Steno data recovery from a broken cluster #13856
Replies: 1 comment 2 replies
-
Do you have access to the that sensor and |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello all,
I am not sure if this is the right way to ask this request, but we have sort of a predicament.
We had a deployed 3-node Security Onion cluster (2.4) collecting network log data. Halfway through our collection, our customer turned off power without notifying us, causing SecOnion to fail to start up.
How do we go about recovering the Steno data stored in the nsm directory? We have a fresh standalone install waiting, but also realize that standalones are usually storing as Suricata.
We need to import this steno data and then generate PCAPs from them to analyze the traffic.
Is there a way to recover this data?
Beta Was this translation helpful? Give feedback.
All reactions