-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /100GB Storage for /nsm500GB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailMy problem is that in the Detections tab i have the following: The problem accured when i updated from 2.4.60 -> 2.4.70 with soup. iv'e tried Differential Update, and Full Update, on each engine, nothing worked. Suricata: Strelka: I would have uploaded some logs from /opt/so/log/suricata but for some reason its completely empty. But i have nothing in the file which is described in the documentation. I hope someone is able to help me based on the information iv'e provided. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 5 comments 55 replies
-
Can you run this query and check the contents of the
This looks a lot like the issue I also aimed at describing in #13112 |
Beta Was this translation helpful? Give feedback.
-
@GitGoodGod Do you have any kind of custom configurations or changes in place? |
Beta Was this translation helpful? Give feedback.
-
Ok, let's try a different approach:
And then click a Full Update for Elastalert and post the logs that you see. |
Beta Was this translation helpful? Give feedback.
-
Can you post the contents of |
Beta Was this translation helpful? Give feedback.
-
Hi Everyone, I'm running a distributed Cluster version 2.4.100 - upgraded and updates. I'm getting a rule missmatch for suricata - and for the love of god can't find the logs that point me to the cause. ElastAlert: OK 024-09-23T06:56:40.043586923Z","message":"Handled request"} this is the output for the so-rule-update that seems to complete successfuly: |
Beta Was this translation helpful? Give feedback.
v.2.4.80 soup fixed the suricata migration failed problem it seems like. :D