Elastic Fleet Agent 9.3.7 generates "failed to unmarshal checkin actions: unexpected end of JSON input" #16173
Version3.2.0 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM40 GB Storage for /250 GB Storage for /nsm250 GB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHello!! I successfully upgraded to SO 3.2.0 over the weekend and subsequently observed a flood of repeated events being generated by Elastic Fleet with the following message: This appears to be an upstream issue involving the Elastic Agent/Fleet check-in mechanism rather than a Security Onion-specific configuration issue. Based on the upstream Elastic Issue #15397 , this appears to be a known issue with the Elastic Agent version (9.3.7) bundled with SO 3.2.0. The issue is reported as resolved in Elastic Agent 9.4.4. In my environment, the Elastic Agent otherwise appears to be operational and is successfully communicating with Fleet/Security Onion. The error appears to be specifically associated with processing the actions returned during the Fleet check-in process. I'm raising this here to confirm whether this is a known issue with the Elastic Agent version bundled with SO 3.2.0, and whether there are plans to update the bundled version in a future Security Onion release. Guidelines
|
Replies: 1 comment
|
There is a plan to upgrade Elastic to 9.4.5 in the next release (3.3). |
There is a plan to upgrade Elastic to 9.4.5 in the next release (3.3).