We upgraded our Security Onion nodes today. We really had no choice. I was surprised to see the so-elastalert container normally running on the manager being unable to start. I happened to glance at the release notes, and tried the commands suggested there. Suffice it to say, I got nowhere.

Read More → Security Onion 2.4.40 and so-elastalert running on the manager

If Zeek on your forward node (sensor) keeps restarting and its detailed status never changes from “health: starting,” to simply “healthy,” have a look at zeek.config.networks.HOME_NET in the Grid Configuration.

Read More → Security Onion 2.4.30, Zeek 6.0.2, and single IPv4 address in $HOME_NET

The Dell PERC H730 Adapter, a 12 Gbit/s SAS controller, in a Dell PowerEdge R330 server, complained about “L2/L3 Cache error was detected on the RAID controller.” This server was using BIOS 2.16.0 in UEFI mode and the SAS controller ran firmware version 25.5.0.0018. Entering X to accept the current predicament went nowhere and nothing else […]

Read More → Dell PowerEdge R330, Dell PERC H730 Adapter, L2/L3 Cache error was detected on the RAID controller