-
Version2.4.30 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /256 Storage for /nsm256 Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailLooking to confirm... is there no longer the ability to pivot to PCAP export from the Kibana SO Dashboard w/ SOv2.4? SOv2.3 had the Hunt and Optionally Pivot to PCAP option w/in the Kibana results, but not seeing that as an option w/ SOv2.4. Appreciate the clarification! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 8 replies
-
Good afternoon, I have the same question. Glad I found this. I've read through what I could find and checked configuration (at least as far as where I guess it would be). The documentation seems to indicate that the hyperlinks should still be there, but I'm not seeing them nor have I found any way to re-enable this functionality. |
Beta Was this translation helpful? Give feedback.
-
Those hyperlinks are not in 2.4 and I've updated the documentation to reflect that: You should be able to do something similar by copying the log.id.uid field value and then searching SOC Dashboards or Hunt for it. Most folks avoid this issue altogether by simply using SOC Dashboards as their primary dashboards interface: |
Beta Was this translation helpful? Give feedback.
-
Thank you, Mike. I understand. Appreciate the feedback.
…On Fri, Dec 15, 2023 at 3:48 PM Mike Reeves ***@***.***> wrote:
I still wish you had kept the hyperlinks in the Kibana views, but I guess
it wasn't to be.
The technical reason that it is not there is due to Kibana removing
support for scripted fields. To make this work again would require someone
to write a Kibana plugin.
—
Reply to this email directly, view it on GitHub
<#11905 (reply in thread)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ASXJQNXUX765ZA7N33PKWPLYJSZRXAVCNFSM6AAAAABAAOJ7RKVHI2DSMVQWIX3LMV43SRDJONRXK43TNFXW4Q3PNVWWK3TUHM3TQNRXHA2TG>
.
You are receiving this because you were mentioned.Message ID:
<Security-Onion-Solutions/securityonion/repo-discussions/11905/comments/7867853
@github.com>
|
Beta Was this translation helpful? Give feedback.
Those hyperlinks are not in 2.4 and I've updated the documentation to reflect that:
https://docs.securityonion.net/en/2.4/kibana.html
You should be able to do something similar by copying the log.id.uid field value and then searching SOC Dashboards or Hunt for it.
Most folks avoid this issue altogether by simply using SOC Dashboards as their primary dashboards interface:
https://docs.securityonion.net/en/2.4/dashboards.html