Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merge Main into Dev #11957

Merged
merged 26 commits into from
Dec 6, 2023
Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
ece3c36
Update import-evtx-logs.json
chateaulav Nov 29, 2023
a6d20bd
Update HOTFIX
weslambert Nov 29, 2023
317b6cb
Merge pull request #11902 from Security-Onion-Solutions/fix/hotfix_ve…
weslambert Nov 29, 2023
2368e8b
Fix action file names
weslambert Nov 29, 2023
a605c5c
Ensure indices managed by ILM can be managed by Curator
weslambert Nov 29, 2023
32b03f5
Merge pull request #11907 from Security-Onion-Solutions/fix/curator_c…
weslambert Nov 30, 2023
4fc3c85
Merge pull request #11890 from chateaulav/chateaulav-import-evtx-logs…
dougburks Nov 30, 2023
6fa4a69
Remove action changes
weslambert Dec 1, 2023
e36044e
Remove close changes
weslambert Dec 1, 2023
55052c4
Merge pull request #11919 from Security-Onion-Solutions/fix/remove_cu…
weslambert Dec 1, 2023
265cde5
move wait_for_salt_minion for hotfix
m0duspwnens Dec 1, 2023
ace5dff
Merge pull request #11923 from Security-Onion-Solutions/hf_soup
m0duspwnens Dec 1, 2023
38868af
avoid exiting salt when ca state applied in post for 2.4.30
m0duspwnens Dec 4, 2023
11a3e12
Merge pull request #11929 from Security-Onion-Solutions/hf_soup
m0duspwnens Dec 4, 2023
55a8b10
Update soup
TOoSmOotH Dec 4, 2023
0b6ba6d
Update soup
TOoSmOotH Dec 4, 2023
802bf9c
Merge pull request #11931 from Security-Onion-Solutions/TOoSmOotH-pat…
TOoSmOotH Dec 4, 2023
90d9e5b
Update soup
TOoSmOotH Dec 5, 2023
b7227e1
Merge pull request #11939 from Security-Onion-Solutions/TOoSmOotH-pat…
TOoSmOotH Dec 5, 2023
fdd4173
Update soup
TOoSmOotH Dec 5, 2023
9446b75
Update soup
TOoSmOotH Dec 5, 2023
8eaa07a
Merge pull request #11942 from Security-Onion-Solutions/TOoSmOotH-pat…
TOoSmOotH Dec 5, 2023
386e921
2.4.30 hotfix
TOoSmOotH Dec 6, 2023
b878728
Merge pull request #11951 from Security-Onion-Solutions/2.4.30hf3
TOoSmOotH Dec 6, 2023
d7bf52d
Merge pull request #11918 from Security-Onion-Solutions/hotfix/2.4.30
TOoSmOotH Dec 6, 2023
0160cae
Merge branch '2.4/dev' into mergeback
TOoSmOotH Dec 6, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions salt/curator/files/action/delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ actions:
description: >-
Delete indices when {{log_size_limit}}(GB) is exceeded.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-import-so-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close import indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-import-so-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete import indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-strelka-so-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close Strelka indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-strelka-so-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete Strelka indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-suricata-so-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close Suricata indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-suricata-so-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete Suricata indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-syslog-so-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close syslog indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-syslog-so-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete syslog indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-zeek-so-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close Zeek indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/logs-zeek-so-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete Zeek indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-beats-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close Beats indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-beats-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete beats indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-elasticsearch-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close elasticsearch indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-elasticsearch-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete elasticsearch indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-firewall-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ actions:
description: >-
Close Firewall indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-firewall-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ actions:
description: >-
Delete firewall indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-ids-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ actions:
description: >-
Close IDS indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-ids-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ actions:
description: >-
Delete IDS indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-import-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close Import indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-import-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete import indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-kibana-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close kibana indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-kibana-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete kibana indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-kratos-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close kratos indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-kratos-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete kratos indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-logstash-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close logstash indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-logstash-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete logstash indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-netflow-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close netflow indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-netflow-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete netflow indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-osquery-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close osquery indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-osquery-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete import indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-ossec-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close ossec indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-ossec-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete ossec indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-redis-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close redis indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-redis-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete redis indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-strelka-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close Strelka indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-strelka-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete Strelka indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-syslog-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close syslog indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-syslog-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete syslog indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-zeek-close.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Close Zeek indices older than {{cur_close_days}} days.
options:
allow_ilm_indices: True
delete_aliases: False
timeout_override:
ignore_empty_list: True
Expand Down
1 change: 1 addition & 0 deletions salt/curator/files/action/so-zeek-delete.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ actions:
description: >-
Delete Zeek indices when older than {{ DELETE_DAYS }} days.
options:
allow_ilm_indices: True
ignore_empty_list: True
disable_action: False
filters:
Expand Down
8 changes: 4 additions & 4 deletions salt/curator/tools/sbin/so-curator-close
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/cur
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/so-strelka-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/so-syslog-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-import-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-strelka-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-suricata-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-syslog-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-zeek-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-strelka-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-suricata-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-syslog-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-zeek-so-close.yml > /dev/null 2>&1;
8 changes: 4 additions & 4 deletions salt/curator/tools/sbin/so-curator-cluster-close
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/cur
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/so-strelka-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/so-syslog-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-import-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-strelka-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-suricata-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-syslog-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-zeek-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-strelka-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-suricata-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-syslog-so-close.yml > /dev/null 2>&1;
docker exec so-curator curator --config /etc/curator/config/curator.yml /etc/curator/action/logs-zeek-so-close.yml > /dev/null 2>&1;