Suppressing Stream5 preprocessor - not working

64 views
Skip to first unread message

Gordon Wallum

unread,
Sep 3, 2019, 2:23:37 PM9/3/19
to security-onion
Hello,

Our Security Onion deployment is being flooded with Stream5 preprocessor alert 129 || 20 || stream5: TCP session without 3-way handshake. I have tried to disable/suppress with no success
  • I have tried using threshold.conf and disabledsid.conf

Below is my threshold.conf configuration
  • suppress gen_id 129, sig_id 20

Sostat-redacted is attached. Any help would be appreciated!

Gordon




sostat-redacted.txt

Tom Wood

unread,
Sep 3, 2019, 2:39:25 PM9/3/19
to securit...@googlegroups.com
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/4f21c90a-6097-4c87-b7ab-19ae0f1253d2%40googlegroups.com.

Steven J

unread,
Sep 4, 2019, 12:41:18 AM9/4/19
to securit...@googlegroups.com
Hi Gordon,

For other gen_id:129 rules, I am using
suppress gen_id 129, sig_id 15, track by_src, ip 172.16.1.0/16


At the same time, where these events have been flooding most installations, there could be a backlog of events that have not been processed yet.  Even though you have suppressed future alerts, the backlog is still likely being pushed through.

Gordon Wallum

unread,
Sep 4, 2019, 1:30:22 PM9/4/19
to securit...@googlegroups.com
Thanks Steven,

The resolution was to clear the back log. Was flooded with events



Steven J

unread,
Sep 4, 2019, 2:56:58 PM9/4/19
to securit...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages