SecurityOnion Azure Market Place Image Zeek & Salt clash on GID #15285
-
Version2.4.190 Installation MethodCloud image (Amazon, Azure, Google) Descriptionconfiguration Installation TypeStandalone Locationcloud Hardware SpecsMeets minimum requirements CPU8 RAM32 Storage for /472 Storage for /nsm0 Network Traffic Collectionother (please provide detail below) Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailI am setting up SO on Azure via the Azure Marketplace image. The setup config wizard pops up, and I complete all the fields that are needed. When the last screen pops up with all the details I selected, and I say "yes". It kicks off the configuration setup of the SO server. It runs through the config for about 30 min, then it hits the following error. [ERROR ] Group zeek is not present, but gid 937 is already taken by group salt I need help to understand how to resolve this. I ran a test before on a test lab running Proxmox and the downloaded ISO, and it went smoothly without errors. However, when I select the Azure Marketplace Image and deploy it via an Azure VM, I hit a snag that Salt is using the gid that the Group Zeek where expecting. Is there a way to assign a new gid for zeek and let it carry on from where it stopped? If I rerun sudo /securityonion/setup/so-setup iso it seems not to clear what it has done, and I have to reload the Azure image. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
-
|
Thanks for reporting this. Our automated testing discovered this last week (possibly caused by recent upstream OS package updates), and we made a change for the next release that attempts to avoid the problem. We're still reviewing new test results, as this appears to be somewhat intermittent. |
Beta Was this translation helpful? Give feedback.
-
|
Thank you for the update. When is the next release planned or scheduled for Azure Marketplace? In the meantime, can I download the standard ISO and try that on an Azure VM? |
Beta Was this translation helpful? Give feedback.
-
|
I don't have a date for the next release, however, you can use the following workaround to get the Azure image up and running:
Thanks again for raising the issue. |
Beta Was this translation helpful? Give feedback.
Thanks for reporting this. Our automated testing discovered this last week (possibly caused by recent upstream OS package updates), and we made a change for the next release that attempts to avoid the problem. We're still reviewing new test results, as this appears to be somewhat intermittent.