Mike Reeves
aa294a7f41
Merge pull request #12195 from Security-Onion-Solutions/2.4/dev
...
2.4.40
2024-01-17 14:04:27 -05:00
Mike Reeves
049d0b53c2
Merge pull request #12194 from Security-Onion-Solutions/2.4.40
...
2.4.40
2024-01-17 12:02:14 -05:00
Mike Reeves
dff6d299a1
2.4.40
2024-01-17 11:59:27 -05:00
Jason Ertel
38965ccab5
Merge pull request #12192 from Security-Onion-Solutions/needsrestarted
...
Needsrestarted
2024-01-16 18:49:22 -05:00
m0duspwnens
eeb249e00d
look for needs_restarted file
2024-01-16 17:22:09 -05:00
m0duspwnens
dff06cb085
changes for telegraf os.sh
2024-01-16 17:03:36 -05:00
m0duspwnens
8c1d1c95db
check needs_restarting rework
2024-01-16 17:02:27 -05:00
weslambert
790f5171a6
Merge pull request #12176 from Security-Onion-Solutions/fix/otx_pulses_template
...
FIX: OTX pulses template
2024-01-12 16:55:58 -05:00
weslambert
252c51dafb
Change order of names
2024-01-12 16:45:18 -05:00
weslambert
a07e6e1058
OTX pulses
2024-01-12 16:43:33 -05:00
weslambert
3f9678056d
OTX pulses template
2024-01-12 16:42:32 -05:00
weslambert
c895b6a274
Merge pull request #12173 from Security-Onion-Solutions/fix/endpoint_metrics_templates
...
Add endpoint metrics templates
2024-01-12 11:26:09 -05:00
Wes
418f41c7e4
Add SOC configuration for metrics
2024-01-12 15:03:18 +00:00
weslambert
05679e79fc
Merge pull request #12171 from Security-Onion-Solutions/2.4/dev
...
Merge 2.4 dev
2024-01-12 08:50:15 -05:00
Josh Brower
af3aa53612
Merge pull request #12170 from Security-Onion-Solutions/fix/nav
...
Remove old nav layers
2024-01-12 08:48:29 -05:00
Wes
5eae349938
Add endpoint metrics templates
2024-01-12 13:47:35 +00:00
Josh Brower
2f8ce33cf7
formatting
2024-01-12 08:47:09 -05:00
Josh Brower
61b2a76a09
Remove old nav layers-rev2
2024-01-12 08:46:23 -05:00
Josh Brower
b89b7cab59
Remove old nav layers
2024-01-12 08:37:32 -05:00
weslambert
71c5e34e03
Merge pull request #12164 from Security-Onion-Solutions/fix/optional_integration_pillar_merge
...
Make sure optional integration pillar values are merged with defaults
2024-01-11 16:14:46 -05:00
weslambert
880300d644
Move ELASTICFLEETMERGED import under allowed states
2024-01-11 14:58:21 -05:00
weslambert
f5b59cacec
Move ELASTICFLEETMERGED import
2024-01-11 14:56:01 -05:00
weslambert
ea5097f1b4
Add back curly brace
2024-01-11 14:51:01 -05:00
weslambert
cc66daba1a
Make sure optional integration pillar values are merged with defaults
2024-01-11 14:49:39 -05:00
Josh Brower
ea54aafa86
Merge pull request #12161 from Security-Onion-Solutions/fix/kibana-restart
...
Check Kibana API not Web
2024-01-11 12:32:19 -05:00
Josh Brower
03f140161c
Check Kibana API not Web
2024-01-11 12:30:23 -05:00
weslambert
7bdc306ad4
Merge pull request #12160 from Security-Onion-Solutions/feature/additional_integrations_3
...
Additional Supported Integrations #3
2024-01-11 12:26:14 -05:00
weslambert
5e1e685ce0
Exclude Cisco failed_attempts pipeline
2024-01-11 10:52:30 -05:00
Wes
c89d674a92
Add settings for integrations
2024-01-11 14:18:06 +00:00
Wes
9b1ddcacb4
Add additional templates for integrations
2024-01-11 14:00:09 +00:00
Wes
5703023008
Add additional packages
2024-01-11 13:59:38 +00:00
Josh Brower
59fe9a0587
Merge pull request #12156 from Security-Onion-Solutions/fix/navigator
...
Upgrade Navigator and fix Playbook layer
2024-01-11 08:48:34 -05:00
Josh Brower
b8e555e913
Upgrade Navigator and fix Playbook layer
2024-01-10 21:16:59 -05:00
Mike Reeves
16b15c786b
Merge pull request #12155 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2024-01-10 14:44:51 -05:00
Mike Reeves
3e13ea5c7a
Update soup
2024-01-10 14:36:49 -05:00
Josh Brower
9159eab9fd
Merge pull request #12151 from Security-Onion-Solutions/fix/so-playbook-reset
...
Fix reinstall & reset stability
2024-01-10 14:23:53 -05:00
Mike Reeves
0519812866
Merge pull request #12154 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-functions
2024-01-10 14:21:49 -05:00
Mike Reeves
fc2f02c0a0
Update so-functions
2024-01-10 14:19:47 -05:00
Mike Reeves
1e3a00a833
Update so-functions
2024-01-10 14:16:55 -05:00
Josh Brower
f21f0a9a96
Replace sed for so-yaml
2024-01-10 11:15:51 -05:00
Josh Brower
6ff764e6a1
refactor for reinstall stability
2024-01-10 10:22:50 -05:00
Jason Ertel
f5568995ac
Merge pull request #12149 from Security-Onion-Solutions/jertel/logs
...
exempt transient license check errors
2024-01-10 09:12:46 -05:00
Jason Ertel
47eea80d03
exempt transient license check errors
2024-01-10 09:07:17 -05:00
Josh Patterson
0b919ff0fa
Merge pull request #12144 from Security-Onion-Solutions/salt3006.5
...
Salt3006.5
2024-01-09 12:09:36 -05:00
m0duspwnens
c9f2038990
remove outdated comment
2024-01-09 11:36:44 -05:00
Josh Brower
bf05efa59f
Merge pull request #12141 from Security-Onion-Solutions/fix/fleet-reset
...
Fix/fleet reset
2024-01-09 10:38:07 -05:00
Josh Brower
b058bc8c05
Move to non-destructive
2024-01-09 10:22:43 -05:00
Josh Brower
7ddda03ee9
Merge pull request #12138 from Security-Onion-Solutions/fix/fim
...
Fix/fim
2024-01-09 08:26:55 -05:00
Josh Brower
5513e74807
comma
2024-01-09 08:12:33 -05:00
Josh Brower
31ee365a91
Fixup FIM events
2024-01-09 08:11:05 -05:00
m0duspwnens
f46ac6b9d7
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.5
2024-01-08 14:02:02 -05:00
m0duspwnens
31f314504e
salt 3006.5
2024-01-08 14:01:40 -05:00
Mike Reeves
0d76ddd49f
Merge pull request #12120 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update so-raid-status for SM based appliances
2024-01-05 10:27:21 -05:00
Mike Reeves
b0447a9af5
Update so-raid-status for SM based appliances
2024-01-05 09:28:04 -05:00
Josh Patterson
ef6eafeff1
Merge pull request #12118 from Security-Onion-Solutions/startupstates
...
enable startup_states: highstate on managers during setup and not wit…
2024-01-04 17:37:27 -05:00
m0duspwnens
ccfdafea0a
enable startup_states: highstate on managers during setup and not with salt
2024-01-04 16:24:48 -05:00
Josh Patterson
93cdac592e
Merge pull request #12116 from Security-Onion-Solutions/issue/12033
...
Issue/12033
2024-01-04 09:54:29 -05:00
m0duspwnens
2eaf0e812a
declare NEW_LIST outside jinja logic
2024-01-03 16:49:28 -05:00
Jorge Reyes
cab7c9d573
Merge pull request #12109 from Security-Onion-Solutions/reyesj2-patch-1
...
Add brasero to packages list for SOD
2024-01-03 14:45:07 -05:00
Jorge Reyes
8c792a8cfa
Add brasero to packages list for SOD
2024-01-03 12:17:57 -05:00
m0duspwnens
c091a0845c
allow user to disable elastic agent sending to manager
2024-01-03 11:48:16 -05:00
Mike Reeves
cf23723c54
Merge pull request #12102 from Security-Onion-Solutions/2.4/main
...
2.4/main
2024-01-02 11:18:07 -05:00
Mike Reeves
30bc02178a
Merge pull request #12100 from Security-Onion-Solutions/mkrtemp
...
2.4.30 hotfix
2024-01-02 11:16:13 -05:00
Mike Reeves
84e8013e46
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-01-02 10:31:14 -05:00
Mike Reeves
80ec4cecec
Merge pull request #12099 from Security-Onion-Solutions/2.4.30hf5
...
2.4.30 hotfix
2024-01-02 10:29:45 -05:00
Mike Reeves
82482d309a
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-01-02 10:09:13 -05:00
Mike Reeves
d437a2856a
2.4.30 hotfix
2024-01-02 09:48:45 -05:00
Josh Patterson
f0b44ad56c
Merge pull request #12095 from Security-Onion-Solutions/startupstates
...
Change salt-minion startup_states
2024-01-02 09:18:21 -05:00
Jason Ertel
cffc3353bc
Merge pull request #12090 from Security-Onion-Solutions/jertel/lasths
...
show last highstate date/time on grid metrics screen; expose maxUploa…
2023-12-29 14:51:09 -05:00
Jason Ertel
e075d07f5c
show last highstate date/time on grid metrics screen; expose maxUploadSize and staleMetricsMs settings on config screen
2023-12-29 11:38:42 -05:00
Jason Ertel
fe8f57c43b
Merge pull request #12071 from Security-Onion-Solutions/jertel/influxerr
...
exclude transient influxdb error
2023-12-22 07:22:45 -05:00
Jason Ertel
3456de3a30
exclude transient influxdb error
2023-12-22 07:16:45 -05:00
Jason Ertel
14767dd8b5
Merge pull request #12067 from Security-Onion-Solutions/jertel/fixcurator
...
only run the file.absent state if there are files to delete
2023-12-21 09:41:46 -05:00
Jason Ertel
8189f46a03
only run the file.absent state if there are files to delete
2023-12-21 09:36:47 -05:00
weslambert
cfb5c1c9d2
Merge pull request #12063 from Security-Onion-Solutions/fix/curator_log_check
...
Ignore Curator logs
2023-12-20 17:47:17 -05:00
weslambert
244968ce23
Remove unnecessary blank lines
2023-12-20 17:30:15 -05:00
weslambert
65f89b22b2
Ignore Curator logs
2023-12-20 17:28:55 -05:00
weslambert
7684aadb87
Merge pull request #12062 from Security-Onion-Solutions/fix/curator_remove
...
Curator Remove Changes
2023-12-20 15:16:47 -05:00
Wes
188744357f
Remove post since function doesn't exist
2023-12-20 19:14:14 +00:00
Wes
4baf4657f6
Curator cleanup
2023-12-20 19:10:22 +00:00
Wes
1006710226
Change Curator disable config
2023-12-20 18:26:27 +00:00
weslambert
cd661027a6
Remove post for 2.4.40
2023-12-20 12:23:20 -05:00
m0duspwnens
28fdf15304
remove comment
2023-12-19 16:37:32 -05:00
Mike Reeves
90edf7e8f1
Merge pull request #12053 from Security-Onion-Solutions/2.4/main
...
2.4/main
2023-12-19 14:40:21 -05:00
Mike Reeves
552e4c0d1c
Merge pull request #12050 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-12-19 14:37:35 -05:00
weslambert
ba2c51bee2
Merge pull request #12052 from Security-Onion-Solutions/fix/analyzer_images
...
Fix analyzer images
2023-12-19 14:30:19 -05:00
m0duspwnens
7b9ac7ae6d
remove checkin_at_boot function
2023-12-19 14:05:19 -05:00
Wes
62708ac97d
Add new image
2023-12-19 18:58:17 +00:00
Wes
f8fdc6d14e
Remove old image
2023-12-19 18:57:54 +00:00
Mike Reeves
72fbf386eb
Merge pull request #12051 from Security-Onion-Solutions/jertel/hotfixm
...
Jertel/hotfixm
2023-12-19 13:48:21 -05:00
Wes
15773bae34
Fix analyzer image links
2023-12-19 18:42:59 +00:00
Jason Ertel
ce8a774129
Merge branch '2.4/main' into jertel/hotfixm
2023-12-19 13:42:13 -05:00
Wes
c06de33318
Test EchoTrail image
2023-12-19 18:36:55 +00:00
Wes
41dc9df7cd
Add images for analyzers
2023-12-19 18:35:10 +00:00
Mike Reeves
cb956fb399
Merge pull request #12049 from Security-Onion-Solutions/2.4.30hf4
...
2.4.30 hotfix
2023-12-19 13:10:51 -05:00
Mike Reeves
5c34cdd943
2.4.30 hotfix
2023-12-19 13:07:25 -05:00
Doug Burks
5e8613f38b
Merge pull request #12048 from Security-Onion-Solutions/2.4/improve-filterlog-parser
...
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-19 12:57:37 -05:00
weslambert
69472e70b4
Merge pull request #12003 from HoangLongVu/2.4/dev
...
2.4/dev Analyzers for Threatfox, MalwareBazaar, Echotrail, Elasticsearch
2023-12-19 12:09:16 -05:00
m0duspwnens
090f3a3e02
only run if in file
2023-12-19 12:08:17 -05:00
Wes
85242651b2
Add Sublime image to assets and change link
2023-12-19 15:49:57 +00:00
Jason Ertel
80cd9920b2
Merge pull request #12047 from Security-Onion-Solutions/jertel/eslogerror
...
exclude log false positives
2023-12-19 10:49:42 -05:00
Jason Ertel
ca21e32d83
log false positives
2023-12-19 10:47:39 -05:00
Wes
6ab12ceec4
Add Elasticsearch image to assets and change link
2023-12-19 15:46:02 +00:00
Wes
bfcf7d4668
Add EchoTrail image to assets and change link
2023-12-19 15:42:23 +00:00
Wes
4a23832267
Don't require advanced options for required values
2023-12-19 15:14:33 +00:00
m0duspwnens
b3be999aea
dont enable startup_states during setup. use salt to add it
2023-12-19 09:00:32 -05:00
Doug Burks
ab5de4c104
update soc defaults.yaml
2023-12-19 07:27:07 -05:00
Wes
614589153b
Update Malwarebazaar test and comply with flake8
2023-12-19 02:57:35 +00:00
Ryan Hoang
5e715036fb
Update malwarebazaar_test.py
2023-12-18 19:54:14 -05:00
Ryan Hoang
748a67314f
Update malwarebazaar_test.py
2023-12-18 19:27:13 -05:00
Ryan Hoang
a561f8c783
Update malwarebazaar_test.py Removed Whitespace
2023-12-18 19:18:26 -05:00
Elijah Gibson
fb5ee6b9e9
Flake8 linting + isInJson tail recursion update
2023-12-18 15:58:16 -05:00
Elijah Gibson
7d6f8d922b
Update malwarebazaar_test.py
...
Flake8 linting
2023-12-18 15:57:41 -05:00
Elijah Gibson
f86adf8053
Merge branch 'Security-Onion-Solutions:2.4/dev' into 2.4/dev
2023-12-18 15:57:00 -05:00
Wes
8f6b1a07b7
Don't use soup for removing Curator files
2023-12-18 20:54:24 +00:00
Wes
6c92672566
Remove Curator configuration and scripts
2023-12-18 20:53:56 +00:00
Wes
aba5893965
Add disabled state for Curator
2023-12-18 20:50:49 +00:00
Josh Patterson
866c9988a0
Merge pull request #12037 from Security-Onion-Solutions/fix/receiver
...
Fix receivers
https://github.com/Security-Onion-Solutions/securityonion/issues/12038
2023-12-18 13:56:33 -05:00
Josh Patterson
f032ff40a2
Merge branch '2.4/dev' into fix/receiver
2023-12-18 13:55:23 -05:00
Semphorin
03421c1bcd
added isInJson tests
2023-12-18 13:54:38 -05:00
Doug Burks
4d8661d2e0
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-18 13:38:04 -05:00
Doug Burks
6a1073b616
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-18 12:57:40 -05:00
Wes
6a4e05d60f
Remove control characters
2023-12-15 20:53:51 +00:00
Wes
981f3642a0
Update tests
2023-12-15 20:53:19 +00:00
m0duspwnens
33a9ac5701
use logstash nodes for logstash extra_hosts
2023-12-15 15:42:49 -05:00
Wes
020472085b
ThreatFox test
2023-12-15 15:16:44 +00:00
Wes
8aaeee20b9
Fix import
2023-12-15 14:40:25 +00:00
Wes
e32de6893b
Remove control characters
2023-12-15 14:27:27 +00:00
Wes
f05eb742dd
Fix patch
2023-12-15 14:26:33 +00:00
Wes
cd3a661dd6
Set malwarebazaar.py to be executable
2023-12-15 14:17:33 +00:00
weslambert
55c957170d
Reduce complexity
2023-12-15 09:00:31 -05:00
Jackson
d41daa37f1
malwarebazaar
2023-12-15 03:00:43 -05:00
Jackson
b59896bb47
ThreatFox and EchoTrail
2023-12-15 02:47:54 -05:00
Jackson
c59a6516fc
fix Elasticsearch lint
2023-12-15 02:34:45 -05:00
Doug Burks
88684a6c19
Merge pull request #12023 from Security-Onion-Solutions/2.4/fix-firewall-queries
...
FIX: Update dashboard and hunt query for firewall logs #12021
2023-12-14 14:56:42 -05:00
weslambert
d0d671a828
Merge pull request #12020 from Security-Onion-Solutions/fix/integration_force
...
Add force option to integrations
2023-12-14 13:44:32 -05:00
Doug Burks
8779fb8cbc
Update defaults.yaml
2023-12-14 13:30:52 -05:00
Doug Burks
042e5ae9f0
https://github.com/Security-Onion-Solutions/securityonion/issues/12021
2023-12-14 12:46:28 -05:00
Josh Patterson
45f50cc121
Merge pull request #12019 from Security-Onion-Solutions/fix/extrahosts
...
fix extra_hosts
2023-12-14 12:03:07 -05:00
Wes
22fcccef1c
Add force option
2023-12-14 16:53:19 +00:00
Jackson
977081b6e7
update Readme.md
2023-12-14 10:37:04 -05:00
m0duspwnens
3dbf97944d
fix extra_hosts. https://github.com/Security-Onion-Solutions/securityonion/issues/12015
2023-12-14 10:26:29 -05:00
m0duspwnens
03b2a7d2de
change 9805 pipeline to send to self. fix extra_hosts for logstash
2023-12-14 10:01:03 -05:00
Jason Ertel
395da2cca0
Merge pull request #12012 from Security-Onion-Solutions/jertel/eslogerror
...
more log false alarms
2023-12-14 08:59:12 -05:00
Jason Ertel
997d323763
more log false alarms
2023-12-14 08:55:18 -05:00
Elijah Gibson
d5edf57ccb
Update elasticsearch.py
2023-12-13 23:04:44 -05:00
Elijah Gibson
94b9089b79
Update elasticsearch.json
2023-12-13 23:03:42 -05:00
Jackson
81e4fe78e7
pushing everything at once
2023-12-13 13:45:48 -05:00
weslambert
5d3f2298b6
Merge pull request #12000 from Security-Onion-Solutions/feature/additional_integrations
...
Additional Integrations #2
2023-12-13 13:23:34 -05:00
Doug Burks
b17e4006a1
Merge pull request #12001 from Security-Onion-Solutions/2.4/update-clear-scripts
...
FIX: Update clear scripts #11991
2023-12-13 12:01:11 -05:00
weslambert
8cf5d9c1a6
Annotations
2023-12-13 11:55:40 -05:00
weslambert
cdac2bfa16
Add Anomali, Cybersixgill, Snort, and ThreatQuotient
2023-12-13 11:03:25 -05:00
weslambert
b0a69d30c9
Add Anomali, Cybersixgill, Snort, and ThreatQuotient packages
2023-12-13 10:44:03 -05:00
Jason Ertel
196d59869a
Merge pull request #11998 from Security-Onion-Solutions/kilo
...
upgrade cla action
2023-12-13 10:18:39 -05:00
Jason Ertel
c0ab8f24e9
upgrade cla action
2023-12-13 10:10:51 -05:00
Jason Ertel
bd26a52227
upgrade cla action
2023-12-13 10:10:23 -05:00
Jason Ertel
03279732b7
upgrade cla action
2023-12-13 10:09:36 -05:00
Doug Burks
2c4d0a0d71
Update so-elastic-fleet-reset
2023-12-12 16:37:50 -05:00
Doug Burks
d49d13289e
Update so-elastic-clear
2023-12-12 16:37:06 -05:00
Doug Burks
aaf60bea87
Update so-nsm-clear
2023-12-12 16:30:17 -05:00
weslambert
e95932f28c
Merge pull request #11990 from Security-Onion-Solutions/fix/remove_curator
...
Remove Curator
2023-12-12 12:31:16 -05:00
Wes
bbe091fa14
Fix accidental change
2023-12-12 15:08:47 +00:00
Wes
54c3167b10
Delete data streams when necessary
2023-12-12 05:25:50 +00:00
Wes
b1721b6467
Fix directory
2023-12-11 21:43:25 +00:00
Jason Ertel
214404265a
Merge pull request #11981 from Security-Onion-Solutions/jertel/importlogs
...
fix import stats
2023-12-11 14:54:29 -05:00
Jason Ertel
25c39540c8
fix import stats
2023-12-11 14:48:46 -05:00
Wes
f7373ed79c
Stop Curator, remove scripts and status
2023-12-11 19:20:52 +00:00
Wes
d203aec44a
Remove Curator
2023-12-08 19:37:06 +00:00
Jason Ertel
be8ed1e1d8
Merge pull request #11970 from Security-Onion-Solutions/jertel/hfm
...
grid page enhancements
2023-12-08 09:56:39 -05:00
Jason Ertel
a732985351
grid page enhancements
2023-12-08 08:38:42 -05:00
Jason Ertel
98947f3906
grid page enhancements
2023-12-08 08:37:42 -05:00
weslambert
b80d7fd610
Merge pull request #11967 from Security-Onion-Solutions/fix/close_remove
...
Remove Curator close configuration
2023-12-07 15:05:38 -05:00
Wes
849e9e14ad
Change soup to remove delete actions and run post_to_2.4.40
2023-12-07 16:49:44 +00:00
Wes
0ebc8c7beb
Change path
2023-12-07 15:17:51 +00:00
Wes
e0801282eb
Remove files
2023-12-07 14:07:26 +00:00
Wes
bdf4b2c68d
Remove settings
2023-12-07 14:03:45 +00:00
Wes
e49fc0dd27
Remove more settings
2023-12-07 14:03:09 +00:00
Wes
f52da4a933
Remove close settings and cron
2023-12-07 13:58:39 +00:00
Wes
f38758a9c7
Remove close scripts
2023-12-07 13:52:25 +00:00
Wes
1ac3a2d2f1
Remove delete files and allow deletion of indices managed by ILM
2023-12-07 13:51:24 +00:00
Wes
965ced94c4
Remove close files
2023-12-07 13:48:08 +00:00
Doug Burks
bc3634b13d
Merge pull request #11960 from Security-Onion-Solutions/2.4/fix-config-links
...
FIX: Documentation links under SOC - Administration - Configuration need updating #11828
2023-12-06 16:04:11 -05:00
Doug Burks
5c50060857
add description for soc_patch.yaml
2023-12-06 15:51:00 -05:00
Doug Burks
00fa75869b
add description for http_x_skin
2023-12-06 15:44:36 -05:00
Doug Burks
ab0e6f9bec
update broken help links in SOC Config
2023-12-06 14:35:51 -05:00
Doug Burks
213cdb479d
Update soc_manager.yaml
2023-12-06 14:19:15 -05:00
Mike Reeves
8da96e93c8
Merge pull request #11957 from Security-Onion-Solutions/mergeback
...
Merge Main into Dev
2023-12-06 13:40:30 -05:00
Mike Reeves
0160cae7d7
Merge branch '2.4/dev' into mergeback
2023-12-06 13:38:53 -05:00
Mike Reeves
d7bf52de76
Merge pull request #11918 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-12-06 13:31:33 -05:00
weslambert
fea5a3026d
Merge pull request #11955 from Security-Onion-Solutions/fix/sublime_analyzer_documentation
...
Sublime Analyzer Documentation
2023-12-06 13:27:03 -05:00
weslambert
7f21bee0d4
Add README
2023-12-06 13:14:17 -05:00
weslambert
ade3a46a9a
Add LocalFile link
2023-12-06 12:58:44 -05:00
weslambert
e6a2e49d37
Add Sublime Platform
2023-12-06 12:57:59 -05:00
weslambert
1438913f6a
Merge pull request #11954 from Security-Onion-Solutions/fix/sublime_analyzer_indentation
...
Fix indentation for rule_results
2023-12-06 12:50:44 -05:00
Wes
51fa4922b9
Fix indentation for rule_results
2023-12-06 17:37:07 +00:00
Mike Reeves
b878728882
Merge pull request #11951 from Security-Onion-Solutions/2.4.30hf3
...
2.4.30 hotfix
2023-12-06 08:36:13 -05:00
Mike Reeves
386e9214fc
2.4.30 hotfix
2023-12-06 08:34:46 -05:00
weslambert
4becf3e20f
Merge pull request #11950 from Security-Onion-Solutions/fix/eml_observable
...
Add eml observable type
2023-12-06 08:30:27 -05:00
weslambert
0334ef9677
Add eml observable type
2023-12-05 19:10:16 -05:00
weslambert
0537e1b3f6
Merge pull request #11945 from Security-Onion-Solutions/feature/sublime_platform_analyzer
...
Sublime Platform Analyzer
2023-12-05 16:51:03 -05:00
Wes
6fff05b444
Remove pytest.ini
2023-12-05 20:14:17 +00:00
Wes
01a37df7fc
Add extra line
2023-12-05 20:02:12 +00:00
Wes
b3e78c9cc3
Update live flow option
2023-12-05 19:55:23 +00:00
Wes
d871b61150
Change author
2023-12-05 18:36:25 +00:00
Wes
b2536a64d8
Remove extra space
2023-12-05 18:33:00 +00:00
Wes
3d1eecfad6
Add Sublime Platform analyzer
2023-12-05 18:31:50 +00:00
Mike Reeves
8eaa07a186
Merge pull request #11942 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2023-12-05 11:26:42 -05:00
Mike Reeves
9446b750c0
Update soup
2023-12-05 11:25:25 -05:00
Mike Reeves
fdd4173632
Update soup
2023-12-05 11:20:56 -05:00
Mike Reeves
b7227e15eb
Merge pull request #11939 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2023-12-05 10:26:56 -05:00
Mike Reeves
90d9e5b927
Update soup
2023-12-05 10:24:31 -05:00
Mike Reeves
802bf9ce27
Merge pull request #11931 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-12-04 14:00:40 -05:00
Mike Reeves
0b6ba6d2f2
Update soup
2023-12-04 13:51:12 -05:00
Mike Reeves
55a8b1064d
Update soup
2023-12-04 13:36:04 -05:00
Josh Patterson
11a3e12e94
Merge pull request #11929 from Security-Onion-Solutions/hf_soup
...
avoid exiting salt when ca state applied in post for 2.4.30
2023-12-04 11:46:27 -05:00
m0duspwnens
38868af08a
avoid exiting salt when ca state applied in post for 2.4.30
2023-12-04 10:11:38 -05:00
Josh Patterson
ace5dff351
Merge pull request #11923 from Security-Onion-Solutions/hf_soup
...
move wait_for_salt_minion for hotfix
2023-12-01 15:37:35 -05:00
m0duspwnens
265cde5296
move wait_for_salt_minion for hotfix
2023-12-01 15:31:15 -05:00
weslambert
55052c4811
Merge pull request #11919 from Security-Onion-Solutions/fix/remove_curator_changes
...
Remove Curator Changes
2023-12-01 11:15:23 -05:00
Wes
e36044e164
Remove close changes
2023-12-01 16:10:56 +00:00
Wes
6fa4a69753
Remove action changes
2023-12-01 16:10:07 +00:00
Doug Burks
4fc3c852a1
Merge pull request #11890 from chateaulav/chateaulav-import-evtx-logs-11889
...
Update import-evtx-logs.json
2023-11-30 13:57:59 -05:00
weslambert
32b03f514e
Merge pull request #11907 from Security-Onion-Solutions/fix/curator_close
...
Curator close fixes
2023-11-30 11:05:49 -05:00
Wes
a605c5c62c
Ensure indices managed by ILM can be managed by Curator
2023-11-29 22:13:20 +00:00
Wes
2368e8b793
Fix action file names
2023-11-29 22:06:11 +00:00
weslambert
317b6cb614
Merge pull request #11902 from Security-Onion-Solutions/fix/hotfix_version
...
Update HOTFIX
2023-11-29 17:03:59 -05:00
weslambert
a6d20bdc71
Update HOTFIX
2023-11-29 17:01:29 -05:00
Doug Burks
93fb10de86
Merge pull request #11897 from Security-Onion-Solutions/2.4/nids-rule-reference
...
FIX: Update NIDS rule.reference in common.nids pipeline #11846
2023-11-29 12:19:12 -05:00
weslambert
1a4d009b7f
Merge pull request #11896 from Security-Onion-Solutions/feature/elastic_certificate_fingerprints
...
Add certificate fingerprints
2023-11-29 12:07:50 -05:00
weslambert
9d63a47792
Certificate hash
2023-11-29 12:01:43 -05:00
weslambert
7001e90667
Client and server fingerprints
2023-11-29 12:00:46 -05:00
weslambert
a0573212c0
Merge pull request #11891 from Security-Onion-Solutions/fix/elastic_ignore_analyzer
...
Ignore analyzer log
2023-11-29 10:05:01 -05:00
weslambert
5f79644aef
Ignore analyzer log
2023-11-29 10:02:13 -05:00
Doug Burks
0603e96c08
FIX: Update NIDS rule.reference in common.nids pipeline #11846
2023-11-29 09:46:11 -05:00
Jonathan Race
ece3c367b5
Update import-evtx-logs.json
...
version updates to match 2.4 release pipelines
2023-11-29 09:20:37 -05:00
Jason Ertel
8953ffcc49
Merge pull request #11855 from Security-Onion-Solutions/jertel/hfm
...
Jertel/hfm
2023-11-21 16:43:28 -05:00
Jason Ertel
9ee3423b32
Merge branch '2.4/dev' into jertel/hfm
2023-11-21 16:42:50 -05:00
Jason Ertel
7d759a99fe
remove hotfix
2023-11-21 16:40:54 -05:00
Mike Reeves
d3802c1668
Merge pull request #11854 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix/2.4.30
2023-11-21 16:39:40 -05:00
Mike Reeves
874618d512
Merge pull request #11853 from Security-Onion-Solutions/2.4.30hf2
...
2.4.30 hotfix
2023-11-21 14:32:53 -05:00
Mike Reeves
fa9032b323
2.4.30 hotfix
2023-11-21 14:28:23 -05:00
Mike Reeves
17942676c6
Merge pull request #11844 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soup
2023-11-21 10:32:24 -05:00
Mike Reeves
458c6de39d
Update soup
2023-11-21 10:30:21 -05:00
Mike Reeves
a39f696a34
Merge pull request #11843 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2023-11-21 10:19:21 -05:00
Mike Reeves
9aa193af3b
Update soup
2023-11-21 10:18:02 -05:00
Mike Reeves
3f1f256748
Merge pull request #11842 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2023-11-21 10:01:13 -05:00
Mike Reeves
c78ea0183f
Update HOTFIX
2023-11-21 09:59:51 -05:00
Mike Reeves
e9417dd437
Merge pull request #11841 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-11-21 09:56:45 -05:00
Mike Reeves
14b5aa476e
Update soup
2023-11-21 09:55:44 -05:00
Jason Ertel
861e850f9a
Merge pull request #11835 from Security-Onion-Solutions/jertel/yaml
...
add support for nested keys
2023-11-20 16:33:17 -05:00
Jason Ertel
6356a0bf95
add support for nested keys
2023-11-20 16:18:30 -05:00
Jason Ertel
f31e288005
Merge pull request #11832 from Security-Onion-Solutions/jertel/hfm
...
Merge hoftix back to 2.4/dev
2023-11-20 15:32:40 -05:00
Jason Ertel
b2ea7138f3
remove hotfix
2023-11-20 15:28:56 -05:00
Jason Ertel
f29a91ea4c
Merge branch '2.4/main' into jertel/hfm
2023-11-20 15:28:27 -05:00
Mike Reeves
4b0033c60a
Merge pull request #11827 from Security-Onion-Solutions/hotfix/2.4.30
...
Hotfix 2.4.30
2023-11-20 15:26:16 -05:00
Mike Reeves
c20004c210
Merge pull request #11826 from Security-Onion-Solutions/2.4.30hf
...
2.4.30 hotfix
2023-11-20 11:35:11 -05:00
Mike Reeves
45dc1ce036
2.4.30 hotfix
2023-11-20 11:32:21 -05:00
Jason Ertel
0cc10fbf80
Merge pull request #11823 from Security-Onion-Solutions/jertel/igwarn
...
ignore libwbclient upgrade warning
2023-11-19 19:46:19 -05:00
Jason Ertel
e71ee97717
ignore libwbclient upgrade warning
2023-11-19 19:03:23 -05:00
Mike Reeves
77d0a7277a
Merge pull request #11818 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-11-17 17:07:54 -05:00
Mike Reeves
2ae87de409
Merge branch 'hotfix/2.4.30' into TOoSmOotH-patch-2
2023-11-17 17:05:11 -05:00
Josh Brower
a69a65c44f
Merge pull request #11819 from Security-Onion-Solutions/hftesting
...
Remove state file
2023-11-17 16:54:08 -05:00
Mike Reeves
d89beefc8c
Update soup
2023-11-17 16:53:11 -05:00
Josh Brower
9c371fc374
Remove state file
2023-11-17 16:52:34 -05:00
Mike Reeves
4fb9cce41c
Update signing_policies.conf
2023-11-17 16:38:50 -05:00
Mike Reeves
e226efa799
Update soup
2023-11-17 16:35:12 -05:00
Josh Brower
82a41894f3
Merge pull request #11817 from Security-Onion-Solutions/hftesting
...
Hftesting
2023-11-17 13:12:06 -05:00
Josh Brower
7aadc3851f
Remove state file
2023-11-17 13:08:15 -05:00
Josh Brower
ca1498fca1
Dont update Defend Integration
2023-11-17 12:19:22 -05:00
Josh Brower
15fc4f2655
Merge pull request #11815 from Security-Onion-Solutions/hftesting
...
use updated code
2023-11-17 11:23:45 -05:00
Josh Brower
089a111ae8
use updated code
2023-11-17 11:20:13 -05:00
Josh Brower
33bd04b797
Merge pull request #11811 from Security-Onion-Solutions/hftesting
...
Move API check logic
2023-11-17 06:02:26 -05:00
Josh Brower
5920a14478
Move API check logic
2023-11-16 20:34:01 -05:00
Jason Ertel
67f116daed
Merge pull request #11809 from Security-Onion-Solutions/jertel/srtmp
...
improve timing of responses
2023-11-16 16:00:27 -05:00
Jason Ertel
c09e8f0d71
improve timing of responses
2023-11-16 15:58:48 -05:00
Jason Ertel
de99cda766
improve timing of responses
2023-11-16 15:51:17 -05:00
Josh Brower
3ede19a106
Merge pull request #11808 from Security-Onion-Solutions/2.4/defendhotfix2
...
Update HOTFIX
2023-11-16 15:25:24 -05:00
weslambert
b6e2df45c7
Update HOTFIX
2023-11-16 14:48:00 -05:00
Josh Brower
af98c8e2da
Merge pull request #11805 from Security-Onion-Solutions/2.4/defendhotfix2
...
.30 hotfix
2023-11-16 11:42:49 -05:00
Josh Brower
6b8e48c973
Remove highstate
2023-11-16 11:41:20 -05:00
Josh Brower
109ee55d8c
Add to pre for .30 soup
2023-11-16 11:37:38 -05:00
Josh Brower
ff8cd194f1
Make sure kibana API is up
2023-11-16 11:21:34 -05:00
Josh Brower
d5dd0d88ed
.30 hotfix
2023-11-16 10:58:23 -05:00
weslambert
46c5bf40e0
Merge pull request #11804 from Security-Onion-Solutions/fix/kibana_corrupt_integration
...
Discard corrupt integration
2023-11-16 10:49:39 -05:00
Wes
3ed7b36865
Discard corrupt integration
2023-11-16 15:45:38 +00:00
Jason Ertel
85649da2cb
Merge pull request #11792 from Security-Onion-Solutions/jertel/auto
...
avoid startup error
2023-11-14 15:42:26 -05:00
Jason Ertel
f7fa4d05fb
avoid startup error
2023-11-14 15:40:52 -05:00
Doug Burks
96b456cd76
Merge pull request #11785 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Hunt HTTP EXE query #11784
2023-11-14 10:03:46 -05:00
Doug Burks
4666b993e5
Update defaults.yaml
2023-11-14 09:58:45 -05:00
Mike Reeves
4fa6b265a0
Merge pull request #11778 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-11-13 15:38:53 -05:00
Mike Reeves
567e19e5d7
Update VERSION
2023-11-13 15:38:23 -05:00
Mike Reeves
f036623d55
Merge pull request #11777 from Security-Onion-Solutions/2.4/dev
...
2.4.30
2023-11-13 15:27:24 -05:00
Mike Reeves
1204ce96f3
Merge pull request #11776 from Security-Onion-Solutions/2.4.30
...
2.4.30
2023-11-13 13:13:29 -05:00
Mike Reeves
bc178a9784
2.4.30
2023-11-13 13:11:49 -05:00
Mike Reeves
c338daabce
Merge pull request #11769 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Update soup
2023-11-13 08:51:40 -05:00
Mike Reeves
fe7af49a82
Update soup
2023-11-13 08:37:46 -05:00
weslambert
aeb09b16db
Merge pull request #11760 from Security-Onion-Solutions/fix/elastic_packages
...
Add Elastic Agent package and upgrade packages when elasticfleet.packages list changes
2023-11-10 10:20:17 -05:00
weslambert
583ec5176e
Add package check
2023-11-10 10:15:52 -05:00
weslambert
4bb1dabb89
Add elastic_agent
2023-11-10 10:14:59 -05:00
Josh Brower
89c3d45abe
Merge pull request #11751 from Security-Onion-Solutions/2.4/fleetresetfix2
...
Remove unneeded datastreams
2023-11-09 15:04:02 -05:00
Josh Brower
551f7831de
Add more clarity to message
2023-11-09 15:01:56 -05:00
Josh Brower
193c9d202e
Remove unneeded datastreams
2023-11-09 14:30:00 -05:00
Josh Brower
b5912fc1e4
Merge pull request #11750 from Security-Onion-Solutions/2.4/defendpolicy
...
Upgrade Defend Integration policy
2023-11-09 12:48:57 -05:00
Josh Brower
33f538b73e
Upgrade Defend Integration policy
2023-11-09 11:52:06 -05:00
Josh Brower
d3ea5def69
Merge pull request #11747 from Security-Onion-Solutions/2.4/resetscriptfix
...
remove state file
2023-11-09 09:12:52 -05:00
Josh Brower
d1b6ef411b
remove state file
2023-11-09 09:01:57 -05:00
Jason Ertel
8ca825b9a1
Merge pull request #11745 from Security-Onion-Solutions/jertel/yaml
...
re-add source pkgs from accidental commit
2023-11-09 07:19:22 -05:00
Jason Ertel
209e237d0d
re-add source pkgs from accidental commit
2023-11-09 00:34:52 -05:00
Jason Ertel
325dceb01b
Merge pull request #11743 from Security-Onion-Solutions/fix/elastic_template_check
...
Additional fixes for index template check
2023-11-09 00:15:14 -05:00
weslambert
02baa18502
Add metrics
2023-11-08 22:41:24 -05:00
Jason Ertel
268dc03131
Merge pull request #11742 from Security-Onion-Solutions/jertel/yaml
...
add yaml helper script; refactor python testing
2023-11-08 21:06:04 -05:00
weslambert
e39edab00d
Exclude osquery and display failed name
2023-11-08 20:55:08 -05:00
weslambert
acb6e84248
Don't load index template if component template doesn't exist
2023-11-08 20:34:08 -05:00
Jason Ertel
9231c8d2f2
replace reset sed with new script
2023-11-08 19:17:32 -05:00
Jason Ertel
bc044fa2d5
more coverage
2023-11-08 18:42:06 -05:00
Jason Ertel
84b815c2ef
add yaml helper script; refactor python testing
2023-11-08 18:30:05 -05:00
Jason Ertel
1ab44a40d3
add yaml helper script; refactor python testing
2023-11-08 18:29:06 -05:00
Jason Ertel
9317e51f20
add yaml helper script; refactor python testing
2023-11-08 18:26:37 -05:00
Jason Ertel
33a8ef1568
add yaml helper script; refactor python testing
2023-11-08 18:24:23 -05:00
Josh Patterson
01e846ba22
Merge pull request #11741 from Security-Onion-Solutions/issue/11738
...
remove comments from BPFs
2023-11-08 15:25:02 -05:00
weslambert
9df3a8fc18
Merge pull request #11740 from Security-Onion-Solutions/fix/elastic_templates
...
Remove template files
2023-11-08 15:20:01 -05:00
weslambert
36098e6314
Remove template files
2023-11-08 14:32:58 -05:00
Jason Ertel
32079a7bce
Merge pull request #11734 from Security-Onion-Solutions/fix/elastic_scripts
...
Improve error handling and add retry logic
2023-11-08 12:19:00 -05:00
Jason Ertel
3701c1d847
ignore retry logging
2023-11-08 11:50:56 -05:00
m0duspwnens
f46aef1611
remove comments from BPFs
2023-11-08 11:23:19 -05:00
Jason Ertel
d256be3eb3
allow template loads to partially succeed only on the initial attempt
2023-11-08 10:32:11 -05:00
Wes
653fda124f
Check expected with retry
2023-11-08 13:02:17 +00:00
Wes
b46e86c39b
Extend index template loading to 60 attempts and a total of ~5 minutes
2023-11-08 02:29:09 +00:00
Wes
de9f9549af
Extend template loading to 24 attempts and a total of ~2 minutes
2023-11-07 23:55:03 +00:00
weslambert
749e22e4b9
Fix if statement
2023-11-07 17:29:38 -05:00
weslambert
69ec1987af
Fix if statement
2023-11-07 17:28:37 -05:00
Wes
570624da7e
Remove RETURN_CODE
2023-11-07 21:09:29 +00:00
Wes
7772657b4b
Remove RETURN_CODE
2023-11-07 21:06:35 +00:00
Jason Ertel
6d97667634
Merge branch '2.4/dev' into kilo
2023-11-07 15:59:52 -05:00
Wes
1676c84f9c
Use the retry function so-elasticsearch-query
2023-11-07 19:56:50 +00:00
Jason Ertel
e665899e4d
Merge pull request #11735 from Security-Onion-Solutions/fix/elastic_agent_template
...
Change pipeline to 1.13.1
2023-11-07 14:11:47 -05:00
weslambert
1dcca0bfd3
Change pipeline to 1.13.1
2023-11-07 12:17:51 -05:00
Wes
0b4a246ddb
State file changes and retry logic
2023-11-07 16:44:42 +00:00
weslambert
f97dc70fcb
Merge pull request #11732 from Security-Onion-Solutions/fix/elastic_agent_template
...
Change pipeline to 1.8.0
2023-11-07 09:08:25 -05:00
weslambert
cce80eb2fb
Change pipeline to 1.8.0
2023-11-07 09:02:48 -05:00
Jason Ertel
2f95512199
Merge branch '2.4/dev' into kilo
2023-11-06 11:27:58 -05:00
Jason Ertel
b008661b6b
Merge pull request #11726 from Security-Onion-Solutions/jertel/auto
...
improve verbosity of setup logs
2023-11-06 11:27:33 -05:00
Jason Ertel
b99c7ce76e
improve verbosity of setup logs
2023-11-06 11:22:35 -05:00
Wes
c30a0d5b5b
Better error handling and state file management
2023-11-06 14:29:01 +00:00
Wes
74eda68d84
Exit if unable to communicate with Elasticsearch
2023-11-06 13:16:35 +00:00
Josh Brower
ef1dfc3152
Merge pull request #11722 from Security-Onion-Solutions/2.4/packageupgrade
...
Set execute permissions
2023-11-06 08:06:13 -05:00
Josh Brower
f6cd35e143
Set execute permissions
2023-11-06 08:03:31 -05:00
Jason Ertel
d010af9a24
Merge pull request #11718 from Security-Onion-Solutions/jertel/auto
...
disregard false positives
2023-11-04 16:32:02 -04:00
Jason Ertel
7a0b21647f
disregard false positives
2023-11-04 10:05:37 -04:00
Josh Patterson
610374816d
Merge pull request #11714 from Security-Onion-Solutions/change/so-minion
...
apply es and soc states to manager if new search or hn are added
2023-11-03 16:43:16 -04:00
Josh Brower
3ff74948d8
Merge pull request #11713 from Security-Onion-Solutions/2.4/agentupdate
...
Upgrade Elastic Agent
2023-11-03 15:23:55 -04:00
Josh Brower
0086c24729
Upgrade Elastic Agent
2023-11-03 15:21:06 -04:00
m0duspwnens
9d2b84818f
apply es and soc states to manager if new search or hn are added
2023-11-03 15:00:13 -04:00
Mike Reeves
b74aa32deb
Merge pull request #11712 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soc_elasticsearch.yaml
2023-11-03 11:33:00 -04:00
Mike Reeves
3d8663db66
Update soc_elasticsearch.yaml
2023-11-03 11:29:45 -04:00
Josh Brower
65978a340f
Merge pull request #11710 from Security-Onion-Solutions/2.4/navlayerfix
...
exit 0
2023-11-03 11:07:10 -04:00
Josh Brower
a8b0e41dbe
exit 0
2023-11-03 11:04:52 -04:00
Jason Ertel
1bc4b44be7
Merge pull request #11709 from Security-Onion-Solutions/jertel/auto
...
ignore malformed open canary log lines
2023-11-03 09:17:23 -04:00
Jason Ertel
1a3d4a2051
ignore malformed open canary log lines
2023-11-03 09:14:26 -04:00
Josh Brower
9d639df882
Merge pull request #11708 from Security-Onion-Solutions/2.4/metadatafix2
...
Dont overwrite metadata
2023-11-03 08:47:48 -04:00
Josh Brower
8c7767b381
Dont overwrite metadata
2023-11-03 08:41:33 -04:00
weslambert
96582add5e
Merge pull request #11704 from Security-Onion-Solutions/feature/integrations_checkpoint_vsphere
...
Checkpoint and VSphere Integrations
2023-11-02 17:17:03 -04:00
Wes
5bfef3f527
Add checkpoint and vsphere templates
2023-11-02 21:10:01 +00:00
Wes
3875970dc5
Add checkpoint and vsphere packages
2023-11-02 21:09:37 +00:00
Jason Ertel
7aa4f28524
Merge pull request #11702 from Security-Onion-Solutions/jertel/auto
...
ignore connectivity problems to docker containers during startup
2023-11-02 16:48:09 -04:00
Jason Ertel
96fdfb3829
ignore connectivity problems to docker containers during startup
2023-11-02 16:46:41 -04:00
weslambert
ac593e4632
Merge pull request #11701 from Security-Onion-Solutions/fix/elastic_templates_common
...
Don't source so-elastic-fleet-common if not there
2023-11-02 16:43:27 -04:00
weslambert
51e7861757
Don't source so-elastic-fleet-common if not there
2023-11-02 16:41:34 -04:00
Jason Ertel
6332df04d1
Merge pull request #11695 from Security-Onion-Solutions/jertel/auto
...
Jertel/auto
2023-11-02 13:07:09 -04:00
Jason Ertel
32701b5941
more log bypass
2023-11-02 12:50:12 -04:00
Josh Brower
0dec6693dc
Merge pull request #11678 from Security-Onion-Solutions/2.4/fleetreset
...
Add Elastic Fleet reset script
2023-11-02 11:33:58 -04:00
Jason Ertel
41a6ab5b4f
Merge pull request #11691 from Security-Onion-Solutions/jertel/auto
...
more log bypass
2023-11-02 10:41:17 -04:00
Jason Ertel
e18e0fd69a
more log bypass
2023-11-02 10:39:14 -04:00
Josh Brower
2c0e287f8c
Fix name
2023-11-02 10:34:24 -04:00
Josh Patterson
9a76cfe3d3
Merge pull request #11690 from Security-Onion-Solutions/upgrade/salt3006.3v2
...
fix UPGRADECOMMAND used for distrib salt upgrade. remove unneeded vars
2023-11-02 10:28:29 -04:00
m0duspwnens
6c4dc7cc09
fix UPGRADECOMMAND used for distrib salt upgrade. remove unneeded vars
2023-11-02 10:23:03 -04:00
Josh Brower
5388b92865
Refactor & cleanup
2023-11-02 10:20:32 -04:00
Jason Ertel
f932444101
Merge pull request #11689 from Security-Onion-Solutions/jertel/auto
...
more log bypass
2023-11-02 10:02:13 -04:00
Jason Ertel
1d2518310d
more log bypass
2023-11-02 09:59:45 -04:00
weslambert
e10f043b1c
Merge pull request #11688 from Security-Onion-Solutions/fix/integrations_roles
...
Add eval and import roles
2023-11-02 09:58:40 -04:00
weslambert
65735fc4d3
Add eval and import roles
2023-11-02 09:54:01 -04:00
Jason Ertel
b7f516fca4
Merge pull request #11687 from Security-Onion-Solutions/jertel/auto
...
adjust log filter to include all hosts
2023-11-02 09:24:08 -04:00
Jason Ertel
c8d8997119
adjust log filter to include all hosts
2023-11-02 09:21:57 -04:00
Josh Brower
c230cf4eb7
Formatting
2023-11-01 17:00:32 -04:00
Josh Brower
344dd7d61f
Add Elastic Fleet reset script
2023-11-01 16:50:20 -04:00
Mike Reeves
cd8949d26b
Merge pull request #11677 from Security-Onion-Solutions/lowram
...
Allow 16GB of memory
2023-11-01 16:38:40 -04:00
weslambert
f9e2940181
Merge pull request #11676 from Security-Onion-Solutions/feature/sublime_platform_integration
...
Sublime Platform Integration
2023-11-01 16:13:57 -04:00
Wes
f33079f1e3
Make settings global
2023-11-01 20:09:56 +00:00
Mike Reeves
e6a0838e4c
Add memory restrictions
2023-11-01 15:26:24 -04:00
Mike Reeves
cc93976db9
Add memory restrictions
2023-11-01 15:17:23 -04:00
Mike Reeves
b3b67acf07
Add memory restrictions
2023-11-01 15:11:54 -04:00
Josh Patterson
64926941dc
Merge pull request #11674 from Security-Onion-Solutions/foxtrot
...
Foxtrot
2023-11-01 15:03:30 -04:00
Wes
c32935e2e6
Remove optional integration from configuration if not enabled
2023-11-01 17:02:43 +00:00
Mike Reeves
4f98beaf9e
Merge pull request #11671 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Remove legacy pillar info
2023-11-01 13:00:34 -04:00
Wes
655c88cd09
Make sure enabled_nodes is populated
2023-11-01 16:47:51 +00:00
Mike Reeves
f62e02a477
Delete pillar/thresholding/pillar.example
2023-11-01 10:42:29 -04:00
Mike Reeves
2b3e405b2d
Delete pillar/thresholding/pillar.usage
2023-11-01 10:41:40 -04:00
Josh Patterson
59328d3909
Merge pull request #11670 from Security-Onion-Solutions/fix/soupagrepo
...
Fix/soupagrepo
2023-11-01 10:36:17 -04:00
m0duspwnens
4d7b1095b7
Merge remote-tracking branch 'origin/2.4/dev' into fix/soupagrepo
2023-11-01 10:31:59 -04:00
m0duspwnens
338146fedd
fix repo update during soup for airgap
2023-11-01 10:19:56 -04:00
Wes
bca1194a46
Sublime SOC Action
2023-11-01 14:01:55 +00:00
Wes
a0926b7b87
Load optional integrations
2023-11-01 13:59:24 +00:00
Wes
44e45843bf
Change optional integration Fleet configuration
2023-11-01 13:52:38 +00:00
Wes
9701d0ac20
Optional integration Fleet configuration
2023-11-01 13:47:20 +00:00
Wes
23ee9c2bb0
Sublime Platform integration
2023-11-01 13:41:40 +00:00
Wes
51247be6b9
Sublime Platform integration defaults
2023-11-01 13:37:52 +00:00
Wes
4dc64400c5
Support document_id
2023-11-01 13:36:32 +00:00
Wes
ae45d40eca
Add Sublime Platform ingest pipeline
2023-11-01 13:34:30 +00:00
Mike Reeves
ebf982bf86
Merge pull request #11666 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Remove unused scripts and functions
2023-10-31 15:18:23 -04:00
Mike Reeves
d07cfdd3fe
Update so-functions
2023-10-31 13:10:55 -04:00
Mike Reeves
497294c363
Delete salt/common/tools/sbin/so-zeek-logs
2023-10-31 12:57:10 -04:00
Mike Reeves
cc3a69683c
Delete salt/manager/tools/sbin/so-allow-view
2023-10-31 12:55:47 -04:00
Mike Reeves
0c98bd96c7
Delete salt/idstools/tools/sbin/so-rule
...
UI does this now
2023-10-31 12:52:00 -04:00
Jason Ertel
a6d456e108
Merge pull request #11665 from Security-Onion-Solutions/jertel/auto
...
ignore specific Suricata errors
2023-10-31 11:20:28 -04:00
Jason Ertel
c420e198fb
ignore specific Suricata errors
2023-10-31 11:18:39 -04:00
weslambert
5a85003952
Merge pull request #11664 from Security-Onion-Solutions/fix/elastic_import
...
Add import roles
2023-10-31 10:47:13 -04:00
weslambert
c354924b68
Add import roles
2023-10-31 10:05:29 -04:00
Jason Ertel
db0d687b87
Merge pull request #11661 from Security-Onion-Solutions/fix/elastic_eval_roles
...
Add roles for eval mode
2023-10-30 22:01:22 -04:00
weslambert
ed6473a34b
Add roles for eval mode
2023-10-30 20:41:49 -04:00
Josh Patterson
1b99d5081a
Merge pull request #11659 from Security-Onion-Solutions/issue/11457
...
ensure networkminer is latest version
2023-10-30 16:20:36 -04:00
m0duspwnens
07e51121ba
ensure networkminer is latest version
2023-10-30 16:11:36 -04:00
weslambert
9a1e95cd09
Merge pull request #11648 from Security-Onion-Solutions/fix/ilm_remove_policy
...
Remove ILM policies for Cases and OSQuery manager indices
2023-10-27 17:28:59 -04:00
weslambert
76dd6f07ab
Remove policy for OSQuery manager indices
2023-10-27 17:26:33 -04:00
weslambert
c955f9210a
Remove policy for Cases indices
2023-10-27 17:24:27 -04:00
Josh Patterson
d35483aa02
Merge pull request #11647 from Security-Onion-Solutions/upgrade/salt3006.3v2
...
Upgrade/salt3006.3v2
2023-10-27 14:37:16 -04:00
Jorge Reyes
a9284b35a2
Merge pull request #11644 from Security-Onion-Solutions/bravo
...
UPGRADE: influxdb 2.7.1 & telegraf 1.28.2
2023-10-27 12:16:48 -04:00
Jason Ertel
58cab35a4c
Merge pull request #11643 from Security-Onion-Solutions/kilo
...
oidc
2023-10-27 11:21:20 -04:00
Jason Ertel
6d7243038c
switch back to kilo version
2023-10-27 11:20:49 -04:00
Jason Ertel
3a83c52660
minor updates
2023-10-27 11:20:05 -04:00
Jason Ertel
d42b5ef901
remove unused url props to avoid kratos complaining about invalid urls when they're blank
2023-10-27 11:18:56 -04:00
m0duspwnens
2b511cef77
Merge branch 'upgrade/salt3006.3' into upgrade/salt3006.3v2
2023-10-27 10:58:09 -04:00
Josh Patterson
4bbcc5002a
Revert "Revert "Upgrade/salt3006.3""
...
This reverts commit c41e19ad0b .
2023-10-27 10:56:45 -04:00
Mike Reeves
f1dbea6e2d
Merge pull request #11623 from Security-Onion-Solutions/warmui
...
Warm Node UI Changes
2023-10-27 10:36:23 -04:00
Mike Reeves
25f1a0251f
Annotation changes for warm node
2023-10-27 09:08:07 -04:00
Mike Reeves
87494f64c7
Annotation changes for warm node
2023-10-27 09:06:12 -04:00
Mike Reeves
ce1858fe05
Annotation changes for warm node
2023-10-27 09:02:39 -04:00
Mike Reeves
9fc3a73035
Annotation changes for warm node
2023-10-27 08:58:08 -04:00
Josh Brower
0d52efafa8
Merge pull request #11637 from Security-Onion-Solutions/2.4/kibanauser
...
2.4/kibanauser
2023-10-27 08:43:12 -04:00
defensivedepth
3b63ef149a
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/kibanauser
2023-10-27 07:50:58 -04:00
defensivedepth
cc3ee43192
Make dirs as needed
2023-10-27 07:49:34 -04:00
Mike Reeves
b37e38e3c3
Update defaults.yaml
2023-10-26 16:03:58 -04:00
Jorge Reyes
25982b79ab
Merge pull request #11633 from Security-Onion-Solutions/reyesj2/influxdb_config
...
UPGRADE: Influxdb 2.7.1 & telegraf 1.28.2
2023-10-26 14:37:09 -04:00
Jason Ertel
cb9d72ebd7
switch back to kilo version
2023-10-26 14:19:59 -04:00
m0duspwnens
7e8f3b753f
add minion name to log, update comment
2023-10-26 13:19:04 -04:00
reyesj2
47373adad2
Specify config.yaml in config_path. Otherwise when no influxd.bolt exists influxdb will fail to read the config file and won't create a new db.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-26 13:15:40 -04:00
m0duspwnens
6891a95254
remove wait_for_salt_minion from so-functions
2023-10-26 13:02:39 -04:00
Mike Reeves
2e0100fd35
Update defaults.yaml
2023-10-26 12:37:55 -04:00
Jason Ertel
a969c319f5
Merge pull request #11631 from Security-Onion-Solutions/kilo
...
oidc
2023-10-26 12:30:06 -04:00
Jason Ertel
4942f83d4f
adjust version to match target branch
2023-10-26 11:45:39 -04:00
Josh Brower
6f4566c23e
Merge pull request #11609 from Security-Onion-Solutions/2.4/kibanauser
...
Add kibana curl config
2023-10-26 10:42:32 -04:00
Wes
891ea997e7
Add lifecycle policies and warm settings
2023-10-26 12:25:37 +00:00
Mike Reeves
01810a782c
Annotation changes for warm node
2023-10-25 16:46:30 -04:00
Mike Reeves
6d6292714f
Annotation changes for warm node
2023-10-25 16:21:47 -04:00
Mike Reeves
88fb7d06e6
Annotation changes for warm node
2023-10-25 16:20:28 -04:00
Josh Patterson
39abe19cfd
Update config.map.jinja
2023-10-25 16:17:06 -04:00
Josh Patterson
807b40019f
Update soc_elasticsearch.yaml
2023-10-25 16:16:48 -04:00
Josh Patterson
5f168a33ed
Update defaults.yaml
2023-10-25 16:16:01 -04:00
Mike Reeves
d1170cb69f
Update soc_elasticsearch.yaml
2023-10-25 16:05:20 -04:00
m0duspwnens
19fdc9319b
fix role update
2023-10-25 15:58:26 -04:00
Mike Reeves
dc53b49f15
Update soup
2023-10-25 15:53:39 -04:00
Josh Patterson
af4b34801f
Update defaults.yaml
2023-10-25 15:48:27 -04:00
Josh Patterson
1ae8896a05
Update config.map.jinja
2023-10-25 15:47:40 -04:00
Mike Reeves
6fb0c5dbfe
Annotation changes for warm node
2023-10-25 15:37:36 -04:00
Mike Reeves
58bf6d3eff
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into warmui
2023-10-25 15:37:14 -04:00
Mike Reeves
a887551dad
Annotation changes for warm node
2023-10-25 15:22:47 -04:00
Jason Ertel
b20177b0ef
Merge branch '2.4/dev' into kilo
2023-10-25 15:19:57 -04:00
defensivedepth
1e710a22ce
Merge remote-tracking branch 'remotes/origin/2.4/dev' into 2.4/kibanauser
2023-10-25 11:33:38 -04:00
Josh Patterson
d562445686
Merge pull request #11619 from Security-Onion-Solutions/revert-11612-upgrade/salt3006.3
...
Revert "Upgrade/salt3006.3"
2023-10-25 11:28:14 -04:00
Josh Patterson
c41e19ad0b
Revert "Upgrade/salt3006.3"
2023-10-25 11:01:13 -04:00
m0duspwnens
a3e6b1ee1d
change generate_ssl wait_for_salt_minion
2023-10-25 09:26:36 -04:00
Jason Ertel
a28cc274ba
Merge branch '2.4/dev' into kilo
2023-10-25 09:04:36 -04:00
Jason Ertel
a66006c8a6
minor updates
2023-10-25 09:04:23 -04:00
defensivedepth
3ad480453a
Rename to remove dupe
2023-10-25 07:20:07 -04:00
Josh Patterson
205748e992
Merge pull request #11613 from Security-Onion-Solutions/issue/11610
...
fix issue/11610
2023-10-24 18:16:44 -04:00
m0duspwnens
dfe707ab64
fix issue/11610
2023-10-24 17:26:39 -04:00
Josh Patterson
308e5ea505
Merge pull request #11612 from Security-Onion-Solutions/upgrade/salt3006.3
...
Upgrade/salt3006.3
2023-10-24 16:45:12 -04:00
m0duspwnens
3e343bff84
fix line to log properly
2023-10-24 16:40:51 -04:00
m0duspwnens
1d6e32fbab
dont exit if salt isnt running
2023-10-24 15:08:50 -04:00
defensivedepth
310a6b4f27
Add kibana curl config
2023-10-24 14:21:01 -04:00
m0duspwnens
180ba3a958
if deb fam, stop salt-master and salt-minion after salt upgrade
2023-10-24 13:24:52 -04:00
m0duspwnens
6d3465626e
if deb fam, stop salt-master and salt-minion after salt upgrade
2023-10-24 12:52:25 -04:00
m0duspwnens
fab91edd2d
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-24 09:41:23 -04:00
m0duspwnens
752390be2e
merge with dev, fix confict
2023-10-24 09:40:09 -04:00
Mike Reeves
02639d3bc5
Merge pull request #11606 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Enable http2 for Suricata
2023-10-24 09:23:07 -04:00
Mike Reeves
4a3fc06a4d
Enable http2 for Suricata
2023-10-24 09:18:10 -04:00
weslambert
0c2b3f3c62
Merge pull request #11600 from Security-Onion-Solutions/fix/suricata_pkt_src
...
Parse pkt_src for Suricata logs
2023-10-23 15:51:30 -04:00
weslambert
660020cc76
Parse pkt_src for Suricata logs
2023-10-23 15:45:41 -04:00
Jorge Reyes
b59a95b72f
Merge pull request #11594 from Security-Onion-Solutions/fix/playbookrule
...
FIX: Add -watch to soctopus saltstate for file SOCtopus.conf. Makes contai…
2023-10-23 11:51:53 -04:00
reyesj2
030a667d26
Add -watch to soctopus saltstate for file SOCtopus.conf. Makes container restart @ highstate if file is updated.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-23 11:47:14 -04:00
Josh Patterson
a40760e601
Merge pull request #11592 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-23 10:37:05 -04:00
m0duspwnens
dc3ca99c12
ask the minion if it can see itself in the mine
2023-10-20 17:16:33 -04:00
m0duspwnens
7e3aa11a73
check mine is populated with ip before telling node to highstate
2023-10-20 16:27:20 -04:00
m0duspwnens
c409339446
change post setup highstate cron to 5 minutes since accepting minion runs a highstate
2023-10-20 13:46:24 -04:00
m0duspwnens
c588bf4395
update mine and highstate minion when added
2023-10-20 13:43:12 -04:00
m0duspwnens
6d77b1e4c3
continue loop if minion not in mine
2023-10-20 13:41:53 -04:00
m0duspwnens
99662c999f
log operation and minion target
2023-10-20 13:41:24 -04:00
m0duspwnens
ef2b89f5bf
fix attempts logic
2023-10-20 13:40:40 -04:00
Josh Patterson
2878f82754
Merge pull request #11582 from Security-Onion-Solutions/minechanges
...
handle a minion not being in the mine data return
2023-10-20 10:07:44 -04:00
m0duspwnens
2e16250c93
handle a minion not being in the mine data return
2023-10-20 10:00:39 -04:00
m0duspwnens
f03bbdbc09
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-19 17:01:12 -04:00
m0duspwnens
dbfccdfff8
fix logging when using wait_for_minion
2023-10-19 16:53:03 -04:00
m0duspwnens
dfcbbfd157
update call to wait_for_salt_minion with new options in so-functions
2023-10-19 15:58:50 -04:00
m0duspwnens
37e803917e
have soup wait_for_salt_minion() before running any highstate
2023-10-19 15:58:10 -04:00
m0duspwnens
66ee074795
add wait_for_salt_minion to so-common
2023-10-19 15:57:24 -04:00
m0duspwnens
90bde94371
handle debian family salt upgrade for soup
2023-10-19 13:46:48 -04:00
m0duspwnens
84f8e1cc92
debian family upgrade salt without -r flag
2023-10-19 13:46:07 -04:00
m0duspwnens
e3830fa286
all more os to set_os in so-common
2023-10-19 13:43:03 -04:00
m0duspwnens
13a5c8baa7
remove extra ||
2023-10-19 11:19:51 -04:00
m0duspwnens
c5610edd83
handle salt for r9 and c9
2023-10-19 11:12:20 -04:00
weslambert
5119e6c45a
Merge pull request #11570 from Security-Onion-Solutions/feature/additional_integrations
...
Additional integrations
2023-10-19 09:30:40 -04:00
m0duspwnens
02e22c87e8
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/salt3006.3
2023-10-19 09:15:31 -04:00
Mike Reeves
0772926992
Merge pull request #11573 from Security-Onion-Solutions/minechanges
2023-10-18 19:45:23 -04:00
m0duspwnens
b2bb92d413
remove extra space
2023-10-18 19:38:19 -04:00
Mike Reeves
19bebe44aa
Merge pull request #11572 from Security-Onion-Solutions/minechanges
2023-10-18 19:37:34 -04:00
m0duspwnens
f30a652e19
add back redirects
2023-10-18 19:31:45 -04:00
m0duspwnens
ff18b1f074
remove redirect
2023-10-18 18:45:14 -04:00
m0duspwnens
9eb682bc40
generate_ca after salt-master and salt-minion states run
2023-10-18 18:37:35 -04:00
Wes
c135f886a9
Remove Carbon Black Cloud integration
2023-10-18 20:41:34 +00:00
Wes
28b7a24cc1
Add templates for integrations
2023-10-18 20:36:04 +00:00
m0duspwnens
a52ee063e5
use generate_ca and generate_ssl functions and move them up
2023-10-18 16:35:33 -04:00
Wes
767a54c91b
Add pkgs
2023-10-18 20:07:26 +00:00
m0duspwnens
ac28e1b967
verify crt and key differently in checkmine
2023-10-18 15:53:12 -04:00
Jorge Reyes
5e10a0d9e2
Merge pull request #11568 from Security-Onion-Solutions/2.4/zeek6
...
Add back plugin-tds/ plugin-profinet. Using patched versions for Zeek 6
2023-10-18 15:39:30 -04:00
reyesj2
dd28dc6ddd
Add back plugin-tds/ plugin-profinet. Using patched versions for Zeek 6
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-18 15:30:32 -04:00
m0duspwnens
e58c1e189c
use x509 instead of file for onchanges
2023-10-18 15:10:17 -04:00
m0duspwnens
1c1b23c328
fix mine update for ca
2023-10-18 15:07:18 -04:00
m0duspwnens
2206cdb0fa
change soup comment
2023-10-18 15:04:39 -04:00
m0duspwnens
1999db0bb3
apply ca state early in setup
2023-10-18 15:02:22 -04:00
m0duspwnens
c3cde61202
docker service watches and requires the intca
2023-10-18 15:01:26 -04:00
m0duspwnens
8e68f96316
check that the manager has a ca in the mine and that it is valid
2023-10-18 13:59:15 -04:00
m0duspwnens
138aa9c554
update the mine with the ca when it is created or changed
2023-10-18 13:54:14 -04:00
weslambert
f0e380870d
Merge pull request #11567 from Security-Onion-Solutions/fix/mhr_docs
...
Add note regarding DNS resolver
2023-10-18 13:46:25 -04:00
weslambert
34717fb65e
Add note regarding DNS resolver
2023-10-18 13:44:09 -04:00
Josh Patterson
d81dfb99d0
Merge pull request #11563 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-17 17:36:46 -04:00
m0duspwnens
fb9a0ab8b6
endif not fi in jinja
2023-10-17 17:33:53 -04:00
m0duspwnens
928fb23e96
only add node to pillar if returned ip from mine
2023-10-17 17:28:28 -04:00
m0duspwnens
d9862aefcf
handle mine.p not being present. only check if mine_ip exists, dont compare to alived ip
2023-10-17 17:09:52 -04:00
m0duspwnens
496b97d706
handle the mine file not being present before checking the size
2023-10-17 15:42:42 -04:00
weslambert
830b5b9a21
Merge pull request #11560 from Security-Onion-Solutions/foxtrot
...
Elastic 8.10.4
2023-10-17 13:47:21 -04:00
weslambert
06e731c762
Update VERSION
2023-10-17 13:33:12 -04:00
weslambert
be2a829524
Elastic 8.10.4
2023-10-17 10:49:03 -04:00
weslambert
8cab242ad0
Elastic 8.10.4
2023-10-17 10:48:31 -04:00
weslambert
99054a2687
Elastic 8.10.4
2023-10-17 10:47:26 -04:00
weslambert
adcb7840bd
Elastic 8.10.3
2023-10-17 10:38:20 -04:00
weslambert
8db6fef92d
Elastic 8.10.3
2023-10-17 10:35:36 -04:00
weslambert
24329e3731
Update config_saved_objects.ndjson
2023-10-17 10:34:38 -04:00
weslambert
1db88bdbb5
Update so-common
2023-10-17 10:33:39 -04:00
weslambert
7c2cdb78e9
Update VERSION
2023-10-17 10:31:53 -04:00
Josh Patterson
e858a1211e
Merge pull request #11558 from Security-Onion-Solutions/excludelogfp
...
mark suricata 7 log line as fp fo so-log-check
2023-10-17 10:02:21 -04:00
m0duspwnens
01cb0fccb6
mark suricata 7 log line as fp fo so-log-check
2023-10-17 10:01:11 -04:00
Josh Patterson
86394dab01
Merge pull request #11555 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-16 17:32:16 -04:00
m0duspwnens
53fcafea50
redo how we check if salt-master is ready and accessible
2023-10-16 16:31:43 -04:00
Jorge Reyes
574a81da7f
Merge pull request #11554 from Security-Onion-Solutions/2.4/zeek6
...
Zeek 6 upgrade
2023-10-16 15:52:48 -04:00
reyesj2
ed693a7ae6
Remove commented lines in defaults.yaml to avoid UI issues.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-16 15:48:51 -04:00
reyesj2
e5c936e8cf
Replace external zeek-community-id with builtin community-id. Disable plugin-tds + plugin-profinet. Not updated for Zeek 6.x
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-16 15:18:26 -04:00
m0duspwnens
9f3a9dfab0
reorder salt.master state
2023-10-16 15:00:53 -04:00
m0duspwnens
c0030bc513
dont need to restart minion service when just adding sleep delay on service start
2023-10-16 15:00:07 -04:00
m0duspwnens
a637b0e61b
apply salt.master and minion state early in setup to prevent the services from restarting later in setup
2023-10-16 14:58:58 -04:00
Jason Ertel
2f0e673ec3
Merge pull request #11552 from Security-Onion-Solutions/jertel/auto
...
only add heavynodes to remoteHostUrls
2023-10-16 13:10:10 -04:00
Jason Ertel
84c39b5de7
only add heavynodes to remoteHostUrls
2023-10-16 13:01:13 -04:00
m0duspwnens
07902d17cc
display container dl status during soup
2023-10-16 11:20:19 -04:00
m0duspwnens
1a7761c531
display container dl status during soup
2023-10-16 11:00:31 -04:00
m0duspwnens
2773da5a12
run the checkmine engine under master instead of minion
2023-10-16 10:34:45 -04:00
m0duspwnens
e23b3a62f3
default interval of 60s
2023-10-13 16:24:11 -04:00
m0duspwnens
57684efddf
checkmine looks for 1 byte file and verify mine ip is correct
2023-10-13 16:23:16 -04:00
m0duspwnens
1641aa111b
add checkmine back
2023-10-13 13:46:31 -04:00
Jason Ertel
ca2530e07f
Merge pull request #11535 from Security-Onion-Solutions/jertel/auto
...
avoid rebooting when testing deb installs
2023-10-12 16:30:24 -04:00
Mike Reeves
104b53c6ec
Merge pull request #11534 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2023-10-12 16:20:37 -04:00
Mike Reeves
6c5f8e4e2d
Update HOTFIX
2023-10-12 16:19:59 -04:00
Mike Reeves
b8d586addd
Merge pull request #11533 from Security-Onion-Solutions/2.4/main
...
2.4/main
2023-10-12 16:19:29 -04:00
Mike Reeves
1b5cd4f53a
Merge pull request #11532 from Security-Onion-Solutions/hotfix/2.4.20
...
Hotfix 2.4.20
2023-10-12 16:16:49 -04:00
m0duspwnens
d2002a5158
add additional comments
2023-10-12 15:58:33 -04:00
m0duspwnens
5250292e95
only allow stable install type. require -r to be used
2023-10-12 15:54:22 -04:00
Mike Reeves
acc6715f90
Merge pull request #11531 from Security-Onion-Solutions/2.4.20hf
...
2.4.20 hotfix
2023-10-12 15:52:44 -04:00
Mike Reeves
b6af59d9b0
2.4.20 hotfix
2023-10-12 15:47:53 -04:00
Jason Ertel
49a651fd72
adjust var name
2023-10-12 15:43:22 -04:00
m0duspwnens
2d688331df
handle version install for stable and onedir install type
2023-10-12 15:32:04 -04:00
m0duspwnens
b12c4a96e9
remove files
2023-10-12 15:11:25 -04:00
m0duspwnens
6dd06c0fe9
change install_centos_onedir to install version provided from command line
2023-10-12 15:07:47 -04:00
Jason Ertel
17ae9b3349
avoid reboot during testing
2023-10-12 13:54:07 -04:00
m0duspwnens
8dc163f074
use script from develop branch
2023-10-12 13:09:07 -04:00
Josh Brower
8ce70e1f18
Merge pull request #11525 from Security-Onion-Solutions/hotfixfunctions
...
Apply named state
2023-10-12 11:05:32 -04:00
defensivedepth
98eab906af
Apply named state
2023-10-12 11:00:24 -04:00
Josh Brower
d558f20715
Merge pull request #11524 from Security-Onion-Solutions/hotfixfunctions
...
Apply state correctly
2023-10-12 10:56:43 -04:00
defensivedepth
967138cdff
Apply state correctly
2023-10-12 10:54:26 -04:00
Josh Brower
c76ac717f2
Merge pull request #11522 from Security-Onion-Solutions/hotfixfunctions
...
Add hotfix changes
2023-10-12 09:52:55 -04:00
defensivedepth
a671ac387a
Add hotfix changes
2023-10-12 09:45:20 -04:00
m0duspwnens
ab4c5acd0c
update bootstrap-salt.sh with stable branch
2023-10-12 09:28:07 -04:00
defensivedepth
1043315e6b
Manage Elastic Defend Integration manually
2023-10-12 09:22:26 -04:00
m0duspwnens
d357864d69
fix upgrade_salt function for oel
2023-10-11 15:32:11 -04:00
Jason Ertel
44b855dd93
merge 2.4/dev
2023-10-11 13:35:16 -04:00
m0duspwnens
2094b4f688
upgrade to salt 3006.3
2023-10-11 09:04:36 -04:00
Josh Patterson
5252482fe3
Merge pull request #11503 from Security-Onion-Solutions/minechanges
...
Minechanges
2023-10-10 16:33:17 -04:00
m0duspwnens
abeebc7bc4
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-10-10 13:13:55 -04:00
m0duspwnens
4193130ed0
reduce salt mine interval to 25 minutes
2023-10-10 13:07:12 -04:00
m0duspwnens
89467adf9c
batch the salt mine update
2023-10-10 13:05:43 -04:00
m0duspwnens
a283e7ea0b
remove checkmine salt engine
2023-10-10 13:00:54 -04:00
Mike Reeves
a54479d603
Merge pull request #11497 from Security-Onion-Solutions/TOoSmOotH-patch-9
...
Update VERSION
2023-10-10 11:07:51 -04:00
Mike Reeves
49ebbf3232
Update VERSION
2023-10-10 11:05:39 -04:00
m0duspwnens
05da5c039c
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-10-10 11:02:19 -04:00
Josh Patterson
f3d0248ec5
Merge pull request #11496 from Security-Onion-Solutions/fix/ping
...
accept icmp on input chain
2023-10-10 10:59:05 -04:00
m0duspwnens
4dc24b22c7
accept icmp on input chain
2023-10-10 10:51:59 -04:00
Mike Reeves
fc0e3c0124
Merge pull request #11476 from Security-Onion-Solutions/2.4/dev
...
2.4.20
2023-10-06 16:45:11 -04:00
Mike Reeves
32c1d6f95c
Merge pull request #11475 from Security-Onion-Solutions/2.4.20
...
2.4.20
2023-10-05 11:41:55 -04:00
Mike Reeves
c25aed9a2b
Update DOWNLOAD_AND_VERIFY_ISO.md
2023-10-05 11:37:49 -04:00
Mike Reeves
d79e27774c
2.4.20
2023-10-05 11:27:48 -04:00
Mike Reeves
194178a250
Merge pull request #11465 from Security-Onion-Solutions/fix/pkgs
...
Fix/pkgs
2023-10-03 10:17:37 -04:00
m0duspwnens
d78b55873d
remove mariadb-devel
2023-10-03 10:15:28 -04:00
Mike Reeves
f3ba28062b
Remove MySQL
2023-10-03 10:05:56 -04:00
m0duspwnens
2434ce14d3
remove removing mariadb-devel
2023-10-03 10:01:07 -04:00
m0duspwnens
66be04e78a
remove mariadb
2023-10-03 09:53:40 -04:00
Jason Ertel
62e9472f1a
Merge pull request #11464 from Security-Onion-Solutions/jertel/lc
...
exclude known issues
2023-10-03 09:46:18 -04:00
Jason Ertel
c699c2fe2a
exclude known issues
2023-10-03 09:43:29 -04:00
Mike Reeves
a35889ebdc
Merge pull request #11461 from Security-Onion-Solutions/fix/pkgs
2023-10-02 17:38:38 -04:00
m0duspwnens
8995752c27
let openssl-devel be installed with mariadb
2023-10-02 16:17:26 -04:00
m0duspwnens
57e76232ec
openssl pkgs in own state
2023-10-02 15:48:53 -04:00
m0duspwnens
d7a14d9e00
update holds
2023-10-02 15:08:22 -04:00
m0duspwnens
6b90961e87
openssl-libs
2023-10-02 14:26:28 -04:00
m0duspwnens
6547afe6c0
dont hold openssl-devel
2023-10-02 13:35:00 -04:00
m0duspwnens
3a5c6ee43a
install version lock before we try to hold pkgs
2023-10-02 12:09:13 -04:00
m0duspwnens
0f08d5d640
install openssl version 1:3.0.7-16.0.1.el9_2
2023-10-02 11:43:03 -04:00
m0duspwnens
f85dd910a3
hold openssl from update during setup
2023-10-02 11:13:08 -04:00
m0duspwnens
c1ab8952eb
hold openssl-devel
2023-10-02 10:59:51 -04:00
m0duspwnens
dfe399291f
hold openssl-libs
2023-10-02 10:54:41 -04:00
m0duspwnens
70a36bafa5
remove -
2023-10-02 10:38:54 -04:00
m0duspwnens
381d95e032
Merge remote-tracking branch 'origin/2.4/dev' into fix/pkgs
2023-10-02 10:37:12 -04:00
m0duspwnens
cd8a74290b
hold openssl version
2023-10-02 10:36:17 -04:00
Jason Ertel
d91eaa9ae5
Merge pull request #11448 from Security-Onion-Solutions/jertel/lc
...
fix exclusion
2023-09-30 18:16:23 -04:00
Jason Ertel
8c7933cd60
fix exclusion
2023-09-30 18:11:29 -04:00
Jason Ertel
88f461042d
Merge pull request #11442 from Security-Onion-Solutions/jertel/lc
...
more known errors
2023-09-29 21:43:51 -04:00
Jason Ertel
ea085c5ff6
more known errors
2023-09-29 21:38:13 -04:00
m0duspwnens
39ea1d317d
add comment
2023-09-29 17:12:14 -04:00
m0duspwnens
827ed7b273
run salt.mine_function state locally and provide pillar info to it
2023-09-29 17:08:42 -04:00
m0duspwnens
8690304dff
change how mine_functions.conf is managed during setup
2023-09-29 16:17:19 -04:00
m0duspwnens
1e327c143c
Merge remote-tracking branch 'origin/2.4/dev' into minechanges
2023-09-29 15:11:06 -04:00
Jason Ertel
19232124f2
Merge pull request #11441 from Security-Onion-Solutions/jertel/lc
...
exclude oom error from cmd line
2023-09-29 14:21:05 -04:00
Jason Ertel
e8b67da08b
exclude oom error from cmd line
2023-09-29 14:20:20 -04:00
Jason Ertel
b5d19bd561
Merge pull request #11440 from Security-Onion-Solutions/jertel/lc
...
exclude logstash errors
2023-09-29 14:13:34 -04:00
m0duspwnens
ad01be66ea
remove checkmine engine. add x509.get_pem_entries to managers mine_functions. simplify mine update during soup
2023-09-29 14:09:04 -04:00
Jason Ertel
d546d52069
exclude logstash
2023-09-29 14:08:44 -04:00
Josh Patterson
13cc8c4258
Merge pull request #11437 from Security-Onion-Solutions/telegraf/redis
...
remove redis from eval
2023-09-29 11:12:24 -04:00
m0duspwnens
9d3f6059ee
remove redis from eval
2023-09-29 11:10:08 -04:00
Jason Ertel
43855b8ca2
Merge pull request #11436 from Security-Onion-Solutions/jertel/lc
...
exclude all playbook logs
2023-09-29 11:04:48 -04:00
Jason Ertel
ec3cc7a854
exclude all playbook logs
2023-09-29 10:49:36 -04:00
Mike Reeves
63be7ef6ca
Merge pull request #11432 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update defaults.yaml
2023-09-28 19:48:14 -04:00
Mike Reeves
b8aad7f5e6
Update defaults.yaml
2023-09-28 19:44:49 -04:00
weslambert
c02e491609
Merge pull request #11430 from Security-Onion-Solutions/fix/elastic_packages
...
Upgrade packages and load integrations when packages change
2023-09-28 14:10:39 -04:00
Wes
670cd19051
Exclude package upgrade script
2023-09-28 18:04:07 +00:00
Wes
8c44481ee1
Load templates after package changes
2023-09-28 17:57:31 +00:00
Mike Reeves
a8c94a891b
Merge pull request #11426 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Fix Yara crontab
2023-09-28 13:09:11 -04:00
Mike Reeves
ff35946050
Fix manager cron logic
2023-09-28 13:06:21 -04:00
Mike Reeves
95d32cb076
Fix manager cron logic
2023-09-28 12:49:46 -04:00
Wes
018186ccbd
Upgrade packages and load integrations when packages change
2023-09-28 16:43:56 +00:00
Mike Reeves
5040df7551
Fix manager cron logic
2023-09-28 12:32:40 -04:00
Jason Ertel
c3604f6e80
Merge pull request #11422 from Security-Onion-Solutions/jertel/lc
...
exclude known issues
2023-09-28 11:47:13 -04:00
Mike Reeves
7a21b7903d
Fix manager cron logic
2023-09-28 11:46:43 -04:00
Mike Reeves
a77a53f20b
Update init.sls
2023-09-28 11:10:17 -04:00
Mike Reeves
ee45fc31a2
Delete salt/strelka/tools/sbin_jinja/so-yara-download
2023-09-28 11:04:16 -04:00
weslambert
ceae22adab
Merge pull request #11423 from Security-Onion-Solutions/fix/elastic_known_certs
...
Exclude known_certs
2023-09-28 09:20:38 -04:00
weslambert
202eb7e876
Exclude known_certs
2023-09-28 09:16:56 -04:00
Jason Ertel
89a9c30cc8
exclude known issues
2023-09-28 08:27:31 -04:00
Jason Ertel
7012ff6609
Merge pull request #11418 from Security-Onion-Solutions/jertel/lc
...
more exclusions
2023-09-28 08:02:29 -04:00
Jason Ertel
621da9e7e3
more exclusions
2023-09-27 22:20:54 -04:00
Jason Ertel
26bb0d064f
Merge pull request #11417 from Security-Onion-Solutions/jertel/lc
...
logcheck improvements
2023-09-27 20:35:06 -04:00
Jason Ertel
9ee64f93ca
logcheck improvements
2023-09-27 20:17:59 -04:00
Jason Ertel
641ff95f41
Merge pull request #11416 from Security-Onion-Solutions/jertel/lc
...
Jertel/lc
2023-09-27 20:03:58 -04:00
Jason Ertel
49115cde55
logcheck improvements
2023-09-27 19:55:46 -04:00
Josh Patterson
7d0e1c92a3
Merge pull request #11415 from Security-Onion-Solutions/issue/11390
...
Issue/11390
2023-09-27 19:39:36 -04:00
m0duspwnens
419acab48a
revert up_to_2.4.20
2023-09-27 19:17:13 -04:00
m0duspwnens
528572c15b
Merge remote-tracking branch 'origin/2.4/dev' into issue/11390
2023-09-27 18:42:07 -04:00
Jason Ertel
d72e4ae97d
ignore soctopus errors
2023-09-27 18:39:23 -04:00
m0duspwnens
76c0b881ff
exclude import from snapshotting previous version pillars and states
2023-09-27 18:20:50 -04:00
Jason Ertel
836c49b755
Merge pull request #11414 from Security-Onion-Solutions/jertel/lc
...
ignore generic python stack trace log lines of code, rely on actual e…
2023-09-27 16:59:34 -04:00
Jason Ertel
24def3a196
ignore generic python stack trace log lines of code, rely on actual error messages
2023-09-27 16:50:01 -04:00
Mike Reeves
b6d58b2fb8
Merge pull request #11411 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
FIX: Remove telegraf beats EPS script
2023-09-27 16:14:51 -04:00
Mike Reeves
770a74c83d
Merge pull request #11409 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Fix zeek from creating summary files
2023-09-27 16:14:34 -04:00
Mike Reeves
039d5ae9aa
Delete salt/telegraf/scripts/beatseps.sh
2023-09-27 16:09:27 -04:00
Mike Reeves
2fb73cd516
Update defaults.yaml
2023-09-27 16:07:38 -04:00
Mike Reeves
2427344dca
Update defaults.yaml
2023-09-27 15:58:58 -04:00
Mike Reeves
62cb661bab
Merge pull request #11408 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix sendmail errors in zeek
2023-09-27 15:53:50 -04:00
Jason Ertel
1e04199ea6
Merge pull request #11406 from Security-Onion-Solutions/jertel/lc
...
ignore generic python stack trace log lines of code, rely on actual e…
2023-09-27 15:52:48 -04:00
Jason Ertel
4666916077
ignore generic python stack trace log lines of code, rely on actual error messages
2023-09-27 15:48:52 -04:00
Mike Reeves
f094b1162d
Update defaults.yaml
2023-09-27 15:48:05 -04:00
Jason Ertel
ae9619f0c3
Merge pull request #11405 from Security-Onion-Solutions/jertel/lc
...
deb OS doesn't use /var/log/cron, skip
2023-09-27 15:42:10 -04:00
Jason Ertel
87cc389088
deb OS doesn't use /var/log/cron, skip
2023-09-27 15:36:13 -04:00
Josh Patterson
ec046a6943
Merge pull request #11404 from Security-Onion-Solutions/fix/filecheckcron
...
Fix/filecheckcron
2023-09-27 12:51:25 -04:00
Mike Reeves
7eefe7b79c
Merge pull request #11403 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update nginx.conf to use user nobody
2023-09-27 12:38:58 -04:00
Mike Reeves
c4fea9cb9d
Update nginx.conf
2023-09-27 11:03:58 -04:00
m0duspwnens
3fded86aa1
Merge remote-tracking branch 'origin/2.4/dev' into fix/filecheckcron
2023-09-27 10:08:17 -04:00
m0duspwnens
05e7c32cf9
remove duplicate filecheck_run cron
2023-09-27 10:08:08 -04:00
Jason Ertel
af2ff2b07c
Merge pull request #11399 from Security-Onion-Solutions/jertel/lc
...
don't inspect imported zeek output
2023-09-27 09:45:39 -04:00
Jason Ertel
b47d915cb6
don't inspect imported zeek output
2023-09-27 09:30:19 -04:00
Jason Ertel
376d525ad7
Merge pull request #11398 from Security-Onion-Solutions/jertel/lc
...
skip zeek spool logs due to test data false positives
2023-09-26 22:01:50 -04:00
Jason Ertel
9c854a13cc
skip zeek spool logs due to test data false positives
2023-09-26 21:41:44 -04:00
Jason Ertel
ff780738fd
Merge pull request #11397 from Security-Onion-Solutions/jertel/lc
...
log check tool initial
2023-09-26 18:23:41 -04:00
Jason Ertel
2c8d413f16
log check tool initial
2023-09-26 18:14:37 -04:00
Jason Ertel
48801da44e
log check tool initial
2023-09-26 18:12:20 -04:00
Josh Patterson
641b8ef0b6
Merge pull request #11393 from Security-Onion-Solutions/issue/11390
...
Issue/11390
2023-09-26 13:26:42 -04:00
m0duspwnens
036a21ff17
Merge remote-tracking branch 'origin/2.4/dev' into issue/11390
2023-09-26 11:01:44 -04:00
m0duspwnens
2abf434ebe
create snapshots of default, local salt and pillars during soup. rsync soup with --delete
2023-09-26 10:56:20 -04:00
weslambert
4dc477cc1d
Merge pull request #11391 from Security-Onion-Solutions/fix/elasticsearch_strelka_image_version
...
Make scan.pe.image_version type of 'float'
2023-09-26 10:21:17 -04:00
Wes
0bba68769b
Make scan.pe.image_version type of 'float'
2023-09-26 14:05:12 +00:00
m0duspwnens
e25d1c0ff3
so-salt-minion-check is jinja template
2023-09-26 10:01:21 -04:00
weslambert
f9ace4791f
Merge pull request #11384 from Security-Onion-Solutions/fix/analyzers_testing
...
Add a note about testing analyzers outside of the Sensoroni Docker container
2023-09-25 14:48:45 -04:00
weslambert
7cb9b5f257
Add the blank line that was removed from the previous commit
2023-09-25 14:41:20 -04:00
weslambert
c95af6b992
Add a note about testing analyzers outside of the Sensoroni Docker container
2023-09-25 14:39:33 -04:00
weslambert
2fc4d2923d
Merge pull request #11289 from Security-Onion-Solutions/fix/elastic_agent_404
...
/app/dashboards to /kibana/app/dashboards
2023-09-25 09:11:50 -04:00
Wes
eeeae08ec8
/app/ to /app/dashboards/
2023-09-21 18:39:06 +00:00
Jason Ertel
220f25e206
Merge pull request #11369 from Security-Onion-Solutions/jertel-patch-1
...
Update soup to prune in background
2023-09-21 09:42:28 -04:00
Jason Ertel
fa3a79a787
Update soup to prune in background
2023-09-21 09:41:44 -04:00
Doug Burks
ca71add51b
Merge pull request #11363 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Config sensoroni doc links should point to correct docs #11362
2023-09-20 08:29:30 -04:00
Doug Burks
3fa3f83007
Update soc_sensoroni.yaml
2023-09-20 08:22:52 -04:00
weslambert
377802410e
Merge pull request #11352 from Security-Onion-Solutions/fix/import_evtx_exists
...
Fix EVTX Imports
2023-09-19 16:11:22 -04:00
Wes
2e0ea3f374
Set final pipeline
2023-09-19 13:33:12 +00:00
Wes
508260bd46
Use event.created for timestamp
2023-09-19 13:32:03 +00:00
Wes
a1e963f834
Reverse timestamps where necessary
2023-09-19 13:28:20 +00:00
Jason Ertel
8a98040008
Merge pull request #11351 from Security-Onion-Solutions/jertel/auto
...
ignore debian apt update output
2023-09-19 09:26:31 -04:00
Jason Ertel
47e611682a
ignore debian apt update output
2023-09-19 09:24:12 -04:00
Wes
5bac1e4d15
Show correct dates and Kibana URL for already processed EVTX files
2023-09-18 21:31:15 +00:00
Jason Ertel
ad025b9683
Merge pull request #11345 from Security-Onion-Solutions/jertel/auto
...
ensure all binds are present to avoid volume sprawl
2023-09-18 15:34:57 -04:00
Josh Patterson
3e97ddc22d
Merge pull request #11344 from Security-Onion-Solutions/fix/idstoolextra_env
...
fix idstool extra_env for container
2023-09-18 15:29:33 -04:00
m0duspwnens
151e8bfc4e
fix idstool extra_env for container
2023-09-18 15:21:45 -04:00
Jason Ertel
a914a02273
prune unused volumes during upgrade
2023-09-18 14:43:02 -04:00
Jason Ertel
bb3632d1b2
fix bind if statement
2023-09-18 14:38:15 -04:00
Jason Ertel
66bb1272ae
avoid volume sprawl
2023-09-18 13:39:56 -04:00
Jason Ertel
bbef96ac25
use unique name
2023-09-18 12:12:57 -04:00
Jason Ertel
f9cbde10a6
avoid volume sprawl
2023-09-18 11:19:21 -04:00
weslambert
fe1bae96ed
Merge pull request #11297 from Security-Onion-Solutions/fix/soc_idh
...
Change description to indicate that opencanary modules only apply to IDH nodes
2023-09-15 11:16:06 -04:00
weslambert
eab6173a31
Merge pull request #11329 from Security-Onion-Solutions/fix/elastic_templates_clean
...
Clean component template directory
2023-09-15 11:00:17 -04:00
Wes
98499c3963
Clean component template directory
2023-09-15 13:51:46 +00:00
Josh Patterson
26da525ebe
Merge pull request #11328 from Security-Onion-Solutions/fix/checkreq
...
improvents for checking system requirements
2023-09-15 09:17:04 -04:00
m0duspwnens
c65c9777bd
improvents for checking system requirements
2023-09-14 17:42:25 -04:00
Josh Brower
af68af7f18
Merge pull request #11317 from Security-Onion-Solutions/2.4/fixes
...
Regex & Transform Role
2023-09-14 10:59:56 -04:00
defensivedepth
0c11a9b733
Add transform role
2023-09-14 09:33:17 -04:00
defensivedepth
59d077f3ff
Fix regex
2023-09-14 08:32:17 -04:00
Jason Ertel
6383712731
Merge pull request #11315 from Security-Onion-Solutions/jertel/auto
...
exclude docker pull unauth errors from failing setup
2023-09-14 07:41:59 -04:00
Jason Ertel
e067b7134e
exclude docker pull unauth errors from failing setup since they'll be retried
2023-09-14 07:38:07 -04:00
Mike Reeves
183c530c82
Merge pull request #11308 from Security-Onion-Solutions/pcapfree
...
Update so-minion
2023-09-13 13:47:21 -04:00
Mike Reeves
33d68478b6
Update so-minion
2023-09-13 11:48:16 -04:00
Mike Reeves
22c0323bda
Update so-minion
2023-09-13 10:57:45 -04:00
Doug Burks
19114c1a26
Merge pull request #11303 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Config pcap doc links should point to steno docs #11302
2023-09-13 07:50:43 -04:00
Doug Burks
11b8e13418
FIX: SOC Config pcap doc links should point to steno docs #11302
2023-09-13 07:37:54 -04:00
Josh Patterson
6fdd7b3751
Merge pull request #11295 from Security-Onion-Solutions/issue/11229
...
dont manage sorules
2023-09-12 09:30:29 -04:00
m0duspwnens
30c3255cb2
dont manage sorules
2023-09-12 08:39:42 -04:00
Wes
35ebbc974c
Change description to indicate that opencanary modules only apply to IDH nodes
2023-09-11 13:52:16 +00:00
Wes
f1d0db8171
/app to /kibana/app
2023-09-11 13:30:11 +00:00
Josh Patterson
9968d697f3
Merge pull request #11288 from Security-Onion-Solutions/issue/11229
...
Issue/11229
2023-09-11 09:19:31 -04:00
m0duspwnens
02c54a264d
Merge remote-tracking branch 'origin/2.4/dev' into issue/11229
2023-09-08 15:29:04 -04:00
m0duspwnens
e814a3409f
fix rule location for rulecat.conf. run so-rule-update if rules change in /opt/so/rules/nids
2023-09-08 15:28:24 -04:00
Jason Ertel
55847c7bdc
Merge pull request #11276 from Security-Onion-Solutions/jertel/auto
...
give priority to presets
2023-09-08 09:26:27 -04:00
Jason Ertel
598515e5b4
give priority to presets
2023-09-08 09:21:13 -04:00
Jason Ertel
692625f8cd
Merge pull request #11271 from Security-Onion-Solutions/jertel/auto
...
addl node types
2023-09-07 17:25:08 -04:00
Jason Ertel
f8ae3f12e6
addl node types
2023-09-07 17:22:10 -04:00
Josh Patterson
3780ed1b4f
Merge pull request #11269 from Security-Onion-Solutions/issue/11210
...
Issue/11210
2023-09-07 16:54:16 -04:00
m0duspwnens
8d269fee30
Merge remote-tracking branch 'origin/2.4/dev' into issue/11210
2023-09-07 15:46:25 -04:00
m0duspwnens
35157f2e8b
add comment
2023-09-07 15:46:04 -04:00
m0duspwnens
60f1947eb4
prevent endgame_dict from being added to standard_actions if it is already present
2023-09-07 14:01:19 -04:00
m0duspwnens
ffaab4a1b4
only add endgame to action if it is populated
2023-09-06 14:19:53 -04:00
weslambert
70e1309c9f
Merge pull request #11261 from Security-Onion-Solutions/fix/remove_default_templates
...
Remove templates
2023-09-06 10:57:09 -04:00
Jason Ertel
5c0045f9f8
Merge pull request #11256 from Security-Onion-Solutions/jertel/sod
...
only ingest pfsense on sensor nodes
2023-09-05 12:50:47 -04:00
Jason Ertel
b66be9c226
only ingest pfsense on sensor nodes
2023-09-05 12:46:49 -04:00
Josh Patterson
651393988a
Merge pull request #11255 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-09-05 11:57:58 -04:00
Wes
cf19c8f8c2
Remove templates
2023-09-05 13:43:41 +00:00
Mike Reeves
ba3ae92702
Merge pull request #11249 from Security-Onion-Solutions/jertel/sod
2023-09-03 22:23:55 -04:00
Jason Ertel
8e2bed7f91
MS testing
2023-09-03 19:56:40 -04:00
Jason Ertel
028b69c7d4
Merge pull request #11245 from Security-Onion-Solutions/jertel/sod
...
ensure hostname is set
2023-09-02 13:49:49 -04:00
Jason Ertel
0cf913a7c1
ensure hostname is set
2023-09-02 06:05:37 -04:00
Jason Ertel
13fbcd712b
Merge pull request #11243 from Security-Onion-Solutions/jertel/sod
...
ensure hostname is set
2023-09-01 20:43:35 -04:00
Jason Ertel
0aae107155
ensure hostname is set
2023-09-01 20:30:53 -04:00
Mike Reeves
d2dcf7e7c1
Merge pull request #11241 from Security-Onion-Solutions/jertel/sod
2023-09-01 18:22:38 -04:00
Jason Ertel
6efdf1b9d0
add additional test modes
2023-09-01 17:24:12 -04:00
Jason Ertel
a11259c683
add additional test modes
2023-09-01 17:08:27 -04:00
Jason Ertel
863db14b61
add additional test modes
2023-09-01 16:27:02 -04:00
Jason Ertel
335aaa5594
add additional test modes
2023-09-01 15:30:53 -04:00
m0duspwnens
07ed93de19
add elastic agent to desktop
2023-09-01 14:33:32 -04:00
Jason Ertel
8093e5ce7c
use IP to avoid host issues
2023-09-01 13:01:17 -04:00
m0duspwnens
585fba4bc6
add functions salt_install_module_deps and salt_patch_x509_v2
2023-09-01 12:40:01 -04:00
weslambert
b8f69b5008
Merge pull request #11239 from Security-Onion-Solutions/fix/syslog_heavynode
...
Add so-elastic-agent
2023-09-01 12:20:44 -04:00
m0duspwnens
aebfb19ab7
add sostatus.sh to desktop for telegraf scripts
2023-09-01 12:05:28 -04:00
m0duspwnens
490669d378
add ssl to desktop for allowed_states
2023-09-01 12:03:01 -04:00
m0duspwnens
3434d0f200
add sensoroni and telegraf back to individual nodes. add seperate block for desktop
2023-09-01 12:02:30 -04:00
weslambert
765a22e6f0
Add so-elastic-agent
2023-09-01 11:31:23 -04:00
Jason Ertel
546c562ef0
expose standard relay timeout in config UI; up default to 45s to accommodate sluggish pillar.get calls
2023-09-01 10:31:02 -04:00
m0duspwnens
b64d4e3658
add telegraf pillar to desktop
2023-09-01 09:53:26 -04:00
m0duspwnens
0fb00d569e
allow states for desktop. give all nodes docker_clean, order it last
2023-09-01 09:39:39 -04:00
m0duspwnens
b64fa51268
give desktop docker state and pillars
2023-09-01 09:16:24 -04:00
Jason Ertel
1871d48f7f
remove unnecesary OTHER submenu
2023-08-31 20:42:00 -04:00
m0duspwnens
b010919099
add sensoroni, telegraf, common states to desktop. allow docker_registry connection to managers for desktop
2023-08-31 13:21:32 -04:00
weslambert
ce2a7135cb
Merge pull request #11232 from Security-Onion-Solutions/fix/strelka_entropy
...
Strelka entropy mapping
2023-08-31 11:21:00 -04:00
Wes
0fed757b11
Add entropy mapping
2023-08-31 15:10:27 +00:00
Wes
1a3b3b21fb
Change entropy value syntax
2023-08-31 15:09:19 +00:00
Josh Patterson
d86e21c751
Merge pull request #11231 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-08-31 10:54:30 -04:00
m0duspwnens
e408718230
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-31 09:56:02 -04:00
m0duspwnens
ee848b8a8c
comments for desktop install
2023-08-31 09:51:55 -04:00
m0duspwnens
a60c34d548
exclude unnecessary pillars from desktop nodes
2023-08-31 09:40:54 -04:00
Doug Burks
8a2fc5d62b
Merge pull request #11226 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md
2023-08-31 09:18:19 -04:00
Doug Burks
da56a421e5
Update motd.md
2023-08-31 09:17:33 -04:00
m0duspwnens
bfb0d0ddb5
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-31 08:58:28 -04:00
m0duspwnens
c812c3991e
we dont need to run convert-gnome-classic script
2023-08-31 08:54:13 -04:00
coreyogburn
ca9dad396f
Merge pull request #11222 from Security-Onion-Solutions/cogburn/11143
...
New Config Default: longRelayTimeoutMs
2023-08-30 15:47:01 -06:00
Corey Ogburn
a615fc8e47
New Config Default: longRelayTimeoutMs
...
Salt is getting a second timeout for operations known to take a long time such as sending and importing files. There's also an entry in soc_soc.yaml so the value can be changed in SOC's config page.
2023-08-30 15:33:01 -06:00
weslambert
ac38f32e32
Merge pull request #11218 from Security-Onion-Solutions/feature/soc_administration_analyzers
...
Analyzer SOC Administration
2023-08-30 16:54:02 -04:00
Josh Patterson
f2d1b9ac95
Merge pull request #11221 from Security-Onion-Solutions/issue/10975
...
iso desktop join grid - set install_type and minion_type
2023-08-30 16:50:46 -04:00
m0duspwnens
14a6280531
iso desktop join grid - set install_type and minion_type
2023-08-30 16:49:17 -04:00
weslambert
41300af944
Set global to false
2023-08-30 16:30:32 -04:00
weslambert
21e91a7537
Fix api_version
2023-08-30 16:10:38 -04:00
weslambert
4127e0fc53
Merge pull request #11219 from Security-Onion-Solutions/fix/elastic_fortigate
...
Correct Fortigate Integration
2023-08-30 15:54:39 -04:00
weslambert
d090852895
Correct fortigate template name
2023-08-30 15:40:40 -04:00
weslambert
78915f900b
Add fortigate package
2023-08-30 15:37:30 -04:00
Wes
8cc19b0748
Add analyzer configuration description
2023-08-30 19:16:38 +00:00
Wes
fe690922de
Add analyzer configuration to the defaults file
2023-08-30 19:16:05 +00:00
Josh Patterson
257a471383
Merge pull request #11217 from Security-Onion-Solutions/issue/10975
...
Issue/10975
2023-08-30 12:28:34 -04:00
weslambert
bee83a320b
Merge pull request #11212 from Security-Onion-Solutions/fix/elastic_heavynode_syslog
...
Add syslog to heavynode
2023-08-30 10:48:03 -04:00
m0duspwnens
b45e114ef2
cant use GLOBALS var due to desktop nongrid install
2023-08-30 10:41:34 -04:00
m0duspwnens
b14614ae53
need $ for vars
2023-08-30 10:32:13 -04:00
m0duspwnens
8381fa1d42
cant import globals because of nongrid desktop install~
2023-08-30 10:26:24 -04:00
m0duspwnens
a3eeba4761
do networking_needful for nongrid desktop network install
2023-08-30 09:51:09 -04:00
m0duspwnens
97587064f8
remove packages from nongrid desktop install
2023-08-30 09:48:52 -04:00
m0duspwnens
ae01da780e
desktop network install nongrid
2023-08-30 09:10:59 -04:00
Wes
60b0af5ab7
Allow external syslog
2023-08-30 13:05:30 +00:00
Wes
0e22acc255
Add tcp and udp integration
2023-08-30 13:04:32 +00:00
Wes
655eea2b00
Add port_bindings
2023-08-30 13:03:56 +00:00
Wes
ce05f29dc4
Add port_bindings for port 514
2023-08-30 13:03:28 +00:00
weslambert
7e12167b52
Merge pull request #11208 from Security-Onion-Solutions/fix/elasticsearch_syslog
...
Make sure a data stream is created for syslog
2023-08-30 08:37:39 -04:00
weslambert
706a6e2d56
Make sure a data stream is created for syslog
2023-08-30 08:34:04 -04:00
m0duspwnens
a4dc482372
add is_desktop_grid var
2023-08-29 13:10:06 -04:00
weslambert
f4191fb7fa
Merge pull request #11197 from Security-Onion-Solutions/feature/elastic_integration_apache
...
Add Apache package and templates
2023-08-29 11:27:08 -04:00
weslambert
d2063c7e11
Add auditd reference back
2023-08-29 11:14:49 -04:00
weslambert
c01a9006a6
Add Apache package
2023-08-29 11:01:22 -04:00
weslambert
f118e25e8c
Add Apache references
2023-08-29 11:00:31 -04:00
weslambert
d40bbf6b09
Add Apache templates
2023-08-29 10:59:40 -04:00
m0duspwnens
0455063a39
edit other/desktop install whiptail
2023-08-29 10:26:29 -04:00
m0duspwnens
532b2c222a
edit other/desktop install whiptail
2023-08-29 10:16:51 -04:00
m0duspwnens
67ea7d31e1
dont exec so-setup desktop
2023-08-29 09:32:10 -04:00
m0duspwnens
a1b1294247
desktop doesnt need docker state
2023-08-29 09:05:01 -04:00
m0duspwnens
1c3d3d703c
add desktop.map.jinja for global vars
2023-08-29 08:56:01 -04:00
m0duspwnens
9c3e3f8e06
Merge remote-tracking branch 'origin/2.4/dev' into issue/10975
2023-08-28 15:42:04 -04:00
Mike Reeves
48e5cf7e67
Merge pull request #11193 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Heavy Node for acks
2023-08-28 14:42:10 -04:00
Mike Reeves
bd61ee22be
Update defaults.map.jinja
2023-08-28 14:41:06 -04:00
Josh Patterson
4f8a0c4173
Merge pull request #11190 from Security-Onion-Solutions/failreposync
...
Failreposync
2023-08-28 12:01:44 -04:00
m0duspwnens
6b0fbe4634
include so-repo-sync in soup_manager_scripts state
2023-08-28 11:53:45 -04:00
Jason Ertel
2616a2bba3
Merge pull request #11186 from Security-Onion-Solutions/jertel/alts
...
fix path to intermediate ca cert on heavy nodes
2023-08-28 11:10:04 -04:00
Jason Ertel
c10e686ec6
fix path to intermediate ca cert on heavy nodes
2023-08-28 11:07:28 -04:00
m0duspwnens
a8ec3717c4
fail soup if so-repo-sync fails
2023-08-28 10:20:53 -04:00
Josh Patterson
7dc855bbbe
Merge pull request #11184 from Security-Onion-Solutions/wheelwatchdog
...
dont need to repo_sync rocky or centos
2023-08-28 09:53:34 -04:00
m0duspwnens
1ef4d2cde1
dont need to repo_sync rocky or centos
2023-08-28 09:37:45 -04:00
Jason Ertel
8c5aa4a0e6
Merge pull request #11178 from Security-Onion-Solutions/jertel/alts
...
ingest pfsense sample data
2023-08-25 16:53:41 -04:00
Jason Ertel
5879eeabfa
ingest pfsense sample data
2023-08-25 16:45:31 -04:00
Jason Ertel
022ee36bca
ingest pfsense sample data
2023-08-25 16:44:03 -04:00
Josh Patterson
aacd689bae
Merge pull request #11177 from Security-Onion-Solutions/wheelwatchdog
...
new python watchdog
2023-08-25 15:32:52 -04:00
m0duspwnens
388c90f641
add oel to set_os
2023-08-25 14:56:42 -04:00
m0duspwnens
c22f9687fb
sync local repo in soup
2023-08-25 13:40:34 -04:00
m0duspwnens
0a88c812e8
differnet watchdog package names for debian vs redhat fams
2023-08-25 13:03:33 -04:00
m0duspwnens
e28ff38d39
Merge remote-tracking branch 'origin/2.4/dev' into wheelwatchdog
2023-08-25 09:40:16 -04:00
m0duspwnens
ab1d97c985
restart filecheck if watchdog pkg changes
2023-08-25 09:39:16 -04:00
m0duspwnens
4a489afb89
remove old and install new watchdog package
2023-08-25 08:55:00 -04:00
Jason Ertel
c957c6ce14
Merge pull request #11169 from Security-Onion-Solutions/jertel/alts
...
fix centos install
2023-08-24 15:06:10 -04:00
Jason Ertel
e57cc03084
fix centos install
2023-08-24 14:41:04 -04:00
Jason Ertel
3a0590f950
Merge pull request #11166 from Security-Onion-Solutions/jertel/alts
...
use the correct var
2023-08-24 13:08:35 -04:00
Jason Ertel
43e4cf632a
use the correct var
2023-08-24 12:57:35 -04:00
Jason Ertel
92c6229e00
Merge pull request #11165 from Security-Onion-Solutions/jertel/alts
...
allow testing runs to proceed with unsupported os
2023-08-24 12:30:07 -04:00
Jason Ertel
8252924203
allow testing runs to proceed with unsupported os
2023-08-24 12:16:25 -04:00
Jason Ertel
bdb88cc87b
Merge pull request #11161 from Security-Onion-Solutions/jertel/alts
...
use consistent cert dir and reduce jinja complexity
2023-08-24 11:18:34 -04:00
Jason Ertel
f4be5641da
cert work
2023-08-23 20:49:37 -04:00
Jason Ertel
4484e2d031
cert work
2023-08-23 18:16:49 -04:00
Jason Ertel
b8dc9ea560
cert work
2023-08-23 17:50:08 -04:00
weslambert
d4bffba736
Merge pull request #11153 from Security-Onion-Solutions/fix/elastic_fleet_integrations
...
Add more Elastic Fleet integrations
2023-08-23 16:22:14 -04:00
Wes
d2d0d53eef
Change order
2023-08-23 20:20:44 +00:00
Wes
31a49268cb
Add o365 and okta
2023-08-23 20:20:06 +00:00
Wes
2f51349ff8
Add SOC configuration
2023-08-23 20:07:42 +00:00
m0duspwnens
a885baf960
add desktop to grid
2023-08-23 15:24:32 -04:00
Wes
3f2793088a
Add templates
2023-08-23 19:02:50 +00:00
Wes
0f24c8e8bb
Add packages
2023-08-23 19:02:32 +00:00
Jason Ertel
8a751e097d
cert path refactor
2023-08-23 14:32:05 -04:00
weslambert
4a582804b0
Merge pull request #11139 from Security-Onion-Solutions/fix/soc_event_fields
...
Update SOC event fields
2023-08-22 10:46:38 -04:00
Mike Reeves
f278056493
Merge pull request #11129 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update HOTFIX
2023-08-21 16:30:34 -04:00
Mike Reeves
f2c665e4fa
Update HOTFIX
2023-08-21 16:30:02 -04:00
Mike Reeves
ce32a0081e
Merge pull request #11128 from Security-Onion-Solutions/2.4/main
...
Merge in hotfix
2023-08-21 16:29:40 -04:00
Mike Reeves
658d132c38
Merge pull request #11127 from Security-Onion-Solutions/hotfix/2.4.10
...
Hotfix/2.4.10
2023-08-21 16:26:27 -04:00
Mike Reeves
7d2f39a06f
Merge pull request #11126 from Security-Onion-Solutions/2410hf
...
2.4.10 Hotfix
2023-08-21 15:39:07 -04:00
Mike Reeves
84d5d52ec8
2.4.10 Hotfix
2023-08-21 15:36:57 -04:00
weslambert
563a495725
Add Playbook
2023-08-21 11:24:07 -04:00
weslambert
9e18fe64cf
Remove OSSEC configuration
2023-08-21 11:20:47 -04:00
weslambert
708a681ed9
Merge pull request #11123 from Security-Onion-Solutions/fix/elastic_fleet_zeek_console
...
Exclude console log
2023-08-21 10:31:32 -04:00
Josh Patterson
a40937409a
Merge pull request #11124 from Security-Onion-Solutions/issue/11122
...
add missing containers to soc_docker.yaml. force port bindings to []string
2023-08-21 10:28:32 -04:00
m0duspwnens
b8d374b2af
add missing containers to soc_docker.yaml. force port bindings to []string
2023-08-21 09:45:23 -04:00
weslambert
fa31bd4bf7
Exclude console log
2023-08-21 09:20:49 -04:00
Mike Reeves
847aab2712
Merge pull request #11120 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update config.sls
2023-08-21 09:17:11 -04:00
Mike Reeves
710b800bc2
Update config.sls
2023-08-21 09:00:11 -04:00
Josh Brower
c92b359b79
Merge pull request #11116 from Security-Onion-Solutions/2.4/hotfixcerts
...
Fix certs on Rec and Heavy
2023-08-21 07:30:44 -04:00
Josh Brower
e2fd371886
Fix certs on Rec and Heavy
2023-08-21 07:26:37 -04:00
Josh Brower
5b453ca972
Merge pull request #11113 from Security-Onion-Solutions/2.4/rec-certs-fix
...
Fix certs for Rec & Heavy
2023-08-21 07:03:58 -04:00
Josh Brower
6784bdcb54
Fix certs for Rec & Heavy
2023-08-20 15:46:07 -04:00
Mike Reeves
7e4036f2a5
Merge pull request #11101 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Fix Hotfix
2023-08-18 15:45:08 -04:00
Mike Reeves
421cfc46ad
Update soup
2023-08-18 15:39:58 -04:00
Mike Reeves
0d4a49a0ff
Update so-setup
2023-08-18 15:34:36 -04:00
Mike Reeves
6453a86c2a
Merge pull request #11098 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2023-08-18 10:10:48 -04:00
Mike Reeves
d657bbdc18
Merge pull request #11100 from Security-Onion-Solutions/jertel/souptest
...
force soup docker output to log
2023-08-18 09:59:24 -04:00
Jason Ertel
8aeb4706e1
force soup docker output to log
2023-08-18 09:57:51 -04:00
Mike Reeves
e04ec1042a
Update soup
2023-08-18 09:12:19 -04:00
Josh Patterson
e77e5c3cea
Merge pull request #11090 from Security-Onion-Solutions/issue/10998
...
Issue/10998
2023-08-17 17:27:45 -04:00
Jason Ertel
222352b4b3
fix typo
2023-08-17 17:26:35 -04:00
m0duspwnens
4ac95447eb
pop sort settings if index_sorting is false
2023-08-17 16:15:27 -04:00
m0duspwnens
9cba9d9ae0
allow to override number_of_replicas from one place in soc ui
2023-08-17 15:00:01 -04:00
Mike Reeves
056072af7d
Merge pull request #11088 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2023-08-17 14:51:25 -04:00
Mike Reeves
fb3fee5d4b
Update HOTFIX
2023-08-17 14:43:35 -04:00
Jason Ertel
e7be8991f1
Merge pull request #11083 from Security-Onion-Solutions/jertel/souptty
...
force image pulls to go into soup log
2023-08-17 13:47:37 -04:00
Jason Ertel
09dd3f529b
force image pulls to go into soup log
2023-08-17 13:45:51 -04:00
weslambert
488c4d5000
Merge pull request #11079 from Security-Onion-Solutions/fix/import_evtx_pcap
...
Assign pipeline to import
2023-08-17 12:29:01 -04:00
Mike Reeves
abad833c5e
Merge pull request #11075 from Security-Onion-Solutions/2.4/soupmods
...
Add soup for 2.4.20
2023-08-17 10:53:52 -04:00
Mike Reeves
4363e71e80
Add soup for 2.4.20
2023-08-17 10:51:59 -04:00
Wes
7971d9749a
Assign pipeline to import
2023-08-17 14:08:48 +00:00
weslambert
5ebe33d45f
Merge pull request #11068 from Security-Onion-Solutions/fix/elastic_fleet_package_force_2
...
Fix so-elastic-fleet-package-load
2023-08-17 08:20:24 -04:00
weslambert
4887eb4957
Update so-elastic-fleet-package-load
2023-08-16 22:31:14 -04:00
weslambert
0620919241
Merge pull request #11064 from Security-Onion-Solutions/fix/elasticfleet_package_force
...
Force package installation
2023-08-16 16:37:39 -04:00
Wes
e84d624d23
Force package installation
2023-08-16 20:10:20 +00:00
Josh Patterson
45bc2ec380
Merge pull request #11060 from Security-Onion-Solutions/issue/10922
...
set timezone during setup. set salt log levels to info
2023-08-16 10:47:13 -04:00
m0duspwnens
9bf7b9bda5
set the timezone earlier in setup
2023-08-16 10:02:47 -04:00
m0duspwnens
ab19fa9ece
set salt log levels to info
2023-08-16 09:21:06 -04:00
m0duspwnens
53d7d69135
update salt docs url in service file
2023-08-16 08:46:24 -04:00
m0duspwnens
b22776dc5a
set timezone to etc/utc during setup
2023-08-15 16:22:02 -04:00
Mike Reeves
dc6d9d4ba2
Merge pull request #11047 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-08-15 07:29:34 -04:00
Mike Reeves
075ef5e02c
Update VERSION
2023-08-15 07:27:48 -04:00
Mike Reeves
16da0b469a
Merge pull request #11040 from Security-Onion-Solutions/2.4/dev
...
2.4.10
2023-08-15 07:14:03 -04:00
Mike Reeves
5c2c2908b8
Merge pull request #11044 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update DOWNLOAD_AND_VERIFY_ISO.md
2023-08-14 16:52:53 -04:00
Mike Reeves
ad9da07de1
Update DOWNLOAD_AND_VERIFY_ISO.md
2023-08-14 16:51:24 -04:00
Jason Ertel
d1210e946c
Merge pull request #11043 from Security-Onion-Solutions/jertel/up
...
Jertel/up
2023-08-14 16:46:21 -04:00
Jason Ertel
5d6fe4d9ae
Merge branch '2.4/main' into jertel/up
2023-08-14 16:44:13 -04:00
Mike Reeves
193f9c08fb
Merge pull request #11042 from Security-Onion-Solutions/2.4.10
...
2.4.10
2023-08-14 16:41:21 -04:00
Mike Reeves
4808c21cf4
2.4.10
2023-08-14 16:34:32 -04:00
Mike Reeves
4106d1f69d
2.4.10
2023-08-14 16:33:08 -04:00
Jason Ertel
007720132b
Merge pull request #11034 from Security-Onion-Solutions/dougburks-patch-1
...
soup should respect current indentation in soc_global.sls
2023-08-13 16:56:50 -04:00
Doug Burks
f3a58cd336
soup should respect current indentation in soc_global.sls
2023-08-13 16:46:32 -04:00
Josh Brower
faca36e74c
Merge pull request #11021 from Security-Onion-Solutions/2.4/esurlfixup
...
Set default for import and eval only
2023-08-12 08:41:54 -04:00
Josh Brower
f38b77892b
Move back
2023-08-11 17:14:48 -04:00
Josh Brower
00297cd864
Move from post to pre
2023-08-11 16:10:16 -04:00
Josh Brower
ce63e47fcd
Enable forced update
2023-08-11 14:47:33 -04:00
Jason Ertel
d53489d674
Merge pull request #11023 from Security-Onion-Solutions/jertel/fixann
...
add missing annotations to avoid soc crash
2023-08-11 13:58:40 -04:00
Jason Ertel
1fb3a59573
add missing annotations to avoid soc crash
2023-08-11 13:41:58 -04:00
Jason Ertel
a5e60363cf
add missing annotations to avoid soc crash
2023-08-11 13:38:16 -04:00
Josh Brower
3f054031a0
Set default for import and eval only
2023-08-11 13:32:22 -04:00
Josh Patterson
4a54febf38
Merge pull request #11016 from Security-Onion-Solutions/issue/10957
...
set SO desktop wallpaper for iso install
2023-08-11 09:22:05 -04:00
m0duspwnens
fdb2ca4167
set SO desktop wallpaper for iso install
2023-08-11 09:15:41 -04:00
Josh Brower
7112d53d4d
Merge pull request #11014 from Security-Onion-Solutions/2.4/templateloadfix
...
Upgrade integration packages
2023-08-10 20:00:57 -04:00
Josh Brower
1d83b2f2e6
Add elasticsearch integration
2023-08-10 19:51:12 -04:00
Josh Brower
a724b95441
Merge branch '2.4/dev' into 2.4/templateloadfix
2023-08-10 19:01:24 -04:00
Josh Brower
0d894b7f52
Upgrade integration packages
2023-08-10 18:57:17 -04:00
Josh Patterson
e32d7eb127
Merge pull request #11012 from Security-Onion-Solutions/issue/10957
...
set desktop background
2023-08-10 16:27:56 -04:00
m0duspwnens
caced64d11
set desktop background
2023-08-10 16:10:39 -04:00
Doug Burks
3ec3f8bcd8
Merge pull request #11011 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md
2023-08-10 15:17:20 -04:00
Doug Burks
4426437ad3
Update motd.md
2023-08-10 15:04:31 -04:00
Josh Patterson
1f0f74ff04
Merge pull request #11009 from Security-Onion-Solutions/fix/soruleupdate
...
ensure only 1 instance of so-rule-update runs. execute the cmd at the end of state run
2023-08-10 12:04:42 -04:00
m0duspwnens
e43900074a
ensure only 1 instance of so-rule-update runs. execute the cmd at the end of state run
2023-08-10 11:54:49 -04:00
Josh Patterson
732d2605a7
Merge pull request #11008 from Security-Onion-Solutions/fix/esanno
...
Fix/esanno
2023-08-10 11:32:14 -04:00
m0duspwnens
4d497022db
replace . with _x_ for soc ui compat
2023-08-10 09:52:18 -04:00
Josh Brower
2680a50927
Merge pull request #11004 from Security-Onion-Solutions/2.4/esurlfix
...
Unset defaults
2023-08-10 08:50:56 -04:00
Josh Brower
874dab7535
Unset defaults
2023-08-09 19:02:53 -04:00
Josh Brower
fe9917ef1c
Merge pull request #11002 from Security-Onion-Solutions/2.4/fixfqdn
...
Move base_url to cert SAN
2023-08-09 16:41:09 -04:00
Josh Brower
e844cf11db
Move base_url to cert SAN
2023-08-09 16:38:27 -04:00
m0duspwnens
f9e272dd8f
add additional annotations for elasticsearch index settings
2023-08-09 16:09:23 -04:00
m0duspwnens
dfe916d7c8
add annotation for so-logs index
2023-08-09 15:19:17 -04:00
Josh Patterson
c3c769922d
Merge pull request #11000 from Security-Onion-Solutions/issue/10954
...
Issue/10954
2023-08-09 11:31:55 -04:00
m0duspwnens
30e3fbb41c
remove extra )
2023-08-09 11:21:16 -04:00
m0duspwnens
78694807ff
Merge remote-tracking branch 'origin/2.4/dev' into issue/10954
2023-08-09 11:19:19 -04:00
m0duspwnens
8844e305ab
use sensor.interface for suricata. make af-packet.interface ro in soc ui
2023-08-09 11:18:47 -04:00
Josh Brower
1a37c43c98
Merge pull request #10997 from Security-Onion-Solutions/2.4/autoupgrade
...
Enable Agent Upgrade Check during highstate
2023-08-09 10:58:26 -04:00
Josh Brower
bf78faa0f0
Enable upgrade check during state run
2023-08-09 10:43:34 -04:00
Josh Brower
204ef7e68f
Merge pull request #10994 from Security-Onion-Solutions/2.4/autoupgrade
...
RC2 Fixes
2023-08-09 09:47:57 -04:00
Josh Patterson
176608d2f9
Merge pull request #10995 from Security-Onion-Solutions/fix/desktop
...
Fix/desktop
2023-08-09 09:34:44 -04:00
m0duspwnens
28dfdbf06d
securityonion_desktop is just desktop
2023-08-09 08:51:39 -04:00
m0duspwnens
a443c654e5
fix desktop pillar in setup
2023-08-09 08:48:00 -04:00
m0duspwnens
6413050f2e
set doc_desktop_url before jinja
2023-08-09 08:39:46 -04:00
m0duspwnens
fe7a940082
add details for enabling in soc gui
2023-08-09 08:31:54 -04:00
Josh Brower
e586d6b967
Extract Elastic Agent tarball for airgap soup
2023-08-09 08:30:19 -04:00
m0duspwnens
2d25e352d4
write to adv_ pillar file since that is where it would be stored from using the soc ui
2023-08-09 08:18:13 -04:00
Josh Brower
4297d51a2d
Refactor for multiple agents
2023-08-09 08:14:52 -04:00
m0duspwnens
1440c72559
changes for desktop referencing Rocky/CentOS to OEL
2023-08-09 08:06:51 -04:00
m0duspwnens
00efc2f88f
rename workstation to desktop for firewall
2023-08-09 07:31:31 -04:00
Josh Patterson
d55c2f889c
Merge pull request #10989 from Security-Onion-Solutions/issue/10973
...
Issue/10973
2023-08-08 19:35:02 -04:00
Josh Brower
e1e535b009
Retry if exit code is error
2023-08-08 18:38:18 -04:00
m0duspwnens
789fff561e
ensure ownership of /opt/so/log/strelka/filecheck.log
2023-08-08 17:55:30 -04:00
m0duspwnens
58fe25623b
ensure ownership of /opt/so/log/strelka/filecheck_stdout.log
2023-08-08 17:48:34 -04:00
m0duspwnens
553b758c61
update cronjobs first, the kill filecheck
2023-08-08 17:28:14 -04:00
m0duspwnens
6da2f117f2
change which user runs filecheck cron based on md engine
2023-08-08 17:25:08 -04:00
Doug Burks
6ad22edf8e
Merge pull request #10987 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.4.10
2023-08-08 17:18:38 -04:00
m0duspwnens
2dbe679849
force restart of filecheck if the config changes
2023-08-08 17:05:03 -04:00
Doug Burks
2f74b69cc3
Update soup for 2.4.10
2023-08-08 16:27:11 -04:00
bryant-treacle
4320dab856
Merge pull request #10986 from Security-Onion-Solutions/fix/windows_event_table
...
Fix/windows event table
2023-08-08 16:23:14 -04:00
bryant-treacle
036b81707b
Update defaults.yaml
2023-08-08 16:10:54 -04:00
Josh Brower
8455d3da6f
Merge pull request #10977 from Security-Onion-Solutions/2.4/squashbug
...
Set as default
2023-08-08 15:55:58 -04:00
bryant-treacle
3d4fd08547
Update defaults.yaml
2023-08-08 15:28:06 -04:00
m0duspwnens
21c80e4953
run so-rule-update after idstools container restart
2023-08-08 15:27:23 -04:00
m0duspwnens
5c704d7e58
run so-rule-update if idstools configs change
2023-08-08 15:20:44 -04:00
m0duspwnens
230f5868f9
sync sorules
2023-08-08 15:14:27 -04:00
m0duspwnens
20dedab4b2
remove previously add rules files
2023-08-08 15:03:06 -04:00
m0duspwnens
9118ac2b56
filter.rules to filters.rules
2023-08-08 13:59:43 -04:00
m0duspwnens
aab89d2483
rule-files does not go under profiling
2023-08-08 13:54:58 -04:00
m0duspwnens
b2e75e77e8
add local.rules and filter.rules to suricata defaults. add extraction.rules, local.rules and filter.rules for suricata metadata
2023-08-08 13:50:19 -04:00
Josh Patterson
bcd1ccd91b
Merge pull request #10983 from Security-Onion-Solutions/fix/tgrafzeekcloss
...
Fix/tgrafzeekcloss
2023-08-08 10:19:46 -04:00
m0duspwnens
673b45af09
import ZEEKMERGED
2023-08-08 09:41:42 -04:00
m0duspwnens
a06040c035
add WORKERS calculation back to zeekcaptureloss script
2023-08-08 09:37:37 -04:00
m0duspwnens
e286b8f2ba
Merge remote-tracking branch 'origin/2.4/dev' into fix/tgrafzeekcloss
2023-08-08 09:36:12 -04:00
m0duspwnens
69553f9017
removes spaces from zeekcaptureloss script
2023-08-08 09:34:59 -04:00
m0duspwnens
609a2bf32e
only import ZEEKMERGED if a sensor type node
2023-08-08 09:27:03 -04:00
Jason Ertel
dad541423d
Merge pull request #10978 from Security-Onion-Solutions/jertel/bumpver
...
update version
2023-08-07 16:36:10 -04:00
Jason Ertel
b9d0d03223
update version
2023-08-07 16:35:05 -04:00
Josh Brower
8611d1848c
Set as default
2023-08-07 15:55:53 -04:00
m0duspwnens
5278601e5d
manage telegraf scripts with a defaults file assigned per node type
2023-08-07 11:18:35 -04:00
Jason Ertel
5c7c3fb996
avoid rare false positive when dasbhoard load completes during setup
2023-07-31 16:09:36 -04:00
Jason Ertel
f4907a5b5c
Merge branch '2.4/dev' into kilo
2023-07-28 14:15:14 -04:00
Jason Ertel
a5c4783564
oidc
2023-07-27 18:36:50 -04:00
Jason Ertel
d3e83d154b
Merge branch '2.4/t dev' into kilo
2023-07-27 10:20:22 -04:00
Jason Ertel
aa36e9a785
oidc
2023-07-27 08:40:27 -04:00
Jason Ertel
b712d505f2
update version to use kilo images
2023-07-26 09:21:23 -04:00
Jason Ertel
6d56deb2e4
oidc 1
2023-07-25 08:12:45 -04:00
Jason Ertel
101e2e8ba1
do not redirect to API URLs when not logged in
2023-07-24 17:05:52 -04:00
Jason Ertel
83bff72cd4
Merge branch '2.4/dev' into kilo
2023-07-18 10:49:12 -04:00
Jason Ertel
b24afac0f4
upgrade registry version
2023-07-18 10:48:42 -04:00
Jason Ertel
b129b4ceaa
prepare for alt login
2023-07-14 17:03:20 -04:00