Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - dstrctdagain321

#1
24.7, 24.10 Series / Re: Crowdsec quits with new update
January 15, 2025, 10:42:47 PM
After digging into logs, I was able to narrow it down to the Appsec collection. Removed it, and no more issues!
#2
24.7, 24.10 Series / Re: Crowdsec quits with new update
January 15, 2025, 09:53:51 PM
I'm guessing the same. Looking through their Discord now to see what I can find. Also, knowing your Crowdsec is working fine tells us a lot.

Are you using Crowdsec to parse Suricata logs by chance?

When reloading Crowdsec in the shell, it performs sanity check and I get:

time="2025-01-15T12:44:49-08:00" level=fatal msg="crowdsec init: while loading scenarios: scenario loading failed: unable to load alert context: compilation of 'match.matched_zones != nil ? match.matched_zones : ''' context value failed: unknown name match (1:1)\n | match.matched_zones != nil ? match.matched_zones : ''\n | ^"
#3
24.7, 24.10 Series / Re: Crowdsec quits with new update
January 15, 2025, 09:19:18 PM
Thank you!

Unfortunately it looks like the old Crowdsec package is no longer available to revert, it simply reinstalls the new one.

I will reach out to Crowdsec and see what I can do.
#4
24.7, 24.10 Series / Crowdsec quits with new update
January 15, 2025, 08:25:55 PM
Hi,

On my install, Crowdsec with 24.7.12 intermittently quits and restarts itself constantly. I am getting this error:

Script action failed with Command '/usr/local/bin/cscli alerts list -l 0 -o json' returned non-zero exit status 1. at Traceback (most recent call last): File "/usr/local/opnsense/service/modules/actions/script_output.py", line 78, in execute subprocess.check_call(script_command, env=self.config_environment, shell=True, File "/usr/local/lib/python3.11/subprocess.py", line 413, in check_call raise CalledProcessError(retcode, cmd) subprocess.CalledProcessError: Command '/usr/local/bin/cscli alerts list -l 0 -o json' returned non-zero exit status 1.
I removed the package, rebooted, reinstalled with the same issue. Would anyone else be experiencing this or have advice? Thank you :)
#5
Ouch, that makes my issue look pretty tame. Unbound is running for me and appears to be working aside from pulling up logs for specific clients. I'll keep an eye out for that too.

Just clarifying, but you're saying you also are experiencing my issue?
#6
Hi,

After the update, individual client queries are not displayed when clicking to show details of individual clients. I'm able to see Unbound queries under "Details" as they come in, but when I click on a client on the "Overview" page, it shows "No results found".
#7
I used your tutorial successfully, but no change in behavior.

Great news though: I updated to the latest 24.7_9 firmware offered to me, and the kernel panics have disappeared! I wish I knew exactly what in the update solved the issue, but it might just continue to be a mystery.
#8
I had the chance to swap RAM with my other box, and the issue persists with different RAM on the same machine, which appears to rule out the RAM.

I noticed I did not attach the entire panic report, so maybe this will be of some use to somebody.
#9
Apologies, been busy but still experiencing issues here.

Output:

SMBIOS 3.3 present.

Handle 0x000A, DMI type 17, 40 bytes
Memory Device
   Array Handle: 0x0009
   Error Information Handle: Not Provided
   Total Width: 64 bits
   Data Width: 64 bits
   Size: 32 GB
   Form Factor: SODIMM
   Set: None
   Locator: Channel-1-DIMM-0
   Bank Locator: BANK 0
   Type: DDR4
   Type Detail: Unknown Synchronous
   Speed: 3200 MT/s
   Manufacturer: Kingston
   Serial Number: a6229aae
   Asset Tag: Channel-1-DIMM-0-AssetTag
   Part Number: KF3200C20S4/32GX
   Rank: 2
   Configured Memory Speed: 3200 MT/s
   Minimum Voltage: 1.2 V
   Maximum Voltage: 1.2 V
   Configured Voltage: 1.2 V


Same RAM as my other box. Coreboot is a newer version I believe, but will need to verify that when I get the chance. I will not be able to attempt a RAM swap anytime soon, but that could end up being a time-saving answer in the long run.

I'm wondering (if)/hoping it's a configuration issue. Anything else I can provide to help the troubleshoot?

Thanks for your help
#10
Thank you!!  :)

It does not display anything I can tell being useful for us besides BIOS version. I attached screenshot.

But I know I am using x2 16 GB Kingston Impact DDR4-3200 SO-DIMM modules.
#11
Hi,

I've noticed a few different threads with folks having similar symptoms, but I'll add my issue here separately. I attached the log of the panic and can share more if needed. I would like some assistance because I'm afraid that the frequent panics will end up damaging my installation or hardware.

I have a Protectli VP2420 with the latest firmware. In fact, it's a brand new box. It's experiencing kernel panics daily at 3am. A reproducible kernel panic also occurs during a health check when checking packages. I assume they are related.

I am only using ACME and Chrony plugins, and Suratica. I am using a LAGG with VLANs. It is connected to a Unifi switch->Unifi Pro 6 (wireless), which is sending tagged/untagged traffic to Protectli.

On an unrelated note, I have another box with the same exact hardware and firmware, but different configuration (using Zenarmor and Suratica). I have been using this box for 6 months with no issues. It is not experiencing kernel panics. It is not using VLANs or LAGG.

Thank you for your help!  8)