Very nice tutorial, but in some linux diustro's screen isn't install automaticly.. if screen isnt install cronjob won't work.... I had that isseu and try to run rita-roll from /opt/rita/ and I've got the supprice screen wasn't installed... SO i've installed it and now it's running :) Recap to add perhaps in de newer version of this video: 1. install screen; 2. Dry run from /opt/rita/rita-roll
@chrisbrenton383427 күн бұрын
Thanks for the ideas!
@SaySupport3 ай бұрын
When I run Rita List, i'm not seeing the database. Is that because I need to wait a few hours?
@ChrisBrenton-yk9eq3 ай бұрын
If you are reading a pcap, the database should show up right away. If you are creating a rolling database to do live monitoring, the database will get created after Zeek writes out it's logs and then RITA imports them. So yes, that usually takes 1-2 hours to happen for the first time. After that, the database will always be there.