Mike Reeves
e4d2513609
Merge pull request #14479 from Security-Onion-Solutions/patch/2.4.141
...
2.4.141
2025-03-31 11:21:30 -04:00
Mike Reeves
22fae2e98d
Merge pull request #14478 from Security-Onion-Solutions/2.4.141
...
2.4.141
2025-03-31 10:38:30 -04:00
Mike Reeves
3850558be3
2.4.141
2025-03-31 10:37:04 -04:00
Jason Ertel
99aa383e01
soup and version updates
2025-03-26 12:11:53 -04:00
Mike Reeves
7a71a5369c
Merge pull request #14439 from Security-Onion-Solutions/2.4/dev
...
2.4.140
2025-03-24 15:08:43 -04:00
Mike Reeves
964b631d58
Merge pull request #14438 from Security-Onion-Solutions/2.4.140
...
2.4.140
2025-03-24 13:43:49 -04:00
Mike Reeves
dcb667b32d
2.4.140
2025-03-24 13:35:39 -04:00
Josh Patterson
60bd960251
Merge pull request #14434 from Security-Onion-Solutions/backto3006.9
...
roll back to 3006.9 but leave prep in place for future upgrades
2025-03-23 12:09:52 -04:00
Josh Patterson
b974c6e8df
roll back to 3006.9 but leave prep in place for future upgrades
2025-03-23 12:07:39 -04:00
Josh Patterson
7484495021
Merge pull request #14433 from Security-Onion-Solutions/soupupdatemine140
...
update mine
2025-03-22 12:59:22 -04:00
Josh Patterson
0952b7528f
update mine
...
update mine after salt-master restart and before highstate
2025-03-22 12:57:13 -04:00
Josh Brower
14c95a5fe0
Merge pull request #14432 from Security-Onion-Solutions/jbfix
...
Remove pcapoutdir
2025-03-22 07:13:44 -04:00
Josh Brower
d0bb86a24f
Remove pcapoutdir
2025-03-22 07:12:19 -04:00
Jorge Reyes
749825af19
Merge pull request #14429 from Security-Onion-Solutions/reyesj2-patch-3
...
FIX: elastic fleet package list get more than 300 results per query
2025-03-21 15:07:15 -05:00
reyesj2
844283cc38
get more results
2025-03-21 14:55:52 -05:00
Jason Ertel
ae0bf1ccdf
Merge pull request #14428 from Security-Onion-Solutions/jertel/wip
...
ignore false positives
2025-03-21 14:56:56 -04:00
Jason Ertel
a0637fa25d
ignore false positives
2025-03-21 14:54:52 -04:00
Josh Patterson
d2a21c1e4c
Merge pull request #14427 from Security-Onion-Solutions/pcapperms
...
move pcapoutdir
2025-03-21 14:50:33 -04:00
Josh Patterson
ed23340157
move pcapoutdir
2025-03-21 14:48:31 -04:00
Jason Ertel
ef6dbf9e46
Merge pull request #14425 from Security-Onion-Solutions/jertel/wip
...
support pcap imports for sensors in distributed grids
2025-03-21 13:17:18 -04:00
Jason Ertel
1236c8c1f2
support pcap imports for sensors in distributed grids
2025-03-21 10:34:55 -04:00
Josh Patterson
51625e19ad
Merge pull request #14423 from Security-Onion-Solutions/salt3006.10
...
work with quotes in version
2025-03-21 08:25:55 -04:00
Josh Patterson
760ff1e45b
work with quotes in version
2025-03-21 08:20:04 -04:00
Josh Patterson
5b3fa17f81
Merge pull request #14422 from Security-Onion-Solutions/salt3006.10
...
fix SALTVERSION grep to work with or without quote
2025-03-20 17:01:17 -04:00
Josh Patterson
053eadbb39
fix SALTVERSION grep to work with or without quote
2025-03-20 16:58:16 -04:00
Josh Patterson
540b0de00c
Merge pull request #14420 from Security-Onion-Solutions/salt3006.10
...
Salt3006.10
2025-03-20 15:50:10 -04:00
Josh Patterson
c30cbf9af0
remove salt-cloud
2025-03-20 15:44:56 -04:00
Josh Patterson
41c0a91d77
ensure versions are strings
2025-03-20 15:42:16 -04:00
Josh Patterson
6e1e5a2ee6
Merge pull request #14419 from Security-Onion-Solutions/salt3006.10
...
make string to not drop 0
2025-03-20 15:31:05 -04:00
Josh Patterson
aa8fd647b6
make string to not drop 0
2025-03-20 15:27:52 -04:00
Mike Reeves
8feae6ba11
Merge pull request #14416 from Security-Onion-Solutions/salt3006.10
...
add bootstrap-salt to preloaded soup_scripts
2025-03-20 13:48:46 -04:00
Josh Patterson
028297cef8
add bootstrap-salt to preloaded soup_scripts
2025-03-20 13:46:30 -04:00
Mike Reeves
19755d4077
Merge pull request #14413 from Security-Onion-Solutions/bootstrap-salt-2025.02.24
...
Update bootstrap-salt.sh
2025-03-20 13:38:34 -04:00
Mike Reeves
cd655e6adb
Merge pull request #14415 from Security-Onion-Solutions/salt3006.10
...
upgrade salt 3006.10
2025-03-20 13:37:26 -04:00
Josh Patterson
2be143d902
upgrade salt 3006.10
2025-03-20 13:22:28 -04:00
Josh Patterson
1b98f9f313
Update bootstrap-salt.sh
2025-03-20 10:03:26 -04:00
Jason Ertel
762ccdd222
Merge pull request #14403 from Security-Onion-Solutions/jertel/wip
...
add no-op soup functions for 2.4.140
2025-03-19 07:24:14 -04:00
Jason Ertel
277504fff6
Merge pull request #14402 from Security-Onion-Solutions/reyesj2-patch-3
...
ldap_search include observer.name
2025-03-18 10:27:16 -04:00
Jason Ertel
3f3e7ea1e8
add no-op soup functions for 2.4.140
2025-03-18 10:12:23 -04:00
reyesj2
4d7fdd390c
ldap_search include observer.name
2025-03-18 08:52:43 -05:00
Jason Ertel
05c93e3796
Merge pull request #14394 from Security-Onion-Solutions/jertel/wip
...
use specified role on new user add
2025-03-17 17:10:45 -04:00
Jorge Reyes
fe21a19c5c
Merge pull request #14396 from Security-Onion-Solutions/reyesj2-patch-3
...
add zeek file_extraction forcedType for instances where a single line…
2025-03-17 14:40:40 -05:00
reyesj2
af6245f19d
add zeek file_extraction forcedType for instances where a single line is speciifed
2025-03-17 14:30:17 -05:00
Jason Ertel
ad8f3dfde7
use specified role on new user add
2025-03-17 14:55:40 -04:00
Jorge Reyes
d23b6958c1
Merge pull request #14379 from Security-Onion-Solutions/reyesj2-patch-3
...
update event pipeline annotation
2025-03-12 13:22:40 -05:00
reyesj2
60b1535018
update event pipeline annotation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-03-12 13:15:57 -05:00
Mike Reeves
758c6728f9
Merge pull request #14375 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2025-03-11 13:27:21 -04:00
Mike Reeves
5234b21743
Update 2-4.yml
2025-03-11 13:25:43 -04:00
Mike Reeves
7d73f6cfd7
Update VERSION
2025-03-11 13:25:00 -04:00
Mike Reeves
fb54c2f533
Merge pull request #14373 from Security-Onion-Solutions/2.4/dev
...
2.4.130
2025-03-11 13:14:26 -04:00
Mike Reeves
e20364cdf5
Merge pull request #14372 from Security-Onion-Solutions/2.4.130
...
2.4.130
2025-03-11 12:10:39 -04:00
Mike Reeves
a9484b4ca9
2.4.130
2025-03-11 12:01:01 -04:00
Josh Brower
6081c46d7f
Merge pull request #14362 from Security-Onion-Solutions/reyesj2-patch-2
...
fix osquery action_data mapping conflict
2025-03-08 10:18:12 -05:00
reyesj2
4dd72ad15c
fix osquery action_data mapping conflict
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-03-07 17:05:13 -06:00
Jason Ertel
4893eda4fe
Merge pull request #14359 from Security-Onion-Solutions/jertel/wip
...
Improve label
2025-03-07 08:44:12 -05:00
Jason Ertel
2af05b9a23
switch back to colon for better clarity
2025-03-07 08:24:19 -05:00
Jason Ertel
0bb76aecb3
Merge branch '2.4/dev' into jertel/wip
2025-03-07 08:23:18 -05:00
Mike Reeves
53ab7a223d
Merge pull request #14358 from Security-Onion-Solutions/dougburks-patch-1
2025-03-07 07:21:14 -05:00
Doug Burks
3037dc7c38
Update soc_soc.yaml to fix previous change
2025-03-07 07:13:27 -05:00
Mike Reeves
bde8a965f3
Merge pull request #14357 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soc_soc.yaml
2025-03-06 21:12:24 -05:00
Mike Reeves
14e95f4898
Update soc_soc.yaml
2025-03-06 21:01:45 -05:00
Mike Reeves
bad0031829
Update soc_soc.yaml
2025-03-06 20:58:23 -05:00
Doug Burks
630140b979
Merge pull request #14354 from Security-Onion-Solutions/dougburks-patch-1
...
Update soc_elasticsearch.yaml to include note about ILM rollover
2025-03-06 12:11:58 -05:00
Doug Burks
cce94d96d1
Update soc_elasticsearch.yaml to include note about ILM rollover
2025-03-06 11:14:48 -05:00
Mike Reeves
bcea02b059
Merge pull request #14301 from Security-Onion-Solutions/truefalse
...
Update annotations for new features
2025-03-05 16:23:00 -05:00
Mike Reeves
03ebc2d86e
Add Actions
2025-03-05 15:58:10 -05:00
Mike Reeves
3021ed5d36
Add Actions
2025-03-05 15:56:26 -05:00
Jorge Reyes
e59ebc89f8
Merge pull request #14346 from Security-Onion-Solutions/reyesj2-patch-2
...
bump version
2025-03-05 14:40:36 -06:00
reyesj2
6a5377ceac
bump version
2025-03-05 14:39:01 -06:00
Jorge Reyes
515cb3aea8
Merge pull request #14345 from Security-Onion-Solutions/reyesj2-patch-2
...
osquery templates
2025-03-05 14:28:08 -06:00
Mike Reeves
b51aa56e86
Some things I thought were bools are not bools
2025-03-05 15:15:26 -05:00
reyesj2
d2884ef00b
typo
2025-03-05 14:02:45 -06:00
reyesj2
0f16b00563
osquery templates
2025-03-05 13:57:47 -06:00
Mike Reeves
b01fb733a9
Some things I thought were bools are not bools
2025-03-05 14:56:26 -05:00
Mike Reeves
945a467ec8
Some things I thought were bools are not bools
2025-03-05 14:54:17 -05:00
Mike Reeves
67f9cd39db
Some things I thought were bools are not bools
2025-03-05 14:53:29 -05:00
Mike Reeves
72ffef9433
Some things I thought were bools are not bools
2025-03-05 14:52:54 -05:00
Mike Reeves
cf536469e6
Some things I thought were bools are not bools
2025-03-05 14:51:56 -05:00
Mike Reeves
c7c6d3e556
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into truefalse
2025-03-05 13:21:21 -05:00
coreyogburn
3a465c2e69
Merge pull request #14343 from Security-Onion-Solutions/cogburn/detections-group-items
...
Add Client Parameter
2025-03-05 09:57:31 -07:00
Corey Ogburn
21a64b6c1d
Add Client Parameter
...
Add groupItemsPerPage so detections groupby tables have proper default value for page size.
2025-03-05 09:43:21 -07:00
Doug Burks
2f6c7d2643
Merge pull request #14340 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add sankey chart to Elastic Agent API dashboard to show relationship between process.name and process.Ext.api.name #14339
2025-03-05 08:02:39 -05:00
Doug Burks
c6c67f4d06
FEATURE: Add sankey chart to Elastic Agent API dashboard to show relationship between process.name and process.Ext.api.name #14339
2025-03-05 06:31:16 -05:00
Jorge Reyes
f35930317b
Merge pull request #14336 from Security-Onion-Solutions/reyesj2-patch-2
...
ES 8.17.3
2025-03-04 15:36:59 -06:00
reyesj2
11dc004811
ES 8.17.3
2025-03-04 14:24:38 -06:00
Jorge Reyes
966503d875
Merge pull request #14331 from Security-Onion-Solutions/reyesj2-patch-2
...
osquery v1.15.0 index templates updates
2025-03-04 13:17:28 -06:00
reyesj2
124bf266b5
osquery v1.15.0 index templates updates
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-03-04 12:27:04 -06:00
Jason Ertel
75e3bba9f5
reduce stdout
2025-03-04 11:35:22 -05:00
Jason Ertel
0ff4fc101b
Merge pull request #14329 from Security-Onion-Solutions/jertel/wip
...
reduce stdout verbosity
2025-03-04 11:23:14 -05:00
Jason Ertel
85450693a2
Merge branch '2.4/dev' into jertel/wip
2025-03-04 10:55:29 -05:00
Jason Ertel
0047246cf2
reduce stdout verbosity
2025-03-04 10:55:12 -05:00
Jorge Reyes
95d3a2d834
Merge pull request #14328 from Security-Onion-Solutions/reyesj2-patch-2
...
install bc package
2025-03-04 09:03:02 -06:00
reyesj2
e1c8bee71a
install bc package
2025-03-04 08:58:41 -06:00
Doug Burks
1c96449ad9
Merge pull request #14327 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Elastic Agent Security Events dashboard should reference user.effective.name #14325
2025-03-04 07:10:41 -05:00
Doug Burks
44535cba8c
FIX: Elastic Agent Security Events dashboard should reference user.effective.name #14325
2025-03-04 06:46:56 -05:00
Jorge Reyes
3f4a5a1b28
Merge pull request #14320 from Security-Onion-Solutions/reyesj2/zeekparslin
...
zeek traceroute & ntp
2025-03-03 10:56:15 -06:00
reyesj2
4bd83f8983
zeek traceroute & ntp
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-03-03 10:48:06 -06:00
Doug Burks
206acbe618
Merge pull request #14312 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: SOC Actions for process.entity_id value must be quoted #14311
2025-03-03 07:09:45 -05:00
Doug Burks
e53f4fd1f1
Update defaults.yaml to quote the process.entity_id value
2025-03-02 05:54:30 -05:00
Jorge Reyes
573a2a5595
Merge pull request #14307 from Security-Onion-Solutions/reyesj2/esmngdint
2025-02-27 17:13:26 -06:00
reyesj2
9bc64bf453
managed int multiline input
2025-02-27 16:48:07 -06:00
Mike Reeves
2ffaf2f601
Add hunt queries
2025-02-27 12:42:03 -05:00
Mike Reeves
4696152f78
Add hunt queries
2025-02-27 12:31:51 -05:00
Mike Reeves
a0944f8359
Add hunt queries
2025-02-27 12:17:57 -05:00
Mike Reeves
1fdbe987b8
Add hunt queries
2025-02-27 12:15:37 -05:00
Mike Reeves
40303c2d78
Add hunt queries
2025-02-27 12:10:59 -05:00
Mike Reeves
4b5048bd80
Add hunt queries
2025-02-27 11:57:57 -05:00
Mike Reeves
9d31050907
roll back SOC changes
2025-02-27 11:32:59 -05:00
Mike Reeves
e930d1dec6
roll back SOC changes
2025-02-27 11:28:06 -05:00
Mike Reeves
1d3bae4a7a
Add additional entries for actions
2025-02-27 11:15:51 -05:00
Mike Reeves
d950e4ebb3
Add additional entries for actions
2025-02-27 11:11:56 -05:00
Mike Reeves
3ba82bd5a4
Fix actions
2025-02-27 11:04:47 -05:00
Jason Ertel
bc969c1ca2
Merge pull request #14302 from Security-Onion-Solutions/jertel/wip
...
more false positives
2025-02-27 08:00:49 -05:00
Jason Ertel
772aa7379f
more false positives
2025-02-27 07:55:22 -05:00
Mike Reeves
6c00cdd726
Fix healthlink
2025-02-26 16:15:00 -05:00
Mike Reeves
8bc500e4da
soc
2025-02-26 14:16:42 -05:00
Mike Reeves
25217c3262
soc
2025-02-26 14:14:25 -05:00
Mike Reeves
0c2797ecdc
soc
2025-02-26 13:49:30 -05:00
Mike Reeves
101f6e744a
sensoroni
2025-02-26 13:44:35 -05:00
Mike Reeves
c5e0b8a42e
sensoroni
2025-02-26 13:40:24 -05:00
Mike Reeves
6d7e0a7a72
sensoroni
2025-02-26 13:39:18 -05:00
Mike Reeves
2bc2e86b01
actions
2025-02-26 13:36:16 -05:00
Mike Reeves
6fec217068
actions
2025-02-26 13:34:32 -05:00
Mike Reeves
ee1af39c55
elastalert
2025-02-26 13:17:08 -05:00
Mike Reeves
a5ae481ea4
globals
2025-02-26 13:10:57 -05:00
Jorge Reyes
f8d19301be
Merge pull request #14300 from Security-Onion-Solutions/betrfix
...
default capinfos to use start/end time arg
2025-02-26 08:32:46 -06:00
reyesj2
80fed1e045
default capinfos to use start/end time arg
2025-02-25 21:47:56 -06:00
Jason Ertel
a94d657251
Merge pull request #14296 from Security-Onion-Solutions/jertel/wip
...
annotation/config updates
2025-02-25 17:04:13 -05:00
Jason Ertel
9dafa062f8
annotation/config updates
2025-02-25 17:00:41 -05:00
Jorge Reyes
c8a6aa42fb
Merge pull request #14290 from Security-Onion-Solutions/reyesj2-patch-41
...
allow installing integrations that require an elastic license
2025-02-24 15:24:38 -06:00
reyesj2
17edc06987
allow installing integrations that require an elastic license
2025-02-24 14:45:43 -06:00
Jorge Reyes
a60afdbaa5
Merge pull request #14288 from Security-Onion-Solutions/reyesj2-patch-41
...
missing metadata field
2025-02-24 10:31:42 -06:00
reyesj2
e2772e899e
component template missing metadata field
2025-02-24 10:24:11 -06:00
Jorge Reyes
43f86e5e37
Merge pull request #14287 from Security-Onion-Solutions/reyesj2-patch-41
...
elasticsearch templates load
2025-02-24 09:11:58 -06:00
reyesj2
d7c06e5ff4
run elasticsearch state, right before completing soup to ensure templates for optional integrations are loaded
2025-02-24 09:02:56 -06:00
reyesj2
3f2b0973af
manually create unused logs-soc@package for successful elasticsearch templates load
2025-02-24 08:59:59 -06:00
Josh Brower
ac841077c2
Merge pull request #14281 from Security-Onion-Solutions/2.4/patch3
...
Remove old defend json
2025-02-23 15:03:05 -05:00
Josh Brower
6d0350793d
Remove old defend json
2025-02-23 14:02:17 -05:00
Jason Ertel
d74f9183a0
Merge pull request #14279 from Security-Onion-Solutions/jertel/wip
...
ensure override for nmcli exists in /etc
2025-02-21 17:13:56 -05:00
Jason Ertel
7155ccaf96
ensure override for nmcli exists in /etc
2025-02-21 17:10:39 -05:00
Jorge Reyes
64996db86b
Merge pull request #14277 from Security-Onion-Solutions/reyesj2-patch-40
...
move removal of eaintegrations.txt to up_to_2.4.130
2025-02-21 14:07:31 -06:00
reyesj2
c1282e77a0
move removal of eaintegrations.txt to up_to_2.4.130
2025-02-21 14:02:22 -06:00
Josh Brower
79574b31b0
Merge pull request #14275 from Security-Onion-Solutions/2.4/patch
...
Dont upgrade integrations during pre-phase
2025-02-21 09:37:34 -05:00
Josh Brower
22f3865602
Dont upgrade integrations during pre-phase
2025-02-21 09:32:36 -05:00
Jason Ertel
f51d255c98
Merge pull request #14274 from Security-Onion-Solutions/jertel/wip
...
Ignore more acceptable test error logs
2025-02-21 08:40:56 -05:00
Jason Ertel
66a2ec7e21
ES upgrade errors to ignore
2025-02-21 08:38:40 -05:00
Jorge Reyes
fc12b1f09b
Merge pull request #14272 from Security-Onion-Solutions/reyesj2-patch-1
...
ES 8.17.2 pipeline version updates
2025-02-20 17:32:20 -06:00
reyesj2
69b559fb26
ES 8.17.2 pipeline version updates
2025-02-20 17:11:28 -06:00
Jorge Reyes
637ed59567
Merge pull request #14271 from Security-Onion-Solutions/reyesj2-patch-1
...
add back settings previously defined when overwritting logs-elastic_a…
2025-02-20 15:26:12 -06:00
reyesj2
df350b5a56
ES 8.17.2
2025-02-20 14:20:09 -06:00
reyesj2
3b6344e7f0
add back settings previously defined when overwritting logs-elastic_agent@package and logs-endpoint.diagnostics.collection@package
2025-02-20 12:42:30 -06:00
Doug Burks
cee9f66689
Merge pull request #14269 from Security-Onion-Solutions/dougburks-patch-1
...
Configure issue template chooser
2025-02-20 13:29:32 -05:00
Doug Burks
5dc9200ee7
Add files via upload
2025-02-20 13:19:22 -05:00
Doug Burks
2be5384980
Create config.yml
2025-02-20 13:19:08 -05:00
Doug Burks
25dfc182a9
Delete .github/ISSUE_TEMPLATE
2025-02-20 13:18:02 -05:00
Jorge Reyes
145648431f
Merge pull request #14267 from Security-Onion-Solutions/reyesj2-patch-1
...
set metrics indices to 0 replicas
2025-02-20 10:13:29 -06:00
Doug Burks
14e7e411c0
Merge pull request #14268 from Security-Onion-Solutions/dougburks-patch-1
...
Create LICENSE
2025-02-20 11:13:12 -05:00
reyesj2
c9b41e2eb1
formatting
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-02-20 10:11:34 -06:00
Doug Burks
7c2118f2f6
Create LICENSE
2025-02-20 11:07:50 -05:00
reyesj2
499d473b9d
set metrics indices to 0 replicas
2025-02-20 10:06:59 -06:00
Josh Brower
41147ae7f3
Merge pull request #14265 from Security-Onion-Solutions/2.4/elasticfix
...
Update Elastic Defend JSON
2025-02-19 16:22:28 -05:00
Josh Brower
c6d72d31cb
Update Elastic Defend JSON
2025-02-19 16:16:38 -05:00
Jorge Reyes
bb101ef95e
Merge pull request #14259 from Security-Onion-Solutions/reyesj2-patch-1
...
make sure optional integrations components list is non-empty
2025-02-19 10:50:37 -06:00
reyesj2
64f6a2d81e
re-enable security (siem) in default kibana space
2025-02-19 10:38:37 -06:00
reyesj2
45c66b93d7
make sure only a non-empty file is loaded
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-02-19 09:23:48 -06:00
Jorge Reyes
a3dba9b566
Merge pull request #14255 from Security-Onion-Solutions/foxtrot
...
ES 8.17.1
2025-02-18 14:58:46 -06:00
Jorge Reyes
f991d8a10a
Update .gitleaks.toml
2025-02-18 14:37:20 -06:00
Jorge Reyes
2b7ebf08cb
Update VERSION
2025-02-18 13:18:08 -06:00
Jason Ertel
23ab8983f7
Revert "Support CLI changing of a user's password without disabling existing auth settings for that user"
...
This reverts commit b25b6f7bf2 .
2025-02-18 12:41:41 -05:00
Jason Ertel
b25b6f7bf2
Support CLI changing of a user's password without disabling existing auth settings for that user
2025-02-18 12:37:25 -05:00
Jason Ertel
b8b77693e1
Merge pull request #14254 from Security-Onion-Solutions/jertel/wip
...
use consistent ciphers across listeners
2025-02-18 12:19:24 -05:00
Jason Ertel
19593cd771
use consistent ciphers across listeners
2025-02-18 12:17:50 -05:00
reyesj2
1be8de7acb
must use null check
2025-02-18 11:16:57 -06:00
Jason Ertel
564d8c2868
Merge branch '2.4/dev' into jertel/wip
2025-02-18 11:50:21 -05:00
Doug Burks
8033cdbc89
Merge pull request #14253 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Add TLSv1.3 to nginx config #14252
2025-02-18 11:49:22 -05:00
Jason Ertel
7dd64380cc
Enable TLSv1.3 and use consistent ciphers across listeners
2025-02-18 11:48:00 -05:00
Doug Burks
5c3e28535a
FIX: Add TLSv1.3 to nginx config #14252
2025-02-18 11:46:45 -05:00
reyesj2
21ed1439e2
update udp integration policy
2025-02-18 10:40:18 -06:00
reyesj2
c1c72ddd9b
update global@custom pipeline ignore null/empty string values
2025-02-18 10:39:54 -06:00
reyesj2
235a8e3934
update index templates for endpoint integration
2025-02-17 18:30:51 -06:00
reyesj2
3530bff320
always update package components state file to ensure index templates are created with any available integration components
2025-02-17 12:29:27 -06:00
reyesj2
12f0195f29
pfsense integration - keep suricata events
2025-02-17 12:28:23 -06:00
reyesj2
85dcfbf368
update kibana default space
2025-02-17 12:27:36 -06:00
reyesj2
8568c372f6
disable fleet apm
2025-02-17 12:21:31 -06:00
Jorge Reyes
810abba83e
Merge pull request #14229 from Security-Onion-Solutions/reyesj2/rel
...
force es pipeline sync
2025-02-13 08:54:06 -06:00
reyesj2
03b76cbcf5
remove state files
2025-02-13 08:51:50 -06:00
reyesj2
c711ffe6c5
keep pipeline "managed" metadata
2025-02-13 08:44:56 -06:00
Jorge Reyes
8094bf9c7c
Merge pull request #14225 from Security-Onion-Solutions/reyesj2/rel
...
update pfsense pipeline version. Remove unused component templates
2025-02-12 16:37:25 -06:00
reyesj2
09c7b31918
update pfsense pipeline version. Remove unused component templates
2025-02-12 16:33:56 -06:00
Jorge Reyes
d1e98d0849
Merge pull request #14224 from Security-Onion-Solutions/reyesj2/rel
...
Revert ES 8.17.2 upgrade -> 8.17.1
2025-02-12 13:18:39 -06:00
reyesj2
40cb3a53ae
Revert ES 8.17.2 upgrade -> 8.17.1
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-02-12 13:18:08 -06:00
Mike Reeves
e9e7434c69
Merge pull request #14222 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update 2-4.yml
2025-02-12 11:30:38 -05:00
Mike Reeves
d2ac6ec10f
Update 2-4.yml
2025-02-12 11:29:07 -05:00
Mike Reeves
4f19884c8d
Merge pull request #14221 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2025-02-12 11:28:11 -05:00
Mike Reeves
16c332ad2e
Update VERSION
2025-02-12 11:27:43 -05:00
Mike Reeves
d430dd2b73
Merge pull request #14219 from Security-Onion-Solutions/2.4/dev
...
2.4.120
2025-02-12 11:14:56 -05:00
Mike Reeves
43a0020a9e
Merge pull request #14220 from Security-Onion-Solutions/fixeroni
...
Merge Conflict Fix
2025-02-12 09:37:04 -05:00
Mike Reeves
b0e82cd59b
Fix Conflict
2025-02-12 09:35:52 -05:00
Mike Reeves
237370f0c7
Merge pull request #14218 from Security-Onion-Solutions/2.4.120
...
2.4.120
2025-02-12 09:20:40 -05:00
Mike Reeves
69be367acf
2.4.120
2025-02-12 09:09:38 -05:00
Jorge Reyes
cdf8943f24
Merge pull request #14214 from Security-Onion-Solutions/reyesj2/rel
...
ES 8.17.2
2025-02-11 11:24:18 -06:00
reyesj2
fb0cd436d3
ES 8.17.2 TODO: Check import-evtx-logs.json for updated pipeline versions
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-02-11 11:23:04 -06:00
reyesj2
33f145a40b
ensure network packet capture integration data has event.module:network_traffic
2025-02-10 13:16:39 -06:00
reyesj2
3b69ff9fc9
integration policy update
2025-02-10 13:16:25 -06:00
Jorge Reyes
66bc0d487c
Merge pull request #14206 from Security-Onion-Solutions/reyesj2-patch-00
...
zeek.software typo
2025-02-07 15:27:52 -06:00
reyesj2
9bde70a8e2
zeek.software typo
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-02-07 15:19:40 -06:00
Jorge Reyes
322941f29a
Merge pull request #14203 from Security-Onion-Solutions/reyesj2-patch-00
...
fix defining custom logstash pipelines when kafka is enabled
2025-02-07 07:52:11 -06:00
reyesj2
dd17ee7665
fix defining custom logstash pipelines when kafka is enabled
2025-02-06 22:19:24 -06:00
Jason Ertel
4b51066327
Merge pull request #14191 from Security-Onion-Solutions/jertel/wip
...
ca download; ignore shard errors on startup; clarify oidc id
2025-02-05 15:09:57 -05:00
Jason Ertel
bf19c6e730
ca download; ignore shard errors on startup; clarify oidc id
2025-02-05 15:04:04 -05:00
Josh Brower
12a2b491c3
Merge pull request #14190 from Security-Onion-Solutions/2.4/fixmsi
...
Refresh Agent installers
2025-02-05 10:22:17 -05:00
Joshua Brower
4636a8d9b1
Refresh Agent installers
2025-02-05 09:38:33 -05:00
Josh Brower
abbb0db1ff
Merge pull request #14189 from Security-Onion-Solutions/2.4/fixmsi
...
Rework for MSI
2025-02-05 09:35:37 -05:00
Joshua Brower
95fe212202
Rework for MSI
2025-02-05 09:29:45 -05:00
coreyogburn
fbb9bf14e9
Merge pull request #14183 from Security-Onion-Solutions/cogburn/escalate-limit
...
New Limit on Bulk Creating Related Events
2025-02-04 15:24:53 -07:00
Corey Ogburn
23ebe966e0
Added Large Values Warning
...
maxBulkEscalateEvents now has a warning that large values may run into other limits.
2025-02-04 10:33:04 -07:00
Corey Ogburn
d0fa6eaf83
New Limit on Bulk Creating Related Events
...
Used by the UI and API to hint at a user that not every event will be attached to a case. Supports values up to 10,000 (the default limit on the number of documents returned by a single ES search).
2025-02-03 14:20:33 -07:00
Josh Brower
7a0309cdf4
Merge pull request #14179 from Security-Onion-Solutions/2.4/fixilmpolicy
...
Fix ip-mappings ILM
2025-02-03 09:35:55 -05:00
Joshua Brower
b874619f0d
Fix ip-mappings ILM
2025-02-03 09:31:08 -05:00
Jason Ertel
028c73fd3a
Merge pull request #14162 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-functions
2025-01-29 10:12:20 -05:00
Mike Reeves
27e9773782
Update so-functions
2025-01-29 10:07:52 -05:00
Josh Patterson
7ae128dec6
Merge pull request #14161 from Security-Onion-Solutions/esdtsn
...
env discovery.type single-node change
2025-01-29 09:29:04 -05:00
Josh Patterson
fe4129c8e0
env discovery.type single-node change
...
only managers and heavynodes are eligible for discovery.type=single-node
2025-01-29 09:11:52 -05:00
Jorge Reyes
8828a3049d
Merge pull request #14155 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
add additional weird_integration
2025-01-27 16:36:17 -06:00
reyesj2
d74b69d84d
add additional weird_integration
2025-01-27 16:34:33 -06:00
Jorge Reyes
abcfe638c9
Merge pull request #14153 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
Reyesj2/es integ tmp
2025-01-27 14:07:32 -06:00
Joshua Brower
49ab0751c0
Remove uneeded import
2025-01-27 15:01:21 -05:00
Joshua Brower
e994f3a220
Fix commits
2025-01-27 14:48:50 -05:00
reyesj2
38b0276458
remove reference to deleted file
2025-01-27 13:45:18 -06:00
reyesj2
a373d96c3c
run managed_soc_annotations.sls from manager state
2025-01-27 13:45:03 -06:00
Josh Brower
97a3f130c8
Update Elastic
2025-01-23 15:32:39 -05:00
reyesj2
5b8f8fb62f
add/remove es annotations/defaults automagically
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-23 12:47:22 -06:00
Josh Brower
9738ef382c
Upgrade Elastic to 8.17.1
2025-01-23 08:12:02 -05:00
Jason Ertel
ca0c1170ab
Merge pull request #14140 from Security-Onion-Solutions/jertel/wip
...
fix issue with first-time api client permission toggling
2025-01-22 17:43:54 -05:00
Jason Ertel
db9387764d
fix issue with first-time api client permission toggling
2025-01-22 17:41:04 -05:00
reyesj2
e0039a08ef
fix forcedType typo
2025-01-22 13:57:26 -06:00
Jorge Reyes
09df4a5771
Merge pull request #14139 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
fixes merging local pillar /global overrides for generated index temp…
2025-01-22 13:12:53 -06:00
reyesj2
81ac1ebc08
fixes merging local pillar /global overrides for generated index templates
2025-01-22 13:12:09 -06:00
Jorge Reyes
c2f5c2226f
Merge pull request #14138 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
add back missing component for http_endpoint_x_generic & winlog_x_win…
2025-01-22 10:16:30 -06:00
reyesj2
d779f7ae7f
add back missing component for http_endpoint_x_generic & winlog_x_winglog
2025-01-22 10:15:16 -06:00
Jorge Reyes
d26c7e6f9b
Merge pull request #14134 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
remove individual <integration>@custom mappings. Moved over to so-fle…
2025-01-21 11:00:18 -06:00
reyesj2
6331298eac
remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1
2025-01-21 10:49:54 -06:00
reyesj2
76abf37351
Merge remote-tracking branch 'origin/2.4/dev' into foxtrot
2025-01-21 09:03:04 -06:00
Jorge Reyes
704e30219a
Merge pull request #14124 from Security-Onion-Solutions/reyesj2-patch-8
...
keep imported data in logs-import-so index
2025-01-17 13:33:26 -06:00
reyesj2
1396083b7d
use so-elasticsearch-query where possible; simplify suricata.alerts index reroute
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-17 13:29:46 -06:00
Jason Ertel
7017024ba7
Merge pull request #14123 from Security-Onion-Solutions/jertel/wip
...
Additional web security measures
2025-01-17 12:31:42 -05:00
Jorge Reyes
942c1aa3a6
Merge pull request #14126 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
merge dev
2025-01-17 11:24:31 -06:00
reyesj2
d35ffef503
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-17 11:23:54 -06:00
Jason Ertel
7705f45d78
Revert "subgrid config annotations"
...
This reverts commit 3ab1b907e4 .
2025-01-17 12:16:12 -05:00
Jason Ertel
964bbe6aa5
additional web server security measures
2025-01-17 12:14:30 -05:00
reyesj2
01a2e4cd4f
check for index existence before attemping rollover
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-17 09:27:28 -06:00
reyesj2
9032d7d7bc
any suricata.alert with event.imported: true remains in logs-import-so
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-16 18:48:31 -06:00
reyesj2
d573c0922d
add 2.4.111 -> postupgrade check
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-16 18:25:06 -06:00
reyesj2
45d3438d18
update ingest pipeline for imported logs
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-16 17:33:14 -06:00
Jorge Reyes
6c80fd0e18
Merge pull request #14116 from Security-Onion-Solutions/reyesj2-patch-8
...
update global@custom
2025-01-15 14:23:40 -06:00
reyesj2
b3b7fb8f29
add null check and move tag lookup to .contains() in global@custom
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-15 12:16:11 -06:00
Jason Ertel
d101fda423
Merge branch '2.4/dev' into jertel/wip
2025-01-15 11:06:05 -05:00
Jorge Reyes
b1d523a4e6
Merge pull request #14113 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
update fleet-optional-integrations-load
2025-01-14 15:26:33 -06:00
reyesj2
dab56f0882
update fleet-optional-integrations-load
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-14 15:24:59 -06:00
Jorge Reyes
846f2485db
Merge pull request #14111 from Security-Onion-Solutions/reyesj2-patch-1
...
update http query
2025-01-14 08:26:43 -06:00
Jorge Reyes
107ca38268
fix http query for "includes" function
2025-01-14 08:24:07 -06:00
Jorge Reyes
35547b476f
update http query
2025-01-14 08:13:27 -06:00
Jorge Reyes
ad765200c3
Merge pull request #14105 from Security-Onion-Solutions/reyesj2/moarzeekparse
...
Additional Zeek parsing & cloudflare_logpush integration
2025-01-13 11:37:21 -06:00
reyesj2
4618256442
include okta-mappings in so-logs-okta.system index template
2025-01-13 11:32:27 -06:00
reyesj2
323ef1d5d6
add missing lifecycle name to trend_micro_vision_one indices
2025-01-13 09:29:22 -06:00
reyesj2
a5b1648b68
add missing lifecycle name to crowdstrike indices
2025-01-13 09:26:16 -06:00
reyesj2
14c920a258
fix hidden ldap menu subtitle
2025-01-13 09:23:32 -06:00
reyesj2
4f92b7ced1
add support for cloudflare_logpush integration
2025-01-13 09:23:05 -06:00
Josh Brower
5ec2006c9e
Merge pull request #14102 from Security-Onion-Solutions/2.4/nav-airgap
...
Fix folder perm
2025-01-10 16:20:18 -05:00
Joshua Brower
dcdf31eee8
Fix folder perm
2025-01-10 16:15:17 -05:00
Jason Ertel
3ab1b907e4
subgrid config annotations
2025-01-10 13:45:42 -05:00
reyesj2
e60a1e4357
zeek ldap & ldap_search parsing
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-09 16:06:10 -06:00
Josh Brower
2de1f0464f
Merge pull request #14091 from Security-Onion-Solutions/2.4/nav-airgap
...
Refactor Navigator Airgap
2025-01-09 11:59:50 -05:00
Joshua Brower
bcb92b63e3
Move json files to container image
2025-01-09 10:58:40 -05:00
Jorge Reyes
412397fa7b
Merge pull request #14089 from Security-Onion-Solutions/reyesj2/moarzeekparse
2025-01-08 17:45:14 -06:00
reyesj2
0e87351a9c
add zeek.quic mappings
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-08 16:18:53 -06:00
Josh Brower
71f4150c27
Merge pull request #14013 from Security-Onion-Solutions/2.4/navigator
...
Refactor Navigator for Detections
2025-01-07 13:34:19 -05:00
Joshua Brower
a2caf7425d
Add config options
2025-01-07 13:22:14 -05:00
Joshua Brower
6fa11a38ef
Update defaults
2025-01-07 13:14:50 -05:00
Joshua Brower
e3f75215b6
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/navigator
2025-01-07 13:06:49 -05:00
Jorge Reyes
06983948b0
Merge pull request #14078 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
run elasticsearch state to sync templates
2025-01-06 21:34:07 -06:00
reyesj2
a21535b0a2
run elasticsearch state to sync templates
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-06 21:33:07 -06:00
Jason Ertel
d14b6e6d7d
Merge pull request #14077 from Security-Onion-Solutions/jertel/wip
...
invalidate user sessions when an admin changes the user's password
2025-01-06 17:26:56 -05:00
Jason Ertel
bd96b5d722
invalidate user sessions when an admin changes the user's password
2025-01-06 17:23:10 -05:00
Jorge Reyes
b431fb1e49
Merge pull request #14075 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
merge dev
2025-01-06 15:18:05 -06:00
reyesj2
b97619b8f9
Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/es-integ-tmp
2025-01-06 14:44:35 -06:00
reyesj2
3d3f0460fa
move addon integration script run to elasticfleet state
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-06 14:42:16 -06:00
Jorge Reyes
37d67ee9d0
Merge pull request #14073 from Security-Onion-Solutions/reyesj2/es-integ-tmp
...
update version to foxtrot
2025-01-06 11:23:27 -06:00
reyesj2
0d49dee46e
update version to foxtrot
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-06 11:22:51 -06:00
reyesj2
9fe3f6042f
Remove individual integrations ip mappings component template. Replaced with global mappings
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-06 10:44:22 -06:00
reyesj2
cdd4a1ff1f
fixes addon integration map file
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2025-01-03 16:06:22 -06:00
Josh Brower
8408a53b82
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/navigator
2025-01-02 16:13:34 -05:00
Jorge Reyes
5969e9accc
Merge pull request #14060 from Security-Onion-Solutions/reyesj2/zeekquic
...
zeek quic support
2025-01-02 08:13:33 -06:00
Doug Burks
927b618ec9
Update Zeek QUIC dashboard, add Hunt query, add quic.server.name as column in Events table
2025-01-02 06:57:56 -05:00
reyesj2
9f83853922
Zeek QUIC support
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-12-31 13:44:20 -06:00
reyesj2
ecf094f684
WIP: support all es fleet integrations
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-12-26 16:18:04 -06:00
Josh Brower
8f5634d958
Merge pull request #14048 from Security-Onion-Solutions/2.4/sigmaHashes
...
Refactor pipeline for hash changes
2024-12-23 15:49:35 -05:00
defensivedepth
7237b8971e
Refactor pipeline for hash changes
2024-12-23 15:41:13 -05:00
Mike Reeves
33239219cb
Merge pull request #14046 from Security-Onion-Solutions/TOoSmOotH-patch-1
2024-12-23 08:34:01 -05:00
Mike Reeves
09ef096620
Update soup
2024-12-23 08:27:45 -05:00
Jason Ertel
6c19a4c68a
Merge pull request #14043 from Security-Onion-Solutions/jertel/wip
...
cloud installs should use the local docker registry data
2024-12-19 15:01:25 -05:00
Jason Ertel
b8afef1ee4
cloud installs should use the local docker registry data
2024-12-19 14:56:40 -05:00
reyesj2
b3436415dc
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-12-18 14:13:25 -06:00
Jorge Reyes
16a819ff4f
Merge pull request #14041 from Security-Onion-Solutions/reyesj2/opencti
...
add ti_opencti integration support
2024-12-18 12:12:03 -06:00
reyesj2
157185c370
add ti_opencti integration support
2024-12-18 11:33:49 -06:00
Mike Reeves
ace6c5c9e4
Merge pull request #14039 from Security-Onion-Solutions/docsfix
...
Fix Discussions Dropdown
2024-12-18 11:42:42 -05:00
Mike Reeves
4a4c8eace2
Update 2-4.yml
2024-12-18 10:49:34 -05:00
Jason Ertel
8183dcf363
Merge pull request #14038 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update 2-4.yml
2024-12-18 10:38:42 -05:00
Mike Reeves
d4f1772d2e
Update 2-4.yml
2024-12-18 10:36:15 -05:00
Jason Ertel
dc1c7d8bd2
Merge pull request #14036 from Security-Onion-Solutions/merger
...
Merge in 2.4.111
2024-12-18 10:25:42 -05:00
Mike Reeves
9c10094914
Fix conflict
2024-12-18 10:19:40 -05:00
Mike Reeves
72fed8d6a7
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
2024-12-18 10:17:04 -05:00
Mike Reeves
ec90adc6d9
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main
2024-12-18 10:16:50 -05:00
Mike Reeves
93f3171a63
Merge pull request #14031 from Security-Onion-Solutions/patch/2.4.111
...
2.4.111
2024-12-18 10:05:48 -05:00
Mike Reeves
7d4c6b1174
Merge branch 'patch/2.4.111' of https://github.com/Security-Onion-Solutions/securityonion into patch/2.4.111
2024-12-18 09:29:08 -05:00
Mike Reeves
3e04bfbd21
2.4.111
2024-12-18 09:27:55 -05:00
Josh Brower
c6ebebc4d0
Merge pull request #14033 from Security-Onion-Solutions/patchfix
...
Delete uneeded files
2024-12-17 16:05:13 -05:00
defensivedepth
17405b849a
Delete uneeded files
2024-12-17 16:01:31 -05:00
Mike Reeves
897e8f6883
2.4.111
2024-12-17 13:03:52 -05:00
Mike Reeves
7d06dd4b1d
Update HOTFIX
2024-12-13 09:20:49 -05:00
Mike Reeves
5bc9fb19a8
Update VERSION
2024-12-13 09:18:58 -05:00
Mike Reeves
607aa1b992
Merge pull request #14016 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix port bind for managing external suricata ruleset
2024-12-10 17:40:35 -05:00
Mike Reeves
e4db2f4819
Update defaults.yaml
2024-12-10 17:19:15 -05:00
defensivedepth
9475211417
Refactor Navigator for Detections
2024-12-09 16:31:51 -05:00
reyesj2
9bc20c26bb
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into reyesj2/es-integ-tmp
2024-12-06 14:29:25 -06:00
Jorge Reyes
14cb41ea87
Merge pull request #14001 from Security-Onion-Solutions/reyesj2/zeekvpn
...
add openvpn & ipsec support to Zeek
2024-12-06 12:06:02 -06:00
Jorge Reyes
edd90cbed4
Merge pull request #14004 from Security-Onion-Solutions/reyesj2/logcheck
...
file extract zeek v7
2024-12-06 10:28:15 -06:00
reyesj2
1de20e9d43
fix zeek file extract
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-12-06 09:55:56 -06:00
reyesj2
ad8b339a3b
fix error due to null reference
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-12-06 09:07:16 -06:00
reyesj2
9532f21c7b
check zeek reporter.log
2024-12-05 13:49:44 -06:00
reyesj2
754d28e95d
add openvpn & ipsec support to Zeek
2024-12-05 09:52:55 -06:00
reyesj2
e3b7d82a8f
remove all non-core integrations from elasticfleet:packages pillar
2024-12-03 08:56:56 -06:00
reyesj2
888145a2ed
remove optional integrations from defaults.yaml & soc_elasticsearch.yaml
2024-12-03 08:55:43 -06:00
Josh Brower
726bdd8735
Merge pull request #13995 from Security-Onion-Solutions/feature/msi
...
fix path
2024-12-02 14:49:22 -05:00
defensivedepth
5b9f6b2d52
fix path
2024-12-02 14:42:56 -05:00
Josh Brower
aabff98bea
Merge pull request #13989 from Security-Onion-Solutions/feature/msi
...
Generate MSI
2024-12-02 09:17:45 -05:00
defensivedepth
aade3db80d
Generate MSI
2024-11-28 07:00:23 -05:00
Jorge Reyes
129c10dde5
Merge pull request #13981 from Security-Onion-Solutions/reyesj2/integ
2024-11-26 00:55:31 -06:00
reyesj2
993d56cb58
ti_rapid7*
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-25 15:51:49 -06:00
reyesj2
efa6a533c3
add missing ilm to index template
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-25 15:47:47 -06:00
Josh Brower
04ffdf9b15
Merge pull request #13958 from Security-Onion-Solutions/2.4/autoenablesigma
...
More flexibility for AutoEnable Sigma rules
2024-11-21 09:47:49 -05:00
defensivedepth
f61bf1bd67
Remove adv
2024-11-21 09:15:29 -05:00
defensivedepth
b1c4e32123
Remove duplicate option
2024-11-21 09:11:44 -05:00
defensivedepth
8958da83b3
Deprecate instead
2024-11-20 18:00:26 -05:00
defensivedepth
3fcf197bc1
Tweak structure
2024-11-19 11:54:15 -05:00
Jason Ertel
532dfd7f5a
Merge pull request #13966 from Security-Onion-Solutions/jertel/wip
...
MFA issuer name shouldn't be an advanced setting
2024-11-19 09:35:26 -05:00
Jason Ertel
92ddf2ec6c
MFA issuer name shouldn't be an advanced setting
2024-11-19 09:27:26 -05:00
coreyogburn
a703f46a0a
Merge pull request #13961 from Security-Onion-Solutions/cogburn/engine-update-config
...
Add Annotations to Existing Detections Options
2024-11-18 14:46:04 -07:00
Corey Ogburn
d86c009f55
Add Annotations to Existing Detections Options
...
The autoUpdateEnabled setting has been present for awhile and now have annotations.
2024-11-18 14:35:55 -07:00
defensivedepth
56d6857cd6
Addl customization for autoenable sigma
2024-11-18 09:03:17 -05:00
Jason Ertel
52bc9be6b6
Merge pull request #13956 from Security-Onion-Solutions/jertel/wip
...
ignore fp from hydra
2024-11-17 18:23:54 -05:00
Jason Ertel
918f26962a
ignore fp from hydra
2024-11-17 12:21:06 -05:00
Jason Ertel
3bf7870729
Merge pull request #13955 from Security-Onion-Solutions/jertel/wip
...
soup corrections
2024-11-16 21:31:08 -05:00
Jason Ertel
0eebe48492
soup corrections
2024-11-16 21:20:24 -05:00
Mike Reeves
e02cb30f1b
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
2024-11-16 20:41:31 -05:00
Mike Reeves
d005f0d7d6
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main
2024-11-16 20:41:20 -05:00
Jason Ertel
cc44558f40
Merge pull request #13954 from Security-Onion-Solutions/jertel/wip
...
revert prev commit
2024-11-16 12:08:49 -05:00
Jason Ertel
73521dd7a7
revert prev commit
2024-11-16 11:09:44 -05:00
Jorge Reyes
3041d7d2b1
Merge pull request #13951 from Security-Onion-Solutions/reyesj2/integ
...
additional integrations
2024-11-15 15:02:04 -06:00
Jason Ertel
b6ab5249f1
Merge pull request #13953 from Security-Onion-Solutions/jertel/wip
...
Connect API upgrades
2024-11-15 14:32:37 -05:00
Jason Ertel
dc838e7148
connect
2024-11-15 14:25:52 -05:00
Jason Ertel
f290e52fbd
connect
2024-11-15 14:25:11 -05:00
Jason Ertel
e4de376394
connect api
2024-11-15 13:42:02 -05:00
reyesj2
44ec237447
additional integration support - cisco secure email gateway - rapid7 threat command
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-15 11:39:01 -06:00
Jorge Reyes
ec5a6aec41
Merge pull request #13946 from Security-Onion-Solutions/foxtrot
...
Zeek 7 w/ http2
2024-11-14 14:52:48 -06:00
Josh Patterson
7f96d20eb4
Merge pull request #13944 from Security-Onion-Solutions/saltbootstrap
...
update bootstrap-salt
2024-11-14 10:25:16 -05:00
Jorge Reyes
dfd9108f39
Merge pull request #13945 from Security-Onion-Solutions/2.4/dev
...
2.4/dev
2024-11-14 09:13:00 -06:00
Jorge Reyes
e07c1e6958
Merge pull request #13943 from Security-Onion-Solutions/zeek7
...
add http2
2024-11-14 09:11:08 -06:00
reyesj2
1113c3924f
zeek http2
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-14 09:09:23 -06:00
m0duspwnens
b1ddaa7211
support installing specified version for rhel variants. remove bootstrap -x python3 since not needed
2024-11-14 09:07:41 -05:00
Jorge Reyes
ff00ddeb3c
Merge pull request #13935 from Security-Onion-Solutions/ilm-detection
2024-11-13 15:07:29 -06:00
reyesj2
ba7a6dbbf0
Remove tuning/defaults "Remove in v7.1 The policy/tuning/defaults package is deprecated. The options set here are now the defaults for Zeek in general."
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-12 18:37:46 -06:00
reyesj2
f3a88de0c3
so-(case/detection)history uses same ilm policy as so-(case/detection)
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-12 16:28:01 -06:00
Jorge Reyes
4e0b5569dc
Merge pull request #13933 from Security-Onion-Solutions/ilm-detection
...
add ilm and update managed index settings
2024-11-12 15:22:05 -06:00
reyesj2
a4d763c1e5
use curl vs es query to force PUT request
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-12 14:50:04 -06:00
m0duspwnens
33fdc23965
remove salt repo files created by saltbootstrap
2024-11-12 11:31:42 -05:00
reyesj2
aaf9f53695
update soup; check for index before applying new index setting
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-11 22:40:06 -06:00
Jason Ertel
59cf049a06
Merge pull request #13930 from Security-Onion-Solutions/jertel/wip
...
ensure roles file exists since no longer syncing clients to es
2024-11-11 18:53:46 -05:00
Jason Ertel
5b74a55c3c
ensure roles file exists since no longer syncing clients to es
2024-11-11 17:21:42 -05:00
Josh Patterson
f2ce070833
Merge pull request #13927 from Security-Onion-Solutions/saltbootstrap
...
upodate saltbootstrap
2024-11-11 16:17:23 -05:00
reyesj2
ce9bd18947
no error when versionlock dir exists after re-running soup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-11 14:59:42 -06:00
m0duspwnens
9e5d0e88de
fix soversion path
2024-11-11 15:56:01 -05:00
reyesj2
43f7989d73
()
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-11 14:47:17 -06:00
m0duspwnens
69245e4fad
have soup_scripts remove old salt repo file
2024-11-11 15:31:57 -05:00
Jason Ertel
f8f496da73
Merge pull request #13923 from Security-Onion-Solutions/jertel/wip
...
Connect API
2024-11-11 15:04:34 -05:00
reyesj2
6dbe0645e5
use auto_expand_replica, configure ilm for so-case* & so-detection*
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-11 13:51:48 -06:00
Jason Ertel
d4ed34d0ea
connect
2024-11-11 11:56:19 -05:00
m0duspwnens
7875406da1
update bootstrap-salt for broadcom changes
2024-11-11 10:54:51 -05:00
Jason Ertel
57a9992a3d
Merge branch '2.4/dev' into jertel/wip
2024-11-11 10:06:44 -05:00
Josh Patterson
b3ce624fff
Merge pull request #13921 from Security-Onion-Solutions/reposynccron
...
only enable repo sync cron if OEL
2024-11-08 16:16:48 -05:00
m0duspwnens
ee4405e75e
only enable repo sync cron if OEL
2024-11-08 16:13:44 -05:00
Josh Brower
f7c3957a43
Merge pull request #13920 from Security-Onion-Solutions/2.4/templaterepos
...
Fix permissions
2024-11-08 15:34:56 -05:00
defensivedepth
dcbb0e48d4
make sure its owned by socore
2024-11-08 14:34:29 -05:00
defensivedepth
74b95a0bcc
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/templaterepos
2024-11-08 09:20:11 -05:00
defensivedepth
8b70aa9f0e
Fix socore permissions
2024-11-08 09:19:41 -05:00
coreyogburn
9095595db1
Merge pull request #13915 from Security-Onion-Solutions/cogburn/source-dates
...
Source Dates
2024-11-07 14:55:48 -07:00
Corey Ogburn
8334fd9c46
Source Dates
2024-11-07 14:44:45 -07:00
Jason Ertel
31cf6a2ebc
connect
2024-11-07 16:17:30 -05:00
Jason Ertel
97f4cbdade
connect
2024-11-07 16:16:37 -05:00
Jason Ertel
ba0abb156a
connect
2024-11-07 16:08:28 -05:00
Josh Brower
47f9b0021c
Merge pull request #13879 from Security-Onion-Solutions/2.4/templaterepos
...
Add local custom template
2024-11-07 15:40:36 -05:00
defensivedepth
f5bd8ab585
Rewrite docs
2024-11-07 15:33:47 -05:00
Jorge Reyes
356236ba4c
Merge pull request #13912 from Security-Onion-Solutions/crowdstrike
...
fix crowdstrike integration
2024-11-07 08:53:36 -06:00
defensivedepth
28d468dd41
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/templaterepos
2024-11-07 07:25:01 -05:00
reyesj2
80b82b0bd6
missing replica 0
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-06 15:24:13 -06:00
reyesj2
039d5c22ac
fix: crowdstrike integration
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-11-06 14:35:41 -06:00
coreyogburn
07b867df76
Merge pull request #13904 from Security-Onion-Solutions/cogburn/ignored-sids
...
Cogburn/ignored sids
2024-11-05 12:30:08 -07:00
Corey Ogburn
52a144c052
Added Help Link to Annotation for IgnoredSidRanges
2024-11-05 12:11:17 -07:00
Corey Ogburn
25d55feeef
More Detailed Description
2024-11-05 11:41:14 -07:00
Corey Ogburn
5e48ccafce
Update Default Value
2024-11-05 11:11:34 -07:00
Corey Ogburn
69dd35c30a
Add Option for Ignoring Ranges of SIDs in Suricata Integrity Check
2024-11-04 14:31:53 -07:00
Josh Patterson
d37a8d51fa
Merge pull request #13900 from Security-Onion-Solutions/saltrepo
...
setup use new salt repo
2024-11-04 13:05:58 -05:00
m0duspwnens
6e14f7b626
fix pub key name
2024-11-04 11:14:00 -05:00
Jason Ertel
e8ab7bce0c
connect
2024-11-04 10:49:30 -05:00
m0duspwnens
083c678400
new salt repo
2024-11-04 09:46:26 -05:00
Jason Ertel
7442ffc7d8
connect
2024-11-01 16:37:24 -04:00
Jason Ertel
25479ca71f
connect
2024-11-01 16:29:04 -04:00
Jason Ertel
c9f6b5206a
connect
2024-11-01 16:18:40 -04:00
Jason Ertel
755cfb4e13
connect
2024-11-01 15:47:33 -04:00
Jason Ertel
fb73517fc1
connect
2024-11-01 15:43:26 -04:00
Jason Ertel
825dbb36dd
connect
2024-11-01 15:37:59 -04:00
Jason Ertel
cd2e5bf2d0
rename role
2024-10-31 17:20:44 -04:00
Jason Ertel
520c9d8d51
rename role
2024-10-31 16:42:42 -04:00
Jason Ertel
370b117938
rename role
2024-10-31 16:39:45 -04:00
Josh Brower
6ab05e7c05
Merge pull request #13890 from Security-Onion-Solutions/2.4/templatefix
...
timestamp fix
2024-10-31 10:59:45 -04:00
defensivedepth
7896f951f3
timestamp fix
2024-10-31 10:24:58 -04:00
Josh Brower
01932d873f
Merge pull request #13883 from Security-Onion-Solutions/2.4/lookuprev2
...
2.4/lookuprev2
2024-10-31 08:46:01 -04:00
Josh Brower
84a8477c5d
Merge pull request #13887 from Security-Onion-Solutions/2.4/soupedite
...
rm eaintegration state file
2024-10-30 17:15:07 -04:00
defensivedepth
6b468eaed3
rm eaintegration state file
2024-10-30 16:52:44 -04:00
Jason Ertel
a146153ee9
switch to json
2024-10-30 12:44:01 -04:00
defensivedepth
c509dab5f1
Use socore user
2024-10-30 11:03:14 -04:00
Josh Brower
1940901386
Merge pull request #13882 from Security-Onion-Solutions/ipmappingses
...
add so-ip-mappings index
2024-10-30 10:28:40 -04:00
reyesj2
36fc3bbd6d
add so-ip-mappings index
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-10-30 10:24:11 -04:00
defensivedepth
5406a263d5
Add local custom template
2024-10-29 19:42:06 -04:00
Jason Ertel
3f3ac21f50
connect
2024-10-29 12:28:24 -04:00
Jason Ertel
11820a16f0
connect
2024-10-29 12:04:38 -04:00
Josh Brower
ac359839e2
Merge pull request #13877 from Security-Onion-Solutions/2.4/lookuprev2
...
Initial support for local lookup
2024-10-29 11:22:39 -04:00
defensivedepth
4c5099d429
Initial support for local lookup
2024-10-29 10:27:54 -04:00
Jason Ertel
1243c7588b
connect
2024-10-28 19:42:01 -04:00
Jason Ertel
624c4855c8
connect
2024-10-28 19:25:20 -04:00
Jason Ertel
12a76a9d35
connect
2024-10-28 19:11:26 -04:00
Josh Brower
6a3e5415cf
Merge pull request #13832 from Security-Onion-Solutions/2.4/sigmapipelines
...
Add process and file creation mappings
2024-10-28 18:30:21 -04:00
coreyogburn
2c4f65009c
Merge pull request #13873 from Security-Onion-Solutions/cogburn/tuning-notes
...
Tuning Notes
2024-10-28 15:37:06 -06:00
defensivedepth
f3ca5b1c42
Remove OS-specific mappings
2024-10-28 09:19:51 -04:00
Corey Ogburn
640f53d085
Cleanup
...
Fix indentation and trailing comma.
2024-10-24 17:05:36 -06:00
Corey Ogburn
1aa9d87c5d
Corrected
...
Put the note on the right model this time.
2024-10-24 17:05:36 -06:00
Corey Ogburn
e11c562022
Added Note to ES Mappings
2024-10-24 17:05:35 -06:00
coreyogburn
a76a2d8e9f
Merge pull request #13800 from Security-Onion-Solutions/cogburn/detection-status-hunt
...
Cogburn/detection status hunt
2024-10-24 16:31:59 -06:00
Jason Ertel
d503c09ef2
connect
2024-10-24 15:45:18 -04:00
Corey Ogburn
6ce52bf9ab
Specify Defaults for detectionEngineStatusQueries
...
Specify the defaults as an example to the user.
2024-10-24 13:11:49 -06:00
Corey Ogburn
f67fcecc6e
Clean up StatusQueries String
2024-10-24 11:18:48 -06:00
Corey Ogburn
b7c392a244
Corrected a misspelling
2024-10-24 11:18:48 -06:00
Corey Ogburn
ad0b0a5e95
Refactor to String
...
To accomodate the config screen, the annotation now specifies it as a multiline string with a yaml syntax. The user can edit the yaml to add or remove queries. The UI will parse the YAML before use.
Also updated the IntegrityFailure queries to specify table columns more relevant to a sync failure than the default ones.
2024-10-24 11:18:47 -06:00
Corey Ogburn
c77b0afd8e
Move to Client/Detections
...
Added a basic annotation.
2024-10-24 11:18:47 -06:00
Corey Ogburn
04ebe4efea
Array to Dictionary
2024-10-24 11:18:46 -06:00
Corey Ogburn
cbb4d6846f
Detection Engine Status Queries
...
A few for testing
2024-10-24 11:18:45 -06:00
Josh Patterson
ba699b8d06
Merge pull request #13863 from Security-Onion-Solutions/issue/13851
...
Issue/13851
2024-10-24 11:00:28 -04:00
m0duspwnens
a0558ace16
replace: False to remove state warning
2024-10-24 10:33:16 -04:00
m0duspwnens
ca793966a8
set retry and interval to remove state warning
2024-10-24 10:32:42 -04:00
Jason Ertel
d9273ec369
exec bit
2024-10-24 09:40:47 -04:00
Jason Ertel
cacd5b0643
connect
2024-10-24 09:36:09 -04:00
Jason Ertel
7c405ff9d7
connect
2024-10-24 08:47:52 -04:00
Jason Ertel
5e6dd2e8b3
connect
2024-10-23 16:49:02 -04:00
Josh Patterson
dbc533e976
Merge pull request #13859 from Security-Onion-Solutions/stpndfls
...
call airgap_rules if airgap. log rsync and git commands
2024-10-23 16:44:41 -04:00
m0duspwnens
4d902da931
call airgap_rules if airgap. log rsync and git commands
2024-10-23 15:58:11 -04:00
Josh Patterson
578a18acbe
Merge pull request #13853 from Security-Onion-Solutions/agcr
...
install createrepo for airgap
2024-10-23 14:21:26 -04:00
m0duspwnens
17ba048b50
use manager state to install createrepo_c for airgap
2024-10-23 10:40:26 -04:00
Josh Patterson
36a2bffdc7
Merge pull request #13855 from Security-Onion-Solutions/issue/204
...
fix HELD for debian families
2024-10-23 09:40:25 -04:00
m0duspwnens
8cc530dd4c
fix HELD for debian families
2024-10-23 09:36:17 -04:00
m0duspwnens
1df104967e
fix pkg name
2024-10-22 16:50:23 -04:00
m0duspwnens
7a0f6d5e93
fix pkg name
2024-10-22 16:42:01 -04:00
m0duspwnens
8d2ae23ae6
install createrepo on airgap and non airgap
2024-10-22 13:56:38 -04:00
m0duspwnens
21f359456c
install createrepo for airgap
2024-10-22 11:35:08 -04:00
Jorge Reyes
2b4dfbe2ca
Merge pull request #13849 from Security-Onion-Solutions/revert-13841-reyesj2/eaintegration
...
Revert "Add support for cybereason integration"
2024-10-21 15:26:15 -04:00
Jorge Reyes
cf95af66c6
Revert "Add support for cybereason integration"
2024-10-21 15:23:05 -04:00
Josh Patterson
b95563bdf1
Merge pull request #13842 from Security-Onion-Solutions/issue/204
...
prevent state from failing if versionlock plugin not installed
2024-10-18 14:48:03 -04:00
m0duspwnens
4d093735ec
prevent state from failing if versionlock plugin not installed
2024-10-18 14:41:23 -04:00
Jorge Reyes
cd5d5b4bb0
Merge pull request #13841 from Security-Onion-Solutions/reyesj2/eaintegration
...
Add support for cybereason integration
2024-10-18 13:40:31 -04:00
reyesj2
8b11019712
Add support for cybereason integration
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-10-18 11:56:47 -04:00
Josh Patterson
1930740d10
Merge pull request #13836 from Security-Onion-Solutions/issue/204
...
Issue/204
2024-10-17 12:23:50 -04:00
m0duspwnens
39230159ae
update description
2024-10-17 12:10:49 -04:00
Jason Ertel
4611ef3713
connect wip
2024-10-17 11:39:36 -04:00
Jason Ertel
1537b69457
connect wip
2024-10-17 11:25:40 -04:00
Jason Ertel
25fe83cd40
connect wip
2024-10-17 11:22:10 -04:00
Jason Ertel
435b9b14e3
connect wip
2024-10-17 10:49:39 -04:00
m0duspwnens
76ff0c56cd
create versionlock pillar dir/files during soup to 120
2024-10-17 10:06:40 -04:00
m0duspwnens
17870bcab8
Merge remote-tracking branch 'origin/2.4/dev' into issue/204
2024-10-17 09:59:36 -04:00
m0duspwnens
5fb660bc9a
remove kernel bool option, just use list
2024-10-17 09:29:03 -04:00
Jason Ertel
f713dbacf8
connect
2024-10-16 17:53:57 -04:00
m0duspwnens
73ce526467
allow users to lock pkgs from upgrade
2024-10-16 17:06:03 -04:00
Jorge Reyes
0ba6df3b23
Merge pull request #13834 from Security-Onion-Solutions/reyesj2/eaintegration
...
FEATURE: add support for trend micro integrations
2024-10-16 17:03:49 -04:00
reyesj2
322199358d
add support for trendmicro integration
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-10-16 16:45:46 -04:00
defensivedepth
dcdfaf66f4
Add process and file creation mappings
2024-10-16 15:20:52 -04:00
Jason Ertel
d8546bf747
connect upgrade
2024-10-16 14:59:15 -04:00
Jason Ertel
1e5bf3aa98
connect upgrade
2024-10-16 14:21:11 -04:00
Jason Ertel
647f057714
Merge branch '2.4/dev' into jertel/wip
2024-10-16 13:44:20 -04:00
Jason Ertel
523ff66389
connect work
2024-10-16 13:44:01 -04:00
Jason Ertel
15c32f9103
connect routes
2024-10-16 12:33:14 -04:00
Jason Ertel
12168531a1
avoid double SSO clicks on initial OIDC login
2024-10-16 12:33:03 -04:00
coreyogburn
a3933bdc79
Merge pull request #13826 from Security-Onion-Solutions/cogburn/ai-switch-flip
...
Changes to allow reviews to start showing
2024-10-15 16:03:18 -06:00
Josh Patterson
ebd21f3f53
Merge pull request #13825 from Security-Onion-Solutions/issue/13808
...
Issue/13808
2024-10-15 17:18:56 -04:00
m0duspwnens
ce6c7c3b91
Merge remote-tracking branch 'origin/2.4/dev' into issue/13808
2024-10-15 13:14:18 -04:00
m0duspwnens
c2e46932ee
fix array def
2024-10-15 12:01:53 -04:00
m0duspwnens
c46fb7e74c
check if service is running before trying to start it
2024-10-15 11:46:09 -04:00
m0duspwnens
ac6637c6ab
set vars global
2024-10-15 09:56:50 -04:00
m0duspwnens
cc19b60146
restore services/top at start of soup
2024-10-15 09:32:14 -04:00
Corey Ogburn
d2bd9c0e26
Changes to allow reviews to start showing
2024-10-10 09:48:59 -06:00
Jason Ertel
7a1edb3833
Merge pull request #13798 from Security-Onion-Solutions/jertel/hfm2
...
main to dev
2024-10-10 11:33:39 -04:00
Jason Ertel
ec7fa5e24a
clear hotfix file
2024-10-10 11:24:10 -04:00
Jason Ertel
295353e804
Merge branch '2.4/main' into jertel/hfm2
2024-10-10 11:23:43 -04:00
Mike Reeves
1cef75d6d3
Merge pull request #13797 from Security-Onion-Solutions/hotfix/2.4.110
...
Hotfix 2.4.110
2024-10-10 11:12:25 -04:00
Mike Reeves
0c4cb863a3
Merge pull request #13796 from Security-Onion-Solutions/2.4.110hf
...
2.4.110 Hotfix
2024-10-10 10:40:42 -04:00
Mike Reeves
404f9a4eb3
2.4.110 Hotfix
2024-10-10 10:37:12 -04:00
Jason Ertel
04e33a6443
Merge pull request #13794 from Security-Onion-Solutions/jertel/hf20241010
...
2.4.110 hotfix
2024-10-10 06:40:51 -04:00
Jason Ertel
787336725c
2.4.110 hotfix
2024-10-10 06:25:59 -04:00
Mike Reeves
b7255f72bb
Merge pull request #13792 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2024-10-09 14:23:36 -04:00
Mike Reeves
e2da31c2b7
Update soup
2024-10-09 14:15:43 -04:00
weslambert
915c3f3c95
Merge pull request #13791 from Security-Onion-Solutions/fix/fleet_custom
...
Use ID instead of name for getting integrations from agent policies
2024-10-09 14:12:40 -04:00
weslambert
c58ed45cf0
Use ID instead of name
2024-10-08 10:55:16 -04:00
weslambert
69857b6b5c
Use ID instead of name
2024-10-08 10:54:54 -04:00
Doug Burks
2381260a55
Merge pull request #13783 from Security-Onion-Solutions/dougburks-patch-1
...
Add 2.4.120 for next release
2024-10-07 16:06:39 -04:00
Doug Burks
ba4fbb9953
Update 2-4.yml
2024-10-07 16:05:45 -04:00
Mike Reeves
7b006fb721
Merge pull request #13780 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-10-07 15:34:25 -04:00
Mike Reeves
f42d82e8df
Update VERSION
2024-10-07 15:30:49 -04:00
Mike Reeves
d5df002f98
Merge pull request #13777 from Security-Onion-Solutions/2.4/dev
...
2.4.110
2024-10-07 15:18:03 -04:00
Mike Reeves
a136bef668
Merge pull request #13776 from Security-Onion-Solutions/2.4.110
...
2.4.110
2024-10-07 10:04:54 -04:00
Mike Reeves
bbc65c32b6
2.4.110
2024-10-07 09:55:54 -04:00
Josh Patterson
0ec136d227
Merge pull request #13764 from Security-Onion-Solutions/safedir
...
Safedir
2024-10-01 15:12:53 -04:00
m0duspwnens
20127e6b1d
hard-reset to the remote revision
2024-10-01 15:09:53 -04:00
m0duspwnens
24817a3919
user socore
2024-10-01 09:21:56 -04:00
Jason Ertel
f448cc9c7d
Merge pull request #13757 from Security-Onion-Solutions/jertel/wip
...
adjustments for support of PKCE OIDC
2024-10-01 08:58:26 -04:00
Jason Ertel
4913df2297
adjustments for support of PKCE OIDC
2024-10-01 08:54:14 -04:00
Josh Brower
8521123d19
Merge pull request #13745 from Security-Onion-Solutions/2.4/agfix
...
Move Airgap later in setup
2024-09-26 15:51:31 -04:00
defensivedepth
3567dfc0dc
Move Airgap later in setup
2024-09-26 15:48:50 -04:00
Josh Brower
500811d5ea
Merge pull request #13743 from Security-Onion-Solutions/2.4/agfix
...
Fix path
2024-09-26 09:50:16 -04:00
defensivedepth
d86694a01c
Fix path
2024-09-26 09:48:28 -04:00
Josh Brower
421120024a
Merge pull request #13740 from Security-Onion-Solutions/2.4/agfix
...
Fix location for airgap
2024-09-26 08:54:58 -04:00
defensivedepth
fe860481c5
Fix location for airgap
2024-09-26 08:52:53 -04:00
Josh Brower
8af086c2a1
Merge pull request #13737 from Security-Onion-Solutions/2.4/summaries
...
Change summaries branch
2024-09-25 15:41:59 -04:00
defensivedepth
778d5be407
Change summaries branch
2024-09-25 15:35:08 -04:00
weslambert
8e8e584087
Merge pull request #13736 from Security-Onion-Solutions/fix/elastic_template_retry
...
Retry after 1 second
2024-09-25 13:08:36 -04:00
weslambert
aacd715379
Retry after 1 second
2024-09-25 13:07:01 -04:00
Jason Ertel
efb9778459
Merge pull request #13734 from Security-Onion-Solutions/jertel/wip
...
lowercase email when looking up ID; allow uppercase emails when modif…
2024-09-25 10:47:15 -04:00
Jason Ertel
073fb16e20
lowercase email when looking up ID; allow uppercase emails when modifying existing users but not when adding new users
2024-09-25 10:26:26 -04:00
Josh Brower
31d8593c8e
Merge pull request #13733 from Security-Onion-Solutions/2.4/sigma-airgapfix
...
Add so repo back in
2024-09-25 10:23:11 -04:00
defensivedepth
445a9679bd
Add so repo back in
2024-09-25 10:18:57 -04:00
weslambert
0bcf9e6be7
Merge pull request #13732 from Security-Onion-Solutions/fix/elastic_templates_latest
...
Check if running during soup
2024-09-25 09:37:02 -04:00
weslambert
50ae37c160
Check if running during soup
2024-09-25 08:25:20 -04:00
Josh Brower
b24c7fbf93
Merge pull request #13729 from Security-Onion-Solutions/2.4/temp-summaries-branch
...
Use temp summaries branch
2024-09-24 17:17:00 -04:00
defensivedepth
48aff374a3
Use temp summaries branch
2024-09-24 15:37:43 -04:00
Josh Brower
0ff9153d1a
Merge pull request #13727 from Security-Onion-Solutions/2.4/filter-tweaks
...
Disable by default & Airgap
2024-09-24 13:06:41 -04:00
defensivedepth
d2397c3c1c
Refactor cron logic
2024-09-24 13:03:51 -04:00
defensivedepth
0a74a53254
Remove cron if disabled
2024-09-24 12:38:49 -04:00
defensivedepth
01f87218de
Airgap support
2024-09-24 12:04:24 -04:00
defensivedepth
5286739414
Disable by default
2024-09-24 10:51:52 -04:00
weslambert
9c7bedb715
Merge pull request #13724 from Security-Onion-Solutions/fix/integration_fields
...
Fix core integration field mappings
2024-09-23 17:44:46 -04:00
Wes
70c5a07913
Add back meta ad error.message
2024-09-23 21:36:40 +00:00
Josh Brower
da3be8d8be
Merge pull request #13709 from Security-Onion-Solutions/2.4/defend-filters
...
Initial Support for managing Elastic Defend Filters
2024-09-23 17:00:10 -04:00
defensivedepth
5cc8198302
Fix permissions
2024-09-23 16:32:42 -04:00
Wes
41112a59ec
Add back meta
2024-09-23 20:12:14 +00:00
defensivedepth
2a890a35a0
Update format
2024-09-23 13:48:12 -04:00
defensivedepth
219cb5e044
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/defend-filters
2024-09-23 13:03:32 -04:00
defensivedepth
ef003ffbb5
Refactor
2024-09-23 12:55:07 -04:00
defensivedepth
074cc8e6ff
Initial commit
2024-09-20 11:58:21 -04:00
Jason Ertel
97569a1e9d
Merge pull request #13694 from Security-Onion-Solutions/jertel/wip
...
add missing annotation file
2024-09-18 14:23:57 -04:00
Jorge Reyes
b4bc0f4719
Merge pull request #13695 from Security-Onion-Solutions/reyesj2/gitsudp
...
enable stig for so desktop
2024-09-18 14:22:08 -04:00
reyesj2
385054b7b8
enable stig for so desktop
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-09-18 14:18:47 -04:00
Jason Ertel
442f7a914a
add missing annotation file
2024-09-18 14:16:43 -04:00
Wes
764eb98bc2
Add custom component for ints
2024-09-17 19:43:13 +00:00
weslambert
4575b502a8
Merge pull request #13686 from Security-Onion-Solutions/fix/opnsense_pfsense_suri_alerts
...
Fix suricata alerts for opnsense and pfsense
2024-09-17 15:33:57 -04:00
Wes
cf0d56eee7
Fix suricata alerts for opnsense and pfsense
2024-09-17 19:24:31 +00:00
Josh Patterson
b7fd19dcfd
Merge pull request #13675 from Security-Onion-Solutions/issue/13247
...
resolve 13247
2024-09-16 16:44:41 -04:00
Jason Ertel
60dfa0f87e
Merge pull request #13676 from Security-Onion-Solutions/jertel/wip
...
remove colon to avoid yaml parsing problems
2024-09-16 15:33:35 -04:00
Jason Ertel
cce9e162d4
remove colon to avoid yaml parsing problems
2024-09-16 15:30:14 -04:00
m0duspwnens
0ab2695ceb
move set to soup
2024-09-16 13:11:08 -04:00
m0duspwnens
56666ad82c
resolve 13247
2024-09-16 11:19:16 -04:00
Jason Ertel
cb41be9e85
Merge pull request #13673 from Security-Onion-Solutions/jertel/wip
...
Clarify enabled settings
2024-09-16 10:53:55 -04:00
Jason Ertel
0566f46d5b
Clarify enabled settings
2024-09-16 10:41:01 -04:00
Jason Ertel
b4e8dd8a7b
Clarify enabled settings
2024-09-16 10:14:52 -04:00
Jason Ertel
1f6735a14d
Clarify enabled settings
2024-09-16 10:12:54 -04:00
Jason Ertel
e0c499645d
Clarify enabled settings
2024-09-16 10:12:09 -04:00
Jason Ertel
217bb388a0
Clarify enabled settings
2024-09-16 10:05:17 -04:00
weslambert
5c8772774f
Merge pull request #13651 from Security-Onion-Solutions/feature/integration_upgrade
...
Upgrade Elastic integrations when new versions are available
2024-09-13 18:07:15 -04:00
weslambert
57e06dced2
Change message
2024-09-13 13:52:01 -04:00
weslambert
973b93e332
Remove check for error
2024-09-13 13:49:53 -04:00
weslambert
bc71af7a1f
Check status
2024-09-13 13:27:26 -04:00
weslambert
fa33348910
Change message
2024-09-13 13:26:17 -04:00
weslambert
da47d247c9
Remove check for cookie
2024-09-13 13:24:55 -04:00
weslambert
9bd7909983
Merge pull request #13666 from Security-Onion-Solutions/m0duspwnens-patch-1
...
exit 1 if unable to connect to kibana
2024-09-13 10:58:31 -04:00
Josh Patterson
06c0d5b0f5
Update so-elastic-fleet-integration-upgrade
2024-09-13 10:13:11 -04:00
weslambert
662f906f9d
Remove IFS
2024-09-13 09:16:53 -04:00
weslambert
2e85dcc36a
Set IFS
2024-09-12 17:59:39 -04:00
weslambert
2ec3f52ea6
Don't use state; set IFS
2024-09-12 17:57:41 -04:00
weslambert
a12e2e2022
Merge pull request #13661 from Security-Onion-Solutions/feature/idh_custom_skins
...
Allow custom IDH skins
2024-09-12 16:38:28 -04:00
Jason Ertel
11a60dbdbf
Merge pull request #13663 from Security-Onion-Solutions/jertel/jinja
...
mark specific settings as allowed to include Jinja
2024-09-12 13:58:07 -04:00
Mike Reeves
ff33cb62df
Merge pull request #13647 from Security-Onion-Solutions/surirules2
...
External Support for Detections
2024-09-12 13:44:20 -04:00
Mike Reeves
cac1539094
Add to firewall settings and annotations
2024-09-12 13:08:01 -04:00
Mike Reeves
3e768bccb8
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into surirules2
2024-09-12 12:58:19 -04:00
Wes
1463b35e2e
Change name
2024-09-12 15:31:12 +00:00
Wes
6518088de7
Allow custom IDH skins
2024-09-12 15:30:11 +00:00
weslambert
31d190cbf4
Merge pull request #13660 from Security-Onion-Solutions/fix/integration_annotations
...
Fix annotations typo
2024-09-12 10:56:43 -04:00
weslambert
24504dcc87
Fix annotations typo
2024-09-12 10:54:13 -04:00
weslambert
742fa4cbd6
Merge pull request #13658 from Security-Onion-Solutions/fix/annotation_barrcuda_imperva
...
Add annotations for barracuda and imperva
2024-09-11 15:59:25 -04:00
weslambert
7f65d122a8
Remove echo
2024-09-11 15:54:34 -04:00
weslambert
602158aa56
Add annotations for barracuda and imperva
2024-09-11 15:52:23 -04:00
weslambert
4c9bbeb5b7
Merge pull request #13657 from Security-Onion-Solutions/feature/integrations_barracuda_imperva
...
Add barracuda and imperva integrations
2024-09-11 15:47:21 -04:00
Wes
f2bb54d993
Add barracuda and imperva integrations
2024-09-11 19:41:38 +00:00
Jason Ertel
fbf0a9652a
Merge pull request #13652 from Security-Onion-Solutions/jertel/esvs
...
es sig pulled from es dir
2024-09-11 11:24:19 -04:00
Jason Ertel
f0e4e52364
es sig pulled from es dir
2024-09-11 11:12:20 -04:00
Wes
e4fa47f27e
Fix common source
2024-09-11 15:01:30 +00:00
Wes
061f42626c
Add functions to common
2024-09-11 15:00:55 +00:00
Wes
5112f5c9ce
Run upgrade during state apply
2024-09-11 14:58:01 +00:00
Wes
409612ff1f
Add script to upgrade integrations
2024-09-11 14:56:57 +00:00
Jason Ertel
8b8737221d
mark specific settings as allowed to include Jinja
2024-09-11 09:28:17 -04:00
Mike Reeves
cabba5e70d
Merge pull request #13648 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Make Standalone installs use Suricata for PCAP
2024-09-10 15:27:16 -04:00
Mike Reeves
da5e91ee03
Update so-functions
2024-09-10 15:24:44 -04:00
Mike Reeves
6e2c319e7e
Fix http2 declaration
2024-09-09 19:42:04 -04:00
Mike Reeves
eab7828bfe
Formatting and add setting
2024-09-09 18:39:19 -04:00
Mike Reeves
38619ae023
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
2024-09-09 18:31:58 -04:00
Josh Patterson
e7a7a8609a
Merge pull request #13640 from Security-Onion-Solutions/esver
...
only elasticsearch image uses es version
2024-09-09 16:45:14 -04:00
m0duspwnens
8702d95434
only elasticsearch image uses es version
2024-09-09 16:38:38 -04:00
weslambert
3b5af6bdd4
Merge pull request #13639 from Security-Onion-Solutions/fix/system_destination_ip
...
Add destination IP for so-system
2024-09-09 16:18:21 -04:00
Wes
25a9fb9b5c
Add destination IP for so-system
2024-09-09 20:16:23 +00:00
Josh Patterson
0984d1587a
Merge pull request #13638 from Security-Onion-Solutions/surireload
...
add so-suricata container req for rule reload
2024-09-09 11:14:57 -04:00
m0duspwnens
7123c62876
add so-suricata container req for rule reload
2024-09-09 11:13:28 -04:00
Josh Patterson
db1713dbde
Merge pull request #13635 from Security-Onion-Solutions/upgrade/docker
...
Upgrade Docker to 27.2.0
2024-09-09 09:32:39 -04:00
m0duspwnens
b150969986
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/docker
2024-09-09 07:56:34 -04:00
Josh Patterson
56aa57dab2
Merge pull request #13625 from Security-Onion-Solutions/esver
...
remove -it
2024-09-06 12:28:08 -04:00
m0duspwnens
ba24c5b219
remove -it
2024-09-06 12:26:55 -04:00
m0duspwnens
43c2436385
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/docker
2024-09-06 11:38:33 -04:00
Josh Patterson
ba0779ea1e
Merge pull request #13624 from Security-Onion-Solutions/esver
...
fix es agent update for soup
2024-09-06 10:46:18 -04:00
m0duspwnens
2e379dd29c
fix line delete causing issues sourcing so-common and es agent grid upgrade
2024-09-06 10:44:35 -04:00
m0duspwnens
331f63eadd
pass path for airgap
2024-09-06 10:30:40 -04:00
m0duspwnens
fc25bfe0df
grab es version from defaults during soup
2024-09-06 09:04:43 -04:00
m0duspwnens
576d218cd9
dont restart suricata during setup. retry rule reload for 3 minutes
2024-09-06 08:10:59 -04:00
Jason Ertel
b9d93118b9
Merge pull request #13620 from Security-Onion-Solutions/jertel/esvs
...
es version shift
2024-09-05 13:43:44 -04:00
Jason Ertel
5625771ffb
es version shift
2024-09-05 13:16:28 -04:00
Jason Ertel
c85e5643db
es version shift
2024-09-05 13:14:45 -04:00
m0duspwnens
21473aba9e
Merge remote-tracking branch 'origin/2.4/dev' into upgrade/docker
2024-09-05 10:23:50 -04:00
Josh Patterson
ad39bc176d
Merge pull request #13616 from Security-Onion-Solutions/esver
...
ref es version
2024-09-05 08:49:22 -04:00
m0duspwnens
5a1d61a042
ref es version
2024-09-05 08:45:44 -04:00
Josh Patterson
8adeb8a120
Merge pull request #13615 from Security-Onion-Solutions/esver
...
resolve issues with es version pinning
2024-09-05 08:41:59 -04:00
m0duspwnens
6581979506
retry suricata rule reload
2024-09-05 07:33:56 -04:00
m0duspwnens
df14cbad44
fix calls to get_elastic_agent_vars
2024-09-04 17:43:49 -04:00
m0duspwnens
72f3eaa8f6
should not have changed this, so changing it back
2024-09-04 16:42:19 -04:00
m0duspwnens
f106191e72
fix image for so-elasticsearch container
2024-09-04 16:01:24 -04:00
Josh Patterson
62b185fd32
Merge pull request #13610 from Security-Onion-Solutions/esver
...
use correct sig based on es image or not
2024-09-04 15:54:30 -04:00
m0duspwnens
7d9b3b1f28
use correct sig
2024-09-04 15:36:17 -04:00
Josh Patterson
71f6b44c0c
Merge pull request #13607 from Security-Onion-Solutions/esver
...
use Elasticsearch version for some containers
2024-09-04 13:30:07 -04:00
Jason Ertel
e14b7bc2fb
Merge pull request #13608 from Security-Onion-Solutions/jertel/hf
...
remove hotfix from dev branch
2024-09-04 13:28:02 -04:00
Jason Ertel
94e9772cf6
remove hotfix from dev branch
2024-09-04 13:25:45 -04:00
m0duspwnens
2b807c2409
update comment
2024-09-04 10:33:14 -04:00
m0duspwnens
0af2e85f91
update annotation.
2024-09-04 10:32:11 -04:00
m0duspwnens
2394488c92
update docker 27.2.0-1 and containerd.io 1.7.21
2024-09-04 09:38:17 -04:00
m0duspwnens
cfdc8ede90
fix es version logic
2024-09-03 16:49:39 -04:00
m0duspwnens
83aa4c9a53
fix awk
2024-09-03 15:22:25 -04:00
m0duspwnens
c20ac6c2d8
fix if and awk
2024-09-03 15:20:49 -04:00
Josh Brower
7311773c20
Merge pull request #13598 from Security-Onion-Solutions/2.4/main
...
Hotfix-2.4.100.20240903
2024-09-03 13:13:16 -04:00
Josh Brower
5472d2586c
Merge pull request #13596 from Security-Onion-Solutions/hotfix/2.4.100
...
Hotfix 2.4.100
2024-09-03 13:07:49 -04:00
m0duspwnens
6d7b76115f
use the version that is longest for the loop
2024-09-03 13:00:37 -04:00
m0duspwnens
a920adcf7f
handle ver1 missing segment
2024-09-03 12:53:53 -04:00
m0duspwnens
529844eb36
update so-image-common to use es version for es containers
2024-09-03 12:38:21 -04:00
Mike Reeves
fd187b11f9
Merge pull request #13595 from Security-Onion-Solutions/hf2.4.100
...
2.4.100 hotfix
2024-09-03 10:32:40 -04:00
Mike Reeves
f6cfd2349b
2.4.100 hotfix
2024-09-03 10:29:14 -04:00
Mike Reeves
9e2e676cc2
Merge pull request #13590 from Security-Onion-Solutions/TOoSmOotH-patch-1
2024-09-01 22:27:30 -04:00
Mike Reeves
5811ee5897
Update so-suricata-reload-rules
2024-09-01 10:39:42 -04:00
weslambert
a11e78176f
Merge pull request #13587 from Security-Onion-Solutions/fix/hotfix_date
...
Update HOTFIX
2024-08-30 16:21:03 -04:00
weslambert
db4c373c45
Merge pull request #13586 from Security-Onion-Solutions/fix/so-system-mappings
...
Add so-system-mappings
2024-08-30 16:20:28 -04:00
weslambert
5be17330d1
Update HOTFIX
2024-08-30 16:14:42 -04:00
weslambert
a7de6993f9
Add so-system-mappings
2024-08-30 16:11:41 -04:00
Mike Reeves
d7446c2a3f
Merge pull request #13574 from Security-Onion-Solutions/sureload
...
Reload Suricata vs restart
2024-08-30 12:50:41 -04:00
Doug Burks
f319f0803a
Merge pull request #13583 from Security-Onion-Solutions/dougburks-patch-1
...
Update Github Discussion template
2024-08-30 11:31:52 -04:00
Doug Burks
9eb76a95ca
Update 2-4.yml
2024-08-30 11:25:51 -04:00
Mike Reeves
afcb30be03
Threhsolds require a restart
2024-08-30 09:43:35 -04:00
Mike Reeves
b9f817201c
Add thresholds to the reload list
2024-08-30 09:15:25 -04:00
Mike Reeves
f17e3e91ec
Merge pull request #13577 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-08-29 16:32:58 -04:00
Mike Reeves
121a64ba57
Update VERSION
2024-08-29 16:31:43 -04:00
Mike Reeves
a9f2dfc4b8
Merge pull request #13576 from Security-Onion-Solutions/2.4/dev
...
2.4.100
2024-08-29 16:18:20 -04:00
Mike Reeves
b7e047d149
Merge pull request #13575 from Security-Onion-Solutions/2.4.100
...
2.4.100
2024-08-29 15:46:15 -04:00
Mike Reeves
f69137b38d
2.4.100
2024-08-29 15:43:42 -04:00
Mike Reeves
edce5186b9
Add support to relaod rules instead of restart
2024-08-29 12:55:06 -04:00
Mike Reeves
306bd8faaa
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
2024-08-29 12:39:41 -04:00
Josh Brower
9746f6e5e2
Merge pull request #13570 from Security-Onion-Solutions/2.4/ignore-logstash-err
...
Exclude logstash startup errors
2024-08-28 16:51:35 -04:00
DefensiveDepth
89a1e2500e
Exclude logstash startup errors
2024-08-28 16:50:11 -04:00
Jason Ertel
394ce29ea3
Merge pull request #13565 from Security-Onion-Solutions/jertel/an2
...
move custom alerters to subgroup; avoid false positives on log check
2024-08-28 09:39:44 -04:00
Jason Ertel
f19a35ff06
move custom alerters to subgroup; avoid false positives on log check
2024-08-28 09:32:25 -04:00
weslambert
8943e88ca8
Merge pull request #13562 from Security-Onion-Solutions/fix/evtx_pipelines
...
Update pipeline version for EVTX
2024-08-27 13:12:10 -04:00
Jason Ertel
18774aa0a7
Merge pull request #13561 from Security-Onion-Solutions/jertel/an2
...
annotation updates
2024-08-27 13:09:20 -04:00
weslambert
af80a78406
Update pipeline version
2024-08-27 13:08:35 -04:00
Jason Ertel
6043da4424
annotation updates
2024-08-27 13:04:43 -04:00
Josh Brower
75086bac7f
Merge pull request #13556 from Security-Onion-Solutions/2.4/fixpolicyload
...
Fix policy load
2024-08-26 16:49:54 -04:00
DefensiveDepth
726df310ee
Add context
2024-08-26 16:15:56 -04:00
DefensiveDepth
b952728b2c
Fix policy load
2024-08-26 15:57:21 -04:00
weslambert
1cac2ff1d4
Merge pull request #13554 from Security-Onion-Solutions/fix/ilm_soc_logs
...
FIX: Add so-soc-logs
2024-08-26 12:54:03 -04:00
weslambert
a93c77a1cc
Merge pull request #13548 from Security-Onion-Solutions/fix/global_custom
...
Use global@custom from common pipeline
2024-08-26 10:42:12 -04:00
weslambert
dd09f5b153
Add so-soc-logs
2024-08-26 10:32:27 -04:00
Josh Patterson
4c10282f40
add es version to annotation
2024-08-26 09:37:19 -04:00
Josh Brower
29f996de66
Merge pull request #13547 from Security-Onion-Solutions/2.4/soupchanges
...
Elastic Fleet refactoring
2024-08-23 13:56:05 -04:00
DefensiveDepth
c575e02fbb
Use correct name
2024-08-23 13:52:20 -04:00
weslambert
e96a0108c3
Add global@custom
2024-08-23 13:05:34 -04:00
DefensiveDepth
e86fce692c
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/soupchanges
2024-08-23 11:44:39 -04:00
DefensiveDepth
8d35c7c139
Merge branch '2.4/soupchanges' of https://github.com/Security-Onion-Solutions/securityonion into 2.4/soupchanges
2024-08-23 11:37:16 -04:00
DefensiveDepth
0a5725a62e
Refactor for Elastic Upgrade
2024-08-23 11:36:47 -04:00
Jorge Reyes
1c6f5126db
Merge pull request #13546 from Security-Onion-Solutions/reyesj2/kfano
...
set kafka.id in common ingest pipeline
2024-08-23 09:50:08 -04:00
reyesj2
1ec5e3bf2a
add kafka.id to common ingest pipeline
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-08-23 09:47:21 -04:00
Jason Ertel
d29727c869
Merge pull request #13540 from Security-Onion-Solutions/jertel/an2
...
exclude all logstash errors related to license manager init log line
2024-08-22 18:17:23 -04:00
Jason Ertel
eabb894580
exclude all logstash errors related to license manager init log line
2024-08-22 17:52:37 -04:00
weslambert
96339f0de6
Merge pull request #13537 from Security-Onion-Solutions/fix/elastic_template_check
...
FIX: Check Elasticsearch for endpoint component template before loading templates
2024-08-22 10:46:49 -04:00
weslambert
d7e3e134a5
Check Elasticsearch for template
2024-08-22 10:33:13 -04:00
Jason Ertel
dfb0ff7a98
Merge pull request #13535 from Security-Onion-Solutions/jertel/an2
...
notification updates
2024-08-22 09:19:43 -04:00
Jason Ertel
48f1e24bf5
notification updates
2024-08-22 09:04:43 -04:00
Jason Ertel
cf47508185
notification updates
2024-08-22 09:02:32 -04:00
weslambert
2a024039bf
Merge pull request #13528 from Security-Onion-Solutions/fix/detections_alerts_ilm
...
Create detections.alerts ILM policy with corresponding name
2024-08-21 14:50:10 -04:00
weslambert
212cc478de
Change back to so
2024-08-21 14:39:24 -04:00
weslambert
88ea60df2a
Fix name
2024-08-21 14:38:57 -04:00
weslambert
c1b7232a88
Fix for detections-alerts
2024-08-21 14:38:29 -04:00
Mike Reeves
04577a48be
Merge pull request #13530 from Security-Onion-Solutions/raidtools
2024-08-21 14:33:40 -04:00
weslambert
18ef37a2d0
Merge pull request #13531 from Security-Onion-Solutions/fix/elastic_templates_fleet_package_check
...
Check for endpoint package
2024-08-21 14:28:12 -04:00
weslambert
4108e67178
Check for endpoint package
2024-08-21 14:22:28 -04:00
Mike Reeves
ff479de7bd
Add support for new appliance raid controllers
2024-08-21 14:10:24 -04:00
weslambert
4afac201b9
Change ILM policy name
2024-08-21 13:25:26 -04:00
weslambert
c30537fe6a
Ensure endpoint is installed
2024-08-21 13:00:04 -04:00
m0duspwnens
7fbf448b22
fail if no defaults file
2024-08-21 11:36:06 -04:00
m0duspwnens
cd9c9a25d3
reference elastic versions from defaults
2024-08-21 11:25:56 -04:00
m0duspwnens
da1671fdf1
add get_elastic_agent_vars function
2024-08-21 11:25:33 -04:00
weslambert
1ed73b6f8e
Merge pull request #13526 from Security-Onion-Solutions/feature/tenable_io
...
Add Tenable IO
2024-08-21 09:03:33 -04:00
m0duspwnens
3d61897522
ref es version from defaults for kibana
2024-08-21 08:51:35 -04:00
DefensiveDepth
f01825166d
Update Fleet Server policy
2024-08-21 08:31:37 -04:00
DefensiveDepth
07f8bda27e
Update agent
2024-08-20 15:23:31 -04:00
DefensiveDepth
e3ecc9d4be
Directly manage the Fleet Server integration config
2024-08-20 15:06:16 -04:00
DefensiveDepth
ca209ed54c
Disable auto-upgrade
2024-08-20 09:14:08 -04:00
DefensiveDepth
df6ff027b5
Remove unneeded elastic upgrade config
2024-08-19 16:05:27 -04:00
weslambert
e772497e12
Merge pull request #13511 from Security-Onion-Solutions/fix/logcheck_unprovisioned
...
Ignore older SOC logs before licenseStatus field
2024-08-16 14:48:56 -04:00
weslambert
205bbd9c61
Use more specific match
2024-08-16 14:31:11 -04:00
weslambert
224bc6b429
Ignore old SOC logs before licenseStatus
2024-08-16 14:15:10 -04:00
weslambert
dc197f6a5c
Add tenable settings
2024-08-15 23:06:53 -04:00
weslambert
f182833a8d
Add tenable_io
2024-08-15 23:03:32 -04:00
weslambert
61ab1f1ef2
Add tenable_io templates
2024-08-15 23:03:07 -04:00
Mike Reeves
e664f2df28
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
2024-08-15 15:35:20 -04:00
Josh Brower
dea582f24a
Merge pull request #13487 from Security-Onion-Solutions/2.4/logcheck
...
Add influxdb known error
2024-08-15 11:57:59 -04:00
DefensiveDepth
b860bf753a
Add influxdb known error
2024-08-15 11:50:34 -04:00
Mike Reeves
b5690f6879
Merge pull request #13483 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update registry version
2024-08-15 09:36:30 -04:00
Mike Reeves
a39ad55578
Update registry version
2024-08-15 09:34:20 -04:00
weslambert
4c276d1211
Merge pull request #13482 from Security-Onion-Solutions/fix/cluster_space_total_field
...
Update column number because of changes to API
2024-08-15 08:29:39 -04:00
weslambert
5f74b1b730
Update column number because of changes to API
2024-08-15 08:26:56 -04:00
Doug Burks
b9040eb0de
Merge pull request #13481 from Security-Onion-Solutions/dougburks-patch-1
...
Update so-elasticsearch-cluster-space-used for changes in _cat/alloca…
2024-08-15 08:20:09 -04:00
Doug Burks
ab63d5dbdb
Update so-elasticsearch-cluster-space-used for changes in _cat/allocation API
2024-08-15 08:01:22 -04:00
Josh Patterson
f233f13637
Merge pull request #13478 from Security-Onion-Solutions/fixsurivars
...
handle suricata network and port vars as string or list
2024-08-13 15:52:11 -04:00
m0duspwnens
c8a8236401
handle suricata network and port vars as string or list
2024-08-13 15:44:08 -04:00
Doug Burks
f5603b1274
Merge pull request #13473 from Security-Onion-Solutions/dougburks-patch-1
...
Update SECURITY.md
2024-08-13 08:50:03 -04:00
Doug Burks
1d27fcc50e
Update SECURITY.md
2024-08-13 08:48:49 -04:00
Jason Ertel
dd2926201d
Merge pull request #13470 from Security-Onion-Solutions/jertel/chgpw
...
fix issue with reset pw and mfa
2024-08-12 17:29:50 -04:00
Jason Ertel
ebcef8adbd
fix issue with reset pw and mfa
2024-08-12 13:35:06 -04:00
Doug Burks
ff14217d38
Merge pull request #13467 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add warning to soup about ssh #13466
2024-08-12 09:23:28 -04:00
Doug Burks
46596f01fa
FEATURE: Add warning to soup about ssh #13466
2024-08-12 09:18:29 -04:00
Doug Burks
c1388a68f0
FEATURE: Add warning to soup about ssh #13466
2024-08-12 09:12:49 -04:00
Jason Ertel
374da11037
Merge pull request #13457 from Security-Onion-Solutions/jerte/fixrepos
...
fix repo path
2024-08-09 07:01:00 -04:00
Jason Ertel
caa8d9ecb0
fix repo path
2024-08-09 06:58:40 -04:00
coreyogburn
02c7de6b1a
Merge pull request #13453 from Security-Onion-Solutions/cogburn/ai-summaries
...
Cogburn/ai summaries
2024-08-08 14:55:11 -06:00
Corey Ogburn
c71b9f6e8f
Fix CopyPasta
...
Strelka annotations referenced ElastAlert. Fixed.
2024-08-08 13:31:08 -06:00
Corey Ogburn
8c1feccbe0
Tweak value
2024-08-08 12:53:51 -06:00
Corey Ogburn
5ee15c8b41
Tweak value
2024-08-08 12:00:07 -06:00
Corey Ogburn
5328f55322
Remove new config value
2024-08-08 11:43:15 -06:00
Corey Ogburn
712f904c43
Config for Repo Folder
...
The folder we checkout the AI Summary repo into should definitely exist.
2024-08-08 10:57:07 -06:00
Corey Ogburn
ccd7d86302
More AI Summaries Config/Annotations
...
Added aiRepoBranch to all 3 detection engines.
Added showUnreviewedAiSummaries to client parameters.
Added annotations.
2024-08-08 10:46:41 -06:00
Corey Ogburn
fc89604982
New Config Values/Annotations for Ai Summaries
...
Each engine pulls the same repo into the same location and shows the summaries.
Which repo and where to keep them is advanced, but turning AI summaries on or off is not.
2024-08-06 13:55:54 -06:00
Jorge Reyes
09f7329a21
Merge pull request #13443 from Security-Onion-Solutions/reyesj2/kfano
...
correct firewall annotation for kafka
2024-08-06 15:29:02 -04:00
reyesj2
cfd6676583
update kafka firewall annotations config
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-08-06 14:40:53 -04:00
Josh Patterson
3713ee9d93
Merge pull request #13441 from Security-Onion-Solutions/issue/13438
...
Issue/13438
2024-08-06 10:43:23 -04:00
m0duspwnens
009c8d55c3
unhold all verions for upgrade
2024-08-06 09:26:58 -04:00
m0duspwnens
c0c01f0d17
lock and unlock salt in soup
2024-08-05 16:50:19 -04:00
m0duspwnens
2fe5dccbb4
fix hold/unhold
2024-08-05 15:25:28 -04:00
m0duspwnens
c83a143eef
apply holds to salt each state run
2024-08-05 15:13:07 -04:00
Jason Ertel
56ef2a4e1c
Merge pull request #13430 from Security-Onion-Solutions/jertel/retryreposync
...
retry up to 5 times if reposync fails
2024-08-02 14:59:27 -04:00
Jason Ertel
c36e8abc19
retry up to 5 times if reposync fails
2024-08-02 14:52:08 -04:00
Jason Ertel
e76293acdb
Merge pull request #13429 from Security-Onion-Solutions/jertel/retryreposync
...
retry up to 5 times if reposync fails
2024-08-02 14:19:30 -04:00
Jason Ertel
5bdb4ed51b
retry up to 5 times if reposync fails
2024-08-02 14:17:14 -04:00
Josh Patterson
aaf5d76071
Merge pull request #13425 from Security-Onion-Solutions/salt3006.9
...
Salt3006.9
2024-08-02 13:37:07 -04:00
m0duspwnens
d9a696a411
run state from local
2024-08-01 14:02:21 -04:00
m0duspwnens
76ab4c92f0
use salt to install py modules during setup
2024-08-01 13:37:22 -04:00
m0duspwnens
60beaf51bc
fail hard if docker py module upgrade failes
2024-08-01 12:32:24 -04:00
m0duspwnens
9ab17ff79c
change dir name
2024-08-01 11:23:34 -04:00
m0duspwnens
1a363790a0
upgrade docker python module
2024-08-01 11:20:08 -04:00
m0duspwnens
d488bb6393
upgrade to salt 3006.9
2024-08-01 08:49:03 -04:00
weslambert
114ad779b4
Merge pull request #13418 from Security-Onion-Solutions/fix/system_mapping
...
Change name for system component
2024-07-31 16:27:32 -04:00
weslambert
49d2ac2b13
Change name for system component
2024-07-31 16:17:57 -04:00
weslambert
9a2252ed3f
Merge pull request #13414 from Security-Onion-Solutions/fix/system_mapping
...
Fix system mapping
2024-07-31 14:26:50 -04:00
Wes
9264a03dbc
Add custom system component
2024-07-31 17:03:26 +00:00
Wes
fb2a42a9af
Use custom system component
2024-07-31 17:02:45 +00:00
weslambert
63531cdbb6
Merge pull request #13410 from Security-Onion-Solutions/fix/elastic_agent_pipeline_version
...
Change agent pipeline version
2024-07-30 17:00:15 -04:00
weslambert
bae348bef7
Change version
2024-07-30 16:44:44 -04:00
weslambert
bd223d8643
Merge pull request #13409 from Security-Onion-Solutions/fix/elastic_fleet_defender
...
Fix defender winlog name change
2024-07-30 15:47:45 -04:00
weslambert
3fa6c72620
Fix name change
2024-07-30 15:45:55 -04:00
weslambert
2b90bdc86a
Merge pull request #13408 from Security-Onion-Solutions/fix/fleet_setup
...
Fix fleet setup
2024-07-30 14:49:29 -04:00
weslambert
6831b72804
Fix fleet setup
2024-07-30 14:46:00 -04:00
weslambert
5e12b928d9
Merge pull request #13407 from Security-Onion-Solutions/fix/merge_revert
...
Add removed changes
2024-07-30 13:04:28 -04:00
weslambert
0453f51e64
Actually ignore missing templates
2024-07-30 12:54:07 -04:00
weslambert
9594e4115c
Elastic 8.14.3
2024-07-30 12:47:56 -04:00
weslambert
201e14f287
Elastic 8.14.3
2024-07-30 12:46:42 -04:00
weslambert
d833bd0d55
Elastic 8.14.3
2024-07-30 12:45:25 -04:00
weslambert
46eeb014af
Add metrics settings
2024-07-30 12:39:50 -04:00
weslambert
8e7a2cf353
Ignore missing templates
2024-07-30 12:38:29 -04:00
Jason Ertel
2c528811cc
Merge pull request #13406 from Security-Onion-Solutions/jertel/force
...
Provide new setting to require OTP
2024-07-30 10:42:11 -04:00
Jason Ertel
3130b56d58
Provide new setting to require OTP
2024-07-30 10:39:57 -04:00
weslambert
b466d83625
Merge pull request #13402 from Security-Onion-Solutions/foxtrot
...
Elastic 8.14.3
2024-07-30 09:28:19 -04:00
weslambert
6d008546f1
Fix pre and add post for 2.4.100
2024-07-30 09:26:46 -04:00
weslambert
c60b14e2e7
Merge branch '2.4/dev' into foxtrot
2024-07-30 08:52:48 -04:00
weslambert
c753a7cffa
Add function for 2.4.100
2024-07-29 13:18:07 -04:00
weslambert
5cba4d7d9b
Update VERSION
2024-07-29 13:16:14 -04:00
Mike Reeves
685df9e5ea
Merge pull request #13373 from Security-Onion-Solutions/suri7rules
...
Update so-rule-update
2024-07-29 13:06:51 -04:00
Mike Reeves
ef5a42cf40
Merge pull request #13381 from Security-Onion-Solutions/consolemsg
...
Turn off console messages
2024-07-29 13:04:40 -04:00
Mike Reeves
45ab6c7309
Merge pull request #13401 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-07-29 12:59:31 -04:00
Mike Reeves
1b54a109d5
Update VERSION
2024-07-29 12:59:00 -04:00
Mike Reeves
945d04a510
Merge pull request #13391 from Security-Onion-Solutions/2.4/dev
...
2.4.90
2024-07-29 12:49:11 -04:00
Mike Reeves
658db27a46
Merge pull request #13399 from Security-Onion-Solutions/2.4.90
...
2.4.90
2024-07-29 11:45:55 -04:00
Mike Reeves
3e248da14d
2.4.90
2024-07-29 11:37:42 -04:00
coreyogburn
ed7f8dbf1d
Merge pull request #13392 from Security-Onion-Solutions/cogburn/sodet-refresh-interval
...
so-detection refresh_interval => 1s
2024-07-25 14:10:39 -06:00
Corey Ogburn
d6af3aab6d
Use a wildcard instead of making 2 requests
2024-07-25 14:05:09 -06:00
Corey Ogburn
0cb067f6f2
Don't forget history
...
Also update so-detectionhistory to have a refresh_interval of 1s.
2024-07-25 14:01:10 -06:00
Corey Ogburn
ccf88fa62b
Add step to soup to set refresh_interval during upgrade
...
The so-detection index needs it's refresh_interval reset during an upgrade. If the index doesn't exist, the config change will set it correctly when it is created.
2024-07-25 13:44:22 -06:00
Corey Ogburn
20f915f649
so-detection refresh_interval => 1s
...
Speeds up the refresh_interval so bulk indexing a single rule does not wait 30s.
2024-07-25 12:53:04 -06:00
Mike Reeves
f447b6b698
Merge pull request #13390 from Security-Onion-Solutions/2.4.90
...
2.4.90
2024-07-25 11:55:59 -04:00
Mike Reeves
66b087f12f
2.4.90
2024-07-25 11:49:57 -04:00
weslambert
f2ad4c40e6
Fix update for 2.4.90
2024-07-24 10:38:05 -04:00
weslambert
8538f2eca2
Elastic Agent update
2024-07-24 09:40:30 -04:00
Wes
c55fa6dc6a
Fix pattern for pipelines
2024-07-23 17:48:32 +00:00
Wes
17f37750e5
Remove onchanges condition
2024-07-23 16:46:18 +00:00
Wes
e789c17bc3
Add global@custom pipeline file
2024-07-23 16:37:37 +00:00
Wes
6f44d39b18
Remove Fleet final pipeline file
2024-07-23 16:37:03 +00:00
Wes
dd85249781
Remove Fleet final pipeline
2024-07-23 16:36:41 +00:00
Wes
bdba621442
Remove soup changes
2024-07-23 16:32:28 +00:00
Mike Reeves
034315ed85
Turn off console messages
2024-07-23 09:46:51 -04:00
Jason Ertel
224c668c31
Merge pull request #13374 from Security-Onion-Solutions/jertel/rmtestparm
...
remove unused test parameters from setup
2024-07-22 11:08:34 -04:00
Jason Ertel
2e17e93cfe
remove unused test parameters from setup
2024-07-22 11:04:45 -04:00
Jason Ertel
7dfb75ba6b
remove unused test parameters from setup
2024-07-22 11:02:56 -04:00
Mike Reeves
af0425b8f1
Update rulecat.conf
2024-07-22 10:20:30 -04:00
Mike Reeves
6cf0a0bb42
Update so-rule-update
2024-07-22 10:19:34 -04:00
Jorge Reyes
d97400e6f5
Merge pull request #13368 from Security-Onion-Solutions/reyesj2/kfps
...
fix kafka-logstash cert for searchnodes
2024-07-21 20:11:42 -04:00
reyesj2
cf1335dd84
searchnode logstash-kafka cert generation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-20 11:31:33 -04:00
coreyogburn
be74449fb9
Merge pull request #13365 from Security-Onion-Solutions/cogburn/suricata-regex-support
...
Cogburn/suricata regex support
2024-07-19 12:47:10 -06:00
Corey Ogburn
45b2413175
Removed Allow/Deny Regexes, Added Enable/Disable Regex
...
Update config and annotations for new regex support for suricata.
2024-07-19 12:45:24 -06:00
Corey Ogburn
022df966c7
Remove Allow/Deny Regex, Add Suricata Enable/Disable Regex
2024-07-19 12:28:04 -06:00
Jorge Reyes
92385d652e
Merge pull request #13363 from Security-Onion-Solutions/reyesj2/ksoup
...
kafka soup pillar
2024-07-19 10:50:48 -04:00
reyesj2
4478d7b55a
kafka soup pillar fix
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-19 09:32:47 -04:00
Wes
612716ee69
Apply ES to load pipelines
2024-07-17 17:35:41 +00:00
Wes
f78a5d1a78
Remove pipeline file
2024-07-17 15:42:40 +00:00
Wes
2d0de87530
Add component templates for Fleet metrics
2024-07-17 15:19:46 +00:00
Josh Patterson
18df491f7e
Merge pull request #13355 from Security-Onion-Solutions/silsll
...
Exclude policy phases if not defined in defaults
2024-07-17 11:09:18 -04:00
m0duspwnens
cee6ee7a2a
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-17 10:16:36 -04:00
m0duspwnens
6d18177f98
only include global phases if defined in default for that index
2024-07-17 10:16:11 -04:00
weslambert
c0bb395571
Remove pipeline file removal
2024-07-17 09:51:51 -04:00
weslambert
f051ddc7f0
Remove pipelines
2024-07-17 09:50:26 -04:00
m0duspwnens
72ad49ed12
add policy for so-lists and so-items
2024-07-16 14:36:06 -04:00
Jorge Reyes
d11f4ef9ba
Merge pull request #13350 from Security-Onion-Solutions/reyesj2/kflux
...
Kafka influxdb metrics & pillar update
2024-07-16 14:26:09 -04:00
reyesj2
03ca7977a0
quote variables
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-16 14:14:55 -04:00
m0duspwnens
91b2e7d400
Merge remote-tracking branch 'origin/2.4/dev' into silsll
2024-07-16 14:06:56 -04:00
m0duspwnens
34c3a58efe
add cold policy
2024-07-16 14:03:48 -04:00
Josh Patterson
a867557f54
Merge pull request #13353 from Security-Onion-Solutions/fci
...
fix custom indices
2024-07-16 13:18:11 -04:00
m0duspwnens
b814f32e0a
fix custom indices
2024-07-16 12:39:30 -04:00
coreyogburn
2df44721d0
Merge pull request #13349 from Security-Onion-Solutions/cogburn/bulk-indexer
...
New Config Values for Detections Bulk Indexer
2024-07-15 15:34:01 -06:00
Corey Ogburn
d0565baaa3
New Config Values for Detections Bulk Indexer
...
`maxScrollSize` defines the "page size" of each scroll request.
`bulkIndexerWorkerCount` defines how many worker threads a bulk indexer should use. 0 or fewer indicates that 1 thread per CPU core should be used.
2024-07-15 14:43:47 -06:00
weslambert
38e7da1334
Merge pull request #13347 from Security-Onion-Solutions/upgrade/elastic_8_14_3
...
Elastic 8.14.3
2024-07-15 16:29:24 -04:00
reyesj2
1b623c5c7a
Show Kafka EPS for nodes with broker role only
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:27:48 -04:00
reyesj2
542a116b8c
use so-yaml add for kafka pillar change
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-15 16:26:52 -04:00
Doug Burks
e7b6496f98
Merge pull request #13348 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346
2024-07-15 15:59:49 -04:00
Doug Burks
3991c7b5fe
FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346
2024-07-15 15:52:00 -04:00
weslambert
678b232c24
Elastic 8.14.3
2024-07-15 15:48:01 -04:00
weslambert
fbd0dbd048
Elastic 8.14.3
2024-07-15 15:46:55 -04:00
weslambert
1df19faf5c
Elastic 8.14.3
2024-07-15 15:44:50 -04:00
weslambert
8ec5794833
Update VERSION
2024-07-15 15:42:40 -04:00
weslambert
bf07d56da6
Merge pull request #13341 from Security-Onion-Solutions/revert-13323-fix/agent_pipeline
...
Revert "Change pipeline version for agent"
2024-07-15 11:38:56 -04:00
weslambert
cdbffa2323
Merge pull request #13342 from Security-Onion-Solutions/revert-13316-foxtrot
...
Revert "Elastic 8.14.2"
2024-07-15 11:38:48 -04:00
Josh Patterson
55469ebd24
Merge pull request #13340 from Security-Onion-Solutions/surianno
...
force var to be list of string
2024-07-15 11:34:00 -04:00
weslambert
4e81860a13
Revert "Change pipeline version for agent"
2024-07-15 11:33:52 -04:00
m0duspwnens
a23789287e
force var to be list of string
2024-07-15 11:29:47 -04:00
weslambert
fe1824aedd
Revert "Elastic 8.14.2"
2024-07-15 11:28:59 -04:00
Jorge Reyes
e58b2c45dd
Merge pull request #13335 from Security-Onion-Solutions/reyesj2/kgz
...
FIX: Kafka configuration updates
2024-07-12 15:55:43 -04:00
reyesj2
5d322ebc0b
Allow searchnodes to run kafka.ssl state for kafka-logstash cert generation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-12 14:45:11 -04:00
reyesj2
7ea8d5efd0
Remove redis input pipeline from searchnodes when global pipeline is Kafka
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-12 14:44:10 -04:00
reyesj2
4182ff66a0
rearrange kafka pillar, declutters SOC ui
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-11 16:37:16 -04:00
reyesj2
ff29d9ca51
Update log-check to ignore kafka data directories
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-11 10:23:51 -04:00
reyesj2
4a88dedcb8
Fixin kafka.ssl state and include name for kafka_user
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 16:18:46 -04:00
reyesj2
cfe5c1d76a
remove elasticsearch.ca from receiver allowed_states. Replaced by generated kafka trust
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 13:24:02 -04:00
weslambert
ebf5159c95
Merge pull request #13323 from Security-Onion-Solutions/fix/agent_pipeline
...
Change pipeline version for agent
2024-07-10 13:01:29 -04:00
weslambert
d432019ad9
Change version from 1.13.1 to 1.20.0
2024-07-10 12:48:08 -04:00
reyesj2
0d8fd42be3
update pillarwatch engine
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:37:07 -04:00
reyesj2
d5faf535c3
Only interact with logstash configuration when Kafka pipeline is enabled otherwise leave it default
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:36:44 -04:00
reyesj2
8e1edd1d91
split Kafka ssl from ssl/init. Certs won't be generated until Kafka is enabled. Also runs some clean up for old Kafka certs
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:32:43 -04:00
reyesj2
d791b23838
Generate new Kafka truststore
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-07-10 11:29:09 -04:00
weslambert
0db0754ee5
Merge pull request #13316 from Security-Onion-Solutions/foxtrot
...
Elastic 8.14.2
2024-07-10 08:53:03 -04:00
Wes
1f5a990b1e
Remove lines that aren't needed right now
2024-07-09 18:32:06 +00:00
weslambert
7a2f01be53
Update VERSION
2024-07-09 13:58:13 -04:00
Doug Burks
dadb0db8f3
Merge pull request #13321 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Update SOC MOTD #13320
2024-07-09 12:58:22 -04:00
Doug Burks
dfd8ac3626
FIX: Update SOC MOTD #13320
2024-07-09 12:55:58 -04:00
weslambert
9716e09b83
Temp change for testing
2024-07-09 12:51:34 -04:00
Wes
669f68ad88
Fleet metric annotations
2024-07-09 15:39:59 +00:00
Doug Burks
32af2d8436
Merge pull request #13318 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Update MOTD #13317
2024-07-09 10:07:47 -04:00
Doug Burks
24e945eee4
FIX: Update MOTD #13317
2024-07-09 10:06:16 -04:00
weslambert
8615e5d5ea
Move enabled and index_clean back to the top
2024-07-08 16:50:06 -04:00
weslambert
2dd5ff4333
Update VERSION
2024-07-08 16:19:53 -04:00
weslambert
6a396ec1aa
Fix accidental double quote removal
2024-07-08 11:44:27 -04:00
weslambert
34f558c023
Merge pull request #13314 from Security-Onion-Solutions/upgrade/elastic_8_14_2
...
Elastic 8.14.2
2024-07-08 10:02:02 -04:00
weslambert
9504f0885a
Elastic 8.14.2
2024-07-08 09:49:07 -04:00
weslambert
ef59678441
Elastic 8.14.2
2024-07-08 09:48:12 -04:00
weslambert
c6f6811f47
Elastic 8.14.2
2024-07-08 09:47:34 -04:00
Mike Reeves
ce8f9fe024
Merge pull request #13299 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Delete old user commands
2024-07-02 14:46:56 -04:00
Mike Reeves
40b7999786
Delete salt/manager/tools/sbin/so-user-list
2024-07-02 14:36:51 -04:00
Mike Reeves
69be03f86a
Delete salt/manager/tools/sbin/so-user-enable
2024-07-02 14:36:36 -04:00
Mike Reeves
8dc8092241
Delete salt/manager/tools/sbin/so-user-disable
2024-07-02 14:36:02 -04:00
Mike Reeves
578c6c567f
Delete old user commands
2024-07-02 14:34:45 -04:00
weslambert
662df1208d
Merge pull request #13296 from Security-Onion-Solutions/fix/soc_ilm_policy
...
Change name for ILM
2024-07-02 09:06:11 -04:00
weslambert
745b6775f1
Change name for ILM
2024-07-02 09:05:35 -04:00
weslambert
176aaa8f3d
Merge pull request #13295 from Security-Onion-Solutions/fix/custom_windows_integration
...
Change name to winlog.winlogs
2024-07-02 09:03:52 -04:00
weslambert
4d499be1a8
Change name
2024-07-02 08:47:29 -04:00
weslambert
c27225d91f
Merge pull request #13290 from Security-Onion-Solutions/fix/elastic_template_changes
...
Changes for Elastic 8.14.1
2024-07-01 11:19:02 -04:00
Wes
1b47d5c622
Changes for Elastic 8.14.1
2024-07-01 15:16:58 +00:00
Wes
32d7927a49
Template changes for Elastic 8.14.1
2024-07-01 15:16:06 +00:00
Jorge Reyes
861630681c
Merge pull request #13282 from Security-Onion-Solutions/reyesj2/rupd
...
FIX: so-rule-update airgap check
2024-06-28 16:26:34 -04:00
reyesj2
9d725f2b0b
fix rule update
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-28 13:45:50 -04:00
Josh Patterson
132263ac1a
Merge pull request #13278 from Security-Onion-Solutions/issue/13073
...
Issue/13073 - disable Logstash on heavynodes
2024-06-27 14:50:18 -04:00
DefensiveDepth
92a847e3bd
Fix Fleet setup
2024-06-27 11:48:54 -04:00
DefensiveDepth
75bbc41d38
Merge remote-tracking branch 'refs/remotes/origin/foxtrot' into foxtrot
2024-06-27 11:48:05 -04:00
weslambert
7716f4aff8
Elastic 8.14.1
2024-06-27 10:49:52 -04:00
weslambert
8eb6dcc5b7
Elastic 8.14.1
2024-06-27 10:49:06 -04:00
weslambert
847638442b
Elastic 8.14.1
2024-06-27 10:48:28 -04:00
weslambert
5743189eef
Elastic 8.14.1
2024-06-27 10:47:46 -04:00
weslambert
81d874c6ae
Update VERSION
2024-06-27 10:42:58 -04:00
Mike Reeves
72146d9566
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
2024-06-27 10:42:07 -04:00
m0duspwnens
bfe8a3a01b
Merge remote-tracking branch 'origin/2.4/dev' into issue/13073
2024-06-27 09:20:12 -04:00
weslambert
71ed9204ff
Merge pull request #13275 from Security-Onion-Solutions/fix/elastic_8_10_4
...
Revert back to 8.10.4
2024-06-27 09:16:54 -04:00
weslambert
222ebbdec1
Revert back to 8.10.4
2024-06-27 09:05:29 -04:00
weslambert
260d4e44bc
Revert back to 8.10.4
2024-06-27 09:04:07 -04:00
weslambert
0c5b3f7c1c
Revert back to 8.10.4
2024-06-27 09:03:28 -04:00
weslambert
feee80cad9
Revert back to 8.10.4
2024-06-27 09:01:55 -04:00
m0duspwnens
5f69456e22
Merge remote-tracking branch 'origin/2.4/dev' into issue/13073
2024-06-27 08:56:44 -04:00
weslambert
e59d124c82
Merge pull request #13271 from Security-Onion-Solutions/upgrade/elastic
...
Elastic 8.14.1
2024-06-26 14:47:54 -04:00
Wes
13d4738e8f
Elastic 8.14.1
2024-06-26 18:39:53 +00:00
weslambert
abdfbba32a
Elastic 8.14.1
2024-06-26 14:06:24 -04:00
weslambert
7d0a961482
Elastic 8.14.1
2024-06-26 14:00:54 -04:00
weslambert
0f226cc08e
Elastic 8.14.1
2024-06-26 13:59:23 -04:00
m0duspwnens
cfcfc6819f
disable logstash in heavynode pillars
2024-06-26 12:53:32 -04:00
m0duspwnens
fe4e2a9540
Merge remote-tracking branch 'origin/2.4/dev' into issue/13073
2024-06-26 12:46:01 -04:00
Josh Patterson
492554d951
Merge pull request #13270 from Security-Onion-Solutions/90soup
...
start soup 2.4.90
2024-06-26 12:40:44 -04:00
m0duspwnens
dfd5e95c93
start soup 2.4.90
2024-06-26 12:37:28 -04:00
m0duspwnens
50f0c43212
merge dev
2024-06-26 12:33:32 -04:00
Mike Reeves
7fe8715bce
Merge pull request #13260 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-06-25 15:40:26 -04:00
Mike Reeves
f837ea944a
Update VERSION
2024-06-25 15:39:39 -04:00
Mike Reeves
c2d43e5d22
Merge pull request #13255 from Security-Onion-Solutions/2.4/dev
...
2.4.80
2024-06-25 15:28:13 -04:00
Mike Reeves
51bb4837f5
Merge pull request #13259 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update .gitleaks.toml
2024-06-25 14:48:41 -04:00
Mike Reeves
caec424e44
Update .gitleaks.toml
2024-06-25 14:47:50 -04:00
Mike Reeves
156176c628
Merge pull request #13256 from Security-Onion-Solutions/fixmain
...
Fix git
2024-06-25 08:30:19 -04:00
Mike Reeves
81b4c4e2c0
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into fixmain
2024-06-25 08:24:27 -04:00
Mike Reeves
9af3e364aa
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
2024-06-25 08:23:10 -04:00
Mike Reeves
d4107dc60a
Merge pull request #13254 from Security-Onion-Solutions/2.4.80
...
2.4.80
2024-06-25 08:17:59 -04:00
Mike Reeves
d34605a512
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-06-25 08:16:31 -04:00
Mike Reeves
af5e7cd72c
2.4.80
2024-06-24 15:41:47 -04:00
Jorge Reyes
93378e92e6
Merge pull request #13253 from Security-Onion-Solutions/kafkaflt
...
Remove unused sbin_jinja for kafka
2024-06-24 14:18:32 -04:00
reyesj2
81ce762250
delete commented block
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-24 14:06:48 -04:00
reyesj2
cb727bf48d
remove unused sbin_jinja from kafka config
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-24 13:45:13 -04:00
Jorge Reyes
9a0bad88cc
Merge pull request #13251 from Security-Onion-Solutions/kafkaflt
...
FIX: update firewall defaults
2024-06-24 12:29:48 -04:00
reyesj2
680e84851b
Re-add manager sbin_jinja file recurse
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-24 12:27:52 -04:00
reyesj2
ea771ed21b
update firewall
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-24 12:01:01 -04:00
reyesj2
c332cd777c
remove import/heavynode artifact caused by kafka cert not existing but being bound in docker. (empty dir created)
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-24 08:50:37 -04:00
Mike Reeves
9fce85c988
Merge pull request #13245 from Security-Onion-Solutions/proxysoup
...
Fix soup for proxy servers
2024-06-21 16:13:02 -04:00
weslambert
6141c7a849
Merge pull request #13246 from Security-Onion-Solutions/fix/detections_license_none
...
Add option for detections without a license
2024-06-21 15:59:09 -04:00
weslambert
bf91030204
Add option for detections without license
2024-06-21 15:33:11 -04:00
Mike Reeves
9577c3f59d
Make soup use reposync from the repo
2024-06-21 15:24:54 -04:00
Mike Reeves
77dedc575e
Make soup use reposync from the repo
2024-06-21 15:20:07 -04:00
Mike Reeves
0295b8d658
Make soup use reposync from the repo
2024-06-21 15:11:23 -04:00
Mike Reeves
6a9d78fa7c
Make soup use reposync from the repo
2024-06-21 15:10:44 -04:00
Mike Reeves
b84521cdd2
Make soup use reposync from the repo
2024-06-21 14:49:16 -04:00
Mike Reeves
ff4679ec08
Make soup use reposync from the repo
2024-06-21 14:45:06 -04:00
Mike Reeves
c5ce7102e8
Make soup use reposync from the repo
2024-06-21 14:41:27 -04:00
Mike Reeves
229cb1e9ef
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main
2024-06-21 14:06:51 -04:00
Mike Reeves
70c001e22b
Update so-repo-sync
2024-06-21 13:37:36 -04:00
Mike Reeves
f1dc22a200
Merge pull request #13244 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soc_manager.yaml
2024-06-21 12:36:17 -04:00
Mike Reeves
aae1b69093
Update soc_manager.yaml
2024-06-21 12:35:01 -04:00
m0duspwnens
469ca44016
fix maps
2024-06-20 16:53:12 -04:00
m0duspwnens
81fcd68e9b
create and use redis:nodes and elasticsearch:nodes pillars
2024-06-20 16:42:11 -04:00
Jorge Reyes
8781419b4a
Merge pull request #13242 from Security-Onion-Solutions/annotupd
...
update kafka annotations
2024-06-20 16:18:40 -04:00
reyesj2
2eea671857
more precise wording in kafka annotation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-20 16:16:55 -04:00
reyesj2
73acfbf864
update kafka annotations
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-20 16:02:45 -04:00
Doug Burks
ae0e994461
Merge pull request #13239 from Security-Onion-Solutions/dougburks-patch-1
...
Update defaults.yaml to put Process actions in logical order
2024-06-20 10:12:06 -04:00
Doug Burks
07b9011636
Update defaults.yaml to put Process actions in logical order
2024-06-20 10:09:27 -04:00
Matthew Wright
bc2b3b7f8f
Merge pull request #13236 from Security-Onion-Solutions/mwright/licenseDropdown
...
Added license presets to defaults.yaml file
2024-06-18 18:05:15 -04:00
unknown
ea02a2b868
Added license presets to defaults.yaml file
2024-06-18 16:52:00 -04:00
Jorge Reyes
ba3a6cbe87
Merge pull request #13234 from Security-Onion-Solutions/reyesj2-patch-4
...
update receiver node allowed states
2024-06-18 15:55:32 -04:00
reyesj2
268dcbe00b
update receiver node allowed states
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-18 15:44:51 -04:00
Josh Patterson
6be97f13d0
Merge pull request #13233 from Security-Onion-Solutions/minefunc
...
fix ca mine_function
2024-06-18 13:58:35 -04:00
Jorge Reyes
95d6c93a07
Merge pull request #13231 from Security-Onion-Solutions/kfeval
2024-06-18 13:15:18 -04:00
m0duspwnens
a2bb220043
fix x509 mine_function
2024-06-18 12:33:33 -04:00
reyesj2
911d6dcce1
update kafka output policy only on eligible grid types
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-18 12:09:59 -04:00
Doug Burks
5f6a9850eb
Merge pull request #13227 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add new Process actions #13226
2024-06-18 10:57:52 -04:00
Doug Burks
de18bf06c3
FEATURE: Add new Process actions #13226
2024-06-18 10:36:41 -04:00
Jorge Reyes
73473d671d
Merge pull request #13222 from Security-Onion-Solutions/reyesj2-patch-3
...
update profile
2024-06-18 09:16:35 -04:00
Josh Brower
3fbab7c3af
Merge pull request #13223 from Security-Onion-Solutions/2.4/timeout
...
Update defaults
2024-06-18 08:55:30 -04:00
DefensiveDepth
521cccaed6
Update defaults
2024-06-18 08:43:00 -04:00
reyesj2
35da3408dc
update profile
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-17 15:53:49 -04:00
Jorge Reyes
c03096e806
Merge pull request #13221 from Security-Onion-Solutions/reyesj2/ksoup
...
suppress fleet policy update in soup
2024-06-17 14:18:34 -04:00
reyesj2
2afc947d6c
suppress fleet policy update in soup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-17 14:12:33 -04:00
Doug Burks
076da649cf
Merge pull request #13217 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add more links and descriptions to SOC MOTD #13216
2024-06-17 12:18:29 -04:00
m0duspwnens
55f8303dc2
remove manager and search pipelines from heavynode
2024-06-17 10:06:43 -04:00
Doug Burks
93ced0959c
FEATURE: Add more links and descriptions to SOC MOTD #13216
2024-06-17 09:25:01 -04:00
Doug Burks
6f13fa50bf
FEATURE: Add more links and descriptions to SOC MOTD #13216
2024-06-17 09:24:32 -04:00
Doug Burks
3bface12e0
FEATURE: Add more links and descriptions to SOC MOTD #13216
2024-06-17 09:23:14 -04:00
Doug Burks
b584c8e353
FEATURE: Add more links and descriptions to SOC MOTD #13216
2024-06-17 09:13:17 -04:00
Jason Ertel
6caf87df2d
Merge pull request #13209 from Security-Onion-Solutions/kfix
...
Fix errors on new installs
2024-06-15 05:09:48 -04:00
reyesj2
4d1f2c2bc1
fix kafka elastic fleet output policy setup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-14 23:04:08 -04:00
reyesj2
0b1175b46c
kafka logstash input plugin handle empty brokers list
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-14 23:03:36 -04:00
reyesj2
4e50dabc56
refix typos
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-14 23:03:06 -04:00
Jason Ertel
ce45a5926a
Merge pull request #13207 from Security-Onion-Solutions/kaffix
...
Standalone logstash error
2024-06-14 18:01:35 -04:00
Josh Brower
c540a4f257
Merge pull request #13208 from Security-Onion-Solutions/2.4/ruletemplates
...
Update rule templates
2024-06-14 16:01:26 -04:00
DefensiveDepth
7af94c172f
Change spelling
2024-06-14 16:00:22 -04:00
DefensiveDepth
7556587e35
Update rule templates
2024-06-14 15:47:57 -04:00
reyesj2
a0030b27e2
add additional retries to elasticfleet scripts
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-14 15:34:40 -04:00
reyesj2
8080e05444
on fresh install kafka nodes pillar may not have populated. Avoiding this by only generating kafka input pipeline when kafka nodes pillar is not empty
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-14 14:17:26 -04:00
Josh Brower
af11879545
Merge pull request #13205 from Security-Onion-Solutions/2.4/customsuricatasources
...
Initial support for custom suricata urls and local rulesets
2024-06-14 13:50:06 -04:00
DefensiveDepth
c89f1c9d95
remove multiline
2024-06-14 13:48:55 -04:00
DefensiveDepth
b7ac599a42
set to empty
2024-06-14 13:21:36 -04:00
DefensiveDepth
8363877c66
move to custom rules
2024-06-14 12:41:44 -04:00
DefensiveDepth
4bcb4b5b9c
removed unneeded import
2024-06-14 09:32:34 -04:00
DefensiveDepth
68302e14b9
add to defaults and tweaks
2024-06-14 09:28:23 -04:00
DefensiveDepth
c1abc7a7f1
Update description
2024-06-14 08:51:34 -04:00
DefensiveDepth
484717d57d
initial support for custom suricata urls and local rulesets
2024-06-14 08:42:10 -04:00
Jorge Reyes
b91c608fcf
Merge pull request #13204 from Security-Onion-Solutions/kaffix
...
Only comment out so-kafka from so-status when it exists & only run en…
2024-06-13 15:54:50 -04:00
reyesj2
8f8ece2b34
Only comment out so-kafka from so-status when it exists & only run ensure_default_pipeline when Kafka is configured
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-13 15:50:34 -04:00
Jorge Reyes
9b5c1c01e9
Merge pull request #13200 from Security-Onion-Solutions/kafka/fix
2024-06-13 12:26:57 -04:00
reyesj2
816a1d446e
Generate kafka-logstash cert on standalone,manager,managersearch in addition to searchnodes.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-13 12:18:13 -04:00
reyesj2
19bfd5beca
fix kafka nodeid assignment to increment correctly
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-13 12:16:39 -04:00
Jorge Reyes
9ac7e051b3
Merge pull request #13190 from Security-Onion-Solutions/reyesj2/kafka
...
Initial Kafka support
2024-06-13 09:42:59 -04:00
reyesj2
80b1d51f76
wrong location for global.pipeline check
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-13 08:50:53 -04:00
Doug Burks
6340ebb36d
Merge pull request #13197 from Security-Onion-Solutions/dougburks-patch-1
...
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-06-12 16:49:21 -04:00
Doug Burks
70721afa51
Update DOWNLOAD_AND_VERIFY_ISO.md
2024-06-12 16:47:26 -04:00
reyesj2
9c31622598
telegraft should only include jolokia config when Kafka is set as the global.pipeline
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 15:42:00 -04:00
reyesj2
f372b0907b
Use kafka:password for kafka certs
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 15:41:10 -04:00
coreyogburn
fac96e0b08
Merge pull request #13183 from Security-Onion-Solutions/cogburn/cleanup-config
...
Fix unnecessary escaping
2024-06-12 11:57:31 -06:00
reyesj2
2bc53f9868
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka
2024-06-12 12:36:58 -04:00
reyesj2
e8106befe9
Append '-securityonion' to all Security Onion related Kafka topics. Adjust logstash to ingest all topics ending in '-securityonion' to avoid having to manually list topic names
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 12:05:16 -04:00
reyesj2
83412b813f
Renamed Kafka pillar
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 11:19:25 -04:00
reyesj2
b56d497543
Revert a so-setup change. Kafka is not an installable option
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 11:17:06 -04:00
reyesj2
dd40962288
Revert a whiptail menu change. Kafka is not an install option
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 11:07:23 -04:00
reyesj2
b7eebad2a5
Update Kafka self reset & add initial Kafka wrapper scripts to build out
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-12 11:01:40 -04:00
m0duspwnens
8f8698fd02
Merge remote-tracking branch 'origin/2.4/dev' into issue/13073
2024-06-12 10:50:18 -04:00
Josh Patterson
092f716f12
Merge pull request #13189 from Security-Onion-Solutions/soupmsgq
...
remove this \n
2024-06-12 10:41:49 -04:00
m0duspwnens
c38f48c7f2
remove this \n
2024-06-12 10:34:32 -04:00
m0duspwnens
98837bc379
this method does not cause soup to fail
2024-06-12 09:11:02 -04:00
m0duspwnens
0f243bb6ec
Merge remote-tracking branch 'origin/2.4/dev' into issue/13073
2024-06-11 16:33:23 -04:00
m0duspwnens
88fc1bbe32
quotes on vars
2024-06-11 16:32:57 -04:00
Corey Ogburn
d5ef0e5744
Fix unnecessary escaping
2024-06-11 12:34:32 -06:00
m0duspwnens
2ecac38f6d
disable logstash on heavynodes
2024-06-11 13:50:29 -04:00
Josh Brower
e90557d7dc
Merge pull request #13179 from Security-Onion-Solutions/2.4/fixintegritycheck
...
Add new bind - suricata all.rules
2024-06-11 13:08:40 -04:00
reyesj2
628893fd5b
remove redundant 'kafka_' from annotations & defaults
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-11 11:56:21 -04:00
reyesj2
a81e4c3362
remove dash(-) from kafka.id
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-11 11:55:17 -04:00
reyesj2
ca7b89c308
Added Kafka reset to SOC UI. Incase of changing an active broker to a controller topics may become unavailable. Resolving this would require manual intervention. This option allows running a reset to start from a clean slate to then configure cluster to desired state before reenabling Kafka as global pipeline.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-11 11:21:13 -04:00
Josh Patterson
03335cc015
Merge pull request #13182 from Security-Onion-Solutions/dockerup
...
upgrade docker
2024-06-11 11:08:40 -04:00
reyesj2
08557ae287
kafka.id field should only be present when metadata for kafka exists
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-11 11:01:34 -04:00
DefensiveDepth
08d2a6242d
Add new bind - suricata all.rules
2024-06-11 10:03:33 -04:00
m0duspwnens
4b481bd405
add epoch to docker for oracle
2024-06-11 09:41:58 -04:00
m0duspwnens
0b1e3b2a7f
upgrade docker for focal
2024-06-10 16:24:44 -04:00
m0duspwnens
dbd9873450
upgrade docker for jammy
2024-06-10 16:04:11 -04:00
m0duspwnens
c6d0a17669
docker upgrade debian 12
2024-06-10 15:43:29 -04:00
m0duspwnens
adeab10f6d
upgrade docker and containerd.io for oracle
2024-06-10 12:14:27 -04:00
reyesj2
824f852ed7
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-10 11:26:23 -04:00
reyesj2
284c1be85f
Update Kafka controller(s) via SOC UI
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-10 11:08:54 -04:00
Jason Ertel
7ad6baf483
Merge pull request #13171 from Security-Onion-Solutions/jertel/yaml
...
correct placement of error check override
2024-06-08 08:21:20 -04:00
Jason Ertel
f1638faa3a
correct placement of error check override
2024-06-08 08:18:34 -04:00
Jason Ertel
dea786abfa
Merge pull request #13170 from Security-Onion-Solutions/jertel/yaml
...
gracefully handle missing parent key
2024-06-08 07:49:49 -04:00
Jason Ertel
f96b82b112
gracefully handle missing parent key
2024-06-08 07:44:46 -04:00
Josh Patterson
95fe11c6b4
Merge pull request #13162 from Security-Onion-Solutions/soupmsgq
...
fix elastic templates not loading due to global_override phases
2024-06-07 16:23:03 -04:00
Jason Ertel
f2f688b9b8
Update soup
2024-06-07 16:18:09 -04:00
m0duspwnens
0139e18271
additional description
2024-06-07 16:03:21 -04:00
Mike Reeves
657995d744
Merge pull request #13165 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update defaults.yaml
2024-06-07 15:38:01 -04:00
Mike Reeves
4057238185
Update defaults.yaml
2024-06-07 15:33:49 -04:00
coreyogburn
fb07ff65c9
Merge pull request #13164 from Security-Onion-Solutions/cogburn/tls-options
...
AdditionalCA and InsecureSkipVerify
2024-06-07 13:10:45 -06:00
Mike Reeves
dbc56ffee7
Update defaults.yaml
2024-06-07 15:09:09 -04:00
Corey Ogburn
ee696be51d
Remove rootCA and insecureSkipVerify from SOC defaults
2024-06-07 13:07:04 -06:00
Corey Ogburn
5d3fd3d389
AdditionalCA and InsecureSkipVerify
...
New fields have been added to manager and then duplicated over to SOC's config in the same vein as how proxy was updated earlier this week.
AdditionalCA holds the PEM formatted public keys that should be trusted when making requests. It has been implemented for both Sigma's zip downloads and Sigma and Suricata's repository clones and pulls.
InsecureSkipVerify has been added to help our users troubleshoot their configuration. Setting it to true will not verify the cert on outgoing requests. Self signed, missing, or invalid certs will not throw an error.
2024-06-07 12:47:09 -06:00
Corey Ogburn
fa063722e1
RootCA and InsecureSkipVerify
...
New empty settings and their annotations.
2024-06-07 09:10:14 -06:00
m0duspwnens
f5cc35509b
fix output alignment
2024-06-07 11:03:26 -04:00
m0duspwnens
d39c8fae54
format output
2024-06-07 09:01:16 -04:00
m0duspwnens
d3b81babec
check for phases with so-yaml, remove if exists
2024-06-06 16:15:21 -04:00
coreyogburn
f35f6bd4c8
Merge pull request #13154 from Security-Onion-Solutions/cogburn/soc-proxy
...
SOC Proxy Setting
2024-06-06 14:03:16 -06:00
Mike Reeves
d5cfef94a3
Merge pull request #13156 from Security-Onion-Solutions/TOoSmOotH-patch-3
2024-06-06 16:01:22 -04:00
Mike Reeves
f37f5ba97b
Update soc_suricata.yaml
2024-06-06 15:57:58 -04:00
Corey Ogburn
42818a9950
Remove proxy from SOC defaults
2024-06-06 13:28:07 -06:00
Corey Ogburn
e85c3e5b27
SOC Proxy Setting
...
The so_proxy value we build during install is now copied to SOC's config.
2024-06-06 11:55:27 -06:00
m0duspwnens
a39c88c7b4
add set to troubleshoot failure
2024-06-06 12:56:24 -04:00
m0duspwnens
73ebf5256a
Merge remote-tracking branch 'origin/2.4/dev' into soupmsgq
2024-06-06 12:44:45 -04:00
Jason Ertel
6d31cd2a41
Merge pull request #13150 from Security-Onion-Solutions/jertel/yaml
...
add ability to retrieve yaml values via so-yaml.py; improve so-minion id matching
2024-06-06 12:09:03 -04:00
Jason Ertel
5600fed9c4
add ability to retrieve yaml values via so-yaml.py; improve so-minion id matching
2024-06-06 11:56:07 -04:00
m0duspwnens
6920b77b4a
fix msg
2024-06-06 11:00:43 -04:00
m0duspwnens
ccd6b3914c
add final msg queue for soup.
