Suricata seeing connection but not decoding #14018
-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU10 RAM32 Storage for /314 Storage for /nsm747 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailSuricata is getting all connection logs from my network to destination port 80 but doesn't seem to be able to decode that into http logs. I've confirmed seen below that the packets are reaching bond0 with their data In Hunt I can see the net conns on port 80 to example.com just fine But looking in http logs returns nothing Not exactly sure what I'm missing here, even turned off checksum validation for Suricata in case there was something funky on the wire there but that had no effect. Notably it appears like other protocol decoding is having issues as well, as SSL only has data for a few internal services and not all the external sites it should see. But simpler protocols like DHCP and DNS appear to be fine. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
Looking at your tcpdump screenshot, it appears that you are seeing outbound traffic but not return traffic. Please check your tap or span port to make sure you are seeing the entire TCP stream. |
Beta Was this translation helpful? Give feedback.
Does your traffic have VLAN tags? What is the output of the following?