-
Version2.4.40 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU32 RAM64 GB Storage for /320GB Storage for /nsm1.8 TB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailI have recently upgraded from 2.4.30 to 2.4.40 after a recent reboot of the grid. The elastalert container is showing up as missing. We do not have any customer elastalert rules. When examine the logs for elastalert I find nothing as far as errors. Any suggestions where I should look would be appreciated. When I run so-elastalert-restart I get 2 highstate errors from salt: Executing sudo docker images returns Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 4 replies
-
What does |
Beta Was this translation helpful? Give feedback.
-
So I was able to get things back up and running. I kind of went a bit heavy handed and disabled all my playbook detections. I rebooted the search node and the container spun up on the manager and problem solved. I did not reboot my manager node. I had run into a similar issue before with experimental rules in the past so I decided to disable them. So, I am wondering was the issue of the container not starting up and timing out due to the search node rather than issue with a rule? |
Beta Was this translation helpful? Give feedback.
So I was able to get things back up and running. I kind of went a bit heavy handed and disabled all my playbook detections. I rebooted the search node and the container spun up on the manager and problem solved. I did not reboot my manager node. I had run into a similar issue before with experimental rules in the past so I decided to disable them. So, I am wondering was the issue of the container not starting up and timing out due to the search node rather than issue with a rule?