-
Notifications
You must be signed in to change notification settings - Fork 287
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🐞No Data in Arkime Dashboard #486
Comments
In some cases the data does not populate right away , you would either need to wait or make sure you have continuous stream of data/traffic coming in. |
Peter
Yes even with All timespan I still don’t see data in Arkime.
…On Wed, Dec 25, 2024 at 7:25 AM Peter Manev ***@***.***> wrote:
In some cases the data does not populate right away , you would either
need to wait or make sure you have continuous stream of data/traffic coming
in.
Is it the same view if you select All time span in Arkime ?
—
Reply to this email directly, view it on GitHub
<#486 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ACHE3NOISTZQ3IJKL6SGMEL2HKP4PAVCNFSM6AAAAABUFCKB76VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDKNRRHA3DSMZTGA>
.
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
Ok and you have continuous traffic or at least had for some time ? |
Yes Peter and I am seeing the constant flow of traffic in eve box and open
search.
…On Thu, Dec 26, 2024 at 3:42 AM Peter Manev ***@***.***> wrote:
Ok and you have continuous traffic or at least had for some time ?
—
Reply to this email directly, view it on GitHub
<#486 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ACHE3NL2DDS6IAXK7QRWHVD2HO6PFAVCNFSM6AAAAABUFCKB76VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDKNRSGMZDCNRUGU>
.
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
And I have been feeding it data for 5 days
On Thu, Dec 26, 2024 at 3:45 AM Charles Wilkerson <
***@***.***> wrote:
… Yes Peter and I am seeing the constant flow of traffic in eve box and open
search.
On Thu, Dec 26, 2024 at 3:42 AM Peter Manev ***@***.***>
wrote:
> Ok and you have continuous traffic or at least had for some time ?
>
> —
> Reply to this email directly, view it on GitHub
> <#486 (comment)>,
> or unsubscribe
> <https://github.com/notifications/unsubscribe-auth/ACHE3NL2DDS6IAXK7QRWHVD2HO6PFAVCNFSM6AAAAABUFCKB76VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDKNRSGMZDCNRUGU>
> .
> You are receiving this because you authored the thread.Message ID:
> ***@***.***>
>
|
Can you share the output of
also try to see if there is any error message in the Arkime logs
|
Peter
I am at work now but I’ll run these commands when get home
…On Thu, Dec 26, 2024 at 5:21 AM Peter Manev ***@***.***> wrote:
Can you share the output of docker ps -a (example)
docker ps -a
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
627bf2ef5ff2 busybox "/bin/sh -c 'chown -…" About an hour ago Exited (0) About an hour ago config-ownership-fix-UCTNkt
af7ffc98e341 nginx:1.27 "/docker-entrypoint.…" About an hour ago Up About an hour (healthy) 80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp config-nginx-CJDkAt
4fe8df6c1c41 jasonish/suricata:7.0 "/new_entrypoint.sh" About an hour ago Up About an hour config-suricata-wmciTo
8ab834b2c2d1 ghcr.io/stamusnetworks/scirius:clear-ndr-v0.9.0 "/bin/bash /opt/scir…" About an hour ago Up About an hour (healthy) 8000/tcp config-scirius-VikwzI
86adfe1b028b config-kibana "./opensearch-dashbo…" About an hour ago Up About an hour (healthy) 5601/tcp config-opensearch-dashboards-HeSGiV
47e3a4c7f7c5 config-arkime "bash -c /start-arki…" About an hour ago Up About an hour (healthy) 8005/tcp config-arkime-dPdnGN
96d87ccc22ce ghcr.io/stamusnetworks/scirius:clear-ndr-v0.9.0 "celery -A suricata …" About an hour ago Up About an hour (healthy) 8000/tcp config-celery-beat-SMIYWJ
b1af4b332c9b ghcr.io/stamusnetworks/scirius:clear-ndr-v0.9.0 "celery -A suricata …" About an hour ago Up About an hour (healthy) 8000/tcp config-celery-worker-YFknkL
b13e2235c4f3 config-fluentd "tini -- /bin/entryp…" About an hour ago Up About an hour 5140/tcp, 24224/tcp config-fluentd-xfTgbT
a4fe69e0a847 docker:27-cli "docker-entrypoint.s…" About an hour ago Up About an hour (healthy) config-cron-LPISLd
e51b013765bc opensearchproject/opensearch:1.3.19 "./opensearch-docker…" About an hour ago Up About an hour (healthy) 9200/tcp, 9300/tcp, 9600/tcp, 9650/tcp config-opensearch-gASVZz
521b0b91c640 nginx:1.27 "/docker-entrypoint.…" About an hour ago Exited (0) About an hour ago config-ssl-keygen-SgqAnu
ef863b824eec rabbitmq:3-management-alpine "docker-entrypoint.s…" About an hour ago Up About an hour (healthy) 4369/tcp, 5671-5672/tcp, 15671-15672/tcp, 15691-15692/tcp, 25672/tcp config-rabbitmq-MCXxJJ
08ce80bf8a9c postgres:17 "docker-entrypoint.s…" About an hour ago Up About an hour (healthy) 5432/tcp config-db-tlpYkt
8f844c7da535 jasonish/evebox:master "/docker-entrypoint.…" About an hour ago Up About an hour config-evebox-cObxnz
also try to see if there is any error message in the Arkime logs
ls -lh config/containers-data/arkime/logs/
—
Reply to this email directly, view it on GitHub
<#486 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ACHE3NLUENTIK3OUWQR67K32HPKC3AVCNFSM6AAAAABUFCKB76VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDKNRSGQYDQOJQGQ>
.
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
Peter here is docker ps -a output:
|
Thanks. Can you try upgrading please : https://docs.clearndr.io/docs/start/common-operations#upgrading
|
|
Peter I ran the update and I am still getting "Oh no, Arkime is empty! There is no data to search" |
What is the output of those two commands:
|
root@clearrva1:/home/charles# ls -lh config/containers-data/suricata/logs/fpc/ |
|
Ok i think i know what's happening. |
Thank you very much!! |
@Wilk4013
or
depending how your docker is installed user-wise and you should be good ! |
Peter
Will try this tomorrow when I get off of work.
…On Mon, Dec 30, 2024 at 12:09 PM Peter Manev ***@***.***> wrote:
@Wilk4013 <https://github.com/Wilk4013>
All you need to do is :
./stamusctl compose update
./stamusctl compose up -d
or
sudo ./stamusctl compose update
sudo ./stamusctl compose up -d
depending how your docker is installed user-wise and you should be good !
—
Reply to this email directly, view it on GitHub
<#486 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ACHE3NNH3A6UIS2QT5DVAI32IF45RAVCNFSM6AAAAABUFCKB76VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDKNRVG4ZDMNRZGA>
.
You are receiving this because you were mentioned.Message ID:
***@***.***>
|
Is there an existing issue for this?
Current Behavior
I installed Clear NDR using docker instructions on 12 core, 32 gig mem, 512 gig mini computer. All seems to be working fine (Kibana, Eve-Box, opensearch dashboards) except there is not data in Arkime Dashboard. Tried recreating container with new pull but still no luck. Can someone help me with this?
Expected Behavior
Expect to see data in Arkime dashboard.
Steps To Reproduce
Install using Docker install instructions from Stamus website.
Docker version
Docker version 27.4.1, build b9d17ea
Docker version
Docker version 27.4.1, build b9d17ea
OS Version
Ubuntu 22.04.5 LTS
Content of the environnement File
N/A
Version of SELKS
version: 1.0.0
arch: linux/amd64
commit: 68aa96734f9eb09db7e90e12eb5cd734d73054e4
Anything else?
No response
The text was updated successfully, but these errors were encountered: