Skip to content
Discussion options

You must be logged in to vote

There is an error when I run "soup" in forward node:

As the error message indicates, you don't need to run soup on anything other than your manager:

Please run this command on the manager; the manager controls the grid.

If you just have a forward node and a manager node (and no search nodes), then your logs are likely sitting in a queue on the manager waiting for a search node to ingest them. From https://docs.securityonion.net/en/2.3/architecture.html#distributed:

If you install a dedicated manager node, you must also deploy one or more search nodes. Otherwise, all logs will queue on the manager and have no place to be stored.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@clopmz
Comment options

@clopmz
Comment options

Answer selected by clopmz
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants