Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
suricata reporting Scirius, Evebox or Kibana
« previous
next »
Print
Pages: [
1
]
Author
Topic: suricata reporting Scirius, Evebox or Kibana (Read 5485 times)
lshantz
Full Member
Posts: 109
Karma: 3
suricata reporting Scirius, Evebox or Kibana
«
on:
October 27, 2019, 11:19:18 pm »
I'm fairly new to Opnsense and Suricata. I came from Pfsense and Snort where reporting was built in.
Either I'm totally missing something, or there is no built in reporting for Suricata in Opnsense. I've digging around and found 3 utilities listed above that apparently will do that for me. I do not see any built in support for any of this. So the question is, what am I missing? If I'm not missing something, then can we get a request in for package support for one of the above?
Is it at all possible for me to manually install Scirius into a web server on the box? I can see a HUGE problem trying implement it on an external server and trying to integrate it all.
I activated IPS and within minutes it blocked a game for a user and because all I can see is raw logs I can't find the rule to clear. In Snort/Pfsense, I could clear a rule within seconds.
Any guidance appreciated.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #1 on:
October 28, 2019, 07:08:33 am »
Isnt in the alert tab the message from the rule which you can search for in rules tab?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
lshantz
Full Member
Posts: 109
Karma: 3
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #2 on:
October 28, 2019, 06:15:50 pm »
Thank you for the reply. There IS an alerts tab, but so far it is blank. Perhaps that is for the IPS mode? I get tons of alerts in the logs file. It is raw data. I would assume that the alerts tab would also be raw data?
In the Snort package on Pfsense, it was fairly intuitive. You get a block, you could easily find it and remove it from the rules. On this, I just get a block and no easy way to determine where or how. For instance, I have a box on 200.63. It gets blocked in a game almost instantly That IP address doesn't show in the log, but it seems that it is being blocked since I can turn IPS off and it starts working again.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #3 on:
October 28, 2019, 07:51:14 pm »
Uncheck both Log setting related to syslog, then you should see something in alerts tab
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
lshantz
Full Member
Posts: 109
Karma: 3
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #4 on:
October 28, 2019, 08:03:18 pm »
Okay, even though it says that will have no effect? I did as suggested. Will wait for a bit and see what pops up.
Enable syslog alerts
Send alerts to system log in fast log format. This will not change the alert logging used by the product itself.
Enable eve syslog output
Send alerts in eve format to syslog, using log level info. This will not change the alert logging used by the product itself. Drop logs will only be send to the internal logger, due to restrictions in suricata.
Later: WOW!! That did not have the desired affect at all. The box crashed HARD!! The only way I was able to get back was to restore from backup. What I saw on monitor after connecting up via HDMI was "IGP1 MBUF that needs checksum offload" over and over which effectively took the LAN port out. All I did was turn off the syslog stuff as suggested.
We are kind of getting away from the original question anyhow. How do I get a nice reporting tool so I can easily block, unblock and see what is happening easily without gleaning raw output data.
«
Last Edit: October 28, 2019, 08:41:01 pm by lshantz
»
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #5 on:
October 28, 2019, 08:47:42 pm »
You dont get it, you shoult NOT use syslog variants
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
lshantz
Full Member
Posts: 109
Karma: 3
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #6 on:
October 28, 2019, 08:53:48 pm »
Oh I get it alright. But turning it off caused the box to hard crash! I would think there should be logic to prevent configuring it to a point it hard crashes like this, but in any event doing as you suggested caused a HUGE mess.
But to my original question, how to I turn on reporting log analysis other than raw data?
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #7 on:
October 28, 2019, 09:19:07 pm »
Crash will most likely come from wrong hyperscan/corasick. Just try to flip.
Theres currently no internal tool for this.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
lshantz
Full Member
Posts: 109
Karma: 3
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #8 on:
October 28, 2019, 09:26:11 pm »
Do you know if this is in the works?
That is 50% of the battle. If you have not tools for analysis, then it is not very useful.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #9 on:
October 28, 2019, 09:34:40 pm »
Why not ELK? Others can do better. It would take too mich ressources for local analysis
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
lshantz
Full Member
Posts: 109
Karma: 3
Re: suricata reporting Scirius, Evebox or Kibana
«
Reply #10 on:
October 28, 2019, 11:24:06 pm »
Why not Elk? Why not indeed. I know nothing of it. I was doing research and those 3 are all I came up with.
That is incorrect about not able to run a backend for Suricata. It has more than enough horsepower. I used Pfsense with the Snort module which has analysis built in. That is why I felt I must be missing something. To have Suricata and not have the backend is like having a car with no transmission.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
suricata reporting Scirius, Evebox or Kibana