-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 GB Storage for /130 GB Storage for /nsm270 GB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailAfter upgrade to 2.4.100 link to open Kibana is showing "404 page not found" error despite showing healthy status in Grid. Possibly related to the other discussion about Kibana but I don't have any unassigned Elastic shards so not certain. "sudo so-status" shows all healthy. "sudo salt-call state.highstate" produces this error:
"sudo so-checkin" shows 4 failures:
Kibana log contains these errors:
I'm not sure where I should start troubleshooting so any help would be appreciated. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Do you see anything in the docker logs? Run Also, have you tried to stop the Kibana contaner, remove it, and apply the Kibana state?
Recheck the log to see if there are still errors. |
Beta Was this translation helpful? Give feedback.
Thanks for the advice, you got me on the right track and I got it fixed. Notes on the issue and fix below for anyone else who may run into this.
Stopping, removing and applying the Kibana state didn't help. The Kibana logs were indicating the problem was the migration of the custom Kibana saved objects. I'm assuming this error was being caused by some of the custom Kibana dashboards I created. I tried running "so-kibana-savedobjects-defaults" but that didn't help either.
This is what the Kibana log was showing: