Commit Graph

  • 2e17e93cfe remove unused test parameters from setup #13374 Jason Ertel 2024-07-22 11:04:45 -04:00
  • 7dfb75ba6b remove unused test parameters from setup Jason Ertel 2024-07-22 11:02:56 -04:00
  • af0425b8f1 Update rulecat.conf #13373 Mike Reeves 2024-07-22 10:20:30 -04:00
  • 6cf0a0bb42 Update so-rule-update Mike Reeves 2024-07-22 10:19:34 -04:00
  • d97400e6f5 Merge pull request #13368 from Security-Onion-Solutions/reyesj2/kfps Jorge Reyes 2024-07-21 20:11:42 -04:00
  • cf1335dd84 searchnode logstash-kafka cert generation #13368 reyesj2 2024-07-20 11:31:33 -04:00
  • be74449fb9 Merge pull request #13365 from Security-Onion-Solutions/cogburn/suricata-regex-support coreyogburn 2024-07-19 12:47:10 -06:00
  • 45b2413175 Removed Allow/Deny Regexes, Added Enable/Disable Regex #13365 Corey Ogburn 2024-07-19 12:45:24 -06:00
  • 022df966c7 Remove Allow/Deny Regex, Add Suricata Enable/Disable Regex Corey Ogburn 2024-07-18 16:09:44 -06:00
  • 92385d652e Merge pull request #13363 from Security-Onion-Solutions/reyesj2/ksoup Jorge Reyes 2024-07-19 10:50:48 -04:00
  • 4478d7b55a kafka soup pillar fix #13363 reyesj2 2024-07-19 09:32:47 -04:00
  • 612716ee69 Apply ES to load pipelines Wes 2024-07-17 17:35:41 +00:00
  • f78a5d1a78 Remove pipeline file Wes 2024-07-17 15:42:40 +00:00
  • 2d0de87530 Add component templates for Fleet metrics Wes 2024-07-17 15:19:46 +00:00
  • 18df491f7e Merge pull request #13355 from Security-Onion-Solutions/silsll Josh Patterson 2024-07-17 11:09:18 -04:00
  • cee6ee7a2a Merge remote-tracking branch 'origin/2.4/dev' into silsll #13355 m0duspwnens 2024-07-17 10:16:36 -04:00
  • 6d18177f98 only include global phases if defined in default for that index m0duspwnens 2024-07-17 10:16:11 -04:00
  • c0bb395571 Remove pipeline file removal weslambert 2024-07-17 09:51:51 -04:00
  • f051ddc7f0 Remove pipelines weslambert 2024-07-17 09:50:26 -04:00
  • 72ad49ed12 add policy for so-lists and so-items m0duspwnens 2024-07-16 14:36:06 -04:00
  • d11f4ef9ba Merge pull request #13350 from Security-Onion-Solutions/reyesj2/kflux Jorge Reyes 2024-07-16 14:26:09 -04:00
  • 03ca7977a0 quote variables #13350 reyesj2 2024-07-16 14:14:55 -04:00
  • 91b2e7d400 Merge remote-tracking branch 'origin/2.4/dev' into silsll m0duspwnens 2024-07-16 14:06:56 -04:00
  • 34c3a58efe add cold policy m0duspwnens 2024-07-16 14:03:48 -04:00
  • a867557f54 Merge pull request #13353 from Security-Onion-Solutions/fci Josh Patterson 2024-07-16 13:18:11 -04:00
  • b814f32e0a fix custom indices #13353 m0duspwnens 2024-07-16 12:39:30 -04:00
  • 2df44721d0 Merge pull request #13349 from Security-Onion-Solutions/cogburn/bulk-indexer coreyogburn 2024-07-15 15:34:01 -06:00
  • d0565baaa3 New Config Values for Detections Bulk Indexer #13349 Corey Ogburn 2024-07-15 14:43:47 -06:00
  • 38e7da1334 Merge pull request #13347 from Security-Onion-Solutions/upgrade/elastic_8_14_3 weslambert 2024-07-15 16:29:24 -04:00
  • 1b623c5c7a Show Kafka EPS for nodes with broker role only reyesj2 2024-07-15 16:27:48 -04:00
  • 542a116b8c use so-yaml add for kafka pillar change reyesj2 2024-07-15 16:26:52 -04:00
  • e7b6496f98 Merge pull request #13348 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-07-15 15:59:49 -04:00
  • 3991c7b5fe FEATURE: Add new action to SOC Actions list to allow users to more easily add their own actions #13346 #13348 Doug Burks 2024-07-15 15:52:00 -04:00
  • 678b232c24 Elastic 8.14.3 #13347 weslambert 2024-07-15 15:48:01 -04:00
  • fbd0dbd048 Elastic 8.14.3 weslambert 2024-07-15 15:46:55 -04:00
  • 1df19faf5c Elastic 8.14.3 weslambert 2024-07-15 15:44:50 -04:00
  • 8ec5794833 Update VERSION weslambert 2024-07-15 15:42:40 -04:00
  • bf07d56da6 Merge pull request #13341 from Security-Onion-Solutions/revert-13323-fix/agent_pipeline weslambert 2024-07-15 11:38:56 -04:00
  • cdbffa2323 Merge pull request #13342 from Security-Onion-Solutions/revert-13316-foxtrot weslambert 2024-07-15 11:38:48 -04:00
  • 55469ebd24 Merge pull request #13340 from Security-Onion-Solutions/surianno Josh Patterson 2024-07-15 11:34:00 -04:00
  • 4e81860a13 Revert "Change pipeline version for agent" #13341 weslambert 2024-07-15 11:33:52 -04:00
  • a23789287e force var to be list of string #13340 m0duspwnens 2024-07-15 11:29:47 -04:00
  • fe1824aedd Revert "Elastic 8.14.2" #13342 weslambert 2024-07-15 11:28:59 -04:00
  • e58b2c45dd Merge pull request #13335 from Security-Onion-Solutions/reyesj2/kgz Jorge Reyes 2024-07-12 15:55:43 -04:00
  • 5d322ebc0b Allow searchnodes to run kafka.ssl state for kafka-logstash cert generation #13335 reyesj2 2024-07-12 14:45:11 -04:00
  • 7ea8d5efd0 Remove redis input pipeline from searchnodes when global pipeline is Kafka reyesj2 2024-07-12 14:44:10 -04:00
  • 4182ff66a0 rearrange kafka pillar, declutters SOC ui reyesj2 2024-07-11 16:37:16 -04:00
  • ff29d9ca51 Update log-check to ignore kafka data directories reyesj2 2024-07-11 10:23:51 -04:00
  • 4a88dedcb8 Fixin kafka.ssl state and include name for kafka_user reyesj2 2024-07-10 16:18:46 -04:00
  • cfe5c1d76a remove elasticsearch.ca from receiver allowed_states. Replaced by generated kafka trust reyesj2 2024-07-10 13:24:02 -04:00
  • ebf5159c95 Merge pull request #13323 from Security-Onion-Solutions/fix/agent_pipeline weslambert 2024-07-10 13:01:29 -04:00
  • d432019ad9 Change version from 1.13.1 to 1.20.0 #13323 weslambert 2024-07-10 12:48:08 -04:00
  • 0d8fd42be3 update pillarwatch engine reyesj2 2024-07-10 11:37:07 -04:00
  • d5faf535c3 Only interact with logstash configuration when Kafka pipeline is enabled otherwise leave it default reyesj2 2024-07-10 11:36:44 -04:00
  • 8e1edd1d91 split Kafka ssl from ssl/init. Certs won't be generated until Kafka is enabled. Also runs some clean up for old Kafka certs reyesj2 2024-07-10 11:32:43 -04:00
  • d791b23838 Generate new Kafka truststore reyesj2 2024-07-10 11:29:09 -04:00
  • 0db0754ee5 Merge pull request #13316 from Security-Onion-Solutions/foxtrot weslambert 2024-07-10 08:53:03 -04:00
  • 1f5a990b1e Remove lines that aren't needed right now #13316 Wes 2024-07-09 18:32:06 +00:00
  • 7a2f01be53 Update VERSION weslambert 2024-07-09 13:58:13 -04:00
  • dadb0db8f3 Merge pull request #13321 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-07-09 12:58:22 -04:00
  • dfd8ac3626 FIX: Update SOC MOTD #13320 #13321 Doug Burks 2024-07-09 12:55:58 -04:00
  • 9716e09b83 Temp change for testing weslambert 2024-07-09 12:51:34 -04:00
  • 669f68ad88 Fleet metric annotations Wes 2024-07-09 15:39:59 +00:00
  • 32af2d8436 Merge pull request #13318 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-07-09 10:07:47 -04:00
