Skip to content
Discussion options

You must be logged in to vote

32MB of RAM

Am I correct in assuming that should be 32GB?

I have looked at this rule PublicID 2027867 and found that this rule I disabled right on Alert page while observing alerts. Since that - there was about two reboots (manual, by request on Grid section), and Mismatch still in place.

Have you tried doing a full update as described at https://docs.securityonion.net/en/2.4/detections.html#options?

It lookus like I need to "undeploy" that rule somehow, but - how? Solution like "justg enable it back" - is not acceptable, it generates too much noise alerts.

I understand that you don't want to keep it enabled it permanently, but have you tried re-enabling the rule temporarily and the…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Zer0-cyber-web
Comment options

Answer selected by Zer0-cyber-web
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants