13:59:23 +00:00
Wes
136097f981
Custom Logstash pipeline annotations
2024-01-31 21:47:09 +00:00
Wes
bc502cc065
Custom Elasticserach pipeline annotations
2024-01-31 21:46:33 +00:00
m0duspwnens
ae32ac40c2
add fleet node nginx to docker annotations
2024-01-31 16:28:45 -05:00
m0duspwnens
2f03248612
use different nginx defaults for so-fleet node hosting artifacts
2024-01-31 16:25:09 -05:00
Mike Reeves
a094d1007b
Merge pull request #12293 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
fix salt lock for airgap version mismatches
2024-01-31 16:21:16 -05:00
Mike Reeves
341ff5b564
Update so-functions
2024-01-31 16:18:51 -05:00
Josh Brower
0fe96bfc2d
switch to symlink
2024-01-31 16:17:40 -05:00
Wes
4672a5b8eb
Custom pipeline configuration in UI
2024-01-31 20:18:17 +00:00
Wes
1853dc398b
Custom pipeline configuration
2024-01-31 20:17:33 +00:00
Wes
bc75be9402
Custom pipelines in UI
2024-01-31 20:16:48 +00:00
Wes
cd4bd6460a
Custom pipelines
2024-01-31 20:16:18 +00:00
Pete
1192dbd530
also remove intca symlink
...
The symlink is created in init.sls; it should be removed here.
2024-01-31 09:01:56 -05:00
Jorge Reyes
4dd0b4a4fd
Merge pull request #12283 from Security-Onion-Solutions/reyesj2-patch-6
...
Remove remediate from initial oscap scan
2024-01-30 15:56:13 -05:00
reyesj2
b5ffa186fb
Remove remediate from initial oscap scan
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-30 15:54:23 -05:00
Josh Brower
0d08bb0a91
Finalize script
2024-01-29 11:37:28 -05:00
Jorge Reyes
cb5e111a00
Merge pull request #12267 from Security-Onion-Solutions/reyesj2-patch-6
...
Update soup
2024-01-29 10:22:35 -05:00
reyesj2
7c08b348aa
Add comment for soup update w/ STIGs enabled
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-29 10:16:34 -05:00
Josh Brower
afa98fa147
update artifacts URL automatically
2024-01-28 14:20:52 -05:00
Josh Brower
1847e5c3c0
Enable nginx on Fleet Node
2024-01-28 11:37:18 -05:00
Josh Brower
cfc33b1a34
Sync Elastic Agent Artifacts
2024-01-28 10:12:25 -05:00
weslambert
dc5ea89255
Merge pull request #12260 from Security-Onion-Solutions/fix/endpoint_diagnostic
...
Add template for endpoint.diagnostic.collection
2024-01-26 16:13:30 -05:00
reyesj2
c4301d7cc1
Soup script update locations
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:51:06 -05:00
reyesj2
91c7b8144d
soup logic
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:43:42 -05:00
reyesj2
2e026b637d
Update soup to retry modified salt command on failure to update soup scripts.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 11:36:33 -05:00
reyesj2
cd6e387bcb
remove --local from soup common.soup_scripts update.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-25 16:15:53 -05:00
Wes
12ab6338db
Add diagnostic
2024-01-25 20:16:52 +00:00
weslambert
cd54d4becb
Fix indent
2024-01-25 13:57:02 -05:00
weslambert
5f1c76f6ec
endpoint.diagnostic.collection
2024-01-25 09:46:25 -05:00
weslambert
d2d70d1c5b
Merge pull request #12250 from Security-Onion-Solutions/fix/scan_pe_flags
...
Fix PE Flags
2024-01-24 14:29:23 -05:00
Jason Ertel
e53030feef
Merge pull request #12248 from Security-Onion-Solutions/jertel/pfeat
...
standardize feature names
2024-01-24 12:12:16 -05:00
Jason Ertel
9f17bd2255
lks/fps
2024-01-24 11:17:32 -05:00
Wes
8426aad56d
Text mapping for scan.pe.flags
2024-01-24 15:10:42 +00:00
Wes
d23d367058
Make scan.pe.flags a string
2024-01-24 15:08:38 +00:00
weslambert
cbdaf2e9a1
Merge pull request #12242 from Security-Onion-Solutions/upgrade/strelka_0.24.01.18
...
Fix quote
2024-01-23 14:02:35 -05:00
weslambert
4d7af21dd5
Fix quote
2024-01-23 13:55:37 -05:00
weslambert
8348506acc
Merge pull request #12240 from Security-Onion-Solutions/upgrade/strelka_0.24.01.18
...
UPGRADE: Strelka 0.24.01.18
2024-01-23 13:50:15 -05:00
weslambert
1698d95efe
Use PLACEHOLDER for key values
2024-01-23 13:45:26 -05:00
weslambert
b1052ddcce
Merge pull request #12241 from Security-Onion-Solutions/fix/leak_test
...
Exclude specific Strelka key values
2024-01-23 13:43:18 -05:00
weslambert
0cb36bb0aa
Exclude StrelkaHexDump and PLACEHOLDER values
2024-01-23 13:39:59 -05:00
weslambert
0ccdfcb07c
Exclude only offset_meta_key
2024-01-23 13:11:43 -05:00
weslambert
63ba97306c
Exclude Strelka defaults
2024-01-23 13:05:58 -05:00
weslambert
72319e33db
Avoid leak test triggering
2024-01-23 12:38:09 -05:00
weslambert
34bb37e415
Merge pull request #12227 from Security-Onion-Solutions/feature/rita_logs
...
RITA Logs
2024-01-23 12:32:32 -05:00
Wes
3bcb0bc132
Update defaults
2024-01-23 17:18:54 +00:00
Jorge Reyes
d25a2d4c30
Merge pull request #12230 from Security-Onion-Solutions/reyesj2-patch-sl
...
Handle non-zero
2024-01-23 08:31:48 -05:00
reyesj2
350b0df3bf
Handle non-zero
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-22 22:48:15 -05:00
Wes
5542db0aac
Leave package version null
2024-01-22 21:07:46 +00:00
Wes
b08db3e05a
Add RITA policy
2024-01-22 20:16:43 +00:00
Wes
80a3942245
Rename RITA pipelines
2024-01-22 20:15:48 +00:00
weslambert
de6151fbe2
Merge pull request #12221 from Security-Onion-Solutions/feature/additional_integrations_4
...
Additional integrations #4 - Part 1
2024-01-19 17:32:37 -05:00
Wes
7118cc8dee
Add additional integration SOC configuration
2024-01-19 22:04:07 +00:00
Wes
05aa8b013a
Add additional integration to templates
2024-01-19 22:02:39 +00:00
Wes
d0457cb61e
Add additional integrations to defaults
2024-01-19 22:00:38 +00:00
Jorge Reyes
c2b44985c7
Merge pull request #12220 from Security-Onion-Solutions/reyesj2-patch-sl
...
Disable stigs setting/verifying umask is set to 077. Known issue with …
2024-01-19 16:06:10 -05:00
reyesj2
8f8c250ed3
Disable stigs setting/verifing umask is set to 077. Known issue with running SOUP
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 16:04:21 -05:00
Mike Reeves
6db32885eb
Merge pull request #12216 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update suricata.common
2024-01-19 13:56:48 -05:00
Mike Reeves
efe8cfda95
Update suricata.common
2024-01-19 13:39:28 -05:00
Mike Reeves
08486e279c
Update suricata.common
2024-01-19 13:36:43 -05:00
Jorge Reyes
40d0411441
Merge pull request #12214 from Security-Onion-Solutions/reyesj2-patch-sl
...
Add stig pillar dir during soup
2024-01-19 10:55:13 -05:00
reyesj2
2b6927da82
Add stig pillar dir during soup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 09:55:23 -05:00
Jorge Reyes
0786806f8f
Merge pull request #12213 from Security-Onion-Solutions/reyesj2-patch-sl
...
Update soup
2024-01-19 08:59:34 -05:00
reyesj2
ca4f2f1dd6
Add creation of additional pillars to soup for stig state
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 08:31:20 -05:00
Jorge Reyes
97e2721754
Merge pull request #12208 from Security-Onion-Solutions/reyesj2-patch-sl
2024-01-18 16:53:14 -05:00
reyesj2
07602076f1
Update telegraf script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 16:48:16 -05:00
reyesj2
caf4036dbf
Update features check
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 16:06:53 -05:00
Jorge Reyes
4a898619a6
Merge pull request #12206 from Security-Onion-Solutions/reyesj2-patch-sl
...
Remove need for stig script
2024-01-18 12:49:28 -05:00
reyesj2
65d46ea27d
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2-patch-sl
2024-01-18 12:24:35 -05:00
reyesj2
67445de4ee
Remove need for stig script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 12:24:01 -05:00
Jorge Reyes
6a8bf0b953
Merge pull request #12202 from Security-Onion-Solutions/reyesj2-patch-sl
...
Add stig state
2024-01-18 09:25:21 -05:00
weslambert
33d74098bd
Merge pull request #12201 from Security-Onion-Solutions/fix/suricata_ike
...
Add Suricata IKE pipeline
2024-01-17 16:50:19 -05:00
reyesj2
3173f9a26f
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2-patch-sl
2024-01-17 16:28:13 -05:00
reyesj2
df921892a3
Remove post scan from remediate log.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 16:23:20 -05:00
reyesj2
739feb25a4
Add telegraf script to import featuresdetected
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 15:55:00 -05:00
reyesj2
4e6924610d
Add additional status checks to so-common-status-check for telegraf
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 15:37:52 -05:00
Mike Reeves
880f2a3e1b
Merge pull request #12197 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-01-17 14:19:30 -05:00
Mike Reeves
958c827fd5
Update VERSION
2024-01-17 14:18:37 -05:00
Mike Reeves
aa294a7f41
Merge pull request #12195 from Security-Onion-Solutions/2.4/dev
...
2.4.40
2024-01-17 14:04:27 -05:00
Mike Reeves
049d0b53c2
Merge pull request #12194 from Security-Onion-Solutions/2.4.40
...
2.4.40
2024-01-17 12:02:14 -05:00
Mike Reeves
dff6d299a1
2.4.40
2024-01-17 11:59:27 -05:00
Wes
e70ce50912
Change description
2024-01-17 14:06:16 +00:00
Jason Ertel
38965ccab5
Merge pull request #12192 from Security-Onion-Solutions/needsrestarted
...
Needsrestarted
2024-01-16 18:49:22 -05:00
m0duspwnens
eeb249e00d
look for needs_restarted file
2024-01-16 17:22:09 -05:00
m0duspwnens
dff06cb085
changes for telegraf os.sh
2024-01-16 17:03:36 -05:00
m0duspwnens
8c1d1c95db
check needs_restarting rework
2024-01-16 17:02:27 -05:00
Wes
f6590ac0bf
Remove Suricata IKEv2 pipeline
2024-01-16 18:10:00 +00:00
Wes
ea64ce92d3
Add Suricata IKE pipeline
2024-01-16 18:09:46 +00:00
Wes
8a92b023b2
Add interface name
2024-01-16 18:09:16 +00:00
reyesj2
6cf0b365e6
Modify yum.conf.jinja to include localpkg_gpgcheck rather than modifying it with so-stig
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-15 21:30:31 -05:00
reyesj2
4bffd8e27c
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2-patch-sl
2024-01-15 21:19:37 -05:00
reyesj2
a73d78300a
Add initial stig state
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-15 21:17:17 -05:00
weslambert
790f5171a6
Merge pull request #12176 from Security-Onion-Solutions/fix/otx_pulses_template
...
FIX: OTX pulses template
2024-01-12 16:55:58 -05:00
weslambert
252c51dafb
Change order of names
2024-01-12 16:45:18 -05:00
weslambert
a07e6e1058
OTX pulses
2024-01-12 16:43:33 -05:00
weslambert
3f9678056d
OTX pulses template
2024-01-12 16:42:32 -05:00
weslambert
c895b6a274
Merge pull request #12173 from Security-Onion-Solutions/fix/endpoint_metrics_templates
...
Add endpoint metrics templates
2024-01-12 11:26:09 -05:00
Wes
418f41c7e4
Add SOC configuration for metrics
2024-01-12 15:03:18 +00:00
weslambert
05679e79fc
Merge pull request #12171 from Security-Onion-Solutions/2.4/dev
...
Merge 2.4 dev
2024-01-12 08:50:15 -05:00
Josh Brower
af3aa53612
Merge pull request #12170 from Security-Onion-Solutions/fix/nav
...
Remove old nav layers
2024-01-12 08:48:29 -05:00
Wes
5eae349938
Add endpoint metrics templates
2024-01-12 13:47:35 +00:00
Josh Brower
2f8ce33cf7
formatting
2024-01-12 08:47:09 -05:00
Josh Brower
61b2a76a09
Remove old nav layers-rev2
2024-01-12 08:46:23 -05:00
Josh Brower
b89b7cab59
Remove old nav layers
2024-01-12 08:37:32 -05:00
weslambert
71c5e34e03
Merge pull request #12164 from Security-Onion-Solutions/fix/optional_integration_pillar_merge
...
Make sure optional integration pillar values are merged with defaults
2024-01-11 16:14:46 -05:00
weslambert
880300d644
Move ELASTICFLEETMERGED import under allowed states
2024-01-11 14:58:21 -05:00
weslambert
f5b59cacec
Move ELASTICFLEETMERGED import
2024-01-11 14:56:01 -05:00
weslambert
ea5097f1b4
Add back curly brace
2024-01-11 14:51:01 -05:00
weslambert
cc66daba1a
Make sure optional integration pillar values are merged with defaults
2024-01-11 14:49:39 -05:00
Josh Brower
ea54aafa86
Merge pull request #12161 from Security-Onion-Solutions/fix/kibana-restart
...
Check Kibana API not Web
2024-01-11 12:32:19 -05:00
Josh Brower
03f140161c
Check Kibana API not Web
2024-01-11 12:30:23 -05:00
weslambert
7bdc306ad4
Merge pull request #12160 from Security-Onion-Solutions/feature/additional_integrations_3
...
Additional Supported Integrations #3
2024-01-11 12:26:14 -05:00
weslambert
5e1e685ce0
Exclude Cisco failed_attempts pipeline
2024-01-11 10:52:30 -05:00
Wes
c89d674a92
Add settings for integrations
2024-01-11 14:18:06 +00:00
Wes
9b1ddcacb4
Add additional templates for integrations
2024-01-11 14:00:09 +00:00
Wes
5703023008
Add additional packages
2024-01-11 13:59:38 +00:00
Josh Brower
59fe9a0587
Merge pull request #12156 from Security-Onion-Solutions/fix/navigator
...
Upgrade Navigator and fix Playbook layer
2024-01-11 08:48:34 -05:00
Josh Brower
b8e555e913
Upgrade Navigator and fix Playbook layer
2024-01-10 21:16:59 -05:00
Mike Reeves
16b15c786b
Merge pull request #12155 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2024-01-10 14:44:51 -05:00
Mike Reeves
3e13ea5c7a
Update soup
2024-01-10 14:36:49 -05:00
Josh Brower
9159eab9fd
Merge pull request #12151 from Security-Onion-Solutions/fix/so-playbook-reset
...
Fix reinstall & reset stability
2024-01-10 14:23:53 -05:00
Mike Reeves
0519812866
Merge pull request #12154 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-functions
2024-01-10 14:21:49 -05:00
Mike Reeves
fc2f02c0a0
Update so-functions
2024-01-10 14:19:47 -05:00
Mike Reeves
1e3a00a833
Update so-functions
2024-01-10 14:16:55 -05:00
Josh Brower
f21f0a9a96
Replace sed for so-yaml
2024-01-10 11:15:51 -05:00
Josh Brower
6ff764e6a1
refactor for reinstall stability
2024-01-10 10:22:50 -05:00
Jason Ertel
f5568995ac
Merge pull request #12149 from Security-Onion-Solutions/jertel/logs
...
exempt transient license check errors
2024-01-10 09:12:46 -05:00
Jason Ertel
47eea80d03
exempt transient license check errors
2024-01-10 09:07:17 -05:00
Josh Patterson
0b919ff0fa
Merge pull request #12144 from Security-Onion-Solutions/salt3006.5
...
Salt3006.5
2024-01-09 12:09:36 -05:00
m0duspwnens
c9f2038990
remove outdated comment
2024-01-09 11:36:44 -05:00
Josh Brower
bf05efa59f
Merge pull request #12141 from Security-Onion-Solutions/fix/fleet-reset
...
Fix/fleet reset
2024-01-09 10:38:07 -05:00
Josh Brower
b058bc8c05
Move to non-destructive
2024-01-09 10:22:43 -05:00
Josh Brower
7ddda03ee9
Merge pull request #12138 from Security-Onion-Solutions/fix/fim
...
Fix/fim
2024-01-09 08:26:55 -05:00
Josh Brower
5513e74807
comma
2024-01-09 08:12:33 -05:00
Josh Brower
31ee365a91
Fixup FIM events
2024-01-09 08:11:05 -05:00
m0duspwnens
f46ac6b9d7
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.5
2024-01-08 14:02:02 -05:00
m0duspwnens
31f314504e
salt 3006.5
2024-01-08 14:01:40 -05:00
Mike Reeves
0d76ddd49f
Merge pull request #12120 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-raid-status for SM based appliances
2024-01-05 10:27:21 -05:00
Mike Reeves
b0447a9af5
Update so-raid-status for SM based appliances
2024-01-05 09:28:04 -05:00
Josh Patterson
ef6eafeff1
Merge pull request #12118 from Security-Onion-Solutions/startupstates
...
enable startup_states: highstate on managers during setup and not wit…
2024-01-04 17:37:27 -05:00
m0duspwnens
ccfdafea0a
enable startup_states: highstate on managers during setup and not with salt
2024-01-04 16:24:48 -05:00
Josh Patterson
93cdac592e
Merge pull request #12116 from Security-Onion-Solutions/issue/12033
...
Issue/12033
2024-01-04 09:54:29 -05:00
m0duspwnens
2eaf0e812a
declare NEW_LIST outside jinja logic
2024-01-03 16:49:28 -05:00
Jorge Reyes
cab7c9d573
Merge pull request #12109 from Security-Onion-Solutions/reyesj2-patch-1
...
Add brasero to packages list for SOD
2024-01-03 14:45:07 -05:00
Jorge Reyes
8c792a8cfa
Add brasero to packages list for SOD
2024-01-03 12:17:57 -05:00
m0duspwnens
c091a0845c
allow user to disable elastic agent sending to manager
2024-01-03 11:48:16 -05:00
Mike Reeves
cf23723c54
Merge pull request #12102 from Security-Onion-Solutions/2.4/main
...
2.4/main
2024-01-02 11:18:07 -05:00
Mike Reeves
30bc02178a
Merge pull request #12100 from Security-Onion-Solutions/mkrtemp
...
2.4.30 hotfix
2024-01-02 11:16:13 -05:00
Mike Reeves
84e8013e46
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-01-02 10:31:14 -05:00
Mike Reeves
80ec4cecec
Merge pull request #12099 from Security-Onion-Solutions/2.4.30hf5
...
2.4.30 hotfix
2024-01-02 10:29:45 -05:00
Mike Reeves
82482d309a
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-01-02 10:09:13 -05:00
Mike Reeves
d437a2856a
2.4.30 hotfix
2024-01-02 09:48:45 -05:00
Josh Patterson
f0b44ad56c
Merge pull request #12095 from Security-Onion-Solutions/startupstates
...
Change salt-minion startup_states
2024-01-02 09:18:21 -05:00
Jason Ertel
cffc3353bc
Merge pull request #12090 from Security-Onion-Solutions/jertel/lasths
...
show last highstate date/time on grid metrics screen; expose maxUploa…
2023-12-29 14:51:09 -05:00
Jason Ertel
e075d07f5c
show last highstate date/time on grid metrics screen; expose maxUploadSize and staleMetricsMs settings on config screen
2023-12-29 11:38:42 -05:00
Jason Ertel
fe8f57c43b
Merge pull request #12071 from Security-Onion-Solutions/jertel/influxerr
...
exclude transient influxdb error
2023-12-22 07:22:45 -05:00
Jason Ertel
3456de3a30
exclude transient influxdb error
2023-12-22 07:16:45 -05:00
Jason Ertel
14767dd8b5
Merge pull request #12067 from Security-Onion-Solutions/jertel/fixcurator
...
only run the file.absent state if there are files to delete
2023-12-21 09:41:46 -05:00
Jason Ertel
8189f46a03
only run the file.absent state if there are files to delete
2023-12-21 09:36:47 -05:00
weslambert
cfb5c1c9d2
Merge pull request #12063 from Security-Onion-Solutions/fix/curator_log_check
...
Ignore Curator logs
2023-12-20 17:47:17 -05:00
weslambert
244968ce23
Remove unnecessary blank lines
2023-12-20 17:30:15 -05:00
weslambert
65f89b22b2
Ignore Curator logs
2023-12-20 17:28:55 -05:00
weslambert
7684aadb87
Merge pull request #12062 from Security-Onion-Solutions/fix/curator_remove
...
Curator Remove Changes
2023-12-20 15:16:47 -05:00
Wes
188744357f
Remove post since function doesn't exist
2023-12-20 19:14:14 +00:00
Wes
4baf4657f6
Curator cleanup
2023-12-20 19:10:22 +00:00
Wes
1006710226
Change Curator disable config
2023-12-20 18:26:27 +00:00
weslambert
cd661027a6
Remove post for 2.4.40
2023-12-20 12:23:20 -05:00
m0duspwnens
28fdf15304
remove comment
2023-12-19 16:37:32 -05:00
Mike Reeves
90edf7e8f1
Merge pull request #12053 from Security-Onion-Solutions/2.4/main
...
2.4/main
2023-12-19 14:40:21 -05:00
Mike Reeves
552e4c0d1c
Merge pull request #12050 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-12-19 14:37:35 -05:00
weslambert
ba2c51bee2
Merge pull request #12052 from Security-Onion-Solutions/fix/analyzer_images
...
Fix analyzer images
2023-12-19 14:30:19 -05:00
m0duspwnens
7b9ac7ae6d
remove checkin_at_boot function
2023-12-19 14:05:19 -05:00
Wes
62708ac97d
Add new image
2023-12-19 18:58:17 +00:00
Wes
f8fdc6d14e
Remove old image
2023-12-19 18:57:54 +00:00
Mike Reeves
72fbf386eb
Merge pull request #12051 from Security-Onion-Solutions/jertel/hotfixm
...
