This started around 7/27 which is around the time that my log retention fell to 1 day. I found the problem and corrected that and the retention time is now rising daily.
The events that return go back to 7/27.
Please provide the output of sostat-redacted, attaching as a plain text file, or using a service like Pastebin.com
Thanks,
Wes
Thanks Wes.
Were you able to find anything?
1502605353 1502604526 1502603693 1502602864 1502602055 1502601216 1502600406
ERROR: Unable to find the matching pcap file based on the time.
The requested event time is: 1502582646
Would you be able to provide an updated copy of output for sostat-redacted?
Thanks,
Wes
Are you receiving these errors for specific types of events/traffic only?
Thanks,
Wes
You know I just remembered something. I got sick and tired of doing the UTC translation that I set the system time to CTD or /American/Chicago with no effect but I didn't set it back to UTC until just now. Do you think that had anything to do with it?
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.