after update from 2.4.100 to the latest, zeek has missing status #14409
Replies: 4 comments 7 replies
-
Have you previously modified your Zeek configuration in any way? What is the output of the following?
Is Zeek logging anything in /nsm/zeek/logs/current/? What is the output of the following?
|
Beta Was this translation helpful? Give feedback.
-
i have not chnaged the zeek config sudo salt-call state.apply zeek queue=True
|
Beta Was this translation helpful? Give feedback.
-
Is Zeek logging anything in /nsm/zeek/logs/current/? = yes |
Beta Was this translation helpful? Give feedback.
-
there is a /opt/zeek/share/zeekctl/scripts/run-zeek: line 61: ulimit: core file size: cannot modify limit: Operation not permitted in stderr.log |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.130
Installation Method
Security Onion ISO image
Description
upgrading
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
56 cpus
RAM
128GB
Storage for /
128GB
Storage for /nsm
2TB
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
No, one or more services are failed (please provide detail below)
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
so-status = so-zeek │ missing │
i run:
grid status has = fault
after few minutes zeek try to start again, and the so-status is:
so-zeek │ running │ Up 3 minutes (health: starting)
but it failed after 5-10min
there are no zeek logs in HUNT section
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions