Replies: 3 comments
-
From SOC go to grid then click the drop down icon next to your standalone node and look at the 'Elasticsearch Status:' Does it also show as 'OK'? |
Beta Was this translation helpful? Give feedback.
-
Yes, all services or dockers are running and green.
-----------------------------------+---------+----------------------- ? This onion is ready to make your adversaries cry! |
Beta Was this translation helpful? Give feedback.
-
I resolved this by putting the elasticsearch docker ip address in the rule. Thanks, |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.50
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
8
RAM
384GB
Storage for /
2.5TB
Storage for /nsm
1.5TB
Network Traffic Collection
span port
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
After a fresh bare metal install of 2.4.50 I receive an error when I run so-elastalert-test. The test is successful but fails to connect to the elastalert docker. It looks like a DNS issue but I don't know.
Error running your filter:
ConnectionError('N/A', "HTTPSConnectionPool(host='security-onion', port=9200): Max retries exceeded with url: /%3Aso-ids-/_search?ignore_unavailable=true&size=1 (Caused by NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7f0d4b611c90>: Failed to establish a new connection: [Errno -2] Name or service not known'))", ConnectionError(MaxRetryError("HTTPSConnectionPool(host='security-onion', port=9200): Max retries exceeded with url: /%3Aso-ids-/_search?ignore_unavailable=true&size=1 (Caused by NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7f0d4b611c90>: Failed to establish a new connection: [Errno -2] Name or service not known'))")))
Any help is appreciated the elastalert rule worked before a fresh install.
TIA,
Chris
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions