Disk Watermark Issue #14100
-
Version2.4.111 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU6 RAM25 Storage for /174G Storage for /nsm350G Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusYes, there are salt failures (please provide detail below) LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) Detailplease excuse this post - I have tried to search for this and didn't find relevant information It seems I have somehow messed up the flood stage water mark elasticsearch > config > cluster > routing > allocation > disk > watermark > flood stage -- I have tried to setting back to 90% , I had somehow set it to 90 without the percent mark , And is failing to bring up elastic I think because of this . I get an error when attempting to change this to anything it gives the error at the top and says look in the hunt, but also not working. Which file would this setting be in for me to manually change from the CLI . thanks in advance Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
What do you see when you run You should be able to go into SOC at |
Beta Was this translation helpful? Give feedback.
What do you see when you run
sudo salt-call pillar.get elasticsearch:config:cluster
? Do you see the 90 without the percentage?You should be able to go into SOC at
elasticsearch > config > cluster > routing > allocation > disk > watermark > flood_stage
and hit the blue circle with the back arrow to return to a default setting.