[Bro] Cluster minimal logs on manager

Jamie Saker cosmotraumatika at gmail.com
Tue Mar 22 11:14:20 PDT 2016

After upgrading/reinstalling the OS on my Bro manager, with a network of a dozen workers, I’ve managed to end up where I’m only seeing minimal logs at the manager (the manager is also the sole proxy):


When I run Bro standalone on one of the sensors, all is well again.  I’ve exchanged the keys so that Bro can manage the workers just fine but apparently the logging isn’t being communicated correctly. Any recommendations other than rebuilding sensors from the OS up? I also know the sensors are seeing good traffic - Snort runs just fine on a tested sensor along with tcpdump, etc. 

Thanks - 


