Morpheus Posted 1 hour ago Report Posted 1 hour ago Complete Host Recovery and Remote Node Reconnection Procedure WinSuricata includes a Host Recovery and Node Recovery system designed to simplify recovery of a centralized WinSuricata Host without requiring every Remote Node to be manually rebuilt or individually re-registered. This is particularly important in larger deployments. A Host may have dozens or more Remote Nodes communicating with it. If the Host experiences a system failure, system restore, disk replacement, PKI corruption, or another event that requires restoration of the Host environment, rebuilding the Host is only part of the recovery process. The more significant problem can occur afterward: Previously deployed Remote Nodes may no longer be able to authenticate to the recovered Host. Without a centralized recovery mechanism, an administrator could be forced to generate a new authentication package for every Remote Node, transfer those packages individually, and perform a reconnection procedure on every sensor. This could be extremely time-consuming in a larger deployment. WinSuricata's Host Recovery and Node Recovery system was designed specifically to eliminate that process. BEFORE USING NODE RECOVERY There is a Host Recovery Package Detected - Recover Nodes button in the WinSuricata Host Manager. Follow these instructions and the button will activate. If you have launched Cleanup & Restore from the WinSuricata Host Manager, the computer has been returned to a state before WinSuricata was installed. The WinSuricata Host must therefore be fully reinstalled before Node Recovery can be performed. 1. Confirm the WinSuricata Host Is Operational Before starting Node Recovery, confirm that: The WinSuricata Host has been fully reinstalled. The WinSuricata Host Manager can be accessed normally from the Desktop shortcut. The Host has network connectivity so the Remote Nodes can connect. Do not begin Remote Node recovery until the Host itself is operational. PROTECT THE HOST RECOVERY FILE The Host Recovery archive is critical to recovering previously registered Remote Nodes. After every Remote Node is added, WinSuricata archives the complete recovery files into: $WinIDSRoot\Backup using the following format: <date>-HostRecovery.zip For example: D:\WinSuricata\Backup\2026-10-03-HostRecovery.zip Keep an Additional Up-To-Date Copy Off the Host Do not rely solely on the copy stored on the WinSuricata Host. If the Host suffers a catastrophic disk failure, storage failure, or complete system loss, a recovery archive stored on that same system may also be lost. Maintain a current copy of the HostRecovery ZIP in a secure location outside the WinSuricata Host. The off-system copy should be protected against unauthorized access because the recovery package contains sensitive Host and Remote Node recovery information. The external copy should be updated whenever the Host Recovery archive changes so that it represents the current Remote Node deployment. The goal is to ensure that a catastrophic Host failure does not also destroy the information required to recover the Remote Nodes. USING THE HOST RECOVERY PACKAGE DETECTED - RECOVER NODES BUTTON Once the WinSuricata Host has been restored and is fully operational, the current Host Recovery archive must be placed in the Host's Temp folder using the required filename. 1. Prepare the Host Recovery Package Locate the most recent Host Recovery archive in: $WinIDSRoot\Backup The file will use the following naming format: <date>-HostRecovery.zip Copy the current recovery archive to: $WinIDSRoot\Temp Rename the copied file to: HostRecovery.zip The final location and filename must be: $WinIDSRoot\Temp\HostRecovery.zip Do not extract the ZIP file. The WinSuricata Host Manager is looking for the recovery package using this exact filename and location. 2. Open the WinSuricata Management Console Launch the WinSuricata Management Console from the desktop shortcut. Once the Host Recovery package is detected, the following button will become available: Host Recovery Package Detected - Recover Nodes Left-click the button to begin the Remote Node recovery process. If the Button Is Not Displayed If the Host Recovery Package Detected - Recover Nodes button is not displayed, verify that: The file exists in $WinIDSRoot\Temp The filename is exactly HostRecovery.zip The file has not been extracted. The ZIP file is located directly in the $WinIDSRoot\Temp folder The WinSuricata Host Manager has been restarted after placing the file in the Temp folder so that the recovery package can be detected. Do not rename the file to the original <date>-HostRecovery.zip name in the Temp folder. The file must be named exactly HostRecovery.zip for the recovery function to detect it. 3. Start Node Recovery Once the Host Recovery Package Detected - Recover Nodes button is available, left-click the button. The recovery process restores the Host-side information required for the previously registered Remote Nodes, including their registration and authentication information. The Remote Nodes are processed as a bulk recovery operation. For large deployments, the Node Recovery process is designed to process 100+ Remote Nodes in less than one minute under normal operating conditions. Do not manually rebuild or re-register the Remote Nodes while the recovery process is running. Allow the recovery process to complete before beginning any individual Remote Node troubleshooting. AFTER RESTORE NODES COMPLETES When the Restore Nodes process finishes, allow the recovered Remote Nodes time to reconnect to the Host. 1. Verify the Remote Nodes in EveBox Open the EveBox console. As each Remote Node reconnects, it will register in the Sensors drop-down list. The number of connected Remote Nodes will also be reflected in the Dashboard Overview section. The recovered nodes should retain their previously established Host Node Alias. 2. Verify Remote Node Telemetry In EveBox, open the Sensors drop-down and select a recovered Remote Node. Verify that events from the selected node are being received by the Host. The recovered Remote Node should begin reporting telemetry normally once its connection to the Host has been re-established. Repeat this verification with additional Remote Nodes as necessary. 3. Allow Time for All Nodes to Reconnect If a large number of Remote Nodes are being recovered, allow sufficient time for the individual sensors to reconnect and begin sending telemetry. Do not immediately begin reinstalling Remote Nodes simply because they do not appear immediately. First confirm that the bulk Node Recovery completed successfully and allow the Remote Nodes time to reconnect. IF A NODE DOES NOT RECONNECT If one or more Remote Nodes remain offline after the Host recovery: Confirm that the Host is operational. Confirm that the Remote Node appears in the recovered Host registration information. Confirm network connectivity between the Host and the Remote Node. Check the affected Remote Node. Restart the WinIDS-EveBoxAgent service on the affected Remote Node. Allow the node time to reconnect. If the node still does not reconnect, troubleshoot that individual node. In some cases, an individual Remote Node may require a new Node package from the Host to be reapplied to that node. This should only be necessary for the affected Remote Node and does not require rebuilding the entire Remote Node deployment. The purpose of bulk Node Recovery is to restore the Host-side registration and authentication environment for the previously deployed Remote Nodes as a single recovery operation. NEW REMOTE NODES The Restore Nodes function is for Remote Nodes that were previously registered with the Host. A new Remote Node that has never been registered must still be deployed using the normal WinSuricata Remote Node installation and registration procedure. Restore Nodes is a recovery function, not the initial Remote Node deployment process. RECOVERY BEST PRACTICE For every WinSuricata Host: Keep the current <date>-HostRecovery.zip both on the Host and in a secure off-system location. The local copy provides convenient access during normal Host recovery. The secure off-system copy protects the deployment against a catastrophic failure in which the WinSuricata Host and its local storage are no longer available. This recovery archive is what allows WinSuricata to restore a large Remote Node deployment without requiring the administrator to manually recreate the registration and authentication information for every sensor. The WinSuricata Recovery Workflow 1. Recover or reinstall the WinSuricata Host. 2. Confirm the Host is operational. 3. Copy the current <date>-HostRecovery.zip to $WinIDSRoot\Temp. 4. Rename the file to HostRecovery.zip. 5. Open the WinSuricata Management Console. 6. Select Host Recovery Package Detected - Recover Nodes. 7. Allow the bulk Node Recovery process to complete. 8. Open EveBox and verify the recovered Remote Nodes. 9. Verify Remote Node telemetry. 10. Troubleshoot only individual nodes that fail to reconnect. This is the intended WinSuricata Host Recovery and Bulk Remote Node Recovery workflow.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now