SGUIL the events reappear the next day

126 views
Skip to first unread message

4evernoob

unread,
Aug 9, 2017, 3:51:35 PM8/9/17
to security-onion

In SGUIL the events reappear the next day after I F8 them from the log. Also 90 percent of the time when I F8 enties I get an error message:
ERROR: Some events may not have been updated. Events may be missing from the DB....

This started around 7/27 which is around the time that my log retention fell to 1 day. I found the problem and corrected that and the retention time is now rising daily.

The events that return go back to 7/27.

Wes

unread,
Aug 9, 2017, 8:54:46 PM8/9/17
to security-onion

Please provide the output of sostat-redacted, attaching as a plain text file, or using a service like Pastebin.com

Thanks,
Wes

4evernoob

unread,
Aug 10, 2017, 2:28:11 PM8/10/17
to security-onion

Yesterday after clearing events in Squil they were still in Squert so I cleared them there and today they seem to be gone but after clearing events again today there were still a small percentage of today's events still showing in Squert.

Thanks Wes.

sostat-redacted.txt

4evernoob

unread,
Aug 14, 2017, 11:04:18 AM8/14/17
to security-onion
On Thursday, August 10, 2017 at 1:28:11 PM UTC-5, 4evernoob wrote:
> Yesterday after clearing events in Squil they were still in Squert so I cleared them there and today they seem to be gone but after clearing events again today there were still a small percentage of today's events still showing in Squert.
>
> Thanks Wes.

Were you able to find anything?

4evernoob

unread,
Aug 14, 2017, 11:35:38 AM8/14/17
to security-onion
I have gotten a couple of these today when attempting to get a transcript on the event out of SGUIL. The events are only one or two days old so they should be there.


1502605353 1502604526 1502603693 1502602864 1502602055 1502601216 1502600406
ERROR: Unable to find the matching pcap file based on the time.
The requested event time is: 1502582646

Wes

unread,
Aug 14, 2017, 2:41:08 PM8/14/17
to security-onion

Would you be able to provide an updated copy of output for sostat-redacted?

Thanks,
Wes

4evernoob

unread,
Aug 14, 2017, 5:19:53 PM8/14/17
to security-onion

Ok here you go.
sostat-redacted.txt

Wes

unread,
Aug 15, 2017, 8:14:16 AM8/15/17
to security-onion
On Monday, August 14, 2017 at 5:19:53 PM UTC-4, 4evernoob wrote:
> Ok here you go.

Are you receiving these errors for specific types of events/traffic only?

Thanks,
Wes

4evernoob

unread,
Aug 15, 2017, 2:38:27 PM8/15/17
to security-onion

No it seems to be that I can F8 them from SGUIL and I can close SGUIL and reopen it and they wont be there but they come back the next day and the only way to get rid of them is F8 in SQUERT so the last time I deleted with SQUERT was the 11th so have everything since the 11th in SQUERT even though I have F8'd them repeatedly in SQUIL.
Another part of this is there are some entries that I can not pull up a transcript on, they error with something like or similiar to...

ERROR: Unable to find the matching pcap file based on the time.

You know I just remembered something. I got sick and tired of doing the UTC translation that I set the system time to CTD or /American/Chicago with no effect but I didn't set it back to UTC until just now. Do you think that had anything to do with it?


Wes Lambert

unread,
Aug 16, 2017, 6:44:30 AM8/16/17
to securit...@googlegroups.com
You''ll definitely want to ensure your system time is set to UTC, as otherwise, it could lead to unpredictable results.


Thanks,
Wes



--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.

4evernoob

unread,
Aug 16, 2017, 4:10:58 PM8/16/17
to security-onion
Yes that fixed it. Everything seems normal so far today.
Thanks for your help Wes.


Reply all
Reply to author
Forward
0 new messages