Skip to content
Discussion options

You must be logged in to vote

I went checked so-zeek-logs and everything was already [*]. I also browsed to /nsm/zeek/logs/current/ and see that there is a syslog.log and it has events in to. But when I go to the hunt dashboard and do a [ * | groupby log.file.path ] there are only 7 zeek files listed.

In so-zeek-logs, have you tried selecting Ok for it to apply the configuration with syslog enabled?
https://docs.securityonion.net/en/2.3/so-zeek-logs.html

Have you checked the zeeklogs:enabled pillar?
https://docs.securityonion.net/en/2.3/filebeat.html#configuration

Still on Sec Onion 2.3.190, hope to upgrade soon.

2.3.190 is over a year old:
https://blog.securityonion.net/2022/12/security-onion-23190-now-available.…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by subs1138
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants