Commit Graph

  • 80b1d51f76 wrong location for global.pipeline check #13190 reyesj2 2024-06-13 08:50:53 -04:00
  • 6340ebb36d Merge pull request #13197 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-06-12 16:49:21 -04:00
  • 70721afa51 Update DOWNLOAD_AND_VERIFY_ISO.md #13197 Doug Burks 2024-06-12 16:47:26 -04:00
  • 9c31622598 telegraft should only include jolokia config when Kafka is set as the global.pipeline reyesj2 2024-06-12 15:42:00 -04:00
  • f372b0907b Use kafka:password for kafka certs reyesj2 2024-06-12 15:41:10 -04:00
  • fac96e0b08 Merge pull request #13183 from Security-Onion-Solutions/cogburn/cleanup-config coreyogburn 2024-06-12 11:57:31 -06:00
  • 2bc53f9868 Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka reyesj2 2024-06-12 12:36:58 -04:00
  • e8106befe9 Append '-securityonion' to all Security Onion related Kafka topics. Adjust logstash to ingest all topics ending in '-securityonion' to avoid having to manually list topic names reyesj2 2024-06-12 12:05:16 -04:00
  • 83412b813f Renamed Kafka pillar reyesj2 2024-06-12 11:19:25 -04:00
  • b56d497543 Revert a so-setup change. Kafka is not an installable option reyesj2 2024-06-12 11:17:06 -04:00
  • dd40962288 Revert a whiptail menu change. Kafka is not an install option reyesj2 2024-06-12 11:07:23 -04:00
  • b7eebad2a5 Update Kafka self reset & add initial Kafka wrapper scripts to build out reyesj2 2024-06-12 11:01:40 -04:00
  • 8f8698fd02 Merge remote-tracking branch 'origin/2.4/dev' into issue/13073 m0duspwnens 2024-06-12 10:50:18 -04:00
  • 092f716f12 Merge pull request #13189 from Security-Onion-Solutions/soupmsgq Josh Patterson 2024-06-12 10:41:49 -04:00
  • c38f48c7f2 remove this \n #13189 m0duspwnens 2024-06-12 10:34:32 -04:00
  • 98837bc379 this method does not cause soup to fail m0duspwnens 2024-06-12 09:11:02 -04:00
  • 0f243bb6ec Merge remote-tracking branch 'origin/2.4/dev' into issue/13073 m0duspwnens 2024-06-11 16:33:23 -04:00
  • 88fc1bbe32 quotes on vars m0duspwnens 2024-06-11 16:32:57 -04:00
  • d5ef0e5744 Fix unnecessary escaping #13183 Corey Ogburn 2024-06-11 12:34:32 -06:00
  • 2ecac38f6d disable logstash on heavynodes m0duspwnens 2024-06-11 13:50:29 -04:00
  • e90557d7dc Merge pull request #13179 from Security-Onion-Solutions/2.4/fixintegritycheck Josh Brower 2024-06-11 13:08:40 -04:00
  • 628893fd5b remove redundant 'kafka_' from annotations & defaults reyesj2 2024-06-11 11:56:21 -04:00
  • a81e4c3362 remove dash(-) from kafka.id reyesj2 2024-06-11 11:55:17 -04:00
  • ca7b89c308 Added Kafka reset to SOC UI. Incase of changing an active broker to a controller topics may become unavailable. Resolving this would require manual intervention. This option allows running a reset to start from a clean slate to then configure cluster to desired state before reenabling Kafka as global pipeline. reyesj2 2024-06-11 11:21:13 -04:00
  • 03335cc015 Merge pull request #13182 from Security-Onion-Solutions/dockerup Josh Patterson 2024-06-11 11:08:40 -04:00
  • 08557ae287 kafka.id field should only be present when metadata for kafka exists reyesj2 2024-06-11 11:01:34 -04:00
  • 08d2a6242d Add new bind - suricata all.rules #13179 DefensiveDepth 2024-06-11 10:03:33 -04:00
  • 4b481bd405 add epoch to docker for oracle #13182 m0duspwnens 2024-06-11 09:41:58 -04:00
  • 0b1e3b2a7f upgrade docker for focal m0duspwnens 2024-06-10 16:24:44 -04:00
  • dbd9873450 upgrade docker for jammy m0duspwnens 2024-06-10 16:04:11 -04:00
  • c6d0a17669 docker upgrade debian 12 m0duspwnens 2024-06-10 15:43:29 -04:00
  • adeab10f6d upgrade docker and containerd.io for oracle m0duspwnens 2024-06-10 12:14:27 -04:00
  • 824f852ed7 merge 2.4/dev reyesj2 2024-06-10 11:26:23 -04:00
  • 284c1be85f Update Kafka controller(s) via SOC UI reyesj2 2024-06-10 11:08:54 -04:00
  • 7ad6baf483 Merge pull request #13171 from Security-Onion-Solutions/jertel/yaml Jason Ertel 2024-06-08 08:21:20 -04:00
  • f1638faa3a correct placement of error check override #13171 Jason Ertel 2024-06-08 08:18:34 -04:00
  • dea786abfa Merge pull request #13170 from Security-Onion-Solutions/jertel/yaml Jason Ertel 2024-06-08 07:49:49 -04:00
  • f96b82b112 gracefully handle missing parent key #13170 Jason Ertel 2024-06-08 07:44:46 -04:00
  • 95fe11c6b4 Merge pull request #13162 from Security-Onion-Solutions/soupmsgq Josh Patterson 2024-06-07 16:23:03 -04:00
  • f2f688b9b8 Update soup #13162 Jason Ertel 2024-06-07 16:18:09 -04:00
  • 0139e18271 additional description m0duspwnens 2024-06-07 16:03:21 -04:00
  • 657995d744 Merge pull request #13165 from Security-Onion-Solutions/TOoSmOotH-patch-3 Mike Reeves 2024-06-07 15:38:01 -04:00
  • 4057238185 Update defaults.yaml #13165 Mike Reeves 2024-06-07 15:33:49 -04:00
  • fb07ff65c9 Merge pull request #13164 from Security-Onion-Solutions/cogburn/tls-options coreyogburn 2024-06-07 13:10:45 -06:00
  • dbc56ffee7 Update defaults.yaml Mike Reeves 2024-06-07 15:09:09 -04:00
  • ee696be51d Remove rootCA and insecureSkipVerify from SOC defaults #13164 Corey Ogburn 2024-06-07 13:04:54 -06:00
  • 5d3fd3d389 AdditionalCA and InsecureSkipVerify Corey Ogburn 2024-06-07 12:47:09 -06:00
  • fa063722e1 RootCA and InsecureSkipVerify Corey Ogburn 2024-06-06 16:36:09 -06:00
  • f5cc35509b fix output alignment m0duspwnens 2024-06-07 11:03:26 -04:00
  • d39c8fae54 format output m0duspwnens 2024-06-07 09:01:16 -04:00
  • d3b81babec check for phases with so-yaml, remove if exists m0duspwnens 2024-06-06 16:15:21 -04:00
  • f35f6bd4c8 Merge pull request #13154 from Security-Onion-Solutions/cogburn/soc-proxy coreyogburn 2024-06-06 14:03:16 -06:00
  • d5cfef94a3 Merge pull request #13156 from Security-Onion-Solutions/TOoSmOotH-patch-3 Mike Reeves 2024-06-06 16:01:22 -04:00
  • f37f5ba97b Update soc_suricata.yaml #13156 Mike Reeves 2024-06-06 15:57:58 -04:00
  • 42818a9950 Remove proxy from SOC defaults #13154 Corey Ogburn 2024-06-06 13:28:07 -06:00
  • e85c3e5b27 SOC Proxy Setting Corey Ogburn 2024-06-05 14:45:06 -06:00
  • a39c88c7b4 add set to troubleshoot failure m0duspwnens 2024-06-06 12:56:24 -04:00
  • 73ebf5256a Merge remote-tracking branch 'origin/2.4/dev' into soupmsgq m0duspwnens 2024-06-06 12:44:45 -04:00
  • 6d31cd2a41 Merge pull request #13150 from Security-Onion-Solutions/jertel/yaml Jason Ertel 2024-06-06 12:09:03 -04:00
  • 5600fed9c4 add ability to retrieve yaml values via so-yaml.py; improve so-minion id matching #13150 Jason Ertel 2024-06-06 11:56:07 -04:00
  • 6920b77b4a fix msg m0duspwnens 2024-06-06 11:00:43 -04:00
  • ccd6b3914c add final msg queue for soup. m0duspwnens 2024-06-06 10:33:55 -04:00
  • c4723263a4 Remove unused kafka reactor reyesj2 2024-06-06 08:59:17 -04:00
  • 4581a46529 Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka reyesj2 2024-06-05 20:47:41 -04:00
  • 33a2c5dcd8 Merge pull request #13141 from Security-Onion-Solutions/sotcprp Josh Patterson 2024-06-05 09:49:39 -04:00
  • f6a8a21f94 remove space #13141 m0duspwnens 2024-06-05 08:58:46 -04:00
  • ff5773c837 move so-tcpreplay back to common. return empty string if no sensor.interface pillar m0duspwnens 2024-06-05 08:56:32 -04:00
