wazuh / wazuh-docker

Wazuh - Docker containers
https://wazuh.com
Other
694 stars 397 forks source link

Wazuh AWS AMI- Dashboard will not load after update #1107

Open paminhoff opened 11 months ago

paminhoff commented 11 months ago

Ran yum update to patch the image. Once complete update, restarted server. Dashboard will not load.

systemctl status of manager, indexer and console below: wazuh-manager.service - Wazuh manager Loaded: loaded (/usr/lib/systemd/system/wazuh-manager.service; enabled; vendor preset: disabled) Active: active (running) since Mon 2023-11-13 19:19:58 UTC; 12min ago Process: 2265 ExecStart=/usr/bin/env /var/ossec/bin/wazuh-control start (code=exited, status=0/SUCCESS) CGroup: /system.slice/wazuh-manager.service ├─2601 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py ├─2602 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py ├─2605 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py ├─2608 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py ├─2651 /var/ossec/bin/wazuh-authd ├─2668 /var/ossec/bin/wazuh-db ├─2693 /var/ossec/bin/wazuh-execd ├─2708 /var/ossec/bin/wazuh-maild ├─2715 /var/ossec/bin/wazuh-analysisd ├─2728 /var/ossec/bin/wazuh-syscheckd ├─2750 /var/ossec/bin/wazuh-remoted ├─2815 /var/ossec/bin/wazuh-logcollector ├─2836 /var/ossec/bin/wazuh-monitord └─2857 /var/ossec/bin/wazuh-modulesd

Nov 13 19:19:50 wazuh-server env[2265]: Started wazuh-analysisd... Nov 13 19:19:51 wazuh-server env[2265]: Started wazuh-syscheckd... Nov 13 19:19:53 wazuh-server env[2265]: Started wazuh-remoted... Nov 13 19:19:54 wazuh-server env[2265]: Started wazuh-logcollector... Nov 13 19:19:55 wazuh-server env[2265]: Started wazuh-monitord... Nov 13 19:19:55 wazuh-server env[2265]: 2023/11/13 19:19:55 wazuh-modulesd: WARNING: 'update_from_year' option cannot be used for 'nvd' provider. Nov 13 19:19:56 wazuh-server env[2265]: Started wazuh-modulesd...

wazuh-indexer.service - Wazuh-indexer Loaded: loaded (/usr/lib/systemd/system/wazuh-indexer.service; enabled; vendor preset: disabled) Active: active (running) since Mon 2023-11-13 19:20:18 UTC; 13min ago Docs: https://documentation.wazuh.com Main PID: 2257 (java) CGroup: /system.slice/wazuh-indexer.service └─2257 /usr/share/wazuh-indexer/jdk/bin/java -Xshare:auto -Dopensearch.networkaddress.cache.ttl=60 -Dopensearch.networkaddress.cache.negative.ttl=10 -XX:+AlwaysPreTouch -Xss1m -Djava.awt.headless=true -Dfile....

Nov 13 19:19:28 wazuh-server systemd[1]: Starting Wazuh-indexer... Nov 13 19:19:36 wazuh-server systemd-entrypoint[2257]: WARNING: A terminally deprecated method in java.lang.System has been called Nov 13 19:19:36 wazuh-server systemd-entrypoint[2257]: WARNING: System::setSecurityManager has been called by org.opensearch.bootstrap.OpenSearch (file:/usr/share/wazuh-indexer/lib/opensearch-2.8.0.jar) Nov 13 19:19:36 wazuh-server systemd-entrypoint[2257]: WARNING: Please consider reporting this to the maintainers of org.opensearch.bootstrap.OpenSearch Nov 13 19:19:36 wazuh-server systemd-entrypoint[2257]: WARNING: System::setSecurityManager will be removed in a future release Nov 13 19:19:40 wazuh-server systemd-entrypoint[2257]: WARNING: A terminally deprecated method in java.lang.System has been called Nov 13 19:19:40 wazuh-server systemd-entrypoint[2257]: WARNING: System::setSecurityManager has been called by org.opensearch.bootstrap.Security (file:/usr/share/wazuh-indexer/lib/opensearch-2.8.0.jar) Nov 13 19:19:40 wazuh-server systemd-entrypoint[2257]: WARNING: Please consider reporting this to the maintainers of org.opensearch.bootstrap.Security Nov 13 19:19:40 wazuh-server systemd-entrypoint[2257]: WARNING: System::setSecurityManager will be removed in a future release

systemctl status wazuh-dashboard.service ● wazuh-dashboard.service - wazuh-dashboard Loaded: loaded (/etc/systemd/system/wazuh-dashboard.service; enabled; vendor preset: disabled) Active: failed (Result: exit-code) since Mon 2023-11-13 23:09:43 UTC; 43s ago Process: 1750 ExecStart=/usr/share/wazuh-dashboard/bin/opensearch-dashboards -c /etc/wazuh-dashboard/opensearch_dashboards.yml (code=exited, status=1/FAILURE) Main PID: 1750 (code=exited, status=1/FAILURE)

Nov 13 23:09:42 wazuh-server opensearch-dashboards[1750]: {"type":"log","@timestamp":"2023-11-13T23:09:42Z","tags":["info","savedobjects-service"],"pid":1750,"message":"...uilder\""} Nov 13 23:09:42 wazuh-server opensearch-dashboards[1750]: {"type":"log","@timestamp":"2023-11-13T23:09:42Z","tags":["info","savedobjects-service"],"pid":1750,"message":"...ibana_3."} Nov 13 23:09:43 wazuh-server opensearch-dashboards[1750]: {"type":"log","@timestamp":"2023-11-13T23:09:43Z","tags":["error","opensearch","data"],"pid":1750,"message":"[v...ds open;"} Nov 13 23:09:43 wazuh-server opensearch-dashboards[1750]: {"type":"log","@timestamp":"2023-11-13T23:09:43Z","tags":["warning","savedobjects-service"],"pid":1750,"message":"Unable ... Nov 13 23:09:43 wazuh-server opensearch-dashboards[1750]: {"type":"log","@timestamp":"2023-11-13T23:09:43Z","tags":["fatal","root"],"pid":1750,"message":"ResponseError: ...ds open;\n Nov 13 23:09:43 wazuh-server opensearch-dashboards[1750]: {"type":"log","@timestamp":"2023-11-13T23:09:43Z","tags":["info","plugins-system"],"pid":1750,"message":"Stoppi...plugins."} Nov 13 23:09:43 wazuh-server opensearch-dashboards[1750]: FATAL {"error":{"root_cause":[{"type":"validation_exception","reason":"Validation Failed: 1: this action would add [2] t... Nov 13 23:09:43 wazuh-server systemd[1]: wazuh-dashboard.service: main process exited, code=exited, status=1/FAILURE Nov 13 23:09:43 wazuh-server systemd[1]: Unit wazuh-dashboard.service entered failed state. Nov 13 23:09:43 wazuh-server systemd[1]: wazuh-dashboard.service failed. Hint: Some lines were ellipsized, use -l to show in full.

juruteknik commented 11 months ago

any workaround to solve this?

paminhoff commented 2 months ago

had to run update as document yum repo update breaks this. Also why is this still on AML2.