New 2.4.111 Install - Elastalert Rule Mismatch #14049
-
Version2.4.111 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU12 RAM32 Storage for /300 Storage for /nsm200 Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailI just did a fresh install of 2.4.111 with no custom modifications to rules or alerts and detection page is showing an Elastalert Rule Mismatch. Reboot clears the error and then 15-20 minutes it comes back. Hunt shows integrity check failed; discrepancies found. Not positive but it seems like a similar issue or the same was reported to be resolved in an earlier 2.4 release. What's the easiest way to resolve this or do I just reinstall since I haven't put much time into this fresh install yet. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 8 comments 14 replies
-
Yeah if you're open to doing a fresh install, lets try that and see if the issue persists. Also I'd recommend swapping your / and nsm partitions while you're at it. The nsm should be the one with the most space. |
Beta Was this translation helpful? Give feedback.
-
Anyone else have any other recommendations besides a reinstall? |
Beta Was this translation helpful? Give feedback.
-
It looks like maybe i spoke too soon because the issue has re-appeared. I see it says there's a discrepancy found which is the same message i was getting before i did the rebuild as recommended, but I don't see what the discrepancies are. Would prepfer to not rebuild this again if possible so any help would be appreciated. |
Beta Was this translation helpful? Give feedback.
-
@murph146 @SanibelJack We have confirmed that there is an issue with a recently-updated Sigma rule - For now, search for that rule in Detections and disable it. It will clear up the mismatch. Our next release will fix the field mapping for that rule. |
Beta Was this translation helpful? Give feedback.
-
I have seen this error consistently on the releases for the past 6 months as of 2.4.111 on clean installs. SO as usual throws install errors at the end of the install on fresh hardware, hypervisors, etc. I forgot how I last resolved this, if I find it, I will post it here. Update:
Restarted SO VM Update: back to mismatch about an hour or so into the refresh. |
Beta Was this translation helpful? Give feedback.
-
Recently updated to 2.4.120 last week and I'm not seeing the ElastAlert Rule Mismatch issue return as of yet. |
Beta Was this translation helpful? Give feedback.
-
@murph146 @SanibelJack @mazda4409 @SankaGamage @Fox-E-1337 With the release of .120 last week, we have reworked the field mappings for the Sigma rules that were causing this issue. Please let me know if you continue to see it post-upgrade. |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
@murph146 @SanibelJack @mazda4409 @SankaGamage @Fox-E-1337 With the release of .120 last week, we have reworked the field mappings for the Sigma rules that were causing this issue. Please let me know if you continue to see it post-upgrade.