No Entries in Suricata Security Onion 2.3.10 #2378
-
Hello, I have a Hyper-V install of latest version of Security Onion. I followed the steps from https://cybersecurity.att.com/documentation/usm-anywhere/deployment-guide/hyperv/getting-traffic-from-physical-network-hyper-v.htm to set the NIC and vSwitch settings. I can see traffic from my monitor port, but nothing is populating in Suricata. When I do a so-status, all entries are green. Anyone else experiencing this or similar with Suricata? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
Update: I ran so-test and the replay data does show in Suricata. But, my live data still does not. I can see entries in Zeek and in Network categories. |
Beta Was this translation helpful? Give feedback.
Update: I ran so-test and the replay data does show in Suricata. But, my live data still does not. I can see entries in Zeek and in Network categories.