Thanks for using Security Onion!
I haven't had any other reports of this issue. Some questions for you:
- Your directory listing shows dailylogs back to 2011-04-10. Have you
had to do this manually for every single one of those days? Or was it
working at some point in time?
- Have you made any changes to the system since installation? For
example, any permissions changes, or perhaps symlinking /nsm to a
different mount point?
- Are there any errors in /var/log/ that would correspond to the "nsm
--sensor --restart" cronjob?
Thanks,
--
Doug Burks, GSE, CISSP
President, Greater Augusta ISSA
http://augusta.issa.org
http://securityonion.blogspot.com
/etc/cron.d/sensor-newday should run every day at midnight and log to
/var/log/nsm/sensor-newday.log. Is there anything in this log file?
Can you include it in your reply?
Based on the separate issue that you created
(http://code.google.com/p/security-onion/issues/detail?id=100), is it
possible that you weren't able to log into the server when you ran
Setup on the sensor? If that were the case, that would explain if you
had to manually create a directory for the sensor in
/nsm/sensor_data/securityonion/rules/.
Thanks,
--
Doug Burks, GSE, CISSP
President, Greater Augusta ISSA
http://augusta.issa.org
http://securityonion.blogspot.com
I closed your issue in the Issue Tracker since it was due to the
non-standard SSH port. The mailing list is more conducive to
discussion, so it's probably better to ask about an issue on the
mailing list first and then add it to the Issue Tracker once we've
confirmed it.
Unfortunately, I'm not sure why your dailylogs aren't being rotated
properly. I've verified that my servers and sensors are rotating
dailylogs correctly. At this point, I would recommend the following:
-Download the ISO from:
http://sourceforge.net/projects/security-onion/files/
-Make sure that you verify the checksum! We've had strange issues in
the past that turned out to be due to a corrupt ISO download.
-Install your server and sensor per the following:
http://securityonion.blogspot.com/2011/04/security-onion-20110321-distributed.html
-Keep the default SSH port and make sure that the sensor correctly
logs into the server during Setup.
-Make no other changes to the system and check the next day for proper
rotation of dailylogs.
Please let us know how it goes!
Thanks,
--
Doug Burks, GSE, CISSP
President, Greater Augusta ISSA
http://augusta.issa.org
http://securityonion.blogspot.com
It sounds like you've pinpointed it. Thanks for your persistence so
far in tracking this down!
Going back through the Issue Tracker, I found an older issue that was
probably related, so I copied your description to it:
http://code.google.com/p/security-onion/issues/detail?id=76
Please let us know if your change works.
Thanks,
--
Doug Burks, GSE, CISSP
President, Greater Augusta ISSA
http://augusta.issa.org
http://securityonion.blogspot.com
Thanks,
--
Doug Burks, GSE, CISSP
President, Greater Augusta ISSA
http://augusta.issa.org
http://securityonion.blogspot.com
Thanks for your feedback. You basically have two options:
1. (RECOMMENDED) Set the server OS and all sensor OSs to GMT. As you
saw in the Sguil mailing list thread, this is recommended by Bamm
Visscher himself. This is assumed in Security Onion and that's why
the sensors are set that way.
2. If you really want to use local time instead of GMT, then the
server OS and all sensor OSs will need to be configured for the same
time zone. You will need to manually set SENSOR_UTC to "N" in all
sensor.conf files.
I hope to document this on the blog and hopefully an official manual
at some point in the future. Anybody interested in contributing to
the Security Onion project with some technical writing? :)
Thanks,
--
Doug Burks, GSE, CISSP
President, Greater Augusta ISSA
http://augusta.issa.org
http://securityonion.blogspot.com