I received Issue 77 in the Security Onion Issue Tracker. The Issue describes an error when enabling Reverse DNS queries in Sguil. I was able to duplicate the issue.
I consulted with Bamm Visscher and he said this was due to Ubuntu's libudp-tcl package. I removed libudp-tcl and Reverse DNS queries started working again.
I've released a new upgrade script that fixes this issue automatically. Just download security-onion-upgrade.sh from http://sourceforge.net/projects/security-onion/files/ and run it like so:
sudo bash security-onion-upgrade.sh
It will then upgrade your Security Onion installation to version 20110122 and Reverse DNS queries should start working correctly.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.