main
mdx 115 lines 2.48 KB
Raw
1 ---
2 title: Troubleshooting index
3 description: Symptom → likely causes → what to check (CoPilot + SIEM stack).
4 ---
5
6 This page is a **symptom-based index**. Find what you’re seeing, then follow the checks.
7
8 > Wireframe note: this is intentionally high-level. As we fill docs, each item will link to deeper pages with exact UI clicks and screenshots.
9
10 ---
11
12 ## Ingestion
13
14 ### No endpoint logs (Wazuh)
15
16 Likely causes:
17 - Wazuh connector not verified
18 - agent not enrolled / offline
19 - indexing/storage issue
20 - tenant/customer association missing
21
22 What to check:
23 - CoPilot: Connectors → Wazuh status
24 - CoPilot: Agents shows host online
25 - Wazuh: agent status + manager logs
26 - Indexer/OpenSearch: index health
27
28 ### No syslog / network logs
29
30 Likely causes:
31 - device not sending syslog
32 - collector not listening / firewall/ACL
33 - parsing pipeline not extracting fields
34 - routing/tenant association missing
35
36 What to check:
37 - device syslog destination IP/port
38 - collector receive logs
39 - Graylog input/stream/pipeline
40
41 ### No third-party integration events (O365/Mimecast/etc.)
42
43 Likely causes:
44 - API credentials/scopes wrong
45 - export/collector not running
46 - routing/tenant association missing
47
48 What to check:
49 - CoPilot: External Services / Integration status
50 - credential permissions
51 - ingestion job logs (if applicable)
52
53 ---
54
55 ## Visualization
56
57 ### Grafana dashboards are empty
58
59 Likely causes:
60 - Grafana connector not verified
61 - provisioning not completed
62 - index pattern/data source misconfigured
63 - data is not flowing yet
64
65 What to check:
66 - CoPilot: connector status
67 - customer provisioning status
68 - Grafana: data source points at correct indices
69
70 ---
71
72 ## Alerting
73
74 ### Graylog alerts not showing in CoPilot
75
76 Likely causes:
77 - Graylog connector not verified
78 - event definitions not firing
79 - `gl-events*` not being written
80 - CoPilot not querying the correct index/pattern
81
82 What to check:
83 - CoPilot: Graylog connector status
84 - Graylog: event definitions + streams
85 - Indexer: `gl-events*` exists and has recent docs
86
87 ---
88
89 ## Incident workflow
90
91 ### Can’t create cases / case workflow feels broken
92
93 Likely causes:
94 - permissions/RBAC
95 - missing required configuration
96
97 What to check:
98 - user permissions/roles
99 - customer/tenant context
100
101 ---
102
103 ## Response
104
105 ### Velociraptor actions not working
106
107 Likely causes:
108 - Velociraptor connector not verified
109 - agent not enrolled in Velociraptor org
110 - permissions missing
111
112 What to check:
113 - CoPilot: Velociraptor connector status
114 - Velociraptor: client visibility
115 - CoPilot: agent metadata has velociraptor identifiers