Replies: 3 comments 12 replies
-
Hello, |
Beta Was this translation helpful? Give feedback.
0 replies
-
Thanks for the suggestion - NSM is at 89% |
Beta Was this translation helpful? Give feedback.
11 replies
-
Same Problem for me, /nsm also nearly full and error 502. What is the solution? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.10
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Standalone
Location
other (please provide detail below)
Hardware Specs
Exceeds minimum requirements
CPU
8
RAM
16GB
Storage for /
250GB
Storage for /nsm
1,015.75 GB / 558.69 GB Free
Network Traffic Collection
other (please provide detail below)
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
Yes, there are additional clues
Detail
Base install of SO v2.4.10 (Hotfix: 20230821) in a Nested ESXi lab environment using VMware port mirroring.
After a week or so of running SO in our lab environment we started receiving "502 Error" messages on the aforementioned pages. This info was pulled from logs within "/opt/so/log/elasticsearch".
[2023-10-03T23:59:07,620][WARN ][org.elasticsearch.cluster.routing.allocation.DiskThresholdMonitor] high disk watermark [85%] exceeded on [J9Dl1_55RK2BWQAEMQL3zw][securityonion][/usr/share/elasticsearch/data] free: 17.3gb[11%], shards will be relocated away from this node; currently relocating away shards totalling [0] bytes; the node is expected to continue to exceed the high disk watermark when these relocations are complete
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions