Create Wazuh Monitors Cause 500 Internal Server Errors

Posted by IndyPilot80@reddit | sysadmin | View on Reddit | 7 comments

I have a problem that I've been chasing for a long time and can't seem to resolve. When creating a new monitor, it usually ends up in 500 Internal server errors. I've created a "per document" monitor. After I save the monitor, I immediate get a "Failed to run the query - Request Timeout after 30000ms". In watching "top" for the CLI, java CPU usage jumps to about 800% and stays there. This usually causes a "500 internal server" error which requires a reboot. In /etc/wazuh-indexer/jvm.options, I've increased the Xms and Xmx to half of the physical RAM size and this doesnt help. Any suggestions?