-
Version2.4.211 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /256 Storage for /nsm512 Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailWe set pcapengine to TRANSISTION ahead of upgrading to SOv3 (still on SOv2.4.211), but PCAP is no longer being written to disk. PCAP via Steno was functional before this switch. No errors in logs, but /nsm/suricata/suripcap directories are all showing zero bytes and PCAP searching from SOC returns no results. BPF exists for Suricata and PCAP with no conflicts that would account. Our understanding is the BPF is applied s/t Steno BFP filters first, then PCAP BPF for the balance. Grid shows 2d of PCAP retention which matches with when we switched to TRANSITION, but again nothing on disk. Forward nodes all reflect TRANSITION and BPF is rendering as expected. Any ideas what could be going on here? Thanks! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
|
Reviewing /opt/so/conf/suricata/suricata.yaml on the forward nodes, seeing the below BPF config... thinking this is related and working to remove via the manager, which interestingly enough has a completely different BPF configured for PCAP. |
Beta Was this translation helpful? Give feedback.
Did you apply the hotfix?