-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU8 RAM20 Storage for /300 Storage for /nsm300 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi all, I am extracting files from zeek and the zeek files log shows the extraction, however when I check the directory it is always empty. Where can I find these extracted files or where do they go? Thanks files.log: directory: Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 8 replies
-
When Zeek extracts files, they are then analyzed by Strelka: |
Beta Was this translation helpful? Give feedback.
-
Hi, I have the same problem, I can't find the file in strelka/processed These are similar entries before and after update from .90 to .110: The file HTTP-FgTK8j1MzI5ETlT3Bc-9839a35b4f8abbf4d36c82848875f727.exe does exist in strelka/processed but the other doesn't exist |
Beta Was this translation helpful? Give feedback.
-
@masedira, could you check file.bytes.missing? I have other installation with .110 and much more events. I have seen that the problem existed before update to .110 If there are missing bytes, the file is not extracted. |
Beta Was this translation helpful? Give feedback.
I just tested it and it works fine for me. You may need to clear the history in /nsm/strelka/history if you have seen this file before. We only process files every 3 days. It is safe to delete all the files in /nsm/trelka/history. We do this because if someone sends out a pdf to 500 of their closest colleagues that the sensor does not process the same pdf 500 times. I would also ensure the mime type of the file is listed in the config in soc. We only extract those mime types.