nksft / graylog2-plugin-exec

An alarm callback plugin for executing a script on Graylog2's server.
MIT License
11 stars 14 forks source link

alert is being triggered but script not running #3

Closed ovadm closed 7 years ago

ovadm commented 7 years ago

Hello,

I set permissions for user graylog to all path and verified that it can execute the script from cli, I even set graylog gid to zero but it didn't help - script still not being executed.

Is there any log file that I can look for the problem

Thanks Ovad

nksft commented 7 years ago

Hi Ovad,

Just for testing you can touch a file in /tmp folder (touch /tmp/test) or put your script in /tmp folder and make it executable. My test script is: #!/bin/bash echo "Test Script $@" >> /tmp/test.log

and in my plugin config: (/tmp/test.sh input1)

ovadm commented 7 years ago

Hi,

I already tried this with no success. I am able to run other java classes with no issue Java version is 7 Graylog usermod set with group 0

Thanks, Ovad

From: nksft [mailto:notifications@github.com] Sent: Thursday, February 23, 2017 3:37 PM To: nksft/graylog2-plugin-exec graylog2-plugin-exec@noreply.github.com Cc: Ovadia Mani ovadm@amdocs.com; Author author@noreply.github.com Subject: Re: [nksft/graylog2-plugin-exec] alert is being triggered but script not running (#3)

Hi Ovad,

Just for testing you can touch a file in /tmp folder (touch /tmp/test) or put your script in /tmp folder and make it executable. My test script is:

!/bin/bash

echo "Test Script $@" >> /tmp/test.log

and in my plugin config: (/tmp/test.sh input1)

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/nksft/graylog2-plugin-exec/issues/3#issuecomment-281992992, or mute the threadhttps://github.com/notifications/unsubscribe-auth/ALMOysucOkdcpWw86f1zWl2xIv56I-x9ks5rfYtwgaJpZM4MIpG9. This message and the information contained herein is proprietary and confidential and subject to the Amdocs policy statement,

you may review at http://www.amdocs.com/email_disclaimer.asp

ovadm commented 7 years ago

Also with command lsof | grep execommand-alarmcallback-1.0.0.jar I can see that the file opens many times

From: Ovadia Mani Sent: Thursday, February 23, 2017 4:16 PM To: 'nksft/graylog2-plugin-exec' reply@reply.github.com; nksft/graylog2-plugin-exec graylog2-plugin-exec@noreply.github.com Cc: Author author@noreply.github.com Subject: RE: [nksft/graylog2-plugin-exec] alert is being triggered but script not running (#3)

Hi,

I already tried this with no success. I am able to run other java classes with no issue Java version is 7 Graylog usermod set with group 0

Thanks, Ovad

From: nksft [mailto:notifications@github.com] Sent: Thursday, February 23, 2017 3:37 PM To: nksft/graylog2-plugin-exec graylog2-plugin-exec@noreply.github.com<mailto:graylog2-plugin-exec@noreply.github.com> Cc: Ovadia Mani ovadm@amdocs.com<mailto:ovadm@amdocs.com>; Author author@noreply.github.com<mailto:author@noreply.github.com> Subject: Re: [nksft/graylog2-plugin-exec] alert is being triggered but script not running (#3)

Hi Ovad,

Just for testing you can touch a file in /tmp folder (touch /tmp/test) or put your script in /tmp folder and make it executable. My test script is:

!/bin/bash

echo "Test Script $@" >> /tmp/test.log

and in my plugin config: (/tmp/test.sh input1)

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/nksft/graylog2-plugin-exec/issues/3#issuecomment-281992992, or mute the threadhttps://github.com/notifications/unsubscribe-auth/ALMOysucOkdcpWw86f1zWl2xIv56I-x9ks5rfYtwgaJpZM4MIpG9. This message and the information contained herein is proprietary and confidential and subject to the Amdocs policy statement,

you may review at http://www.amdocs.com/email_disclaimer.asp

ovadm commented 7 years ago

btw though the jar file opens, I couldn't find any of the classes inside running

nksft commented 7 years ago

Oracle Java SE 8 or later is in the Graylog 2 requirements. Maybe this will help to solve your problem.

ovadm commented 7 years ago

No, same result.

From: nksft [mailto:notifications@github.com] Sent: Thursday, February 23, 2017 5:03 PM To: nksft/graylog2-plugin-exec graylog2-plugin-exec@noreply.github.com Cc: Ovadia Mani ovadm@amdocs.com; Author author@noreply.github.com Subject: Re: [nksft/graylog2-plugin-exec] alert is being triggered but script not running (#3)

Oracle Java SE 8 or later is in the Graylog 2 requirementshttp://docs.graylog.org/en/2.2/pages/installation.html#system-requirements. Maybe this will help to solve your problem.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/nksft/graylog2-plugin-exec/issues/3#issuecomment-282015663, or mute the threadhttps://github.com/notifications/unsubscribe-auth/ALMOymtPb0sduZSUWX68d0EN_a0Asiuzks5rfZ-tgaJpZM4MIpG9. This message and the information contained herein is proprietary and confidential and subject to the Amdocs policy statement,

you may review at http://www.amdocs.com/email_disclaimer.asp

ovadm commented 7 years ago

Solved following gl upgrade to 2.2.1 Not sure why thanks

From: nksft [mailto:notifications@github.com] Sent: Thursday, February 23, 2017 5:03 PM To: nksft/graylog2-plugin-exec graylog2-plugin-exec@noreply.github.com Cc: Ovadia Mani ovadm@amdocs.com; Author author@noreply.github.com Subject: Re: [nksft/graylog2-plugin-exec] alert is being triggered but script not running (#3)

Oracle Java SE 8 or later is in the Graylog 2 requirementshttp://docs.graylog.org/en/2.2/pages/installation.html#system-requirements. Maybe this will help to solve your problem.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/nksft/graylog2-plugin-exec/issues/3#issuecomment-282015663, or mute the threadhttps://github.com/notifications/unsubscribe-auth/ALMOymtPb0sduZSUWX68d0EN_a0Asiuzks5rfZ-tgaJpZM4MIpG9. This message and the information contained herein is proprietary and confidential and subject to the Amdocs policy statement,

you may review at http://www.amdocs.com/email_disclaimer.asp

nksft commented 7 years ago

Glad to hear it. What was your gl version?

ovadm commented 7 years ago

2.1.2

From: nksft [mailto:notifications@github.com] Sent: Tuesday, February 28, 2017 10:28 AM To: nksft/graylog2-plugin-exec graylog2-plugin-exec@noreply.github.com Cc: Ovadia Mani ovadm@amdocs.com; Author author@noreply.github.com Subject: Re: [nksft/graylog2-plugin-exec] alert is being triggered but script not running (#3)

Glad to hear it. What was your gl version?

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/nksft/graylog2-plugin-exec/issues/3#issuecomment-282974396, or mute the threadhttps://github.com/notifications/unsubscribe-auth/ALMOyp9r1jTEjOPUMW1IBInPQWbvNCKvks5rg9p0gaJpZM4MIpG9. This message and the information contained herein is proprietary and confidential and subject to the Amdocs policy statement,

you may review at http://www.amdocs.com/email_disclaimer.asp