-
Notifications
You must be signed in to change notification settings - Fork 640
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Analyzers in TheHive not updating? #1052
Comments
If the analyzer has already been enabled in Cortex, then it will be always listed even if you update your catalog. So, please double check that these analyzers are no longer available on Cortex. TheHive doesn't store the analyzers list. |
@nadouani Where is the Analyzers tab generated from? Without /Cortex_Analyzers present it's still reporting as available. |
After finally getting fed up with this issue, I installed Kibana and tracked down the issue. Cortex is storing the analyzers in Elasticsearch and the record isn't being delete, updated, or retired when the analyzer is deleted. This may only be an issue for people who updated from 5/6, which was our upgrade path. However I had to delete the record of origin for FileInfo_6 in Cortex_4 to remove the entry from the responders due to the FileInfo_7 usage/release in Devel. |
This issue is related to Cortex and is similar to TheHive-Project/Cortex#234. |
Analyzers in TheHive not updating?
Request Type
Bug
Work Environment
Problem Description
The analyzers in HiveRC2 are not updating from Cortex correctly.
Specifically the following analyzers no longer exist and the catalog has been updated via .sh
Complementary information
The text was updated successfully, but these errors were encountered: