Syslog shows *missing #9571
Replies: 4 comments 15 replies
-
That Sankey diagram seems to indicate that you've got a whole lot of data coming in via syslog, but it's not being recognized so it doesn't have an event.category assigned to it (hence the *Missing). What are you ingesting via syslog in Security Onion? If you need to see what's coming in, try this query in Hunt: event.dataset: "syslog" | groupby source.ip |
Beta Was this translation helpful? Give feedback.
-
I will try that query and get back to you but I have pfsense sending Syslog to Security Onion. I have changed what is being sent and will see if the logs change. |
Beta Was this translation helpful? Give feedback.
-
Standard port and the CEF is working fine with filebeat now. Sent from my iPhoneOn Feb 20, 2023, at 1:26 PM, An0th3rguy ***@***.***> wrote:
Have you managed to map it to the existing syslog port 514 or you did configuration for a new port (9003). Thanks
—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you authored the thread.Message ID: ***@***.***>
|
Beta Was this translation helpful? Give feedback.
-
Any help with configuration would be appreciated. Still unable to get it
work. Thank you
…On Mon, Feb 20, 2023 at 8:38 PM Skullack ***@***.***> wrote:
Standard port and the CEF is working fine with filebeat now. Sent from my
iPhoneOn Feb 20, 2023, at 1:26 PM, An0th3rguy ***@***.***> wrote:
Have you managed to map it to the existing syslog port 514 or you did
configuration for a new port (9003). Thanks
—Reply to this email directly, view it on GitHub, or unsubscribe.You are
receiving this because you authored the thread.Message ID: ***@***.***>
—
Reply to this email directly, view it on GitHub
<#9571 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AIIB6BVEHCRQYHT4OVHILNLWYPB2XANCNFSM6AAAAAATZ66RTI>
.
You are receiving this because you commented.Message ID:
<Security-Onion-Solutions/securityonion/repo-discussions/9571/comments/5056822
@github.com>
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hey community.
I am getting over 9 million *missing on syslog in 24 hours on the alerts tab and not sure where this is coming from or even how to stop getting that.
Can anyone point me in a direction on what to look for that is causing this and possible fix.
Beta Was this translation helpful? Give feedback.
All reactions