Open tenee opened 3 years ago
Events should be loaded from ES. Are you sure that events are forwarded to ES and properly indexed?
How can I check that events are forwarded to ES and properly indexed? I installed ES following the installation of Suricata hoping that scirius would be able to represent the events but I don't understand why the events are not processed.
Is this still an issue? If you check in Kibana , do you have events populated?
Hi everyone, I have a problem configuring Scirius with Suricata. launching the commands to start both, from termimal everything seems to work correctly and also the logs are written correctly. it seems that scirius is unable to intercept events
Suricata run command
sudo suricata -c /etc/suricata/suricata.yaml -i eth0
Scirius run command
python manage.py runserver < ip:port >
This is the configuration of suricata on scirius
The rules have been enabled in the graphical interface and during the suricata configuration, but scirius does not seem to detect any events:
1)![image](https://user-images.githubusercontent.com/70138364/91031040-5180b780-e600-11ea-9ef5-6d611f0a5470.png)
2)![image](https://user-images.githubusercontent.com/70138364/91031100-65c4b480-e600-11ea-96eb-6710ec569579.png)
also scirius does not load the menu on the right well:
The version of Suricata is 5.0.3 and the version of Scirius is 3.4.0
Could you give me some solution on how to solve the problem?
Thanks in advance