Troubleshooting

Find the symptom you are seeing and follow the steps under it, from the most common cause to the least.

No events appear

If a machine is installed but its events list stays empty, the cause is almost always that no source is switched on, or that a rule is dropping or hiding the events. Check these in order.

  1. A source is on. Every source is off until you switch it on, so a new machine reports nothing. Open Configure for the machine (or your global settings on the Filters page) and turn on at least one, such as socket for a web service.
  2. The program was restarted after the change. Source changes apply to programs started afterwards, never to one already running; see When it applies.
  3. You ran it with es-python. A program started with plain python is not watched. Check how your service manager, container or test runner starts it.
  4. The machine is installed. Its status on the Machines page should read installed. If it reads created, pending or failed, finish the install.
  5. No rule is dropping the events. Every account starts with two Don't send rules, with the patterns re and write. A rule pattern matches any part of an event's name, so these drop every event whose name contains re or write anywhere. Review them under Default rules.
  6. Nothing is hiding them on the page. Clear the events toolbar filters (whitelist, blacklist, time range, machine, severity), check the Show control is not set to suppressed only, and check the right product's list is open; see Filtering.
  7. The data really reached a risky operation. An event means untrusted data from a source you switched on reached a sink. A program that only reads a file, with no file source, or never passes its input anywhere risky, produces nothing.
  8. Your plan is active and has room. An account with no plan yet shows no events, and events past a month's quota are stored but hidden unless the quota is raised; the next month starts with fresh room.
  9. The computer can reach EyalSec. Run eyalsec info and check that the server address it shows, including its port, is reachable from the computer through any firewall or proxy.

If the machine shows old copy running or clone, see those sections below.

The install fails

The installer prints a red line saying why it stopped. Find it below, fix the cause, then generate a fresh install command and run that; see Troubleshooting the install for more.

Message says What to do
this install command is no longer valid (es-python) or this install command was already used or has expired Each command works once and only for 10 minutes. Click Install on the machine's row again and run the new command.
this host is ... but the build selected for this machine is ... The machine's operating system or architecture on the dashboard does not match this computer. Add a machine with the right values and delete the wrong one (see Set the OS), then install the new one.
this host has glibc ..., but the build selected ... needs ... The chosen operating system is newer than this computer. Add a machine with the distro this computer actually runs.
not enough free disk Free up the space it names, in both your temporary folder and ~/opt.
missing required tool: ... Install the tool it names (for example curl or tar) with your system's package manager.
HOME ... is not writable or cannot create $HOME/opt Run the installer as the user who will run es-python, in a normal login shell.
integrity check failed The download was damaged on the way. Generate a fresh command and try again.
the machine limit ... or no active plan when adding the machine See Adding a machine is refused.

A machine stuck in pending or failed can simply be installed again with a fresh command.

"es-python: command not found"

The installer put es-python in ~/.local/bin and added that folder to your PATH, but a terminal opened before the install does not see the change. Open a new terminal or run exec $SHELL. If that does not help, follow PATH and "command not found", which also covers cron and systemd.

Adding a machine is refused

The message tells you which limit you hit. "Your account has no active plan yet" means no plan is set up; see No plan yet. "Machine limit reached" means you already have as many machines of that product as your plan allows: delete one you no longer use, or email sales@eyalsec.com for more. See Machine limit.

A Raise rule is rejected

"Raise rules are not enabled for your account" means blocking is not part of your plan. Every other rule mode works without it. Email sales@eyalsec.com to have Raise enabled; see Raise.

My program stopped with an EyalSec RuntimeError

A message such as RuntimeError: EyalSec: untrusted data from ... reached sink ... means a Raise rule (or the --raise flag) blocked a risky operation, as designed. The matching event on the dashboard shows exactly what was blocked. If it should not have been blocked, narrow or switch off the Raise rule in Rules, or catch the error in your code. See Report and Raise.

A setting change did nothing

Rules reach a running program within about 30 seconds. Source changes, and changes to what is sent with each event, apply only to programs started after the change, so restart the program. A setting on the machine itself also overrides the global one on the Filters page; see Scope.

The machine shows "old copy running"

A program started under an earlier install of this machine is still running. Reinstalling issued a new credential, so that old program can no longer send events. Restart it (and any service that runs it) so it starts under the current install; the badge clears on its own once it stops. See Old copy running.

The machine shows "clone"

The machine's install was seen from a second computer, or showed signs of tampering, and its events are refused until you reinstall it. Do not copy an installed es-python to other computers: add a machine for each one. If you did not copy it, treat it as a security finding, investigate the computer, and email support@eyalsec.com with the machine's name if you need help. See Clone.

The machine shows "newer build available"

A newer EyalSec build exists for this machine. Nothing is broken; to take it, reinstall the machine and restart your programs.

A package misbehaves under es-python

If a library that works with your regular Python fails under es-python, first check which copy imports with es-python -m _eyalsec_bridge; see Bundled libraries. If the problem is a version conflict with a bundled library, let your own copy of that library win with ES2_PREFER_APP_LIBS. If a package compiled for your regular Python is the problem, try ES2_NO_SYSTEM_SITE=1 or a virtual environment. See Packages and libraries.

I cannot sign in

"Too many failed attempts. Please try again later." means sign-in is paused for your account or network after several wrong passwords. Wait and try again, or reset your password; see Sign in and Forgot password. If you lost your two-factor device, use a backup code. If none of that works, email support@eyalsec.com.

Still stuck

See Getting help for how to reach us and what to include.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo