Skip to content
Discussion options

You must be logged in to vote

Digging a bit deeper, all the traffic from these strange subnets is only showing up from a very narrow window of time as I was doing the final setup of the of the reinstalled Security Onion Instance. As part of that work I ran so-test. It appears these alerts came from the sample PCAP's. Sorry for wasting people's time. #feelingstupid

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@bird2473
Comment options

Answer selected by pgatty
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants