Skip to content

Hyper-V VM Sensor not sensing any traffic #14014

Discussion options

You must be logged in to vote

This issue is resolved. It turns out that the ports required for the data to transfer from the Sensor to the Manger were not opened. Per this How-To https://docs.securityonion.net/en/2.4/firewall.html#firewall we only opened 443, 5000, 8086, 4505, 4506 through to the Manager. That made everything show Healthy, but no logs were sent from Sensor to Manager. When we allowed the rest of the ports all the traffic came in as expected.

I suggest the docs be updated to reflect the accurate list of required ports in the 'All nodes to Manager' list.

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
2 replies
@kspringer-maf
Comment options

@kspringer-maf
Comment options

Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Answer selected by kspringer-maf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants