Request yes/no option to enable Pcap during Sensor installation #14176
-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptioninstallation Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPUlots RAMlots Storage for /lots Storage for /nsmlots Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI am requesting a step be added to the Sensor installation flow that asks if PCAP should be enabled or disabled. I've got a global network grid with many remote Sensors and it would be a real time and resource saver if we could have Steno disabled when we install instead of having to wait for the new Sensor to sync with the Grid and then turning it off in the configs and waiting for things to sync again. Also during that time period that Steno is active, it's consuming disk space with Pcap files. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
We've invested significant time and effort into building a web config interface so that the text-based portion of Setup can be as simple as possible. We have no plans to add back any complexity to the text-based portion of Setup. Here's a possible workaround:
|
Beta Was this translation helpful? Give feedback.
We've invested significant time and effort into building a web config interface so that the text-based portion of Setup can be as simple as possible. We have no plans to add back any complexity to the text-based portion of Setup. Here's a possible workaround:
Disable stenographer by changing your grid default PCAP engine to Suricata:
https://docs.securityonion.net/en/2.4/suricata.html#pcap
Then change your grid default Suricata configuration to only record PCAP for NIDS alerts OR perhaps use the
tag
option but don't define any tags:https://docs.securityonion.net/en/2.4/suricata.html#conditional-pcap