Skip to content
Discussion options

You must be logged in to vote

You need to install a searchnode for the logs to be ingested. A searchnode is what runs elasticsearch, so without it it makes sense why you are not seeing any logs via SOC. https://docs.securityonion.net/en/2.4/architecture.html#distributed

If you see zeek logs on the sensor at /nsm/zeek/logs/current/ but nothing in SOC, check Elastic Fleet and ensure the agents are showing up as 'Healthy'

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@DUser26
Comment options

Answer selected by reyesj2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants