c9b909e51d
finetune new honeypots logging
2021-11-02 19:13:28 +00:00
ea624351b5
finetuning logstash.conf for new honeypots
2021-10-29 16:28:16 +00:00
c1eb9f7216
logstash parsing for ddospot, hellpot
2021-10-28 18:57:55 +00:00
1a844d13ba
start integrating new honeypots into ELK
2021-10-27 16:14:52 +00:00
348a5d572b
bump elastic stack to 7.15.1
2021-10-26 13:56:38 +00:00
eefd38a335
bump elastic stack to 7.15.0
...
no image upgrade before 7.15.1
2021-09-30 20:40:42 +00:00
ed0c5aa89f
add logstash-output-gelf, fixes #861
2021-09-15 17:39:04 +00:00
9de1bdd0b5
tweaking, bump elastic stack to 7.14.1, rebuild dashboards
2021-09-15 15:58:44 +00:00
06ef8850fe
prep for ELK 7.13.4, start full integration of new honeypots
2021-08-25 15:04:27 +00:00
4cb84166c5
bump ewsposter to 1.2.0, elk stack to 7.13.2
2021-06-28 16:30:40 +00:00
f51ab7ec0f
prepare to bump elastic stack to 7.13.1
2021-06-10 17:03:22 +00:00
de38e5e86f
Rebuild Logstash, Elasticsearch
...
Setting static limits for Elasticsearch / Logstash on Xms, Xmx and Container RAM results in unwanted side effects for some installations. With Elastic supporting dynamic heap management for Java 14+ we now use OpenJDK 16 JRE and as such remove limitations. This should improve stability for T-Pot, provided the minimum requirements will be met.
2021-05-26 11:00:49 +00:00
0c5ab33b8a
bump elastic stack to 7.12.1
2021-05-17 16:32:03 +00:00
d5f0ceb15b
push elastic stack to 7.11.1
2021-02-19 10:17:30 +00:00
80d9efa729
bump elk stack images to alpine 3.13
2021-02-12 13:54:42 +00:00
e5f29f3c90
bump elk stack to 7.11.0
2021-02-12 13:21:35 +00:00
af6ce8854d
bump elastic stack to 7.10.1
2020-12-10 15:20:18 +00:00
f3f9f6ae72
cleanup
2020-12-03 00:01:38 +00:00
8a7e81815e
prep for Elastic Stack 7.10.0
2020-12-02 22:36:17 +00:00
92925cecbd
bump dicompot to latest master
2020-10-27 21:30:33 +00:00
f204cdf9b8
bump elk to 7.3
2020-10-27 19:43:32 +00:00
ff4a394e3b
reverting elk to 7.9.1
2020-10-15 12:24:46 +00:00
488da48df7
Bump Logstash version to 7.9.2
2020-10-04 18:04:15 -07:00
47dca8b835
continue pin / prep images ghcr
2020-09-04 12:37:28 +00:00
54a6a944aa
prep for ipphoney
2020-08-25 12:25:59 +00:00
b86d2c715b
prep for ipphoney
2020-08-24 21:36:08 +00:00
5080151b7c
prep for elk 7.9
2020-08-24 10:35:46 +00:00
c1f7146800
prep elk stack for 7.9.0
2020-08-20 15:03:16 +00:00
c28642932a
bump elk stack to 7.8.1
2020-08-13 08:34:44 +00:00
6d29f504df
provide fix for #669
2020-07-06 23:30:11 +00:00
16a7cdb975
tweaking
...
Update logstash config for new Dicompot fields
Revert Dionaea back to 0.8.0, latest master was unstable
2020-06-26 23:48:48 +00:00
238a08b055
tweaking
...
cleanup index-pattern
add dicompot log to logstash
2020-06-24 13:21:29 +00:00
99d8cf9b32
fix for query fields
2020-06-24 10:22:09 +00:00
81c6351cf1
fix for keeping daily index
2020-06-23 21:40:38 +00:00
65e849cf33
bump elk stack to 7.8
2020-06-21 21:11:21 +00:00
a396356785
add honeysap logstash config
2020-06-19 22:53:56 +00:00
2882668826
Add a new elasticsearch honeypot
...
adjust installer
adjust elasticpot configs to T-Pot's environment
create Dockerfile
adjust logstash config
update Readme
2020-06-17 18:09:59 +00:00
4cc1aa08c2
tweaking
...
Bump ELK stack to 7.7.1
Install curator via pip
Some tweaks
2020-06-08 21:56:16 +00:00
be918033e0
bump to ELK 7.7.0
2020-05-14 16:27:57 +00:00
680194adf7
prep for new listbot FQDN
2020-05-12 09:19:09 +00:00
ed73d83317
Update update.sh
2020-04-22 17:48:32 +02:00
a6c8d3d712
Update Dockerfile
2020-04-22 17:15:44 +02:00
1a7b3b3795
Load listbot data from OTC
2020-04-22 16:50:41 +02:00
73e1842c16
offload listbot from netlify CDN
2020-04-02 13:12:11 +00:00
df22adb45d
bump elk stack to 7.6.1
2020-03-05 21:20:11 +00:00
f11ad6b523
tweaking
...
ELK 7.6.0 is not ready for production, however it works if APM is enabled (disabled in config, so image wont build as precaution)
Remove SISSDEN from ewsposter, suricata
Bump suricata to 5.0.1
Alpine now support suricata incl. enabled JA3 support, move back to Alpine install
2020-02-14 15:28:06 +00:00
5ce5911ec1
cleanup
2020-02-03 12:59:21 +00:00
b9da9f04af
adjust default field
2020-02-03 12:18:43 +00:00
984ba958fb
logstash template not upgraded
...
with daily index enabled logstash will not be able to put new events into ES
simple solution, just deleting logstash template upon logstash start and leave it to logstash to upload the latest template
.
2020-02-01 14:08:23 +00:00
5a4724bcba
elk 7.x dev test
2020-01-31 14:21:55 +00:00