I ran 'sudo sostat' and it says 'Logstash is running', 'Kibana is not running', 'ElastAlert is not running', 'Curator is not running'. It suggests to run 'sudo so-elastic-start', which I did. Running 'sudo sostat' again says 'Kibana is not running' but Curator and ElastAlert are now running.
Running 'sudo so-elastic-start' a second time results in Kibana getting started and running successfully. But, the Kibana webpage says 'Kibana server is not ready yet'.
What happened? All worked great until I ran 'sudo soup'.
I ran 'sudo soup' on a second SO Server of ours and the exact same issues have occurred. Kibana is not working on a second server now.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/efc89da7-89dd-4a5c-aae7-3eaa352038f9%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
{"type":"response","@timestamp":"2019-05-20T18:12:49Z","tags":[],"pid":1,"method":"get","statusCode":200,"req":{"url":"/bundles/app/kibana/bootstrap.js","method":"get","headers":{"host":"127.0.0.1:5601","user-agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36","dnt":"1","accept":"*/*","referer":"https://REDACTED/app/kibana","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9","x-forwarded-for":"65.129.48.36","x-forwarded-host":"REDACTED","x-forwarded-server":"localhost","connection":"Keep-Alive"},"remoteAddress":"172.17.0.1","userAgent":"172.17.0.1","referer":"https://REDACTED/app/kibana"},"res":{"statusCode":200,"responseTime":5,"contentLength":9},"message":"GET /bundles/app/kibana/bootstrap.js 200 5ms - 9.0B"}
{"type":"response","@timestamp":"2019-05-20T18:12:49Z","tags":[],"pid":1,"method":"get","statusCode":200,"req":{"url":"/bundles/commons.style.css","method":"get","headers":{"host":"127.0.0.1:5601","user-agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36","dnt":"1","accept":"text/css,*/*;q=0.1","referer":"https://REDACTED/app/kibana","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9","x-forwarded-for":"65.129.48.36","x-forwarded-host":"REDACTED","x-forwarded-server":"localhost","connection":"Keep-Alive"},"remoteAddress":"172.17.0.1","userAgent":"172.17.0.1","referer":"https://REDACTED/app/kibana"},"res":{"statusCode":200,"responseTime":12,"contentLength":9},"message":"GET /bundles/commons.style.css 200 12ms - 9.0B"}
{"type":"response","@timestamp":"2019-05-20T18:12:49Z","tags":[],"pid":1,"method":"get","statusCode":200,"req":{"url":"/bundles/kibana.style.css","method":"get","headers":{"host":"127.0.0.1:5601","user-agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36","dnt":"1","accept":"text/css,*/*;q=0.1","referer":"https://REDACTED/app/kibana","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9","x-forwarded-for":"65.129.48.36","x-forwarded-host":"REDACTED","x-forwarded-server":"localhost","connection":"Keep-Alive"},"remoteAddress":"172.17.0.1","userAgent":"172.17.0.1","referer":"https://REDACTED/app/kibana"},"res":{"statusCode":200,"responseTime":2,"contentLength":9},"message":"GET /bundles/kibana.style.css 200 2ms - 9.0B"}
Here's the log tail of Server2.
{"type":"log","@timestamp":"2019-05-20T16:54:28Z","tags":["status","plugin:elasti...@6.7.2","info"],"pid":1,"state":"green","message":"Status changed from yellow to green - Ready","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}
{"type":"log","@timestamp":"2019-05-20T16:54:28Z","tags":["info","migrations"],"pid":1,"message":"Creating index .kibana_3."}
{"type":"log","@timestamp":"2019-05-20T16:54:28Z","tags":["warning","migrations"],"pid":1,"message":"Another Kibana instance appears to be migrating the index. Waiting for that migration to complete. If no other Kibana instance is attempting migrations, you can get past this message by deleting index .kibana_3 and restarting Kibana."}
The good news is that Squert is still working on all boxes.
I ran 'sudo soup' on our 3rd SO Server and it's webpage now says that 'Kibana server is not ready yet' and the logs say the same message as our 2nd box about 'Another Kibana instance appears to be migrating the index. Waiting for that migration to complete'.
The good news is that Squert is still working on all boxes.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/7938e298-c47f-4243-816e-b28ca2bff39c%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Server1
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 3680 100 3680 0 0 28403 0 --:--:-- --:--:-- --:--:-- 28527
green open .kibana_2 zBlvfGBMQHihMMGNxU4dWQ 1 0 496 0 432kb 432kb
green open .kibana_1 VWqDEguKT2atqAl37vFXXA 1 0 495 146 1.7mb 1.7mb
Server2
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0green open .kibana_3 zn-0GgwmRL6oWyvwiqm3Yw 1 0 492 0 448.8kb 448.8kb
green open .kibana_2 S5olWfDAS1CuuT1O2taQfQ 1 0 492 0 480.2kb 480.2kb
100 98256 100 98256 0 green open .kibana_1 yZzV3zQUSPuX-wQAsxlIqA 1 0 491 0 441.7kb 441.7kb
0 342k 0 --:--:-- --:--:-- --:--:-- 343k
Server3
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
green open .kibana ihsGuEifQLykMr5kMArvhw 1 0 487 393 2.2mb 2.2mb
100 10509 100 10509 0 0 6502 0 0:00:01 0:00:01 --:--:-- 6507
green open .kibana_2 O53DUaoDQCq8g9EideWMWQ 1 0 0 0 261b 261b
This is all very strange. I think tomorrow I'll just rebuild the server with the latest iso.
I reran the setup on Server1 and again Squert works fine, but now Kibana webpage has a big red bar that says 'Kibana did not load properly. Check the server output for more information'
This is all very strange. I think tomorrow I'll just rebuild the server with the latest iso.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/e4c90bda-0b1f-4b1b-b621-d13236c6027e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAHjBB6E0QK0118-uhAZPpNnvCM-P9m9WO-N839FGsBRjRFJ6Cg%40mail.gmail.com.
I've the exact same error
--
______________________________
itiviti.com <https://www.itiviti.com/>
*The information contained in or attached to this email is strictly
confidential. If you are not the intended recipient, please notify us
immediately by telephone and return the message to us.*
communications by definition contain personal information. The Itiviti
group of companies is subject to European data protection regulations.
Itiviti’s Privacy Notice is available at www.itiviti.com
<http://www.itiviti.com>. Itiviti expects the recipient of this email to be
compliant with Itiviti’s Privacy Notice and applicable regulations. Please
advise us immediately at dataprote...@Itiviti.com if you are not
compliant with these.*
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/8ae8ef8f-552f-4370-8add-a73a3dd4971b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAHjBB6FdgCoWb%3DsQj077uT7q1XwmvT8-wLAa0rvKZ6qVHU9jLQ%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAA1S6bfZik4iR3BEHh08eOGm8QUF4_J2R48MWozipjDy0FHNFw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAHjBB6E%2B7_YZzQ6zOyijMPaC22G9vqeH7DYdxuXdoqwRXENznw%40mail.gmail.com.
sysadmin@SecurityOnion1:~$ sudo dpkg -l | grep securityonion-elastic
ii securityonion-elastic 20180130-1ubuntu1securityonion79 all Elastic Stack on Security Onion
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/310dabee-3765-463e-b75d-7483ca8947aa%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Grep output is the same as previous post.
I ran soup again, no errors.
Grep output is the same as previous post.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/3a2b0dc4-e371-4c5e-bdf9-047911fda83a%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Kris
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/Y2z13igTXsU/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAHjBB6Fnij4AQJAJX7sJZSfGV-BUDA5jLj90tAy9q212qTb2OQ%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAHjBB6H19AdG2Nq8iSu1g6ZuHnOVfo_1nD0xdwF3YL8JUXkO3g%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAA1S6bdXM_%3D_Gy9e4dxziuip4jpBMYXyfZdacj%3DD-AwOigo5Bg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAHjBB6GJ%3DAZ6re22JTc2LxOb9t5ZodMq-EiTqe-7KYR9YkuYhA%40mail.gmail.com.
--
______________________________
itiviti.com <https://www.itiviti.com/>
*The information contained in or attached to this email is strictly
confidential. If you are not the intended recipient, please notify us
immediately by telephone and return the message to us.*
communications by definition contain personal information. The Itiviti
group of companies is subject to European data protection regulations.
Itiviti’s Privacy Notice is available at www.itiviti.com
<http://www.itiviti.com>. Itiviti expects the recipient of this email to be
compliant with Itiviti’s Privacy Notice and applicable regulations. Please
advise us immediately at dataprote...@Itiviti.com if you are not
compliant with these.*
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/b38cc287-f1b4-4939-ace3-d395eec1c317%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
yes I've rebooted multiple times,
the output of dpkg -l | grep securityonion-elastic is
ii securityonion-elastic 20190510-1ubuntu1securityonion3 all Elastic Stack on Security Onion
--
______________________________
itiviti.com <https://www.itiviti.com/>
*The information contained in or attached to this email is strictly
confidential. If you are not the intended recipient, please notify us
immediately by telephone and return the message to us.*
communications by definition contain personal information. The Itiviti
group of companies is subject to European data protection regulations.
Itiviti’s Privacy Notice is available at www.itiviti.com
<http://www.itiviti.com>. Itiviti expects the recipient of this email to be
compliant with Itiviti’s Privacy Notice and applicable regulations. Please
advise us immediately at dataprote...@Itiviti.com if you are not
compliant with these.*
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/965a3285-33dd-4533-9fd8-3c43381a7b7f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
the operation that have been done on it during this week is so-stop so-start (that can upgrade docker image),
and when I come back there was these on the servers I've tried to soup but nothing changes
--
______________________________
itiviti.com <https://www.itiviti.com/>
*The information contained in or attached to this email is strictly
confidential. If you are not the intended recipient, please notify us
immediately by telephone and return the message to us.*
communications by definition contain personal information. The Itiviti
group of companies is subject to European data protection regulations.
Itiviti’s Privacy Notice is available at www.itiviti.com
<http://www.itiviti.com>. Itiviti expects the recipient of this email to be
compliant with Itiviti’s Privacy Notice and applicable regulations. Please
advise us immediately at dataprote...@Itiviti.com if you are not
compliant with these.*
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/c593b820-89ad-43f6-9d3c-4c987fe127e0%40googlegroups.com.
I have also experienced the same errors but found that if I used the server console with Http://localhost:5601/app/kibana I could get to all my data.
I know re-running the setup may not be a good solution for everyone, but I reviewed my logs and was OK with dumping them. It cleaned everything up for me and all my SO servers are running ok now. My main server needed upgraded anyway.
I love the visibility Kibana gives! Thank you SO team!
please upgrade your browser
This kibana installation has strict security requirements enabled that your current browser does not meet.
any idea ?
--
______________________________
itiviti.com <https://www.itiviti.com/>
*The information contained in or attached to this email is strictly
confidential. If you are not the intended recipient, please notify us
immediately by telephone and return the message to us.*
communications by definition contain personal information. The Itiviti
group of companies is subject to European data protection regulations.
Itiviti’s Privacy Notice is available at www.itiviti.com
<http://www.itiviti.com>. Itiviti expects the recipient of this email to be
compliant with Itiviti’s Privacy Notice and applicable regulations. Please
advise us immediately at dataprote...@Itiviti.com if you are not
compliant with these.*
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/d8168d14-e3ae-4b7c-b720-6447b527faa4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
i've try 3 different system: windows/windows-server/linux
on browser : chrome/firefox/egde/internet-explorer
Fireproof,
Are you still running 14.04? If so, you'll want to upgrade to 16.04:
https://securityonion.readthedocs.io/en/latest/upgrading-from-14.04-to-16.04.html
Otherwise, did you receive any errors when running soup?
What is the result of the following?
my issue is the same as Fireproof, it's working with localhost:5601
I'm in 16.04
dpkg -l | grep securityonion-elastic give :
--
______________________________
itiviti.com <https://www.itiviti.com/>
*The information contained in or attached to this email is strictly
confidential. If you are not the intended recipient, please notify us
immediately by telephone and return the message to us.*
communications by definition contain personal information. The Itiviti
group of companies is subject to European data protection regulations.
Itiviti’s Privacy Notice is available at www.itiviti.com
<http://www.itiviti.com>. Itiviti expects the recipient of this email to be
compliant with Itiviti’s Privacy Notice and applicable regulations. Please
advise us immediately at dataprote...@Itiviti.com if you are not
compliant with these.*
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/f462e675-6722-489f-af5b-69f8317d62ea%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Thanks
dpkg -l | grep securityonion-elastic
ii securityonion-elastic 20180130-1ubuntu1securityonion153 all Elastic Stack on Security Onion
curl
-X GET "localhost:9200/_cat/indices/.kib*?v&s=index"
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open .kibana_1 dRHUM7jhQuu1SnT8LZyh0w 1 0 490 144 1.7mb 1.7mb
Any help is much appreciated.
Regards,
Brian
Hi Kris,Have you checked the Kibana log for any additional clues?/var/log/kibana/kibana.logOn Mon, May 20, 2019 at 1:33 PM Kris Springer <kspr...@innovateteam.com> wrote:I ran 'sudo soup' on a second SO Server of ours and the exact same issues have occurred. Kibana is not working on a second server now.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to securit...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/efc89da7-89dd-4a5c-aae7-3eaa352038f9%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
sudo so-elastic-start
sudo so-elastic-configure-kibana
Then refresh your browser to re-login to Kibana.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/67ee827f-eacc-4045-a6dd-b924aa003e7b%40googlegroups.com.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/73a5e796-e68d-4760-b206-387c4599331c%40googlegroups.com.
Kris Springer
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/Y2z13igTXsU/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAJ%2BhwWCxVYUC6Rb9K32bJb%2BfjYAc%2B20OdFbHjjjAYcdqkAB-kw%40mail.gmail.com.