After last OS update few days ago, alerts stopped working #13769
-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationairgap Hardware SpecsExceeds minimum requirements CPU6 RAM128GB Storage for /293GB Storage for /nsm5.8TB Network Traffic Collectiontap Network Traffic Speedsmore than 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailUpgraded from 2.4.50 to 2.4.100 and now alerts are not showing up in SOC. Running the query Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 3 replies
-
Whats the output of
|
Beta Was this translation helpful? Give feedback.
-
Thank you for your reply, it really helped. I did notice there was no inbound traffic, so I dug into the networking settings on my hypervisor and saw the trunk port was changed (STIG compliance). Changed back to the original trunk port, documented, and it's working fine now. Again, thank you. |
Beta Was this translation helpful? Give feedback.
Thank you for your reply, it really helped. I did notice there was no inbound traffic, so I dug into the networking settings on my hypervisor and saw the trunk port was changed (STIG compliance). Changed back to the original trunk port, documented, and it's working fine now. Again, thank you.