Hello all,
I use Elastiflow 7.9.0 with ELK stack in my LAB environment, and my Threats IP Reputation doesn’t show any data anymore.
Kibana doens’t see any fields sec.threat name and here is my flowcoll.yml input configuration:
EF_PROCESSOR_ENRICH_APP_ID_ENABLE: “false”
EF_PROCESSOR_ENRICH_APP_ID_PATH: “/etc/elastiflow/app/cisco.yml”
#EF_PROCESSOR_ENRICH_APP_ID_TTL: 7200
#EF_PROCESSOR_ENRICH_APP_IPPORT_ENABLE: “false”
#EF_PROCESSOR_ENRICH_APP_IPPORT_PATH: “”
#EF_PROCESSOR_ENRICH_APP_IPPORT_PRIVATE: “true”
#EF_PROCESSOR_ENRICH_APP_IPPORT_PUBLIC: “false”
#EF_PROCESSOR_ENRICH_APP_IPPORT_TTL: 7200
#EF_PROCESSOR_ENRICH_APP_REFRESH_RATE: 15
#EF_PROCESSOR_ENRICH_ASN_PREF: lookup
#EF_PROCESSOR_ENRICH_COMMUNITYID_ENABLE: “true”
#EF_PROCESSOR_ENRICH_COMMUNITYID_SEED: 0
#EF_PROCESSOR_ENRICH_CONVERSATIONID_ENABLE: “true”
#EF_PROCESSOR_ENRICH_CONVERSATIONID_SEED: 0
EF_PROCESSOR_ENRICH_IPADDR_DNS_ENABLE: “true”
#EF_PROCESSOR_ENRICH_IPADDR_DNS_INCLEXCL_PATH: “”
#EF_PROCESSOR_ENRICH_IPADDR_DNS_INCLEXCL_REFRESH_RATE: 15
EF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_IP: “x.x.x.x”
#EF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_TIMEOUT: 3000
EF_PROCESSOR_ENRICH_IPADDR_DNS_RESOLVE_PRIVATE: “true”
EF_PROCESSOR_ENRICH_IPADDR_DNS_RESOLVE_PUBLIC: “true”
#EF_PROCESSOR_ENRICH_IPADDR_DNS_USERDEF_PATH: “”
#EF_PROCESSOR_ENRICH_IPADDR_DNS_USERDEF_REFRESH_RATE: 15
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_ASN_ENABLE: “true”
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_ASN_PATH: /etc/elastiflow/maxmind/GeoLite2-ASN.mmdb
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_ENABLE: “true”
#EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_INCLEXCL_PATH: “”
#EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_INCLEXCL_REFRESH_RATE: 15
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_LANG: en
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_PATH: /etc/elastiflow/maxmind/GeoLite2-City.mmdb
EF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_VALUES: city,country,country_code,location,timezone
#EF_PROCESSOR_ENRICH_IPADDR_METADATA_ENABLE: “false”
#EF_PROCESSOR_ENRICH_IPADDR_METADATA_REFRESH_RATE: 15
#EF_PROCESSOR_ENRICH_IPADDR_METADATA_USERDEF_PATH: “”
EF_PROCESSOR_ENRICH_IPADDR_NETINTEL_AS_PREFIX_PRECISION: all
#EF_PROCESSOR_ENRICH_IPADDR_TTL: 7200
#EF_PROCESSOR_ENRICH_JOIN_ASN: “true”
#EF_PROCESSOR_ENRICH_JOIN_CLOUD: “true”
#EF_PROCESSOR_ENRICH_JOIN_GEOIP: “true”
#EF_PROCESSOR_ENRICH_JOIN_NETATTR: “true”
#EF_PROCESSOR_ENRICH_JOIN_SEC: “true”
#EF_PROCESSOR_ENRICH_JOIN_SUBNETATTR: “true”
EF_PROCESSOR_ENRICH_NETIF_FLOW_OPTIONS_ENABLE: “true”
#EF_PROCESSOR_ENRICH_NETIF_METADATA_ENABLE: “false”
#EF_PROCESSOR_ENRICH_NETIF_METADATA_REFRESH_RATE: 15
#EF_PROCESSOR_ENRICH_NETIF_METADATA_USERDEF_PATH: “”
#EF_PROCESSOR_ENRICH_NETIF_SNMP_ACCESS_ENABLE: “false”
#EF_PROCESSOR_ENRICH_NETIF_SNMP_ACCESS_PATH: /etc/elastiflow/settings/snmp_access.yml
#EF_PROCESSOR_ENRICH_NETIF_SNMP_ACCESS_REFRESH_RATE: 15
#EF_PROCESSOR_ENRICH_NETIF_SNMP_COMMUNITIES: public
#EF_PROCESSOR_ENRICH_NETIF_SNMP_ENABLE: “false”
#EF_PROCESSOR_ENRICH_NETIF_SNMP_PORT: 161
#EF_PROCESSOR_ENRICH_NETIF_SNMP_RETRIES: 1
#EF_PROCESSOR_ENRICH_NETIF_SNMP_TIMEOUT: 2
#EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHENTICATION_PASSPHRASE: “”
#EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_AUTHENTICATION_PROTOCOL: noauth
#EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_PRIVACY_PASSPHRASE: “”
#EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_PRIVACY_PROTOCOL: nopriv
#EF_PROCESSOR_ENRICH_NETIF_SNMP_V3_USERNAME: “”
#EF_PROCESSOR_ENRICH_NETIF_SNMP_VERSION: 2
#EF_PROCESSOR_ENRICH_NETIF_TTL: 7200
#EF_PROCESSOR_ENRICH_OPTION_ENUM_TTL: 7200
#EF_PROCESSOR_ENRICH_SAMPLERATE_CACHE_SIZE: 32768
#EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_ENABLE: “false”
#EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_OVERRIDE: “false”
#EF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_PATH: /etc/elastiflow/settings/sample_rate.yml
EF_PROCESSOR_ENRICH_TOTALS_IF_NO_DELTAS: “false”
#EF_PROCESSOR_EXPAND_CLISRV: “true”
#EF_PROCESSOR_EXPAND_CLISRV_NO_L4_PORTS: “true”
#EF_PROCESSOR_IFA_ENABLE: “false”
#EF_PROCESSOR_IFA_POOL_SIZE: 0
#EF_PROCESSOR_IFA_QUEUE_SIZE: 64
#EF_PROCESSOR_KEEP_CPU_TICKS: “false”
#EF_PROCESSOR_PERCENT_NORM: 100
#EF_PROCESSOR_POOL_SIZE: 0
#EF_PROCESSOR_TIMESTAMP_PRECISION: ms
#EF_PROCESSOR_TRANSLATE_KEEP_IDS: default
What could be a problem?
It worked couple days ago, even restoring back my VM from snapshot with previously working state doesn’t get any results.