-
Notifications
You must be signed in to change notification settings - Fork 23
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Integrations maintenance request [Month 12] #604
Comments
Wazuh Indexer Splunk integrationBuilt Docker composedocker compose -f compose.indexer-splunk.yml up -d
[+] Running 12/12
✔ splunk Pulled 47.2s
✔ a09bb1026942 Pull complete 2.9s
✔ 59de139ab4a7 Pull complete 2.9s
✔ 240852bc4e7c Pull complete 11.5s
✔ 570e3b526dc7 Pull complete 11.5s
✔ 4bd60e134244 Pull complete 11.6s
✔ d0501d93737f Pull complete 39.7s
✔ 4f4fb700ef54 Pull complete 39.7s
✔ e1b7b6f16b3d Pull complete 43.9s
✔ dcabfc195708 Pull complete 43.9s
✔ 74f154f0ed61 Pull complete 43.9s
✔ de8d9d75b1c5 Pull complete 44.0s
[+] Running 8/8
✔ Container splunk-integration-generate-certs-config-1 Exited 1.3s
✔ Container splunk-integration-wazuh-certs-generator-1 Exited 4.0s
✔ Container splunk-integration-wazuh.indexer-1 Healthy 46.5s
✔ Container splunk-integration-generator-1 Exited 4.0s
✔ Container splunk-integration-wazuh.dashboard-1 Started 3.7s
✔ Container splunk-integration-events-generator-1 Started 46.7s
✔ Container splunk-integration-splunk-1 Healthy 55.7s
✔ Container splunk-integration-logstash-1 Started |
Because the dashboard did not work in the Splunk integration I tried again several times. I stopped all the docker images that were generated, deleted them and recreated them. I did not manage to see data in any of the Splunk dashboards again. The only error I found within the docker containers was within the splunk-integration-logstash-1 container: Same error repeatedly with different Events |
Description
The Wazuh Indexer team is responsible for the maintenance of the third-party integrations hosted in the wazuh/wazuh-indexer repository. We must ensure these integrations work under new releases of the third-party software (Splunk, Elastic, Logstash, …) and our own.
For that, we need to:
Note
Issues
The text was updated successfully, but these errors were encountered: