Skip to content

Version Upgrade of Analyzer makes all Analyzers invisible for TheHive (Cortex2) #75

@crackytsi

Description

@crackytsi

Request Type

Bug

Work Environment

Question Answer
OS version (server) Debian 8
Cortex version / git hash 2.0.1
Package Type DEB

Problem Description

After an update of an Analyzer, Cortex does not list anymore any Analyzer.

Reproduce

  1. I changed an self-developed Analyzers from version 1.0 to 1.1 in the JSON Config file and added another accepted input type (instead of just IP, I added domain and fqdn additionally).
  2. I restarted Cortex2 to reload the analyzer. The Analyzer became visible (in version 1.0 without any accepted dataType and version 1.1 with the 3 accepted dataTypes.
  3. I checked TheHive, there was still only the old data-types accepted. So I restarted TheHive.
  4. Now not even one cortex analyzer was listed.
  5. I restarted Cortex and TheHive again.
  6. I stopped Cortex/TheHive and finally ES and restarted ES, then Cortex, then TheHive
  7. I tried different Browsers (Chrome, IE, Firefox), but there are still no analyzers found.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions