mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 07:15:27 +02:00
Compare commits
26
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5a4599a57d | ||
|
|
f7dbfba178 | ||
|
|
0a628bb7e7 | ||
|
|
bd6647e775 | ||
|
|
da2c19188a | ||
|
|
90b3d37be6 | ||
|
|
fcd2f67076 | ||
|
|
a9cdd17694 | ||
|
|
b32aaac290 | ||
|
|
1aee3f28dc | ||
|
|
678cb0d5b2 | ||
|
|
31c5190a1f | ||
|
|
4ce7a06abe | ||
|
|
ba95b9bbc2 | ||
|
|
99322cf26a | ||
|
|
117548757f | ||
|
|
22bda63847 | ||
|
|
2a4611df45 | ||
|
|
563269cbac | ||
|
|
523c39d4f2 | ||
|
|
b4557e973c | ||
|
|
0f53a7e0bc | ||
|
|
8de8ba811a | ||
|
|
d122ee7fea | ||
|
|
9732e1c639 | ||
|
|
53f9ebcd46 |
No files matched your search
@@ -241,7 +241,7 @@ if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
|
|||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # appears in so-dockerregistry log for so-tcpreplay following docker upgrade to 29.2.1-1
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # so-dockerregistry logs a tag lookup miss during image copy; not tied to one docker version
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Could not index event to Elasticsearch.*\"version\" => \"9.0.8\"" # Expected during Elastic upgrade temporarily, as policies referencing older pipelines are updated
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Could not index event to Elasticsearch.*\"version\" => \"9.0.8\"" # Expected during Elastic upgrade temporarily, as policies referencing older pipelines are updated
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -18,10 +18,10 @@ dockergroup:
|
|||||||
dockerheldpackages:
|
dockerheldpackages:
|
||||||
pkg.installed:
|
pkg.installed:
|
||||||
- pkgs:
|
- pkgs:
|
||||||
- containerd.io: 2.2.1-1.el9
|
- containerd.io: 2.3.6-1.el9
|
||||||
- docker-ce: 3:29.2.1-1.el9
|
- docker-ce: 3:29.8.1-1.el9
|
||||||
- docker-ce-cli: 1:29.2.1-1.el9
|
- docker-ce-cli: 1:29.8.1-1.el9
|
||||||
- docker-ce-rootless-extras: 29.2.1-1.el9
|
- docker-ce-rootless-extras: 29.8.1-1.el9
|
||||||
- hold: True
|
- hold: True
|
||||||
- update_holds: True
|
- update_holds: True
|
||||||
|
|
||||||
|
|||||||
@@ -30,17 +30,14 @@
|
|||||||
'azure_metrics.monitor': 'azure.monitor',
|
'azure_metrics.monitor': 'azure.monitor',
|
||||||
'azure_metrics.storage_account': 'azure.storage_account',
|
'azure_metrics.storage_account': 'azure.storage_account',
|
||||||
'azure_openai.metrics': 'azure.open_ai',
|
'azure_openai.metrics': 'azure.open_ai',
|
||||||
'beat.state': 'beats.stack_monitoring.state',
|
|
||||||
'beat.stats': 'beats.stack_monitoring.stats',
|
|
||||||
'enterprisesearch.health': 'enterprisesearch.stack_monitoring.health',
|
|
||||||
'enterprisesearch.stats': 'enterprisesearch.stack_monitoring.stats',
|
|
||||||
'kibana.cluster_actions': 'kibana.stack_monitoring.cluster_actions',
|
'kibana.cluster_actions': 'kibana.stack_monitoring.cluster_actions',
|
||||||
'kibana.cluster_rules': 'kibana.stack_monitoring.cluster_rules',
|
'kibana.cluster_rules': 'kibana.stack_monitoring.cluster_rules',
|
||||||
'kibana.node_actions': 'kibana.stack_monitoring.node_actions',
|
'kibana.node_actions': 'kibana.stack_monitoring.node_actions',
|
||||||
'kibana.node_rules': 'kibana.stack_monitoring.node_rules',
|
'kibana.node_rules': 'kibana.stack_monitoring.node_rules',
|
||||||
'kibana.stats': 'kibana.stack_monitoring.stats',
|
'kibana.stats': 'kibana.stack_monitoring.stats',
|
||||||
'kibana.status': 'kibana.stack_monitoring.status',
|
'kibana.status': 'kibana.stack_monitoring.status',
|
||||||
'logstash.node_cel': 'logstash.stack_monitoring.node',
|
'logstash.node': 'logstash.stack_monitoring.node',
|
||||||
|
'logstash.node_cel': 'logstash.node',
|
||||||
'logstash.node_stats': 'logstash.stack_monitoring.node_stats',
|
'logstash.node_stats': 'logstash.stack_monitoring.node_stats',
|
||||||
'synthetics.browser': 'synthetics-browser',
|
'synthetics.browser': 'synthetics-browser',
|
||||||
'synthetics.browser_network': 'synthetics-browser.network',
|
'synthetics.browser_network': 'synthetics-browser.network',
|
||||||
|
|||||||
@@ -3309,6 +3309,7 @@ elasticsearch:
|
|||||||
composed_of:
|
composed_of:
|
||||||
- event-mappings
|
- event-mappings
|
||||||
- logs-system.security@package
|
- logs-system.security@package
|
||||||
|
- so-fleet_system.security_caseless-1
|
||||||
- logs-system.security@custom
|
- logs-system.security@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4175,6 +4176,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.forwarded@package
|
- logs-windows.forwarded@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.forwarded@custom
|
- logs-windows.forwarded@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4224,6 +4226,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.powershell@package
|
- logs-windows.powershell@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.powershell@custom
|
- logs-windows.powershell@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4273,6 +4276,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.powershell_operational@package
|
- logs-windows.powershell_operational@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.powershell_operational@custom
|
- logs-windows.powershell_operational@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4322,6 +4326,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.sysmon_operational@package
|
- logs-windows.sysmon_operational@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.sysmon_operational@custom
|
- logs-windows.sysmon_operational@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
|
|||||||
+123
@@ -0,0 +1,123 @@
|
|||||||
|
{
|
||||||
|
"_meta": {
|
||||||
|
"managed_by": "security_onion",
|
||||||
|
"managed": true,
|
||||||
|
"description": "Adds .caseless for Lucene queries. Restates each field's package type and .text."
|
||||||
|
},
|
||||||
|
"template": {
|
||||||
|
"mappings": {
|
||||||
|
"properties": {
|
||||||
|
"process": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "wildcard",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"parent": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "wildcard",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"file": {
|
||||||
|
"properties": {
|
||||||
|
"path": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
+80
@@ -0,0 +1,80 @@
|
|||||||
|
{
|
||||||
|
"_meta": {
|
||||||
|
"managed_by": "security_onion",
|
||||||
|
"managed": true,
|
||||||
|
"description": "Adds .caseless for Lucene queries. Keeps each field's existing keyword type."
