-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptioninstallation Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM128 GB Storage for /222 GB Storage for /nsm11 TB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailHi!
It's a plain vanilla heavynode installation and I have not changed a thing. The rest of my SO deployment (manager+search+sensor) works fine. Any ideas on how to fix the logstash pipeline on the heavynode? Thanks in advance! Cheers, Ben Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
-
Have you looked at |
Beta Was this translation helpful? Give feedback.
-
Can I somehow recreate this broken certificate? |
Beta Was this translation helpful? Give feedback.
-
The Security Onion Pro Service explained to me, that the error "Logstash EPS at 0" on the InfluxDB status page is a bug in case of heavynodes. Everything works fine, alarms show up in SOC, but you will not see data in Kibana that is stored in the Elasticsearch instance on a heavynode (yet). |
Beta Was this translation helpful? Give feedback.
The Security Onion Pro Service explained to me, that the error "Logstash EPS at 0" on the InfluxDB status page is a bug in case of heavynodes. Everything works fine, alarms show up in SOC, but you will not see data in Kibana that is stored in the Elasticsearch instance on a heavynode (yet).