LetMeR00t / TA-thehive-cortex

Technical add-on for Splunk related to TheHive/Cortex from TheHive project
GNU Lesser General Public License v3.0
49 stars 11 forks source link

[BUG] #55

Closed Kiorgen closed 1 year ago

Kiorgen commented 1 year ago

Request Type

Bug

Work Environment

Question Answer
OS version (server) Ubuntu 20.04
TheHive version 3.0.0

Problem Description

Describe your problem here

Hi! I have one problem. After weekends my app for hive/cortex doesn't get events from hive/cortex server. External search command 'cortexjobs' returned error code 15. . Help pls

Logs (issued from the search.log with logging mode set to DEBUG under Settings/Configuration)

05-23-2023 13:31:13.581 INFO ResultsCollationProcessor [3763121 phase_1] - Writing remote_event_providers.csv to disk 05-23-2023 13:31:13.939 ERROR script [3763121 phase_1] - SearchMessage orig_component=script sid=1684837873.1960 message_key=EXTERN:SCRIPT_NONZERO_RETURN_%s%d_%s message=External search command 'cortexjobs' returned error code 15. . 05-23-2023 13:31:13.944 INFO ReducePhaseExecutor [3763121 phase_1] - Not downloading remote search.log files. Reason: No remote event providers. 05-23-2023 13:31:13.945 INFO ReducePhaseExecutor [3763121 phase_1] - Not downloading remote search_telemetry.json files. Reason: No remote event providers. 05-23-2023 13:31:13.945 INFO ReducePhaseExecutor [3763121 phase_1] - Ending phase_1

Kiorgen commented 1 year ago

Okay, i solved my problem after 2 days, sorry. Permissions were not global