socprime / soc_workflow_app_ce

SOC Workflow App helps Security Analysts and Threat Hunters explore suspicious events, look into raw events arriving at the Elastic Stack, and view Saved Searches configured by teammates.
https://my.socprime.com/soc-workflow-app/
Other
92 stars 26 forks source link

Plugin soc_workflow_ce [6.6.1] is incompatible with Kibana [7.1.0] #7

Closed peasead closed 4 years ago

peasead commented 5 years ago

I was trying to do a fresh plugin install on version 7.1 of the Elastic Stack and got the following error.

sudo /usr/share/kibana/bin/./kibana-plugin install file:///home/user/soc_workflow_app_ce/dist/soc_workflow_ce_1.9.4.zip
Attempting to transfer from file:///home/user/soc_workflow_app_ce/dist/soc_workflow_ce_1.9.4.zip
Transferring 12610186 bytes....................
Transfer complete
Retrieving metadata from plugin archive
Extracting plugin archive
Extraction complete
Plugin installation was unsuccessful due to error "Plugin soc_workflow_ce [6.6.1] is incompatible with Kibana [7.1.0]"

I tried to go into ./soc_workflow_app_ce/soc_workflow_ce/package.json and change kibana to 7.1.0, but as expected, that didn't fix the issue.

Elasticsearch

{
  "name" : "rocknsm",
  "cluster_name" : "rocknsm",
  "cluster_uuid" : "3zEgGHU0RvaLrLIrLKMZ9Q",
  "version" : {
    "number" : "7.1.0",
    "build_flavor" : "default",
    "build_type" : "rpm",
    "build_hash" : "606a173",
    "build_date" : "2019-05-16T00:43:15.323135Z",
    "build_snapshot" : false,
    "lucene_version" : "8.0.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

Kibana

{
  "name": "rocknsm",
  "uuid": "a4acc597-da8f-403f-82eb-ea291fdccb27",
  "version": {
    "number": "7.1.0",
    "build_hash": "7bdb99203c3b0d113668b9a96b1daaa920d654a2",
    "build_number": 23222,
    "build_snapshot": false
  },
socprime commented 5 years ago

Kibana version 7 isn't supported by SOC Workflow App CE in this repository for the present moment, but we plan to update the version of the application with new features in this repository

Zuckonit commented 4 years ago

any progress?

peasead commented 4 years ago

Whelp...the install worked when I updated package.json to 7.4.2 (which is my Kibnana version).

When I restarted Kibana, I had this error when I clicked on the SOC Workflow app

Version: 7.4.2
Build: 26506
Error: [$injector:modulerr] Failed to instantiate module kibana due to:
[$injector:modulerr] Failed to instantiate module app/soc_workflow_ce due to:
[$injector:modulerr] Failed to instantiate module ui.select due to:
[$injector:nomod] Module 'ui.select' is not available! You either misspelled the module name or forgot to load it. If registering a module ensure that you specify the dependencies as the second argument.

https://errors.angularjs.org/1.7.8/$injector/modulerr?p0=kibana&p1=%5B%24injector%3Amodulerr%5D%20Failed%20to%20instantiate%20module%20app%2Fsoc_workflow_ce%20due%20to%3A%0A%5B%24injector%3Amodulerr%5D%20Failed%20to%20instantiate%20module%20ui.select%20due%20to%3A%0A%5B%24injector%3Anomod%5D%20Module%20'ui.select'%20is%20not%20available!%20You%20either%20misspelled%20the%20module%20name%20or%20forgot%20to%20load%20it.%20If%20registering%20a%20module%20ensure%20that%20you%20specify%20the%20dependencies%20as%20the%20second%20argument.%0A%0A%0Ahttps%3A%2F%2Ferrors.angularjs.org%2F1.7.8%2F%24injector%2Fmodulerr%3Fp0%3Dapp%252Fsoc_workflow_ce%26p1%3D%255B%2524injector%253Amodulerr%255D%2520Failed%2520to%2520instantiate%2520module%2520ui.select%2520due%2520to%253A%250A%255B%2524injector%253Anomod%255D%2520Module%2520'ui.select'%2520is%2520not%2520available!%2520You%2520either%2520misspelled%2520the%2520module%2520name%2520or%2520forgot%2520to%2520load%2520it.%2520If%2520registering%2520a%2520module%2520ensure%2520that%2520you%2520specify%2520the%2520dependencies%2520as%2520the%2520second%2520argument.%250A%250Ahttps%253A%252F%252Ferrors.angularjs.org%252F1.7.8%252F%2524injector%252Fmodulerr%253Fp0%253Dui.select%2526p1%253D%25255B%252524injector%25253Anomod%25255D%252520Module%252520'ui.select'%252520is%252520not%252520available!%252520You%252520either%252520misspelled%252520the%252520module%252520name%252520or%252520forgot%252520to%252520load%252520it.%252520If%252520registering%252520a%252520module%252520ensure%252520that%252520you%252520specify%252520the%252520dependencies%252520as%252520the%252520second%252520argument.%25250Ahttps%25253A%25252F%25252Ferrors.angularjs.org%25252F1.7.8%25252F%252524injector%25252Fnomod%25253Fp0%25253Dui.select%25250Ahttps%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A1394%25250Ahttps%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A21517%25250Aensure%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A20985%25250Ahttps%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A51569%25250AforEach%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A2611%25250AloadModules%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A51225%25250Ahttps%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A51658%25250AforEach%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A2611%25250AloadModules%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A51225%25250Ahttps%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A51658%25250AforEach%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A2611%25250AloadModules%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A51225%25250AcreateInjector%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A49261%25250AdoBootstrap%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A417%25253A17184%25250Ahttps%25253A%25252F%25252F192.168.132.172%25252Fbundles%25252Fcommons.bundle.js%25253A3%25253A2307419%25250Astart%252540https%25253A%25252F%25252F192.168.132.172%25252Fbundles%25252Fcommons.bundle.js%25253A3%25253A2303377%25250AtryCatch%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A471%25253A789580%25250Ainvoke%252540https%25253A%25252F%25252F192.168.132.172%25252Fbuilt_assets%25252Fdlls%25252Fvendors.bundle.dll.js%25253A471%25253A793419%25250AasyncGeneratorStep%252540https%25253A%25252F%25252F192.168.132.172%25252Fbundles%25252Fcommons.bundle.js%25253A3%25253A2292425%25250A_next%252540https%25253A%25252F%25252F192.168.132.172%25252Fbundles%25252Fcommons.bundle.js%25253A3%25253A2292753%25250ApromiseReactionJob%252540%25255Bnative%252520code%25255D%250Ahttps%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A1394%250Ahttps%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A52109%250AforEach%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A2611%250AloadModules%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A51225%250Ahttps%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A51658%250AforEach%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A2611%250AloadModules%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A51225%250Ahttps%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A51658%250AforEach%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A2611%250AloadModules%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A51225%250AcreateInjector%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A49261%250AdoBootstrap%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A417%253A17184%250Ahttps%253A%252F%252F192.168.132.172%252Fbundles%252Fcommons.bundle.js%253A3%253A2307419%250Astart%2540https%253A%252F%252F192.168.132.172%252Fbundles%252Fcommons.bundle.js%253A3%253A2303377%250AtryCatch%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A471%253A789580%250Ainvoke%2540https%253A%252F%252F192.168.132.172%252Fbuilt_assets%252Fdlls%252Fvendors.bundle.dll.js%253A471%253A793419%250AasyncGeneratorStep%2540https%253A%252F%252F192.168.132.172%252Fbundles%252Fcommons.bundle.js%253A3%253A2292425%250A_next%2540https%253A%252F%252F192.168.132.172%252Fbundles%252Fcommons.bundle.js%253A3%253A2292753%250ApromiseReactionJob%2540%255Bnative%2520code%255D%0Ahttps%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A1394%0Ahttps%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A52109%0AforEach%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A2611%0AloadModules%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A51225%0Ahttps%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A51658%0AforEach%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A2611%0AloadModules%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A51225%0AcreateInjector%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A49261%0AdoBootstrap%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A417%3A17184%0Ahttps%3A%2F%2F192.168.132.172%2Fbundles%2Fcommons.bundle.js%3A3%3A2307419%0Astart%40https%3A%2F%2F192.168.132.172%2Fbundles%2Fcommons.bundle.js%3A3%3A2303377%0AtryCatch%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A471%3A789580%0Ainvoke%40https%3A%2F%2F192.168.132.172%2Fbuilt_assets%2Fdlls%2Fvendors.bundle.dll.js%3A471%3A793419%0AasyncGeneratorStep%40https%3A%2F%2F192.168.132.172%2Fbundles%2Fcommons.bundle.js%3A3%3A2292425%0A_next%40https%3A%2F%2F192.168.132.172%2Fbundles%2Fcommons.bundle.js%3A3%3A2292753%0ApromiseReactionJob%40%5Bnative%20code%5D
https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:417:1394
https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:417:52109
forEach@https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:417:2611
loadModules@https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:417:51225
createInjector@https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:417:49261
doBootstrap@https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:417:17184
https://192.168.132.172/bundles/commons.bundle.js:3:2307419
start@https://192.168.132.172/bundles/commons.bundle.js:3:2303377
tryCatch@https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:471:789580
invoke@https://192.168.132.172/built_assets/dlls/vendors.bundle.dll.js:471:793419
asyncGeneratorStep@https://192.168.132.172/bundles/commons.bundle.js:3:2292425
_next@https://192.168.132.172/bundles/commons.bundle.js:3:2292753
promiseReactionJob@[native code]

Steps:

socprime commented 4 years ago

Hello peasead! Thank you for your interest in our apps. The error "Module 'ui.select' is not available!" is directly connected with version incompatibility problem

syloktools commented 4 years ago

Really need to get this going. I am having the same issue.

Anna7835 commented 4 years ago

Is Kibana 7.4.2 supported now?

socprime commented 4 years ago

Hello everyone! Thank you for your interest in our apps and for your patience. We have just updated the SOC Workflow App Community Edition to version 3.7.4. Now it supports ELK stack up to version 7.6.1. You can download it from this repository or from our Marketplace - tdm.socprime.com