Replies: 15 comments 19 replies
-
Does your Fleet server show healthy as well? |
Beta Was this translation helpful? Give feedback.
-
I completely reinstalled the security onion server today: I logged into the GUI, went to admin/config/firewall/hostgroups/elastic_agent_endpoint. selected my node and then added my single test client address to it. went to fleet, and added node. node shows healthy in fleet but still getting the same errors and no host data in kibana. Jan 14, 2024 @ 15:50:52.300 Jan 14, 2024 @ 15:50:50.963 |
Beta Was this translation helpful? Give feedback.
-
from here which redirects to git hub - https://securityonionsolutions.com/software |
Beta Was this translation helpful? Give feedback.
-
the test client has the agent installed in it from the SO server. used the link and install instructions on the fleet to do the install. client is ubuntu server 22.04 w/ all current patches |
Beta Was this translation helpful? Give feedback.
-
thanks for the reply chris. sorry, i did not download the clients from there. i removed all the clients i had and re-installed using the download that you showed. all installed without issue on the client side but i noticed this in the logs after when it started to pull policy (showed for each client): Jan 20, 2024 @ 23:51:07.375 Jan 20, 2024 @ 23:51:07.259 Jan 20, 2024 @ 23:51:07.259 after a few minutes, i started to see the same errors again though: Jan 21, 2024 @ 00:07:53.748 again, this is a stand alone VM. |
Beta Was this translation helpful? Give feedback.
-
sorry for the delay, more work travel. so i see the hosts as healthy in elastic fleet: for the tcpdump, i don't see anything adnormal: from the SO server: |
Beta Was this translation helpful? Give feedback.
-
logstash log has these errors over and over again: and this: and this: sec-onion resolves to 127.0.0.1 |
Beta Was this translation helpful? Give feedback.
-
i am going to download the 2.4.40 cd and reinstall from scratch. i will post once i am done if it worked or not |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
i removed the existing client, purged directories, and downloaded/installed client from elastic. still getting the same error. |
Beta Was this translation helpful? Give feedback.
-
any update on this issue? |
Beta Was this translation helpful? Give feedback.
-
NoSent from my Verizon, Samsung Galaxy smartphone
-------- Original message --------From: Chris Morgret ***@***.***> Date: 4/3/24 07:58 (GMT-06:00) To: Security-Onion-Solutions/securityonion ***@***.***> Cc: ws6543 ***@***.***>, Author ***@***.***> Subject: Re: [Security-Onion-Solutions/securityonion] Fleet agents not able to
send data (Discussion #12140)
Are you seeing data now?
—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you authored the thread.Message ID: ***@***.***>
|
Beta Was this translation helpful? Give feedback.
-
so if i am reading this right events are hitting the manager and being passed to redis: [root@sec-onion logstash]# sudo so-logstash-pipeline-stats manager but events from redis are not getting to elastic search? i attached the logstash, redis, and elasticsearch logs. i did restart the redis service at 04:27 so ignore those errors. [org.elasticsearch.xpack.transform.transforms.TransformTask] [endpoint.metadata_united-default-8.10.2] is already failed but encountered new failure; reason [Failed to load transform configuration for transform [endpoint.metadata_united-default-8.10.2 [2024-04-06T04:19:34,991][ERROR][org.elasticsearch.xpack.transform.transforms.TransformPersistentTasksExecutor] Failed to load transform configuration for transform [endpoint.metadata_united-default-8.10.2] |
Beta Was this translation helpful? Give feedback.
-
after looking at the transform issue, i was able to do the following: also i am still getting the failed to publish events log message |
Beta Was this translation helpful? Give feedback.
-
sorry for the delay, i thought i uploaded this already but must have forgot to. i regenerated the log tonight |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.30
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
6
RAM
16
Storage for /
300
Storage for /nsm
1000
Network Traffic Collection
span port
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
This is a setup for a home lab before we can deploy to a production environment.
I did a fresh install of 2.4.30 and then updated with salt after. No errors on that part.
In Admin, Config, FW, hostgroups, elastic_agent_endpoint i added the IP;s of my VM;s (single ip per line, no , after)
in elastic fleet, i added 6 hosts to monitor. all show healthy.
if i click on an agent, then more agent metrics it is blank (ie no data). clicking on dashboard, agent info i see this error over and over for every host:
failed to publish events: write tcp --agent-source-ip--:60718->--SO-destintation-IP--:5055: write: connection reset by peer
Failed to publish events caused by: write tcp --agent-source-ip--:60718->--SO-destintation-IP--:5055: write: connection reset by peer
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions