PaloAltoNetworks / minemeld

Main MineMeld documentation repo
380 stars 64 forks source link

Minemeld Starting sudden issue #37

Closed XiQshoner closed 5 years ago

XiQshoner commented 5 years ago

I think this is probably wasted breath as it seems minemeld isn't being supported for free anymore.

However, recently my miners starting acting up. So I was going to restart the minemeld service via CLI. That didn't go to well as I received this error.

Someone@MineMeld:~$ sudo service minemeld start

Might be something with a recent update, I am running Ubuntu LTS 16.0.4 as the build recommends. Any help would be appreciated, as I have these dynamic lists deployed to 80+ firewalls.

jtschichold commented 5 years ago

Hi @XiQshoner, open source MineMeld is still maintained, working on a new release as we speak :-) The warning you see do not explain the issues with the Miners. Could you add more details about the errors you see on the WebUI?

If you are on 16.04, I suggest upgrading to MineMeld 0.9.60 - it was released some weeks ago.

Thanks, Luigi

XiQshoner commented 5 years ago

Thanks for the quick reply, maybe the Palo Alto live community is just slow. I ran a apt-get upgrade on my Ubuntu instance and it helped with the starting errors. The miner in question is still polling, if it errors out again I will update this request accordingly. I will move to 0.9.60 today sometime.

XiQshoner commented 5 years ago

The miner in question is recordedfuture.IPRiskList. Essentially, it seems the miner will poll until it errors out. The indicators don't seem to be cycling as usual and old data is not being churned.

On a side note, I ran the sudo /usr/sbin/minemeld-auto-update and it said that VERSION: 0.9.52 was the best found.

jtschichold commented 5 years ago

Could you send me the error you see on the RF Miner?

XiQshoner commented 5 years ago

Fortunately, this is now polling with success. If something else happens with this node I will update the ticket.