WebInterface - No events in Alerts & Dashboard tab #13990
Unanswered
YvesEutelsat
asked this question in
2.4
Replies: 1 comment 3 replies
-
Check the logstash and elasticsearch logs on the Manager (in /opt/so/log) -- if the new Manager is having issues receiving data or writing it to Elasticsearch, there will be errors there. Are the Search and Sensor nodes showing up properly in Grid Members and in Elastic Fleet? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Version
2.4.110
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
airgap
Hardware Specs
Exceeds minimum requirements
CPU
16
RAM
128G
Storage for /
275G
Storage for /nsm
1.7T
Network Traffic Collection
tap
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
Good day,
I recently replaced the VM manager within the distributed deployment. On the search and sensor node, I used the command "SecurityOnion/setup/so-setup iso" to re-initiate the network configuration so they can join the VM manager. When connecting to the WebInterface, I can see under "Grid" search & sensor node. All containers are running showing green status.
Sensor is capturing traffic since in the pcap & suricata folder, there are files with latest date/time.
Would someone have a suggestion for next step so I can see the count increase in the WebInterface "Alerts & Dashboard" menu? I did follow the troubleshooting guideline within Security Onion documentation.
Assistance is much appreciated, thanks
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions