Replies: 1 comment
-
I don't know if we've tested with Profishark so we can't really guarantee that it works. Looking at your tcpdump output, it appears to be just broadcast and multicast traffic so I'm not sure that you're seeing the actual traffic that you want to see. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version: 2.3.260
Installation Method: Network installation on Ubuntu 20.04
Description: Connecting: Profitap
Hardware Specs: Exceeds minimum requirements
Network Traffic Collection: Profishark-tap
I have the following problem:
I try to connect my Profishark with my security onion distribution. I have one active forward node.
I can theoretically send data with "sudo so-import-pcap" to my security onion. So my connection to the Security Onion manager is working.
I can capture data with "tcpdump -i enx..." and with the Profishark manager. So I can receive data with my tap.
But I can not pick up any data with Zeek/suricata or Stenographer and I don't know why.
message I get in security onion

Zeek logs:
theoretical tcpdump
what may be interesting is the amount of Rx packets I receive but in the end I can caputre data with profishark manager or tcpdump
sensoroni logs
Beta Was this translation helpful? Give feedback.
All reactions