Compare commits

...
Author SHA1 Message Date
Mike Reeves 5d88755429 Increase contextLimitSmall to 1000000 2026-10-09 13:14:26 -04:00
Mike Reeves ecc75ef65a Merge branch '3/dev' into mreeves/soai-haiku 2026-10-09 13:13:45 -04:00
Mike Reeves 037f6d3d4f Update agent mapping for Investigator and DetectionEngineer 2026-10-09 13:09:09 -04:00
Mike Reeves 0cc7e36af5 Reduce contextLimitSmall from 1000000 to 100000 2026-10-09 12:47:46 -04:00
Mike Reeves 946e904434 Merge pull request #16301 from Security-Onion-Solutions/mreeves/alert-triage-agent
Map the AlertTriage and Notifier agents to a model
2026-10-09 12:39:24 -04:00
Mike Reeves b17b596a64 Add Claude Haiku to the SOAI assistant models 2026-10-09 10:11:25 -04:00
Matthew Wright 603949002b Merge pull request #16312 from Security-Onion-Solutions/mwright/md-img-toggle
Add allowExternalMarkdownImages SOC Setting
2026-10-08 12:38:45 -04:00
Matthew Wright de63f95ab0 turn off advanced 2026-10-08 12:38:13 -04:00
Matthew Wright a1b76650fb add external image markdown toggle 2026-10-08 12:10:30 -04:00
Jorge Reyes 0cd8e53832 Merge pull request #16311 from Security-Onion-Solutions/reyesj2-patch-4
regenerate elastic agent installer
2026-10-08 10:13:30 -05:00
Jason Ertel ad249782fc Merge pull request #16310 from Security-Onion-Solutions/jertel/wip
new destination timeout annotation; fix fp
2026-10-08 10:48:26 -04:00
Jason Ertel 2eab084358 new destination timeout annotation; fix fp 2026-10-08 10:46:15 -04:00
Jorge Reyes 547d2a316b Merge pull request #16306 from Security-Onion-Solutions/reyesj2/es948
ES 9.4.8
2026-10-07 16:17:52 -05:00
Mike Reeves b11fc6257a Map the AlertTriage and Notifier agents to a model
SOC disables a built-in agent that has no agentMapping entry, so the new
AlertTriage agent and the Notifier it delegates to need one to run.
2026-10-06 20:43:04 -04:00
Jason Ertel d1114a0dae Merge pull request #16300 from Security-Onion-Solutions/jertel/wip
update tick interval desc
2026-10-06 18:41:48 -04:00
Jason Ertel f4b301d71c update tick interval desc 2026-10-06 18:32:49 -04:00
3 changed files with 30 additions and 3 deletions

No files matched your search

+1
View File
@@ -178,6 +178,7 @@ if [[ $EXCLUDE_FALSE_POSITIVE_ERRORS == 'Y' ]]; then
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Missing ory_kratos_session cookie" # expected WARN log lines indicating invalid auth header
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|Static assets preprocessor only supports GET and HEAD requests" # expected WARN log lines indicating invalid auth header
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|respondError" # respondError is a function name, output via http middleware as standard request logging
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|GET /kibana/" # Ignore Kibana queries with triggered words
fi
if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
+14 -2
View File
@@ -1540,8 +1540,10 @@ soc:
agentic: false
agentMapping:
Orchestrator: sonnet@SOAI
Investigator: gemma@SOAI
DetectionEngineer: gemma@SOAI
Investigator: haiku@SOAI
DetectionEngineer: haiku@SOAI
AlertTriage: haiku@SOAI
Notifier: haiku@SOAI
useMemory: false
useMemoryScanner: false
dontScanBefore: ""
@@ -1821,6 +1823,7 @@ soc:
cacheExpirationMs: 300000
casesEnabled: true
detectionsEnabled: true
allowExternalMarkdownImages: false
inactiveTools: ['toolUnused']
exportNodeId:
tools:
@@ -2813,6 +2816,15 @@ soc:
enabled: true
adapter: SOAI
charsPerTokenEstimate: 4
- id: haiku
displayName: Claude Haiku
origin: USA
contextLimitSmall: 1000000
contextLimitLarge: 1000000
lowBalanceColorAlert: 500000
enabled: true
adapter: SOAI
charsPerTokenEstimate: 4
- id: gemma
displayName: Gemma
origin: USA
+15 -1
View File
@@ -513,6 +513,10 @@ soc:
description: Enables or disables the SOC notification module.
forcedType: bool
global: True
connectionTimeoutSeconds:
description: Duration (in seconds) to wait for a response from the remote notification endpoint host before giving up.
forcedType: int
global: True
postgres:
host:
description: Hostname or IP address of the PostgreSQL server used by SOC. Defaults to the manager hostname.
@@ -937,6 +941,12 @@ soc:
DetectionEngineer:
description: This agent manages detections and their overrides, including tuning noisy rules and authoring rule content.
global: True
AlertTriage:
description: This agent triages alerts autonomously for the Alert Triage automation, ending each run with a report and an assessment of the alert. It can notify through the Notifier but cannot acknowledge alerts or escalate to cases.
global: True
Notifier:
description: This agent sends a single notification on behalf of another agent, such as AlertTriage, and takes no other action.
global: True
useMemory:
description: Enables the Memory system for OnionAI
global: True
@@ -1025,7 +1035,7 @@ soc:
forcedType: int
automationSettings:
tickIntervalSeconds:
description: How often, in seconds, the automation scheduler checks for automations that are due to run. Must be greater than 0.
description: How often, in seconds, the automation scheduler checks for automations that are due to run. Must be greater than 0. This value is also the default interval for new automations, however admins can override individual automation intervals to a longer value via the Agent Studio.
global: True
advanced: True
forcedType: int
@@ -1151,6 +1161,10 @@ soc:
description: Set to true to enable the Detections module in SOC.
global: True
forcedType: bool
allowExternalMarkdownImages:
description: Set to true to let user-written Markdown, such as case descriptions and comments, load images from other servers. Loading an image sends a request to its server, so leave this disabled unless needed; Onion AI output never loads external images.
global: True
forcedType: bool
inactiveTools:
description: List of external tools to remove from the SOC UI.
global: True