No information available from OpenCanary #14874
Replies: 2 comments 1 reply
-
Is the IDH node showing up properly in the Grid screen on the Manager? Is the Elastic Agent running on the IDH node listed as "Healthy" in the Fleet interface? On the IDH node, are there any logs in the file at /nsm/idh/opencanary.log? |
Beta Was this translation helpful? Give feedback.
-
Try this.
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.160
Installation Method
Security Onion ISO image
Location
On-prem with internet access
Installation Type
Distributed (3 nodes)
Hardware Specs
ManagerSearch Node (Physical)
CPU : 8
RAM : 16
Storage : 1TB
Sensor Node (Vmware with two network cards on bridge)
CPU : 4
RAM : 12
Storage : 200GB
IDH Node (Vmware with network card on bridge)
CPU : 2
RAM : 2
Storage : 100GB
Configuration
Manager with one sensor node and one IDH node
Status
All services on all nodes are running OK
Detail
Hello,
I am having a problem with the alerts that OpenCanary should generate.
I configured the IDH node following all the instructions here https://docs.securityonion.net/en/2.4/idh.html#idh. After running tests on the different ports I activated, I don't see any information in Dashboards or Hunt coming from OpenCanary. The same goes for the “opencanary” query in Dashboard and Hunt's Onion Query Language, as well as in Kibana with the queries
event.module: opencanary
and
event.dataset: idh
.However, I do get information from Suricata and Zeek after running
so-test
in the ManagerSearch node.It's as if I hadn't configured anything for the IDH and OpenCanary nodes, even though I think I followed everything in the documentation in the idh section https://docs.securityonion.net/en/2.4/idh.html#idh
Thank you in advance for any help.
Guidelines
I have read the discussion guidelines at Read before posting! #1720 and assert that I have followed the guidelines.
Beta Was this translation helpful? Give feedback.
All reactions