New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
No Data in Kibana or Moloch after upload #117
Comments
A couple things we could due to debug:
|
debug.txt |
There is some some weird stuff going on right off the bat, not quite sure what to think of it:
...
...
and all sorts of other errors about "no living connections" soon thereafter. But here's the other thing that's weird, a little bit later:
So I see a couple of things that I haven't seen before:
Anyway, these seem to be both related to the issues you're having. Something specific to your system configuration or platform, as I've never seen these particular errors in the distros I've tested Malcolm on. |
The VM is running 16GB RAM. output of ulimit -a
zeek
zeek-logs/upload
|
the If you run The other thing that's weird is that everything's owned by root. Normally everything can run as a regular user just fine. If it were me, I would to this:
|
I went back through my OS configurations all were present as specified in the Operating system configuration. I was able to resolve the problem after a rebuild. I did not create a non root user account prior to running 'install.py'. The malcolm directory was built under the non-existing users path i.e. /home/user/Malcolm. I am now seeing data, thank you so much for all the help. |
Super, I'm glad. Have a good day, stay safe. |
I followed the installation guide for Ubuntu 18.04 LTS, I used the git method for grabbing the install files. Everything installed and populated exactly as stated in the guide. When I attempt to upload a pcap through https://localhost:8443 the pcap is accepted. I have validated this by checking the pcap/upload directory and I see it move over to the pcap/processed directory. The mime type for my pcap shows "application/vnd.tcpdump.pcap". I also ran "docker-compose ps" and everything is "up" with elastalert, kibana, elasticsearch, and logstash showing "(healthy)". I have tried running the wipe.sh script and doing reboots with no change. The pcap does not show in the history or sessions tab of moloch even when specifying "all" as a time range. I'm not really sure what to do at this point.
The text was updated successfully, but these errors were encountered: