Elasticsearch status pending/Kibana 404 after update to 2.4.70 #13128
Replies: 2 comments
-
This morning the Elasticsearch status has changed to OK, but Kibana, Elastic Fleet, etc, still give a 404 error. The so-kibana container shows that it's running. Not sure what else I can do here. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Would check these logs for any issues:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.70
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
24
RAM
192
Storage for /
1 TB
Storage for /nsm
40 TB
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
I came in this morning to find Security Onion no longer able to show alerts. All of my nodes had a status of "Restart", which indicated that they were pending a restart. It looked as though some kind of automatic update had tried to apply itself over the weekend. After rebooting the SO nodes, the Forward node did not show up in the grid. After troubleshooting and looking through logs, I didn't see anything that stood out so I figured I'd try running soup to see if there was an update that didn't complete correctly or something along those lines. Soup upgraded my SO from 2.4.60 to 2.4.70. After the upgrade, the forward node appeared in my grid again with all services up and available. However, the manager node has a persistent status of:
Elasticsearch status: Pending
Also, Kibana will not open. Attempting to do so returns a 404 error.
Running a salt highstate also returns errors. There appears to be some kind of communication error. Salt highstate errors are as follows:
I really don't want to have to re-install Security Onion yet again. Any help is very much appreciated. Thanks.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions