Skip to content
Discussion options

You must be logged in to vote

Current setup SecOnion 2.3, running on single server. Network data is being sent from SPANs on a couple switches that I know should be seeing a few of the same packets in transit. I am not seeing double Zeek logs like I expected. Is this because the data broker, Redis, is doing dedup? Part of Zeek autocorrecting? or is there something else in SecOnion that I need to get smart on?

I don't think there is anything in 2.3 that would be de-duplicating the logs. To answer why you're not seeing duplication would require much more knowledge of your network, IP ranges, NAT, switch configuration, and Security Onion configuration. If the Security Onion box is under-powered, then it's possible that…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by subs1138
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants