mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 15:25:26 +02:00
Compare commits
38
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
547d2a316b | ||
|
|
1c4eef4224 | ||
|
|
d1114a0dae | ||
|
|
f4b301d71c | ||
|
|
c6e42131b2 | ||
|
|
337dddf596 | ||
|
|
f7dbfba178 | ||
|
|
0a628bb7e7 | ||
|
|
bd6647e775 | ||
|
|
da2c19188a | ||
|
|
90b3d37be6 | ||
|
|
fcd2f67076 | ||
|
|
a9cdd17694 | ||
|
|
b32aaac290 | ||
|
|
1aee3f28dc | ||
|
|
678cb0d5b2 | ||
|
|
31c5190a1f | ||
|
|
4ce7a06abe | ||
|
|
ba95b9bbc2 | ||
|
|
43475452b3 | ||
|
|
99322cf26a | ||
|
|
117548757f | ||
|
|
22bda63847 | ||
|
|
2a4611df45 | ||
|
|
89f8bcd19f | ||
|
|
563269cbac | ||
|
|
523c39d4f2 | ||
|
|
b4557e973c | ||
|
|
0f53a7e0bc | ||
|
|
8de8ba811a | ||
|
|
d122ee7fea | ||
|
|
9732e1c639 | ||
|
|
53f9ebcd46 | ||
|
|
47d74f1ae1 | ||
|
|
855716846a | ||
|
|
8e35d70595 | ||
|
|
e4625cfcae | ||
|
|
eb803dce0e |
No files matched your search
@@ -177,6 +177,7 @@ if [[ $EXCLUDE_FALSE_POSITIVE_ERRORS == 'Y' ]]; then
|
|||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Unexpected authorization header" # expected WARN log lines indicating invalid auth header
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Unexpected authorization header" # expected WARN log lines indicating invalid auth header
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Missing ory_kratos_session cookie" # expected WARN log lines indicating invalid auth header
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Missing ory_kratos_session cookie" # expected WARN log lines indicating invalid auth header
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Static assets preprocessor only supports GET and HEAD requests" # expected WARN log lines indicating invalid auth header
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Static assets preprocessor only supports GET and HEAD requests" # expected WARN log lines indicating invalid auth header
|
||||||
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|respondError" # respondError is a function name, output via http middleware as standard request logging
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
|
if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
|
||||||
@@ -240,7 +241,7 @@ if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
|
|||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # appears in so-dockerregistry log for so-tcpreplay following docker upgrade to 29.2.1-1
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # so-dockerregistry logs a tag lookup miss during image copy; not tied to one docker version
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Could not index event to Elasticsearch.*\"version\" => \"9.0.8\"" # Expected during Elastic upgrade temporarily, as policies referencing older pipelines are updated
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Could not index event to Elasticsearch.*\"version\" => \"9.0.8\"" # Expected during Elastic upgrade temporarily, as policies referencing older pipelines are updated
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -18,10 +18,10 @@ dockergroup:
|
|||||||
dockerheldpackages:
|
dockerheldpackages:
|
||||||
pkg.installed:
|
pkg.installed:
|
||||||
- pkgs:
|
- pkgs:
|
||||||
- containerd.io: 2.2.1-1.el9
|
- containerd.io: 2.3.6-1.el9
|
||||||
- docker-ce: 3:29.2.1-1.el9
|
- docker-ce: 3:29.8.1-1.el9
|
||||||
- docker-ce-cli: 1:29.2.1-1.el9
|
- docker-ce-cli: 1:29.8.1-1.el9
|
||||||
- docker-ce-rootless-extras: 29.2.1-1.el9
|
- docker-ce-rootless-extras: 29.8.1-1.el9
|
||||||
- hold: True
|
- hold: True
|
||||||
- update_holds: True
|
- update_holds: True
|
||||||
|
|
||||||
|
|||||||
@@ -29,7 +29,7 @@
|
|||||||
"\\.gz$"
|
"\\.gz$"
|
||||||
],
|
],
|
||||||
"include_files": [],
|
"include_files": [],
|
||||||
"processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- drop_fields:\n fields: [\"host\"]\n ignore_missing: true\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: system.security\n- add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.security-2.22.3\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: windows.sysmon_operational\n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-windows.sysmon_operational-3.9.0\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: system.application\n - add_fields:\n target: event\n fields:\n dataset: system.application\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.application-2.22.3\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: system.system\n - add_fields:\n target: event\n fields:\n dataset: system.system\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.system-2.22.3\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: windows.powershell_operational\n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-windows.powershell_operational-3.9.0\n- add_fields:\n target: data_stream\n fields:\n dataset: import",
|
"processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- add_fields:\n target: event\n fields:\n dataset: windows.forwarded\n module: windows\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: import.evtx\n- if:\n equals:\n winlog.channel: 'Security'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n- if:\n equals:\n winlog.channel: 'Windows PowerShell'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell\n module: windows\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.application\n module: system\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.system\n module: system\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: import",
|
||||||
"tags": [
|
"tags": [
|
||||||
"import"
|
"import"
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -30,17 +30,14 @@
|
|||||||
'azure_metrics.monitor': 'azure.monitor',
|
'azure_metrics.monitor': 'azure.monitor',
|
||||||
'azure_metrics.storage_account': 'azure.storage_account',
|
'azure_metrics.storage_account': 'azure.storage_account',
|
||||||
'azure_openai.metrics': 'azure.open_ai',
|
'azure_openai.metrics': 'azure.open_ai',
|
||||||
'beat.state': 'beats.stack_monitoring.state',
|
|
||||||
'beat.stats': 'beats.stack_monitoring.stats',
|
|
||||||
'enterprisesearch.health': 'enterprisesearch.stack_monitoring.health',
|
|
||||||
'enterprisesearch.stats': 'enterprisesearch.stack_monitoring.stats',
|
|
||||||
'kibana.cluster_actions': 'kibana.stack_monitoring.cluster_actions',
|
'kibana.cluster_actions': 'kibana.stack_monitoring.cluster_actions',
|
||||||
'kibana.cluster_rules': 'kibana.stack_monitoring.cluster_rules',
|
'kibana.cluster_rules': 'kibana.stack_monitoring.cluster_rules',
|
||||||
'kibana.node_actions': 'kibana.stack_monitoring.node_actions',
|
'kibana.node_actions': 'kibana.stack_monitoring.node_actions',
|
||||||
'kibana.node_rules': 'kibana.stack_monitoring.node_rules',
|
'kibana.node_rules': 'kibana.stack_monitoring.node_rules',
|
||||||
'kibana.stats': 'kibana.stack_monitoring.stats',
|
'kibana.stats': 'kibana.stack_monitoring.stats',
|
||||||
'kibana.status': 'kibana.stack_monitoring.status',
|
'kibana.status': 'kibana.stack_monitoring.status',
|
||||||
'logstash.node_cel': 'logstash.stack_monitoring.node',
|
'logstash.node': 'logstash.stack_monitoring.node',
|
||||||
|
'logstash.node_cel': 'logstash.node',
|
||||||
'logstash.node_stats': 'logstash.stack_monitoring.node_stats',
|
'logstash.node_stats': 'logstash.stack_monitoring.node_stats',
|
||||||
'synthetics.browser': 'synthetics-browser',
|
'synthetics.browser': 'synthetics-browser',
|
||||||
'synthetics.browser_network': 'synthetics-browser.network',
|
'synthetics.browser_network': 'synthetics-browser.network',
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
elasticsearch:
|
elasticsearch:
|
||||||
enabled: false
|
enabled: false
|
||||||
esheap: '600m'
|
esheap: '600m'
|
||||||
version: 9.4.5
|
version: 9.4.8
|
||||||
index_clean: true
|
index_clean: true
|
||||||
data_retention_method: DLM
|
data_retention_method: DLM
|
||||||
vm:
|
vm:
|
||||||
@@ -3309,6 +3309,7 @@ elasticsearch:
|
|||||||
composed_of:
|
composed_of:
|
||||||
- event-mappings
|
- event-mappings
|
||||||
- logs-system.security@package
|
- logs-system.security@package
|
||||||
|
- so-fleet_system.security_caseless-1
|
||||||
- logs-system.security@custom
|
- logs-system.security@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4175,6 +4176,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.forwarded@package
|
- logs-windows.forwarded@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.forwarded@custom
|
- logs-windows.forwarded@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4224,6 +4226,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.powershell@package
|
- logs-windows.powershell@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.powershell@custom
|
- logs-windows.powershell@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4273,6 +4276,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.powershell_operational@package
|
- logs-windows.powershell_operational@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.powershell_operational@custom
|
- logs-windows.powershell_operational@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
@@ -4322,6 +4326,7 @@ elasticsearch:
|
|||||||
index_template:
|
index_template:
|
||||||
composed_of:
|
composed_of:
|
||||||
- logs-windows.sysmon_operational@package
|
- logs-windows.sysmon_operational@package
|
||||||
|
- so-fleet_process_caseless-1
|
||||||
- logs-windows.sysmon_operational@custom
|
- logs-windows.sysmon_operational@custom
|
||||||
- so-fleet_integrations.ip_mappings-1
|
- so-fleet_integrations.ip_mappings-1
|
||||||
- so-fleet_globals-1
|
- so-fleet_globals-1
|
||||||
|
|||||||
@@ -99,7 +99,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"set": {
|
"set": {
|
||||||
"if": "ctx.tags != null && ctx.tags.contains('import')",
|
"if": "ctx.tags != null && ctx.tags.contains('import') && ctx._index != null && ctx._index.startsWith('logs-import-')",
|
||||||
"override": true,
|
"override": true,
|
||||||
"field": "data_stream.dataset",
|
"field": "data_stream.dataset",
|
||||||
"value": "import"
|
"value": "import"
|
||||||
@@ -107,7 +107,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"set": {
|
"set": {
|
||||||
"if": "ctx.tags != null && ctx.tags.contains('import')",
|
"if": "ctx.tags != null && ctx.tags.contains('import') && ctx._index != null && ctx._index.startsWith('logs-import-')",
|
||||||
"override": true,
|
"override": true,
|
||||||
"field": "data_stream.namespace",
|
"field": "data_stream.namespace",
|
||||||
"value": "so"
|
"value": "so"
|
||||||
|
|||||||
@@ -0,0 +1,31 @@
|
|||||||
|
{
|
||||||
|
"description" : "import.evtx: normalize imported EVTX and reroute to logs-<dataset>-import",
|
||||||
|
"processors" : [
|
||||||
|
{ "script": {
|
||||||
|
"description": "Host from the event, not the importing node",
|
||||||
|
"lang": "painless",
|
||||||
|
"source": "Map host = ['os': ['type': 'windows', 'family': 'windows', 'platform': 'windows']]; def cn = ctx.winlog?.computer_name; if (cn != null && cn.toString().length() > 0) { String name = cn.toString(); int dot = name.indexOf('.'); if (dot > 0) { name = name.substring(0, dot); } host.put('hostname', name); host.put('name', name.toLowerCase()); } ctx.host = host;"
|
||||||
|
} },
|
||||||
|
{ "script": {
|
||||||
|
"description": "String event IDs, as Winlogbeat sends",
|
||||||
|
"lang": "painless",
|
||||||
|
"source": "if (ctx.winlog?.event_id != null) { ctx.winlog.event_id = ctx.winlog.event_id.toString(); } if (ctx.event?.code != null) { ctx.event.code = ctx.event.code.toString(); }"
|
||||||
|
} },
|
||||||
|
{ "script": {
|
||||||
|
"description": "Unnamed <Data> to param1..N, as Winlogbeat",
|
||||||
|
"lang": "painless",
|
||||||
|
"if": "ctx.winlog?.event_data?.Data instanceof Map && ctx.winlog.event_data.Data['#text'] != null",
|
||||||
|
"source": "def t = ctx.winlog.event_data.Data['#text']; List vals = t instanceof List ? t : [t]; for (int i = 0; i < vals.size(); i++) { ctx.winlog.event_data['param' + (i + 1)] = vals.get(i); } ctx.winlog.event_data.remove('Data');"
|
||||||
|
} },
|
||||||
|
{ "script": {
|
||||||
|
"description": "String values and LF line endings, as Winlogbeat",
|
||||||
|
"lang": "painless",
|
||||||
|
"if": "ctx.winlog?.event_data instanceof Map || ctx.winlog?.user_data instanceof Map",
|
||||||
|
"source": "String lf = String.valueOf((char) 10); String crlf = String.valueOf((char) 13) + lf; for (def key : ['event_data', 'user_data']) { def m = ctx.winlog[key]; if (!(m instanceof Map)) { continue; } for (def e : m.entrySet()) { def v = e.getValue(); if (v instanceof String) { e.setValue(v.replace(crlf, lf)); } else if (v instanceof Number || v instanceof Boolean) { e.setValue(v.toString()); } } }"
|
||||||
|
} },
|
||||||
|
{ "set": { "description": "event.kind, as Winlogbeat", "field": "event.kind", "value": "event", "override": false } },
|
||||||
|
{ "set": { "field": "data_stream.dataset", "copy_from": "event.dataset", "override": true, "ignore_empty_value": true } },
|
||||||
|
{ "set": { "field": "data_stream.namespace", "value": "import", "override": true } },
|
||||||
|
{ "reroute": { "dataset": "{{data_stream.dataset}}", "namespace": "{{data_stream.namespace}}" } }
|
||||||
|
]
|
||||||
|
}
|
||||||
+123
@@ -0,0 +1,123 @@
|
|||||||
|
{
|
||||||
|
"_meta": {
|
||||||
|
"managed_by": "security_onion",
|
||||||
|
"managed": true,
|
||||||
|
"description": "Adds .caseless for Lucene queries. Restates each field's package type and .text."
|
||||||
|
},
|
||||||
|
"template": {
|
||||||
|
"mappings": {
|
||||||
|
"properties": {
|
||||||
|
"process": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "wildcard",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"parent": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "wildcard",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"file": {
|
||||||
|
"properties": {
|
||||||
|
"path": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
},
|
||||||
|
"text": {
|
||||||
|
"type": "match_only_text"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
+80
@@ -0,0 +1,80 @@
|
|||||||
|
{
|
||||||
|
"_meta": {
|
||||||
|
"managed_by": "security_onion",
|
||||||
|
"managed": true,
|
||||||
|
"description": "Adds .caseless for Lucene queries. Keeps each field's existing keyword type."
|
||||||
|
},
|
||||||
|
"template": {
|
||||||
|
"mappings": {
|
||||||
|
"properties": {
|
||||||
|
"process": {
|
||||||
|
"properties": {
|
||||||
|
"command_line": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"parent": {
|
||||||
|
"properties": {
|
||||||
|
"executable": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"name": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"command_line": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"file": {
|
||||||
|
"properties": {
|
||||||
|
"path": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"fields": {
|
||||||
|
"caseless": {
|
||||||
|
"type": "keyword",
|
||||||
|
"ignore_above": 1024,
|
||||||
|
"normalizer": "lowercase"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -22,7 +22,7 @@ kibana:
|
|||||||
- default
|
- default
|
||||||
- file
|
- file
|
||||||
migrations:
|
migrations:
|
||||||
discardCorruptObjects: "9.4.5"
|
discardCorruptObjects: "9.4.8"
|
||||||
telemetry:
|
telemetry:
|
||||||
enabled: False
|
enabled: False
|
||||||
xpack:
|
xpack:
|
||||||
|
|||||||
@@ -42,7 +42,8 @@ def loadYaml(filename):
|
|||||||
try:
|
try:
|
||||||
with open(filename, "r") as file:
|
with open(filename, "r") as file:
|
||||||
content = file.read()
|
content = file.read()
|
||||||
return yaml.safe_load(content)
|
loaded = yaml.safe_load(content)
|
||||||
|
return loaded if loaded is not None else {}
|
||||||
except FileNotFoundError:
|
except FileNotFoundError:
|
||||||
print(f"File not found: {filename}", file=sys.stderr)
|
print(f"File not found: {filename}", file=sys.stderr)
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|||||||
@@ -95,6 +95,20 @@ class TestRemove(unittest.TestCase):
|
|||||||
expected = "key1:\n child1: 123\n child2:\n deep2: ab\nkey2: false\n"
|
expected = "key1:\n child1: 123\n child2:\n deep2: ab\nkey2: false\n"
|
||||||
self.assertEqual(actual, expected)
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_remove_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-remove-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.remove([filename, "key1"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
self.assertEqual(actual, "{}\n")
|
||||||
|
|
||||||
def test_remove_missing_args(self):
|
def test_remove_missing_args(self):
|
||||||
with patch('sys.exit', new=MagicMock()) as sysmock:
|
with patch('sys.exit', new=MagicMock()) as sysmock:
|
||||||
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
@@ -294,6 +308,36 @@ class TestRemove(unittest.TestCase):
|
|||||||
expected = "key1:\n child1: 123\n child2:\n deep1: 45\n deep2: d\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
expected = "key1:\n child1: 123\n child2:\n deep1: 45\n deep2: d\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
||||||
self.assertEqual(actual, expected)
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_add_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-add-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.add([filename, "telegraf.output", "BOTH"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
expected = "telegraf:\n output: BOTH\n"
|
||||||
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_add_empty_file_simple(self):
|
||||||
|
filename = "/tmp/so-yaml_test-add-empty-simple.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.add([filename, "telegraf", "BOTH"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
expected = "telegraf: BOTH\n"
|
||||||
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
def test_replace_missing_arg(self):
|
def test_replace_missing_arg(self):
|
||||||
with patch('sys.exit', new=MagicMock()) as sysmock:
|
with patch('sys.exit', new=MagicMock()) as sysmock:
|
||||||
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
@@ -346,6 +390,21 @@ class TestRemove(unittest.TestCase):
|
|||||||
expected = "key1:\n child1: 123\n child2:\n deep1: 46\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
expected = "key1:\n child1: 123\n child2:\n deep1: 46\nkey2: false\nkey3:\n- e\n- f\n- g\n"
|
||||||
self.assertEqual(actual, expected)
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
|
def test_replace_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-replace-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
code = soyaml.replace([filename, "telegraf.output", "BOTH"])
|
||||||
|
self.assertEqual(code, 0)
|
||||||
|
|
||||||
|
file = open(filename, "r")
|
||||||
|
actual = file.read()
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
expected = "telegraf:\n output: BOTH\n"
|
||||||
|
self.assertEqual(actual, expected)
|
||||||
|
|
||||||
def test_convert(self):
|
def test_convert(self):
|
||||||
self.assertEqual(soyaml.convertType("foo"), "foo")
|
self.assertEqual(soyaml.convertType("foo"), "foo")
|
||||||
self.assertEqual(soyaml.convertType("foo.bar"), "foo.bar")
|
self.assertEqual(soyaml.convertType("foo.bar"), "foo.bar")
|
||||||
@@ -506,6 +565,18 @@ class TestRemove(unittest.TestCase):
|
|||||||
self.assertEqual(result, 2)
|
self.assertEqual(result, 2)
|
||||||
self.assertEqual("", mock_stdout.getvalue())
|
self.assertEqual("", mock_stdout.getvalue())
|
||||||
|
|
||||||
|
def test_get_empty_file(self):
|
||||||
|
with patch('sys.stdout', new=StringIO()) as mock_stdout:
|
||||||
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
|
filename = "/tmp/so-yaml_test-get-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.get([filename, "telegraf.output"])
|
||||||
|
self.assertEqual(result, 2)
|
||||||
|
self.assertEqual("", mock_stdout.getvalue())
|
||||||
|
self.assertIn("Key 'telegraf.output' not found by so-yaml.py", mock_stderr.getvalue())
|
||||||
|
|
||||||
def test_get_usage(self):
|
def test_get_usage(self):
|
||||||
with patch('sys.exit', new=MagicMock()) as sysmock:
|
with patch('sys.exit', new=MagicMock()) as sysmock:
|
||||||
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
with patch('sys.stderr', new=StringIO()) as mock_stderr:
|
||||||
@@ -991,3 +1062,29 @@ class TestLoadYaml(unittest.TestCase):
|
|||||||
soyaml.loadYaml("/tmp/so-yaml_test-unreadable.yaml")
|
soyaml.loadYaml("/tmp/so-yaml_test-unreadable.yaml")
|
||||||
sysmock.assert_called_with(1)
|
sysmock.assert_called_with(1)
|
||||||
self.assertIn("Error reading file", mock_stderr.getvalue())
|
self.assertIn("Error reading file", mock_stderr.getvalue())
|
||||||
|
|
||||||
|
def test_load_yaml_empty_file(self):
|
||||||
|
filename = "/tmp/so-yaml_test-load-empty.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.loadYaml(filename)
|
||||||
|
self.assertEqual(result, {})
|
||||||
|
|
||||||
|
def test_load_yaml_whitespace_only(self):
|
||||||
|
filename = "/tmp/so-yaml_test-load-whitespace.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.write(" \n\n \n")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.loadYaml(filename)
|
||||||
|
self.assertEqual(result, {})
|
||||||
|
|
||||||
|
def test_load_yaml_comments_only(self):
|
||||||
|
filename = "/tmp/so-yaml_test-load-comments.yaml"
|
||||||
|
file = open(filename, "w")
|
||||||
|
file.write("# Just a comment\n# Another comment\n")
|
||||||
|
file.close()
|
||||||
|
|
||||||
|
result = soyaml.loadYaml(filename)
|
||||||
|
self.assertEqual(result, {})
|
||||||
@@ -1183,6 +1183,13 @@ up_to_3.4.0() {
|
|||||||
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
||||||
docker rm -f so-kratos so-hydra so-soc >> $SOUP_LOG 2>&1
|
docker rm -f so-kratos so-hydra so-soc >> $SOUP_LOG 2>&1
|
||||||
|
|
||||||
|
for template in so-metrics-logstash.node so-metrics-logstash.stack_monitoring.node; do
|
||||||
|
if ! remove_elasticsearch_index_template "$template" "logstash node and node_cel index patterns reversed"; then
|
||||||
|
FINAL_MESSAGE_QUEUE+=("WARNING: Unable to automatically remove the $template index template. Addon integration templates may fail to load until it is removed:")
|
||||||
|
FINAL_MESSAGE_QUEUE+=(" - sudo so-elasticsearch-query _index_template/$template -XDELETE && so-checkin")
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
INSTALLEDVERSION=3.4.0
|
INSTALLEDVERSION=3.4.0
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1248,6 +1255,10 @@ valid_soauth_range() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
post_to_3.4.0() {
|
post_to_3.4.0() {
|
||||||
|
for idx in "metrics-logstash.node-default" "metrics-logstash.stack_monitoring.node-default"; do
|
||||||
|
rollover_index "$idx"
|
||||||
|
done
|
||||||
|
|
||||||
set_postversion 3.4.0
|
set_postversion 3.4.0
|
||||||
}
|
}
|
||||||
### 3.4.0 End ###
|
### 3.4.0 End ###
|
||||||
@@ -1524,9 +1535,10 @@ verify_es_version_compatibility() {
|
|||||||
["8.18.4"]="8.18.6 8.18.8 9.0.8"
|
["8.18.4"]="8.18.6 8.18.8 9.0.8"
|
||||||
["8.18.6"]="8.18.8 9.0.8"
|
["8.18.6"]="8.18.8 9.0.8"
|
||||||
["8.18.8"]="9.0.8"
|
["8.18.8"]="9.0.8"
|
||||||
["9.0.8"]="9.3.3 9.3.7 9.4.5"
|
["9.0.8"]="9.3.3 9.3.7 9.4.5 9.4.8"
|
||||||
["9.3.3"]="9.3.7 9.4.5"
|
["9.3.3"]="9.3.7 9.4.5 9.4.8"
|
||||||
["9.3.7"]="9.4.5"
|
["9.3.7"]="9.4.5 9.4.8"
|
||||||
|
["9.4.5"]="9.4.8"
|
||||||
)
|
)
|
||||||
|
|
||||||
# Elasticsearch MUST upgrade through these versions
|
# Elasticsearch MUST upgrade through these versions
|
||||||
|
|||||||
@@ -9,7 +9,7 @@
|
|||||||
'epel-testing.repo',
|
'epel-testing.repo',
|
||||||
'saltstack.repo',
|
'saltstack.repo',
|
||||||
'salt-latest.repo',
|
'salt-latest.repo',
|
||||||
'wazuh.repo'
|
'wazuh.repo',
|
||||||
'Rocky-Base.repo',
|
'Rocky-Base.repo',
|
||||||
'Rocky-CR.repo',
|
'Rocky-CR.repo',
|
||||||
'Rocky-Debuginfo.repo',
|
'Rocky-Debuginfo.repo',
|
||||||
|
|||||||
+18
-6
@@ -118,21 +118,33 @@ crondetectionsbackup:
|
|||||||
- month: '*'
|
- month: '*'
|
||||||
- dayweek: '*'
|
- dayweek: '*'
|
||||||
|
|
||||||
|
# sigma-cli only loads *.yml from the pipelines dir
|
||||||
socsigmafinalpipeline:
|
socsigmafinalpipeline:
|
||||||
file.managed:
|
file.managed:
|
||||||
- name: /opt/so/conf/soc/sigma_final_pipeline.yaml
|
- name: /opt/so/conf/soc/sigma_pipelines/sigma_final_pipeline.yml
|
||||||
- source: salt://soc/files/soc/sigma_final_pipeline.yaml
|
- source: salt://soc/files/soc/sigma_final_pipeline.yaml
|
||||||
- user: 939
|
- user: 939
|
||||||
- group: 939
|
- group: 939
|
||||||
- mode: 600
|
- mode: 600
|
||||||
|
- makedirs: True
|
||||||
|
|
||||||
socsigmasopipeline:
|
# sigma-cli loads every *.yml here; clean removes anything else
|
||||||
file.managed:
|
socsigmapipelines:
|
||||||
- name: /opt/so/conf/soc/sigma_so_pipeline.yaml
|
file.recurse:
|
||||||
- source: salt://soc/files/soc/sigma_so_pipeline.yaml
|
- name: /opt/so/conf/soc/sigma_pipelines
|
||||||
|
- source: salt://soc/files/soc/sigma_pipelines
|
||||||
- user: 939
|
- user: 939
|
||||||
- group: 939
|
- group: 939
|
||||||
- mode: 600
|
- file_mode: 600
|
||||||
|
- clean: True
|
||||||
|
- require:
|
||||||
|
- file: socsigmafinalpipeline
|
||||||
|
|
||||||
|
socsigmapipelinesold:
|
||||||
|
file.absent:
|
||||||
|
- names:
|
||||||
|
- /opt/so/conf/soc/sigma_final_pipeline.yaml
|
||||||
|
- /opt/so/conf/soc/sigma_so_pipeline.yaml
|
||||||
|
|
||||||
socsigmaplaybookpipeline:
|
socsigmaplaybookpipeline:
|
||||||
file.managed:
|
file.managed:
|
||||||
|
|||||||
@@ -1561,6 +1561,14 @@ soc:
|
|||||||
reconcilePersona: ""
|
reconcilePersona: ""
|
||||||
toolUseTurnAttempts: 12
|
toolUseTurnAttempts: 12
|
||||||
toolUseTurnDelayMs: 175
|
toolUseTurnDelayMs: 175
|
||||||
|
agentSessionMaxTurns: 20
|
||||||
|
agentStreamFlushIntervalMs: 1000
|
||||||
|
agentStreamIdleTimeoutSeconds: 300
|
||||||
|
automationSettings:
|
||||||
|
tickIntervalSeconds: 60
|
||||||
|
maxConcurrentItems: 4
|
||||||
|
maxQueuedItems: 0
|
||||||
|
alertTriageEpoch: "2026-09-24T00:00:00Z"
|
||||||
tools:
|
tools:
|
||||||
filterEventFields:
|
filterEventFields:
|
||||||
- "@timestamp"
|
- "@timestamp"
|
||||||
@@ -1634,13 +1642,6 @@ soc:
|
|||||||
database: securityonion
|
database: securityonion
|
||||||
user: ""
|
user: ""
|
||||||
password: ""
|
password: ""
|
||||||
postgresmetrics:
|
|
||||||
host: ""
|
|
||||||
port: 5432
|
|
||||||
sslMode: "require"
|
|
||||||
database: telegraf
|
|
||||||
user: ""
|
|
||||||
password: ""
|
|
||||||
salt:
|
salt:
|
||||||
queueDir: /opt/sensoroni/queue
|
queueDir: /opt/sensoroni/queue
|
||||||
timeoutMs: 45000
|
timeoutMs: 45000
|
||||||
|
|||||||
@@ -47,9 +47,8 @@ so-soc:
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
|
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
|
||||||
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
|
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
|
||||||
- /opt/so/conf/soc/sigma_so_pipeline.yaml:/opt/sensoroni/sigma_so_pipeline.yaml:ro
|
- /opt/so/conf/soc/sigma_pipelines:/opt/sensoroni/sigma_pipelines:ro
|
||||||
- /opt/so/conf/soc/sigma_playbook_pipeline.yaml:/opt/sensoroni/sigma_playbook_pipeline.yaml:ro
|
- /opt/so/conf/soc/sigma_playbook_pipeline.yaml:/opt/sensoroni/sigma_playbook_pipeline.yaml:ro
|
||||||
- /opt/so/conf/soc/sigma_final_pipeline.yaml:/opt/sensoroni/sigma_final_pipeline.yaml:ro
|
|
||||||
- /opt/so/conf/soc/playbook_placeholder_map.yaml:/opt/sensoroni/playbook_placeholder_map.yaml:ro
|
- /opt/so/conf/soc/playbook_placeholder_map.yaml:/opt/sensoroni/playbook_placeholder_map.yaml:ro
|
||||||
- /opt/so/conf/soc/playbook_placeholder_map_custom.yaml:/opt/sensoroni/playbook_placeholder_map_custom.yaml:ro
|
- /opt/so/conf/soc/playbook_placeholder_map_custom.yaml:/opt/sensoroni/playbook_placeholder_map_custom.yaml:ro
|
||||||
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
||||||
@@ -107,6 +106,7 @@ so-soc:
|
|||||||
- file: socclientsroles
|
- file: socclientsroles
|
||||||
- file: socplaybookplaceholdermap
|
- file: socplaybookplaceholdermap
|
||||||
- file: socplaybookplaceholdermapcustom
|
- file: socplaybookplaceholdermapcustom
|
||||||
|
- file: socsigmapipelines
|
||||||
|
|
||||||
delete_so-soc_so-status.disabled:
|
delete_so-soc_so-status.disabled:
|
||||||
file.uncomment:
|
file.uncomment:
|
||||||
|
|||||||
@@ -0,0 +1,477 @@
|
|||||||
|
name: Security Onion ES|QL Pipeline
|
||||||
|
# ES|QL query settings
|
||||||
|
priority: 92
|
||||||
|
transformations:
|
||||||
|
- id: esql_default_index
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val: .ds-logs-*
|
||||||
|
- id: esql_source_metadata
|
||||||
|
type: set_state
|
||||||
|
key: metadata
|
||||||
|
val: "_id, _index, _source"
|
||||||
|
- id: esql_source_keep
|
||||||
|
type: set_state
|
||||||
|
key: keep
|
||||||
|
val: "_id, _index, _source"
|
||||||
|
# unmapped fields read as null instead of failing the query
|
||||||
|
- id: esql_unmapped_fields
|
||||||
|
type: set_state
|
||||||
|
key: unmapped_fields
|
||||||
|
val: nullify
|
||||||
|
# FROM targets per logsource, any namespace; later entries win, correlations get the union
|
||||||
|
- id: esql_index_process_creation
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-system.security-*
|
||||||
|
- .ds-logs-windows.powershell-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-auditd_manager.auditd-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_process_creation_windows
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-system.security-*
|
||||||
|
- .ds-logs-windows.powershell-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_process_creation_linux
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-auditd_manager.auditd-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_process_creation_macos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.process-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: process_creation
|
||||||
|
- id: esql_index_file
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_file_windows
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_file_linux
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_file_macos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.file-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_event
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_delete
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_rename
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_change
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: file_access
|
||||||
|
- id: esql_index_registry
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.registry-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: registry_set
|
||||||
|
- type: logsource
|
||||||
|
category: registry_add
|
||||||
|
- type: logsource
|
||||||
|
category: registry_delete
|
||||||
|
- type: logsource
|
||||||
|
category: registry_event
|
||||||
|
- id: esql_index_library
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.library-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: image_load
|
||||||
|
- type: logsource
|
||||||
|
category: driver_load
|
||||||
|
- id: esql_index_endpoint_network
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_endpoint_network_windows
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_endpoint_network_linux
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_endpoint_network_macos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: network_connection
|
||||||
|
- type: logsource
|
||||||
|
product: macos
|
||||||
|
category: dns_query
|
||||||
|
- id: esql_index_sysmon_only
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: process_access
|
||||||
|
- type: logsource
|
||||||
|
category: create_remote_thread
|
||||||
|
- type: logsource
|
||||||
|
category: pipe_created
|
||||||
|
- type: logsource
|
||||||
|
category: create_stream_hash
|
||||||
|
- type: logsource
|
||||||
|
category: wmi_event
|
||||||
|
- type: logsource
|
||||||
|
category: raw_access_thread
|
||||||
|
- type: logsource
|
||||||
|
category: process_tampering
|
||||||
|
- type: logsource
|
||||||
|
category: sysmon_status
|
||||||
|
- type: logsource
|
||||||
|
category: sysmon_error
|
||||||
|
- type: logsource
|
||||||
|
category: file_executable_detected
|
||||||
|
- type: logsource
|
||||||
|
category: file_block_executable
|
||||||
|
- type: logsource
|
||||||
|
category: file_block_shredding
|
||||||
|
- type: logsource
|
||||||
|
category: clipboard_capture
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: sysmon
|
||||||
|
- id: esql_index_ps_operational
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-windows.powershell_operational-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: ps_script
|
||||||
|
- type: logsource
|
||||||
|
category: ps_module
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: powershell
|
||||||
|
- id: esql_index_ps_classic
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-windows.powershell-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: ps_classic_start
|
||||||
|
- type: logsource
|
||||||
|
category: ps_classic_provider_start
|
||||||
|
- type: logsource
|
||||||
|
category: ps_classic_script
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: powershell-classic
|
||||||
|
- id: esql_index_win_security
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.security-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: security
|
||||||
|
- id: esql_index_win_system
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.system-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: system
|
||||||
|
- id: esql_index_win_application
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.application-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: windows
|
||||||
|
service: application
|
||||||
|
- id: esql_index_linux_auth
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.auth-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: auth
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: sshd
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: sudo
|
||||||
|
- id: esql_index_linux_syslog
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-system.syslog-*
|
||||||
|
- .ds-logs-syslog-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: syslog
|
||||||
|
- id: esql_index_linux_auditd
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-auditd_manager.auditd-*
|
||||||
|
- .ds-logs-auditd.log-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: linux
|
||||||
|
service: auditd
|
||||||
|
- id: esql_index_network
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-zeek-so-*
|
||||||
|
- .ds-logs-suricata-so-*
|
||||||
|
- .ds-logs-suricata.alerts-so-*
|
||||||
|
- .ds-logs-endpoint.events.network-*
|
||||||
|
- .ds-logs-windows.sysmon_operational-*
|
||||||
|
- .ds-logs-sysmon_linux.log-*
|
||||||
|
- .ds-logs-windows.forwarded-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
- id: esql_index_so_network
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-zeek-so-*
|
||||||
|
- .ds-logs-suricata-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_cond_op: or
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: connection
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: dns
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: http
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: file
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: x509
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: ssl
|
||||||
|
- type: logsource
|
||||||
|
category: network
|
||||||
|
service: ssh
|
||||||
|
- type: logsource
|
||||||
|
category: dns
|
||||||
|
- id: esql_index_zeek
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-zeek-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: zeek
|
||||||
|
- id: esql_index_opencanary
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-idh-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: opencanary
|
||||||
|
- id: esql_index_kratos
|
||||||
|
type: set_state
|
||||||
|
key: index
|
||||||
|
val:
|
||||||
|
- .ds-logs-kratos-so-*
|
||||||
|
- .ds-logs-import-so-*
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
product: kratos
|
||||||
|
|
||||||
+10
-12
@@ -14,18 +14,16 @@ transformations:
|
|||||||
- process.args
|
- process.args
|
||||||
- related.ip
|
- related.ip
|
||||||
- dns.resolved_ip
|
- dns.resolved_ip
|
||||||
- id: esql_default_index
|
# Not every source maps .caseless; EQL/ES|QL already match case-insensitively.
|
||||||
type: set_state
|
- id: caseless_to_parent_fields
|
||||||
key: index
|
type: field_name_mapping
|
||||||
val: .ds-logs-*
|
mapping:
|
||||||
- id: esql_source_metadata
|
process.executable.caseless: process.executable
|
||||||
type: set_state
|
process.name.caseless: process.name
|
||||||
key: metadata
|
process.parent.executable.caseless: process.parent.executable
|
||||||
val: "_id, _index, _source"
|
process.parent.name.caseless: process.parent.name
|
||||||
- id: esql_source_keep
|
target.process.executable.caseless: target.process.executable
|
||||||
type: set_state
|
target.process.name.caseless: target.process.name
|
||||||
key: keep
|
|
||||||
val: "_id, _index, _source"
|
|
||||||
- id: baseline_field_name_mapping
|
- id: baseline_field_name_mapping
|
||||||
type: field_name_mapping
|
type: field_name_mapping
|
||||||
mapping:
|
mapping:
|
||||||
@@ -2,13 +2,13 @@ name: Security Onion - Playbook Pipeline
|
|||||||
priority: 97
|
priority: 97
|
||||||
transformations:
|
transformations:
