If you click on "SID" or the signature name for Suricata alerts, the Moloch trace appears to be empty. I can't find any in the handful of malware I ran through it that populated Moloch so that the SID or signature finds it. I see data in Moloch when I click on link for an IP address from the Suricata tab, so it is being populated, but not for the SID or signature links.
If you click on "SID" or the signature name for Suricata alerts, the Moloch trace appears to be empty. I can't find any in the handful of malware I ran through it that populated Moloch so that the SID or signature finds it. I see data in Moloch when I click on link for an IP address from the Suricata tab, so it is being populated, but not for the SID or signature links.