-
Notifications
You must be signed in to change notification settings - Fork 285
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Kibana did not load properly. Check the server output for more information #238
Comments
root@SELKS:~# selks-health-check_stamus Jun 23 18:57:07 SELKS systemd[1]: Starting LSB: Next Generation IDS/IPS... Jun 23 18:57:07 SELKS systemd[1]: Starting Elasticsearch... Jun 23 18:57:52 SELKS logstash[374]: [2020-06-23T18:57:52,818][INFO ][logstash.outputs.elasticsearch][main] Attempting to install template {:manage_template=>{"template"=>"… Jun 23 18:57:36 SELKS kibana[373]: {"type":"log","@timestamp":"2020-06-23T15:57:36Z","tags":["listening","info"],"pid":373,"message":"Server running at http:/…calhost:5601"} Jun 23 18:57:12 SELKS evebox[367]: 2020-06-23 18:57:12 (server.go:335) -- Failed to ping Elastic Search, delaying startup: : Get "http://localhost:920…ection refused Jun 23 18:58:39 SELKS systemd[1]: molochviewer-selks.service: Scheduled restart job, restart counter is at 1. Jun 23 18:58:36 SELKS systemd[1]: Started Moloch Pcap Read. |
Can you try resetting the dashboards from the web Interface?
… --
Regards,
Peter Manev
On 23 Jun 2020, at 18:28, MaratKzn ***@***.***> wrote:
***@***.***:~# selks-health-check_stamus
● suricata.service - LSB: Next Generation IDS/IPS
Loaded: loaded (/etc/init.d/suricata; generated)
Active: active (running) since Tue 2020-06-23 18:57:07 EEST; 30min ago
Docs: man:systemd-sysv-generator(8)
Process: 654 ExecStart=/etc/init.d/suricata start (code=exited, status=0/SUCCESS)
Tasks: 10 (limit: 4915)
Memory: 325.0M
CGroup: /system.slice/suricata.service
└─704 /usr/bin/suricata -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata.pid --af-packet -D -v --user=logstash
Jun 23 18:57:07 SELKS systemd[1]: Starting LSB: Next Generation IDS/IPS...
Jun 23 18:57:07 SELKS suricata[654]: Starting suricata in IDS (af-packet) mode... done.
Jun 23 18:57:07 SELKS systemd[1]: Started LSB: Next Generation IDS/IPS.
● elasticsearch.service - Elasticsearch
Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2020-06-23 18:57:26 EEST; 30min ago
Docs: https://www.elastic.co
Main PID: 653 (java)
Tasks: 97 (limit: 4915)
Memory: 1.6G
CGroup: /system.slice/elasticsearch.service
├─653 /usr/share/elasticsearch/jdk/bin/java -Xshare:auto -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=10 -XX:+AlwaysPreTouch -Xss1m -D…
└─901 /usr/share/elasticsearch/modules/x-pack-ml/platform/linux-x86_64/bin/controller
Jun 23 18:57:07 SELKS systemd[1]: Starting Elasticsearch...
Jun 23 18:57:26 SELKS systemd[1]: Started Elasticsearch.
● logstash.service - logstash
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2020-06-23 18:57:06 EEST; 30min ago
Main PID: 374 (java)
Tasks: 37 (limit: 4915)
Memory: 960.4M
CGroup: /system.slice/logstash.service
└─374 /bin/java -Xms1g -Xmx1g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -Djava.awt.headless=true -Dfile.en…
Jun 23 18:57:52 SELKS logstash[374]: [2020-06-23T18:57:52,818][INFO ][logstash.outputs.elasticsearch][main] Attempting to install template {:manage_template=>{"template"=>"…
Jun 23 18:57:52 SELKS logstash[374]: [2020-06-23T18:57:52,835][INFO ][logstash.outputs.elasticsearch][main] Installing elasticsearch template to _template/logstash
Jun 23 18:57:52 SELKS logstash[374]: [2020-06-23T18:57:52,841][INFO ][logstash.outputs.elasticsearch][main] Installing elasticsearch template to _template/logstash
Jun 23 18:57:52 SELKS logstash[374]: [2020-06-23T18:57:52,980][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/vendor…2-City.mmdb"}
Jun 23 18:57:53 SELKS logstash[374]: [2020-06-23T18:57:53,134][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/vendor…2-City.mmdb"}
Jun 23 18:57:53 SELKS logstash[374]: [2020-06-23T18:57:53,207][INFO ][logstash.javapipeline ][main] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>4, "pipe…
Jun 23 18:57:54 SELKS logstash[374]: [2020-06-23T18:57:54,481][INFO ][logstash.javapipeline ][main] Pipeline started {"pipeline.id"=>"main"}
Jun 23 18:57:54 SELKS logstash[374]: [2020-06-23T18:57:54,520][INFO ][logstash.agent ] Pipelines running {:count=>1, :running_pipelines=>[:main], :no…ipelines=>[]}
Jun 23 18:57:54 SELKS logstash[374]: [2020-06-23T18:57:54,522][INFO ][filewatch.observingtail ][main][d4aef1d642dafd3cc0ec28e9e79530daa4bc5c58ba6b725806ceff6c…b collections
Jun 23 18:57:54 SELKS logstash[374]: [2020-06-23T18:57:54,777][INFO ][logstash.agent ] Successfully started Logstash API endpoint {:port=>9600}
Hint: Some lines were ellipsized, use -l to show in full.
● kibana.service - Kibana
Loaded: loaded (/etc/systemd/system/kibana.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2020-06-23 18:57:06 EEST; 30min ago
Main PID: 373 (node)
Tasks: 11 (limit: 4915)
Memory: 1.1G
CGroup: /system.slice/kibana.service
└─373 /usr/share/kibana/bin/../node/bin/node /usr/share/kibana/bin/../src/cli
Jun 23 18:57:36 SELKS kibana[373]: ***@***.***":"2020-06-23T15:57:36Z","tags":["listening","info"],"pid":373,"message":"Server running at http:/…calhost:5601"}
Jun 23 18:57:37 SELKS kibana[373]: ***@***.***":"2020-06-23T15:57:37Z","tags":["info","http","server","Kibana"],"pid":373,"message":"http server…calhost:5601"}
Jun 23 18:58:19 SELKS kibana[373]: ***@***.***":"2020-06-23T15:58:19Z","tags":[],"pid":373,"method":"get","statusCode":400,"req":{"url":"/api/saved_objec…
Jun 23 18:58:24 SELKS kibana[373]: ***@***.***":"2020-06-23T15:58:24Z","tags":[],"pid":373,"method":"get","statusCode":404,"req":{"url":"/bundles/25.bund…
Jun 23 18:58:27 SELKS kibana[373]: ***@***.***":"2020-06-23T15:58:27Z","tags":[],"pid":373,"method":"post","statusCode":400,"req":{"url":"/internal/searc…
Jun 23 18:58:35 SELKS kibana[373]: ***@***.***":"2020-06-23T15:58:35Z","tags":[],"pid":373,"method":"post","statusCode":400,"req":{"url":"/api/ui_metric/…
Jun 23 18:59:09 SELKS kibana[373]: ***@***.***":"2020-06-23T15:59:09Z","tags":[],"pid":373,"method":"get","statusCode":302,"req":{"url":"/","method":"get…
Jun 23 18:59:09 SELKS kibana[373]: ***@***.***":"2020-06-23T15:59:09Z","tags":[],"pid":373,"method":"get","statusCode":302,"req":{"url":"/spaces/enter","…
Jun 23 18:59:09 SELKS kibana[373]: ***@***.***":"2020-06-23T15:59:09Z","tags":[],"pid":373,"method":"get","statusCode":200,"req":{"url":"/app/kibana","me…
Jun 23 18:59:09 SELKS kibana[373]: ***@***.***":"2020-06-23T15:59:09Z","tags":["api"],"pid":373,"method":"get","statusCode":200,"req":{"url":"/bundles/ap…
Hint: Some lines were ellipsized, use -l to show in full.
● evebox.service - EveBox Server
Loaded: loaded (/lib/systemd/system/evebox.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2020-06-23 18:57:06 EEST; 30min ago
Main PID: 367 (evebox)
Tasks: 8 (limit: 4915)
Memory: 38.9M
CGroup: /system.slice/evebox.service
└─367 /usr/bin/evebox server
Jun 23 18:57:12 SELKS evebox[367]: 2020-06-23 18:57:12 (server.go:335) -- Failed to ping Elastic Search, delaying startup: : Get "http://localhost:920…ection refused
Jun 23 18:57:15 SELKS evebox[367]: 2020-06-23 18:57:15 (server.go:335) -- Failed to ping Elastic Search, delaying startup: : Get "http://localhost:920…ection refused
Jun 23 18:57:18 SELKS evebox[367]: 2020-06-23 18:57:18 (server.go:335) -- Failed to ping Elastic Search, delaying startup: : Get "http://localhost:920…ection refused
Jun 23 18:57:21 SELKS evebox[367]: 2020-06-23 18:57:21 (server.go:335) -- Failed to ping Elastic Search, delaying startup: : Get "http://localhost:920…ection refused
Jun 23 18:57:24 SELKS evebox[367]: 2020-06-23 18:57:24 (server.go:335) -- Failed to ping Elastic Search, delaying startup: : Get "http://localhost:920…ection refused
Jun 23 18:57:28 SELKS evebox[367]: 2020-06-23 18:57:28 (server.go:338) -- Connected to Elastic Search (version: 7.8.0)
Jun 23 18:57:28 SELKS evebox[367]: 2020-06-23 18:57:28 (elasticsearch.go:177) -- Assuming Logstash style index
Jun 23 18:57:28 SELKS evebox[367]: 2020-06-23 18:57:28 (server.go:131) -- Session reaper started
Jun 23 18:57:28 SELKS evebox[367]: 2020-06-23 18:57:28 (server.go:165) -- Authentication disabled.
Jun 23 18:57:28 SELKS evebox[367]: 2020-06-23 18:57:28 (server.go:261) -- Listening on [127.0.0.1]:5636
Hint: Some lines were ellipsized, use -l to show in full.
● molochviewer-selks.service - Moloch Viewer
Loaded: loaded (/etc/systemd/system/molochviewer-selks.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2020-06-23 18:58:39 EEST; 29min ago
Main PID: 1200 (sh)
Tasks: 12 (limit: 4915)
Memory: 43.0M
CGroup: /system.slice/molochviewer-selks.service
├─1200 /bin/sh -c /data/moloch/bin/node viewer.js -c /data/moloch/etc/config.ini >> /data/moloch/logs/viewer.log 2>&1
└─1201 /data/moloch/bin/node viewer.js -c /data/moloch/etc/config.ini
Jun 23 18:58:39 SELKS systemd[1]: molochviewer-selks.service: Scheduled restart job, restart counter is at 1.
Jun 23 18:58:39 SELKS systemd[1]: Stopped Moloch Viewer.
Jun 23 18:58:39 SELKS systemd[1]: Started Moloch Viewer.
● molochpcapread-selks.service - Moloch Pcap Read
Loaded: loaded (/etc/systemd/system/molochpcapread-selks.service; enabled; vendor preset: enabled)
Active: active (running) since Tue 2020-06-23 18:58:36 EEST; 29min ago
Main PID: 1190 (sh)
Tasks: 5 (limit: 4915)
Memory: 206.0M
CGroup: /system.slice/molochpcapread-selks.service
├─1190 /bin/sh -c /data/moloch/bin/moloch-capture -c /data/moloch/etc/config.ini -m -s -R /data/nsm/ >> /data/moloch/logs/capture.log 2>&1
└─1191 /data/moloch/bin/moloch-capture -c /data/moloch/etc/config.ini -m -s -R /data/nsm/
Jun 23 18:58:36 SELKS systemd[1]: Started Moloch Pcap Read.
scirius RUNNING pid 804, uptime 0:30:51
ii elasticsearch 7.8.0 amd64 Distributed RESTful search engine built for the cloud
ii elasticsearch-curator 5.8.1 amd64 Have indices in Elasticsearch? This is the tool for you!\n\nLike a museum curator manages the exhibits and collections on display, \nElasticsearch Curator helps you curate, or manage your indices.
ii evebox 1:0.11.1 amd64 no description given
ii kibana 7.8.0 amd64 Explore and visualize your Elasticsearch data
ii kibana-dashboards-stamus 2020042401 amd64 Kibana 6 dashboard templates.
ii logstash 1:7.8.0-1 all An extensible logging pipeline
ii moloch 2.3.1-1 amd64 Moloch Full Packet System
ii scirius 3.5.0-3 amd64 Django application to manage Suricata ruleset
ii suricata 1:2020050401-0stamus0 amd64 Suricata open source multi-thread IDS/IPS/NSM system.
Filesystem Type Size Used Avail Use% Mounted on
udev devtmpfs 16G 0 16G 0% /dev
tmpfs tmpfs 3.2G 17M 3.2G 1% /run
/dev/sda1 ext4 438G 6.0G 409G 2% /
tmpfs tmpfs 16G 0 16G 0% /dev/shm
tmpfs tmpfs 5.0M 0 5.0M 0% /run/lock
tmpfs tmpfs 16G 0 16G 0% /sys/fs/cgroup
tmpfs tmpfs 3.2G 0 3.2G 0% /run/user/0
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or unsubscribe.
|
Yes! |
Meant from the gui , (sorry Should have been clearer )
https://github.com/StamusNetworks/SELKS/wiki/How-to-load-or-update-dashboards#from-scirius
You can also just download ready to use SELKS 6
https://github.com/StamusNetworks/SELKS/wiki/First-time-setup
Or you were upgrading from 5? (Just do I don’t misunderstand )
… --
Regards,
Peter Manev
On 24 Jun 2020, at 09:19, MaratKzn ***@***.***> wrote:
Yes!
cd /usr/share/python/scirius/ && . bin/activate && python bin/manage.py kibana_reset && deactivate
Reset does not help!
I want to clarify that after installation everything works, problems begin after the update.
—
You are receiving this because you commented.
Reply to this email directly, view it on GitHub, or unsubscribe.
|
Done!
I made a clean installation of SELKS 6.0 from your finished build: SELKS-6.0-nodesktop.iso |
If you are on a Chrome - can you pres Ctrl+Shif+j when you reload the kibana page , does it show any erros? |
I had the same issue. I fix it by adding the setting below to my /etc/nginx/sites-available/selks6.conf Maybe just workaround. Any suggestion? |
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'unsafe-eval' 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-P5polb1UreUSOe5V/Pv7tc+yeZuJXiOi/3fqhGsU7BE='), or a nonce ('nonce-...') is required to enable inline execution. bootstrap.js:11 ^ A single error about an inline script not firing due to content security policy is expected! |
That - #238 (comment) is your fix i think. |
After adding to /etc/nginx/sites-available/selks6.conf, it works! |
Do you have |
Well, here is no users_v7 index. Not created. |
I am not sure to be honest - what is the users_v7 index? |
I don't know. But, the completely fresh install SELKS6 have this index and SELKS5 to SELKS6 upgrade don't have this index.
Is it here some console script to complete re-create all indexes?
7. července 2020 15:23:56 SELČ, Peter Manev <notifications@github.com> napsal:
…I am not sure to be honest - what is the users_v7 index?
--
You are receiving this because you commented.
Reply to this email directly or view it on GitHub:
#238 (comment)
--
Odesláno z mého telefonu s Androidem pomocí pošty K-9 Mail. Omluvte prosím moji stručnost.
|
Not that i know of - but i think this might be the set up for the user by Moloch done during first time setup script. |
It could have been also that there was some migration in process not finished yet. |
After upgrading Kibana to 7.9.2 you need add the new block to Nginx with new port
|
I have updated the docs here - https://github.com/StamusNetworks/SELKS/wiki/Kibana-did-not-load-properly |
After upgrade Kibana to 7.10.1 need to add new block to nginx config, as before -
|
Updated the docs - https://github.com/StamusNetworks/SELKS/wiki/Kibana-did-not-load-properly |
After SELKS 6.0 install and
selks-upgrade_stamus
ELK stack 7.8.0
The text was updated successfully, but these errors were encountered: