-
Notifications
You must be signed in to change notification settings - Fork 568
Replies: 1 comment · 7 replies
-
Are you able to run |
Beta Was this translation helpful? Give feedback.
All reactions
-
oh man... dont i feel dumb.... PEBCAK error looks like i have 3 duplicate indexes specifically here:
here is the output
|
Beta Was this translation helpful? Give feedback.
All reactions
-
Check why they are unassigned - |
Beta Was this translation helpful? Give feedback.
All reactions
-
Just a note, ive had a lot of issues and am basically rebuilding this entire machine from the beginning as nothing literally was working out of the box. I have no clue why, but it's working as I go throughout the github. This is probably the biggest issue that is the last thing I have currently. I am extremely new to the whole ELK stack overall and trying to figure things out at this time. But here is the info you requested. version 2.3 didnt have these issues on 2.4. this is a personal project of mine. input -
Output below:
Correct me if im wrong.. this is a standard installation for a management node and no other nodes are in my environment. This isn't mission critical but im learning throughout this entire process and just found out that shard replication errors is happening because of me having only 1 node on the network. BUT if i had (i think..) a sensor on my network on a separate i would assume this would not be an issue , correct? Im probably wrong. |
Beta Was this translation helpful? Give feedback.
All reactions
-
Does this work on the replica shards? https://docs.securityonion.net/en/2.4/release-notes.html#known-issues |
Beta Was this translation helpful? Give feedback.
All reactions
-
(sorry if i explain this wrong) Just an update here
Hopefully the original poster has the similar issue and can try that as well which sounded like it |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.50
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
32
RAM
800GB
Storage for /
256GB
Storage for /nsm
16TB
Network Traffic Collection
other (please provide detail below)
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
I was messing around with configuring a custom log integration through the Elastic Agent, and after I had I had configured it and got it to work all was fine until I started to notice that I was not getting any other logs.
During the configuration process I had had discovered that the custom logs were being indexed by the index template "so-logs" instead of the custom template I created so I increased the priority of my custom one to be above so-logs.
After discovering the issue I reverted all the changes I had made but am still not seeing any logs. I even spun up a fresh SO install on a test server and compared all the index templates side by side and everything matched what I have on my main server.
The only error I see in the logs is the following but google doesn't return anything useful
Any help at all would be appreciated.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions