4. Known problems and limitations

4.1. Active-CTI / RetroHunt - Post Update problem

In some cases, Active-CTI and RetroHunt (available with the LIS license) may not work optimally.

Workaround : contact Gatewatcher Technical Support.


4.2. GCenter Backup/Restore - Error management

If an error has been made by the user while applying the restore procedure, the menu progress bar (`Admin-Backup/Restore - Backup operations` screen) remains blocked and no error message is visible in the WebUI.

Workaround: no workaround.


4.3. GCenter Backup/Restore - Pairing the GCap

Following a GCenter backup, if the GCap pairing is deleted, then restoring the backup will not enable restoring the connection with the previously deleted GCap.

Workaround: reapply the pairing.


4.4. Incorrect GCap status after updating the GCenter

The GCap status may be wrong after updating the GCenter (Last update = unknown / State: Online but update outdated)

Workaround: apply again the ruleset configuration at the GCap level.


4.5. Sigflow Manager - Transform Category

Applying a Transform category raises a 500 error if no ruleset is available on GCenter.

Workaround: create a ruleset.


4.6. Sigflow Manager - Error 500 when adding a rule in a custom source

Adding a rule raises a 500 error if the following conditions are present:

  • The addition is done by editing a custom source

  • the rule already exists in another custom source (same SID)

Workaround: change the SID of the rule you want to add to avoid the SID conflict.


4.7. Sigflow Manager - Inconsistency in displaying the number of categories and rules in a category

The `Sigflow > Sources` homepage shows the number of categories and rules contained in each source.
It is possible that the information presented is inconsistent with the actual content of the sources.
This case can occur after editing a custom source or an update.

Workaround: no workaround.


4.8. Sigflow Configuration - Custom source name cannot contain space

In the `Config - Sigflow/sources` screen of the legacy web UI, it is possible to define a custom source of signatures for the Sigflow detection engine.
During the addition procedure, the source name must be entered.
This name must not contain any space otherwise it will generate an error.

Workaround: change the name by removing spaces.


4.9. GCenter Backup/Restore - Error in FQDN

In v2.5.3.103, when restoring a backup, if the FQDN of the target GCenter is different then an error is generated.

Workaround: change the FQDN of the target GCenter and perform a reboot.


4.10. Kibana - Error 500 due to changing storage media for ES data

Following the change of ES data storage media, a temporary 500 error may appear when accessing Kibana.

Workaround: wait a few minutes.


4.11. Migration - Problem with online update configuration

During the migration to v2.5.3.103, in some cases, the process fails due to the configuration of the online update.

Workaround: this problem is corrected in v2.5.3.103-HF1.


4.12. Migration - Problem with the detected user base of NDR interface

During the migration to v2.5.3.103, when the database of detected users, visible on the NDR interface in the `users` tab, contains several tens of thousands of entries, the update process does not succeed.

Workaround: this problem is corrected in v2.5.3.103-HF1.


4.13. Migration - Problem with the application of Sigflow rulesets

During the migration to v2.5.3.103, if a ruleset other than the `default_ruleset` is used it may not apply correctly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.14. Network - Problem with interface MTU configuration

In some cases, the MTU of the MGMT0 and VPN0 interfaces does not apply correctly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.15. Network - VPN connectivity issue between GCap and GCenter

In the case of using the VPN0 interface, the VPN tunnel between GCap and GCenter may not work properly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.16. GUM - Problem with the configuration of the address of a local repository

In the GUM configuration, if the local repository address contains a number, an error appears.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.17. Backup/Restore - Wrong format of the logs of the export in Syslog

When restoring a backup, if the log format is in `ECS`, it will be reset to `Legacy` in the Syslog export configuration.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.18. Migration - Improper configuration of scheduled backups

During the migration to v2.5.3.103, the configuration of the scheduled backup could be wrong.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.19. ECS - Missing http_refer field

The `http_refer` field is missing in ECS-formatted events.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.20. CTI - Active-CTI Alerts Missing in the NDR Interface

In some cases, Active-CTI alerts are not present in the NDR interface.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.21. CTI - Change of the SID of the Active-CTI rules with each update of Sigflow

The SIDs of rules generated by Active-CTI change when an update to the Sigflow engine.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.22. Sigflow - Error while updating engine

When updating the Sigflow engine, an error message may appear.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.23. NDR interface - Loss of filter on IP address in Asset and User views.

When clicking on an alert from the NDR `Asset` and `User` views, if a filter is set for the IP address, it will be deleted.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.24. XDP Filter - Configuration synchronization

When an interface is added or removed from the GCap, the configuration synchronization does not perform correctly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.25. WebUI - Access Issue

In some cases, access to the WebUI is not possible.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.26. Malcore - File storage space saturation

In some cases, the file storage space can fill up quickly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.27. Retention - Saturation of the storage space in Elasticsearch

It is possible to configure retention that is greater than the available storage space, which can render data indexing inoperative in Elasticsearch.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.28. NDR Interface - Problem with muting alerts

In some cases, muting alerts doesn't work properly.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.29. Kibana - Beacon Detect dashboard

From the NDR interface, the redirection to the Beacon Detect dashboard is not done correctly.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.30. Update - Issue with UEFI version

In UEFI, updating to the next major version is not done correctly.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.31. NDR - User detection

User detection is not performing correctly with the next major release of GCap.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.32. NDR Interface - Alert Filtering

In some cases, the filtering of alerts in the NDR interface does not perform correctly.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.33. NDR interface - Solution health

On the homepage, some of the platform's health status counters are incorrect.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.34. Help - Embedded documentation

In some cases, the redirection to the embedded documentation is done to the wrong section.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.35. NDR Interface - Home Page links

Some links on the home page redirect the user with a wrong date and time filter.

Workaround: this issue is fixed in v2.5.3.103-HF3.


4.36. DGA - Addition of a comment

When configuring the DGA engine, it is not possible via the web interface to add a comment when adding an exception.

Workaround: this issue is fixed in v2.5.3.103-HF3.