Skip to content
Discussion options

You must be logged in to vote

In the end, disabling the Playbook, where I enabled lots of rules, "kinda" did the trick. The search node was around 2.5 load on the dedicated Proxmox host and on the other host with all the VMs + SO Manager + SO Sensor, the load dropped down to 5. I moved the search node back to the host where others VMs are and the load is now around 9.4 - 9.8. I hope it will stay like this.

Yes, enabling lots of plays in Playbook will generate lots of Elasticsearch queries. Specifically, did you enable the Malicious Nishang PowerShell Commandlets play or any experimental plays?

From https://docs.securityonion.net/en/2.4/playbook.html#putting-a-play-into-production:
Performance testing is still ongoin…

Replies: 1 comment 10 replies

Comment options

You must be logged in to vote
10 replies
@Crimson1110
Comment options

@dougburks
Comment options

@Crimson1110
Comment options

@dougburks
Comment options

Answer selected by Crimson1110
@Crimson1110
Comment options

@dougburks
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants