-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationairgap Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /750 Storage for /nsm750 Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailBACKGROUND: I just reloaded my entire SO Suite with Manager Node, 2x Search Nodes, and 2x Sensors. However, I have Elastic Agents installed on my endpoints that were installed previously from my 2.4.8 build that I just reloaded (not upgraded) with 2.4.100. QUESTION: Do I have to uninstall and re-install Elastic Agent on my endpoints or will the agents connect to the new Manager Node and upgrade naturally? All configurations from 2.4.8 are the SAME as 2.4.100 in my network - nothing has changed, all ports and IPs and firewalls are configured as it was before. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Agents deployed from your last system will try to connect if IP scheme is the same, but they were deployed with a different certificate. In my experience, you will probably have to uninstall/reinstall agents with new creds. Are you getting a lot of SSL errors in /opt/so/log/logstash/logstash.log ? |
Beta Was this translation helpful? Give feedback.
Agents deployed from your last system will try to connect if IP scheme is the same, but they were deployed with a different certificate. In my experience, you will probably have to uninstall/reinstall agents with new creds.
Are you getting a lot of SSL errors in /opt/so/log/logstash/logstash.log ?