  • 24e945eee4 FIX: Update MOTD #13317 #13318 Doug Burks 2024-07-09 10:06:16 -04:00
  • 8615e5d5ea Move enabled and index_clean back to the top weslambert 2024-07-08 16:50:06 -04:00
  • 2dd5ff4333 Update VERSION weslambert 2024-07-08 16:19:53 -04:00
  • 6a396ec1aa Fix accidental double quote removal weslambert 2024-07-08 11:44:27 -04:00
  • 34f558c023 Merge pull request #13314 from Security-Onion-Solutions/upgrade/elastic_8_14_2 weslambert 2024-07-08 10:02:02 -04:00
  • 9504f0885a Elastic 8.14.2 #13314 weslambert 2024-07-08 09:49:07 -04:00
  • ef59678441 Elastic 8.14.2 weslambert 2024-07-08 09:48:12 -04:00
  • c6f6811f47 Elastic 8.14.2 weslambert 2024-07-08 09:47:34 -04:00
  • ce8f9fe024 Merge pull request #13299 from Security-Onion-Solutions/TOoSmOotH-patch-2 Mike Reeves 2024-07-02 14:46:56 -04:00
  • 40b7999786 Delete salt/manager/tools/sbin/so-user-list #13299 Mike Reeves 2024-07-02 14:36:51 -04:00
  • 69be03f86a Delete salt/manager/tools/sbin/so-user-enable Mike Reeves 2024-07-02 14:36:36 -04:00
  • 8dc8092241 Delete salt/manager/tools/sbin/so-user-disable Mike Reeves 2024-07-02 14:36:02 -04:00
  • 578c6c567f Delete old user commands Mike Reeves 2024-07-02 14:34:45 -04:00
  • 662df1208d Merge pull request #13296 from Security-Onion-Solutions/fix/soc_ilm_policy weslambert 2024-07-02 09:06:11 -04:00
  • 745b6775f1 Change name for ILM #13296 weslambert 2024-07-02 09:05:35 -04:00
  • 176aaa8f3d Merge pull request #13295 from Security-Onion-Solutions/fix/custom_windows_integration weslambert 2024-07-02 09:03:52 -04:00
  • 4d499be1a8 Change name #13295 weslambert 2024-07-02 08:47:29 -04:00
  • c27225d91f Merge pull request #13290 from Security-Onion-Solutions/fix/elastic_template_changes weslambert 2024-07-01 11:19:02 -04:00
  • 1b47d5c622 Changes for Elastic 8.14.1 #13290 Wes 2024-07-01 15:16:58 +00:00
  • 32d7927a49 Template changes for Elastic 8.14.1 Wes 2024-07-01 15:16:06 +00:00
  • 861630681c Merge pull request #13282 from Security-Onion-Solutions/reyesj2/rupd Jorge Reyes 2024-06-28 16:26:34 -04:00
  • 9d725f2b0b fix rule update #13282 reyesj2 2024-06-28 13:45:50 -04:00
  • 132263ac1a Merge pull request #13278 from Security-Onion-Solutions/issue/13073 Josh Patterson 2024-06-27 14:50:18 -04:00
  • 92a847e3bd Fix Fleet setup DefensiveDepth 2024-06-27 11:48:54 -04:00
  • 75bbc41d38 Merge remote-tracking branch 'refs/remotes/origin/foxtrot' into foxtrot DefensiveDepth 2024-06-27 11:48:05 -04:00
  • 7716f4aff8 Elastic 8.14.1 weslambert 2024-06-27 10:49:52 -04:00
  • 8eb6dcc5b7 Elastic 8.14.1 weslambert 2024-06-27 10:49:06 -04:00
  • 847638442b Elastic 8.14.1 weslambert 2024-06-27 10:48:28 -04:00
  • 5743189eef Elastic 8.14.1 weslambert 2024-06-27 10:47:46 -04:00
  • 81d874c6ae Update VERSION weslambert 2024-06-27 10:42:58 -04:00
  • 72146d9566 Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev Mike Reeves 2024-06-27 10:42:07 -04:00
  • bfe8a3a01b Merge remote-tracking branch 'origin/2.4/dev' into issue/13073 #13278 m0duspwnens 2024-06-27 09:20:12 -04:00
  • 71ed9204ff Merge pull request #13275 from Security-Onion-Solutions/fix/elastic_8_10_4 weslambert 2024-06-27 09:16:54 -04:00
  • 222ebbdec1 Revert back to 8.10.4 #13275 weslambert 2024-06-27 09:05:29 -04:00
  • 260d4e44bc Revert back to 8.10.4 weslambert 2024-06-27 09:04:07 -04:00
  • 0c5b3f7c1c Revert back to 8.10.4 weslambert 2024-06-27 09:03:28 -04:00