View MAC address #14384
View MAC address
#14384
Replies: 2 comments 6 replies
-
I double check zeek.conn log and the mac-address field is not there.. What is your use-case for wanting to see mac-address? You know depending on your placement of network taps you will not see the "actual" source/destination mac-address.. For example, typically you place a network tap at the egress choke section of your network between your router and firewall... With that you will only see the destination-mac of the next-hop firewall and source-mac of your router.. |
Beta Was this translation helpful? Give feedback.
6 replies
-
The only reliable source for MAC Addresses would be the dhcp log. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I'm starting to use Security-Onion (2.4.130) and I wanted to ask you if, and if so how, it is possible to view, in addition to the IPs, also the MAC addresses, especially in the Alerts windows.
Beta Was this translation helpful? Give feedback.
All reactions