After Upgrade , Suricata wont work #15651
Unanswered
danigijon92-afk
asked this question in
2.4
Replies: 1 comment 2 replies
-
|
What does the syncBlock file say? https://docs.securityonion.net/en/2.4/nids.html#sync-block |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.211
Installation Method
Security Onion ISO image
Description
upgrading
Installation Type
Standalone
Location
other (please provide detail below)
Hardware Specs
Exceeds minimum requirements
CPU
4
RAM
24
Storage for /
1TB
Storage for /nsm
1TB
Network Traffic Collection
span port
Network Traffic Speeds
more than 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Hi,
After upgrading version, im facing this issue :
Suricata Rules:no rules configured
ElastAlert: Rule Mismatch
Strelka: Rule Mismatch
Suricata: Sync Blocked
I noticed the following on yaml , same as
#15335
I found the suricata.yaml file which has references to non-existent folders (/etc/suricata/) but changing the entries to point to /opt/so/conf/suricata/rules, saving and restarting suricata, resets the entries. Where is the config for suricata located if it's resetting that yaml? Is it all in the Docker container?
how this can be fixed?
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions