-
Version2.4.211 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU10 RAM32 Storage for /500 Storage for /nsm500 Network Traffic Collectionspan port Network Traffic Speedsmore than 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi, Symptoms:
What I already checked/tried:
Any idea what's going on here, i.e. why all sensor nodes stop sending alerts - and how I could get them working again? Thanks much for any clue... Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
|
Troubleshoot your ingest pipeline, you can start at the sensor. Check your raw logs for Zeek and Suricata in Logstash would be next, on your Manager node, check the Logstash log Do you see any issues in the pipeline? |
Beta Was this translation helpful? Give feedback.
-
How should I go about that? Are they stored on the sensor node? In a file? Where?
Oops - As it turned out I've got the exact same error message for every S.O. node in the grid (!) To me that The question is which one and equally important - how could I fix this in order to get the setup working agin?
Didn't check these so far, because of the above error message. |
Beta Was this translation helpful? Give feedback.


Check this certificate first -
openssl x509 -in /etc/pki/elasticfleet-logstash.crt -noout -enddateif that certificate is valid then check the one in Fleet.Fleet > Settings > edit
grid-logstashoutput (click the pencil on the right)If the one in Fleet is expired, replace the client certificate and key in Fleet with
/etc/pki/elasticfleet-logstash.crtandelasticfleet-logstash.key