SourceFire IDS showing EPOC time as Device Receipt Time
I have recently integrated Sourcefire IDS device onto ESM via the eStreamer connector. However I am facing an issue with the device receipt time which is showing the epoc time (1970). All malware events are showing the right time, its only the connection (RNA) events are having this issue.
Has someone come across such issue in any implementation with eStreamer. is this something to do with the Smart connector or with sourcefire ?
sourcefire version is 5.X
Its a fault with the SmartConnector. We also discovered this issue.
We have had to use a parser override to fix the time up, and there is a bug ticket in for this as well as of about 6-8months ago (number escapes me). I thought this may have been fixed in later SmartConnector releases (last seen in 7.04 possibly?) If you are using an older SmartConnector version you may want to give a newer one a try...
I have installed 7.0.7.x version, We have also open a case with CISCO and HP to figure out where the issue is coming from. So far we were able to fix the LastPacketTimeStamp issue which was coming as NULL previously. there was configuration issue in DC.
I will keep this thread updated with the solution as and when available.