Phrozyn
8c4c71bfff
Updating mq creds in cron/healthAndStatus.conf for user mozdef (was using qa2)
2017-06-15 15:05:01 -05:00
Brandon Myers
eb8a4c7173
Replace mq server to localhost in healthandstatus
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:05:00 -05:00
Brandon Myers
3e4d8bfc4f
Remove eventStatsAlert cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:59 -05:00
Brandon Myers
8cde233dd2
Remove other http references esCacheMaint cron
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:59 -05:00
Brandon Myers
5345b03ff7
Update cron script to remove http prefix
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:59 -05:00
Brandon Myers
c56f98456b
Break apart healthToMongo cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:59 -05:00
Brandon Myers
82b1e17a10
Convert auditDFileAlerts shell script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:59 -05:00
Brandon Myers
c144719898
Convert fxa health and status to cron shell script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:58 -05:00
Brandon Myers
d83344b13b
Convert eventStats to own cron shell script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:58 -05:00
Brandon Myers
7db4c05fea
Break apart esCacheMaint cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:58 -05:00
Brandon Myers
cba73e1dd5
Add new line to duo logpull conf
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:58 -05:00
Brandon Myers
960f7f33e8
Update duolog pull mozdef url
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:57 -05:00
Brandon Myers
eaa5137e3c
Modify duo loginput url
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:57 -05:00
Brandon Myers
67cf919d20
Add creds to duo_logpull config
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:57 -05:00
Brandon Myers
fabd0051bd
Add sample mozdef url in duologpull
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:57 -05:00
Brandon Myers
6e719e9f0c
Fix logpull script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:57 -05:00
Brandon Myers
40d66285a9
Add duolog pull crons from kangs repo
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:56 -05:00
Phrozyn
9a58559047
Removing history for mozdefGoogleCrednetials.json and committing encrypted version.
2017-06-15 15:04:56 -05:00
Brandon Myers
d573580c10
Increase verbosity for pruneIndexes
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:55 -05:00
Brandon Myers
b9bf9e3f58
Increase logger level for rotateIndexes
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:55 -05:00
Brandon Myers
e34c321e60
Update auth02mozdef script with bool comparison
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:53 -05:00
Brandon Myers
3d5343d371
Modify auth02mozdef config with requirements
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:52 -05:00
Brandon Myers
5b2fa87c48
Update changes to auth02mozdef.py
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:52 -05:00
Brandon Myers
5f82b63dc2
Modify ip blocklist to ignore > 3 months
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:04:51 -05:00
Phrozyn
3e02f27d14
modified esservers to new cluster.
2017-06-15 15:04:45 -05:00
Brandon Myers
1073950c94
Remove mozdefes references in dev
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:48 -05:00
Brandon Myers
ee07fe18a3
Modify esservers from localhost to cluster
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:45 -05:00
Brandon Myers
70ce14c4e3
Fix minor config parameter in cloudTrailAlerts
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:45 -05:00
Brandon Myers
931ec16021
Fix merge with cron directory
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:44 -05:00
Brandon Myers
ef6e483c7e
First import of existing files from prod
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:44 -05:00
Brandon Myers
0722ae4740
Add missing files from prod
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:43 -05:00
Brandon Myers
94c4a2307f
Remove unused fxaAccountCreateAlerts
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:43 -05:00
Brandon Myers
4181fcd276
Fixup remaining kibana-int references
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:43 -05:00
Brandon Myers
0b0c58ff6a
Update missing paths to /opt/mozdef
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:43 -05:00
Brandon Myers
e9a4a67e5a
Modify .py scripts to use /opt dir
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:41 -05:00
Brandon Myers
ddcbfb1db6
Modify cron scripts to use /opt dir
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:40 -05:00
Brandon Myers
81a07bc2d5
Rename mozdefqa1 to localhost in configs
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:40 -05:00
Brandon Myers
e43fe3c323
Replace kibana-int with .kibana as index
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:40 -05:00
Brandon Myers
2d79e07679
Change cpu usage to cpu percent
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:40 -05:00
Brandon Myers
fb5a8fcb50
Switch from MultiMatch to QueryStringMatch in crons
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:33 -05:00
Brandon Myers
b8f9aa8d10
Add size to search query
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:33 -05:00
Brandon Myers
4bc99b0e38
Remove pyes comments
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:32 -05:00
Brandon Myers
5b28f6746a
Convert auditDAlerts cron scrit
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:32 -05:00
Brandon Myers
dc8e96f04c
Convert eventStats cron job
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:32 -05:00
Brandon Myers
ef8bd7ca70
Fix auditDFileAlerts update object
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:32 -05:00
Brandon Myers
f8f32b75b5
Modify auditDFileAlerts cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:32 -05:00
Brandon Myers
03168fcf61
Remove fxaAccountCreateAlerts cron script for alert
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:31 -05:00
Brandon Myers
aded70c659
Modify marketPlaceNotices cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:31 -05:00
Brandon Myers
a4df1fa184
Remove pyes from okta2mozdef
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:31 -05:00
Brandon Myers
891b65ef56
Update okta2mozdef cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:31 -05:00
Brandon Myers
6bbc261e8b
Readd used crons
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:31 -05:00
Brandon Myers
e1b8fd1f99
Modify eventStatsAlerts.py cron script with dependency
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:30 -05:00
Brandon Myers
27e101b241
Update collectSSHFingerprints.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:30 -05:00
Brandon Myers
691e551ca3
Update correlateUserMacAddress.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:30 -05:00
Brandon Myers
1ef8576ef5
Update cloudtrail2mozdef.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:30 -05:00
Brandon Myers
fd7b273fea
Update cloudTrailAlerts.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:29 -05:00
Brandon Myers
a202a88b62
Update collectAttackers.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:29 -05:00
Brandon Myers
ac23691809
Remove comments from syncAlertsToMongo
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:29 -05:00
Brandon Myers
944624fd04
Remove comment from healthToMongo cron
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:29 -05:00
Brandon Myers
b60eca5c93
Update createIPBlockList.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:29 -05:00
Brandon Myers
d3425772b6
Update esCacheMaint.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:28 -05:00
Brandon Myers
34ddc557a3
Update healthAndStatus.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:28 -05:00
Brandon Myers
46fd487ee6
Fixup healthToMongo with health stats in ES
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:28 -05:00
Brandon Myers
7bc678b2d9
Update pruneIndexes.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:25 -05:00
Brandon Myers
ac52fc3f70
Update rotateIndexes.py cron script
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:25 -05:00
Brandon Myers
0a443b8668
Fix up syncAlertsToMongo cron
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:25 -05:00
Phrozyn
39a9d91017
adding cronic script to filter cron emails - avoiding email overload.
2017-06-15 15:03:25 -05:00
Phrozyn
80c3240002
Updating defaultTemplate.json to include apiVersion as a string.
2017-06-15 15:03:24 -05:00
Phrozyn
90e80a4c24
removed defaulttemplate object from json.
2017-06-15 15:03:24 -05:00
Phrozyn
f035de521d
Addding sourceipv4address field to be a string.
2017-06-15 15:03:24 -05:00
Phrozyn
bb4d4a3ce9
Addding sourceipv4address field to be a string.
2017-06-15 15:03:24 -05:00
Phrozyn
159612eaf1
Addding sourceipv4address field to be a string.
2017-06-15 15:03:24 -05:00
Brandon Myers
a77d67d64d
Remove cloudtrail2mozdef hack
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:23 -05:00
Brandon Myers
fccd23128e
Configure auth02mozdef.json
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:23 -05:00
Brandon Myers
38ee234650
Add auth02mozdef cron files
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:22 -05:00
Brandon Myers
3dc6f1d780
Be explicit about config file inclusions in cron
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:05 -05:00
Brandon Myers
a7b7f36653
Remove unused cron scripts excluding setupIndexTemplates
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:03:02 -05:00
Phrozyn
9fdbdc0d1d
adding new default mapping template.
2017-06-15 15:02:48 -05:00
Brandon Myers
6caaad320d
Remove duplicate definitions of toUTC
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:02:46 -05:00
Phrozyn
8ceb41f033
Removing notifyRelengSSHAccess from cron
2017-06-15 15:01:05 -05:00
Phrozyn
ca493ac4bf
mend
2017-06-15 15:00:49 -05:00
Phrozyn
4418ddcd3a
Corrected original config for QA1.
2017-06-15 15:00:48 -05:00
Brandon Myers
375b0290de
Update conf files to use US/Pacific
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:00:48 -05:00
Brandon Myers
79c5cf96ed
Update cron to use US/Pacific as timezone
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:00:47 -05:00
Phrozyn
402eb250a7
diff config for releng ssh access.
2017-06-15 15:00:46 -05:00
Phrozyn
c2ee6e63c4
Changed RelengSSH.conf to UTC
2017-06-15 15:00:45 -05:00
Brandon Myers
0735c61f09
Update releng SSH script to use UTC
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:00:44 -05:00
Phrozyn
0d403940ca
Removed counter and Events, only sending timestamp and summary.
2017-06-15 15:00:44 -05:00
Phrozyn
d6c1a88733
Updated notifyRelengSSHAccess.conf with address for cron email to releng team.
2017-06-15 15:00:44 -05:00
Phrozyn
e88bf198b3
Adjusted timing of notifyRelengSSHAccesstimedelta and ssh_access_signreleng_pyes timedelta.
2017-06-15 15:00:44 -05:00
Phrozyn
84a03b09c7
modified notify for releng signing infra to 24 hours
2017-06-15 15:00:43 -05:00
Phrozyn
6430b8f2d0
Added logic to filter out infrasec logins.
2017-06-15 15:00:43 -05:00
Brandon Myers
99fa7ca655
Remove rra files
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 15:00:42 -05:00
A Smith
75d6bfda3b
Corrected path for qaipblocklist.txt
...
Corrected path for qaipblocklist.txt
2017-06-15 15:00:42 -05:00
Brandon Myers
b3ef583338
Update leftover files from public repo
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2017-06-15 14:59:39 -05:00
Brandon Myers
1d8c59b93f
Setup codebase for merge of two repos
2017-06-15 14:56:47 -05:00
A Smith
261e360997
Adding defaultTemplate back in
2016-11-04 09:27:00 -05:00
A Smith
9fa80ec31e
Removing this template to add a new one
2016-11-04 09:19:06 -05:00
Jeff Bryner
ca3a441664
correction to default mapping to allow for sub objects while explicitly choosing which types to convert to string
2016-10-30 20:26:31 -07:00
Jeff Bryner
73a685e3d2
update default mapping to match all fields as string non analyzed by default, explicitly set exceptions
2016-10-30 11:13:35 -07:00
Gene Wood
0c7e411262
Remove cloudtrail logic which hard codes the S3 bucket name if the script can not authenticate to the target AWS account.
...
https://bugzilla.mozilla.org/show_bug.cgi?id=1217976
2016-10-27 12:20:01 -07:00
kang
cb33e86b33
Add support to import auth0 logs intomozdef
2016-08-04 14:28:29 -07:00
Jeff Bryner
1ae54e25f6
Merge pull request #348 from pwnbus/standardize_bro_intel
...
Standardize other bro_* categories
2016-06-28 12:24:34 -07:00
Brandon Myers
5765bdf7b7
Update other bro_* categories
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2016-06-28 13:47:40 -05:00
Brandon Myers
0669b6594d
Update bro_notice category to bronotice
...
Signed-off-by: Brandon Myers <bmyers@mozilla.com>
2016-06-28 13:26:33 -05:00
Jeff Bryner
48a650f379
Merge pull request #323 from yashmehrotra/master
...
[Mozilla Winter of Security] 3D interactive Attack visualization via Landmass
2016-01-24 11:51:49 -08:00
Yash Mehrotra
5c23ef38fe
Added read field in collectAttackers
...
Frontend working for Read
Batman is awesome
Empty Vessels make the most noise -> Yash Mehrotra
2016-01-18 19:13:07 +05:30
Jeff Bryner
57a87866f2
Merge pull request #315 from gdestuynder/master
...
Fixup and normalize input of Okta logs
2015-11-18 13:43:52 -08:00
Jeff Bryner
b2e29997de
add index templates
2015-11-16 14:59:13 -08:00
Guillaume Destuynder
ea1cac493d
Normalize details.sourceipaddress, details.username, details.sourceuri from Okta logs
...
See also https://github.com/jeffbryner/MozDef/issues/312
2015-11-06 16:27:03 -08:00
Guillaume Destuynder
e7ac3581b5
Report errors when failing to communicate with Okta
2015-11-06 14:29:45 -08:00
Guillaume Destuynder
9d170e3bef
Use state class for saving the lastrun state (imported from cloudtrail2mozdef.py)
2015-11-06 14:04:36 -08:00
Guillaume Destuynder
8d5d3cd12a
Fix trailing whitespaces
2015-11-05 14:58:51 -08:00
Gene Wood
312fcad8a4
Wrapped additional AWS calls with exception handling
2015-10-21 15:33:58 -07:00
Gene Wood
f84e9726a7
Added the ability to iterate over multiple AWS accounts, multiple regions, and the s3 buckets associated with the CloudTrail in each account/region combination
...
* Added RoleManager to cache and manage assumed IAM roles and their credentials
* Added HACK to workaround missing permissions requested in https://bugzilla.mozilla.org/show_bug.cgi?id=1216784
* Added State class to manage and store state instead of writing state to the config file
* Constrained s3 bucket key searches to the specific paths that we're interested in, instead of all keys in all paths of the bucket
* Constrained searches for account/region combinations which have no lastrun value to the previous hour instead of the previous 2 days
* Added new options
* aws_accounts : comma delimited list of AWS account IDs to gather CloudTrail data from
* assumed_role_arns : comma delimited list of ARNs of AWS IAM Roles in various AWS accounts that we can assume in order to query for CloudTrail configuration or fetch s3 data
* bucket_account_map : json encoded dictionary of the mapping of s3 bucket names to their associated AWS account numbers
* state_file_name : filename of the new state storage json file
* regions : list of AWS regions to iterate over for each account looking for CloudTrail configurations
* Removed options
* lastrun : this information is now stored in the state file instead of the config
2015-10-21 13:40:29 -07:00
Jeff Bryner
b9adf1d2bb
add support for google api login/logout event import, closes #272
2015-05-14 16:00:00 -07:00
Jeff Bryner
9a5eae8454
minor: fix missing parens, closes #266
2015-04-01 10:16:18 -07:00
Jeff Bryner
a0a993e432
ignore 0.0.0.0, closes #266
2015-04-01 09:53:14 -07:00
Jeff Bryner
97b9296b69
correct the aggregation, add broadcast attacker option, closes #263 , closes #264
2015-03-28 07:40:20 -07:00
Jeff Bryner
08859d75b2
add auto categorization of attackers, closes #262
2015-03-27 08:39:55 -07:00
Jeff Bryner
648f484d71
minor bugfix in format string
2015-03-27 08:37:44 -07:00
Jeff Bryner
f6484f5c92
add cronjob for alerting on event category statistical deviations over time
2015-02-26 17:04:04 -08:00
Jeff Bryner
f9361c1151
lower the threshold for attacker creation
2015-01-30 09:20:31 -08:00
Julien Vehent
76727906c3
fix mig api error location in mig2mozdef.py
2015-01-26 09:19:52 -05:00
Jeff Bryner
9e5ecb4873
explicitly set alert exchange to durable
2015-01-15 15:25:13 -08:00
Jeff Bryner
b8ffb3a21d
minor chmod +x
2015-01-13 14:55:25 -08:00
Jeff Bryner
7c8fa9592e
chmod +x and update target conf file
2014-12-19 12:32:11 -08:00
Jeff Bryner
6ef2631c40
fix old/new index mismatch between log message and action
2014-12-18 17:02:46 -08:00
Jeff Bryner
2b2c4fb3e3
minor cleanup to comments, logging
2014-12-18 16:54:25 -08:00
Jeff Bryner
2b53c6cd1f
logic updates, debug messages with moar info
2014-12-18 16:02:09 -08:00
Jeff Bryner
e86c71834a
update snapshot backup to allow multiple snapshots/day
2014-12-18 14:32:41 -08:00
Jeff Bryner
2352b475e2
correct mixed tabs/spaces
2014-12-15 15:39:26 -08:00
Jeff Bryner
34b6fcb483
Merge pull request #120 from netantho/averez-114-snapshots
...
better snapshots
2014-12-15 12:48:46 -08:00
Jeff Bryner
a43c0eaeb3
add correlation for user to mac address in new intel index closes #211
2014-12-09 15:19:26 -08:00
Jeff Bryner
844cc0e7df
add event stats to the health/status
2014-12-09 09:35:44 -08:00
Jeff Bryner
cc306e8a3f
minor query change
2014-12-09 09:35:17 -08:00
Jeff Bryner
3f902121ab
Add aggregation cron script to tally category counts for statistical analysis, closes #207
2014-12-01 10:24:14 -08:00
Julien Vehent
6cf16bdb35
minor fixes to mig2mozdef
2014-11-26 12:49:30 -05:00
Jeff Bryner
003a2f3bfc
Merge pull request #203 from jvehent/migpgpauth
...
Replace client cert with PGP token in mig2mozdef.py
2014-11-26 08:14:25 -08:00
Julien Vehent
67e5f9e963
Replace client cert with PGP token in mig2mozdef.py
...
This will require provisioning changes to replace the existing client cert with a
gnupg keyring in puppet.
2014-11-15 17:02:17 -05:00
Jeff Bryner
7aa3f1e0cb
round occasionally long, longs from rabbit queue api
2014-11-14 13:14:30 -08:00
Jeff Bryner
c7c1d20d22
Add facility to create IP block list based on attackers. Closes #198
2014-11-04 15:13:52 -08:00
Jeff Bryner
059b297b8a
move okta default event structure to details for consistency with other event structures
2014-10-21 09:02:31 -07:00
Jeff Bryner
a71f0cea24
add import script for okta sso events
2014-10-20 16:55:27 -07:00
Jeff Bryner
628b3ff4aa
add index to the esmetadata.id field
2014-10-20 10:39:22 -07:00
Julien Vehent
d0439082e9
fix status value in MIG api search for mig2mozdef
2014-10-11 22:45:59 -04:00
Jeff Bryner
1944f8fa16
fill in some rarely used toUTC gaps
2014-10-08 10:51:59 -07:00
Jeff Bryner
ab375094f5
watchdog script to monitor JVM memory usage and clear cache to lower memory usage if needed
2014-10-08 10:40:06 -07:00
Jeff Bryner
b95ce562fb
add health to mongo run to the status shell script
2014-10-08 10:39:25 -07:00
Jeff Bryner
618675b72b
UTC date default for sync alert search, update dockerfile to all alerts.js, events.js
2014-08-05 23:46:18 -07:00