Elastic showing 0 count for heavy nodes #12043
Replies: 2 comments 29 replies
-
I would make sure that you have the managed switch setup correctly, do a ip a find which ethernet port is being used as the tap port then do a tcpdump -i on that ethernet port to check what is coming in or not coming in. If you don't see anything besides ssh traffic then check the switch and make sure you have the port configuration setup may it be a span port or mirror port setup. Could possibly be a bad ethernet cable, its slim but it is possible. If you already tried these, check the logs and see whats going on there, might be a kibana problem or logstash problem. Hope this helps you get everything figured out! |
Beta Was this translation helpful? Give feedback.
-
What is your cluster settings on your manager - |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.30
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
8
RAM
32
Storage for /
1TB
Storage for /nsm
1TB
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
All heavy nodes show services running fine. Kibana is showing 0 count for logs. Nothing is showing.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions