Suricata not generating alerts #11366
Replies: 1 comment
-
First, please note that 2.3.190 is from December of last year: We recommend updating to a more recent version of 2.3: or the new 2.4:
Have you gone through all of the troubleshooting steps in the documentation? |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello, I am having issues on my distributed SO 2.3.190 build. Currently on one of them, Suricata alerts are no longer populating within the /nsm/suricata/* on the sensor. TCPDUMP on the sensor returns data flow for bond0. Redis queue shows change for manager. I am still getting Zeek alerts also. All services look good for the entire stack to, and so does the suricata log via 'docker logs so-suricata'. The Suricata.yaml also has the interface for bond0 within it.
What do you think could possibly be the problem here? I know alot of the time the best solution if data retention isn't a huge need is to redeploy, however I feel like this is a simple fix in some file. If you need anymore information, please let me know. Thank you.
Beta Was this translation helpful? Give feedback.
All reactions