Commit Graph

  • fadb6e2aa9 Re-add original timestamp format + ignore failures with this processor #12881 reyesj2 2024-04-29 16:57:48 -04:00
  • 192d91565d Update final pipeline timestamp format for event.module system events reyesj2 2024-04-29 16:34:29 -04:00
  • 82ef4c96c3 Merge pull request #12880 from Security-Onion-Solutions/issue/12878 Josh Patterson 2024-04-29 15:54:25 -04:00
  • a6e8b25969 Add Kafka connectivity between manager - > receiver nodes. Add connectivity to Kafka between other node types that may need to publish to Kafka. reyesj2 2024-04-29 15:48:57 -04:00
  • 529bc01d69 Add missing configuration for nodes running Kafka broker role only reyesj2 2024-04-29 14:53:52 -04:00
  • a663bf63c6 set Suricata as default pcap engine for eval #12880 m0duspwnens 2024-04-29 14:22:04 -04:00
  • 11055b1d32 Rename kafkapass -> kafka_pass Run so-kafka-clusterid within nodes.sls state so switchover is consistent reyesj2 2024-04-29 14:09:09 -04:00
  • a0388fd568 engines config for valueWatch m0duspwnens 2024-04-29 14:02:10 -04:00
  • fd9a91420d Use SOC UI to configure list of KRaft (Kafka) controllers for cluster reyesj2 2024-04-29 11:37:24 -04:00
  • 529c8d7cf2 Remove salt reactor for Kafka reyesj2 2024-04-29 11:35:46 -04:00
  • 13ccb58f84 Merge pull request #12876 from Security-Onion-Solutions/2.4/sigmafix Josh Brower 2024-04-29 09:12:09 -04:00
  • 086ebe1a7c Split kafka defaults between broker / controller Setup config.map.jinja to update broker / controller / combined node types reyesj2 2024-04-29 09:08:14 -04:00
  • 29c964cca1 Set kafka.nodes state to run first to populate kafka.nodes pillar reyesj2 2024-04-29 09:04:52 -04:00
  • f2c3c928fc Sigma pivot fix and cleanup #12876 DefensiveDepth 2024-04-29 08:49:05 -04:00
  • 3cbc29e767 Merge pull request #12875 from Security-Onion-Solutions/jertel/wf Jason Ertel 2024-04-29 05:16:07 -07:00
  • 89cb8b79fd restrict workflows to so #12875 Jason Ertel 2024-04-29 08:07:19 -04:00
  • b5c5c7857b Merge pull request #12846 from petiepooo/fix/check-srvc-status Mike Reeves 2024-04-25 15:10:42 -04:00
  • ed05d51969 Merge pull request #12865 from Security-Onion-Solutions/issue/12637 Josh Patterson 2024-04-25 10:08:05 -04:00
  • 2c7eb3c755 only apply ulimits to suricata container if user enable mmap-locked #12865 m0duspwnens 2024-04-25 10:05:59 -04:00
  • cc17de2184 Merge pull request #12864 from Security-Onion-Solutions/fix/exclude_suricata weslambert 2024-04-25 09:23:38 -04:00
  • b424426298 Exclude suricata #12864 weslambert 2024-04-25 09:14:18 -04:00
  • 03f9160fcc Merge pull request #12860 from Security-Onion-Solutions/issue/12856 Josh Patterson 2024-04-25 09:07:44 -04:00
  • d50de804a8 update annotation #12860 m0duspwnens 2024-04-25 09:04:34 -04:00
  • 983ef362e9 Merge pull request #12858 from Security-Onion-Solutions/fix/index_sorting weslambert 2024-04-25 08:54:22 -04:00
  • d88c1a5e0a Merge pull request #12861 from Security-Onion-Solutions/2.4/detectionlogs Josh Brower 2024-04-24 20:07:32 -04:00
  • 44afa55274 Fix comments about deletion #12858 weslambert 2024-04-24 17:41:37 -04:00
  • ab832e4bb2 Include logstash-prefixed indices weslambert 2024-04-24 17:17:53 -04:00
  • 3c3ed8b5c5 Add runtime status logs #12861 DefensiveDepth 2024-04-24 16:33:47 -04:00
  • c9d9979f22 allow for enabled/disable of so-elasticsearch-indices-delete cronjob m0duspwnens 2024-04-24 16:18:45 -04:00
  • 383420b554 Merge pull request #12859 from Security-Onion-Solutions/issue/12637 Josh Patterson 2024-04-24 15:44:37 -04:00
