Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Old non-existent analysers showing in Cortex after an upgrade #234

Closed
daskydasky opened this issue Oct 24, 2019 · 1 comment
Closed

Old non-existent analysers showing in Cortex after an upgrade #234

daskydasky opened this issue Oct 24, 2019 · 1 comment
Assignees
Labels
Milestone

Comments

@daskydasky
Copy link

Request Type

Bug

Work Environment

Question Answer
OS version (server) Debian
OS version (client) Windows 10
Cortex version / git hash 3.0.0-1
Package Type deb
Browser type & version Chrome 77.0

Problem Description

Old non-existent analysers showing in Cortex after an upgrade.
I have upgraded TheHive / Cortex / Cortex Analysers and in Hive could not see any analysers.
Basically in Cortex on analysers tab still showing previously installed analysers.
Analysers catalogue is up to date.

Possible Solutions

As a workaround, I have created a new organization.

@RtKelleher
Copy link

RtKelleher commented Oct 25, 2019

I had opened a similar ticket awhile back.

I found by trial and error that you can remove the old analyzers in Elastic-search by deleting the first document referring to the analyzer (e.g. POST DELETE /Cortex_4/_doc/ or by query)

I'm unsure why they are not removed, but that was the only way I could get rid of the old analyzers.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants