Граф коммитов

1409 Коммитов

Автор SHA1 Сообщение Дата
Phrozyn 39a9d91017
adding cronic script to filter cron emails - avoiding email overload. 2017-06-15 15:03:25 -05:00
Phrozyn 80c3240002
Updating defaultTemplate.json to include apiVersion as a string. 2017-06-15 15:03:24 -05:00
Phrozyn 90e80a4c24
removed defaulttemplate object from json. 2017-06-15 15:03:24 -05:00
Phrozyn f035de521d
Addding sourceipv4address field to be a string. 2017-06-15 15:03:24 -05:00
Phrozyn bb4d4a3ce9
Addding sourceipv4address field to be a string. 2017-06-15 15:03:24 -05:00
Phrozyn 159612eaf1
Addding sourceipv4address field to be a string. 2017-06-15 15:03:24 -05:00
Brandon Myers bfba1d3c4c
Add apiVersion mapping fix for cloudtrail
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:23 -05:00
Brandon Myers a77d67d64d
Remove cloudtrail2mozdef hack
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:23 -05:00
Brandon Myers 6774599a37
Add exception in fxaFixup for fxa-auth-server
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:23 -05:00
Brandon Myers fccd23128e
Configure auth02mozdef.json
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:23 -05:00
Brandon Myers 38ee234650
Add auth02mozdef cron files
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:22 -05:00
Brandon Myers 362c870cfa
Add unit test for no results in client
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:22 -05:00
Brandon Myers 0b5efec854
Update alert test case with master
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:22 -05:00
Brandon Myers 731da67eba
Fix timestamp related issues in tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:22 -05:00
Brandon Myers 44b5e8aa4a
Fix unit test suite current timestamp
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:22 -05:00
Gene Wood b4ffb4d42e
Set default alert_filename based on the following convention
Test class : TestAlertExampleName
Alert class : AlertExampleName
Alert filename : example_name.py
2017-06-15 15:03:21 -05:00
Brandon Myers 0562a77be7
Update alert unit tests to use alert_filename
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:20 -05:00
Gene Wood 3c16556065
Derive alert_name from class name 2017-06-15 15:03:07 -05:00
Brandon Myers c3226d0488
Remove correlated alerts alert unit test
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:07 -05:00
Brandon Myers 113b4c8125
Remove filtersFromKibana feature
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:06 -05:00
Brandon Myers 176886e1a2
Remove unused alerts
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:06 -05:00
Brandon Myers 3e818ebdf9
Move test config file to tests root
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:06 -05:00
Brandon Myers 07182bf99c
Fix paths in tests/libs
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:06 -05:00
Brandon Myers 20e0d8a3fb
Move test files under tests/lib
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:06 -05:00
Brandon Myers 3dc6f1d780
Be explicit about config file inclusions in cron
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:05 -05:00
Brandon Myers a7b7f36653
Remove unused cron scripts excluding setupIndexTemplates
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:02 -05:00
Phrozyn 9fdbdc0d1d
adding new default mapping template. 2017-06-15 15:02:48 -05:00
Brandon Myers d1265dd651
Add two cloudtrail alerts to run
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:48 -05:00
Brandon Myers e4f1046961
Fix cloudtrail_pyes
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:48 -05:00
Brandon Myers 18091b58af
Update formatting weirdness in alerts
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:48 -05:00
Brandon Myers 63ddffc11e
Fix alerttask import
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:47 -05:00
Brandon Myers 6caaad320d
Remove duplicate definitions of toUTC
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:46 -05:00
Brandon Myers 3a3221987f
Add cloudtrail couple alerts
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:12 -05:00
Brandon Myers 2d55f2f1f5
Convert releng alert to non pyes
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:12 -05:00
Brandon Myers c41c31c181
Fix up alert unit tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:11 -05:00
Brandon Myers 5cbc540ff5
Fix search query unit tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:11 -05:00
Brandon Myers 02ad68ed25
Fix bruteforce_ssh_pyes alert
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:11 -05:00
Brandon Myers 8e52a89c4c
Finish updating alert unit tests to new format
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:11 -05:00
Brandon Myers d517fb1ad3
Improve some alert unit tests to better format
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:11 -05:00
Brandon Myers 63608e3bf6
Restrict unit test access from running on mozilla
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:10 -05:00
Brandon Myers ff4260f879
Configure rest api to handle no kibana index
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:10 -05:00
Brandon Myers 28c2a7fd45
Remove bot/safe mozdefbot
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:08 -05:00
Brandon Myers e832b313ee
Fix flush_bulk for pyes only
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:01 -05:00
Brandon Myers df8cb7905f
Remove utils in favor of lib es client
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:01 -05:00
Brandon Myers 76174add7d
Update mq directory with search class
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:01 -05:00
Brandon Myers 5082d87f68
Update alertWorker config
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:00 -05:00
Brandon Myers 49a042107e
Remove mq/safe directory and files
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:01:58 -05:00
Brandon Myers 67b38ae579
Remove mq/mq files and directory
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:01:42 -05:00
Brandon Myers 7c9cad5352
Remove pyes exception handling from rest
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:01:24 -05:00
Brandon Myers 7b14fcef69
Update rest api with tests
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:01:24 -05:00