Replies: 3 comments 1 reply
-
Temporal solution: |
Beta Was this translation helpful? Give feedback.
-
https://docs.securityonion.net/en/2.4/elasticsearch.html#cluster You have are runing a multi-node cluster. The above command will keep data off your manager node. You can further remove the |
Beta Was this translation helpful? Give feedback.
-
Hi m-ops, thank you, I think it should be by default on the distribute env and the manager node. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.80
Installation Method
Security Onion ISO image
Description
installation
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
16
RAM
512
Storage for /
100
Storage for /nsm
1tb
Network Traffic Collection
span port
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
Hi security onion team,
I see that the log is being save on the manager and the Search node at the same time, when the manager should run it own instance of Elasticsearch which cause the disk of manager to be full. I have 3 node 1 receiver,manager,search , when I check the /nsm,elasticsearch/indices/ I have the same amount of log on the search as the manger which according to the doc should not be possible because the manager run it own instance of elasticsearch.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions