Hi,
I’m getting a similar error message on Ubuntu (no docker) with flowcoll 7.7.0.
Result of tail -f /var/log/elastiflow/flowcoll/flowcoll.log | grep netintel
while the service is restarting :
{"level":"info","ts":"2025-02-07T19:46:57.376+0100","logger":"flowcoll.processor[default]","caller":"envconf/logger.go:49","msg":"EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_API_ADDR=https://query.netintel.elastiflow.com"}
{"level":"info","ts":"2025-02-07T19:46:59.915+0100","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:283","msg":"initializing threat type collection"}
{"level":"info","ts":"2025-02-07T19:46:59.915+0100","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:365","msg":"fetching resource from file: /var/lib/elastiflow/flowcoll/threat_collection.pb"}
{"level":"info","ts":"2025-02-07T19:46:59.918+0100","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:288","msg":"Threat Type size: 53230 bytes"}
{"level":"info","ts":"2025-02-07T19:46:59.922+0100","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:262","msg":"initializing ipdb"}
{"level":"info","ts":"2025-02-07T19:46:59.923+0100","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:349","msg":"fetching resource from server: RESOURCE_IP_DB"}
{"level":"error","ts":"2025-02-07T19:48:30.445+0100","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:223","msg":"error initializing ipdb & threat collection","error":"error initializing ip trie: failed to initialize ipdb: error fetching resource from server: context deadline exceeded (Client.Timeout or context cancellation while reading body)","stacktrace":"github.com/elastiflow/go-enrich-ipaddr/netintel.(*NetIntel).Run\n\t/go/pkg/mod/github.com/elastiflow/go-enrich-ipaddr@v1.1.1/netintel/enricher.go:223\ngithub.com/elastiflow/go-enrich-ipaddr/enrichipaddr.New\n\t/go/pkg/mod/github.com/elastiflow/go-enrich-ipaddr@v1.1.1/enrichipaddr/enrichipaddr.go:144\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/cached.(*Components).generateEnrichIPAddrCache\n\t/tmp/collectors/pkg/processors/flowprocessor/cached/cached.go:257\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/cached.(*Components).buildCaches\n\t/tmp/collectors/pkg/processors/flowprocessor/cached/cached.go:85\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor/cached.NewCachedComponents\n\t/tmp/collectors/pkg/processors/flowprocessor/cached/cached.go:55\ngithub.com/elastiflow/flowcoll/pkg/processors/flowprocessor.NewInstantiatorRegistration.newCreateInstanceFunc.func1\n\t/tmp/collectors/pkg/processors/flowprocessor/instance_registration.go:150\ngithub.com/elastiflow/go-env-conf/instantiator.(*Instantiator).Run\n\t/go/pkg/mod/github.com/elastiflow/go-env-conf@v0.8.7/instantiator/instantiator.go:78\ngithub.com/elastiflow/flowcoll/pkg/apps/unified_flowcoll.(*App).Run\n\t/tmp/collectors/pkg/apps/unified_flowcoll/app.go:157\nmain.main\n\t/tmp/collectors/cmd/flowcoll/main.go:106\nruntime.main\n\t/usr/local/go/src/runtime/proc.go:271"}
{"level":"info","ts":"2025-02-07T19:48:30.446+0100","logger":"ipaddr_enricher.netintel_threats","caller":"netintel/enricher.go:245","msg":"running netintel"}
Here is the content of my flowcoll.yml :
EF_ACCOUNT_ID: "XYZ"
EF_LICENSE_ACCEPTED: "true"
EF_FLOW_LICENSE_KEY: "XYZ"
EF_LOGGER_FILE_LOG_ENABLE: "true"
EF_LOGGER_LEVEL: info
EF_FLOW_SERVER_UDP_IP: 0.0.0.0
EF_FLOW_SERVER_UDP_PORT: 2055
EF_FLOW_SERVER_UDP_READ_BUFFER_MAX_SIZE: 134217728
EF_AWS_VPC_FLOW_LOG_S3_ENABLE: "false"
EF_PROCESSOR_ENRICH_APP_ID_ENABLE: "true"
EF_PROCESSOR_ENRICH_APP_ID_PATH: "/etc/elastiflow/app/appid.yml"
EF_PROCESSOR_ENRICH_APP_IPPORT_ENABLE: "true"
EF_PROCESSOR_ENRICH_APP_IPPORT_PATH: "/etc/elastiflow/settings/apps_user_defined.yml"
EF_PROCESSOR_ENRICH_APP_IPPORT_PRIVATE: "true"
EF_PROCESSOR_ENRICH_APP_IPPORT_PUBLIC: "true"
EF_PROCESSOR_ENRICH_IPADDR_DNS_ENABLE: "true"
EF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_IP: "192.168.90.254"
EF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_TIMEOUT: 3000
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_ASN_ENABLE: "true"
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_ENABLE: "true"
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_INCLEXCL_PATH: "/etc/elastiflow/maxmind/incl_excl.yml"
EF_PROCESSOR_ENRICH_IPADDR_METADATA_ENABLE: "true"
EF_PROCESSOR_ENRICH_IPADDR_METADATA_REFRESH_RATE: 15
EF_PROCESSOR_ENRICH_IPADDR_METADATA_USERDEF_PATH: "/etc/elastiflow/metadata/ipaddrs.yml"
EF_PROCESSOR_ENRICH_NETIF_FLOW_OPTIONS_ENABLE: "true"
EF_PROCESSOR_ENRICH_NETIF_METADATA_ENABLE: "true"
EF_PROCESSOR_ENRICH_NETIF_METADATA_USERDEF_PATH: "/etc/elastiflow/metadata/netifs.yml"
EF_PROCESSOR_ENRICH_NETIF_SNMP_COMMUNITIES: public
EF_PROCESSOR_ENRICH_NETIF_SNMP_ENABLE: "true"
EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_ENABLE: "true"
EF_OUTPUT_ELASTICSEARCH_ADDRESSES: 192.168.90.251:9200
EF_OUTPUT_ELASTICSEARCH_ECS_ENABLE: "true"
EF_OUTPUT_ELASTICSEARCH_ENABLE: "true"
EF_OUTPUT_ELASTICSEARCH_INDEX_PERIOD: rollover
EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ILM_LIFECYCLE: rollover
EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_REPLICAS: 0
EF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_SHARDS: 1
EF_OUTPUT_ELASTICSEARCH_PASSWORD: "XYZ"
EF_OUTPUT_ELASTICSEARCH_TIMESTAMP_SOURCE: end
EF_OUTPUT_ELASTICSEARCH_TLS_CA_CERT_FILEPATH: "/etc/elastiflow/ca/ca.crt"
EF_OUTPUT_ELASTICSEARCH_TLS_ENABLE: "true"
EF_OUTPUT_ELASTICSEARCH_TLS_SKIP_VERIFICATION: "false"
EF_OUTPUT_ELASTICSEARCH_USERNAME: "XYZ"
EF_OUTPUT_OPENSEARCH_ECS_ENABLE: "false"
EF_OUTPUT_OPENSEARCH_ENABLE: "false"
Thanks for your help.