|
||||||
# Route to lowercase-normalized .caseless subfields for case-insensitive matching.
|
# Route to lowercase-normalized .caseless subfields for case-insensitive matching.
|
||||||
# file.path.caseless exists on Defend only (Sysmon file events lack it);
|
|
||||||
# registry.path / dll.path / file.name have no .caseless on any source.
|
# registry.path / dll.path / file.name have no .caseless on any source.
|
||||||
- id: case_insensitive_string_fields
|
- id: case_insensitive_string_fields
|
||||||
type: field_name_mapping
|
type: field_name_mapping
|
||||||
mapping:
|
mapping:
|
||||||
process.executable: process.executable.caseless
|
process.executable: process.executable.caseless
|
||||||
process.parent.executable: process.parent.executable.caseless
|
process.parent.executable: process.parent.executable.caseless
|
||||||
|
process.parent.name: process.parent.name.caseless
|
||||||
process.command_line: process.command_line.caseless
|
process.command_line: process.command_line.caseless
|
||||||
process.parent.command_line: process.parent.command_line.caseless
|
process.parent.command_line: process.parent.command_line.caseless
|
||||||
file.path: file.path.caseless
|
file.path: file.path.caseless
|
||||||
|
|||||||
@@ -861,6 +861,15 @@ soc:
|
|||||||
description: Indicates if the Assistant Module should operate in agentic mode or not. If true, agents can work together to solve tasks.
|
description: Indicates if the Assistant Module should operate in agentic mode or not. If true, agents can work together to solve tasks.
|
||||||
global: True
|
global: True
|
||||||
forcedType: bool
|
forcedType: bool
|
||||||
|
automations:
|
||||||
|
description: Scheduled automations for the Onion AI assistant, managed from the Agent Studio.
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
readonlyUi: True
|
||||||
|
storage: db
|
||||||
|
forcedType: string
|
||||||
|
syntax: json
|
||||||
|
helpLink: onion-ai
|
||||||
agents:
|
agents:
|
||||||
description: Agent definitions for the Onion AI assistant, managed from the Agent Studio. An entry naming a system agent overrides only the fields an admin may change; everything else comes from the built-in definition.
|
description: Agent definitions for the Onion AI assistant, managed from the Agent Studio. An entry naming a system agent overrides only the fields an admin may change; everything else comes from the built-in definition.
|
||||||
global: True
|
global: True
|
||||||
@@ -893,6 +902,9 @@ soc:
|
|||||||
- field: persona
|
- field: persona
|
||||||
label: Persona
|
label: Persona
|
||||||
multiline: True
|
multiline: True
|
||||||
|
- field: maxConcurrentInstances
|
||||||
|
label: Max Concurrent Instances
|
||||||
|
forcedType: int
|
||||||
skills:
|
skills:
|
||||||
description: Skill definitions for the Onion AI assistant, managed from the Agent Studio. An entry naming a system skill overrides only its enabled state and persona addendum; its tool set comes from the built-in definition.
|
description: Skill definitions for the Onion AI assistant, managed from the Agent Studio. An entry naming a system skill overrides only its enabled state and persona addendum; its tool set comes from the built-in definition.
|
||||||
global: True
|
global: True
|
||||||
@@ -996,6 +1008,43 @@ soc:
|
|||||||
description: The number of times to retry extracting memories from a session if errors occur.
|
description: The number of times to retry extracting memories from a session if errors occur.
|
||||||
global: True
|
global: True
|
||||||
advanced: True
|
advanced: True
|
||||||
|
agentSessionMaxTurns:
|
||||||
|
description: Maximum number of model turns a headless agent session, such as one started by an automation, may take before it is stopped. Turns taken by delegated sub-agents count toward this limit. A session that reaches the limit is recorded as failed.
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
forcedType: int
|
||||||
|
agentStreamFlushIntervalMs:
|
||||||
|
description: Milliseconds between writes of a streaming headless agent turn to the database. Lower values show progress sooner in the Agent Studio at the cost of more frequent Elasticsearch updates.
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
forcedType: int
|
||||||
|
agentStreamIdleTimeoutSeconds:
|
||||||
|
description: Seconds a streaming headless agent turn may go without receiving any output before it is abandoned and the session is recorded as failed. Set to 0 to disable the timeout.
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
forcedType: int
|
||||||
|
automationSettings:
|
||||||
|
tickIntervalSeconds:
|
||||||
|
description: How often, in seconds, the automation scheduler checks for automations that are due to run. Must be greater than 0. This value is also the default interval for new automations, however admins can override individual automation intervals to a longer value via the Agent Studio.
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
forcedType: int
|
||||||
|
maxConcurrentItems:
|
||||||
|
description: Maximum number of automation work items that may run at the same time. Additional work items wait in the queue until a running item finishes. User chat sessions count toward this limit but are never held back by it. Set to 0 to disable the limit.
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
forcedType: int
|
||||||
|
maxQueuedItems:
|
||||||
|
description: Maximum number of automation work items that may wait to start. Once the queue is full, no new work items are created until the backlog drains. Set to 0 to disable the limit.
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
|
forcedType: int
|
||||||
|
alertTriageEpoch:
|
||||||
|
description: The earliest alert time the Alert Triage automation will consider. Alerts before this time are never triaged, which keeps a first run on an existing deployment from working through old history. Must be in UTC format (2026-09-24T00:00:00Z).
|
||||||
|
regex: '^(\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(\.\d+)?Z)?$'
|
||||||
|
regexFailureMessage: Expecting date in RFC3339 format (2026-09-24T00:00:00Z)
|
||||||
|
global: True
|
||||||
|
advanced: True
|
||||||
tools:
|
tools:
|
||||||
filterEventFields:
|
filterEventFields:
|
||||||
description: A whitelist of fields to return when OnionAI uses the query_events tool. All other fields are removed. One field per line.
|
description: A whitelist of fields to return when OnionAI uses the query_events tool. All other fields are removed. One field per line.
|
||||||
|
|||||||
Reference in new issue
Block a user