Need help determining: do I have insufficient hardware and storage or is the server experiencing other issues? #13756
Unanswered
chrislawso
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have an older standalone securityonion that has been running for a while on Version: 2.3.190 and I noticed that in Alerts page if I select a custom date range of older than 2 days ago the page shows "No data available".
securityonion only shows me alerts for the previous 2 days, nothing older. The xeon machine has 64gb of ram, seconion is installed on 2* 1TB 2.5" sata hard drives in perc raid1 with bbu write back cache enabled.
In the command line df -h shows
/ used 26G and 268G avail
/nsm used 556G and 71G avail
In grafana dashboard I noticed that container uptime so-suricate has 2.9days, so-wazuh container uptime is 37.4days, all other containers have 155 days of uptime.
More info from grafana dashboard page:
CPU Usage mean 22.5%
Memory Usage mean 53.7%
Disk Usage / shows 8.8%
Disk Usage /nsm 88.9%
Swap Usage 100%
IO wait mean 0.5%
Monitor Interface Traffic Inbound Max 393 Mb/s , Mean 205 Mb/s
Monitor Interface Drops - Inbound Max 666.7 mp/s , Mean 634.6 mp/s , Last 633.3 mp/s
Zeek Package loss Mean 0%
Suricate Packet Loss mean 0%
Stenographer Packet Loss mean 0%
CPU Tasks Running mean 0.8
Ultimately I intend on upgrading or installing new version of security onion on this machine and if necessary upgrading the hardware.
First, before performing any changes I want to troubleshoot and try to understand:
What is causing the alert history to only show alerts up to approximately two days ago? Does the machine require more storage space? Or is the container uptime of so-suricate at 2.9days the cause of missing alerts? Or something else?
What might be the causes of the monitor interface drops of approx 650 mp/s?
Is there anything else abnormal about the above statistics dashboard info?
Thank you
Beta Was this translation helpful? Give feedback.
All reactions