Replies: 2 comments 1 reply
-
Probably because the PCAP with the malware has another $HOME_NET than configured in your SO ? |
Beta Was this translation helpful? Give feedback.
1 reply
-
Have you tried following the Troubleshooting Alerts section of the documentation? If that doesn't help, please share the outcome of each step so that we can assist you further. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.100
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Eval
Location
airgap
Hardware Specs
Meets minimum requirements
CPU
8
RAM
10GB
Storage for /
200
Storage for /nsm
200
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
I want to import the PCAPs, as described in https://blog.securityonion.net/2021/07/quick-malware-analysis-malware-traffic_29.html
I import the PCAP via:

The importing is successful. I can see the connections in the dashboard when I filter for the specific time range.
But in the alert tab, there is no suricata alert.
I saw a similar problem: #2489
Doing the described steps with another malware pcap was also not successful.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions