-
Version2.4.40 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU60 RAM128 Storage for /256 Storage for /nsm256 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusYes, there are salt failures (please provide detail below) LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailHello again! I am once again asking for you guys to descend some knowledge down upon me. My SO-Elastalert container has gone missing. I have been fighting it for some time now, it happens almost after every reboot. But generally just asking it to restart, or .old-ing some of my elastalert rules fixes it. But this time, I have .old-ed all my rules. And have asked it to restart a great many times. I am met with this response when running sudo so-elastalert-restart: It counts all the way up to 300 then:
Summary for local Running a high state provides just: The elastalert.log in /opt/so/log is empty. For my elastalert rules, I have most contained within the playbook folder. I have one contained outside of the playbook folder. Not sure if that matters for anything. Really appreciate any kind of help or guidance on this issue! Thanks again! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 11 replies
-
Check your Elasticsearch log - |
Beta Was this translation helpful? Give feedback.
check heap memory config