After upgrade to 2.4.200, Zeek docker container fails to start #15336
Unanswered
ZacharyPax
asked this question in
2.4
Replies: 1 comment 4 replies
-
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment

Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.200
Installation Method
Security Onion ISO image
Description
upgrading
Installation Type
Standalone
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
32
RAM
256GB
Storage for /
1TB
Storage for /nsm
13.5TB
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
Hello,
After upgrading to Security Onion 2.4.200 with SOUP, the so-zeek container fails to start. This is despite Suricata and Stenographer working. Traffic is present on the bond port, but Zeek doesn't analyze it and the docker container repeatedly gets stuck "starting" or fails out.
The docker container logs simply repeat this:
removing stale lock
checking configurations ...
logger scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
manager scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
proxy scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
worker-1-1 scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
/usr/local/sbin/zeek.sh: line 8: kill: (34) - No such process
checking configurations ...
logger scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
manager scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
proxy scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
worker-1-1 scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
/usr/local/sbin/zeek.sh: line 8: kill: (31) - No such process
checking configurations ...
logger scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
manager scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
proxy scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
worker-1-1 scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
/usr/local/sbin/zeek.sh: line 8: kill: (31) - No such process
checking configurations ...
logger scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
manager scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
proxy scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
worker-1-1 scripts failed.
fatal error in /opt/zeek/share/zeek/site/local.zeek, line 3: can't find tuning/defaults
/usr/local/sbin/zeek.sh: line 8: kill: (31) - No such process
Additionally, if it is worth mentioning, the file /opt/zeek/share/zeek/site/local.zeek simply does not exist. Nor does the entire directory structure going there (/opt/zeek does not exist.) I do not know if it existed prior to the upgrade.
Thanks,
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions