Skip to content
Discussion options

You must be logged in to vote

It seems that Suricata is writing alerts to disk but the sensor clean script is deleting those files because it thinks you're running out of disk space.

I would try lowering suricata maxsize to something smaller like 25000. Then run sudo so-checkin on the forward node and verify that it picks up the new setting. Suricata should then purge old pcap until /nsm/suripcap is down to 25T. Then see if the sensor clean script stops deleting the suricata eve log.

Also, it looks like your old steno pcap has aged out so you should be able to switch from TRANSITION to SURICATA to stop running steno altogether. This won't necessarily help your disk space issue but it will lower CPU and RAM usage on th…

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@technox123
Comment options

@dougburks
Comment options

Answer selected by technox123
@technox123
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants