-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU10 RAM32 Storage for /500GB Storage for /nsm500GB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi, The problem: Disk space on the manager node regularly fills up beyond 80% causing elasticsearch and/or elastalert to shut down. In order to make them start again I've drastically reduced the retention periods for warm, cold and delete phases via the admin gui from their defaults to several days. While this makes elasticsearch/elastalert start again this can't be a long term solution. So I came up with the following ideas:
Thanks much in advance for any clue Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Have you seen this section of our documentation?
|
Beta Was this translation helpful? Give feedback.
Yes, you can do that on the fly without data loss if you follow the directions at: https://docs.securityonion.net/en/2.4/elasticsearch.html#elasticsearch-node-roles
Make sure you see the other page that it links to at:
https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-cluster.html#cluster-shard-allocation-filtering