Snort mailing list archives
Re: Ignoring Backups - TCP Stateful?
From: Doug Burks <doug.burks () gmail com>
Date: Fri, 5 Dec 2014 15:22:15 -0500
Replies inline. On Fri, Dec 5, 2014 at 2:40 PM, Colony.Three <Colony.Three () protonmail ch> wrote:
I am at a loss. I don't even know whether SecurityOnion is capturing packets or not.
"sudo sostat" can help you with this. If you need help interpreting the sostat output, please run the following command: sudo sostat-redacted There will be a lot of output, so you may need to increase your terminal's scroll buffer OR redirect the output of the command to a file: sudo sostat-redacted > sostat-redacted.txt 2>&1 sostat-redacted will automatically redact any IPv4/IPv6/MAC addresses, but there may be additional sensitive info that you still need to redact manually. Attach the output to your email in plain text format (.txt) OR use a service like http://pastebin.com.
Either my rules modifications were perfect, or nothing's being captured. I infer that ELSA would be the best way to see recent actual basic packet traffic, but Firefox will not let me in. "localhost:3154 uses an invalid security certificate"
Have you tried to configure Firefox to accept the self-signed certificate?
... much less do I know how to determine whether my backups are excluded from packet capture. I can't do backups until I'm sure the packets are -not- being captured. It's been almost a week now since my last backups.
Have you tried my previous BPF suggestion? Would it help to simplify the BPF by removing "src"? So something like this? not(tcp host 192.168.1.4 and tcp port 8027) You could test your BPF using tcpdump in real time while running a test backup.
Can anyone advise? I'm not particular. -------- Original Message -------- Subject: Re: [Snort-users] Ignoring Backups - TCP Stateful? Time (GMT): Dec 04 2014 15:21:24 From: Colony.Three () protonmail ch To: doug.burks () gmail com CC: snort-users () lists sourceforge netIn my case, the backups server calls rsync to backup the LAN machines (concurrently). The rsync daemon is not used anywhere.Can you provide more information about what the actual traffic flowslook like? Perhaps some example traffic flows?Would it help to simplify the BPF by removing "src"? So something like this?not(tcp host 192.168.1.4 and tcp port 8027)Not sure the best way to get this traffic? Part of the problem is I don't want to fill up my SO disk with backup traffic, but maybe I can run a ptial backup for a short time.
-- Doug Burks Need Security Onion Training or Commercial Support? http://securityonionsolutions.com Last day to register for 3-Day Training Class in Augusta GA is 12/11! ------------------------------------------------------------------------------ Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get technology previously reserved for billion-dollar corporations, FREE http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Ignoring Backups - TCP Stateful? colony.three (Dec 03)
- Re: Ignoring Backups - TCP Stateful? Doug Burks (Dec 03)
- <Possible follow-ups>
- Re: Ignoring Backups - TCP Stateful? Colony.Three (Dec 03)
- Re: Ignoring Backups - TCP Stateful? Doug Burks (Dec 04)
- Re: Ignoring Backups - TCP Stateful? Colony.Three (Dec 04)
- Re: Ignoring Backups - TCP Stateful? Colony.Three (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Doug Burks (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Colony.Three (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Doug Burks (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Colony.Three (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Doug Burks (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Colony.Three (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Doug Burks (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Colony.Three (Dec 05)
- Re: Ignoring Backups - TCP Stateful? Doug Burks (Dec 05)