Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
[X] duplicated the issue on a fresh installation of the latest version
information about your system and how you installed Security Onion
Oracle Linux Server release 9.3Linux version 5.15.0-101.103.2.1.el9uek.x86_64 (mockbuild@host-100-100-224-7) (gcc (GCC) 11.3.1 20220421 (Red Hat 11.3.1-2.1.0.2), GNU ld version 2.35.2-24.0.1.el9) #2 SMP Tue May 2 01:10:45 PDT 2023
Security Onion Version:2.4.30
relevant log files
the import is trying to use logs-system.security-1.34.0 based on the elastic-agent policy when Elastic and Logstash are configured with logs-system.security-1.43.0
This applies to the following pipelines, based on the preset agent policy that was not updated with the 2.4 release.
information about your system and how you installed Security Onion
Oracle Linux Server release 9.3
Linux version 5.15.0-101.103.2.1.el9uek.x86_64 (mockbuild@host-100-100-224-7) (gcc (GCC) 11.3.1 20220421 (Red Hat 11.3.1-2.1.0.2), GNU ld version 2.35.2-24.0.1.el9) #2 SMP Tue May 2 01:10:45 PDT 2023
Security Onion Version:
2.4.30
relevant log files
the import is trying to use
logs-system.security-1.34.0
based on the elastic-agent policy when Elastic and Logstash are configured withlogs-system.security-1.43.0
This applies to the following pipelines, based on the preset agent policy that was not updated with the 2.4 release.
logs-system.system-1.34.0
->logs-system.system-1.43.0
logs-system.security-1.34.0
->logs-system.security-1.43.0
logs-system.application-1.34.0
->logs-system.application-1.43.0
logs-windows.sysmon_operational-1.24.0
->logs-windows.sysmon_operational-1.38.0
logs-windows.powershell_operational-1.24.0
->logs-windows.powershell_operational-1.38.0
Affected file:
salt/elasticfleet/files/integrations/grid-nodes_general/import-evtx-logs.json
Logstash ingest pipeline versions:
Logstash error when attempting to import
evtx
data:include reproduction steps