No traffic between Forward & Manager node #11861
Replies: 1 comment 2 replies
-
The forward node should automatically send alerts and metadata to the manager. Is there a firewall or other network device between the forward node and manager that may be interfering with the traffic? Have you run tcpdump on the manager's management interface to see if the forward node's traffic is reaching the manager? |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.30
Installation Method
Security Onion ISO image
Description
installation
Installation Type
Distributed
Location
airgap
Hardware Specs
Meets minimum requirements
CPU
8
RAM
32
Storage for /
82G
Storage for /nsm
159G
Network Traffic Collection
tap
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Good day,
Manager (Qty: 1), Search (Qty: 1), and Forward (Qty: 1) nodes have been installed. They are all able to communicate together. Every nodes have been added to "Grid Members". The issue is there is no data/logs from Forward to Manager. When I verify the Dashboard or Alerts section, there is nothing showing up. On the Forward node monitor interface, I did a "tcpdump -i interface". There are traffic on that interface.
It seems there is a setting that I have to turn on or off in order for the data to go to Manager. Is there a line I need to add into a file either on Manager or Forward node?
Any assistance or guidance would be much appreciated.
Thanks
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions