Commit Graph

  • af7f7d0728 Fix file paths DefensiveDepth 2025-11-17 12:00:08 -05:00
  • a7337c95e1 Merge pull request #15234 from Security-Onion-Solutions/reyesj2/pipeline-upd Jorge Reyes 2025-11-17 10:36:10 -06:00
  • 3f7c3326ea Merge pull request #15237 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-17 09:27:53 -05:00
  • bf41de8c14 rm salt keyring and repo file for deb Josh Patterson 2025-11-17 08:56:02 -05:00
  • de4424fab0 remove typos reyesj2 2025-11-14 19:15:51 -06:00
  • 136a829509 detect-sqli deprecated in favor of detect-sql-injection reyesj2 2025-11-14 16:51:00 -06:00
  • bcec999be4 zeek.dns reduce errors reyesj2 2025-11-14 15:42:22 -06:00
  • 7c73b4713f update analyzer pipeline reyesj2 2025-11-14 15:41:54 -06:00
  • 45b4b1d963 ingest zeek analyzer.log + update dpd dashboard with analyzer tag reyesj2 2025-11-14 14:42:58 -06:00
  • fcfd74ec1e zeek.analyzer format json reyesj2 2025-11-14 14:14:54 -06:00
  • 68b0cd7549 rename zeek.dpd zeek.analyzer reyesj2 2025-11-14 14:14:12 -06:00
  • 715d801ce8 format json zeek.dns reyesj2 2025-11-14 13:02:44 -06:00
  • 4a810696e7 Merge pull request #15231 from Security-Onion-Solutions/reyesj2/bond0 Jorge Reyes 2025-11-14 12:12:46 -06:00
  • 6b525a2c21 fix so-setup error duplicate bond0 reyesj2 2025-11-14 11:19:32 -06:00
  • a5d8385f07 Merge pull request #15230 from Security-Onion-Solutions/reyesj2/pipeline-upd Jorge Reyes 2025-11-14 10:43:33 -06:00
  • 211bf7e77b ignore errors on tld script reyesj2 2025-11-14 09:25:19 -06:00
  • 1542b74133 move dns tld fields to its own pipeline reyesj2 2025-11-14 09:24:58 -06:00
  • 431e5abf89 Extract ETPRO key if found DefensiveDepth 2025-11-14 09:39:33 -05:00
  • 4314c79f85 bump suricata dns logging version reyesj2 2025-11-14 08:24:31 -06:00
  • da9717bc79 don't attempt rename if field doesn't exist -- reducing pipeline stat errors reyesj2 2025-11-14 08:15:40 -06:00
  • f047677d8a Check correct files DefensiveDepth 2025-11-14 09:03:08 -05:00
  • 045cf7866c Merge pull request #15225 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-11-14 08:37:37 -05:00
  • 431e0b0780 format suricata.alert json reyesj2 2025-11-13 19:29:50 -06:00
  • e782266caa suricata 8 dns v3 reyesj2 2025-11-13 19:21:31 -06:00
  • a4666b2c08 Merge pull request #15229 from Security-Onion-Solutions/cogburn/toggle-models coreyogburn 2025-11-13 16:13:24 -07:00
  • dcc3206e51 Add Enabled Flag to Models Corey Ogburn 2025-11-13 15:32:28 -07:00
  • 8358b6ea6f Merge pull request #15228 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-13 16:34:43 -05:00
  • d1a66a91c6 Merge pull request #15221 from Security-Onion-Solutions/cogburn/compress-context coreyogburn 2025-11-13 14:33:56 -07:00
  • 7fdcb92614 wait for 200 from registry before proceeding Josh Patterson 2025-11-13 16:30:58 -05:00
  • cec1890b6b pcap annotations Jason Ertel 2025-11-13 16:15:47 -05:00
  • b2606b6094 fix perms DefensiveDepth 2025-11-13 14:10:51 -05:00
  • b1b66045ea Change in prompt wording Corey Ogburn 2025-11-13 12:08:47 -07:00
  • 33b22bf2e4 Shorten Prompt Corey Ogburn 2025-11-13 11:08:53 -07:00
  • 3a38886345 CompressContextPrompt Corey Ogburn 2025-11-12 15:02:42 -07:00
  • 7be70faab6 format json reyesj2 2025-11-13 10:49:37 -06:00
  • 2729fdbea6 Merge pull request #15223 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-13 11:35:43 -05:00
  • bfd08d1d2e Merge pull request #15204 from Security-Onion-Solutions/reyesj2/retention Jorge Reyes 2025-11-13 10:05:49 -06:00
  • 37b3fd9b7b add detections backup DefensiveDepth 2025-11-13 10:41:12 -05:00
  • 573dded921 refactor to hash DefensiveDepth 2025-11-13 09:25:20 -05:00
  • fed75c7b39 use -r with bootstrap to disable script repo Josh Patterson 2025-11-12 19:47:25 -05:00
  • 3427df2a54 update bootstrap-salt to latest Josh Patterson 2025-11-12 18:07:14 -05:00
  • be11c718f6 configure salt then install it Josh Patterson 2025-11-12 18:06:55 -05:00
  • 235dfd78f1 Revert "salt-minion service KillMode to control-group" Josh Patterson 2025-11-12 14:20:28 -05:00
  • 7c8b9b4374 salt-minion service KillMode to control-group Josh Patterson 2025-11-12 12:30:29 -05:00
  • 81d7c313af remove dupe DefensiveDepth 2025-11-12 11:11:01 -05:00
  • 9a6ff75793 Merge remote-tracking branch 'origin/2.4/dev' into idstools-refactor DefensiveDepth 2025-11-12 08:51:51 -05:00
  • 1f24796eba Fix ETPRO check DefensiveDepth 2025-11-12 08:48:47 -05:00
  • 7762faf075 Merge pull request #15219 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-11-12 08:12:23 -05:00
  • 80fbb31372 fix test Jason Ertel 2025-11-11 17:04:19 -05:00
  • 7c45db2295 add support to so-yaml for using yaml file content for values Jason Ertel 2025-11-11 16:57:54 -05:00
  • 0545e1d33b add support to so-yaml for using yaml file content for values Jason Ertel 2025-11-11 16:55:00 -05:00
  • 55bbbdb58d idstools removal refactor DefensiveDepth 2025-11-11 14:34:28 -05:00
  • 3a8a6bf5ff idstools removal refactor DefensiveDepth 2025-11-11 14:12:51 -05:00
  • 13789bc56f idstools removal refactor DefensiveDepth 2025-11-11 13:45:37 -05:00
  • 11518f6eea idstools removal refactor DefensiveDepth 2025-11-11 13:41:32 -05:00
  • 08147e27b0 Merge pull request #15213 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-11-10 19:08:58 -05:00
  • c9153617be Merge pull request #15211 from Security-Onion-Solutions/bravo Josh Patterson 2025-11-10 17:09:43 -05:00
  • 245ceb2d49 suricata defaults and annotation Josh Patterson 2025-11-10 16:40:11 -05:00
  • 4c65975907 reduce pcapMaxCount to fit better with max upload size Jason Ertel 2025-11-10 15:44:05 -05:00
  • dfef7036ce Merge pull request #15209 from Security-Onion-Solutions/TOoSmOotH-patch-1 Mike Reeves 2025-11-10 14:53:00 -05:00
  • 44594ba726 Update defaults.yaml Mike Reeves 2025-11-10 14:24:27 -05:00
  • 1876c4d9df fix var name Josh Patterson 2025-11-10 14:16:16 -05:00
  • a2ff66b5d0 update annotation Josh Patterson 2025-11-10 14:12:20 -05:00
  • e3972dc5af Merge remote-tracking branch 'origin/2.4/dev' into bravo Josh Patterson 2025-11-10 13:28:42 -05:00
  • 18c0f197b2 suricata bpf Josh Patterson 2025-11-10 13:28:19 -05:00
  • 5b371c220c Merge pull request #15207 from Security-Onion-Solutions/reyesj2/forwardnode-sensor Jorge Reyes 2025-11-10 08:46:12 -06:00
  • 78c193f0a2 handle bpf for suricata 8 pcap Josh Patterson 2025-11-07 17:40:24 -05:00
  • 274295bc97 return exit codes Josh Patterson 2025-11-07 17:39:13 -05:00
  • 6c7ef622c1 spaces removed from expected output Josh Patterson 2025-11-07 17:08:33 -05:00
  • da1cac0d53 tls-log, http-log and syslog outputs deprecated https://github.com/Security-Onion-Solutions/securityonion/issues/15203 Josh Patterson 2025-11-06 16:32:55 -05:00
  • a84df14137 rename forward node -> sensor node reyesj2 2025-11-06 15:23:55 -06:00
  • 4a49f9d004 Merge branch '2.4/dev' into reyesj2/retention Jorge Reyes 2025-11-06 14:29:08 -06:00
  • 1eb4b5379a show 30d scheduled deletions or 7d scheduled deletions depending on what historical data is available reyesj2 2025-11-06 14:25:25 -06:00
  • 35c7fc06d7 fix bug showing duplicate backing indices in recommendations reyesj2 2025-11-06 14:24:58 -06:00
  • b69d453a68 typo reyesj2 2025-11-06 14:24:29 -06:00
  • 2f6fb717c1 Merge remote-tracking branch 'origin/2.4/dev' into idstools-refactor DefensiveDepth 2025-11-06 10:38:37 -05:00
  • b7e1989d45 resolve block-size not large enough for max fragmented IP packet size warning Josh Patterson 2025-11-06 09:49:46 -05:00
  • 202b03b32b Merge pull request #15201 from Security-Onion-Solutions/reyesj2-patch-5 Jorge Reyes 2025-11-06 08:18:38 -06:00
  • 1aa871ec94 small fixes reyesj2 2025-11-05 17:55:57 -06:00
  • 4ffbb0bbd9 Merge remote-tracking branch 'origin/2.4/dev' into bravo Josh Patterson 2025-11-05 15:22:11 -05:00
  • f859fe6517 Merge pull request #15192 from Security-Onion-Solutions/securityonion-strelka Jorge Reyes 2025-11-05 08:07:01 -06:00
  • 021b425b8b Merge pull request #15198 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-11-04 16:10:53 -05:00
  • d95122ca01 ensure previous setup outcomes are cleared Jason Ertel 2025-11-04 16:02:39 -05:00
  • 81d3c7351b Merge pull request #15194 from Security-Onion-Solutions/reyesj2/ea-policy Josh Patterson 2025-11-03 17:16:35 -05:00
  • ccb8ffd6eb Update install_agent_grid.sls Josh Patterson 2025-11-03 17:05:48 -05:00
  • 5a8ea57a1b move off of cmd.script with args \ https://github.com/saltstack/salt/issues/68298 reyesj2 2025-11-03 15:31:14 -06:00
  • 60228ec6e6 Merge pull request #15193 from Security-Onion-Solutions/salt300616 Josh Patterson 2025-11-03 16:02:25 -05:00
  • 574703e551 unlock/lock salt-cloud if installed Josh Patterson 2025-11-03 15:39:19 -05:00
  • fa154f1a8f update salt cloud config if configured Josh Patterson 2025-11-03 14:12:19 -05:00
  • 635545630b strelka use single master image reyesj2 2025-11-03 09:36:46 -06:00
  • df8afda999 Merge pull request #15188 from Security-Onion-Solutions/cogburn/multiple-models Mike Reeves 2025-11-03 09:39:16 -05:00
  • f80b090c93 Update limits Corey Ogburn 2025-10-31 14:48:30 -06:00
  • 806173f7e3 Available Models Corey Ogburn 2025-10-31 14:07:11 -06:00
  • 2f6c1b82a6 Merge pull request #15185 from Security-Onion-Solutions/salt300616 Josh Patterson 2025-10-31 09:47:01 -04:00
  • b8c2808abe update salt-cloud profile after new code copied Josh Patterson 2025-10-30 15:09:40 -04:00
  • 9027e4e065 update salt-cloud profile after new code copied Josh Patterson 2025-10-30 14:48:48 -04:00
  • 8ca5276a0e update cloud profile with local and point to new code Josh Patterson 2025-10-30 13:59:08 -04:00
  • ee45a5524d Merge remote-tracking branch 'origin/2.4/dev' into salt300616 Josh Patterson 2025-10-30 13:13:55 -04:00
  • 70d4223a75 update salt-cloud config if salt was upgraded Josh Patterson 2025-10-30 13:13:16 -04:00
  • 7ab2840381 Merge pull request #15182 from Security-Onion-Solutions/reyesj2-influxdb-metrics Jorge Reyes 2025-10-30 12:03:58 -05:00