Skip to content

Commit 4484247

Browse files
rr404jdv
andauthored
StackHealh Doc pages V1.0.2 - compact + content check (#938)
* regrouping diagnosis and resolution + fixing content and making it more compact * se offline update * issue_se_no_alerts.md update + nano changes internal link in root cause of earlier 2 * lp offline update * lp no log read + nano update - link * lp_no_logs_parsed + nano up * _lp_no_alerts simplificaiton by pointing to se no alert * rx integ offline update * fw integ offline update * link fix --------- Co-authored-by: jdv <julien@crowdsec.net>
1 parent df65248 commit 4484247

File tree

17 files changed

+692
-1199
lines changed

17 files changed

+692
-1199
lines changed

crowdsec-docs/docs/appsec/quickstart/general.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -179,7 +179,7 @@ This scenario can only be triggered again after a 1-minute delay.
179179
180180
### Multiple AppSec Configurations
181181
182-
You can [load multiple AppSec configurations](/appsec/vpatch_crs.md) for different rule sets:
182+
You can [load multiple AppSec configurations](/appsec/vpatch_and_crs) for different rule sets:
183183
184184
```yaml
185185
# /etc/crowdsec/acquis.d/appsec.yaml

crowdsec-docs/unversioned/getting_started/installation/whm.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -148,7 +148,7 @@ Most of the time it will be a port conflict or config file error
148148
- Check the logs for error
149149
- In CrowdSec's logs sudo less /var/log/crowdsec.log: Note that it might be very verbose.
150150
- You can also check: sudo journalctl -u crowdsec
151-
- Ultimately, you can check the [Security Engine Troubleshooting section](/u/troubleshooting/security_engine.mdx)
151+
- Ultimately, you can check the [Security Engine Troubleshooting section](/u/troubleshooting/security_engine)
152152

153153
### Changing port configuration
154154

crowdsec-docs/unversioned/getting_started/post_installation/acquisition_troubleshoot.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ The first thing to check is that the log file is found and readable by the Crowd
2121

2222
Within the CrowdSec log file it will log if the file was found or not.
2323

24-
Log file locations change by distribution, you can find the default log location [outlined here](/u/troubleshooting/security_engine.mdx#where-are-the-logs-stored).
24+
Log file locations change by distribution, you can find the default log location [outlined here](/u/troubleshooting/security_engine#where-are-the-logs-stored).
2525

2626
<FormattedTabs
2727
bash="grep '/path/to/your/file.log' /var/log/crowdsec.log"

crowdsec-docs/unversioned/getting_started/post_installation/troubleshoot.mdx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ import FormattedTabs from '@site/src/components/formatted-tabs';
99

1010
# Troubleshoot
1111

12-
This troubleshoot section is intended to help you resolve common issues that may arise during the installation process. You can find extensive [troubleshooting documentation](/u/troubleshooting/intro.md) if this document does not resolve your issues.
12+
This troubleshoot section is intended to help you resolve common issues that may arise during the installation process. You can find extensive [troubleshooting documentation](/u/troubleshooting/intro) if this document does not resolve your issues.
1313

1414
# Logs and Errors
1515

@@ -89,6 +89,6 @@ After you have made the changes you will need to restart the CrowdSec service.
8989
9090
## Next Steps?
9191
92-
If the above hasn't resolved the issue you are facing, you can find more detailed troubleshooting documentation [here](/u/troubleshooting/intro.md).
92+
If the above hasn't resolved the issue you are facing, you can find more detailed troubleshooting documentation [here](/u/troubleshooting/intro).
9393
9494
If you have resolved the issue you can continue with the [post installation steps](/getting_started/next_steps.mdx#1-crowdsec-console-).

crowdsec-docs/unversioned/troubleshooting/console_issues.md

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -10,22 +10,22 @@ This page lists all possible health check issues, their trigger conditions, and
1010

1111
- 🔥 **Critical**: Immediate attention required - core functionality is impaired
1212
- ⚠️ **High**: Important issue that should be addressed soon - may impact protection effectiveness
13-
- 💡 **Recomended**: Additionnal actions that will continue improving your security posture *(comming in next iterations of Stack Health)*
13+
- 💡 **Recommended**: Additionnal actions that will continue improving your security posture *(comming in next iterations of Stack Health)*
1414
- 🌟 **Bonus** : Optimization advises and upper tier recommendation with great return on value *(comming in next iterations of Stack Health)*
1515

1616
## Health Check Issues Overview
1717

1818
| Issue | Criticality | Summary | Resolution |
1919
|-------|-------------|---------|------------|
20-
| **Security Engine Offline** | 🔥 Critical | Security Engine has not reported to Console for 24+ hours | [Troubleshooting](/u/troubleshooting/issue_se_offline) |
21-
| **Security Engine No Alerts** | ⚠️ High | No alerts generated in the last 48 hours | [Troubleshooting](/u/troubleshooting/issue_se_no_alerts) |
22-
| **Security Engine Too Many Alerts** | ⚠️ High | More than 250,000 alerts in 6 hours | [Troubleshooting](/u/troubleshooting/issue_se_too_many_alerts) |
23-
| **Log Processor Offline** | 🔥 Critical | Log Processor has not checked in with LAPI for 24+ hours | [Troubleshooting](/u/troubleshooting/issue_lp_offline) |
24-
| **Log Processor No Alerts** | ⚠️ High | Log Processor has not generated alerts in 48 hours | [Troubleshooting](/u/troubleshooting/issue_lp_no_alerts) |
25-
| **Log Processor No Logs Read** | 🔥 Critical | No logs acquired in the last 24 hours | [Troubleshooting](/u/troubleshooting/issue_lp_no_logs_read) |
26-
| **Log Processor No Logs Parsed** | 🔥 Critical | Logs read but none parsed in the last 48 hours | [Troubleshooting](/u/troubleshooting/issue_lp_no_logs_parsed) |
2720
| **Integration for Firewall Offline** | 🔥 Critical | Firewall has not pulled from BLaaS endpoint for 24+ hours | [Troubleshooting](/u/troubleshooting/issue_integration_fw_offline) |
2821
| **Integration for RC Offline** | 🔥 Critical | Remediation Component has not pulled from endpoint for 24+ hours | [Troubleshooting](/u/troubleshooting/issue_integration_rc_offline) |
22+
| **Log Processor No Alerts** | ⚠️ High | Log Processor has not generated alerts in 48 hours | [Troubleshooting](/u/troubleshooting/issue_lp_no_alerts) |
23+
| **Log Processor No Logs Parsed** | 🔥 Critical | Logs read but none parsed in the last 48 hours | [Troubleshooting](/u/troubleshooting/issue_lp_no_logs_parsed) |
24+
| **Log Processor No Logs Read** | 🔥 Critical | No logs acquired in the last 24 hours | [Troubleshooting](/u/troubleshooting/issue_lp_no_logs_read) |
25+
| **Log Processor Offline** | 🔥 Critical | Log Processor has not checked in with LAPI for 24+ hours | [Troubleshooting](/u/troubleshooting/issue_lp_offline) |
26+
| **Security Engine No Alerts** | ⚠️ High | No alerts generated in the last 48 hours | [Troubleshooting](/u/troubleshooting/issue_se_no_alerts) |
27+
| **Security Engine Offline** | 🔥 Critical | Security Engine has not reported to Console for 24+ hours | [Troubleshooting](/u/troubleshooting/issue_se_offline) |
28+
| **Security Engine Too Many Alerts** | ⚠️ High | More than 250,000 alerts in 6 hours | [Troubleshooting](/u/troubleshooting/issue_se_too_many_alerts) |
2929

3030
## Issue Dependencies
3131

crowdsec-docs/unversioned/troubleshooting/intro.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,9 @@ If you received a health check alert from the CrowdSec Console, check out the [*
2121

2222
## Troubleshooting by Topic
2323

24-
* [Security Engine Troubleshooting](/u/troubleshooting/security_engine.mdx)
25-
* [Remediation Components Troubleshooting](/u/troubleshooting/remediation_components.mdx)
26-
* [CTI Troubleshooting](/u/troubleshooting/cti.mdx)
24+
* [Security Engine Troubleshooting](/u/troubleshooting/security_engine)
25+
* [Remediation Components Troubleshooting](/u/troubleshooting/remediation_components)
26+
* [CTI Troubleshooting](/u/troubleshooting/cti)
2727

2828
## Community support
2929

0 commit comments

Comments
 (0)