-
Version2.4.10 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU28 RAM200 Storage for /1TB Storage for /nsm3TB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailDisabling and suppressing in web UI doesn't work. More than one manager-type pillar exists, minion id's listed below: [soc@mgt nids]$ sudo so-rule disabled list More than one manager-type pillar exists, minion id's listed below: Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 3 replies
-
Did you use |
Beta Was this translation helpful? Give feedback.
-
It seems like disabling via web interface without single quotes works, but I still get that error message: More than one manager-type pillar exists, minion id's listed below: However if I try Unfortunatelly suppressing still doesn't work. |
Beta Was this translation helpful? Give feedback.
-
Analyst Quick Links->SIDS - Thresholding thresholding: # Reduced alerts It doesn't work because suppressed events still show in alerts queue. |
Beta Was this translation helpful? Give feedback.
-
It works like a charm! Congratulations and best regards |
Beta Was this translation helpful? Give feedback.
Did you use
're:STUN'
in the administration->idstools->sids->disabled field? I was able to confirm that single quotes does not work (like the documentation shows), but I could successfully disable rules using no quotes (ie:re:STUN
).