Replies: 2 comments 2 replies
-
Those are kernel messages https://docs.securityonion.net/en/2.4/console.html#console What does |
Beta Was this translation helpful? Give feedback.
-
If you just have your two ethernet interfaces connected to a switch and in the same network, you probably have the sensor's monitor interface connected to a normal switchport. That's not enough; it has to be configured as a SPAN port so it sees all packets, not just broadcast/multicast. Please reread this section of the docs: https://docs.securityonion.net/en/2.3/hardware.html#packets |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.60
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Meets minimum requirements
CPU
6
RAM
16
Storage for /
269GB available
Storage for /nsm
592GB available
Network Traffic Collection
other (please provide detail below)
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
I installed Security Onion 2.4.60 with ISO file. First, I noticed nothing from SOC but Pending Reboot. And when I rebooted, It continiously displaying [165400.436562] IPTables-dropped IN=eno1 OUT= MAC= ff:ff:ff:ff:ff:ff:b8:85:84:ab:22:a8:08:00 SRC=192.168.10.212 DS=192.168.10.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=54862 PROTO=UDP SPT=137 DPT=137 LEN=58 every 30 seconds I guess.
My installation is standalone but my PC (Dell all-in-one) has 1 interface, so used USB ethernet adapter. But my 2 interfaces is in same local network. I don't know if this caused it. Is it only for informational purpose or pointing why I can't take alerts?
PC: Dell OptiPlex 7460
2 network adapter. I unplugged USB ethernet adapter. But it was same before I unplug second interface.
Suricata rules are enabled but not a single alerts shown. I assume these 2 has connection.

As shown below,

curl testmynids.org/uid/index.html
should trigger rule of Suricata and generate alert. but nothing shows.Guidelines
Beta Was this translation helpful? Give feedback.
All reactions