No log sources coming in after adding a forwarder and 2 Indexers from a standalone system to distributed #14180
Replies: 2 comments 2 replies
-
Ok, we re-installed all 4 VM nodes successfully and are back online. We suspect that we ran into the issue by installing a 3rd party certificate on the Manager for the web console and that did not get over to the 2 Indexers and 1 forwarder. We did see an x509 error in the logstash logs and that gave us our clue to rebuild. Thanks everyone! |
Beta Was this translation helpful? Give feedback.
1 reply
-
All the logs are from this thread, started by my manager - #14178 |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.111
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Meets minimum requirements
CPU
8
RAM
16
Storage for /
500
Storage for /nsm
200
Network Traffic Collection
other (please provide detail below)
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
local:
Data failed to compile:
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions