Log/Events retention in Security Onion 2.4.80 #13552
-
Hello all, By default for how long SO is keeping records like PCAP, alarm events etc? I have installed Standalone on 200GB HDD. Could not find option to control retention in configuration Thanks in Advance |
Beta Was this translation helpful? Give feedback.
Answered by
dougburks
Aug 27, 2024
Replies: 1 comment 1 reply
-
By default, Security Onion will try to store as much data as possible without filling up your storage. For more information, please see: |
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
networklord
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
By default, Security Onion will try to store as much data as possible without filling up your storage. For more information, please see:
https://docs.securityonion.net/en/2.4/stenographer.html#disk-free-percentage
https://docs.securityonion.net/en/2.4/elasticsearch.html#index-management