Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
Monit alerts with Suricata
« previous
next »
Print
Pages: [
1
]
Author
Topic: Monit alerts with Suricata (Read 4496 times)
Dantichrist
Newbie
Posts: 31
Karma: 1
Monit alerts with Suricata
«
on:
March 29, 2021, 11:16:53 pm »
I hope that this is the right place to ask this.
I have been trying to get alerts working for suricata, and haven't been able to get them to work. I do get alerts for anything else that I have set up so I know that I have the alert settings set up properly.
I have set it up as it is shown in the manual
https://docs.opnsense.org/manual/monit.html
verbatim but I'm not getting alerts when I have blocked entries in the suricata log.
One thing that is really strange thing that I noticed is that if I vi /usr/local/etc/monitrc I have this in the config:
check file SURICATA_ALERT with path "/var/log/suricata/eve.json"
if content = \xe2\x80\x9cblocked\xe2\x80\x9d then alert
If I cat the same file I get this:
check file SURICATA_ALERT with path "/var/log/suricata/eve.json"
if content = “blocked” then alert
If I look at it with less or more I get this:
check file SURICATA_ALERT with path "/var/log/suricata/eve.json"
if content = <E2><80><9C>blocked<E2><80><9D> then alert
If I manually change "if content =" to blocked with vi I still don't get alerts even thought the status page in the UI shows that the service test is being triggered. If I reboot or make any changes to monit via the web interface it will change back to \xe2\x80\x9cblocked\xe2\x80\x9d.
I've spent a few days trying different things, and reading anything that I can get my hands on to to try to get this working and I'm out of ideas.
Can anyone give me any direction on what to try next? Thank you in advance for your time.
«
Last Edit: March 30, 2021, 12:18:00 am by Dantichrist
»
Logged
QBANIN
Newbie
Posts: 32
Karma: 0
Re: Monit alerts with Suricata
«
Reply #1 on:
March 29, 2021, 11:29:17 pm »
This setup works for me.
«
Last Edit: March 29, 2021, 11:31:58 pm by QBANIN
»
Logged
Dantichrist
Newbie
Posts: 31
Karma: 1
Re: Monit alerts with Suricata
«
Reply #2 on:
March 29, 2021, 11:47:51 pm »
Thank you for the reply. That's how I have it set up as well. The names are all that is different. I should have attached screen shots in the first post.
I only have four alert types set for "not on" and content failed isn't one of them.
«
Last Edit: March 29, 2021, 11:50:16 pm by Dantichrist
»
Logged
QBANIN
Newbie
Posts: 32
Karma: 0
Re: Monit alerts with Suricata
«
Reply #3 on:
March 30, 2021, 01:04:28 am »
IMO you are using wrong quotation marks
https://en.wikipedia.org/wiki/Quotation_mark
Take a closer look at both mine and your screenshot.
«
Last Edit: March 30, 2021, 01:06:29 am by QBANIN
»
Logged
Dantichrist
Newbie
Posts: 31
Karma: 1
Re: Monit alerts with Suricata
«
Reply #4 on:
March 30, 2021, 03:00:38 am »
Thank you for your reply. They are the same quotation marks that was copied directly from the Opnsense page covering monit. I'm not sure if the dark background has them looking different to you for some reason. Here is a screenshot with the stock theme. Tell me what the difference is because I don't see any.
My eyes aren't as good as they used to be because I'm old so who knows? lol
«
Last Edit: March 30, 2021, 03:09:09 am by Dantichrist
»
Logged
QBANIN
Newbie
Posts: 32
Karma: 0
Re: Monit alerts with Suricata
«
Reply #5 on:
March 30, 2021, 11:18:45 am »
Try to copy-paste this:
Code:
[Select]
content = "blocked"
Logged
Dantichrist
Newbie
Posts: 31
Karma: 1
Re: Monit alerts with Suricata
«
Reply #6 on:
March 30, 2021, 10:36:07 pm »
Done, and there was no change. Still no alert when I trigger it.
I've seen the forum thread that you got these settings from on here a few days ago. I copied/pasted those too with the same results. Literally the only difference is the naming scheme. The content itself is the same.
I can see when it's supposed to trigger because I can see "content match" on the status page.
One thing that I did notice is that after the updates today I don't see the weird differences with the monitrc file that I described in the OP.
«
Last Edit: March 31, 2021, 09:46:22 pm by Dantichrist
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
Monit alerts with Suricata