Remote sensor not sending logs :(Failed to connect to backoff): #8089
-
Hey everyone, Which I guess makes sense but I'm not sure how or why. SITE 1 SENSOR ------->Wireguardgateway ------>Manager Sensor can ping join all that fun stuff with manager, everything is green, devices is on grid yadda yadda, but the logs are not being sent via filebate/logstash. I've confirmed Suricata is generating alerts and Zeek is pulling metadata. I did the telnet thing ports appear to be open so it doesn't appear to be a routing/fw issue but I have to admit I'm not exactly an elk pro. I'm getting the errors below from the filebeat logs Manager:
Sensor:
Thanks |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
UPDATE: |
Beta Was this translation helpful? Give feedback.
UPDATE:
Resolved the issue.
Changed mss on the VPN gateway and filebeat worked.
Came to the conclusion after doing packet capture and seeing tons of transmission requests and broken coms.
Hope this helps someone down the road.