Replies: 3 comments
-
Please post the error so that we can troubleshoot further. |
Beta Was this translation helpful? Give feedback.
0 replies
-
This is the error popup.
***@***.***
From: Josh Brower ***@***.***>
Sent: Friday, January 3, 2025 9:25 AM
To: Security-Onion-Solutions/securityonion ***@***.***>
Cc: Eric Vanderveer ***@***.***>; Author ***@***.***>
Subject: Re: [Security-Onion-Solutions/securityonion] Disable rules from terminal (Discussion #14055)
I can't disable them from the web interface since I receive an error window at the top of the page.
Please post the error so that we can troubleshoot further.
—
Reply to this email directly, view it on GitHub<#14055 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/ATLMUC5H4OUW4PAP2JAQW332I2MSXAVCNFSM6AAAAABUL7U4SCVHI2DSMVQWIX3LMV43URDJONRXK43TNFXW4Q3PNVWWK3TUHMYTCNZSGYYTSOA>.
You are receiving this because you authored the thread.Message ID: ***@***.******@***.***>>
|
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Version
2.4.110
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Meets minimum requirements
CPU
8
RAM
32
Storage for /
200G
Storage for /nsm
320G
Network Traffic Collection
span port
Network Traffic Speeds
Less than 1Gbps
Status
No, one or more services are failed (please provide detail below)
Salt Status
No, there are no failures
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
I have turned on all the alert rules for my SO and now I can't get elastalert to start, it shows it is missing. I can't disable them from the web interface since I receive an error window at the top of the page. When ever I reboot the server is horribly slow and I really believe it's because of the alerts. Once it stops being slow, usually a day, I can start moving around the manager in a terminal. Where can I disable these rules? I have gone in the the so/rules directory and have removed the rules from there but they keep coming back.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions