-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptioninstallation Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU52 RAM512 Storage for /448 Storage for /nsm27T Network Traffic Collectiontap Network Traffic Speedsmore than 10Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailI setup a new setup for a bigger install. One manager, two receivers and a forwarder all on the same switch/VLAN. It was on 2.4.9 , just updated to see if it would fix the issue but no. Everything is showing as up and connected. The sensor/forwarder is receiving a lot of traffic but nothing is being alerted/captured. No EPS showing or anything. Could use some assistance/ideas on where to look. I even reinstalled the sensor just in case. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
to add more, I am getting nothing, nothing appearing on the dashboards as all. On the forwarder Zeek logs are there and showing they are working. |
Beta Was this translation helpful? Give feedback.
-
You need to install a searchnode for the logs to be ingested. A searchnode is what runs elasticsearch, so without it it makes sense why you are not seeing any logs via SOC. https://docs.securityonion.net/en/2.4/architecture.html#distributed
|
Beta Was this translation helpful? Give feedback.
You need to install a searchnode for the logs to be ingested. A searchnode is what runs elasticsearch, so without it it makes sense why you are not seeing any logs via SOC. https://docs.securityonion.net/en/2.4/architecture.html#distributed
If you see zeek logs on the sensor at/nsm/zeek/logs/current/
but nothing in SOC, check Elastic Fleet and ensure the agents are showing up as 'Healthy'