Commit Graph

  • c4a70b540e Merge pull request #15232 from Security-Onion-Solutions/idstools-refactor 2.4/dev Josh Brower 2025-12-05 12:58:10 -05:00
  • bef85772e3 Merge branch 'idstools-refactor' of https://github.com/Security-Onion-Solutions/securityonion into idstools-refactor #15232 idstools-refactor DefensiveDepth 2025-12-05 12:13:32 -05:00
  • a6b19c4a6c Remove idstools config from manager pillar file DefensiveDepth 2025-12-05 12:13:05 -05:00
  • 44f5e6659b Merge branch '2.4/dev' into idstools-refactor Josh Brower 2025-12-05 10:30:54 -05:00
  • 3f9a9b7019 tweak threshold DefensiveDepth 2025-12-05 10:23:24 -05:00
  • b7ad985c7a Add cron.abset DefensiveDepth 2025-12-05 09:48:46 -05:00
  • dba087ae25 Update version from 2.4.0-delta to 2.4.200 Josh Brower 2025-12-05 09:43:31 -05:00
  • bbc4b1b502 Merge pull request #15241 from Security-Onion-Solutions/reyesj2/advilm Jorge Reyes 2025-12-04 14:43:12 -06:00
  • 9304513ce8 Add support for suricata rules load status DefensiveDepth 2025-12-04 12:26:13 -05:00
  • 0b127582cb 2.4.200 soup changes #15241 reyesj2/advilm reyesj2 2025-12-03 20:49:25 -06:00
  • 6e9b8791c8 Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into reyesj2/advilm reyesj2 2025-12-03 20:27:13 -06:00
  • ef87ad77c3 Merge branch 'reyesj2/advilm' of github.com:Security-Onion-Solutions/securityonion into reyesj2/advilm reyesj2 2025-12-03 20:23:03 -06:00
  • 8477420911 logstash adv config state file reyesj2 2025-12-03 20:10:06 -06:00
  • f5741e318f Merge pull request #15281 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-12-03 16:37:07 -05:00
  • 545060103a Merge remote-tracking branch 'origin/2.4/dev' into bravo bravo Josh Patterson 2025-12-03 16:33:27 -05:00
  • e010b5680a Merge pull request #15280 from Security-Onion-Solutions/reservegid Josh Patterson 2025-12-03 16:24:12 -05:00
  • 8620d3987e add saltgid #15280 Josh Patterson 2025-12-03 15:04:28 -05:00
  • 30487a54c1 skip continue prompt if user cannot actually contine #15281 jertel/wip Jason Ertel 2025-12-03 11:52:10 -05:00
  • f15a39c153 Add historical hashes DefensiveDepth 2025-12-03 11:24:04 -05:00
  • aed27fa111 reserve group ids Josh Patterson 2025-12-03 11:19:46 -05:00
  • 822c411e83 Update version to 2.4.0-delta Josh Brower 2025-12-02 21:24:24 -05:00
  • 41b3ac7554 Backup salt master config DefensiveDepth 2025-12-02 19:58:56 -05:00
  • 23575fdf6c edit actual file DefensiveDepth 2025-12-02 19:19:57 -05:00
  • 52f70dc49a Cleanup idstools DefensiveDepth 2025-12-02 17:40:30 -05:00
  • 79c9749ff7 Merge remote-tracking branch 'origin/2.4/dev' into idstools-refactor DefensiveDepth 2025-12-02 17:40:04 -05:00
  • 8d2701e143 Merge branch '2.4/dev' into reyesj2/advilm Jorge Reyes 2025-12-02 15:42:15 -06:00
  • 877444ac29 cert update is a forced update reyesj2 2025-12-02 15:16:59 -06:00
  • b0d9426f1b automated cert update for kafka fleet output policy reyesj2 2025-12-02 15:11:00 -06:00
  • 18accae47e annotation typo reyesj2 2025-12-02 15:10:29 -06:00
  • 55e3a2c6b6 Merge pull request #15277 from Security-Onion-Solutions/soyamllistremove Josh Patterson 2025-12-02 15:09:47 -05:00
  • ef092e2893 rename to removelistitem #15277 Josh Patterson 2025-12-02 15:01:32 -05:00
  • 89eb95c077 add removefromlist Josh Patterson 2025-12-02 14:46:24 -05:00
  • e871ec358e need additional line bw class Josh Patterson 2025-12-02 14:43:33 -05:00
