IDH port scan detection doesn't work #12180
Replies: 1 comment 1 reply
-
Verify that the logs are being generated as expected - you can view them in Hunt. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello.
I've encountered a problem. After enabling the portscan_x_enabled option in administration->configuration->idh->opencanary->config
I don't receive any alerts in security onion when scanning IDH ports with nmap (without options, just "nmap idh_node_ip"). At the same time, I receive notifications from ssh, ftp and other services when I try to interact with idh
After some googling I came across this discussion (#11875) which recommends importing a playbook to receive a port scan alert. Could you answer a few questions regarding this?
Thank you very much.
Beta Was this translation helpful? Give feedback.
All reactions