Skip to content
Discussion options

You must be logged in to vote

There is a firewall it is set to allow any to any from the sensors to the master.

Is this a simple firewall that just does port blocking or is it a next-gen firewall that could be doing IPS or other kinds of packet manipulation?

Have you checked the logs on the sensor in /opt/so/log/ and specifically telegraf?

Are all devices in your Security Onion sync'd to the same NTP server and do they all currently show the same exact time?

Replies: 2 comments 8 replies

Comment options

You must be logged in to vote
6 replies
@jgiuliano2024
Comment options

@dougburks
Comment options

@jgiuliano2024
Comment options

@dougburks
Comment options

Answer selected by jgiuliano2024
@jgiuliano2024
Comment options

@jgiuliano2024
Comment options

Comment options

You must be logged in to vote
2 replies
@tsmith-spscc
Comment options

@jgiuliano2024
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
3 participants