Suricata is reporting a rule mismatch in the Detections section #13155
-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU32 RAM128GB Storage for /150GB Storage for /nsm6TB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI updated from 2.4.60 to 2.4.70 yesterday. I noticed when I logged in that the Detections section had an orange exclamation point. It is reporting that Suricata has a Rule Mismatch. Checking in the hunt section, the error it is throwing is: "{"fields":{"error":"yaml: unmarshal errors:\n line 266: cannot unmarshal !!map into []*model.Override\n line 271: cannot unmarshal !!map into []*model.Override\n line 276: cannot unmarshal !!map into []*model.Override"},"level":"error","timestamp":"2024-06-06T18:20:06.093138607Z","message":"unable to sync suricata community detections"}" I am not sure where to look to fix this issue. Thanks! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Can you please post the contents of the following file, from the Manager:
|
Beta Was this translation helpful? Give feedback.
Can you please post the contents of the following file, from the Manager:
/opt/so/saltstack/local/salt/suricata/thresholding/sids.yaml