Compare commits

..
Author SHA1 Message Date
defensivedepth 90b3d37be6 Clarify req 2026-10-05 08:14:13 -04:00
defensivedepth fcd2f67076 Merge remote-tracking branch 'origin/3/dev' into sigma-pipeline-dir 2026-10-05 07:44:53 -04:00
defensivedepth a9cdd17694 Refactor sigma pipelines 2026-10-02 14:23:57 -04:00
Josh Brower b32aaac290 Merge pull request #16278 from Security-Onion-Solutions/evtx-import-datastreams
EVTX Import cleanup
2026-10-02 13:30:57 -04:00
Josh Brower 1aee3f28dc Merge pull request #16279 from Security-Onion-Solutions/process-caseless-mappings
caseless for non-Defend sources
2026-10-02 13:30:45 -04:00
Josh Patterson 678cb0d5b2 Merge pull request #16286 from Security-Onion-Solutions/fix/docker-29.8.1
upgrade docker 29.8.1 and containerd 2.3.6
2026-10-02 12:05:04 -04:00
Josh Patterson 31c5190a1f add missing comma 2026-10-02 12:03:04 -04:00
Josh Patterson 4ce7a06abe upgrade docker to 29.8.1 and containerd.io to 2.3.6
Latest upstream stable for el9. All four NVRs are already carried by the SO
prod repo, so no repo change is needed -- a so-repo-sync refresh is enough.

Tested on a managersearch and a heavynode (OL 9.8, 3.4.0), upgrading from
29.2.1/2.2.1 both by hand and through the state itself:

- The 29.8.1 RPM ships a byte-identical docker.service, so the full ExecStart
  override in files/iptables-disabled.conf still resolves correctly and the
  hand-written DOCKER/DOCKER-ISOLATION/DOCKER-USER chains came back
  byte-identical on both nodes across upgrade, restart and reboot.
- update_holds re-pinned the versionlock from the old NVRs to the new ones
  without intervention, so soup's path needs no change.
- docker-py 7.1.0 still creates sobridge and soauth (forced by removing both);
  bridges keep their configured kernel names rather than br-<hash>.
- 29.6 changed how dynamic port allocation treats
  net.ipv4.ip_local_reserved_ports; Strelka's 57314 is both published and
  reserved, and docker-proxy still owns it with no bind errors.
- docker ps --format json gained a HealthStatus key. Additive, so so-status,
  so-log-check and so-docker-prune all still parse it.
- containerd 2.3.6 ships the same config.toml, and it is %config(noreplace)
  and unmodified on disk, so no .rpmnew and disabled_plugins=["cri"] survives.
- Zeek/Suricata/Strelka pipeline verified end-to-end with so-test: 111k packets
  replayed, 0 capture loss, file extraction and ES ingest all landed.

The manifest unknown exclusion in so-log-check still fires on 29.8.1 -- it
comes from a tag lookup during the registry-to-registry image copy, not from
the 29.2.1 upgrade the old comment blamed -- so only the comment changes.
2026-10-02 12:03:04 -04:00
defensivedepth 43475452b3 set module 2026-10-01 19:17:52 -04:00
coreyogburn 117548757f Merge pull request #16280 from Security-Onion-Solutions/cogburn/unified-automations
Unified Automations
2026-10-01 10:29:45 -06:00
Corey Ogburn 22bda63847 Unified Automations
Remove the template and mark automations as advanced, readonly, and stored in the DB.
2026-10-01 09:59:12 -06:00
defensivedepth 89f8bcd19f evtx-import fixup 2026-10-01 10:28:10 -04:00
Jason Ertel 563269cbac Merge pull request #16277 from Security-Onion-Solutions/jertel/wip
support empty yaml files
2026-10-01 10:10:55 -04:00
Jason Ertel 523c39d4f2 fix flake 2026-10-01 10:09:20 -04:00
Jason Ertel b4557e973c support empty yaml files 2026-10-01 10:03:39 -04:00
13 changed files with 644 additions and 39 deletions

No files matched your search

+1 -1
View File
@@ -241,7 +241,7 @@ if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # appears in so-dockerregistry log for so-tcpreplay following docker upgrade to 29.2.1-1
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # so-dockerregistry logs a tag lookup miss during image copy; not tied to one docker version
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Could not index event to Elasticsearch.*\"version\" => \"9.0.8\"" # Expected during Elastic upgrade temporarily, as policies referencing older pipelines are updated
fi
+4 -4
View File
@@ -18,10 +18,10 @@ dockergroup:
dockerheldpackages:
pkg.installed:
- pkgs:
- containerd.io: 2.2.1-1.el9
- docker-ce: 3:29.2.1-1.el9
- docker-ce-cli: 1:29.2.1-1.el9
- docker-ce-rootless-extras: 29.2.1-1.el9
- containerd.io: 2.3.6-1.el9
- docker-ce: 3:29.8.1-1.el9
- docker-ce-cli: 1:29.8.1-1.el9
- docker-ce-rootless-extras: 29.8.1-1.el9
- hold: True
- update_holds: True
@@ -29,7 +29,7 @@
"\\.gz$"
],
"include_files": [],
"processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- drop_fields:\n fields: [\"host\"]\n ignore_missing: true\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: system.security\n- add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.security-2.22.3\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: windows.sysmon_operational\n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-windows.sysmon_operational-3.9.0\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: system.application\n - add_fields:\n target: event\n fields:\n dataset: system.application\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.application-2.22.3\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: system.system\n - add_fields:\n target: event\n fields:\n dataset: system.system\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-system.system-2.22.3\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: data_stream\n fields:\n dataset: windows.powershell_operational\n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n - add_fields:\n target: \"@metadata\"\n fields:\n pipeline: logs-windows.powershell_operational-3.9.0\n- add_fields:\n target: data_stream\n fields:\n dataset: import",
"processors": "- dissect:\n tokenizer: \"/nsm/import/%{import.id}/evtx/%{import.file}\"\n field: \"log.file.path\"\n target_prefix: \"\"\n- decode_json_fields:\n fields: [\"message\"]\n target: \"\"\n- add_fields:\n target: event\n fields:\n dataset: windows.forwarded\n module: windows\n imported: true\n- add_fields:\n target: \"@metadata\"\n fields:\n pipeline: import.evtx\n- if:\n equals:\n winlog.channel: 'Security'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.security\n module: system\n- if:\n equals:\n winlog.channel: 'Windows PowerShell'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell\n module: windows\n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-Sysmon/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.sysmon_operational\n module: windows\n imported: true\n- if:\n equals:\n winlog.channel: 'Application'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.application\n module: system\n- if:\n equals:\n winlog.channel: 'System'\n then: \n - add_fields:\n target: event\n fields:\n dataset: system.system\n module: system\n \n- if:\n equals:\n winlog.channel: 'Microsoft-Windows-PowerShell/Operational'\n then: \n - add_fields:\n target: event\n fields:\n dataset: windows.powershell_operational\n module: windows\n- add_fields:\n target: data_stream\n fields:\n type: logs\n dataset: import",
"tags": [
"import"
],
@@ -99,7 +99,7 @@
},
{
"set": {
"if": "ctx.tags != null && ctx.tags.contains('import')",
"if": "ctx.tags != null && ctx.tags.contains('import') && ctx._index != null && ctx._index.startsWith('logs-import-')",
"override": true,
"field": "data_stream.dataset",
"value": "import"
@@ -107,7 +107,7 @@
},
{
"set": {
"if": "ctx.tags != null && ctx.tags.contains('import')",
"if": "ctx.tags != null && ctx.tags.contains('import') && ctx._index != null && ctx._index.startsWith('logs-import-')",
"override": true,
"field": "data_stream.namespace",
"value": "so"
@@ -0,0 +1,31 @@
{
"description" : "import.evtx: normalize imported EVTX and reroute to logs-<dataset>-import",
"processors" : [
{ "script": {
"description": "Host from the event, not the importing node",
"lang": "painless",
"source": "Map host = ['os': ['type': 'windows', 'family': 'windows', 'platform': 'windows']]; def cn = ctx.winlog?.computer_name; if (cn != null && cn.toString().length() > 0) { String name = cn.toString(); int dot = name.indexOf('.'); if (dot > 0) { name = name.substring(0, dot); } host.put('hostname', name); host.put('name', name.toLowerCase()); } ctx.host = host;"
} },
{ "script": {
"description": "String event IDs, as Winlogbeat sends",
"lang": "painless",
"source": "if (ctx.winlog?.event_id != null) { ctx.winlog.event_id = ctx.winlog.event_id.toString(); } if (ctx.event?.code != null) { ctx.event.code = ctx.event.code.toString(); }"
} },
{ "script": {
"description": "Unnamed <Data> to param1..N, as Winlogbeat",
"lang": "painless",
"if": "ctx.winlog?.event_data?.Data instanceof Map && ctx.winlog.event_data.Data['#text'] != null",
"source": "def t = ctx.winlog.event_data.Data['#text']; List vals = t instanceof List ? t : [t]; for (int i = 0; i < vals.size(); i++) { ctx.winlog.event_data['param' + (i + 1)] = vals.get(i); } ctx.winlog.event_data.remove('Data');"
} },
{ "script": {
"description": "String values and LF line endings, as Winlogbeat",
"lang": "painless",
"if": "ctx.winlog?.event_data instanceof Map || ctx.winlog?.user_data instanceof Map",
"source": "String lf = String.valueOf((char) 10); String crlf = String.valueOf((char) 13) + lf; for (def key : ['event_data', 'user_data']) { def m = ctx.winlog[key]; if (!(m instanceof Map)) { continue; } for (def e : m.entrySet()) { def v = e.getValue(); if (v instanceof String) { e.setValue(v.replace(crlf, lf)); } else if (v instanceof Number || v instanceof Boolean) { e.setValue(v.toString()); } } }"
} },
{ "set": { "description": "event.kind, as Winlogbeat", "field": "event.kind", "value": "event", "override": false } },
{ "set": { "field": "data_stream.dataset", "copy_from": "event.dataset", "override": true, "ignore_empty_value": true } },
{ "set": { "field": "data_stream.namespace", "value": "import", "override": true } },
{ "reroute": { "dataset": "{{data_stream.dataset}}", "namespace": "{{data_stream.namespace}}" } }
]
}
+2 -1
View File
@@ -42,7 +42,8 @@ def loadYaml(filename):
try:
with open(filename, "r") as file:
content = file.read()
return yaml.safe_load(content)
loaded = yaml.safe_load(content)
return loaded if loaded is not None else {}
except FileNotFoundError:
print(f"File not found: {filename}", file=sys.stderr)
sys.exit(1)
+97
View File
@@ -95,6 +95,20 @@ class TestRemove(unittest.TestCase):
expected = "key1:\n child1: 123\n child2:\n deep2: ab\nkey2: false\n"
self.assertEqual(actual, expected)
def test_remove_empty_file(self):
filename = "/tmp/so-yaml_test-remove-empty.yaml"
file = open(filename, "w")
file.close()
code = soyaml.remove([filename, "key1"])
self.assertEqual(code, 0)
file = open(filename, "r")
actual = file.read()
file.close()
self.assertEqual(actual, "{}\n")
def test_remove_missing_args(self):
with patch('sys.exit', new=MagicMock()) as sysmock:
with patch('sys.stderr', new=StringIO()) as mock_stderr:
@@ -294,6 +308,36 @@ class TestRemove(unittest.TestCase):
expected = "key1:\n child1: 123\n child2:\n deep1: 45\n deep2: d\nkey2: false\nkey3:\n- e\n- f\n- g\n"
self.assertEqual(actual, expected)
def test_add_empty_file(self):
filename = "/tmp/so-yaml_test-add-empty.yaml"
file = open(filename, "w")
file.close()
code = soyaml.add([filename, "telegraf.output", "BOTH"])
self.assertEqual(code, 0)
file = open(filename, "r")
actual = file.read()
file.close()
expected = "telegraf:\n output: BOTH\n"
self.assertEqual(actual, expected)
def test_add_empty_file_simple(self):
filename = "/tmp/so-yaml_test-add-empty-simple.yaml"
file = open(filename, "w")
file.close()
code = soyaml.add([filename, "telegraf", "BOTH"])
self.assertEqual(code, 0)
file = open(filename, "r")
actual = file.read()
file.close()
expected = "telegraf: BOTH\n"
self.assertEqual(actual, expected)
def test_replace_missing_arg(self):
with patch('sys.exit', new=MagicMock()) as sysmock:
with patch('sys.stderr', new=StringIO()) as mock_stderr:
@@ -346,6 +390,21 @@ class TestRemove(unittest.TestCase):
expected = "key1:\n child1: 123\n child2:\n deep1: 46\nkey2: false\nkey3:\n- e\n- f\n- g\n"
self.assertEqual(actual, expected)
def test_replace_empty_file(self):
filename = "/tmp/so-yaml_test-replace-empty.yaml"
file = open(filename, "w")
file.close()
code = soyaml.replace([filename, "telegraf.output", "BOTH"])
self.assertEqual(code, 0)
file = open(filename, "r")
actual = file.read()
file.close()
expected = "telegraf:\n output: BOTH\n"
self.assertEqual(actual, expected)
def test_convert(self):
self.assertEqual(soyaml.convertType("foo"), "foo")
self.assertEqual(soyaml.convertType("foo.bar"), "foo.bar")
@@ -506,6 +565,18 @@ class TestRemove(unittest.TestCase):
self.assertEqual(result, 2)
self.assertEqual("", mock_stdout.getvalue())
def test_get_empty_file(self):
with patch('sys.stdout', new=StringIO()) as mock_stdout:
with patch('sys.stderr', new=StringIO()) as mock_stderr:
filename = "/tmp/so-yaml_test-get-empty.yaml"
file = open(filename, "w")
file.close()
result = soyaml.get([filename, "telegraf.output"])
self.assertEqual(result, 2)
self.assertEqual("", mock_stdout.getvalue())
self.assertIn("Key 'telegraf.output' not found by so-yaml.py", mock_stderr.getvalue())
def test_get_usage(self):
with patch('sys.exit', new=MagicMock()) as sysmock:
with patch('sys.stderr', new=StringIO()) as mock_stderr:
@@ -991,3 +1062,29 @@ class TestLoadYaml(unittest.TestCase):
soyaml.loadYaml("/tmp/so-yaml_test-unreadable.yaml")
sysmock.assert_called_with(1)
self.assertIn("Error reading file", mock_stderr.getvalue())
def test_load_yaml_empty_file(self):
filename = "/tmp/so-yaml_test-load-empty.yaml"
file = open(filename, "w")
file.close()
result = soyaml.loadYaml(filename)
self.assertEqual(result, {})
def test_load_yaml_whitespace_only(self):
filename = "/tmp/so-yaml_test-load-whitespace.yaml"
file = open(filename, "w")
file.write(" \n\n \n")
file.close()
result = soyaml.loadYaml(filename)
self.assertEqual(result, {})
def test_load_yaml_comments_only(self):
filename = "/tmp/so-yaml_test-load-comments.yaml"
file = open(filename, "w")
file.write("# Just a comment\n# Another comment\n")
file.close()
result = soyaml.loadYaml(filename)
self.assertEqual(result, {})
+1 -1
View File
@@ -9,7 +9,7 @@
'epel-testing.repo',
'saltstack.repo',
'salt-latest.repo',
'wazuh.repo'
'wazuh.repo',
'Rocky-Base.repo',
'Rocky-CR.repo',
'Rocky-Debuginfo.repo',
+18 -6
View File
@@ -118,21 +118,33 @@ crondetectionsbackup:
- month: '*'
- dayweek: '*'
# sigma-cli only loads *.yml from the pipelines dir
socsigmafinalpipeline:
file.managed:
- name: /opt/so/conf/soc/sigma_final_pipeline.yaml
- name: /opt/so/conf/soc/sigma_pipelines/sigma_final_pipeline.yml
- source: salt://soc/files/soc/sigma_final_pipeline.yaml
