Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Logging Issue as soon as I deploy velo on 2.3.90 #7

Open
Xboarder56 opened this issue Dec 17, 2021 · 2 comments
Open

Logging Issue as soon as I deploy velo on 2.3.90 #7

Xboarder56 opened this issue Dec 17, 2021 · 2 comments

Comments

@Xboarder56
Copy link

Xboarder56 commented Dec 17, 2021

I'm pretty sure the velo deployment is the root cause. I took a snapshot prior to deployment but shortly after deploying velo on a clean SO instance all my logs stop working in elastic/SOC dashboard including hunt. I'm not entirely sure of the cause. so-status shows green and I made a ticket over on the discussion forums there when it first happened after an upgrade.

Velo installs and works correctly but the remaining security onion stack has issues. I'm thinking either Logstash or elastic (not familiar enough with how it all integrates)

@weslambert
Copy link
Owner

Thanks for reporting! This is probably because the manager or search pipeline is failing (pipeline will fail, but Logstash will still be running and show as OK). It's likely something to do with the Logstash configuration. I'll take a look.

@Bal33p
Copy link

Bal33p commented Jan 18, 2022

I am experiencing the same issue
installing VR blew away all of my third-party filebeat firewall settings then would break minion
I finally got it installed and now none of my indexes show data in soc since the day I installed it back on 1/14/22

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants