Replies: 3 comments 3 replies
-
Did you follow the instructions at https://docs.securityonion.net/en/2.3/cloud-ami.html including the following?
|
Beta Was this translation helpful? Give feedback.
-
Yes. If I do a tcpdump -i eth1, I see traffic. If I do a ps -elf | grep zeek, I see the process trying to listen on bond0. If I do a tcpdump -i bond0, there' s no traffic. dmesg and /var/log/messages have errors around bond0: Apr 25 08:44:17 hc4pcapng3pv NetworkManager[801]: [1650876257.6154] device (eth1): Activation: starting connection 'bond0-slave-eth1' (45c58b5a-be5b-4b57-869b-6509400560c2) |
Beta Was this translation helpful? Give feedback.
-
Did you follow the instructions at https://docs.securityonion.net/en/2.3/cloud-ami.html#aws-sensor-setup?
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
We have an on-prem manager and several on-prem sensor nodes. I was able to launch the SO AMI successfully and connect it to the manager. The AMI sensor is string to sniff bond0 rather than eth1. While eth1 is part of the bond, the bond fails because it's AWS.
Is using an AMI sensor with an on-prem manager supported?
Thanks,
Larry
Beta Was this translation helpful? Give feedback.
All reactions