Commit Graph

  • 9738ef382c Upgrade Elastic to 8.17.1 Josh Brower 2025-01-23 08:12:02 -05:00
  • ca0c1170ab Merge pull request #14140 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-01-22 17:43:54 -05:00
  • db9387764d fix issue with first-time api client permission toggling #14140 Jason Ertel 2025-01-22 17:41:04 -05:00
  • e0039a08ef fix forcedType typo reyesj2 2025-01-22 13:57:26 -06:00
  • 09df4a5771 Merge pull request #14139 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-22 13:12:53 -06:00
  • 81ac1ebc08 fixes merging local pillar /global overrides for generated index templates #14139 reyesj2 2025-01-22 13:12:09 -06:00
  • c2f5c2226f Merge pull request #14138 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-22 10:16:30 -06:00
  • d779f7ae7f add back missing component for http_endpoint_x_generic & winlog_x_winglog #14138 reyesj2 2025-01-22 10:13:01 -06:00
  • d26c7e6f9b Merge pull request #14134 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-21 11:00:18 -06:00
  • 6331298eac remove individual <integration>@custom mappings. Moved over to so-fleet_integrations.ip_mappings-1 #14134 reyesj2 2025-01-21 10:49:54 -06:00
  • 76abf37351 Merge remote-tracking branch 'origin/2.4/dev' into foxtrot reyesj2 2025-01-21 09:03:04 -06:00
  • 9db3cd901c update documentation of core functionality m0duspwnens 2025-01-18 10:45:10 -05:00
  • 64c9230423 prevent conflicts with network manager in base vm m0duspwnens 2025-01-18 10:44:44 -05:00
  • 17943ef0db add hypervisor state to hypervisor node m0duspwnens 2025-01-18 08:24:50 -05:00
  • 8ed3f0b1cc change base image path for so-salt-cloud m0duspwnens 2025-01-18 07:30:36 -05:00
  • 7c50a5e17b cloud-init needs to import repo gpg keys so packags can install m0duspwnens 2025-01-17 23:16:18 -05:00
  • c13c85bd2d manager needs ssh config. need -r to ignore bootstrap provided repos m0duspwnens 2025-01-17 22:54:46 -05:00
  • ae01dc9639 manager needs more packages for salt-cloud. change location of priv key for salt-cloud config m0duspwnens 2025-01-17 22:26:39 -05:00
  • a74ed0daf0 fix disabling cloud-init and system shutdown. increase ram/cpu of base vm. shrink disk_size to 6G for testing m0duspwnens 2025-01-17 21:25:40 -05:00
  • 60387651d2 recreate the base vm if any of the cloud init files change m0duspwnens 2025-01-17 20:13:42 -05:00
  • 3a78be68d6 ensure cloud-init is removed m0duspwnens 2025-01-17 20:05:35 -05:00
  • a896332db3 fix deprecation m0duspwnens 2025-01-17 19:49:41 -05:00
  • 54eeb0e327 handle refreshing base image and reinstalling the vm if the source qcow2 image changes m0duspwnens 2025-01-17 19:27:04 -05:00
  • 704e30219a Merge pull request #14124 from Security-Onion-Solutions/reyesj2-patch-8 #14133 Jorge Reyes 2025-01-17 13:33:26 -06:00
  • 1396083b7d use so-elasticsearch-query where possible; simplify suricata.alerts index reroute #14124 reyesj2 2025-01-17 13:29:46 -06:00
  • 7017024ba7 Merge pull request #14123 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-01-17 12:31:42 -05:00
  • 942c1aa3a6 Merge pull request #14126 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-17 11:24:31 -06:00
  • d35ffef503 merge 2.4/dev #14126 reyesj2 2025-01-17 11:23:54 -06:00
  • 7705f45d78 Revert "subgrid config annotations" #14123 Jason Ertel 2025-01-17 12:16:12 -05:00
  • 964bbe6aa5 additional web server security measures Jason Ertel 2025-01-17 12:14:30 -05:00
  • 01a2e4cd4f check for index existence before attemping rollover reyesj2 2025-01-17 09:27:28 -06:00
  • 1f13554bd9 move add virt install and pool creation to images/init. start moving to /nsm/libvirt/ m0duspwnens 2025-01-17 09:43:39 -05:00
  • 9032d7d7bc any suricata.alert with event.imported: true remains in logs-import-so reyesj2 2025-01-16 18:48:31 -06:00
  • d573c0922d add 2.4.111 -> postupgrade check reyesj2 2025-01-16 18:25:06 -06:00
  • 45d3438d18 update ingest pipeline for imported logs reyesj2 2025-01-16 17:33:14 -06:00
  • 4cc3691489 give all nodes access to soc license pillar file m0duspwnens 2025-01-16 17:51:39 -05:00
  • 24eadf2507 add libvirt state to highstate for hypervisor. update allowed_states for libvirt m0duspwnens 2025-01-16 17:46:20 -05:00
  • a274bfb744 license note m0duspwnens 2025-01-16 17:45:07 -05:00
  • 2277c792b9 update feature error logging in so-minion m0duspwnens 2025-01-16 17:13:36 -05:00
  • 61f5614ac9 added logging and error handling so-minion m0duspwnens 2025-01-16 16:57:36 -05:00
  • 6367aed62a reactor needs to match runner function parameter structure m0duspwnens 2025-01-16 14:59:11 -05:00
  • 739f592061 remove old line of code m0duspwnens 2025-01-16 14:06:01 -05:00
  • 116c2b73c1 update gitignore m0duspwnens 2025-01-16 11:16:34 -05:00
  • 58be7ae5db rename from coreol9 or coreol9Small to sool9 m0duspwnens 2025-01-16 11:16:20 -05:00
  • 0e0fb885d2 hypervisor highstate after image creation, not when key accepted m0duspwnens 2025-01-16 11:13:36 -05:00
  • e8546b82f8 default image: sool9. cloud-init add local repo m0duspwnens 2025-01-16 08:43:46 -05:00
  • 837fbab96d minimize packages installed on manager for hyper m0duspwnens 2025-01-15 17:00:06 -05:00
  • cbd2d88000 sync the runners m0duspwnens 2025-01-15 16:59:39 -05:00
  • 6c80fd0e18 Merge pull request #14116 from Security-Onion-Solutions/reyesj2-patch-8 #14125 Jorge Reyes 2025-01-15 14:23:40 -06:00
  • 01ac1cdcca check features and allowed/states m0duspwnens 2025-01-15 14:13:12 -05:00
  • b3b7fb8f29 add null check and move tag lookup to .contains() in global@custom #14116 reyesj2 2025-01-15 12:16:11 -06:00
  • d101fda423 Merge branch '2.4/dev' into jertel/wip Jason Ertel 2025-01-15 11:06:05 -05:00
  • b1d523a4e6 Merge pull request #14113 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-14 15:26:33 -06:00
  • dab56f0882 update fleet-optional-integrations-load #14113 reyesj2 2025-01-14 15:24:59 -06:00
  • 161e8a6c21 ssh config for manager. dont need to create soqemussh user on manager m0duspwnens 2025-01-14 16:21:17 -05:00
  • 2e3c1adc63 runner to setup manager for first hypervisor m0duspwnens 2025-01-14 16:20:21 -05:00
  • 846f2485db Merge pull request #14111 from Security-Onion-Solutions/reyesj2-patch-1 Jorge Reyes 2025-01-14 08:26:43 -06:00
  • 107ca38268 fix http query for "includes" function #14111 Jorge Reyes 2025-01-14 08:24:07 -06:00
  • 35547b476f update http query Jorge Reyes 2025-01-14 08:13:27 -06:00
  • ad765200c3 Merge pull request #14105 from Security-Onion-Solutions/reyesj2/moarzeekparse Jorge Reyes 2025-01-13 11:37:21 -06:00
  • 4618256442 include okta-mappings in so-logs-okta.system index template #14105 reyesj2 2025-01-13 11:32:27 -06:00
  • 323ef1d5d6 add missing lifecycle name to trend_micro_vision_one indices reyesj2 2025-01-13 09:29:22 -06:00
  • a5b1648b68 add missing lifecycle name to crowdstrike indices reyesj2 2025-01-13 09:26:16 -06:00
  • 14c920a258 fix hidden ldap menu subtitle reyesj2 2025-01-13 09:23:32 -06:00
  • 4f92b7ced1 add support for cloudflare_logpush integration reyesj2 2025-01-13 09:23:05 -06:00
  • 5ec2006c9e Merge pull request #14102 from Security-Onion-Solutions/2.4/nav-airgap Josh Brower 2025-01-10 16:20:18 -05:00
  • dcdf31eee8 Fix folder perm #14102 Joshua Brower 2025-01-10 16:15:17 -05:00
  • 3ab1b907e4 subgrid config annotations Jason Ertel 2025-01-10 13:45:42 -05:00
  • e60a1e4357 zeek ldap & ldap_search parsing reyesj2 2025-01-09 16:06:10 -06:00
  • 776afa4a36 setup items on manager when hypervisor joins the grid m0duspwnens 2025-01-09 16:32:41 -05:00
  • 3cac19d498 createvm script without setting network in base domain m0duspwnens 2025-01-09 16:31:51 -05:00
  • 2ba8a87c9d add directory where qcow2 images will be distributed from m0duspwnens 2025-01-09 16:20:56 -05:00
  • d677dc51de add comment about reactors required by salt-master m0duspwnens 2025-01-09 16:19:23 -05:00
  • ebbfcd169c add pkg required for so-qcow2-modify-network m0duspwnens 2025-01-09 16:17:50 -05:00
  • 574d2994d1 use cmd.run instead of cmd.script to resolve issue 64962 m0duspwnens 2025-01-09 16:16:59 -05:00
  • ecc5d64584 move logge def to global m0duspwnens 2025-01-09 16:14:57 -05:00
  • 6888682f92 add comments for raid scripts m0duspwnens 2025-01-09 16:14:01 -05:00
  • 0197cdb33d fix bridge forwarding on hypervisors bridge m0duspwnens 2025-01-09 16:12:33 -05:00
  • 2de1f0464f Merge pull request #14091 from Security-Onion-Solutions/2.4/nav-airgap Josh Brower 2025-01-09 11:59:50 -05:00
  • bcb92b63e3 Move json files to container image #14091 Joshua Brower 2025-01-09 10:58:40 -05:00
  • 412397fa7b Merge pull request #14089 from Security-Onion-Solutions/reyesj2/moarzeekparse Jorge Reyes 2025-01-08 17:45:14 -06:00
  • 0e87351a9c add zeek.quic mappings #14089 reyesj2 2025-01-08 16:18:53 -06:00
  • 71f4150c27 Merge pull request #14013 from Security-Onion-Solutions/2.4/navigator Josh Brower 2025-01-07 13:34:19 -05:00
  • a2caf7425d Add config options #14013 Joshua Brower 2025-01-07 13:22:14 -05:00
  • 6fa11a38ef Update defaults Joshua Brower 2025-01-07 13:14:50 -05:00
  • e3f75215b6 Merge remote-tracking branch 'origin/2.4/dev' into 2.4/navigator Joshua Brower 2025-01-07 13:06:49 -05:00
  • 06983948b0 Merge pull request #14078 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-06 21:34:07 -06:00
  • a21535b0a2 run elasticsearch state to sync templates #14078 reyesj2 2025-01-06 21:33:07 -06:00
  • d14b6e6d7d Merge pull request #14077 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-01-06 17:26:56 -05:00
  • bd96b5d722 invalidate user sessions when an admin changes the user's password #14077 Jason Ertel 2025-01-06 17:23:10 -05:00
  • b431fb1e49 Merge pull request #14075 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-06 15:18:05 -06:00
  • b97619b8f9 Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/es-integ-tmp #14075 reyesj2 2025-01-06 14:44:35 -06:00
  • 3d3f0460fa move addon integration script run to elasticfleet state reyesj2 2025-01-06 14:42:16 -06:00
  • 37d67ee9d0 Merge pull request #14073 from Security-Onion-Solutions/reyesj2/es-integ-tmp Jorge Reyes 2025-01-06 11:23:27 -06:00
  • 0d49dee46e update version to foxtrot #14073 reyesj2 2025-01-06 11:22:51 -06:00
  • 9fe3f6042f Remove individual integrations ip mappings component template. Replaced with global mappings reyesj2 2025-01-06 10:44:22 -06:00
  • cdd4a1ff1f fixes addon integration map file reyesj2 2025-01-03 16:06:22 -06:00
  • 8408a53b82 Merge remote-tracking branch 'origin/2.4/dev' into 2.4/navigator Josh Brower 2025-01-02 16:13:34 -05:00
  • 5969e9accc Merge pull request #14060 from Security-Onion-Solutions/reyesj2/zeekquic Jorge Reyes 2025-01-02 08:13:33 -06:00
  • 927b618ec9 Update Zeek QUIC dashboard, add Hunt query, add quic.server.name as column in Events table #14060 Doug Burks 2025-01-02 06:57:56 -05:00