Issue Elastic _Id Field Pivot to PCAP #13968
-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationairgap Hardware SpecsMeets minimum requirements CPU8 RAM32 Storage for /100 Storage for /nsm100 Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailIn earlier versions of Security Onion, users leveraging Elastic could click on the value field in _id to pivot directly to the PCAP associated with a specific event. However, I’m now unable to perform this action and was wondering if something has changed. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
Having exactly the same issue. Same SO version, but SO has network access. ISO install method - ManagerSearch+Forward node. |
Beta Was this translation helpful? Give feedback.
-
There is no way to link to PCAP from kibana. You must use SOC to pull it. Kibana removed scripted fields several versions ago which is how we were able to do this in the past. |
Beta Was this translation helpful? Give feedback.
There is no way to link to PCAP from kibana. You must use SOC to pull it. Kibana removed scripted fields several versions ago which is how we were able to do this in the past.