"Agent Spoofing - Multiple Hosts Using Same Agent" message since 2.4.190 upgrade #15186
-
Version2.4.190 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 physical, 32 with hyperthread RAM128 Storage for /32 TB Storage for /nsm28 TB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailSince upgrading to 2.4.190 two days ago, I am getting several alerts in Elastic Security on the Kibana side stating "Agent Spoofing - Multiple Hosts Using Same Agent" indicating multiple Elastic Agents having the same Agent ID. I've never seen that message before during this entire deployment. Any ideas on where I should even start troubleshooting? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
|
Anyone have any ideas on how to troubleshoot this particular issue? |
Beta Was this translation helpful? Give feedback.
-
|
It looks like that rule query is that event.agent_id_status field appears to have an issue open with it when ingesting logs using logstash (Security Onion logs go from agent -> logstash -> redis) elastic/kibana#183959 note the comment elastic/kibana#183959 (comment) |
Beta Was this translation helpful? Give feedback.
It looks like that rule query is
that event.agent_id_status field appears to have an issue open with it when ingesting logs using logstash (Security Onion logs go from agent -> logstash -> redis) elastic/kibana#183959 note the comment elastic/kibana#183959 (comment)