Skip to content
Discussion options

You must be logged in to vote

I have a forward node ingesting 0.5-2.5Gbps nominal on a 10Gbps TAP with a few spikes up to 4Gbps during heavy days.
It has 4x 8TB LFF SATA drives in a RAID5 mounted at /nsm, but that maxes out at about 3Gbps ingest (1Kiops/240MBps to disk) at which point I see iowait spikes of 1sec or more. With 22TB for PCAPs, I get around three days of retention during a normal weekday cycle, more during the quiet weekends.
It has 16 3GHz physical cores, x2 for SMP (AMD EPYC 7313P), and peaks at about 25%, so 8-core (16 threads) would probably have been sufficient for that but the 7313P is still a cheap CPU. That's with ETGPL+TALOS rulesets in suricata, plus zeek and steno.
It has 64GB RAM, which is ab…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@BlueSkyGreenWater
Comment options

Comment options

You must be logged in to vote
1 reply
@BlueSkyGreenWater
Comment options

Answer selected by TOoSmOotH
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants