- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
01-26-2017 08:16 AM
We installed Minemeld on Ubuntu 14.04 as documented and it's mostly working, except that from time to time the output lists are empty and PAN-OS Monitor>System complains:
medium::EDL(DSHIELD20) Downloaded file is either not a text file or empty file. Using old copy for refresh.
It's an unpredictable behavior and the EDL file comes back after a while.
I can see in /opt/minemeld/log/minemeld-web.log that the file size is sometimes 1 instead of, say, 560 (DShield20) or 22419 (Spamhaus DROP) so it's definitely a server issue.
What's going on?
Jan
01-31-2017 12:33 AM
Hi @irt-unimi,
found the problem, it is already fixed in the current beta. There will be a new release by the end of this week with the fix included. Let me know if you would like to install the beta.
luigi
01-30-2017 06:49 AM
Hi Luigi,
minemeld-engine.log does indeed show something interesting in the timeframe of the outage:
2017-01-27T07:11:39 (22615)connectionpool._new_conn INFO: Starting new HTTPS connection (1): www.dshield.org 2017-01-27T07:11:40 (22615)basepoller._actor_loop INFO: DSHIELD20BLOCKLIST - command: 1485497499987 sudden_death 2017-01-27T07:11:40 (22615)basepoller._actor_loop INFO: DSHIELD20BLOCKLIST - command: 1485497499987 age_out 2017-01-27T07:11:40 (22615)basepoller._actor_loop INFO: DSHIELD20BLOCKLIST - command: 1485497499987 gc 2017-01-27T07:11:55 (22615)basepoller._actor_loop INFO: DSHIELD20BLOCKLIST - command: 1485497515622 age_out 2017-01-27T07:16:12 (22615)basepoller._actor_loop INFO: DSHIELD20BLOCKLIST - command: 1485497772715 age_out 2017-01-27T07:20:29 (22615)basepoller._actor_loop INFO: DSHIELD20BLOCKLIST - command: 1485498029750 age_out 2017-01-27T07:21:59 (22615)basepoller._actor_loop INFO: DSHIELD20BLOCKLIST - command: 1485498119031 poll
Do you think it's DSHIELD not responding? And what can be done?
01-30-2017 06:50 AM
Hi @irt-unimi,
logs look normal. Please could you share a screenshot of the STATS section of the dshield.block Miner ?
01-30-2017 07:05 AM
hi @irt-unimi,
counters look good. Would you mind sending your minemeld-web.log file over at lmori@paloaltonetworks.com ?
Thanks,
luigi
01-31-2017 12:33 AM
Hi @irt-unimi,
found the problem, it is already fixed in the current beta. There will be a new release by the end of this week with the fix included. Let me know if you would like to install the beta.
luigi
01-31-2017 01:28 AM
Great Luigi, thank you.
02-13-2017 09:10 PM - edited 02-14-2017 01:38 AM
Hi Luigi,
Did the fix make 8.0 GA, as I'm running into the same problem?
The MM lists are accessible via the browser, but I get and error from PAN-OS that they are not a text file. I have disabled the certificate profile, tried URLs, IP ranges & individuals (statics), but all display the same error. The MM engine log seems to be fine.
Bouced MM and firewall..
Thanks,
Tim
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!