Monitor Interface Drops #10344
Replies: 6 comments 7 replies
-
Do you use jumbo frames on your network? |
Beta Was this translation helpful? Give feedback.
-
So I just replaced all the cables with fresh brand new, no difference in drops. I don't have the ability to set up a SPAN port on my switch but I'll try replacing the TAP next. It was working fine with my old setup which was a single node, that's why my gut says it is something on the forward node not behaving correctly or an error that occured during install |
Beta Was this translation helpful? Give feedback.
-
Sorry the screenshot is from a phone but you can see the max over a 24 hour time frame for both traffic and loss. I actually downloaded some large files to see if something was getting buffered and dropping but I didn't notice a change in loss with larger bandwidth usage |
Beta Was this translation helpful? Give feedback.
-
Here is the info for the monitor interface as well as the bond0 interface
|
Beta Was this translation helpful? Give feedback.
-
I am also getting Zeek errors about too little traffic and too much loss which makes me think the numbers are real, Zeek is saying 10% loss in the alerts on Kibana, however on Grafana it shows 0% loss for Zeek, Suricata, and Sten which I am not sure why there is a discrepancy there. I switched out my TAP for a new SharkTAP and I didn't see any change in the packet loss. Any other thoughts on things to try? I rarely saw any loss on my old setup which was a single node, otherwise I am loving the performance boost of having a distributed setup now. |
Beta Was this translation helpful? Give feedback.
-
Here is an example of the alert that keeps getting generated, currently the % ranges from 10-39% with 1800 alerts in the last 24 hours
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I just installed a new distributed deployment on my network, all on hardware (Dell Servers running Ununtu 20.04 LTS with SO installed after), have a manager, search, honeypot and forward node all setup and working. The only issue with the setup seems to be on the forward node, on the Grafana interface it is showing a high rate of drops on the monitor interface, none for steno/suricata/zeek and I got a few alerts from Zeek saying it expected at least 1 TCP ACK and got zero so I assume it is indeed dropping some traffic. I am getting Zeek and Suricata alerts on what traffic is being sniffed and everything reports OK on all boxes from running SO-status. The NIC is an Intel on a Dell server, traffic is sent via a 1G Shark TAP. I did have a few issues when I did the install on the forward node, kept telling me the monitor interface was unmanaged by NetworkManager and I had to follow a guide to disable the Ubuntu networking and switch to using NetworkManager only which fixed the install issue and allowed it to proceed without error. Below is the Ethtool output for the NIC and I am not seeing any potential issues there either. Not sure what to do next trouble shooting wise. Thanks for any help!!
Beta Was this translation helpful? Give feedback.
All reactions