Hello, I've been troubleshooting an issue for a bit now and I'm not sure where to go.
ISSUE: I have two Linux hosts (FleetDM Server itsself on Ubuntu, and a Debian server) who will not respond to queries, yet show up as valid hosts listing all software/vulns,etc...
STACK
• Ubuntu 24.04 LTS hosted on a major cloud provider
• Apache2 for Reverse Proxy
• All services running localhost (Apache, REDIS, MYSQL, FleetDM)
ERROR LOGS:
• syslog shows errors like '2024-08-10T123652.090409+00:00 FleetDM fleet[753]: level=error ts=2024-08-10T123652.088296762Z component=http method=POST uri=/api/v1/osquery/distributed/write took=4.885414ms ip_addr=XXX.245.XXX.41 x_for_ip_addr=XXX.245.XXX.41 ingestion-err="campaignID=10 waiting for listener" err="error in query ingestion" '
• No errors in mysql logs
• No errors in redis logs
• No erros in apache2 logs
SCREENSHOTS:
• My FleetDM Config file
• FleetDM Hosts Dashboard
• Queries Page
• Live Query page
• Ubuntu syslog errors
• Apache2 Virtual Host File
FIREWALL:
• Configured on the cloud provider portal
• Inbound Ports 22,80,443 open on all machines
• No outbound ports blocked
And recommendations on where to go, what to troubleshoot next, or any configuration recommendations?
Thanks in advance