mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 07:15:27 +02:00
Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3e5a934ff8 |
No files matched your search
@@ -13,7 +13,6 @@ body:
|
|||||||
- 3.1.0
|
- 3.1.0
|
||||||
- 3.2.0
|
- 3.2.0
|
||||||
- 3.3.0
|
- 3.3.0
|
||||||
- 3.4.0
|
|
||||||
- Other (please provide detail below)
|
- Other (please provide detail below)
|
||||||
validations:
|
validations:
|
||||||
required: true
|
required: true
|
||||||
|
|||||||
@@ -183,7 +183,7 @@ http {
|
|||||||
ssl_prefer_server_ciphers on;
|
ssl_prefer_server_ciphers on;
|
||||||
ssl_protocols TLSv1.2 TLSv1.3;
|
ssl_protocols TLSv1.2 TLSv1.3;
|
||||||
|
|
||||||
location ~* (^/login|^/login/.*|^/js/.*|^/css/.*|^/images/.*|^/pages/.*|^/docs/.*) {
|
location ~* (^/login/.*|^/js/.*|^/css/.*|^/images/.*|^/pages/.*|^/docs/.*) {
|
||||||
proxy_pass http://{{ GLOBALS.manager }}:9822;
|
proxy_pass http://{{ GLOBALS.manager }}:9822;
|
||||||
proxy_read_timeout 90;
|
proxy_read_timeout 90;
|
||||||
proxy_connect_timeout 90;
|
proxy_connect_timeout 90;
|
||||||
|
|||||||
@@ -1556,69 +1556,6 @@ soc:
|
|||||||
reconcilePersona: ""
|
reconcilePersona: ""
|
||||||
toolUseTurnAttempts: 12
|
toolUseTurnAttempts: 12
|
||||||
toolUseTurnDelayMs: 175
|
toolUseTurnDelayMs: 175
|
||||||
tools:
|
|
||||||
filterEventFields:
|
|
||||||
- "@timestamp"
|
|
||||||
- "client.name"
|
|
||||||
- "destination.ip"
|
|
||||||
- "destination.port"
|
|
||||||
- "destination.geo.country_name"
|
|
||||||
- "dns.query.name"
|
|
||||||
- "dns.query_name"
|
|
||||||
- "event.action"
|
|
||||||
- "event.category"
|
|
||||||
- "event.module"
|
|
||||||
- "event.dataset"
|
|
||||||
- "event.outcome"
|
|
||||||
- "event.severity"
|
|
||||||
- "event.severity_label"
|
|
||||||
- "event.type"
|
|
||||||
- "event_data.agent.name"
|
|
||||||
- "event_data.host.os.name"
|
|
||||||
- "file.mime_type"
|
|
||||||
- "file.name"
|
|
||||||
- "hash.md5"
|
|
||||||
- "hash.sha1"
|
|
||||||
- "host.mac"
|
|
||||||
- "host.name"
|
|
||||||
- "host.os.name"
|
|
||||||
- "http.method"
|
|
||||||
- "http.useragent"
|
|
||||||
- "http.virtual_host"
|
|
||||||
- "log.id.uid"
|
|
||||||
- "network.community_id"
|
|
||||||
- "network.protocol"
|
|
||||||
- "network.transport"
|
|
||||||
- "notice.message"
|
|
||||||
- "observer.name"
|
|
||||||
- "process.name"
|
|
||||||
- "process.executable"
|
|
||||||
- "process.entity_id"
|
|
||||||
- "process.command_line"
|
|
||||||
- "process.Ext.ancestry"
|
|
||||||
- "process.parent.entity_id"
|
|
||||||
- "process.parent.command_line"
|
|
||||||
- "rule.category"
|
|
||||||
- "rule.name"
|
|
||||||
- "rule.uuid"
|
|
||||||
- "software.name"
|
|
||||||
- "software.type"
|
|
||||||
- "software.version.unparsed"
|
|
||||||
- "source.ip"
|
|
||||||
- "source.port"
|
|
||||||
- "source.geo.country_name"
|
|
||||||
- "ssh.cypher_algorithm"
|
|
||||||
- "ssh.client"
|
|
||||||
- "ssh.server"
|
|
||||||
- "ssl.cipher"
|
|
||||||
- "ssl.server_name"
|
|
||||||
- "ssl.version"
|
|
||||||
- "system.auth.sudo.command"
|
|
||||||
- "user.name"
|
|
||||||
- "user.domain"
|
|
||||||
- "user.effective.name"
|
|
||||||
- "weird.name"
|
|
||||||
- "tags"
|
|
||||||
onionconfig:
|
onionconfig:
|
||||||
saltstackDir: /opt/so/saltstack
|
saltstackDir: /opt/so/saltstack
|
||||||
bypassEnabled: false
|
bypassEnabled: false
|
||||||
|
|||||||
@@ -916,11 +916,6 @@ soc:
|
|||||||
description: The number of times to retry extracting memories from a session if errors occur.
|
description: The number of times to retry extracting memories from a session if errors occur.
|
||||||
global: True
|
global: True
|
||||||
advanced: True
|
advanced: True
|
||||||
tools:
|
|
||||||
filterEventFields:
|
|
||||||
description: A whitelist of fields to return when OnionAI uses the query_events tool. All other fields are removed. One field per line.
|
|
||||||
global: True
|
|
||||||
multiline: True
|
|
||||||
client:
|
client:
|
||||||
assistant:
|
assistant:
|
||||||
enabled:
|
enabled:
|
||||||
|
|||||||
Reference in new issue
Block a user