Cisco DUO Authentication Logs Broken on 2.4.130 #14389
-
Version2.4.130 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU4 RAM16 Storage for /370gb Storage for /nsm40tb Network Traffic Collectionother (please provide detail below) Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI updated to SecurityOnion 2.4.130 yesterday and my Cisco DUO integration is giving me errors. They added a "Collect Cisco Duo logs via API v2" to the integration. I set this up with the same creds as I gave the v1 integration. All logs seem to be working except the one I most care about, authentications. From the elastic agent log, I was able to pull the following error:
I checked the security privileges of the API key and it looks to be set correctly.
I would appreciate any direction on fixing this error. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Beta Was this translation helpful? Give feedback.
Have you tried removing and then re-adding the integration to your agent policy?
You can also completely uninstall the integration and reinstall in-case something is off with the integration.
Uninstall is under 'settings' when you navigate to the integration page. It may not let you uninstall until you remove it from your active agent policy