Phrozyn
|
39a9d91017
|
adding cronic script to filter cron emails - avoiding email overload.
|
2017-06-15 15:03:25 -05:00 |
Phrozyn
|
80c3240002
|
Updating defaultTemplate.json to include apiVersion as a string.
|
2017-06-15 15:03:24 -05:00 |
Phrozyn
|
90e80a4c24
|
removed defaulttemplate object from json.
|
2017-06-15 15:03:24 -05:00 |
Phrozyn
|
f035de521d
|
Addding sourceipv4address field to be a string.
|
2017-06-15 15:03:24 -05:00 |
Phrozyn
|
bb4d4a3ce9
|
Addding sourceipv4address field to be a string.
|
2017-06-15 15:03:24 -05:00 |
Phrozyn
|
159612eaf1
|
Addding sourceipv4address field to be a string.
|
2017-06-15 15:03:24 -05:00 |
Brandon Myers
|
bfba1d3c4c
|
Add apiVersion mapping fix for cloudtrail
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:23 -05:00 |
Brandon Myers
|
a77d67d64d
|
Remove cloudtrail2mozdef hack
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:23 -05:00 |
Brandon Myers
|
6774599a37
|
Add exception in fxaFixup for fxa-auth-server
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:23 -05:00 |
Brandon Myers
|
fccd23128e
|
Configure auth02mozdef.json
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:23 -05:00 |
Brandon Myers
|
38ee234650
|
Add auth02mozdef cron files
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:22 -05:00 |
Brandon Myers
|
362c870cfa
|
Add unit test for no results in client
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:22 -05:00 |
Brandon Myers
|
0b5efec854
|
Update alert test case with master
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:22 -05:00 |
Brandon Myers
|
731da67eba
|
Fix timestamp related issues in tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:22 -05:00 |
Brandon Myers
|
44b5e8aa4a
|
Fix unit test suite current timestamp
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:22 -05:00 |
Gene Wood
|
b4ffb4d42e
|
Set default alert_filename based on the following convention
Test class : TestAlertExampleName
Alert class : AlertExampleName
Alert filename : example_name.py
|
2017-06-15 15:03:21 -05:00 |
Brandon Myers
|
0562a77be7
|
Update alert unit tests to use alert_filename
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:20 -05:00 |
Gene Wood
|
3c16556065
|
Derive alert_name from class name
|
2017-06-15 15:03:07 -05:00 |
Brandon Myers
|
c3226d0488
|
Remove correlated alerts alert unit test
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:07 -05:00 |
Brandon Myers
|
113b4c8125
|
Remove filtersFromKibana feature
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:06 -05:00 |
Brandon Myers
|
176886e1a2
|
Remove unused alerts
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:06 -05:00 |
Brandon Myers
|
3e818ebdf9
|
Move test config file to tests root
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:06 -05:00 |
Brandon Myers
|
07182bf99c
|
Fix paths in tests/libs
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:06 -05:00 |
Brandon Myers
|
20e0d8a3fb
|
Move test files under tests/lib
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:06 -05:00 |
Brandon Myers
|
3dc6f1d780
|
Be explicit about config file inclusions in cron
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:05 -05:00 |
Brandon Myers
|
a7b7f36653
|
Remove unused cron scripts excluding setupIndexTemplates
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:03:02 -05:00 |
Phrozyn
|
9fdbdc0d1d
|
adding new default mapping template.
|
2017-06-15 15:02:48 -05:00 |
Brandon Myers
|
d1265dd651
|
Add two cloudtrail alerts to run
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:48 -05:00 |
Brandon Myers
|
e4f1046961
|
Fix cloudtrail_pyes
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:48 -05:00 |
Brandon Myers
|
18091b58af
|
Update formatting weirdness in alerts
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:48 -05:00 |
Brandon Myers
|
63ddffc11e
|
Fix alerttask import
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:47 -05:00 |
Brandon Myers
|
6caaad320d
|
Remove duplicate definitions of toUTC
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:46 -05:00 |
Brandon Myers
|
3a3221987f
|
Add cloudtrail couple alerts
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:12 -05:00 |
Brandon Myers
|
2d55f2f1f5
|
Convert releng alert to non pyes
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:12 -05:00 |
Brandon Myers
|
c41c31c181
|
Fix up alert unit tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:11 -05:00 |
Brandon Myers
|
5cbc540ff5
|
Fix search query unit tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:11 -05:00 |
Brandon Myers
|
02ad68ed25
|
Fix bruteforce_ssh_pyes alert
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:11 -05:00 |
Brandon Myers
|
8e52a89c4c
|
Finish updating alert unit tests to new format
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:11 -05:00 |
Brandon Myers
|
d517fb1ad3
|
Improve some alert unit tests to better format
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:11 -05:00 |
Brandon Myers
|
63608e3bf6
|
Restrict unit test access from running on mozilla
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:10 -05:00 |
Brandon Myers
|
ff4260f879
|
Configure rest api to handle no kibana index
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:10 -05:00 |
Brandon Myers
|
28c2a7fd45
|
Remove bot/safe mozdefbot
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:08 -05:00 |
Brandon Myers
|
e832b313ee
|
Fix flush_bulk for pyes only
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:01 -05:00 |
Brandon Myers
|
df8cb7905f
|
Remove utils in favor of lib es client
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:01 -05:00 |
Brandon Myers
|
76174add7d
|
Update mq directory with search class
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:01 -05:00 |
Brandon Myers
|
5082d87f68
|
Update alertWorker config
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:02:00 -05:00 |
Brandon Myers
|
49a042107e
|
Remove mq/safe directory and files
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:01:58 -05:00 |
Brandon Myers
|
67b38ae579
|
Remove mq/mq files and directory
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:01:42 -05:00 |
Brandon Myers
|
7c9cad5352
|
Remove pyes exception handling from rest
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:01:24 -05:00 |
Brandon Myers
|
7b14fcef69
|
Update rest api with tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
|
2017-06-15 15:01:24 -05:00 |