<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error reading last checkpoint in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126353#M98542</link>
    <description>&lt;P&gt;I'd like to fix the instability issue first, I think it's related to memory exhaustion.&lt;/P&gt;
&lt;P&gt;Would you mind unicast me the logs from /opt/minemeld/log ? My email is lmori@paloaltonetworks.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also please note that when MineMeld start without a checkpoint it starts crunching all the indicators, and it could take a while. Are your running 0.9.24 or 0.9.26 ? Before 0.9.26 the GUI wasn't responsive under load, the only thing you could do was waiting for the CPU load to lower.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
    <pubDate>Tue, 15 Nov 2016 09:10:01 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2016-11-15T09:10:01Z</dc:date>
    <item>
      <title>Error reading last checkpoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126331#M98539</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing an issue that floods my output SIEM a little to often. The issue seems to be that the miner node is unable to register where it left of during the last check. Any tips on solving this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2016-11-14T08:54:30 (17269)base.read_checkpoint ERROR: sslabusech_dyreblacklist - Error reading last checkpoint
Traceback (most recent call last):
  File "/opt/minemeld/engine/0.9.26/local/lib/python2.7/site-packages/minemeld/ft/base.py", line 245, in read_checkpoint
    with open(self.name+'.chkp', 'r') as f:
IOError: [Errno 2] No such file or directory: 'sslabusech_dyreblacklist.chkp'
2016-11-14T08:54:30 (17269)base.state INFO: sslabusech_dyreblacklist - transitioning to state 1
2016-11-14T08:54:30 (17270)base.read_checkpoint ERROR: sslabusech_ipblacklist - Error reading last checkpoint
Traceback (most recent call last):
  File "/opt/minemeld/engine/0.9.26/local/lib/python2.7/site-packages/minemeld/ft/base.py", line 245, in read_checkpoint
    with open(self.name+'.chkp', 'r') as f:
IOError: [Errno 2] No such file or directory: 'sslabusech_ipblacklist.chkp'
2016-11-14T08:54:30 (17270)base.state INFO: sslabusech_ipblacklist - transitioning to state 1
2016-11-14T08:54:30 (17270)base.read_checkpoint ERROR: openbl_base - Error reading last checkpoint&lt;/PRE&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Forseti&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 08:20:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126331#M98539</guid>
      <dc:creator>Forseti</dc:creator>
      <dc:date>2016-11-15T08:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: Error reading last checkpoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126336#M98540</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48459"&gt;@Forseti﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;that ERROR happens only when the engine starts if the checkpoint does not exist. It could happen for 2 reasons:&lt;/P&gt;
&lt;P&gt;- the node is new and there is no previous checkpoint to load&lt;/P&gt;
&lt;P&gt;- the engine didn't have a "clean" shut down&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- could you check before those ERROR messages if you see additional ERRORs ?&lt;/P&gt;
&lt;P&gt;- check also the OS syslog and dmesg to see if there was a problem with memory or disk exhaustion&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 08:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126336#M98540</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-15T08:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error reading last checkpoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126343#M98541</link>
      <description>Hi Imori, The machine gets rebooted at night because as it seems that the minemeld process isn't stable. (I wasn't able to logon via the web gui after a couple of hours) I can't seem to stop it properly. Neither using 'sudo service mineld stop' nor via supervisord. I've already removed and reinstalled MineMeld completely but the issue seems to persist. However, that seems to be the root of this issue. And ofcourse, now that I try to mimick the behavior, it all goes well.. Will check back when a get a sample! Regards, Jan</description>
      <pubDate>Tue, 15 Nov 2016 08:54:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126343#M98541</guid>
      <dc:creator>Forseti</dc:creator>
      <dc:date>2016-11-15T08:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Error reading last checkpoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126353#M98542</link>
      <description>&lt;P&gt;I'd like to fix the instability issue first, I think it's related to memory exhaustion.&lt;/P&gt;
&lt;P&gt;Would you mind unicast me the logs from /opt/minemeld/log ? My email is lmori@paloaltonetworks.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also please note that when MineMeld start without a checkpoint it starts crunching all the indicators, and it could take a while. Are your running 0.9.24 or 0.9.26 ? Before 0.9.26 the GUI wasn't responsive under load, the only thing you could do was waiting for the CPU load to lower.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 09:10:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126353#M98542</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-15T09:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error reading last checkpoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126393#M98543</link>
      <description>&lt;P&gt;Luigi, thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For future reference: issue was caused by rabbitmq starting after minemeld had already started.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 12:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126393#M98543</guid>
      <dc:creator>Forseti</dc:creator>
      <dc:date>2016-11-15T12:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Error reading last checkpoint</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126650#M98544</link>
      <description>&lt;P&gt;An additional check for this will be added in the next release.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 07:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-reading-last-checkpoint/m-p/126650#M98544</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2016-11-16T07:23:01Z</dc:date>
    </item>
  </channel>
</rss>

