Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
21.1.7: Suricata alert log not working
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: 21.1.7: Suricata alert log not working (Read 7504 times)
adk20
Newbie
Posts: 46
Karma: 3
21.1.7: Suricata alert log not working
«
on:
June 17, 2021, 12:15:59 am »
After the update to 21.1.7, the Suricata alert log (Services > Intrusion Detection > Administration > Alerts) appears to be broken for me.
I can see the newest 7 entries (default setting). When changing the number of entries per page or viewing another page than the first, I see old entries from before the update. To see the newest 7 again, I need to navigate to an entirely different page (e.g. Lobby) and then go back to the alert log. Then the same happens again.
Rebooting and deleting the alert log didn't help. Neither did clearing my browser cache.
Any feedback is much appreciated.
Logged
adk20
Newbie
Posts: 46
Karma: 3
Re: 21.1.7: Suricata alert log not working
«
Reply #1 on:
June 17, 2021, 09:11:29 pm »
The 21.1.7_1 hotfix did not solve this problem for me. Any ideas as to what might be the cause of this bug?
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: 21.1.7: Suricata alert log not working
«
Reply #2 on:
June 18, 2021, 07:51:40 am »
Hotfix was for pfTables page and DNS API resolver consumers, not for intrusion detection / log files. So far nobody else reported what you are seeing.
Are you sure this is a problem with the page and not with the log file / logging settings in intrusion detection? Might be best to clear the log and see if that helps.
Cheers,
Franco
Logged
adk20
Newbie
Posts: 46
Karma: 3
Re: 21.1.7: Suricata alert log not working
«
Reply #3 on:
June 18, 2021, 01:03:33 pm »
@Franco, thanks for your response.
Unfortunately, deleting the log file does not fix the issue. I am also unsure which setting should cause this odd behavior. Any hints in this regard are much appreciated. However, I would think that the GUI does not allow you to configure settings that break functionality!?
Moreover, the issue only arose after the upgrade to 21.1.7. I haven't touched the Suricata log settings in months.
When I open one of the logs from the previous weeks, everything works as expeced. Flipping through the pages, changing entries per page and so on.
In the current log, I can only view the first seven entries. Clicking through the pages or changing the number of entries per page etc. results in a blank page - "no results found!".
I did reset the log and deleted this and last weeks' logs. A new log with a fresh time stamp is created but, alas, the problem persists.
On a side note: What I noticed before but didn't pay much attention to is that when I have 50 entries per page displayed, the following is displayed at the bottom of the page: "Showing 1 to 7 of 51 entries". Has anyone else observed this?
I am at my wit's end. Any clues are much valued.
Cheers,
adk
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #4 on:
June 18, 2021, 02:03:35 pm »
I have just checked it. The error occurs before Opnsense 21.1.7. In my case since last 13th. I have cleared the browser cache, updated Opnsense to 21.1.7.1 and the problem persists.
«
Last Edit: June 18, 2021, 02:11:56 pm by yeraycito
»
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: 21.1.7: Suricata alert log not working
«
Reply #5 on:
June 18, 2021, 02:29:27 pm »
Maybe
https://github.com/opnsense/core/commit/644b647cf
# opnsense-patch 644b647cf
Cheers,
Franco
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #6 on:
June 18, 2021, 02:33:11 pm »
Solved. I cleared the alert log and it seems to be working. Before that it had gone from 7 results to 50 results in the alert log. When I went back to 7 results it was showing the data correctly. I still deleted all the alert logs.
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #7 on:
June 18, 2021, 02:57:55 pm »
Fixed without applying the new patch.
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #8 on:
June 18, 2021, 03:04:10 pm »
I was wrong, it is not solved, you have to apply the patch. When reloading the results of the alerts they disappear.
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: 21.1.7: Suricata alert log not working
«
Reply #9 on:
June 18, 2021, 03:05:35 pm »
This is all rather fishy to be honest...
Cheers,
Franco
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #10 on:
June 18, 2021, 03:14:57 pm »
I don't know what you mean by suspicious. We just want to help things run smoothly. I've posted a lot of screenshots explaining the problem and the possible solutions I've been able to find. If you think it's bad that we're trying to help you find and fix problems, just say so.
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: 21.1.7: Suricata alert log not working
«
Reply #11 on:
June 18, 2021, 03:22:51 pm »
To me it is simply unclear from the multiple posting structure if you applied the patch, how much success you had or how it was different or if the problem persisted.
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #12 on:
June 18, 2021, 03:38:44 pm »
I posted the comments and images in order as things happened, as is logical and normal and without having applied the patch and the problem was not solved. It couldn't be clearer. Now I have applied the patch and it seems that the problem has been solved.
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #13 on:
June 18, 2021, 04:11:06 pm »
After applying the new patch, all alerts are well recorded.
Logged
yeraycito
Sr. Member
Posts: 288
Karma: 18
Re: 21.1.7: Suricata alert log not working
«
Reply #14 on:
June 18, 2021, 04:14:58 pm »
The problem is that the number of results does not correspond to the number of page views. This has not been resolved with the new patch.
I hope this is clear to you. It would be appreciated if you could be nicer to those of us who just want to help.
Logged
Print
Pages: [
1
]
2
« previous
next »
OPNsense Forum
»
Archive
»
21.1 Legacy Series
»
21.1.7: Suricata alert log not working