Hostname of the manager unexplicably changed during update to 2.4.100 #13634
-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU4 RAM32 Storage for /100G Storage for /nsm200G Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues Detail
5 days ago, After some troubleshooting and trial and error, I got most of the containers running, except for the following 2:
idstoolsWhen trying to start the idstools, I get the following:
This mentions the
However, the hostname is
I have searched (grep -r) all over the filesystem for files where this so-manager-tou is mentioned, but to no avail except for the log files. Not a single configuration file or anything... socWhen trying to start the soc, I get the following:
Also here this
When doing
As you can see, it tried to find This is after the upgrade to 2.4.100, after some troubleshooting en trial and error where I got all but 2 containers working:
Below also an error I found, pertaining to so-manager-tou:
Here it talks about x509 certificate which (I assume during initial setup) has been created for so-manager hostname, and not for so-manager-tou. x509 certificateGoing down the x509 rabbit hole (and leaving some bits out for readability and security reasons):
Here it mentions the The one thing I can think of right now in the direction of I have verified: the manager has been installed with Any help would be highly appreciated, because I am lost here... Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
And, as always, you are searching for hours on end without finding anything. You decide to start a discussion on github, gather as much usefull info as possible, you file the case and POOF : progress! Seems I overlooked the following file where this
1 down, 1 to go... |
Beta Was this translation helpful? Give feedback.
-
And also the last one which refused to start earlier, now is able to start:
But my question remains: why did it suddenly wanted to use so-manager-tou instead of so-manager ? Anyways, my setup seems to work again. I will not look any further. Maybe someone has some use in the info I posted here. Have a nice one! |
Beta Was this translation helpful? Give feedback.
And also the last one which refused to start earlier, now is able to start: