So, concerning the DEGRADED issue:
- Here are the logs around the timestamp when I had a DEGRADED message:
{"@timestamp":"2020-09-30T09:00:04.44128021Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1440,"name":"HttpLib.cpp"}}},"message":"HttpLib.cpp:1440 Establishing GET connection to [https://<elasticsearch_node>:9200/_cluster/health]","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:04.72186299Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":65,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:65 Elasticsearch connection is down","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:04.123138026Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"warning","origin":{"file":{"line":446,"name":"AgentComms.cpp"}}},"message":"AgentComms.cpp:446 Failed to read ActionRequest.","process":{"pid":244854,"thread":{"id":263068}}}
{"@timestamp":"2020-09-30T09:00:04.124573172Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":266,"name":"AgentComms.cpp"}}},"message":"AgentComms.cpp:266 Agent state stream is closed. Stopping state reading.","process":{"pid":244854,"thread":{"id":263067}}}
{"@timestamp":"2020-09-30T09:00:05.124542339Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":479,"name":"AgentComms.cpp"}}},"message":"AgentComms.cpp:479 Attempting to reestablish Agent actions stream.","process":{"pid":244854,"thread":{"id":263068}}}
{"@timestamp":"2020-09-30T09:00:05.125059651Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":360,"name":"AgentComms.cpp"}}},"message":"AgentComms.cpp:360 Attempting to reestablish Agent check-in stream.","process":{"pid":244854,"thread":{"id":263067}}}
{"@timestamp":"2020-09-30T09:00:09.81063867Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1440,"name":"HttpLib.cpp"}}},"message":"HttpLib.cpp:1440 Establishing GET connection to [https://<elasticsearch_node>:9200/_cluster/health]","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:09.109686360Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":65,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:65 Elasticsearch connection is down","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:09.174425088Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":110,"name":"AgentConnectionInfo.cpp"}}},"message":"AgentConnectionInfo.cpp:110 Validated agent is root/admin","process":{"pid":244854,"thread":{"id":244897}}}
{"@timestamp":"2020-09-30T09:00:09.174728928Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":118,"name":"AgentConnectionInfo.cpp"}}},"message":"AgentConnectionInfo.cpp:118 Established stage 1 connection to agent","process":{"pid":244854,"thread":{"id":244897}}}
{"@timestamp":"2020-09-30T09:00:10.188804197Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":565,"name":"AgentComms.cpp"}}},"message":"AgentComms.cpp:565 Connecting to Agent.","process":{"pid":244854,"thread":{"id":244897}}}
{"@timestamp":"2020-09-30T09:00:14.119281356Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1440,"name":"HttpLib.cpp"}}},"message":"HttpLib.cpp:1440 Establishing GET connection to [https://<elasticsearch_node>:9200/_cluster/health]","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:14.153836592Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":65,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:65 Elasticsearch connection is down","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:29.268475875Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":65,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:65 Elasticsearch connection is down","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:31.191574993Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":592,"name":"AgentComms.cpp"}}},"message":"AgentComms.cpp:592 Agent connection established.","process":{"pid":244854,"thread":{"id":244897}}}
{"@timestamp":"2020-09-30T09:00:34.274866210Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"info","origin":{"file":{"line":1440,"name":"HttpLib.cpp"}}},"message":"HttpLib.cpp:1440 Establishing GET connection to [https://<elasticsearch_node>:9200/_cluster/health]","process":{"pid":244854,"thread":{"id":244891}}}
{"@timestamp":"2020-09-30T09:00:34.301478832Z","agent":{"id":"31e817fc-6fcf-4bd4-8d29-e3e5206e2c46","type":"endpoint"},"ecs":{"version":"1.5.0"},"log":{"level":"notice","origin":{"file":{"line":65,"name":"BulkQueueConsumer.cpp"}}},"message":"BulkQueueConsumer.cpp:65 Elasticsearch connection is down","process":{"pid":244854,"thread":{"id":244891}}}
I'm showing the few first and last lines to show that they flood the logs.
So, no "found in config"
in here.
edit: the rest of the post is below because of the character limit