StamusNetworks / SELKS

A Suricata based IDS/IPS/NSM distro
https://www.stamus-networks.com/open-source/#selks
GNU General Public License v3.0
1.44k stars 284 forks source link

elasticsearch Unassigned shards and "kernel captured packets" no data available #271

Open Product opened 3 years ago

Product commented 3 years ago

please help me .thanx "kernel captured packets" no data available :

i requested : GET /rest/rules/es/logstash_eve/?from_date=1604380909615&value=stats.tcp.reassembly_memuse&hosts=xxxx-xxxx

HTTP 200 OK Allow: GET, HEAD, OPTIONS Content-Type: application/json Vary: Accept { "from_date": 1604380909615, "interval": 1730801 }

elasticsearch Unassigned shards:

curl -XGET 'http://localhost:9200/_cat/shards'

fields_v3 0 p STARTED 42 46.8kb 127.0.0.1 xxxx-xxxx lookups_v1 0 p STARTED 0 208b 127.0.0.1 xxxx-xxxx .kibana_task_manager_1 0 p STARTED 5 39.8kb 127.0.0.1 xxxx-xxxx logstash-flow-2020.11.05 0 p STARTED 1434148 618.9mb 127.0.0.1 xxxx-xxxx logstash-rdp-2020.11.05 0 p STARTED 24 57.6kb 127.0.0.1 xxxx-xxxx logstash-fileinfo-2020.11.05 0 p STARTED 314951 242.6mb 127.0.0.1 xxxx-xxxx dstats 0 p STARTED 1707 1.2mb 127.0.0.1 xxxx-xxxx dstats 0 r UNASSIGNED
hunts_v2 0 p STARTED 0 208b 127.0.0.1 xxxx-xxxx sessions2-201105 0 p STARTED 694666 1.1gb 127.0.0.1 xxxx-xxxx logstash-snmp-2020.11.05 0 p STARTED 1956343 327.1mb 127.0.0.1 xxxx-xxxx .kibana_2 0 p STARTED 1143 877.4kb 127.0.0.1 xxxx-xxxx logstash-http-2020.11.05 0 p STARTED 214058 138.2mb 127.0.0.1 xxxx-xxxx queries_v3 0 p STARTED 0 208b 127.0.0.1 xxxx-xxxx users_v7 0 p STARTED 2 13.3kb 127.0.0.1 xxxx-xxxx logstash-alert-2020.11.05 0 p STARTED 12324 27.8mb 127.0.0.1 xxxx-xxxx .kibana_3 0 p STARTED 1140 512.2kb 127.0.0.1 xxxx-xxxx logstash-smb-2020.11.05 0 p STARTED 75799 24.9mb 127.0.0.1 xxxx-xxxx logstash-anomaly-2020.11.05 0 p STARTED 6953 1.7mb 127.0.0.1 xxxx-xxxx stats_v4 0 p STARTED 0 208b 127.0.0.1 xxxx-xxxx sequence_v3 0 p STARTED 1 2.8kb 127.0.0.1 xxxx-xxxx .async-search 0 p STARTED 1 313.2kb 127.0.0.1 xxxx-xxxx logstash-dhcp-2020.11.05 0 p STARTED 63086 7.3mb 127.0.0.1 xxxx-xxxx .kibana_4 0 p STARTED 1148 483.2kb 127.0.0.1 xxxx-xxxx dstats_v4 1 p STARTED 0 208b 127.0.0.1 xxxx-xxxx dstats_v4 0 p STARTED 0 208b 127.0.0.1 xxxx-xxxx logstash-tls-2020.11.05 0 p STARTED 110890 86.5mb 127.0.0.1 xxxx-xxxx logstash-ssh-2020.11.05 0 p STARTED 19 145.6kb 127.0.0.1 xxxx-xxxx .apm-agent-configuration 0 p STARTED 0 261b 127.0.0.1 xxxx-xxxx .kibana_1 0 p STARTED 1145 412.2kb 127.0.0.1 xxxx-xxxx logstash-dns-2020.11.05 0 p STARTED 299908 129.6mb 127.0.0.1 xxxx-xxxx .apm-custom-link 0 p STARTED 0 261b 127.0.0.1 xxxx-xxxx files_v6 1 p STARTED 0 208b 127.0.0.1 xxxx-xxxx files_v6 0 p STARTED 2 8.8kb 127.0.0.1 xxxx-xxxx logstash-krb5-2020.11.05 0 p STARTED 2634 1mb 127.0.0.1 xxxx-xxxx logstash-2020.11.05 0 p STARTED 3060 13.7mb 127.0.0.1 xxxx-xxxx stats 0 p STARTED 1 2.1mb 127.0.0.1 xxxx-xxxx stats 0 r UNASSIGNED

how to fix it ? thank you very much.

pevma commented 3 years ago

Thanks for trying out SELKS. What is your question exactly - sorry if i may miss the obvious.

Product commented 3 years ago

Thanks for trying out SELKS. What is your question exactly - sorry if i may miss the obvious.

i have three questions.

  1. my management dashboard "capture stats " show no data available , and "memory usage" same 2 .the elasticsearch status is "yellow" . "cluster info " show "Unassigned shards"
  2. i run "selks-upgrade_stamus" and update the system ,then kibana show "Kibana did not load properly............."
pevma commented 3 years ago

Did you make sure the nginx config is up to date - https://github.com/StamusNetworks/SELKS/wiki/Kibana-did-not-load-properly

Product commented 3 years ago

Did you make sure the nginx config is up to date - https://github.com/StamusNetworks/SELKS/wiki/Kibana-did-not-load-properly

thank you very much my management dashboard "capture stats " show no data available , and "memory usage" same . how to fix this ?

pevma commented 3 years ago

It might have needed some time to populate?