[Bro] - broctl running, no new logs

william de ping bill.de.ping at gmail.com
Wed Jun 6 01:23:20 PDT 2018


Hi everyone,

I have a cluster setup for bro 2.5.
After a while, broctl shows all instances are running (workers,proxies and
manager) , yet no new log files are written to spool/manager.

broctl cron is enabled, and when I tried to run broctl print
Drop::drop_info I get :
manager   Drop::drop_info = <unknown id>
worker-0-2   <error: cannot connect to 127.0.0.1:1234>

any thoughts on the reason for that ?
how can I recover from this besides restarting in response to monitoring
new log files ?

Thank you
B
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20180606/9a2b794d/attachment.html 


More information about the Bro mailing list