Skip to content
Discussion options

You must be logged in to vote

So moving from 16.04 to 2.3 and used to seeing Uncatorgized events in 16.04 and Suricata, and wanted to see if that is still in 2.3.

In Security Onion 2.3, the equivalent of Uncategorized Events is shown on the Alerts page. The default view shows events that have not been acknowledged or escalated:
https://docs.securityonion.net/en/2.3/alerts.html

Second I know that we were able to get Top 20 alerts, and uncategorized events via mysql (and via sostat).

Alerts are now stored in Elasticsearch rather than mysql, so you might be able to put together a command line query using so-elasticsearch-query:
https://docs.securityonion.net/en/2.3/so-elasticsearch-query.html

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@xfaith
Comment options

@dougburks
Comment options

@xfaith
Comment options

@dougburks
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants