Replies: 1 comment 7 replies
-
|
What does these return? You can also check your |
Beta Was this translation helpful? Give feedback.
7 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.180
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
airgap
Hardware Specs
Meets minimum requirements
CPU
8
RAM
16
Storage for /
500 GB
Storage for /nsm
350 gb
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
I am trying to find practical steps on tracking why I am losing auditd logs from my security onion instance everyday. I have not altered the default index retention settings but everyday at least twice a day I see a massive drop in my count of auditd logs. All of my nodes have many GBs of space remaining and this deployment is only 8 days old so im sure im not hitting retention periods this quickly.
The documentation page has very vague details on how this process works outside of the manual configuration changes you can make to determine how long data should be searchable. But I need to see why are my logs dropping and a potential fix for this.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions