2.4.40 Integrations Index Templates not showing in Kibana. #12215
-
Version2.4.40 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM64 GB Storage for /315 GB Storage for /nsm8.5 TB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailAfter updating to 2.4.40, we are not seeing the index templates for the newest integrations show in Kibana, or the integration showing under the "installed" section from Kibana. From previous releases, we usually see newly added integrations under the "installed" section, and all of the integration index templates/component templates are present. After the upgrade to 2.4.40, the templates for the newly supported integrations, cisco_ftd, cisco_ios, iis, etc, are not present when looking in stack management from Kibana, nor are they "installed" when looking at integrations from Kibana. We do see the all index settings for these new integrations in the SOC console under Administration > Configuration > index_settings > $index (eg., so-logs-cisco_ftd_x_log). Will this cause a problem if we start trying to use the 2.4.40 newly supported integrations without the index/component templates being present in stack management? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Do you see eaintegrations.txt present if you look in /opt/so/state on the manager? If so, try the following: sudo rm -f /opt/so/state/eaintegrations.txt |
Beta Was this translation helpful? Give feedback.
Do you see eaintegrations.txt present if you look in /opt/so/state on the manager?
If so, try the following:
sudo rm -f /opt/so/state/eaintegrations.txt
sudo salt-call state.apply elasticfleet