Skip to content
Discussion options

You must be logged in to vote

When you configured your manager node, did you configure it as a manager or managersearch?

It sounds like you configured it as just as a manager.

From https://docs.securityonion.net/en/2.3/architecture.html#distributed:

If you install a dedicated manager node, you must also deploy one or more search nodes. Otherwise, all logs will queue on the manager and have no place to be stored. If you are limited on the number of nodes you can deploy, you can install a manager search node so that your manager node can act as a search node and store those logs. However, please keep in mind that overall performance and scalability of a manager search node will be lower compared to our recommended arch…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@jcmadick
Comment options

@dougburks
Comment options

@jcmadick
Comment options

Answer selected by jcmadick
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants