Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alexander_Wilke
Advisor

Skyline -Delete existing configuration completely and start with fresh paylod.json import?

Hello,

I am using skyline since a longer period with different version upgrades included. Some environments started with older versions than others. Sometimes we had issues/bugs with importing the config.

It looks like my environment is not having the same consistent config and I would like to delete all existing configuration files and start with a fresh default config.

 

How can I delete the config for

CPviewExporter

OtlpAgent

CPotelcol

or at least for CPotelcol which contains the prometheus exporter configs.

 

PS:
Is this configuration needed for Maestro / 64l environments to send traffic from the standby chassis OR is this SK only for non scalable/non-maestro environments?


https://support.checkpoint.com/results/sk/sk182222

Grafana dashboard does not report metrics for the standby cluster member

0 Kudos
8 Replies
Elad_Chomsky
Employee
Employee

Hi @Alexander_Wilke , 

This steps might help you:

1) Run /opt/CPotelcol/CPotelcolCli.sh stop

2) Run /opt/CPviewExporter/CPviewExporterCli.sh stop

3) Run /opt/CPotlpAgent/CPotlpagentCli.sh stop
3) Run /opt/CPotelcol/CPotelcolCli.sh set_dynamic_config "$(cat /opt/CPotelcol/config.json)"

4) Run the configuration again

to reset the system we usually recommend this method. In most cases the relevant configuration to delete is CPotelcol, the rest are changing more rarely. 

0 Kudos
Alexander_Wilke
Advisor

Hello,

the "delete" is not working:

 

[Expert@xxx-ch01-01:dplane]# /opt/CPotelcol/CPotelcolCli.sh "$(cat /opt/CPotelcol/config.json)"
/opt/CPotelcol/CPotelcolCli.sh help - show this message and exit
/opt/CPotelcol/CPotelcolCli.sh start - Start the monitoring components
/opt/CPotelcol/CPotelcolCli.sh stop - Stop the monitoring components
/opt/CPotelcol/CPotelcolCli.sh show - Show the monitoring components status in json format
/opt/CPotelcol/CPotelcolCli.sh is_running - Show if the monitoring components is running
/opt/CPotelcol/CPotelcolCli.sh is_active - Show if the monitoring components is active
/opt/CPotelcol/CPotelcolCli.sh set_dynamic_config <yaml> - Set the otcol dynamic configuration using a custom yaml ( See OT collector config format), if yaml empty config is deleted.
/opt/CPotelcol/CPotelcolCli.sh reconfigure - Reconfigure the monitoring components
Invalid Arguments
[Expert@xxx-ch01-01:dplane]#

 

 

This command is not working, too:

/opt/CPotelcol/CPotelcolCli.sh set_dynamic_config empty.yml

If I reconfigure the cpotelcol, then the old config is there again with several times the same certificate.

0 Kudos
Elad_Chomsky
Employee
Employee

Apology, I fixed the command - Notice to use the baseline template. it expects a JSON. 

Alexander_Wilke
Advisor

Hello @Elad_Chomsky 

it did not fully delete the configuration.

1_01:
{"enabled":false,"export-targets":[]}

 

Further with "g_all" or "gexec -b all -c '' " because it looks like in the latest skyline versions the configuration is individual per SGM and works on standby chassis, too.

 

However, after I ran your steps, stoped the services on all SGMs and "set_Dynamic_config" and after that recomnfigured with my payload.json I still see all the many many certificates in the "sklnctl --show_open_telemetry" command.

 

Looks like the config was not deleted or not everywhere.

0 Kudos
Alex-
Leader Leader
Leader

Hi Elad,

 

Thanks, it fixed an issue we had with a cluster member which stopped sending metrics and was also upgraded through multiple versions before the current version of the daemon.

I don't know if it is required but I had to additionally do a cps top;cpstart on the member to have the stats flowing in again.

0 Kudos
Alexander_Wilke
Advisor

Hey Alex,
I get metrics however the sp_security_group_id is wrong. It has the id "0" which seems to be wrong because it has at least 1 SG.
So it looks like not all config is reverted/resetted which was what I was looking for.

0 Kudos
Elad_Chomsky
Employee
Employee

Hi @Alexander_Wilke ,

Please contact me in private at eladch@checkpoint.com.

I will try to assist you on this issue. 

0 Kudos
Elad_Chomsky
Employee
Employee

Hi @Alex- ,

Sounds like a deeper problem, I suggest to open a ticket to the official channels on CheckPoint, so we can extract debugs and directly assist you to understand what has happened. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events