-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 to 16 depending on node RAM16 or 32gb Storage for /512 Storage for /nsm512 Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailIt is in the notes that you have to modify the rules but not sure what ones. I want my forward only to send to the receiver nodes ignoring the master node. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 6 replies
-
Actually there is a setting for this. If you change that to false it will tell all of your elastic agents to use receivers instead of the manager. Make sure you click Advanced to expose this setting. |
Beta Was this translation helpful? Give feedback.
-
The documentation for receiver nodes has been updated to explain this feature. https://docs.securityonion.net/en/2.4/architecture.html#receiver-node |
Beta Was this translation helpful? Give feedback.
Actually there is a setting for this.
If you change that to false it will tell all of your elastic agents to use receivers instead of the manager. Make sure you click Advanced to expose this setting.