osquery, strelka, sysmon logs missing from dashboard and hunt #10146
Replies: 1 comment
-
I guess, the answer is already there above. I'm excited to tryout SO 2.4 and see which features made it up there. :) Many thanks to SO-developers! :) |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello Everyone!
I would like to direct this query to the developers.
Scenario: I attended the instructor-led training online on May 2022. We were given a zip file for practice using a Standalone install. My Security Onion was timely for the release at that time (version 2.3.110). Everything went well. However, after a few upgrades of Security Onion, I noticed the logs osquery, strelka and sysmon (I followed Sir Bryant's Sysmon for Linux page and it was working for a while) when out of the blue the mentioned logs above (and it was only then I noticed) are nowhere to be found from the dashboard and hunt interfaces.
So, after searching, I saw this page, specifically the section that says... `````
So, I'd like clarification on these issues:
Thank you Security Onion for giving the community a very much capable platform for hunting evil. I especially enjoyed utilizing the dashboards and seing almost instantly where things are coming from. :) 👍
Beta Was this translation helpful? Give feedback.
All reactions