Hi Chris,
It seems it is not working correctly on a 'Eval' installation. Tried twice in two different machines, one of them with a fresh installation, but with the same result...
# docker logs so-elasticsearch
Importing PKCS12 keypair into Java keystore
Importing keystore /usr/share/elasticsearch/config/elasticsearch.p12 to /usr/share/elasticsearch/config/sokeys...
Entry for alias 1 successfully imported.
Import command completed: 1 entries successfully imported, 0 entries failed or cancelled
uncaught exception in thread [main]
java.lang.IllegalArgumentException: Cannot have additional setting [transport.type] in plugin [SoTls], already added in plugin [x-pack-security]
at org.elasticsearch.plugins.PluginsService.updatedSettings(PluginsService.java:216)
at org.elasticsearch.node.Node.<init>(Node.java:318)
at org.elasticsearch.node.Node.<init>(Node.java:266)
at org.elasticsearch.bootstrap.Bootstrap$5.<init>(Bootstrap.java:227)
at org.elasticsearch.bootstrap.Bootstrap.setup(Bootstrap.java:227)
at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:393)
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:170)
at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:161)
at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86)
at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:127)
at org.elasticsearch.cli.Command.main(Command.java:90)
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:126)
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:92)
For complete error details, refer to the log at /var/log/elasticsearch/securityonioneval.log
Checking Docker status
Docker ------------------------- [ OK ]
Checking container statuses
so-cortex ---------------------- [ OK ]
so-curator --------------------- [ OK ]
so-dockerregistry -------------- [ OK ]
so-elastalert --------------- [ ERROR ]
so-elasticsearch ------------ [ ERROR ]
so-filebeat -------------------- [ OK ]
so-fleet ----------------------- [ OK ]
so-grafana --------------------- [ OK ]
so-idstools -------------------- [ OK ]
so-influxdb -------------------- [ OK ]
so-kibana ---------------------- [ OK ]
so-kratos ---------------------- [ OK ]
so-mysql ----------------------- [ OK ]
so-nginx ----------------------- [ OK ]
so-playbook -------------------- [ OK ]
so-redis ----------------------- [ OK ]
so-sensoroni ------------------- [ OK ]
I will try however in a Standalone installation.
Best regards,
Raimundo