-
Version2.4.40 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /70 GB Storage for /nsm130 GB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailHello there, after the weekend, I saw /nsm was nearly full, so I delete some pcap files (auto delete doesn't work well) and deactivate Stenographer (just using suricata). But since the influxdb show "NSM Disk High Usage" the traffic doesn't show as Altert to the managersearch. Before the weekend, everything works fine. Already tried after searching similar issue: Every log file looks fine except of this logstash: logstash.log
Any idea whats going on? Kind regards Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 2 replies
-
Do you get any errors when you run "sudo so-redis-restart" on the Manager Search? |
Beta Was this translation helpful? Give feedback.
-
The installation type says distributed, but is this a standalone node? |
Beta Was this translation helpful? Give feedback.
-
I have found the problem. The Redis queue was full. The solution can be found in the official documentation: https://docs.securityonion.net/en/2.4/redis.html#queue Many thanks for your help. |
Beta Was this translation helpful? Give feedback.
I have found the problem. The Redis queue was full. The solution can be found in the official documentation: https://docs.securityonion.net/en/2.4/redis.html#queue
Many thanks for your help.