mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 07:15:27 +02:00
Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
99322cf26a | ||
|
|
2a4611df45 | ||
|
|
0f53a7e0bc | ||
|
|
d122ee7fea |
No files matched your search
@@ -30,17 +30,14 @@
|
|||||||
'azure_metrics.monitor': 'azure.monitor',
|
'azure_metrics.monitor': 'azure.monitor',
|
||||||
'azure_metrics.storage_account': 'azure.storage_account',
|
'azure_metrics.storage_account': 'azure.storage_account',
|
||||||
'azure_openai.metrics': 'azure.open_ai',
|
'azure_openai.metrics': 'azure.open_ai',
|
||||||
'beat.state': 'beats.stack_monitoring.state',
|
|
||||||
'beat.stats': 'beats.stack_monitoring.stats',
|
|
||||||
'enterprisesearch.health': 'enterprisesearch.stack_monitoring.health',
|
|
||||||
'enterprisesearch.stats': 'enterprisesearch.stack_monitoring.stats',
|
|
||||||
'kibana.cluster_actions': 'kibana.stack_monitoring.cluster_actions',
|
'kibana.cluster_actions': 'kibana.stack_monitoring.cluster_actions',
|
||||||
'kibana.cluster_rules': 'kibana.stack_monitoring.cluster_rules',
|
'kibana.cluster_rules': 'kibana.stack_monitoring.cluster_rules',
|
||||||
'kibana.node_actions': 'kibana.stack_monitoring.node_actions',
|
'kibana.node_actions': 'kibana.stack_monitoring.node_actions',
|
||||||
'kibana.node_rules': 'kibana.stack_monitoring.node_rules',
|
'kibana.node_rules': 'kibana.stack_monitoring.node_rules',
|
||||||
'kibana.stats': 'kibana.stack_monitoring.stats',
|
'kibana.stats': 'kibana.stack_monitoring.stats',
|
||||||
'kibana.status': 'kibana.stack_monitoring.status',
|
'kibana.status': 'kibana.stack_monitoring.status',
|
||||||
'logstash.node_cel': 'logstash.stack_monitoring.node',
|
'logstash.node': 'logstash.stack_monitoring.node',
|
||||||
|
'logstash.node_cel': 'logstash.node',
|
||||||
'logstash.node_stats': 'logstash.stack_monitoring.node_stats',
|
'logstash.node_stats': 'logstash.stack_monitoring.node_stats',
|
||||||
'synthetics.browser': 'synthetics-browser',
|
'synthetics.browser': 'synthetics-browser',
|
||||||
'synthetics.browser_network': 'synthetics-browser.network',
|
'synthetics.browser_network': 'synthetics-browser.network',
|
||||||
|
|||||||
@@ -3309,6 +3309,7 @@ elasticsearch:
|
|||||||
composed_of:
|
composed_of:
|
||||||
- event-mappings
|
- event-mappings
|
||||||
- logs-system.security@package
|
- logs-system.security@package
|
||||||
|
- so-fleet_system.security_caseless-1
|
||||||
- logs-system.security@custom
|
- logs-system.security@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4175,6 +4176,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.forwarded@package
|
- logs-windows.forwarded@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.forwarded@custom
|
- logs-windows.forwarded@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4224,6 +4226,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.powershell@package
|
- logs-windows.powershell@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.powershell@custom
|
- logs-windows.powershell@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4273,6 +4276,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.powershell_operational@package
|
- logs-windows.powershell_operational@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.powershell_operational@custom
|
- logs-windows.powershell_operational@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4322,6 +4326,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.sysmon_operational@package
|
- logs-windows.sysmon_operational@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.sysmon_operational@custom
|
- logs-windows.sysmon_operational@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
|
|||||||
+123
@@ -0,0 +1,123 @@
|
|||||||
|
{
|
||||||
|
"_meta": {
|
||||||
|
"managed_by": "security_onion",
|
||||||
|
"managed": true,
|
||||||
|
"description": "Adds .caseless for Lucene queries. Restates each field's package type and .text."
|
||||||
|
},
|
||||||
|
"template": {
|
||||||
|
"mappings": {
|
||||||
|
"properties": {
|
||||||
|
"process": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "wildcard",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"parent": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "wildcard",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"file": {
|
||||||
|
"properties": {
|
||||||
|
"path": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
+80
@@ -0,0 +1,80 @@
|
|||||||
|
{
|
||||||
|
"_meta": {
|
||||||
|
"managed_by": "security_onion",
|
||||||
|
"managed": true,
|
||||||
|
"description": "Adds .caseless for Lucene queries. Keeps each field's existing keyword type."
|
||||||
|
},
|
||||||
|
"template": {
|
||||||
|
"mappings": {
|
||||||
|
"properties": {
|
||||||
|
"process": {
|
||||||
|
"properties": {
|
||||||
|
"command_line": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"parent": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"file": {
|
||||||
|
"properties": {
|
||||||
|
"path": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1183,6 +1183,13 @@ up_to_3.4.0() {
|
|||||||
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
||||||
docker rm -f so-kratos so-hydra so-soc >> $SOUP_LOG 2>&1
|
docker rm -f so-kratos so-hydra so-soc >> $SOUP_LOG 2>&1
|
||||||
|
|
||||||
|
for template in so-metrics-logstash.node so-metrics-logstash.stack_monitoring.node; do
|
||||||
|
if ! remove_elasticsearch_index_template "$template" "logstash node and node_cel index patterns reversed"; then
|
||||||
|
FINAL_MESSAGE_QUEUE+=("WARNING: Unable to automatically remove the $template index template. Addon integration templates may fail to load until it is removed:")
|
||||||
|
FINAL_MESSAGE_QUEUE+=(" - sudo so-elasticsearch-query _index_template/$template -XDELETE && so-checkin")
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
INSTALLEDVERSION=3.4.0
|
INSTALLEDVERSION=3.4.0
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1248,6 +1255,10 @@ valid_soauth_range() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
post_to_3.4.0() {
|
post_to_3.4.0() {
|
||||||
|
for idx in "metrics-logstash.node-default" "metrics-logstash.stack_monitoring.node-default"; do
|
||||||
|
rollover_index "$idx"
|
||||||
|
done
|
||||||
|
|
||||||
set_postversion 3.4.0
|
set_postversion 3.4.0
|
||||||
}
|
}
|
||||||
### 3.4.0 End ###
|
### 3.4.0 End ###
|
||||||
|
|||||||
@@ -2,13 +2,13 @@ name: Security Onion - Playbook Pipeline
|
|||||||
priority: 97
|
priority: 97
|
||||||
transformations:
|
transformations:
|
||||||
# Route to lowercase-normalized .caseless subfields for case-insensitive matching.
|
# Route to lowercase-normalized .caseless subfields for case-insensitive matching.
|
||||||
# file.path.caseless exists on Defend only (Sysmon file events lack it);
|
|
||||||
# registry.path / dll.path / file.name have no .caseless on any source.
|
# registry.path / dll.path / file.name have no .caseless on any source.
|
||||||
- id: case_insensitive_string_fields
|
- id: case_insensitive_string_fields
|
||||||
type: field_name_mapping
|
type: field_name_mapping
|
||||||
mapping:
|
mapping:
|
||||||
process.executable: process.executable.caseless
|
process.executable: process.executable.caseless
|
||||||
process.parent.executable: process.parent.executable.caseless
|
process.parent.executable: process.parent.executable.caseless
|
||||||
|
process.parent.name: process.parent.name.caseless
|
||||||
process.command_line: process.command_line.caseless
|
process.command_line: process.command_line.caseless
|
||||||
process.parent.command_line: process.parent.command_line.caseless
|
process.parent.command_line: process.parent.command_line.caseless
|
||||||
file.path: file.path.caseless
|
file.path: file.path.caseless
|
||||||
|
|||||||
@@ -26,6 +26,16 @@ transformations:
|
|||||||
type: set_state
|
type: set_state
|
||||||
key: keep
|
key: keep
|
||||||
val: "_id, _index, _source"
|
val: "_id, _index, _source"
|
||||||
|
# Not every source maps .caseless; EQL/ES|QL already match case-insensitively.
|
||||||
|
- id: caseless_to_parent_fields
|
||||||
|
type: field_name_mapping
|
||||||
|
mapping:
|
||||||
|
process.executable.caseless: process.executable
|
||||||
|
process.name.caseless: process.name
|
||||||
|
process.parent.executable.caseless: process.parent.executable
|
||||||
|
process.parent.name.caseless: process.parent.name
|
||||||
|
target.process.executable.caseless: target.process.executable
|
||||||
|
target.process.name.caseless: target.process.name
|
||||||
- id: baseline_field_name_mapping
|
- id: baseline_field_name_mapping
|
||||||
type: field_name_mapping
|
type: field_name_mapping
|
||||||
mapping:
|
mapping:
|
||||||
|
|||||||
Reference in new issue
Block a user