Replies: 2 comments 2 replies
-
Vanilla install. Add FIM integration to elastic agent. Agent picks up file event:
But SO can't handle it:
Guess it's broken. |
Beta Was this translation helpful? Give feedback.
1 reply
-
@keis3cker Thanks for your reply. Is there a workaround or would you perhaps have a link to the reported issue? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.30
Installation Method
Security Onion ISO image
Description
installation
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
5
RAM
48
Storage for /
300
Storage for /nsm
6TB
Network Traffic Collection
tap
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
Using Fleet elastic-agent I copied the existing
endpoints-initial
policy and added File Integrity Monitoring and pushed it to 10 CentOS7 nodes. Nodes are healthy but no FIM events are generated./opt/so/log/logstash/logstash.log
mentions this error:Full logline:
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions