Replies: 1 comment 1 reply
-
The iptables messages you show in your screenshots are kernel messages https://docs.securityonion.net/en/2.4/console.html#console When you want to add a node to your Security Onion grid as you mentioned you need to add the new nodes IP address to the firewall config in SOC. You also need to either wait ~15 minutes for the change to be automatically applied or hit the 'synchronize grid' button at the top of SOC. For your elastic agent troubles you need to allow them through the firewall as well. https://docs.securityonion.net/en/2.4/elastic-agent.html#elastic-agent |
Beta Was this translation helpful? Give feedback.
-
Version
2.4.60
Installation Method
Security Onion ISO image
Description
installation
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Meets minimum requirements
CPU
4
RAM
16gb
Storage for /
200gb
Storage for /nsm
Unknown
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
No, one or more services are failed (please provide detail below)
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
I am trying to set up a distributed installation type. Whenever I create the manager node, I continuously get IPTables-dropped posted every 15-20 seconds. I am not able to connect search nodes to the manager through the installation. I get "setup is unable to access the manager." I have added the IP
address of the search node through SOC-Admin-Config, however I am still not able to connect it. Th
This is the 5+ attempt at trying to install the node and the agents. The first time, I was able to connect the search nodes, but I was not able to install the elastic agents onto the endpoints through the downloader. I kept getting install failed to connect on port xxx.
Now, I'm not even able to connect the search nodes on this new attempt. I'm sure there is more information needed to help, please ask and I would be grateful for any help. Thank you!
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions