Reinstall Threat Intel Plugin

(Daniel Morgan) #1

Greetings Graylog Community!

I’m fairly new to Graylog and I’ve finally taken the plunge to join the forums in the hope that I can one day add some value to other Grayloggers .

Unfortunately this time, I have made a bit of a boo boo in my Graylog instance by manually removing all the Threat intel related plugins from the Lookup tables, as well as Content packs page, in an attempt to try and reinstall it. The reason I did this was because I found some logs on my server that referenced the following:

[LookupTableService] Lookup table does not exist
[LookupTableService] Lookup table does not exist

I was running a 2.x version of Graylog, and then upgraded to 3.0.1 (Straight upgrade, not a fresh install).

Is it possible to actually reinstall this plugin, and if so, how do I do this? Would really appreciate any help here. Please let me know if there is additional information I should be supplying.

Thank you in advance!

(Daniel Morgan) #2

I managed to figure this out on my own. Seems after upgrading from 2.x to 3.x, this caused some issues. I was able to reinstall the plugins from the Graylog Plugin Threat Intel on Github.

I did however uninstall the Graylog-Server package first, on my Ubuntu 18.04 instance. And then reinstall it. This did not interfere with any of my data or existing configs, and reinstalled back perfectly.

My pipelines for the threat intel data are all working great now!

(Jan Doberstein) #3

the data and most configuration is store in Elasticsearch and mongoDB - as long as you use the same, this is possible. Means remove and install Graylog again.

(system) closed #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.