Distributed Deployment - No Data #13892
-
Version2.4.10 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU4 RAM96 Storage for /500G Storage for /nsm400G Network Traffic Collectionother (please provide detail below) Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailThis is my 20 plus time install and setup sOs . All privious installation setup seem to work fine during my eval. This is new Distributed enviroment -Client installed Agent succesful - this is always works *witth this new setup up node - I have no data @ all in the Dashboard, Sysmon Over....etc ..no Data from the client -Please list all the step and where i should look for troubleshooting the distributed setup Thanks for your help Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 6 comments 1 reply
-
If everything else is functioning fine but you're not getting any data in SOC, this may indicate a network issue since its not receiving any data to display. I'd recommend checking the physical connections to the devices within your grid, especially any TAPs or SPANs you may have. |
Beta Was this translation helpful? Give feedback.
-
This is just a Eval setup with distributed model. No TAP or SPAN port involved. I had add new clients to the mix still no data. I see the Redis Queue piling up in the Manager and Search Node. Just need to know if I shutdown All other nodes with this help with troubleshooting. Can the SOC function with Just Manager and Search node? Is there a method similar to tracert to track the flow of data between node? |
Beta Was this translation helpful? Give feedback.
-
Does the Elastic Fleet console show the client computer as healthy? Is there anything useful in the logs there? |
Beta Was this translation helpful? Give feedback.
-
Yes they all there show healthy, all node are healthy - no data |
Beta Was this translation helpful? Give feedback.
-
Well I wiped out the entired installation and redo everything from scratch. All working now. -Manger *Best place to look is Elastic Agents - All Green and noticed the EPS number changes. -I am looking for info on how to monitor the Fleet - The client only know the manager ip or host name so how do you know it is talking or sending info the Fleet node? Thanks for your help |
Beta Was this translation helpful? Give feedback.
-
I'm running into constant issues now and am afraid redoing from scratch is the only fix on a lab image. Everything started after a power outage and the whole SO image got corrupted. Had it on an HDD due to how big these installs are. |
Beta Was this translation helpful? Give feedback.
Well I wiped out the entired installation and redo everything from scratch. All working now.
-Manger
-Search
-Add client - check all work.
-Add Receiver - check grid check elastic agent all works
-Add Fleet - check grid check elastic agent all works
*Best place to look is Elastic Agents - All Green and noticed the EPS number changes.
-I am looking for info on how to monitor the Fleet - The client only know the manager ip or host name so how do you know it is talking or sending info the Fleet node?
Thanks for your help