<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
</head>
<body>
<p>Hi,<br>
</p>
<div class="moz-cite-prefix">On 3/12/21 10:15 AM, Soni, Drupad
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:DB5P138MB0008B441BA5D103B83AB059CA96F9@DB5P138MB0008.EURP138.PROD.OUTLOOK.COM">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
{font-family:"Univers for KPMG";
panose-1:2 11 6 3 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;}
span.EmailStyle22
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:1071348806;
mso-list-type:hybrid;
mso-list-template-ids:-1168621700 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level2
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level3
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l0:level4
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level5
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level6
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
@list l0:level7
{mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level8
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-position:left;
text-indent:-.25in;}
@list l0:level9
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-position:right;
text-indent:-9.0pt;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1"> Which operating system,
which IntelMQ version, which installation method do you use?<br>
<p class="MsoNormal">
Ubuntu 18.04 LTS. We have tried installation using Native
packages, git cloning and pip. Intelmq version: 2.3.0 ,
Mongodb: 4.4 , Elasticsearch & Kibana: 5.5.3<o:p></o:p></p>
</div>
</blockquote>
<p>As you write about the Debian package below, I assume you are
working with the native packages now? Or did you mix them?<br>
</p>
<p>Regarding MongoDB: server versions 2.6.10 and 3.6.8 have been
reported to work with IntelMQ's mongoDB output. Version 4 is
*likely* to work as well.
<a class="moz-txt-link-freetext" href="https://intelmq.readthedocs.io/en/latest/user/bots.html#mongodb">https://intelmq.readthedocs.io/en/latest/user/bots.html#mongodb</a><br>
</p>
<p>Regarding ElasticSearch: IntelMQ's ES Output bot only supports
version 7:
<a class="moz-txt-link-freetext" href="https://intelmq.readthedocs.io/en/latest/user/bots.html#elasticsearch-output-bot">https://intelmq.readthedocs.io/en/latest/user/bots.html#elasticsearch-output-bot</a><br>
</p>
<blockquote type="cite"
cite="mid:DB5P138MB0008B441BA5D103B83AB059CA96F9@DB5P138MB0008.EURP138.PROD.OUTLOOK.COM">
<div class="WordSection1">
<p class="MsoNormal"><o:p></o:p></p>
<p class="MsoNormal"> What are you unable to
access and what is the exact error you get?<br>
There are different scenarios,<o:p></o:p></p>
<ol style="margin-top:0in" type="1" start="1">
<li class="MsoListParagraph"
style="margin-left:0in;mso-list:l0 level1 lfo1">When we
tried installing new instance for intelmq:<o:p></o:p></li>
</ol>
<p class="MsoListParagraph">Issue that we are facing: Debian
package (Intelmq-manager) does not prompt for username and
password due to this it is not getting installed properly and
we unable to access GUI<o:p></o:p></p>
</div>
</blockquote>
What do you mean by "not getting installed properly"? Did you get an
error on installation?<br>
<blockquote type="cite"
cite="mid:DB5P138MB0008B441BA5D103B83AB059CA96F9@DB5P138MB0008.EURP138.PROD.OUTLOOK.COM">
<div class="WordSection1">
<ol style="margin-top:0in" type="1" start="2">
<li class="MsoListParagraph"
style="margin-left:0in;mso-list:l0 level1 lfo1">On a
successfully installed intelmq setup integrated with
mongodb:<o:p></o:p></li>
</ol>
<p class="MsoListParagraph">The setup was working fine but
recently we have faced issue where Intelmq bots of mongodb and
elasticsearch both have stopped working. It asks for pymongo
package even after fulfilling the dependency</p>
</div>
</blockquote>
What does `pip3 list | grep pymongo` show and what are the exact log
entries of the bot?<br>
<blockquote type="cite"
cite="mid:DB5P138MB0008B441BA5D103B83AB059CA96F9@DB5P138MB0008.EURP138.PROD.OUTLOOK.COM">
<div class="WordSection1">
<p class="MsoListParagraph"> and elasticsearch is showing error
ES version needed 5.0<x<6.0 </p>
</div>
</blockquote>
<p>See above. IntelMQ only supports ES 7.</p>
<p>Hope that helps.<br>
</p>
<p>kind regards<br>
Sebastian Wagner<br>
</p>
<pre class="moz-signature" cols="72">--
// Sebastian Wagner <a class="moz-txt-link-rfc2396E" href="mailto:wagner@cert.at"><wagner@cert.at></a> - T: +43 1 5056416 7201
// CERT Austria - <a class="moz-txt-link-freetext" href="https://www.cert.at/">https://www.cert.at/</a>
// Eine Initiative der nic.at GmbH - <a class="moz-txt-link-freetext" href="https://www.nic.at/">https://www.nic.at/</a>
// Firmenbuchnummer 172568b, LG Salzburg</pre>
</body>
</html>