Commit Graph

  • 07b92eef9e vol sprawl #11360 Jason Ertel 2023-09-19 17:22:42 -04:00
  • 377802410e Merge pull request #11352 from Security-Onion-Solutions/fix/import_evtx_exists weslambert 2023-09-19 16:11:22 -04:00
  • 8855619453 vol sprawl Jason Ertel 2023-09-19 12:52:28 -04:00
  • 2e0ea3f374 Set final pipeline #11352 Wes 2023-09-19 13:33:12 +00:00
  • 508260bd46 Use event.created for timestamp Wes 2023-09-19 13:32:03 +00:00
  • a1e963f834 Reverse timestamps where necessary Wes 2023-09-19 13:28:20 +00:00
  • 8a98040008 Merge pull request #11351 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-09-19 09:26:31 -04:00
  • 47e611682a ignore debian apt update output #11351 Jason Ertel 2023-09-19 09:24:12 -04:00
  • 5bac1e4d15 Show correct dates and Kibana URL for already processed EVTX files Wes 2023-09-18 21:31:15 +00:00
  • ad025b9683 Merge pull request #11345 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-09-18 15:34:57 -04:00
  • 3e97ddc22d Merge pull request #11344 from Security-Onion-Solutions/fix/idstoolextra_env Josh Patterson 2023-09-18 15:29:33 -04:00
  • 151e8bfc4e fix idstool extra_env for container #11344 m0duspwnens 2023-09-18 15:21:45 -04:00
  • a914a02273 prune unused volumes during upgrade #11345 Jason Ertel 2023-09-18 14:43:02 -04:00
  • bb3632d1b2 fix bind if statement Jason Ertel 2023-09-18 14:38:15 -04:00
  • 66bb1272ae avoid volume sprawl Jason Ertel 2023-09-18 13:39:56 -04:00
  • bbef96ac25 use unique name Jason Ertel 2023-09-18 12:12:57 -04:00
  • f9cbde10a6 avoid volume sprawl Jason Ertel 2023-09-18 11:19:21 -04:00
  • fe1bae96ed Merge pull request #11297 from Security-Onion-Solutions/fix/soc_idh weslambert 2023-09-15 11:16:06 -04:00
  • eab6173a31 Merge pull request #11329 from Security-Onion-Solutions/fix/elastic_templates_clean weslambert 2023-09-15 11:00:17 -04:00
  • 98499c3963 Clean component template directory #11329 Wes 2023-09-15 13:51:46 +00:00
  • 26da525ebe Merge pull request #11328 from Security-Onion-Solutions/fix/checkreq Josh Patterson 2023-09-15 09:17:04 -04:00
  • c65c9777bd improvents for checking system requirements #11328 m0duspwnens 2023-09-14 17:42:25 -04:00
  • af68af7f18 Merge pull request #11317 from Security-Onion-Solutions/2.4/fixes Josh Brower 2023-09-14 10:59:56 -04:00
  • 0c11a9b733 Add transform role #11317 defensivedepth 2023-09-14 09:33:17 -04:00
  • 59d077f3ff Fix regex defensivedepth 2023-09-14 08:32:17 -04:00
  • 6383712731 Merge pull request #11315 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-09-14 07:41:59 -04:00
  • e067b7134e exclude docker pull unauth errors from failing setup since they'll be retried #11315 Jason Ertel 2023-09-14 07:38:07 -04:00
  • 183c530c82 Merge pull request #11308 from Security-Onion-Solutions/pcapfree Mike Reeves 2023-09-13 13:47:21 -04:00
  • 33d68478b6 Update so-minion #11308 Mike Reeves 2023-09-13 11:48:16 -04:00
  • 22c0323bda Update so-minion Mike Reeves 2023-09-13 10:57:45 -04:00
  • 19114c1a26 Merge pull request #11303 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2023-09-13 07:50:43 -04:00
  • 11b8e13418 FIX: SOC Config pcap doc links should point to steno docs #11302 #11303 Doug Burks 2023-09-13 07:37:54 -04:00
  • 6fdd7b3751 Merge pull request #11295 from Security-Onion-Solutions/issue/11229 Josh Patterson 2023-09-12 09:30:29 -04:00
  • 30c3255cb2 dont manage sorules #11295 m0duspwnens 2023-09-12 08:39:42 -04:00
  • 35ebbc974c Change description to indicate that opencanary modules only apply to IDH nodes #11297 Wes 2023-09-11 13:52:16 +00:00
  • f1d0db8171 /app to /kibana/app Wes 2023-09-11 13:30:11 +00:00
  • 9968d697f3 Merge pull request #11288 from Security-Onion-Solutions/issue/11229 Josh Patterson 2023-09-11 09:19:31 -04:00
  • 7763218b71 Merge pull request #11287 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2023-09-11 09:08:21 -04:00
  • 29f12fac90 Update soup for 2.3.270 #11287 Doug Burks 2023-09-11 09:05:19 -04:00
  • 02c54a264d Merge remote-tracking branch 'origin/2.4/dev' into issue/11229 #11288 m0duspwnens 2023-09-08 15:29:04 -04:00
  • e814a3409f fix rule location for rulecat.conf. run so-rule-update if rules change in /opt/so/rules/nids m0duspwnens 2023-09-08 15:28:24 -04:00
  • 55847c7bdc Merge pull request #11276 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-09-08 09:26:27 -04:00
  • 598515e5b4 give priority to presets #11276 Jason Ertel 2023-09-08 09:21:13 -04:00
  • 692625f8cd Merge pull request #11271 from Security-Onion-Solutions/jertel/auto Jason Ertel 2023-09-07 17:25:08 -04:00
  • f8ae3f12e6 addl node types #11271 Jason Ertel 2023-09-07 17:22:10 -04:00
  • 3780ed1b4f Merge pull request #11269 from Security-Onion-Solutions/issue/11210 Josh Patterson 2023-09-07 16:54:16 -04:00
  • 8d269fee30 Merge remote-tracking branch 'origin/2.4/dev' into issue/11210 #11269 m0duspwnens 2023-09-07 15:46:25 -04:00
  • 35157f2e8b add comment m0duspwnens 2023-09-07 15:46:04 -04:00
  • 60f1947eb4 prevent endgame_dict from being added to standard_actions if it is already present m0duspwnens 2023-09-07 14:01:19 -04:00
  • ffaab4a1b4 only add endgame to action if it is populated m0duspwnens 2023-09-06 14:19:53 -04:00
  • 70e1309c9f Merge pull request #11261 from Security-Onion-Solutions/fix/remove_default_templates weslambert 2023-09-06 10:57:09 -04:00
  • 5c0045f9f8 Merge pull request #11256 from Security-Onion-Solutions/jertel/sod Jason Ertel 2023-09-05 12:50:47 -04:00
  • b66be9c226 only ingest pfsense on sensor nodes #11256 Jason Ertel 2023-09-05 12:46:49 -04:00
  • 651393988a Merge pull request #11255 from Security-Onion-Solutions/issue/10975 Josh Patterson 2023-09-05 11:57:58 -04:00
  • cf19c8f8c2 Remove templates #11261 Wes 2023-09-05 13:43:41 +00:00
  • ba3ae92702 Merge pull request #11249 from Security-Onion-Solutions/jertel/sod Mike Reeves 2023-09-03 22:23:55 -04:00
  • 8e2bed7f91 MS testing #11249 Jason Ertel 2023-09-03 19:56:40 -04:00
  • 028b69c7d4 Merge pull request #11245 from Security-Onion-Solutions/jertel/sod Jason Ertel 2023-09-02 13:49:49 -04:00
  • 0cf913a7c1 ensure hostname is set #11245 Jason Ertel 2023-09-02 06:05:37 -04:00
  • 13fbcd712b Merge pull request #11243 from Security-Onion-Solutions/jertel/sod Jason Ertel 2023-09-01 20:43:35 -04:00
  • 0aae107155 ensure hostname is set #11243 Jason Ertel 2023-09-01 20:30:53 -04:00
  • d2dcf7e7c1 Merge pull request #11241 from Security-Onion-Solutions/jertel/sod Mike Reeves 2023-09-01 18:22:38 -04:00
  • 6efdf1b9d0 add additional test modes #11241 Jason Ertel 2023-09-01 17:24:12 -04:00
  • a11259c683 add additional test modes Jason Ertel 2023-09-01 17:08:27 -04:00
  • 863db14b61 add additional test modes Jason Ertel 2023-09-01 16:27:02 -04:00
  • 335aaa5594 add additional test modes Jason Ertel 2023-09-01 15:30:53 -04:00
  • 07ed93de19 add elastic agent to desktop #11255 m0duspwnens 2023-09-01 14:33:32 -04:00
  • 8093e5ce7c use IP to avoid host issues Jason Ertel 2023-09-01 13:01:17 -04:00
  • 585fba4bc6 add functions salt_install_module_deps and salt_patch_x509_v2 m0duspwnens 2023-09-01 12:40:01 -04:00
  • b8f69b5008 Merge pull request #11239 from Security-Onion-Solutions/fix/syslog_heavynode weslambert 2023-09-01 12:20:44 -04:00
  • aebfb19ab7 add sostatus.sh to desktop for telegraf scripts m0duspwnens 2023-09-01 12:05:28 -04:00
  • 490669d378 add ssl to desktop for allowed_states m0duspwnens 2023-09-01 12:03:01 -04:00
  • 3434d0f200 add sensoroni and telegraf back to individual nodes. add seperate block for desktop m0duspwnens 2023-09-01 12:02:30 -04:00
  • 765a22e6f0 Add so-elastic-agent #11239 weslambert 2023-09-01 11:31:23 -04:00
  • 546c562ef0 expose standard relay timeout in config UI; up default to 45s to accommodate sluggish pillar.get calls Jason Ertel 2023-09-01 10:31:02 -04:00
  • b64d4e3658 add telegraf pillar to desktop m0duspwnens 2023-09-01 09:53:26 -04:00
  • 0fb00d569e allow states for desktop. give all nodes docker_clean, order it last m0duspwnens 2023-09-01 09:39:39 -04:00
  • b64fa51268 give desktop docker state and pillars m0duspwnens 2023-09-01 09:16:24 -04:00
  • 1871d48f7f remove unnecesary OTHER submenu Jason Ertel 2023-08-31 20:42:00 -04:00
  • b010919099 add sensoroni, telegraf, common states to desktop. allow docker_registry connection to managers for desktop m0duspwnens 2023-08-31 13:21:32 -04:00
  • ce2a7135cb Merge pull request #11232 from Security-Onion-Solutions/fix/strelka_entropy weslambert 2023-08-31 11:21:00 -04:00
  • 0fed757b11 Add entropy mapping #11232 Wes 2023-08-31 15:10:27 +00:00
  • 1a3b3b21fb Change entropy value syntax Wes 2023-08-31 15:09:19 +00:00
  • d86e21c751 Merge pull request #11231 from Security-Onion-Solutions/issue/10975 Josh Patterson 2023-08-31 10:54:30 -04:00
  • 1a9f8f0bc2 Merge pull request #11228 from Security-Onion-Solutions/master Doug Burks 2023-08-31 10:19:45 -04:00
  • 3e5f354d8b Merge pull request #11227 from Security-Onion-Solutions/dougburks-patch-1 #11228 Doug Burks 2023-08-31 10:16:55 -04:00
  • a1b76d2cd3 Update 2-4.yml #11227 Doug Burks 2023-08-31 10:12:47 -04:00
  • e408718230 Merge remote-tracking branch 'origin/2.4/dev' into issue/10975 #11231 m0duspwnens 2023-08-31 09:56:02 -04:00
  • ee848b8a8c comments for desktop install m0duspwnens 2023-08-31 09:51:55 -04:00
  • a60c34d548 exclude unnecessary pillars from desktop nodes m0duspwnens 2023-08-31 09:40:54 -04:00
  • 8a2fc5d62b Merge pull request #11226 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2023-08-31 09:18:19 -04:00
  • da56a421e5 Update motd.md #11226 Doug Burks 2023-08-31 09:17:33 -04:00
  • bfb0d0ddb5 Merge remote-tracking branch 'origin/2.4/dev' into issue/10975 m0duspwnens 2023-08-31 08:58:28 -04:00
  • c812c3991e we dont need to run convert-gnome-classic script m0duspwnens 2023-08-31 08:54:13 -04:00
  • ca9dad396f Merge pull request #11222 from Security-Onion-Solutions/cogburn/11143 coreyogburn 2023-08-30 15:47:01 -06:00
  • a615fc8e47 New Config Default: longRelayTimeoutMs #11222 Corey Ogburn 2023-08-30 15:33:01 -06:00
  • ac38f32e32 Merge pull request #11218 from Security-Onion-Solutions/feature/soc_administration_analyzers weslambert 2023-08-30 16:54:02 -04:00
  • f2d1b9ac95 Merge pull request #11221 from Security-Onion-Solutions/issue/10975 Josh Patterson 2023-08-30 16:50:46 -04:00
  • 14a6280531 iso desktop join grid - set install_type and minion_type #11221 m0duspwnens 2023-08-30 16:49:17 -04:00
  • 41300af944 Set global to false #11218 weslambert 2023-08-30 16:30:32 -04:00