Search node missing
#14897
Replies: 2 comments 2 replies
-
You need a searchnode to store the logs. That can be either a managersearch or a searchnode. https://docs.securityonion.net/en/2.4/architecture.html#distributed |
Beta Was this translation helpful? Give feedback.
0 replies
-
Thanks for the reply. So, it means if we don't have manager-search or search node then we will not be able to see the logs on SOC. I also apply tcp dump filter on the manager interface connected to forward node even we are not receiving the logs on that interface. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.60
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Meets minimum requirements
CPU
16
RAM
200GB
Storage for /
100TB
Storage for /nsm
5 TB
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Hello Team,
I have a question. We have configured two nodes: a Manager and a Sensor. The Sensor is connected in TAP mode, and we are receiving traffic on the Sensor interface connected to the TAP interface. However, we are not receiving any logs on the Manager interface that is connected to the Sensor. As a result, we are unable to see any alerts in the SOC console.
We also noticed that we have not configured a Search node.
So, my question is: Are we not receiving traffic on the Manager because the Search node is not configured?
If we configure the Manager node as a Manager-Search node, will we be able to see the traffic and alerts in the SOC console?
We have verified that all services are running fine using the so-status command. The clocks on both the Manager and Sensor are synchronized with NTP, and connectivity between them is confirmed to be working.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions