suddenly the logs not appearing anymore on the Kibana GUI
The logs are coming and i see it under the archive.logÂ
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
Best Regards
Hello Miki,
First of all, sorry for the late reply.
As a first step, please, check if new alerts are generated in the alerts.json
file.
If you see no new alerts being generated on the alerts.json
file:
    it may be a problem with the Wazuh manager. In that case please look in the ossec.log
file for traces of error or other problem and paste it here.
If you see news alerts being generated on the alerts.json
file:
    It may be a problem with Filebeat, Elastic or Kibana. You should check its logs and paste here any trace of error:
systemctl status filebeat -l | grep -i -E "err|warn"
systemctl status kibana -l | grep -i -E "err|warn"
/var/log/elasticsearch or systemctl status elasticsearch -l | grep -i -E "err|warn"
Let me know if you find any errors. Greetings and stay safe.
JP Sáez
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2f318772-af99-423a-b5a2-42f7cc2710a4%40googlegroups.com.
Helo again Miki,
I can see shards related errors in both filebeat and elastic logs{"type":"validation_exception","reason":"Validation Failed: 1: this action would add [3] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}
Elastic 7.x has a limit for the maximum number of shards that can be allocated in a single node. If exceeded elasticsearch won’t start, but you can get your node to start by configuring inside /etc/elasticsearch/elasticsearch.yml
the following setting: cluster.max_shards_per_node: 2000.
Keep in mind that 2k shards per node is above Elasticsearch limit, so consider managing your indices shards to reduce its number.
Greetings,
JP Sáez
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2f318772-af99-423a-b5a2-42f7cc2710a4%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2f318772-af99-423a-b5a2-42f7cc2710a4%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e0534983-237c-4cfe-afff-3d147562a1ac%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2f318772-af99-423a-b5a2-42f7cc2710a4%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e0534983-237c-4cfe-afff-3d147562a1ac%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2f318772-af99-423a-b5a2-42f7cc2710a4%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e0534983-237c-4cfe-afff-3d147562a1ac%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/448fd3d1-de6c-45a9-ba28-f68688763bb3%40googlegroups.com.
Hello again Miky,
Seems like 2k max shards are too much for your ES node. Please, set the value back to the 1k default value and check which of the following fixes fits the better your use case:
POST _reindex
{
"source": {
"index": "wazuh-alerts-3.x-2020-01.*"
},
"dest": {
"index": "wazuh-alerts-3.x-2020"
}
}Â
You can close/open and index as in the following example:
curl -X POST "ELASTIC_IP:9200/index_name/_close"
curl -X POST "ELASTIC_IP:9200/index_name/_open"Â
cluster.max_shards_per_node
above 1.000 shards per node again. As you have seen it could lead to issues easily. You could try setting it to 1200 or 1100 instead of 2K as we previously tried.Let me know how it goes. Greetings
JP
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2f318772-af99-423a-b5a2-42f7cc2710a4%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e0534983-237c-4cfe-afff-3d147562a1ac%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/448fd3d1-de6c-45a9-ba28-f68688763bb3%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e70486de-d9e5-43a1-9bfc-7e162dd24534%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2f318772-af99-423a-b5a2-42f7cc2710a4%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e0534983-237c-4cfe-afff-3d147562a1ac%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/448fd3d1-de6c-45a9-ba28-f68688763bb3%40googlegroups.com.
--Best Regards
Miki AlkalayMobile: 972-54-6496293
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/bce700b7-b2b8-4f6f-bbdb-205c96e0e3fe%40googlegroups.com.
Hello again Miki,
I think in this situation it is a good idea to back to the initial state (set the cluster.max_shards_per_node
back to 1000) and recheck the ES logs and cluster health:
cluster.max_shards_per_node: 1000
value on /etc/elasticsearch/elasticsearch.yml
. Remember to restart ESjournalctl -u kibana.service
GET _cluster/health
After checking this data we can choose the better option and see why increasing the soft open shards limit failed. Let me know how it goes.
Greetings, JP