Commit Graph

  • 9730c4561d add elasticsearch pillar to manager m0duspwnens 2020-07-10 14:08:39 -04:00
  • 358ef78cd9 Do not stop curator since imported data will now be placed into a longer term so-import index Jason Ertel 2020-07-10 13:58:46 -04:00
  • 811bbb4cb0 Require sudo to run an import Jason Ertel 2020-07-10 12:49:12 -04:00
  • 33375a0809 Merge pull request #973 from Security-Onion-Solutions/fix/curator_logsizelimit weslambert 2020-07-10 13:57:58 -04:00
  • 6e99ca600f Move zeek_clean to so-sensor-clean #973 Wes Lambert 2020-07-10 17:56:40 +00:00
  • 5eb33d5ac7 Logstash Import and Template Assignment Mike Reeves 2020-07-10 13:53:55 -04:00
  • 24b8f81e38 merge with dev and resolve conflicts m0duspwnens 2020-07-10 12:20:14 -04:00
  • bbef7955b2 Update eval.sls Mike Reeves 2020-07-10 11:36:46 -04:00
  • 9da4dd0ac9 Merge pull request #971 from Security-Onion-Solutions/feature/espillarz Mike Reeves 2020-07-10 11:35:24 -04:00
  • c656bec9c0 Merge branch 'dev' into feature/espillarz #971 Mike Reeves 2020-07-10 11:35:12 -04:00
  • 0a1b5f29eb merge with dev and resolv conflicts m0duspwnens 2020-07-10 10:48:49 -04:00
  • 1f48dc765e merge with dev and resolv conflicts m0duspwnens 2020-07-10 10:36:48 -04:00
  • 3706aa76d8 Add jinja extension Mike Reeves 2020-07-10 10:35:31 -04:00
  • 2ce254dfb0 add new DPD query to Hunt Doug Burks 2020-07-10 06:00:36 -04:00
  • f5114c034d change Log Type query in Hunt to include event.dataset in the groupby Doug Burks 2020-07-10 05:52:10 -04:00
  • 1a6c4c12b4 Fix elasticsearch yaml Mike Reeves 2020-07-09 21:56:32 -04:00
  • 6bfd777d25 Enabled elastalert log Jason Ertel 2020-07-09 21:34:35 -04:00
  • 8ef18f9044 Fiz pillar Mike Reeves 2020-07-09 18:51:59 -04:00
  • b2e7a4221c master to manager for ssl signing policy m0duspwnens 2020-07-09 17:19:17 -04:00
  • 9a7035326d Update Logstash pillar Mike Reeves 2020-07-09 17:09:20 -04:00
  • 9c2dcd2318 fix reference to master grain m0duspwnens 2020-07-09 17:06:44 -04:00
  • ad6c9e7fe9 recurse actions for curator Mike Reeves 2020-07-09 16:58:35 -04:00
  • 6094d19b0b Make hot default Mike Reeves 2020-07-09 16:54:31 -04:00
  • 3c6465bb7f ES Jinja the config Mike Reeves 2020-07-09 16:42:39 -04:00
  • 33179141a1 Enable PCAP pivots from imports Jason Ertel 2020-07-09 16:11:33 -04:00
  • 5ca3ecf4bd fix reference to master grain m0duspwnens 2020-07-09 15:42:39 -04:00
  • 7b91704894 Merge pull request #970 from Security-Onion-Solutions/defensivedepth-patch-2-host-pillar Josh Brower 2020-07-09 15:32:38 -04:00
  • 58d290aa57 Update so-setup #970 Josh Brower 2020-07-09 15:32:19 -04:00
  • c5eff1d89e [feat][WIP] Add option to run so-allow -a <ip/cidr> during setup William Wernert 2020-07-09 14:47:55 -04:00
  • 206bdc60f3 Merge pull request #967 from Security-Onion-Solutions/feature/low-level-alerts Josh Brower 2020-07-09 13:56:31 -04:00
  • bdd0f64462 add period m0duspwnens 2020-07-09 13:54:48 -04:00
  • 52f7111e1d Feature - low level alerts #967 Josh Brower 2020-07-09 13:53:55 -04:00
  • aea3099df6 change wording m0duspwnens 2020-07-09 13:52:31 -04:00
  • 823ee42120 https://github.com/Security-Onion-Solutions/securityonion/issues/404 m0duspwnens 2020-07-09 13:45:24 -04:00
  • 7c6677916a Curator actions Mike Reeves 2020-07-09 12:56:29 -04:00
  • 357efac873 Add index specific curator settings Mike Reeves 2020-07-09 12:10:53 -04:00
  • ca20279a09 Add curator to static pillar Mike Reeves 2020-07-09 12:00:07 -04:00
  • 96bcf9d9f3 Add temaplte files per index Mike Reeves 2020-07-09 11:51:55 -04:00
  • 3cf31e2460 https://github.com/Security-Onion-Solutions/securityonion/issues/404 m0duspwnens 2020-07-09 11:27:06 -04:00
  • 9c2f7d574d Add ES settings to pillar Mike Reeves 2020-07-09 11:19:02 -04:00
  • 2c32c24bf0 Fix logstash logic Mike Reeves 2020-07-09 09:16:48 -04:00
  • 2bfdb09674 Merge pull request #966 from Security-Onion-Solutions/issue/959 Josh Patterson 2020-07-09 08:52:30 -04:00
  • d539f1ddf8 fix typo #966 m0duspwnens 2020-07-09 08:51:53 -04:00
  • 8dfafffef0 remove duplicate line for message2.conn_uids Doug Burks 2020-07-09 06:44:08 -04:00
  • 818f7f56b2 Merge pull request #965 from Security-Onion-Solutions/feature/add_gcp_check weslambert 2020-07-08 23:31:37 -04:00
  • c01047fad2 Add /dev/null #965 weslambert 2020-07-08 23:30:50 -04:00
  • 889ba67d85 Move EC2 to more generic cloud verbiage weslambert 2020-07-08 23:27:46 -04:00
  • ce00d829e1 Move EC2 to more generic cloud verbiage and check for GCP weslambert 2020-07-08 23:26:48 -04:00
  • 49e5cb311e [fix][WIP] set ssl cert for redirect 443 server block William Wernert 2020-07-08 16:05:48 -04:00
  • 533ed395e7 [fix][WIP] Remove ssl and http2 from redirect server block William Wernert 2020-07-08 15:59:31 -04:00
  • a0ffe26334 [fix] Only one default_server is allowed per port William Wernert 2020-07-08 15:56:36 -04:00
  • 67fb46f519 Merge pull request #963 from Security-Onion-Solutions/fix/curator_logsizelimit weslambert 2020-07-08 15:40:54 -04:00
  • 99ce77e9bd Merge pull request #962 from Security-Onion-Solutions/issue/959 Josh Patterson 2020-07-08 15:39:22 -04:00
  • f2cea273b6 Add standalone evaluation for log_size_limit #963 Wes Lambert 2020-07-08 19:39:14 +00:00
  • 59061926f0 pillarize yum.conf installonly_limit and proxy #962 m0duspwnens 2020-07-08 15:37:20 -04:00
  • 0c3e35c55e [fix] correct jinja template syntax William Wernert 2020-07-08 14:30:27 -04:00
  • cfd1b82e00 [refactor] Redirect to correct url_base + combine configs William Wernert 2020-07-08 13:49:33 -04:00
  • beda67d2a9 Merge pull request #955 from Security-Onion-Solutions/fix/strelka_message_drop weslambert 2020-07-08 10:56:06 -04:00
  • 4cf31e1ee7 Drop message field and original exiftool keys #955 weslambert 2020-07-08 10:55:40 -04:00
  • fef803a86c Add ignore_failure to geoip processor calls #942 Doug Burks 2020-07-08 10:41:14 -04:00
  • 3352eb77e9 Merge pull request #954 from Security-Onion-Solutions/issue/825 Josh Patterson 2020-07-08 09:53:18 -04:00
  • 5f68542241 add pillar example for filebeat inputs/output #954 m0duspwnens 2020-07-08 09:52:25 -04:00
  • 9c11de5455 Merge pull request #953 from Security-Onion-Solutions/fix/zeek_files_uid weslambert 2020-07-08 09:40:04 -04:00
  • b25a3b6986 Rename uids to uid #953 weslambert 2020-07-08 09:39:37 -04:00
  • 88b7a31195 Merge pull request #952 from Security-Onion-Solutions/fix/wazuh_authdport weslambert 2020-07-08 09:26:28 -04:00
  • 987acaeb7b Add Wazuh Authd Port #952 weslambert 2020-07-08 09:26:04 -04:00
  • 10cbc96f48 Merge pull request #948 from Security-Onion-Solutions/fix/fleet Josh Brower 2020-07-07 20:56:43 -04:00
  • b4b122dbd9 Fleet setup bugfix #948 Josh Brower 2020-07-07 20:55:47 -04:00
  • 4231fb1d1a Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev William Wernert 2020-07-07 17:38:30 -04:00
  • 72a98b33a7 [fix] Change test to check value of $SO_ERROR William Wernert 2020-07-07 17:38:23 -04:00
  • cdce804c9f Update 9700_output_strelka.conf.jinja Mike Reeves 2020-07-07 17:36:49 -04:00
  • 2992938596 Merge pull request #947 from Security-Onion-Solutions/fix/strelka_exiftool weslambert 2020-07-07 17:13:57 -04:00
  • fc377cd3c1 Merge pull request #945 from Security-Onion-Solutions/issue/929 Mike Reeves 2020-07-07 16:31:33 -04:00
  • 1954a389b0 Update so-functions Mike Reeves 2020-07-07 16:12:07 -04:00
  • 9576151993 Merge pull request #944 from Security-Onion-Solutions/issue/937 Mike Reeves 2020-07-07 16:07:47 -04:00
  • 3b50ce032a Add fields for exiftool keys #947 Wes Lambert 2020-07-07 20:02:09 +00:00
  • 07cc89e4d6 Merge pull request #943 from Security-Onion-Solutions/issue/825 Josh Patterson 2020-07-07 15:51:08 -04:00
  • fff713db85 changes for https://github.com/Security-Onion-Solutions/securityonion/issues/825 #943 m0duspwnens 2020-07-07 15:48:47 -04:00
  • eccfaf94fb Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion into issue/937 #944 Mike Reeves 2020-07-07 15:10:12 -04:00
  • f4f189cc50 correct capitalization of true Jason Ertel 2020-07-07 14:28:11 -04:00
  • 640cfee3e1 Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev William Wernert 2020-07-07 13:12:50 -04:00
  • 3815f7e58e [refactor] Edit logic around setup failure/completion William Wernert 2020-07-07 13:12:46 -04:00
  • 1d47cec928 [refactor] Move install_cleanup outside of whiptail functions William Wernert 2020-07-07 13:02:58 -04:00
  • 0b995533ea [refactor] Only notify user of error found during setup William Wernert 2020-07-07 13:01:29 -04:00
  • ec89ab39ac Update 9999_output_redis.conf.jinja Mike Reeves 2020-07-07 11:56:45 -04:00
  • 34e06ecde1 Merge pull request #940 from Security-Onion-Solutions/feature/strelka_fuid weslambert 2020-07-07 11:01:09 -04:00
  • e0570e1db7 Add Zeek FUID for Strelka records #940 Wes Lambert 2020-07-07 15:00:01 +00:00
  • c59096d9bd rename node pillar to elasticsearch Mike Reeves 2020-07-07 10:42:12 -04:00
  • 62cc02301e Do not attempt to install a plugin or bc command if already exists Jason Ertel 2020-07-07 10:28:15 -04:00
  • d334d5ab83 Merge pull request #938 from Security-Onion-Solutions/fix/strelka_filebeat weslambert 2020-07-07 09:48:19 -04:00
  • 2fdd5fd77b Fix pillar reference for Strelka/FB #938 Wes Lambert 2020-07-07 13:46:57 +00:00
  • e2c9184b29 [fix][refactor] Don't use relative path in so-setup-network William Wernert 2020-07-07 08:45:28 -04:00
  • 291ac3c597 Fix SSL Perms #945 Mike Reeves 2020-07-06 17:24:04 -04:00
  • be5f4b04c6 Fix SSL Perms Mike Reeves 2020-07-06 17:21:23 -04:00
  • cc6d0c1cb5 Merge pull request #935 from Security-Onion-Solutions/issue/929 Mike Reeves 2020-07-06 16:45:19 -04:00
  • 3b452ab597 Change grafana to use anon auth #935 Mike Reeves 2020-07-06 16:39:43 -04:00
  • cc2f023840 Merge pull request #934 from Security-Onion-Solutions/issue/142 Mike Reeves 2020-07-06 16:12:48 -04:00
  • f05e366d49 Fix salt upgrade script #934 Mike Reeves 2020-07-06 15:56:55 -04:00
  • be3390a796 Fix Logstash state Mike Reeves 2020-07-06 15:53:21 -04:00
  • da0a0ae6ae Merge pull request #933 from Security-Onion-Solutions/quickfix/firewall Josh Patterson 2020-07-06 15:20:00 -04:00