This repository was archived by the owner on Apr 16, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 522
This repository was archived by the owner on Apr 16, 2021. It is now read-only.
Elastic Stack Beta 3 #1172
Copy link
Copy link
Closed
Description
-
Elasticsearch
-
Kibana
- Kibana 5.6.5
- load settings via new API
- load dashboards via new API
- update new Home - Sensors - Count TSVB viz to search cross cluster (
*:logstash-*
instead oflogstash-*
) and check other TSVB viz as well - move FreqServer visualizations to a separate dashboard to avoid leaving blank space on dashboards when FreqServer is disabled
- move DomainStats visualizations to a separate dashboard to avoid leaving blank space on dashboards when DomainStats is disabled
- on Software and Syslog dashboards, search panel at bottom should not display _id by default since pivoting to CapMe won't work
- Bro - SNMP Duration field needs to be set to Duration - Seconds - Seconds - 6 Decimal Places
- improve Help page, add more Getting Started information
- add basic dashboard for Beats
-
Logstash
- Logstash 5.6.5
- stop using _all
- move to a single mapping type:
dougburks/securityonion-elastic@4a1ae52 - allow user to expose logstash ports to network to send logs from external sources
- support for beats input port 5044:
dougburks/securityonion-elastic@4a1ae52
dougburks/securityonion-elastic@cb84aaf
configure output/index creation for Elastic Beats dougburks/securityonion-elastic#144 - support for beats output
- grok parser error for Microsoft-Windows-Sysmon/Operational Logstash - grok parser error #1182
-
so-elastic-download
-
CapMe
-
Docker
-
ElastAlert
-
Setup
- improve
HIGHEST_REVERSE_PORT
detection for sensors joining master:
https://groups.google.com/d/topic/security-onion/EsbeYoh4ymU/discussion
dougburks/securityonion-elastic@f04be5d
dougburks/securityonion-elastic@d4ed5c6 - fix verbiage for Elasticsearch disk usage
- improve
-
so-allow-elastic
Metadata
Metadata
Assignees
Labels
No labels