We use Paul Halliday's Bro_agent in our environment to forward Bro notices and intel matches to the sguil DB for analysts to review in Squert. Since the recent Squert update, these events no longer contain any data when viewed in Squert. The events show up, but just say they contain no data whereas they used to contain the information logged in bro's notice.log. When we review the Bro alerts with the sguil client relevant alert data is available, so it looks like the bro_agent is still successful in transmitting the alert data into the sguil DB. My guess is that the recent Squert update broke the way Squert queries this Bro data.
I've attached an sostat-redacted from our master server, as well as screenshots of Bro notices from both Squert and Sguil. I used capture-loss alerts for the sake of not providing information in our environment - you'll notice that the squert alert doesn't contain any data, but the alert in sguil show's the percentage of capture loss reported. This is similar across all our Bro notices.
I know this is is not officially supported functionality for Security Onion, but the ability to review Bro data in Squert has been incredibly useful for us to date. I'm curious if anyone else on the mailing list has encountered this problem, or has ideas on how to fix it :)
Thanks!
James Gordon
Doug,
I can confirm that this fixed the issue. Thanks much for your assistance with this!
James Gordon