Rule synchronization is currently blocked in suricata #15329
-
Version2.4.200 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM128 GB Storage for /5 TB Storage for /nsm10 TB Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailSince upgrading to 2.4.200, I am seeing an error in the detections page on the soc web app. For suricata it shows, "sync blocked" and hovering over the message shows "rule synchronization is currently blocked." Any idea on what could be causing this. Thank you! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
just went through it so had the page still up |
Beta Was this translation helpful? Give feedback.
just went through it so had the page still up
https://docs.securityonion.net/en/2.4/nids.html#syncblock