Showing posts with label elsa. Show all posts
Showing posts with label elsa. Show all posts

Thursday, May 31, 2018

Security Onion 16.04.4.1 ISO image now available!

We're pleased to announce that Security Onion 16.04.4.1 RC2 has been promoted to RELEASE status!


This release resolves the following issues:

Issue 1247: Ubuntu 16.04 Xenial Support
https://github.com/Security-Onion-Solutions/security-onion/issues/1247

Issue 1202: CapMe: purge pcap symlinks older than 24 hours
https://github.com/Security-Onion-Solutions/security-onion/issues/1202

Issue 1169: Squert: remove search link from context menu
https://github.com/Security-Onion-Solutions/security-onion/issues/1169

Issue 875: Allow mysql root password
https://github.com/Security-Onion-Solutions/security-onion/issues/875

Release Notes
ELSA, Argus, and PRADS are no longer included in Security Onion.

For more information about this release, please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/16.04.4.1

Security Onion 14.04 EOL Notice
All new development will now be on Security Onion 16.04.  Security Onion 14.04 will reach EOL on November 30, 2018.  After that date, we will not provide any support for Security Onion 14.04.  Please plan to upgrade or replace any existing 14.04 systems before that date.

Installation Guide
We've updated the Installation guide to reflect the download locations for the new ISO image:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Installation

Existing Deployments
If you have existing installations of Security Onion 14.04, you can upgrade to 16.04:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrading-from-14.04-to-16.04

Want us to upgrade your deployment for you?  Please contact Security Onion Solutions for pricing and scheduling:
https://securityonionsolutions.com

Training
We also offer onsite and online training!  For pricing and availability, please see:
https://securityonionsolutions.com

Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists

Thanks!

Monday, April 9, 2018

6 month EOL notice for ELSA

This morning we released an updated Setup package and ISO image that both default to Elastic instead of ELSA:

https://blog.securityonion.net/2018/04/securityonion-setup-20120912.html


https://blog.securityonion.net/2018/04/security-onion-elastic-stack-general.html

ELSA will reach End Of Life (EOL) on October 9, 2018.  After that date, we will no longer provide updates or support of any kind for ELSA.

For more information, please see:

https://github.com/Security-Onion-Solutions/security-onion/wiki/ELSA#eol

https://github.com/Security-Onion-Solutions/security-onion/wiki/ELSA-to-Elastic

securityonion-setup - 20120912-0ubuntu0securityonion251 now available for Security Onion!

The following package is now available:

securityonion-setup - 20120912-0ubuntu0securityonion251

This new package should resolve the following issue:

Issue 1216: Setup - default to Elastic
https://github.com/Security-Onion-Solutions/security-onion/issues/1216

Release Notes
Setup now defaults to Elastic instead of ELSA.  ELSA will reach End Of Life on October 9, 2018.  If for some reason you still need to run the old ELSA version of Setup, you can manually run:
sudo sosetup-elsa
Thanks
Thanks to Wes Lambert for testing this package!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Training
We offer both onsite and online training!  For more information, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Thursday, January 18, 2018

Security Advisory for ELSA

Introduction
Jeffrey Medsger reported multiple Cross-Site Scripting (XSS) vulnerabilities in ELSA.

These issues are resolved in the following ELSA packages:
securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion12
securityonion-elsa-extras - 20151011-1ubuntu1securityonion58

Resolution
To resolve these issues, simply install the new ELSA packages according to our normal update instructions:
https://securityonion.net/wiki/Upgrade

Thanks
Special thanks to Jeffrey Medsger for responsibly disclosing these security issues per our Security page (https://securityonion.net/security) and for submitting patches for some of the issues!

Timeline
All times below are in Eastern time.
1/2/2018 1:19 AM - Received initial notification from Jeffrey Medsger concerning ELSA XSS vulnerabilities.
1/2/2018 6:05 PM - Confirmed receipt of email and confirmed issues.
1/3/2018 4:35 PM - Asked Jeffrey Medsger to test new packages.
1/10/2018 12:26 AM - Jeffrey Medsger confirmed original XSS issues resolved and reported additional XSS issues.
1/10/2018 1:32 PM - Confirmed receipt of email with new XSS issues.
1/12/2018 2:02 PM - Asked Jeffrey Medsger to test latest packages.
1/13/2018 4:00 PM - Jeffrey Medsger confirmed issues resolved.
1/13/2018 4:03 PM - Confirmed receipt of email and began regression testing.
1/18/2018 8:32 AM - Completed regression testing.

Wednesday, August 30, 2017

New ELSA Packages Available for Security Onion

I've built new ELSA packages and the new package versions are as follows:
securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion10
securityonion-elsa-extras - 20151011-1ubuntu1securityonion56

These new packages should resolve the following issues:

Issue 1074: securityonion-elsa-extras: add 5140 parser
https://github.com/Security-Onion-Solutions/security-onion/issues/1074

Issue 1075: securityonion-elsa-extras: add storage calculator
https://github.com/Security-Onion-Solutions/security-onion/issues/1075

Issue 1076: securityonion-elsa-extras: refactor securityonion-elsa-reset
https://github.com/Security-Onion-Solutions/security-onion/issues/1076

Issue 1080: securityonion-elsa-extras: add delaycompress for elsa logs
https://github.com/Security-Onion-Solutions/security-onion/issues/1080

Issue 1122: securityonion-elsa: remove 300px limitation
https://github.com/Security-Onion-Solutions/security-onion/issues/1122

Thanks
Thanks to the following for submitting pull requests!
Brian Kellogg
Wes Lambert
Github user "4A61736F6E"
Pete Nelson
Phil Plantamura
Thanks to Wes Lambert and Phil Plantamura for testing the new packages!

Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference 2017 will be on Friday September 15 in beautiful Augusta, GA!
https://securityonion.net/conference

Training
We have a 4-day Security Onion training class right before the Security Onion Conference in Augusta GA.  For this and other training options, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://securityonion.net/wiki/Support

Thanks!

Thursday, March 16, 2017

Towards ELK on Security Onion: A Technology Preview

UPDATED 2018/04/09! We've released a newer version!
https://blog.securityonion.net/2018/04/security-onion-elastic-stack-general.html

Over the last few years, we've had lots of folks ask for ELK (Elasticsearch, Logstash, and Kibana) on Security Onion.  The time has come to begin working towards ELK on Security Onion!

In the grand tradition of "release early, release often", we're releasing a very early Technology Preview of what ELK on Security Onion might look like.  This Technology Preview consists of a script that will take a Security Onion VM in Evaluation Mode and convert it from ELSA to ELK.  We're releasing this now because we want to get your feedback as early as possible in this project.

Thanks
Special thanks to Justin Henderson for his Logstash configs and installation guide!
https://github.com/SMAPPER/Logstash-Configs

Special thanks to Phil Hagen for all his work on SOF-ELK!
https://github.com/philhagen/sof-elk

Warnings and Disclaimers

  • This technology PREVIEW is PRE-ALPHA, BLEEDING EDGE, and TOTALLY UNSUPPORTED!
  • If this breaks your system, you get to keep both pieces!
  • This script is a work in progress and is in constant flux.
  • This script is intended to build a quick prototype proof of concept so you can see what our ultimate ELK configuration might look like.  This configuration will change drastically over time leading up to the final release.
  • Do NOT run this on a system that you care about!
  • Do NOT run this on a system that has data that you care about!
  • This script should only be run on a TEST box with TEST data!
  • This script is only designed for standalone boxes and does NOT support distributed deployments.
  • Use of this script may result in nausea, vomiting, or a burning sensation.

Bring on the ELK
Enough disclaimers?  Let's do this!

Start with a disposable TEST VM with the following minimum requirements:

  • 2 CPU cores
  • 4GB RAM
  • 20GB virtual hard drive
  • (1) management interface with full Internet access
  • (1) sniffing interface (separate from management interface)
  • Security Onion 14.04.5.2 ISO image installed
  • Setup ran in Evaluation Mode

Download the script:
wget https://raw.githubusercontent.com/Security-Onion-Solutions/elastic-test/master/securityonion_elsa2elastic.sh
Run the script with sudo privileges:
sudo bash securityonion_elsa2elastic.sh
Please read through all the WARNINGS and DISCLAIMERS and ONLY proceed if you agree.

The script will take at least 10 minutes depending on the speed of your hardware and Internet connection.

After a minute or two, you should be able to access Kibana via the following URL:
https://localhost/app/kibana

You should see our new Security Onion login window.  Enter the same credentials that you use to login to Sguil and Squert.  This login window will provide single sign on for both Kibana and CapMe to allow seamless pivoting to full packet capture!

Once logged into Kibana, you will automatically start on our Overview dashboard and you will see links to other dashboards as well.  These dashboards are designed to work at 1024x768 screen resolution in order to maximize compatibility.

As you search through the data in Kibana, you should see Bro logs, syslog, and Snort alerts.  Logstash should have parsed out most fields in most Bro logs and Snort alerts.

Notice that the search panels at the bottom of the dashboards display the source_ip and destination_ip fields with hyperlinks.  These hyperlinks will take you to a dashboard that will help you analyze the traffic relating to that particular IP address.

UID fields are also hyperlinked.  This hyperlink will start a new Kibana search for that particular UID.  In the case of Bro UIDs this will show you all Bro logs related to that particular connection.

Each log entry also has an _id field that is hyperlinked.  This hyperlink will take you to CapMe, allowing you to request full packet capture for any arbitrary log type!  This assumes that the log is for tcp or udp traffic that was seen by Bro and Bro recorded it correctly in its conn.log.  CapMe should try to do the following:

  • retrieve the _id from Elasticsearch
  • parse out timestamp
  • if Bro log, parse out the CID, otherwise parse out src IP, src port, dst IP, and dst port
  • query Elasticsearch for those terms and try to find the corresponding bro_conn log
  • parse out sensor name (hostname-interface)
  • send a request to sguild to request pcap from that sensor name

Previously, in Squert, you could pivot from an IP address to ELSA.  That pivot has been removed and replaced with a pivot to ELK.

Screenshots
Using wget to download the script


Running the script as root with "sudo bash securityonion_elsa2elk.sh"

TODO and HARDWARE REQUIREMENTS

Thanks to Justin Henderson and Phil Hagen!

WARNINGS and DISCLAIMERS

Instructions at end of script

New Security Onion login window (use your existing Sguil/Squert credentials) provides single sign on for both Kibana and CapMe

Overview Dashboard contains graphs and links to other dashboards

All of our dashboards include a search panel at the bottom so you can quickly drill into details

Indicator Dashboard is great for seeing the most interesting data types for a particular IP address

Notices Dashboard shows Bro Notices

NIDS Dashboards shows NIDS alerts from Snort or Suricata 
Bro_conn Dashboard allows you to slice and dice Bro's conn.log



Bro_dns Dashboard allows you to slice and dice Bro's dns.log

Bro_http Dashboard allows you to slice and dice Bro's http.log

Bro_ssl Dashboard allows you to slice and dice Bro's ssl.log

Scrolling down the Bro_http Dashboard, we see raw logs with hyperlinks to pivot to further information

Clicking the source IP address in the previous screenshot takes us to the Indicator Dashboard for the source IP

Clicking the destination IP address takes us to the Indicator Dashboard for the destination IP

Clicking the uid field takes us to the Indicator Dashboard for the Bro connection ID

Clicking the _id hyperlink takes us to CapMe to retrieve full packet capture for that stream

Feedback
We're releasing this now because we want to get your feedback as early as possible in this project.  Please try it out and send your feedback to our mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists

What do you think?

What works well?

What needs to be improved?

Any questions or other comments?

Thanks in advance for any and all feedback!

UPDATE 2017-03-16 Fixed link to Justin Henderson's github repo

UPDATE 2017-06-01 Renamed github repo from elk-test to elastic-test

UPDATE 2017-06-03 Added link to Technology Preview 2

UPDATE 2017-07-28 Changed TP2 link to point to TP3

UPDATE 2017-09-16 Changed TP3 link to point to ALPHA

UPDATE 2017-11-01 Changed ALPHA link to point to BETA

UPDATE 2017-11-30 Changed BETA link to point to BETA 2

UPDATE 2017-12-18 Changed BETA 2 link to point to BETA 3


Monday, January 23, 2017

securityonion-elsa-extras - 20151011-1ubuntu1securityonion49 resolves an issue with recent MySQL updates

Ubuntu released new MySQL packages recently:
https://www.ubuntu.com/usn/usn-3174-1/

These packages contain some changes which prevented ELSA from creating new database tables.  I've updated our securityonion-elsa-extras package to set the newly required MySQL permissions and the new package version is as follows:
securityonion-elsa-extras - 20151011-1ubuntu1securityonion49

This should resolve the following issue:

securityonion-elsa-extras: new MySQL packages require changes to elsa user #1065
https://github.com/Security-Onion-Solutions/security-onion/issues/1065

This package has been tested by Wes Lambert.  Thanks, Wes!

Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
Security Onion Solutions provides onsite, online, and on-demand training.  For more information, please see:
https://securityonionsolutions.com

Conference
Our annual Security Onion Conference will be Friday September 15, 2017:
https://securityonion.net/conference

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Friday, January 20, 2017

Latest MySQL packages may impact ELSA databases

Ubuntu released new MySQL packages yesterday:
https://www.ubuntu.com/usn/usn-3174-1/

These packages contain some changes which may impact ELSA databases.  It is recommended to not install these updates until we can confirm the extent of the changes and any workarounds necessary.

Updates will be posted here as they become available.

UPDATE 2017/01/20 5:00 PM Eastern:
A preliminary ELSA package update has been submitted for testing:
https://groups.google.com/d/topic/security-onion-testing/xHmKLB8kNJg/discussion

UPDATE 2017/01/21 6:09 PM Eastern:
Adding a link to Issue 1065 for tracking:
https://github.com/Security-Onion-Solutions/security-onion/issues/1065

UPDATE 2017/01/23 6:13 AM Eastern:
Published updated ELSA package:
http://blog.securityonion.net/2017/01/securityonion-elsa-extras-20151011.html

Tuesday, January 17, 2017

New ELSA packages add support for Bro rfb.log

The following packages are now available:
securityonion-elsa-extras - 20151011-1ubuntu1securityonion48
securityonion-web-page - 20141015-0ubuntu0securityonion72

These new packages should resolve the following issues:

Issue 1036: securityonion-elsa-extras: add pattern for Bro rfb.log
https://github.com/Security-Onion-Solutions/security-onion/issues/1036

Issue 1037: securityonion-web-page: add ELSA queries for Bro rfb.log
https://github.com/Security-Onion-Solutions/security-onion/issues/1037

These packages have been tested by Wes Lambert.  Thanks, Wes!

Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
Security Onion Solutions provides onsite, online, and on-demand training.  For more information, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Monday, November 14, 2016

securityonion-elsa-extras - 20151011-1ubuntu1securityonion40 resolves an issue

The following package is now available:
securityonion-elsa-extras - 20151011-1ubuntu1securityonion40

This new package should resolve the following issue:

Issue 1010: securityonion-elsa-extras: Windows process enhancements
https://github.com/Security-Onion-Solutions/security-onion/issues/1010

Thanks to Brian Kellogg for submitted these new ELSA patterns!

Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
Security Onion Solutions provides onsite, online, and on-demand training.  For more information, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Friday, September 30, 2016

securityonion-web-page - 20141015-0ubuntu0securityonion71 resolves several issues

The following package is now available:
securityonion-web-page - 20141015-0ubuntu0securityonion71

This new package should resolve the following issues:

Issue 1001: securityonion-web-page: move Top/Bottom links to beginning of line
https://github.com/Security-Onion-Solutions/security-onion/issues/1001

Issue 1002: securityonion-web-page: fix ELSA FIREWALL_ACCESS_DENY queries
https://github.com/Security-Onion-Solutions/security-onion/issues/1002

Issue 1004: securityonion-web-page: standardize Autoruns queries
https://github.com/Security-Onion-Solutions/security-onion/issues/1004

Screenshots
Top / Bottom links are now at the beginning of the line
and Autoruns queries have been standardized


DNS - Top 100 Requests

DNS - Bottom 100 Requests


Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
Security Onion Solutions provides onsite, online, and on-demand training.  For more information, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Wednesday, September 28, 2016

securityonion-elsa-extras - 20151011-1ubuntu1securityonion38 resolves an issue

The following package is now available:
securityonion-elsa-extras - 20151011-1ubuntu1securityonion38

This new package should resolve the following issue:

Issue 997: securityonion-elsa-extras: better parsing for event id 4776
https://github.com/Security-Onion-Solutions/security-onion/issues/997

Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
Security Onion Solutions provides onsite, online, and on-demand training.  For more information, please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Wednesday, August 24, 2016

securityonion-web-page - 20141015-0ubuntu0securityonion68 resolves an issue

Tom Webb recently posted to the Internet Storm Center about checking HTTP status codes:
https://isc.sans.edu/forums/diary/522+Error+Code+for+the+Win/21377/

I've added a new HTTP Top Status Code query to the ELSA hunting menu and built a new package:
securityonion-web-page - 20141015-0ubuntu0securityonion68

This new package should resolve the following issue:

Issue 984: securityonion-web-page: add HTTP top status code
https://github.com/Security-Onion-Solutions/security-onion/issues/984

Thanks
Thanks to Wes Lambert for testing this package!

Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 9 and registration closes on Friday September 2!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Monday, August 22, 2016

securityonion-elsa-extras - 20151011-1ubuntu1securityonion37 resolves 2 issues

James Taylor and Josh Brower submitted updates for some ELSA patterns.  I've merged their pull requests and built a new package:
securityonion-elsa-extras - 20151011-1ubuntu1securityonion37

This new package has been tested by James Taylor, Josh Brower, and Wes Lambert (thanks!) and should resolve the following issues:

Issue 979: securityonion-elsa-extras: additional patterns for Sysmon 4 and 4.11
https://github.com/Security-Onion-Solutions/security-onion/issues/979

Issue 983: securityonion-elsa-extras: add "AR-LOG" header to autoruns pattern
https://github.com/Security-Onion-Solutions/security-onion/issues/983

Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 9 and registration closes on Friday September 2!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Monday, August 8, 2016

New ELSA packages resolve several issues

I've merged several pull requests:
https://github.com/Security-Onion-Solutions/securityonion-elsa-extras/pull/10
https://github.com/Security-Onion-Solutions/securityonion-elsa-extras/pull/15
https://github.com/Security-Onion-Solutions/securityonion-elsa-extras/pull/17
https://github.com/Security-Onion-Solutions/securityonion-elsa-extras/pull/18
https://github.com/Security-Onion-Solutions/securityonion-web-page/pull/5

Martin Holste merged several pull requests in his ELSA repo:
https://github.com/mcholste/elsa/pull/16
https://github.com/mcholste/elsa/pull/40
https://github.com/mcholste/elsa/pull/39
https://github.com/mcholste/elsa/pull/37

I've built new packages including all of these changes and the new
package versions are as follows:
securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion9
securityonion-elsa-extras - 20151011-1ubuntu1securityonion35
securityonion-web-page - 20141015-0ubuntu0securityonion67

These new packages should resolve the following issues:

Issue 950: ELSA: change Help link to point to ELSA Github
https://github.com/Security-Onion-Solutions/security-onion/issues/950

Issue 827: securityonion-elsa-extras: merge additional patterns including DNP3 and Modbus
https://github.com/Security-Onion-Solutions/security-onion/issues/827

Issue 970: securityonion-web-page: add queries for autoruns, dnp3, and modbus
https://github.com/Security-Onion-Solutions/security-onion/issues/970

Issue 973: securityonion-web-page: Apache ServerName localhost
https://github.com/Security-Onion-Solutions/security-onion/issues/973

Issue 964: securityonion-web-page: add "bottom" queries for long tail analysis
https://github.com/Security-Onion-Solutions/security-onion/issues/964

Issue 976: securityonion-web-page: additional protections in securityonion.conf
https://github.com/Security-Onion-Solutions/security-onion/issues/976

These packages have been tested by the following (thanks!):
Phil Plantamura
Josh Brower
Wes Lambert
James Taylor

Screenshots
DNP3 - Top SRC IPs 
DNP3 - Top DST IPs 
DNP3 - Top DST Ports 
DNP3 - Top Requests 
DNP3 - Top Replies

Modbus - Top SRC IPs

Modbus - Top DST IPs

Modbus - Top DST Ports

Modbus - Top Functions

Modbus - Top Exceptions

Autoruns Queries
 
DNS - Bottom Requests (Long Tail Analysis)
Updating
These packages are now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Conference
Security Onion Conference will be on Friday September 9 and registration is open!
https://securityonion.net/conference

Training
Need training?  Please see:
https://securityonionsolutions.com

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Monday, July 4, 2016

securityonion-web-page - 20141015-0ubuntu0securityonion60 resolves 2 issues

I've updated the following package:

securityonion-web-page - 20141015-0ubuntu0securityonion60

It should resolve the following issues:

Issue 952: securityonion-web-page: add FTP Data query to FTP category:
https://github.com/Security-Onion-Solutions/security-onion/issues/952

With the current FTP queries in ELSA, if you pivot to full packet capture, you only see the FTP control channel (you don't see actual files being transferred).  This update add a new query to the FTP category to help users to find the FTP data channel where files are actually transferred.

Issue 957: securityonion-web-page: change public site hyperlinks to https
https://github.com/Security-Onion-Solutions/security-onion/issues/957

Our public websites for the Security Onion project and for Security Onion Solutions now default to https, so we're changing all hyperlinks from http to https.

Wes Lambert tested this package.  Thanks, Wes!

Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
The next round of online classes is next week!
https://attendee.gototraining.com/9z73w/catalog/8119062504158470144

Conference
Security Onion Conference will be on Friday September 9 and registration is open!
https://securityonion.net/conference

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Thursday, June 2, 2016

securityonion-elsa-extras - 20151011-1ubuntu1securityonion32 resolves an issue

I've updated the following package:

securityonion-elsa-extras - 20151011-1ubuntu1securityonion32

It should resolve the following issue:

Issue 908: securityonion-elsa-extras: add securityonion-elsa-reset script
https://github.com/Security-Onion-Solutions/security-onion/issues/908

Wes Lambert tested this package.  Thanks, Wes!

Updating
This package is now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
The next round of online classes will be in July:
https://attendee.gototraining.com/9z73w/catalog/8119062504158470144

Conference
Security Onion Conference will be on Friday September 9!
http://blog.securityonion.net/2016/03/security-onion-conference-2016-cfp.html

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Monday, May 9, 2016

securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion8 resolves an issue with ELSA Dashboard GeoIP mapping

Martin Holste committed some fixes for ELSA dashboard maps recently:
https://github.com/mcholste/elsa/commit/1566d32054cb886a404c68fb6db8d5420d0f85b3

I've built new ELSA packages with all the latest fixes:
securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion8
securityonion-elsa-extras - 20151011-1ubuntu1securityonion30

These packages should resolve the following issue:

ELSA: Improve dashboard map shading #864
https://github.com/Security-Onion-Solutions/security-onion/issues/864

Wes Lambert tested these packages.  Thanks, Wes!

You can build an ELSA GeoIP dashboard as shown here:
http://blog.securityonion.net/2016/02/securityonion-elsa-1205chartsjsd3.html



Updating
These new packages are now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Security Onion t-shirts are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
Our next round of online classes is next week!
http://blog.securityonion.net/2016/03/next-round-of-security-onion-online.html

Conference
Security Onion Conference will be on Friday September 9 and CFP is open!
http://blog.securityonion.net/2016/03/security-onion-conference-2016-cfp.html

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Tuesday, April 26, 2016

New ELSA packages resolve 2 issues

Martin Holste committed some fixes for ELSA email recently:
https://github.com/mcholste/elsa/commit/d6b57293ea2d83d35fc530e8d8071539013b3469
https://github.com/mcholste/elsa/commit/9ea0a9d6ed589297094b97c514f29e20eab0c567
https://github.com/mcholste/elsa/commit/6ad7966897a6c18573788d657cc6e28147dc9880

I've built a new ELSA package with all the latest fixes:
securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion7

Also, Harvii submitted a pull request to remove a non-ASCII character from securityonion-elsa-reset-archive:
https://github.com/Security-Onion-Solutions/securityonion-elsa-extras/pull/16

I've merged the pull request and the new package is as follows:
securityonion-elsa-extras - 20151011-1ubuntu1securityonion28

These packages should resolve the following issues:

Issue 881: ELSA: remove non-ascii character from securityonion-elsa-reset-archive
https://github.com/Security-Onion-Solutions/security-onion/issues/881

Issue 882: ELSA: fix email
https://github.com/Security-Onion-Solutions/security-onion/issues/882

Wes Lambert tested these packages.  Thanks, Wes!

Updating
These new packages are now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Several folks have asked about Security Onion t-shirts and they are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
Our next round of online classes is coming up in a few weeks:
http://blog.securityonion.net/2016/03/next-round-of-security-onion-online.html

Conference
Security Onion Conference will be on Friday September 9 and CFP is open!
http://blog.securityonion.net/2016/03/security-onion-conference-2016-cfp.html

Support
Need support?  Please see:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Support

Thanks!

Monday, February 1, 2016

securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion6 resolves issue with map dashboard

Brian Haugli found an issue when rendering ELSA dashboards with maps:

Issue 842: securityonion-elsa: map dashboard displays empty screen
https://github.com/Security-Onion-Solutions/security-onion/issues/842

Martin Holste fixed the bug and I've packaged the fix. The following packages are now available in our stable repo:
securityonion-elsa - 1205chartsjsd3-1ubuntu1securityonion6
securityonion-elsa-extras - 20151011-1ubuntu1securityonion27

Screenshots

Suppose you want to create an ELSA dashboard based on the "Connections - Groupby Resp Country" query:



Click the ELSA drop-down menu and then click Dashboards.  The Dashboards window appears:



Click "Create/import new dashboard".  "Create New Dashboard" window appears.  Specify your desired Title and Alias and then set Auth to "Any authenticated user":



Click the Submit button to return to the Dashboards window:



Click the Actions drop-down menu and then click Edit.  On the Edit page, click "Add Chart".  "Create New Chart" window appears.  Specify your desired Title, set Type to "Map", then add your Label and Query.  Note that the query specifically excludes results where the responder country code is null ("-"):


 Click the Submit button and then click "Finished Editing".  Dashboard appears:



Updating
These new packages are now available in our stable repo.  Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade

Want to show your support for Security Onion?
Several folks have asked about Security Onion t-shirts and they are available in our CafePress store!
http://www.cafepress.com/securityonion/11820053

Training
The next round of online training sessions will be in February.  Please stay tuned for the announcement.

Commercial Support
Need commercial support?  Please see:
http://securityonionsolutions.com

Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists

Thanks!

Search This Blog

Featured Post

Security Onion 3.1.0 Hotfix 20260528 Now Available!

Last week, we released Security Onion 3.1.0: https://blog.securityonion.net/2026/05/security-onion-310-now-available-with.html Today we are ...

Popular Posts

Blog Archive