I have tried to overcome some issues with the JVM size and passwords that would not generate and just have a flashing cursor by upgrading to 4.9 with Ubuntu 22.04 patch 4, however I am now dealing with other issues
Azure logs
Sep 11, 2024 @ 14:26:38.000 azure ERROR Error: An error occurred while trying to obtain the authentication token: HTTPSConnectionPool(host='
login.microsoftonline.com', port=443): Max retries exceeded with url: /
contoso.onmicrosoft.com/oauth2/v2.0/token (Caused by ConnectTimeoutError(<urllib3.connection.HTTPSConnection object at 0x79f09a04cee0>, 'Connection to
login.microsoftonline.com timed out. (connect timeout=10)'))
Sep 11, 2024 @ 14:25:18.000 azure INFO Database integrity check finished
Sep 11, 2024 @ 14:25:18.000 azure INFO Azure Graph starting.
Sep 11, 2024 @ 14:25:18.000 azure DEBUG Graph: Using the auth file /var/ossec/wodles/azure/graph_credentials.txt for authentication
Sep 11, 2024 @ 14:25:18.000 azure INFO Graph: Getting authentication token.
Sep 11, 2024 @ 14:25:17.000 azure ERROR Error: An error occurred while trying to obtain the authentication token: HTTPSConnectionPool(host='
login.microsoftonline.com', port=443): Max retries exceeded with url: /
contoso.onmicrosoft.com/oauth2/v2.0/token (Caused by ConnectTimeoutError(<urllib3.connection.HTTPSConnection object at 0x790d29f48ee0>, 'Connection to
login.microsoftonline.com timed out. (connect timeout=10)'))
Wazuh-modulesd
Sep 11, 2024 @ 14:29:30.000 wazuh-modulesd DEBUG curl_easy_perform() failed: Timeout was reached
Sep 11, 2024 @ 14:28:30.000 wazuh-modulesd DEBUG curl_easy_perform() failed: Timeout was reached
wazuh-modulesd:azure-logs
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs ERROR azure-ad-graph: Returned error code: '1'.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs INFO Checking database integrity
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs INFO Finished Graphs log collection for request 'azure-ad-graph'.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs INFO Finished Graphs log collection for the domain '
contoso.onmicrosoft.com'.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs DEBUG Fetching logs finished.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs WARNING Interval overtaken.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs INFO Starting fetching of logs.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs INFO Starting Graphs log collection for the domain '
contoso.onmicrosoft.com'.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs DEBUG Creating argument list.
Sep 11, 2024 @ 14:30:41.000 wazuh-modulesd:azure-logs DEBUG Launching command: wodles/azure/azure-logs --graph --graph_auth_path /var/ossec/wodles/azure/graph_credentials.txt --graph_tenant_domain
contoso.onmicrosoft.com --graph_tag microsoft-entra_id --graph_query 'auditLogs/signIns' --debug 2
wazuh-modulesd:ms-graph
Sep 11, 2024 @ 14:31:30.000 wazuh-modulesd:ms-graph WARNING No response received when attempting to obtain access token.
Sep 11, 2024 @ 14:31:30.000 wazuh-modulesd:ms-graph INFO Obtaining access token.
Sep 11, 2024 @ 14:31:30.000 wazuh-modulesd:ms-graph DEBUG Microsoft Graph API Access Token URL: '
https://login.microsoftonline.com/205cb9c8-6d96-394v-9e13-61ec0376d06b/oauth2/v2.0/token'
Sep 11, 2024 @ 14:30:30.000 wazuh-modulesd:ms-graph WARNING No response received when attempting to obtain access token.
wazuh-modulesd:office365 (Note: I can get a token manually)
Sep 11, 2024 @ 14:31:30.000 wazuh-modulesd:office365 DEBUG Scanning tenant: '205cb9c8-6d96-394v-9e13-61ec0376d06b'
Sep 11, 2024 @ 14:31:30.000 wazuh-modulesd:office365 DEBUG Office 365 API access token URL: '
https://login.microsoftonline.com/205cb9c8-6d96-394v-9e13-61ec0376d06b/oauth2/v2.0/token'
Sep 11, 2024 @ 14:30:30.000 wazuh-modulesd:office365 DEBUG Unknown error while getting access token.
wazuh-cluster.log
[2024-09-11T13:35:11,447][WARN ][o.o.s.a.BackendRegistry ] [node-1] Authentication finally failed for admin from
10.80.192.120:52196[2024-09-11T13:35:12,900][WARN ][o.o.p.c.u.JsonConverter ] [node-1] Json Mapping Error: Cannot invoke "java.lang.Long.longValue()" because "this.cacheMaxSize" is null (through reference chain: org.opensearch.performanceanalyzer.collectors.CacheConfigMetricsCollector$CacheMaxSizeStatus["Cache_MaxSize"])
[2024-09-11T13:36:37,906][WARN ][o.o.p.c.u.JsonConverter ] [node-1] Json Mapping Error: Cannot invoke "java.lang.Long.longValue()" because "this.cacheMaxSize" is null (through reference chain: org.opensearch.performanceanalyzer.collectors.CacheConfigMetricsCollector$CacheMaxSizeStatus["Cache_MaxSize"])
[2024-09-11T13:36:42,906][WARN ][o.o.p.c.u.JsonConverter ] [node-1] Json Mapping Error: Cannot invoke "java.lang.Long.longValue()" because "this.cacheMaxSize" is null (through reference chain: org.opensearch.performanceanalyzer.collectors.CacheConfigMetricsCollector$CacheMaxSizeStatus["Cache_MaxSize"])
[2024-09-11T13:36:47,542][INFO ][o.o.j.s.JobScheduler ] [node-1] Will delay 34792 miliseconds for next execution of job wazuh-alerts-4.x-2024.08.31
[2024-09-11T13:36:47,907][WARN ][o.o.p.c.u.JsonConverter ] [node-1] Json Mapping Error: Cannot invoke "java.lang.Long.longValue()" because "this.cacheMaxSize" is null (through reference chain: org.opensearch.performanceanalyzer.collectors.CacheConfigMetricsCollector$CacheMaxSizeStatus["Cache_MaxSize"])
[2024-09-11T13:36:48,430][INFO ][o.o.i.i.ManagedIndexRunner] [node-1] Executing attempt_transition_step for wazuh-alerts-4.x-2024.08.31
[2024-09-11T13:36:48,430][INFO ][o.o.i.i.ManagedIndexRunner] [node-1] Finished executing attempt_transition_step for wazuh-alerts-4.x-2024.08.31
[2024-09-11T13:36:52,908][WARN ][o.o.p.c.u.JsonConverter ] [node-1] Json Mapping Error: Cannot invoke "java.lang.Long.longValue()" because "this.cacheMaxSize" is null (through reference chain: org.opensearch.performanceanalyzer.collectors.CacheConfigMetricsCollector$CacheMaxSizeStatus["Cache_MaxSize"])