Are you using Chrome or a Chromium-based browser to access Squert? Have you tried looking in Sguil?
Please provide the output of "sudo sostat-redacted" and attach it as a text file.
Thanks,
Wes
Hey there
I followed the instructions found on the wiki and tried to google as much as I could, however I'm running into a huge problem. It seems that for some reason squert is not loading alerts. I went and I did a tcpdump for my interface and it turns out the only traffic it is getting is the traffic intended for Security Onion. It's a VM on an ESXI server. I have all virtual switches set to promiscuous and I have the netflow setup on the switch to send the traffic to Secutity Onion. All services are up according to "service nsm status" and ufw says that all default firewall rules are up. Am I missing anything? Can provide additional information if necessary.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
The only other thing I could think of is the NIC not being in promiscuous mode.