2024-06-06 10:33:55 -04:00
reyesj2
c4723263a4
Remove unused kafka reactor
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-06 08:59:17 -04:00
reyesj2
4581a46529
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka
2024-06-05 20:47:41 -04:00
Josh Patterson
33a2c5dcd8
Merge pull request #13141 from Security-Onion-Solutions/sotcprp
...
move so-tcpreplay from common state to sensor state
2024-06-05 09:49:39 -04:00
m0duspwnens
f6a8a21f94
remove space
2024-06-05 08:58:46 -04:00
m0duspwnens
ff5773c837
move so-tcpreplay back to common. return empty string if no sensor.interface pillar
2024-06-05 08:56:32 -04:00
m0duspwnens
66f8084916
Merge remote-tracking branch 'origin/2.4/dev' into sotcprp
2024-06-05 08:32:54 -04:00
m0duspwnens
a2467d0418
move so-tcpreplay to sensor state
2024-06-05 08:24:57 -04:00
reyesj2
3b0339a9b3
create kafka.id from kafka {partition}-{offset}-{timestamp} for tracking event
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-04 14:27:52 -04:00
reyesj2
fb1d4fdd3c
update license
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-04 12:33:51 -04:00
Josh Patterson
56a16539ae
Merge pull request #13134 from Security-Onion-Solutions/sotcprp
...
so-tcpreplay now runs if manager is offline
2024-06-04 10:43:33 -04:00
m0duspwnens
c0b2cf7388
add the curlys
2024-06-04 10:28:21 -04:00
reyesj2
d9c58d9333
update receiver pillar access
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-04 08:33:45 -04:00
Josh Patterson
ef3a52468f
Merge pull request #13129 from Security-Onion-Solutions/salt3006.8
...
salt 3006.6
2024-06-03 15:29:19 -04:00
m0duspwnens
c88b731793
revert to 3006.6
2024-06-03 15:27:08 -04:00
reyesj2
2e85a28c02
Remove so-kafka-clusterid script, created during soup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-06-02 18:25:59 -04:00
weslambert
964fef1aab
Merge pull request #13117 from Security-Onion-Solutions/fix/items_and_lists
...
Add templates for .items and .lists indices
2024-05-31 16:34:29 -04:00
reyesj2
1a832fa0a5
Move soup kafka needfuls to up_to_2.4.80
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-31 14:04:46 -04:00
reyesj2
75bdc92bbf
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka
2024-05-31 14:02:43 -04:00
Wes
a8c231ad8c
Add component templates
2024-05-31 17:47:01 +00:00
Wes
f396247838
Add index templates and lifecycle policies
2024-05-31 17:46:19 +00:00
reyesj2
e3ea4776c7
Update kafka nodes pillar before running highstate with pillarwatch engine. This allows configuring your Kafka controllers before cluster comes up for the first time
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-31 13:34:28 -04:00
coreyogburn
37a928b065
Merge pull request #13107 from Security-Onion-Solutions/cogburn/detection-templates
...
Added TemplateDetections To Detection ClientParams
2024-05-30 16:26:17 -06:00
Corey Ogburn
85c269e697
Added TemplateDetections To Detection ClientParams
...
The UI can now insert templates when you select a Detection language. These are those templates, annotated.
2024-05-30 15:59:03 -06:00
m0duspwnens
6e70268ab9
Merge remote-tracking branch 'origin/2.4/dev' into sotcprp
2024-05-30 16:34:37 -04:00
Josh Patterson
fb8929ea37
Merge pull request #13103 from Security-Onion-Solutions/salt3006.8
...
Salt3006.8
2024-05-30 16:32:05 -04:00
weslambert
5d9c0dd8b5
Merge pull request #13101 from Security-Onion-Solutions/fix/separate_suricata
...
Separate Suricata alerts into a specific data stream
2024-05-30 16:30:55 -04:00
m0duspwnens
debf093c54
Merge remote-tracking branch 'origin/2.4/dev' into salt3006.8
2024-05-30 15:58:10 -04:00
reyesj2
00b5a5cc0c
Revert "revert version for soup test before 2.4.80 pipeline unpaused"
...
This reverts commit 48713a4e7b .
2024-05-30 15:13:16 -04:00
reyesj2
dbb99d0367
Remove bad config
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-30 15:10:15 -04:00
m0duspwnens
7702f05756
upgrade salt 3006.8. soup for 2.4.80
2024-05-30 15:00:32 -04:00
Wes
2c635bce62
Set index for Suricata alerts
2024-05-30 17:02:31 +00:00
reyesj2
48713a4e7b
revert version for soup test before 2.4.80 pipeline unpaused
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-30 13:00:34 -04:00
Wes
e831354401
Add Suricata alerts setting for configuration
2024-05-30 17:00:11 +00:00
Wes
55c5ea5c4c
Add template for Suricata alerts
2024-05-30 16:58:56 +00:00
reyesj2
1fd5165079
Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/kafka
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-29 23:37:40 -04:00
reyesj2
949cea95f4
Update pillarWatch config for global.pipeline
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-29 23:19:44 -04:00
Mike Reeves
12762e08ef
Merge pull request #13093 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-05-29 16:54:31 -04:00
Mike Reeves
62bdb2627a
Update VERSION
2024-05-29 16:53:27 -04:00
reyesj2
386be4e746
WIP: Manage Kafka nodes pillar role value
...
This way when kafka_controllers is updated the pillar value gets updated and any non-controllers get updated to revert to 'broker' only role.
Needs more testing when a new controller joins in this manner Kafka errors due to cluster metadata being out of sync. One solution is to remove /nsm/kafka/data/__cluster_metadata-0/quorum-state and restart cluster. Alternative is working with Kafka cli tools to inform cluster of new voter, likely best option but requires a wrapper script of some sort to be created for updating cluster in-place.
Easiest option is to have all receivers join grid and then configure Kafka with specific controllers via SOC UI prior to enabling Kafka. This way Kafka cluster comes up in the desired configuration with no need for immediately modifying cluster
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-29 16:48:39 -04:00
Mike Reeves
dfcf7a436f
Merge pull request #13091 from Security-Onion-Solutions/2.4/dev
...
2.4.70
2024-05-29 16:41:54 -04:00
reyesj2
d9ec556061
Update some annotations and defaults
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-29 16:41:02 -04:00
reyesj2
876d860488
elastic agent should be able to communicate over 9092 for sending logs to kafka brokers
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-29 16:40:15 -04:00
Mike Reeves
88651219a6
Merge pull request #13090 from Security-Onion-Solutions/2.4.70
...
2.4.70
2024-05-29 14:54:16 -04:00
Mike Reeves
a655f8dc04
2.4.70
2024-05-29 14:52:47 -04:00
Mike Reeves
e98b8566c9
2.4.70
2024-05-29 14:50:22 -04:00
Josh Brower
ef10794e3b
Merge pull request #13089 from Security-Onion-Solutions/2.4/realert
...
fix rsync
2024-05-29 11:12:45 -04:00
DefensiveDepth
0d034e7adc
fix rsync
2024-05-29 10:55:56 -04:00
reyesj2
59097070ef
Revert "Remove unneeded jolokia aggregate metrics to reduce data ingested to influx"
...
This reverts commit 1c1a1a1d3f .
2024-05-28 12:17:43 -04:00
reyesj2
77b5aa4369
Correct dashboard name
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-28 11:34:35 -04:00
reyesj2
0d7c331ff0
only show specific fields when hovering over Kafka influxdb panels
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-28 11:29:38 -04:00
reyesj2
1c1a1a1d3f
Remove unneeded jolokia aggregate metrics to reduce data ingested to influx
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-28 11:14:19 -04:00
reyesj2
47efcfd6e2
Add basic Kafka metrics to 'Security Onion Performance' influxdb dashboard
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-28 10:55:11 -04:00
reyesj2
15a0b959aa
Add jolokia metrics for influxdb dashboard
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-28 10:51:39 -04:00
Josh Brower
ca49943a7f
Merge pull request #13085 from Security-Onion-Solutions/2.4/soupchange
...
Check to see if local exists
2024-05-28 10:25:46 -04:00
DefensiveDepth
ee4ca0d7a2
Check to see if local exists
2024-05-28 10:24:09 -04:00
Josh Brower
0d634f3b8e
Merge pull request #13084 from Security-Onion-Solutions/2.4/soupchange
...
Fix fi
2024-05-28 10:05:33 -04:00
DefensiveDepth
f68ac23f0e
Fix fi
...
Signed-off-by: DefensiveDepth <Josh@defensivedepth.com >
2024-05-28 10:03:31 -04:00
Josh Brower
825c4a9adb
Merge pull request #13083 from Security-Onion-Solutions/2.4/soupchange
...
Backup .yml files too
2024-05-28 09:45:53 -04:00
DefensiveDepth
2a2b86ebe6
Dont overwrite
2024-05-28 09:43:45 -04:00
DefensiveDepth
74dfc25376
backup local rules
2024-05-28 09:29:10 -04:00
DefensiveDepth
81ee60e658
Backup .yml files too
2024-05-28 06:42:18 -04:00
reyesj2
fcb6a47e8c
Remove redis.sh telegraf script when Kafka is global pipeline
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-26 21:10:41 -04:00
Josh Brower
49fd84a3a7
Merge pull request #13081 from Security-Onion-Solutions/2.4/soupchange
...
Dont bail - just wait for enter
2024-05-24 16:28:40 -04:00
DefensiveDepth
58b565558d
Dont bail - just wait for enter
2024-05-24 16:21:59 -04:00
Josh Brower
185fb38b2d
Merge pull request #13079 from Security-Onion-Solutions/2.4/sigmapipelineupdates
...
Add IDH mappings
2024-05-24 14:48:22 -04:00
DefensiveDepth
550b3ee92d
Add IDH mappings
2024-05-24 14:46:24 -04:00
Josh Brower
29a87fd166
Merge pull request #13078 from Security-Onion-Solutions/2.4/socdefaultsdet
...
Add instructions for sigma and yara repos
2024-05-24 13:02:01 -04:00
DefensiveDepth
f90d40b471
Fix typo
2024-05-24 12:56:17 -04:00
DefensiveDepth
4344988abe
Add instructions for sigma and yara repos
2024-05-24 12:54:36 -04:00
Josh Brower
979147a111
Merge pull request #13062 from Security-Onion-Solutions/2.4/backupscript
...
Detections backup script
2024-05-24 10:06:56 -04:00
DefensiveDepth
66725b11b3
Added unit tests
2024-05-24 09:55:10 -04:00
Jason Ertel
19f9c4e389
Merge pull request #13076 from Security-Onion-Solutions/jertel/eaconfig
...
provide default columns when viewing SOC logs
2024-05-24 08:39:17 -04:00
Jason Ertel
bd11d59c15
add event.dataset since there are other datasets in soc logs
2024-05-24 08:38:12 -04:00
Jason Ertel
15155613c3
provide default columns when viewing SOC logs
2024-05-24 08:23:45 -04:00
m0duspwnens
b5f656ae58
dont render pillar each time so-tcpreplay runs
2024-05-23 13:22:22 -04:00
Josh Patterson
7177392adc
Merge pull request #13071 from Security-Onion-Solutions/telfinwip
...
Telfinwip
2024-05-23 10:46:54 -04:00
m0duspwnens
ea7715f729
use waitforstate var instead.
2024-05-23 10:41:10 -04:00
m0duspwnens
0b9ebefdb6
only show telem status in final whiptail if new deployment
2024-05-23 10:08:23 -04:00
Mike Reeves
19e66604d0
Merge pull request #13069 from Security-Onion-Solutions/TOoSmOotH-patch-8
...
Update defaults.yaml
2024-05-23 08:22:05 -04:00
Mike Reeves
1e6161f89c
Update defaults.yaml
2024-05-23 08:19:43 -04:00
Josh Brower
a8c287c491
Merge pull request #13067 from Security-Onion-Solutions/2.4/fixpipeline
...
Fix strelka rule.uuid
2024-05-23 07:53:14 -04:00
Doug Burks
2c4f5f0a91
Merge pull request #13066 from Security-Onion-Solutions/dougburks-patch-1
...
Update defaults.yaml to fix order of groupby tables and eliminate dup…
2024-05-23 06:02:49 -04:00
DefensiveDepth
8e7c487cb0
Fix strelka rule.uuid
2024-05-23 05:59:31 -04:00
Doug Burks
3d4f3a04a3
Update defaults.yaml to fix order of groupby tables and eliminate duplicate
2024-05-23 05:56:18 -04:00
Josh Brower
ce063cf435
Merge pull request #13063 from Security-Onion-Solutions/2.4/yarafix
...
Fix casing issue
2024-05-22 18:51:54 -04:00
DefensiveDepth
a072e34cfe
Fix casing issue
2024-05-22 17:12:41 -04:00
DefensiveDepth
d19c1a514b
Detections backup script
2024-05-22 15:12:23 -04:00
weslambert
b415810485
Merge pull request #13061 from Security-Onion-Solutions/fix/tab_casing
...
Change tab casing to be consistent with other whiptail prompts
2024-05-22 13:44:09 -04:00
weslambert
3cfd710756
Change tab casing to be consistent with other whiptail prompts
2024-05-22 13:41:32 -04:00
reyesj2
382cd24a57
Small changes needed for using new Kafka docker image + added Kafka logging output to /opt/so/log/kafka/
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:39:21 -04:00
reyesj2
b1beb617b3
Logstash should be disabled when Kafka is enabled except when a minion override exists OR node is a standalone
...
- Standalone subscribes to Kafka topics via logstash for ingest
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:38:09 -04:00
reyesj2
91f8b1fef7
Set default replication factor back to Kafka default
...
If replication factor is > 1 Kafka will fail to start until another broker is added
- For internal automated testing purposes a Standalone will be utilized
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-22 13:35:09 -04:00
Jason Ertel
ca6e2b8e22
Merge pull request #13054 from Security-Onion-Solutions/jertel/eaconfig
...
fix elastalert settings
2024-05-21 18:38:03 -04:00
Jason Ertel
8af3158ea7
fix elastalert settings
2024-05-21 18:28:21 -04:00
Josh Brower
8b011b8d7e
Merge pull request #13053 from Security-Onion-Solutions/2.4/alertsefaults
...
Add rule.uuid to default groupbys
2024-05-21 17:54:27 -04:00
DefensiveDepth
f9e9b825cf
Removed unneeded groupby
2024-05-21 17:53:20 -04:00
DefensiveDepth
3992ef1082
Add rule.uuid to default groupbys
2024-05-21 17:45:56 -04:00
weslambert
556fdfdcf9
Merge pull request #13052 from Security-Onion-Solutions/fix/add_rule_uuid
...
Add rule.uuid for YARA matches
2024-05-21 17:09:49 -04:00
weslambert
f4490fab58
Add rule.uuid for YARA matches
2024-05-21 17:05:39 -04:00
weslambert
5aaf44ebb2
Merge pull request #13049 from Security-Onion-Solutions/fix/detections_alerts_component_template
...
Exclude detections from template name matching
2024-05-21 13:45:19 -04:00
weslambert
deb140e38e
Exclude detections from template name matching
2024-05-21 13:38:52 -04:00
Jason Ertel
3de6454d4f
Merge pull request #13047 from Security-Onion-Solutions/jertel/eaconfig
...
Jertel/eaconfig
2024-05-21 13:34:20 -04:00
Jason Ertel
d57cc9627f
exclude false positives related to detections
2024-05-21 13:31:50 -04:00
Jason Ertel
8ce19a93b9
exclude false positives related to detections
2024-05-21 13:29:20 -04:00
Jason Ertel
d315b95d77
elastalert settings
2024-05-21 07:15:19 -04:00
Doug Burks
6172816f61
Merge pull request #13044 from Security-Onion-Solutions/dougburks-patch-1
...
Update README.md with new Detections screenshot number
2024-05-21 06:49:35 -04:00
Doug Burks
03826dd32c
Update README.md with new Detections screenshot number
2024-05-21 06:43:07 -04:00
Jason Ertel
b7a4f20c61
elastalert settings
2024-05-20 20:11:30 -04:00
Jason Ertel
02b4d37c11
elastalert settings
2024-05-20 20:00:31 -04:00
Jason Ertel
f8ce039065
elastalert settings
2024-05-20 19:58:12 -04:00
Jason Ertel
e2d0b8f4c7
elastalert settings
2024-05-20 19:38:36 -04:00
Jason Ertel
8a3061fe3e
elastalert settings
2024-05-20 19:36:06 -04:00
Jason Ertel
c594168b65
elastalert settings
2024-05-20 19:05:43 -04:00
Jason Ertel
31fdf15ce1
Merge branch '2.4/dev' into jertel/eaconfig
2024-05-20 18:59:35 -04:00
Jason Ertel
6b2219b7f2
elastalert settings
2024-05-20 18:52:37 -04:00
coreyogburn
64144b4759
Merge pull request #13041 from Security-Onion-Solutions/cogburn/integrity-checker-annotations
...
Annotate integrityCheckFrequencySeconds per det engine
2024-05-20 14:52:38 -06:00
Corey Ogburn
6e97c39f58
Marked as Advanced
2024-05-20 14:52:05 -06:00
Corey Ogburn
026023fd0a
Annotate integrityCheckFrequencySeconds per det engine
2024-05-20 14:35:11 -06:00
Jorge Reyes
d7ee89542a
Merge pull request #13040 from Security-Onion-Solutions/lkscript
...
Create helper script for tpm enrollment
2024-05-20 15:25:50 -04:00
reyesj2
6fac6eebce
Helper script for enrolling tpm into luks
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-20 14:37:54 -04:00
coreyogburn
3c3497c2fd
Merge pull request #13039 from Security-Onion-Solutions/cogburn/integrity-check
...
Add Default IntegrityCheck Frequency Values
2024-05-20 11:26:30 -06:00
Corey Ogburn
fcc72a4f4e
Add Default IntegrityCheck Frequency Values
2024-05-20 11:23:25 -06:00
coreyogburn
28dea9be58
Merge pull request #13037 from Security-Onion-Solutions/cogburn/comp-report-path-change
...
Change Compilation Report Path
2024-05-17 15:48:52 -06:00
Corey Ogburn
0cc57fc240
Change Compilation Report Path
...
Move compilation report path to /opt/so/state and mount that foulder in SOC
2024-05-17 15:47:23 -06:00
weslambert
17518b90ca
Merge pull request #13036 from Security-Onion-Solutions/fix/yara_compile_report
...
Create YARA compile report for SOC integrity check
2024-05-17 16:15:21 -04:00
weslambert
d9edff38df
Create compile report for SOC integrity check
2024-05-17 16:10:10 -04:00
Jason Ertel
300d8436a8
Merge pull request #13035 from Security-Onion-Solutions/jertel/eaconfig
...
add support for custom alerters
2024-05-17 15:01:54 -04:00
Jason Ertel
1c4d36760a
add support for custom alerters
2024-05-17 14:49:39 -04:00
reyesj2
34a5985311
Create tpm enrollment script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-16 21:14:57 -04:00
Josh Patterson
aa0163349b
Merge pull request #13031 from Security-Onion-Solutions/issue/13021
...
Issue/13021
2024-05-16 16:40:17 -04:00
Josh Patterson
572b8d08d9
Merge branch '2.4/dev' into issue/13021
2024-05-16 16:39:17 -04:00
m0duspwnens
cc6cb346e7
fix issue/13030
2024-05-16 16:31:45 -04:00
m0duspwnens
b54632080e
check if exists in override before popping
2024-05-16 16:04:17 -04:00
Josh Patterson
44d3468f65
Merge pull request #13029 from Security-Onion-Solutions/revert-13028-issue/13021
...
Revert "dont merge policy from global_overrides if not defined in default index_settings"
2024-05-16 15:48:05 -04:00
Josh Patterson
9d4668f4d3
Revert "dont merge policy from global_overrides if not defined in default index_settings"
2024-05-16 15:45:55 -04:00
Josh Patterson
da2ac4776e
Merge pull request #13028 from Security-Onion-Solutions/issue/13021
...
dont merge policy from global_overrides if not defined in default index_settings
2024-05-16 14:33:51 -04:00
m0duspwnens
9796354b48
dont merge policy from global_overrides if not defined in default index_settings
2024-05-16 14:27:32 -04:00
Jason Ertel
aa32eb9c0e
Merge pull request #13025 from Security-Onion-Solutions/jertel/suridp
...
exclude detect-parse errors
2024-05-15 19:21:30 -04:00
Jason Ertel
4771810361
exclude detect-parse errors
2024-05-15 19:10:50 -04:00
Mike Reeves
52f27c00ce
Merge pull request #13024 from Security-Onion-Solutions/TOoSmOotH-patch-7
...
Update soup
2024-05-15 18:07:28 -04:00
Mike Reeves
ab9ec2ec6b
Update soup
2024-05-15 18:04:01 -04:00
Josh Patterson
4d7835612d
Merge pull request #13022 from Security-Onion-Solutions/soupaml
...
add a newline to final output of so-elastic-agent-gen-installers
2024-05-15 16:37:53 -04:00
m0duspwnens
8076ea0e0a
add another space
2024-05-15 16:34:05 -04:00
Josh Brower
320ae641b1
Merge pull request #13023 from Security-Onion-Solutions/2.4/sigmapipelineupdates
...
alphabetical order
2024-05-15 16:30:45 -04:00
DefensiveDepth
b4aec9a9d0
alphabetical order
2024-05-15 16:29:21 -04:00
m0duspwnens
6af0308482
add a newline
2024-05-15 16:26:44 -04:00
Josh Patterson
08024c7511
Merge pull request #13020 from Security-Onion-Solutions/issue/13012
...
Issue/13012
2024-05-15 15:33:01 -04:00
m0duspwnens
3a56058f7f
update description
2024-05-15 15:31:31 -04:00
Mike Reeves
795de7ab07
Merge pull request #13019 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update enabled.sls
2024-05-15 14:08:40 -04:00
Mike Reeves
8803ad4018
Update enabled.sls
2024-05-15 14:05:48 -04:00
m0duspwnens
62a8024c6c
Merge remote-tracking branch 'origin/2.4/dev' into issue/13012
2024-05-15 13:48:46 -04:00
m0duspwnens
ea253726a0
fix soup
2024-05-15 13:48:32 -04:00
Mike Reeves
a0af25c314
Merge pull request #13017 from Security-Onion-Solutions/surimigrate
...
Update enabled.sls
2024-05-15 11:40:50 -04:00
Mike Reeves
e3a0847867
Update soup
2024-05-15 11:31:41 -04:00
Mike Reeves
7345d2c5a6
Update enabled.sls
2024-05-15 11:16:20 -04:00
Josh Patterson
7cbc3a83c6
Merge pull request #13016 from Security-Onion-Solutions/soupaml
...
so-yaml in soup_scripts
2024-05-15 10:49:56 -04:00
m0duspwnens
427b1e4524
revert soup_scripts back to common
2024-05-15 10:28:02 -04:00
m0duspwnens
2dbbe8dec4
soup_scripts put so-yaml in salt file system. move soup scripts to manager.soup_scripts
2024-05-15 10:07:06 -04:00
Josh Patterson
e76c2c95a9
Merge pull request #13013 from Security-Onion-Solutions/issue/13012
...
remove idh.services from idh node pillar files
2024-05-15 08:37:15 -04:00
m0duspwnens
51862e5803
remove idh.services from idh node pillar files
2024-05-14 13:08:51 -04:00
Doug Burks
27ad84ebd9
Merge pull request #13011 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add NetFlow dashboard #13009
2024-05-14 10:15:25 -04:00
Doug Burks
67645a662d
FEATURE: Add NetFlow dashboard #13009
2024-05-14 10:14:16 -04:00
Doug Burks
1d16f6b7ed
Merge pull request #13010 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add NetFlow dashboard #13009
2024-05-14 10:02:40 -04:00
Doug Burks
5b45c80a62
FEATURE: Add NetFlow dashboard #13009
2024-05-14 10:01:18 -04:00
weslambert
6dec9b4cf7
Merge pull request #12986 from Security-Onion-Solutions/fix/old_strelka
...
Remove old Strelka configuration for YARA
2024-05-14 09:27:19 -04:00
weslambert
13062099b3
Remove YARA script update and reference to exclusions
2024-05-13 18:04:16 -04:00
weslambert
7250fb1188
Merge pull request #13004 from Security-Onion-Solutions/fix/detections_alerts_indices
...
FIX: Detections alerts indices
2024-05-13 17:02:52 -04:00
Josh Patterson
437d0028db
Merge pull request #13003 from Security-Onion-Solutions/localdirs
...
create local directories during soup if needed
2024-05-13 16:33:04 -04:00
m0duspwnens
1ef9509aac
define local_salt_dir
2024-05-13 14:34:22 -04:00
weslambert
d606f259d1
Add detection alerts
2024-05-13 14:25:11 -04:00
weslambert
c8870eae65
Add detection alerts template
2024-05-13 14:23:47 -04:00
Josh Brower
2419066dc8
Merge pull request #13001 from Security-Onion-Solutions/2.4/socdefaults
...
2.4/socdefaults
2024-05-13 13:39:31 -04:00
DefensiveDepth
e430de88d3
Change rule updates to 24h
2024-05-13 13:15:06 -04:00
DefensiveDepth
c4c38f58cb
Update descriptions
2024-05-13 13:13:57 -04:00
weslambert
26b5a39912
Change index to detections.alerts
2024-05-13 12:59:17 -04:00
m0duspwnens
eb03858230
missed one
2024-05-13 12:44:57 -04:00
m0duspwnens
2643da978b
those functions in so-functions
2024-05-13 11:51:10 -04:00
m0duspwnens
649f52dac7
create_local_directories in soup too
2024-05-13 10:37:56 -04:00
Mike Reeves
927fe91f25
Merge pull request #13000 from Security-Onion-Solutions/soupz
...
Backup Suricata for migration
2024-05-13 10:12:34 -04:00
Mike Reeves
9d6f6c7893
Update soup
2024-05-13 10:09:35 -04:00
Mike Reeves
28e40e42b3
Update soc_soc.yaml
2024-05-13 09:58:32 -04:00
Mike Reeves
6c71c45ef6
Update soup
2024-05-13 09:55:57 -04:00
Mike Reeves
641899ad56
Backup Suricata for migration and remove advanced from reverselookups
2024-05-13 09:50:14 -04:00
Doug Burks
d120326cb9
Merge pull request #12999 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add more fields to the SOC Dashboards URL for so-import-pcap #12972
2024-05-13 09:20:01 -04:00
Doug Burks
a4f2d8f327
Merge pull request #12998 from Security-Onion-Solutions/dougburks-patch-2
...
Update README.md to reference new screenshots for 2.4.70
2024-05-13 08:42:33 -04:00
Doug Burks
ae323cf385
Update README.md to include new Detections screenshot
2024-05-13 08:34:44 -04:00
Doug Burks
788c31014d
Update README.md to reference new screenshots for 2.4.70
2024-05-13 08:30:48 -04:00
Jason Ertel
154dc605ef
Merge pull request #12994 from Security-Onion-Solutions/jertel/testcy
...
support upgrade tests
2024-05-10 16:57:19 -04:00
Jason Ertel
2a0e33401d
support upgrade tests
2024-05-10 16:54:50 -04:00
Josh Patterson
79b4d7b6b6
Merge pull request #12992 from Security-Onion-Solutions/issue/12991
...
Fix IDH node
2024-05-10 12:43:09 -04:00
m0duspwnens
986cbb129a
pkg not file
2024-05-10 12:33:56 -04:00
m0duspwnens
950c68783c
add pkg policycoreutils-python-utils to idh node
2024-05-10 11:46:00 -04:00
Doug Burks
cec75ba475
Merge pull request #12989 from Security-Onion-Solutions/dougburks-patch-2
...
FIX: so-index-list typo #12988
2024-05-10 08:06:29 -04:00
Doug Burks
26cb8d43e1
FIX: so-index-list typo #12988
2024-05-10 08:01:56 -04:00
Doug Burks
a1291e43c3
FIX: so-index-list typo #12988
2024-05-10 07:58:13 -04:00
Jason Ertel
45fd07cdf8
Merge pull request #12987 from Security-Onion-Solutions/jertel/testcy
...
Add quick action to find related alerts for a detection
2024-05-09 18:08:08 -04:00
Jason Ertel
fecd674fdb
Add quick action to find related alerts for a detection
2024-05-09 17:55:41 -04:00
Jason Ertel
dff2de4527
Merge pull request #12984 from Security-Onion-Solutions/jertel/testcy
...
tests will retry on any rule import failure
2024-05-09 15:50:37 -04:00
Jason Ertel
19e1aaa1a6
exclude detection rule errors
2024-05-09 15:45:33 -04:00
Jason Ertel
074d063fee
tests will retry on any rule import failure
2024-05-09 14:52:58 -04:00
Wes
6ed82d7b29
Remove YARA download in setup
2024-05-09 17:27:46 +00:00
Wes
ea4cf42913
Remove old YARA update script
2024-05-09 17:26:54 +00:00
Wes
8a34f5621c
Remove old YARA download script
2024-05-09 17:26:45 +00:00
Wes
823ff7ce11
Remove exclusions and repos
2024-05-09 17:03:13 +00:00
Josh Patterson
fb8456b4a6
Merge pull request #12983 from Security-Onion-Solutions/fix/strelka
...
fix strelka errors
2024-05-09 12:04:40 -04:00
m0duspwnens
c864fec70c
allow strelka.manager to run on standalone
2024-05-09 11:53:50 -04:00
m0duspwnens
a74fee4cd0
strelka compiled rules
2024-05-09 11:26:02 -04:00
m0duspwnens
3a99624eb8
seperate manager states for strelka
2024-05-09 10:03:02 -04:00
Mike Reeves
656bf60fda
Merge pull request #12973 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update config.sls
2024-05-08 16:42:19 -04:00
weslambert
cdc47cb1cd
Merge pull request #12975 from Security-Onion-Solutions/fix/strelka_watch
...
Use state
2024-05-08 16:39:49 -04:00
weslambert
01a68568a6
Use state
2024-05-08 16:37:13 -04:00
reyesj2
2ad87bf1fe
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-08 16:30:45 -04:00
reyesj2
eca2a4a9c8
Logstash consumer threads should match topic partition count
...
- Default is set to 3. If there are too many consumer threads it may lead to idle logstash worker threads and could require decreasing this value to saturate workers
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-08 16:17:09 -04:00
reyesj2
dff609d829
Add basic read-only metric collection from Kafka
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-08 16:13:09 -04:00
weslambert
b916465b06
Merge pull request #12974 from Security-Onion-Solutions/fix/strelka_yara
...
Account for 0 active rules and change watch
2024-05-08 15:59:20 -04:00
weslambert
0567b93534
Remove mode
2024-05-08 15:39:59 -04:00
Mike Reeves
ad9fdf064b
Update config.sls
2024-05-08 15:24:29 -04:00
Wes
77e2117051
Account for 0 active rules and change watch
2024-05-08 18:47:52 +00:00
Doug Burks
5b7b6e5fb8
FEATURE: Add more fields to the SOC Dashboards URL for so-import-pcap #12972
2024-05-08 14:00:23 -04:00
Doug Burks
c7845bdf56
Merge pull request #12970 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Adjust so-import-pcap so that suricata works when it is pcapengine #12969
2024-05-08 13:28:05 -04:00
Doug Burks
5a5a1e86ac
FIX: Adjust so-import-pcap so that suricata works when it is pcapengine #12969
2024-05-08 13:26:36 -04:00
Josh Patterson
796eefc2f0
Merge pull request #12965 from Security-Onion-Solutions/orchit
...
searchnode installation improvements
2024-05-08 10:24:33 -04:00
m0duspwnens
1862deaf5e
add copyright
2024-05-08 10:14:08 -04:00
m0duspwnens
0d2e5e0065
need repo and docker first
2024-05-08 09:50:01 -04:00
m0duspwnens
5dc098f0fc
remove test file
2024-05-08 08:54:24 -04:00
Mike Reeves
af681881e6
Merge pull request #12963 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Make the url list read only
2024-05-08 08:45:34 -04:00
Josh Brower
47dc911b79
Merge pull request #12964 from Security-Onion-Solutions/2.4/agstrelka
...
remove old yara airgap code
2024-05-08 08:45:16 -04:00
DefensiveDepth
6d2ecce9b7
remove old yara airgap code
2024-05-08 08:43:37 -04:00
Mike Reeves
326c59bb26
Update soc_idstools.yaml
2024-05-08 08:42:38 -04:00
Mike Reeves
c1257f1c13
Merge pull request #12961 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Change so soc writes urls as a list
2024-05-07 17:23:12 -04:00
Mike Reeves
2eee617788
Update soc_idstools.yaml
2024-05-07 17:21:01 -04:00
Jason Ertel
70ef8092a7
Merge pull request #12959 from Security-Onion-Solutions/jertel/testcy
...
update suri regex for testing
2024-05-07 11:37:31 -07:00
Jason Ertel
8364b2a730
update for testing
2024-05-07 14:30:52 -04:00
coreyogburn
cb7dea1295
Merge pull request #12957 from Security-Onion-Solutions/cogburn/retry-import
...
Specify Error Retry Wait and Error Limit for All Detection Engines
2024-05-07 11:20:26 -06:00
Corey Ogburn
1da88b70ac
Specify Error Retry Wait and Error Limit for All Detection Engines
...
If a sync errors out, the engine will wait `communityRulesImportErrorSeconds` seconds instead of the usual `communityRulesImportFrequencySeconds` seconds wait.
If `failAfterConsecutiveErrorCount` errors happen in a row when syncing detections to ElasticSearch then the sync is considered a failure and will give up and try again later. This assumes ElasticSearch is the source of the errors and backs of in hopes it'll be able to fix itself.
2024-05-07 10:34:50 -06:00
Jason Ertel
b4817fa062
Merge pull request #12956 from Security-Onion-Solutions/jertel/testcy
...
test regexes for detections
2024-05-07 08:45:38 -07:00
weslambert
bc24227732
Merge pull request #12955 from Security-Onion-Solutions/fix/cef
...
Add CEF
2024-05-07 11:23:53 -04:00
weslambert
2e70d157e2
Add ref
2024-05-07 11:13:51 -04:00
m0duspwnens
5e2e5b2724
Merge remote-tracking branch 'origin/2.4/dev' into orchit
2024-05-07 10:44:14 -04:00
m0duspwnens
dcc1f656ee
predownload logstash and elastic for new searchnode and heavynode
2024-05-07 10:13:51 -04:00
weslambert
23da1f6ee9
Merge pull request #12951 from Security-Onion-Solutions/fix/remove_watch
...
Remove watch
2024-05-07 09:23:56 -04:00
Wes
bee8c2c1ce
Remove watch
2024-05-07 13:21:59 +00:00
Jason Ertel
4ebe070cd8
test regexes for detections
2024-05-06 19:03:12 -04:00
weslambert
a5e89c0854
Merge pull request #12947 from Security-Onion-Solutions/fix/strelka_yara_distributed
...
Fix YARA rules for distributed deployments
2024-05-06 15:53:08 -04:00
weslambert
a25e43db8f
Merge pull request #12948 from Security-Onion-Solutions/fix/strelka_yara_watch
...
Restart Strelka backend when YARA rules change
2024-05-06 15:52:57 -04:00
Josh Brower
b997e44715
Merge pull request #12939 from Security-Onion-Solutions/2.4/detections-airgap
...
Initial airgap support for detections
2024-05-06 15:46:29 -04:00
Wes
1e48955376
Restart when rules change
2024-05-06 19:39:03 +00:00
Wes
5056ec526b
Add compiled directory
2024-05-06 19:27:38 +00:00
m0duspwnens
2431d7b028
Merge branch '2.4/detections-airgap' of https://github.com/Security-Onion-Solutions/securityonion into 2.4/detections-airgap
2024-05-06 15:27:27 -04:00
Wes
d2fa77ae10
Update compile script
2024-05-06 19:10:41 +00:00
Wes
445fb31634
Add manager SLS
2024-05-06 19:09:37 +00:00
Wes
5aa611302a
Handle YARA rules for distributed deployments
2024-05-06 19:08:01 +00:00
m0duspwnens
554a203541
update airgapEnabled in map file
2024-05-06 12:59:45 -04:00
DefensiveDepth
be1758aea7
Fix license and folder
2024-05-06 12:22:44 -04:00
m0duspwnens
38f74d2e9e
change quotes
2024-05-06 11:38:30 -04:00
m0duspwnens
5b966b83a9
change rulesRepos for airgap or not
2024-05-06 09:26:52 -04:00
Doug Burks
a67f0d93a0
Merge pull request #12942 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add event.dataset to all Events table layouts #12641
2024-05-06 09:23:09 -04:00
Doug Burks
3f73b14a6a
FEATURE: Add event.dataset to all Events table layouts #12641
2024-05-06 09:20:47 -04:00
Doug Burks
e57d1a5fb5
Merge pull request #12941 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for stun logs #12940
2024-05-06 08:57:58 -04:00
Doug Burks
f689cfcd0a
FEATURE: Add Events table columns for stun logs #12940
2024-05-06 08:52:43 -04:00
DefensiveDepth
26c6a98b45
Initial airgap support for detections
2024-05-06 08:43:01 -04:00
Doug Burks
45c344e3fa
Merge pull request #12938 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for tunnel logs #12937
2024-05-06 08:40:02 -04:00
Doug Burks
7b905f5a94
FEATURE: Add Events table columns for tunnel logs #12937
2024-05-06 08:22:08 -04:00
Josh Brower
6d5ff59657
Merge pull request #12929 from Security-Onion-Solutions/2.4/verifyexclude
...
Exclude new sigma rules
2024-05-03 15:38:25 -04:00
DefensiveDepth
7f12d4c815
Exclude new sigma rules
2024-05-03 15:22:53 -04:00
Josh Patterson
b50789a77c
Merge pull request #12928 from Security-Onion-Solutions/orchit
...
Orchit
2024-05-03 15:17:34 -04:00
m0duspwnens
bdf1b45a07
redirect and throw in bg
2024-05-03 14:54:44 -04:00
m0duspwnens
3d4fd59a15
orchit
2024-05-03 13:48:51 -04:00
Doug Burks
91c9f26a0c
Merge pull request #12926 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add hyperlink to airgap screen in setup #12925
2024-05-03 13:02:30 -04:00
Doug Burks
6cbbb81cad
FEATURE: Add hyperlink to airgap screen in setup #12925
2024-05-03 12:59:41 -04:00
m0duspwnens
442a717d75
orchit
2024-05-03 12:08:57 -04:00
m0duspwnens
fa3522a233
fix requirement
2024-05-03 11:10:21 -04:00
m0duspwnens
bbc374b56e
add logic in orch
2024-05-03 09:56:52 -04:00
Doug Burks
9ae6fc5666
Merge pull request #12922 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Update so-whiptail to make installation screen more consistent #12921
2024-05-03 09:43:59 -04:00
Doug Burks
5fe8c6a95f
Update so-whiptail to make installation screen more consistent
2024-05-03 09:38:34 -04:00
m0duspwnens
2929877042
fix var
2024-05-02 16:37:54 -04:00
m0duspwnens
8035740d2b
Merge remote-tracking branch 'origin/2.4/dev' into orchit
2024-05-02 16:34:24 -04:00
Josh Patterson
4f8aaba6c6
Merge pull request #12918 from Security-Onion-Solutions/pw
...
run so-rule-update if ruleset or code changes for idstools
2024-05-02 16:33:24 -04:00
m0duspwnens
e9b1263249
orchestate searchnode deployment
2024-05-02 16:32:43 -04:00
Josh Patterson
3b2d3573d8
Update pillarWatch.py
2024-05-02 16:06:04 -04:00
reyesj2
e960ae66a3
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka
2024-05-02 15:12:27 -04:00
reyesj2
093cbc5ebc
Reconfigure Kafka defaults
...
- Set default number of partitions per topic -> 3. Helps ensure that out of the box we can take advantage of multi-node Kafka clusters via load balancing across atleast 3 brokers. Also multiple searchnodes will be able to pull from each topic. In this case 3 searchnodes (consumers) would be able to pull from all topics concurrently.
- Set default replication factor -> 2. This is the minimum value required for redundancy. Every partition will have 1 replica. In this case if we have 2 brokers each topic will have 3 partitions (load balanced across brokers) and each partition will have a replica on separate broker for redundancy
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-02 15:10:13 -04:00
reyesj2
f663ef8c16
Setup Kafka to use PKCS12 and remove need for converting to JKS
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-02 14:53:28 -04:00
reyesj2
de9f6425f9
Automatically switch between Kafka output policy and logstash output policy when globals.pipeline changes
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-02 12:13:46 -04:00
m0duspwnens
33d1170a91
add default pillar value for pillarWatch
2024-05-02 11:58:39 -04:00
Doug Burks
240ffc0862
Merge pull request #12915 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve File dashboard #12914
2024-05-02 10:44:58 -04:00
Doug Burks
0822a46e94
FIX: Improve File dashboard #12914
2024-05-02 10:42:34 -04:00
Doug Burks
1be3e6204d
FIX: Improve File dashboard #12914
2024-05-02 10:38:56 -04:00
weslambert
956ae7a7ae
Merge pull request #12909 from Security-Onion-Solutions/fix/detection_mappings
...
Update mappings for detection fields
2024-05-01 16:15:40 -04:00
Wes
3285ae9366
Update mappings for detection fields
2024-05-01 20:11:56 +00:00
reyesj2
47ced60243
Create new Kafka output policy using salt
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 14:49:51 -04:00
Josh Patterson
72b2503b49
Merge pull request #12906 from Security-Onion-Solutions/det_easr
...
Apply autoEnabledSigmaRules based on role if defined and default if not
2024-05-01 13:05:36 -04:00
reyesj2
58ebbfba20
Add kafka state to standalone highstate
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 13:03:14 -04:00
reyesj2
e164d15ec6
Generate different Kafka certs for different SO nodetypes
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 13:02:47 -04:00
reyesj2
3efdb4e532
Reconfigure logstash Kafka input
...
- TODO: Configure what topics are pulled to searchnodes via the SOC UI
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 13:01:29 -04:00
Mike Reeves
854799fabb
Merge pull request #12902 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update config.sls
2024-05-01 12:56:04 -04:00
m0duspwnens
47ba4c0f57
add new annotation for soc autoEnabledSigmaRules
2024-05-01 12:55:29 -04:00
Mike Reeves
10c8e4203c
Update config.sls
2024-05-01 12:54:21 -04:00
Jason Ertel
05c69925c9
Merge pull request #12904 from Security-Onion-Solutions/jertel/wf
...
mark detections settings as read-only via the UI
2024-05-01 09:54:03 -07:00
Jason Ertel
252d9a5320
make rule settings advanced
2024-05-01 12:51:04 -04:00
m0duspwnens
7122709bbf
set Sigma rules based on role if defined and default if not
2024-05-01 12:25:34 -04:00
Mike Reeves
f7223f132a
Update config.sls
2024-05-01 12:00:39 -04:00
Mike Reeves
8cd75902f2
Update config.sls
2024-05-01 11:47:51 -04:00
Jason Ertel
c71af9127b
mark detections settings as read-only via the UI
2024-05-01 11:47:38 -04:00
weslambert
e6f45161c1
Merge pull request #12900 from Security-Onion-Solutions/fix/cold_min_age
...
Cold min_age to 60d
2024-05-01 11:24:48 -04:00
weslambert
fe2edeb2fb
30d to 60d
2024-05-01 11:01:59 -04:00
weslambert
6294f751ee
Cold min_age to 60d
2024-05-01 10:59:41 -04:00
reyesj2
de0af58cf8
Write out Kafka pillar path
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 10:45:46 -04:00
reyesj2
84abfa6881
Remove check for existing value since Kafka pillar is made empty on upgrade
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 10:45:05 -04:00
reyesj2
6b60e85a33
Make kafka configuration changes prior to 2.4.70 upgrade
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 10:15:26 -04:00
reyesj2
63f3e23e2b
soup typo
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 09:54:19 -04:00
Jason Ertel
ad1cda1746
Merge pull request #12893 from Security-Onion-Solutions/jertel/wf
...
update annotations for duplication
2024-05-01 06:32:13 -07:00
Jason Ertel
66563a4da0
zeek networks will only ever have one HOME_NETWORKS setting
2024-05-01 09:31:11 -04:00
Jason Ertel
d0e140cf7b
zeek networks will only ever have one HOME_NETWORKS setting
2024-05-01 09:30:52 -04:00
Jason Ertel
87c6d0a820
zeek networks will only ever have one HOME_NETWORKS setting
2024-05-01 09:29:36 -04:00
reyesj2
eb1249618b
Update soup for Kafka
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 09:27:01 -04:00
reyesj2
cef9bb1487
Dynamically create Kafka topics based on event.module from elastic agent logs eg. zeek-topic. Depends on Kafka brokers having auto.create.topics.enable set to true
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-05-01 09:16:13 -04:00
Doug Burks
9a25d3c30f
Merge pull request #12897 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Lower EVAL memory requirement to 8GB RAM #12896
2024-05-01 08:01:20 -04:00
Doug Burks
9a4a85e3ae
FEATURE: Lower EVAL memory requirement to 8GB RAM #12896
2024-05-01 07:54:38 -04:00
reyesj2
bb49944b96
Setup elastic fleet rollover from logstash -> kafka output policy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-30 16:47:40 -04:00
Jason Ertel
72db369fbb
Merge branch '2.4/dev' into jertel/wf
2024-04-30 15:16:41 -04:00
Jason Ertel
84db82852c
annotation updates for custom settings
2024-04-30 15:14:56 -04:00
reyesj2
fcc4050f86
Add id to grid-kafka fleet output policy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-30 12:59:53 -04:00
reyesj2
9c83a52c6d
Add Kafka output to elastic-fleet setup. Includes separating topics by event.module with fallback to default-logs if no event.module is specified or doesn't match processors
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-30 12:01:31 -04:00
coreyogburn
ea4750d8ad
Merge pull request #12882 from Security-Onion-Solutions/cogburn/community-repos
...
Mark Repos as Community
2024-04-30 09:12:25 -06:00
Doug Burks
e9944796c8
Merge pull request #12886 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Elasticsearch min_age regex #12885
2024-04-30 10:26:04 -04:00
Doug Burks
4d6124f982
FIX: Elasticsearch min_age regex #12885
2024-04-30 10:18:34 -04:00
Jorge Reyes
dd168e1cca
Merge pull request #12881 from Security-Onion-Solutions/2.4/finalpipefix
...
Update expected timestamp format in final pipeline for system events
2024-04-30 09:39:18 -04:00
Corey Ogburn
ddf662bdb4
Mark Repos as Community
...
Indicate that detection rules pulled from configured repos should be marked as Community rules.
2024-04-29 16:22:30 -06:00
reyesj2
fadb6e2aa9
Re-add original timestamp format + ignore failures with this processor
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 16:57:48 -04:00
reyesj2
192d91565d
Update final pipeline timestamp format for event.module system events
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 16:34:29 -04:00
Josh Patterson
82ef4c96c3
Merge pull request #12880 from Security-Onion-Solutions/issue/12878
...
set Suricata as default pcap engine for eval
2024-04-29 15:54:25 -04:00
reyesj2
a6e8b25969
Add Kafka connectivity between manager - > receiver nodes.
...
Add connectivity to Kafka between other node types that may need to publish to Kafka.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 15:48:57 -04:00
reyesj2
529bc01d69
Add missing configuration for nodes running Kafka broker role only
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 14:53:52 -04:00
m0duspwnens
a663bf63c6
set Suricata as default pcap engine for eval
2024-04-29 14:22:04 -04:00
reyesj2
11055b1d32
Rename kafkapass -> kafka_pass
...
Run so-kafka-clusterid within nodes.sls state so switchover is consistent
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 14:09:09 -04:00
reyesj2
fd9a91420d
Use SOC UI to configure list of KRaft (Kafka) controllers for cluster
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 11:37:24 -04:00
reyesj2
529c8d7cf2
Remove salt reactor for Kafka
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 11:35:46 -04:00
Josh Brower
13ccb58f84
Merge pull request #12876 from Security-Onion-Solutions/2.4/sigmafix
...
Sigma pivot fix and cleanup
2024-04-29 09:12:09 -04:00
reyesj2
086ebe1a7c
Split kafka defaults between broker / controller
...
Setup config.map.jinja to update broker / controller / combined node types
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 09:08:14 -04:00
reyesj2
29c964cca1
Set kafka.nodes state to run first to populate kafka.nodes pillar
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-29 09:04:52 -04:00
DefensiveDepth
f2c3c928fc
Sigma pivot fix and cleanup
2024-04-29 08:49:05 -04:00
Jason Ertel
3cbc29e767
Merge pull request #12875 from Security-Onion-Solutions/jertel/wf
...
restrict workflows to so
2024-04-29 05:16:07 -07:00
Jason Ertel
89cb8b79fd
restrict workflows to so
2024-04-29 08:07:19 -04:00
Mike Reeves
b5c5c7857b
Merge pull request #12846 from petiepooo/fix/check-srvc-status
...
check status before stopping service
2024-04-25 15:10:42 -04:00
Josh Patterson
ed05d51969
Merge pull request #12865 from Security-Onion-Solutions/issue/12637
...
only apply ulimits to suricata container if user enable mmap-locked
2024-04-25 10:08:05 -04:00
m0duspwnens
2c7eb3c755
only apply ulimits to suricata container if user enable mmap-locked
2024-04-25 10:05:59 -04:00
weslambert
cc17de2184
Merge pull request #12864 from Security-Onion-Solutions/fix/exclude_suricata
...
Exclude suricata from disk space-based index deletion
2024-04-25 09:23:38 -04:00
weslambert
b424426298
Exclude suricata
2024-04-25 09:14:18 -04:00
Josh Patterson
03f9160fcc
Merge pull request #12860 from Security-Onion-Solutions/issue/12856
...
allow for enabled/disable of so-elasticsearch-indices-delete cronjob
2024-04-25 09:07:44 -04:00
m0duspwnens
d50de804a8
update annotation
2024-04-25 09:04:34 -04:00
weslambert
983ef362e9
Merge pull request #12858 from Security-Onion-Solutions/fix/index_sorting
...
Change index sorting to account for older so-prefixed indices
2024-04-25 08:54:22 -04:00
Josh Brower
d88c1a5e0a
Merge pull request #12861 from Security-Onion-Solutions/2.4/detectionlogs
...
Add runtime status logs
2024-04-24 20:07:32 -04:00
weslambert
44afa55274
Fix comments about deletion
2024-04-24 17:41:37 -04:00
weslambert
ab832e4bb2
Include logstash-prefixed indices
2024-04-24 17:17:53 -04:00
DefensiveDepth
3c3ed8b5c5
Add runtime status logs
2024-04-24 16:33:47 -04:00
m0duspwnens
c9d9979f22
allow for enabled/disable of so-elasticsearch-indices-delete cronjob
2024-04-24 16:18:45 -04:00
Josh Patterson
383420b554
Merge pull request #12859 from Security-Onion-Solutions/issue/12637
...
Issue/12637
2024-04-24 15:44:37 -04:00
m0duspwnens
73b5bb1a75
add memlock to so-suricata container
2024-04-24 15:35:17 -04:00
weslambert
59a02635ed
Change index sorting
2024-04-24 15:18:49 -04:00
m0duspwnens
13a6520a8c
mmap-locked default no
2024-04-24 13:50:12 -04:00
m0duspwnens
4b7f826a2a
quote is so true becomes yes
2024-04-24 13:29:55 -04:00
m0duspwnens
0bd0c7b1ec
allow for mmap-locked to be configured
2024-04-24 13:26:25 -04:00
weslambert
428fe787c4
Merge pull request #12852 from Security-Onion-Solutions/fix/elastic_max_age
...
Remove hot max_age
2024-04-24 10:15:06 -04:00
weslambert
1b3a0a3de8
Remove hot max_age
2024-04-24 10:11:02 -04:00
weslambert
96ec285241
Merge pull request #12848 from Security-Onion-Solutions/fix/elastic_annotation
...
Fix description, regex, and type for cold, warm, and hot
2024-04-24 09:22:05 -04:00
weslambert
75b5e16696
Update description, type, and regex
2024-04-24 09:14:39 -04:00
weslambert
8a0a435700
Fix warm description
2024-04-24 08:35:19 -04:00
Pete
e53e7768a0
check status before stopping service
...
resolves #12811 so-verify detects rare false error
If salt is uninstalled during call to so-setup where it detects a previous install, the "Failed" keyword from "systemctl stop $service" causes so-verify to falsely detect an installation error. This might happen if the user removes the salt packages between calls to so-setup, or if upgrading from Ubuntu 20.04 to 22.04 then installing 2.4.xx on top of a 2.3.xx installation.
The fix is to wrap the call to stop the service in a check if the service is running.
This ignores the setting of pid var, as the next use of pid is within a while loop that will not execute for the same reason the systemctl stop call was not launched in the background.
2024-04-23 21:24:39 +00:00
reyesj2
36573d6005
Update kafka cert permissions
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-23 16:45:36 -04:00
reyesj2
aa0c589361
Update kafka managed node pillar template to include its process.role
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-23 13:51:12 -04:00
weslambert
bef408b944
Merge pull request #12844 from Security-Onion-Solutions/fix/elastic_annotation
...
Fix warm description
2024-04-23 10:47:04 -04:00
weslambert
691b02a15e
Fix warm description
2024-04-23 10:40:09 -04:00
Josh Brower
fc1c41e5a4
Merge pull request #12841 from Security-Onion-Solutions/2.4/logfix
...
Temp exclude yara runtime status log
2024-04-23 07:36:02 -04:00
DefensiveDepth
58ddd55123
Exclude yara runtime log
2024-04-23 07:28:07 -04:00
reyesj2
685b80e519
Merge remote-tracking branch 'remotes/origin/kaffytaffy' into reyesj2/kafka
2024-04-22 16:45:59 -04:00
reyesj2
5a401af1fd
Update kafka process_x_roles annotation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-22 16:44:35 -04:00
reyesj2
25d63f7516
Setup kafka reactor for managing kafka controllers globally
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-22 16:42:59 -04:00
Jorge Reyes
d402943403
Merge pull request #12773 from Security-Onion-Solutions/reyesj2/kismet
...
Kismet integration for WiFi devices
2024-04-22 15:59:22 -04:00
Josh Brower
64c43b1a55
Merge pull request #12805 from Security-Onion-Solutions/2.4/detectiondefaults
...
Strelka fixes and more
2024-04-19 16:53:07 -04:00
DefensiveDepth
a237ef5d96
Update default queries
2024-04-19 16:33:35 -04:00
m0duspwnens
6c5e0579cf
logging changes. ensure salt master has pillarWatch engine
2024-04-19 09:32:32 -04:00
reyesj2
4ac04a1a46
add kafkapass soc annotation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-18 16:46:36 -04:00
reyesj2
746128e37b
update so-kafka-clusterid
...
This is a temporary script used to setup kafka secret and clusterid needed for kafka to start. This scripts functionality will be replaced by soup/setup scripts
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-18 15:13:29 -04:00
reyesj2
fe81ffaf78
Variables no longer used. Replaced by map file
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-18 15:11:22 -04:00
m0duspwnens
1f6eb9cdc3
match keys better. go through files reverse first found is prio
2024-04-18 13:50:37 -04:00
Doug Burks
c48da45ac3
Merge pull request #12820 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Elastic retention setting not being honored when manager hostname is a subset of search node hostname #12819
2024-04-18 11:59:57 -04:00
reyesj2
5cc358de4e
Update map files to handle empty kafka:nodes pillar
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-18 11:58:25 -04:00
Doug Burks
406dda6051
Update so-elasticsearch-cluster-space-used
2024-04-18 11:48:15 -04:00
Doug Burks
229a989914
Update so-elasticsearch-cluster-space-total
2024-04-18 11:47:01 -04:00
DefensiveDepth
6c6647629c
Refactor yara for compilation
2024-04-18 11:32:17 -04:00
m0duspwnens
610dd2c08d
improve it
2024-04-18 11:11:14 -04:00
m0duspwnens
506bbd314d
more comments, better logging
2024-04-18 10:26:10 -04:00
Doug Burks
7f9bc1fc0f
Merge pull request #12817 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add queue=True to so-checkin so that it will wait for any ru…
2024-04-18 09:30:55 -04:00
Doug Burks
8d9aae1983
FEATURE: Add queue=True to so-checkin so that it will wait for any running states #12815
2024-04-18 09:28:30 -04:00
m0duspwnens
4caa6a10b5
watch a pillar in files and take action
2024-04-17 18:09:04 -04:00
reyesj2
665b7197a6
Update Kafka nodeid
...
Update so-minion to include running kafka.nodes state to ensure nodeid is generated for new brokers
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-17 17:08:41 -04:00
Mike Reeves
3854620bcd
Merge pull request #12810 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update limited-analyst.json
2024-04-17 13:21:04 -04:00
Mike Reeves
67a57e9df7
Update limited-analyst.json
2024-04-17 13:14:45 -04:00
m0duspwnens
4b79623ce3
watch pillar files for changes and do something
2024-04-16 16:51:35 -04:00
DefensiveDepth
ff28476191
Fix compile_yara path
2024-04-16 13:10:17 -04:00
DefensiveDepth
8cc4d2668e
Move compile_yara
2024-04-16 12:52:14 -04:00
DefensiveDepth
dbfb178556
Add test
2024-04-16 12:22:53 -04:00
m0duspwnens
c4994a208b
restart salt minion if a manager and signing policies change
2024-04-15 11:37:21 -04:00
reyesj2
eedea2ca88
Merge remote-tracking branch 'remotes/origin/kaffytaffy' into reyesj2/kafka
2024-04-12 16:24:33 -04:00
reyesj2
de6ea29e3b
update default process.role to broker only
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 16:18:53 -04:00
m0duspwnens
bb983d4ba2
just broker as default process
2024-04-12 16:16:03 -04:00
Josh Brower
5e8b16569f
Merge pull request #12793 from Security-Onion-Solutions/2.4/detectiondefaults
...
Add docs for ruleset change
2024-04-12 13:54:06 -04:00
m0duspwnens
c014508519
need /opt/so/conf/ca/cacerts on receiver for kafka to run
2024-04-12 13:50:25 -04:00
DefensiveDepth
f5e42e73af
Add docs for ruleset change
2024-04-12 13:30:20 -04:00
reyesj2
fcfbb1e857
Merge kaffytaffy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 12:50:56 -04:00
reyesj2
911ee579a9
Typo
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 12:16:20 -04:00
reyesj2
a6ff92b099
Note to remove so-kafka-clusterid. Update soup and setup to generate needed kafka pillar values
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 12:11:18 -04:00
m0duspwnens
d73ba7dd3e
order kafka pillar assignment
2024-04-12 11:55:26 -04:00
m0duspwnens
04ddcd5c93
add receiver managersearch and standalone to kafka.nodes pillar
2024-04-12 11:52:57 -04:00
reyesj2
af29ae1968
Merge kaffytaffy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 11:43:46 -04:00
reyesj2
fbd3cff90d
Make global.pipeline use GLOBALMERGED value
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-12 11:21:19 -04:00
m0duspwnens
0ed9894b7e
create kratos local pillar dirs during setup
2024-04-12 11:19:46 -04:00
m0duspwnens
a54a72c269
move kafka_cluster_id to kafka:cluster_id
2024-04-12 11:19:20 -04:00
Josh Brower
5b81a73e58
Merge pull request #12791 from Security-Onion-Solutions/2.4/detectiondefaults
...
Fix fingerprint paths
2024-04-12 09:01:38 -04:00
DefensiveDepth
49ccd86c39
Fix fingerprint paths
2024-04-12 08:35:44 -04:00
m0duspwnens
f514e5e9bb
add kafka to receiver
2024-04-11 16:23:05 -04:00
reyesj2
3955587372
Use global.pipeline for redis / kafka states
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 16:20:09 -04:00
reyesj2
6b28dc72e8
Update annotation for global.pipeline
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:38:33 -04:00
reyesj2
ca7253a589
Run kafka-clusterid script when pillar values are missing
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:38:03 -04:00
reyesj2
af53dcda1b
Remove references to kafkanode
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 15:32:00 -04:00
reyesj2
55cf90f477
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 14:44:59 -04:00
reyesj2
c269fb90ac
Added a Kismet Wifi devices dashboard for an overview of kismet data
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 14:41:54 -04:00
Mike Reeves
1250a728ac
Merge pull request #12769 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update analyst.json
2024-04-11 14:30:17 -04:00
reyesj2
68e016090b
Fix network.wireless.ssid not parsing
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 13:21:54 -04:00
reyesj2
fd689a4607
Fix typo in ingest pipeline
...
Test to fix duplicate events in SOC, by removing conflicting field event.created
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-11 11:18:04 -04:00
Josh Brower
ae09869417
Merge pull request #12780 from Security-Onion-Solutions/2.4/detectiondefaults
...
Enable Detections Adv by default
2024-04-11 09:32:34 -04:00
DefensiveDepth
1c5f02ade2
Update annotations
2024-04-11 09:21:08 -04:00
DefensiveDepth
ed97aa4e78
Enable Detections Adv by default
2024-04-11 08:21:20 -04:00
reyesj2
7124f04138
Update ingest pipelines to match updated mappings
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-10 16:13:06 -04:00
reyesj2
2ab9cbba61
Update wording for Kismet poll interval annotation
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-10 16:12:22 -04:00
reyesj2
4097e1d81a
Create mappings for Kismet integration
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-10 16:10:27 -04:00
m0duspwnens
d3bd56b131
disable logstash and redis if kafka enabled
2024-04-10 14:13:27 -04:00
m0duspwnens
e9e61ea2d8
Merge remote-tracking branch 'origin/2.4/dev' into kaffytaffy
2024-04-10 13:14:13 -04:00
m0duspwnens
86b984001d
annotations and enable/disable from ui
2024-04-10 10:39:06 -04:00
Mike Reeves
2206553e03
Update analyst.json
2024-04-10 09:49:21 -04:00
m0duspwnens
fa7f8104c8
Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy
2024-04-09 11:13:02 -04:00
m0duspwnens
bd5fe43285
jinja config files
2024-04-09 11:07:53 -04:00
m0duspwnens
d38051e806
fix client and server properties formatting
2024-04-09 10:36:37 -04:00
m0duspwnens
daa5342986
items not keys in for loop
2024-04-09 10:22:05 -04:00
m0duspwnens
c48436ccbf
fix dict update
2024-04-09 10:19:17 -04:00
m0duspwnens
7aa00faa6c
fix var
2024-04-09 09:31:54 -04:00
m0duspwnens
6217a7b9a9
add defaults and jijafy kafka config
2024-04-09 09:27:21 -04:00
reyesj2
d67ebabc95
Remove logstash output to kafka pipeline. Add additional topics for searchnodes to ingest and add partition/offset info to event
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-08 16:38:03 -04:00
Josh Brower
b9474b9352
Merge pull request #12766 from Security-Onion-Solutions/2.4/sigma-pipeline
...
Ship Defender logs + more
2024-04-08 16:35:24 -04:00
DefensiveDepth
376efab40c
Ship Defender logs
2024-04-08 14:01:38 -04:00
reyesj2
65274e89d7
Add client_id to logstash pipeline. To identify which searchnode is pulling messages
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-05 15:38:00 -04:00
coreyogburn
acf29a6c9c
Merge pull request #12760 from Security-Onion-Solutions/cogburn/detection-author-remap
...
Detection Author as a Keyword instead of Text
2024-04-05 11:39:53 -06:00
reyesj2
721e04f793
initial logstash input from kafka over ssl
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-05 13:37:14 -04:00
Corey Ogburn
00cea6fb80
Detection Author as a Keyword instead of Text
...
With Quick Actions added to Detections, as many fields should be usable as possible.
2024-04-05 11:22:47 -06:00
reyesj2
433309ef1a
Generate kafka cluster id if it doesn't exist
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-05 09:35:12 -04:00
Mike Reeves
cbc95d0b30
Merge pull request #12759 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update so-log-check
2024-04-05 08:17:50 -04:00
Mike Reeves
21f86be8ee
Update so-log-check
2024-04-05 08:03:42 -04:00
Josh Brower
8e38c3763e
Merge pull request #12756 from Security-Onion-Solutions/2.4/detections-defaults
...
Use list not string
2024-04-04 17:00:38 -04:00
DefensiveDepth
ca807bd6bd
Use list not string
2024-04-04 16:58:39 -04:00
reyesj2
735cfb4c29
Autogenerate kafka topics when a message it sent to non-existing topic
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-04 16:45:58 -04:00
reyesj2
6202090836
Merge remote-tracking branch 'origin/kaffytaffy' into reyesj2/kafka
2024-04-04 16:27:06 -04:00
reyesj2
436cbc1f06
Add kafka signing_policy for client/server auth. Add kafka-client cert on manager so manager can interact with kafka using its own cert
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-04 16:21:29 -04:00
reyesj2
40b08d737c
Generate kafka keystore on changes to kafka.key
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-04 16:16:53 -04:00
m0duspwnens
4c5b42b898
restart container on server config changes
2024-04-04 15:47:01 -04:00
m0duspwnens
7a6b72ebac
add so-kafka to manager for firewall
2024-04-04 15:46:11 -04:00
Josh Brower
f72cbd5f23
Merge pull request #12755 from Security-Onion-Solutions/2.4/detections-defaults
...
2.4/detections defaults
2024-04-04 11:33:59 -04:00
Josh Brower
1d7e47f589
Merge pull request #12682 from Security-Onion-Solutions/2.4/soup-playbook
...
2.4/soup playbook
2024-04-04 11:28:09 -04:00
DefensiveDepth
49d5fa95a2
Detections tweaks
2024-04-04 11:26:44 -04:00
Jason Ertel
204f44449a
Merge pull request #12754 from Security-Onion-Solutions/jertel/ana
...
skip telemetry summary in airgap mode
2024-04-04 10:39:07 -04:00
Jason Ertel
6046848ee7
skip telemetry summary in airgap mode
2024-04-04 10:25:32 -04:00
Doug Burks
b0aee238b1
Merge pull request #12753 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add dashboards specific to Elastic Agent #12746
2024-04-04 09:35:21 -04:00
Doug Burks
d8ac3f1292
FEATURE: Add dashboards specific to Elastic Agent #12746
2024-04-04 09:30:05 -04:00
Mike Reeves
8788b34c8a
Merge pull request #12752 from Security-Onion-Solutions/updates23
...
Allow 2.3 to update
2024-04-04 09:25:41 -04:00
Mike Reeves
784ec54795
2.3 updates
2024-04-04 09:24:17 -04:00
Mike Reeves
54fce4bf8f
2.3 updates
2024-04-04 09:21:16 -04:00
Mike Reeves
c4ebe25bab
Attempt to fix 2.3 when main repo changes
2024-04-04 09:18:37 -04:00
Doug Burks
7b4e207329
Merge pull request #12751 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module sigma #12743
2024-04-04 09:13:53 -04:00
Doug Burks
5ec3b834fb
FEATURE: Add Events table columns for event.module sigma #12743
2024-04-04 09:11:41 -04:00
Mike Reeves
7668fa1396
Attempt to fix 2.3 when main repo changes
2024-04-04 09:03:29 -04:00
Mike Reeves
470b0e4bf6
Attempt to fix 2.3 when main repo changes
2024-04-04 08:55:13 -04:00
Mike Reeves
d3f163bf9e
Attempt to fix 2.3 when main repo changes
2024-04-04 08:54:04 -04:00
Mike Reeves
4b31632dfc
Attempt to fix 2.3 when main repo changes
2024-04-04 08:52:37 -04:00
DefensiveDepth
c2f7f7e3a5
Remove dup line
2024-04-04 08:52:30 -04:00
DefensiveDepth
07cb0c7d46
Merge remote-tracking branch 'origin/2.4/dev' into 2.4/soup-playbook
2024-04-04 08:51:09 -04:00
Mike Reeves
14c824143b
Attempt to fix 2.3 when main repo changes
2024-04-04 08:48:44 -04:00
Jason Ertel
c75c411426
Merge pull request #12749 from Security-Onion-Solutions/jertel/ana
...
Clarify annotation description re: Airgap
2024-04-04 07:53:18 -04:00
Jason Ertel
a7fab380b4
clarify telemetry annotation
2024-04-04 07:51:23 -04:00
Jason Ertel
a9517e1291
clarify telemetry annotation
2024-04-04 07:49:30 -04:00
Josh Brower
1017838cfc
Merge pull request #12748 from Security-Onion-Solutions/2.4/exclude-elastalert
...
Exclude Elastalert EQL errors
2024-04-04 06:57:22 -04:00
DefensiveDepth
1d221a574b
Exclude Elastalert EQL errors
2024-04-04 06:48:25 -04:00
Jason Ertel
a35bfc4822
Merge pull request #12747 from Security-Onion-Solutions/jertel/ana
...
do not prompt about telemetry on airgap installs
2024-04-03 21:50:38 -04:00
Jason Ertel
7c64fc8c05
do not prompt about telemetry on airgap installs
2024-04-03 18:08:42 -04:00
DefensiveDepth
f66cca96ce
YARA casing
2024-04-03 16:17:29 -04:00
Mike Reeves
12da7db22c
Attempt to fix 2.3 when main repo changes
2024-04-03 15:38:23 -04:00
m0duspwnens
1b8584d4bb
allow manager to manager on kafka ports
2024-04-03 15:36:35 -04:00
Mike Reeves
9c59f42c16
Attempt to fix 2.3 when main repo changes
2024-04-03 15:23:09 -04:00
coreyogburn
fb5eea8284
Merge pull request #12744 from Security-Onion-Solutions/cogburn/detection-state
...
Update SOC Config with State File Paths
2024-04-03 13:19:26 -06:00
Mike Reeves
9db9af27ae
Attempt to fix 2.3 when main repo changes
2024-04-03 15:14:50 -04:00
Corey Ogburn
0f50a265cf
Update SOC Config with State File Paths
...
Each detection engine is getting a state file to help manage the timer over restarts. By default, the files will go in soc's config folder inside a fingerprints folder.
2024-04-03 13:12:18 -06:00
Jason Ertel
3e05c04aa1
Merge pull request #12731 from Security-Onion-Solutions/jertel/ana
...
SOC Telemetry
2024-04-03 14:51:41 -04:00
Jason Ertel
8f8896c505
fix link
2024-04-03 14:45:39 -04:00
Jason Ertel
941a841da0
fix link
2024-04-03 14:41:57 -04:00
reyesj2
13105c4ab3
Generate certs for use with elasticfleet kafka output policy
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-03 14:34:07 -04:00
reyesj2
dc27bbb01d
Set kafka heap size. To be later configured from SOC
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-03 14:30:52 -04:00
Jason Ertel
2b8a051525
fix link
2024-04-03 14:30:09 -04:00
Mike Reeves
1c7cc8dd3b
Merge pull request #12741 from Security-Onion-Solutions/metrics
...
Change code to allow for non root
2024-04-03 12:56:17 -04:00
Doug Burks
58d081eed1
Merge pull request #12742 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module kratos #12740
2024-04-03 12:48:24 -04:00
Doug Burks
9078b2bad2
FEATURE: Add Events table columns for event.module kratos #12740
2024-04-03 12:46:29 -04:00
Mike Reeves
8889c974b8
Change code to allow for non root
2024-04-03 12:38:59 -04:00
Doug Burks
f615a73120
Merge pull request #12739 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add dashboard for SOC Login Failures #12738
2024-04-03 12:01:08 -04:00
Doug Burks
66844af1c2
FEATURE: Add dashboard for SOC Login Failures #12738
2024-04-03 11:54:53 -04:00
Mike Reeves
a0b7d89eb6
Merge pull request #12734 from Security-Onion-Solutions/metrics
...
Add Elastic Agent Status Metrics
2024-04-03 11:12:53 -04:00
Mike Reeves
c31e459c2b
Change metrics reporting order
2024-04-03 11:06:00 -04:00
m0duspwnens
b863060df1
kafka broker and listener on 0.0.0.0
2024-04-03 11:05:24 -04:00
weslambert
d96d696c35
Merge pull request #12735 from Security-Onion-Solutions/feature/cef
...
Add cef
2024-04-03 10:49:44 -04:00
Wes
105eadf111
Add cef
2024-04-03 14:40:41 +00:00
Jason Ertel
ca57c20691
suppress soup update output for cleaner console
2024-04-03 10:31:24 -04:00
Jason Ertel
c4767bfdc8
suppress soup update output for cleaner console
2024-04-03 10:28:43 -04:00
Mike Reeves
0de1f76139
add agent count to reposync
2024-04-03 10:26:59 -04:00
Jason Ertel
5f4a0fdfad
suppress soup update output for cleaner console
2024-04-03 10:26:48 -04:00
m0duspwnens
18f95e867f
port 9093 for kafka docker
2024-04-03 10:24:53 -04:00
m0duspwnens
ed6137a76a
allow sensor and searchnode to connect to manager kafka ports
2024-04-03 10:24:10 -04:00
m0duspwnens
c3f02a698e
add kafka nodes as extra hosts for the container
2024-04-03 10:23:36 -04:00
m0duspwnens
db106f8ca1
listen on 0.0.0.0 for CONTROLLER
2024-04-03 10:22:47 -04:00
Jason Ertel
c712529cf6
suppress soup update output for cleaner console
2024-04-03 10:21:35 -04:00
Mike Reeves
976ddd3982
add agentstatus to telegraf
2024-04-03 10:06:08 -04:00
Mike Reeves
64748b98ad
add agentstatus to telegraf
2024-04-03 09:56:12 -04:00
Mike Reeves
3335612365
add agentstatus to telegraf
2024-04-03 09:54:16 -04:00
Mike Reeves
513273c8c3
add agentstatus to telegraf
2024-04-03 09:43:55 -04:00
Mike Reeves
0dfde3c9f2
add agentstatus to telegraf
2024-04-03 09:40:14 -04:00
Mike Reeves
0efdcfcb52
add agentstatus to telegraf
2024-04-03 09:36:02 -04:00
Josh Brower
fbdcc53fe0
Merge pull request #12732 from Security-Onion-Solutions/2.4/detections-defaults
...
Feature - auto-enabled Sigma rules
2024-04-03 09:01:09 -04:00
m0duspwnens
8e47cc73a5
kafka.nodes pillar to lf
2024-04-03 08:54:17 -04:00
m0duspwnens
639bf05081
add so-manager to kafka.nodes pillar
2024-04-03 08:52:26 -04:00
Jason Ertel
c1b5ef0891
ensure so-yaml.py is updated during soup
2024-04-03 08:44:40 -04:00
DefensiveDepth
a8f25150f6
Feature - auto-enabled Sigma rules
2024-04-03 08:21:50 -04:00
Jason Ertel
1ee2a6d37b
Improve wording for Airgap annotation
2024-04-03 08:21:30 -04:00
Mike Reeves
f64d9224fb
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into metrics
2024-04-02 17:22:20 -04:00
m0duspwnens
4e142e0212
put alphabetical
2024-04-02 16:47:35 -04:00
m0duspwnens
c9bf1c86c6
Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy
2024-04-02 16:40:47 -04:00
reyesj2
82830c8173
Fix typos and fix error related to elasticsearch saltstate being called from logstash state. Logstash will be removed from kafkanodes in future
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:37:39 -04:00
reyesj2
7f5741c43b
Fix kafka storage setup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:36:22 -04:00
reyesj2
643d4831c1
CRLF -> LF
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:35:14 -04:00
reyesj2
b032eed22a
Update kafka to use manager docker registry
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:34:06 -04:00
reyesj2
1b49c8540e
Fix kafka keystore script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 16:32:15 -04:00
m0duspwnens
f7534a0ae3
make manager download so-kafka container
2024-04-02 16:01:12 -04:00
Jason Ertel
b6187ab769
Improve wording for Airgap annotation
2024-04-02 15:54:39 -04:00
m0duspwnens
780ad9eb10
add kafka to manager nodes
2024-04-02 15:50:25 -04:00
Mike Reeves
283939b18a
Gather metrics from elastic agent to influx
2024-04-02 15:36:01 -04:00
m0duspwnens
e25bc8efe4
Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy
2024-04-02 13:36:47 -04:00
Jason Ertel
3b112e20e3
fix syntax error
2024-04-02 12:32:33 -04:00
reyesj2
26abe90671
Removed duplicate kafka setup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-04-02 12:19:46 -04:00
Doug Burks
23a6c4adb6
Merge pull request #12725 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:54:15 -04:00
Doug Burks
2f03cbf115
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:42:20 -04:00
Doug Burks
a678a5a416
Merge pull request #12724 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:15:20 -04:00
Doug Burks
b2b54ccf60
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 10:11:16 -04:00
Doug Burks
55e71c867c
Merge pull request #12723 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module playbook #12703
2024-04-02 10:04:21 -04:00
Doug Burks
6c2437f8ef
FEATURE: Add Events table columns for event.module playbook #12703
2024-04-02 09:55:56 -04:00
Doug Burks
261f2cbaf7
Merge pull request #12722 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module strelka #12716
2024-04-02 09:43:15 -04:00
Jason Ertel
f083558666
break out into sep func
2024-04-02 09:42:43 -04:00
Doug Burks
505eeea66a
Update defaults.yaml
2024-04-02 09:39:54 -04:00
Josh Brower
1001aa665d
Merge pull request #12720 from Security-Onion-Solutions/2.4/detections-defaults
...
Add default columns
2024-04-02 09:21:06 -04:00
DefensiveDepth
7f488422b0
Add default columns
2024-04-02 09:13:27 -04:00
Mike Reeves
21f78a039a
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main
2024-04-02 08:47:08 -04:00
Jason Ertel
f17d8d3369
analytics
2024-04-01 10:59:44 -04:00
Jason Ertel
ff777560ac
limit col size
2024-04-01 10:35:15 -04:00
Jason Ertel
2c68fd6311
limit col size
2024-04-01 10:32:54 -04:00
Jason Ertel
c1bf710e46
limit col size
2024-04-01 10:32:25 -04:00
Jason Ertel
9d2b40f366
Merge branch '2.4/dev' into jertel/ana
2024-04-01 09:50:38 -04:00
Jason Ertel
3aea2dec85
analytics
2024-04-01 09:50:18 -04:00
coreyogburn
65f6b7022c
Merge pull request #12702 from Security-Onion-Solutions/cogburn/yaml-fix
...
Correct YAML
2024-03-29 15:59:34 -06:00
Corey Ogburn
e5a3a54aea
Proper YAML
2024-03-29 14:31:43 -06:00
Doug Burks
be88dbe181
Merge pull request #12700 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add individual dashboards for Zeek SSL and Suricata SSL logs…
2024-03-29 15:41:14 -04:00
Doug Burks
b64ed5535e
FEATURE: Add individual dashboards for Zeek SSL and Suricata SSL logs #12699
2024-03-29 15:29:38 -04:00
Doug Burks
5be56703e9
Merge pull request #12698 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for zeek ssl and suricata ssl #12697
2024-03-29 14:46:39 -04:00
Doug Burks
0c7ba62867
FEATURE: Add Events table columns for zeek ssl and suricata ssl #12697
2024-03-29 14:44:29 -04:00
coreyogburn
d9d851040c
Merge pull request #12696 from Security-Onion-Solutions/cogburn/manual-sync
...
New Settings for Manual Sync in Detections
2024-03-29 12:43:08 -06:00
Corey Ogburn
e747a4e3fe
New Settings for Manual Sync in Detections
2024-03-29 12:25:03 -06:00
reyesj2
000d15a53c
Kismet integration: TODO Elasticsearch mappings
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-03-29 13:56:01 -04:00
Doug Burks
cc2164221c
Merge pull request #12695 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add process.command_line to Process Info and Process Ancestry dashboards #12694
2024-03-29 13:04:09 -04:00
Doug Burks
102c3271d1
FEATURE: Add process.command_line to Process Info and Process Ancestry dashboards #12694
2024-03-29 12:04:47 -04:00
DefensiveDepth
32b8649c77
Add more error checking
2024-03-28 14:31:02 -04:00
DefensiveDepth
9c5ba92589
Check if container is running first
2024-03-28 13:23:40 -04:00
DefensiveDepth
d2c9e0ea4a
Cleanup
2024-03-28 13:04:48 -04:00
Jason Ertel
2928b71616
Merge pull request #12683 from Security-Onion-Solutions/jertel/lc
...
disregard errors in removed applications that occurred before th…
2024-03-28 09:48:26 -04:00
Jason Ertel
216b8c01bf
disregard errors that in removed applications that occurred before the upgrade
2024-03-28 09:31:39 -04:00
DefensiveDepth
ce0c9f846d
Remove containers from so-status
2024-03-27 16:13:52 -04:00
DefensiveDepth
ba262ee01a
Check to see if Playbook is enabled
2024-03-27 15:43:25 -04:00
DefensiveDepth
b571eeb8e6
Initial cut of .70 soup changes
2024-03-27 14:58:16 -04:00
Mike Reeves
7fe377f899
Merge pull request #12674 from Security-Onion-Solutions/ipv6fix
...
Fix Input Validation to allow for IPv6
2024-03-27 09:48:01 -04:00
Mike Reeves
d57f773072
Fix regex to allow ipv6 in bpfs
2024-03-27 09:36:42 -04:00
Doug Burks
389357ad2b
Merge pull request #12667 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events table columns for event.module elastic_agent #12666
2024-03-26 16:11:46 -04:00
Doug Burks
e2caf4668e
FEATURE: Add Events table columns for event.module elastic_agent #12666
2024-03-26 16:08:41 -04:00
Josh Brower
63a58efba4
Merge pull request #12656 from Security-Onion-Solutions/2.4/detections-fixes
...
Add bindings for sigma repos
2024-03-26 09:33:38 -04:00
DefensiveDepth
bbcd3116f7
Fixes
2024-03-26 09:31:46 -04:00
Josh Brower
9c12aa261e
Merge pull request #12660 from Security-Onion-Solutions/kilo
...
Initial cut to remove Playbook and deps
2024-03-26 08:31:11 -04:00
DefensiveDepth
cc0f4847ba
Casing and validation
2024-03-26 08:10:57 -04:00
Doug Burks
923b80ba60
Merge pull request #12663 from Security-Onion-Solutions/feature/improve-soc-dashboards
...
FEATURE: Include additional groupby fields in Dashboards relating to sankey diagrams #12657
2024-03-26 07:52:54 -04:00
DefensiveDepth
7c4ea8a58e
Add Detections SOC Config
2024-03-26 07:39:39 -04:00
Doug Burks
20bd9a9701
FEATURE: Include additional groupby fields in Dashboards relating to sankey diagrams #12657
2024-03-26 07:39:24 -04:00
Josh Brower
f0cb30a649
Merge pull request #12659 from Security-Onion-Solutions/2.4/remove-playbook
...
Remove Playbook ref
2024-03-25 21:12:22 -04:00
DefensiveDepth
94ee761207
Remove Playbook ref
2024-03-25 21:11:47 -04:00
Josh Brower
0a5dc411d0
Merge pull request #12658 from Security-Onion-Solutions/2.4/remove-playbook
...
Initial cut to remove Playbook and deps
2024-03-25 19:45:51 -04:00
DefensiveDepth
d7ecad4333
Initial cut to remove Playbook and deps
2024-03-25 19:42:31 -04:00
DefensiveDepth
49fa800b2b
Add bindings for sigma repos
2024-03-25 14:45:50 -04:00
reyesj2
446f1ffdf5
merge 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-03-25 13:55:48 -04:00
weslambert
57553bc1e5
Merge pull request #12652 from Security-Onion-Solutions/feature/pfsense_suricata
...
FEATURE: pfSense Suricata logs
2024-03-25 10:10:13 -04:00
weslambert
df058b3f4a
Merge branch '2.4/dev' into feature/pfsense_suricata
2024-03-25 10:08:03 -04:00
Wes
5e21da443f
Minor verbiage updates
2024-03-25 13:58:32 +00:00
Josh Patterson
7898277a9b
Merge pull request #12651 from Security-Onion-Solutions/issue/12637
...
Allow for additional af-packet tuning options for Suricata
2024-03-25 09:37:52 -04:00
m0duspwnens
029d8a0e8f
handle yes/no on checksum-checks
2024-03-25 09:30:41 -04:00
Josh Brower
b8d33ab983
Merge pull request #12639 from Security-Onion-Solutions/2.4/enable-detections
...
Enable Detections
2024-03-25 09:30:01 -04:00
weslambert
e124791d5d
Merge pull request #12650 from Security-Onion-Solutions/fix/soc_template
...
FIX: http.response.status_code
2024-03-25 09:29:19 -04:00
coreyogburn
8ae30d0a77
Merge pull request #12640 from Security-Onion-Solutions/cogburn/sigma-repo-support
...
Update ElastAlert Config with Default Repos
2024-03-22 14:24:18 -06:00
m0duspwnens
81f3d69eb9
remove mmap-locked.
2024-03-22 15:55:59 -04:00
Corey Ogburn
237946e916
Specify Folder in Rule Repo
2024-03-22 13:52:20 -06:00
Corey Ogburn
3d04d37030
Update ElastAlert Config with Default Repos
2024-03-22 13:52:20 -06:00
m0duspwnens
bb0da2a5c5
add additional suricata af-packet config items
2024-03-22 14:34:14 -04:00
Doug Burks
d6ce3851ec
Merge pull request #12644 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Specify that static IP address is recommended #12643
2024-03-22 13:47:33 -04:00
Doug Burks
9c6f3f4808
FIX: Specify that static IP address is recommended #12643
2024-03-22 13:41:44 -04:00
Doug Burks
1ab56033a2
Merge pull request #12642 from Security-Onion-Solutions/fix/add-event.dataset
...
FEATURE: Add event.dataset to all Events column layouts #12641
2024-03-22 13:22:57 -04:00
Doug Burks
a78a304d4f
FEATURE: Add event.dataset to all Events column layouts #12641
2024-03-22 13:19:31 -04:00
DefensiveDepth
5ca9ec4b17
Enable Detections
2024-03-22 10:12:26 -04:00
weslambert
4e1543b6a8
Get only code
2024-03-22 09:56:21 -04:00
Jason Ertel
0e7d08b957
Merge pull request #12638 from Security-Onion-Solutions/jertel/logs
...
disregard benign telegraf error
2024-03-22 09:53:52 -04:00
Jason Ertel
f889a089bf
disregard benign telegraf error
2024-03-22 09:48:27 -04:00
Doug Burks
2b019ec8fe
Merge pull request #12634 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add Events column layout for event.module system #12628
2024-03-22 05:52:23 -04:00
Wes
5934829e0d
Include pfsense config
2024-03-21 20:08:33 +00:00
Wes
486a633dfe
Add pfsense Suricata config
2024-03-21 20:07:59 +00:00
weslambert
77ac342786
Merge pull request #12632 from Security-Onion-Solutions/fix/remove_temp_yara
...
Remove temp YARA
2024-03-21 10:11:32 -04:00
weslambert
8429a364dc
Remove Strelka rules watch
2024-03-21 10:09:36 -04:00
weslambert
1568f57096
Remove Strelka config
2024-03-21 10:07:27 -04:00
weslambert
f431e9ae08
Remove Strelka config
2024-03-21 10:06:25 -04:00
Josh Brower
4b03d088c3
Merge pull request #12611 from Security-Onion-Solutions/2.4/enable-detections
...
Change Detections defaults
2024-03-21 08:04:03 -04:00
DefensiveDepth
4a33234c34
Default update to 24 hours
2024-03-21 07:26:19 -04:00
Doug Burks
778997bed4
FEATURE: Add Events column layout for event.module system #12628
2024-03-20 17:07:37 -04:00
Doug Burks
655d3e349c
Merge pull request #12627 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 16:11:33 -04:00
Doug Burks
f3b921342e
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 16:06:25 -04:00
Doug Burks
fff4d20e39
Update soc_suricata.yaml
2024-03-20 16:03:45 -04:00
Doug Burks
d2fb067110
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 15:57:32 -04:00
Doug Burks
876690a9f6
FIX: Annotations for BPF and Suricata PCAP #12626
2024-03-20 15:49:46 -04:00
Jason Ertel
4c2f2759d4
Merge pull request #12601 from Security-Onion-Solutions/jertel/suripcap
...
reschedule close/lock jobs
2024-03-20 12:11:15 -04:00
Mike Reeves
dd603934bc
Merge pull request #12619 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2024-03-20 11:06:05 -04:00
Mike Reeves
d4d17e1835
Update VERSION
2024-03-20 11:04:40 -04:00
DefensiveDepth
d84af803a6
Enable Autoupdates
2024-03-20 08:48:31 -04:00
DefensiveDepth
020eb47026
Change Detections defaults
2024-03-19 13:53:37 -04:00
Wes
c6df805556
Add SOC template
2024-03-18 14:53:36 +00:00
Jason Ertel
47d447eadd
Merge branch '2.4/dev' into jertel/suripcap
2024-03-18 07:34:43 -04:00
Jason Ertel
af5b3feb96
re-schedule lock jobs
2024-03-18 07:34:18 -04:00
Mike Reeves
6069c586d3
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main
2024-01-24 16:07:31 -05:00
weslambert
2168698595
Update VERSION
2024-01-22 20:27:19 -05:00
Mike Reeves
3bdc0340b8
Merge branch 'hotfix/2.4.30' into 2.4/main
2023-12-19 13:21:33 -05:00
reyesj2
8cf29682bb
Update to merge in 2.4/dev
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-11-29 13:41:23 -05:00
reyesj2
86dc7cc804
Kafka init
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-11-29 13:34:25 -05:00