-
Notifications
You must be signed in to change notification settings - Fork 70
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Alert Dasboard read for review #46
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
mreeve-snl
approved these changes
Nov 17, 2023
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
updated branch to be in line with release-1.1.0, and have it merge into release, LGTM
llwaterhouse
approved these changes
Nov 17, 2023
llwaterhouse
added a commit
that referenced
this pull request
Nov 17, 2023
This reverts commit 92ac3de.
mitchelbaker-cisa
pushed a commit
that referenced
this pull request
Nov 17, 2023
Co-authored-by: Diabe <0743724407@HQ.DHS.GOV> Co-authored-by: Michael Reeves <147089975+mreeve-snl@users.noreply.github.com>
llwaterhouse
added a commit
that referenced
this pull request
Nov 21, 2023
* Adding updates to troubleshooting to address the latest issues. * Added Filtering.md to documents to discuss how to filter out unnessecary logs * Change "activate selected" to "Enable" * Changed "New - User Security" to "User Security" to reflect current dashboard name * Updated dashboard count and location * Adds a script to export dashboards * Adding Compute Software Overview dashboard * User HR Dashboard Ready for Review and Release * Bump Elasticsearch Version * Bump version in readme * adding alert dashboard (#46) Co-authored-by: Diabe <0743724407@HQ.DHS.GOV> Co-authored-by: Michael Reeves <147089975+mreeve-snl@users.noreply.github.com> * Add a command to allow the execution of the winlogbeat.exe file (#38) Co-authored-by: Clint Baxley <clint.baxley-ctr@ecstech.com> * add process_explorer.ndjson file (#37) Co-authored-by: root <root@LS1.524zunprk23u3ery524odj1xdc.dx.internal.cloudapp.net> Co-authored-by: Connor <107427279+causand22@users.noreply.github.com> * Creating Initial Draft of issue templates (#34) * Creating Initial Draft of issue templates Issue Templates to aid with docs_update * Update bug-or-error-report.md * Update bug-or-error-report.md Minor typos * Proofread bug-or-error-report.md, updated phrasing in some places --------- Co-authored-by: Chad Poland <128160399+Chad-CISA@users.noreply.github.com> Co-authored-by: Linda Waterhouse <82845774+llwaterhouse@users.noreply.github.com> Co-authored-by: mitchelbaker-cisa <mitchel.baker@cisa.dhs.gov> * remove input controls and update filtering with Kibana Control filters for (hostname, process exe, process pid) * Alert Dashboard review (#49) * adding alert dashboard * Create Alerting_dashboard.ndjson * Rename Alerting_dasboard.ndjson to Alerting_dashboard.ndjson * Rename Alerting_dashboard.ndjson to alert_dashboard.ndjson * Delete dasboards directory --------- Co-authored-by: Diabe <0743724407@HQ.DHS.GOV> Co-authored-by: Michael Reeves <147089975+mreeve-snl@users.noreply.github.com> * Delete dasboards directory (#50) * Update deploy.sh to debug issue #33 Add logging to indicate the script's progress and where it might be failing + introduce a maximum number of 60 attempts to check for Elasticsearch readiness, preventing the script from hanging indefinitely. * Updates the dashboard menu and all of the dashboards that use it. (#53) * Change the navigation menu to exclude the old home page and include the new dashboards. * Delete the security dashboard home --------- Co-authored-by: Clint Baxley <clint.baxley-ctr@ecstech.com> * Lme update functionality (#30) * adding updates to chapter3 for deploy.sh changes * adding updates to dashboard and lme_update to log and run as better cron jobs * adding in more notes to chapter3 on update functionality * Added the following features to deploy.sh: - update function to add lme_upadte.sh and dashboard_update.sh to root's crontab - fixed final permissions so that /opt/lme is readable by `sudo` group - y/n on the uninstall options fixed - upgrade function updated to check for 1.0 version and only remove crontab in upgrading from 0.5.1 - usage function to print the usage * fixing read/write on the files_for_windows.zip * fixing backups permissions * Update chapter3.md (#29) * Update chapter3.md Changed winlogbeat 8.5.0 link to one, that allows user to download not only zip, but also sha512 control sum and also choose between zip and MSI. * Update chapter3.md Changed Winlogbeat to 8.11.1 * Update the readmes to delete old dashboards and import new ones. (#54) Co-authored-by: Clint Baxley <clint.baxley-ctr@ecstech.com> * Update Uninstall_Sysmon64.ps1 (#27) Check if Sysmon is installed, run the uninstall command with elevated privileges, and handle potential errors. Remove the Sysmon executable if the uninstallation is successful. * Deploy upgrade 1.1.0 (#58) * adding in upgrade command to go from 1.0 -> 1.1.0 * pushing upgrade notes * adding updates to deploy.sh for upgrading 1.0 -> 1.1.0 * adding CONTRIBUTING.md,RELEASES.md, and Custom PR-Template (#41) * adding Contribution and release documentation to help standardize these processes * Update CONTRIBUTING.md fixed typos. * documenting PR template to standardize and streamline Pull Requests * adding a few more changes * adding formatting changes * Rename pull_request_template.md to pull_request_template.md Actually renamed directory PULL_REUQEST_TEMPLATE to PULL_REQUEST_TEMPLATE --------- Co-authored-by: Linda Waterhouse <82845774+llwaterhouse@users.noreply.github.com> * remove updates that break the installation process, need more refactoring/testing before we can push these changes * Release 1.1.0 small updates (#61) * updating deploy.sh with fixes that solve permissions issues and still provide security for files with plaintext passwords * updating docs to state more accurate required disk sizes --------- Co-authored-by: Alden Hilton <106177711+adhilto@users.noreply.github.com> Co-authored-by: Clint Baxley <clint.baxley-ctr@ecstech.com> Co-authored-by: Connor Aubry <caubry@sandia.gov> Co-authored-by: Grant (SNL) <108766839+rgbrow1949@users.noreply.github.com> Co-authored-by: Clint Baxley <c.baxley-ctr@ecstech.com> Co-authored-by: ddiabe <133152385+ddiabe@users.noreply.github.com> Co-authored-by: Diabe <0743724407@HQ.DHS.GOV> Co-authored-by: mitchelbaker-cisa <149098823+mitchelbaker-cisa@users.noreply.github.com> Co-authored-by: root <root@LS1.524zunprk23u3ery524odj1xdc.dx.internal.cloudapp.net> Co-authored-by: Connor <107427279+causand22@users.noreply.github.com> Co-authored-by: Chad Poland <128160399+Chad-CISA@users.noreply.github.com> Co-authored-by: Linda Waterhouse <82845774+llwaterhouse@users.noreply.github.com> Co-authored-by: mitchelbaker-cisa <mitchel.baker@cisa.dhs.gov> Co-authored-by: Dmytro Korzhevin <dkorzhevin@gmail.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
π£ Description
π Motivation and context
π§ͺ Testing
β Pre-approval checklist
in code comments.
to reflect the changes in this PR.
β Pre-merge checklist
β Post-merge checklist