so-elastalert Missing from Distributed Installation #13908
Unanswered
squirtle-turtle
asked this question in
2.4
Replies: 2 comments 5 replies
-
Can you provide the output of the following commands?
For the salt command we're more focused on the results from the manager and the search nodes. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Thank you for the help! Command results: Unassigned shards command:
Salt command results from manager and search nodes:
|
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Version
2.4.110
Installation Method
Cloud image (Amazon, Azure, Google)
Description
upgrading
Installation Type
Distributed
Location
cloud
Hardware Specs
Exceeds minimum requirements
CPU
16
RAM
65.8 GB
Storage for /
270.5 GB
Storage for /nsm
2146.4 GB
Network Traffic Collection
span port
Network Traffic Speeds
Less than 1Gbps
Status
No, one or more services are failed (please provide detail below)
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
We have a distributed environment, including 2 search nodes and 7 forward nodes. There is a mix of on-premise and cloud forward nodes; search nodes and our manager node are hosted in AWS.
On our manager node, so-elastalert is missing, and the Docker container cannot be found. Manual reinstallation of the Docker container (docker pull) fails.
The issue first arose on a prior manager node when we spun up and accepted the second search node. We redeployed the manager and the search nodes. It worked for a little while - a couple of hours. The issue repeated itself on the second manager node after we tried to do a scorched-earth rebuild. We reviewed other posts here (anything similar) and didn't have any luck.
The errors we get on the Elastic side are tied to unallocated shards. How can we rectify this?
Errors when running "sudo salt-call state.highstate":
Clues in logs:
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions