-
Version2.4.90 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationother (please provide detail below) Hardware SpecsExceeds minimum requirements CPU12 RAM52 gb Storage for /2Tb Storage for /nsm2Tb Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi I have this in my system: I have checked with Wireshark that they are ICMP messages Type 3, Code 10. And SO is parsing them as source port 3, destination por 10. I can provide you more info if you tell me what do you need. This installation is just 7 days old. I'm new in SO and I have not created or modified parsers or anything similar. Thaks! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
This is the message of one of the events {"ts":1725358584.32528,"uid":"C0j3bY3Wo2ejRyirsl","id.orig_h":"17.253.122.197","id.orig_p":3,"id.resp_h":"...","id.resp_p":10,"proto":"icmp","conn_state":"OTH","local_orig":false,"local_resp":true,"missed_bytes":0,"orig_pkts":1,"orig_ip_bytes":576,"resp_pkts":0,"resp_ip_bytes":0,"community_id":"1:************","orig_mac_oui":"HUAWEI TECHNOLOGIES CO.,LTD"} |
Beta Was this translation helpful? Give feedback.
-
It's normal for Zeek to log the ICMP type as source port and ICMP code as destination port. For more information, please see https://docs.zeek.org/en/current/scripts/base/protocols/conn/main.zeek.html:
|
Beta Was this translation helpful? Give feedback.
It's normal for Zeek to log the ICMP type as source port and ICMP code as destination port. For more information, please see https://docs.zeek.org/en/current/scripts/base/protocols/conn/main.zeek.html: