error starting up wazuh

500 views
Skip to first unread message

Raul Trevino

unread,
Apr 17, 2023, 7:09:45 PM4/17/23
to Wazuh mailing list

Jose Camargo

unread,
Apr 17, 2023, 9:57:31 PM4/17/23
to Wazuh mailing list
Hi Raul,

There is a similar issue reported here: https://github.com/wazuh/wazuh-kibana-app/issues/4946 and it seems to be related to incomplete rule files. Can you please verify if this is the case?

I'll be awaiting your comments.

Regards,

Raul Trevino

unread,
Apr 19, 2023, 12:51:12 PM4/19/23
to Jose Camargo, Wazuh mailing list
Hello Jose,

I just checked on this and it's not related,  all rules are ok.

--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/MXvk6tBnbdQ/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/4122481b-c285-49ed-b041-8a21db15b176n%40googlegroups.com.

Jose Camargo

unread,
Apr 19, 2023, 1:47:40 PM4/19/23
to Wazuh mailing list
Hi Raul,

If you check the logs, do you see any other indication of the error? Please try checking with the following commands:

  • Wazuh indexer:
    • cat /var/log/wazuh-indexer/wazuh-cluster.log | grep -i -E "error|warn"

  • Wazuh manager:
    • cat /var/log/filebeat/filebeat | grep -i -E "error|warn"
    • cat /var/ossec/logs/ossec.log | grep -i -E "error|warn"
    • cat /var/ossec/logs/cluster.log | grep -i -E "error|warn"
    • cat /var/ossec/logs/api.log | grep -i -E "error|warn"

  • Wazuh dashboard:
    • journalctl -u wazuh-dashboard
    • cat /usr/share/wazuh-dashboard/data/wazuh/logs/wazuhapp.log | grep -i -E "error|warn"
If you see any related errors please send them to me so I can analyze them.

Thank you!


Regards,
Jose Camargo
Reply all
Reply to author
Forward
0 new messages