# Going from standalone to Bro cluster error

**URL:** <https://community.zeek.org/t/going-from-standalone-to-bro-cluster-error/4424>\
**Category:** Zeek\
**Created:** [October 20, 2016, 3:41pm UTC](https://community.zeek.org/t/going-from-standalone-to-bro-cluster-error/4424 "2016-10-20T15:41:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Hacecky](https://avatars.discourse-cdn.com/v4/letter/e/ccd318/32.png) [@Eric\_Hacecky](https://community.zeek.org/u/Eric_Hacecky)\
**Post date:** [October 20, 2016, 3:41pm UTC](https://community.zeek.org/t/going-from-standalone-to-bro-cluster-error/4424/1 "2016-10-20T15:41:40Z")

</div>

I'm in the process of converting my Bro installs from standalone instances to a Bro Cluster.

The previous standalone Bro instance/server I'm using for testing is not able to be updated by the manager when I list it as a worker node.

I have the following 3 machines:

manager - New Bro install. version 2.5-beta-79 (rhel7 python 2.7.5)  
worker1 - New Bro install. version 2.5-beta-79 (rhel7 python 2.7.5)  
worker2 - Previous standalone Bro instance. version 2.4 \<---- Notice the version differs, does worker2 need to run the same version as the manager? (rhel6 python 2.6.6)

Everything works between manager and worker1.

Here is the output from broctl when worker2 is listed in node.cfg.

//  
[BroControl] \> check  
manager scripts are ok.  
proxy-1 scripts are ok.  
worker-1 scripts are ok.  
worker-2 scripts are ok.

[BroControl] \> install  
removing old policies in /usr/local/bro/spool/installed-scripts-do-not-touch/site ...  
removing old policies in /usr/local/bro/spool/installed-scripts-do-not-touch/auto ...  
creating policy directories ...  
installing site policies ...  
generating cluster-layout.bro ...  
generating local-networks.bro ...  
generating broctl-config.bro ...  
generating broctl-config.sh ...  
updating nodes ...  
sh: line 1: /bin/python: No such file or directory  
sh: line 2: [/bin/echo,: No such file or directory  
sh: line 3: syntax error near unexpected token `done'  
sh: line 3: `done'  
Error: cannot create a directory on node worker-2  
Error: Failed to establish ssh connection to host \<redacted IP for worker2\>  
//

ssh keys are working as intended. Even though the error says, "failed to establish ssh connection on host" I can see manager login on worker2 as the root user via ssh in secure log.

/bin/python is 2.6.6 and is in root's path. Everything in question is owned by root.

Any ideas?

Thanks,  
Eric

---

<div class="post-metadata">

**Author:** ![Daniel\_Thayer](https://avatars.discourse-cdn.com/v4/letter/d/8dc957/32.png) [@Daniel\_Thayer](https://community.zeek.org/u/Daniel_Thayer)\
**Post date:** [October 20, 2016, 4:15pm UTC](https://community.zeek.org/t/going-from-standalone-to-bro-cluster-error/4424/2 "2016-10-20T16:15:05Z")

</div>

All of the machines in a Bro cluster must be running the same OS  
version, because when you run "broctl install" (or "broctl deploy"),  
broctl will copy the bro installation (the executables and scripts)  
from the manager to all of the other machines in your cluster.  
This ensures that all machines in the cluster run the same version  
of Bro with the same configuration.

If you had previously built and installed Bro on worker-2, then  
it would just get overwritten by broctl.

---

<div class="post-metadata">

**Author:** ![Eric\_Hacecky](https://avatars.discourse-cdn.com/v4/letter/e/ccd318/32.png) [@Eric\_Hacecky](https://community.zeek.org/u/Eric_Hacecky)\
**Post date:** [October 20, 2016, 4:39pm UTC](https://community.zeek.org/t/going-from-standalone-to-bro-cluster-error/4424/3 "2016-10-20T16:39:10Z")

</div>

Makes sense. Thanks Daniel.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/going-from-standalone-to-bro-cluster-error/4424/4 "2022-05-06T15:44:10Z")

</div>