  • 66f8084916 Merge remote-tracking branch 'origin/2.4/dev' into sotcprp m0duspwnens 2024-06-05 08:32:54 -04:00
  • a2467d0418 move so-tcpreplay to sensor state m0duspwnens 2024-06-05 08:24:57 -04:00
  • 3b0339a9b3 create kafka.id from kafka {partition}-{offset}-{timestamp} for tracking event reyesj2 2024-06-04 14:27:52 -04:00
  • fb1d4fdd3c update license reyesj2 2024-06-04 12:33:51 -04:00
  • 56a16539ae Merge pull request #13134 from Security-Onion-Solutions/sotcprp Josh Patterson 2024-06-04 10:43:33 -04:00
  • c0b2cf7388 add the curlys #13134 m0duspwnens 2024-06-04 10:28:21 -04:00
  • d9c58d9333 update receiver pillar access reyesj2 2024-06-04 08:33:45 -04:00
  • ef3a52468f Merge pull request #13129 from Security-Onion-Solutions/salt3006.8 Josh Patterson 2024-06-03 15:29:19 -04:00
  • c88b731793 revert to 3006.6 #13129 m0duspwnens 2024-06-03 15:27:08 -04:00
  • 2e85a28c02 Remove so-kafka-clusterid script, created during soup reyesj2 2024-06-02 18:25:59 -04:00
  • 964fef1aab Merge pull request #13117 from Security-Onion-Solutions/fix/items_and_lists weslambert 2024-05-31 16:34:29 -04:00
  • 1a832fa0a5 Move soup kafka needfuls to up_to_2.4.80 reyesj2 2024-05-31 14:04:46 -04:00
  • 75bdc92bbf Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2/kafka reyesj2 2024-05-31 14:02:43 -04:00
  • a8c231ad8c Add component templates #13117 Wes 2024-05-31 17:47:01 +00:00
  • f396247838 Add index templates and lifecycle policies Wes 2024-05-31 17:46:19 +00:00
  • e3ea4776c7 Update kafka nodes pillar before running highstate with pillarwatch engine. This allows configuring your Kafka controllers before cluster comes up for the first time reyesj2 2024-05-31 13:34:28 -04:00
  • 37a928b065 Merge pull request #13107 from Security-Onion-Solutions/cogburn/detection-templates coreyogburn 2024-05-30 16:26:17 -06:00
  • 85c269e697 Added TemplateDetections To Detection ClientParams #13107 Corey Ogburn 2024-05-30 15:59:03 -06:00
  • 6e70268ab9 Merge remote-tracking branch 'origin/2.4/dev' into sotcprp m0duspwnens 2024-05-30 16:34:37 -04:00
  • fb8929ea37 Merge pull request #13103 from Security-Onion-Solutions/salt3006.8 Josh Patterson 2024-05-30 16:32:05 -04:00
  • 5d9c0dd8b5 Merge pull request #13101 from Security-Onion-Solutions/fix/separate_suricata weslambert 2024-05-30 16:30:55 -04:00
  • debf093c54 Merge remote-tracking branch 'origin/2.4/dev' into salt3006.8 #13103 m0duspwnens 2024-05-30 15:58:10 -04:00
  • 00b5a5cc0c Revert "revert version for soup test before 2.4.80 pipeline unpaused" reyesj2 2024-05-30 15:13:16 -04:00
  • dbb99d0367 Remove bad config reyesj2 2024-05-30 15:10:15 -04:00
  • 7702f05756 upgrade salt 3006.8. soup for 2.4.80 m0duspwnens 2024-05-30 15:00:32 -04:00
  • 2c635bce62 Set index for Suricata alerts #13101 Wes 2024-05-30 17:02:31 +00:00
  • 48713a4e7b revert version for soup test before 2.4.80 pipeline unpaused reyesj2 2024-05-30 13:00:34 -04:00
  • e831354401 Add Suricata alerts setting for configuration Wes 2024-05-30 17:00:11 +00:00
  • 55c5ea5c4c Add template for Suricata alerts Wes 2024-05-30 16:58:56 +00:00
  • 1fd5165079 Merge remote-tracking branch 'origin/2.4/dev' into reyesj2/kafka reyesj2 2024-05-29 23:37:40 -04:00
  • 949cea95f4 Update pillarWatch config for global.pipeline reyesj2 2024-05-29 23:19:44 -04:00
  • 12762e08ef Merge pull request #13093 from Security-Onion-Solutions/TOoSmOotH-patch-1 Mike Reeves 2024-05-29 16:54:31 -04:00
  • 62bdb2627a Update VERSION #13093 Mike Reeves 2024-05-29 16:53:27 -04:00