Questions about enabled detection after initial setup #14815
-
Version2.4.160 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU4 RAM24GB Storage for /314 Storage for /nsm673 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi, Would it be possible to parse the confidence value and show it in the details table so that it is possible to filter for it? Best regards Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 4 replies
-
Beta Was this translation helpful? Give feedback.
-
Hi Chris, Is there a way
Best regards |
Beta Was this translation helpful? Give feedback.
Yes, that's why I mentioned you would need to have no tuning applied to see that. There isn't a field in the rule that specifies whether it is enabled by default or not.
It really comes down to your network and what you want to alert on.