Replies: 3 comments
-
yo mate hope all is good, yesterday i faced the same issue while adding rules in elastalert, under good luck |
Beta Was this translation helpful? Give feedback.
-
i faced this issue when create a miss configured rule and restart the so-elastalert , please check if you have any suspesious rule |
Beta Was this translation helpful? Give feedback.
-
Thanks for the hints. It had to do with misconfigured rules, but not elastalert rules (I've got no custom elastalert rules for now), but there seems to be a problem with my custom suricata rules. Commented out all of them and the elastalert error was gone :-). |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.80
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
10
RAM
32GB
Storage for /
500GB
Storage for /nsm
500GB
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
No, one or more services are failed (please provide detail below)
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
Hi,
After rebooting my 2.4.80 cluster because OS-Updates had been installed requiring a reboot (status for all nodes was "Reboot") I ended up with the manager node going to "Fault".
Already tried rebooting the manager node several times - didn't help.
so-elastalert-restart
didn't solve the problem either: ran for several minutes and ended up withRunning
sudo so-elasticsearch-query _cluster/health?pretty
givesAny ideas as to what's wrong here and how I can get my system back running again?
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions