● suricata.service - LSB: Next Generation IDS/IPS
Loaded: loaded (/etc/init.d/suricata; generated; vendor preset: enabled)
Active: active (running) since Tue 2019-04-16 11:57:17 EEST; 32min ago
Docs: man:systemd-sysv-generator(8)
Process: 7455 ExecStop=/etc/init.d/suricata stop (code=exited, status=0/SUCCESS)
Process: 7463 ExecStart=/etc/init.d/suricata start (code=exited, status=0/SUCCESS)
Tasks: 8 (limit: 4915)
CGroup: /system.slice/suricata.service
└─7471 /usr/bin/suricata -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata.pid --af-packet -D -v --user=logstash
Apr 16 11:57:17 SELKS systemd[1]: Stopped LSB: Next Generation IDS/IPS.
Apr 16 11:57:17 SELKS systemd[1]: Starting LSB: Next Generation IDS/IPS...
Apr 16 11:57:17 SELKS suricata[7463]: Starting suricata in IDS (af-packet) mode... done.
Apr 16 11:57:17 SELKS systemd[1]: Started LSB: Next Generation IDS/IPS.
● elasticsearch.service - Elasticsearch
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)
Active: failed (Result: exit-code) since Tue 2019-04-16 11:58:23 EEST; 31min ago
Process: 7581 ExecStart=/usr/share/elasticsearch/bin/elasticsearch -p ${PID_DIR}/elasticsearch.pid --quiet (code=exited, status=1/FAILURE)
Main PID: 7581 (code=exited, status=1/FAILURE)
Apr 16 11:58:22 SELKS elasticsearch[7581]: at org.elasticsearch.bootstrap.Elasticsearch.execute(Elasticsearch.java:150)
Apr 16 11:58:22 SELKS elasticsearch[7581]: at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86)
Apr 16 11:58:22 SELKS elasticsearch[7581]: at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:124)
Apr 16 11:58:22 SELKS elasticsearch[7581]: at org.elasticsearch.cli.Command.main(Command.java:90)
Apr 16 11:58:22 SELKS elasticsearch[7581]: at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:116)
Apr 16 11:58:22 SELKS elasticsearch[7581]: at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:93)
Apr 16 11:58:22 SELKS elasticsearch[7581]: Refer to the log for complete error details.
Apr 16 11:58:23 SELKS systemd[1]: elasticsearch.service: Main process exited, code=exited, status=1/FAILURE
Apr 16 11:58:23 SELKS systemd[1]: elasticsearch.service: Unit entered failed state.
Apr 16 11:58:23 SELKS systemd[1]: elasticsearch.service: Failed with result 'exit-code'.
● logstash.service - logstash
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2019-04-16 09:20:47 EEST; 3h 9min ago
Main PID: 426 (java)
Tasks: 33 (limit: 4915)
CGroup: /system.slice/logstash.service
└─426 /usr/bin/java -Xms4g -Xms4g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djruby.compile.invokedynamic=true -Djruby.jit.threshold=0 -XX:+HeapDumpOnOutOfMemoryError -Djava.security.egd=file:/dev/urandom -cp /usr/share/logstash/logstash-core/lib/jars/animal-sniffer-annotations-1.14.jar:/usr/share/logstash/logstash-core/lib/jars/commons-codec-1.11.jar:/usr/share/logstash/logstash-core/lib/jars/commons-compiler-3.0.8.jar:/usr/share/logstash/logstash-core/lib/jars/error_prone_annotations-2.0.18.jar:/usr/share/logstash/logstash-core/lib/jars/google-java-format-1.1.jar:/usr/share/logstash/logstash-core/lib/jars/gradle-license-report-0.7.1.jar:/usr/share/logstash/logstash-core/lib/jars/guava-22.0.jar:/usr/share/logstash/logstash-core/lib/jars/j2objc-annotations-1.1.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-annotations-2.9.8.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-core-2.9.8.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-databind-2.9.8.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-dataformat-cbor-2.9.8.jar:/usr/share/logstash/logstash-core/lib/jars/janino-3.0.8.jar:/usr/share/logstash/logstash-core/lib/jars/javassist-3.22.0-GA.jar:/usr/share/logstash/logstash-core/lib/jars/jruby-complete-9.2.6.0.jar:/usr/share/logstash/logstash-core/lib/jars/jsr305-1.3.9.jar:/usr/share/logstash/logstash-core/lib/jars/log4j-api-2.9.1.jar:/usr/share/logstash/logstash-core/lib/jars/log4j-core-2.9.1.jar:/usr/share/logstash/logstash-core/lib/jars/log4j-slf4j-impl-2.9.1.jar:/usr/share/logstash/logstash-core/lib/jars/logstash-core.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.commands-3.6.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.contenttype-3.4.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.expressions-3.4.300.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.filesystem-1.3.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.jobs-3.5.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.resources-3.7.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.runtime-3.7.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.app-1.3.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.common-3.6.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.preferences-3.4.1.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.registry-3.5.101.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.jdt.core-3.10.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.osgi-3.7.1.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.text-3.5.101.jar:/usr/share/logstash/logstash-core/lib/jars/slf4j-api-1.7.25.jar org.logstash.Logstash --path.settings /etc/logstash
Apr 16 12:29:45 SELKS logstash[426]: [2019-04-16T12:29:45,212][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:29:45 SELKS logstash[426]: [2019-04-16T12:29:45,767][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:29:50 SELKS logstash[426]: [2019-04-16T12:29:50,215][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:29:50 SELKS logstash[426]: [2019-04-16T12:29:50,770][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:29:55 SELKS logstash[426]: [2019-04-16T12:29:55,219][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:29:55 SELKS logstash[426]: [2019-04-16T12:29:55,774][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:30:00 SELKS logstash[426]: [2019-04-16T12:30:00,223][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:30:00 SELKS logstash[426]: [2019-04-16T12:30:00,777][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:30:05 SELKS logstash[426]: [2019-04-16T12:30:05,227][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
Apr 16 12:30:05 SELKS logstash[426]: [2019-04-16T12:30:05,780][WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"
http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [
http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
● kibana.service - Kibana
Loaded: loaded (/etc/systemd/system/kibana.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2019-04-16 11:57:11 EEST; 32min ago
Main PID: 7351 (node)
Tasks: 11 (limit: 4915)
CGroup: /system.slice/kibana.service
└─7351 /usr/share/kibana/bin/../node/bin/node --no-warnings --max-http-header-size=65536 /usr/share/kibana/bin/../src/cli -c /etc/kibana/kibana.yml
Apr 16 12:30:02 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:02Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"Unable to revive connection:
http://localhost:9200/"}
Apr 16 12:30:02 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:02Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"No living connections"}
Apr 16 12:30:03 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:03Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"Unable to revive connection:
http://localhost:9200/"}
Apr 16 12:30:03 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:03Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"No living connections"}
Apr 16 12:30:03 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:03Z","tags":["warning","task_manager"],"pid":7351,"message":"PollError No Living connections"}
Apr 16 12:30:05 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:05Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"Unable to revive connection:
http://localhost:9200/"}
Apr 16 12:30:05 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:05Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"No living connections"}
Apr 16 12:30:06 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:06Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"Unable to revive connection:
http://localhost:9200/"}
Apr 16 12:30:06 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:06Z","tags":["warning","elasticsearch","admin"],"pid":7351,"message":"No living connections"}
Apr 16 12:30:06 SELKS kibana[7351]: {"type":"log","@timestamp":"2019-04-16T09:30:06Z","tags":["warning","task_manager"],"pid":7351,"message":"PollError No Living connections"}
● evebox.service - EveBox Server
Loaded: loaded (/lib/systemd/system/evebox.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2019-04-16 09:20:47 EEST; 3h 9min ago
Main PID: 431 (evebox)
Tasks: 9 (limit: 4915)
CGroup: /system.slice/evebox.service
└─431 /usr/bin/evebox server
Apr 16 12:29:38 SELKS evebox[431]: 2019-04-16 12:29:38 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:29:41 SELKS evebox[431]: 2019-04-16 12:29:41 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:29:44 SELKS evebox[431]: 2019-04-16 12:29:44 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:29:47 SELKS evebox[431]: 2019-04-16 12:29:47 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:29:50 SELKS evebox[431]: 2019-04-16 12:29:50 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:29:53 SELKS evebox[431]: 2019-04-16 12:29:53 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:29:56 SELKS evebox[431]: 2019-04-16 12:29:56 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:29:59 SELKS evebox[431]: 2019-04-16 12:29:59 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:30:02 SELKS evebox[431]: 2019-04-16 12:30:02 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
Apr 16 12:30:05 SELKS evebox[431]: 2019-04-16 12:30:05 (server.go:350) <Error> -- Failed to ping Elastic Search, delaying startup: : Get
http://localhost:9200/: dial tcp [::1]:9200: connect: connection refused
● molochviewer-selks.service - Moloch Viewer
Loaded: loaded (/etc/systemd/system/molochviewer-selks.service; enabled; vendor preset: enabled)
Active: failed (Result: exit-code) since Tue 2019-04-16 09:28:15 EEST; 3h 1min ago
Process: 2202 ExecStart=/bin/sh -c /data/moloch/bin/node viewer.js -c /data/moloch/etc/config.ini >> /data/moloch/logs/viewer.log 2>&1 (code=exited, status=1/FAILURE)
Main PID: 2202 (code=exited, status=1/FAILURE)
Apr 16 09:26:45 SELKS systemd[1]: molochviewer-selks.service: Main process exited, code=exited, status=1/FAILURE
Apr 16 09:26:45 SELKS systemd[1]: molochviewer-selks.service: Unit entered failed state.
Apr 16 09:26:45 SELKS systemd[1]: molochviewer-selks.service: Failed with result 'exit-code'.
Apr 16 09:28:15 SELKS systemd[1]: molochviewer-selks.service: Service hold-off time over, scheduling restart.
Apr 16 09:28:15 SELKS systemd[1]: Stopped Moloch Viewer.
Apr 16 09:28:15 SELKS systemd[1]: molochviewer-selks.service: Start request repeated too quickly.
Apr 16 09:28:15 SELKS systemd[1]: Failed to start Moloch Viewer.
Apr 16 09:28:15 SELKS systemd[1]: molochviewer-selks.service: Unit entered failed state.
Apr 16 09:28:15 SELKS systemd[1]: molochviewer-selks.service: Failed with result 'exit-code'.
● molochpcapread-selks.service - Moloch Pcap Read
Loaded: loaded (/etc/systemd/system/molochpcapread-selks.service; enabled; vendor preset: enabled)
Active: failed (Result: exit-code) since Tue 2019-04-16 09:26:51 EEST; 3h 3min ago
Process: 2108 ExecStart=/bin/sh -c /data/moloch/bin/moloch-capture -c /data/moloch/etc/config.ini -m -s -R /data/nsm/ >> /data/moloch/logs/capture.log 2>&1 (code=exited, status=1/FAILURE)
Main PID: 2108 (code=exited, status=1/FAILURE)
Apr 16 09:25:21 SELKS systemd[1]: molochpcapread-selks.service: Failed with result 'exit-code'.
Apr 16 09:26:51 SELKS systemd[1]: molochpcapread-selks.service: Service hold-off time over, scheduling restart.
Apr 16 09:26:51 SELKS systemd[1]: Stopped Moloch Pcap Read.
Apr 16 09:26:51 SELKS systemd[1]: molochpcapread-selks.service: Start request repeated too quickly.
Apr 16 09:26:51 SELKS systemd[1]: Failed to start Moloch Pcap Read.
Apr 16 09:26:51 SELKS systemd[1]: molochpcapread-selks.service: Unit entered failed state.
Apr 16 09:26:51 SELKS systemd[1]: molochpcapread-selks.service: Failed with result 'exit-code'.
scirius RUNNING pid 7406, uptime 0:32:55
ii elasticsearch-curator 5.6.0 amd64 Have indices in Elasticsearch? This is the tool for you!\n\nLike a museum curator manages the exhibits and collections on display, \nElasticsearch Curator helps you curate, or manage your indices.
ii evebox 1:0.10.2 amd64 no description given
ii kibana 6.7.1 amd64 Explore and visualize your Elasticsearch data
ii kibana-dashboards-stamus
2019030501 amd64 Kibana 6 dashboard templates.
ii logstash 1:6.7.1-1 all An extensible logging pipeline
ii moloch 1.8.0-1 amd64 Moloch Full Packet System
ii scirius 3.2.0-1 amd64 Django application to manage Suricata ruleset
ii suricata 2019040702-0stamus0 amd64 Suricata open source multi-thread IDS/IPS/NSM system.
Filesystem Type Size Used Avail Use% Mounted on
udev devtmpfs 12G 0 12G 0% /dev
tmpfs tmpfs 2.4G 39M 2.3G 2% /run
/dev/sda2 ext4 442G 61G 359G 15% /
tmpfs tmpfs 12G 0 12G 0% /dev/shm
tmpfs tmpfs 5.0M 0 5.0M 0% /run/lock
tmpfs tmpfs 12G 0 12G 0% /sys/fs/cgroup
/dev/sda1 vfat 511M 132K 511M 1% /boot/efi
tmpfs tmpfs 2.4G 0 2.4G 0% /run/user/1000
tmpfs tmpfs 2.4G 4.0K 2.4G 1% /run/user/112