Replies: 3 comments 4 replies
-
when trying to run so-rule-update |
Beta Was this translation helpful? Give feedback.
-
The IP address CIDR block of the network you want to monitor, is it in Suricata "HOME_NET"? SO > Administration > Configuration > suricata > config > vars > address-groups > HOME_NET By default the following RFC1918 CIDR blocks are entered: If your network is inside these CIDR blocks then the setting is correct. If it is not, then add your CIDR block. |
Beta Was this translation helpful? Give feedback.
-
Looking at your first screenshot, it's failing to download the rules. Do you have Internet access? If not, you might consider an airgap installation: For additional troubleshooting steps, please see the Troubleshooting Alerts section of the documentation: |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.0
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Standalone
Location
other (please provide detail below)
Hardware Specs
Meets minimum requirements
CPU
20
RAM
100000
Storage for /
1000
Storage for /nsm
1000
Network Traffic Collection
span port
Network Traffic Speeds
more than 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
why is there no suricata alert after i install the 2.4 ,i dont know what i missed out but there is no error , just that no alert , even if i import some pcap supposed to flag some alert but it doesnt
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions