Issues with AI Playbook #14903
Unanswered
Zer0-cyber-web
asked this question in
2.4
Replies: 2 comments 1 reply
-
Beta Was this translation helpful? Give feedback.
1 reply
-
I would suggest then to name this question accordingly. Now it sounds: while probably should be: But sometimes it gives correct answer though. What do you think? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.160
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
12
RAM
32
Storage for /
500Gb
Storage for /nsm
16Tb
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Hi!

On "Guided analysis" tab - there is a notice says "Some of these playbooks were generated by AI and it's possible that they may not be 100% accurate. Please let us know if you see any issues.".
So - where to I can send report on issue? Like this one, for example:
While:
I monitor entire LAN traffic from SPAN port. There are about 900 hosts and 30 servers. 2 DC controllers, which are DNS-servers for domain hosts.
Not quite. As I mentioned above - there are 2 DC, which are DNS for domain hosts. And those DC are sending upstream requeset to our NGFW, which is blocking malicious DNS requests. But not all hosts are in domain, they send DNS request directly to NGFW, which forwards all request to upstream DNS servers.
So - DC in role of DNS are quite busy, yes. But that alert came from Suricate, which monitors content of traffic, not just DNS requests.
Issues as on first screenshot - are happening quite often. Can I do something to improve playbooks efficience?
I have more such questions, and can be a test-data supplier for improvements.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions