New Install Not Ingesting Zeek Logs #13032
-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU24 RAM64gb Storage for /447gb Storage for /nsm6705gb Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailBrand new install of 2.4.60. Have a ManagerSearch node and 3 Forward nodes. No event.module: "zeek" logs are being ingested. Suricata logs are coming in from the sensors and elastic agent logs coming in fine but not the Zeek logs. I see Zeek logs being generated on the sensors under /nsm/zeek/logs/* just not being ingested in our Manager it looks like. The deployment otherwise is healthy - (Grid, elastic-agent status, so-status) show running + healthy + low resource usage. Any insight on what might be the problem? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 5 replies
-
Running "so-elasticsearch-query logs-zeek-so/_search?q=event.dataset:conn", I get the following:
|
Beta Was this translation helpful? Give feedback.
Update from 2.4.60 to 2.4.70 miraculously fixed. Zeek logs now coming in.