-
Version2.4.200 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPUManager: 8 CPU RAMManager: 32 GB Storage for /82 GB total, 26 GB available Storage for /nsm159 GB total, 35 GB available Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailAbout a month ago, alerts stopped appearing. Upgraded from SO ver 2.4.180 to ver 2.4.201, still no alerts appearing. Rebooted nodes, still no alerts appearing. All grid (manager, search, and sensor) node's services are showing green "Running". Sensor node grid status shows "Suricata Rules: 48018 loaded" Detections tab: "Total Found: 69,903" Clicking Options, Suricata "Full Update" completes successful. Alerts tab: "Total Found: 0" I see Suricata logs on the sensor: Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
|
On your sensor node, what does the Elastic agent status show? If that shows ok, go to your manager node and check the Logstash log, You can also check you Elasticsearch for any issues with |
Beta Was this translation helpful? Give feedback.

If you go into
Kibana > Fleet > Settings > Outputs > grid-logstash (click the pencil to edit)and check theClient SSL certificatefor expiration. If it is expired, replace the Client SSL certificate and key with/etc/pki/elasticfleet-logstash.crt and .key