I have a problem with one of my sensors.
The problem is only on 1 monitor interface, for few days now, the sensor didn't update some log files, in my case dns-json.log and dns.log
avril 20 09:09 stats.log
avril 20 09:09 alert-json.log
avril 20 08:56 dns-json.log
avril 20 08:56 dns.log
If i run command : nsm_sensor_ps-restart
DNS log files are correctly populated but after 1 min there is no new data.
Obviously, if i run tcpdump on this interface i can see that DNS traffic is coming well...
I have check logs file for barnyard and suricata but nothing found, I tried to reboot the server but same issue.
For second interface all files are populated correctly...
Any idea to investigate ?
Regards,
Stephane
Stephane,
Please provide the output of sostat-redacted, attaching as a plain text file, or using a service like Pastebin.com
Thanks,
Wes
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/ttchNgEOTgs/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.