Known Issue: NIDS/HIDS/PRADS Does Not Start If ASEC Is Enabled
|AlienVault Ticket ID||ENG-105802|
After upgrading to USM Appliance version 5.4, some customers noticed that NIDS or PRADS stopped working and there were no AlienVault NIDS events displaying.
AlienVault has reproduced this behavior internally and identified that this is because ASEC was enabled in ossim_setup. Disabling ASEC and running alienvault-reconfig resolves the issue.
To check and disable asec
Connect to the AlienVault Console through SSH and use your credentials to log in.
The AlienVault Setup menu displays.
On the AlienVault Setup main menu, select Jailbreak System to gain command line access.
Select Yes when prompted. You will be in the root directory.
- Using a text editor of your choice, open /etc/ossim/ossim_setup.conf.
Locate the asec setting under the [sensor] section:
- If your file shows asec=yes, change it to asec=no and save the file.
Restart all services for changes to apply:
alienvault-reconfig -c -v -d