Grid Page Empty After Node Update #12883
Replies: 5 comments 1 reply
-
Oh, I'm also seeing the same error described here: #11207 in my logstash logs |
Beta Was this translation helpful? Give feedback.
-
bump This is becoming an issue as I cannot view agent utilization metrics, which is one of our primary use cases for deploying SO |
Beta Was this translation helpful? Give feedback.
-
Update: found another error in /opt/so/log/elasticsearch/securityonion.log whic hseems related:
|
Beta Was this translation helpful? Give feedback.
-
After running the reset script all agents you have deployed will need to be uninstalled and redeployed. Have you uninstalled and reinstalled the agent on your endpoints? |
Beta Was this translation helpful? Give feedback.
-
Tried a fresh install to no avail :/ https://myonion.dev/api/grid returns an empty list Everything else seems to be working fine. No clue why I can't get this endpoint to work |
Beta Was this translation helpful? Give feedback.
-
Version
2.4.60
Installation Method
Other (please provide detail below)
Description
upgrading
Installation Type
Standalone
Location
cloud
Hardware Specs
Exceeds minimum requirements
CPU
8
RAM
32
Storage for /
255G
Storage for /nsm
255G
Network Traffic Collection
other (please provide detail below)
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
I've been stably running SO via the Azure Marketplace image for a couple weeks now. Today, I logged in and noticed on the Grid page my sole node (standalone mode) status bar was Red. Clicking around it seemed SO wanted me to update the node. I obliged by clicking the update button in the UI, and after it completed I can no longer see the node (or any info) in the Grid page.
so-status
shows all services running correctly, and I can view my Crowdstrike-integrated logs in both SOC as well as Elastic, so I don't believe there's anything severe going on here. That being said, I'd love to get the bottom of why this happened. I tried a full reset usingso-elastic-fleet-reset
, which completed successfully with no change to the Grid page. I did find these logs which seem relevant:Any idea what the problem might be or where I should look next? Thanks!
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions