mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 23:35:37 +02:00
Compare commits
15
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
603949002b | ||
|
|
de63f95ab0 | ||
|
|
a1b76650fb | ||
|
|
0cd8e53832 | ||
|
|
0210ccfcc3 | ||
|
|
517076330a | ||
|
|
ad249782fc | ||
|
|
2eab084358 | ||
|
|
547d2a316b | ||
|
|
1c4eef4224 | ||
|
|
d1114a0dae | ||
|
|
f4b301d71c | ||
|
|
c6e42131b2 | ||
|
|
337dddf596 | ||
|
|
f7dbfba178 |
No files matched your search
@@ -178,6 +178,7 @@ if [[ $EXCLUDE_FALSE_POSITIVE_ERRORS == 'Y' ]]; then
|
|||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Missing ory_kratos_session cookie" # expected WARN log lines indicating invalid auth header
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Missing ory_kratos_session cookie" # expected WARN log lines indicating invalid auth header
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Static assets preprocessor only supports GET and HEAD requests" # expected WARN log lines indicating invalid auth header
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Static assets preprocessor only supports GET and HEAD requests" # expected WARN log lines indicating invalid auth header
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|respondError" # respondError is a function name, output via http middleware as standard request logging
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|respondError" # respondError is a function name, output via http middleware as standard request logging
|
||||||
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|GET /kibana/" # Ignore Kibana queries with triggered words
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
|
if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
elasticsearch:
|
elasticsearch:
|
||||||
enabled: false
|
enabled: false
|
||||||
esheap: '600m'
|
esheap: '600m'
|
||||||
version: 9.4.5
|
version: 9.4.8
|
||||||
index_clean: true
|
index_clean: true
|
||||||
data_retention_method: DLM
|
data_retention_method: DLM
|
||||||
vm:
|
vm:
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ kibana:
|
|||||||
- default
|
- default
|
||||||
- file
|
- file
|
||||||
migrations:
|
migrations:
|
||||||
discardCorruptObjects: "9.4.5"
|
discardCorruptObjects: "9.4.8"
|
||||||
telemetry:
|
telemetry:
|
||||||
enabled: False
|
enabled: False
|
||||||
xpack:
|
xpack:
|
||||||
|
|||||||
@@ -1131,9 +1131,6 @@ post_to_3.2.0() {
|
|||||||
|
|
||||||
### 3.3.0 Scripts ###
|
### 3.3.0 Scripts ###
|
||||||
up_to_3.3.0() {
|
up_to_3.3.0() {
|
||||||
# download 9.4.5 elastic agent packages
|
|
||||||
determine_elastic_agent_upgrade
|
|
||||||
|
|
||||||
# remove existing (patched) elasticsearch index template to match integration naming change
|
# remove existing (patched) elasticsearch index template to match integration naming change
|
||||||
if ! remove_elasticsearch_index_template "so-logs-sentinel_one_cloud_funnel.login" "sentinel_one_cloud_funnel.login changed to sentinel_one_cloud_funnel.logins"; then
|
if ! remove_elasticsearch_index_template "so-logs-sentinel_one_cloud_funnel.login" "sentinel_one_cloud_funnel.login changed to sentinel_one_cloud_funnel.logins"; then
|
||||||
FINAL_MESSAGE_QUEUE+=("WARNING: Unable to automatically remove the so-logs-sentinel_one_cloud_funnel.login index template. This step can be performed manually using the following command:")
|
FINAL_MESSAGE_QUEUE+=("WARNING: Unable to automatically remove the so-logs-sentinel_one_cloud_funnel.login index template. This step can be performed manually using the following command:")
|
||||||
@@ -1166,10 +1163,6 @@ post_to_3.3.0() {
|
|||||||
# Recollate again since some internal DBs were excluded during 3.2.0 soup
|
# Recollate again since some internal DBs were excluded during 3.2.0 soup
|
||||||
recollate_postgres
|
recollate_postgres
|
||||||
|
|
||||||
# Generate 9.4.5 elastic agent installers
|
|
||||||
echo "Regenerating Elastic Agent Installers"
|
|
||||||
/sbin/so-elastic-agent-gen-installers
|
|
||||||
|
|
||||||
telegraf_repair
|
telegraf_repair
|
||||||
|
|
||||||
set_postversion 3.3.0
|
set_postversion 3.3.0
|
||||||
@@ -1178,6 +1171,9 @@ post_to_3.3.0() {
|
|||||||
|
|
||||||
### 3.4.0 Scripts ###
|
### 3.4.0 Scripts ###
|
||||||
up_to_3.4.0() {
|
up_to_3.4.0() {
|
||||||
|
# download 9.4.8 elastic agent packages
|
||||||
|
determine_elastic_agent_upgrade
|
||||||
|
|
||||||
set_soauth_range
|
set_soauth_range
|
||||||
|
|
||||||
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
echo "Removing so-kratos, so-hydra and so-soc so they are recreated on the soauth network."
|
||||||
@@ -1255,6 +1251,10 @@ valid_soauth_range() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
post_to_3.4.0() {
|
post_to_3.4.0() {
|
||||||
|
# Generate 9.4.8 elastic agent installers
|
||||||
|
echo "Regenerating Elastic Agent Installers"
|
||||||
|
/sbin/so-elastic-agent-gen-installers
|
||||||
|
|
||||||
for idx in "metrics-logstash.node-default" "metrics-logstash.stack_monitoring.node-default"; do
|
for idx in "metrics-logstash.node-default" "metrics-logstash.stack_monitoring.node-default"; do
|
||||||
rollover_index "$idx"
|
rollover_index "$idx"
|
||||||
done
|
done
|
||||||
@@ -1535,9 +1535,10 @@ verify_es_version_compatibility() {
|
|||||||
["8.18.4"]="8.18.6 8.18.8 9.0.8"
|
["8.18.4"]="8.18.6 8.18.8 9.0.8"
|
||||||
["8.18.6"]="8.18.8 9.0.8"
|
["8.18.6"]="8.18.8 9.0.8"
|
||||||
["8.18.8"]="9.0.8"
|
["8.18.8"]="9.0.8"
|
||||||
["9.0.8"]="9.3.3 9.3.7 9.4.5"
|
["9.0.8"]="9.3.3 9.3.7 9.4.5 9.4.8"
|
||||||
["9.3.3"]="9.3.7 9.4.5"
|
["9.3.3"]="9.3.7 9.4.5 9.4.8"
|
||||||
["9.3.7"]="9.4.5"
|
["9.3.7"]="9.4.5 9.4.8"
|
||||||
|
["9.4.5"]="9.4.8"
|
||||||
)
|
)
|
||||||
|
|
||||||
# Elasticsearch MUST upgrade through these versions
|
# Elasticsearch MUST upgrade through these versions
|
||||||
|
|||||||
@@ -1821,6 +1821,7 @@ soc:
|
|||||||
cacheExpirationMs: 300000
|
cacheExpirationMs: 300000
|
||||||
casesEnabled: true
|
casesEnabled: true
|
||||||
detectionsEnabled: true
|
detectionsEnabled: true
|
||||||
|
allowExternalMarkdownImages: false
|
||||||
inactiveTools: ['toolUnused']
|
inactiveTools: ['toolUnused']
|
||||||
exportNodeId:
|
exportNodeId:
|
||||||
tools:
|
tools:
|
||||||
|
|||||||
@@ -513,6 +513,10 @@ soc:
|
|||||||
description: Enables or disables the SOC notification module.
|
description: Enables or disables the SOC notification module.
|
||||||
forcedType: bool
|
forcedType: bool
|
||||||
global: True
|
global: True
|
||||||
|
connectionTimeoutSeconds:
|
||||||
|
description: Duration (in seconds) to wait for a response from the remote notification endpoint host before giving up.
|
||||||
|
forcedType: int
|
||||||
|
global: True
|
||||||
postgres:
|
postgres:
|
||||||
host:
|
host:
|
||||||
description: Hostname or IP address of the PostgreSQL server used by SOC. Defaults to the manager hostname.
|
description: Hostname or IP address of the PostgreSQL server used by SOC. Defaults to the manager hostname.
|
||||||
@@ -1025,7 +1029,7 @@ soc:
|
|||||||
forcedType: int
|
forcedType: int
|
||||||
automationSettings:
|
automationSettings:
|
||||||
tickIntervalSeconds:
|
tickIntervalSeconds:
|
||||||
description: How often, in seconds, the automation scheduler checks for automations that are due to run. Must be greater than 0.
|
description: How often, in seconds, the automation scheduler checks for automations that are due to run. Must be greater than 0. This value is also the default interval for new automations, however admins can override individual automation intervals to a longer value via the Agent Studio.
|
||||||
global: True
|
global: True
|
||||||
advanced: True
|
advanced: True
|
||||||
forcedType: int
|
forcedType: int
|
||||||
@@ -1151,6 +1155,10 @@ soc:
|
|||||||
description: Set to true to enable the Detections module in SOC.
|
description: Set to true to enable the Detections module in SOC.
|
||||||
global: True
|
global: True
|
||||||
forcedType: bool
|
forcedType: bool
|
||||||
|
allowExternalMarkdownImages:
|
||||||
|
description: Set to true to let user-written Markdown, such as case descriptions and comments, load images from other servers. Loading an image sends a request to its server, so leave this disabled unless needed; Onion AI output never loads external images.
|
||||||
|
global: True
|
||||||
|
forcedType: bool
|
||||||
inactiveTools:
|
inactiveTools:
|
||||||
description: List of external tools to remove from the SOC UI.
|
description: List of external tools to remove from the SOC UI.
|
||||||
global: True
|
global: True
|
||||||
|
|||||||
@@ -1333,8 +1333,8 @@ DISA STIG for Oracle Linux 9 V1R3.</xccdf-1.2:description>
|
|||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="false"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="false"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
|
||||||
@@ -1935,8 +1935,8 @@ standard DISA STIG for Oracle Linux 9 profile.</xccdf-1.2:description>
|
|||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="false"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="false"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
|
||||||
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
|
<xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
|
||||||
|
|||||||
Reference in new issue
Block a user