Commit Graph

  • c712529cf6 suppress soup update output for cleaner console Jason Ertel 2024-04-03 10:21:35 -04:00
  • 976ddd3982 add agentstatus to telegraf Mike Reeves 2024-04-03 10:06:08 -04:00
  • 64748b98ad add agentstatus to telegraf Mike Reeves 2024-04-03 09:56:12 -04:00
  • 3335612365 add agentstatus to telegraf Mike Reeves 2024-04-03 09:54:16 -04:00
  • 513273c8c3 add agentstatus to telegraf Mike Reeves 2024-04-03 09:43:55 -04:00
  • 0dfde3c9f2 add agentstatus to telegraf Mike Reeves 2024-04-03 09:40:14 -04:00
  • 0efdcfcb52 add agentstatus to telegraf Mike Reeves 2024-04-03 09:36:02 -04:00
  • fbdcc53fe0 Merge pull request #12732 from Security-Onion-Solutions/2.4/detections-defaults Josh Brower 2024-04-03 09:01:09 -04:00
  • 8e47cc73a5 kafka.nodes pillar to lf m0duspwnens 2024-04-03 08:54:17 -04:00
  • 639bf05081 add so-manager to kafka.nodes pillar m0duspwnens 2024-04-03 08:52:26 -04:00
  • c1b5ef0891 ensure so-yaml.py is updated during soup Jason Ertel 2024-04-03 08:44:40 -04:00
  • a8f25150f6 Feature - auto-enabled Sigma rules #12732 DefensiveDepth 2024-04-03 08:21:50 -04:00
  • 1ee2a6d37b Improve wording for Airgap annotation Jason Ertel 2024-04-03 08:21:30 -04:00
  • f64d9224fb Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into metrics Mike Reeves 2024-04-02 17:22:20 -04:00
  • 4e142e0212 put alphabetical m0duspwnens 2024-04-02 16:47:35 -04:00
  • c9bf1c86c6 Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy m0duspwnens 2024-04-02 16:40:47 -04:00
  • 82830c8173 Fix typos and fix error related to elasticsearch saltstate being called from logstash state. Logstash will be removed from kafkanodes in future reyesj2 2024-04-02 16:37:39 -04:00
  • 7f5741c43b Fix kafka storage setup reyesj2 2024-04-02 16:36:22 -04:00
  • 643d4831c1 CRLF -> LF reyesj2 2024-04-02 16:35:14 -04:00
  • b032eed22a Update kafka to use manager docker registry reyesj2 2024-04-02 16:34:06 -04:00
  • 1b49c8540e Fix kafka keystore script reyesj2 2024-04-02 16:32:15 -04:00
  • f7534a0ae3 make manager download so-kafka container m0duspwnens 2024-04-02 16:01:12 -04:00
  • b6187ab769 Improve wording for Airgap annotation Jason Ertel 2024-04-02 15:54:39 -04:00
  • 780ad9eb10 add kafka to manager nodes m0duspwnens 2024-04-02 15:50:25 -04:00
  • 283939b18a Gather metrics from elastic agent to influx Mike Reeves 2024-04-02 15:36:01 -04:00
  • e25bc8efe4 Merge remote-tracking branch 'origin/reyesj2/kafka' into kaffytaffy m0duspwnens 2024-04-02 13:36:47 -04:00
  • 3b112e20e3 fix syntax error Jason Ertel 2024-04-02 12:32:33 -04:00
  • 26abe90671 Removed duplicate kafka setup reyesj2 2024-04-02 12:19:46 -04:00
  • 23a6c4adb6 Merge pull request #12725 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-02 10:54:15 -04:00
  • 2f03cbf115 FEATURE: Add Events table columns for event.module strelka #12716 #12725 Doug Burks 2024-04-02 10:42:20 -04:00
  • a678a5a416 Merge pull request #12724 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-02 10:15:20 -04:00
  • b2b54ccf60 FEATURE: Add Events table columns for event.module strelka #12716 #12724 Doug Burks 2024-04-02 10:11:16 -04:00
  • 55e71c867c Merge pull request #12723 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-02 10:04:21 -04:00
  • 6c2437f8ef FEATURE: Add Events table columns for event.module playbook #12703 #12723 Doug Burks 2024-04-02 09:55:56 -04:00
  • 261f2cbaf7 Merge pull request #12722 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-04-02 09:43:15 -04:00
  • f083558666 break out into sep func Jason Ertel 2024-04-02 09:42:43 -04:00
  • 505eeea66a Update defaults.yaml #12722 Doug Burks 2024-04-02 09:39:54 -04:00
  • 1001aa665d Merge pull request #12720 from Security-Onion-Solutions/2.4/detections-defaults Josh Brower 2024-04-02 09:21:06 -04:00
  • 7f488422b0 Add default columns #12720 DefensiveDepth 2024-04-02 09:13:27 -04:00
  • 21f78a039a Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main Mike Reeves 2024-04-02 08:47:08 -04:00
  • 94c7dabd9e Merge pull request #12693 from Security-Onion-Solutions/dev master 2.3.300-20240401 Mike Reeves 2024-04-01 11:37:59 -04:00
  • 2f3b92887b Merge pull request #12714 from Security-Onion-Solutions/2.3.300 #12693 dev Mike Reeves 2024-04-01 11:26:43 -04:00
  • d15678f638 Update VERIFY_ISO.md #12714 Mike Reeves 2024-04-01 11:25:29 -04:00
  • 93c29bc1da 2.3.300 Mike Reeves 2024-04-01 11:22:31 -04:00
  • f17d8d3369 analytics Jason Ertel 2024-04-01 10:59:44 -04:00
  • ff777560ac limit col size Jason Ertel 2024-04-01 10:35:15 -04:00
  • 2c68fd6311 limit col size Jason Ertel 2024-04-01 10:32:54 -04:00
  • c1bf710e46 limit col size Jason Ertel 2024-04-01 10:32:25 -04:00
  • 9d2b40f366 Merge branch '2.4/dev' into jertel/ana Jason Ertel 2024-04-01 09:50:38 -04:00
  • 3aea2dec85 analytics Jason Ertel 2024-04-01 09:50:18 -04:00
  • 65f6b7022c Merge pull request #12702 from Security-Onion-Solutions/cogburn/yaml-fix coreyogburn 2024-03-29 15:59:34 -06:00
  • e5a3a54aea Proper YAML #12702 Corey Ogburn 2024-03-29 14:31:43 -06:00
  • be88dbe181 Merge pull request #12700 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-29 15:41:14 -04:00
  • b64ed5535e FEATURE: Add individual dashboards for Zeek SSL and Suricata SSL logs #12699 #12700 Doug Burks 2024-03-29 15:29:38 -04:00
  • 5be56703e9 Merge pull request #12698 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-29 14:46:39 -04:00
  • 0c7ba62867 FEATURE: Add Events table columns for zeek ssl and suricata ssl #12697 #12698 Doug Burks 2024-03-29 14:44:29 -04:00
  • d9d851040c Merge pull request #12696 from Security-Onion-Solutions/cogburn/manual-sync coreyogburn 2024-03-29 12:43:08 -06:00
  • e747a4e3fe New Settings for Manual Sync in Detections #12696 Corey Ogburn 2024-03-29 12:25:03 -06:00
  • 000d15a53c Kismet integration: TODO Elasticsearch mappings reyesj2 2024-03-29 13:56:01 -04:00
  • cc2164221c Merge pull request #12695 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-29 13:04:09 -04:00
  • 102c3271d1 FEATURE: Add process.command_line to Process Info and Process Ancestry dashboards #12694 #12695 Doug Burks 2024-03-29 12:04:47 -04:00
  • 56263675f6 Merge pull request #12692 from Security-Onion-Solutions/2.3.300 Mike Reeves 2024-03-29 09:55:15 -04:00
  • 1599e69851 2.3.300 #12692 Mike Reeves 2024-03-29 09:43:50 -04:00
  • 32b8649c77 Add more error checking DefensiveDepth 2024-03-28 14:31:02 -04:00
  • 9c5ba92589 Check if container is running first DefensiveDepth 2024-03-28 13:23:40 -04:00
  • d2c9e0ea4a Cleanup DefensiveDepth 2024-03-28 13:04:48 -04:00
  • 2928b71616 Merge pull request #12683 from Security-Onion-Solutions/jertel/lc Jason Ertel 2024-03-28 09:48:26 -04:00
  • 216b8c01bf disregard errors that in removed applications that occurred before the upgrade #12683 Jason Ertel 2024-03-28 09:31:39 -04:00
  • 5ae7e27ace Merge pull request #12677 from Security-Onion-Solutions/fix/strelka_yara_ignore weslambert 2024-03-27 16:17:34 -04:00
  • ce0c9f846d Remove containers from so-status DefensiveDepth 2024-03-27 16:13:52 -04:00
  • 945d2abeed Ignore more rules #12677 weslambert 2024-03-27 16:13:30 -04:00
  • ba262ee01a Check to see if Playbook is enabled DefensiveDepth 2024-03-27 15:43:25 -04:00
  • b571eeb8e6 Initial cut of .70 soup changes DefensiveDepth 2024-03-27 14:58:16 -04:00
  • 7fe377f899 Merge pull request #12674 from Security-Onion-Solutions/ipv6fix Mike Reeves 2024-03-27 09:48:01 -04:00
  • d57f773072 Fix regex to allow ipv6 in bpfs #12674 Mike Reeves 2024-03-27 09:36:42 -04:00
  • 389357ad2b Merge pull request #12667 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-26 16:11:46 -04:00
  • e2caf4668e FEATURE: Add Events table columns for event.module elastic_agent #12666 #12667 Doug Burks 2024-03-26 16:08:41 -04:00
  • 63a58efba4 Merge pull request #12656 from Security-Onion-Solutions/2.4/detections-fixes Josh Brower 2024-03-26 09:33:38 -04:00
  • bbcd3116f7 Fixes #12656 DefensiveDepth 2024-03-26 09:31:46 -04:00
  • 9c12aa261e Merge pull request #12660 from Security-Onion-Solutions/kilo Josh Brower 2024-03-26 08:31:11 -04:00
  • cc0f4847ba Casing and validation DefensiveDepth 2024-03-26 08:10:57 -04:00
  • 923b80ba60 Merge pull request #12663 from Security-Onion-Solutions/feature/improve-soc-dashboards Doug Burks 2024-03-26 07:52:54 -04:00
  • 7c4ea8a58e Add Detections SOC Config DefensiveDepth 2024-03-26 07:39:39 -04:00
  • 20bd9a9701 FEATURE: Include additional groupby fields in Dashboards relating to sankey diagrams #12657 #12663 Doug Burks 2024-03-26 07:39:24 -04:00
  • f0cb30a649 Merge pull request #12659 from Security-Onion-Solutions/2.4/remove-playbook #12660 Josh Brower 2024-03-25 21:12:22 -04:00
  • 94ee761207 Remove Playbook ref #12659 DefensiveDepth 2024-03-25 21:11:47 -04:00
  • 0a5dc411d0 Merge pull request #12658 from Security-Onion-Solutions/2.4/remove-playbook Josh Brower 2024-03-25 19:45:51 -04:00
  • d7ecad4333 Initial cut to remove Playbook and deps #12658 DefensiveDepth 2024-03-25 19:42:31 -04:00
  • 49fa800b2b Add bindings for sigma repos DefensiveDepth 2024-03-25 14:45:50 -04:00
  • 446f1ffdf5 merge 2.4/dev reyesj2 2024-03-25 13:55:48 -04:00
  • 57553bc1e5 Merge pull request #12652 from Security-Onion-Solutions/feature/pfsense_suricata weslambert 2024-03-25 10:10:13 -04:00
  • df058b3f4a Merge branch '2.4/dev' into feature/pfsense_suricata #12652 weslambert 2024-03-25 10:08:03 -04:00
  • 5e21da443f Minor verbiage updates Wes 2024-03-25 13:58:32 +00:00
  • 7898277a9b Merge pull request #12651 from Security-Onion-Solutions/issue/12637 Josh Patterson 2024-03-25 09:37:52 -04:00
  • 029d8a0e8f handle yes/no on checksum-checks #12651 m0duspwnens 2024-03-25 09:30:41 -04:00
  • b8d33ab983 Merge pull request #12639 from Security-Onion-Solutions/2.4/enable-detections Josh Brower 2024-03-25 09:30:01 -04:00
  • e124791d5d Merge pull request #12650 from Security-Onion-Solutions/fix/soc_template weslambert 2024-03-25 09:29:19 -04:00
  • 8ae30d0a77 Merge pull request #12640 from Security-Onion-Solutions/cogburn/sigma-repo-support coreyogburn 2024-03-22 14:24:18 -06:00
  • 81f3d69eb9 remove mmap-locked. m0duspwnens 2024-03-22 15:55:59 -04:00
  • 237946e916 Specify Folder in Rule Repo #12640 Corey Ogburn 2024-03-22 13:51:59 -06:00