I have noticed this week that I am seeing a LOT of traffic between our EOC server and one of the Orion sites.
I currently have 4 Orions feeding into our EOC server. I noticed on our local Orion server that the top conversation/end points has been between our EOC and one of the remote Orions.
What is interesting (and I might not understand this) is that in NetFlow it shows the conversations using ports other than 17777. I was under the impression that EOC would use only 17777. I am seeing ports like 2197, 1541, 1182, 2898.
When I do a netstat -b and look for the remote Orion server I see it listed like
TCP EOCservername:2898 Orionservername:17777 ESTABLISHED 5092
It might be that the ports reflected by NetFlow are local random ports but I don't understand why I am seeing so much traffic between these servers. The remote Orion in question only has 1 node that I am monitoring.
Thoughts?