Template Error - Log Ingestion Not Working #14545
-
Version2.4.140 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU64 RAM251G Storage for /558G Storage for /nsm38T Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailHello, I am currently experiencing the following errors when running As a result of this error, logs are not being ingested, and I suspect this template problem is the root cause.
Could anyone offer advice on how to troubleshoot or resolve this template error? Any insights would be greatly appreciated. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 5 replies
-
Have you made any configuration changes to existing templates or created custom index templates? Are you able to post the full log so we can see which template(s) is having an issue? I only see templates successfully loading in the screenshot |
Beta Was this translation helpful? Give feedback.
-
My issue was with the |
Beta Was this translation helpful? Give feedback.
My issue was with the
logs-cisco_duo.auth-*
template and was due to some custom configurations in the SO Console under elasticsearch > advanced [adv]. Initially, I was searching for a solution in Elastic's Index Management > Templates, but the overriding settings in the advanced configurations were the root cause.