Jertel/hotfixm
2023-12-19 13:48:21 -05:00
Wes
15773bae34
Fix analyzer image links
2023-12-19 18:42:59 +00:00
Jason Ertel
ce8a774129
Merge branch '2.4/main' into jertel/hotfixm
2023-12-19 13:42:13 -05:00
Wes
c06de33318
Test EchoTrail image
2023-12-19 18:36:55 +00:00
Wes
41dc9df7cd
Add images for analyzers
2023-12-19 18:35:10 +00:00
Mike Reeves
cb956fb399
Merge pull request #12049 from Security-Onion-Solutions/2.4.30hf4
...
2.4.30 hotfix
2023-12-19 13:10:51 -05:00
Mike Reeves
5c34cdd943
2.4.30 hotfix
2023-12-19 13:07:25 -05:00
Doug Burks
5e8613f38b
Merge pull request #12048 from Security-Onion-Solutions/2.4/improve-filterlog-parser
...
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-19 12:57:37 -05:00
weslambert
69472e70b4
Merge pull request #12003 from HoangLongVu/2.4/dev
...
2.4/dev Analyzers for Threatfox, MalwareBazaar, Echotrail, Elasticsearch
2023-12-19 12:09:16 -05:00
m0duspwnens
090f3a3e02
only run if in file
2023-12-19 12:08:17 -05:00
Wes
85242651b2
Add Sublime image to assets and change link
2023-12-19 15:49:57 +00:00
Jason Ertel
80cd9920b2
Merge pull request #12047 from Security-Onion-Solutions/jertel/eslogerror
...
exclude log false positives
2023-12-19 10:49:42 -05:00
Jason Ertel
ca21e32d83
log false positives
2023-12-19 10:47:39 -05:00
Wes
6ab12ceec4
Add Elasticsearch image to assets and change link
2023-12-19 15:46:02 +00:00
Wes
bfcf7d4668
Add EchoTrail image to assets and change link
2023-12-19 15:42:23 +00:00
Wes
4a23832267
Don't require advanced options for required values
2023-12-19 15:14:33 +00:00
m0duspwnens
b3be999aea
dont enable startup_states during setup. use salt to add it
2023-12-19 09:00:32 -05:00
Doug Burks
ab5de4c104
update soc defaults.yaml
2023-12-19 07:27:07 -05:00
Wes
614589153b
Update Malwarebazaar test and comply with flake8
2023-12-19 02:57:35 +00:00
Ryan Hoang
5e715036fb
Update malwarebazaar_test.py
2023-12-18 19:54:14 -05:00
Ryan Hoang
748a67314f
Update malwarebazaar_test.py
2023-12-18 19:27:13 -05:00
Ryan Hoang
a561f8c783
Update malwarebazaar_test.py Removed Whitespace
2023-12-18 19:18:26 -05:00
Elijah Gibson
fb5ee6b9e9
Flake8 linting + isInJson tail recursion update
2023-12-18 15:58:16 -05:00
Elijah Gibson
7d6f8d922b
Update malwarebazaar_test.py
...
Flake8 linting
2023-12-18 15:57:41 -05:00
Elijah Gibson
f86adf8053
Merge branch 'Security-Onion-Solutions:2.4/dev' into 2.4/dev
2023-12-18 15:57:00 -05:00
Wes
8f6b1a07b7
Don't use soup for removing Curator files
2023-12-18 20:54:24 +00:00
Wes
6c92672566
Remove Curator configuration and scripts
2023-12-18 20:53:56 +00:00
Wes
aba5893965
Add disabled state for Curator
2023-12-18 20:50:49 +00:00
Josh Patterson
866c9988a0
Merge pull request #12037 from Security-Onion-Solutions/fix/receiver
...
Fix receivers
https://github.com/Security-Onion-Solutions/securityonion/issues/12038
2023-12-18 13:56:33 -05:00
Josh Patterson
f032ff40a2
Merge branch '2.4/dev' into fix/receiver
2023-12-18 13:55:23 -05:00
Semphorin
03421c1bcd
added isInJson tests
2023-12-18 13:54:38 -05:00
Doug Burks
4d8661d2e0
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-18 13:38:04 -05:00
Doug Burks
6a1073b616
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-18 12:57:40 -05:00
Wes
6a4e05d60f
Remove control characters
2023-12-15 20:53:51 +00:00
Wes
981f3642a0
Update tests
2023-12-15 20:53:19 +00:00
m0duspwnens
33a9ac5701
use logstash nodes for logstash extra_hosts
2023-12-15 15:42:49 -05:00
Wes
020472085b
ThreatFox test
2023-12-15 15:16:44 +00:00
Wes
8aaeee20b9
Fix import
2023-12-15 14:40:25 +00:00
Wes
e32de6893b
Remove control characters
2023-12-15 14:27:27 +00:00
Wes
f05eb742dd
Fix patch
2023-12-15 14:26:33 +00:00
Wes
cd3a661dd6
Set malwarebazaar.py to be executable
2023-12-15 14:17:33 +00:00
weslambert
55c957170d
Reduce complexity
2023-12-15 09:00:31 -05:00
Jackson
d41daa37f1
malwarebazaar
2023-12-15 03:00:43 -05:00
Jackson
b59896bb47
ThreatFox and EchoTrail
2023-12-15 02:47:54 -05:00
Jackson
c59a6516fc
fix Elasticsearch lint
2023-12-15 02:34:45 -05:00
Doug Burks
88684a6c19
Merge pull request #12023 from Security-Onion-Solutions/2.4/fix-firewall-queries
...
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-14 14:56:42 -05:00
weslambert
d0d671a828
Merge pull request #12020 from Security-Onion-Solutions/fix/integration_force
...
Add force option to integrations
2023-12-14 13:44:32 -05:00
Doug Burks
8779fb8cbc
Update defaults.yaml
2023-12-14 13:30:52 -05:00
Doug Burks
042e5ae9f0
https://github.com/Security-Onion-Solutions/securityonion/issues/12021
2023-12-14 12:46:28 -05:00
Josh Patterson
45f50cc121
Merge pull request #12019 from Security-Onion-Solutions/fix/extrahosts
...
fix extra_hosts
2023-12-14 12:03:07 -05:00
Wes
22fcccef1c
Add force option
2023-12-14 16:53:19 +00:00
Jackson
977081b6e7
update Readme.md
2023-12-14 10:37:04 -05:00
m0duspwnens
3dbf97944d
fix extra_hosts. https://github.com/Security-Onion-Solutions/securityonion/issues/12015
2023-12-14 10:26:29 -05:00
m0duspwnens
03b2a7d2de
change 9805 pipeline to send to self. fix extra_hosts for logstash
2023-12-14 10:01:03 -05:00
Jason Ertel
395da2cca0
Merge pull request #12012 from Security-Onion-Solutions/jertel/eslogerror
...
more log false alarms
2023-12-14 08:59:12 -05:00
Jason Ertel
997d323763
more log false alarms
2023-12-14 08:55:18 -05:00
Elijah Gibson
d5edf57ccb
Update elasticsearch.py
2023-12-13 23:04:44 -05:00
Elijah Gibson
94b9089b79
Update elasticsearch.json
2023-12-13 23:03:42 -05:00
Jackson
81e4fe78e7
pushing everything at once
2023-12-13 13:45:48 -05:00
weslambert
5d3f2298b6
Merge pull request #12000 from Security-Onion-Solutions/feature/additional_integrations
...
Additional Integrations #2
2023-12-13 13:23:34 -05:00
Doug Burks
b17e4006a1
Merge pull request #12001 from Security-Onion-Solutions/2.4/update-clear-scripts
...
FIX: Update clear scripts #11991
2023-12-13 12:01:11 -05:00
weslambert
8cf5d9c1a6
Annotations
2023-12-13 11:55:40 -05:00
weslambert
cdac2bfa16
Add Anomali, Cybersixgill, Snort, and ThreatQuotient
2023-12-13 11:03:25 -05:00
weslambert
b0a69d30c9
Add Anomali, Cybersixgill, Snort, and ThreatQuotient packages
2023-12-13 10:44:03 -05:00
Jason Ertel
196d59869a
Merge pull request #11998 from Security-Onion-Solutions/kilo
...
upgrade cla action
2023-12-13 10:18:39 -05:00
Jason Ertel
c0ab8f24e9
upgrade cla action
2023-12-13 10:10:51 -05:00
Jason Ertel
bd26a52227
upgrade cla action
2023-12-13 10:10:23 -05:00
Jason Ertel
03279732b7
upgrade cla action
2023-12-13 10:09:36 -05:00
Doug Burks
2c4d0a0d71
Update so-elastic-fleet-reset
2023-12-12 16:37:50 -05:00
Doug Burks
d49d13289e
Update so-elastic-clear
2023-12-12 16:37:06 -05:00
Doug Burks
aaf60bea87
Update so-nsm-clear
2023-12-12 16:30:17 -05:00
weslambert
e95932f28c
Merge pull request #11990 from Security-Onion-Solutions/fix/remove_curator
...
Remove Curator
2023-12-12 12:31:16 -05:00
Wes
bbe091fa14
Fix accidental change
2023-12-12 15:08:47 +00:00
Wes
54c3167b10
Delete data streams when necessary
2023-12-12 05:25:50 +00:00
Wes
b1721b6467
Fix directory
2023-12-11 21:43:25 +00:00
Jason Ertel
214404265a
Merge pull request #11981 from Security-Onion-Solutions/jertel/importlogs
...
fix import stats
2023-12-11 14:54:29 -05:00
Jason Ertel
25c39540c8
fix import stats
2023-12-11 14:48:46 -05:00
Wes
f7373ed79c
Stop Curator, remove scripts and status
2023-12-11 19:20:52 +00:00
Wes
d203aec44a
Remove Curator
2023-12-08 19:37:06 +00:00
Jason Ertel
be8ed1e1d8
Merge pull request #11970 from Security-Onion-Solutions/jertel/hfm
...
grid page enhancements
2023-12-08 09:56:39 -05:00
Jason Ertel
a732985351
grid page enhancements
2023-12-08 08:38:42 -05:00
Jason Ertel
98947f3906
grid page enhancements
2023-12-08 08:37:42 -05:00
weslambert
b80d7fd610
Merge pull request #11967 from Security-Onion-Solutions/fix/close_remove
...
Remove Curator close configuration
2023-12-07 15:05:38 -05:00
Wes
849e9e14ad
Change soup to remove delete actions and run post_to_2.4.40
2023-12-07 16:49:44 +00:00
Wes
0ebc8c7beb
Change path
2023-12-07 15:17:51 +00:00
Wes
e0801282eb
Remove files
2023-12-07 14:07:26 +00:00
Wes
bdf4b2c68d
Remove settings
2023-12-07 14:03:45 +00:00
Wes
e49fc0dd27
Remove more settings
2023-12-07 14:03:09 +00:00
Wes
f52da4a933
Remove close settings and cron
2023-12-07 13:58:39 +00:00
Wes
f38758a9c7
Remove close scripts
2023-12-07 13:52:25 +00:00
Wes
1ac3a2d2f1
Remove delete files and allow deletion of indices managed by ILM
2023-12-07 13:51:24 +00:00
Wes
965ced94c4
Remove close files
2023-12-07 13:48:08 +00:00
Doug Burks
bc3634b13d
Merge pull request #11960 from Security-Onion-Solutions/2.4/fix-config-links
...
FIX: Documentation links under SOC - Administration - Configuration need updating #11828
2023-12-06 16:04:11 -05:00
Doug Burks
5c50060857
add description for soc_patch.yaml
2023-12-06 15:51:00 -05:00
Doug Burks
00fa75869b
add description for http_x_skin
2023-12-06 15:44:36 -05:00
Doug Burks
ab0e6f9bec
update broken help links in SOC Config
2023-12-06 14:35:51 -05:00
Doug Burks
213cdb479d
Update soc_manager.yaml
2023-12-06 14:19:15 -05:00
Mike Reeves
8da96e93c8
Merge pull request #11957 from Security-Onion-Solutions/mergeback
...
Merge Main into Dev
2023-12-06 13:40:30 -05:00
Mike Reeves
0160cae7d7
Merge branch '2.4/dev' into mergeback
2023-12-06 13:38:53 -05:00
Mike Reeves
d7bf52de76
Merge pull request #11918 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-12-06 13:31:33 -05:00
weslambert
fea5a3026d
Merge pull request #11955 from Security-Onion-Solutions/fix/sublime_analyzer_documentation
...
Sublime Analyzer Documentation
2023-12-06 13:27:03 -05:00
weslambert
7f21bee0d4
Add README
2023-12-06 13:14:17 -05:00
weslambert
ade3a46a9a
Add LocalFile link
2023-12-06 12:58:44 -05:00
weslambert
e6a2e49d37
Add Sublime Platform
2023-12-06 12:57:59 -05:00
weslambert
1438913f6a
Merge pull request #11954 from Security-Onion-Solutions/fix/sublime_analyzer_indentation
...
Fix indentation for rule_results
2023-12-06 12:50:44 -05:00
Wes
51fa4922b9
Fix indentation for rule_results
2023-12-06 17:37:07 +00:00
Mike Reeves
b878728882
Merge pull request #11951 from Security-Onion-Solutions/2.4.30hf3
...
2.4.30 hotfix
2023-12-06 08:36:13 -05:00
Mike Reeves
386e9214fc
2.4.30 hotfix
2023-12-06 08:34:46 -05:00
weslambert
4becf3e20f
Merge pull request #11950 from Security-Onion-Solutions/fix/eml_observable
...
Add eml observable type
2023-12-06 08:30:27 -05:00
weslambert
0334ef9677
Add eml observable type
2023-12-05 19:10:16 -05:00
weslambert
0537e1b3f6
Merge pull request #11945 from Security-Onion-Solutions/feature/sublime_platform_analyzer
...
Sublime Platform Analyzer
2023-12-05 16:51:03 -05:00
Wes
6fff05b444
Remove pytest.ini
2023-12-05 20:14:17 +00:00
Wes
01a37df7fc
Add extra line
2023-12-05 20:02:12 +00:00
Wes
b3e78c9cc3
Update live flow option
2023-12-05 19:55:23 +00:00
Wes
d871b61150
Change author
2023-12-05 18:36:25 +00:00
Wes
b2536a64d8
Remove extra space
2023-12-05 18:33:00 +00:00
Wes
3d1eecfad6
Add Sublime Platform analyzer
2023-12-05 18:31:50 +00:00
Mike Reeves
8eaa07a186
Merge pull request #11942 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2023-12-05 11:26:42 -05:00
Mike Reeves
9446b750c0
Update soup
2023-12-05 11:25:25 -05:00
Mike Reeves
fdd4173632
Update soup
2023-12-05 11:20:56 -05:00
Mike Reeves
b7227e15eb
Merge pull request #11939 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2023-12-05 10:26:56 -05:00
Mike Reeves
90d9e5b927
Update soup
2023-12-05 10:24:31 -05:00
Mike Reeves
802bf9ce27
Merge pull request #11931 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-12-04 14:00:40 -05:00
Mike Reeves
0b6ba6d2f2
Update soup
2023-12-04 13:51:12 -05:00
Mike Reeves
55a8b1064d
Update soup
2023-12-04 13:36:04 -05:00
Josh Patterson
11a3e12e94
Merge pull request #11929 from Security-Onion-Solutions/hf_soup
...
avoid exiting salt when ca state applied in post for 2.4.30
2023-12-04 11:46:27 -05:00
m0duspwnens
38868af08a
avoid exiting salt when ca state applied in post for 2.4.30
2023-12-04 10:11:38 -05:00
Josh Patterson
ace5dff351
Merge pull request #11923 from Security-Onion-Solutions/hf_soup
...
move wait_for_salt_minion for hotfix
2023-12-01 15:37:35 -05:00
m0duspwnens
265cde5296
move wait_for_salt_minion for hotfix
2023-12-01 15:31:15 -05:00
weslambert
55052c4811
Merge pull request #11919 from Security-Onion-Solutions/fix/remove_curator_changes
...
Remove Curator Changes
2023-12-01 11:15:23 -05:00
Wes
e36044e164
Remove close changes
2023-12-01 16:10:56 +00:00
Wes
6fa4a69753
Remove action changes
2023-12-01 16:10:07 +00:00
Doug Burks
4fc3c852a1
Merge pull request #11890 from chateaulav/chateaulav-import-evtx-logs-11889
...
Update import-evtx-logs.json
2023-11-30 13:57:59 -05:00
weslambert
32b03f514e
Merge pull request #11907 from Security-Onion-Solutions/fix/curator_close
...
Curator close fixes
2023-11-30 11:05:49 -05:00
Wes
a605c5c62c
Ensure indices managed by ILM can be managed by Curator
2023-11-29 22:13:20 +00:00
Wes
2368e8b793
Fix action file names
2023-11-29 22:06:11 +00:00
weslambert
317b6cb614
Merge pull request #11902 from Security-Onion-Solutions/fix/hotfix_version
...
Update HOTFIX
2023-11-29 17:03:59 -05:00
weslambert
a6d20bdc71
Update HOTFIX
2023-11-29 17:01:29 -05:00
Doug Burks
93fb10de86
Merge pull request #11897 from Security-Onion-Solutions/2.4/nids-rule-reference
...
FIX: Update NIDS rule.reference in common.nids pipeline #11846
2023-11-29 12:19:12 -05:00
weslambert
1a4d009b7f
Merge pull request #11896 from Security-Onion-Solutions/feature/elastic_certificate_fingerprints
...
Add certificate fingerprints
2023-11-29 12:07:50 -05:00
weslambert
9d63a47792
Certificate hash
2023-11-29 12:01:43 -05:00
weslambert
7001e90667
Client and server fingerprints
2023-11-29 12:00:46 -05:00
weslambert
a0573212c0
Merge pull request #11891 from Security-Onion-Solutions/fix/elastic_ignore_analyzer
...
Ignore analyzer log
2023-11-29 10:05:01 -05:00
weslambert
5f79644aef
Ignore analyzer log
2023-11-29 10:02:13 -05:00
Doug Burks
0603e96c08
FIX: Update NIDS rule.reference in common.nids pipeline #11846
2023-11-29 09:46:11 -05:00
Jonathan Race
ece3c367b5
Update import-evtx-logs.json
...
version updates to match 2.4 release pipelines
2023-11-29 09:20:37 -05:00
Jason Ertel
8953ffcc49
Merge pull request #11855 from Security-Onion-Solutions/jertel/hfm
...
Jertel/hfm
2023-11-21 16:43:28 -05:00
Jason Ertel
9ee3423b32
Merge branch '2.4/dev' into jertel/hfm
2023-11-21 16:42:50 -05:00
Jason Ertel
7d759a99fe
remove hotfix
2023-11-21 16:40:54 -05:00
Mike Reeves
d3802c1668
Merge pull request #11854 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-11-21 16:39:40 -05:00
Mike Reeves
874618d512
Merge pull request #11853 from Security-Onion-Solutions/2.4.30hf2
...
2.4.30 hotfix
2023-11-21 14:32:53 -05:00
Mike Reeves
fa9032b323
2.4.30 hotfix
2023-11-21 14:28:23 -05:00
Mike Reeves
17942676c6
Merge pull request #11844 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soup
2023-11-21 10:32:24 -05:00
Mike Reeves
458c6de39d
Update soup
2023-11-21 10:30:21 -05:00
Mike Reeves
a39f696a34
Merge pull request #11843 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2023-11-21 10:19:21 -05:00
Mike Reeves
9aa193af3b
Update soup
2023-11-21 10:18:02 -05:00
Mike Reeves
3f1f256748
Merge pull request #11842 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2023-11-21 10:01:13 -05:00
Mike Reeves
c78ea0183f
Update HOTFIX
2023-11-21 09:59:51 -05:00
Mike Reeves
e9417dd437
Merge pull request #11841 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-11-21 09:56:45 -05:00
Mike Reeves
14b5aa476e
Update soup
2023-11-21 09:55:44 -05:00
Jason Ertel
861e850f9a
Merge pull request #11835 from Security-Onion-Solutions/jertel/yaml
...
add support for nested keys
2023-11-20 16:33:17 -05:00
Jason Ertel
6356a0bf95
add support for nested keys
2023-11-20 16:18:30 -05:00
Jason Ertel
f31e288005
Merge pull request #11832 from Security-Onion-Solutions/jertel/hfm
...
Merge hoftix back to 2.4/dev
2023-11-20 15:32:40 -05:00
Jason Ertel
b2ea7138f3
remove hotfix
2023-11-20 15:28:56 -05:00
Jason Ertel
f29a91ea4c
Merge branch '2.4/main' into jertel/hfm
2023-11-20 15:28:27 -05:00
Mike Reeves
4b0033c60a
Merge pull request #11827 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix 2.4.30
2023-11-20 15:26:16 -05:00
Mike Reeves
c20004c210
Merge pull request #11826 from Security-Onion-Solutions/2.4.30hf
...
2.4.30 hotfix
2023-11-20 11:35:11 -05:00
Mike Reeves
45dc1ce036
2.4.30 hotfix
2023-11-20 11:32:21 -05:00
Jason Ertel
0cc10fbf80
Merge pull request #11823 from Security-Onion-Solutions/jertel/igwarn
...
ignore libwbclient upgrade warning
2023-11-19 19:46:19 -05:00
Jason Ertel
e71ee97717
ignore libwbclient upgrade warning
2023-11-19 19:03:23 -05:00
Mike Reeves
77d0a7277a
Merge pull request #11818 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-11-17 17:07:54 -05:00
Mike Reeves
2ae87de409
Merge branch 'hotfix/2.4.30' into TOoSmOotH-patch-2
2023-11-17 17:05:11 -05:00
Josh Brower
a69a65c44f
Merge pull request #11819 from Security-Onion-Solutions/hftesting
...
Remove state file
2023-11-17 16:54:08 -05:00
Mike Reeves
d89beefc8c
Update soup
2023-11-17 16:53:11 -05:00
Josh Brower
9c371fc374
Remove state file
2023-11-17 16:52:34 -05:00
Mike Reeves
4fb9cce41c
Update signing_policies.conf
2023-11-17 16:38:50 -05:00
Mike Reeves
e226efa799
Update soup
2023-11-17 16:35:12 -05:00
Josh Brower
82a41894f3
Merge pull request #11817 from Security-Onion-Solutions/hftesting
...
Hftesting
2023-11-17 13:12:06 -05:00
Josh Brower
7aadc3851f
Remove state file
2023-11-17 13:08:15 -05:00
Josh Brower
ca1498fca1
Dont update Defend Integration
2023-11-17 12:19:22 -05:00
Josh Brower
15fc4f2655
Merge pull request #11815 from Security-Onion-Solutions/hftesting
...
use updated code
2023-11-17 11:23:45 -05:00
Josh Brower
089a111ae8
use updated code
2023-11-17 11:20:13 -05:00
Josh Brower
33bd04b797
Merge pull request #11811 from Security-Onion-Solutions/hftesting
...
Move API check logic
2023-11-17 06:02:26 -05:00
Josh Brower
5920a14478
Move API check logic
2023-11-16 20:34:01 -05:00
Jason Ertel
67f116daed
Merge pull request #11809 from Security-Onion-Solutions/jertel/srtmp
...
improve timing of responses
2023-11-16 16:00:27 -05:00
Jason Ertel
c09e8f0d71
improve timing of responses
2023-11-16 15:58:48 -05:00
Jason Ertel
de99cda766
improve timing of responses
2023-11-16 15:51:17 -05:00
Josh Brower
3ede19a106
Merge pull request #11808 from Security-Onion-Solutions/2.4/defendhotfix2
...
Update HOTFIX
2023-11-16 15:25:24 -05:00
weslambert
b6e2df45c7
Update HOTFIX
2023-11-16 14:48:00 -05:00
Josh Brower
af98c8e2da
Merge pull request #11805 from Security-Onion-Solutions/2.4/defendhotfix2
...
.30 hotfix
2023-11-16 11:42:49 -05:00
Josh Brower
6b8e48c973
Remove highstate
2023-11-16 11:41:20 -05:00
Josh Brower
109ee55d8c
Add to pre for .30 soup
2023-11-16 11:37:38 -05:00
Josh Brower
ff8cd194f1
Make sure kibana API is up
2023-11-16 11:21:34 -05:00
Josh Brower
d5dd0d88ed
.30 hotfix
2023-11-16 10:58:23 -05:00
weslambert
46c5bf40e0
Merge pull request #11804 from Security-Onion-Solutions/fix/kibana_corrupt_integration
...
Discard corrupt integration
2023-11-16 10:49:39 -05:00
Wes
3ed7b36865
Discard corrupt integration
2023-11-16 15:45:38 +00:00
Jason Ertel
85649da2cb
Merge pull request #11792 from Security-Onion-Solutions/jertel/auto
...
avoid startup error
2023-11-14 15:42:26 -05:00
Jason Ertel
f7fa4d05fb
avoid startup error
2023-11-14 15:40:52 -05:00
Doug Burks
96b456cd76
Merge pull request #11785 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Hunt HTTP EXE query #11784
2023-11-14 10:03:46 -05:00
Doug Burks
4666b993e5
Update defaults.yaml
2023-11-14 09:58:45 -05:00
Mike Reeves
4fa6b265a0
Merge pull request #11778 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-11-13 15:38:53 -05:00
Mike Reeves
567e19e5d7
Update VERSION
2023-11-13 15:38:23 -05:00
Mike Reeves
f036623d55
Merge pull request #11777 from Security-Onion-Solutions/2.4/dev
...
2.4.30
2023-11-13 15:27:24 -05:00
Mike Reeves
1204ce96f3
Merge pull request #11776 from Security-Onion-Solutions/2.4.30
...
2.4.30
2023-11-13 13:13:29 -05:00
Mike Reeves
bc178a9784
2.4.30
2023-11-13 13:11:49 -05:00
Mike Reeves
c338daabce
Merge pull request #11769 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Update soup
2023-11-13 08:51:40 -05:00
Mike Reeves
fe7af49a82
Update soup
2023-11-13 08:37:46 -05:00
weslambert
aeb09b16db
Merge pull request #11760 from Security-Onion-Solutions/fix/elastic_packages
...
Add Elastic Agent package and upgrade packages when elasticfleet.packages list changes
2023-11-10 10:20:17 -05:00
weslambert
583ec5176e
Add package check
2023-11-10 10:15:52 -05:00
weslambert
4bb1dabb89
Add elastic_agent
2023-11-10 10:14:59 -05:00
Josh Brower
89c3d45abe
Merge pull request #11751 from Security-Onion-Solutions/2.4/fleetresetfix2
...
Remove unneeded datastreams
2023-11-09 15:04:02 -05:00
Josh Brower
551f7831de
Add more clarity to message
2023-11-09 15:01:56 -05:00
Josh Brower
193c9d202e
Remove unneeded datastreams
2023-11-09 14:30:00 -05:00
Josh Brower
b5912fc1e4
Merge pull request #11750 from Security-Onion-Solutions/2.4/defendpolicy
...
Upgrade Defend Integration policy
2023-11-09 12:48:57 -05:00
Josh Brower
33f538b73e
Upgrade Defend Integration policy
2023-11-09 11:52:06 -05:00
Josh Brower
d3ea5def69
Merge pull request #11747 from Security-Onion-Solutions/2.4/resetscriptfix
...
remove state file
2023-11-09 09:12:52 -05:00
Josh Brower
d1b6ef411b
remove state file
2023-11-09 09:01:57 -05:00
Jason Ertel
8ca825b9a1
Merge pull request #11745 from Security-Onion-Solutions/jertel/yaml
...
re-add source pkgs from accidental commit
2023-11-09 07:19:22 -05:00
Jason Ertel
209e237d0d
re-add source pkgs from accidental commit
2023-11-09 00:34:52 -05:00
Jason Ertel
325dceb01b
Merge pull request #11743 from Security-Onion-Solutions/fix/elastic_template_check
...
Additional fixes for index template check
2023-11-09 00:15:14 -05:00
weslambert
02baa18502
Add metrics
2023-11-08 22:41:24 -05:00
Jason Ertel
268dc03131
Merge pull request #11742 from Security-Onion-Solutions/jertel/yaml
...
add yaml helper script; refactor python testing
2023-11-08 21:06:04 -05:00
weslambert
e39edab00d
Exclude osquery and display failed name
2023-11-08 20:55:08 -05:00
weslambert
acb6e84248
Don't load index template if component template doesn't exist
2023-11-08 20:34:08 -05:00
Jason Ertel
9231c8d2f2
replace reset sed with new script
2023-11-08 19:17:32 -05:00
Jason Ertel
bc044fa2d5
more coverage
2023-11-08 18:42:06 -05:00
Jason Ertel
84b815c2ef
add yaml helper script; refactor python testing
2023-11-08 18:30:05 -05:00
Jason Ertel
1ab44a40d3
add yaml helper script; refactor python testing
2023-11-08 18:29:06 -05:00
Jason Ertel
9317e51f20
add yaml helper script; refactor python testing
2023-11-08 18:26:37 -05:00
Jason Ertel
33a8ef1568
add yaml helper script; refactor python testing
2023-11-08 18:24:23 -05:00
Josh Patterson
01e846ba22
Merge pull request #11741 from Security-Onion-Solutions/issue/11738
...
remove comments from BPFs
2023-11-08 15:25:02 -05:00
weslambert
9df3a8fc18
Merge pull request #11740 from Security-Onion-Solutions/fix/elastic_templates
...
Remove template files
2023-11-08 15:20:01 -05:00
weslambert
36098e6314
Remove template files
2023-11-08 14:32:58 -05:00
Jason Ertel
32079a7bce
Merge pull request #11734 from Security-Onion-Solutions/fix/elastic_scripts
...
Improve error handling and add retry logic
2023-11-08 12:19:00 -05:00
Jason Ertel
3701c1d847
ignore retry logging
2023-11-08 11:50:56 -05:00
m0duspwnens
f46aef1611
remove comments from BPFs
2023-11-08 11:23:19 -05:00
Jason Ertel
d256be3eb3
allow template loads to partially succeed only on the initial attempt
2023-11-08 10:32:11 -05:00
Wes
653fda124f
Check expected with retry
2023-11-08 13:02:17 +00:00
Wes
b46e86c39b
Extend index template loading to 60 attempts and a total of ~5 minutes
2023-11-08 02:29:09 +00:00
Wes
de9f9549af
Extend template loading to 24 attempts and a total of ~2 minutes
2023-11-07 23:55:03 +00:00
weslambert
749e22e4b9
Fix if statement
2023-11-07 17:29:38 -05:00
weslambert
69ec1987af
Fix if statement
2023-11-07 17:28:37 -05:00
Wes
570624da7e
Remove RETURN_CODE
2023-11-07 21:09:29 +00:00
Wes
7772657b4b
Remove RETURN_CODE
2023-11-07 21:06:35 +00:00
Jason Ertel
6d97667634
Merge branch '2.4/dev' into kilo
2023-11-07 15:59:52 -05:00
Wes
1676c84f9c
Use the retry function so-elasticsearch-query
2023-11-07 19:56:50 +00:00
Jason Ertel
e665899e4d
Merge pull request #11735 from Security-Onion-Solutions/fix/elastic_agent_template
...
Change pipeline to 1.13.1
2023-11-07 14:11:47 -05:00
weslambert
1dcca0bfd3
Change pipeline to 1.13.1
2023-11-07 12:17:51 -05:00
Wes
0b4a246ddb
State file changes and retry logic
2023-11-07 16:44:42 +00:00
weslambert
f97dc70fcb
Merge pull request #11732 from Security-Onion-Solutions/fix/elastic_agent_template
...
Change pipeline to 1.8.0
2023-11-07 09:08:25 -05:00
weslambert
cce80eb2fb
Change pipeline to 1.8.0
2023-11-07 09:02:48 -05:00
Jason Ertel
2f95512199
Merge branch '2.4/dev' into kilo
2023-11-06 11:27:58 -05:00
Jason Ertel
b008661b6b
Merge pull request #11726 from Security-Onion-Solutions/jertel/auto
...
improve verbosity of setup logs
2023-11-06 11:27:33 -05:00
Jason Ertel
b99c7ce76e
improve verbosity of setup logs
2023-11-06 11:22:35 -05:00
Wes
c30a0d5b5b
Better error handling and state file management
2023-11-06 14:29:01 +00:00
Wes
74eda68d84
Exit if unable to communicate with Elasticsearch
2023-11-06 13:16:35 +00:00
Josh Brower
ef1dfc3152
Merge pull request #11722 from Security-Onion-Solutions/2.4/packageupgrade
...
Set execute permissions
2023-11-06 08:06:13 -05:00
Josh Brower
f6cd35e143
Set execute permissions
2023-11-06 08:03:31 -05:00
Jason Ertel
d010af9a24
Merge pull request #11718 from Security-Onion-Solutions/jertel/auto
...
disregard false positives
2023-11-04 16:32:02 -04:00
Jason Ertel
7a0b21647f
disregard false positives
2023-11-04 10:05:37 -04:00
Josh Patterson
610374816d
Merge pull request #11714 from Security-Onion-Solutions/change/so-minion
...
apply es and soc states to manager if new search or hn are added
2023-11-03 16:43:16 -04:00
Josh Brower
3ff74948d8
Merge pull request #11713 from Security-Onion-Solutions/2.4/agentupdate
...
Upgrade Elastic Agent
2023-11-03 15:23:55 -04:00
Josh Brower
0086c24729
Upgrade Elastic Agent
2023-11-03 15:21:06 -04:00
m0duspwnens
9d2b84818f
apply es and soc states to manager if new search or hn are added
2023-11-03 15:00:13 -04:00
Mike Reeves
b74aa32deb
Merge pull request #11712 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soc_elasticsearch.yaml
2023-11-03 11:33:00 -04:00
Mike Reeves
3d8663db66
Update soc_elasticsearch.yaml
2023-11-03 11:29:45 -04:00
Josh Brower
65978a340f
Merge pull request #11710 from Security-Onion-Solutions/2.4/navlayerfix
...
exit 0
2023-11-03 11:07:10 -04:00
Josh Brower
a8b0e41dbe
exit 0
2023-11-03 11:04:52 -04:00
Jason Ertel
1bc4b44be7
Merge pull request #11709 from Security-Onion-Solutions/jertel/auto
...
ignore malformed open canary log lines
2023-11-03 09:17:23 -04:00
Jason Ertel
1a3d4a2051
ignore malformed open canary log lines
2023-11-03 09:14:26 -04:00
Josh Brower
9d639df882
Merge pull request #11708 from Security-Onion-Solutions/2.4/metadatafix2
...
Dont overwrite metadata
2023-11-03 08:47:48 -04:00
Josh Brower
8c7767b381
Dont overwrite metadata
2023-11-03 08:41:33 -04:00
weslambert
96582add5e
Merge pull request #11704 from Security-Onion-Solutions/feature/integrations_checkpoint_vsphere
...
Checkpoint and VSphere Integrations
2023-11-02 17:17:03 -04:00
Wes
5bfef3f527
Add checkpoint and vsphere templates
2023-11-02 21:10:01 +00:00
Wes
3875970dc5
Add checkpoint and vsphere packages
2023-11-02 21:09:37 +00:00
Jason Ertel
7aa4f28524
Merge pull request #11702 from Security-Onion-Solutions/jertel/auto
...
ignore connectivity problems to docker containers during startup
2023-11-02 16:48:09 -04:00
Jason Ertel
96fdfb3829
ignore connectivity problems to docker containers during startup
2023-11-02 16:46:41 -04:00
weslambert
ac593e4632
Merge pull request #11701 from Security-Onion-Solutions/fix/elastic_templates_common
...
Don't source so-elastic-fleet-common if not there
2023-11-02 16:43:27 -04:00
weslambert
51e7861757
Don't source so-elastic-fleet-common if not there
2023-11-02 16:41:34 -04:00
Jason Ertel
6332df04d1
Merge pull request #11695 from Security-Onion-Solutions/jertel/auto
...
Jertel/auto
2023-11-02 13:07:09 -04:00
Jason Ertel
32701b5941
more log bypass
2023-11-02 12:50:12 -04:00
Josh Brower
0dec6693dc
Merge pull request #11678 from Security-Onion-Solutions/2.4/fleetreset
...
Add Elastic Fleet reset script
2023-11-02 11:33:58 -04:00
Jason Ertel
41a6ab5b4f
Merge pull request #11691 from Security-Onion-Solutions/jertel/auto
...
more log bypass
2023-11-02 10:41:17 -04:00
Jason Ertel
e18e0fd69a
more log bypass
2023-11-02 10:39:14 -04:00
Josh Brower
2c0e287f8c
Fix name
2023-11-02 10:34:24 -04:00
Josh Patterson
9a76cfe3d3
Merge pull request #11690 from Security-Onion-Solutions/upgrade/salt3006.3v2
...
fix UPGRADECOMMAND used for distrib salt upgrade. remove unneeded vars
2023-11-02 10:28:29 -04:00
m0duspwnens
6c4dc7cc09
fix UPGRADECOMMAND used for distrib salt upgrade. remove unneeded vars
2023-11-02 10:23:03 -04:00
Josh Brower
5388b92865
Refactor & cleanup
2023-11-02 10:20:32 -04:00
Jason Ertel
f932444101
Merge pull request #11689 from Security-Onion-Solutions/jertel/auto
...
more log bypass
2023-11-02 10:02:13 -04:00
Jason Ertel
1d2518310d
more log bypass
2023-11-02 09:59:45 -04:00
weslambert
e10f043b1c
Merge pull request #11688 from Security-Onion-Solutions/fix/integrations_roles
...
Add eval and import roles
2023-11-02 09:58:40 -04:00
weslambert
65735fc4d3
Add eval and import roles
2023-11-02 09:54:01 -04:00
Jason Ertel
b7f516fca4
Merge pull request #11687 from Security-Onion-Solutions/jertel/auto
...
adjust log filter to include all hosts
2023-11-02 09:24:08 -04:00
Jason Ertel
c8d8997119
adjust log filter to include all hosts
2023-11-02 09:21:57 -04:00
Josh Brower
c230cf4eb7
Formatting
2023-11-01 17:00:32 -04:00
Josh Brower
344dd7d61f
Add Elastic Fleet reset script
2023-11-01 16:50:20 -04:00
Mike Reeves
cd8949d26b
Merge pull request #11677 from Security-Onion-Solutions/lowram
...
Allow 16GB of memory
2023-11-01 16:38:40 -04:00
weslambert
f9e2940181
Merge pull request #11676 from Security-Onion-Solutions/feature/sublime_platform_integration
...
Sublime Platform Integration
2023-11-01 16:13:57 -04:00
Wes
f33079f1e3
Make settings global
2023-11-01 20:09:56 +00:00
Mike Reeves
e6a0838e4c
Add memory restrictions
2023-11-01 15:26:24 -04:00
Mike Reeves
cc93976db9
Add memory restrictions
2023-11-01 15:17:23 -04:00
Mike Reeves
b3b67acf07
Add memory restrictions
2023-11-01 15:11:54 -04:00
Josh Patterson
64926941dc
Merge pull request #11674 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2023-11-01 15:03:30 -04:00
Wes
c32935e2e6
Remove optional integration from configuration if not enabled
2023-11-01 17:02:43 +00:00
Mike Reeves
4f98beaf9e
Merge pull request #11671 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Remove legacy pillar info
2023-11-01 13:00:34 -04:00
Wes
655c88cd09
Make sure enabled_nodes is populated
2023-11-01 16:47:51 +00:00
Mike Reeves
f62e02a477
Delete pillar/thresholding/pillar.example
2023-11-01 10:42:29 -04:00
Mike Reeves
2b3e405b2d
Delete pillar/thresholding/pillar.usage
2023-11-01 10:41:40 -04:00
Josh Patterson
59328d3909
Merge pull request #11670 from Security-Onion-Solutions/fix/soupagrepo
...
Fix/soupagrepo
2023-11-01 10:36:17 -04:00
m0duspwnens
4d7b1095b7
Merge remote-tracking branch 'origin/2.4/dev' into fix/soupagrepo
2023-11-01 10:31:59 -04:00
m0duspwnens
338146fedd
fix repo update during soup for airgap
2023-11-01 10:19:56 -04:00
Wes
bca1194a46
Sublime SOC Action
2023-11-01 14:01:55 +00:00
Wes
a0926b7b87
Load optional integrations
2023-11-01 13:59:24 +00:00
Wes
44e45843bf
Change optional integration Fleet configuration
2023-11-01 13:52:38 +00:00
Wes
9701d0ac20
Optional integration Fleet configuration
2023-11-01 13:47:20 +00:00
Wes
23ee9c2bb0
Sublime Platform integration
2023-11-01 13:41:40 +00:00
Wes
51247be6b9
Sublime Platform integration defaults
2023-11-01 13:37:52 +00:00
Wes
4dc64400c5
Support document_id
2023-11-01 13:36:32 +00:00
Wes
ae45d40eca
Add Sublime Platform ingest pipeline
2023-11-01 13:34:30 +00:00
Mike Reeves
ebf982bf86
Merge pull request #11666 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Remove unused scripts and functions
2023-10-31 15:18:23 -04:00
Mike Reeves
d07cfdd3fe
Update so-functions
2023-10-31 13:10:55 -04:00
Mike Reeves
497294c363
Delete salt/common/tools/sbin/so-zeek-logs
2023-10-31 12:57:10 -04:00
Mike Reeves
cc3a69683c
Delete salt/manager/tools/sbin/so-allow-view
2023-10-31 12:55:47 -04:00
Mike Reeves
0c98bd96c7
Delete salt/idstools/tools/sbin/so-rule
...
UI does this now
2023-10-31 12:52:00 -04:00
Jason Ertel
a6d456e108
Merge pull request #11665 from Security-Onion-Solutions/jertel/auto
...
ignore specific Suricata errors
2023-10-31 11:20:28 -04:00
Jason Ertel
c420e198fb
ignore specific Suricata errors
2023-10-31 11:18:39 -04:00
weslambert
5a85003952
Merge pull request #11664 from Security-Onion-Solutions/fix/elastic_import
...
Add import roles
2023-10-31 10:47:13 -04:00
weslambert
c354924b68
Add import roles
2023-10-31 10:05:29 -04:00
Jason Ertel
db0d687b87
Merge pull request #11661 from Security-Onion-Solutions/fix/elastic_eval_roles
...
Add roles for eval mode
2023-10-30 22:01:22 -04:00
weslambert
ed6473a34b
Add roles for eval mode
2023-10-30 20:41:49 -04:00
Josh Patterson
1b99d5081a
Merge pull request #11659 from Security-Onion-Solutions/issue/11457
...
ensure networkminer is latest version
2023-10-30 16:20:36 -04:00
m0duspwnens
07e51121ba
ensure networkminer is latest version
2023-10-30 16:11:36 -04:00
weslambert
9a1e95cd09
Merge pull request #11648 from Security-Onion-Solutions/fix/ilm_remove_policy
...
Remove ILM policies for Cases and OSQuery manager indices
2023-10-27 17:28:59 -04:00
weslambert
76dd6f07ab
Remove policy for OSQuery manager indices
2023-10-27 17:26:33 -04:00
weslambert
c955f9210a
Remove policy for Cases indices
2023-10-27 17:24:27 -04:00
Josh Patterson
d35483aa02
Merge pull request #11647 from Security-Onion-Solutions/upgrade/salt3006.3v2
...
Upgrade/salt3006.3v2
2023-10-27 14:37:16 -04:00
Jorge Reyes
a9284b35a2
Merge pull request #11644 from Security-Onion-Solutions/bravo
...
UPGRADE: influxdb 2.7.1 & telegraf 1.28.2
2023-10-27 12:16:48 -04:00
Jason Ertel
58cab35a4c
Merge pull request #11643 from Security-Onion-Solutions/kilo
...
oidc
2023-10-27 11:21:20 -04:00
Jason Ertel
6d7243038c
switch back to kilo version
2023-10-27 11:20:49 -04:00
Jason Ertel
3a83c52660
minor updates
2023-10-27 11:20:05 -04:00
Jason Ertel
d42b5ef901
remove unused url props to avoid kratos complaining about invalid urls when they're blank
2023-10-27 11:18:56 -04:00
m0duspwnens
2b511cef77
Merge branch 'upgrade/salt3006.3' into upgrade/salt3006.3v2
2023-10-27 10:58:09 -04:00
Josh Patterson
4bbcc5002a
Revert "Revert "Upgrade/salt3006.3""
...
This reverts commit c41e19ad0b .
2023-10-27 10:56:45 -04:00
Mike Reeves
f1dbea6e2d
Merge pull request #11623 from Security-Onion-Solutions/warmui
...
Warm Node UI Changes
2023-10-27 10:36:23 -04:00
Mike Reeves
25f1a0251f
Annotation changes for warm node
2023-10-27 09:08:07 -04:00
Mike Reeves
87494f64c7
Annotation changes for warm node
2023-10-27 09:06:12 -04:00
Mike Reeves
ce1858fe05
Annotation changes for warm node
2023-10-27 09:02:39 -04:00
Mike Reeves
9fc3a73035
Annotation changes for warm node
2023-10-27 08:58:08 -04:00
Josh Brower
0d52efafa8
Merge pull request #11637 from Security-Onion-Solutions/2.4/kibanauser
...
2.4/kibanauser
2023-10-27 08:43:12 -04:00
defensivedepth
3b63ef149a
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/kibanauser
2023-10-27 07:50:58 -04:00
defensivedepth
cc3ee43192
Make dirs as needed
2023-10-27 07:49:34 -04:00
Mike Reeves
b37e38e3c3
Update defaults.yaml
2023-10-26 16:03:58 -04:00
Jorge Reyes
25982b79ab
Merge pull request #11633 from Security-Onion-Solutions/reyesj2/influxdb_config
...
UPGRADE: Influxdb 2.7.1 & telegraf 1.28.2
2023-10-26 14:37:09 -04:00
Jason Ertel
cb9d72ebd7
switch back to kilo version
2023-10-26 14:19:59 -04:00
m0duspwnens
7e8f3b753f
add minion name to log, update comment
2023-10-26 13:19:04 -04:00
reyesj2
47373adad2
Specify config.yaml in config_path. Otherwise when no influxd.bolt exists influxdb will fail to read the config file and won't create a new db.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-26 13:15:40 -04:00
m0duspwnens
6891a95254
remove wait_for_salt_minion from so-functions
2023-10-26 13:02:39 -04:00
Mike Reeves
2e0100fd35
Update defaults.yaml
2023-10-26 12:37:55 -04:00
Jason Ertel
a969c319f5
Merge pull request #11631 from Security-Onion-Solutions/kilo
...
oidc
2023-10-26 12:30:06 -04:00
Jason Ertel
4942f83d4f
adjust version to match target branch
2023-10-26 11:45:39 -04:00
Josh Brower
6f4566c23e
Merge pull request #11609 from Security-Onion-Solutions/2.4/kibanauser
...
Add kibana curl config
2023-10-26 10:42:32 -04:00
Wes
891ea997e7
Add lifecycle policies and warm settings
2023-10-26 12:25:37 +00:00
Mike Reeves
01810a782c
Annotation changes for warm node
2023-10-25 16:46:30 -04:00
Mike Reeves
6d6292714f
Annotation changes for warm node
2023-10-25 16:21:47 -04:00
Mike Reeves
88fb7d06e6
Annotation changes for warm node
2023-10-25 16:20:28 -04:00
Josh Patterson
39abe19cfd
Update config.map.jinja
2023-10-25 16:17:06 -04:00
Josh Patterson
807b40019f
Update soc_elasticsearch.yaml
2023-10-25 16:16:48 -04:00
Josh Patterson
5f168a33ed
Update defaults.yaml
2023-10-25 16:16:01 -04:00
Mike Reeves
d1170cb69f
Update soc_elasticsearch.yaml
2023-10-25 16:05:20 -04:00
m0duspwnens
19fdc9319b
fix role update
2023-10-25 15:58:26 -04:00
Mike Reeves
dc53b49f15
Update soup
2023-10-25 15:53:39 -04:00
Josh Patterson
af4b34801f
Update defaults.yaml
2023-10-25 15:48:27 -04:00
Josh Patterson
1ae8896a05
Update config.map.jinja
2023-10-25 15:47:40 -04:00
Mike Reeves
6fb0c5dbfe
Annotation changes for warm node
2023-10-25 15:37:36 -04:00
Mike Reeves
58bf6d3eff
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into warmui
2023-10-25 15:37:14 -04:00
Mike Reeves
a887551dad
Annotation changes for warm node
2023-10-25 15:22:47 -04:00
Jason Ertel
b20177b0ef
Merge branch '2.4/dev' into kilo
2023-10-25 15:19:57 -04:00
defensivedepth
1e710a22ce
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/kibanauser
2023-10-25 11:33:38 -04:00
Josh Patterson
d562445686
Merge pull request #11619 from Security-Onion-Solutions/revert-11612-upgrade/salt3006.3
...
Revert "Upgrade/salt3006.3"
2023-10-25 11:28:14 -04:00
Josh Patterson
c41e19ad0b
Revert "Upgrade/salt3006.3"
2023-10-25 11:01:13 -04:00
m0duspwnens
a3e6b1ee1d
change generate_ssl wait_for_salt_minion
2023-10-25 09:26:36 -04:00
Jason Ertel
a28cc274ba
Merge branch '2.4/dev' into kilo
2023-10-25 09:04:36 -04:00
Jason Ertel
a66006c8a6
minor updates
2023-10-25 09:04:23 -04:00
defensivedepth
3ad480453a
Rename to remove dupe
2023-10-25 07:20:07 -04:00
Josh Patterson
205748e992
Merge pull request #11613 from Security-Onion-Solutions/issue/11610
...
fix issue/11610
2023-10-24 18:16:44 -04:00
m0duspwnens
dfe707ab64
fix issue/11610
2023-10-24 17:26:39 -04:00
Josh Patterson
308e5ea505
Merge pull request #11612 from Security-Onion-Solutions/upgrade/salt3006.3
...
Upgrade/salt3006.3
2023-10-24 16:45:12 -04:00
m0duspwnens
3e343bff84
fix line to log properly
2023-10-24 16:40:51 -04:00
m0duspwnens
1d6e32fbab
dont exit if salt isnt running
2023-10-24 15:08:50 -04:00
defensivedepth
310a6b4f27
Add kibana curl config
2023-10-24 14:21:01 -04:00
m0duspwnens
180ba3a958
if deb fam, stop salt-master and salt-minion after salt upgrade
2023-10-24 13:24:52 -04:00
m0duspwnens
6d3465626e
if deb fam, stop salt-master and salt-minion after salt upgrade
2023-10-24 12:52:25 -04:00
m0duspwnens
fab91edd2d
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-24 09:41:23 -04:00
m0duspwnens
752390be2e
merge with dev, fix confict
2023-10-24 09:40:09 -04:00
Mike Reeves
02639d3bc5
Merge pull request #11606 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Enable http2 for Suricata
2023-10-24 09:23:07 -04:00
Mike Reeves
4a3fc06a4d
Enable http2 for Suricata
2023-10-24 09:18:10 -04:00
weslambert
0c2b3f3c62
Merge pull request #11600 from Security-Onion-Solutions/fix/suricata_pkt_src
...
Parse pkt_src for Suricata logs
2023-10-23 15:51:30 -04:00
weslambert
660020cc76
Parse pkt_src for Suricata logs
2023-10-23 15:45:41 -04:00
Jorge Reyes
b59a95b72f
Merge pull request #11594 from Security-Onion-Solutions/fix/playbookrule
...
FIX: Add -watch to soctopus saltstate for file SOCtopus.conf. Makes contai…
2023-10-23 11:51:53 -04:00
reyesj2
030a667d26
Add -watch to soctopus saltstate for file SOCtopus.conf. Makes container restart @ highstate if file is updated.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-23 11:47:14 -04:00
Josh Patterson
a40760e601
Merge pull request #11592 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-23 10:37:05 -04:00
m0duspwnens
dc3ca99c12
ask the minion if it can see itself in the mine
2023-10-20 17:16:33 -04:00
m0duspwnens
7e3aa11a73
check mine is populated with ip before telling node to highstate
2023-10-20 16:27:20 -04:00
m0duspwnens
c409339446
change post setup highstate cron to 5 minutes since accepting minion runs a highstate
2023-10-20 13:46:24 -04:00
m0duspwnens
c588bf4395
update mine and highstate minion when added
2023-10-20 13:43:12 -04:00
m0duspwnens
6d77b1e4c3
continue loop if minion not in mine
2023-10-20 13:41:53 -04:00
m0duspwnens
99662c999f
log operation and minion target
2023-10-20 13:41:24 -04:00
m0duspwnens
ef2b89f5bf
fix attempts logic
2023-10-20 13:40:40 -04:00
Josh Patterson
2878f82754
Merge pull request #11582 from Security-Onion-Solutions/minechanges
...
handle a minion not being in the mine data return
2023-10-20 10:07:44 -04:00
m0duspwnens
2e16250c93
handle a minion not being in the mine data return
2023-10-20 10:00:39 -04:00
m0duspwnens
f03bbdbc09
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-19 17:01:12 -04:00
m0duspwnens
dbfccdfff8
fix logging when using wait_for_minion
2023-10-19 16:53:03 -04:00
m0duspwnens
dfcbbfd157
update call to wait_for_salt_minion with new options in so-functions
2023-10-19 15:58:50 -04:00
m0duspwnens
37e803917e
have soup wait_for_salt_minion() before running any highstate
2023-10-19 15:58:10 -04:00
m0duspwnens
66ee074795
add wait_for_salt_minion to so-common
2023-10-19 15:57:24 -04:00
m0duspwnens
90bde94371
handle debian family salt upgrade for soup
2023-10-19 13:46:48 -04:00
m0duspwnens
84f8e1cc92
debian family upgrade salt without -r flag
2023-10-19 13:46:07 -04:00
m0duspwnens
e3830fa286
all more os to set_os in so-common
2023-10-19 13:43:03 -04:00
m0duspwnens
13a5c8baa7
remove extra ||
2023-10-19 11:19:51 -04:00
m0duspwnens
c5610edd83
handle salt for r9 and c9
2023-10-19 11:12:20 -04:00
weslambert
5119e6c45a
Merge pull request #11570 from Security-Onion-Solutions/feature/additional_integrations
...
Additional integrations
2023-10-19 09:30:40 -04:00
m0duspwnens
02e22c87e8
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-19 09:15:31 -04:00
Mike Reeves
0772926992
Merge pull request #11573 from Security-Onion-Solutions/minechanges
2023-10-18 19:45:23 -04:00
m0duspwnens
b2bb92d413
remove extra space
2023-10-18 19:38:19 -04:00
Mike Reeves
19bebe44aa
Merge pull request #11572 from Security-Onion-Solutions/minechanges
2023-10-18 19:37:34 -04:00
m0duspwnens
f30a652e19
add back redirects
2023-10-18 19:31:45 -04:00
m0duspwnens
ff18b1f074
remove redirect
2023-10-18 18:45:14 -04:00
m0duspwnens
9eb682bc40
generate_ca after salt-master and salt-minion states run
2023-10-18 18:37:35 -04:00
Wes
c135f886a9
Remove Carbon Black Cloud integration
2023-10-18 20:41:34 +00:00
Wes
28b7a24cc1
Add templates for integrations
2023-10-18 20:36:04 +00:00
m0duspwnens
a52ee063e5
use generate_ca and generate_ssl functions and move them up
2023-10-18 16:35:33 -04:00
Wes
767a54c91b
Add pkgs
2023-10-18 20:07:26 +00:00
m0duspwnens
ac28e1b967
verify crt and key differently in checkmine
2023-10-18 15:53:12 -04:00
Jorge Reyes
5e10a0d9e2
Merge pull request #11568 from Security-Onion-Solutions/2.4/zeek6
...
Add back plugin-tds/ plugin-profinet. Using patched versions for Zeek 6
2023-10-18 15:39:30 -04:00
reyesj2
dd28dc6ddd
Add back plugin-tds/ plugin-profinet. Using patched versions for Zeek 6
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-18 15:30:32 -04:00
m0duspwnens
e58c1e189c
use x509 instead of file for onchanges
2023-10-18 15:10:17 -04:00
m0duspwnens
1c1b23c328
fix mine update for ca
2023-10-18 15:07:18 -04:00
m0duspwnens
2206cdb0fa
change soup comment
2023-10-18 15:04:39 -04:00
m0duspwnens
1999db0bb3
apply ca state early in setup
2023-10-18 15:02:22 -04:00
m0duspwnens
c3cde61202
docker service watches and requires the intca
2023-10-18 15:01:26 -04:00
m0duspwnens
8e68f96316
check that the manager has a ca in the mine and that it is valid
2023-10-18 13:59:15 -04:00
m0duspwnens
138aa9c554
update the mine with the ca when it is created or changed
2023-10-18 13:54:14 -04:00
weslambert
f0e380870d
Merge pull request #11567 from Security-Onion-Solutions/fix/mhr_docs
...
Add note regarding DNS resolver
2023-10-18 13:46:25 -04:00
weslambert
34717fb65e
Add note regarding DNS resolver
2023-10-18 13:44:09 -04:00
Josh Patterson
d81dfb99d0
Merge pull request #11563 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-17 17:36:46 -04:00
m0duspwnens
fb9a0ab8b6
endif not fi in jinja
2023-10-17 17:33:53 -04:00
m0duspwnens
928fb23e96
only add node to pillar if returned ip from mine
2023-10-17 17:28:28 -04:00
m0duspwnens
d9862aefcf
handle mine.p not being present. only check if mine_ip exists, dont compare to alived ip
2023-10-17 17:09:52 -04:00
m0duspwnens
496b97d706
handle the mine file not being present before checking the size
2023-10-17 15:42:42 -04:00
weslambert
830b5b9a21
Merge pull request #11560 from Security-Onion-Solutions/foxtrot
...
Elastic 8.10.4
2023-10-17 13:47:21 -04:00
weslambert
06e731c762
Update VERSION
2023-10-17 13:33:12 -04:00
weslambert
be2a829524
Elastic 8.10.4
2023-10-17 10:49:03 -04:00
weslambert
8cab242ad0
Elastic 8.10.4
2023-10-17 10:48:31 -04:00
weslambert
99054a2687
Elastic 8.10.4
2023-10-17 10:47:26 -04:00
weslambert
adcb7840bd
Elastic 8.10.3
2023-10-17 10:38:20 -04:00
weslambert
8db6fef92d
Elastic 8.10.3
2023-10-17 10:35:36 -04:00
weslambert
24329e3731
Update config_saved_objects.ndjson
2023-10-17 10:34:38 -04:00
weslambert
1db88bdbb5
Update so-common
2023-10-17 10:33:39 -04:00
weslambert
7c2cdb78e9
Update VERSION
2023-10-17 10:31:53 -04:00
Josh Patterson
e858a1211e
Merge pull request #11558 from Security-Onion-Solutions/excludelogfp
...
mark suricata 7 log line as fp fo so-log-check
2023-10-17 10:02:21 -04:00
m0duspwnens
01cb0fccb6
mark suricata 7 log line as fp fo so-log-check
2023-10-17 10:01:11 -04:00
Josh Patterson
86394dab01
Merge pull request #11555 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-16 17:32:16 -04:00
m0duspwnens
53fcafea50
redo how we check if salt-master is ready and accessible
2023-10-16 16:31:43 -04:00
Jorge Reyes
574a81da7f
Merge pull request #11554 from Security-Onion-Solutions/2.4/zeek6
...
Zeek 6 upgrade
2023-10-16 15:52:48 -04:00
reyesj2
ed693a7ae6
Remove commented lines in defaults.yaml to avoid UI issues.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-16 15:48:51 -04:00
reyesj2
e5c936e8cf
Replace external zeek-community-id with builtin community-id. Disable plugin-tds + plugin-profinet. Not updated for Zeek 6.x
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-16 15:18:26 -04:00
m0duspwnens
9f3a9dfab0
reorder salt.master state
2023-10-16 15:00:53 -04:00
m0duspwnens
c0030bc513
dont need to restart minion service when just adding sleep delay on service start
2023-10-16 15:00:07 -04:00
m0duspwnens
a637b0e61b
apply salt.master and minion state early in setup to prevent the services from restarting later in setup
2023-10-16 14:58:58 -04:00
Jason Ertel
2f0e673ec3
Merge pull request #11552 from Security-Onion-Solutions/jertel/auto
...
only add heavynodes to remoteHostUrls
2023-10-16 13:10:10 -04:00
Jason Ertel
84c39b5de7
only add heavynodes to remoteHostUrls
2023-10-16 13:01:13 -04:00
m0duspwnens
07902d17cc
display container dl status during soup
2023-10-16 11:20:19 -04:00
m0duspwnens
1a7761c531
display container dl status during soup
2023-10-16 11:00:31 -04:00
m0duspwnens
2773da5a12
run the checkmine engine under master instead of minion
2023-10-16 10:34:45 -04:00
m0duspwnens
e23b3a62f3
default interval of 60s
2023-10-13 16:24:11 -04:00
m0duspwnens
57684efddf
checkmine looks for 1 byte file and verify mine ip is correct
2023-10-13 16:23:16 -04:00
m0duspwnens
1641aa111b
add checkmine back
2023-10-13 13:46:31 -04:00
Jason Ertel
ca2530e07f
Merge pull request #11535 from Security-Onion-Solutions/jertel/auto
...
avoid rebooting when testing deb installs
2023-10-12 16:30:24 -04:00
Mike Reeves
104b53c6ec
Merge pull request #11534 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2023-10-12 16:20:37 -04:00
Mike Reeves
6c5f8e4e2d
Update HOTFIX
2023-10-12 16:19:59 -04:00
Mike Reeves
b8d586addd
Merge pull request #11533 from Security-Onion-Solutions/2.4/main
...
2.4/main
2023-10-12 16:19:29 -04:00
m0duspwnens
d2002a5158
add additional comments
2023-10-12 15:58:33 -04:00
m0duspwnens
5250292e95
only allow stable install type. require -r to be used
2023-10-12 15:54:22 -04:00
Jason Ertel
49a651fd72
adjust var name
2023-10-12 15:43:22 -04:00
m0duspwnens
2d688331df
handle version install for stable and onedir install type
2023-10-12 15:32:04 -04:00
m0duspwnens
b12c4a96e9
remove files
2023-10-12 15:11:25 -04:00
m0duspwnens
6dd06c0fe9
change install_centos_onedir to install version provided from command line
2023-10-12 15:07:47 -04:00
Jason Ertel
17ae9b3349
avoid reboot during testing
2023-10-12 13:54:07 -04:00
m0duspwnens
8dc163f074
use script from develop branch
2023-10-12 13:09:07 -04:00
m0duspwnens
ab4c5acd0c
update bootstrap-salt.sh with stable branch
2023-10-12 09:28:07 -04:00
m0duspwnens
d357864d69
fix upgrade_salt function for oel
2023-10-11 15:32:11 -04:00
Jason Ertel
44b855dd93
merge 2.4/dev
2023-10-11 13:35:16 -04:00
m0duspwnens
2094b4f688
upgrade to salt 3006.3
2023-10-11 09:04:36 -04:00
Josh Patterson
5252482fe3
Merge pull request #11503 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-10 16:33:17 -04:00
m0duspwnens
abeebc7bc4
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-10-10 13:13:55 -04:00
m0duspwnens
4193130ed0
reduce salt mine interval to 25 minutes
2023-10-10 13:07:12 -04:00
m0duspwnens
89467adf9c
batch the salt mine update
2023-10-10 13:05:43 -04:00
m0duspwnens
a283e7ea0b
remove checkmine salt engine
2023-10-10 13:00:54 -04:00
Mike Reeves
a54479d603
Merge pull request #11497 from Security-Onion-Solutions/TOoSmOotH-patch-9
...
Update VERSION
2023-10-10 11:07:51 -04:00
Mike Reeves
49ebbf3232
Update VERSION
2023-10-10 11:05:39 -04:00
m0duspwnens
05da5c039c
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-10-10 11:02:19 -04:00
Josh Patterson
f3d0248ec5
Merge pull request #11496 from Security-Onion-Solutions/fix/ping
...
accept icmp on input chain
2023-10-10 10:59:05 -04:00
m0duspwnens
4dc24b22c7
accept icmp on input chain
2023-10-10 10:51:59 -04:00
m0duspwnens
39ea1d317d
add comment
2023-09-29 17:12:14 -04:00
m0duspwnens
827ed7b273
run salt.mine_function state locally and provide pillar info to it
2023-09-29 17:08:42 -04:00
m0duspwnens
8690304dff
change how mine_functions.conf is managed during setup
2023-09-29 16:17:19 -04:00
m0duspwnens
1e327c143c
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-09-29 15:11:06 -04:00
m0duspwnens
ad01be66ea
remove checkmine engine. add x509.get_pem_entries to managers mine_functions. simplify mine update during soup
2023-09-29 14:09:04 -04:00
Jason Ertel
5c7c3fb996
avoid rare false positive when dasbhoard load completes during setup
2023-07-31 16:09:36 -04:00
Jason Ertel
f4907a5b5c
Merge branch '2.4/dev' into kilo
2023-07-28 14:15:14 -04:00
Jason Ertel
a5c4783564
oidc
2023-07-27 18:36:50 -04:00
Jason Ertel
d3e83d154b
Merge branch '2.4/t dev' into kilo
2023-07-27 10:20:22 -04:00
Jason Ertel
aa36e9a785
oidc
2023-07-27 08:40:27 -04:00
Jason Ertel
b712d505f2
update version to use kilo images
2023-07-26 09:21:23 -04:00
Jason Ertel
6d56deb2e4
oidc 1
2023-07-25 08:12:45 -04:00
Jason Ertel
101e2e8ba1
do not redirect to API URLs when not logged in
2023-07-24 17:05:52 -04:00
Jason Ertel
83bff72cd4
Merge branch '2.4/dev' into kilo
2023-07-18 10:49:12 -04:00
Jason Ertel
b24afac0f4
upgrade registry version
2023-07-18 10:48:42 -04:00
Jason Ertel
b129b4ceaa
prepare for alt login
2023-07-14 17:03:20 -04:00