-
Version2.4.120 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM192gb Storage for /100 - 300gb Storage for /nsm300 - 2.4tb Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI am looking to rebuild Security Onion with a complete revamp of Searchnodes and Receiver nodes. I do not mind losing data, I am just looking to not have to rebuild every grid member from scratch again along with resetting up all the elastic agents to the new Fleet grid member. I came across faster storage and want to just cut the search and receiver nodes over as quickly as possible as I will also need to reclaim storage that they are currently running on. Last time I did something similar during testing, I could not add any new searchnodes or receiver nodes to the grid for some reason. I didnt check logs and just rebuilt from scratch since it was not fully setup. Is there a better way to just reinstall the searchnodes and receiver nodes when the previous grid members are lost due to storage reclaim and redeployed to new setup? The Grid members that will not be impacted will be Manager, Fleet, Sensors. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
You should be able to remove search nodes and receiver nodes as shown in the You should be able to add search nodes and receiver nodes as shown in the |
Beta Was this translation helpful? Give feedback.
You should be able to remove search nodes and receiver nodes as shown in the
Removing a Node
section of the documentation:https://docs.securityonion.net/en/2.4/removing-a-node.html
You should be able to add search nodes and receiver nodes as shown in the
Configuration
section of the documentation:https://docs.securityonion.net/en/2.4/configuration.html#production-server-distributed-deployment