Security Onion 2.4.10 Virtual Machine Import PCAP Failure #12031
-
Version2.4.10 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeImport Locationairgap Hardware SpecsMeets minimum requirements CPU4 RAM16GB Storage for /200GB Storage for /nsmI am unsure Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) Detail
This is a part of an isolated student lab set up with a Security Onion 2 VM and Ubuntu 22.04 VM within VMware Workstation with the intent to move it onto an ESXi environment. The Ubuntu VM can access the SO VM with no issues. Neither VM has internet access. My goal is to be able to import PCAPs from the Ubuntu 22 VM and use the SOC for analysis. When using Grid or so-import-pcap no alerts show on the Dashboard. I have tried running the url-update script from the error log, that did not work. In Grid, it states Kibana is running and healthy; however, when I try to access Kibana it states the server is not ready. This is the same for Elastic Fleet and Osquery Manager. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Have you tried the latest version, 2.4.30? There have been alot of stability fixes from .10 to .30 |
Beta Was this translation helpful? Give feedback.
Have you tried the latest version, 2.4.30? There have been alot of stability fixes from .10 to .30