Suricata rule mismatch in 2.4.90 #13524
-
Version2.4.90 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationairgap Hardware SpecsExceeds minimum requirements CPU24 RAM64 GB Storage for /500 GB Storage for /nsm48 TB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailMy issue essentially mirrors the issue described in #13124 My initial installation was on release 2.4.60, after upgrading to 2.4.70 the issue began though instead of resolving as it did for a few in the above discussion after going to 2.4.80, I'm still experiencing it on 2.4.90.
I would say very few configuration changes in the grand scheme of things had been made prior to 2.4.80 and only a couple of tuning changes as well. Forcing a sync of any kind within detections changes nothing, there are no entries in local.rules, and the metadata engine is still Zeek. There are no errors when running salt-call state.highstate Please let me know what else I can try! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 17 replies
-
Look at this: #13525 |
Beta Was this translation helpful? Give feedback.
-
@Syngelik Can you please post the output of the following, run from the Manager:
|
Beta Was this translation helpful? Give feedback.
-
@Syngelik Is there literally nothing in the Also, please confirm what version you are on - .80 or .90 ? |
Beta Was this translation helpful? Give feedback.
Can you doublecheck what version you are on?