- user: 939
- group: 939
- mode: 600
- makedirs: True
socsigmasopipeline:
file.managed:
- name: /opt/so/conf/soc/sigma_so_pipeline.yaml
- source: salt://soc/files/soc/sigma_so_pipeline.yaml
# sigma-cli loads every *.yml here; clean removes anything else
socsigmapipelines:
file.recurse:
- name: /opt/so/conf/soc/sigma_pipelines
- source: salt://soc/files/soc/sigma_pipelines
- user: 939
- group: 939
- mode: 600
- file_mode: 600
- clean: True
- require:
- file: socsigmafinalpipeline
socsigmapipelinesold:
file.absent:
- names:
- /opt/so/conf/soc/sigma_final_pipeline.yaml
- /opt/so/conf/soc/sigma_so_pipeline.yaml
socsigmaplaybookpipeline:
file.managed:
+2 -2
View File
@@ -47,9 +47,8 @@ so-soc:
{% endif %}
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
- /opt/so/conf/soc/sigma_so_pipeline.yaml:/opt/sensoroni/sigma_so_pipeline.yaml:ro
- /opt/so/conf/soc/sigma_pipelines:/opt/sensoroni/sigma_pipelines:ro
- /opt/so/conf/soc/sigma_playbook_pipeline.yaml:/opt/sensoroni/sigma_playbook_pipeline.yaml:ro
- /opt/so/conf/soc/sigma_final_pipeline.yaml:/opt/sensoroni/sigma_final_pipeline.yaml:ro
- /opt/so/conf/soc/playbook_placeholder_map.yaml:/opt/sensoroni/playbook_placeholder_map.yaml:ro
- /opt/so/conf/soc/playbook_placeholder_map_custom.yaml:/opt/sensoroni/playbook_placeholder_map_custom.yaml:ro
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
@@ -107,6 +106,7 @@ so-soc:
- file: socclientsroles
- file: socplaybookplaceholdermap
- file: socplaybookplaceholdermapcustom
- file: socsigmapipelines
delete_so-soc_so-status.disabled:
file.uncomment:
@@ -0,0 +1,477 @@
name: Security Onion ES|QL Pipeline
# ES|QL query settings
priority: 92
transformations:
- id: esql_default_index
type: set_state
key: index
val: .ds-logs-*
- id: esql_source_metadata
type: set_state
key: metadata
val: "_id, _index, _source"
- id: esql_source_keep
type: set_state
key: keep
val: "_id, _index, _source"
# unmapped fields read as null instead of failing the query
- id: esql_unmapped_fields
type: set_state
key: unmapped_fields
val: nullify
# FROM targets per logsource, any namespace; later entries win, correlations get the union
- id: esql_index_process_creation
type: set_state
key: index
val:
- .ds-logs-endpoint.events.process-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-system.security-*
- .ds-logs-windows.powershell-*
- .ds-logs-windows.forwarded-*
- .ds-logs-sysmon_linux.log-*
- .ds-logs-auditd_manager.auditd-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
category: process_creation
- id: esql_index_process_creation_windows
type: set_state
key: index
val:
- .ds-logs-endpoint.events.process-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-system.security-*
- .ds-logs-windows.powershell-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: windows
category: process_creation
- id: esql_index_process_creation_linux
type: set_state
key: index
val:
- .ds-logs-endpoint.events.process-*
- .ds-logs-sysmon_linux.log-*
- .ds-logs-auditd_manager.auditd-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: linux
category: process_creation
- id: esql_index_process_creation_macos
type: set_state
key: index
val:
- .ds-logs-endpoint.events.process-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: macos
category: process_creation
- id: esql_index_file
type: set_state
key: index
val:
- .ds-logs-endpoint.events.file-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-sysmon_linux.log-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: file_event
- type: logsource
category: file_delete
- type: logsource
category: file_rename
- type: logsource
category: file_change
- type: logsource
category: file_access
- id: esql_index_file_windows
type: set_state
key: index
val:
- .ds-logs-endpoint.events.file-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
product: windows
category: file_event
- type: logsource
product: windows
category: file_delete
- type: logsource
product: windows
category: file_rename
- type: logsource
product: windows
category: file_change
- type: logsource
product: windows
category: file_access
- id: esql_index_file_linux
type: set_state
key: index
val:
- .ds-logs-endpoint.events.file-*
- .ds-logs-sysmon_linux.log-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
product: linux
category: file_event
- type: logsource
product: linux
category: file_delete
- type: logsource
product: linux
category: file_rename
- type: logsource
product: linux
category: file_change
- type: logsource
product: linux
category: file_access
- id: esql_index_file_macos
type: set_state
key: index
val:
- .ds-logs-endpoint.events.file-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
product: macos
category: file_event
- type: logsource
product: macos
category: file_delete
- type: logsource
product: macos
category: file_rename
- type: logsource
product: macos
category: file_change
- type: logsource
product: macos
category: file_access
- id: esql_index_registry
type: set_state
key: index
val:
- .ds-logs-endpoint.events.registry-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: registry_set
- type: logsource
category: registry_add
- type: logsource
category: registry_delete
- type: logsource
category: registry_event
- id: esql_index_library
type: set_state
key: index
val:
- .ds-logs-endpoint.events.library-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: image_load
- type: logsource
category: driver_load
- id: esql_index_endpoint_network
type: set_state
key: index
val:
- .ds-logs-endpoint.events.network-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-sysmon_linux.log-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: network_connection
- type: logsource
category: dns_query
- id: esql_index_endpoint_network_windows
type: set_state
key: index
val:
- .ds-logs-endpoint.events.network-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
product: windows
category: network_connection
- type: logsource
product: windows
category: dns_query
- id: esql_index_endpoint_network_linux
type: set_state
key: index
val:
- .ds-logs-endpoint.events.network-*
- .ds-logs-sysmon_linux.log-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
product: linux
category: network_connection
- type: logsource
product: linux
category: dns_query
- id: esql_index_endpoint_network_macos
type: set_state
key: index
val:
- .ds-logs-endpoint.events.network-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
product: macos
category: network_connection
- type: logsource
product: macos
category: dns_query
- id: esql_index_sysmon_only
type: set_state
key: index
val:
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: process_access
- type: logsource
category: create_remote_thread
- type: logsource
category: pipe_created
- type: logsource
category: create_stream_hash
- type: logsource
category: wmi_event
- type: logsource
category: raw_access_thread
- type: logsource
category: process_tampering
- type: logsource
category: sysmon_status
- type: logsource
category: sysmon_error
- type: logsource
category: file_executable_detected
- type: logsource
category: file_block_executable
- type: logsource
category: file_block_shredding
- type: logsource
category: clipboard_capture
- type: logsource
product: windows
service: sysmon
- id: esql_index_ps_operational
type: set_state
key: index
val:
- .ds-logs-windows.powershell_operational-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: ps_script
- type: logsource
category: ps_module
- type: logsource
product: windows
service: powershell
- id: esql_index_ps_classic
type: set_state
key: index
val:
- .ds-logs-windows.powershell-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: ps_classic_start
- type: logsource
category: ps_classic_provider_start
- type: logsource
category: ps_classic_script
- type: logsource
product: windows
service: powershell-classic
- id: esql_index_win_security
type: set_state
key: index
val:
- .ds-logs-system.security-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: windows
service: security
- id: esql_index_win_system
type: set_state
key: index
val:
- .ds-logs-system.system-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: windows
service: system
- id: esql_index_win_application
type: set_state
key: index
val:
- .ds-logs-system.application-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: windows
service: application
- id: esql_index_linux_auth
type: set_state
key: index
val:
- .ds-logs-system.auth-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
product: linux
service: auth
- type: logsource
product: linux
service: sshd
- type: logsource
product: linux
service: sudo
- id: esql_index_linux_syslog
type: set_state
key: index
val:
- .ds-logs-system.syslog-*
- .ds-logs-syslog-so-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: linux
service: syslog
- id: esql_index_linux_auditd
type: set_state
key: index
val:
- .ds-logs-auditd_manager.auditd-*
- .ds-logs-auditd.log-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: linux
service: auditd
- id: esql_index_network
type: set_state
key: index
val:
- .ds-logs-zeek-so-*
- .ds-logs-suricata-so-*
- .ds-logs-suricata.alerts-so-*
- .ds-logs-endpoint.events.network-*
- .ds-logs-windows.sysmon_operational-*
- .ds-logs-sysmon_linux.log-*
- .ds-logs-windows.forwarded-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
category: network
- id: esql_index_so_network
type: set_state
key: index
val:
- .ds-logs-zeek-so-*
- .ds-logs-suricata-so-*
- .ds-logs-import-so-*
rule_cond_op: or
rule_conditions:
- type: logsource
category: network
service: connection
- type: logsource
category: network
service: dns
- type: logsource
category: network
service: http
- type: logsource
category: network
service: file
- type: logsource
category: network
service: x509
- type: logsource
category: network
service: ssl
- type: logsource
category: network
service: ssh
- type: logsource
category: dns
- id: esql_index_zeek
type: set_state
key: index
val:
- .ds-logs-zeek-so-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: zeek
- id: esql_index_opencanary
type: set_state
key: index
val:
- .ds-logs-idh-so-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: opencanary
- id: esql_index_kratos
type: set_state
key: index
val:
- .ds-logs-kratos-so-*
- .ds-logs-import-so-*
rule_conditions:
- type: logsource
product: kratos
@@ -14,18 +14,6 @@ transformations:
- process.args
- related.ip
- dns.resolved_ip
- id: esql_default_index
type: set_state
key: index
val: .ds-logs-*
- id: esql_source_metadata
type: set_state
key: metadata
val: "_id, _index, _source"
- id: esql_source_keep
type: set_state
key: keep
val: "_id, _index, _source"
# Not every source maps .caseless; EQL/ES|QL already match case-insensitively.
- id: caseless_to_parent_fields
type: field_name_mapping
+8 -9
View File
@@ -862,15 +862,14 @@ soc:
global: True
forcedType: bool
automations:
template:
description: Scheduled automations for the Onion AI assistant, managed from the Agent Studio. Each automation is stored under its own generated ID so its history and rollback are independent of every other automation.
global: True
advanced: False
readonlyUi: True
duplicates: True
forcedType: string
syntax: json
helpLink: onion-ai
description: Scheduled automations for the Onion AI assistant, managed from the Agent Studio.
global: True
advanced: True
readonlyUi: True
storage: db
forcedType: string
syntax: json
helpLink: onion-ai
agents:
description: Agent definitions for the Onion AI assistant, managed from the Agent Studio. An entry naming a system agent overrides only the fields an admin may change; everything else comes from the built-in definition.
global: True