01-23-2019 04:38 AM
I used to run standalone MM 0.9.50 with CentOS 7, perfectly. Last week I updated MM to 0.9.52 with the help of @lmori and the proccess was completed with success. See ( https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Updating-MineMeld-from-0-9-50-to-the-lates... ).
However since the upload my MM doesn't work the same way. On my Dashboard is visible that my miner works fine, more than 90K indicators, but almost none of them ara available, less than 1K in the outputs (see figure below).
If we detailed the proccess, we see that the status of many nodes is "stopped". The number of indicators forwarded by the miners is high.
The number of indicators forwarded by the aggregators is almost the same.
But the number of indicators available by the outputs is extrmely low.
Has anybody experienced something similar? How you dealed with the problem?
01-23-2019 04:55 AM
could you try this:
01-23-2019 06:08 AM
first I restarted just the engine through the web interface, but not changed. Then I restarted my server and I got a bit more indicators.
I still have many nodes with the staus "stopped". And the number of the indicators in the output isn't matching yet.
What is this parameter?
Can it be changed even higher? What is the consequence?
01-29-2019 09:52 AM
02-04-2019 10:11 AM
I'm sorry to insist. I still have nodes with the staus "stopped". I tryed to find any other evidences of the problem, but I got nothing. Unhappy, this is happening since I upgraded to 0.9.52.
Did you have the opportunity to see my last reply (https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Problems-with-CentOs-7-and-MM-0-9-52/m-p/2...)?
02-04-2019 11:24 AM
Our server team just upgraded my Minemeld to CentOS7 0.9.52 and it only lists about 29k indicators but only 43 total in the output. I have an Ubuntu 14.04 image running 0.9.52 and it has 231k indicators and 77k output.
We have never had CentOS running yet but that is our PROD operating system and they want us to use it. Right now I just have my test box feeding the PAN the EDL.
I tried bumping up to 60 on the timeout.
02-11-2019 03:52 AM
Hi @xhoms and @lmori
Apparently there is a problem with the version 0.9.52 and the CentOS. Do you have any other known issue? Is it being addressed? It is impacting our environment. Do you advise rolling back to 0.9.50 version? If yes, How to do it?
02-11-2019 04:24 AM
yes, I am looking into this. The problem seems to be related to RabbitMQ.
If you want to install the previous version, you can use the update procedure for Ansible but in the file change the line 7 to look like roles/minemeld/tasks/core.yml:
02-11-2019 08:54 AM
That doesn't work either.
02-12-2019 02:49 AM
I can confirm it is extremely unstable. I tried rolling back to the previous version using the tips of @lmori in the previous post. At first it failed and present a fatal error. I enabled the extensions the error desapeared, but I'm still getting the "stopped" status for some nodes. The curious point is that, after the rolling back, I'm still getting the 0.9.52 vrsion in MM WEBGUI.
Did you experienced something similar @StephenBradley ?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!