looking at the sosetup.log of a working sensor and comparing with the one thats having issues is almost the same. the only difference is at the end of the file on the sensor that is NOT working has this...
[INFO ] Loading fresh modules for state activity
[INFO ] Fetching file from saltenv 'base', ** done ** 'top.sls'
Passed invalid arguments: object of type 'ConstructorError' has no len()
otherwise they are the same. i get errors about database already exist but that makes sense because im rerunning the sosetup.
not sure if it helps but when the sosetup gets to "Configuring elsa" it takes almost 5 hours to complete. has lots of "indexing index 'perm' and 'temps'
also i waited 10 min after a reboot and still shows all services as fail...
user@sensor:/var/log/nsm$ sudo service nsm status
Status: HIDS
* ossec_agent (sguil) [ FAIL ]
Status: Bro
Name Type Host Status Pid Peers Started
manager manager x.x.x.x running 4499 3 29 Jan 16:25:02
proxy proxy x.x.x.x running 4655 3 29 Jan 16:25:05
sensor-eth1-1 worker x.x.x.x running 4808 2 29 Jan 16:25:07
sensor-eth2-1 worker 1x.x.x.x running 4969 2 29 Jan 16:25:09
Status: sensor-eth1
* netsniff-ng (full packet data) [ FAIL ]
* pcap_agent (sguil) [ FAIL ]
* snort_agent-1 (sguil) [ FAIL ]
* snort-1 (alert data) [ FAIL ]
* barnyard2-1 (spooler, unified2 format) [ FAIL ]
Status: sensor-eth2
* netsniff-ng (full packet data) [ FAIL ]
* pcap_agent (sguil) [ FAIL ]
* snort_agent-1 (sguil) [ FAIL ]
* snort-1 (alert data) [ FAIL ]
* barnyard2-1 (spooler, unified2 format) [ FAIL ]
Thanks for the help!
On Thursday, 29 January 2015 10:59:07 UTC-5, Doug Burks wrote:
> Hi Grant,
>
> Replies inline.