Replies: 5 comments 3 replies
-
#1720 Can you give some more information about your server? |
Beta Was this translation helpful? Give feedback.
-
The server is a VMWare virtual machine. The network traffic is collected using one Great Scott Gadgets Throwing Star LAN Tap Pro The server has 4 core and 16GB RAM. Regards RS |
Beta Was this translation helpful? Give feedback.
-
@ricamz I think cm-ops was asking for more information about how you installed Security Onion. Did you use our Security Onion ISO image or did you do a network installation on some other Linux distribution? Please note that 2.3 reaches End Of Life in less than 4 months: So this might be a good opportunity to move to 2.4 anyway.
Depending on how much traffic you're monitoring, this could result in packet loss. So you may want to consider replacing with an actual tap: |
Beta Was this translation helpful? Give feedback.
-
Hi Doug. I have installed a standalone version but didn't add a sniffing interface. I am not able to access the server now, as I am on holidays. But will confirm once I am there. Thank you for your help. For me the big issue with the Elastic agent is that I don't have the same level of alerts as in Wazuh (or at least it gives a little work to achieve the same level of alerts): file changes, logs, users activity, http errors (and other applications). I produce a weekly report that is based on those alerts and I still don't have the sniffing interface 100% operational. I know that I will have to change to the 2.4 version, but for now the 2.3 is giving me the right level of alerts. Regards RS |
Beta Was this translation helpful? Give feedback.
-
Hi all. Still have this error: When I perform the so-monitor-add eth1 command it issues the error: Error: NetworkManager is not running. Can anyone help on this? RS |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi.
I am running SO in a standalone version, in 2.3.270.
I had the system running for some months and now I want to add a network interface for traffic monitoring (suricata).
When I perform the so-monitor-add eth1 command (for the second interface) it issues the error:
Error: NetworkManager is not running.
Error: NetworkManager is not running.
Do you know what could be the problem?
Regards
Ricardo
Beta Was this translation helpful? Give feedback.
All reactions