-
Hi all, We have a standalone server that we upgraded from 140 to 160 today, but I noticed that we haven't received any suricata alerts since 8/30 (2 days ago). so-status shows all "Ok", nothing changed except for todays upgrade, and docker logs so-suricata zeek is working fine, and I see traffic on bond0 Thanks |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
Have you tried restarting the docker container?
Have you tried
Did you make any custom changes to Suricata configuration in /opt/so/saltstack/default/ instead of /opt/so/saltstack/local/ this could have caused you to lose your custom changes including your $HOMENET variable that may explain Suricata not triggering alerts |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
@mbaki