Commit Graph

  • eaacb7b71e Fleet cleanup Josh Brower 2020-06-03 05:54:35 -04:00
  • e6fcf75181 Re-ordered wazuh setup to avoid agent-service failures due to missing client.keys file; Prepare for user profile settings screen support in reverse proxy Jason Ertel 2020-06-02 17:31:43 -04:00
  • 014274930a Merge pull request #815 from Security-Onion-Solutions/fix/syslog_cleanup weslambert 2020-06-02 15:32:32 -04:00
  • c91bc0e681 Clean up some stuff #815 weslambert 2020-06-02 15:31:48 -04:00
  • 25aae21cf6 Trying to get decoded packet Mike Reeves 2020-06-02 15:06:39 -04:00
  • b507b87871 Trying to get decoded packet Mike Reeves 2020-06-02 14:49:07 -04:00
  • fb68506418 Add mor suricata ingest parser types Mike Reeves 2020-06-02 14:42:15 -04:00
  • 3096d8d988 Add mor suricata ingest parser types Mike Reeves 2020-06-02 14:34:38 -04:00
  • 0ea2252b5b Add Suricata Flow pipeline Mike Reeves 2020-06-02 13:40:46 -04:00
  • 98e0f0d7d8 Merge pull request #814 from Security-Onion-Solutions/feature/syslog weslambert 2020-06-02 13:39:23 -04:00
  • 8cac30728b update Logstash config #814 Wes Lambert 2020-06-02 17:36:36 +00:00
  • 91673a5d70 Update FB config Wes Lambert 2020-06-02 17:33:42 +00:00
  • 782c669835 Fleet standalone fixes - req Josh Brower 2020-06-02 12:42:14 -04:00
  • 617f60d472 Fix Syntax Mike Reeves 2020-06-02 12:01:26 -04:00
  • e63f39a9c4 Rename dataset Mike Reeves 2020-06-02 11:58:14 -04:00
  • d47acd1d80 Change suricata to hit suricata.common Mike Reeves 2020-06-02 11:41:13 -04:00
  • 77df87880c Fleet standalone fixes - fleet sa req Josh Brower 2020-06-02 10:20:29 -04:00
  • b5cc653179 Fleet standalone fixes - mainip Josh Brower 2020-06-02 09:39:42 -04:00
  • 42683ddb67 always restart acng and registry containers when docker restarts Jason Ertel 2020-06-02 09:12:25 -04:00
  • 07c0075fc0 Upgrade containerd.io and docker-ce to match ISO rpms Jason Ertel 2020-06-02 08:43:06 -04:00
  • b695b7f245 Fleet standalone fixes - firewall Josh Brower 2020-06-02 08:05:48 -04:00
  • 9d5f4049b5 Avoid filtering NIC when it's an empty string Jason Ertel 2020-06-02 05:51:58 -04:00
  • 69f940fe8c Merge pull request #811 from Security-Onion-Solutions/feature/updatetool Mike Reeves 2020-06-01 20:49:42 -04:00
  • 307cbe4b77 Couple of QOL scripts #811 Mike Reeves 2020-06-01 20:48:25 -04:00
  • 4b14ecf1d9 Fleet standalone fixes Josh Brower 2020-06-01 16:36:32 -04:00
  • 45d17c5148 Pillarize Suricata Round 1 Mike Reeves 2020-06-01 14:53:04 -04:00
  • cc6a323f45 Merge pull request #810 from Security-Onion-Solutions/issue/749 Josh Patterson 2020-06-01 12:20:28 -04:00
  • f5c8091fd6 remove unneeded INITIALSETUP var from addtotab #810 m0duspwnens 2020-06-01 12:17:52 -04:00
  • 1737b46abb Merge remote-tracking branch 'remotes/origin/dev' into issue/749 m0duspwnens 2020-06-01 12:15:00 -04:00
  • 80d1814f10 remove event.module:zeek to make queries more generic Doug Burks 2020-06-01 12:00:33 -04:00
  • b091fe07c9 Merge pull request #809 from Security-Onion-Solutions/feature/metasuri Mike Reeves 2020-06-01 11:05:38 -04:00
  • 03f34404b1 Suricata 5 Meta Data #809 Mike Reeves 2020-06-01 11:03:43 -04:00
  • 551c663046 Merge pull request #808 from Security-Onion-Solutions/fix/tunnel_parents weslambert 2020-06-01 09:52:55 -04:00
  • 51f5d64ef6 Rename tunnel_parents #808 Wes Lambert 2020-06-01 13:51:32 +00:00
  • fa8b88b090 Merge pull request #806 from Security-Onion-Solutions/feature/vxlan_tunnel_id weslambert 2020-06-01 08:54:12 -04:00
  • d7ce3d4719 fix naming of uid field for tunnel #806 Wes Lambert 2020-06-01 12:52:57 +00:00
  • f559621f00 add x509 issuer and subject groupby queries Doug Burks 2020-06-01 07:48:50 -04:00
  • 46dc5f42e9 combine two http queries into one with multiple groupby Doug Burks 2020-06-01 07:30:08 -04:00
  • 5ddfb7ccce fix merge conflicts m0duspwnens 2020-05-29 17:31:07 -04:00
  • 0eeafa292e Merge pull request #802 from Security-Onion-Solutions/quickfix/wazuh/whitelistmanager Josh Patterson 2020-05-29 17:26:10 -04:00
  • 4dfb58a98c change how whitelist script determines if wazuh is enabled #802 m0duspwnens 2020-05-29 17:22:39 -04:00
  • 5f4e480b4c Merge pull request #801 from Security-Onion-Solutions/quickfix/search/nginx Josh Patterson 2020-05-29 17:02:49 -04:00
  • 17879ad88c add nginx state to searchnode in salt/top #801 m0duspwnens 2020-05-29 17:01:43 -04:00
  • a84203be7c Merge remote-tracking branch 'remotes/origin/dev' into issue/749 m0duspwnens 2020-05-29 16:38:10 -04:00
  • 828f8a0df8 Merge pull request #800 from Security-Onion-Solutions/quickfix/node Josh Patterson 2020-05-29 16:37:04 -04:00
  • d7e904e1ab fix minion_type for *NODE install_type #800 m0duspwnens 2020-05-29 16:35:39 -04:00
  • 9ae68b52ef Merge remote-tracking branch 'remotes/origin/dev' into issue/749 m0duspwnens 2020-05-29 16:22:00 -04:00
  • 16d6e4ae2e Merge pull request #799 from Security-Onion-Solutions/quickfix/distrib_install_firewall Josh Patterson 2020-05-29 15:36:53 -04:00
  • 52954d8e5d set_intial_firewall policy sooner in install process so packages can be installed if masterupdates are enabled #799 m0duspwnens 2020-05-29 15:34:18 -04:00
  • 15fc97e516 adding suricata.master state to mastersearch - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 m0duspwnens 2020-05-29 13:11:55 -04:00
  • 6db8470de7 Merge remote-tracking branch 'remotes/origin/dev' into issue/749 m0duspwnens 2020-05-29 13:09:49 -04:00
  • 42ea39ee35 Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into dev m0duspwnens 2020-05-29 13:09:26 -04:00
  • aa24dacb86 Merge pull request #798 from Security-Onion-Solutions/quickfix/master_navigator Josh Patterson 2020-05-29 13:08:43 -04:00
  • 3143643692 add navigator to master if enabled #798 m0duspwnens 2020-05-29 13:05:26 -04:00
  • 30641d0fa9 Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into dev m0duspwnens 2020-05-29 13:01:08 -04:00
  • 2db2054cce update instructions in logstash customer pipelines and templates - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 m0duspwnens 2020-05-29 10:58:53 -04:00
  • 7957b51409 change master roots priority to local m0duspwnens 2020-05-29 10:57:43 -04:00
  • 2601ffe902 Merge pull request #797 from Security-Onion-Solutions/fix/radius_parsing weslambert 2020-05-29 07:56:22 -04:00
  • 4059121dd6 fix framed_addr field #797 Wes Lambert 2020-05-29 11:55:18 +00:00
  • 046bca626e Fleet pw check fix Josh Brower 2020-05-28 16:51:37 -04:00
  • e8e48a4beb Fleet standalone bugfixes Josh Brower 2020-05-28 16:40:12 -04:00
  • 0d8c0e1fa6 Fleet standalone fixes Josh Brower 2020-05-28 16:27:18 -04:00
  • 40fa5293bf move fileserve update to suricata.master m0duspwnens 2020-05-28 15:54:11 -04:00
  • 3952faba85 Add missing semi-colons to break out of the case block Jason Ertel 2020-05-28 15:27:14 -04:00
  • f5300d3d5a Merge pull request #794 from Security-Onion-Solutions/feature/zeek-stats weslambert 2020-05-28 13:55:43 -04:00
  • 7f75050682 Add basic Zeek stats script #794 Wes Lambert 2020-05-28 17:54:15 +00:00
  • aeb71bb8f0 Simplified setup script Josh Brower 2020-05-28 13:21:25 -04:00
  • 71d381aeae apply suricata.master state during setup - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 m0duspwnens 2020-05-28 13:19:38 -04:00
  • 7c232318ad Merge pull request #793 from Security-Onion-Solutions/fix/so-stop-exact-match weslambert 2020-05-28 13:17:56 -04:00
  • b835c2e27e Update for exact match (ex. thehive, thehive-es, thehive-cortex) #793 weslambert 2020-05-28 13:17:31 -04:00
  • ae6f028666 Merge pull request #792 from Security-Onion-Solutions/fix/suricata_config_nsm weslambert 2020-05-28 13:00:15 -04:00
  • 12f426d4f4 Move eve.json to /nsm #792 weslambert 2020-05-28 12:59:41 -04:00
  • 8291de40cf Merge pull request #791 from Security-Onion-Solutions/fix/socto-ip-hostname weslambert 2020-05-28 12:46:57 -04:00
  • 869bfb947d add master to SOCtopus hosts file #791 Wes Lambert 2020-05-28 16:45:48 +00:00
  • 9de1a25703 Merge pull request #789 from Security-Onion-Solutions/fix/filebeat_init weslambert 2020-05-28 12:11:39 -04:00
  • d2263db0ff Update init.sls #789 weslambert 2020-05-28 12:11:08 -04:00
  • 4f15de8b77 refresh salt fileserver if suricata rule symlink is created m0duspwnens 2020-05-28 12:00:22 -04:00
  • e53e891bd6 Fleet reactor - Typo fix Josh Brower 2020-05-28 11:36:38 -04:00
  • 6c4946f4e2 Provide option to skip reboot after setup completes Jason Ertel 2020-05-28 10:20:39 -04:00
  • c775e583dd Merge pull request #788 from Security-Onion-Solutions/feature/filebeat-syslog-fw weslambert 2020-05-28 09:58:15 -04:00
  • b7d7747f65 allow syslog #788 Wes Lambert 2020-05-28 13:56:02 +00:00
  • 2b4cfe2b02 Merge pull request #786 from Security-Onion-Solutions/feature/suri5 Mike Reeves 2020-05-28 09:41:41 -04:00
  • 8304d91b0b Merge branch 'dev' into feature/suri5 #786 Mike Reeves 2020-05-28 09:41:28 -04:00
  • 091cc8b789 fix how local salt and pillar dirs are created - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 m0duspwnens 2020-05-28 08:57:07 -04:00
  • 3883c8bfe0 Merge pull request #784 from Security-Onion-Solutions/feature/filebeat-syslog weslambert 2020-05-28 08:39:11 -04:00
  • d2b93d531e Basic syslog config #784 Wes Lambert 2020-05-28 12:36:29 +00:00
  • 5afc05feb2 Update FB init for syslog Wes Lambert 2020-05-28 12:35:22 +00:00
  • b9bdca509e update Filebeat config for syslog Wes Lambert 2020-05-28 12:33:41 +00:00
  • f3efafc9ca combine two notice queries into one query with multiple groupby Doug Burks 2020-05-28 08:01:33 -04:00
  • 60cc3e9675 remove address from DHCP leases query Doug Burks 2020-05-28 07:50:52 -04:00
  • 2a21d7403f Open firewall from all networks for automated testing Jason Ertel 2020-05-28 00:47:46 -04:00
  • a75301cd0e Ensure IP is available to child process executing so-allow Jason Ertel 2020-05-27 22:00:58 -04:00
  • 1e5d5397a4 Support multiple command line options for setup, along with dynamic values per option Jason Ertel 2020-05-27 19:42:48 -04:00
  • 8b83799253 create local dirs sooner - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 m0duspwnens 2020-05-27 18:16:02 -04:00
  • 63e0a1e8a2 create local salt and pillar dirs - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 m0duspwnens 2020-05-27 17:18:17 -04:00
  • 59cc927878 Merge remote-tracking branch 'remotes/origin/dev' into issue/749 m0duspwnens 2020-05-27 15:56:38 -04:00
  • 3712eb0acb [fix] Redirect so-allow output to log William Wernert 2020-05-27 15:49:41 -04:00
  • 04800277c2 Merge pull request #783 from Security-Onion-Solutions/fix/hive_rename_bug weslambert 2020-05-27 15:44:22 -04:00
  • 6a935b5452 Hive to TheHive #783 weslambert 2020-05-27 15:43:41 -04:00
  • 11c641fd1b Initial support - integrated Fleet setup Josh Brower 2020-05-27 15:34:14 -04:00