Commit Graph

  • c269fb90ac Added a Kismet Wifi devices dashboard for an overview of kismet data reyesj2 2024-04-11 14:41:54 -04:00
  • 1250a728ac Merge pull request #12769 from Security-Onion-Solutions/TOoSmOotH-patch-3 Mike Reeves 2024-04-11 14:30:17 -04:00
  • 68e016090b Fix network.wireless.ssid not parsing reyesj2 2024-04-11 13:21:54 -04:00
  • fd689a4607 Fix typo in ingest pipeline Test to fix duplicate events in SOC, by removing conflicting field event.created reyesj2 2024-04-11 11:18:04 -04:00
  • ae09869417 Merge pull request #12780 from Security-Onion-Solutions/2.4/detectiondefaults Josh Brower 2024-04-11 09:32:34 -04:00
  • 1c5f02ade2 Update annotations #12780 DefensiveDepth 2024-04-11 09:21:08 -04:00
  • ed97aa4e78 Enable Detections Adv by default DefensiveDepth 2024-04-11 08:21:20 -04:00
  • 7124f04138 Update ingest pipelines to match updated mappings reyesj2 2024-04-10 16:13:06 -04:00
  • 2ab9cbba61 Update wording for Kismet poll interval annotation reyesj2 2024-04-10 16:12:22 -04:00
  • 4097e1d81a Create mappings for Kismet integration reyesj2 2024-04-10 16:10:27 -04:00
  • d3bd56b131 disable logstash and redis if kafka enabled m0duspwnens 2024-04-10 14:13:27 -04:00
  • e9e61ea2d8 Merge remote-tracking branch 'origin/2.4/dev' into kaffytaffy m0duspwnens 2024-04-10 13:14:13 -04:00
  • 86b984001d annotations and enable/disable from ui m0duspwnens 2024-04-10 10:39:06 -04:00
  • 2206553e03 Update analyst.json #12769 Mike Reeves 2024-04-10 09:49:21 -04:00
  • fa7f8104c8 Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy m0duspwnens 2024-04-09 11:13:02 -04:00
  • bd5fe43285 jinja config files m0duspwnens 2024-04-09 11:07:53 -04:00
  • d38051e806 fix client and server properties formatting m0duspwnens 2024-04-09 10:36:37 -04:00
  • daa5342986 items not keys in for loop m0duspwnens 2024-04-09 10:22:05 -04:00
  • c48436ccbf fix dict update m0duspwnens 2024-04-09 10:19:17 -04:00
  • 7aa00faa6c fix var m0duspwnens 2024-04-09 09:31:54 -04:00
  • 6217a7b9a9 add defaults and jijafy kafka config m0duspwnens 2024-04-09 09:27:21 -04:00
  • d67ebabc95 Remove logstash output to kafka pipeline. Add additional topics for searchnodes to ingest and add partition/offset info to event reyesj2 2024-04-08 16:38:03 -04:00
  • b9474b9352 Merge pull request #12766 from Security-Onion-Solutions/2.4/sigma-pipeline Josh Brower 2024-04-08 16:35:24 -04:00
  • 376efab40c Ship Defender logs #12766 DefensiveDepth 2024-04-08 14:01:38 -04:00
  • 65274e89d7 Add client_id to logstash pipeline. To identify which searchnode is pulling messages reyesj2 2024-04-05 15:38:00 -04:00
  • acf29a6c9c Merge pull request #12760 from Security-Onion-Solutions/cogburn/detection-author-remap coreyogburn 2024-04-05 11:39:53 -06:00
  • 721e04f793 initial logstash input from kafka over ssl reyesj2 2024-04-05 13:37:14 -04:00
  • 00cea6fb80 Detection Author as a Keyword instead of Text #12760 Corey Ogburn 2024-04-05 11:22:47 -06:00
  • 433309ef1a Generate kafka cluster id if it doesn't exist reyesj2 2024-04-05 09:35:12 -04:00
  • cbc95d0b30 Merge pull request #12759 from Security-Onion-Solutions/TOoSmOotH-patch-2 Mike Reeves 2024-04-05 08:17:50 -04:00
  • 21f86be8ee Update so-log-check #12759 Mike Reeves 2024-04-05 08:03:42 -04:00
  • 8e38c3763e Merge pull request #12756 from Security-Onion-Solutions/2.4/detections-defaults Josh Brower 2024-04-04 17:00:38 -04:00
  • ca807bd6bd Use list not string #12756 DefensiveDepth 2024-04-04 16:58:39 -04:00
  • 735cfb4c29 Autogenerate kafka topics when a message it sent to non-existing topic reyesj2 2024-04-04 16:45:58 -04:00
  • 6202090836 Merge remote-tracking branch 'origin/kaffytaffy' into reyesj2/kafka reyesj2 2024-04-04 16:27:06 -04:00
  • 436cbc1f06 Add kafka signing_policy for client/server auth. Add kafka-client cert on manager so manager can interact with kafka using its own cert reyesj2 2024-04-04 16:21:29 -04:00
  • 40b08d737c Generate kafka keystore on changes to kafka.key reyesj2 2024-04-04 16:16:53 -04:00
  • 4c5b42b898 restart container on server config changes m0duspwnens 2024-04-04 15:47:01 -04:00
  • 7a6b72ebac add so-kafka to manager for firewall m0duspwnens 2024-04-04 15:46:11 -04:00
  • f72cbd5f23 Merge pull request #12755 from Security-Onion-Solutions/2.4/detections-defaults Josh Brower 2024-04-04 11:33:59 -04:00
  • 1d7e47f589 Merge pull request #12682 from Security-Onion-Solutions/2.4/soup-playbook Josh Brower 2024-04-04 11:28:09 -04:00
  • 49d5fa95a2 Detections tweaks #12755 DefensiveDepth 2024-04-04 11:26:44 -04:00
  • 204f44449a Merge pull request #12754 from Security-Onion-Solutions/jertel/ana Jason Ertel 2024-04-04 10:39:07 -04:00
  • 6046848ee7 skip telemetry summary in airgap mode #12754 Jason Ertel 2024-04-04 10:25:32 -04:00
  • b0aee238b1 Merge pull request #12753 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-04 09:35:21 -04:00
  • 5639440e3d Update soup 2.3/main Mike Reeves 2024-04-04 09:34:42 -04:00
  • d8ac3f1292 FEATURE: Add dashboards specific to Elastic Agent #12746 #12753 Doug Burks 2024-04-04 09:30:05 -04:00
  • 8788b34c8a Merge pull request #12752 from Security-Onion-Solutions/updates23 Mike Reeves 2024-04-04 09:25:41 -04:00
  • 784ec54795 2.3 updates #12752 Mike Reeves 2024-04-04 09:24:17 -04:00
  • 54fce4bf8f 2.3 updates Mike Reeves 2024-04-04 09:21:16 -04:00
  • c4ebe25bab Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-04 09:18:37 -04:00
  • 7b4e207329 Merge pull request #12751 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-04 09:13:53 -04:00
  • 5ec3b834fb FEATURE: Add Events table columns for event.module sigma #12743 #12751 Doug Burks 2024-04-04 09:11:41 -04:00
  • 7668fa1396 Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-04 09:03:29 -04:00
  • 470b0e4bf6 Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-04 08:55:13 -04:00
  • d3f163bf9e Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-04 08:54:04 -04:00
  • 4b31632dfc Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-04 08:52:37 -04:00
  • c2f7f7e3a5 Remove dup line #12682 DefensiveDepth 2024-04-04 08:52:30 -04:00
  • 07cb0c7d46 Merge remote-tracking branch 'origin/2.4/dev' into 2.4/soup-playbook DefensiveDepth 2024-04-04 08:51:09 -04:00
  • 14c824143b Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-04 08:48:44 -04:00
  • c75c411426 Merge pull request #12749 from Security-Onion-Solutions/jertel/ana Jason Ertel 2024-04-04 07:53:18 -04:00
  • a7fab380b4 clarify telemetry annotation #12749 Jason Ertel 2024-04-04 07:51:23 -04:00
  • a9517e1291 clarify telemetry annotation Jason Ertel 2024-04-04 07:49:30 -04:00
  • 1017838cfc Merge pull request #12748 from Security-Onion-Solutions/2.4/exclude-elastalert Josh Brower 2024-04-04 06:57:22 -04:00
  • 1d221a574b Exclude Elastalert EQL errors #12748 DefensiveDepth 2024-04-04 06:48:25 -04:00
  • a35bfc4822 Merge pull request #12747 from Security-Onion-Solutions/jertel/ana Jason Ertel 2024-04-03 21:50:38 -04:00
  • 7c64fc8c05 do not prompt about telemetry on airgap installs #12747 Jason Ertel 2024-04-03 18:08:42 -04:00
  • f66cca96ce YARA casing DefensiveDepth 2024-04-03 16:17:29 -04:00
  • f50ae02559 Update soup Mike Reeves 2024-04-03 15:58:56 -04:00
  • 12da7db22c Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-03 15:38:23 -04:00
  • 1b8584d4bb allow manager to manager on kafka ports m0duspwnens 2024-04-03 15:36:35 -04:00
  • 9c59f42c16 Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-03 15:23:09 -04:00
  • fb5eea8284 Merge pull request #12744 from Security-Onion-Solutions/cogburn/detection-state coreyogburn 2024-04-03 13:19:26 -06:00
  • 9db9af27ae Attempt to fix 2.3 when main repo changes Mike Reeves 2024-04-03 15:14:50 -04:00
  • 0f50a265cf Update SOC Config with State File Paths #12744 Corey Ogburn 2024-04-03 13:12:18 -06:00
  • 3e05c04aa1 Merge pull request #12731 from Security-Onion-Solutions/jertel/ana Jason Ertel 2024-04-03 14:51:41 -04:00
  • 8f8896c505 fix link #12731 Jason Ertel 2024-04-03 14:45:39 -04:00
  • 941a841da0 fix link Jason Ertel 2024-04-03 14:41:57 -04:00
  • 13105c4ab3 Generate certs for use with elasticfleet kafka output policy reyesj2 2024-04-03 14:34:07 -04:00
  • dc27bbb01d Set kafka heap size. To be later configured from SOC reyesj2 2024-04-03 14:30:52 -04:00
  • 2b8a051525 fix link Jason Ertel 2024-04-03 14:30:09 -04:00
  • 1c7cc8dd3b Merge pull request #12741 from Security-Onion-Solutions/metrics Mike Reeves 2024-04-03 12:56:17 -04:00
  • 58d081eed1 Merge pull request #12742 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-03 12:48:24 -04:00
  • 9078b2bad2 FEATURE: Add Events table columns for event.module kratos #12740 #12742 Doug Burks 2024-04-03 12:46:29 -04:00
  • 8889c974b8 Change code to allow for non root #12741 Mike Reeves 2024-04-03 12:38:59 -04:00
  • f615a73120 Merge pull request #12739 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-03 12:01:08 -04:00
  • 66844af1c2 FEATURE: Add dashboard for SOC Login Failures #12738 #12739 Doug Burks 2024-04-03 11:54:53 -04:00
  • a0b7d89eb6 Merge pull request #12734 from Security-Onion-Solutions/metrics Mike Reeves 2024-04-03 11:12:53 -04:00
  • c31e459c2b Change metrics reporting order #12734 Mike Reeves 2024-04-03 11:06:00 -04:00
  • b863060df1 kafka broker and listener on 0.0.0.0 m0duspwnens 2024-04-03 11:05:24 -04:00
  • d96d696c35 Merge pull request #12735 from Security-Onion-Solutions/feature/cef weslambert 2024-04-03 10:49:44 -04:00
  • 105eadf111 Add cef #12735 Wes 2024-04-03 14:40:41 +00:00
  • ca57c20691 suppress soup update output for cleaner console Jason Ertel 2024-04-03 10:31:24 -04:00
  • c4767bfdc8 suppress soup update output for cleaner console Jason Ertel 2024-04-03 10:28:43 -04:00
  • 0de1f76139 add agent count to reposync Mike Reeves 2024-04-03 10:26:59 -04:00
  • 5f4a0fdfad suppress soup update output for cleaner console Jason Ertel 2024-04-03 10:26:48 -04:00
  • 18f95e867f port 9093 for kafka docker m0duspwnens 2024-04-03 10:24:53 -04:00
  • ed6137a76a allow sensor and searchnode to connect to manager kafka ports m0duspwnens 2024-04-03 10:24:10 -04:00
  • c3f02a698e add kafka nodes as extra hosts for the container m0duspwnens 2024-04-03 10:23:36 -04:00
  • db106f8ca1 listen on 0.0.0.0 for CONTROLLER m0duspwnens 2024-04-03 10:22:47 -04:00