Replies: 8 comments 11 replies
-
What are your hardware specs? |
Beta Was this translation helpful? Give feedback.
-
Sorry I wasn’t detailed enough. What are the specs of the VM that SO is
installed in?
On Mon, Aug 22, 2022 at 2:09 PM mstannh ***@***.***> wrote:
Sure........
2 x Intel Xeon E5-2699 18-Core 2.3 Ghz CPUs
256 Gbytes memory
10 Gbase T ethernet
NFS mounted disks - Oracle ZS5-4 DE3-24C
and we are monitoring inbound / outbound traffic from a mirrored port on
an Oracle ES2-64 switch.
—
Reply to this email directly, view it on GitHub
<#8567 (reply in thread)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AY3AYRKCNMWG5NUBS3PC2TTV2O67NANCNFSM57HXIP5Q>
.
You are receiving this because you commented.Message ID:
<Security-Onion-Solutions/securityonion/repo-discussions/8567/comments/3450048
@github.com>
--
Isaac Golding
Owner
Isaac Golding Services Co. <https://isaacgolding.com/>
|
Beta Was this translation helpful? Give feedback.
-
Thanks for that input. |
Beta Was this translation helpful? Give feedback.
-
What does disk wait look like? (Builtin Grafana dashboards will show you that) My initial thought is the NFS is causing issues - from the docs: https://docs.securityonion.net/en/2.3/hardware.html#storage
|
Beta Was this translation helpful? Give feedback.
-
For what it's worth I'm still seeing the same or similar error. I'll start digging into logs and try to find who/what is getting killed. |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
I looked at /opt/so/log/stenographer/ to examine Diagnostic logging for Stenographer, There was nothing there. Do i need to configure a value or run a commend to run/collect steno diagnostic data? |
Beta Was this translation helpful? Give feedback.
-
Please disregard my last comment as I was on the wrong node. |
Beta Was this translation helpful? Give feedback.
-
We have a distributed Security Onion V 2.3.140 installation running on VirtualBox 6.1.36 r152435 {Qt5.9.7) extensions are not install
Nodes are Manager, Search, Sensor.
The installation is working fine except that the sensor is retaining memory and eventually aborts after a couple of hours
The system is receiving packets about every minute however there is a cycle where it is extremely busy and then greatly reduced traffic
Peak times start on the half hour and run for 30 minutes. During peak periods the the sensor ingests approximately 450 GB of data. during reduced traffic periods the sensor ingests 500MB of data.
We are filtering port 443 and ARP.
Symptoms are:
Please reference the attached images that show consumption of resources an error messages.
Beta Was this translation helpful? Give feedback.
All reactions