1
Zenarmor (Sensei) / Re: Zenarmor 1.14: External Elastic database - no data available in reports
« on: August 11, 2023, 10:08:27 am »
More information from my setup as well.
I have configured an external ES DB after upgrading Zenarmor to 1.14.2. It basically works but some reports don't display data.
These reports are:
I would expect to see data in at least some of them.
One more factor that can make a difference is the fact I use custom lifecycle policy and custom index names in ES. However I've made sure all mappings are defined exactly the same way as indices created by Zenarmor during the installation process.
I have configured an external ES DB after upgrading Zenarmor to 1.14.2. It basically works but some reports don't display data.
These reports are:
- Egress New Connections by App Over Time
- Egress New Connections by Source Over Time
- New Connections & Unique Remote Hosts
- Unique Local Hosts
- Facts/Connections is set to NaN
- Facts/unique Local Devices is set to 0
- HTTP Transactions by Source Over Time
- Top Egress Users
- Top Ingress Users
- Top OS
- Top Session Creators Over Time
- Top Servers Over Time
I would expect to see data in at least some of them.
One more factor that can make a difference is the fact I use custom lifecycle policy and custom index names in ES. However I've made sure all mappings are defined exactly the same way as indices created by Zenarmor during the installation process.