Can't add a replacement forward sensor #11812
-
Version2.4.20 Installation MethodSecurity Onion ISO image Descriptioninstallation Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU14 RAM64GB Storage for /500GB Storage for /nsm500GB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI have a distributed installation of SO 2.4.20 that has been working well, consisting of manager, search, and forward nodes. Recently, I had a hardware failure on the VM host that is hosting the forward sensor and, when everything was restored, the forward node was not working properly. Specifically, so-steno was showing as a missing service. I played with trying to fix that for a while but couldn't, and so, on the theory that "it's just a sensor," I went a head and reinstalled SO on the forward node. The problem I'm having is that the install goes fine, the forward node connects to the manager, and I approve the addition tot he grid on the manager, but then the forward node never shows up in the Grid. This seemed a little like this user's issue but I've tried all the steps in that, including, most recently, assigning the forward sensor host an entirely different IP and DNS name. Still no luck. As noted in the comments to the issue above, I have looked in the sensoroni logs, but don't see anything obviously interesting there. I've restarted SOC and I've restarted both the manager node and the forward node, but no luck. Any ideas of further troubleshooting to try? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
Its a bug on 2.4.20. It is fixed on 2.4.30. |
Beta Was this translation helpful? Give feedback.
-
Got it. Updating to 2.4.30 now--will report if/when that fixes it. Thanks! |
Beta Was this translation helpful? Give feedback.
Its a bug on 2.4.20. It is fixed on 2.4.30.
FIX: Global BPF prevents new sensor from applying highstate #11610