-
Notifications
You must be signed in to change notification settings - Fork 287
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
No alert in scirius #113
Comments
Is that a recent upgrade? |
Yes it's similar configuration. |
Any errors in the |
Nope.. [2018-04-20T10:31:31,227][INFO ][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/modules/netflow/configuration"} |
What about if you restart elasticsearch and logstash? |
The restart doesn't do anything. ii logstash 1:5.6.9-1 all An extensible logging pipeline |
When you say no alert - do you mean in Scirius or in Kibana SN ALERTS dashboards? Both have no alerts or just Scirius ? Can you also please paste the last 10 lines of your |
Looking at the output you pasted above - looks good, no errs on the logstash side . |
Both have no alerts. |
Since when? For what period is that? |
I haven't received any alert since the install. |
It maybe so that there isnt any alerts in that period of time. |
No error in suricata.log. |
On 20 Apr 2018, at 21:17, sbeaulieu-vu ***@***.***> wrote:
No error in suricata.log.
It doesn't find anything when I do a internal nessus scan.
That's not normal.
Maybe you need to adjust the HOME/EXTERNAL net variables in the Suricata config depending on where you are doing the scan.
… —
You are receiving this because you commented.
Reply to this email directly, view it on GitHub, or mute the thread.
|
I have the same issue. |
Did you adjust the HOME/EXT net variables in |
I didn't found Home/Ext in /etc/suricata/selks4-addin.yaml the only HOME/EXT settings I have is in /etc/suricata/suricata.yaml HOME_NET 172.16.0.0/12 |
apologies - you are correct - that is the file holding the Net variables. |
Great, I've missed that point. Thank you. |
After installation and setting, I get all the traffic, eve.json is growing but there is no alert on the dashboard.
I looked into git issue to see what could be my problem but nothing work.
I increased the memory of elasticsearch and logstash just so you know.
The text was updated successfully, but these errors were encountered: