Project

General

Profile

Actions

Support #3704

closed
LY CT

Suricata alerts don't show up in Prelude-SIEM

Support #3704: Suricata alerts don't show up in Prelude-SIEM

Added by Little Yu almost 6 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
Normal
Affected Versions:
Label:

Description

Hello,

I've been trying for the past week to configure both Suricata and Prelude but it seems like Suricata alerts don't show up in Prelude even though I've added it to prelude and the alerts show up in fast.log normally.

Can you help me ?

Thanks

VJ Updated by Victor Julien almost 6 years ago Actions #1

  • Tracker changed from Bug to Support
  • Assignee set to Community Ticket
  • Priority changed from Immediate to Normal

AH Updated by Andreas Herz almost 6 years ago Actions #2

Can you share more details about your setup/configuration?

TA Updated by Thomas Andrejak almost 6 years ago Actions #3

Hello

We need these information:
  • Linux Distribution
  • Version of Prelude ? With packets ?
  • Version of suricata ? With packets ?
  • Triggered rules that should shows up in Prelude ?

You can download a prepared iso with Prelude and Suricata included here: https://www.prelude-siem.org/pkg/prelude_va/prelude-oss-v5.1.0.iso

Regards

LY Updated by Little Yu almost 6 years ago Actions #4

Andreas Herz wrote in #note-2:

Can you share more details about your setup/configuration?

Hi, thanks a lot for your answer but I've finally resolved it. I don't know what the problem was as all I did was deleted everything and install it again with the same setup/config.

Thanks again!

VJ Updated by Victor Julien almost 6 years ago Actions #5

  • Status changed from New to Closed
Actions

Also available in: PDF Atom