Closed ThepoisonedApple closed 2 years ago
Hello @ThepoisonedApple
Thanks for reporting this, we will investigate it and we will apply a fix accordingly if necessary, could you tell us in which system you are performing the migration?
Regards, Raúl.
system info: OS: Debian19 cluster: all in one Before migration: wazuh-manager 4.2.5-1 opendistroforelasticsearch 1.13.2-1 opendistroforelasticsearch-kibana 1.13.2 filebeat 7.10.2 After Migration: wazuh-manager 4.3.4-1 wazuh-indexer 4.3.4-1 wazuh-dashboard 4.3.4-1 filebeat 7.10.2
By default, the documentation recommends uninstalling the opendistro-perfomance-analyzer
plugin and the unattended installation of 4.2 removes the plugin automatically during the install process, it may be the case that the user does a step-by-step and keeps the plugin, so that when starting elasticsearch the following directory is created in /dev/shm/:
drwxr-xr-x. 2 elasticsearch elasticsearch 40 Jun 27 14:24 performanceanalyzer
When performing the migration process, I have reproduced the error in Centos 8 Stream, error in /var/log/wazuh-indexer/wazuh-cluster.log file:
[2022-06-27T14:29:05,022][ERROR][o.o.p.r.EventLogFileHandler] [node-1] Error writing entry 'NOT_INITIALIZED'. Cause:
java.nio.file.AccessDeniedException: /dev/shm/performanceanalyzer/1656340140000.tmp
Conclusion, a note should be added in the migration process to change the owner and group of this directory recursively to wazuh-indexer, as @ThepoisonedApple proposes
More information about the /dev/shm directory: https://datacadamia.com/os/linux/shared_memory
The /dev/shm directory seems to be neccessary to be mounted (tried to start service with shared memory disabled)
Reported orphan directory if uninstall is performed: https://github.com/wazuh/wazuh-packages/issues/1693
Regards, Raúl.
After migration performance analyzer gives error.
solution:
needs to be added after Migrating to the Wazuh indexer step 8