-
Notifications
You must be signed in to change notification settings - Fork 622
Closed
Milestone
Description
Upgrade to latest Zeek Ethercat plugin:
cisagov/icsnpp-ethercat#16
This resolves a long standing issue in the plugin where it was logging all ARP traffic by default:
cisagov/icsnpp-ethercat#5
Since it no longer logs all ARP traffic by default, we can remove the ecat_arp_info exclusion from our Zeek defaults.yaml:
https://github.com/Security-Onion-Solutions/securityonion/blob/2.4/main/salt/zeek/defaults.yaml
Remove the ARP page from documentation:
https://docs.securityonion.net/en/2.4/arp.html
Reactions are currently unavailable