This update resolves the following issue:
Issue 348: Update CapME with a new option to query Bro conn.log via ELSA
Thanks to the following for testing the new packages!
The new packages are now available in our stable repo. Please see our Upgrade page for full upgrade instructions:
After installing the new packages, you'll need to restart Bro:
sudo broctl restartScreenshots
|Restarting Bro using "sudo broctl restart"|
|When pivoting from ELSA, CapMe now defaults to searching ELSA instead of the sancp table|
If you have any questions or problems, please use our mailing list:
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
We especially need help in answering support questions on the mailing list and IRC channel. Thanks!
Want to learn more about Security Onion? Sign up for the upcoming 8-hour class in Augusta GA!