no alerts and logs in hunt from idh #12512
-
Version2.4.50 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU32 RAM64 Storage for /500 Storage for /nsm500 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues Detailwhen installing the idh module and deploying it to the manager node, there are no logs from opencanary, playbooks are active, http bait is available, but nothing happens when entering the login and password. I tried to do everything that was described in the community but there was no result. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 8 comments 7 replies
-
I have the same problem, I do TCPDUMP to the interfaces and there is traffic without problem, but it does not appear reflected in the tool or in alerts or in the GRID please help |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
The problem still persists, could you please suggest steps to troubleshoot since it’s not clear what to do about it |
Beta Was this translation helpful? Give feedback.
-
I’ll add: when installing node idh, the installation occurs correctly, the node itself is visible in the grid, there are no errors, but when accessing in IDH port 22 ssh or 80 http and entering login and password, opencanary events are not generated (at least they are not visible in hunt) |
Beta Was this translation helpful? Give feedback.
-
Do you see logs generated in |
Beta Was this translation helpful? Give feedback.
-
Can you suggest any solution to this problem? or other troubleshooting actions? |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
In general, we managed to solve the problem by reinstalling IDH on a separate network and setting up a firewall rule in the admin panel. but no matter how much I deployed the idh module on the same network where the manager node and other sec onion elements were, the problem with the elastic agent remained. @reyesj2 thank you for your feedback and help in this matter! |
Beta Was this translation helpful? Give feedback.
From elastic fleet when you click on the 'so-idh4' agent you should be able to pull up logs about that agent and maybe why its degraded.
Click on 'Dataset' and unselect any that are selected so it shows all logs.
The so-idh4 node status in SOC -> Grid is still OK/green?