telekom-security / tpotce

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
GNU General Public License v3.0
6.6k stars 1.06k forks source link

Dashboard - Kibana #1492

Closed shaw2020 closed 5 months ago

shaw2020 commented 5 months ago

Before you post your issue make sure it has not been answered yet and provide basic support information if you come to the conclusion it is a new issue.




⚠️ Basic support information (commands are expected to run as root)

shaw2020 commented 5 months ago

Good morning, recently I installed the "HIVE" honeypot on my server with Debian 11.8. However, when I access the Kibana dashboard under the Suricata dashboard to view attack actions, I receive the following message in several fields:

suricata event bar: The field "tls.ja3.hash.keyword" associated with this object no longer exists in the data view. Please use another field.

suricata events: The field "tls.ja3.hash.keyword" associated with this object no longer exists in the data view. Please use another field.

All fields display a message like this. I need to know what I can do to resolve this issue. error dashboard kibana error dashboard kibana 2

t3chn0m4g3 commented 5 months ago

Are there any Suricata logs, i.e. eve.json, in the /data folder? If not the Suricata dashboard is empty as there are no logs.

shaw2020 commented 5 months ago

So the dashboard is only like this because no log has arrived yet?