-
Version2.4.30 Installation MethodSecurity Onion ISO image Descriptioninstallation Installation TypeEval Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /1TB Storage for /nsm627G Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailHello, I am not receiving any kind of alerts on a default setup. bond0 is seeing traffic, I have the default alert rules setup, and when I replay test data in the grid area, it fails to produce alerts. I have seen other complaints of this in the discussion area, however they are referred to the setup guide. I have followed it exactly with no luck. I've also tried installing the older versions of SO via ISO (2.4.20, 2.4.10) on bare metal, along with installing proxmox on the bare metal NUC and installing the ISO, installing Debian/Ubuntu on bare metal and installing SO - also with no luck. 2.3 worked great on this device and I wanted to upgrade to 2.4 because of the feature set, but I just cannot get it working. I don't know where to begin looking for an issue like this. I would appreciate some guidance. Here are almost all logs from /opt/so/log/: I've also attached some screenshots of when I replay test data in grid, along with an influxdb screenshot to show that it is seeing network traffic Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 16 replies
-
Have you tried following the Troubleshooting Alerts section in the documentation? |
Beta Was this translation helpful? Give feedback.
Interesting. It's possible that it's a bad drive, but can you share /opt/so/SO-Elastic-Agent_Installer.log so that we can see if there any other reasons why it may have timed out?