Replies: 5 comments 6 replies
-
I think this is similar issue I'm having as well on another thread. |
Beta Was this translation helpful? Give feedback.
-
What does |
Beta Was this translation helpful? Give feedback.
-
@markmaunu @stondino00 Do you run setup with proxy settings? |
Beta Was this translation helpful? Give feedback.
-
Has the hostname or IP of the Manager changed since you originally ran setup? Did you re-run setup on the Manager? You can try the following (from the Manager):
This will uninstall the Elastic Agent on all Grid Nodes & reinstall it. |
Beta Was this translation helpful? Give feedback.
-
@markmaunu Is it possible that your network is already using the 172.17.x.x range? If so, have you tried adjusting the Docker network range as shown at https://docs.securityonion.net/en/2.4/docker.html#networking-and-bridging? |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.20
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
8
RAM
64G
Storage for /
293GB
Storage for /nsm
14TB
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
The sensor node is running without issues and collecting suricata logs, zeek logs and pcaps locally . The manager node is not displaying any data in the UI . There are no errors on the sensor node running sudo salt-call state.highstate
Two errors on the manager node running sudo salt-call state.highstate
Function: cmd.run
Name: /usr/sbin/so-elastic-fleet-es-url-update
Result: False
Comment: Attempt 1: Returned a result of "False", with the following comment: "Command "/usr/sbin/so-elastic-fleet-es-url-update" run"
Command "/usr/sbin/so-elastic-fleet-es-url-update" run
Started: 18:30:25.658136
Duration: 30180.413 ms
Changes:
----------
pid:
3647601
retcode:
1
stderr:
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
Function: cmd.run
Name: /usr/sbin/so-elastic-fleet-outputs-update
Result: False
Comment: Attempt 1: Returned a result of "False", with the following comment: "Command "/usr/sbin/so-elastic-fleet-outputs-update" run"
Command "/usr/sbin/so-elastic-fleet-outputs-update" run
Started: 18:29:51.232606
Duration: 30166.332 ms
Changes:
----------
pid:
3646249
retcode:
1
stderr:
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions