Problem Sensor #14446
Problem Sensor
#14446
Replies: 1 comment
-
https://docs.securityonion.net/en/latest/virtualbox.html#virtualbox Did you follow this part?
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.120
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
airgap
Hardware Specs
Exceeds minimum requirements
CPU
4
RAM
16
Storage for /
1TB
Storage for /nsm
512 GB
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
I'm experiencing a problem with version 2.4.120. I have a distributed installation, and when I log in to the front end, I see that alerts aren't being indexed. I log in to the sensor node and run a TCP dump on the bond0 interface, and no traffic is arriving. Traffic is arriving on the physical interface of the server where the sensor server is running.
To fix this, run the following command on the host that hosts the Sensor VM:
vboxmanage modifyvm VMSEC3 --nicpromisc2 allow-all.
This fixes the problem temporarily, but then it comes back and stops working.
Has anyone experienced something similar?
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions