New events not showing in Evebox now #223
Replies: 4 comments 2 replies
-
How and where are you getting events into the database? Can you add |
Beta Was this translation helpful? Give feedback.
-
I'm not sure how I'm getting events into the database - I'm brand new to Suricata/Evebox...is there something I can check?
I'm not using Elasticsearch/Kibana/ELK or anything like that. I started Evebox and added the '-vvv' as you described, so the following was the actual command:
And this was the output after a few seconds:
|
Beta Was this translation helpful? Give feedback.
-
No new events, no. I can see all kinds and types of events from '3 days ago', but nothing newer. Here's a screenshot (which I have Event Type set to 'All'): |
Beta Was this translation helpful? Give feedback.
-
OK, this is really strange, but I just got to work this morning, and I hit my browser's refresh button (which I tried many times yesterday), and now Evebox is showing current events/alerts! That is so weird! Any idea why this would happen? And thank you for all your help, and thank you for creating this awesome project. |
Beta Was this translation helpful? Give feedback.
-
I had Evebox running great last week (I recently set up a test Suricata/Evebox machine).
However, today it's not showing new events. Last week I was monitoring the Alert-Events page from a browser on my own workstation over the network and would just hit the 'Refresh' button every once in a while to keep an eye on things and it would properly Refresh and show me things from a 'few seconds ago'. However, when I booted my workstation this morning, and opened a tab to look at Evebox, it's not showing "current" events/alerts - the newest thing that it's showing is from 3 days ago (Friday). I've tried clicking all over the place on the Evebox page, but can't get it to show any events newer than 3 days ago. I know events are coming in because I can 'tail' the 'eve.json' and the 'fast.log' file and I see stuff constantly coming in.
It must be something that I'm doing wrong, or some setting somewhere, but can't figure it out.
Beta Was this translation helpful? Give feedback.
All reactions