2.4.130 Upgrade - No longer can retrieve PCAPs on Standalone #14380
-
Version2.4.130 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU48 RAM128GB Storage for /500GB Storage for /nsm18TB Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailSince upgrading to 2.4.130, even after a full reboot, I am unable to retrieve PCAPs. The only thing returned is: "No search results were found." I am using Stenographer on a Standalone installation. The PCAPs are indeed being recorded, but the GUI simply does not retrieve them for me. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 7 comments 8 replies
-
I should add that so-pcap-export with a regular stenographer query works as expected. |
Beta Was this translation helpful? Give feedback.
-
Can you share any errors found in /opt/so/log/sensoroni/sensoroni.log? If you aren't seeing any errors try tailing that file and executing another pull pcap via the UI |
Beta Was this translation helpful? Give feedback.
-
Good morning and thanks for getting back to me! At first I didn't see any errors but I was able to capture something. Please see below: {"fields":{"jobId":REDACTED},"level":"info","timestamp":"2025-03-13T13:56:33.690978502Z","message":"Discovered pending job"} (Please note that I manually redacted the job ID because I personally don't want the amount of PCAP jobs I run being public.) This led me to believe that the job wasn't taking the time from the GUI. Upon checking the job in the GUI, I do see that there is no time range attached to the job when I create it with the GUI. For whatever reason on my setup the GUI time selector thing doesn't actually apply a time, even after hitting apply. Manually typing a time in and using the "Custom Range" function also doesn't work. Manually typing a time and then hitting apply in the GUI also doesn't work. I'm going to experiment with different browsers and see if it's a browser thing. There are however no console or network errors when I load the GUI so I'm not entirely sure. Thanks for your help so far! |
Beta Was this translation helpful? Give feedback.
-
Is the time configured correctly on both the standalone and your machine? |
Beta Was this translation helpful? Give feedback.
-
Looks like this is a regression. I've created issue #14387 to work on this. |
Beta Was this translation helpful? Give feedback.
-
Hi have the same issue after update to 2.4.130 |
Beta Was this translation helpful? Give feedback.
-
@ZacharyPax @011248163264 we've just released Security Onion 2.4.140 which should resolve this issue. Please try updating and see if that helps. |
Beta Was this translation helpful? Give feedback.
Looks like this is a regression. I've created issue #14387 to work on this.