OSQuery never gets response when running queries #13891
-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationairgap Hardware SpecsExceeds minimum requirements CPU12 RAM128G Storage for /293 G Storage for /nsm7T Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailCurrently, I get no results when running queries to the installed agents from osquery. The agents respond otherwise, logs are being collected, but osquery specifically doesn't get a response. The agents have the default endpoints-initial policy on them. I see Healthy listed in the statuses. I am running against rocky 9 clients. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
I think this is similar to #13819 . As I do now see the results in discover, but the live query page itself just spins and spins. |
Beta Was this translation helpful? Give feedback.
-
@mralexc 2.4.130 was just released, with the latest Elastic updates. I would suggest upgrading. https://blog.securityonion.net/2025/03/security-onion-24130-now-available.html |
Beta Was this translation helpful? Give feedback.
@mralexc 2.4.130 was just released, with the latest Elastic updates. I would suggest upgrading.
https://blog.securityonion.net/2025/03/security-onion-24130-now-available.html