Start a new topic

Specific host keeps not being enrolled in Sandfly - troubleshooting tips ?

Hi to the Sandfly community,


There is a host running Oracle Linux 9.6 that I can't get added to the list of systems to be scanned (nb: the setting is a  small home lab ).


In the past, I could enroll various systems on Ubuntu, Debian and Oracle Linux (OL) as well but this ones keeps failing. Other Linux boxes could be added without any issue.


Regarding that specific host, it was possible to note that :

- the system hosting Sandfly can ssh into the OL sysem ;

- on the network, ssh traffic and connection can be seen when the OL host is added to Sandfly (no fw issue) ;

- several attempts to add the host all failed.


Sandfly is the latest version, and I am wondering please if there are are tips / checks to troubleshoot that kind of situation - many thanks.


Alex

1 Comment

Hi Alexandre P.,


The first question would be what does the Scanning Error Log say when attempting to add or scan that Oracle Linux 9.6 host?

Additionally, are you able to add other OL 9.6 hosts or is this the one and only OL 9.6 host with this problem?

Also, if that OL host with the issue is a VM clone of another VM that is also added into Sandfly, did you change its Machine ID, UUIDs, etc. to ensure that it has a unique set of identifiers? If not Sandfly could be detecting it as the original VM, which potentially can cause host conflicts should both VMs are (or trying to be) in Sandfly.


We hope that this information will help to resolve this issue. If not, please send the messages from the scanning error log along with any new information.



- Steve Busko


Head of Customer Service and Support (CSS)


Sandfly Security - https://www.sandflysecurity.com/

Follow us at:

Reddit - https://www.reddit.com/r/SandflySecurity/

Twitter - https://twitter.com/sandflysecurity

Login or Signup to post a comment