4. Known problems and limitations
4.1. Active-CTI / RetroHunt - Post Update problem
In some cases, Active-CTI and RetroHunt (available with the LIS license) may not work optimally.
Workaround : contact Gatewatcher Technical Support.
4.2. GCenter Backup/Restore - Error management
If an error has been made by the user while applying the restore procedure, the menu progress bar (`Admin-Backup/Restore - Backup operations` screen) remains blocked and no error message is visible in the WebUI.
Workaround: no workaround.
4.3. GCenter Backup/Restore - Pairing the GCap
Following a GCenter backup, if the GCap pairing is deleted, then restoring the backup will not enable restoring the connection with the previously deleted GCap.
Workaround: reapply the pairing.
4.4. Incorrect GCap status after updating the GCenter
The GCap status may be wrong after updating the GCenter (Last update = unknown / State: Online but update outdated)
Workaround: apply again the ruleset configuration at the GCap level.
4.5. Sigflow Manager - Transform Category
Applying a Transform category raises a 500 error if no ruleset is available on GCenter.
Workaround: create a ruleset.
4.6. Sigflow Manager - Error 500 when adding a rule in a custom source
Adding a rule raises a 500 error if the following conditions are present:
The addition is done by editing a custom source
the rule already exists in another custom source (same SID)
Workaround: change the SID of the rule you want to add to avoid the SID conflict.
4.7. Sigflow Manager - Inconsistency in displaying the number of categories and rules in a category
`Sigflow > Sources` homepage shows the number of categories and rules contained in each source.Workaround: no workaround.
4.8. Sigflow Configuration - Custom source name cannot contain space
`Config - Sigflow/sources` screen of the legacy web UI, it is possible to define a custom source of signatures for the Sigflow detection engine.Workaround: change the name by removing spaces.
4.9. GCenter Backup/Restore - Error in FQDN
In v2.5.3.103, when restoring a backup, if the FQDN of the target GCenter is different then an error is generated.
Workaround: change the FQDN of the target GCenter and perform a reboot.
4.10. Kibana - Error 500 due to changing storage media for ES data
Following the change of ES data storage media, a temporary 500 error may appear when accessing Kibana.
Workaround: wait a few minutes.
4.11. Migration - Problem with online update configuration
Workaround: this problem is corrected in v2.5.3.103-HF1.
4.12. Migration - Problem with the detected user base of NDR interface
`users` tab, contains several tens of thousands of entries, the update process does not succeed.Workaround: this problem is corrected in v2.5.3.103-HF1.
4.13. Migration - Problem with the application of Sigflow rulesets
`default_ruleset` is used it may not apply correctly.Workaround: this problem is corrected in v2.5.3.103-HF2.
4.14. Network - Problem with interface MTU configuration
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.15. Network - VPN connectivity issue between GCap and GCenter
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.16. GUM - Problem with the configuration of the address of a local repository
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.17. Backup/Restore - Wrong format of the logs of the export in Syslog
`ECS`, it will be reset to `Legacy` in the Syslog export configuration.Workaround: this problem is corrected in v2.5.3.103-HF2.
4.18. Migration - Improper configuration of scheduled backups
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.19. ECS - Missing http_refer field
`http_refer` field is missing in ECS-formatted events.Workaround: this problem is corrected in v2.5.3.103-HF2.
4.20. CTI - Active-CTI Alerts Missing in the NDR Interface
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.21. CTI - Change of the SID of the Active-CTI rules with each update of Sigflow
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.22. Sigflow - Error while updating engine
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.23. NDR interface - Loss of filter on IP address in Asset and User views.
`Asset` and `User` views, if a filter is set for the IP address, it will be deleted.Workaround: this problem is corrected in v2.5.3.103-HF2.
4.24. XDP Filter - Configuration synchronization
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.25. WebUI - Access Issue
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.26. Malcore - File storage space saturation
Workaround: this problem is corrected in v2.5.3.103-HF2.
4.27. Retention - Saturation of the storage space in Elasticsearch
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.28. NDR Interface - Problem with muting alerts
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.29. Kibana - Beacon Detect dashboard
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.30. Update - Issue with UEFI version
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.31. NDR - User detection
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.32. NDR Interface - Alert Filtering
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.33. NDR interface - Solution health
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.34. Help - Embedded documentation
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.35. NDR Interface - Home Page links
Workaround: this issue is fixed in v2.5.3.103-HF3.
4.36. DGA - Addition of a comment
Workaround: this issue is fixed in v2.5.3.103-HF3.