SO Sensor Showing Fault in Grid #13691
-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU2 x Intel(R) Xeon(R) CPU E5-2620 v3 @ 2.40GHz RAM96.00 GB Storage for /1022M Storage for /nsm3.4T Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI have 4 sensors running. 1 shows fault in Grid view no metrics showing and cpu at 100%. The node can reach the master on all ports that are needed. The node is sending data to the master. Everything about the node shows it's working as it should. Netstat shows the following ports have established connections to the master 443, 8220, 4505, 8086, 4506, 5055. I have removed the node from grid and fleet rebooted no change. I removed it from both again and reinstalled the node from scratch no change. All other sensor nodes are fine and showing metrics for the hardware. The sensor is a bare metal server. Dell R430
Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 8 replies
-
What is the output of the following command on the sensor?
|
Beta Was this translation helpful? Give feedback.
-
Thank you for your help Doug! |
Beta Was this translation helpful? Give feedback.
Is this a simple firewall that just does port blocking or is it a next-gen firewall that could be doing IPS or other kinds of packet manipulation?
Have you checked the logs on the sensor in /opt/so/log/ and specifically telegraf?
Are all devices in your Security Onion sync'd to the same NTP server and do they all currently show the same exact time?