Detections from saricata on lab #13632
Replies: 1 comment
-
The Detections interface shows all possible detections. If one of those detections actually detects something, then it generates an alert in the Alerts interface. For more information, please see:
What version are you running? 2.4.90 included some speed improvements: |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4 Pre-release (Beta, Release Candidate)
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Standalone
Location
airgap
Hardware Specs
Meets minimum requirements
CPU
4
RAM
16
Storage for /
100gb
Storage for /nsm
100gb
Network Traffic Collection
tap
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
I have security onion running in a lab environment. Is the detections tab actual detections or are they the list of rules that SO uses for alerts? Is there a way to speed up the detection rules being automatically created on first install for an airgapped environment?
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions