<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MineMeld engine:fatal message in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-fatal-message/m-p/222551#M98129</link>
    <description>&lt;P&gt;In case anyone else runs into this, we were unable to find a solution and rolled back the VM hosting the server as an alternate solution.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jul 2018 15:00:20 GMT</pubDate>
    <dc:creator>woodd0</dc:creator>
    <dc:date>2018-07-17T15:00:20Z</dc:date>
    <item>
      <title>MineMeld engine:fatal message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-fatal-message/m-p/221641#M98127</link>
      <description>&lt;P&gt;I'm getting the below message in my minemeld logs and not sure what is causing it&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2018-07-11T00:30:28 (16652)config._destroy_old_nodes INFO: Destroyed nodes: [_ConfigChange(nodename=u'Amazon_IPv4_Agg_General', nodeclass=u'minemeld.ft.ipop.AggregateIPv4FT', change=1, detail={'inputs': ['Amazon_AWS', 'Amazon_CloudFront', 'Amazon_EC2', 'Amazon_S3', 'Amazon_Route53_Agg'], 'config': {'whitelist_prefixes': ['Amazon', 'wl'], 'infilters': [{'conditions': ["__method == 'withdraw'"], 'name': 'accept withdraws', 'actions': ['accept']}, {'conditions': ["type == 'IPv4'"], 'name': 'accept IPv4', 'actions': ['accept']}, {'name': 'drop all', 'actions': ['drop']}]}, 'class': 'minemeld.ft.ipop.AggregateIPv4FT', 'output': True}), _ConfigChange(nodename=u'compromisedIPs-1531162062986', nodeclass=u'minemeld.ft.http.HttpFT', change=1, detail={'inputs': [], 'config': {'url': '&lt;A href="https://rules.emergingthreats.net/open/suricata/rules/compromised-ips.txt" target="_blank"&gt;https://rules.emergingthreats.net/open/suricata/rules/compromised-ips.txt&lt;/A&gt;', 'attributes': {'direction': 'inbound', 'type': 'IPv4', 'confidence': 50, 'share_level': 'green'}, 'source_name': 'ET.compromised_ips'}, 'class': 'minemeld.ft.http.HttpFT', 'output': True}), _ConfigChange(nodename=u'wood_IPagg', nodeclass=u'minemeld.ft.ipop.AggregateIPv4FT', change=1, detail={'inputs': ['compromisedIPs-1531162062986', 'blockIPs-1531162050810'], 'config': {'whitelist_prefixes': ['wl'], 'infilters': [{'conditions': ["__method == 'withdraw'"], 'name': 'accept withdraws', 'actions': ['accept']}, {'conditions': ["type == 'IPv4'"], 'name': 'accept IPv4', 'actions': ['accept']}, {'name': 'drop all', 'actions': ['drop']}]}, 'class': 'minemeld.ft.ipop.AggregateIPv4FT', 'output': True}), _ConfigChange(nodename=u'Amazon_Route53_Agg', nodeclass=u'minemeld.ft.ipop.AggregateIPv4FT', change=1, detail={'inputs': ['Amazon_ROUTE53', 'Amazon_Route53_HealthChecks'], 'config': {'whitelist_prefixes': ['Amazon', 'wl'], 'infilters': [{'conditions': ["__method == 'withdraw'"], 'name': 'accept withdraws', 'actions': ['accept']}, {'conditions': ["type == 'IPv4'"], 'name': 'accept IPv4', 'actions': ['accept']}, {'name': 'drop all', 'actions': ['drop']}]}, 'class': 'minemeld.ft.ipop.AggregateIPv4FT', 'output': True}), _ConfigChange(nodename=u'feedMCGreen-1531163955644', nodeclass=u'minemeld.ft.redis.RedisSet', change=1, detail={'inputs': ['wood_IPagg'], 'indicator_types': ['any'], 'node_type': 'output', 'output': False, 'config': {'infilters': [{'conditions': ["__method == 'withdraw'"], 'name': 'accept withdraws', 'actions': ['accept']}, {'conditions': ['confidence &amp;gt;= 50', 'confidence &amp;lt; 75', "share_level == 'green'"], 'name': 'accept confidence 50-75 and share level green', 'actions': ['accept']}, {'name': 'drop all', 'actions': ['drop']}]}, 'class': 'minemeld.ft.redis.RedisSet'}), _ConfigChange(nodename=u'blockIPs-1531162050810', nodeclass=u'minemeld.ft.http.HttpFT', change=1, detail={'inputs': [], 'config': {'url': '&lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;', 'attributes': {'confidence': 50, 'type': 'IPv4', 'share_level': 'green'}, 'source_name': 'ET.block_ips', 'ignore_regex': '^#'}, 'class': 'minemeld.ft.http.HttpFT', 'output': True}), _ConfigChange(nodename=u'wood_output', nodeclass=u'minemeld.ft.redis.RedisSet', change=1, detail={'inputs': ['wood_IPagg'], 'config': {'infilters': [{'conditions': ["__method == 'withdraw'"], 'name': 'accept withdraws', 'actions': ['accept']}, {'conditions': ['confidence &amp;gt; 75', "share_level == 'green'"], 'name': 'accept confidence &amp;gt; 75 and share level green', 'actions': ['accept']}, {'name': 'drop all', 'actions': ['drop']}]}, 'class': 'minemeld.ft.redis.RedisSet', 'output': False}), _ConfigChange(nodename=u'Amazon_Feed', nodeclass=u'minemeld.ft.redis.RedisSet', change=1, detail={'inputs': ['Amazon_IPv4_Agg_General'], 'config': {'infilters': [{'conditions': ["__method == 'withdraw'"], 'name': 'accept withdraws', 'actions': ['accept']}, {'conditions': ['confidence &amp;gt; 75', "share_level == 'green'"], 'name': 'accept confidence &amp;gt; 75 and share level green', 'actions': ['accept']}, {'name': 'drop all', 'actions': ['drop']}]}, 'class': 'minemeld.ft.redis.RedisSet', 'output': False})]&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt; File "/opt/minemeld/engine/current/bin/mm-run", line 11, in &amp;lt;module&amp;gt;&lt;BR /&gt; sys.exit(main())&lt;BR /&gt; File "/opt/minemeld/engine/0.9.48.post1/local/lib/python2.7/site-packages/minemeld/run/launcher.py", line 218, in main&lt;BR /&gt; config = minemeld.run.config.load_config(args.config)&lt;BR /&gt; File "/opt/minemeld/engine/0.9.48.post1/local/lib/python2.7/site-packages/minemeld/run/config.py", line 567, in load_config&lt;BR /&gt; return _load_config_from_dir(config_path)&lt;BR /&gt; File "/opt/minemeld/engine/0.9.48.post1/local/lib/python2.7/site-packages/minemeld/run/config.py", line 417, in _load_config_from_dir&lt;BR /&gt; _destroy_old_nodes(cconfig)&lt;BR /&gt; File "/opt/minemeld/engine/0.9.48.post1/local/lib/python2.7/site-packages/minemeld/run/config.py", line 357, in _destroy_old_nodes&lt;BR /&gt; dpool = multiprocessing.Pool()&lt;BR /&gt; File "/usr/lib/python2.7/multiprocessing/__init__.py", line 232, in Pool&lt;BR /&gt; return Pool(processes, initializer, initargs, maxtasksperchild)&lt;BR /&gt; File "/usr/lib/python2.7/multiprocessing/pool.py", line 138, in __init__&lt;BR /&gt; self._setup_queues()&lt;BR /&gt; File "/usr/lib/python2.7/multiprocessing/pool.py", line 234, in _setup_queues&lt;BR /&gt; self._inqueue = SimpleQueue()&lt;BR /&gt; File "/usr/lib/python2.7/multiprocessing/queues.py", line 352, in __init__&lt;BR /&gt; self._rlock = Lock()&lt;BR /&gt; File "/usr/lib/python2.7/multiprocessing/synchronize.py", line 147, in __init__&lt;BR /&gt; SemLock.__init__(self, SEMAPHORE, 1, 1)&lt;BR /&gt; File "/usr/lib/python2.7/multiprocessing/synchronize.py", line 75, in __init__&lt;BR /&gt; sl = self._semlock = _multiprocessing.SemLock(kind, value, maxvalue)&lt;BR /&gt;OSError: [Errno 30] Read-only file system&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have rebooted the system but that hasn't cleared anything up.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 00:45:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-fatal-message/m-p/221641#M98127</guid>
      <dc:creator>johnsonto</dc:creator>
      <dc:date>2018-07-11T00:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld engine:fatal message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-fatal-message/m-p/221787#M98128</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I work with johnsonto, and can add some context to the error log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, we had two miners aggregating together into an output, and that's been working for some time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another two-miner to output pair was made, and while the config had a mismatch between confidence levels (such that nothing was being output), the MineMeld server was still working as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed the prototype of the new output node for a lower confidence, and also created a few more independent miners which connected to a new third output. After this change, the above error reared up, and is preventing our MineMeld engine from running. We're able to commit a new config, but when the engine tries to start up, it continues to crash, always on the same "OSError: Read-only file system".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far we've been able to change the config, and that leaves me wondering what exactly is read-only.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 18:04:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-fatal-message/m-p/221787#M98128</guid>
      <dc:creator>woodd0</dc:creator>
      <dc:date>2018-07-11T18:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: MineMeld engine:fatal message</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-fatal-message/m-p/222551#M98129</link>
      <description>&lt;P&gt;In case anyone else runs into this, we were unable to find a solution and rolled back the VM hosting the server as an alternate solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 15:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/minemeld-engine-fatal-message/m-p/222551#M98129</guid>
      <dc:creator>woodd0</dc:creator>
      <dc:date>2018-07-17T15:00:20Z</dc:date>
    </item>
  </channel>
</rss>

