Commit Graph

  • 9df3a8fc18 Merge pull request #11740 from Security-Onion-Solutions/fix/elastic_templates weslambert 2023-11-08 15:20:01 -05:00
  • 36098e6314 Remove template files #11740 weslambert 2023-11-08 14:32:58 -05:00
  • 32079a7bce Merge pull request #11734 from Security-Onion-Solutions/fix/elastic_scripts Jason Ertel 2023-11-08 12:19:00 -05:00
  • 3701c1d847 ignore retry logging #11734 Jason Ertel 2023-11-08 11:50:56 -05:00
  • f46aef1611 remove comments from BPFs #11741 m0duspwnens 2023-11-08 11:23:19 -05:00
  • d256be3eb3 allow template loads to partially succeed only on the initial attempt Jason Ertel 2023-11-08 10:32:11 -05:00
  • 653fda124f Check expected with retry Wes 2023-11-08 13:02:17 +00:00
  • b46e86c39b Extend index template loading to 60 attempts and a total of ~5 minutes Wes 2023-11-08 02:29:09 +00:00
  • de9f9549af Extend template loading to 24 attempts and a total of ~2 minutes Wes 2023-11-07 23:55:03 +00:00
  • 749e22e4b9 Fix if statement weslambert 2023-11-07 17:29:38 -05:00
  • 69ec1987af Fix if statement weslambert 2023-11-07 17:28:37 -05:00
  • 570624da7e Remove RETURN_CODE Wes 2023-11-07 21:09:29 +00:00
  • 7772657b4b Remove RETURN_CODE Wes 2023-11-07 21:06:35 +00:00
  • 6d97667634 Merge branch '2.4/dev' into kilo Jason Ertel 2023-11-07 15:59:52 -05:00
  • 1676c84f9c Use the retry function so-elasticsearch-query Wes 2023-11-07 19:56:50 +00:00
  • e665899e4d Merge pull request #11735 from Security-Onion-Solutions/fix/elastic_agent_template Jason Ertel 2023-11-07 14:11:47 -05:00
  • 1dcca0bfd3 Change pipeline to 1.13.1 #11735 weslambert 2023-11-07 12:17:51 -05:00
  • 0b4a246ddb State file changes and retry logic Wes 2023-11-07 16:44:42 +00:00
  • f97dc70fcb Merge pull request #11732 from Security-Onion-Solutions/fix/elastic_agent_template weslambert 2023-11-07 09:08:25 -05:00
  • cce80eb2fb Change pipeline to 1.8.0 #11732 weslambert 2023-11-07 09:02:48 -05:00
  • 2f95512199 Merge branch '2.4/dev' into kilo Jason Ertel 2023-11-06 11:27:58 -05:00
  • b008661b6b Merge pull request #11726 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-06 11:27:33 -05:00
  • b99c7ce76e improve verbosity of setup logs #11726 Jason Ertel 2023-11-06 11:22:35 -05:00
  • c30a0d5b5b Better error handling and state file management Wes 2023-11-06 14:29:01 +00:00
  • 74eda68d84 Exit if unable to communicate with Elasticsearch Wes 2023-11-06 13:16:35 +00:00
  • ef1dfc3152 Merge pull request #11722 from Security-Onion-Solutions/2.4/packageupgrade Josh Brower 2023-11-06 08:06:13 -05:00
  • f6cd35e143 Set execute permissions #11722 Josh Brower 2023-11-06 08:03:31 -05:00
  • d010af9a24 Merge pull request #11718 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-04 16:32:02 -04:00
  • 7a0b21647f disregard false positives #11718 Jason Ertel 2023-11-04 10:05:37 -04:00
  • 610374816d Merge pull request #11714 from Security-Onion-Solutions/change/so-minion Josh Patterson 2023-11-03 16:43:16 -04:00
  • 3ff74948d8 Merge pull request #11713 from Security-Onion-Solutions/2.4/agentupdate Josh Brower 2023-11-03 15:23:55 -04:00
  • 0086c24729 Upgrade Elastic Agent #11713 Josh Brower 2023-11-03 15:21:06 -04:00
  • 9d2b84818f apply es and soc states to manager if new search or hn are added #11714 m0duspwnens 2023-11-03 15:00:13 -04:00
  • b74aa32deb Merge pull request #11712 from Security-Onion-Solutions/TOoSmOotH-patch-5 Mike Reeves 2023-11-03 11:33:00 -04:00
  • 3d8663db66 Update soc_elasticsearch.yaml #11712 Mike Reeves 2023-11-03 11:29:45 -04:00
  • 65978a340f Merge pull request #11710 from Security-Onion-Solutions/2.4/navlayerfix Josh Brower 2023-11-03 11:07:10 -04:00
  • a8b0e41dbe exit 0 #11710 Josh Brower 2023-11-03 11:04:52 -04:00
  • 1bc4b44be7 Merge pull request #11709 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-03 09:17:23 -04:00
  • 1a3d4a2051 ignore malformed open canary log lines #11709 Jason Ertel 2023-11-03 09:14:26 -04:00
  • 9d639df882 Merge pull request #11708 from Security-Onion-Solutions/2.4/metadatafix2 Josh Brower 2023-11-03 08:47:48 -04:00
  • 8c7767b381 Dont overwrite metadata #11708 Josh Brower 2023-11-03 08:41:33 -04:00
  • 96582add5e Merge pull request #11704 from Security-Onion-Solutions/feature/integrations_checkpoint_vsphere weslambert 2023-11-02 17:17:03 -04:00
  • 5bfef3f527 Add checkpoint and vsphere templates #11704 Wes 2023-11-02 21:10:01 +00:00
  • 3875970dc5 Add checkpoint and vsphere packages Wes 2023-11-02 21:09:37 +00:00
  • 7aa4f28524 Merge pull request #11702 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-02 16:48:09 -04:00
  • 96fdfb3829 ignore connectivity problems to docker containers during startup #11702 Jason Ertel 2023-11-02 16:46:41 -04:00
  • ac593e4632 Merge pull request #11701 from Security-Onion-Solutions/fix/elastic_templates_common weslambert 2023-11-02 16:43:27 -04:00
  • 51e7861757 Don't source so-elastic-fleet-common if not there #11701 weslambert 2023-11-02 16:41:34 -04:00
  • 6332df04d1 Merge pull request #11695 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-02 13:07:09 -04:00
  • 32701b5941 more log bypass #11695 Jason Ertel 2023-11-02 12:50:12 -04:00
  • 0dec6693dc Merge pull request #11678 from Security-Onion-Solutions/2.4/fleetreset Josh Brower 2023-11-02 11:33:58 -04:00
  • 41a6ab5b4f Merge pull request #11691 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-02 10:41:17 -04:00
  • e18e0fd69a more log bypass #11691 Jason Ertel 2023-11-02 10:39:14 -04:00
  • 2c0e287f8c Fix name #11678 Josh Brower 2023-11-02 10:34:24 -04:00
  • 9a76cfe3d3 Merge pull request #11690 from Security-Onion-Solutions/upgrade/salt3006.3v2 Josh Patterson 2023-11-02 10:28:29 -04:00
  • 6c4dc7cc09 fix UPGRADECOMMAND used for distrib salt upgrade. remove unneeded vars #11690 m0duspwnens 2023-11-02 10:23:03 -04:00
  • 5388b92865 Refactor & cleanup Josh Brower 2023-11-02 10:20:32 -04:00
  • f932444101 Merge pull request #11689 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-02 10:02:13 -04:00
  • 1d2518310d more log bypass #11689 Jason Ertel 2023-11-02 09:59:45 -04:00
  • e10f043b1c Merge pull request #11688 from Security-Onion-Solutions/fix/integrations_roles weslambert 2023-11-02 09:58:40 -04:00
  • 65735fc4d3 Add eval and import roles #11688 weslambert 2023-11-02 09:54:01 -04:00
  • b7f516fca4 Merge pull request #11687 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-11-02 09:24:08 -04:00
  • c8d8997119 adjust log filter to include all hosts #11687 Jason Ertel 2023-11-02 09:21:57 -04:00
  • c230cf4eb7 Formatting Josh Brower 2023-11-01 17:00:32 -04:00
  • 344dd7d61f Add Elastic Fleet reset script Josh Brower 2023-11-01 16:50:20 -04:00
  • cd8949d26b Merge pull request #11677 from Security-Onion-Solutions/lowram Mike Reeves 2023-11-01 16:38:40 -04:00