|
||||||
|
},
|
||||||
|
"template": {
|
||||||
|
"mappings": {
|
||||||
|
"properties": {
|
||||||
|
"process": {
|
||||||
|
"properties": {
|
||||||
|
"command_line": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"parent": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"file": {
|
||||||
|
"properties": {
|
||||||
|
"path": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -42,7 +42,8 @@ def loadYaml(filename):
|
|||||||
try:
|
try:
|
||||||
with open(filename, "r") as file:
|
with open(filename, "r") as file:
|
||||||
content = file.read()
|
content = file.read()
|
||||||
return yaml.safe_load(content)
|
loaded = yaml.safe_load(content)
|
||||||
|
return loaded if loaded is not None else {}
|
||||||
except FileNotFoundError:
|
except FileNotFoundError:
|
||||||
print(f"File not found: {filename}", file=sys.stderr)
|
print(f"File not found: {filename}", file=sys.stderr)
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|||||||
@@ -95,6 +95,20 @@ class TestRemove(unittest.TestCase):
|
|||||||
expected = "key1:\n child1: 123\n child2:\n deep2: ab\nkey2: false\n"
|
expected = "key1:\n child1: 123\n child2:\n deep2: ab\nkey2: false\n"
|
||||||
self.assertEqual(actual, expected)
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_remove_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-remove-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.remove([filename, "key1"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
self.assertEqual(actual, "{}\n")
|
||||||
|
|
||||||
def test_remove_missing_args(self):
|
def test_remove_missing_args(self):
|
||||||
with patch('sys.exit', new=MagicMock()) as sysmock:
|
with patch('sys.exit', new=MagicMock()) as sysmock:
|
||||||
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
@@ -294,6 +308,36 @@ class TestRemove(unittest.TestCase):
|
|||||||
expected = "key1:\n child1: 123\n child2:\n deep1: 45\n deep2: d\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
expected = "key1:\n child1: 123\n child2:\n deep1: 45\n deep2: d\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
||||||
self.assertEqual(actual, expected)
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_add_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-add-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.add([filename, "telegraf.output", "BOTH"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
expected = "telegraf:\n output: BOTH\n"
|
||||||
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_add_empty_file_simple(self):
|
||||||
|
filename = "/tmp/so-yaml_test-add-empty-simple.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.add([filename, "telegraf", "BOTH"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
expected = "telegraf: BOTH\n"
|
||||||
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
def test_replace_missing_arg(self):
|
def test_replace_missing_arg(self):
|
||||||
with patch('sys.exit', new=MagicMock()) as sysmock:
|
with patch('sys.exit', new=MagicMock()) as sysmock:
|
||||||
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
@@ -346,6 +390,21 @@ class TestRemove(unittest.TestCase):
|
|||||||
expected = "key1:\n child1: 123\n child2:\n deep1: 46\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
expected = "key1:\n child1: 123\n child2:\n deep1: 46\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
||||||
self.assertEqual(actual, expected)
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_replace_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-replace-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.replace([filename, "telegraf.output", "BOTH"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
expected = "telegraf:\n output: BOTH\n"
|
||||||
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
def test_convert(self):
|
def test_convert(self):
|
||||||
self.assertEqual(soyaml.convertType("foo"), "foo")
|
self.assertEqual(soyaml.convertType("foo"), "foo")
|
||||||
self.assertEqual(soyaml.convertType("foo.bar"), "foo.bar")
|
self.assertEqual(soyaml.convertType("foo.bar"), "foo.bar")
|
||||||
@@ -506,6 +565,18 @@ class TestRemove(unittest.TestCase):
|
|||||||
self.assertEqual(result, 2)
|
self.assertEqual(result, 2)
|
||||||
self.assertEqual("", mock_stdout.getvalue())
|
self.assertEqual("", mock_stdout.getvalue())
|
||||||
|
|
||||||
|
def test_get_empty_file(self):
|
||||||
|
with patch('sys.stdout', new=StringIO()) as mock_stdout:
|
||||||
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
|
filename = "/tmp/so-yaml_test-get-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.get([filename, "telegraf.output"])
|
||||||
|
self.assertEqual(result, 2)
|
||||||
|
self.assertEqual("", mock_stdout.getvalue())
|
||||||
|
self.assertIn("Key 'telegraf.output' not found by so-yaml.py", mock_stderr.getvalue())
|
||||||
|
|
||||||
def test_get_usage(self):
|
def test_get_usage(self):
|
||||||
with patch('sys.exit', new=MagicMock()) as sysmock:
|
with patch('sys.exit', new=MagicMock()) as sysmock:
|
||||||
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
@@ -991,3 +1062,29 @@ class TestLoadYaml(unittest.TestCase):
|
|||||||
soyaml.loadYaml("/tmp/so-yaml_test-unreadable.yaml")
|
soyaml.loadYaml("/tmp/so-yaml_test-unreadable.yaml")
|
||||||
sysmock.assert_called_with(1)
|
sysmock.assert_called_with(1)
|
||||||
self.assertIn("Error reading file", mock_stderr.getvalue())
|
self.assertIn("Error reading file", mock_stderr.getvalue())
|
||||||
|
|
||||||
|
def test_load_yaml_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-load-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.loadYaml(filename)
|
||||||
|
self.assertEqual(result, {})
|
||||||
|
|
||||||
|
def test_load_yaml_whitespace_only(self):
|
||||||
|
filename = "/tmp/so-yaml_test-load-whitespace.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.write(" \n\n \n")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.loadYaml(filename)
|
||||||
|
self.assertEqual(result, {})
|
||||||
|
|
||||||
|
def test_load_yaml_comments_only(self):
|
||||||
|
filename = "/tmp/so-yaml_test-load-comments.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.write("# Just a comment\n# Another comment\n")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.loadYaml(filename)
|
||||||
|
self.assertEqual(result, {})
|
||||||
@@ -1183,6 +1183,13 @@ up_to_3.4.0() {
|
|||||||
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
||||||
docker rm -f so-kratos so-hydra so-soc >> $SOUP_LOG 2>&1
|
docker rm -f so-kratos so-hydra so-soc >> $SOUP_LOG 2>&1
|
||||||
|
|
||||||
|
for template in so-metrics-logstash.node so-metrics-logstash.stack_monitoring.node; do
|
||||||
|
if ! remove_elasticsearch_index_template "$template" "logstash node and node_cel index patterns reversed"; then
|
||||||
|
FINAL_MESSAGE_QUEUE+=("WARNING: Unable to automatically remove the $template index template. Addon integration templates may fail to load until it is removed:")
|
||||||
|
FINAL_MESSAGE_QUEUE+=(" - sudo so-elasticsearch-query _index_template/$template -XDELETE && so-checkin")
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
INSTALLEDVERSION=3.4.0
|
INSTALLEDVERSION=3.4.0
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1248,6 +1255,10 @@ valid_soauth_range() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
post_to_3.4.0() {
|
post_to_3.4.0() {
|
||||||
|
for idx in "metrics-logstash.node-default" "metrics-logstash.stack_monitoring.node-default"; do
|
||||||
|
rollover_index "$idx"
|
||||||
|
done
|
||||||
|
|
||||||
set_postversion 3.4.0
|
set_postversion 3.4.0
|
||||||
}
|
}
|
||||||
### 3.4.0 End ###
|
### 3.4.0 End ###
|
||||||
|
|||||||
@@ -9,7 +9,7 @@
|
|||||||
'epel-testing.repo',
|
'epel-testing.repo',
|
||||||
'saltstack.repo',
|
'saltstack.repo',
|
||||||
'salt-latest.repo',
|
'salt-latest.repo',
|
||||||
'wazuh.repo'
|
'wazuh.repo',
|
||||||
'Rocky-Base.repo',
|
'Rocky-Base.repo',
|
||||||
'Rocky-CR.repo',
|
'Rocky-CR.repo',
|
||||||
'Rocky-Debuginfo.repo',
|
'Rocky-Debuginfo.repo',
|
||||||
|
|||||||
+18
-6
@@ -118,21 +118,33 @@ crondetectionsbackup:
|
|||||||
- month: '*'
|
- month: '*'
|
||||||
- dayweek: '*'
|
- dayweek: '*'
|
||||||
|
|
||||||
|
# sigma-cli only loads *.yml from the pipelines dir
|
||||||
socsigmafinalpipeline:
|
socsigmafinalpipeline:
|
||||||
file.managed:
|
file.managed:
|
||||||
- name: /opt/so/conf/soc/sigma_final_pipeline.yaml
|
- name: /opt/so/conf/soc/sigma_pipelines/sigma_final_pipeline.yml
|
||||||
- source: salt://soc/files/soc/sigma_final_pipeline.yaml
|
- source: salt://soc/files/soc/sigma_final_pipeline.yaml
|
||||||
- user: 939
|
- user: 939
|
||||||
- group: 939
|
- group: 939
|
||||||
- mode: 600
|
- mode: 600
|
||||||
|
- makedirs: True
|
||||||
|
|
||||||
socsigmasopipeline:
|
# sigma-cli loads every *.yml here; clean removes anything else
|
||||||
file.managed:
|
socsigmapipelines:
|
||||||
- name: /opt/so/conf/soc/sigma_so_pipeline.yaml
|
file.recurse:
|
||||||
- source: salt://soc/files/soc/sigma_so_pipeline.yaml
|
- name: /opt/so/conf/soc/sigma_pipelines
|
||||||
|
- source: salt://soc/files/soc/sigma_pipelines
|
||||||
