Increasing the number of Suricata and Zeek instances #1924
-
Hi All, Does anyone know how I can increase the number of Suricata and Zeek instances running on my Standalone Security Onion 2.3? I used the defaults (1 instance) during set up and Grafana is showing a lot of PCAP packet loss (about 50%), but my CPU usage is quite low. The docs make it sound like increasing the Suricata instances will help lower the PCAP packet loss. Does this sound right to anyone? Thank you! |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 4 replies
-
Edit your minion's sls file: Updated these: |
Beta Was this translation helpful? Give feedback.
-
Restart services: |
Beta Was this translation helpful? Give feedback.
-
If Grafana is showing Suricata packet loss, then you would want to tune Suricata. If Grafana is showing Zeek packet loss, then you would want to tune Zeek. If Grafana is showing PCAP packet loss, then that doesn't necessarily mean that you need to tune Zeek or Suricata, as those processes are totally independent of the Stenographer process that performs full packet capture: You might want to start with filtering out traffic that you don't want Stenographer to write to disk: |
Beta Was this translation helpful? Give feedback.
Edit your minion's sls file:
/opt/so/saltstack/local/pillar/minions/so-sensor01_sensor.sls
Updated these:
zeek_lbprocs
suriprocs