-
Version2.4.20 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM32 Storage for /
Storage for /nsm
Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHey! Architecture:
Problem: agents not sending logs to heavy nodes.
Finally, questions:
Thanks a lot! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Heavy nodes are supported however you cannot have local elastic agents send data to it as the node is not part of the cluster. Elastic Agent requires all agents to send data to the same cluster. There are 2 agents running on the heavy node. The one that pulls all the logs from zeek etc is running in standalone mode. You could configure standalone agents on site to report to the heavy node but this would require you to manage updates etc manually. |
Beta Was this translation helpful? Give feedback.
Heavy nodes are supported however you cannot have local elastic agents send data to it as the node is not part of the cluster. Elastic Agent requires all agents to send data to the same cluster. There are 2 agents running on the heavy node. The one that pulls all the logs from zeek etc is running in standalone mode. You could configure standalone agents on site to report to the heavy node but this would require you to manage updates etc manually.