Commit Graph

  • b4e556496b add elasticsearch_rest to assigned hostgroups where missing #933 m0duspwnens 2020-07-06 15:18:47 -04:00
  • 623c37f1f5 Merge remote-tracking branch 'remotes/origin/dev' into issue/142 Mike Reeves 2020-07-06 14:35:46 -04:00
  • 1016315196 Change Logic for logstash Mike Reeves 2020-07-06 13:58:38 -04:00
  • 087080d583 Add logix for logstash_settings Mike Reeves 2020-07-06 13:16:40 -04:00
  • 57bbb02c65 [refactor][fix] Move nmcli status list gen to a function William Wernert 2020-07-02 17:17:46 -04:00
  • 99d490bc06 [fix][refactor] Move detect_ec2 and add echo statement William Wernert 2020-07-02 17:15:46 -04:00
  • cfeb95a718 Merge pull request #924 from Security-Onion-Solutions/feature/so-container-scripts bryant-treacle 2020-07-02 14:42:49 -04:00
  • 541de278c9 Merge pull request #918 from Security-Onion-Solutions/versionfix Mike Reeves 2020-07-02 10:39:15 -04:00
  • 5df88f6f2d Update so-functions #918 Mike Reeves 2020-07-02 10:36:28 -04:00
  • 86a2650fbf Update VERSION Mike Reeves 2020-07-02 10:34:50 -04:00
  • c895503fe6 Merge pull request #917 from Security-Onion-Solutions/updateversion Mike Reeves 2020-07-02 10:06:23 -04:00
  • 63ef3a1e07 Update VERSION #917 Mike Reeves 2020-07-02 10:05:12 -04:00
  • 0b10b775c5 Additional so-container scripts #924 bryant-treacle 2020-07-02 07:02:35 +00:00
  • b9a176201f Merge pull request #913 from Security-Onion-Solutions/feature/setup-changes William Wernert 2020-07-02 14:01:46 -04:00
  • d2ba25e784 Merge branch 'dev' into feature/setup-changes #913 William Wernert 2020-07-02 14:00:10 -04:00
  • 0bfa3d486e Merge pull request #923 from Security-Onion-Solutions/fix/es-allow weslambert 2020-07-02 13:32:45 -04:00
  • bbc752b6d9 Fix my typo #923 weslambert 2020-07-02 13:32:19 -04:00
  • 518c8db3de Merge pull request #922 from Security-Onion-Solutions/feature/low-level-alerts Josh Brower 2020-07-02 12:18:03 -04:00
  • 69ace6fbfa Initial commit - Low Level Alerts #922 Josh Brower 2020-07-02 12:16:56 -04:00
  • cf6a229f51 Import now requires execution on a sensor node due to the need for zeek and suricata; Automatically stop curator if curator is installed Jason Ertel 2020-07-02 12:07:24 -04:00
  • c7a3cc9c17 [fix][revert] Change source in so-allow to correct path William Wernert 2020-07-02 08:58:14 -04:00
  • 4cedacf8fd Improve curator verbiage in so-import-pcap Jason Ertel 2020-07-02 06:01:12 -04:00
  • 07d13b7ad0 Merge pull request #916 from Security-Onion-Solutions/defensivedepth-patch-1 Josh Brower 2020-07-02 05:32:45 -04:00
  • 7811ea5d4c Delete playbook_db_init.sql.backup #916 Josh Brower 2020-07-02 05:32:35 -04:00
  • 0f915ec85e Merge pull request #915 from Security-Onion-Solutions/feature/playbook-updates Josh Brower 2020-07-02 05:31:30 -04:00
  • 3c93f9fd45 Playbook setup fix #915 Josh Brower 2020-07-02 05:30:30 -04:00
  • ac01b8de4b Stop curator when directed on PCAP imports Jason Ertel 2020-07-01 22:03:58 -04:00
  • 98cfba18e9 fix zeek.ftp description Doug Burks 2020-07-01 20:27:40 -04:00
  • f6adf4ed56 fix zeek.smb_mapping description Doug Burks 2020-07-01 20:26:51 -04:00
  • 2cbd5ffe61 fix zeek.ssh description Doug Burks 2020-07-01 20:26:06 -04:00
  • e3126064e8 Improve usage instructions for so-import-pcap Jason Ertel 2020-07-01 17:58:02 -04:00
  • aeda3fde74 [revert] Remove regex from setup log grep William Wernert 2020-07-01 17:39:04 -04:00
  • 408b5ee32d [ix] Fix if conditions William Wernert 2020-07-01 16:53:43 -04:00
  • 96e93b012d Adjust imports for filebeat configuration to ensure import data is placed into ES Jason Ertel 2020-07-01 17:18:01 -04:00
  • d893aa0032 Playbook Updates Josh Brower 2020-07-01 16:48:07 -04:00
  • b671f28562 [fix] Rename function whiptail_bond_nics to whiptail_sensor_nics William Wernert 2020-07-01 16:32:33 -04:00
  • 85a3f3c277 Merge branch 'dev' into feature/setup-changes William Wernert 2020-07-01 16:24:55 -04:00
  • b4f9fe5f54 [fix] Remove quotes William Wernert 2020-07-01 16:24:41 -04:00
  • b75cb36058 Merge branch 'feature/ec2_setup' into feature/setup-changes William Wernert 2020-07-01 16:23:48 -04:00
  • 54c3327240 [refactor] Simplify ec2 detection + handling William Wernert 2020-07-01 16:23:38 -04:00
  • d6feafb12a Correct indentation in filebeat.yaml Jason Ertel 2020-07-01 15:39:23 -04:00
  • ab42126d8e Add logstash_settings pillar Mike Reeves 2020-07-01 15:25:35 -04:00
  • 5580f05daf Add logstash pillar Mike Reeves 2020-07-01 15:07:00 -04:00
  • f580da5d56 Update 9999_output_redis.conf.jinja Mike Reeves 2020-07-01 14:45:54 -04:00
  • 70e4ce3e98 Add batch to output Mike Reeves 2020-07-01 14:38:51 -04:00
  • 4b5571a8d6 [refactor][fix] Remove unnecessary variable William Wernert 2020-07-01 13:56:15 -04:00
  • 44890edc79 [refactor] Use regex in error check for setup log William Wernert 2020-07-01 13:51:54 -04:00
  • 549fd93cba Merge pull request #912 from Security-Onion-Solutions/issue/642 Josh Patterson 2020-07-01 13:44:49 -04:00
  • f98c497d79 change setup and whiptail back to bro #912 m0duspwnens 2020-07-01 13:43:37 -04:00
  • 26b0daf2da Add other setup-related items for EC2 interface Wes Lambert 2020-07-01 17:42:51 +00:00
  • fd939a06b9 whitespace cleanup m0duspwnens 2020-07-01 13:40:40 -04:00
  • 3cf79995a2 Modify Whiptail menu for EC2 NIC Wes Lambert 2020-07-01 17:32:43 +00:00
  • 38db512eda fix spacing m0duspwnens 2020-07-01 13:29:19 -04:00
  • 4e7e19af54 pillarize zeek node.cfg. change reference from bro to zeek. m0duspwnens 2020-07-01 13:26:27 -04:00
  • db764902c7 [fix] Change if condition when checking nmcli status William Wernert 2020-07-01 13:05:11 -04:00
  • 19b997ece0 Merge branch 'dev' into feature/setup-changes William Wernert 2020-07-01 12:56:57 -04:00
  • 7bb97f2b2d [fix] Remove "Panel Title" from Kibana CPU graph William Wernert 2020-07-01 11:12:21 -04:00
  • 90f4b8e043 [feat] Add welcome/instruction wording to initial menu William Wernert 2020-07-01 11:03:18 -04:00
  • c97798b57d [feat] Add check to see if bond nics are managed by Network Manager William Wernert 2020-07-01 09:43:39 -04:00
  • 3a9d252af3 [fix] Correct indent in create_local_directories() William Wernert 2020-07-01 09:42:07 -04:00
  • de620c88a1 Merge pull request #910 from Security-Onion-Solutions/version-correction William Wernert 2020-06-30 15:57:30 -04:00
  • a49532d15c Remove HH prefix to ensure compatibility with updated build system #910 Jason Ertel 2020-06-30 15:54:56 -04:00
  • a3deb868ad Improve filebeat config indentation Jason Ertel 2020-06-30 14:57:34 -04:00
  • 930f15eea5 Introduce so-import-pcap tool - WIP Jason Ertel 2020-06-30 14:56:08 -04:00
  • 8dedd60da8 Merge branch 'feature/fast-fail' into feature/setup-changes William Wernert 2020-06-30 14:27:04 -04:00
  • ce8a59243c [feat] Add grep for "Error" to fail if nmcli fails William Wernert 2020-06-30 14:26:48 -04:00
  • 8d624e6ade [fix] Move navigatordefaultlayer file.managed state to nginx sls William Wernert 2020-06-30 10:53:10 -04:00
  • cab232ae9f [feat] Add check for disk space during setup William Wernert 2020-06-30 10:11:02 -04:00
  • ba81b7275a Merge pull request #909 from Security-Onion-Solutions/fix/1.4.1 1.4.1 Mike Reeves 2020-06-30 09:55:10 -04:00
  • a1791f1e2e Update to 1.4.1 #909 Mike Reeves 2020-06-30 09:47:20 -04:00
  • a74d52a986 Merge pull request #908 from Security-Onion-Solutions/bugfix/hostname-regex Mike Reeves 2020-06-30 09:14:20 -04:00
  • 1022bf5b99 [fix] Apply regex filter to hostname input #908 William Wernert 2020-06-29 15:53:21 -04:00
  • 9f39875192 [fix] Apply regex filter to hostname input William Wernert 2020-06-29 15:53:21 -04:00
  • 376a6e5fd5 Merge pull request #907 from Security-Onion-Solutions/feature/spacing-so-allow Josh Brower 2020-06-30 08:13:38 -04:00
  • 1c0443458c so-allow spacing fix #907 Josh Brower 2020-06-30 08:13:00 -04:00
  • 0b7026a11e Merge pull request #906 from Security-Onion-Solutions/fix/ingest_parsing weslambert 2020-06-29 23:07:22 -04:00
  • 84e2965fef Addl krb fix #906 Wes Lambert 2020-06-30 03:06:01 +00:00
  • bf8798f1d1 Fix krb client/server cert subject parsing Wes Lambert 2020-06-30 03:04:01 +00:00
  • 8f5da66335 Add null safe operator for query name Wes Lambert 2020-06-30 03:02:38 +00:00
  • 46d58acdd9 Merge pull request #905 from Security-Onion-Solutions/issue/878 Josh Patterson 2020-06-29 16:24:41 -04:00
  • 0f9d8024f8 add sensoroni to so-status output for sensors - https://github.com/Security-Onion-Solutions/securityonion/issues/878 #905 m0duspwnens 2020-06-29 16:23:04 -04:00
  • c73071c95e Merge pull request #904 from Security-Onion-Solutions/issue/583 Josh Patterson 2020-06-29 16:17:22 -04:00
  • efaf41107c update description in localrules/local.rules for idstools #904 m0duspwnens 2020-06-29 16:14:36 -04:00
  • 67f2eedad1 cleanup whitespace in idstools enable/disable.conf m0duspwnens 2020-06-29 16:11:30 -04:00
  • fe8df22063 cleanup whitespace in idstools enable/disable.conf m0duspwnens 2020-06-29 16:03:14 -04:00
  • fdaab8da9f Merge branch 'dev' into feature/setup-changes William Wernert 2020-06-29 15:54:36 -04:00
  • 23c0363899 [fix] Reference correct directory in nginx sls and remove navigator sls William Wernert 2020-06-29 15:54:17 -04:00
  • b97ecd2d7a Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev William Wernert 2020-06-29 15:53:29 -04:00
  • 0a97328acc [fix] Apply regex filter to hostname input William Wernert 2020-06-29 15:53:21 -04:00
  • 6bc7f023ff Merge pull request #903 from Security-Onion-Solutions/quickfix/suricata Josh Patterson 2020-06-29 15:39:40 -04:00
  • d7580fe6a0 fix suricata state if suripins or suri procs arent set #903 m0duspwnens 2020-06-29 15:38:05 -04:00
  • 53c3b1579b [feat] Reformat install type menu William Wernert 2020-06-29 15:20:17 -04:00
  • 8e15f858dd Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev William Wernert 2020-06-29 15:14:12 -04:00
  • abe063602b Update whiptail snort Mike Reeves 2020-06-29 14:57:42 -04:00
  • b398d58dc9 Merge pull request #902 from Security-Onion-Solutions/feature/es_allow weslambert 2020-06-29 14:51:09 -04:00
  • ed60d48c81 Add ES REST API option for so-allow #902 Wes Lambert 2020-06-29 18:49:16 +00:00
  • 8cbccb656d [fix] Apply shellcheck fixes William Wernert 2020-06-29 11:32:25 -04:00
  • b01bdf35f9 [fix] Remove port binding from telegraf docker state William Wernert 2020-06-29 11:31:44 -04:00
  • 8ee2142de4 pillarize idstools - https://github.com/Security-Onion-Solutions/securityonion/issues/583 m0duspwnens 2020-06-29 11:21:47 -04:00
  • 378ad97e7b Disabled socket listener Mike Reeves 2020-06-29 11:16:19 -04:00