-
Notifications
You must be signed in to change notification settings - Fork 12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update to Bro 2.5.2 and raspbian 201711-29 #3
Comments
you may try my pull request (which hasn't been accepted yet): |
Thank you gebhard73. I found your pull yesterday and I am trying to install
following it better than original. If I found some error or mistake I will
feedback you.
I have started again from an empty SD card.
Thanks for your kindly help.
Regards,
2017-12-28 16:20 GMT+01:00 gebhard73 <[email protected]>:
… you may try my pull request (which hasn't been accepted yet):
#2 <#2>
and make sure to use my repo for download of the code:
https://github.com/gebhard73/foxhound-nsm
git clone https://github.com/gebhard73/foxhound-nsm.git
pls also note that an update will have side effects (because the
installation file isn't yet suitable for updates but only for clean
installs); I'd suggest investing in a new SD card...
Any feedback is appreciated.
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#3 (comment)>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/AhOCr4s-4lLnNLRu7CpIvbPc1r7JcOMPks5tE7GsgaJpZM4ROQ8l>
.
--
Antonio Ramírez
|
Hi @gebhard73 , I've found an error during the criticalstack configuration. Is it normal? |
Hi, the error should only be present during installation because afterwards the mentioned configuration should be automatically written with broctl by the install script. |
Hi, any update, has it worked for you? Thanks. |
Hello,
I have been so busy in job and with exams. Work and study is a little bit
hard. This weekend I will test to execute de cron jobs manually and see
what happend.
For my master final job I have choose to use the foxhound deployment as a
base for an IDS domestic black box and deploy a web user interface. If you
feel confortable I will have for sure a lot of configurations questions for
bro and the critical stack integration so If you feel confortable maybe you
can help me.
I have the first question, ¿how can I disable the mail notifications?
Thanks and regards,
2017-12-30 20:00 GMT+01:00 gebhard73 <[email protected]>:
… Hi, any update, has it worked for you? Thanks.
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#3 (comment)>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/AhOCr-j7I2p0gC69Ug7szJKNWObeio3-ks5tFohMgaJpZM4ROQ8l>
.
--
Antonio Ramírez
|
I may suggest that you read the bro documentation to get familiar with it, e.g. https://www.bro.org/documentation/index.html Hints:
If foxhound works in general, please close the issue. If not, have a look at my pull requests and the issue I've opened. |
thanks for your kindly help. Now i have things already to work but the geoip is not working. have you done something special for it? Thanks |
How do you access geoip / how do you recognize the error? |
I was wrong. I found the country information in the resp_cc field of connections.log. The only point is that critical stack log is not generated and i do not know how try to fix. critical stack is already istalled and in master i have the signatures downloaded. in broctl scripts loaded is already these ones... Do you find this issue too? Thanks |
Glad you found it. Regarding critical stack log: can you please provide more details where you have loooked? Where have you missed the logs? Thanks! |
yes, I looked the following files to check if everything is ok and it seems to be.
Also with the broctl I check for the loaded scripts
but in the bro var log folder doesn't appear the intel.log
This is the output of the broctl deploy too
and the update script.
Am I doing something wrong related to the critical stack? Thanks for your kindly help! |
thanks for the details, I'll have a look over the weekend |
OK, it seems that critical stack package for Pi isn't up to date anymore ... The string Workaround:
Then run a Double-check: the seen and do_notice stuff is loaded, see Please let me know if this helped. |
yeah!! it works!!! I will mention you (if you want) in my academic report so please, write me a private message or email. |
just last question, is there any way to add geoip location in all logs not only in the connections? |
hmmm - I don't think so, but you may add it using scripts: Perhaps use geo information one step later, e.g. in ELK? / Splunk? |
I am having some errors installing Bro 2.5.2. I am working to try to update to the latest version of tools. Could you help me?
The text was updated successfully, but these errors were encountered: