Sheldon Carmichael
unread,Jul 25, 2018, 11:35:43 AM7/25/18Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to security-onion
I have a Master Node & 2 Heavy Nodes. Master/Heavy at one site and 2nd Heavy at another site.
My Master & Heavy at the main site have been experiencing the errors below for the past few weeks when running SOUP. The Heavy Node at the 2nd location doesn't have the same issue. I saw it was using a cached timestamp, so I figured maybe it was a time issue.
After reviewing some network firewall logs, I noticed external NTP traffic was getting dropped from the Master/Heavy at the main site, but not from the Heavy at the 2nd site. So, I went ahead and just configured them all to talk to our internal NTP servers using /etc/ntp.conf. I also restarted the ntp.service and validated the changes took effect using ntpq -p. But, this doesn't seem to fix the issue and it is still occurring.
Any ideas? Am I even remotely on the right track? I know it also says I am not authorized to perform this operation, but I don't know where to begin with that.
Thanks in advance for the help.
================Error During SOUP===================
Starting Docker service...
Checking Security Onion Docker image status...
WARN[0005] Error while downloading remote metadata, using cached timestamp - this might not be the latest version available remotely
ERRO[0005] Metadata for timestamp expired
you are not authorized to perform this operation: server returned 401.
so-curator has been updated.
WARN[0010] Error while downloading remote metadata, using cached timestamp - this might not be the latest version available remotely
ERRO[0010] Metadata for timestamp expired
you are not authorized to perform this operation: server returned 401.
so-domainstats has been updated.
WARN[0010] Error while downloading remote metadata, using cached timestamp - this might not be the latest version available remotely
ERRO[0010] Metadata for timestamp expired
you are not authorized to perform this operation: server returned 401.
so-elastalert has been updated.
WARN[0010] Error while downloading remote metadata, using cached timestamp - this might not be the latest version available remotely
ERRO[0010] Metadata for timestamp expired
you are not authorized to perform this operation: server returned 401.
so-elasticsearch has been updated.
WARN[0010] Error while downloading remote metadata, using cached timestamp - this might not be the latest version available remotely
ERRO[0010] Metadata for timestamp expired
you are not authorized to perform this operation: server returned 401.
so-freqserver has been updated.
WARN[0010] Error while downloading remote metadata, using cached timestamp - this might not be the latest version available remotely
ERRO[0010] Metadata for timestamp expired
you are not authorized to perform this operation: server returned 401.
so-kibana has been updated.
WARN[0010] Error while downloading remote metadata, using cached timestamp - this might not be the latest version available remotely
ERRO[0010] Metadata for timestamp expired
you are not authorized to perform this operation: server returned 401.
so-logstash has been updated.