Sostat output: the elastic instance is on yellow and i cant request any information from it like curl localhost:9200/_cat/indices and get this message:
=========================================================================
Last update
=========================================================================
Commandline: apt install ./docker-ce-rootless-extras_20.10.5~3-0~ubuntu-xenial_amd64.deb
Requested-By: viper (1000)
Upgrade: docker-ce-rootless-extras:amd64 (5:20.10.4~3-0~ubuntu-xenial, 5:20.10.5~3-0~ubuntu-xenial)
End-Date: 2021-03-11 16:41:32
Start-Date: 2021-03-11 16:41:54
Commandline: apt-get -y dist-upgrade
Requested-By: viper (1000)
Upgrade: python2.7-dev:amd64 (2.7.12-1ubuntu0~16.04.16, 2.7.12-1ubuntu0~16.04.18), git-man:amd64 (1:2.7.4-0ubuntu1.9, 1:2.7.4-0ubuntu1.10), python2.7-minimal:amd64 (2.7.12-1ubuntu0~16.04.16, 2.7.12-1ubuntu0~16.04.18), libpython2.7:amd64 (2.7.12-1ubuntu0~16.04.16, 2.7.12-1ubuntu0~16.04.18), python2.7:amd64 (2.7.12-1ubuntu0~16.04.16, 2.7.12-1ubuntu0~16.04.18), git:amd64 (1:2.7.4-0ubuntu1.9, 1:2.7.4-0ubuntu1.10), libpython2.7-dev:amd64 (2.7.12-1ubuntu0~16.04.16, 2.7.12-1ubuntu0~16.04.18), securityonion-suricata:amd64 (5.0.5-1ubuntu1securityonion2, 5.0.6-1ubuntu1securityonion1), libglib2.0-bin:amd64 (2.48.2-0ubuntu4.6, 2.48.2-0ubuntu4.7), wpasupplicant:amd64 (2.4-0ubuntu6.7, 2.4-0ubuntu6.8), libglib2.0-data:amd64 (2.48.2-0ubuntu4.6, 2.48.2-0ubuntu4.7), libpython2.7-minimal:amd64 (2.7.12-1ubuntu0~16.04.16, 2.7.12-1ubuntu0~16.04.18), libpython2.7-stdlib:amd64 (2.7.12-1ubuntu0~16.04.16, 2.7.12-1ubuntu0~16.04.18), libglib2.0-0:amd64 (2.48.2-0ubuntu4.6, 2.48.2-0ubuntu4.7)
End-Date: 2021-03-11 16:42:11
=========================================================================
Elasticsearch
=========================================================================
Elasticsearch is running.
Cluster Name: "cg-mstr-vipertd"
Cluster Status: "yellow"
Total Nodes: 1
Failed Nodes: 0
Total Indices: 294
Total Shards: 314
Total Documents: 1968562317
Total Size: 1992169MB
Free Memory: 2%
Total Number of Events: 725903763
Avg. Event Size (In Bytes): 1234
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
268383a7756d so-elasticsearch 5.40% 5.518GiB / 15.64GiB 35.27% 265MB / 463MB 7.63GB / 425MB 133
=========================================================================
Logstash
=========================================================================
Logstash is running.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
39388c0eb03b so-logstash 10.49% 1.125GiB / 15.64GiB 7.19% 140MB / 257MB 97.8MB / 11.3MB 150
Logstash Queue Stats:
Queue Type: memory
Queue settings can be modified in /etc/logstash/logstash.yml.
Event Summary (since restart):
Events In: 112218
Events Out: 112218
=========================================================================
Kibana
=========================================================================
Kibana is running.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
77c8b5235967 so-kibana 0.94% 212.4MiB / 15.64GiB 1.33% 32.1MB / 9.63MB 60.1MB / 0B 12
=========================================================================
ElastAlert
=========================================================================
ElastAlert is running.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
3e1b11307a10 so-elastalert 0.02% 71.96MiB / 15.64GiB 0.45% 229kB / 305kB 27.1MB / 12.3kB 13
=========================================================================
Curator
=========================================================================
Curator is running.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
ff983f3b8089 so-curator 0.00% 14.73MiB / 15.64GiB 0.09% 425MB / 931kB 14.8MB / 0B 1
=========================================================================
syslog-ng stats
=========================================================================
SourceName;SourceId;SourceInstance;State;Type;Number
destination;d_syslog;;a;processed;333
destination;d_console_all;;a;processed;16
dst.tcp;d_logstash#0;tcp,127.0.0.1:6050;a;dropped;62106
dst.tcp;d_logstash#0;tcp,127.0.0.1:6050;a;processed;240580
destination;d_cron;;a;processed;232
destination;d_error;;a;processed;15
center;;queued;a;processed;241832
destination;d_auth;;a;processed;530
destination;d_daemon;;a;processed;101
global;payload_reallocs;;a;processed;13
destination;d_xconsole;;a;processed;16
destination;d_debug;;a;processed;9
destination;d_logstash;;a;processed;240580
WARNING! syslog-ng reports drops!
dst.tcp;d_logstash#0;tcp,127.0.0.1:6050;a;dropped;62106
=========================================================================
Version Information
=========================================================================
Ubuntu 16.04.7 LTS
securityonion-sostat 20120722-0ubuntu0securityonion148