  • f9e2940181 Merge pull request #11676 from Security-Onion-Solutions/feature/sublime_platform_integration weslambert 2023-11-01 16:13:57 -04:00
  • f33079f1e3 Make settings global #11676 Wes 2023-11-01 20:09:56 +00:00
  • e6a0838e4c Add memory restrictions #11677 Mike Reeves 2023-11-01 15:26:24 -04:00
  • cc93976db9 Add memory restrictions Mike Reeves 2023-11-01 15:17:23 -04:00
  • b3b67acf07 Add memory restrictions Mike Reeves 2023-11-01 15:11:54 -04:00
  • 64926941dc Merge pull request #11674 from Security-Onion-Solutions/foxtrot Josh Patterson 2023-11-01 15:03:30 -04:00
  • c32935e2e6 Remove optional integration from configuration if not enabled Wes 2023-11-01 17:02:43 +00:00
  • 4f98beaf9e Merge pull request #11671 from Security-Onion-Solutions/TOoSmOotH-patch-4 Mike Reeves 2023-11-01 13:00:34 -04:00
  • 655c88cd09 Make sure enabled_nodes is populated Wes 2023-11-01 16:47:51 +00:00
  • f62e02a477 Delete pillar/thresholding/pillar.example #11671 Mike Reeves 2023-11-01 10:42:29 -04:00
  • 2b3e405b2d Delete pillar/thresholding/pillar.usage Mike Reeves 2023-11-01 10:41:40 -04:00
  • 59328d3909 Merge pull request #11670 from Security-Onion-Solutions/fix/soupagrepo #11674 Josh Patterson 2023-11-01 10:36:17 -04:00
  • 4d7b1095b7 Merge remote-tracking branch 'origin/2.4/dev' into fix/soupagrepo #11670 m0duspwnens 2023-11-01 10:31:59 -04:00
  • 338146fedd fix repo update during soup for airgap m0duspwnens 2023-11-01 10:19:56 -04:00
  • bca1194a46 Sublime SOC Action Wes 2023-11-01 14:01:55 +00:00
  • a0926b7b87 Load optional integrations Wes 2023-11-01 13:59:24 +00:00
  • 44e45843bf Change optional integration Fleet configuration Wes 2023-11-01 13:52:38 +00:00
  • 9701d0ac20 Optional integration Fleet configuration Wes 2023-11-01 13:47:20 +00:00
  • 23ee9c2bb0 Sublime Platform integration Wes 2023-11-01 13:41:40 +00:00
  • 51247be6b9 Sublime Platform integration defaults Wes 2023-11-01 13:37:52 +00:00
  • 4dc64400c5 Support document_id Wes 2023-11-01 13:36:32 +00:00
  • ae45d40eca Add Sublime Platform ingest pipeline Wes 2023-11-01 13:34:30 +00:00
  • ebf982bf86 Merge pull request #11666 from Security-Onion-Solutions/TOoSmOotH-patch-3 Mike Reeves 2023-10-31 15:18:23 -04:00
  • d07cfdd3fe Update so-functions #11666 Mike Reeves 2023-10-31 13:10:55 -04:00
  • 497294c363 Delete salt/common/tools/sbin/so-zeek-logs Mike Reeves 2023-10-31 12:57:10 -04:00
  • cc3a69683c Delete salt/manager/tools/sbin/so-allow-view Mike Reeves 2023-10-31 12:55:47 -04:00
  • 0c98bd96c7 Delete salt/idstools/tools/sbin/so-rule Mike Reeves 2023-10-31 12:52:00 -04:00
  • a6d456e108 Merge pull request #11665 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-10-31 11:20:28 -04:00
  • c420e198fb ignore specific Suricata errors #11665 Jason Ertel 2023-10-31 11:18:39 -04:00
  • 5a85003952 Merge pull request #11664 from Security-Onion-Solutions/fix/elastic_import weslambert 2023-10-31 10:47:13 -04:00
  • c354924b68 Add import roles #11664 weslambert 2023-10-31 10:05:29 -04:00
  • db0d687b87 Merge pull request #11661 from Security-Onion-Solutions/fix/elastic_eval_roles Jason Ertel 2023-10-30 22:01:22 -04:00
  • ed6473a34b Add roles for eval mode #11661 weslambert 2023-10-30 20:41:49 -04:00
  • 1b99d5081a Merge pull request #11659 from Security-Onion-Solutions/issue/11457 Josh Patterson 2023-10-30 16:20:36 -04:00