Installation verification error #12167
Replies: 1 comment
-
What is the output of Standalone install minimum specs call for 200GB storage space available. https://docs.securityonion.net/en/2.4/hardware.html#minimum-specs |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.30
Installation Method
Security Onion ISO image
Description
installation
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
8
RAM
32
Storage for /
65
Storage for /nsm
125
Network Traffic Collection
span port
Detail
VMware 16.0 both interfaces bridged to NICs
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Details
sudo cat /root/errors.log
[MIRROR] kernel-core-5.14.0-362.13.1.el9_3.x86_64.rpm: Curl error (92): Stream error in the HTTP/2 framing layer for https://repo.securityonion.net/file/so-repo/prod/2.4/oracle/9/kernel-core-5.14.0-362.13.1.el9_3.x86_64.rpm [HTTP/2 stream 0 was not closed cleanly: INTERNAL_ERROR (err 2)] {"statusCode":500,"error":"Internal Server Error","message":"runtime_exception\n\tCaused by:\n\t\tno_shard_available_action_exception: index [metrics-endpoint.metadata_current_default] has no active shard copy\n\tRoot causes:\n\t\truntime_exception: Failed to deduce dest mappings"}
$ grep "error" /opt/so/log/elasticsearch/securityonion.log
[2024-01-12T05:18:31,578][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-occurrences-monthly-aligned] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:31,578][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-occurrences-30d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:31,578][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-timeslices-monthly-aligned] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:31,734][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-timeslices-30d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:31,937][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-occurrences-7d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:32,286][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-timeslices-7d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:32,460][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-occurrences-90d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:32,625][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-timeslices-weekly-aligned] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:32,806][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-occurrences-weekly-aligned] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:32,973][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-timeslices-90d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [so@so ~]$ [so@so ~]$ grep "error" /opt/so/log/elasticsearch/securityonion.log [2024-01-12T05:18:31,578][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-occurrences-monthly-aligned] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:31,578][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-occurrences-30d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:31,578][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-timeslices-monthly-aligned] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1] [2024-01-12T05:18:31,734][INFO ][org.elasticsearch.xpack.transform.transforms.TransformFailureHandler] [slo-summary-timeslices-30d-rolling] Transform encountered an exception: [Failed to execute phase [query], ; org.elasticsearch.action.search.SearchPhaseExecutionException: Search rejected due to missing shards [[.slo-observability.sli-v2][0]]. Consider using
allow_partial_search_resultssetting to bypass this error.]; Will automatically retry [1/-1]_search_results
setting`Guidelines
Beta Was this translation helpful? Give feedback.
All reactions