TheHive-Project / TheHive-Project/Cortex

No analyzers found even though analyzer path is given

Open
#427 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Scala
Stars
1.6k
Forks
264
PR merge metrics
No merged PRs in 30d

Description

No analyzers found even though analyzer path is given

Request Type

Bug

Work Environment
Question Answer
Distributor ID: Ubuntu
Description: Ubuntu 20.04.5 LTS
Release: 20.0
Problem Description

I've installed Cortex and cortex analyzer. did exactly as asked in documentation on cortex GitHub page.
updated database as the first step, created user.
Installed cortex analyzer, changed that directory in application.conf file as well.
now that i've restarted cortex the analyzer tab is not showing up. hence I can't enable them also.

Steps to Reproduce

application.conf file analyzer section

ANALYZERS

analyzer {

analyzer location

url can be point to:

- directory where analyzers are installed

- json file containing the list of analyzer descriptions

urls = [
#"https://download.thehive-project.org/analyzers.json"
"/opt/cortex/Cortex-Analyzers/analyzers"
]
# Sane defaults. Do not change unless you know what you are doing.
fork-join-executor {
# Min number of threads available for analysis.
parallelism-min = 2
# Parallelism (threads) ... ceil(available processors * factor).
parallelism-factor = 2.0
# Max number of threads available for analysis.
parallelism-max = 4
}
}

RESPONDERS

responder {

responder location (same format as analyzer.urls)

urls = [
#"https://download.thehive-project.org/responders.json"
#"/absolute/path/of/responders"
"/opt/cortex/Cortex-Analyzers/analyzers"
]

Sane defaults. Do not change unless you know what you are doing.

fork-join-executor {
# Min number of threads available for analysis.
parallelism-min = 2
# Parallelism (threads) ... ceil(available processors * factor).
parallelism-factor = 2.0
# Max number of threads available for analysis.
parallelism-max = 4
}
}

Proxy configuration to retrieve catalogs

play.ws.proxy {

host = proxy.example.com

port = 3128

}


for now I'm just trying to get cortex up and running including analyzers, connecting it with ELK and hive is not mandatory for me as of now.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with application.conf's analyzer.urls setting and the analyzer installation path shown in the report; compare them with the Cortex GitHub documentation for the matching release. Reproduce on Ubuntu 20.04.5 LTS and verify that the analyzer tab appears after restarting Cortex.

Written by the indexing model from the issue text.

Assessment

Tech stack
scala, ubuntu
Domain
backend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.