Skip to content
Discussion options

You must be logged in to vote

There is a so-sensor-clean script that handles deleting the zeek logs based on the crit_disk_usage function, which is 90%. Another option would be to utilize BPFs to filter out zeek logs that are not relevant to your environment. More info here: https://docs.securityonion.net/en/2.4/bpf.html#bpf

In the mean time, you could manually delete those older zeek logs to free up some space.

Replies: 4 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by ejgh-oe
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants