-
Version2.4.30 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU12 RAM28 Storage for /200 Storage for /nsm120 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailYes...I know...nobody cares about IPv6...until it sneaks around your monitoring... :) This is potentially just a more general information seeking discussion. At first I thought it was just the monitored home ranges; but even if that was the case I'd at least see the sources/destinations tagged appropriately just not see alerts triggered. For giggles on a workstation I disabled ipv4 and just watched youtube videos for 30 minutes. Filtering for ip.version: 6 yielded exactly no records whatsoever. Just seems like a small tweak needs to happen in the pipeline somewhere but I'm not smart enough to locate where. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
For these logs that have the |
Beta Was this translation helpful? Give feedback.
For these logs that have the
ip.version
field, what is theevent.dataset
field set to? Is itpfsense.firewall
?