Replies: 1 comment 4 replies
-
In the upcoming version 2.4.180, the combined setting will default to 1 but you'll be able to set the value to whatever works best for your deployment. Our testing so far has indicated that combined 1 should be an improvement for the vast majority of deployments out there. For your one server to have that much of a change in performance definitely seems like an anomaly and I have to wonder if there is something else going on. Is this a physical machine or VM? Is it one physical CPU or multiple? How many Zeek workers? How many Suricata workers? Any other sniffing processes on the box? In addition to the capture loss statistics share above, what was the Zeek packet loss during this time? It's also worth noting that Zeek capture loss can be indicative of upstream loss in your SPAN port so it may not be an issue with your Security Onion machine or its configuration. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.170
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Meets minimum requirements
CPU
128
RAM
256
Storage for /
3.5 TB
Storage for /nsm
24 TB
Network Traffic Collection
span port
Network Traffic Speeds
more than 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
Yes, there are additional clues in /opt/so/log/ (please provide detail below)
Detail
Hi guys!
I always follow your updates closely. I would like to address my case of the topic with changing NIC Channels combined to 1 for monitor interfaces. This actually works on most of our sensors. But there is one server where applying this setting has different consequences. In general, there is a server with two INTEL XXV710 for 25GbE SFP28 cards. The following settings are already installed on them:
With a dynamic value of combined 119 (out of 128), we get the following drops:
However, after setting both maps to combined 1, we get the following:
Moreover, before changing the value, the incoming traffic on monitoring was 10-25 Gb/s, and after the change it was 4-5 Gb/s.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions