Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 521 forks source link

sostat: don't show pf_ring output if af_packet in use #1623

Closed weslambert closed 4 years ago

weslambert commented 5 years ago

In addition, show percentage of capture.kernel_drops vs. capture.kernel_packets in stats.log.

dougburks commented 4 years ago

Looks like drops vs packets percentage has already been implemented at https://github.com/Security-Onion-Solutions/security-onion/issues/1663.

dougburks commented 4 years ago

The following package is now available at ppa:securityonion/test:

securityonion-sostat - 20120722-0ubuntu0securityonion144

Please test as follows:

Thanks in advance for your time and effort!

weslambert commented 4 years ago

Confirmed working as expected. 👍

dougburks commented 4 years ago

Thanks @weslambert !

dougburks commented 4 years ago

Published: https://blog.securityonion.net/2020/04/securityonion-sostat-20120722.html