4. Known problems and limitations

4.1. Active-CTI / RetroHunt - Post-update problem

In some cases, Active-CTI and RetroHunt (available with the LIS license) may not work optimally.

Workaround: contact the Gatewatcher technical support.


4.2. GCenter Backup/Restore - Error management

If the user has made a mistake while applying the restore procedure, the menu progress bar (Admin-Backup/Restore - Backup operations screen) remains blocked and no error message is visible in the WebUI.

Workaround: no solution.


4.3. GCenter Backup/Restore - Pairing the GCap

Following a GCenter backup, if the GCap pairing is deleted, then restoring the backup will not enable restoring the connection with the previously deleted GCap.

Workaround: reapply the pairing.


4.4. Incorrect GCap status after updating the GCenter

The status of the GCap may be erroneous following the GCenter update (Last update = unknown / Status: Online but update outdated)

Workaround: apply again the ruleset configuration at the GCap level.


4.5. Sigflow Manager - Transform Category

Applying a Transform category raises a 500 error if no ruleset is available on GCenter.

Workaround: create a ruleset.


4.6. Sigflow Manager - Error 500 when adding a rule to a custom source

Adding a rule raises a 500 error if the following conditions are present:

  • The rule is added by editing a custom source

  • The rule already exists in another custom source (same SID)

Workaround: change the rule's SID that is to be added in order to avoid the SID conflict.


4.7. Sigflow Manager - Inconsistency in the display of the number of categories and rules of a category

The `Sigflow > Sources homepage shows the number of categories and rules contained in each source.
It is possible that the information displayed is inconsistent with the sources' actual content.
This situation may occur after editing a custom source or an update.

Workaround: no workaround.


4.8. Sigflow configuration - Custom source name cannot contain space

In the `Config - Sigflow/sources screen of the legacy web UI, it is possible to define a custom source of signatures for the Sigflow detection engine.
During the addition procedure, the source name must be entered.
This name must not contain any space otherwise it will generate an error.

Workaround: change name by removing the spaces.


4.9. GCenter Backup/Restore - Error with FQDN

In v2.5.3.103, when restoring a backup, if the FQDN of the target GCenter is different then an error occurs.

Workaround: need to change the target GCenter FQDN and restart.


4.10. Kibana - Error code 500 after the modification of the storage media for ES data

Following the change of ES data storage media, a temporary 500 error may appear when accessing Kibana.

Workaround: wait few minutes.


4.11. Migration - Problem with online update configuration

During the migration to v2.5.3.103, in some cases, the process fails due to the configuration of the online update.

Workaround: this problem is corrected in v2.5.3.103-HF1.


4.12. Migration - Problem with the detected user base of NDR interface

During the migration to v2.5.3.103, when the database of detected users, visible on the NDR interface in the tab `users`, contains several tens of thousands of entries, the update process does not succeed.

Workaround: this problem is corrected in v2.5.3.103-HF1.


4.13. Migration - Problem with the application of Sigflow rulesets

During the v2.5.3.103 migration, if a ruleset other than the `default_ruleset` is used it may not be applied correctly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.14. Network - Problem with interface MTU configuration

In some cases, the MTU of the MGMT0 and VPN0 interfaces does not apply correctly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.15. Network - VPN connectivity issue between GCap and GCenter

In the case of using the VPN0 interface, the VPN tunnel between GCap and GCenter may not work properly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.16. GUM - Issue with local repository address configuration

In the GUM configuration, if the local repo address contains a number, an error appears.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.17. Backup/Restore - Wrong format of the logs from export to Syslog

When restoring a backup, if the log format is in `ECS`, it will be reset to `Legacy` in the syslog export configuration.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.18. Migration - Improper configuration of scheduled backups

During the migration to v2.5.3.103, the configuration of the scheduled backup could be wrong.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.19. ECS - Missing http_refer field

The `http_refer` field is missing in ECS events.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.20. CTI - Active-CTI alerts missing in the NDR interface

In some cases, Active-CTI alerts are not present in the NDR interface.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.21. CTI - Change of the SID of the Active-CTI rules with each update of Sigflow

The SIDs of the rules generated by Active-CTI change when the Sigflow engine is updated.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.22. Sigflow - Error while updating engine

When updating the Sigflow engine, an error message may appear.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.23. NDR Interface - Loss of filter on IP address in Asset and User views

When clicking on an alert from the NDR `User` and `Asset` views, if a filter is set for the IP address, it will be deleted.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.24. XDP Filter - Configuration Synchronization

When an interface is added or removed from the GCap, configuration synchronization does not run properly.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.25. WebUI - Access issue

In some cases, access to the WebUI is not possible.

Workaround: this problem is corrected in v2.5.3.103-HF2.


4.26. Malcore: File storage space saturation

In some cases, the file storage space can quickly become full.

Workaround: this problem is corrected in v2.5.3.103-HF2.