Closed taskula closed 6 months ago
Does this happen after a fresh restart of the agent? I ask, because I do see a way the agent could get into this state, for example if it submitted some events and some failed for some reason, it will try to resubmit all again. However, it should start clean, or at least given a different error, then enter this error state.
With Elasticsearch I've only ever seen all fail or none, so this is a case I'll have to look at more closely.
I did some testing with Opensearch 2.11.x a while back but am currently not running it. I'll see about flipping back to it again for a while.
I have not seen any more errors today after restarting the agent. That's odd because I was sure I tried restarting it before creating this issue. However as of now evebox-agent is working normally and no more error messages are present. I will report back if I am able to reproduce the issue. For now, thanks a ton for the quick response!
Hi,
First of all, thank you for the amazing project.
I have Evebox version 0.18.0 connected to OpenSearch 2.10.2. Evebox-agents are sending Suricata events to OpenSearch and the events can be viewed on my Evebox server. My problem is that on our Suricata/evebox-agent hosts, syslog grows daily by a few GB with the following errors:
I have cut the logs by "..." but the same error message just keeps repeating (with different "_id" value), and the above two entries are repeated every second in syslog/journal.
agent.yaml
Am I missing something?