  • 73b5bb1a75 add memlock to so-suricata container #12859 m0duspwnens 2024-04-24 15:35:17 -04:00
  • 59a02635ed Change index sorting weslambert 2024-04-24 15:18:49 -04:00
  • 13a6520a8c mmap-locked default no m0duspwnens 2024-04-24 13:50:12 -04:00
  • 4b7f826a2a quote is so true becomes yes m0duspwnens 2024-04-24 13:29:55 -04:00
  • 0bd0c7b1ec allow for mmap-locked to be configured m0duspwnens 2024-04-24 13:26:25 -04:00
  • 05244cfd75 watch files change engine m0duspwnens 2024-04-24 13:19:39 -04:00
  • 428fe787c4 Merge pull request #12852 from Security-Onion-Solutions/fix/elastic_max_age weslambert 2024-04-24 10:15:06 -04:00
  • 1b3a0a3de8 Remove hot max_age #12852 weslambert 2024-04-24 10:11:02 -04:00
  • 96ec285241 Merge pull request #12848 from Security-Onion-Solutions/fix/elastic_annotation weslambert 2024-04-24 09:22:05 -04:00
  • 75b5e16696 Update description, type, and regex #12848 weslambert 2024-04-24 09:14:39 -04:00
  • 8a0a435700 Fix warm description weslambert 2024-04-24 08:35:19 -04:00
  • e53e7768a0 check status before stopping service #12846 Pete 2024-04-23 21:24:39 +00:00
  • 36573d6005 Update kafka cert permissions reyesj2 2024-04-23 16:45:36 -04:00
  • aa0c589361 Update kafka managed node pillar template to include its process.role reyesj2 2024-04-23 13:51:12 -04:00
  • bef408b944 Merge pull request #12844 from Security-Onion-Solutions/fix/elastic_annotation weslambert 2024-04-23 10:47:04 -04:00
  • 691b02a15e Fix warm description #12844 weslambert 2024-04-23 10:40:09 -04:00
  • fc1c41e5a4 Merge pull request #12841 from Security-Onion-Solutions/2.4/logfix Josh Brower 2024-04-23 07:36:02 -04:00
  • 58ddd55123 Exclude yara runtime log #12841 DefensiveDepth 2024-04-23 07:28:07 -04:00
  • 685b80e519 Merge remote-tracking branch 'remotes/origin/kaffytaffy' into reyesj2/kafka reyesj2 2024-04-22 16:45:59 -04:00
  • 5a401af1fd Update kafka process_x_roles annotation reyesj2 2024-04-22 16:44:35 -04:00
  • 25d63f7516 Setup kafka reactor for managing kafka controllers globally reyesj2 2024-04-22 16:42:59 -04:00
  • d402943403 Merge pull request #12773 from Security-Onion-Solutions/reyesj2/kismet Jorge Reyes 2024-04-22 15:59:22 -04:00
  • 64c43b1a55 Merge pull request #12805 from Security-Onion-Solutions/2.4/detectiondefaults Josh Brower 2024-04-19 16:53:07 -04:00
  • a237ef5d96 Update default queries #12805 DefensiveDepth 2024-04-19 16:33:35 -04:00
  • 6c5e0579cf logging changes. ensure salt master has pillarWatch engine m0duspwnens 2024-04-19 09:32:32 -04:00
  • 4ac04a1a46 add kafkapass soc annotation reyesj2 2024-04-18 16:46:36 -04:00
  • 746128e37b update so-kafka-clusterid This is a temporary script used to setup kafka secret and clusterid needed for kafka to start. This scripts functionality will be replaced by soup/setup scripts reyesj2 2024-04-18 15:13:29 -04:00
  • fe81ffaf78 Variables no longer used. Replaced by map file reyesj2 2024-04-18 15:11:22 -04:00
  • 1f6eb9cdc3 match keys better. go through files reverse first found is prio m0duspwnens 2024-04-18 13:50:37 -04:00
  • c48da45ac3 Merge pull request #12820 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-18 11:59:57 -04:00
  • 5cc358de4e Update map files to handle empty kafka:nodes pillar reyesj2 2024-04-18 11:58:25 -04:00
  • 406dda6051 Update so-elasticsearch-cluster-space-used #12820 Doug Burks 2024-04-18 11:48:15 -04:00
  • 229a989914 Update so-elasticsearch-cluster-space-total Doug Burks 2024-04-18 11:47:01 -04:00
  • 6c6647629c Refactor yara for compilation DefensiveDepth 2024-04-18 11:32:17 -04:00
  • 610dd2c08d improve it m0duspwnens 2024-04-18 11:11:14 -04:00
  • 506bbd314d more comments, better logging m0duspwnens 2024-04-18 10:26:10 -04:00
  • 7f9bc1fc0f Merge pull request #12817 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-18 09:30:55 -04:00
  • 8d9aae1983 FEATURE: Add queue=True to so-checkin so that it will wait for any running states #12815 #12817 Doug Burks 2024-04-18 09:28:30 -04:00
  • 4caa6a10b5 watch a pillar in files and take action m0duspwnens 2024-04-17 18:09:04 -04:00
  • 665b7197a6 Update Kafka nodeid Update so-minion to include running kafka.nodes state to ensure nodeid is generated for new brokers reyesj2 2024-04-17 17:08:41 -04:00
  • 3854620bcd Merge pull request #12810 from Security-Onion-Solutions/TOoSmOotH-patch-1 Mike Reeves 2024-04-17 13:21:04 -04:00
  • 67a57e9df7 Update limited-analyst.json #12810 Mike Reeves 2024-04-17 13:14:45 -04:00
  • 4b79623ce3 watch pillar files for changes and do something m0duspwnens 2024-04-16 16:51:35 -04:00
  • ff28476191 Fix compile_yara path DefensiveDepth 2024-04-16 13:10:17 -04:00
  • 8cc4d2668e Move compile_yara DefensiveDepth 2024-04-16 12:52:14 -04:00
  • dbfb178556 Add test DefensiveDepth 2024-04-16 12:22:53 -04:00
  • c4994a208b restart salt minion if a manager and signing policies change m0duspwnens 2024-04-15 11:37:21 -04:00
  • eedea2ca88 Merge remote-tracking branch 'remotes/origin/kaffytaffy' into reyesj2/kafka reyesj2 2024-04-12 16:24:33 -04:00
  • de6ea29e3b update default process.role to broker only reyesj2 2024-04-12 16:18:53 -04:00
  • bb983d4ba2 just broker as default process m0duspwnens 2024-04-12 16:16:03 -04:00
  • 5e8b16569f Merge pull request #12793 from Security-Onion-Solutions/2.4/detectiondefaults Josh Brower 2024-04-12 13:54:06 -04:00
  • c014508519 need /opt/so/conf/ca/cacerts on receiver for kafka to run m0duspwnens 2024-04-12 13:50:25 -04:00
  • f5e42e73af Add docs for ruleset change #12793 DefensiveDepth 2024-04-12 13:30:20 -04:00
  • fcfbb1e857 Merge kaffytaffy #12792 reyesj2 2024-04-12 12:50:56 -04:00
  • 911ee579a9 Typo reyesj2 2024-04-12 12:16:20 -04:00
  • a6ff92b099 Note to remove so-kafka-clusterid. Update soup and setup to generate needed kafka pillar values reyesj2 2024-04-12 12:11:18 -04:00
  • d73ba7dd3e order kafka pillar assignment m0duspwnens 2024-04-12 11:55:26 -04:00
  • 04ddcd5c93 add receiver managersearch and standalone to kafka.nodes pillar m0duspwnens 2024-04-12 11:52:57 -04:00
  • af29ae1968 Merge kaffytaffy reyesj2 2024-04-12 11:43:46 -04:00
  • fbd3cff90d Make global.pipeline use GLOBALMERGED value reyesj2 2024-04-12 11:21:19 -04:00
  • 0ed9894b7e create kratos local pillar dirs during setup m0duspwnens 2024-04-12 11:19:46 -04:00
  • a54a72c269 move kafka_cluster_id to kafka:cluster_id m0duspwnens 2024-04-12 11:19:20 -04:00
  • 5b81a73e58 Merge pull request #12791 from Security-Onion-Solutions/2.4/detectiondefaults Josh Brower 2024-04-12 09:01:38 -04:00
  • 49ccd86c39 Fix fingerprint paths #12791 DefensiveDepth 2024-04-12 08:35:44 -04:00
  • f514e5e9bb add kafka to receiver m0duspwnens 2024-04-11 16:23:05 -04:00
  • 3955587372 Use global.pipeline for redis / kafka states reyesj2 2024-04-11 16:20:09 -04:00
  • 6b28dc72e8 Update annotation for global.pipeline reyesj2 2024-04-11 15:38:33 -04:00
  • ca7253a589 Run kafka-clusterid script when pillar values are missing reyesj2 2024-04-11 15:38:03 -04:00
  • af53dcda1b Remove references to kafkanode reyesj2 2024-04-11 15:32:00 -04:00
  • 55cf90f477 merge 2.4/dev #12773 reyesj2 2024-04-11 14:44:59 -04:00