Compare commits

...
Author SHA1 Message Date
Mike Reeves 5d88755429 Increase contextLimitSmall to 1000000 2026-10-09 13:14:26 -04:00
Mike Reeves ecc75ef65a Merge branch '3/dev' into mreeves/soai-haiku 2026-10-09 13:13:45 -04:00
Mike Reeves 037f6d3d4f Update agent mapping for Investigator and DetectionEngineer 2026-10-09 13:09:09 -04:00
Mike Reeves 0cc7e36af5 Reduce contextLimitSmall from 1000000 to 100000 2026-10-09 12:47:46 -04:00
Mike Reeves 946e904434 Merge pull request #16301 from Security-Onion-Solutions/mreeves/alert-triage-agent
Map the AlertTriage and Notifier agents to a model
2026-10-09 12:39:24 -04:00
Mike Reeves b17b596a64 Add Claude Haiku to the SOAI assistant models 2026-10-09 10:11:25 -04:00
Matthew Wright 603949002b Merge pull request #16312 from Security-Onion-Solutions/mwright/md-img-toggle
Add allowExternalMarkdownImages SOC Setting
2026-10-08 12:38:45 -04:00
Matthew Wright de63f95ab0 turn off advanced 2026-10-08 12:38:13 -04:00
Matthew Wright a1b76650fb add external image markdown toggle 2026-10-08 12:10:30 -04:00
Jorge Reyes 0cd8e53832 Merge pull request #16311 from Security-Onion-Solutions/reyesj2-patch-4
regenerate elastic agent installer
2026-10-08 10:13:30 -05:00
reyesj2 0210ccfcc3 elastic agent 9.4.8 regenerate installer 2026-10-08 09:54:41 -05:00
reyesj2 517076330a stg profile update - breaks so-elastic-agent / so-elastic-fleet containers 2026-10-08 09:54:35 -05:00
Jason Ertel ad249782fc Merge pull request #16310 from Security-Onion-Solutions/jertel/wip
new destination timeout annotation; fix fp
2026-10-08 10:48:26 -04:00
Jorge Reyes 547d2a316b Merge pull request #16306 from Security-Onion-Solutions/reyesj2/es948
ES 9.4.8
2026-10-07 16:17:52 -05:00
Jorge Reyes 1c4eef4224 Update version from 3.0.0-foxtrot to 3.4.0 2026-10-07 12:31:45 -05:00
Mike Reeves b11fc6257a Map the AlertTriage and Notifier agents to a model
SOC disables a built-in agent that has no agentMapping entry, so the new
AlertTriage agent and the Notifier it delegates to need one to run.
2026-10-06 20:43:04 -04:00
Jason Ertel d1114a0dae Merge pull request #16300 from Security-Onion-Solutions/jertel/wip
update tick interval desc
2026-10-06 18:41:48 -04:00
Jorge Reyes c6e42131b2 Update version from 3.4.0 to 3.0.0-foxtrot 2026-10-06 13:45:22 -05:00
reyesj2 337dddf596 ES 9.4.8 2026-10-06 13:44:52 -05:00
6 changed files with 42 additions and 19 deletions