  • 271a2f74ad Merge pull request #15275 from Security-Onion-Solutions/soyamllistremove Josh Patterson 2025-12-02 14:34:09 -05:00
  • d6bd951c37 add new so-yaml_test for removefromlist #15275 Josh Patterson 2025-12-02 14:31:57 -05:00
  • 8abd4c9c78 Remove idstools files DefensiveDepth 2025-12-02 12:42:15 -05:00
  • 45a8c0acd1 merge 2.4/dev reyesj2 2025-12-02 11:16:08 -06:00
  • c372cd533d Merge remote-tracking branch 'origin/2.4/dev' into idstools-refactor DefensiveDepth 2025-12-01 16:10:22 -05:00
  • 999f83ce57 Create dir earlier DefensiveDepth 2025-12-01 14:21:58 -05:00
  • 6fbed2dd9f Merge pull request #15264 from Security-Onion-Solutions/reyesj2-patch-2 Jorge Reyes 2025-12-01 11:11:25 -06:00
  • 7b4d471d7e cert expire test certtest Josh Patterson 2025-12-01 12:02:55 -05:00
  • 36a6a59d55 renew certs 7 days before expire Josh Patterson 2025-12-01 11:54:10 -05:00
  • 875de88cb4 Merge pull request #15271 from Security-Onion-Solutions/TOoSmOotH-patch-2 Mike Reeves 2025-12-01 10:03:12 -05:00
  • 63bb44886e Add JA4D option to config.zeek.ja4 #15271 TOoSmOotH-patch-2 Mike Reeves 2025-12-01 10:00:42 -05:00
  • bda83a47a2 Remove header DefensiveDepth 2025-11-29 17:45:22 -05:00
  • e96cfd35f7 Refactor for simplicity DefensiveDepth 2025-11-29 17:00:51 -05:00
  • 65c96b2edf Add error handling DefensiveDepth 2025-11-29 16:27:22 -05:00
  • 87477ae4f6 Removed uneeded bind DefensiveDepth 2025-11-29 15:40:10 -05:00
  • 89a9106d79 Add context DefensiveDepth 2025-11-29 15:17:28 -05:00
  • 1284150382 Move to manager init DefensiveDepth 2025-11-27 08:39:19 -05:00
  • edf3c9464f add --certs flag to update certs. Used with --force, to ensure certs are updated even if hosts update isn't needed #15264 reyesj2-patch-2 reyesj2 2025-11-25 16:16:19 -06:00
  • 4bb0a7c9d9 Merge remote-tracking branch 'origin/2.4/dev' into idstools-refactor DefensiveDepth 2025-11-25 13:52:21 -05:00
  • ced3af818c Refactor for Airgap DefensiveDepth 2025-11-25 13:51:50 -05:00
  • cc8fb96047 valid config for number_of_replicas in allocate action includes 0 reyesj2 2025-11-24 11:12:09 -06:00
  • 3339b50daf drop forcemerge when max_num_segements doesn't exist or empty reyesj2 2025-11-21 16:39:45 -06:00
  • 415ea07a4f clean up reyesj2 2025-11-21 16:04:26 -06:00
  • b80ec95fa8 update regex, revert to default will allow setting value back to '' | None reyesj2 2025-11-21 14:41:03 -06:00
  • 99cb51482f unneeded 'set' reyesj2 2025-11-21 14:32:58 -06:00
  • 90638f7a43 Merge branch 'reyesj2/advea' into reyesj2/advilm reyesj2 2025-11-21 14:25:28 -06:00
  • 1fb00c8eb6 update so-elastic-fleet-outputs-update to use advanced output options when set, else empty "". Also trigger update_logstash_outputs() when hash of config_yaml has changed reyesj2 2025-11-21 14:22:42 -06:00
  • 4490ea7635 format EA logstash output adv config items reyesj2 2025-11-21 14:21:17 -06:00
  • bce7a20d8b soc configurable EA logstash output adv settings reyesj2 2025-11-21 14:19:51 -06:00
  • 9c06713f32 Merge pull request #15251 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-21 14:54:30 -05:00
  • 23da0d4ba0 use timestamp in filename to prevent duplicates #15251 Josh Patterson 2025-11-21 14:49:03 -05:00
  • d5f2cfb354 Merge pull request #15248 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-20 17:28:32 -05:00
  • fb5ad4193d indicate base image download start #15248 Josh Patterson 2025-11-20 17:13:36 -05:00
  • 1f5f283c06 update hypervisor annotaion. preinit instead of initialized Josh Patterson 2025-11-20 16:53:55 -05:00
  • cf048030c4 Merge pull request #15247 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-20 16:04:49 -05:00
  • 2d716b44a8 update comment #15247 Josh Patterson 2025-11-20 15:52:21 -05:00
  • d70d652310 Merge pull request #15244 from Security-Onion-Solutions/reyesj2/suricapfile Jorge Reyes 2025-11-20 14:31:43 -06:00
  • c5db7c8752 suricata.capture_file keyword #15244 reyesj2 2025-11-20 14:26:12 -06:00
  • 6f42ff3442 suricata capture_file reyesj2 2025-11-20 14:16:49 -06:00
  • 433dab7376 format json reyesj2 2025-11-20 14:16:10 -06:00
  • 97c1a46013 update annotation for general failure Josh Patterson 2025-11-20 15:08:04 -05:00
  • fbe97221bb set initialized status Josh Patterson 2025-11-20 14:43:09 -05:00
  • 841ce6b6ec update hypervisor annotation for image download or ssh key creation failure Josh Patterson 2025-11-20 13:55:22 -05:00
  • dd0b4c3820 fix failed or hung qcow2 image download Josh Patterson 2025-11-19 15:48:53 -05:00
  • b52dd53e29 advanced ilm actions reyesj2 2025-11-19 13:24:55 -06:00
  • a155f45036 always update annotation / defaults for managed integrations reyesj2 2025-11-19 13:24:29 -06:00
  • b407c68d88 Merge remote-tracking branch 'origin/2.4/dev' into bravo Josh Patterson 2025-11-19 10:23:11 -05:00
  • 5b6a7035af need python_shell for pipes Josh Patterson 2025-11-19 10:22:58 -05:00
  • 12d490ad4a Merge pull request #15240 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-11-19 10:01:03 -05:00
  • 76cbd18d2c communicate to the viewer that OS patches may take some time #15240 Jason Ertel 2025-11-19 09:56:42 -05:00
  • 148ef7ef21 add default ruleset DefensiveDepth 2025-11-18 11:57:30 -05:00
  • 1b55642c86 Refactor rules location DefensiveDepth 2025-11-18 09:58:14 -05:00
  • af7f7d0728 Fix file paths DefensiveDepth 2025-11-17 12:00:08 -05:00
  • a7337c95e1 Merge pull request #15234 from Security-Onion-Solutions/reyesj2/pipeline-upd Jorge Reyes 2025-11-17 10:36:10 -06:00
  • 3f7c3326ea Merge pull request #15237 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-17 09:27:53 -05:00
  • bf41de8c14 rm salt keyring and repo file for deb #15237 Josh Patterson 2025-11-17 08:56:02 -05:00
  • de4424fab0 remove typos reyesj2 2025-11-14 19:15:51 -06:00
  • 136a829509 detect-sqli deprecated in favor of detect-sql-injection #15234 reyesj2 2025-11-14 16:51:00 -06:00
  • bcec999be4 zeek.dns reduce errors reyesj2 2025-11-14 15:42:22 -06:00
  • 7c73b4713f update analyzer pipeline reyesj2 2025-11-14 15:41:54 -06:00
  • 45b4b1d963 ingest zeek analyzer.log + update dpd dashboard with analyzer tag reyesj2 2025-11-14 14:42:58 -06:00
  • fcfd74ec1e zeek.analyzer format json reyesj2 2025-11-14 14:14:54 -06:00
  • 68b0cd7549 rename zeek.dpd zeek.analyzer reyesj2 2025-11-14 14:14:12 -06:00
  • 715d801ce8 format json zeek.dns reyesj2 2025-11-14 13:02:44 -06:00
  • 4a810696e7 Merge pull request #15231 from Security-Onion-Solutions/reyesj2/bond0 Jorge Reyes 2025-11-14 12:12:46 -06:00
  • 6b525a2c21 fix so-setup error duplicate bond0 #15231 reyesj2 2025-11-14 11:19:32 -06:00
  • a5d8385f07 Merge pull request #15230 from Security-Onion-Solutions/reyesj2/pipeline-upd Jorge Reyes 2025-11-14 10:43:33 -06:00