SURICATA TCP duplicated option after SURICATA upgrade

245 views
Skip to first unread message

namobud...@gmail.com

unread,
Jul 28, 2016, 10:54:36 AM7/28/16
to security-onion
Hello Group,

I'm getting a ton of "SURICATA TCP duplicated option" alerts in SQUIL after doing an sudo soup to the new SURICATA upgrade this morning.

I'm going to tune them out, but was wondering if it just means exactly what it says that's a duplicate alert as I do I have two NICS pulling in tap traffic.

Thanks,

Wes

unread,
Jul 28, 2016, 12:44:30 PM7/28/16
to security-onion

I'm not quite sure. You may be able to find more information by posting here (OISF Users mailing list):

https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users

Thanks,
Wes

namobud...@gmail.com

unread,
Jul 28, 2016, 4:27:17 PM7/28/16
to security-onion

I just disabled the alert I wasn't able to find out anything more.

Reply all
Reply to author
Forward
0 new messages