No files matched your search

+1 -1
View File
@@ -1,7 +1,7 @@
elasticsearch:
enabled: false
esheap: '600m'
version: 9.4.5
version: 9.4.8
index_clean: true
data_retention_method: DLM
vm:
+1 -1
View File
@@ -22,7 +22,7 @@ kibana:
- default
- file
migrations:
discardCorruptObjects: "9.4.5"
discardCorruptObjects: "9.4.8"
telemetry:
enabled: False
xpack:
+12 -11
View File
@@ -1131,9 +1131,6 @@ post_to_3.2.0() {
### 3.3.0 Scripts ###
up_to_3.3.0() {
# download 9.4.5 elastic agent packages
determine_elastic_agent_upgrade
# remove existing (patched) elasticsearch index template to match integration naming change
if ! remove_elasticsearch_index_template "so-logs-sentinel_one_cloud_funnel.login" "sentinel_one_cloud_funnel.login changed to sentinel_one_cloud_funnel.logins"; then
FINAL_MESSAGE_QUEUE+=("WARNING: Unable to automatically remove the so-logs-sentinel_one_cloud_funnel.login index template. This step can be performed manually using the following command:")
@@ -1165,11 +1162,7 @@ telegraf_repair() {
post_to_3.3.0() {
# Recollate again since some internal DBs were excluded during 3.2.0 soup
recollate_postgres
# Generate 9.4.5 elastic agent installers
echo "Regenerating Elastic Agent Installers"
/sbin/so-elastic-agent-gen-installers
telegraf_repair
set_postversion 3.3.0
@@ -1178,6 +1171,9 @@ post_to_3.3.0() {
### 3.4.0 Scripts ###
up_to_3.4.0() {
# download 9.4.8 elastic agent packages
determine_elastic_agent_upgrade
set_soauth_range
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
@@ -1255,6 +1251,10 @@ valid_soauth_range() {
}
post_to_3.4.0() {
# Generate 9.4.8 elastic agent installers
echo "Regenerating Elastic Agent Installers"
/sbin/so-elastic-agent-gen-installers
for idx in "metrics-logstash.node-default" "metrics-logstash.stack_monitoring.node-default"; do
rollover_index "$idx"
done
@@ -1535,9 +1535,10 @@ verify_es_version_compatibility() {
["8.18.4"]="8.18.6 8.18.8 9.0.8"
["8.18.6"]="8.18.8 9.0.8"
["8.18.8"]="9.0.8"
["9.0.8"]="9.3.3 9.3.7 9.4.5"
["9.3.3"]="9.3.7 9.4.5"
["9.3.7"]="9.4.5"
["9.0.8"]="9.3.3 9.3.7 9.4.5 9.4.8"
["9.3.3"]="9.3.7 9.4.5 9.4.8"
["9.3.7"]="9.4.5 9.4.8"
["9.4.5"]="9.4.8"
)
# Elasticsearch MUST upgrade through these versions
+14 -2
View File
@@ -1540,8 +1540,10 @@ soc:
agentic: false
agentMapping:
Orchestrator: sonnet@SOAI
Investigator: gemma@SOAI
DetectionEngineer: gemma@SOAI
Investigator: haiku@SOAI
DetectionEngineer: haiku@SOAI
AlertTriage: haiku@SOAI
Notifier: haiku@SOAI
useMemory: false
useMemoryScanner: false
dontScanBefore: ""
@@ -1821,6 +1823,7 @@ soc:
cacheExpirationMs: 300000
casesEnabled: true
detectionsEnabled: true
allowExternalMarkdownImages: false
inactiveTools: ['toolUnused']
exportNodeId:
tools:
@@ -2813,6 +2816,15 @@ soc:
enabled: true
adapter: SOAI
charsPerTokenEstimate: 4
- id: haiku
displayName: Claude Haiku
origin: USA
contextLimitSmall: 1000000
contextLimitLarge: 1000000
lowBalanceColorAlert: 500000
enabled: true
adapter: SOAI
charsPerTokenEstimate: 4
- id: gemma
displayName: Gemma
origin: USA
+10
View File
@@ -941,6 +941,12 @@ soc:
DetectionEngineer:
description: This agent manages detections and their overrides, including tuning noisy rules and authoring rule content.
global: True
AlertTriage:
description: This agent triages alerts autonomously for the Alert Triage automation, ending each run with a report and an assessment of the alert. It can notify through the Notifier but cannot acknowledge alerts or escalate to cases.
global: True
Notifier:
description: This agent sends a single notification on behalf of another agent, such as AlertTriage, and takes no other action.
global: True
useMemory:
description: Enables the Memory system for OnionAI
global: True
@@ -1155,6 +1161,10 @@ soc:
description: Set to true to enable the Detections module in SOC.
global: True
forcedType: bool
allowExternalMarkdownImages:
description: Set to true to let user-written Markdown, such as case descriptions and comments, load images from other servers. Loading an image sends a request to its server, so leave this disabled unless needed; Onion AI output never loads external images.
global: True
forcedType: bool
inactiveTools:
description: List of external tools to remove from the SOC UI.
global: True
+4 -4
View File
@@ -1333,8 +1333,8 @@ DISA STIG for Oracle Linux 9 V1R3.</xccdf-1.2:description>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="false"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="false"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
@@ -1935,8 +1935,8 @@ standard DISA STIG for Oracle Linux 9 profile.</xccdf-1.2:description>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="false"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="false"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>