Security Onion 2.4.30, Zeek 6.0.2, and single IPv4 address in $HOME_NET
If Zeek on your forward node (sensor) keeps restarting and its detailed status never changes from “health: starting,” to simply “healthy,” have a look at zeek.config.networks.HOME_NET
in the Grid Configuration.
In my case I had specified a single IPv4 address among six other larger address blocks. Changing this address to a /31 address block made all the difference. I could probably have specified the address as a /32, but leaving it as /31 clearly single out the two relevant link net addresses.