You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
No, one or more services are failed (please provide detail below)
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
Installation
Security Onion
Confirmed ISO download
securityonion-2.4.211-20260407.iso
Host Machine
Windows 11 Home
13th Gen Intel® Core™ i9-13980HX
32GB RAM
8GB Graphics card
SSD
VirtualBox 7.2.4
New virtual machine
VM Name: Security Onion 2.x
VM Folder:
ISO Image: securityonion-2.4.211-20260407.iso
OS Edition
OS: Linux
OS Distribution: Ubuntu
OS Version: Ubuntu (64-bit)
Set up unattended guest OS installation
Specify virtual hardware
Base Memory: 16GB (16384MB)
Number of CPUs: 4
Specify virtual hard disk
Create a New Virtual Hard Disk
Disk Size: 200GB
Settings
General
Features
Shared Clipboard: Bidirectional
Display
Screen
Video Memory: 128MB
Network
Adapter 1
Attach to: NAT
Adapter 2
Attach to: Internal Network
Name: intnet
Power On
Do you wish to continue? (Type the entire word ‘yes’ to proceed.): yes
Username:
Password:
Initial Install Complete. Press [Enter] to reboot?:
After reboot
Login with username and password
Would you like to continue: yes
Select an option: Install
What kind of installation would you like to do: EVAL
Type agree to accept terms: AGREE
How should this mode be install: Standard
Enter the hostname: so-eval
Please enter the NIC for management:
Choose how to set up your management interface: DHCP
Select YES to keep DHCP or NO to go back: Yes
How would you like to connect to the internet? Direct
Do you want to keep the default Docker IP range? Yes
Please add NICs to the Monitor interface
Please enter an email address to create an administrator:
Enter a password:
How would you like to access the web interface? IP
Do you want to allow access to this Security Onion …via the web interface? Yes
Enter a single IP address or an IP range: 10.0.2.0/24 NAT IPv4 Prefix
Enable SOC Telemetry to help improve future versions? No
Options screen, Press the TAB key to select yes or no: Yes
Progress seems to occur….
After “2026-08-31T14:40:39Z | INFO | Executing command: salt-key -yd so-eval_eval”
Message: “The key glob ‘so-eval’ does not match any unaccepted keys.”
After a while (> 15 minutes) progress seems to occur…
There are messages about, “kernel watchdog: BUG: soft lockup – CPU stuck for …”
But progress seems to continue…
Later after message, “[INFO ] Executing state docker container running for [so-kibana]”
Message: “kernel:BUG: workqueue lockup – pool cpus=3 node=0 flags=0x0 …”
But progress seems to continue…
After 4 hours, I get a pop up window that says….
Install had a problem. Please see /root/sosetup.log for details
A summary of errors can be found in /root/errors.log
Select Ok to exit
And there is an “Ok” button.
However, messages continue to be sent to the screen especially the “BUG: soft lockup….” Messages
The last bit of the errors.log file are
Failed to complete a chunk of bulk package installs -- /tmp/esfleet_bulk_install_11.json
[ERROR ] Encountered StreamClosedException
[ERROR ] Job highstate_schedule already exists in schedule.
[ERROR ] An exception occurred in this state: Traceback (most recent call last):
[ERROR ] An exception occurred in this state: Traceback (most recent call last):
[ERROR ] (‘image’: (‘Time_Elapsed’: 0.1256….., ‘retcode’: 0, ‘Status’: ‘Image is up to date for so-eval:5000/security-onion-solutions/so-stelka-backend:2.4.211’))
Result: False
Result: False
Result: False
Result: False
sudo securityonion-status command not found
I don’t get to a desktop, so I can’t check to see if the browser access will work
I am stuck.
Guidelines
I have read the discussion guidelines at Read before posting! #1720 and assert that I have followed the guidelines.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Version
2.4.211
Installation Method
Security Onion ISO image
Description
installation
Installation Type
Eval
Location
other (please provide detail below)
Hardware Specs
Exceeds minimum requirements
CPU
4
RAM
16
Storage for /
200GB
Storage for /nsm
?
Network Traffic Collection
other (please provide detail below)
Network Traffic Speeds
Less than 1Gbps
Status
No, one or more services are failed (please provide detail below)
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
Installation
Security Onion
Confirmed ISO download
securityonion-2.4.211-20260407.iso
Host Machine
Windows 11 Home
13th Gen Intel® Core™ i9-13980HX
32GB RAM
8GB Graphics card
SSD
VirtualBox 7.2.4
New virtual machine
VM Name: Security Onion 2.x
VM Folder:
ISO Image: securityonion-2.4.211-20260407.iso
OS Edition
OS: Linux
OS Distribution: Ubuntu
OS Version: Ubuntu (64-bit)
Set up unattended guest OS installation
Specify virtual hardware
Base Memory: 16GB (16384MB)
Number of CPUs: 4
Specify virtual hard disk
Create a New Virtual Hard Disk
Disk Size: 200GB
Settings
General
Features
Shared Clipboard: Bidirectional
Display
Screen
Video Memory: 128MB
Network
Adapter 1
Attach to: NAT
Adapter 2
Attach to: Internal Network
Name: intnet
Power On
Do you wish to continue? (Type the entire word ‘yes’ to proceed.): yes
Username:
Password:
Initial Install Complete. Press [Enter] to reboot?:
After reboot
Login with username and password
Would you like to continue: yes
Select an option: Install
What kind of installation would you like to do: EVAL
Type agree to accept terms: AGREE
How should this mode be install: Standard
Enter the hostname: so-eval
Please enter the NIC for management:
Choose how to set up your management interface: DHCP
Select YES to keep DHCP or NO to go back: Yes
How would you like to connect to the internet? Direct
Do you want to keep the default Docker IP range? Yes
Please add NICs to the Monitor interface
Please enter an email address to create an administrator:
Enter a password:
How would you like to access the web interface? IP
Do you want to allow access to this Security Onion …via the web interface? Yes
Enter a single IP address or an IP range: 10.0.2.0/24 NAT IPv4 Prefix
Enable SOC Telemetry to help improve future versions? No
Options screen, Press the TAB key to select yes or no: Yes
Progress seems to occur….
After “2026-08-31T14:40:39Z | INFO | Executing command: salt-key -yd so-eval_eval”
Message: “The key glob ‘so-eval’ does not match any unaccepted keys.”
After a while (> 15 minutes) progress seems to occur…
There are messages about, “kernel watchdog: BUG: soft lockup – CPU stuck for …”
But progress seems to continue…
Later after message, “[INFO ] Executing state docker container running for [so-kibana]”
Message: “kernel:BUG: workqueue lockup – pool cpus=3 node=0 flags=0x0 …”
But progress seems to continue…
After 4 hours, I get a pop up window that says….
Install had a problem. Please see /root/sosetup.log for details
A summary of errors can be found in /root/errors.log
Select Ok to exit
And there is an “Ok” button.
However, messages continue to be sent to the screen especially the “BUG: soft lockup….” Messages
The last bit of the errors.log file are
Failed to complete a chunk of bulk package installs -- /tmp/esfleet_bulk_install_11.json
[ERROR ] Encountered StreamClosedException
[ERROR ] Job highstate_schedule already exists in schedule.
[ERROR ] An exception occurred in this state: Traceback (most recent call last):
[ERROR ] An exception occurred in this state: Traceback (most recent call last):
[ERROR ] (‘image’: (‘Time_Elapsed’: 0.1256….., ‘retcode’: 0, ‘Status’: ‘Image is up to date for so-eval:5000/security-onion-solutions/so-stelka-backend:2.4.211’))
Result: False
Result: False
Result: False
Result: False
sudo securityonion-status command not found
I don’t get to a desktop, so I can’t check to see if the browser access will work
I am stuck.
Guidelines
All reactions