- user: 939
|
- user: 939
|
||||||
- group: 939
|
- group: 939
|
||||||
- mode: 600
|
- file_mode: 600
|
||||||
|
- clean: True
|
||||||
|
- require:
|
||||||
|
- file: socsigmafinalpipeline
|
||||||
|
|
||||||
|
socsigmapipelinesold:
|
||||||
|
file.absent:
|
||||||
|
- names:
|
||||||
|
- /opt/so/conf/soc/sigma_final_pipeline.yaml
|
||||||
|
- /opt/so/conf/soc/sigma_so_pipeline.yaml
|
||||||
|
|
||||||
socsigmaplaybookpipeline:
|
socsigmaplaybookpipeline:
|
||||||
file.managed:
|
file.managed:
|
||||||
|
|||||||
@@ -47,9 +47,8 @@ so-soc:
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
|
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
|
||||||
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
|
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
|
||||||
- /opt/so/conf/soc/sigma_so_pipeline.yaml:/opt/sensoroni/sigma_so_pipeline.yaml:ro
|
- /opt/so/conf/soc/sigma_pipelines:/opt/sensoroni/sigma_pipelines:ro
|
||||||
- /opt/so/conf/soc/sigma_playbook_pipeline.yaml:/opt/sensoroni/sigma_playbook_pipeline.yaml:ro
|
- /opt/so/conf/soc/sigma_playbook_pipeline.yaml:/opt/sensoroni/sigma_playbook_pipeline.yaml:ro
|
||||||
- /opt/so/conf/soc/sigma_final_pipeline.yaml:/opt/sensoroni/sigma_final_pipeline.yaml:ro
|
|
||||||
- /opt/so/conf/soc/playbook_placeholder_map.yaml:/opt/sensoroni/playbook_placeholder_map.yaml:ro
|
- /opt/so/conf/soc/playbook_placeholder_map.yaml:/opt/sensoroni/playbook_placeholder_map.yaml:ro
|
||||||
- /opt/so/conf/soc/playbook_placeholder_map_custom.yaml:/opt/sensoroni/playbook_placeholder_map_custom.yaml:ro
|
- /opt/so/conf/soc/playbook_placeholder_map_custom.yaml:/opt/sensoroni/playbook_placeholder_map_custom.yaml:ro
|
||||||
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
||||||
@@ -107,6 +106,7 @@ so-soc:
|
|||||||
- file: socclientsroles
|
- file: socclientsroles
|
||||||
- file: socplaybookplaceholdermap
|
- file: socplaybookplaceholdermap
|
||||||
- file: socplaybookplaceholdermapcustom
|
- file: socplaybookplaceholdermapcustom
|
||||||
|
- file: socsigmapipelines
|
||||||
|
|
||||||
delete_so-soc_so-status.disabled:
|
delete_so-soc_so-status.disabled:
|
||||||
file.uncomment:
|
file.uncomment:
|
||||||
|
|||||||
@@ -0,0 +1,477 @@
|
|||||||
|
name: Security Onion ES|QL Pipeline
|
||||||
|
# ES|QL query settings
|
||||||
|
priority: 92
|
||||||
|
transformations:
|
||||||
|
- id: esql_default_index
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val: .ds-logs-*
|
||||||
|
- id: esql_source_metadata
|
||||||
|
type: set_state
|
||||||
|
key: metadata
|
||||||
|
val: "_id, _index, _source"
|
||||||
|
- id: esql_source_keep
|
||||||
|
type: set_state
|
||||||
|
key: keep
|
||||||
|
val: "_id, _index, _source"
|
||||||
|
# unmapped fields read as null instead of failing the query
|
||||||
|
- id: esql_unmapped_fields
|
||||||
|
type: set_state
|
||||||
|
key: unmapped_fields
|
||||||
|
val: nullify
|
||||||
|
# FROM targets per logsource, any namespace; later entries win, correlations get the union
|
||||||
|
- id: esql_index_process_creation
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-system.security-*
|
||||||
|
- .ds-logs-windows.powershell-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-auditd_manager.auditd-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_process_creation_windows
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-system.security-*
|
||||||
|
- .ds-logs-windows.powershell-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_process_creation_linux
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-auditd_manager.auditd-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_process_creation_macos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_file
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_file_windows
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_file_linux
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_file_macos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_registry
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.registry-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: registry_set
|
||||||
|
- type: logsource
|
||||||
|
category: registry_add
|
||||||
|
- type: logsource
|
||||||
|
category: registry_delete
|
||||||
|
- type: logsource
|
||||||
|
category: registry_event
|
||||||
|
- id: esql_index_library
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.library-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: image_load
|
||||||
|
- type: logsource
|
||||||
|
category: driver_load
|
||||||
|
- id: esql_index_endpoint_network
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_endpoint_network_windows
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_endpoint_network_linux
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_endpoint_network_macos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_sysmon_only
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: process_access
|
||||||
|
- type: logsource
|
||||||
|
category: create_remote_thread
|
||||||
|
- type: logsource
|
||||||
|
category: pipe_created
|
||||||
|
- type: logsource
|
||||||
|
category: create_stream_hash
|
||||||
|
- type: logsource
|
||||||
|
category: wmi_event
|
||||||
|
- type: logsource
|
||||||
|
category: raw_access_thread
|
||||||
|
- type: logsource
|
||||||
|
category: process_tampering
|
||||||
|
- type: logsource
|
||||||
|
category: sysmon_status
|
||||||
|
- type: logsource
|
||||||
|
category: sysmon_error
|
||||||
|
- type: logsource
|
||||||
|
category: file_executable_detected
|
||||||
|
- type: logsource
|
||||||
|
category: file_block_executable
|
||||||
|
- type: logsource
|
||||||
|
category: file_block_shredding
|
||||||
|
- type: logsource
|
||||||
|
category: clipboard_capture
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: sysmon
|
||||||
|
- id: esql_index_ps_operational
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-windows.powershell_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: ps_script
|
||||||
|
- type: logsource
|
||||||
|
category: ps_module
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: powershell
|
||||||
|
- id: esql_index_ps_classic
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-windows.powershell-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: ps_classic_start
|
||||||
|
- type: logsource
|
||||||
|
category: ps_classic_provider_start
|
||||||
|
- type: logsource
|
||||||
|
category: ps_classic_script
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: powershell-classic
|
||||||
|
- id: esql_index_win_security
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.security-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: security
|
||||||
|
- id: esql_index_win_system
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.system-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: system
|
||||||
|
- id: esql_index_win_application
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.application-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: application
|
||||||
|
- id: esql_index_linux_auth
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.auth-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: auth
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: sshd
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: sudo
|
||||||
|
- id: esql_index_linux_syslog
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.syslog-*
|
||||||
|
- .ds-logs-syslog-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: syslog
|
||||||
|
- id: esql_index_linux_auditd
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-auditd_manager.auditd-*
|
||||||
|
- .ds-logs-auditd.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: auditd
|
||||||
|
- id: esql_index_network
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-zeek-so-*
|
||||||
|
- .ds-logs-suricata-so-*
|
||||||
|
- .ds-logs-suricata.alerts-so-*
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
- id: esql_index_so_network
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-zeek-so-*
|
||||||
|
- .ds-logs-suricata-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: connection
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: dns
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: http
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: file
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: x509
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: ssl
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: ssh
|
||||||
|
- type: logsource
|
||||||
|
category: dns
|
||||||
|
- id: esql_index_zeek
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-zeek-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: zeek
|
||||||
|
- id: esql_index_opencanary
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-idh-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: opencanary
|
||||||
|
- id: esql_index_kratos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-kratos-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: kratos
|
||||||
|
|
||||||
+10
-12
@@ -14,18 +14,16 @@ transformations:
|
|||||||
- process.args
|
- process.args
|
||||||
- related.ip
|
- related.ip
|
||||||
- dns.resolved_ip
|
- dns.resolved_ip
|
||||||
- id: esql_default_index
|
# Not every source maps .caseless; EQL/ES|QL already match case-insensitively.
|
||||||
type: set_state
|
- id: caseless_to_parent_fields
|
||||||
key: index
|
type: field_name_mapping
|
||||||
val: .ds-logs-*
|
mapping:
|
||||||
- id: esql_source_metadata
|
process.executable.caseless: process.executable
|
||||||
type: set_state
|
process.name.caseless: process.name
|
||||||
key: metadata
|
process.parent.executable.caseless: process.parent.executable
|
||||||
val: "_id, _index, _source"
|
process.parent.name.caseless: process.parent.name
|
||||||
- id: esql_source_keep
|
target.process.executable.caseless: target.process.executable
|
||||||
type: set_state
|
target.process.name.caseless: target.process.name
|
||||||
key: keep
|
|
||||||
val: "_id, _index, _source"
|
|
||||||
- id: baseline_field_name_mapping
|
- id: baseline_field_name_mapping
|
||||||
type: field_name_mapping
|
type: field_name_mapping
|
||||||
mapping:
|
mapping:
|
||||||
@@ -2,13 +2,13 @@ name: Security Onion - Playbook Pipeline
|
|||||||
priority: 97
|
priority: 97
|
||||||
transformations:
|
transformations:
|
||||||
# Route to lowercase-normalized .caseless subfields for case-insensitive matching.
|
# Route to lowercase-normalized .caseless subfields for case-insensitive matching.
|
||||||
# file.path.caseless exists on Defend only (Sysmon file events lack it);
|
|
||||||
# registry.path / dll.path / file.name have no .caseless on any source.
|
# registry.path / dll.path / file.name have no .caseless on any source.
|
||||||
- id: case_insensitive_string_fields
|
- id: case_insensitive_string_fields
|
||||||
type: field_name_mapping
|
type: field_name_mapping
|
||||||
mapping:
|
mapping:
|
||||||
process.executable: process.executable.caseless
|
process.executable: process.executable.caseless
|
||||||
process.parent.executable: process.parent.executable.caseless
|
process.parent.executable: process.parent.executable.caseless
|
||||||
|
process.parent.name: process.parent.name.caseless
|
||||||
process.command_line: process.command_line.caseless
|
process.command_line: process.command_line.caseless
|
||||||
process.parent.command_line: process.parent.command_line.caseless
|
process.parent.command_line: process.parent.command_line.caseless
|
||||||
file.path: file.path.caseless
|
file.path: file.path.caseless
|
||||||
|
|||||||
@@ -862,15 +862,14 @@ soc:
|
|||||||
global: True
|
global: True
|
||||||
forcedType: bool
|
forcedType: bool
|
||||||
automations:
|
automations:
|
||||||
template:
|
description: Scheduled automations for the Onion AI assistant, managed from the Agent Studio.
|
||||||
description: Scheduled automations for the Onion AI assistant, managed from the Agent Studio. Each automation is stored under its own generated ID so its history and rollback are independent of every other automation.
|
global: True
|
||||||
global: True
|
advanced: True
|
||||||
advanced: False
|
readonlyUi: True
|
||||||
readonlyUi: True
|
storage: db
|
||||||
duplicates: True
|
forcedType: string
|
||||||
forcedType: string
|
syntax: json
|
||||||
syntax: json
|
helpLink: onion-ai
|
||||||
helpLink: onion-ai
|
|
||||||
agents:
|
agents:
|
||||||
description: Agent definitions for the Onion AI assistant, managed from the Agent Studio. An entry naming a system agent overrides only the fields an admin may change; everything else comes from the built-in definition.
|
description: Agent definitions for the Onion AI assistant, managed from the Agent Studio. An entry naming a system agent overrides only the fields an admin may change; everything else comes from the built-in definition.
|
||||||
global: True
|
global: True
|
||||||
|
|||||||
Reference in new issue
Block a user