Winlogbeat being rejected by security onion #10802
Replies: 1 comment 2 replies
-
Is your Security Onion box configured as Eval or Import mode perhaps? From https://docs.securityonion.net/en/2.3/beats.html:
|
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Wimlogbeat currently being port forwarded over a pfsense firewall (logs coming in from agents beyond the WAN to SO on the LAN) to seconion,
watching with a tcpdump -i int port 5044, it makes it through the firewall okay only to be rejected with a rst/ack by SO (so-status allow set to accept both the host ip and the firewall ip for 5044)
Anyone got any ideas how to fix?
Beta Was this translation helpful? Give feedback.
All reactions