Commit Graph

  • cd5483623b update import/eval fleet output config -- try to prevent corrupt dual 'default' output polices from having a successful installation reyesj2 2025-09-18 14:33:34 -05:00
  • faa112eddf update last so-elastic-fleet-common functions reyesj2 2025-09-18 12:18:16 -05:00
  • 422b4bc4c9 Add local custom Playbooks 2.4/playbooklocalrepo DefensiveDepth 2025-09-18 12:22:20 -04:00
  • 6cdd88808a Add local custom Playbooks DefensiveDepth 2025-09-18 12:07:21 -04:00
  • f663f22628 elastic_fleet_integration_id reyesj2 2025-09-18 10:27:54 -05:00
  • 8b07ff453d elastic_fleet_integration_policy_package_version reyesj2 2025-09-18 10:21:07 -05:00
  • 24a0fa3f6d add fleet_api wrapper for curl retries reyesj2 2025-09-18 10:15:57 -05:00
  • a5011b398d add err check and retries to elastic_fleet_integration_policy_package_name and associated scripts reyesj2 2025-09-18 09:39:56 -05:00
  • 5b70398c0a add error check & retries to elastic_fleet_integration_policy_names and associated scripts reyesj2 2025-09-17 15:35:20 -05:00
  • f3aaee1e41 update elastic_fleet_agent_policy_ids scripts already check rc reyesj2 2025-09-17 14:59:41 -05:00
  • d0e875928d add error checking and retries for elastic_fleet_installed_packages & associated script reyesj2 2025-09-17 14:59:13 -05:00
  • 3e16bc8335 Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into reyesj2/es-fleet-patch reyesj2 2025-09-17 14:37:43 -05:00
  • c1d85493df Merge pull request #15045 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2025-09-17 14:23:23 -04:00
  • e01d0f81ea Update 2-4.yml Doug Burks 2025-09-17 14:22:40 -04:00
  • 376d0f3295 Merge pull request #15044 from Security-Onion-Solutions/jertel/wip Jason Ertel 2025-09-17 14:22:02 -04:00
  • 4418623f73 bump version Jason Ertel 2025-09-17 14:20:44 -04:00
  • d1f4e26e29 Merge pull request #15043 from Security-Onion-Solutions/2.4/dev 2.4.180-20250916 Doug Burks 2025-09-17 14:15:32 -04:00
  • 5166db1caa Merge pull request #15042 from Security-Onion-Solutions/2.4/main Doug Burks 2025-09-17 13:13:46 -04:00
  • ff5ad586af Merge pull request #15040 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2025-09-17 13:00:26 -04:00
  • 9e24d21282 remove unused functions from so-elastic-fleet-common reyesj2 2025-09-17 11:41:27 -05:00
  • 5806999f63 add error check & retries to elastic_fleet_bulk_package_install reyesj2 2025-09-17 11:39:06 -05:00
  • 4dae1afe0b Add files via upload Doug Burks 2025-09-17 12:37:29 -04:00
  • 456cad1ada Update DOWNLOAD_AND_VERIFY_ISO.md for 2.4.180 Doug Burks 2025-09-17 12:36:55 -04:00
  • ded520c2c1 Merge remote-tracking branch 'origin/2.4/dev' into idstools-refactor DefensiveDepth 2025-09-17 10:42:43 -04:00
  • a77157391c remove idstools DefensiveDepth 2025-09-17 10:42:05 -04:00
  • 063a2b3348 update elastic_fleet_package_version_check & elastic_fleet_package_install to add error checking + retries. Update related scripts reyesj2 2025-09-16 21:56:53 -05:00
  • bcd2e95fbe add error checking and retries to elastic_fleet_integration_policy_upgrade reyesj2 2025-09-16 21:22:03 -05:00
  • 94e8cd84e6 because of more aggressive exits use salt to rerun script as needed reyesj2 2025-09-16 21:07:33 -05:00
  • 948d72c282 add error check and retry to elastic_fleet_integration_update reyesj2 2025-09-16 21:07:02 -05:00
  • bdeb92ab05 add err check and retries for elastic_fleet_integration_create reyesj2 2025-09-16 20:30:45 -05:00
  • fdb5ad810a add err check and retries around func elastic_fleet_policy_create reyesj2 2025-09-16 20:10:48 -05:00
  • f588a80ec7 fix jq error when indices don't exist (seen on fresh installs when fleet hasn't ever been installed) reyesj2 2025-09-16 10:37:26 -05:00
  • 562b7e54cb Merge pull request #15031 from Security-Onion-Solutions/reyesj2/kfoutput Jorge Reyes 2025-09-15 15:33:48 -05:00
  • 3c847bca8b Merge pull request #15034 from Security-Onion-Solutions/reyesj2/patch31 Jorge Reyes 2025-09-15 15:28:42 -05:00
  • ce2cc26224 run so-elastic-agent-gen-installers reyesj2 2025-09-15 15:25:38 -05:00
  • f3c574679c Merge pull request #15033 from Security-Onion-Solutions/reyesj2/patch31 Jorge Reyes 2025-09-15 15:21:46 -05:00
  • 5da3fed1ce 8.18.6 agent reyesj2 2025-09-15 15:19:43 -05:00
  • e6bcf5db6b fix case of broken kafka output policy when new receiver is added and secret storage was overwritten reyesj2 2025-09-15 13:46:02 -05:00
  • 4d24c57903 Merge pull request #15028 from Security-Onion-Solutions/reyesj2/ea-alerter Jorge Reyes 2025-09-12 14:45:20 -05:00
  • 0606c0a454 agent monitor template & dataset name update reyesj2 2025-09-12 14:26:22 -05:00
  • bb984e05e3 Merge pull request #15026 from Security-Onion-Solutions/vlb2 Josh Patterson 2025-09-12 14:34:18 -04:00
  • b35b0aaf2c Merge pull request #14941 from Security-Onion-Solutions/reyesj2/lgest Jorge Reyes 2025-09-12 13:22:40 -05:00
  • 62f04fa5dd fix role check Josh Patterson 2025-09-12 14:09:30 -04:00
  • d89df5f0dd Merge pull request #15025 from Security-Onion-Solutions/2.4/fixes Josh Brower 2025-09-12 13:44:03 -04:00
  • f0c1922600 Support endpoint logs with no host.ip field DefensiveDepth 2025-09-12 13:31:34 -04:00
  • ab2cdd18ed Support endpoint logs with no host.ip field DefensiveDepth 2025-09-12 13:29:43 -04:00
  • 889bb7ddf4 Merge pull request #15024 from Security-Onion-Solutions/reyesj2/pypy Jorge Reyes 2025-09-12 11:11:34 -05:00
  • a959f90d0b Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/pypy reyesj2 2025-09-12 11:05:54 -05:00
  • a54cd004d6 Merge pull request #15013 from Security-Onion-Solutions/reyesj2/kfoutput Jorge Reyes 2025-09-12 07:34:54 -05:00
  • 5100032fbd Merge pull request #15022 from Security-Onion-Solutions/reyesj2/cfqdn-recv Jorge Reyes 2025-09-11 16:33:41 -05:00
  • 0f235baa7e receiver custom fqdn reyesj2 2025-09-11 16:14:43 -05:00
  • e5660b8c8e Merge pull request #15020 from Security-Onion-Solutions/reyesj2/essuriroll Jorge Reyes 2025-09-11 16:03:30 -05:00
  • 588a1b86d1 suricata metadata index rollover 1d -> 30d reyesj2 2025-09-11 15:46:45 -05:00
  • 46f0afa24b Merge pull request #15019 from Security-Onion-Solutions/reyesj2/ea-alerter Jorge Reyes 2025-09-11 14:34:46 -05:00
  • a7651b2734 lower filestream fingerprint length reyesj2 2025-09-11 14:30:49 -05:00
  • 890f76e45c avoid delay in log ingest after a forced kafka output policy update reyesj2 2025-09-10 20:21:11 -05:00
  • 03892bad5e Merge pull request #15015 from Security-Onion-Solutions/vlb2 Josh Patterson 2025-09-10 14:58:41 -04:00
  • e6eecc93c8 Merge pull request #15012 from Security-Onion-Solutions/reyesj2/ea-alerter Jorge Reyes 2025-09-10 13:19:21 -05:00
  • 8dc0f8d20e fix elastic agent ssl unpack error reyesj2 2025-09-10 12:49:30 -05:00
  • fbdc0c4705 add configurable realert threshold per agent reyesj2 2025-09-10 10:56:09 -05:00
  • d1a2b57aa2 Merge pull request #15011 from Security-Onion-Solutions/hideroni Josh Patterson 2025-09-10 09:15:55 -04:00
  • f5ec1d4b7c don't show sensoroni config changes Josh Patterson 2025-09-10 09:09:02 -04:00
  • 0aa556e375 Merge pull request #15009 from Security-Onion-Solutions/reyesj2/ea-alerter Jorge Reyes 2025-09-09 17:00:39 -05:00
  • d9e86c15bc Merge pull request #15010 from Security-Onion-Solutions/vlb2 Josh Patterson 2025-09-09 17:15:52 -04:00
  • 4107fa006f fix repo files to remove Josh Patterson 2025-09-09 16:51:42 -04:00
  • 29980ea958 offline threshold check reyesj2 2025-09-09 15:39:55 -05:00
  • 8f36d2ec00 update log file name reyesj2 2025-09-09 15:38:50 -05:00
  • 10511b8431 Merge pull request #15008 from Security-Onion-Solutions/cogburn/fix-templates coreyogburn 2025-09-09 14:03:36 -06:00
  • 2535ae953d Fix Index Patterns Corey Ogburn 2025-09-09 14:00:01 -06:00
  • 2f68cd7483 Merge pull request #14991 from Security-Onion-Solutions/cogburn/wip-module coreyogburn 2025-09-09 10:32:06 -06:00
  • 6655276410 force update to kafka-fleet-output-policy reyesj2 2025-09-08 21:13:29 -05:00
  • 9f7bcb0f7d add --force flag to so-kafka-fleet-output-policy & default to using fleet secret storage for client key reyesj2 2025-09-08 21:13:11 -05:00
  • aa43177d8c Fix Setting Name Corey Ogburn 2025-09-05 11:31:08 -06:00
  • 12959d114c added threshold config fields for assistant Matthew Wright 2025-09-04 16:36:51 -04:00
  • 855b489c4b datastream reyesj2 2025-09-04 10:39:57 -05:00
  • 673f9cb544 Responding to Feedback Corey Ogburn 2025-09-04 09:20:50 -06:00
  • 0a3ff47008 Cleanup Annotations Corey Ogburn 2025-09-03 12:12:27 -06:00
  • 834e34128d Non-dev URL Corey Ogburn 2025-08-28 16:03:35 -06:00
  • 73776f8d11 Cleaning up New ES Indexes Corey Ogburn 2025-08-27 12:46:19 -06:00
  • 120e61e45c ClientParams Corey Ogburn 2025-08-26 16:06:14 -06:00
  • fc2d450de0 Update Settings Corey Ogburn 2025-08-26 09:16:04 -06:00
  • cea4eaf081 Updated Assistant Mapping Corey Ogburn 2025-08-06 09:02:43 -06:00
  • b1753f86f9 New Message Structure Corey Ogburn 2025-07-30 13:14:09 -06:00
  • 6323fbf46b Content Object Corey Ogburn 2025-07-30 11:48:27 -06:00
  • ba601c39b3 Rough Go at New Mappings/Settings Corey Ogburn 2025-07-29 11:23:28 -06:00
  • ec27517bdd New Config Values Corey Ogburn 2025-07-11 10:37:50 -06:00
  • 624ec3c93e Merge pull request #15003 from Security-Onion-Solutions/fix/wording Josh Brower 2025-09-08 09:10:43 -04:00
  • f318a84c18 Update so-elastic-fleet-reset Josh Brower 2025-09-08 09:03:33 -04:00
  • 8cca58dba9 Merge pull request #14998 from Security-Onion-Solutions/vlb2 Josh Patterson 2025-09-05 17:13:37 -04:00
  • 6c196ea61a Merge branch '2.4/dev' into vlb2 Jason Ertel 2025-09-05 17:11:10 -04:00
  • 207572f2f9 remove debug added to fail_setup Josh Patterson 2025-09-05 14:16:03 -04:00
  • 4afc986f48 firewall and logstash pipeline for managerhype Josh Patterson 2025-09-05 13:14:47 -04:00
  • ba5d140d4b Merge pull request #14996 from Security-Onion-Solutions/reyesj2/ea-alerter Jorge Reyes 2025-09-05 10:41:59 -05:00
  • 348f9dcaec prevent multiple script instances using file lock reyesj2 2025-09-05 10:01:24 -05:00
  • 915b9e7bd7 use logrotate reyesj2 2025-09-05 09:22:44 -05:00
  • dfec29d18e custom kquery reyesj2 2025-09-04 15:37:28 -05:00
  • 77fef02116 Merge pull request #14994 from Security-Onion-Solutions/vlb2 Josh Patterson 2025-09-04 11:06:31 -04:00
  • 38ef4a6046 pass pillar properly Josh Patterson 2025-09-04 11:02:27 -04:00
  • f3328c41fb Merge pull request #14990 from Security-Onion-Solutions/vlb2 Josh Patterson 2025-09-03 10:37:46 -04:00
  • a007fa6505 Merge remote-tracking branch 'origin/2.4/dev' into vlb2 Josh Patterson 2025-09-03 09:52:49 -04:00