Abandoned Suripcap directories #15671
Unanswered
alan-lafleur
asked this question in
2.4
Replies: 1 comment 1 reply
-
|
What is your Do you need to query for PCAP during the time frame of the PCAP? If not you could remove them. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.211
Installation Method
Security Onion ISO image
Description
other (please provide detail below)
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
20 physical, 80 logical
RAM
132 Gig
Storage for /
293G
Storage for /nsm
1.5T
Network Traffic Collection
span port
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
I had increased the threads for Suricata up to 78 at one point as a test, then backed down to 48 which is what I have currently. Looking in /nsm/suripcap, I see folders 49-78 in there and appear to no longer be written to based on the date.
Will these folders eventually be removed automatically or can I go in and manually delete them without fear of corruption?
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions